bundle.yaml 1.9 MB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117211821192120212121222123212421252126212721282129213021312132213321342135213621372138213921402141214221432144214521462147214821492150215121522153215421552156215721582159216021612162216321642165216621672168216921702171217221732174217521762177217821792180218121822183218421852186218721882189219021912192219321942195219621972198219922002201220222032204220522062207220822092210221122122213221422152216221722182219222022212222222322242225222622272228222922302231223222332234223522362237223822392240224122422243224422452246224722482249225022512252225322542255225622572258225922602261226222632264226522662267226822692270227122722273227422752276227722782279228022812282228322842285228622872288228922902291229222932294229522962297229822992300230123022303230423052306230723082309231023112312231323142315231623172318231923202321232223232324232523262327232823292330233123322333233423352336233723382339234023412342234323442345234623472348234923502351235223532354235523562357235823592360236123622363236423652366236723682369237023712372237323742375237623772378237923802381238223832384238523862387238823892390239123922393239423952396239723982399240024012402240324042405240624072408240924102411241224132414241524162417241824192420242124222423242424252426242724282429243024312432243324342435243624372438243924402441244224432444244524462447244824492450245124522453245424552456245724582459246024612462246324642465246624672468246924702471247224732474247524762477247824792480248124822483248424852486248724882489249024912492249324942495249624972498249925002501250225032504250525062507250825092510251125122513251425152516251725182519252025212522252325242525252625272528252925302531253225332534253525362537253825392540254125422543254425452546254725482549255025512552255325542555255625572558255925602561256225632564256525662567256825692570257125722573257425752576257725782579258025812582258325842585258625872588258925902591259225932594259525962597259825992600260126022603260426052606260726082609261026112612261326142615261626172618261926202621262226232624262526262627262826292630263126322633263426352636263726382639264026412642264326442645264626472648264926502651265226532654265526562657265826592660266126622663266426652666266726682669267026712672267326742675267626772678267926802681268226832684268526862687268826892690269126922693269426952696269726982699270027012702270327042705270627072708270927102711271227132714271527162717271827192720272127222723272427252726272727282729273027312732273327342735273627372738273927402741274227432744274527462747274827492750275127522753275427552756275727582759276027612762276327642765276627672768276927702771277227732774277527762777277827792780278127822783278427852786278727882789279027912792279327942795279627972798279928002801280228032804280528062807280828092810281128122813281428152816281728182819282028212822282328242825282628272828282928302831283228332834283528362837283828392840284128422843284428452846284728482849285028512852285328542855285628572858285928602861286228632864286528662867286828692870287128722873287428752876287728782879288028812882288328842885288628872888288928902891289228932894289528962897289828992900290129022903290429052906290729082909291029112912291329142915291629172918291929202921292229232924292529262927292829292930293129322933293429352936293729382939294029412942294329442945294629472948294929502951295229532954295529562957295829592960296129622963296429652966296729682969297029712972297329742975297629772978297929802981298229832984298529862987298829892990299129922993299429952996299729982999300030013002300330043005300630073008300930103011301230133014301530163017301830193020302130223023302430253026302730283029303030313032303330343035303630373038303930403041304230433044304530463047304830493050305130523053305430553056305730583059306030613062306330643065306630673068306930703071307230733074307530763077307830793080308130823083308430853086308730883089309030913092309330943095309630973098309931003101310231033104310531063107310831093110311131123113311431153116311731183119312031213122312331243125312631273128312931303131313231333134313531363137313831393140314131423143314431453146314731483149315031513152315331543155315631573158315931603161316231633164316531663167316831693170317131723173317431753176317731783179318031813182318331843185318631873188318931903191319231933194319531963197319831993200320132023203320432053206320732083209321032113212321332143215321632173218321932203221322232233224322532263227322832293230323132323233323432353236323732383239324032413242324332443245324632473248324932503251325232533254325532563257325832593260326132623263326432653266326732683269327032713272327332743275327632773278327932803281328232833284328532863287328832893290329132923293329432953296329732983299330033013302330333043305330633073308330933103311331233133314331533163317331833193320332133223323332433253326332733283329333033313332333333343335333633373338333933403341334233433344334533463347334833493350335133523353335433553356335733583359336033613362336333643365336633673368336933703371337233733374337533763377337833793380338133823383338433853386338733883389339033913392339333943395339633973398339934003401340234033404340534063407340834093410341134123413341434153416341734183419342034213422342334243425342634273428342934303431343234333434343534363437343834393440344134423443344434453446344734483449345034513452345334543455345634573458345934603461346234633464346534663467346834693470347134723473347434753476347734783479348034813482348334843485348634873488348934903491349234933494349534963497349834993500350135023503350435053506350735083509351035113512351335143515351635173518351935203521352235233524352535263527352835293530353135323533353435353536353735383539354035413542354335443545354635473548354935503551355235533554355535563557355835593560356135623563356435653566356735683569357035713572357335743575357635773578357935803581358235833584358535863587358835893590359135923593359435953596359735983599360036013602360336043605360636073608360936103611361236133614361536163617361836193620362136223623362436253626362736283629363036313632363336343635363636373638363936403641364236433644364536463647364836493650365136523653365436553656365736583659366036613662366336643665366636673668366936703671367236733674367536763677367836793680368136823683368436853686368736883689369036913692369336943695369636973698369937003701370237033704370537063707370837093710371137123713371437153716371737183719372037213722372337243725372637273728372937303731373237333734373537363737373837393740374137423743374437453746374737483749375037513752375337543755375637573758375937603761376237633764376537663767376837693770377137723773377437753776377737783779378037813782378337843785378637873788378937903791379237933794379537963797379837993800380138023803380438053806380738083809381038113812381338143815381638173818381938203821382238233824382538263827382838293830383138323833383438353836383738383839384038413842384338443845384638473848384938503851385238533854385538563857385838593860386138623863386438653866386738683869387038713872387338743875387638773878387938803881388238833884388538863887388838893890389138923893389438953896389738983899390039013902390339043905390639073908390939103911391239133914391539163917391839193920392139223923392439253926392739283929393039313932393339343935393639373938393939403941394239433944394539463947394839493950395139523953395439553956395739583959396039613962396339643965396639673968396939703971397239733974397539763977397839793980398139823983398439853986398739883989399039913992399339943995399639973998399940004001400240034004400540064007400840094010401140124013401440154016401740184019402040214022402340244025402640274028402940304031403240334034403540364037403840394040404140424043404440454046404740484049405040514052405340544055405640574058405940604061406240634064406540664067406840694070407140724073407440754076407740784079408040814082408340844085408640874088408940904091409240934094409540964097409840994100410141024103410441054106410741084109411041114112411341144115411641174118411941204121412241234124412541264127412841294130413141324133413441354136413741384139414041414142414341444145414641474148414941504151415241534154415541564157415841594160416141624163416441654166416741684169417041714172417341744175417641774178417941804181418241834184418541864187418841894190419141924193419441954196419741984199420042014202420342044205420642074208420942104211421242134214421542164217421842194220422142224223422442254226422742284229423042314232423342344235423642374238423942404241424242434244424542464247424842494250425142524253425442554256425742584259426042614262426342644265426642674268426942704271427242734274427542764277427842794280428142824283428442854286428742884289429042914292429342944295429642974298429943004301430243034304430543064307430843094310431143124313431443154316431743184319432043214322432343244325432643274328432943304331433243334334433543364337433843394340434143424343434443454346434743484349435043514352435343544355435643574358435943604361436243634364436543664367436843694370437143724373437443754376437743784379438043814382438343844385438643874388438943904391439243934394439543964397439843994400440144024403440444054406440744084409441044114412441344144415441644174418441944204421442244234424442544264427442844294430443144324433443444354436443744384439444044414442444344444445444644474448444944504451445244534454445544564457445844594460446144624463446444654466446744684469447044714472447344744475447644774478447944804481448244834484448544864487448844894490449144924493449444954496449744984499450045014502450345044505450645074508450945104511451245134514451545164517451845194520452145224523452445254526452745284529453045314532453345344535453645374538453945404541454245434544454545464547454845494550455145524553455445554556455745584559456045614562456345644565456645674568456945704571457245734574457545764577457845794580458145824583458445854586458745884589459045914592459345944595459645974598459946004601460246034604460546064607460846094610461146124613461446154616461746184619462046214622462346244625462646274628462946304631463246334634463546364637463846394640464146424643464446454646464746484649465046514652465346544655465646574658465946604661466246634664466546664667466846694670467146724673467446754676467746784679468046814682468346844685468646874688468946904691469246934694469546964697469846994700470147024703470447054706470747084709471047114712471347144715471647174718471947204721472247234724472547264727472847294730473147324733473447354736473747384739474047414742474347444745474647474748474947504751475247534754475547564757475847594760476147624763476447654766476747684769477047714772477347744775477647774778477947804781478247834784478547864787478847894790479147924793479447954796479747984799480048014802480348044805480648074808480948104811481248134814481548164817481848194820482148224823482448254826482748284829483048314832483348344835483648374838483948404841484248434844484548464847484848494850485148524853485448554856485748584859486048614862486348644865486648674868486948704871487248734874487548764877487848794880488148824883488448854886488748884889489048914892489348944895489648974898489949004901490249034904490549064907490849094910491149124913491449154916491749184919492049214922492349244925492649274928492949304931493249334934493549364937493849394940494149424943494449454946494749484949495049514952495349544955495649574958495949604961496249634964496549664967496849694970497149724973497449754976497749784979498049814982498349844985498649874988498949904991499249934994499549964997499849995000500150025003500450055006500750085009501050115012501350145015501650175018501950205021502250235024502550265027502850295030503150325033503450355036503750385039504050415042504350445045504650475048504950505051505250535054505550565057505850595060506150625063506450655066506750685069507050715072507350745075507650775078507950805081508250835084508550865087508850895090509150925093509450955096509750985099510051015102510351045105510651075108510951105111511251135114511551165117511851195120512151225123512451255126512751285129513051315132513351345135513651375138513951405141514251435144514551465147514851495150515151525153515451555156515751585159516051615162516351645165516651675168516951705171517251735174517551765177517851795180518151825183518451855186518751885189519051915192519351945195519651975198519952005201520252035204520552065207520852095210521152125213521452155216521752185219522052215222522352245225522652275228522952305231523252335234523552365237523852395240524152425243524452455246524752485249525052515252525352545255525652575258525952605261526252635264526552665267526852695270527152725273527452755276527752785279528052815282528352845285528652875288528952905291529252935294529552965297529852995300530153025303530453055306530753085309531053115312531353145315531653175318531953205321532253235324532553265327532853295330533153325333533453355336533753385339534053415342534353445345534653475348534953505351535253535354535553565357535853595360536153625363536453655366536753685369537053715372537353745375537653775378537953805381538253835384538553865387538853895390539153925393539453955396539753985399540054015402540354045405540654075408540954105411541254135414541554165417541854195420542154225423542454255426542754285429543054315432543354345435543654375438543954405441544254435444544554465447544854495450545154525453545454555456545754585459546054615462546354645465546654675468546954705471547254735474547554765477547854795480548154825483548454855486548754885489549054915492549354945495549654975498549955005501550255035504550555065507550855095510551155125513551455155516551755185519552055215522552355245525552655275528552955305531553255335534553555365537553855395540554155425543554455455546554755485549555055515552555355545555555655575558555955605561556255635564556555665567556855695570557155725573557455755576557755785579558055815582558355845585558655875588558955905591559255935594559555965597559855995600560156025603560456055606560756085609561056115612561356145615561656175618561956205621562256235624562556265627562856295630563156325633563456355636563756385639564056415642564356445645564656475648564956505651565256535654565556565657565856595660566156625663566456655666566756685669567056715672567356745675567656775678567956805681568256835684568556865687568856895690569156925693569456955696569756985699570057015702570357045705570657075708570957105711571257135714571557165717571857195720572157225723572457255726572757285729573057315732573357345735573657375738573957405741574257435744574557465747574857495750575157525753575457555756575757585759576057615762576357645765576657675768576957705771577257735774577557765777577857795780578157825783578457855786578757885789579057915792579357945795579657975798579958005801580258035804580558065807580858095810581158125813581458155816581758185819582058215822582358245825582658275828582958305831583258335834583558365837583858395840584158425843584458455846584758485849585058515852585358545855585658575858585958605861586258635864586558665867586858695870587158725873587458755876587758785879588058815882588358845885588658875888588958905891589258935894589558965897589858995900590159025903590459055906590759085909591059115912591359145915591659175918591959205921592259235924592559265927592859295930593159325933593459355936593759385939594059415942594359445945594659475948594959505951595259535954595559565957595859595960596159625963596459655966596759685969597059715972597359745975597659775978597959805981598259835984598559865987598859895990599159925993599459955996599759985999600060016002600360046005600660076008600960106011601260136014601560166017601860196020602160226023602460256026602760286029603060316032603360346035603660376038603960406041604260436044604560466047604860496050605160526053605460556056605760586059606060616062606360646065606660676068606960706071607260736074607560766077607860796080608160826083608460856086608760886089609060916092609360946095609660976098609961006101610261036104610561066107610861096110611161126113611461156116611761186119612061216122612361246125612661276128612961306131613261336134613561366137613861396140614161426143614461456146614761486149615061516152615361546155615661576158615961606161616261636164616561666167616861696170617161726173617461756176617761786179618061816182618361846185618661876188618961906191619261936194619561966197619861996200620162026203620462056206620762086209621062116212621362146215621662176218621962206221622262236224622562266227622862296230623162326233623462356236623762386239624062416242624362446245624662476248624962506251625262536254625562566257625862596260626162626263626462656266626762686269627062716272627362746275627662776278627962806281628262836284628562866287628862896290629162926293629462956296629762986299630063016302630363046305630663076308630963106311631263136314631563166317631863196320632163226323632463256326632763286329633063316332633363346335633663376338633963406341634263436344634563466347634863496350635163526353635463556356635763586359636063616362636363646365636663676368636963706371637263736374637563766377637863796380638163826383638463856386638763886389639063916392639363946395639663976398639964006401640264036404640564066407640864096410641164126413641464156416641764186419642064216422642364246425642664276428642964306431643264336434643564366437643864396440644164426443644464456446644764486449645064516452645364546455645664576458645964606461646264636464646564666467646864696470647164726473647464756476647764786479648064816482648364846485648664876488648964906491649264936494649564966497649864996500650165026503650465056506650765086509651065116512651365146515651665176518651965206521652265236524652565266527652865296530653165326533653465356536653765386539654065416542654365446545654665476548654965506551655265536554655565566557655865596560656165626563656465656566656765686569657065716572657365746575657665776578657965806581658265836584658565866587658865896590659165926593659465956596659765986599660066016602660366046605660666076608660966106611661266136614661566166617661866196620662166226623662466256626662766286629663066316632663366346635663666376638663966406641664266436644664566466647664866496650665166526653665466556656665766586659666066616662666366646665666666676668666966706671667266736674667566766677667866796680668166826683668466856686668766886689669066916692669366946695669666976698669967006701670267036704670567066707670867096710671167126713671467156716671767186719672067216722672367246725672667276728672967306731673267336734673567366737673867396740674167426743674467456746674767486749675067516752675367546755675667576758675967606761676267636764676567666767676867696770677167726773677467756776677767786779678067816782678367846785678667876788678967906791679267936794679567966797679867996800680168026803680468056806680768086809681068116812681368146815681668176818681968206821682268236824682568266827682868296830683168326833683468356836683768386839684068416842684368446845684668476848684968506851685268536854685568566857685868596860686168626863686468656866686768686869687068716872687368746875687668776878687968806881688268836884688568866887688868896890689168926893689468956896689768986899690069016902690369046905690669076908690969106911691269136914691569166917691869196920692169226923692469256926692769286929693069316932693369346935693669376938693969406941694269436944694569466947694869496950695169526953695469556956695769586959696069616962696369646965696669676968696969706971697269736974697569766977697869796980698169826983698469856986698769886989699069916992699369946995699669976998699970007001700270037004700570067007700870097010701170127013701470157016701770187019702070217022702370247025702670277028702970307031703270337034703570367037703870397040704170427043704470457046704770487049705070517052705370547055705670577058705970607061706270637064706570667067706870697070707170727073707470757076707770787079708070817082708370847085708670877088708970907091709270937094709570967097709870997100710171027103710471057106710771087109711071117112711371147115711671177118711971207121712271237124712571267127712871297130713171327133713471357136713771387139714071417142714371447145714671477148714971507151715271537154715571567157715871597160716171627163716471657166716771687169717071717172717371747175717671777178717971807181718271837184718571867187718871897190719171927193719471957196719771987199720072017202720372047205720672077208720972107211721272137214721572167217721872197220722172227223722472257226722772287229723072317232723372347235723672377238723972407241724272437244724572467247724872497250725172527253725472557256725772587259726072617262726372647265726672677268726972707271727272737274727572767277727872797280728172827283728472857286728772887289729072917292729372947295729672977298729973007301730273037304730573067307730873097310731173127313731473157316731773187319732073217322732373247325732673277328732973307331733273337334733573367337733873397340734173427343734473457346734773487349735073517352735373547355735673577358735973607361736273637364736573667367736873697370737173727373737473757376737773787379738073817382738373847385738673877388738973907391739273937394739573967397739873997400740174027403740474057406740774087409741074117412741374147415741674177418741974207421742274237424742574267427742874297430743174327433743474357436743774387439744074417442744374447445744674477448744974507451745274537454745574567457745874597460746174627463746474657466746774687469747074717472747374747475747674777478747974807481748274837484748574867487748874897490749174927493749474957496749774987499750075017502750375047505750675077508750975107511751275137514751575167517751875197520752175227523752475257526752775287529753075317532753375347535753675377538753975407541754275437544754575467547754875497550755175527553755475557556755775587559756075617562756375647565756675677568756975707571757275737574757575767577757875797580758175827583758475857586758775887589759075917592759375947595759675977598759976007601760276037604760576067607760876097610761176127613761476157616761776187619762076217622762376247625762676277628762976307631763276337634763576367637763876397640764176427643764476457646764776487649765076517652765376547655765676577658765976607661766276637664766576667667766876697670767176727673767476757676767776787679768076817682768376847685768676877688768976907691769276937694769576967697769876997700770177027703770477057706770777087709771077117712771377147715771677177718771977207721772277237724772577267727772877297730773177327733773477357736773777387739774077417742774377447745774677477748774977507751775277537754775577567757775877597760776177627763776477657766776777687769777077717772777377747775777677777778777977807781778277837784778577867787778877897790779177927793779477957796779777987799780078017802780378047805780678077808780978107811781278137814781578167817781878197820782178227823782478257826782778287829783078317832783378347835783678377838783978407841784278437844784578467847784878497850785178527853785478557856785778587859786078617862786378647865786678677868786978707871787278737874787578767877787878797880788178827883788478857886788778887889789078917892789378947895789678977898789979007901790279037904790579067907790879097910791179127913791479157916791779187919792079217922792379247925792679277928792979307931793279337934793579367937793879397940794179427943794479457946794779487949795079517952795379547955795679577958795979607961796279637964796579667967796879697970797179727973797479757976797779787979798079817982798379847985798679877988798979907991799279937994799579967997799879998000800180028003800480058006800780088009801080118012801380148015801680178018801980208021802280238024802580268027802880298030803180328033803480358036803780388039804080418042804380448045804680478048804980508051805280538054805580568057805880598060806180628063806480658066806780688069807080718072807380748075807680778078807980808081808280838084808580868087808880898090809180928093809480958096809780988099810081018102810381048105810681078108810981108111811281138114811581168117811881198120812181228123812481258126812781288129813081318132813381348135813681378138813981408141814281438144814581468147814881498150815181528153815481558156815781588159816081618162816381648165816681678168816981708171817281738174817581768177817881798180818181828183818481858186818781888189819081918192819381948195819681978198819982008201820282038204820582068207820882098210821182128213821482158216821782188219822082218222822382248225822682278228822982308231823282338234823582368237823882398240824182428243824482458246824782488249825082518252825382548255825682578258825982608261826282638264826582668267826882698270827182728273827482758276827782788279828082818282828382848285828682878288828982908291829282938294829582968297829882998300830183028303830483058306830783088309831083118312831383148315831683178318831983208321832283238324832583268327832883298330833183328333833483358336833783388339834083418342834383448345834683478348834983508351835283538354835583568357835883598360836183628363836483658366836783688369837083718372837383748375837683778378837983808381838283838384838583868387838883898390839183928393839483958396839783988399840084018402840384048405840684078408840984108411841284138414841584168417841884198420842184228423842484258426842784288429843084318432843384348435843684378438843984408441844284438444844584468447844884498450845184528453845484558456845784588459846084618462846384648465846684678468846984708471847284738474847584768477847884798480848184828483848484858486848784888489849084918492849384948495849684978498849985008501850285038504850585068507850885098510851185128513851485158516851785188519852085218522852385248525852685278528852985308531853285338534853585368537853885398540854185428543854485458546854785488549855085518552855385548555855685578558855985608561856285638564856585668567856885698570857185728573857485758576857785788579858085818582858385848585858685878588858985908591859285938594859585968597859885998600860186028603860486058606860786088609861086118612861386148615861686178618861986208621862286238624862586268627862886298630863186328633863486358636863786388639864086418642864386448645864686478648864986508651865286538654865586568657865886598660866186628663866486658666866786688669867086718672867386748675867686778678867986808681868286838684868586868687868886898690869186928693869486958696869786988699870087018702870387048705870687078708870987108711871287138714871587168717871887198720872187228723872487258726872787288729873087318732873387348735873687378738873987408741874287438744874587468747874887498750875187528753875487558756875787588759876087618762876387648765876687678768876987708771877287738774877587768777877887798780878187828783878487858786878787888789879087918792879387948795879687978798879988008801880288038804880588068807880888098810881188128813881488158816881788188819882088218822882388248825882688278828882988308831883288338834883588368837883888398840884188428843884488458846884788488849885088518852885388548855885688578858885988608861886288638864886588668867886888698870887188728873887488758876887788788879888088818882888388848885888688878888888988908891889288938894889588968897889888998900890189028903890489058906890789088909891089118912891389148915891689178918891989208921892289238924892589268927892889298930893189328933893489358936893789388939894089418942894389448945894689478948894989508951895289538954895589568957895889598960896189628963896489658966896789688969897089718972897389748975897689778978897989808981898289838984898589868987898889898990899189928993899489958996899789988999900090019002900390049005900690079008900990109011901290139014901590169017901890199020902190229023902490259026902790289029903090319032903390349035903690379038903990409041904290439044904590469047904890499050905190529053905490559056905790589059906090619062906390649065906690679068906990709071907290739074907590769077907890799080908190829083908490859086908790889089909090919092909390949095909690979098909991009101910291039104910591069107910891099110911191129113911491159116911791189119912091219122912391249125912691279128912991309131913291339134913591369137913891399140914191429143914491459146914791489149915091519152915391549155915691579158915991609161916291639164916591669167916891699170917191729173917491759176917791789179918091819182918391849185918691879188918991909191919291939194919591969197919891999200920192029203920492059206920792089209921092119212921392149215921692179218921992209221922292239224922592269227922892299230923192329233923492359236923792389239924092419242924392449245924692479248924992509251925292539254925592569257925892599260926192629263926492659266926792689269927092719272927392749275927692779278927992809281928292839284928592869287928892899290929192929293929492959296929792989299930093019302930393049305930693079308930993109311931293139314931593169317931893199320932193229323932493259326932793289329933093319332933393349335933693379338933993409341934293439344934593469347934893499350935193529353935493559356935793589359936093619362936393649365936693679368936993709371937293739374937593769377937893799380938193829383938493859386938793889389939093919392939393949395939693979398939994009401940294039404940594069407940894099410941194129413941494159416941794189419942094219422942394249425942694279428942994309431943294339434943594369437943894399440944194429443944494459446944794489449945094519452945394549455945694579458945994609461946294639464946594669467946894699470947194729473947494759476947794789479948094819482948394849485948694879488948994909491949294939494949594969497949894999500950195029503950495059506950795089509951095119512951395149515951695179518951995209521952295239524952595269527952895299530953195329533953495359536953795389539954095419542954395449545954695479548954995509551955295539554955595569557955895599560956195629563956495659566956795689569957095719572957395749575957695779578957995809581958295839584958595869587958895899590959195929593959495959596959795989599960096019602960396049605960696079608960996109611961296139614961596169617961896199620962196229623962496259626962796289629963096319632963396349635963696379638963996409641964296439644964596469647964896499650965196529653965496559656965796589659966096619662966396649665966696679668966996709671967296739674967596769677967896799680968196829683968496859686968796889689969096919692969396949695969696979698969997009701970297039704970597069707970897099710971197129713971497159716971797189719972097219722972397249725972697279728972997309731973297339734973597369737973897399740974197429743974497459746974797489749975097519752975397549755975697579758975997609761976297639764976597669767976897699770977197729773977497759776977797789779978097819782978397849785978697879788978997909791979297939794979597969797979897999800980198029803980498059806980798089809981098119812981398149815981698179818981998209821982298239824982598269827982898299830983198329833983498359836983798389839984098419842984398449845984698479848984998509851985298539854985598569857985898599860986198629863986498659866986798689869987098719872987398749875987698779878987998809881988298839884988598869887988898899890989198929893989498959896989798989899990099019902990399049905990699079908990999109911991299139914991599169917991899199920992199229923992499259926992799289929993099319932993399349935993699379938993999409941994299439944994599469947994899499950995199529953995499559956995799589959996099619962996399649965996699679968996999709971997299739974997599769977997899799980998199829983998499859986998799889989999099919992999399949995999699979998999910000100011000210003100041000510006100071000810009100101001110012100131001410015100161001710018100191002010021100221002310024100251002610027100281002910030100311003210033100341003510036100371003810039100401004110042100431004410045100461004710048100491005010051100521005310054100551005610057100581005910060100611006210063100641006510066100671006810069100701007110072100731007410075100761007710078100791008010081100821008310084100851008610087100881008910090100911009210093100941009510096100971009810099101001010110102101031010410105101061010710108101091011010111101121011310114101151011610117101181011910120101211012210123101241012510126101271012810129101301013110132101331013410135101361013710138101391014010141101421014310144101451014610147101481014910150101511015210153101541015510156101571015810159101601016110162101631016410165101661016710168101691017010171101721017310174101751017610177101781017910180101811018210183101841018510186101871018810189101901019110192101931019410195101961019710198101991020010201102021020310204102051020610207102081020910210102111021210213102141021510216102171021810219102201022110222102231022410225102261022710228102291023010231102321023310234102351023610237102381023910240102411024210243102441024510246102471024810249102501025110252102531025410255102561025710258102591026010261102621026310264102651026610267102681026910270102711027210273102741027510276102771027810279102801028110282102831028410285102861028710288102891029010291102921029310294102951029610297102981029910300103011030210303103041030510306103071030810309103101031110312103131031410315103161031710318103191032010321103221032310324103251032610327103281032910330103311033210333103341033510336103371033810339103401034110342103431034410345103461034710348103491035010351103521035310354103551035610357103581035910360103611036210363103641036510366103671036810369103701037110372103731037410375103761037710378103791038010381103821038310384103851038610387103881038910390103911039210393103941039510396103971039810399104001040110402104031040410405104061040710408104091041010411104121041310414104151041610417104181041910420104211042210423104241042510426104271042810429104301043110432104331043410435104361043710438104391044010441104421044310444104451044610447104481044910450104511045210453104541045510456104571045810459104601046110462104631046410465104661046710468104691047010471104721047310474104751047610477104781047910480104811048210483104841048510486104871048810489104901049110492104931049410495104961049710498104991050010501105021050310504105051050610507105081050910510105111051210513105141051510516105171051810519105201052110522105231052410525105261052710528105291053010531105321053310534105351053610537105381053910540105411054210543105441054510546105471054810549105501055110552105531055410555105561055710558105591056010561105621056310564105651056610567105681056910570105711057210573105741057510576105771057810579105801058110582105831058410585105861058710588105891059010591105921059310594105951059610597105981059910600106011060210603106041060510606106071060810609106101061110612106131061410615106161061710618106191062010621106221062310624106251062610627106281062910630106311063210633106341063510636106371063810639106401064110642106431064410645106461064710648106491065010651106521065310654106551065610657106581065910660106611066210663106641066510666106671066810669106701067110672106731067410675106761067710678106791068010681106821068310684106851068610687106881068910690106911069210693106941069510696106971069810699107001070110702107031070410705107061070710708107091071010711107121071310714107151071610717107181071910720107211072210723107241072510726107271072810729107301073110732107331073410735107361073710738107391074010741107421074310744107451074610747107481074910750107511075210753107541075510756107571075810759107601076110762107631076410765107661076710768107691077010771107721077310774107751077610777107781077910780107811078210783107841078510786107871078810789107901079110792107931079410795107961079710798107991080010801108021080310804108051080610807108081080910810108111081210813108141081510816108171081810819108201082110822108231082410825108261082710828108291083010831108321083310834108351083610837108381083910840108411084210843108441084510846108471084810849108501085110852108531085410855108561085710858108591086010861108621086310864108651086610867108681086910870108711087210873108741087510876108771087810879108801088110882108831088410885108861088710888108891089010891108921089310894108951089610897108981089910900109011090210903109041090510906109071090810909109101091110912109131091410915109161091710918109191092010921109221092310924109251092610927109281092910930109311093210933109341093510936109371093810939109401094110942109431094410945109461094710948109491095010951109521095310954109551095610957109581095910960109611096210963109641096510966109671096810969109701097110972109731097410975109761097710978109791098010981109821098310984109851098610987109881098910990109911099210993109941099510996109971099810999110001100111002110031100411005110061100711008110091101011011110121101311014110151101611017110181101911020110211102211023110241102511026110271102811029110301103111032110331103411035110361103711038110391104011041110421104311044110451104611047110481104911050110511105211053110541105511056110571105811059110601106111062110631106411065110661106711068110691107011071110721107311074110751107611077110781107911080110811108211083110841108511086110871108811089110901109111092110931109411095110961109711098110991110011101111021110311104111051110611107111081110911110111111111211113111141111511116111171111811119111201112111122111231112411125111261112711128111291113011131111321113311134111351113611137111381113911140111411114211143111441114511146111471114811149111501115111152111531115411155111561115711158111591116011161111621116311164111651116611167111681116911170111711117211173111741117511176111771117811179111801118111182111831118411185111861118711188111891119011191111921119311194111951119611197111981119911200112011120211203112041120511206112071120811209112101121111212112131121411215112161121711218112191122011221112221122311224112251122611227112281122911230112311123211233112341123511236112371123811239112401124111242112431124411245112461124711248112491125011251112521125311254112551125611257112581125911260112611126211263112641126511266112671126811269112701127111272112731127411275112761127711278112791128011281112821128311284112851128611287112881128911290112911129211293112941129511296112971129811299113001130111302113031130411305113061130711308113091131011311113121131311314113151131611317113181131911320113211132211323113241132511326113271132811329113301133111332113331133411335113361133711338113391134011341113421134311344113451134611347113481134911350113511135211353113541135511356113571135811359113601136111362113631136411365113661136711368113691137011371113721137311374113751137611377113781137911380113811138211383113841138511386113871138811389113901139111392113931139411395113961139711398113991140011401114021140311404114051140611407114081140911410114111141211413114141141511416114171141811419114201142111422114231142411425114261142711428114291143011431114321143311434114351143611437114381143911440114411144211443114441144511446114471144811449114501145111452114531145411455114561145711458114591146011461114621146311464114651146611467114681146911470114711147211473114741147511476114771147811479114801148111482114831148411485114861148711488114891149011491114921149311494114951149611497114981149911500115011150211503115041150511506115071150811509115101151111512115131151411515115161151711518115191152011521115221152311524115251152611527115281152911530115311153211533115341153511536115371153811539115401154111542115431154411545115461154711548115491155011551115521155311554115551155611557115581155911560115611156211563115641156511566115671156811569115701157111572115731157411575115761157711578115791158011581115821158311584115851158611587115881158911590115911159211593115941159511596115971159811599116001160111602116031160411605116061160711608116091161011611116121161311614116151161611617116181161911620116211162211623116241162511626116271162811629116301163111632116331163411635116361163711638116391164011641116421164311644116451164611647116481164911650116511165211653116541165511656116571165811659116601166111662116631166411665116661166711668116691167011671116721167311674116751167611677116781167911680116811168211683116841168511686116871168811689116901169111692116931169411695116961169711698116991170011701117021170311704117051170611707117081170911710117111171211713117141171511716117171171811719117201172111722117231172411725117261172711728117291173011731117321173311734117351173611737117381173911740117411174211743117441174511746117471174811749117501175111752117531175411755117561175711758117591176011761117621176311764117651176611767117681176911770117711177211773117741177511776117771177811779117801178111782117831178411785117861178711788117891179011791117921179311794117951179611797117981179911800118011180211803118041180511806118071180811809118101181111812118131181411815118161181711818118191182011821118221182311824118251182611827118281182911830118311183211833118341183511836118371183811839118401184111842118431184411845118461184711848118491185011851118521185311854118551185611857118581185911860118611186211863118641186511866118671186811869118701187111872118731187411875118761187711878118791188011881118821188311884118851188611887118881188911890118911189211893118941189511896118971189811899119001190111902119031190411905119061190711908119091191011911119121191311914119151191611917119181191911920119211192211923119241192511926119271192811929119301193111932119331193411935119361193711938119391194011941119421194311944119451194611947119481194911950119511195211953119541195511956119571195811959119601196111962119631196411965119661196711968119691197011971119721197311974119751197611977119781197911980119811198211983119841198511986119871198811989119901199111992119931199411995119961199711998119991200012001120021200312004120051200612007120081200912010120111201212013120141201512016120171201812019120201202112022120231202412025120261202712028120291203012031120321203312034120351203612037120381203912040120411204212043120441204512046120471204812049120501205112052120531205412055120561205712058120591206012061120621206312064120651206612067120681206912070120711207212073120741207512076120771207812079120801208112082120831208412085120861208712088120891209012091120921209312094120951209612097120981209912100121011210212103121041210512106121071210812109121101211112112121131211412115121161211712118121191212012121121221212312124121251212612127121281212912130121311213212133121341213512136121371213812139121401214112142121431214412145121461214712148121491215012151121521215312154121551215612157121581215912160121611216212163121641216512166121671216812169121701217112172121731217412175121761217712178121791218012181121821218312184121851218612187121881218912190121911219212193121941219512196121971219812199122001220112202122031220412205122061220712208122091221012211122121221312214122151221612217122181221912220122211222212223122241222512226122271222812229122301223112232122331223412235122361223712238122391224012241122421224312244122451224612247122481224912250122511225212253122541225512256122571225812259122601226112262122631226412265122661226712268122691227012271122721227312274122751227612277122781227912280122811228212283122841228512286122871228812289122901229112292122931229412295122961229712298122991230012301123021230312304123051230612307123081230912310123111231212313123141231512316123171231812319123201232112322123231232412325123261232712328123291233012331123321233312334123351233612337123381233912340123411234212343123441234512346123471234812349123501235112352123531235412355123561235712358123591236012361123621236312364123651236612367123681236912370123711237212373123741237512376123771237812379123801238112382123831238412385123861238712388123891239012391123921239312394123951239612397123981239912400124011240212403124041240512406124071240812409124101241112412124131241412415124161241712418124191242012421124221242312424124251242612427124281242912430124311243212433124341243512436124371243812439124401244112442124431244412445124461244712448124491245012451124521245312454124551245612457124581245912460124611246212463124641246512466124671246812469124701247112472124731247412475124761247712478124791248012481124821248312484124851248612487124881248912490124911249212493124941249512496124971249812499125001250112502125031250412505125061250712508125091251012511125121251312514125151251612517125181251912520125211252212523125241252512526125271252812529125301253112532125331253412535125361253712538125391254012541125421254312544125451254612547125481254912550125511255212553125541255512556125571255812559125601256112562125631256412565125661256712568125691257012571125721257312574125751257612577125781257912580125811258212583125841258512586125871258812589125901259112592125931259412595125961259712598125991260012601126021260312604126051260612607126081260912610126111261212613126141261512616126171261812619126201262112622126231262412625126261262712628126291263012631126321263312634126351263612637126381263912640126411264212643126441264512646126471264812649126501265112652126531265412655126561265712658126591266012661126621266312664126651266612667126681266912670126711267212673126741267512676126771267812679126801268112682126831268412685126861268712688126891269012691126921269312694126951269612697126981269912700127011270212703127041270512706127071270812709127101271112712127131271412715127161271712718127191272012721127221272312724127251272612727127281272912730127311273212733127341273512736127371273812739127401274112742127431274412745127461274712748127491275012751127521275312754127551275612757127581275912760127611276212763127641276512766127671276812769127701277112772127731277412775127761277712778127791278012781127821278312784127851278612787127881278912790127911279212793127941279512796127971279812799128001280112802128031280412805128061280712808128091281012811128121281312814128151281612817128181281912820128211282212823128241282512826128271282812829128301283112832128331283412835128361283712838128391284012841128421284312844128451284612847128481284912850128511285212853128541285512856128571285812859128601286112862128631286412865128661286712868128691287012871128721287312874128751287612877128781287912880128811288212883128841288512886128871288812889128901289112892128931289412895128961289712898128991290012901129021290312904129051290612907129081290912910129111291212913129141291512916129171291812919129201292112922129231292412925129261292712928129291293012931129321293312934129351293612937129381293912940129411294212943129441294512946129471294812949129501295112952129531295412955129561295712958129591296012961129621296312964129651296612967129681296912970129711297212973129741297512976129771297812979129801298112982129831298412985129861298712988129891299012991129921299312994129951299612997129981299913000130011300213003130041300513006130071300813009130101301113012130131301413015130161301713018130191302013021130221302313024130251302613027130281302913030130311303213033130341303513036130371303813039130401304113042130431304413045130461304713048130491305013051130521305313054130551305613057130581305913060130611306213063130641306513066130671306813069130701307113072130731307413075130761307713078130791308013081130821308313084130851308613087130881308913090130911309213093130941309513096130971309813099131001310113102131031310413105131061310713108131091311013111131121311313114131151311613117131181311913120131211312213123131241312513126131271312813129131301313113132131331313413135131361313713138131391314013141131421314313144131451314613147131481314913150131511315213153131541315513156131571315813159131601316113162131631316413165131661316713168131691317013171131721317313174131751317613177131781317913180131811318213183131841318513186131871318813189131901319113192131931319413195131961319713198131991320013201132021320313204132051320613207132081320913210132111321213213132141321513216132171321813219132201322113222132231322413225132261322713228132291323013231132321323313234132351323613237132381323913240132411324213243132441324513246132471324813249132501325113252132531325413255132561325713258132591326013261132621326313264132651326613267132681326913270132711327213273132741327513276132771327813279132801328113282132831328413285132861328713288132891329013291132921329313294132951329613297132981329913300133011330213303133041330513306133071330813309133101331113312133131331413315133161331713318133191332013321133221332313324133251332613327133281332913330133311333213333133341333513336133371333813339133401334113342133431334413345133461334713348133491335013351133521335313354133551335613357133581335913360133611336213363133641336513366133671336813369133701337113372133731337413375133761337713378133791338013381133821338313384133851338613387133881338913390133911339213393133941339513396133971339813399134001340113402134031340413405134061340713408134091341013411134121341313414134151341613417134181341913420134211342213423134241342513426134271342813429134301343113432134331343413435134361343713438134391344013441134421344313444134451344613447134481344913450134511345213453134541345513456134571345813459134601346113462134631346413465134661346713468134691347013471134721347313474134751347613477134781347913480134811348213483134841348513486134871348813489134901349113492134931349413495134961349713498134991350013501135021350313504135051350613507135081350913510135111351213513135141351513516135171351813519135201352113522135231352413525135261352713528135291353013531135321353313534135351353613537135381353913540135411354213543135441354513546135471354813549135501355113552135531355413555135561355713558135591356013561135621356313564135651356613567135681356913570135711357213573135741357513576135771357813579135801358113582135831358413585135861358713588135891359013591135921359313594135951359613597135981359913600136011360213603136041360513606136071360813609136101361113612136131361413615136161361713618136191362013621136221362313624136251362613627136281362913630136311363213633136341363513636136371363813639136401364113642136431364413645136461364713648136491365013651136521365313654136551365613657136581365913660136611366213663136641366513666136671366813669136701367113672136731367413675136761367713678136791368013681136821368313684136851368613687136881368913690136911369213693136941369513696136971369813699137001370113702137031370413705137061370713708137091371013711137121371313714137151371613717137181371913720137211372213723137241372513726137271372813729137301373113732137331373413735137361373713738137391374013741137421374313744137451374613747137481374913750137511375213753137541375513756137571375813759137601376113762137631376413765137661376713768137691377013771137721377313774137751377613777137781377913780137811378213783137841378513786137871378813789137901379113792137931379413795137961379713798137991380013801138021380313804138051380613807138081380913810138111381213813138141381513816138171381813819138201382113822138231382413825138261382713828138291383013831138321383313834138351383613837138381383913840138411384213843138441384513846138471384813849138501385113852138531385413855138561385713858138591386013861138621386313864138651386613867138681386913870138711387213873138741387513876138771387813879138801388113882138831388413885138861388713888138891389013891138921389313894138951389613897138981389913900139011390213903139041390513906139071390813909139101391113912139131391413915139161391713918139191392013921139221392313924139251392613927139281392913930139311393213933139341393513936139371393813939139401394113942139431394413945139461394713948139491395013951139521395313954139551395613957139581395913960139611396213963139641396513966139671396813969139701397113972139731397413975139761397713978139791398013981139821398313984139851398613987139881398913990139911399213993139941399513996139971399813999140001400114002140031400414005140061400714008140091401014011140121401314014140151401614017140181401914020140211402214023140241402514026140271402814029140301403114032140331403414035140361403714038140391404014041140421404314044140451404614047140481404914050140511405214053140541405514056140571405814059140601406114062140631406414065140661406714068140691407014071140721407314074140751407614077140781407914080140811408214083140841408514086140871408814089140901409114092140931409414095140961409714098140991410014101141021410314104141051410614107141081410914110141111411214113141141411514116141171411814119141201412114122141231412414125141261412714128141291413014131141321413314134141351413614137141381413914140141411414214143141441414514146141471414814149141501415114152141531415414155141561415714158141591416014161141621416314164141651416614167141681416914170141711417214173141741417514176141771417814179141801418114182141831418414185141861418714188141891419014191141921419314194141951419614197141981419914200142011420214203142041420514206142071420814209142101421114212142131421414215142161421714218142191422014221142221422314224142251422614227142281422914230142311423214233142341423514236142371423814239142401424114242142431424414245142461424714248142491425014251142521425314254142551425614257142581425914260142611426214263142641426514266142671426814269142701427114272142731427414275142761427714278142791428014281142821428314284142851428614287142881428914290142911429214293142941429514296142971429814299143001430114302143031430414305143061430714308143091431014311143121431314314143151431614317143181431914320143211432214323143241432514326143271432814329143301433114332143331433414335143361433714338143391434014341143421434314344143451434614347143481434914350143511435214353143541435514356143571435814359143601436114362143631436414365143661436714368143691437014371143721437314374143751437614377143781437914380143811438214383143841438514386143871438814389143901439114392143931439414395143961439714398143991440014401144021440314404144051440614407144081440914410144111441214413144141441514416144171441814419144201442114422144231442414425144261442714428144291443014431144321443314434144351443614437144381443914440144411444214443144441444514446144471444814449144501445114452144531445414455144561445714458144591446014461144621446314464144651446614467144681446914470144711447214473144741447514476144771447814479144801448114482144831448414485144861448714488144891449014491144921449314494144951449614497144981449914500145011450214503145041450514506145071450814509145101451114512145131451414515145161451714518145191452014521145221452314524145251452614527145281452914530145311453214533145341453514536145371453814539145401454114542145431454414545145461454714548145491455014551145521455314554145551455614557145581455914560145611456214563145641456514566145671456814569145701457114572145731457414575145761457714578145791458014581145821458314584145851458614587145881458914590145911459214593145941459514596145971459814599146001460114602146031460414605146061460714608146091461014611146121461314614146151461614617146181461914620146211462214623146241462514626146271462814629146301463114632146331463414635146361463714638146391464014641146421464314644146451464614647146481464914650146511465214653146541465514656146571465814659146601466114662146631466414665146661466714668146691467014671146721467314674146751467614677146781467914680146811468214683146841468514686146871468814689146901469114692146931469414695146961469714698146991470014701147021470314704147051470614707147081470914710147111471214713147141471514716147171471814719147201472114722147231472414725147261472714728147291473014731147321473314734147351473614737147381473914740147411474214743147441474514746147471474814749147501475114752147531475414755147561475714758147591476014761147621476314764147651476614767147681476914770147711477214773147741477514776147771477814779147801478114782147831478414785147861478714788147891479014791147921479314794147951479614797147981479914800148011480214803148041480514806148071480814809148101481114812148131481414815148161481714818148191482014821148221482314824148251482614827148281482914830148311483214833148341483514836148371483814839148401484114842148431484414845148461484714848148491485014851148521485314854148551485614857148581485914860148611486214863148641486514866148671486814869148701487114872148731487414875148761487714878148791488014881148821488314884148851488614887148881488914890148911489214893148941489514896148971489814899149001490114902149031490414905149061490714908149091491014911149121491314914149151491614917149181491914920149211492214923149241492514926149271492814929149301493114932149331493414935149361493714938149391494014941149421494314944149451494614947149481494914950149511495214953149541495514956149571495814959149601496114962149631496414965149661496714968149691497014971149721497314974149751497614977149781497914980149811498214983149841498514986149871498814989149901499114992149931499414995149961499714998149991500015001150021500315004150051500615007150081500915010150111501215013150141501515016150171501815019150201502115022150231502415025150261502715028150291503015031150321503315034150351503615037150381503915040150411504215043150441504515046150471504815049150501505115052150531505415055150561505715058150591506015061150621506315064150651506615067150681506915070150711507215073150741507515076150771507815079150801508115082150831508415085150861508715088150891509015091150921509315094150951509615097150981509915100151011510215103151041510515106151071510815109151101511115112151131511415115151161511715118151191512015121151221512315124151251512615127151281512915130151311513215133151341513515136151371513815139151401514115142151431514415145151461514715148151491515015151151521515315154151551515615157151581515915160151611516215163151641516515166151671516815169151701517115172151731517415175151761517715178151791518015181151821518315184151851518615187151881518915190151911519215193151941519515196151971519815199152001520115202152031520415205152061520715208152091521015211152121521315214152151521615217152181521915220152211522215223152241522515226152271522815229152301523115232152331523415235152361523715238152391524015241152421524315244152451524615247152481524915250152511525215253152541525515256152571525815259152601526115262152631526415265152661526715268152691527015271152721527315274152751527615277152781527915280152811528215283152841528515286152871528815289152901529115292152931529415295152961529715298152991530015301153021530315304153051530615307153081530915310153111531215313153141531515316153171531815319153201532115322153231532415325153261532715328153291533015331153321533315334153351533615337153381533915340153411534215343153441534515346153471534815349153501535115352153531535415355153561535715358153591536015361153621536315364153651536615367153681536915370153711537215373153741537515376153771537815379153801538115382153831538415385153861538715388153891539015391153921539315394153951539615397153981539915400154011540215403154041540515406154071540815409154101541115412154131541415415154161541715418154191542015421154221542315424154251542615427154281542915430154311543215433154341543515436154371543815439154401544115442154431544415445154461544715448154491545015451154521545315454154551545615457154581545915460154611546215463154641546515466154671546815469154701547115472154731547415475154761547715478154791548015481154821548315484154851548615487154881548915490154911549215493154941549515496154971549815499155001550115502155031550415505155061550715508155091551015511155121551315514155151551615517155181551915520155211552215523155241552515526155271552815529155301553115532155331553415535155361553715538155391554015541155421554315544155451554615547155481554915550155511555215553155541555515556155571555815559155601556115562155631556415565155661556715568155691557015571155721557315574155751557615577155781557915580155811558215583155841558515586155871558815589155901559115592155931559415595155961559715598155991560015601156021560315604156051560615607156081560915610156111561215613156141561515616156171561815619156201562115622156231562415625156261562715628156291563015631156321563315634156351563615637156381563915640156411564215643156441564515646156471564815649156501565115652156531565415655156561565715658156591566015661156621566315664156651566615667156681566915670156711567215673156741567515676156771567815679156801568115682156831568415685156861568715688156891569015691156921569315694156951569615697156981569915700157011570215703157041570515706157071570815709157101571115712157131571415715157161571715718157191572015721157221572315724157251572615727157281572915730157311573215733157341573515736157371573815739157401574115742157431574415745157461574715748157491575015751157521575315754157551575615757157581575915760157611576215763157641576515766157671576815769157701577115772157731577415775157761577715778157791578015781157821578315784157851578615787157881578915790157911579215793157941579515796157971579815799158001580115802158031580415805158061580715808158091581015811158121581315814158151581615817158181581915820158211582215823158241582515826158271582815829158301583115832158331583415835158361583715838158391584015841158421584315844158451584615847158481584915850158511585215853158541585515856158571585815859158601586115862158631586415865158661586715868158691587015871158721587315874158751587615877158781587915880158811588215883158841588515886158871588815889158901589115892158931589415895158961589715898158991590015901159021590315904159051590615907159081590915910159111591215913159141591515916159171591815919159201592115922159231592415925159261592715928159291593015931159321593315934159351593615937159381593915940159411594215943159441594515946159471594815949159501595115952159531595415955159561595715958159591596015961159621596315964159651596615967159681596915970159711597215973159741597515976159771597815979159801598115982159831598415985159861598715988159891599015991159921599315994159951599615997159981599916000160011600216003160041600516006160071600816009160101601116012160131601416015160161601716018160191602016021160221602316024160251602616027160281602916030160311603216033160341603516036160371603816039160401604116042160431604416045160461604716048160491605016051160521605316054160551605616057160581605916060160611606216063160641606516066160671606816069160701607116072160731607416075160761607716078160791608016081160821608316084160851608616087160881608916090160911609216093160941609516096160971609816099161001610116102161031610416105161061610716108161091611016111161121611316114161151611616117161181611916120161211612216123161241612516126161271612816129161301613116132161331613416135161361613716138161391614016141161421614316144161451614616147161481614916150161511615216153161541615516156161571615816159161601616116162161631616416165161661616716168161691617016171161721617316174161751617616177161781617916180161811618216183161841618516186161871618816189161901619116192161931619416195161961619716198161991620016201162021620316204162051620616207162081620916210162111621216213162141621516216162171621816219162201622116222162231622416225162261622716228162291623016231162321623316234162351623616237162381623916240162411624216243162441624516246162471624816249162501625116252162531625416255162561625716258162591626016261162621626316264162651626616267162681626916270162711627216273162741627516276162771627816279162801628116282162831628416285162861628716288162891629016291162921629316294162951629616297162981629916300163011630216303163041630516306163071630816309163101631116312163131631416315163161631716318163191632016321163221632316324163251632616327163281632916330163311633216333163341633516336163371633816339163401634116342163431634416345163461634716348163491635016351163521635316354163551635616357163581635916360163611636216363163641636516366163671636816369163701637116372163731637416375163761637716378163791638016381163821638316384163851638616387163881638916390163911639216393163941639516396163971639816399164001640116402164031640416405164061640716408164091641016411164121641316414164151641616417164181641916420164211642216423164241642516426164271642816429164301643116432164331643416435164361643716438164391644016441164421644316444164451644616447164481644916450164511645216453164541645516456164571645816459164601646116462164631646416465164661646716468164691647016471164721647316474164751647616477164781647916480164811648216483164841648516486164871648816489164901649116492164931649416495164961649716498164991650016501165021650316504165051650616507165081650916510165111651216513165141651516516165171651816519165201652116522165231652416525165261652716528165291653016531165321653316534165351653616537165381653916540165411654216543165441654516546165471654816549165501655116552165531655416555165561655716558165591656016561165621656316564165651656616567165681656916570165711657216573165741657516576165771657816579165801658116582165831658416585165861658716588165891659016591165921659316594165951659616597165981659916600166011660216603166041660516606166071660816609166101661116612166131661416615166161661716618166191662016621166221662316624166251662616627166281662916630166311663216633166341663516636166371663816639166401664116642166431664416645166461664716648166491665016651166521665316654166551665616657166581665916660166611666216663166641666516666166671666816669166701667116672166731667416675166761667716678166791668016681166821668316684166851668616687166881668916690166911669216693166941669516696166971669816699167001670116702167031670416705167061670716708167091671016711167121671316714167151671616717167181671916720167211672216723167241672516726167271672816729167301673116732167331673416735167361673716738167391674016741167421674316744167451674616747167481674916750167511675216753167541675516756167571675816759167601676116762167631676416765167661676716768167691677016771167721677316774167751677616777167781677916780167811678216783167841678516786167871678816789167901679116792167931679416795167961679716798167991680016801168021680316804168051680616807168081680916810168111681216813168141681516816168171681816819168201682116822168231682416825168261682716828168291683016831168321683316834168351683616837168381683916840168411684216843168441684516846168471684816849168501685116852168531685416855168561685716858168591686016861168621686316864168651686616867168681686916870168711687216873168741687516876168771687816879168801688116882168831688416885168861688716888168891689016891168921689316894168951689616897168981689916900169011690216903169041690516906169071690816909169101691116912169131691416915169161691716918169191692016921169221692316924169251692616927169281692916930169311693216933169341693516936169371693816939169401694116942169431694416945169461694716948169491695016951169521695316954169551695616957169581695916960169611696216963169641696516966169671696816969169701697116972169731697416975169761697716978169791698016981169821698316984169851698616987169881698916990169911699216993169941699516996169971699816999170001700117002170031700417005170061700717008170091701017011170121701317014170151701617017170181701917020170211702217023170241702517026170271702817029170301703117032170331703417035170361703717038170391704017041170421704317044170451704617047170481704917050170511705217053170541705517056170571705817059170601706117062170631706417065170661706717068170691707017071170721707317074170751707617077170781707917080170811708217083170841708517086170871708817089170901709117092170931709417095170961709717098170991710017101171021710317104171051710617107171081710917110171111711217113171141711517116171171711817119171201712117122171231712417125171261712717128171291713017131171321713317134171351713617137171381713917140171411714217143171441714517146171471714817149171501715117152171531715417155171561715717158171591716017161171621716317164171651716617167171681716917170171711717217173171741717517176171771717817179171801718117182171831718417185171861718717188171891719017191171921719317194171951719617197171981719917200172011720217203172041720517206172071720817209172101721117212172131721417215172161721717218172191722017221172221722317224172251722617227172281722917230172311723217233172341723517236172371723817239172401724117242172431724417245172461724717248172491725017251172521725317254172551725617257172581725917260172611726217263172641726517266172671726817269172701727117272172731727417275172761727717278172791728017281172821728317284172851728617287172881728917290172911729217293172941729517296172971729817299173001730117302173031730417305173061730717308173091731017311173121731317314173151731617317173181731917320173211732217323173241732517326173271732817329173301733117332173331733417335173361733717338173391734017341173421734317344173451734617347173481734917350173511735217353173541735517356173571735817359173601736117362173631736417365173661736717368173691737017371173721737317374173751737617377173781737917380173811738217383173841738517386173871738817389173901739117392173931739417395173961739717398173991740017401174021740317404174051740617407174081740917410174111741217413174141741517416174171741817419174201742117422174231742417425174261742717428174291743017431174321743317434174351743617437174381743917440174411744217443174441744517446174471744817449174501745117452174531745417455174561745717458174591746017461174621746317464174651746617467174681746917470174711747217473174741747517476174771747817479174801748117482174831748417485174861748717488174891749017491174921749317494174951749617497174981749917500175011750217503175041750517506175071750817509175101751117512175131751417515175161751717518175191752017521175221752317524175251752617527175281752917530175311753217533175341753517536175371753817539175401754117542175431754417545175461754717548175491755017551175521755317554175551755617557175581755917560175611756217563175641756517566175671756817569175701757117572175731757417575175761757717578175791758017581175821758317584175851758617587175881758917590175911759217593175941759517596175971759817599176001760117602176031760417605176061760717608176091761017611176121761317614176151761617617176181761917620176211762217623176241762517626176271762817629176301763117632176331763417635176361763717638176391764017641176421764317644176451764617647176481764917650176511765217653176541765517656176571765817659176601766117662176631766417665176661766717668176691767017671176721767317674176751767617677176781767917680176811768217683176841768517686176871768817689176901769117692176931769417695176961769717698176991770017701177021770317704177051770617707177081770917710177111771217713177141771517716177171771817719177201772117722177231772417725177261772717728177291773017731177321773317734177351773617737177381773917740177411774217743177441774517746177471774817749177501775117752177531775417755177561775717758177591776017761177621776317764177651776617767177681776917770177711777217773177741777517776177771777817779177801778117782177831778417785177861778717788177891779017791177921779317794177951779617797177981779917800178011780217803178041780517806178071780817809178101781117812178131781417815178161781717818178191782017821178221782317824178251782617827178281782917830178311783217833178341783517836178371783817839178401784117842178431784417845178461784717848178491785017851178521785317854178551785617857178581785917860178611786217863178641786517866178671786817869178701787117872178731787417875178761787717878178791788017881178821788317884178851788617887178881788917890178911789217893178941789517896178971789817899179001790117902179031790417905179061790717908179091791017911179121791317914179151791617917179181791917920179211792217923179241792517926179271792817929179301793117932179331793417935179361793717938179391794017941179421794317944179451794617947179481794917950179511795217953179541795517956179571795817959179601796117962179631796417965179661796717968179691797017971179721797317974179751797617977179781797917980179811798217983179841798517986179871798817989179901799117992179931799417995179961799717998179991800018001180021800318004180051800618007180081800918010180111801218013180141801518016180171801818019180201802118022180231802418025180261802718028180291803018031180321803318034180351803618037180381803918040180411804218043180441804518046180471804818049180501805118052180531805418055180561805718058180591806018061180621806318064180651806618067180681806918070180711807218073180741807518076180771807818079180801808118082180831808418085180861808718088180891809018091180921809318094180951809618097180981809918100181011810218103181041810518106181071810818109181101811118112181131811418115181161811718118181191812018121181221812318124181251812618127181281812918130181311813218133181341813518136181371813818139181401814118142181431814418145181461814718148181491815018151181521815318154181551815618157181581815918160181611816218163181641816518166181671816818169181701817118172181731817418175181761817718178181791818018181181821818318184181851818618187181881818918190181911819218193181941819518196181971819818199182001820118202182031820418205182061820718208182091821018211182121821318214182151821618217182181821918220182211822218223182241822518226182271822818229182301823118232182331823418235182361823718238182391824018241182421824318244182451824618247182481824918250182511825218253182541825518256182571825818259182601826118262182631826418265182661826718268182691827018271182721827318274182751827618277182781827918280182811828218283182841828518286182871828818289182901829118292182931829418295182961829718298182991830018301183021830318304183051830618307183081830918310183111831218313183141831518316183171831818319183201832118322183231832418325183261832718328183291833018331183321833318334183351833618337183381833918340183411834218343183441834518346183471834818349183501835118352183531835418355183561835718358183591836018361183621836318364183651836618367183681836918370183711837218373183741837518376183771837818379183801838118382183831838418385183861838718388183891839018391183921839318394183951839618397183981839918400184011840218403184041840518406184071840818409184101841118412184131841418415184161841718418184191842018421184221842318424184251842618427184281842918430184311843218433184341843518436184371843818439184401844118442184431844418445184461844718448184491845018451184521845318454184551845618457184581845918460184611846218463184641846518466184671846818469184701847118472184731847418475184761847718478184791848018481184821848318484184851848618487184881848918490184911849218493184941849518496184971849818499185001850118502185031850418505185061850718508185091851018511185121851318514185151851618517185181851918520185211852218523185241852518526185271852818529185301853118532185331853418535185361853718538185391854018541185421854318544185451854618547185481854918550185511855218553185541855518556185571855818559185601856118562185631856418565185661856718568185691857018571185721857318574185751857618577185781857918580185811858218583185841858518586185871858818589185901859118592185931859418595185961859718598185991860018601186021860318604186051860618607186081860918610186111861218613186141861518616186171861818619186201862118622186231862418625186261862718628186291863018631186321863318634186351863618637186381863918640186411864218643186441864518646186471864818649186501865118652186531865418655186561865718658186591866018661186621866318664186651866618667186681866918670186711867218673186741867518676186771867818679186801868118682186831868418685186861868718688186891869018691186921869318694186951869618697186981869918700187011870218703187041870518706187071870818709187101871118712187131871418715187161871718718187191872018721187221872318724187251872618727187281872918730187311873218733187341873518736187371873818739187401874118742187431874418745187461874718748187491875018751187521875318754187551875618757187581875918760187611876218763187641876518766187671876818769187701877118772187731877418775187761877718778187791878018781187821878318784187851878618787187881878918790187911879218793187941879518796187971879818799188001880118802188031880418805188061880718808188091881018811188121881318814188151881618817188181881918820188211882218823188241882518826188271882818829188301883118832188331883418835188361883718838188391884018841188421884318844188451884618847188481884918850188511885218853188541885518856188571885818859188601886118862188631886418865188661886718868188691887018871188721887318874188751887618877188781887918880188811888218883188841888518886188871888818889188901889118892188931889418895188961889718898188991890018901189021890318904189051890618907189081890918910189111891218913189141891518916189171891818919189201892118922189231892418925189261892718928189291893018931189321893318934189351893618937189381893918940189411894218943189441894518946189471894818949189501895118952189531895418955189561895718958189591896018961189621896318964189651896618967189681896918970189711897218973189741897518976189771897818979189801898118982189831898418985189861898718988189891899018991189921899318994189951899618997189981899919000190011900219003190041900519006190071900819009190101901119012190131901419015190161901719018190191902019021190221902319024190251902619027190281902919030190311903219033190341903519036190371903819039190401904119042190431904419045190461904719048190491905019051190521905319054190551905619057190581905919060190611906219063190641906519066190671906819069190701907119072190731907419075190761907719078190791908019081190821908319084190851908619087190881908919090190911909219093190941909519096190971909819099191001910119102191031910419105191061910719108191091911019111191121911319114191151911619117191181911919120191211912219123191241912519126191271912819129191301913119132191331913419135191361913719138191391914019141191421914319144191451914619147191481914919150191511915219153191541915519156191571915819159191601916119162191631916419165191661916719168191691917019171191721917319174191751917619177191781917919180191811918219183191841918519186191871918819189191901919119192191931919419195191961919719198191991920019201192021920319204192051920619207192081920919210192111921219213192141921519216192171921819219192201922119222192231922419225192261922719228192291923019231192321923319234192351923619237192381923919240192411924219243192441924519246192471924819249192501925119252192531925419255192561925719258192591926019261192621926319264192651926619267192681926919270192711927219273192741927519276192771927819279192801928119282192831928419285192861928719288192891929019291192921929319294192951929619297192981929919300193011930219303193041930519306193071930819309193101931119312193131931419315193161931719318193191932019321193221932319324193251932619327193281932919330193311933219333193341933519336193371933819339193401934119342193431934419345193461934719348193491935019351193521935319354193551935619357193581935919360193611936219363193641936519366193671936819369193701937119372193731937419375193761937719378193791938019381193821938319384193851938619387193881938919390193911939219393193941939519396193971939819399194001940119402194031940419405194061940719408194091941019411194121941319414194151941619417194181941919420194211942219423194241942519426194271942819429194301943119432194331943419435194361943719438194391944019441194421944319444194451944619447194481944919450194511945219453194541945519456194571945819459194601946119462194631946419465194661946719468194691947019471194721947319474194751947619477194781947919480194811948219483194841948519486194871948819489194901949119492194931949419495194961949719498194991950019501195021950319504195051950619507195081950919510195111951219513195141951519516195171951819519195201952119522195231952419525195261952719528195291953019531195321953319534195351953619537195381953919540195411954219543195441954519546195471954819549195501955119552195531955419555195561955719558195591956019561195621956319564195651956619567195681956919570195711957219573195741957519576195771957819579195801958119582195831958419585195861958719588195891959019591195921959319594195951959619597195981959919600196011960219603196041960519606196071960819609196101961119612196131961419615196161961719618196191962019621196221962319624196251962619627196281962919630196311963219633196341963519636196371963819639196401964119642196431964419645196461964719648196491965019651196521965319654196551965619657196581965919660196611966219663196641966519666196671966819669196701967119672196731967419675196761967719678196791968019681196821968319684196851968619687196881968919690196911969219693196941969519696196971969819699197001970119702197031970419705197061970719708197091971019711197121971319714197151971619717197181971919720197211972219723197241972519726197271972819729197301973119732197331973419735197361973719738197391974019741197421974319744197451974619747197481974919750197511975219753197541975519756197571975819759197601976119762197631976419765197661976719768197691977019771197721977319774197751977619777197781977919780197811978219783197841978519786197871978819789197901979119792197931979419795197961979719798197991980019801198021980319804198051980619807198081980919810198111981219813198141981519816198171981819819198201982119822198231982419825198261982719828198291983019831198321983319834198351983619837198381983919840198411984219843198441984519846198471984819849198501985119852198531985419855198561985719858198591986019861198621986319864198651986619867198681986919870198711987219873198741987519876198771987819879198801988119882198831988419885198861988719888198891989019891198921989319894198951989619897198981989919900199011990219903199041990519906199071990819909199101991119912199131991419915199161991719918199191992019921199221992319924199251992619927199281992919930199311993219933199341993519936199371993819939199401994119942199431994419945199461994719948199491995019951199521995319954199551995619957199581995919960199611996219963199641996519966199671996819969199701997119972199731997419975199761997719978199791998019981199821998319984199851998619987199881998919990199911999219993199941999519996199971999819999200002000120002200032000420005200062000720008200092001020011200122001320014200152001620017200182001920020200212002220023200242002520026200272002820029200302003120032200332003420035200362003720038200392004020041200422004320044200452004620047200482004920050200512005220053200542005520056200572005820059200602006120062200632006420065200662006720068200692007020071200722007320074200752007620077200782007920080200812008220083200842008520086200872008820089200902009120092200932009420095200962009720098200992010020101201022010320104201052010620107201082010920110201112011220113201142011520116201172011820119201202012120122201232012420125201262012720128201292013020131201322013320134201352013620137201382013920140201412014220143201442014520146201472014820149201502015120152201532015420155201562015720158201592016020161201622016320164201652016620167201682016920170201712017220173201742017520176201772017820179201802018120182201832018420185201862018720188201892019020191201922019320194201952019620197201982019920200202012020220203202042020520206202072020820209202102021120212202132021420215202162021720218202192022020221202222022320224202252022620227202282022920230202312023220233202342023520236202372023820239202402024120242202432024420245202462024720248202492025020251202522025320254202552025620257202582025920260202612026220263202642026520266202672026820269202702027120272202732027420275202762027720278202792028020281202822028320284202852028620287202882028920290202912029220293202942029520296202972029820299203002030120302203032030420305203062030720308203092031020311203122031320314203152031620317203182031920320203212032220323203242032520326203272032820329203302033120332203332033420335203362033720338203392034020341203422034320344203452034620347203482034920350203512035220353203542035520356203572035820359203602036120362203632036420365203662036720368203692037020371203722037320374203752037620377203782037920380203812038220383203842038520386203872038820389203902039120392203932039420395203962039720398203992040020401204022040320404204052040620407204082040920410204112041220413204142041520416204172041820419204202042120422204232042420425204262042720428204292043020431204322043320434204352043620437204382043920440204412044220443204442044520446204472044820449204502045120452204532045420455204562045720458204592046020461204622046320464204652046620467204682046920470204712047220473204742047520476204772047820479204802048120482204832048420485204862048720488204892049020491204922049320494204952049620497204982049920500205012050220503205042050520506205072050820509205102051120512205132051420515205162051720518205192052020521205222052320524205252052620527205282052920530205312053220533205342053520536205372053820539205402054120542205432054420545205462054720548205492055020551205522055320554205552055620557205582055920560205612056220563205642056520566205672056820569205702057120572205732057420575205762057720578205792058020581205822058320584205852058620587205882058920590205912059220593205942059520596205972059820599206002060120602206032060420605206062060720608206092061020611206122061320614206152061620617206182061920620206212062220623206242062520626206272062820629206302063120632206332063420635206362063720638206392064020641206422064320644206452064620647206482064920650206512065220653206542065520656206572065820659206602066120662206632066420665206662066720668206692067020671206722067320674206752067620677206782067920680206812068220683206842068520686206872068820689206902069120692206932069420695206962069720698206992070020701207022070320704207052070620707207082070920710207112071220713207142071520716207172071820719207202072120722207232072420725207262072720728207292073020731207322073320734207352073620737207382073920740207412074220743207442074520746207472074820749207502075120752207532075420755207562075720758207592076020761207622076320764207652076620767207682076920770207712077220773207742077520776207772077820779207802078120782207832078420785207862078720788207892079020791207922079320794207952079620797207982079920800208012080220803208042080520806208072080820809208102081120812208132081420815208162081720818208192082020821208222082320824208252082620827208282082920830208312083220833208342083520836208372083820839208402084120842208432084420845208462084720848208492085020851208522085320854208552085620857208582085920860208612086220863208642086520866208672086820869208702087120872208732087420875208762087720878208792088020881208822088320884208852088620887208882088920890208912089220893208942089520896208972089820899209002090120902209032090420905209062090720908209092091020911209122091320914209152091620917209182091920920209212092220923209242092520926209272092820929209302093120932209332093420935209362093720938209392094020941209422094320944209452094620947209482094920950209512095220953209542095520956209572095820959209602096120962209632096420965209662096720968209692097020971209722097320974209752097620977209782097920980209812098220983209842098520986209872098820989209902099120992209932099420995209962099720998209992100021001210022100321004210052100621007210082100921010210112101221013210142101521016210172101821019210202102121022210232102421025210262102721028210292103021031210322103321034210352103621037210382103921040210412104221043210442104521046210472104821049210502105121052210532105421055210562105721058210592106021061210622106321064210652106621067210682106921070210712107221073210742107521076210772107821079210802108121082210832108421085210862108721088210892109021091210922109321094210952109621097210982109921100211012110221103211042110521106211072110821109211102111121112211132111421115211162111721118211192112021121211222112321124211252112621127211282112921130211312113221133211342113521136211372113821139211402114121142211432114421145211462114721148211492115021151211522115321154211552115621157211582115921160211612116221163211642116521166211672116821169211702117121172211732117421175211762117721178211792118021181211822118321184211852118621187211882118921190211912119221193211942119521196211972119821199212002120121202212032120421205212062120721208212092121021211212122121321214212152121621217212182121921220212212122221223212242122521226212272122821229212302123121232212332123421235212362123721238212392124021241212422124321244212452124621247212482124921250212512125221253212542125521256212572125821259212602126121262212632126421265212662126721268212692127021271212722127321274212752127621277212782127921280212812128221283212842128521286212872128821289212902129121292212932129421295212962129721298212992130021301213022130321304213052130621307213082130921310213112131221313213142131521316213172131821319213202132121322213232132421325213262132721328213292133021331213322133321334213352133621337213382133921340213412134221343213442134521346213472134821349213502135121352213532135421355213562135721358213592136021361213622136321364213652136621367213682136921370213712137221373213742137521376213772137821379213802138121382213832138421385213862138721388213892139021391213922139321394213952139621397213982139921400214012140221403214042140521406214072140821409214102141121412214132141421415214162141721418214192142021421214222142321424214252142621427214282142921430214312143221433214342143521436214372143821439214402144121442214432144421445214462144721448214492145021451214522145321454214552145621457214582145921460214612146221463214642146521466214672146821469214702147121472214732147421475214762147721478214792148021481214822148321484214852148621487214882148921490214912149221493214942149521496214972149821499215002150121502215032150421505215062150721508215092151021511215122151321514215152151621517215182151921520215212152221523215242152521526215272152821529215302153121532215332153421535215362153721538215392154021541215422154321544215452154621547215482154921550215512155221553215542155521556215572155821559215602156121562215632156421565215662156721568215692157021571215722157321574215752157621577215782157921580215812158221583215842158521586215872158821589215902159121592215932159421595215962159721598215992160021601216022160321604216052160621607216082160921610216112161221613216142161521616216172161821619216202162121622216232162421625216262162721628216292163021631216322163321634216352163621637216382163921640216412164221643216442164521646216472164821649216502165121652216532165421655216562165721658216592166021661216622166321664216652166621667216682166921670216712167221673216742167521676216772167821679216802168121682216832168421685216862168721688216892169021691216922169321694216952169621697216982169921700217012170221703217042170521706217072170821709217102171121712217132171421715217162171721718217192172021721217222172321724217252172621727217282172921730217312173221733217342173521736217372173821739217402174121742217432174421745217462174721748217492175021751217522175321754217552175621757217582175921760217612176221763217642176521766217672176821769217702177121772217732177421775217762177721778217792178021781217822178321784217852178621787217882178921790217912179221793217942179521796217972179821799218002180121802218032180421805218062180721808218092181021811218122181321814218152181621817218182181921820218212182221823218242182521826218272182821829218302183121832218332183421835218362183721838218392184021841218422184321844218452184621847218482184921850218512185221853218542185521856218572185821859218602186121862218632186421865218662186721868218692187021871218722187321874218752187621877218782187921880218812188221883218842188521886218872188821889218902189121892218932189421895218962189721898218992190021901219022190321904219052190621907219082190921910219112191221913219142191521916219172191821919219202192121922219232192421925219262192721928219292193021931219322193321934219352193621937219382193921940219412194221943219442194521946219472194821949219502195121952219532195421955219562195721958219592196021961219622196321964219652196621967219682196921970219712197221973219742197521976219772197821979219802198121982219832198421985219862198721988219892199021991219922199321994219952199621997219982199922000220012200222003220042200522006220072200822009220102201122012220132201422015220162201722018220192202022021220222202322024220252202622027220282202922030220312203222033220342203522036220372203822039220402204122042220432204422045220462204722048220492205022051220522205322054220552205622057220582205922060220612206222063220642206522066220672206822069220702207122072220732207422075220762207722078220792208022081220822208322084220852208622087220882208922090220912209222093220942209522096220972209822099221002210122102221032210422105221062210722108221092211022111221122211322114221152211622117221182211922120221212212222123221242212522126221272212822129221302213122132221332213422135221362213722138221392214022141221422214322144221452214622147221482214922150221512215222153221542215522156221572215822159221602216122162221632216422165221662216722168221692217022171221722217322174221752217622177221782217922180221812218222183221842218522186221872218822189221902219122192221932219422195221962219722198221992220022201222022220322204222052220622207222082220922210222112221222213222142221522216222172221822219222202222122222222232222422225222262222722228222292223022231222322223322234222352223622237222382223922240222412224222243222442224522246222472224822249222502225122252222532225422255222562225722258222592226022261222622226322264222652226622267222682226922270222712227222273222742227522276222772227822279222802228122282222832228422285222862228722288222892229022291222922229322294222952229622297222982229922300223012230222303223042230522306223072230822309223102231122312223132231422315223162231722318223192232022321223222232322324223252232622327223282232922330223312233222333223342233522336223372233822339223402234122342223432234422345223462234722348223492235022351223522235322354223552235622357223582235922360223612236222363223642236522366223672236822369223702237122372223732237422375223762237722378223792238022381223822238322384223852238622387223882238922390223912239222393223942239522396223972239822399224002240122402224032240422405224062240722408224092241022411224122241322414224152241622417224182241922420224212242222423224242242522426224272242822429224302243122432224332243422435224362243722438224392244022441224422244322444224452244622447224482244922450224512245222453224542245522456224572245822459224602246122462224632246422465224662246722468224692247022471224722247322474224752247622477224782247922480224812248222483224842248522486224872248822489224902249122492224932249422495224962249722498224992250022501225022250322504225052250622507225082250922510225112251222513225142251522516225172251822519225202252122522225232252422525225262252722528225292253022531225322253322534225352253622537225382253922540225412254222543225442254522546225472254822549225502255122552225532255422555225562255722558225592256022561225622256322564225652256622567225682256922570225712257222573225742257522576225772257822579225802258122582225832258422585225862258722588225892259022591225922259322594225952259622597225982259922600226012260222603226042260522606226072260822609226102261122612226132261422615226162261722618226192262022621226222262322624226252262622627226282262922630226312263222633226342263522636226372263822639226402264122642226432264422645226462264722648226492265022651226522265322654226552265622657226582265922660226612266222663226642266522666226672266822669226702267122672226732267422675226762267722678226792268022681226822268322684226852268622687226882268922690226912269222693226942269522696226972269822699227002270122702227032270422705227062270722708227092271022711227122271322714227152271622717227182271922720227212272222723227242272522726227272272822729227302273122732227332273422735227362273722738227392274022741227422274322744227452274622747227482274922750227512275222753227542275522756227572275822759227602276122762227632276422765227662276722768227692277022771227722277322774227752277622777227782277922780227812278222783227842278522786227872278822789227902279122792227932279422795227962279722798227992280022801228022280322804228052280622807228082280922810228112281222813228142281522816228172281822819228202282122822228232282422825228262282722828228292283022831228322283322834228352283622837228382283922840228412284222843228442284522846228472284822849228502285122852228532285422855228562285722858228592286022861228622286322864228652286622867228682286922870228712287222873228742287522876228772287822879228802288122882228832288422885228862288722888228892289022891228922289322894228952289622897228982289922900229012290222903229042290522906229072290822909229102291122912229132291422915229162291722918229192292022921229222292322924229252292622927229282292922930229312293222933229342293522936229372293822939229402294122942229432294422945229462294722948229492295022951229522295322954229552295622957229582295922960229612296222963229642296522966229672296822969229702297122972229732297422975229762297722978229792298022981229822298322984229852298622987229882298922990229912299222993229942299522996229972299822999230002300123002230032300423005230062300723008230092301023011230122301323014230152301623017230182301923020230212302223023230242302523026230272302823029230302303123032230332303423035230362303723038230392304023041230422304323044230452304623047230482304923050230512305223053230542305523056230572305823059230602306123062230632306423065230662306723068230692307023071230722307323074230752307623077230782307923080230812308223083230842308523086230872308823089230902309123092230932309423095230962309723098230992310023101231022310323104231052310623107231082310923110231112311223113231142311523116231172311823119231202312123122231232312423125231262312723128231292313023131231322313323134231352313623137231382313923140231412314223143231442314523146231472314823149231502315123152231532315423155231562315723158231592316023161231622316323164231652316623167231682316923170231712317223173231742317523176231772317823179231802318123182231832318423185231862318723188231892319023191231922319323194231952319623197231982319923200232012320223203232042320523206232072320823209232102321123212232132321423215232162321723218232192322023221232222322323224232252322623227232282322923230232312323223233232342323523236232372323823239232402324123242232432324423245232462324723248232492325023251232522325323254232552325623257232582325923260232612326223263232642326523266232672326823269232702327123272232732327423275232762327723278232792328023281232822328323284232852328623287232882328923290232912329223293232942329523296232972329823299233002330123302233032330423305233062330723308233092331023311233122331323314233152331623317233182331923320233212332223323233242332523326233272332823329233302333123332233332333423335233362333723338233392334023341233422334323344233452334623347233482334923350233512335223353233542335523356233572335823359233602336123362233632336423365233662336723368233692337023371233722337323374233752337623377233782337923380233812338223383233842338523386233872338823389233902339123392233932339423395233962339723398233992340023401234022340323404234052340623407234082340923410234112341223413234142341523416234172341823419234202342123422234232342423425234262342723428234292343023431234322343323434234352343623437234382343923440234412344223443234442344523446234472344823449234502345123452234532345423455234562345723458234592346023461234622346323464234652346623467234682346923470234712347223473234742347523476234772347823479234802348123482234832348423485234862348723488234892349023491234922349323494234952349623497234982349923500235012350223503235042350523506235072350823509235102351123512235132351423515235162351723518235192352023521235222352323524235252352623527235282352923530235312353223533235342353523536235372353823539235402354123542235432354423545235462354723548235492355023551235522355323554235552355623557235582355923560235612356223563235642356523566235672356823569235702357123572235732357423575235762357723578235792358023581235822358323584235852358623587235882358923590235912359223593235942359523596235972359823599236002360123602236032360423605236062360723608236092361023611236122361323614236152361623617236182361923620236212362223623236242362523626236272362823629236302363123632236332363423635236362363723638236392364023641236422364323644236452364623647236482364923650236512365223653236542365523656236572365823659236602366123662236632366423665236662366723668236692367023671236722367323674236752367623677236782367923680236812368223683236842368523686236872368823689236902369123692236932369423695236962369723698236992370023701237022370323704237052370623707237082370923710237112371223713237142371523716237172371823719237202372123722237232372423725237262372723728237292373023731237322373323734237352373623737237382373923740237412374223743237442374523746237472374823749237502375123752237532375423755237562375723758237592376023761237622376323764237652376623767237682376923770237712377223773237742377523776237772377823779237802378123782237832378423785237862378723788237892379023791237922379323794237952379623797237982379923800238012380223803238042380523806238072380823809238102381123812238132381423815238162381723818238192382023821238222382323824238252382623827238282382923830238312383223833238342383523836238372383823839238402384123842238432384423845238462384723848238492385023851238522385323854238552385623857238582385923860238612386223863238642386523866238672386823869238702387123872238732387423875238762387723878238792388023881238822388323884238852388623887238882388923890238912389223893238942389523896238972389823899239002390123902239032390423905239062390723908239092391023911239122391323914239152391623917239182391923920239212392223923239242392523926239272392823929239302393123932239332393423935239362393723938239392394023941239422394323944239452394623947239482394923950239512395223953239542395523956239572395823959239602396123962239632396423965239662396723968239692397023971239722397323974239752397623977239782397923980239812398223983239842398523986239872398823989239902399123992239932399423995239962399723998239992400024001240022400324004240052400624007240082400924010240112401224013240142401524016240172401824019240202402124022240232402424025240262402724028240292403024031240322403324034240352403624037240382403924040240412404224043240442404524046240472404824049240502405124052240532405424055240562405724058240592406024061240622406324064240652406624067240682406924070240712407224073240742407524076240772407824079240802408124082240832408424085240862408724088240892409024091240922409324094240952409624097240982409924100241012410224103241042410524106241072410824109241102411124112241132411424115241162411724118241192412024121241222412324124241252412624127241282412924130241312413224133241342413524136241372413824139241402414124142241432414424145241462414724148241492415024151241522415324154241552415624157241582415924160241612416224163241642416524166241672416824169241702417124172241732417424175241762417724178241792418024181241822418324184241852418624187241882418924190241912419224193241942419524196241972419824199242002420124202242032420424205242062420724208242092421024211242122421324214242152421624217242182421924220242212422224223242242422524226242272422824229242302423124232242332423424235242362423724238242392424024241242422424324244242452424624247242482424924250242512425224253242542425524256242572425824259242602426124262242632426424265242662426724268242692427024271242722427324274242752427624277242782427924280242812428224283242842428524286242872428824289242902429124292242932429424295242962429724298242992430024301243022430324304243052430624307243082430924310243112431224313243142431524316243172431824319243202432124322243232432424325243262432724328243292433024331243322433324334243352433624337243382433924340243412434224343243442434524346243472434824349243502435124352243532435424355243562435724358243592436024361243622436324364243652436624367243682436924370243712437224373243742437524376243772437824379243802438124382243832438424385243862438724388243892439024391243922439324394243952439624397243982439924400244012440224403244042440524406244072440824409244102441124412244132441424415244162441724418244192442024421244222442324424244252442624427244282442924430244312443224433244342443524436244372443824439244402444124442244432444424445244462444724448244492445024451244522445324454244552445624457244582445924460244612446224463244642446524466244672446824469244702447124472244732447424475244762447724478244792448024481244822448324484244852448624487244882448924490244912449224493244942449524496244972449824499245002450124502245032450424505245062450724508245092451024511245122451324514245152451624517245182451924520245212452224523245242452524526245272452824529245302453124532245332453424535245362453724538245392454024541245422454324544245452454624547245482454924550245512455224553245542455524556245572455824559245602456124562245632456424565245662456724568245692457024571245722457324574245752457624577245782457924580245812458224583245842458524586245872458824589245902459124592245932459424595245962459724598245992460024601246022460324604246052460624607246082460924610246112461224613246142461524616246172461824619246202462124622246232462424625246262462724628246292463024631246322463324634246352463624637246382463924640246412464224643246442464524646246472464824649246502465124652246532465424655246562465724658246592466024661246622466324664246652466624667246682466924670246712467224673246742467524676246772467824679246802468124682246832468424685246862468724688246892469024691246922469324694246952469624697246982469924700247012470224703247042470524706247072470824709247102471124712247132471424715247162471724718247192472024721247222472324724247252472624727247282472924730247312473224733247342473524736247372473824739247402474124742247432474424745247462474724748247492475024751247522475324754247552475624757247582475924760247612476224763247642476524766247672476824769247702477124772247732477424775247762477724778247792478024781247822478324784247852478624787247882478924790247912479224793247942479524796247972479824799248002480124802248032480424805248062480724808248092481024811248122481324814248152481624817248182481924820248212482224823248242482524826248272482824829248302483124832248332483424835248362483724838248392484024841248422484324844248452484624847248482484924850248512485224853248542485524856248572485824859248602486124862248632486424865248662486724868248692487024871248722487324874248752487624877248782487924880248812488224883248842488524886248872488824889248902489124892248932489424895248962489724898248992490024901249022490324904249052490624907249082490924910249112491224913249142491524916249172491824919249202492124922249232492424925249262492724928249292493024931249322493324934249352493624937249382493924940249412494224943249442494524946249472494824949249502495124952249532495424955249562495724958249592496024961249622496324964249652496624967249682496924970249712497224973249742497524976249772497824979249802498124982249832498424985249862498724988249892499024991249922499324994249952499624997249982499925000250012500225003250042500525006250072500825009250102501125012250132501425015250162501725018250192502025021250222502325024250252502625027250282502925030250312503225033250342503525036250372503825039250402504125042250432504425045250462504725048250492505025051250522505325054250552505625057250582505925060250612506225063250642506525066250672506825069250702507125072250732507425075250762507725078250792508025081250822508325084250852508625087250882508925090250912509225093250942509525096250972509825099251002510125102251032510425105251062510725108251092511025111251122511325114251152511625117251182511925120251212512225123251242512525126251272512825129251302513125132251332513425135251362513725138251392514025141251422514325144251452514625147251482514925150251512515225153251542515525156251572515825159251602516125162251632516425165251662516725168251692517025171251722517325174251752517625177251782517925180251812518225183251842518525186251872518825189251902519125192251932519425195251962519725198251992520025201252022520325204252052520625207252082520925210252112521225213252142521525216252172521825219252202522125222252232522425225252262522725228252292523025231252322523325234252352523625237252382523925240252412524225243252442524525246252472524825249252502525125252252532525425255252562525725258252592526025261252622526325264252652526625267252682526925270252712527225273252742527525276252772527825279252802528125282252832528425285252862528725288252892529025291252922529325294252952529625297252982529925300253012530225303253042530525306253072530825309253102531125312253132531425315253162531725318253192532025321253222532325324253252532625327253282532925330253312533225333253342533525336253372533825339253402534125342253432534425345253462534725348253492535025351253522535325354253552535625357253582535925360253612536225363253642536525366253672536825369253702537125372253732537425375253762537725378253792538025381253822538325384253852538625387253882538925390253912539225393253942539525396253972539825399254002540125402254032540425405254062540725408254092541025411254122541325414254152541625417254182541925420254212542225423254242542525426254272542825429254302543125432254332543425435254362543725438254392544025441254422544325444254452544625447254482544925450254512545225453254542545525456254572545825459254602546125462254632546425465254662546725468254692547025471254722547325474254752547625477254782547925480254812548225483254842548525486254872548825489254902549125492254932549425495254962549725498254992550025501255022550325504255052550625507255082550925510255112551225513255142551525516255172551825519255202552125522255232552425525255262552725528255292553025531255322553325534255352553625537255382553925540255412554225543255442554525546255472554825549255502555125552255532555425555255562555725558255592556025561255622556325564255652556625567255682556925570255712557225573255742557525576255772557825579255802558125582255832558425585255862558725588255892559025591255922559325594255952559625597255982559925600256012560225603256042560525606256072560825609256102561125612256132561425615256162561725618256192562025621256222562325624256252562625627256282562925630256312563225633256342563525636256372563825639256402564125642256432564425645256462564725648256492565025651256522565325654256552565625657256582565925660256612566225663256642566525666256672566825669256702567125672256732567425675256762567725678256792568025681256822568325684256852568625687256882568925690256912569225693256942569525696256972569825699257002570125702257032570425705257062570725708257092571025711257122571325714257152571625717257182571925720257212572225723257242572525726257272572825729257302573125732257332573425735257362573725738257392574025741257422574325744257452574625747257482574925750257512575225753257542575525756257572575825759257602576125762257632576425765257662576725768257692577025771257722577325774257752577625777257782577925780257812578225783257842578525786257872578825789257902579125792257932579425795257962579725798257992580025801258022580325804258052580625807258082580925810258112581225813258142581525816258172581825819258202582125822258232582425825258262582725828258292583025831258322583325834258352583625837258382583925840258412584225843258442584525846258472584825849258502585125852258532585425855258562585725858258592586025861258622586325864258652586625867258682586925870258712587225873258742587525876258772587825879258802588125882258832588425885258862588725888258892589025891258922589325894258952589625897258982589925900259012590225903259042590525906259072590825909259102591125912259132591425915259162591725918259192592025921259222592325924259252592625927259282592925930259312593225933259342593525936259372593825939259402594125942259432594425945259462594725948259492595025951259522595325954259552595625957259582595925960259612596225963259642596525966259672596825969259702597125972259732597425975259762597725978259792598025981259822598325984259852598625987259882598925990259912599225993259942599525996259972599825999260002600126002260032600426005260062600726008260092601026011260122601326014260152601626017260182601926020260212602226023260242602526026260272602826029260302603126032260332603426035260362603726038260392604026041260422604326044260452604626047260482604926050260512605226053260542605526056260572605826059260602606126062260632606426065260662606726068260692607026071260722607326074260752607626077260782607926080260812608226083260842608526086260872608826089260902609126092260932609426095260962609726098260992610026101261022610326104261052610626107261082610926110261112611226113261142611526116261172611826119261202612126122261232612426125261262612726128261292613026131261322613326134261352613626137261382613926140261412614226143261442614526146261472614826149261502615126152261532615426155261562615726158261592616026161261622616326164261652616626167261682616926170261712617226173261742617526176261772617826179261802618126182261832618426185261862618726188261892619026191261922619326194261952619626197261982619926200262012620226203262042620526206262072620826209262102621126212262132621426215262162621726218262192622026221262222622326224262252622626227262282622926230262312623226233262342623526236262372623826239262402624126242262432624426245262462624726248262492625026251262522625326254262552625626257262582625926260262612626226263262642626526266262672626826269262702627126272262732627426275262762627726278262792628026281262822628326284262852628626287262882628926290262912629226293262942629526296262972629826299263002630126302263032630426305263062630726308263092631026311263122631326314263152631626317263182631926320263212632226323263242632526326263272632826329263302633126332263332633426335263362633726338263392634026341263422634326344263452634626347263482634926350263512635226353263542635526356263572635826359263602636126362263632636426365263662636726368263692637026371263722637326374263752637626377263782637926380263812638226383263842638526386263872638826389263902639126392263932639426395263962639726398263992640026401264022640326404264052640626407264082640926410264112641226413264142641526416264172641826419264202642126422264232642426425264262642726428264292643026431264322643326434264352643626437264382643926440264412644226443264442644526446264472644826449264502645126452264532645426455264562645726458264592646026461264622646326464264652646626467264682646926470264712647226473264742647526476264772647826479264802648126482264832648426485264862648726488264892649026491264922649326494264952649626497264982649926500265012650226503265042650526506265072650826509265102651126512265132651426515265162651726518265192652026521265222652326524265252652626527265282652926530265312653226533265342653526536265372653826539265402654126542265432654426545265462654726548265492655026551265522655326554265552655626557265582655926560265612656226563265642656526566265672656826569265702657126572265732657426575265762657726578265792658026581265822658326584265852658626587265882658926590265912659226593265942659526596265972659826599266002660126602266032660426605266062660726608266092661026611266122661326614266152661626617266182661926620266212662226623266242662526626266272662826629266302663126632266332663426635266362663726638266392664026641266422664326644266452664626647266482664926650266512665226653266542665526656266572665826659266602666126662266632666426665266662666726668266692667026671266722667326674266752667626677266782667926680266812668226683266842668526686266872668826689266902669126692266932669426695266962669726698266992670026701267022670326704267052670626707267082670926710267112671226713267142671526716267172671826719267202672126722267232672426725267262672726728267292673026731267322673326734267352673626737267382673926740267412674226743267442674526746267472674826749267502675126752267532675426755267562675726758267592676026761267622676326764267652676626767267682676926770267712677226773267742677526776267772677826779267802678126782267832678426785267862678726788267892679026791267922679326794267952679626797267982679926800268012680226803268042680526806268072680826809268102681126812268132681426815268162681726818268192682026821268222682326824268252682626827268282682926830268312683226833268342683526836268372683826839268402684126842268432684426845268462684726848268492685026851268522685326854268552685626857268582685926860268612686226863268642686526866268672686826869268702687126872268732687426875268762687726878268792688026881268822688326884268852688626887268882688926890268912689226893268942689526896268972689826899269002690126902269032690426905269062690726908269092691026911269122691326914269152691626917269182691926920269212692226923269242692526926269272692826929269302693126932269332693426935269362693726938269392694026941269422694326944269452694626947269482694926950269512695226953269542695526956269572695826959269602696126962269632696426965269662696726968269692697026971269722697326974269752697626977269782697926980269812698226983269842698526986269872698826989269902699126992269932699426995269962699726998269992700027001270022700327004270052700627007270082700927010270112701227013270142701527016270172701827019270202702127022270232702427025270262702727028270292703027031270322703327034270352703627037270382703927040270412704227043270442704527046270472704827049270502705127052270532705427055270562705727058270592706027061270622706327064270652706627067270682706927070270712707227073270742707527076270772707827079270802708127082270832708427085270862708727088270892709027091270922709327094270952709627097270982709927100271012710227103271042710527106271072710827109271102711127112271132711427115271162711727118271192712027121271222712327124271252712627127271282712927130271312713227133271342713527136271372713827139271402714127142271432714427145271462714727148271492715027151271522715327154271552715627157271582715927160271612716227163271642716527166271672716827169271702717127172271732717427175271762717727178271792718027181271822718327184271852718627187271882718927190271912719227193271942719527196271972719827199272002720127202272032720427205272062720727208272092721027211272122721327214272152721627217272182721927220272212722227223272242722527226272272722827229272302723127232272332723427235272362723727238272392724027241272422724327244272452724627247272482724927250272512725227253272542725527256272572725827259272602726127262272632726427265272662726727268272692727027271272722727327274272752727627277272782727927280272812728227283272842728527286272872728827289272902729127292272932729427295272962729727298272992730027301273022730327304273052730627307273082730927310273112731227313273142731527316273172731827319273202732127322273232732427325273262732727328273292733027331273322733327334273352733627337273382733927340273412734227343273442734527346273472734827349273502735127352273532735427355273562735727358273592736027361273622736327364273652736627367273682736927370273712737227373273742737527376273772737827379273802738127382273832738427385273862738727388273892739027391273922739327394273952739627397273982739927400274012740227403274042740527406274072740827409274102741127412274132741427415274162741727418274192742027421274222742327424274252742627427274282742927430274312743227433274342743527436274372743827439274402744127442274432744427445274462744727448274492745027451274522745327454274552745627457274582745927460274612746227463274642746527466274672746827469274702747127472274732747427475274762747727478274792748027481274822748327484274852748627487274882748927490274912749227493274942749527496274972749827499275002750127502275032750427505275062750727508275092751027511275122751327514275152751627517275182751927520275212752227523275242752527526275272752827529275302753127532275332753427535275362753727538275392754027541275422754327544275452754627547275482754927550275512755227553275542755527556275572755827559275602756127562275632756427565275662756727568275692757027571275722757327574275752757627577275782757927580275812758227583275842758527586275872758827589275902759127592275932759427595275962759727598275992760027601276022760327604276052760627607276082760927610276112761227613276142761527616276172761827619276202762127622276232762427625276262762727628276292763027631276322763327634276352763627637276382763927640276412764227643276442764527646276472764827649276502765127652276532765427655276562765727658276592766027661276622766327664276652766627667276682766927670276712767227673276742767527676276772767827679276802768127682276832768427685276862768727688276892769027691276922769327694276952769627697276982769927700277012770227703277042770527706277072770827709277102771127712277132771427715277162771727718277192772027721277222772327724277252772627727277282772927730277312773227733277342773527736277372773827739277402774127742277432774427745277462774727748277492775027751277522775327754277552775627757277582775927760277612776227763277642776527766277672776827769277702777127772277732777427775277762777727778277792778027781277822778327784277852778627787277882778927790277912779227793277942779527796277972779827799278002780127802278032780427805278062780727808278092781027811278122781327814278152781627817278182781927820278212782227823278242782527826278272782827829278302783127832278332783427835278362783727838278392784027841278422784327844278452784627847278482784927850278512785227853278542785527856278572785827859278602786127862278632786427865278662786727868278692787027871278722787327874278752787627877278782787927880278812788227883278842788527886278872788827889278902789127892278932789427895278962789727898278992790027901279022790327904279052790627907279082790927910279112791227913279142791527916279172791827919279202792127922279232792427925279262792727928279292793027931279322793327934279352793627937279382793927940279412794227943279442794527946279472794827949279502795127952279532795427955279562795727958279592796027961279622796327964279652796627967279682796927970279712797227973279742797527976279772797827979279802798127982279832798427985279862798727988279892799027991279922799327994279952799627997279982799928000280012800228003280042800528006280072800828009280102801128012280132801428015280162801728018280192802028021280222802328024280252802628027280282802928030280312803228033280342803528036280372803828039280402804128042280432804428045280462804728048280492805028051280522805328054280552805628057280582805928060280612806228063280642806528066280672806828069280702807128072280732807428075280762807728078280792808028081280822808328084280852808628087280882808928090280912809228093280942809528096280972809828099281002810128102281032810428105281062810728108281092811028111281122811328114281152811628117281182811928120281212812228123281242812528126281272812828129281302813128132281332813428135281362813728138281392814028141281422814328144281452814628147281482814928150281512815228153281542815528156281572815828159281602816128162281632816428165281662816728168281692817028171281722817328174281752817628177281782817928180281812818228183281842818528186281872818828189281902819128192281932819428195281962819728198281992820028201282022820328204282052820628207282082820928210282112821228213282142821528216282172821828219282202822128222282232822428225282262822728228282292823028231282322823328234282352823628237282382823928240282412824228243282442824528246282472824828249282502825128252282532825428255282562825728258282592826028261282622826328264282652826628267282682826928270282712827228273282742827528276282772827828279282802828128282282832828428285282862828728288282892829028291282922829328294282952829628297282982829928300283012830228303283042830528306283072830828309283102831128312283132831428315283162831728318283192832028321283222832328324283252832628327283282832928330283312833228333283342833528336283372833828339283402834128342283432834428345283462834728348283492835028351283522835328354283552835628357283582835928360283612836228363283642836528366283672836828369283702837128372283732837428375283762837728378283792838028381283822838328384283852838628387283882838928390283912839228393283942839528396283972839828399284002840128402284032840428405284062840728408284092841028411284122841328414284152841628417284182841928420284212842228423284242842528426284272842828429284302843128432284332843428435284362843728438284392844028441284422844328444284452844628447284482844928450284512845228453284542845528456284572845828459284602846128462284632846428465284662846728468284692847028471284722847328474284752847628477284782847928480284812848228483284842848528486284872848828489284902849128492284932849428495284962849728498284992850028501285022850328504285052850628507285082850928510285112851228513285142851528516285172851828519285202852128522285232852428525285262852728528285292853028531285322853328534285352853628537285382853928540285412854228543285442854528546285472854828549285502855128552285532855428555285562855728558285592856028561285622856328564285652856628567285682856928570285712857228573285742857528576285772857828579285802858128582285832858428585285862858728588285892859028591285922859328594285952859628597285982859928600286012860228603286042860528606286072860828609286102861128612286132861428615286162861728618286192862028621286222862328624286252862628627286282862928630286312863228633286342863528636286372863828639286402864128642286432864428645286462864728648286492865028651286522865328654286552865628657286582865928660286612866228663286642866528666286672866828669286702867128672286732867428675286762867728678286792868028681286822868328684286852868628687286882868928690286912869228693286942869528696286972869828699287002870128702287032870428705287062870728708287092871028711287122871328714287152871628717287182871928720287212872228723287242872528726287272872828729287302873128732287332873428735287362873728738287392874028741287422874328744287452874628747287482874928750287512875228753287542875528756287572875828759287602876128762287632876428765287662876728768287692877028771287722877328774287752877628777287782877928780287812878228783287842878528786287872878828789287902879128792287932879428795287962879728798287992880028801288022880328804288052880628807288082880928810288112881228813288142881528816288172881828819288202882128822288232882428825288262882728828288292883028831288322883328834288352883628837288382883928840288412884228843288442884528846288472884828849288502885128852288532885428855288562885728858288592886028861288622886328864288652886628867288682886928870288712887228873288742887528876288772887828879288802888128882288832888428885288862888728888288892889028891288922889328894288952889628897288982889928900289012890228903289042890528906289072890828909289102891128912289132891428915289162891728918289192892028921289222892328924289252892628927289282892928930289312893228933289342893528936289372893828939289402894128942289432894428945289462894728948289492895028951289522895328954289552895628957289582895928960289612896228963289642896528966289672896828969289702897128972289732897428975289762897728978289792898028981289822898328984289852898628987289882898928990289912899228993289942899528996289972899828999290002900129002290032900429005290062900729008290092901029011290122901329014290152901629017290182901929020290212902229023290242902529026290272902829029290302903129032290332903429035290362903729038290392904029041290422904329044290452904629047290482904929050290512905229053290542905529056290572905829059290602906129062290632906429065290662906729068290692907029071290722907329074290752907629077290782907929080290812908229083290842908529086290872908829089290902909129092290932909429095290962909729098290992910029101291022910329104291052910629107291082910929110291112911229113291142911529116291172911829119291202912129122291232912429125291262912729128291292913029131291322913329134291352913629137291382913929140291412914229143291442914529146291472914829149291502915129152291532915429155291562915729158291592916029161291622916329164291652916629167291682916929170291712917229173291742917529176291772917829179291802918129182291832918429185291862918729188291892919029191291922919329194291952919629197291982919929200292012920229203292042920529206292072920829209292102921129212292132921429215292162921729218292192922029221292222922329224292252922629227292282922929230292312923229233292342923529236292372923829239292402924129242292432924429245292462924729248292492925029251292522925329254292552925629257292582925929260292612926229263292642926529266292672926829269292702927129272292732927429275292762927729278292792928029281292822928329284292852928629287292882928929290292912929229293292942929529296292972929829299293002930129302293032930429305293062930729308293092931029311293122931329314293152931629317293182931929320293212932229323293242932529326293272932829329293302933129332293332933429335293362933729338293392934029341293422934329344293452934629347293482934929350293512935229353293542935529356293572935829359293602936129362293632936429365293662936729368293692937029371293722937329374293752937629377293782937929380293812938229383293842938529386293872938829389293902939129392293932939429395293962939729398293992940029401294022940329404294052940629407294082940929410294112941229413294142941529416294172941829419294202942129422294232942429425294262942729428294292943029431294322943329434294352943629437294382943929440294412944229443294442944529446294472944829449294502945129452294532945429455294562945729458294592946029461294622946329464294652946629467294682946929470294712947229473294742947529476294772947829479294802948129482294832948429485294862948729488294892949029491294922949329494294952949629497294982949929500295012950229503295042950529506295072950829509295102951129512295132951429515295162951729518295192952029521295222952329524295252952629527295282952929530295312953229533295342953529536295372953829539295402954129542295432954429545295462954729548295492955029551295522955329554295552955629557295582955929560295612956229563295642956529566295672956829569295702957129572295732957429575295762957729578295792958029581295822958329584295852958629587295882958929590295912959229593295942959529596295972959829599296002960129602296032960429605296062960729608296092961029611296122961329614296152961629617296182961929620296212962229623296242962529626296272962829629296302963129632296332963429635296362963729638296392964029641296422964329644296452964629647296482964929650296512965229653296542965529656296572965829659296602966129662296632966429665296662966729668296692967029671296722967329674296752967629677296782967929680296812968229683296842968529686296872968829689296902969129692296932969429695296962969729698296992970029701297022970329704297052970629707297082970929710297112971229713297142971529716297172971829719297202972129722297232972429725297262972729728297292973029731297322973329734297352973629737297382973929740297412974229743297442974529746297472974829749297502975129752297532975429755297562975729758297592976029761297622976329764297652976629767297682976929770297712977229773297742977529776297772977829779297802978129782297832978429785297862978729788297892979029791297922979329794297952979629797297982979929800298012980229803298042980529806298072980829809298102981129812298132981429815298162981729818298192982029821298222982329824298252982629827298282982929830298312983229833298342983529836298372983829839298402984129842298432984429845298462984729848298492985029851298522985329854298552985629857298582985929860298612986229863298642986529866298672986829869298702987129872298732987429875298762987729878298792988029881298822988329884298852988629887298882988929890298912989229893298942989529896298972989829899299002990129902299032990429905299062990729908299092991029911299122991329914299152991629917299182991929920299212992229923299242992529926299272992829929299302993129932299332993429935299362993729938299392994029941299422994329944299452994629947299482994929950299512995229953299542995529956299572995829959299602996129962299632996429965299662996729968299692997029971299722997329974299752997629977299782997929980299812998229983299842998529986299872998829989299902999129992299932999429995299962999729998299993000030001300023000330004300053000630007300083000930010300113001230013300143001530016300173001830019300203002130022300233002430025300263002730028300293003030031300323003330034300353003630037300383003930040300413004230043300443004530046300473004830049300503005130052300533005430055300563005730058300593006030061300623006330064300653006630067300683006930070300713007230073300743007530076300773007830079300803008130082300833008430085300863008730088300893009030091300923009330094300953009630097300983009930100301013010230103301043010530106301073010830109301103011130112301133011430115301163011730118301193012030121301223012330124301253012630127301283012930130301313013230133301343013530136301373013830139301403014130142301433014430145301463014730148301493015030151301523015330154301553015630157301583015930160301613016230163301643016530166301673016830169301703017130172301733017430175301763017730178301793018030181301823018330184301853018630187301883018930190301913019230193301943019530196301973019830199302003020130202302033020430205302063020730208302093021030211302123021330214302153021630217302183021930220302213022230223302243022530226302273022830229302303023130232302333023430235302363023730238302393024030241302423024330244302453024630247302483024930250302513025230253302543025530256302573025830259302603026130262302633026430265302663026730268302693027030271302723027330274302753027630277302783027930280302813028230283302843028530286302873028830289302903029130292302933029430295302963029730298302993030030301303023030330304303053030630307303083030930310303113031230313303143031530316303173031830319303203032130322303233032430325303263032730328303293033030331303323033330334303353033630337303383033930340303413034230343303443034530346303473034830349303503035130352303533035430355303563035730358303593036030361303623036330364303653036630367303683036930370303713037230373303743037530376303773037830379303803038130382303833038430385303863038730388303893039030391303923039330394303953039630397303983039930400304013040230403304043040530406304073040830409304103041130412304133041430415304163041730418304193042030421304223042330424304253042630427304283042930430304313043230433304343043530436304373043830439304403044130442304433044430445304463044730448304493045030451304523045330454304553045630457304583045930460304613046230463304643046530466304673046830469304703047130472304733047430475304763047730478304793048030481304823048330484304853048630487304883048930490304913049230493304943049530496304973049830499305003050130502305033050430505305063050730508305093051030511305123051330514305153051630517305183051930520305213052230523305243052530526305273052830529305303053130532305333053430535305363053730538305393054030541305423054330544305453054630547305483054930550305513055230553305543055530556305573055830559305603056130562305633056430565305663056730568305693057030571305723057330574305753057630577305783057930580305813058230583305843058530586305873058830589305903059130592305933059430595305963059730598305993060030601306023060330604306053060630607306083060930610306113061230613306143061530616306173061830619306203062130622306233062430625306263062730628306293063030631306323063330634306353063630637306383063930640306413064230643306443064530646306473064830649306503065130652306533065430655306563065730658306593066030661306623066330664306653066630667306683066930670306713067230673306743067530676306773067830679306803068130682306833068430685306863068730688306893069030691306923069330694306953069630697306983069930700307013070230703307043070530706307073070830709307103071130712307133071430715307163071730718307193072030721307223072330724307253072630727307283072930730307313073230733307343073530736307373073830739307403074130742307433074430745307463074730748307493075030751307523075330754307553075630757307583075930760307613076230763307643076530766307673076830769307703077130772307733077430775307763077730778307793078030781307823078330784307853078630787307883078930790307913079230793307943079530796307973079830799308003080130802308033080430805308063080730808308093081030811308123081330814308153081630817308183081930820308213082230823308243082530826308273082830829308303083130832308333083430835308363083730838308393084030841308423084330844308453084630847308483084930850308513085230853308543085530856308573085830859308603086130862308633086430865308663086730868308693087030871308723087330874308753087630877308783087930880308813088230883308843088530886308873088830889308903089130892308933089430895308963089730898308993090030901309023090330904309053090630907309083090930910309113091230913309143091530916309173091830919309203092130922309233092430925309263092730928309293093030931309323093330934309353093630937309383093930940309413094230943309443094530946309473094830949309503095130952309533095430955309563095730958309593096030961309623096330964309653096630967309683096930970309713097230973309743097530976309773097830979309803098130982309833098430985309863098730988309893099030991309923099330994309953099630997309983099931000310013100231003310043100531006310073100831009310103101131012310133101431015310163101731018310193102031021310223102331024310253102631027310283102931030310313103231033310343103531036310373103831039310403104131042310433104431045310463104731048310493105031051310523105331054310553105631057310583105931060310613106231063310643106531066310673106831069310703107131072310733107431075310763107731078310793108031081310823108331084310853108631087310883108931090310913109231093310943109531096310973109831099311003110131102311033110431105311063110731108311093111031111311123111331114311153111631117311183111931120311213112231123311243112531126311273112831129311303113131132311333113431135311363113731138311393114031141311423114331144311453114631147311483114931150311513115231153311543115531156311573115831159311603116131162311633116431165311663116731168311693117031171311723117331174311753117631177311783117931180311813118231183311843118531186311873118831189311903119131192311933119431195311963119731198311993120031201312023120331204312053120631207312083120931210312113121231213312143121531216312173121831219312203122131222312233122431225312263122731228312293123031231312323123331234312353123631237312383123931240312413124231243312443124531246312473124831249312503125131252312533125431255312563125731258312593126031261312623126331264312653126631267312683126931270312713127231273312743127531276312773127831279312803128131282312833128431285312863128731288312893129031291312923129331294312953129631297312983129931300313013130231303313043130531306313073130831309313103131131312313133131431315313163131731318313193132031321313223132331324313253132631327313283132931330313313133231333313343133531336313373133831339313403134131342313433134431345313463134731348313493135031351313523135331354313553135631357313583135931360313613136231363313643136531366313673136831369313703137131372313733137431375313763137731378313793138031381313823138331384313853138631387313883138931390313913139231393313943139531396313973139831399314003140131402314033140431405314063140731408314093141031411314123141331414314153141631417314183141931420314213142231423314243142531426314273142831429314303143131432314333143431435314363143731438314393144031441314423144331444314453144631447314483144931450314513145231453314543145531456314573145831459314603146131462314633146431465314663146731468314693147031471314723147331474314753147631477314783147931480314813148231483314843148531486314873148831489314903149131492314933149431495314963149731498314993150031501315023150331504315053150631507315083150931510315113151231513315143151531516315173151831519315203152131522315233152431525315263152731528315293153031531315323153331534315353153631537315383153931540315413154231543315443154531546315473154831549315503155131552315533155431555315563155731558315593156031561315623156331564315653156631567315683156931570315713157231573315743157531576315773157831579315803158131582315833158431585315863158731588315893159031591315923159331594315953159631597315983159931600316013160231603316043160531606316073160831609316103161131612316133161431615316163161731618316193162031621316223162331624316253162631627316283162931630316313163231633316343163531636316373163831639316403164131642316433164431645316463164731648316493165031651316523165331654316553165631657316583165931660316613166231663316643166531666316673166831669316703167131672316733167431675316763167731678316793168031681316823168331684316853168631687316883168931690316913169231693316943169531696316973169831699317003170131702317033170431705317063170731708317093171031711317123171331714317153171631717317183171931720317213172231723317243172531726317273172831729317303173131732317333173431735317363173731738317393174031741317423174331744317453174631747317483174931750317513175231753317543175531756317573175831759317603176131762317633176431765317663176731768317693177031771317723177331774317753177631777317783177931780317813178231783317843178531786317873178831789317903179131792317933179431795317963179731798317993180031801318023180331804318053180631807318083180931810318113181231813318143181531816318173181831819318203182131822318233182431825318263182731828318293183031831318323183331834318353183631837318383183931840318413184231843318443184531846318473184831849318503185131852318533185431855318563185731858318593186031861318623186331864318653186631867318683186931870318713187231873318743187531876318773187831879318803188131882318833188431885318863188731888318893189031891318923189331894318953189631897318983189931900319013190231903319043190531906319073190831909319103191131912319133191431915319163191731918319193192031921319223192331924319253192631927319283192931930319313193231933319343193531936319373193831939319403194131942319433194431945319463194731948319493195031951319523195331954319553195631957319583195931960319613196231963319643196531966319673196831969319703197131972319733197431975319763197731978319793198031981319823198331984319853198631987319883198931990319913199231993319943199531996319973199831999320003200132002320033200432005320063200732008320093201032011320123201332014320153201632017320183201932020320213202232023320243202532026320273202832029320303203132032320333203432035320363203732038320393204032041320423204332044320453204632047320483204932050320513205232053320543205532056320573205832059320603206132062320633206432065320663206732068320693207032071320723207332074320753207632077320783207932080320813208232083320843208532086320873208832089320903209132092320933209432095320963209732098320993210032101321023210332104321053210632107321083210932110321113211232113321143211532116321173211832119321203212132122321233212432125321263212732128321293213032131321323213332134321353213632137321383213932140321413214232143321443214532146321473214832149321503215132152321533215432155321563215732158321593216032161321623216332164321653216632167321683216932170321713217232173321743217532176321773217832179321803218132182321833218432185321863218732188321893219032191321923219332194321953219632197321983219932200322013220232203322043220532206322073220832209322103221132212322133221432215322163221732218322193222032221322223222332224322253222632227322283222932230322313223232233322343223532236322373223832239322403224132242322433224432245322463224732248322493225032251322523225332254322553225632257322583225932260322613226232263322643226532266322673226832269322703227132272322733227432275322763227732278322793228032281322823228332284322853228632287322883228932290322913229232293322943229532296322973229832299323003230132302323033230432305323063230732308323093231032311323123231332314323153231632317323183231932320323213232232323323243232532326323273232832329323303233132332323333233432335323363233732338323393234032341323423234332344323453234632347323483234932350323513235232353323543235532356323573235832359323603236132362323633236432365323663236732368323693237032371323723237332374323753237632377323783237932380323813238232383323843238532386323873238832389323903239132392323933239432395323963239732398323993240032401324023240332404324053240632407324083240932410324113241232413324143241532416324173241832419324203242132422324233242432425324263242732428324293243032431324323243332434324353243632437324383243932440324413244232443324443244532446324473244832449324503245132452324533245432455324563245732458324593246032461324623246332464324653246632467324683246932470324713247232473324743247532476324773247832479324803248132482324833248432485324863248732488324893249032491324923249332494324953249632497324983249932500325013250232503325043250532506325073250832509325103251132512325133251432515325163251732518325193252032521325223252332524325253252632527325283252932530325313253232533325343253532536325373253832539325403254132542325433254432545325463254732548325493255032551325523255332554325553255632557325583255932560325613256232563325643256532566325673256832569325703257132572325733257432575325763257732578325793258032581325823258332584325853258632587325883258932590325913259232593325943259532596325973259832599326003260132602326033260432605326063260732608326093261032611326123261332614326153261632617326183261932620326213262232623326243262532626326273262832629326303263132632326333263432635326363263732638326393264032641326423264332644326453264632647326483264932650326513265232653326543265532656326573265832659326603266132662326633266432665326663266732668326693267032671326723267332674326753267632677326783267932680326813268232683326843268532686326873268832689326903269132692326933269432695326963269732698326993270032701327023270332704327053270632707327083270932710327113271232713327143271532716327173271832719327203272132722327233272432725327263272732728327293273032731327323273332734327353273632737327383273932740327413274232743327443274532746327473274832749327503275132752327533275432755327563275732758327593276032761327623276332764327653276632767327683276932770327713277232773327743277532776327773277832779327803278132782327833278432785327863278732788327893279032791327923279332794327953279632797327983279932800328013280232803328043280532806328073280832809328103281132812328133281432815328163281732818328193282032821328223282332824328253282632827328283282932830328313283232833328343283532836328373283832839328403284132842328433284432845328463284732848328493285032851328523285332854328553285632857328583285932860328613286232863328643286532866328673286832869328703287132872328733287432875328763287732878328793288032881328823288332884328853288632887328883288932890328913289232893328943289532896328973289832899329003290132902329033290432905329063290732908329093291032911329123291332914329153291632917329183291932920329213292232923329243292532926329273292832929329303293132932329333293432935329363293732938329393294032941329423294332944329453294632947329483294932950329513295232953329543295532956329573295832959329603296132962329633296432965329663296732968329693297032971329723297332974329753297632977329783297932980329813298232983329843298532986329873298832989329903299132992329933299432995329963299732998329993300033001330023300333004330053300633007330083300933010330113301233013330143301533016330173301833019330203302133022330233302433025330263302733028330293303033031330323303333034330353303633037330383303933040330413304233043330443304533046330473304833049330503305133052330533305433055330563305733058330593306033061330623306333064330653306633067330683306933070330713307233073330743307533076330773307833079330803308133082330833308433085330863308733088330893309033091330923309333094330953309633097330983309933100331013310233103331043310533106331073310833109331103311133112331133311433115331163311733118331193312033121331223312333124331253312633127331283312933130331313313233133331343313533136331373313833139331403314133142331433314433145331463314733148331493315033151
  1. apiVersion: apiextensions.k8s.io/v1
  2. kind: CustomResourceDefinition
  3. metadata:
  4. annotations:
  5. controller-gen.kubebuilder.io/version: v0.19.0
  6. labels:
  7. external-secrets.io/component: controller
  8. name: clusterexternalsecrets.external-secrets.io
  9. spec:
  10. group: external-secrets.io
  11. names:
  12. categories:
  13. - external-secrets
  14. kind: ClusterExternalSecret
  15. listKind: ClusterExternalSecretList
  16. plural: clusterexternalsecrets
  17. shortNames:
  18. - ces
  19. singular: clusterexternalsecret
  20. scope: Cluster
  21. versions:
  22. - additionalPrinterColumns:
  23. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  24. name: Store
  25. type: string
  26. - jsonPath: .spec.refreshTime
  27. name: Refresh Interval
  28. type: string
  29. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  30. name: Ready
  31. type: string
  32. name: v1
  33. schema:
  34. openAPIV3Schema:
  35. description: ClusterExternalSecret is the Schema for the clusterexternalsecrets API.
  36. properties:
  37. apiVersion:
  38. description: |-
  39. APIVersion defines the versioned schema of this representation of an object.
  40. Servers should convert recognized schemas to the latest internal value, and
  41. may reject unrecognized values.
  42. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  43. type: string
  44. kind:
  45. description: |-
  46. Kind is a string value representing the REST resource this object represents.
  47. Servers may infer this from the endpoint the client submits requests to.
  48. Cannot be updated.
  49. In CamelCase.
  50. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  51. type: string
  52. metadata:
  53. type: object
  54. spec:
  55. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  56. properties:
  57. externalSecretMetadata:
  58. description: The metadata of the external secrets to be created
  59. properties:
  60. annotations:
  61. additionalProperties:
  62. type: string
  63. type: object
  64. labels:
  65. additionalProperties:
  66. type: string
  67. type: object
  68. type: object
  69. externalSecretName:
  70. description: |-
  71. The name of the external secrets to be created.
  72. Defaults to the name of the ClusterExternalSecret
  73. maxLength: 253
  74. minLength: 1
  75. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  76. type: string
  77. externalSecretSpec:
  78. description: The spec for the ExternalSecrets to be created
  79. properties:
  80. data:
  81. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  82. items:
  83. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  84. properties:
  85. remoteRef:
  86. description: |-
  87. RemoteRef points to the remote secret and defines
  88. which secret (version/property/..) to fetch.
  89. properties:
  90. conversionStrategy:
  91. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  92. enum:
  93. - Default
  94. - Unicode
  95. type: string
  96. decodingStrategy:
  97. description: Used to define a decoding Strategy. Defaults to None when omitted.
  98. enum:
  99. - Auto
  100. - Base64
  101. - Base64URL
  102. - None
  103. type: string
  104. key:
  105. description: Key is the key used in the Provider, mandatory
  106. type: string
  107. metadataPolicy:
  108. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  109. enum:
  110. - None
  111. - Fetch
  112. type: string
  113. nullBytePolicy:
  114. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  115. enum:
  116. - Ignore
  117. - Fail
  118. type: string
  119. property:
  120. description: Used to select a specific property of the Provider value (if a map), if supported
  121. type: string
  122. version:
  123. description: Used to select a specific version of the Provider value, if supported
  124. type: string
  125. required:
  126. - key
  127. type: object
  128. secretKey:
  129. description: The key in the Kubernetes Secret to store the value.
  130. maxLength: 253
  131. minLength: 1
  132. pattern: ^[-._a-zA-Z0-9]+$
  133. type: string
  134. sourceRef:
  135. description: |-
  136. SourceRef allows you to override the source
  137. from which the value will be pulled.
  138. maxProperties: 1
  139. minProperties: 1
  140. properties:
  141. generatorRef:
  142. description: |-
  143. GeneratorRef points to a generator custom resource.
  144. Deprecated: The generatorRef is not implemented in .data[].
  145. this will be removed with v1.
  146. properties:
  147. apiVersion:
  148. default: generators.external-secrets.io/v1alpha1
  149. description: Specify the apiVersion of the generator resource
  150. type: string
  151. kind:
  152. description: Specify the Kind of the generator resource
  153. enum:
  154. - ACRAccessToken
  155. - BeyondtrustWorkloadCredentialsDynamicSecret
  156. - ClusterGenerator
  157. - CloudsmithAccessToken
  158. - ECRAuthorizationToken
  159. - Fake
  160. - GCRAccessToken
  161. - GithubAccessToken
  162. - GitlabDeployToken
  163. - QuayAccessToken
  164. - Password
  165. - SSHKey
  166. - STSSessionToken
  167. - UUID
  168. - VaultDynamicSecret
  169. - Webhook
  170. - Grafana
  171. - MFA
  172. type: string
  173. name:
  174. description: Specify the name of the generator resource
  175. maxLength: 253
  176. minLength: 1
  177. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  178. type: string
  179. required:
  180. - kind
  181. - name
  182. type: object
  183. storeRef:
  184. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  185. properties:
  186. kind:
  187. description: |-
  188. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  189. Defaults to `SecretStore`
  190. enum:
  191. - SecretStore
  192. - ClusterSecretStore
  193. type: string
  194. name:
  195. description: Name of the SecretStore resource
  196. maxLength: 253
  197. minLength: 1
  198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  199. type: string
  200. type: object
  201. type: object
  202. required:
  203. - remoteRef
  204. - secretKey
  205. type: object
  206. type: array
  207. dataFrom:
  208. description: |-
  209. DataFrom is used to fetch all properties from a specific Provider data
  210. If multiple entries are specified, the Secret keys are merged in the specified order
  211. items:
  212. description: |-
  213. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  214. when using DataFrom to fetch multiple values from a Provider.
  215. properties:
  216. extract:
  217. description: |-
  218. Used to extract multiple key/value pairs from one secret
  219. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  220. properties:
  221. conversionStrategy:
  222. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  223. enum:
  224. - Default
  225. - Unicode
  226. type: string
  227. decodingStrategy:
  228. description: Used to define a decoding Strategy. Defaults to None when omitted.
  229. enum:
  230. - Auto
  231. - Base64
  232. - Base64URL
  233. - None
  234. type: string
  235. key:
  236. description: Key is the key used in the Provider, mandatory
  237. type: string
  238. metadataPolicy:
  239. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  240. enum:
  241. - None
  242. - Fetch
  243. type: string
  244. nullBytePolicy:
  245. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  246. enum:
  247. - Ignore
  248. - Fail
  249. type: string
  250. property:
  251. description: Used to select a specific property of the Provider value (if a map), if supported
  252. type: string
  253. version:
  254. description: Used to select a specific version of the Provider value, if supported
  255. type: string
  256. required:
  257. - key
  258. type: object
  259. find:
  260. description: |-
  261. Used to find secrets based on tags or regular expressions
  262. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  263. properties:
  264. conversionStrategy:
  265. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  266. enum:
  267. - Default
  268. - Unicode
  269. type: string
  270. decodingStrategy:
  271. description: Used to define a decoding Strategy. Defaults to None when omitted.
  272. enum:
  273. - Auto
  274. - Base64
  275. - Base64URL
  276. - None
  277. type: string
  278. name:
  279. description: Finds secrets based on the name.
  280. properties:
  281. regexp:
  282. description: Finds secrets base
  283. type: string
  284. type: object
  285. nullBytePolicy:
  286. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  287. enum:
  288. - Ignore
  289. - Fail
  290. type: string
  291. path:
  292. description: A root path to start the find operations.
  293. type: string
  294. tags:
  295. additionalProperties:
  296. type: string
  297. description: Find secrets based on tags.
  298. type: object
  299. type: object
  300. rewrite:
  301. description: |-
  302. Used to rewrite secret Keys after getting them from the secret Provider
  303. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  304. items:
  305. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  306. maxProperties: 1
  307. minProperties: 1
  308. properties:
  309. merge:
  310. description: |-
  311. Used to merge key/values in one single Secret
  312. The resulting key will contain all values from the specified secrets
  313. properties:
  314. conflictPolicy:
  315. default: Error
  316. description: Used to define the policy to use in conflict resolution.
  317. enum:
  318. - Ignore
  319. - Error
  320. type: string
  321. into:
  322. default: ""
  323. description: |-
  324. Used to define the target key of the merge operation.
  325. Required if strategy is JSON. Ignored otherwise.
  326. type: string
  327. priority:
  328. description: Used to define key priority in conflict resolution.
  329. items:
  330. type: string
  331. type: array
  332. priorityPolicy:
  333. default: Strict
  334. description: Used to define the policy when a key in the priority list does not exist in the input.
  335. enum:
  336. - IgnoreNotFound
  337. - Strict
  338. type: string
  339. strategy:
  340. default: Extract
  341. description: Used to define the strategy to use in the merge operation.
  342. enum:
  343. - Extract
  344. - JSON
  345. type: string
  346. type: object
  347. regexp:
  348. description: |-
  349. Used to rewrite with regular expressions.
  350. The resulting key will be the output of a regexp.ReplaceAll operation.
  351. properties:
  352. source:
  353. description: Used to define the regular expression of a re.Compiler.
  354. type: string
  355. target:
  356. description: Used to define the target pattern of a ReplaceAll operation.
  357. type: string
  358. required:
  359. - source
  360. - target
  361. type: object
  362. transform:
  363. description: |-
  364. Used to apply string transformation on the secrets.
  365. The resulting key will be the output of the template applied by the operation.
  366. properties:
  367. template:
  368. description: |-
  369. Used to define the template to apply on the secret name.
  370. `.value ` will specify the secret name in the template.
  371. type: string
  372. required:
  373. - template
  374. type: object
  375. type: object
  376. type: array
  377. sourceRef:
  378. description: |-
  379. SourceRef points to a store or generator
  380. which contains secret values ready to use.
  381. Use this in combination with Extract or Find pull values out of
  382. a specific SecretStore.
  383. When sourceRef points to a generator Extract or Find is not supported.
  384. The generator returns a static map of values
  385. maxProperties: 1
  386. minProperties: 1
  387. properties:
  388. generatorRef:
  389. description: GeneratorRef points to a generator custom resource.
  390. properties:
  391. apiVersion:
  392. default: generators.external-secrets.io/v1alpha1
  393. description: Specify the apiVersion of the generator resource
  394. type: string
  395. kind:
  396. description: Specify the Kind of the generator resource
  397. enum:
  398. - ACRAccessToken
  399. - BeyondtrustWorkloadCredentialsDynamicSecret
  400. - ClusterGenerator
  401. - CloudsmithAccessToken
  402. - ECRAuthorizationToken
  403. - Fake
  404. - GCRAccessToken
  405. - GithubAccessToken
  406. - GitlabDeployToken
  407. - QuayAccessToken
  408. - Password
  409. - SSHKey
  410. - STSSessionToken
  411. - UUID
  412. - VaultDynamicSecret
  413. - Webhook
  414. - Grafana
  415. - MFA
  416. type: string
  417. name:
  418. description: Specify the name of the generator resource
  419. maxLength: 253
  420. minLength: 1
  421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  422. type: string
  423. required:
  424. - kind
  425. - name
  426. type: object
  427. storeRef:
  428. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  429. properties:
  430. kind:
  431. description: |-
  432. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  433. Defaults to `SecretStore`
  434. enum:
  435. - SecretStore
  436. - ClusterSecretStore
  437. type: string
  438. name:
  439. description: Name of the SecretStore resource
  440. maxLength: 253
  441. minLength: 1
  442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  443. type: string
  444. type: object
  445. type: object
  446. type: object
  447. type: array
  448. refreshInterval:
  449. default: 1h0m0s
  450. description: |-
  451. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  452. specified as Golang Duration strings.
  453. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  454. Example values: "1h0m0s", "2h30m0s", "10m0s"
  455. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  456. type: string
  457. refreshPolicy:
  458. description: |-
  459. RefreshPolicy determines how the ExternalSecret should be refreshed:
  460. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  461. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  462. No periodic updates occur if refreshInterval is 0.
  463. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  464. enum:
  465. - CreatedOnce
  466. - Periodic
  467. - OnChange
  468. type: string
  469. secretStoreRef:
  470. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  471. properties:
  472. kind:
  473. description: |-
  474. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  475. Defaults to `SecretStore`
  476. enum:
  477. - SecretStore
  478. - ClusterSecretStore
  479. type: string
  480. name:
  481. description: Name of the SecretStore resource
  482. maxLength: 253
  483. minLength: 1
  484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  485. type: string
  486. type: object
  487. syncWindows:
  488. description: |-
  489. SyncWindows optionally restricts when periodic refreshes may occur.
  490. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  491. properties:
  492. kind:
  493. description: |-
  494. Kind applies to every window in the list.
  495. "allow" -- syncs are permitted only while at least one window is active;
  496. all other times are blocked.
  497. "deny" -- syncs are blocked while any window is active;
  498. all other times are permitted.
  499. enum:
  500. - allow
  501. - deny
  502. type: string
  503. windows:
  504. description: Windows is the list of schedule+duration pairs.
  505. items:
  506. description: |-
  507. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  508. within a SyncWindows block.
  509. properties:
  510. duration:
  511. description: |-
  512. Duration specifies how long the window stays open after each Schedule
  513. firing. Example: "8h".
  514. type: string
  515. schedule:
  516. description: |-
  517. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  518. named shorthand such as @daily or @every 1h. It marks the start time of
  519. each window occurrence.
  520. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  521. minLength: 1
  522. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  523. type: string
  524. required:
  525. - duration
  526. - schedule
  527. type: object
  528. minItems: 1
  529. type: array
  530. required:
  531. - kind
  532. - windows
  533. type: object
  534. target:
  535. default:
  536. creationPolicy: Owner
  537. deletionPolicy: Retain
  538. description: |-
  539. ExternalSecretTarget defines the Kubernetes Secret to be created,
  540. there can be only one target per ExternalSecret.
  541. properties:
  542. creationPolicy:
  543. default: Owner
  544. description: |-
  545. CreationPolicy defines rules on how to create the resulting Secret.
  546. Defaults to "Owner"
  547. enum:
  548. - Owner
  549. - Orphan
  550. - Merge
  551. - None
  552. - CreateOrMerge
  553. type: string
  554. deletionPolicy:
  555. default: Retain
  556. description: |-
  557. DeletionPolicy defines rules on how to delete the resulting Secret.
  558. Defaults to "Retain"
  559. enum:
  560. - Delete
  561. - Merge
  562. - Retain
  563. type: string
  564. immutable:
  565. description: Immutable defines if the final secret will be immutable
  566. type: boolean
  567. manifest:
  568. description: |-
  569. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  570. When specified, ExternalSecret will create the resource type defined here
  571. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  572. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  573. properties:
  574. apiVersion:
  575. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  576. minLength: 1
  577. type: string
  578. kind:
  579. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  580. minLength: 1
  581. type: string
  582. required:
  583. - apiVersion
  584. - kind
  585. type: object
  586. name:
  587. description: |-
  588. The name of the Secret resource to be managed.
  589. Defaults to the .metadata.name of the ExternalSecret resource
  590. maxLength: 253
  591. minLength: 1
  592. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  593. type: string
  594. template:
  595. description: Template defines a blueprint for the created Secret resource.
  596. properties:
  597. data:
  598. additionalProperties:
  599. type: string
  600. type: object
  601. engineVersion:
  602. default: v2
  603. description: |-
  604. EngineVersion specifies the template engine version
  605. that should be used to compile/execute the
  606. template specified in .data and .templateFrom[].
  607. enum:
  608. - v2
  609. type: string
  610. mergePolicy:
  611. default: Replace
  612. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  613. enum:
  614. - Replace
  615. - Merge
  616. type: string
  617. metadata:
  618. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  619. properties:
  620. annotations:
  621. additionalProperties:
  622. type: string
  623. type: object
  624. finalizers:
  625. items:
  626. type: string
  627. type: array
  628. labels:
  629. additionalProperties:
  630. type: string
  631. type: object
  632. type: object
  633. templateFrom:
  634. items:
  635. description: |-
  636. TemplateFrom specifies a source for templates.
  637. Each item in the list can either reference a ConfigMap or a Secret resource.
  638. properties:
  639. configMap:
  640. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  641. properties:
  642. items:
  643. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  644. items:
  645. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  646. properties:
  647. key:
  648. description: A key in the ConfigMap/Secret
  649. maxLength: 253
  650. minLength: 1
  651. pattern: ^[-._a-zA-Z0-9]+$
  652. type: string
  653. templateAs:
  654. default: Values
  655. description: TemplateScope specifies how the template keys should be interpreted.
  656. enum:
  657. - Values
  658. - KeysAndValues
  659. type: string
  660. required:
  661. - key
  662. type: object
  663. type: array
  664. name:
  665. description: The name of the ConfigMap/Secret resource
  666. maxLength: 253
  667. minLength: 1
  668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  669. type: string
  670. required:
  671. - items
  672. - name
  673. type: object
  674. literal:
  675. type: string
  676. secret:
  677. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  678. properties:
  679. items:
  680. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  681. items:
  682. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  683. properties:
  684. key:
  685. description: A key in the ConfigMap/Secret
  686. maxLength: 253
  687. minLength: 1
  688. pattern: ^[-._a-zA-Z0-9]+$
  689. type: string
  690. templateAs:
  691. default: Values
  692. description: TemplateScope specifies how the template keys should be interpreted.
  693. enum:
  694. - Values
  695. - KeysAndValues
  696. type: string
  697. required:
  698. - key
  699. type: object
  700. type: array
  701. name:
  702. description: The name of the ConfigMap/Secret resource
  703. maxLength: 253
  704. minLength: 1
  705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  706. type: string
  707. required:
  708. - items
  709. - name
  710. type: object
  711. target:
  712. default: Data
  713. description: |-
  714. Target specifies where to place the template result.
  715. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  716. any other value is rejected because it would allow writes to privileged Secret fields.
  717. For custom resources (when spec.target.manifest is set), this supports
  718. nested paths like "spec.database.config" or "data".
  719. type: string
  720. valuesDecodingStrategy:
  721. description: |-
  722. Used to define a decoding Strategy for the rendered template values.
  723. Defaults to None when omitted.
  724. enum:
  725. - Auto
  726. - Base64
  727. - Base64URL
  728. - None
  729. type: string
  730. type: object
  731. type: array
  732. type:
  733. type: string
  734. type: object
  735. type: object
  736. type: object
  737. namespaceSelector:
  738. description: |-
  739. The labels to select by to find the Namespaces to create the ExternalSecrets in.
  740. Deprecated: Use NamespaceSelectors instead.
  741. properties:
  742. matchExpressions:
  743. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  744. items:
  745. description: |-
  746. A label selector requirement is a selector that contains values, a key, and an operator that
  747. relates the key and values.
  748. properties:
  749. key:
  750. description: key is the label key that the selector applies to.
  751. type: string
  752. operator:
  753. description: |-
  754. operator represents a key's relationship to a set of values.
  755. Valid operators are In, NotIn, Exists and DoesNotExist.
  756. type: string
  757. values:
  758. description: |-
  759. values is an array of string values. If the operator is In or NotIn,
  760. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  761. the values array must be empty. This array is replaced during a strategic
  762. merge patch.
  763. items:
  764. type: string
  765. type: array
  766. x-kubernetes-list-type: atomic
  767. required:
  768. - key
  769. - operator
  770. type: object
  771. type: array
  772. x-kubernetes-list-type: atomic
  773. matchLabels:
  774. additionalProperties:
  775. type: string
  776. description: |-
  777. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  778. map is equivalent to an element of matchExpressions, whose key field is "key", the
  779. operator is "In", and the values array contains only "value". The requirements are ANDed.
  780. type: object
  781. type: object
  782. x-kubernetes-map-type: atomic
  783. namespaceSelectors:
  784. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  785. items:
  786. description: |-
  787. A label selector is a label query over a set of resources. The result of matchLabels and
  788. matchExpressions are ANDed. An empty label selector matches all objects. A null
  789. label selector matches no objects.
  790. properties:
  791. matchExpressions:
  792. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  793. items:
  794. description: |-
  795. A label selector requirement is a selector that contains values, a key, and an operator that
  796. relates the key and values.
  797. properties:
  798. key:
  799. description: key is the label key that the selector applies to.
  800. type: string
  801. operator:
  802. description: |-
  803. operator represents a key's relationship to a set of values.
  804. Valid operators are In, NotIn, Exists and DoesNotExist.
  805. type: string
  806. values:
  807. description: |-
  808. values is an array of string values. If the operator is In or NotIn,
  809. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  810. the values array must be empty. This array is replaced during a strategic
  811. merge patch.
  812. items:
  813. type: string
  814. type: array
  815. x-kubernetes-list-type: atomic
  816. required:
  817. - key
  818. - operator
  819. type: object
  820. type: array
  821. x-kubernetes-list-type: atomic
  822. matchLabels:
  823. additionalProperties:
  824. type: string
  825. description: |-
  826. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  827. map is equivalent to an element of matchExpressions, whose key field is "key", the
  828. operator is "In", and the values array contains only "value". The requirements are ANDed.
  829. type: object
  830. type: object
  831. x-kubernetes-map-type: atomic
  832. type: array
  833. namespaces:
  834. description: |-
  835. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  836. Deprecated: Use NamespaceSelectors instead.
  837. items:
  838. maxLength: 63
  839. minLength: 1
  840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  841. type: string
  842. type: array
  843. refreshTime:
  844. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  845. type: string
  846. required:
  847. - externalSecretSpec
  848. type: object
  849. status:
  850. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  851. properties:
  852. conditions:
  853. items:
  854. description: ClusterExternalSecretStatusCondition defines the observed state of a ClusterExternalSecret resource.
  855. properties:
  856. message:
  857. type: string
  858. status:
  859. type: string
  860. type:
  861. description: ClusterExternalSecretConditionType defines a value type for ClusterExternalSecret conditions.
  862. type: string
  863. required:
  864. - status
  865. - type
  866. type: object
  867. type: array
  868. externalSecretName:
  869. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  870. type: string
  871. failedNamespaces:
  872. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  873. items:
  874. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  875. properties:
  876. namespace:
  877. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  878. type: string
  879. reason:
  880. description: Reason is why the ExternalSecret failed to apply to the namespace
  881. type: string
  882. required:
  883. - namespace
  884. type: object
  885. type: array
  886. provisionedNamespaces:
  887. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  888. items:
  889. type: string
  890. type: array
  891. type: object
  892. type: object
  893. served: true
  894. storage: true
  895. subresources:
  896. status: {}
  897. - additionalPrinterColumns:
  898. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  899. name: Store
  900. type: string
  901. - jsonPath: .spec.refreshTime
  902. name: Refresh Interval
  903. type: string
  904. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  905. name: Ready
  906. type: string
  907. deprecated: true
  908. name: v1beta1
  909. schema:
  910. openAPIV3Schema:
  911. description: ClusterExternalSecret is the schema for the clusterexternalsecrets API.
  912. properties:
  913. apiVersion:
  914. description: |-
  915. APIVersion defines the versioned schema of this representation of an object.
  916. Servers should convert recognized schemas to the latest internal value, and
  917. may reject unrecognized values.
  918. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  919. type: string
  920. kind:
  921. description: |-
  922. Kind is a string value representing the REST resource this object represents.
  923. Servers may infer this from the endpoint the client submits requests to.
  924. Cannot be updated.
  925. In CamelCase.
  926. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  927. type: string
  928. metadata:
  929. type: object
  930. spec:
  931. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  932. properties:
  933. externalSecretMetadata:
  934. description: The metadata of the external secrets to be created
  935. properties:
  936. annotations:
  937. additionalProperties:
  938. type: string
  939. type: object
  940. labels:
  941. additionalProperties:
  942. type: string
  943. type: object
  944. type: object
  945. externalSecretName:
  946. description: |-
  947. The name of the external secrets to be created.
  948. Defaults to the name of the ClusterExternalSecret
  949. maxLength: 253
  950. minLength: 1
  951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  952. type: string
  953. externalSecretSpec:
  954. description: The spec for the ExternalSecrets to be created
  955. properties:
  956. data:
  957. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  958. items:
  959. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  960. properties:
  961. remoteRef:
  962. description: |-
  963. RemoteRef points to the remote secret and defines
  964. which secret (version/property/..) to fetch.
  965. properties:
  966. conversionStrategy:
  967. default: Default
  968. description: Used to define a conversion Strategy
  969. enum:
  970. - Default
  971. - Unicode
  972. type: string
  973. decodingStrategy:
  974. default: None
  975. description: Used to define a decoding Strategy
  976. enum:
  977. - Auto
  978. - Base64
  979. - Base64URL
  980. - None
  981. type: string
  982. key:
  983. description: Key is the key used in the Provider, mandatory
  984. type: string
  985. metadataPolicy:
  986. default: None
  987. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  988. enum:
  989. - None
  990. - Fetch
  991. type: string
  992. property:
  993. description: Used to select a specific property of the Provider value (if a map), if supported
  994. type: string
  995. version:
  996. description: Used to select a specific version of the Provider value, if supported
  997. type: string
  998. required:
  999. - key
  1000. type: object
  1001. secretKey:
  1002. description: The key in the Kubernetes Secret to store the value.
  1003. maxLength: 253
  1004. minLength: 1
  1005. pattern: ^[-._a-zA-Z0-9]+$
  1006. type: string
  1007. sourceRef:
  1008. description: |-
  1009. SourceRef allows you to override the source
  1010. from which the value will be pulled.
  1011. maxProperties: 1
  1012. minProperties: 1
  1013. properties:
  1014. generatorRef:
  1015. description: |-
  1016. GeneratorRef points to a generator custom resource.
  1017. Deprecated: The generatorRef is not implemented in .data[].
  1018. this will be removed with v1.
  1019. properties:
  1020. apiVersion:
  1021. default: generators.external-secrets.io/v1alpha1
  1022. description: Specify the apiVersion of the generator resource
  1023. type: string
  1024. kind:
  1025. description: Specify the Kind of the generator resource
  1026. enum:
  1027. - ACRAccessToken
  1028. - ClusterGenerator
  1029. - ECRAuthorizationToken
  1030. - Fake
  1031. - GCRAccessToken
  1032. - GithubAccessToken
  1033. - QuayAccessToken
  1034. - Password
  1035. - SSHKey
  1036. - STSSessionToken
  1037. - UUID
  1038. - VaultDynamicSecret
  1039. - Webhook
  1040. - Grafana
  1041. type: string
  1042. name:
  1043. description: Specify the name of the generator resource
  1044. maxLength: 253
  1045. minLength: 1
  1046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1047. type: string
  1048. required:
  1049. - kind
  1050. - name
  1051. type: object
  1052. storeRef:
  1053. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1054. properties:
  1055. kind:
  1056. description: |-
  1057. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1058. Defaults to `SecretStore`
  1059. enum:
  1060. - SecretStore
  1061. - ClusterSecretStore
  1062. type: string
  1063. name:
  1064. description: Name of the SecretStore resource
  1065. maxLength: 253
  1066. minLength: 1
  1067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1068. type: string
  1069. type: object
  1070. type: object
  1071. required:
  1072. - remoteRef
  1073. - secretKey
  1074. type: object
  1075. type: array
  1076. dataFrom:
  1077. description: |-
  1078. DataFrom is used to fetch all properties from a specific Provider data
  1079. If multiple entries are specified, the Secret keys are merged in the specified order
  1080. items:
  1081. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  1082. properties:
  1083. extract:
  1084. description: |-
  1085. Used to extract multiple key/value pairs from one secret
  1086. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1087. properties:
  1088. conversionStrategy:
  1089. default: Default
  1090. description: Used to define a conversion Strategy
  1091. enum:
  1092. - Default
  1093. - Unicode
  1094. type: string
  1095. decodingStrategy:
  1096. default: None
  1097. description: Used to define a decoding Strategy
  1098. enum:
  1099. - Auto
  1100. - Base64
  1101. - Base64URL
  1102. - None
  1103. type: string
  1104. key:
  1105. description: Key is the key used in the Provider, mandatory
  1106. type: string
  1107. metadataPolicy:
  1108. default: None
  1109. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  1110. enum:
  1111. - None
  1112. - Fetch
  1113. type: string
  1114. property:
  1115. description: Used to select a specific property of the Provider value (if a map), if supported
  1116. type: string
  1117. version:
  1118. description: Used to select a specific version of the Provider value, if supported
  1119. type: string
  1120. required:
  1121. - key
  1122. type: object
  1123. find:
  1124. description: |-
  1125. Used to find secrets based on tags or regular expressions
  1126. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1127. properties:
  1128. conversionStrategy:
  1129. default: Default
  1130. description: Used to define a conversion Strategy
  1131. enum:
  1132. - Default
  1133. - Unicode
  1134. type: string
  1135. decodingStrategy:
  1136. default: None
  1137. description: Used to define a decoding Strategy
  1138. enum:
  1139. - Auto
  1140. - Base64
  1141. - Base64URL
  1142. - None
  1143. type: string
  1144. name:
  1145. description: Finds secrets based on the name.
  1146. properties:
  1147. regexp:
  1148. description: Finds secrets base
  1149. type: string
  1150. type: object
  1151. path:
  1152. description: A root path to start the find operations.
  1153. type: string
  1154. tags:
  1155. additionalProperties:
  1156. type: string
  1157. description: Find secrets based on tags.
  1158. type: object
  1159. type: object
  1160. rewrite:
  1161. description: |-
  1162. Used to rewrite secret Keys after getting them from the secret Provider
  1163. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  1164. items:
  1165. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  1166. maxProperties: 1
  1167. minProperties: 1
  1168. properties:
  1169. regexp:
  1170. description: |-
  1171. Used to rewrite with regular expressions.
  1172. The resulting key will be the output of a regexp.ReplaceAll operation.
  1173. properties:
  1174. source:
  1175. description: Used to define the regular expression of a re.Compiler.
  1176. type: string
  1177. target:
  1178. description: Used to define the target pattern of a ReplaceAll operation.
  1179. type: string
  1180. required:
  1181. - source
  1182. - target
  1183. type: object
  1184. transform:
  1185. description: |-
  1186. Used to apply string transformation on the secrets.
  1187. The resulting key will be the output of the template applied by the operation.
  1188. properties:
  1189. template:
  1190. description: |-
  1191. Used to define the template to apply on the secret name.
  1192. `.value ` will specify the secret name in the template.
  1193. type: string
  1194. required:
  1195. - template
  1196. type: object
  1197. type: object
  1198. type: array
  1199. sourceRef:
  1200. description: |-
  1201. SourceRef points to a store or generator
  1202. which contains secret values ready to use.
  1203. Use this in combination with Extract or Find pull values out of
  1204. a specific SecretStore.
  1205. When sourceRef points to a generator Extract or Find is not supported.
  1206. The generator returns a static map of values
  1207. maxProperties: 1
  1208. minProperties: 1
  1209. properties:
  1210. generatorRef:
  1211. description: GeneratorRef points to a generator custom resource.
  1212. properties:
  1213. apiVersion:
  1214. default: generators.external-secrets.io/v1alpha1
  1215. description: Specify the apiVersion of the generator resource
  1216. type: string
  1217. kind:
  1218. description: Specify the Kind of the generator resource
  1219. enum:
  1220. - ACRAccessToken
  1221. - ClusterGenerator
  1222. - ECRAuthorizationToken
  1223. - Fake
  1224. - GCRAccessToken
  1225. - GithubAccessToken
  1226. - QuayAccessToken
  1227. - Password
  1228. - SSHKey
  1229. - STSSessionToken
  1230. - UUID
  1231. - VaultDynamicSecret
  1232. - Webhook
  1233. - Grafana
  1234. type: string
  1235. name:
  1236. description: Specify the name of the generator resource
  1237. maxLength: 253
  1238. minLength: 1
  1239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1240. type: string
  1241. required:
  1242. - kind
  1243. - name
  1244. type: object
  1245. storeRef:
  1246. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1247. properties:
  1248. kind:
  1249. description: |-
  1250. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1251. Defaults to `SecretStore`
  1252. enum:
  1253. - SecretStore
  1254. - ClusterSecretStore
  1255. type: string
  1256. name:
  1257. description: Name of the SecretStore resource
  1258. maxLength: 253
  1259. minLength: 1
  1260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1261. type: string
  1262. type: object
  1263. type: object
  1264. type: object
  1265. type: array
  1266. refreshInterval:
  1267. default: 1h0m0s
  1268. description: |-
  1269. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  1270. specified as Golang Duration strings.
  1271. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  1272. Example values: "1h0m0s", "2h30m0s", "10m0s"
  1273. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  1274. type: string
  1275. refreshPolicy:
  1276. description: |-
  1277. RefreshPolicy determines how the ExternalSecret should be refreshed:
  1278. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  1279. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  1280. No periodic updates occur if refreshInterval is 0.
  1281. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  1282. enum:
  1283. - CreatedOnce
  1284. - Periodic
  1285. - OnChange
  1286. type: string
  1287. secretStoreRef:
  1288. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1289. properties:
  1290. kind:
  1291. description: |-
  1292. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1293. Defaults to `SecretStore`
  1294. enum:
  1295. - SecretStore
  1296. - ClusterSecretStore
  1297. type: string
  1298. name:
  1299. description: Name of the SecretStore resource
  1300. maxLength: 253
  1301. minLength: 1
  1302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1303. type: string
  1304. type: object
  1305. target:
  1306. default:
  1307. creationPolicy: Owner
  1308. deletionPolicy: Retain
  1309. description: |-
  1310. ExternalSecretTarget defines the Kubernetes Secret to be created
  1311. There can be only one target per ExternalSecret.
  1312. properties:
  1313. creationPolicy:
  1314. default: Owner
  1315. description: |-
  1316. CreationPolicy defines rules on how to create the resulting Secret.
  1317. Defaults to "Owner"
  1318. enum:
  1319. - Owner
  1320. - Orphan
  1321. - Merge
  1322. - None
  1323. type: string
  1324. deletionPolicy:
  1325. default: Retain
  1326. description: |-
  1327. DeletionPolicy defines rules on how to delete the resulting Secret.
  1328. Defaults to "Retain"
  1329. enum:
  1330. - Delete
  1331. - Merge
  1332. - Retain
  1333. type: string
  1334. immutable:
  1335. description: Immutable defines if the final secret will be immutable
  1336. type: boolean
  1337. name:
  1338. description: |-
  1339. The name of the Secret resource to be managed.
  1340. Defaults to the .metadata.name of the ExternalSecret resource
  1341. maxLength: 253
  1342. minLength: 1
  1343. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1344. type: string
  1345. template:
  1346. description: Template defines a blueprint for the created Secret resource.
  1347. properties:
  1348. data:
  1349. additionalProperties:
  1350. type: string
  1351. type: object
  1352. engineVersion:
  1353. default: v2
  1354. description: |-
  1355. EngineVersion specifies the template engine version
  1356. that should be used to compile/execute the
  1357. template specified in .data and .templateFrom[].
  1358. enum:
  1359. - v2
  1360. type: string
  1361. mergePolicy:
  1362. default: Replace
  1363. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  1364. enum:
  1365. - Replace
  1366. - Merge
  1367. type: string
  1368. metadata:
  1369. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  1370. properties:
  1371. annotations:
  1372. additionalProperties:
  1373. type: string
  1374. type: object
  1375. labels:
  1376. additionalProperties:
  1377. type: string
  1378. type: object
  1379. type: object
  1380. templateFrom:
  1381. items:
  1382. description: TemplateFrom defines a source for template data.
  1383. properties:
  1384. configMap:
  1385. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1386. properties:
  1387. items:
  1388. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1389. items:
  1390. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1391. properties:
  1392. key:
  1393. description: A key in the ConfigMap/Secret
  1394. maxLength: 253
  1395. minLength: 1
  1396. pattern: ^[-._a-zA-Z0-9]+$
  1397. type: string
  1398. templateAs:
  1399. default: Values
  1400. description: TemplateScope defines the scope of the template when processing template data.
  1401. enum:
  1402. - Values
  1403. - KeysAndValues
  1404. type: string
  1405. required:
  1406. - key
  1407. type: object
  1408. type: array
  1409. name:
  1410. description: The name of the ConfigMap/Secret resource
  1411. maxLength: 253
  1412. minLength: 1
  1413. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1414. type: string
  1415. required:
  1416. - items
  1417. - name
  1418. type: object
  1419. literal:
  1420. type: string
  1421. secret:
  1422. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1423. properties:
  1424. items:
  1425. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1426. items:
  1427. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1428. properties:
  1429. key:
  1430. description: A key in the ConfigMap/Secret
  1431. maxLength: 253
  1432. minLength: 1
  1433. pattern: ^[-._a-zA-Z0-9]+$
  1434. type: string
  1435. templateAs:
  1436. default: Values
  1437. description: TemplateScope defines the scope of the template when processing template data.
  1438. enum:
  1439. - Values
  1440. - KeysAndValues
  1441. type: string
  1442. required:
  1443. - key
  1444. type: object
  1445. type: array
  1446. name:
  1447. description: The name of the ConfigMap/Secret resource
  1448. maxLength: 253
  1449. minLength: 1
  1450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1451. type: string
  1452. required:
  1453. - items
  1454. - name
  1455. type: object
  1456. target:
  1457. default: Data
  1458. description: TemplateTarget defines the target field where the template result will be stored.
  1459. enum:
  1460. - Data
  1461. - Annotations
  1462. - Labels
  1463. type: string
  1464. type: object
  1465. type: array
  1466. type:
  1467. type: string
  1468. type: object
  1469. type: object
  1470. type: object
  1471. namespaceSelector:
  1472. description: The labels to select by to find the Namespaces to create the ExternalSecrets in
  1473. properties:
  1474. matchExpressions:
  1475. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1476. items:
  1477. description: |-
  1478. A label selector requirement is a selector that contains values, a key, and an operator that
  1479. relates the key and values.
  1480. properties:
  1481. key:
  1482. description: key is the label key that the selector applies to.
  1483. type: string
  1484. operator:
  1485. description: |-
  1486. operator represents a key's relationship to a set of values.
  1487. Valid operators are In, NotIn, Exists and DoesNotExist.
  1488. type: string
  1489. values:
  1490. description: |-
  1491. values is an array of string values. If the operator is In or NotIn,
  1492. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1493. the values array must be empty. This array is replaced during a strategic
  1494. merge patch.
  1495. items:
  1496. type: string
  1497. type: array
  1498. x-kubernetes-list-type: atomic
  1499. required:
  1500. - key
  1501. - operator
  1502. type: object
  1503. type: array
  1504. x-kubernetes-list-type: atomic
  1505. matchLabels:
  1506. additionalProperties:
  1507. type: string
  1508. description: |-
  1509. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1510. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1511. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1512. type: object
  1513. type: object
  1514. x-kubernetes-map-type: atomic
  1515. namespaceSelectors:
  1516. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1517. items:
  1518. description: |-
  1519. A label selector is a label query over a set of resources. The result of matchLabels and
  1520. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1521. label selector matches no objects.
  1522. properties:
  1523. matchExpressions:
  1524. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1525. items:
  1526. description: |-
  1527. A label selector requirement is a selector that contains values, a key, and an operator that
  1528. relates the key and values.
  1529. properties:
  1530. key:
  1531. description: key is the label key that the selector applies to.
  1532. type: string
  1533. operator:
  1534. description: |-
  1535. operator represents a key's relationship to a set of values.
  1536. Valid operators are In, NotIn, Exists and DoesNotExist.
  1537. type: string
  1538. values:
  1539. description: |-
  1540. values is an array of string values. If the operator is In or NotIn,
  1541. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1542. the values array must be empty. This array is replaced during a strategic
  1543. merge patch.
  1544. items:
  1545. type: string
  1546. type: array
  1547. x-kubernetes-list-type: atomic
  1548. required:
  1549. - key
  1550. - operator
  1551. type: object
  1552. type: array
  1553. x-kubernetes-list-type: atomic
  1554. matchLabels:
  1555. additionalProperties:
  1556. type: string
  1557. description: |-
  1558. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1559. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1560. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1561. type: object
  1562. type: object
  1563. x-kubernetes-map-type: atomic
  1564. type: array
  1565. namespaces:
  1566. description: |-
  1567. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  1568. Deprecated: Use NamespaceSelectors instead.
  1569. items:
  1570. maxLength: 63
  1571. minLength: 1
  1572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1573. type: string
  1574. type: array
  1575. refreshTime:
  1576. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  1577. type: string
  1578. required:
  1579. - externalSecretSpec
  1580. type: object
  1581. status:
  1582. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  1583. properties:
  1584. conditions:
  1585. items:
  1586. description: ClusterExternalSecretStatusCondition indicates the status of the ClusterExternalSecret.
  1587. properties:
  1588. message:
  1589. type: string
  1590. status:
  1591. type: string
  1592. type:
  1593. description: ClusterExternalSecretConditionType indicates the condition of the ClusterExternalSecret.
  1594. type: string
  1595. required:
  1596. - status
  1597. - type
  1598. type: object
  1599. type: array
  1600. externalSecretName:
  1601. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  1602. type: string
  1603. failedNamespaces:
  1604. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  1605. items:
  1606. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  1607. properties:
  1608. namespace:
  1609. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  1610. type: string
  1611. reason:
  1612. description: Reason is why the ExternalSecret failed to apply to the namespace
  1613. type: string
  1614. required:
  1615. - namespace
  1616. type: object
  1617. type: array
  1618. provisionedNamespaces:
  1619. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  1620. items:
  1621. type: string
  1622. type: array
  1623. type: object
  1624. type: object
  1625. served: false
  1626. storage: false
  1627. subresources:
  1628. status: {}
  1629. ---
  1630. apiVersion: apiextensions.k8s.io/v1
  1631. kind: CustomResourceDefinition
  1632. metadata:
  1633. annotations:
  1634. controller-gen.kubebuilder.io/version: v0.19.0
  1635. labels:
  1636. external-secrets.io/component: controller
  1637. name: clusterpushsecrets.external-secrets.io
  1638. spec:
  1639. group: external-secrets.io
  1640. names:
  1641. categories:
  1642. - external-secrets
  1643. kind: ClusterPushSecret
  1644. listKind: ClusterPushSecretList
  1645. plural: clusterpushsecrets
  1646. singular: clusterpushsecret
  1647. scope: Cluster
  1648. versions:
  1649. - additionalPrinterColumns:
  1650. - jsonPath: .metadata.creationTimestamp
  1651. name: AGE
  1652. type: date
  1653. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  1654. name: Status
  1655. type: string
  1656. name: v1alpha1
  1657. schema:
  1658. openAPIV3Schema:
  1659. description: ClusterPushSecret is the Schema for the ClusterPushSecrets API that enables cluster-wide management of pushing Kubernetes secrets to external providers.
  1660. properties:
  1661. apiVersion:
  1662. description: |-
  1663. APIVersion defines the versioned schema of this representation of an object.
  1664. Servers should convert recognized schemas to the latest internal value, and
  1665. may reject unrecognized values.
  1666. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  1667. type: string
  1668. kind:
  1669. description: |-
  1670. Kind is a string value representing the REST resource this object represents.
  1671. Servers may infer this from the endpoint the client submits requests to.
  1672. Cannot be updated.
  1673. In CamelCase.
  1674. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  1675. type: string
  1676. metadata:
  1677. type: object
  1678. spec:
  1679. description: ClusterPushSecretSpec defines the configuration for a ClusterPushSecret resource.
  1680. properties:
  1681. namespaceSelectors:
  1682. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1683. items:
  1684. description: |-
  1685. A label selector is a label query over a set of resources. The result of matchLabels and
  1686. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1687. label selector matches no objects.
  1688. properties:
  1689. matchExpressions:
  1690. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1691. items:
  1692. description: |-
  1693. A label selector requirement is a selector that contains values, a key, and an operator that
  1694. relates the key and values.
  1695. properties:
  1696. key:
  1697. description: key is the label key that the selector applies to.
  1698. type: string
  1699. operator:
  1700. description: |-
  1701. operator represents a key's relationship to a set of values.
  1702. Valid operators are In, NotIn, Exists and DoesNotExist.
  1703. type: string
  1704. values:
  1705. description: |-
  1706. values is an array of string values. If the operator is In or NotIn,
  1707. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1708. the values array must be empty. This array is replaced during a strategic
  1709. merge patch.
  1710. items:
  1711. type: string
  1712. type: array
  1713. x-kubernetes-list-type: atomic
  1714. required:
  1715. - key
  1716. - operator
  1717. type: object
  1718. type: array
  1719. x-kubernetes-list-type: atomic
  1720. matchLabels:
  1721. additionalProperties:
  1722. type: string
  1723. description: |-
  1724. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1725. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1726. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1727. type: object
  1728. type: object
  1729. x-kubernetes-map-type: atomic
  1730. type: array
  1731. pushSecretMetadata:
  1732. description: The metadata of the external secrets to be created
  1733. properties:
  1734. annotations:
  1735. additionalProperties:
  1736. type: string
  1737. type: object
  1738. labels:
  1739. additionalProperties:
  1740. type: string
  1741. type: object
  1742. type: object
  1743. pushSecretName:
  1744. description: |-
  1745. The name of the push secrets to be created.
  1746. Defaults to the name of the ClusterPushSecret
  1747. maxLength: 253
  1748. minLength: 1
  1749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1750. type: string
  1751. pushSecretSpec:
  1752. description: PushSecretSpec defines what to do with the secrets.
  1753. properties:
  1754. data:
  1755. description: Secret Data that should be pushed to providers
  1756. items:
  1757. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  1758. properties:
  1759. conversionStrategy:
  1760. default: None
  1761. description: Used to define a conversion Strategy for the secret keys
  1762. enum:
  1763. - None
  1764. - ReverseUnicode
  1765. type: string
  1766. match:
  1767. description: Match a given Secret Key to be pushed to the provider.
  1768. properties:
  1769. remoteRef:
  1770. description: Remote Refs to push to providers.
  1771. properties:
  1772. property:
  1773. description: Name of the property in the resulting secret
  1774. type: string
  1775. remoteKey:
  1776. description: Name of the resulting provider secret.
  1777. type: string
  1778. required:
  1779. - remoteKey
  1780. type: object
  1781. secretKey:
  1782. description: Secret Key to be pushed
  1783. type: string
  1784. required:
  1785. - remoteRef
  1786. type: object
  1787. metadata:
  1788. description: |-
  1789. Metadata is metadata attached to the secret.
  1790. The structure of metadata is provider specific, please look it up in the provider documentation.
  1791. x-kubernetes-preserve-unknown-fields: true
  1792. required:
  1793. - match
  1794. type: object
  1795. type: array
  1796. dataTo:
  1797. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  1798. items:
  1799. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  1800. properties:
  1801. conversionStrategy:
  1802. default: None
  1803. description: Used to define a conversion Strategy for the secret keys
  1804. enum:
  1805. - None
  1806. - ReverseUnicode
  1807. type: string
  1808. match:
  1809. description: |-
  1810. Match pattern for selecting keys from the source Secret.
  1811. If not specified, all keys are selected.
  1812. properties:
  1813. regexp:
  1814. description: |-
  1815. Regexp matches keys by regular expression.
  1816. If not specified, all keys are matched.
  1817. type: string
  1818. type: object
  1819. metadata:
  1820. description: |-
  1821. Metadata is metadata attached to the secret.
  1822. The structure of metadata is provider specific, please look it up in the provider documentation.
  1823. x-kubernetes-preserve-unknown-fields: true
  1824. remoteKey:
  1825. description: |-
  1826. RemoteKey is the name of the single provider secret that will receive ALL
  1827. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  1828. When set, per-key expansion is skipped and a single push is performed.
  1829. The provider's store prefix (if any) is still prepended to this value.
  1830. When not set, each matched key is pushed as its own individual provider secret.
  1831. type: string
  1832. rewrite:
  1833. description: |-
  1834. Rewrite operations to transform keys before pushing to the provider.
  1835. Operations are applied sequentially.
  1836. items:
  1837. description: PushSecretRewrite defines how to transform secret keys before pushing.
  1838. properties:
  1839. regexp:
  1840. description: Used to rewrite with regular expressions.
  1841. properties:
  1842. source:
  1843. description: Used to define the regular expression of a re.Compiler.
  1844. type: string
  1845. target:
  1846. description: Used to define the target pattern of a ReplaceAll operation.
  1847. type: string
  1848. required:
  1849. - source
  1850. - target
  1851. type: object
  1852. transform:
  1853. description: Used to apply string transformation on the secrets.
  1854. properties:
  1855. template:
  1856. description: |-
  1857. Used to define the template to apply on the secret name.
  1858. `.value ` will specify the secret name in the template.
  1859. type: string
  1860. required:
  1861. - template
  1862. type: object
  1863. type: object
  1864. x-kubernetes-validations:
  1865. - message: exactly one of regexp or transform must be set
  1866. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  1867. type: array
  1868. storeRef:
  1869. description: StoreRef specifies which SecretStore to push to. Required.
  1870. properties:
  1871. kind:
  1872. default: SecretStore
  1873. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1874. enum:
  1875. - SecretStore
  1876. - ClusterSecretStore
  1877. type: string
  1878. labelSelector:
  1879. description: Optionally, sync to secret stores with label selector
  1880. properties:
  1881. matchExpressions:
  1882. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1883. items:
  1884. description: |-
  1885. A label selector requirement is a selector that contains values, a key, and an operator that
  1886. relates the key and values.
  1887. properties:
  1888. key:
  1889. description: key is the label key that the selector applies to.
  1890. type: string
  1891. operator:
  1892. description: |-
  1893. operator represents a key's relationship to a set of values.
  1894. Valid operators are In, NotIn, Exists and DoesNotExist.
  1895. type: string
  1896. values:
  1897. description: |-
  1898. values is an array of string values. If the operator is In or NotIn,
  1899. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1900. the values array must be empty. This array is replaced during a strategic
  1901. merge patch.
  1902. items:
  1903. type: string
  1904. type: array
  1905. x-kubernetes-list-type: atomic
  1906. required:
  1907. - key
  1908. - operator
  1909. type: object
  1910. type: array
  1911. x-kubernetes-list-type: atomic
  1912. matchLabels:
  1913. additionalProperties:
  1914. type: string
  1915. description: |-
  1916. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1917. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1918. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1919. type: object
  1920. type: object
  1921. x-kubernetes-map-type: atomic
  1922. name:
  1923. description: Optionally, sync to the SecretStore of the given name
  1924. maxLength: 253
  1925. minLength: 1
  1926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1927. type: string
  1928. type: object
  1929. type: object
  1930. x-kubernetes-validations:
  1931. - message: storeRef must specify either name or labelSelector
  1932. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  1933. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  1934. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  1935. type: array
  1936. deletionPolicy:
  1937. default: None
  1938. description: Deletion Policy to handle Secrets in the provider.
  1939. enum:
  1940. - Delete
  1941. - None
  1942. type: string
  1943. refreshInterval:
  1944. default: 1h0m0s
  1945. description: The Interval to which External Secrets will try to push a secret definition
  1946. type: string
  1947. secretStoreRefs:
  1948. items:
  1949. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  1950. properties:
  1951. kind:
  1952. default: SecretStore
  1953. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1954. enum:
  1955. - SecretStore
  1956. - ClusterSecretStore
  1957. type: string
  1958. labelSelector:
  1959. description: Optionally, sync to secret stores with label selector
  1960. properties:
  1961. matchExpressions:
  1962. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1963. items:
  1964. description: |-
  1965. A label selector requirement is a selector that contains values, a key, and an operator that
  1966. relates the key and values.
  1967. properties:
  1968. key:
  1969. description: key is the label key that the selector applies to.
  1970. type: string
  1971. operator:
  1972. description: |-
  1973. operator represents a key's relationship to a set of values.
  1974. Valid operators are In, NotIn, Exists and DoesNotExist.
  1975. type: string
  1976. values:
  1977. description: |-
  1978. values is an array of string values. If the operator is In or NotIn,
  1979. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1980. the values array must be empty. This array is replaced during a strategic
  1981. merge patch.
  1982. items:
  1983. type: string
  1984. type: array
  1985. x-kubernetes-list-type: atomic
  1986. required:
  1987. - key
  1988. - operator
  1989. type: object
  1990. type: array
  1991. x-kubernetes-list-type: atomic
  1992. matchLabels:
  1993. additionalProperties:
  1994. type: string
  1995. description: |-
  1996. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1997. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1998. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1999. type: object
  2000. type: object
  2001. x-kubernetes-map-type: atomic
  2002. name:
  2003. description: Optionally, sync to the SecretStore of the given name
  2004. maxLength: 253
  2005. minLength: 1
  2006. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2007. type: string
  2008. type: object
  2009. type: array
  2010. selector:
  2011. description: The Secret Selector (k8s source) for the Push Secret
  2012. maxProperties: 1
  2013. minProperties: 1
  2014. properties:
  2015. generatorRef:
  2016. description: Point to a generator to create a Secret.
  2017. properties:
  2018. apiVersion:
  2019. default: generators.external-secrets.io/v1alpha1
  2020. description: Specify the apiVersion of the generator resource
  2021. type: string
  2022. kind:
  2023. description: Specify the Kind of the generator resource
  2024. enum:
  2025. - ACRAccessToken
  2026. - BeyondtrustWorkloadCredentialsDynamicSecret
  2027. - ClusterGenerator
  2028. - CloudsmithAccessToken
  2029. - ECRAuthorizationToken
  2030. - Fake
  2031. - GCRAccessToken
  2032. - GithubAccessToken
  2033. - GitlabDeployToken
  2034. - QuayAccessToken
  2035. - Password
  2036. - SSHKey
  2037. - STSSessionToken
  2038. - UUID
  2039. - VaultDynamicSecret
  2040. - Webhook
  2041. - Grafana
  2042. - MFA
  2043. type: string
  2044. name:
  2045. description: Specify the name of the generator resource
  2046. maxLength: 253
  2047. minLength: 1
  2048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2049. type: string
  2050. required:
  2051. - kind
  2052. - name
  2053. type: object
  2054. secret:
  2055. description: Select a Secret to Push.
  2056. properties:
  2057. name:
  2058. description: |-
  2059. Name of the Secret.
  2060. The Secret must exist in the same namespace as the PushSecret manifest.
  2061. maxLength: 253
  2062. minLength: 1
  2063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2064. type: string
  2065. selector:
  2066. description: |-
  2067. Selector chooses secrets using a labelSelector.
  2068. It must not be empty: an empty selector resolves to labels.Everything(),
  2069. which would push every Secret in the namespace to the provider.
  2070. properties:
  2071. matchExpressions:
  2072. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2073. items:
  2074. description: |-
  2075. A label selector requirement is a selector that contains values, a key, and an operator that
  2076. relates the key and values.
  2077. properties:
  2078. key:
  2079. description: key is the label key that the selector applies to.
  2080. type: string
  2081. operator:
  2082. description: |-
  2083. operator represents a key's relationship to a set of values.
  2084. Valid operators are In, NotIn, Exists and DoesNotExist.
  2085. type: string
  2086. values:
  2087. description: |-
  2088. values is an array of string values. If the operator is In or NotIn,
  2089. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2090. the values array must be empty. This array is replaced during a strategic
  2091. merge patch.
  2092. items:
  2093. type: string
  2094. type: array
  2095. x-kubernetes-list-type: atomic
  2096. required:
  2097. - key
  2098. - operator
  2099. type: object
  2100. type: array
  2101. x-kubernetes-list-type: atomic
  2102. matchLabels:
  2103. additionalProperties:
  2104. type: string
  2105. description: |-
  2106. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2107. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2108. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2109. type: object
  2110. type: object
  2111. x-kubernetes-map-type: atomic
  2112. x-kubernetes-validations:
  2113. - message: selector must set matchLabels or matchExpressions
  2114. rule: has(self.matchLabels) && size(self.matchLabels) > 0 || has(self.matchExpressions) && size(self.matchExpressions) > 0
  2115. type: object
  2116. x-kubernetes-validations:
  2117. - message: exactly one of name or selector must be set
  2118. rule: has(self.name) != has(self.selector)
  2119. type: object
  2120. template:
  2121. description: Template defines a blueprint for the created Secret resource.
  2122. properties:
  2123. data:
  2124. additionalProperties:
  2125. type: string
  2126. type: object
  2127. engineVersion:
  2128. default: v2
  2129. description: |-
  2130. EngineVersion specifies the template engine version
  2131. that should be used to compile/execute the
  2132. template specified in .data and .templateFrom[].
  2133. enum:
  2134. - v2
  2135. type: string
  2136. mergePolicy:
  2137. default: Replace
  2138. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  2139. enum:
  2140. - Replace
  2141. - Merge
  2142. type: string
  2143. metadata:
  2144. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  2145. properties:
  2146. annotations:
  2147. additionalProperties:
  2148. type: string
  2149. type: object
  2150. finalizers:
  2151. items:
  2152. type: string
  2153. type: array
  2154. labels:
  2155. additionalProperties:
  2156. type: string
  2157. type: object
  2158. type: object
  2159. templateFrom:
  2160. items:
  2161. description: |-
  2162. TemplateFrom specifies a source for templates.
  2163. Each item in the list can either reference a ConfigMap or a Secret resource.
  2164. properties:
  2165. configMap:
  2166. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2167. properties:
  2168. items:
  2169. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2170. items:
  2171. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2172. properties:
  2173. key:
  2174. description: A key in the ConfigMap/Secret
  2175. maxLength: 253
  2176. minLength: 1
  2177. pattern: ^[-._a-zA-Z0-9]+$
  2178. type: string
  2179. templateAs:
  2180. default: Values
  2181. description: TemplateScope specifies how the template keys should be interpreted.
  2182. enum:
  2183. - Values
  2184. - KeysAndValues
  2185. type: string
  2186. required:
  2187. - key
  2188. type: object
  2189. type: array
  2190. name:
  2191. description: The name of the ConfigMap/Secret resource
  2192. maxLength: 253
  2193. minLength: 1
  2194. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2195. type: string
  2196. required:
  2197. - items
  2198. - name
  2199. type: object
  2200. literal:
  2201. type: string
  2202. secret:
  2203. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2204. properties:
  2205. items:
  2206. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2207. items:
  2208. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2209. properties:
  2210. key:
  2211. description: A key in the ConfigMap/Secret
  2212. maxLength: 253
  2213. minLength: 1
  2214. pattern: ^[-._a-zA-Z0-9]+$
  2215. type: string
  2216. templateAs:
  2217. default: Values
  2218. description: TemplateScope specifies how the template keys should be interpreted.
  2219. enum:
  2220. - Values
  2221. - KeysAndValues
  2222. type: string
  2223. required:
  2224. - key
  2225. type: object
  2226. type: array
  2227. name:
  2228. description: The name of the ConfigMap/Secret resource
  2229. maxLength: 253
  2230. minLength: 1
  2231. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2232. type: string
  2233. required:
  2234. - items
  2235. - name
  2236. type: object
  2237. target:
  2238. default: Data
  2239. description: |-
  2240. Target specifies where to place the template result.
  2241. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  2242. any other value is rejected because it would allow writes to privileged Secret fields.
  2243. For custom resources (when spec.target.manifest is set), this supports
  2244. nested paths like "spec.database.config" or "data".
  2245. type: string
  2246. valuesDecodingStrategy:
  2247. description: |-
  2248. Used to define a decoding Strategy for the rendered template values.
  2249. Defaults to None when omitted.
  2250. enum:
  2251. - Auto
  2252. - Base64
  2253. - Base64URL
  2254. - None
  2255. type: string
  2256. type: object
  2257. type: array
  2258. type:
  2259. type: string
  2260. type: object
  2261. updatePolicy:
  2262. default: Replace
  2263. description: UpdatePolicy to handle Secrets in the provider.
  2264. enum:
  2265. - Replace
  2266. - IfNotExists
  2267. type: string
  2268. required:
  2269. - secretStoreRefs
  2270. - selector
  2271. type: object
  2272. refreshTime:
  2273. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  2274. type: string
  2275. required:
  2276. - pushSecretSpec
  2277. type: object
  2278. status:
  2279. description: ClusterPushSecretStatus contains the status information for the ClusterPushSecret resource.
  2280. properties:
  2281. conditions:
  2282. items:
  2283. description: PushSecretStatusCondition indicates the status of the PushSecret.
  2284. properties:
  2285. lastTransitionTime:
  2286. format: date-time
  2287. type: string
  2288. message:
  2289. type: string
  2290. reason:
  2291. type: string
  2292. status:
  2293. type: string
  2294. type:
  2295. description: PushSecretConditionType indicates the condition of the PushSecret.
  2296. type: string
  2297. required:
  2298. - status
  2299. - type
  2300. type: object
  2301. type: array
  2302. failedNamespaces:
  2303. description: Failed namespaces are the namespaces that failed to apply an PushSecret
  2304. items:
  2305. description: ClusterPushSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  2306. properties:
  2307. namespace:
  2308. description: Namespace is the namespace that failed when trying to apply an PushSecret
  2309. type: string
  2310. reason:
  2311. description: Reason is why the PushSecret failed to apply to the namespace
  2312. type: string
  2313. required:
  2314. - namespace
  2315. type: object
  2316. type: array
  2317. provisionedNamespaces:
  2318. description: ProvisionedNamespaces are the namespaces where the ClusterPushSecret has secrets
  2319. items:
  2320. type: string
  2321. type: array
  2322. pushSecretName:
  2323. type: string
  2324. type: object
  2325. type: object
  2326. served: true
  2327. storage: true
  2328. subresources:
  2329. status: {}
  2330. ---
  2331. apiVersion: apiextensions.k8s.io/v1
  2332. kind: CustomResourceDefinition
  2333. metadata:
  2334. annotations:
  2335. controller-gen.kubebuilder.io/version: v0.19.0
  2336. labels:
  2337. external-secrets.io/component: controller
  2338. name: clustersecretstores.external-secrets.io
  2339. spec:
  2340. group: external-secrets.io
  2341. names:
  2342. categories:
  2343. - external-secrets
  2344. kind: ClusterSecretStore
  2345. listKind: ClusterSecretStoreList
  2346. plural: clustersecretstores
  2347. shortNames:
  2348. - css
  2349. singular: clustersecretstore
  2350. scope: Cluster
  2351. versions:
  2352. - additionalPrinterColumns:
  2353. - jsonPath: .metadata.creationTimestamp
  2354. name: AGE
  2355. type: date
  2356. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  2357. name: Status
  2358. type: string
  2359. - jsonPath: .status.capabilities
  2360. name: Capabilities
  2361. type: string
  2362. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  2363. name: Ready
  2364. type: string
  2365. name: v1
  2366. schema:
  2367. openAPIV3Schema:
  2368. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  2369. properties:
  2370. apiVersion:
  2371. description: |-
  2372. APIVersion defines the versioned schema of this representation of an object.
  2373. Servers should convert recognized schemas to the latest internal value, and
  2374. may reject unrecognized values.
  2375. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  2376. type: string
  2377. kind:
  2378. description: |-
  2379. Kind is a string value representing the REST resource this object represents.
  2380. Servers may infer this from the endpoint the client submits requests to.
  2381. Cannot be updated.
  2382. In CamelCase.
  2383. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  2384. type: string
  2385. metadata:
  2386. type: object
  2387. spec:
  2388. description: SecretStoreSpec defines the desired state of SecretStore.
  2389. properties:
  2390. conditions:
  2391. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  2392. items:
  2393. description: |-
  2394. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  2395. for a ClusterSecretStore instance.
  2396. properties:
  2397. namespaceRegexes:
  2398. description: Choose namespaces by using regex matching
  2399. items:
  2400. type: string
  2401. type: array
  2402. namespaceSelector:
  2403. description: Choose namespace using a labelSelector
  2404. properties:
  2405. matchExpressions:
  2406. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2407. items:
  2408. description: |-
  2409. A label selector requirement is a selector that contains values, a key, and an operator that
  2410. relates the key and values.
  2411. properties:
  2412. key:
  2413. description: key is the label key that the selector applies to.
  2414. type: string
  2415. operator:
  2416. description: |-
  2417. operator represents a key's relationship to a set of values.
  2418. Valid operators are In, NotIn, Exists and DoesNotExist.
  2419. type: string
  2420. values:
  2421. description: |-
  2422. values is an array of string values. If the operator is In or NotIn,
  2423. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2424. the values array must be empty. This array is replaced during a strategic
  2425. merge patch.
  2426. items:
  2427. type: string
  2428. type: array
  2429. x-kubernetes-list-type: atomic
  2430. required:
  2431. - key
  2432. - operator
  2433. type: object
  2434. type: array
  2435. x-kubernetes-list-type: atomic
  2436. matchLabels:
  2437. additionalProperties:
  2438. type: string
  2439. description: |-
  2440. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2441. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2442. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2443. type: object
  2444. type: object
  2445. x-kubernetes-map-type: atomic
  2446. namespaces:
  2447. description: Choose namespaces by name
  2448. items:
  2449. maxLength: 63
  2450. minLength: 1
  2451. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2452. type: string
  2453. type: array
  2454. type: object
  2455. type: array
  2456. controller:
  2457. description: |-
  2458. Used to select the correct ESO controller (think: ingress.ingressClassName)
  2459. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  2460. type: string
  2461. provider:
  2462. description: Used to configure the provider. Only one provider may be set
  2463. maxProperties: 1
  2464. minProperties: 1
  2465. properties:
  2466. akeyless:
  2467. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  2468. properties:
  2469. akeylessGWApiURL:
  2470. description: Akeyless GW API Url from which the secrets to be fetched from.
  2471. type: string
  2472. authSecretRef:
  2473. description: Auth configures how the operator authenticates with Akeyless.
  2474. properties:
  2475. kubernetesAuth:
  2476. description: |-
  2477. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  2478. token stored in the named Secret resource.
  2479. properties:
  2480. accessID:
  2481. description: the Akeyless Kubernetes auth-method access-id
  2482. type: string
  2483. k8sConfName:
  2484. description: Kubernetes-auth configuration name in Akeyless-Gateway
  2485. type: string
  2486. secretRef:
  2487. description: |-
  2488. Optional secret field containing a Kubernetes ServiceAccount JWT used
  2489. for authenticating with Akeyless. If a name is specified without a key,
  2490. `token` is the default. If one is not specified, the one bound to
  2491. the controller will be used.
  2492. properties:
  2493. key:
  2494. description: |-
  2495. A key in the referenced Secret.
  2496. Some instances of this field may be defaulted, in others it may be required.
  2497. maxLength: 253
  2498. minLength: 1
  2499. pattern: ^[-._a-zA-Z0-9]+$
  2500. type: string
  2501. name:
  2502. description: The name of the Secret resource being referred to.
  2503. maxLength: 253
  2504. minLength: 1
  2505. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2506. type: string
  2507. namespace:
  2508. description: |-
  2509. The namespace of the Secret resource being referred to.
  2510. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2511. maxLength: 63
  2512. minLength: 1
  2513. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2514. type: string
  2515. type: object
  2516. serviceAccountRef:
  2517. description: |-
  2518. Optional service account field containing the name of a kubernetes ServiceAccount.
  2519. If the service account is specified, the service account secret token JWT will be used
  2520. for authenticating with Akeyless. If the service account selector is not supplied,
  2521. the secretRef will be used instead.
  2522. properties:
  2523. audiences:
  2524. description: |-
  2525. Audience specifies the `aud` claim for the service account token
  2526. Some providers automatically extend the audience field based on well-known annotations for workload
  2527. identity (e.g. IRSA or GCP Workload Identity)
  2528. items:
  2529. type: string
  2530. type: array
  2531. name:
  2532. description: The name of the ServiceAccount resource being referred to.
  2533. maxLength: 253
  2534. minLength: 1
  2535. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2536. type: string
  2537. namespace:
  2538. description: |-
  2539. Namespace of the resource being referred to.
  2540. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2541. maxLength: 63
  2542. minLength: 1
  2543. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2544. type: string
  2545. required:
  2546. - name
  2547. type: object
  2548. required:
  2549. - accessID
  2550. - k8sConfName
  2551. type: object
  2552. secretRef:
  2553. description: |-
  2554. Reference to a Secret that contains the details
  2555. to authenticate with Akeyless.
  2556. properties:
  2557. accessID:
  2558. description: The SecretAccessID is used for authentication
  2559. properties:
  2560. key:
  2561. description: |-
  2562. A key in the referenced Secret.
  2563. Some instances of this field may be defaulted, in others it may be required.
  2564. maxLength: 253
  2565. minLength: 1
  2566. pattern: ^[-._a-zA-Z0-9]+$
  2567. type: string
  2568. name:
  2569. description: The name of the Secret resource being referred to.
  2570. maxLength: 253
  2571. minLength: 1
  2572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2573. type: string
  2574. namespace:
  2575. description: |-
  2576. The namespace of the Secret resource being referred to.
  2577. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2578. maxLength: 63
  2579. minLength: 1
  2580. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2581. type: string
  2582. type: object
  2583. accessType:
  2584. description: |-
  2585. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2586. In some instances, `key` is a required field.
  2587. properties:
  2588. key:
  2589. description: |-
  2590. A key in the referenced Secret.
  2591. Some instances of this field may be defaulted, in others it may be required.
  2592. maxLength: 253
  2593. minLength: 1
  2594. pattern: ^[-._a-zA-Z0-9]+$
  2595. type: string
  2596. name:
  2597. description: The name of the Secret resource being referred to.
  2598. maxLength: 253
  2599. minLength: 1
  2600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2601. type: string
  2602. namespace:
  2603. description: |-
  2604. The namespace of the Secret resource being referred to.
  2605. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2606. maxLength: 63
  2607. minLength: 1
  2608. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2609. type: string
  2610. type: object
  2611. accessTypeParam:
  2612. description: |-
  2613. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2614. In some instances, `key` is a required field.
  2615. properties:
  2616. key:
  2617. description: |-
  2618. A key in the referenced Secret.
  2619. Some instances of this field may be defaulted, in others it may be required.
  2620. maxLength: 253
  2621. minLength: 1
  2622. pattern: ^[-._a-zA-Z0-9]+$
  2623. type: string
  2624. name:
  2625. description: The name of the Secret resource being referred to.
  2626. maxLength: 253
  2627. minLength: 1
  2628. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2629. type: string
  2630. namespace:
  2631. description: |-
  2632. The namespace of the Secret resource being referred to.
  2633. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2634. maxLength: 63
  2635. minLength: 1
  2636. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2637. type: string
  2638. type: object
  2639. type: object
  2640. serviceAccountRef:
  2641. description: |-
  2642. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  2643. authentication on AKS Workload Identity. The operator obtains a federated
  2644. identity token from this ServiceAccount via the TokenRequest API instead
  2645. of using the ESO controller pod identity. Ignored for other access types.
  2646. properties:
  2647. audiences:
  2648. description: |-
  2649. Audience specifies the `aud` claim for the service account token
  2650. Some providers automatically extend the audience field based on well-known annotations for workload
  2651. identity (e.g. IRSA or GCP Workload Identity)
  2652. items:
  2653. type: string
  2654. type: array
  2655. name:
  2656. description: The name of the ServiceAccount resource being referred to.
  2657. maxLength: 253
  2658. minLength: 1
  2659. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2660. type: string
  2661. namespace:
  2662. description: |-
  2663. Namespace of the resource being referred to.
  2664. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2665. maxLength: 63
  2666. minLength: 1
  2667. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2668. type: string
  2669. required:
  2670. - name
  2671. type: object
  2672. type: object
  2673. caBundle:
  2674. description: |-
  2675. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  2676. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  2677. are used to validate the TLS connection.
  2678. format: byte
  2679. type: string
  2680. caProvider:
  2681. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  2682. properties:
  2683. key:
  2684. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  2685. maxLength: 253
  2686. minLength: 1
  2687. pattern: ^[-._a-zA-Z0-9]+$
  2688. type: string
  2689. name:
  2690. description: The name of the object located at the provider type.
  2691. maxLength: 253
  2692. minLength: 1
  2693. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2694. type: string
  2695. namespace:
  2696. description: |-
  2697. The namespace the Provider type is in.
  2698. Can only be defined when used in a ClusterSecretStore.
  2699. maxLength: 63
  2700. minLength: 1
  2701. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2702. type: string
  2703. type:
  2704. description: The type of provider to use such as "Secret", or "ConfigMap".
  2705. enum:
  2706. - Secret
  2707. - ConfigMap
  2708. type: string
  2709. required:
  2710. - name
  2711. - type
  2712. type: object
  2713. ignoreCache:
  2714. description: |-
  2715. IgnoreCache bypasses the Gateway cache for secret reads when true.
  2716. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  2717. type: boolean
  2718. required:
  2719. - akeylessGWApiURL
  2720. - authSecretRef
  2721. type: object
  2722. aws:
  2723. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  2724. properties:
  2725. additionalRoles:
  2726. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  2727. items:
  2728. type: string
  2729. type: array
  2730. auth:
  2731. description: |-
  2732. Auth defines the information necessary to authenticate against AWS
  2733. if not set aws sdk will infer credentials from your environment
  2734. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  2735. properties:
  2736. jwt:
  2737. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  2738. properties:
  2739. serviceAccountRef:
  2740. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  2741. properties:
  2742. audiences:
  2743. description: |-
  2744. Audience specifies the `aud` claim for the service account token
  2745. Some providers automatically extend the audience field based on well-known annotations for workload
  2746. identity (e.g. IRSA or GCP Workload Identity)
  2747. items:
  2748. type: string
  2749. type: array
  2750. name:
  2751. description: The name of the ServiceAccount resource being referred to.
  2752. maxLength: 253
  2753. minLength: 1
  2754. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2755. type: string
  2756. namespace:
  2757. description: |-
  2758. Namespace of the resource being referred to.
  2759. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2760. maxLength: 63
  2761. minLength: 1
  2762. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2763. type: string
  2764. required:
  2765. - name
  2766. type: object
  2767. type: object
  2768. secretRef:
  2769. description: |-
  2770. AWSAuthSecretRef holds secret references for AWS credentials
  2771. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  2772. properties:
  2773. accessKeyIDSecretRef:
  2774. description: The AccessKeyID is used for authentication
  2775. properties:
  2776. key:
  2777. description: |-
  2778. A key in the referenced Secret.
  2779. Some instances of this field may be defaulted, in others it may be required.
  2780. maxLength: 253
  2781. minLength: 1
  2782. pattern: ^[-._a-zA-Z0-9]+$
  2783. type: string
  2784. name:
  2785. description: The name of the Secret resource being referred to.
  2786. maxLength: 253
  2787. minLength: 1
  2788. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2789. type: string
  2790. namespace:
  2791. description: |-
  2792. The namespace of the Secret resource being referred to.
  2793. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2794. maxLength: 63
  2795. minLength: 1
  2796. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2797. type: string
  2798. type: object
  2799. secretAccessKeySecretRef:
  2800. description: The SecretAccessKey is used for authentication
  2801. properties:
  2802. key:
  2803. description: |-
  2804. A key in the referenced Secret.
  2805. Some instances of this field may be defaulted, in others it may be required.
  2806. maxLength: 253
  2807. minLength: 1
  2808. pattern: ^[-._a-zA-Z0-9]+$
  2809. type: string
  2810. name:
  2811. description: The name of the Secret resource being referred to.
  2812. maxLength: 253
  2813. minLength: 1
  2814. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2815. type: string
  2816. namespace:
  2817. description: |-
  2818. The namespace of the Secret resource being referred to.
  2819. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2820. maxLength: 63
  2821. minLength: 1
  2822. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2823. type: string
  2824. type: object
  2825. sessionTokenSecretRef:
  2826. description: |-
  2827. The SessionToken used for authentication
  2828. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  2829. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  2830. properties:
  2831. key:
  2832. description: |-
  2833. A key in the referenced Secret.
  2834. Some instances of this field may be defaulted, in others it may be required.
  2835. maxLength: 253
  2836. minLength: 1
  2837. pattern: ^[-._a-zA-Z0-9]+$
  2838. type: string
  2839. name:
  2840. description: The name of the Secret resource being referred to.
  2841. maxLength: 253
  2842. minLength: 1
  2843. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2844. type: string
  2845. namespace:
  2846. description: |-
  2847. The namespace of the Secret resource being referred to.
  2848. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2849. maxLength: 63
  2850. minLength: 1
  2851. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2852. type: string
  2853. type: object
  2854. type: object
  2855. type: object
  2856. customSessionTags:
  2857. additionalProperties:
  2858. type: string
  2859. description: |-
  2860. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  2861. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  2862. type: object
  2863. x-kubernetes-validations:
  2864. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  2865. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  2866. externalID:
  2867. description: AWS External ID set on assumed IAM roles
  2868. type: string
  2869. prefix:
  2870. description: Prefix adds a prefix to all retrieved values.
  2871. type: string
  2872. region:
  2873. description: AWS Region to be used for the provider
  2874. type: string
  2875. role:
  2876. description: Role is a Role ARN which the provider will assume
  2877. type: string
  2878. secretsManager:
  2879. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  2880. properties:
  2881. forceDeleteWithoutRecovery:
  2882. description: |-
  2883. Specifies whether to delete the secret without any recovery window. You
  2884. can't use both this parameter and RecoveryWindowInDays in the same call.
  2885. If you don't use either, then by default Secrets Manager uses a 30 day
  2886. recovery window.
  2887. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  2888. type: boolean
  2889. recoveryWindowInDays:
  2890. description: |-
  2891. The number of days from 7 to 30 that Secrets Manager waits before
  2892. permanently deleting the secret. You can't use both this parameter and
  2893. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  2894. then by default Secrets Manager uses a 30-day recovery window.
  2895. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  2896. format: int64
  2897. type: integer
  2898. type: object
  2899. service:
  2900. description: Service defines which service should be used to fetch the secrets
  2901. enum:
  2902. - SecretsManager
  2903. - ParameterStore
  2904. - CertificateManager
  2905. type: string
  2906. sessionTags:
  2907. description: AWS STS assume role session tags
  2908. items:
  2909. description: |-
  2910. Tag is a key-value pair that can be attached to an AWS resource.
  2911. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  2912. properties:
  2913. key:
  2914. type: string
  2915. value:
  2916. type: string
  2917. required:
  2918. - key
  2919. - value
  2920. type: object
  2921. type: array
  2922. sessionTagsPolicy:
  2923. default: None
  2924. description: |-
  2925. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  2926. None (default): no tags are added.
  2927. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  2928. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  2929. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  2930. enum:
  2931. - None
  2932. - Simple
  2933. - Custom
  2934. type: string
  2935. transitiveTagKeys:
  2936. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  2937. items:
  2938. type: string
  2939. type: array
  2940. required:
  2941. - region
  2942. - service
  2943. type: object
  2944. azurekv:
  2945. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  2946. properties:
  2947. authSecretRef:
  2948. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  2949. properties:
  2950. clientCertificate:
  2951. description: The Azure ClientCertificate of the service principle used for authentication.
  2952. properties:
  2953. key:
  2954. description: |-
  2955. A key in the referenced Secret.
  2956. Some instances of this field may be defaulted, in others it may be required.
  2957. maxLength: 253
  2958. minLength: 1
  2959. pattern: ^[-._a-zA-Z0-9]+$
  2960. type: string
  2961. name:
  2962. description: The name of the Secret resource being referred to.
  2963. maxLength: 253
  2964. minLength: 1
  2965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2966. type: string
  2967. namespace:
  2968. description: |-
  2969. The namespace of the Secret resource being referred to.
  2970. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2971. maxLength: 63
  2972. minLength: 1
  2973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2974. type: string
  2975. type: object
  2976. clientId:
  2977. description: The Azure clientId of the service principle or managed identity used for authentication.
  2978. properties:
  2979. key:
  2980. description: |-
  2981. A key in the referenced Secret.
  2982. Some instances of this field may be defaulted, in others it may be required.
  2983. maxLength: 253
  2984. minLength: 1
  2985. pattern: ^[-._a-zA-Z0-9]+$
  2986. type: string
  2987. name:
  2988. description: The name of the Secret resource being referred to.
  2989. maxLength: 253
  2990. minLength: 1
  2991. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2992. type: string
  2993. namespace:
  2994. description: |-
  2995. The namespace of the Secret resource being referred to.
  2996. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2997. maxLength: 63
  2998. minLength: 1
  2999. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3000. type: string
  3001. type: object
  3002. clientSecret:
  3003. description: The Azure ClientSecret of the service principle used for authentication.
  3004. properties:
  3005. key:
  3006. description: |-
  3007. A key in the referenced Secret.
  3008. Some instances of this field may be defaulted, in others it may be required.
  3009. maxLength: 253
  3010. minLength: 1
  3011. pattern: ^[-._a-zA-Z0-9]+$
  3012. type: string
  3013. name:
  3014. description: The name of the Secret resource being referred to.
  3015. maxLength: 253
  3016. minLength: 1
  3017. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3018. type: string
  3019. namespace:
  3020. description: |-
  3021. The namespace of the Secret resource being referred to.
  3022. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3023. maxLength: 63
  3024. minLength: 1
  3025. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3026. type: string
  3027. type: object
  3028. tenantId:
  3029. description: The Azure tenantId of the managed identity used for authentication.
  3030. properties:
  3031. key:
  3032. description: |-
  3033. A key in the referenced Secret.
  3034. Some instances of this field may be defaulted, in others it may be required.
  3035. maxLength: 253
  3036. minLength: 1
  3037. pattern: ^[-._a-zA-Z0-9]+$
  3038. type: string
  3039. name:
  3040. description: The name of the Secret resource being referred to.
  3041. maxLength: 253
  3042. minLength: 1
  3043. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3044. type: string
  3045. namespace:
  3046. description: |-
  3047. The namespace of the Secret resource being referred to.
  3048. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3049. maxLength: 63
  3050. minLength: 1
  3051. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3052. type: string
  3053. type: object
  3054. type: object
  3055. authType:
  3056. default: ServicePrincipal
  3057. description: |-
  3058. Auth type defines how to authenticate to the keyvault service.
  3059. Valid values are:
  3060. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  3061. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  3062. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  3063. enum:
  3064. - ServicePrincipal
  3065. - ManagedIdentity
  3066. - WorkloadIdentity
  3067. type: string
  3068. customCloudConfig:
  3069. description: |-
  3070. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  3071. Required when EnvironmentType is AzureStackCloud.
  3072. Optional for other environment types - useful for Azure China when using Workload Identity
  3073. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  3074. standard China Cloud endpoint (login.chinacloudapi.cn).
  3075. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  3076. configuration is not supported with the legacy go-autorest SDK.
  3077. properties:
  3078. activeDirectoryEndpoint:
  3079. description: |-
  3080. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  3081. Required when using custom cloud configuration
  3082. type: string
  3083. keyVaultDNSSuffix:
  3084. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  3085. type: string
  3086. keyVaultEndpoint:
  3087. description: KeyVaultEndpoint is the Key Vault service endpoint
  3088. type: string
  3089. resourceManagerEndpoint:
  3090. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  3091. type: string
  3092. required:
  3093. - activeDirectoryEndpoint
  3094. type: object
  3095. environmentType:
  3096. default: PublicCloud
  3097. description: |-
  3098. EnvironmentType specifies the Azure cloud environment endpoints to use for
  3099. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  3100. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  3101. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  3102. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  3103. enum:
  3104. - PublicCloud
  3105. - USGovernmentCloud
  3106. - ChinaCloud
  3107. - GermanCloud
  3108. - AzureStackCloud
  3109. type: string
  3110. identityId:
  3111. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  3112. type: string
  3113. serviceAccountRef:
  3114. description: |-
  3115. ServiceAccountRef specified the service account
  3116. that should be used when authenticating with WorkloadIdentity.
  3117. properties:
  3118. audiences:
  3119. description: |-
  3120. Audience specifies the `aud` claim for the service account token
  3121. Some providers automatically extend the audience field based on well-known annotations for workload
  3122. identity (e.g. IRSA or GCP Workload Identity)
  3123. items:
  3124. type: string
  3125. type: array
  3126. name:
  3127. description: The name of the ServiceAccount resource being referred to.
  3128. maxLength: 253
  3129. minLength: 1
  3130. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3131. type: string
  3132. namespace:
  3133. description: |-
  3134. Namespace of the resource being referred to.
  3135. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3136. maxLength: 63
  3137. minLength: 1
  3138. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3139. type: string
  3140. required:
  3141. - name
  3142. type: object
  3143. tenantId:
  3144. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  3145. type: string
  3146. useAzureSDK:
  3147. default: false
  3148. description: |-
  3149. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  3150. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  3151. type: boolean
  3152. vaultUrl:
  3153. description: Vault Url from which the secrets to be fetched from.
  3154. type: string
  3155. required:
  3156. - vaultUrl
  3157. type: object
  3158. barbican:
  3159. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  3160. properties:
  3161. auth:
  3162. description: BarbicanAuth contains the authentication information for Barbican.
  3163. properties:
  3164. applicationCredentialID:
  3165. description: ID of the application credential used for authentication.
  3166. maxProperties: 1
  3167. minProperties: 1
  3168. properties:
  3169. secretRef:
  3170. description: |-
  3171. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3172. In some instances, `key` is a required field.
  3173. properties:
  3174. key:
  3175. description: |-
  3176. A key in the referenced Secret.
  3177. Some instances of this field may be defaulted, in others it may be required.
  3178. maxLength: 253
  3179. minLength: 1
  3180. pattern: ^[-._a-zA-Z0-9]+$
  3181. type: string
  3182. name:
  3183. description: The name of the Secret resource being referred to.
  3184. maxLength: 253
  3185. minLength: 1
  3186. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3187. type: string
  3188. namespace:
  3189. description: |-
  3190. The namespace of the Secret resource being referred to.
  3191. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3192. maxLength: 63
  3193. minLength: 1
  3194. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3195. type: string
  3196. type: object
  3197. value:
  3198. minLength: 1
  3199. type: string
  3200. type: object
  3201. applicationCredentialSecret:
  3202. description: BarbicanProviderAppCredSecretRef defines a reference to an Application Credential Secret.
  3203. properties:
  3204. secretRef:
  3205. description: |-
  3206. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3207. In some instances, `key` is a required field.
  3208. properties:
  3209. key:
  3210. description: |-
  3211. A key in the referenced Secret.
  3212. Some instances of this field may be defaulted, in others it may be required.
  3213. maxLength: 253
  3214. minLength: 1
  3215. pattern: ^[-._a-zA-Z0-9]+$
  3216. type: string
  3217. name:
  3218. description: The name of the Secret resource being referred to.
  3219. maxLength: 253
  3220. minLength: 1
  3221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3222. type: string
  3223. namespace:
  3224. description: |-
  3225. The namespace of the Secret resource being referred to.
  3226. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3227. maxLength: 63
  3228. minLength: 1
  3229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3230. type: string
  3231. type: object
  3232. required:
  3233. - secretRef
  3234. type: object
  3235. authType:
  3236. default: password
  3237. description: |-
  3238. AuthType selects how Barbican authenticates.
  3239. - "password": use username and password.
  3240. - "applicationCredential": use application credential ID and secret.
  3241. Defaults to "password".
  3242. enum:
  3243. - password
  3244. - applicationCredential
  3245. type: string
  3246. password:
  3247. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  3248. properties:
  3249. secretRef:
  3250. description: |-
  3251. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3252. In some instances, `key` is a required field.
  3253. properties:
  3254. key:
  3255. description: |-
  3256. A key in the referenced Secret.
  3257. Some instances of this field may be defaulted, in others it may be required.
  3258. maxLength: 253
  3259. minLength: 1
  3260. pattern: ^[-._a-zA-Z0-9]+$
  3261. type: string
  3262. name:
  3263. description: The name of the Secret resource being referred to.
  3264. maxLength: 253
  3265. minLength: 1
  3266. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3267. type: string
  3268. namespace:
  3269. description: |-
  3270. The namespace of the Secret resource being referred to.
  3271. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3272. maxLength: 63
  3273. minLength: 1
  3274. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3275. type: string
  3276. type: object
  3277. required:
  3278. - secretRef
  3279. type: object
  3280. username:
  3281. description: Username / Password authentication fields.
  3282. maxProperties: 1
  3283. minProperties: 1
  3284. properties:
  3285. secretRef:
  3286. description: |-
  3287. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3288. In some instances, `key` is a required field.
  3289. properties:
  3290. key:
  3291. description: |-
  3292. A key in the referenced Secret.
  3293. Some instances of this field may be defaulted, in others it may be required.
  3294. maxLength: 253
  3295. minLength: 1
  3296. pattern: ^[-._a-zA-Z0-9]+$
  3297. type: string
  3298. name:
  3299. description: The name of the Secret resource being referred to.
  3300. maxLength: 253
  3301. minLength: 1
  3302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3303. type: string
  3304. namespace:
  3305. description: |-
  3306. The namespace of the Secret resource being referred to.
  3307. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3308. maxLength: 63
  3309. minLength: 1
  3310. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3311. type: string
  3312. type: object
  3313. value:
  3314. minLength: 1
  3315. type: string
  3316. type: object
  3317. type: object
  3318. x-kubernetes-validations:
  3319. - message: password auth requires both username and password
  3320. rule: (has(self.authType) && self.authType == 'applicationCredential') || (has(self.username) && has(self.password))
  3321. - message: applicationCredential auth requires both applicationCredentialID and applicationCredentialSecret
  3322. rule: self.authType != 'applicationCredential' || (has(self.applicationCredentialID) && has(self.applicationCredentialSecret))
  3323. - message: password auth should not include applicationCredential fields
  3324. rule: (has(self.authType) && self.authType == 'applicationCredential') || (!has(self.applicationCredentialID) && !has(self.applicationCredentialSecret))
  3325. - message: applicationCredential auth should not include password fields
  3326. rule: self.authType != 'applicationCredential' || (!has(self.username) && !has(self.password))
  3327. authURL:
  3328. type: string
  3329. domainName:
  3330. type: string
  3331. region:
  3332. type: string
  3333. tenantName:
  3334. type: string
  3335. required:
  3336. - auth
  3337. type: object
  3338. beyondtrust:
  3339. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  3340. properties:
  3341. auth:
  3342. description: Auth configures how the operator authenticates with Beyondtrust.
  3343. properties:
  3344. apiKey:
  3345. description: APIKey If not provided then ClientID/ClientSecret become required.
  3346. properties:
  3347. secretRef:
  3348. description: SecretRef references a key in a secret that will be used as value.
  3349. properties:
  3350. key:
  3351. description: |-
  3352. A key in the referenced Secret.
  3353. Some instances of this field may be defaulted, in others it may be required.
  3354. maxLength: 253
  3355. minLength: 1
  3356. pattern: ^[-._a-zA-Z0-9]+$
  3357. type: string
  3358. name:
  3359. description: The name of the Secret resource being referred to.
  3360. maxLength: 253
  3361. minLength: 1
  3362. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3363. type: string
  3364. namespace:
  3365. description: |-
  3366. The namespace of the Secret resource being referred to.
  3367. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3368. maxLength: 63
  3369. minLength: 1
  3370. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3371. type: string
  3372. type: object
  3373. value:
  3374. description: Value can be specified directly to set a value without using a secret.
  3375. type: string
  3376. type: object
  3377. certificate:
  3378. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  3379. properties:
  3380. secretRef:
  3381. description: SecretRef references a key in a secret that will be used as value.
  3382. properties:
  3383. key:
  3384. description: |-
  3385. A key in the referenced Secret.
  3386. Some instances of this field may be defaulted, in others it may be required.
  3387. maxLength: 253
  3388. minLength: 1
  3389. pattern: ^[-._a-zA-Z0-9]+$
  3390. type: string
  3391. name:
  3392. description: The name of the Secret resource being referred to.
  3393. maxLength: 253
  3394. minLength: 1
  3395. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3396. type: string
  3397. namespace:
  3398. description: |-
  3399. The namespace of the Secret resource being referred to.
  3400. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3401. maxLength: 63
  3402. minLength: 1
  3403. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3404. type: string
  3405. type: object
  3406. value:
  3407. description: Value can be specified directly to set a value without using a secret.
  3408. type: string
  3409. type: object
  3410. certificateKey:
  3411. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  3412. properties:
  3413. secretRef:
  3414. description: SecretRef references a key in a secret that will be used as value.
  3415. properties:
  3416. key:
  3417. description: |-
  3418. A key in the referenced Secret.
  3419. Some instances of this field may be defaulted, in others it may be required.
  3420. maxLength: 253
  3421. minLength: 1
  3422. pattern: ^[-._a-zA-Z0-9]+$
  3423. type: string
  3424. name:
  3425. description: The name of the Secret resource being referred to.
  3426. maxLength: 253
  3427. minLength: 1
  3428. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3429. type: string
  3430. namespace:
  3431. description: |-
  3432. The namespace of the Secret resource being referred to.
  3433. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3434. maxLength: 63
  3435. minLength: 1
  3436. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3437. type: string
  3438. type: object
  3439. value:
  3440. description: Value can be specified directly to set a value without using a secret.
  3441. type: string
  3442. type: object
  3443. clientId:
  3444. description: ClientID is the API OAuth Client ID.
  3445. properties:
  3446. secretRef:
  3447. description: SecretRef references a key in a secret that will be used as value.
  3448. properties:
  3449. key:
  3450. description: |-
  3451. A key in the referenced Secret.
  3452. Some instances of this field may be defaulted, in others it may be required.
  3453. maxLength: 253
  3454. minLength: 1
  3455. pattern: ^[-._a-zA-Z0-9]+$
  3456. type: string
  3457. name:
  3458. description: The name of the Secret resource being referred to.
  3459. maxLength: 253
  3460. minLength: 1
  3461. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3462. type: string
  3463. namespace:
  3464. description: |-
  3465. The namespace of the Secret resource being referred to.
  3466. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3467. maxLength: 63
  3468. minLength: 1
  3469. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3470. type: string
  3471. type: object
  3472. value:
  3473. description: Value can be specified directly to set a value without using a secret.
  3474. type: string
  3475. type: object
  3476. clientSecret:
  3477. description: ClientSecret is the API OAuth Client Secret.
  3478. properties:
  3479. secretRef:
  3480. description: SecretRef references a key in a secret that will be used as value.
  3481. properties:
  3482. key:
  3483. description: |-
  3484. A key in the referenced Secret.
  3485. Some instances of this field may be defaulted, in others it may be required.
  3486. maxLength: 253
  3487. minLength: 1
  3488. pattern: ^[-._a-zA-Z0-9]+$
  3489. type: string
  3490. name:
  3491. description: The name of the Secret resource being referred to.
  3492. maxLength: 253
  3493. minLength: 1
  3494. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3495. type: string
  3496. namespace:
  3497. description: |-
  3498. The namespace of the Secret resource being referred to.
  3499. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3500. maxLength: 63
  3501. minLength: 1
  3502. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3503. type: string
  3504. type: object
  3505. value:
  3506. description: Value can be specified directly to set a value without using a secret.
  3507. type: string
  3508. type: object
  3509. type: object
  3510. server:
  3511. description: Auth configures how API server works.
  3512. properties:
  3513. apiUrl:
  3514. type: string
  3515. apiVersion:
  3516. type: string
  3517. clientTimeOutSeconds:
  3518. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  3519. type: integer
  3520. decrypt:
  3521. default: true
  3522. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  3523. type: boolean
  3524. retrievalType:
  3525. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  3526. type: string
  3527. separator:
  3528. description: A character that separates the folder names.
  3529. type: string
  3530. verifyCA:
  3531. type: boolean
  3532. required:
  3533. - apiUrl
  3534. - verifyCA
  3535. type: object
  3536. required:
  3537. - auth
  3538. - server
  3539. type: object
  3540. beyondtrustworkloadcredentials:
  3541. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  3542. properties:
  3543. auth:
  3544. description: |-
  3545. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  3546. Currently supports API key authentication via Kubernetes secret reference.
  3547. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3548. properties:
  3549. apikey:
  3550. description: |-
  3551. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  3552. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  3553. properties:
  3554. token:
  3555. description: |-
  3556. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  3557. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  3558. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  3559. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3560. properties:
  3561. key:
  3562. description: |-
  3563. A key in the referenced Secret.
  3564. Some instances of this field may be defaulted, in others it may be required.
  3565. maxLength: 253
  3566. minLength: 1
  3567. pattern: ^[-._a-zA-Z0-9]+$
  3568. type: string
  3569. name:
  3570. description: The name of the Secret resource being referred to.
  3571. maxLength: 253
  3572. minLength: 1
  3573. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3574. type: string
  3575. namespace:
  3576. description: |-
  3577. The namespace of the Secret resource being referred to.
  3578. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3579. maxLength: 63
  3580. minLength: 1
  3581. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3582. type: string
  3583. type: object
  3584. required:
  3585. - token
  3586. type: object
  3587. required:
  3588. - apikey
  3589. type: object
  3590. caBundle:
  3591. description: |-
  3592. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3593. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  3594. If not set, the system's trusted root certificates are used.
  3595. format: byte
  3596. type: string
  3597. caProvider:
  3598. description: |-
  3599. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  3600. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3601. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  3602. properties:
  3603. key:
  3604. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3605. maxLength: 253
  3606. minLength: 1
  3607. pattern: ^[-._a-zA-Z0-9]+$
  3608. type: string
  3609. name:
  3610. description: The name of the object located at the provider type.
  3611. maxLength: 253
  3612. minLength: 1
  3613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3614. type: string
  3615. namespace:
  3616. description: |-
  3617. The namespace the Provider type is in.
  3618. Can only be defined when used in a ClusterSecretStore.
  3619. maxLength: 63
  3620. minLength: 1
  3621. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3622. type: string
  3623. type:
  3624. description: The type of provider to use such as "Secret", or "ConfigMap".
  3625. enum:
  3626. - Secret
  3627. - ConfigMap
  3628. type: string
  3629. required:
  3630. - name
  3631. - type
  3632. type: object
  3633. folderPath:
  3634. description: |-
  3635. FolderPath specifies the default folder path for secret retrieval.
  3636. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  3637. Example: "production/database" or "dev/api-keys"
  3638. Leave empty to retrieve secrets from the root folder.
  3639. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  3640. type: string
  3641. server:
  3642. description: |-
  3643. Server configures the BeyondTrust Workload Credentials server connection details.
  3644. Includes the API URL and Site ID for your BeyondTrust instance.
  3645. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3646. properties:
  3647. apiUrl:
  3648. description: |-
  3649. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  3650. This should be the full URL to your BeyondTrust instance.
  3651. Example: https://api.beyondtrust.io/siie
  3652. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  3653. type: string
  3654. siteId:
  3655. description: |-
  3656. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  3657. This identifier is unique to your BeyondTrust Workload Credentials instance.
  3658. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  3659. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  3660. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3661. type: string
  3662. required:
  3663. - apiUrl
  3664. - siteId
  3665. type: object
  3666. required:
  3667. - auth
  3668. - server
  3669. type: object
  3670. bitwardensecretsmanager:
  3671. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  3672. properties:
  3673. apiURL:
  3674. type: string
  3675. auth:
  3676. description: |-
  3677. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  3678. Make sure that the token being used has permissions on the given secret.
  3679. properties:
  3680. secretRef:
  3681. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  3682. properties:
  3683. credentials:
  3684. description: AccessToken used for the bitwarden instance.
  3685. properties:
  3686. key:
  3687. description: |-
  3688. A key in the referenced Secret.
  3689. Some instances of this field may be defaulted, in others it may be required.
  3690. maxLength: 253
  3691. minLength: 1
  3692. pattern: ^[-._a-zA-Z0-9]+$
  3693. type: string
  3694. name:
  3695. description: The name of the Secret resource being referred to.
  3696. maxLength: 253
  3697. minLength: 1
  3698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3699. type: string
  3700. namespace:
  3701. description: |-
  3702. The namespace of the Secret resource being referred to.
  3703. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3704. maxLength: 63
  3705. minLength: 1
  3706. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3707. type: string
  3708. type: object
  3709. required:
  3710. - credentials
  3711. type: object
  3712. required:
  3713. - secretRef
  3714. type: object
  3715. bitwardenServerSDKURL:
  3716. type: string
  3717. caBundle:
  3718. description: |-
  3719. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  3720. can be performed.
  3721. type: string
  3722. caProvider:
  3723. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  3724. properties:
  3725. key:
  3726. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3727. maxLength: 253
  3728. minLength: 1
  3729. pattern: ^[-._a-zA-Z0-9]+$
  3730. type: string
  3731. name:
  3732. description: The name of the object located at the provider type.
  3733. maxLength: 253
  3734. minLength: 1
  3735. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3736. type: string
  3737. namespace:
  3738. description: |-
  3739. The namespace the Provider type is in.
  3740. Can only be defined when used in a ClusterSecretStore.
  3741. maxLength: 63
  3742. minLength: 1
  3743. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3744. type: string
  3745. type:
  3746. description: The type of provider to use such as "Secret", or "ConfigMap".
  3747. enum:
  3748. - Secret
  3749. - ConfigMap
  3750. type: string
  3751. required:
  3752. - name
  3753. - type
  3754. type: object
  3755. identityURL:
  3756. type: string
  3757. organizationID:
  3758. description: OrganizationID determines which organization this secret store manages.
  3759. type: string
  3760. projectID:
  3761. description: ProjectID determines which project this secret store manages.
  3762. type: string
  3763. required:
  3764. - auth
  3765. - organizationID
  3766. - projectID
  3767. type: object
  3768. chef:
  3769. description: Chef configures this store to sync secrets with chef server
  3770. properties:
  3771. auth:
  3772. description: Auth defines the information necessary to authenticate against chef Server
  3773. properties:
  3774. secretRef:
  3775. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  3776. properties:
  3777. privateKeySecretRef:
  3778. description: SecretKey is the Signing Key in PEM format, used for authentication.
  3779. properties:
  3780. key:
  3781. description: |-
  3782. A key in the referenced Secret.
  3783. Some instances of this field may be defaulted, in others it may be required.
  3784. maxLength: 253
  3785. minLength: 1
  3786. pattern: ^[-._a-zA-Z0-9]+$
  3787. type: string
  3788. name:
  3789. description: The name of the Secret resource being referred to.
  3790. maxLength: 253
  3791. minLength: 1
  3792. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3793. type: string
  3794. namespace:
  3795. description: |-
  3796. The namespace of the Secret resource being referred to.
  3797. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3798. maxLength: 63
  3799. minLength: 1
  3800. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3801. type: string
  3802. type: object
  3803. required:
  3804. - privateKeySecretRef
  3805. type: object
  3806. required:
  3807. - secretRef
  3808. type: object
  3809. serverUrl:
  3810. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  3811. type: string
  3812. username:
  3813. description: UserName should be the user ID on the chef server
  3814. type: string
  3815. required:
  3816. - auth
  3817. - serverUrl
  3818. - username
  3819. type: object
  3820. cloudrusm:
  3821. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  3822. properties:
  3823. auth:
  3824. description: CSMAuth contains a secretRef for credentials.
  3825. properties:
  3826. secretRef:
  3827. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  3828. properties:
  3829. accessKeyIDSecretRef:
  3830. description: The AccessKeyID is used for authentication
  3831. properties:
  3832. key:
  3833. description: |-
  3834. A key in the referenced Secret.
  3835. Some instances of this field may be defaulted, in others it may be required.
  3836. maxLength: 253
  3837. minLength: 1
  3838. pattern: ^[-._a-zA-Z0-9]+$
  3839. type: string
  3840. name:
  3841. description: The name of the Secret resource being referred to.
  3842. maxLength: 253
  3843. minLength: 1
  3844. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3845. type: string
  3846. namespace:
  3847. description: |-
  3848. The namespace of the Secret resource being referred to.
  3849. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3850. maxLength: 63
  3851. minLength: 1
  3852. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3853. type: string
  3854. type: object
  3855. accessKeySecretSecretRef:
  3856. description: The AccessKeySecret is used for authentication
  3857. properties:
  3858. key:
  3859. description: |-
  3860. A key in the referenced Secret.
  3861. Some instances of this field may be defaulted, in others it may be required.
  3862. maxLength: 253
  3863. minLength: 1
  3864. pattern: ^[-._a-zA-Z0-9]+$
  3865. type: string
  3866. name:
  3867. description: The name of the Secret resource being referred to.
  3868. maxLength: 253
  3869. minLength: 1
  3870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3871. type: string
  3872. namespace:
  3873. description: |-
  3874. The namespace of the Secret resource being referred to.
  3875. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3876. maxLength: 63
  3877. minLength: 1
  3878. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3879. type: string
  3880. type: object
  3881. required:
  3882. - accessKeyIDSecretRef
  3883. - accessKeySecretSecretRef
  3884. type: object
  3885. type: object
  3886. projectID:
  3887. description: ProjectID is the project, which the secrets are stored in.
  3888. type: string
  3889. required:
  3890. - auth
  3891. type: object
  3892. conjur:
  3893. description: Conjur configures this store to sync secrets using conjur provider
  3894. properties:
  3895. auth:
  3896. description: Defines authentication settings for connecting to Conjur.
  3897. maxProperties: 1
  3898. minProperties: 1
  3899. properties:
  3900. apikey:
  3901. description: Authenticates with Conjur using an API key.
  3902. properties:
  3903. account:
  3904. description: Account is the Conjur organization account name.
  3905. type: string
  3906. apiKeyRef:
  3907. description: |-
  3908. A reference to a specific 'key' containing the Conjur API key
  3909. within a Secret resource. In some instances, `key` is a required field.
  3910. properties:
  3911. key:
  3912. description: |-
  3913. A key in the referenced Secret.
  3914. Some instances of this field may be defaulted, in others it may be required.
  3915. maxLength: 253
  3916. minLength: 1
  3917. pattern: ^[-._a-zA-Z0-9]+$
  3918. type: string
  3919. name:
  3920. description: The name of the Secret resource being referred to.
  3921. maxLength: 253
  3922. minLength: 1
  3923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3924. type: string
  3925. namespace:
  3926. description: |-
  3927. The namespace of the Secret resource being referred to.
  3928. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3929. maxLength: 63
  3930. minLength: 1
  3931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3932. type: string
  3933. type: object
  3934. userRef:
  3935. description: |-
  3936. A reference to a specific 'key' containing the Conjur username
  3937. within a Secret resource. In some instances, `key` is a required field.
  3938. properties:
  3939. key:
  3940. description: |-
  3941. A key in the referenced Secret.
  3942. Some instances of this field may be defaulted, in others it may be required.
  3943. maxLength: 253
  3944. minLength: 1
  3945. pattern: ^[-._a-zA-Z0-9]+$
  3946. type: string
  3947. name:
  3948. description: The name of the Secret resource being referred to.
  3949. maxLength: 253
  3950. minLength: 1
  3951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3952. type: string
  3953. namespace:
  3954. description: |-
  3955. The namespace of the Secret resource being referred to.
  3956. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3957. maxLength: 63
  3958. minLength: 1
  3959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3960. type: string
  3961. type: object
  3962. required:
  3963. - account
  3964. - apiKeyRef
  3965. - userRef
  3966. type: object
  3967. cert:
  3968. description: Cert enables certificate-based authentication using a client certificate and key.
  3969. properties:
  3970. account:
  3971. description: Account is the Conjur organization account name.
  3972. type: string
  3973. clientCertRef:
  3974. description: |-
  3975. ClientCertRef is a reference to a specific 'key' containing the client certificate
  3976. within a Secret resource. The certificate must be PEM-encoded.
  3977. properties:
  3978. key:
  3979. description: |-
  3980. A key in the referenced Secret.
  3981. Some instances of this field may be defaulted, in others it may be required.
  3982. maxLength: 253
  3983. minLength: 1
  3984. pattern: ^[-._a-zA-Z0-9]+$
  3985. type: string
  3986. name:
  3987. description: The name of the Secret resource being referred to.
  3988. maxLength: 253
  3989. minLength: 1
  3990. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3991. type: string
  3992. namespace:
  3993. description: |-
  3994. The namespace of the Secret resource being referred to.
  3995. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3996. maxLength: 63
  3997. minLength: 1
  3998. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3999. type: string
  4000. type: object
  4001. clientKeyRef:
  4002. description: |-
  4003. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  4004. within a Secret resource. The key must be PEM-encoded.
  4005. properties:
  4006. key:
  4007. description: |-
  4008. A key in the referenced Secret.
  4009. Some instances of this field may be defaulted, in others it may be required.
  4010. maxLength: 253
  4011. minLength: 1
  4012. pattern: ^[-._a-zA-Z0-9]+$
  4013. type: string
  4014. name:
  4015. description: The name of the Secret resource being referred to.
  4016. maxLength: 253
  4017. minLength: 1
  4018. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4019. type: string
  4020. namespace:
  4021. description: |-
  4022. The namespace of the Secret resource being referred to.
  4023. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4024. maxLength: 63
  4025. minLength: 1
  4026. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4027. type: string
  4028. type: object
  4029. hostId:
  4030. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  4031. type: string
  4032. serviceID:
  4033. description: The conjur authn cert webservice id
  4034. type: string
  4035. required:
  4036. - account
  4037. - clientCertRef
  4038. - clientKeyRef
  4039. - serviceID
  4040. type: object
  4041. jwt:
  4042. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  4043. properties:
  4044. account:
  4045. description: Account is the Conjur organization account name.
  4046. type: string
  4047. hostId:
  4048. description: |-
  4049. Optional HostID for JWT authentication. This may be used depending
  4050. on how the Conjur JWT authenticator policy is configured.
  4051. type: string
  4052. secretRef:
  4053. description: |-
  4054. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  4055. authenticate with Conjur using the JWT authentication method.
  4056. properties:
  4057. key:
  4058. description: |-
  4059. A key in the referenced Secret.
  4060. Some instances of this field may be defaulted, in others it may be required.
  4061. maxLength: 253
  4062. minLength: 1
  4063. pattern: ^[-._a-zA-Z0-9]+$
  4064. type: string
  4065. name:
  4066. description: The name of the Secret resource being referred to.
  4067. maxLength: 253
  4068. minLength: 1
  4069. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4070. type: string
  4071. namespace:
  4072. description: |-
  4073. The namespace of the Secret resource being referred to.
  4074. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4075. maxLength: 63
  4076. minLength: 1
  4077. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4078. type: string
  4079. type: object
  4080. serviceAccountRef:
  4081. description: |-
  4082. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  4083. a token for with the `TokenRequest` API.
  4084. properties:
  4085. audiences:
  4086. description: |-
  4087. Audience specifies the `aud` claim for the service account token
  4088. Some providers automatically extend the audience field based on well-known annotations for workload
  4089. identity (e.g. IRSA or GCP Workload Identity)
  4090. items:
  4091. type: string
  4092. type: array
  4093. name:
  4094. description: The name of the ServiceAccount resource being referred to.
  4095. maxLength: 253
  4096. minLength: 1
  4097. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4098. type: string
  4099. namespace:
  4100. description: |-
  4101. Namespace of the resource being referred to.
  4102. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4103. maxLength: 63
  4104. minLength: 1
  4105. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4106. type: string
  4107. required:
  4108. - name
  4109. type: object
  4110. serviceID:
  4111. description: The conjur authn jwt webservice id
  4112. type: string
  4113. required:
  4114. - account
  4115. - serviceID
  4116. type: object
  4117. type: object
  4118. caBundle:
  4119. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  4120. type: string
  4121. caProvider:
  4122. description: |-
  4123. Used to provide custom certificate authority (CA) certificates
  4124. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  4125. that contains a PEM-encoded certificate.
  4126. properties:
  4127. key:
  4128. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4129. maxLength: 253
  4130. minLength: 1
  4131. pattern: ^[-._a-zA-Z0-9]+$
  4132. type: string
  4133. name:
  4134. description: The name of the object located at the provider type.
  4135. maxLength: 253
  4136. minLength: 1
  4137. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4138. type: string
  4139. namespace:
  4140. description: |-
  4141. The namespace the Provider type is in.
  4142. Can only be defined when used in a ClusterSecretStore.
  4143. maxLength: 63
  4144. minLength: 1
  4145. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4146. type: string
  4147. type:
  4148. description: The type of provider to use such as "Secret", or "ConfigMap".
  4149. enum:
  4150. - Secret
  4151. - ConfigMap
  4152. type: string
  4153. required:
  4154. - name
  4155. - type
  4156. type: object
  4157. url:
  4158. description: URL is the endpoint of the Conjur instance.
  4159. type: string
  4160. required:
  4161. - auth
  4162. - url
  4163. type: object
  4164. crd:
  4165. description: |-
  4166. CRD configures this store to sync secrets from arbitrary Kubernetes resources,
  4167. including both custom resources (CRDs) and core API resources. Resources are
  4168. selected by API group, version and kind, where group can be "" (empty string)
  4169. for core resources such as ConfigMap. Reading the core v1 Secret is
  4170. intentionally blocked — use the Kubernetes provider for that.
  4171. properties:
  4172. auth:
  4173. description: |-
  4174. Auth configures authentication to the Kubernetes API, same as the
  4175. Kubernetes provider. Required when Server.URL is set (unless using AuthRef).
  4176. maxProperties: 1
  4177. minProperties: 1
  4178. properties:
  4179. cert:
  4180. description: has both clientCert and clientKey as secretKeySelector
  4181. properties:
  4182. clientCert:
  4183. description: |-
  4184. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4185. In some instances, `key` is a required field.
  4186. properties:
  4187. key:
  4188. description: |-
  4189. A key in the referenced Secret.
  4190. Some instances of this field may be defaulted, in others it may be required.
  4191. maxLength: 253
  4192. minLength: 1
  4193. pattern: ^[-._a-zA-Z0-9]+$
  4194. type: string
  4195. name:
  4196. description: The name of the Secret resource being referred to.
  4197. maxLength: 253
  4198. minLength: 1
  4199. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4200. type: string
  4201. namespace:
  4202. description: |-
  4203. The namespace of the Secret resource being referred to.
  4204. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4205. maxLength: 63
  4206. minLength: 1
  4207. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4208. type: string
  4209. type: object
  4210. clientKey:
  4211. description: |-
  4212. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4213. In some instances, `key` is a required field.
  4214. properties:
  4215. key:
  4216. description: |-
  4217. A key in the referenced Secret.
  4218. Some instances of this field may be defaulted, in others it may be required.
  4219. maxLength: 253
  4220. minLength: 1
  4221. pattern: ^[-._a-zA-Z0-9]+$
  4222. type: string
  4223. name:
  4224. description: The name of the Secret resource being referred to.
  4225. maxLength: 253
  4226. minLength: 1
  4227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4228. type: string
  4229. namespace:
  4230. description: |-
  4231. The namespace of the Secret resource being referred to.
  4232. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4233. maxLength: 63
  4234. minLength: 1
  4235. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4236. type: string
  4237. type: object
  4238. required:
  4239. - clientCert
  4240. - clientKey
  4241. type: object
  4242. serviceAccount:
  4243. description: points to a service account that should be used for authentication
  4244. properties:
  4245. audiences:
  4246. description: |-
  4247. Audience specifies the `aud` claim for the service account token
  4248. Some providers automatically extend the audience field based on well-known annotations for workload
  4249. identity (e.g. IRSA or GCP Workload Identity)
  4250. items:
  4251. type: string
  4252. type: array
  4253. name:
  4254. description: The name of the ServiceAccount resource being referred to.
  4255. maxLength: 253
  4256. minLength: 1
  4257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4258. type: string
  4259. namespace:
  4260. description: |-
  4261. Namespace of the resource being referred to.
  4262. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4263. maxLength: 63
  4264. minLength: 1
  4265. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4266. type: string
  4267. required:
  4268. - name
  4269. type: object
  4270. token:
  4271. description: use static token to authenticate with
  4272. properties:
  4273. bearerToken:
  4274. description: |-
  4275. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4276. In some instances, `key` is a required field.
  4277. properties:
  4278. key:
  4279. description: |-
  4280. A key in the referenced Secret.
  4281. Some instances of this field may be defaulted, in others it may be required.
  4282. maxLength: 253
  4283. minLength: 1
  4284. pattern: ^[-._a-zA-Z0-9]+$
  4285. type: string
  4286. name:
  4287. description: The name of the Secret resource being referred to.
  4288. maxLength: 253
  4289. minLength: 1
  4290. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4291. type: string
  4292. namespace:
  4293. description: |-
  4294. The namespace of the Secret resource being referred to.
  4295. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4296. maxLength: 63
  4297. minLength: 1
  4298. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4299. type: string
  4300. type: object
  4301. required:
  4302. - bearerToken
  4303. type: object
  4304. type: object
  4305. authRef:
  4306. description: |-
  4307. AuthRef references a Secret containing a kubeconfig. Same semantics as the
  4308. Kubernetes provider.
  4309. properties:
  4310. key:
  4311. description: |-
  4312. A key in the referenced Secret.
  4313. Some instances of this field may be defaulted, in others it may be required.
  4314. maxLength: 253
  4315. minLength: 1
  4316. pattern: ^[-._a-zA-Z0-9]+$
  4317. type: string
  4318. name:
  4319. description: The name of the Secret resource being referred to.
  4320. maxLength: 253
  4321. minLength: 1
  4322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4323. type: string
  4324. namespace:
  4325. description: |-
  4326. The namespace of the Secret resource being referred to.
  4327. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4328. maxLength: 63
  4329. minLength: 1
  4330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4331. type: string
  4332. type: object
  4333. resource:
  4334. description: Resource identifies the CRD by its API group, version and kind.
  4335. properties:
  4336. group:
  4337. description: |-
  4338. Group is the API group of the resource. Use "" (empty string) for core
  4339. Kubernetes resources such as ConfigMap; use e.g. "config.example.io"
  4340. for a CRD. The field is required to be present in the manifest — write
  4341. `group: ""` explicitly for core resources so typos fail at admission
  4342. time rather than later at discovery.
  4343. type: string
  4344. kind:
  4345. description: Kind is the Kubernetes resource kind (e.g. "MyCustomResource").
  4346. minLength: 1
  4347. type: string
  4348. version:
  4349. description: Version is the API version of the resource (e.g. "v1alpha1").
  4350. minLength: 1
  4351. type: string
  4352. required:
  4353. - group
  4354. - kind
  4355. - version
  4356. type: object
  4357. server:
  4358. description: |-
  4359. Server configures the Kubernetes API address and TLS trust, same as the
  4360. Kubernetes provider. When omitted, the URL defaults to the in-cluster API.
  4361. properties:
  4362. caBundle:
  4363. description: CABundle is a base64-encoded CA certificate
  4364. format: byte
  4365. type: string
  4366. caProvider:
  4367. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  4368. properties:
  4369. key:
  4370. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4371. maxLength: 253
  4372. minLength: 1
  4373. pattern: ^[-._a-zA-Z0-9]+$
  4374. type: string
  4375. name:
  4376. description: The name of the object located at the provider type.
  4377. maxLength: 253
  4378. minLength: 1
  4379. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4380. type: string
  4381. namespace:
  4382. description: |-
  4383. The namespace the Provider type is in.
  4384. Can only be defined when used in a ClusterSecretStore.
  4385. maxLength: 63
  4386. minLength: 1
  4387. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4388. type: string
  4389. type:
  4390. description: The type of provider to use such as "Secret", or "ConfigMap".
  4391. enum:
  4392. - Secret
  4393. - ConfigMap
  4394. type: string
  4395. required:
  4396. - name
  4397. - type
  4398. type: object
  4399. url:
  4400. default: kubernetes.default
  4401. description: configures the Kubernetes server Address.
  4402. type: string
  4403. type: object
  4404. whitelist:
  4405. description: |-
  4406. Whitelist optionally restricts which object names and requested properties
  4407. are allowed to be read.
  4408. properties:
  4409. rules:
  4410. description: |-
  4411. Rules is a list of allow rules. If rules are set, at least one rule must
  4412. match for a request to be allowed.
  4413. items:
  4414. description: CRDProviderWhitelistRule defines a single allow rule for CRD reads.
  4415. properties:
  4416. name:
  4417. description: |-
  4418. Name is an optional regular expression matched against the bare object name.
  4419. For both SecretStore and ClusterSecretStore this is always the object name
  4420. without any namespace prefix (e.g. "my-db-spec", not "prod/my-db-spec").
  4421. type: string
  4422. namespace:
  4423. description: |-
  4424. Namespace is an optional regular expression matched against the namespace of
  4425. the object. Applies only when a ClusterSecretStore is used; it is ignored
  4426. for SecretStore (where the namespace is fixed to the store namespace).
  4427. type: string
  4428. properties:
  4429. description: |-
  4430. Properties is an optional list of regular expressions matched against
  4431. requested property keys (for example: "spec.secretValue").
  4432. items:
  4433. type: string
  4434. type: array
  4435. type: object
  4436. type: array
  4437. type: object
  4438. required:
  4439. - resource
  4440. type: object
  4441. x-kubernetes-validations:
  4442. - message: one of auth or authRef is required
  4443. rule: has(self.auth) || has(self.authRef)
  4444. - message: at most one of the fields in [auth authRef] may be set
  4445. rule: '[has(self.auth),has(self.authRef)].filter(x,x==true).size() <= 1'
  4446. delinea:
  4447. description: |-
  4448. Delinea DevOps Secrets Vault
  4449. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  4450. properties:
  4451. clientId:
  4452. description: ClientID is the non-secret part of the credential.
  4453. properties:
  4454. secretRef:
  4455. description: SecretRef references a key in a secret that will be used as value.
  4456. properties:
  4457. key:
  4458. description: |-
  4459. A key in the referenced Secret.
  4460. Some instances of this field may be defaulted, in others it may be required.
  4461. maxLength: 253
  4462. minLength: 1
  4463. pattern: ^[-._a-zA-Z0-9]+$
  4464. type: string
  4465. name:
  4466. description: The name of the Secret resource being referred to.
  4467. maxLength: 253
  4468. minLength: 1
  4469. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4470. type: string
  4471. namespace:
  4472. description: |-
  4473. The namespace of the Secret resource being referred to.
  4474. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4475. maxLength: 63
  4476. minLength: 1
  4477. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4478. type: string
  4479. type: object
  4480. value:
  4481. description: Value can be specified directly to set a value without using a secret.
  4482. type: string
  4483. type: object
  4484. clientSecret:
  4485. description: ClientSecret is the secret part of the credential.
  4486. properties:
  4487. secretRef:
  4488. description: SecretRef references a key in a secret that will be used as value.
  4489. properties:
  4490. key:
  4491. description: |-
  4492. A key in the referenced Secret.
  4493. Some instances of this field may be defaulted, in others it may be required.
  4494. maxLength: 253
  4495. minLength: 1
  4496. pattern: ^[-._a-zA-Z0-9]+$
  4497. type: string
  4498. name:
  4499. description: The name of the Secret resource being referred to.
  4500. maxLength: 253
  4501. minLength: 1
  4502. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4503. type: string
  4504. namespace:
  4505. description: |-
  4506. The namespace of the Secret resource being referred to.
  4507. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4508. maxLength: 63
  4509. minLength: 1
  4510. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4511. type: string
  4512. type: object
  4513. value:
  4514. description: Value can be specified directly to set a value without using a secret.
  4515. type: string
  4516. type: object
  4517. tenant:
  4518. description: Tenant is the chosen hostname / site name.
  4519. type: string
  4520. tld:
  4521. description: |-
  4522. TLD is based on the server location that was chosen during provisioning.
  4523. If unset, defaults to "com".
  4524. type: string
  4525. urlTemplate:
  4526. description: |-
  4527. URLTemplate
  4528. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  4529. type: string
  4530. required:
  4531. - clientId
  4532. - clientSecret
  4533. - tenant
  4534. type: object
  4535. doppler:
  4536. description: Doppler configures this store to sync secrets using the Doppler provider
  4537. properties:
  4538. auth:
  4539. description: Auth configures how the Operator authenticates with the Doppler API
  4540. properties:
  4541. oidcConfig:
  4542. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  4543. properties:
  4544. expirationSeconds:
  4545. default: 600
  4546. description: |-
  4547. ExpirationSeconds sets the ServiceAccount token validity duration.
  4548. Defaults to 10 minutes.
  4549. format: int64
  4550. type: integer
  4551. identity:
  4552. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  4553. type: string
  4554. serviceAccountRef:
  4555. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  4556. properties:
  4557. audiences:
  4558. description: |-
  4559. Audience specifies the `aud` claim for the service account token
  4560. Some providers automatically extend the audience field based on well-known annotations for workload
  4561. identity (e.g. IRSA or GCP Workload Identity)
  4562. items:
  4563. type: string
  4564. type: array
  4565. name:
  4566. description: The name of the ServiceAccount resource being referred to.
  4567. maxLength: 253
  4568. minLength: 1
  4569. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4570. type: string
  4571. namespace:
  4572. description: |-
  4573. Namespace of the resource being referred to.
  4574. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4575. maxLength: 63
  4576. minLength: 1
  4577. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4578. type: string
  4579. required:
  4580. - name
  4581. type: object
  4582. required:
  4583. - identity
  4584. - serviceAccountRef
  4585. type: object
  4586. secretRef:
  4587. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  4588. properties:
  4589. dopplerToken:
  4590. description: |-
  4591. The DopplerToken is used for authentication.
  4592. See https://docs.doppler.com/reference/api#authentication for auth token types.
  4593. The Key attribute defaults to dopplerToken if not specified.
  4594. properties:
  4595. key:
  4596. description: |-
  4597. A key in the referenced Secret.
  4598. Some instances of this field may be defaulted, in others it may be required.
  4599. maxLength: 253
  4600. minLength: 1
  4601. pattern: ^[-._a-zA-Z0-9]+$
  4602. type: string
  4603. name:
  4604. description: The name of the Secret resource being referred to.
  4605. maxLength: 253
  4606. minLength: 1
  4607. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4608. type: string
  4609. namespace:
  4610. description: |-
  4611. The namespace of the Secret resource being referred to.
  4612. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4613. maxLength: 63
  4614. minLength: 1
  4615. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4616. type: string
  4617. type: object
  4618. required:
  4619. - dopplerToken
  4620. type: object
  4621. type: object
  4622. x-kubernetes-validations:
  4623. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  4624. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  4625. config:
  4626. description: Doppler config (required if not using a Service Token)
  4627. type: string
  4628. format:
  4629. description: Format enables the downloading of secrets as a file (string)
  4630. enum:
  4631. - json
  4632. - dotnet-json
  4633. - env
  4634. - yaml
  4635. - docker
  4636. type: string
  4637. nameTransformer:
  4638. description: Environment variable compatible name transforms that change secret names to a different format
  4639. enum:
  4640. - upper-camel
  4641. - camel
  4642. - lower-snake
  4643. - tf-var
  4644. - dotnet-env
  4645. - lower-kebab
  4646. type: string
  4647. project:
  4648. description: Doppler project (required if not using a Service Token)
  4649. type: string
  4650. required:
  4651. - auth
  4652. type: object
  4653. dvls:
  4654. description: DVLS configures this store to sync secrets using Devolutions Server provider
  4655. properties:
  4656. auth:
  4657. description: Auth defines the authentication method to use.
  4658. properties:
  4659. secretRef:
  4660. description: SecretRef contains the Application ID and Application Secret for authentication.
  4661. properties:
  4662. appId:
  4663. description: AppID is the reference to the secret containing the Application ID.
  4664. properties:
  4665. key:
  4666. description: |-
  4667. A key in the referenced Secret.
  4668. Some instances of this field may be defaulted, in others it may be required.
  4669. maxLength: 253
  4670. minLength: 1
  4671. pattern: ^[-._a-zA-Z0-9]+$
  4672. type: string
  4673. name:
  4674. description: The name of the Secret resource being referred to.
  4675. maxLength: 253
  4676. minLength: 1
  4677. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4678. type: string
  4679. namespace:
  4680. description: |-
  4681. The namespace of the Secret resource being referred to.
  4682. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4683. maxLength: 63
  4684. minLength: 1
  4685. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4686. type: string
  4687. type: object
  4688. appSecret:
  4689. description: AppSecret is the reference to the secret containing the Application Secret.
  4690. properties:
  4691. key:
  4692. description: |-
  4693. A key in the referenced Secret.
  4694. Some instances of this field may be defaulted, in others it may be required.
  4695. maxLength: 253
  4696. minLength: 1
  4697. pattern: ^[-._a-zA-Z0-9]+$
  4698. type: string
  4699. name:
  4700. description: The name of the Secret resource being referred to.
  4701. maxLength: 253
  4702. minLength: 1
  4703. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4704. type: string
  4705. namespace:
  4706. description: |-
  4707. The namespace of the Secret resource being referred to.
  4708. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4709. maxLength: 63
  4710. minLength: 1
  4711. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4712. type: string
  4713. type: object
  4714. required:
  4715. - appId
  4716. - appSecret
  4717. type: object
  4718. required:
  4719. - secretRef
  4720. type: object
  4721. insecure:
  4722. description: |-
  4723. Insecure allows connecting to DVLS over plain HTTP.
  4724. This is NOT RECOMMENDED for production use.
  4725. Set to true only if you understand the security implications.
  4726. type: boolean
  4727. serverUrl:
  4728. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  4729. type: string
  4730. vault:
  4731. description: |-
  4732. Vault is the name or UUID of the vault to fetch secrets from.
  4733. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  4734. type: string
  4735. required:
  4736. - auth
  4737. - serverUrl
  4738. type: object
  4739. fake:
  4740. description: Fake configures a store with static key/value pairs
  4741. properties:
  4742. data:
  4743. items:
  4744. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  4745. properties:
  4746. key:
  4747. type: string
  4748. value:
  4749. type: string
  4750. version:
  4751. type: string
  4752. required:
  4753. - key
  4754. - value
  4755. type: object
  4756. type: array
  4757. validationResult:
  4758. description: ValidationResult is defined type for the number of validation results.
  4759. type: integer
  4760. required:
  4761. - data
  4762. type: object
  4763. fortanix:
  4764. description: Fortanix configures this store to sync secrets using the Fortanix provider
  4765. properties:
  4766. apiKey:
  4767. description: APIKey is the API token to access SDKMS Applications.
  4768. properties:
  4769. secretRef:
  4770. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  4771. properties:
  4772. key:
  4773. description: |-
  4774. A key in the referenced Secret.
  4775. Some instances of this field may be defaulted, in others it may be required.
  4776. maxLength: 253
  4777. minLength: 1
  4778. pattern: ^[-._a-zA-Z0-9]+$
  4779. type: string
  4780. name:
  4781. description: The name of the Secret resource being referred to.
  4782. maxLength: 253
  4783. minLength: 1
  4784. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4785. type: string
  4786. namespace:
  4787. description: |-
  4788. The namespace of the Secret resource being referred to.
  4789. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4790. maxLength: 63
  4791. minLength: 1
  4792. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4793. type: string
  4794. type: object
  4795. type: object
  4796. apiUrl:
  4797. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  4798. type: string
  4799. type: object
  4800. gcpsm:
  4801. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  4802. properties:
  4803. auth:
  4804. description: Auth defines the information necessary to authenticate against GCP
  4805. properties:
  4806. secretRef:
  4807. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  4808. properties:
  4809. secretAccessKeySecretRef:
  4810. description: The SecretAccessKey is used for authentication
  4811. properties:
  4812. key:
  4813. description: |-
  4814. A key in the referenced Secret.
  4815. Some instances of this field may be defaulted, in others it may be required.
  4816. maxLength: 253
  4817. minLength: 1
  4818. pattern: ^[-._a-zA-Z0-9]+$
  4819. type: string
  4820. name:
  4821. description: The name of the Secret resource being referred to.
  4822. maxLength: 253
  4823. minLength: 1
  4824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4825. type: string
  4826. namespace:
  4827. description: |-
  4828. The namespace of the Secret resource being referred to.
  4829. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4830. maxLength: 63
  4831. minLength: 1
  4832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4833. type: string
  4834. type: object
  4835. type: object
  4836. workloadIdentity:
  4837. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  4838. properties:
  4839. clusterLocation:
  4840. description: |-
  4841. ClusterLocation is the location of the cluster
  4842. If not specified, it fetches information from the metadata server
  4843. type: string
  4844. clusterName:
  4845. description: |-
  4846. ClusterName is the name of the cluster
  4847. If not specified, it fetches information from the metadata server
  4848. type: string
  4849. clusterProjectID:
  4850. description: |-
  4851. ClusterProjectID is the project ID of the cluster
  4852. If not specified, it fetches information from the metadata server
  4853. type: string
  4854. serviceAccountRef:
  4855. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  4856. properties:
  4857. audiences:
  4858. description: |-
  4859. Audience specifies the `aud` claim for the service account token
  4860. Some providers automatically extend the audience field based on well-known annotations for workload
  4861. identity (e.g. IRSA or GCP Workload Identity)
  4862. items:
  4863. type: string
  4864. type: array
  4865. name:
  4866. description: The name of the ServiceAccount resource being referred to.
  4867. maxLength: 253
  4868. minLength: 1
  4869. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4870. type: string
  4871. namespace:
  4872. description: |-
  4873. Namespace of the resource being referred to.
  4874. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4875. maxLength: 63
  4876. minLength: 1
  4877. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4878. type: string
  4879. required:
  4880. - name
  4881. type: object
  4882. required:
  4883. - serviceAccountRef
  4884. type: object
  4885. workloadIdentityFederation:
  4886. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  4887. properties:
  4888. audience:
  4889. description: |-
  4890. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  4891. If specified, Audience found in the external account credential config will be overridden with the configured value.
  4892. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  4893. type: string
  4894. awsSecurityCredentials:
  4895. description: |-
  4896. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  4897. when using the AWS metadata server is not an option.
  4898. properties:
  4899. awsCredentialsSecretRef:
  4900. description: |-
  4901. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  4902. Secret should be created with below names for keys
  4903. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  4904. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  4905. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  4906. properties:
  4907. name:
  4908. description: name of the secret.
  4909. maxLength: 253
  4910. minLength: 1
  4911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4912. type: string
  4913. namespace:
  4914. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  4915. maxLength: 63
  4916. minLength: 1
  4917. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4918. type: string
  4919. required:
  4920. - name
  4921. type: object
  4922. region:
  4923. description: region is for configuring the AWS region to be used.
  4924. example: ap-south-1
  4925. maxLength: 50
  4926. minLength: 1
  4927. pattern: ^[a-z0-9-]+$
  4928. type: string
  4929. required:
  4930. - awsCredentialsSecretRef
  4931. - region
  4932. type: object
  4933. credConfig:
  4934. description: |-
  4935. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  4936. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  4937. serviceAccountRef must be used by providing operators service account details.
  4938. properties:
  4939. key:
  4940. description: key name holding the external account credential config.
  4941. maxLength: 253
  4942. minLength: 1
  4943. pattern: ^[-._a-zA-Z0-9]+$
  4944. type: string
  4945. name:
  4946. description: name of the configmap.
  4947. maxLength: 253
  4948. minLength: 1
  4949. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4950. type: string
  4951. namespace:
  4952. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  4953. maxLength: 63
  4954. minLength: 1
  4955. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4956. type: string
  4957. required:
  4958. - key
  4959. - name
  4960. type: object
  4961. externalTokenEndpoint:
  4962. description: |-
  4963. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  4964. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  4965. URL is having the expected value.
  4966. type: string
  4967. gcpServiceAccountEmail:
  4968. description: |-
  4969. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  4970. after Workload Identity Federation. Use this to grant access through the service account's
  4971. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  4972. service_account_impersonation_url in the external account JSON from credConfig;
  4973. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  4974. on that ServiceAccount.
  4975. example: my-gsa@my-project.iam.gserviceaccount.com
  4976. minLength: 1
  4977. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  4978. type: string
  4979. serviceAccountRef:
  4980. description: |-
  4981. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  4982. when Kubernetes is configured as provider in workload identity pool.
  4983. properties:
  4984. audiences:
  4985. description: |-
  4986. Audience specifies the `aud` claim for the service account token
  4987. Some providers automatically extend the audience field based on well-known annotations for workload
  4988. identity (e.g. IRSA or GCP Workload Identity)
  4989. items:
  4990. type: string
  4991. type: array
  4992. name:
  4993. description: The name of the ServiceAccount resource being referred to.
  4994. maxLength: 253
  4995. minLength: 1
  4996. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4997. type: string
  4998. namespace:
  4999. description: |-
  5000. Namespace of the resource being referred to.
  5001. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5002. maxLength: 63
  5003. minLength: 1
  5004. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5005. type: string
  5006. required:
  5007. - name
  5008. type: object
  5009. type: object
  5010. type: object
  5011. location:
  5012. description: Location optionally defines a location for a secret
  5013. type: string
  5014. projectID:
  5015. description: ProjectID project where secret is located
  5016. type: string
  5017. secretVersionSelectionPolicy:
  5018. default: LatestOrFail
  5019. description: |-
  5020. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  5021. when "latest" is disabled or destroyed.
  5022. Possible values are:
  5023. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  5024. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  5025. type: string
  5026. type: object
  5027. github:
  5028. description: |-
  5029. Github configures this store to push GitHub Actions or Dependabot secrets using the GitHub API provider.
  5030. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  5031. properties:
  5032. appID:
  5033. description: appID specifies the Github APP that will be used to authenticate the client
  5034. format: int64
  5035. type: integer
  5036. auth:
  5037. description: auth configures how secret-manager authenticates with a Github instance.
  5038. properties:
  5039. privateKey:
  5040. description: |-
  5041. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5042. In some instances, `key` is a required field.
  5043. properties:
  5044. key:
  5045. description: |-
  5046. A key in the referenced Secret.
  5047. Some instances of this field may be defaulted, in others it may be required.
  5048. maxLength: 253
  5049. minLength: 1
  5050. pattern: ^[-._a-zA-Z0-9]+$
  5051. type: string
  5052. name:
  5053. description: The name of the Secret resource being referred to.
  5054. maxLength: 253
  5055. minLength: 1
  5056. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5057. type: string
  5058. namespace:
  5059. description: |-
  5060. The namespace of the Secret resource being referred to.
  5061. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5062. maxLength: 63
  5063. minLength: 1
  5064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5065. type: string
  5066. type: object
  5067. required:
  5068. - privateKey
  5069. type: object
  5070. environment:
  5071. description: environment will be used to fetch secrets from a particular environment within a github repository
  5072. type: string
  5073. installationID:
  5074. description: installationID specifies the Github APP installation that will be used to authenticate the client
  5075. format: int64
  5076. type: integer
  5077. orgSecretVisibility:
  5078. description: |-
  5079. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  5080. Valid values are "all" or "private".
  5081. When unset, new secrets are created with visibility "all" and existing secrets preserve
  5082. whatever visibility they already have in GitHub.
  5083. enum:
  5084. - all
  5085. - private
  5086. type: string
  5087. organization:
  5088. description: organization will be used to fetch secrets from the Github organization
  5089. type: string
  5090. repository:
  5091. description: repository will be used to fetch secrets from the Github repository within an organization
  5092. type: string
  5093. secretType:
  5094. default: Actions
  5095. description: |-
  5096. secretType specifies which GitHub secret service to use.
  5097. Defaults to Actions for backwards compatibility.
  5098. enum:
  5099. - Actions
  5100. - Dependabot
  5101. type: string
  5102. uploadURL:
  5103. description: Upload URL for enterprise instances. Default to URL.
  5104. type: string
  5105. url:
  5106. default: https://github.com/
  5107. description: URL configures the Github instance URL. Defaults to https://github.com/.
  5108. type: string
  5109. required:
  5110. - appID
  5111. - auth
  5112. - installationID
  5113. - organization
  5114. type: object
  5115. x-kubernetes-validations:
  5116. - message: Dependabot secrets do not support environments
  5117. rule: self.secretType != 'Dependabot' || !has(self.environment) || size(self.environment) == 0
  5118. gitlab:
  5119. description: GitLab configures this store to sync secrets using GitLab Variables provider
  5120. properties:
  5121. auth:
  5122. description: Auth configures how secret-manager authenticates with a GitLab instance.
  5123. properties:
  5124. SecretRef:
  5125. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  5126. properties:
  5127. accessToken:
  5128. description: AccessToken is used for authentication.
  5129. properties:
  5130. key:
  5131. description: |-
  5132. A key in the referenced Secret.
  5133. Some instances of this field may be defaulted, in others it may be required.
  5134. maxLength: 253
  5135. minLength: 1
  5136. pattern: ^[-._a-zA-Z0-9]+$
  5137. type: string
  5138. name:
  5139. description: The name of the Secret resource being referred to.
  5140. maxLength: 253
  5141. minLength: 1
  5142. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5143. type: string
  5144. namespace:
  5145. description: |-
  5146. The namespace of the Secret resource being referred to.
  5147. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5148. maxLength: 63
  5149. minLength: 1
  5150. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5151. type: string
  5152. type: object
  5153. type: object
  5154. required:
  5155. - SecretRef
  5156. type: object
  5157. caBundle:
  5158. description: |-
  5159. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  5160. can be performed.
  5161. format: byte
  5162. type: string
  5163. caProvider:
  5164. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  5165. properties:
  5166. key:
  5167. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5168. maxLength: 253
  5169. minLength: 1
  5170. pattern: ^[-._a-zA-Z0-9]+$
  5171. type: string
  5172. name:
  5173. description: The name of the object located at the provider type.
  5174. maxLength: 253
  5175. minLength: 1
  5176. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5177. type: string
  5178. namespace:
  5179. description: |-
  5180. The namespace the Provider type is in.
  5181. Can only be defined when used in a ClusterSecretStore.
  5182. maxLength: 63
  5183. minLength: 1
  5184. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5185. type: string
  5186. type:
  5187. description: The type of provider to use such as "Secret", or "ConfigMap".
  5188. enum:
  5189. - Secret
  5190. - ConfigMap
  5191. type: string
  5192. required:
  5193. - name
  5194. - type
  5195. type: object
  5196. environment:
  5197. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  5198. type: string
  5199. groupIDs:
  5200. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  5201. items:
  5202. type: string
  5203. type: array
  5204. inheritFromGroups:
  5205. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  5206. type: boolean
  5207. projectID:
  5208. description: ProjectID specifies a project where secrets are located.
  5209. type: string
  5210. url:
  5211. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  5212. type: string
  5213. required:
  5214. - auth
  5215. type: object
  5216. ibm:
  5217. description: IBM configures this store to sync secrets using IBM Cloud provider
  5218. properties:
  5219. auth:
  5220. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  5221. maxProperties: 1
  5222. minProperties: 1
  5223. properties:
  5224. containerAuth:
  5225. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  5226. properties:
  5227. iamEndpoint:
  5228. type: string
  5229. profile:
  5230. description: the IBM Trusted Profile
  5231. type: string
  5232. tokenLocation:
  5233. description: Location the token is mounted on the pod
  5234. type: string
  5235. required:
  5236. - profile
  5237. type: object
  5238. secretRef:
  5239. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  5240. properties:
  5241. iamEndpoint:
  5242. description: The IAM endpoint used to obain a token
  5243. type: string
  5244. secretApiKeySecretRef:
  5245. description: The SecretAccessKey is used for authentication
  5246. properties:
  5247. key:
  5248. description: |-
  5249. A key in the referenced Secret.
  5250. Some instances of this field may be defaulted, in others it may be required.
  5251. maxLength: 253
  5252. minLength: 1
  5253. pattern: ^[-._a-zA-Z0-9]+$
  5254. type: string
  5255. name:
  5256. description: The name of the Secret resource being referred to.
  5257. maxLength: 253
  5258. minLength: 1
  5259. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5260. type: string
  5261. namespace:
  5262. description: |-
  5263. The namespace of the Secret resource being referred to.
  5264. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5265. maxLength: 63
  5266. minLength: 1
  5267. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5268. type: string
  5269. type: object
  5270. type: object
  5271. type: object
  5272. serviceUrl:
  5273. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  5274. type: string
  5275. required:
  5276. - auth
  5277. type: object
  5278. infisical:
  5279. description: Infisical configures this store to sync secrets using the Infisical provider
  5280. properties:
  5281. auth:
  5282. description: Auth configures how the Operator authenticates with the Infisical API
  5283. properties:
  5284. awsAuthCredentials:
  5285. description: AwsAuthCredentials represents the credentials for AWS authentication.
  5286. properties:
  5287. identityId:
  5288. description: |-
  5289. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5290. In some instances, `key` is a required field.
  5291. properties:
  5292. key:
  5293. description: |-
  5294. A key in the referenced Secret.
  5295. Some instances of this field may be defaulted, in others it may be required.
  5296. maxLength: 253
  5297. minLength: 1
  5298. pattern: ^[-._a-zA-Z0-9]+$
  5299. type: string
  5300. name:
  5301. description: The name of the Secret resource being referred to.
  5302. maxLength: 253
  5303. minLength: 1
  5304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5305. type: string
  5306. namespace:
  5307. description: |-
  5308. The namespace of the Secret resource being referred to.
  5309. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5310. maxLength: 63
  5311. minLength: 1
  5312. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5313. type: string
  5314. type: object
  5315. required:
  5316. - identityId
  5317. type: object
  5318. azureAuthCredentials:
  5319. description: AzureAuthCredentials represents the credentials for Azure authentication.
  5320. properties:
  5321. identityId:
  5322. description: |-
  5323. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5324. In some instances, `key` is a required field.
  5325. properties:
  5326. key:
  5327. description: |-
  5328. A key in the referenced Secret.
  5329. Some instances of this field may be defaulted, in others it may be required.
  5330. maxLength: 253
  5331. minLength: 1
  5332. pattern: ^[-._a-zA-Z0-9]+$
  5333. type: string
  5334. name:
  5335. description: The name of the Secret resource being referred to.
  5336. maxLength: 253
  5337. minLength: 1
  5338. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5339. type: string
  5340. namespace:
  5341. description: |-
  5342. The namespace of the Secret resource being referred to.
  5343. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5344. maxLength: 63
  5345. minLength: 1
  5346. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5347. type: string
  5348. type: object
  5349. resource:
  5350. description: |-
  5351. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5352. In some instances, `key` is a required field.
  5353. properties:
  5354. key:
  5355. description: |-
  5356. A key in the referenced Secret.
  5357. Some instances of this field may be defaulted, in others it may be required.
  5358. maxLength: 253
  5359. minLength: 1
  5360. pattern: ^[-._a-zA-Z0-9]+$
  5361. type: string
  5362. name:
  5363. description: The name of the Secret resource being referred to.
  5364. maxLength: 253
  5365. minLength: 1
  5366. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5367. type: string
  5368. namespace:
  5369. description: |-
  5370. The namespace of the Secret resource being referred to.
  5371. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5372. maxLength: 63
  5373. minLength: 1
  5374. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5375. type: string
  5376. type: object
  5377. required:
  5378. - identityId
  5379. type: object
  5380. gcpIamAuthCredentials:
  5381. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  5382. properties:
  5383. identityId:
  5384. description: |-
  5385. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5386. In some instances, `key` is a required field.
  5387. properties:
  5388. key:
  5389. description: |-
  5390. A key in the referenced Secret.
  5391. Some instances of this field may be defaulted, in others it may be required.
  5392. maxLength: 253
  5393. minLength: 1
  5394. pattern: ^[-._a-zA-Z0-9]+$
  5395. type: string
  5396. name:
  5397. description: The name of the Secret resource being referred to.
  5398. maxLength: 253
  5399. minLength: 1
  5400. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5401. type: string
  5402. namespace:
  5403. description: |-
  5404. The namespace of the Secret resource being referred to.
  5405. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5406. maxLength: 63
  5407. minLength: 1
  5408. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5409. type: string
  5410. type: object
  5411. serviceAccountKeyFilePath:
  5412. description: |-
  5413. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5414. In some instances, `key` is a required field.
  5415. properties:
  5416. key:
  5417. description: |-
  5418. A key in the referenced Secret.
  5419. Some instances of this field may be defaulted, in others it may be required.
  5420. maxLength: 253
  5421. minLength: 1
  5422. pattern: ^[-._a-zA-Z0-9]+$
  5423. type: string
  5424. name:
  5425. description: The name of the Secret resource being referred to.
  5426. maxLength: 253
  5427. minLength: 1
  5428. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5429. type: string
  5430. namespace:
  5431. description: |-
  5432. The namespace of the Secret resource being referred to.
  5433. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5434. maxLength: 63
  5435. minLength: 1
  5436. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5437. type: string
  5438. type: object
  5439. required:
  5440. - identityId
  5441. - serviceAccountKeyFilePath
  5442. type: object
  5443. gcpIdTokenAuthCredentials:
  5444. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  5445. properties:
  5446. identityId:
  5447. description: |-
  5448. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5449. In some instances, `key` is a required field.
  5450. properties:
  5451. key:
  5452. description: |-
  5453. A key in the referenced Secret.
  5454. Some instances of this field may be defaulted, in others it may be required.
  5455. maxLength: 253
  5456. minLength: 1
  5457. pattern: ^[-._a-zA-Z0-9]+$
  5458. type: string
  5459. name:
  5460. description: The name of the Secret resource being referred to.
  5461. maxLength: 253
  5462. minLength: 1
  5463. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5464. type: string
  5465. namespace:
  5466. description: |-
  5467. The namespace of the Secret resource being referred to.
  5468. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5469. maxLength: 63
  5470. minLength: 1
  5471. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5472. type: string
  5473. type: object
  5474. required:
  5475. - identityId
  5476. type: object
  5477. jwtAuthCredentials:
  5478. description: JwtAuthCredentials represents the credentials for JWT authentication.
  5479. properties:
  5480. identityId:
  5481. description: |-
  5482. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5483. In some instances, `key` is a required field.
  5484. properties:
  5485. key:
  5486. description: |-
  5487. A key in the referenced Secret.
  5488. Some instances of this field may be defaulted, in others it may be required.
  5489. maxLength: 253
  5490. minLength: 1
  5491. pattern: ^[-._a-zA-Z0-9]+$
  5492. type: string
  5493. name:
  5494. description: The name of the Secret resource being referred to.
  5495. maxLength: 253
  5496. minLength: 1
  5497. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5498. type: string
  5499. namespace:
  5500. description: |-
  5501. The namespace of the Secret resource being referred to.
  5502. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5503. maxLength: 63
  5504. minLength: 1
  5505. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5506. type: string
  5507. type: object
  5508. jwt:
  5509. description: |-
  5510. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5511. In some instances, `key` is a required field.
  5512. properties:
  5513. key:
  5514. description: |-
  5515. A key in the referenced Secret.
  5516. Some instances of this field may be defaulted, in others it may be required.
  5517. maxLength: 253
  5518. minLength: 1
  5519. pattern: ^[-._a-zA-Z0-9]+$
  5520. type: string
  5521. name:
  5522. description: The name of the Secret resource being referred to.
  5523. maxLength: 253
  5524. minLength: 1
  5525. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5526. type: string
  5527. namespace:
  5528. description: |-
  5529. The namespace of the Secret resource being referred to.
  5530. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5531. maxLength: 63
  5532. minLength: 1
  5533. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5534. type: string
  5535. type: object
  5536. required:
  5537. - identityId
  5538. - jwt
  5539. type: object
  5540. kubernetesAuthCredentials:
  5541. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  5542. properties:
  5543. identityId:
  5544. description: |-
  5545. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5546. In some instances, `key` is a required field.
  5547. properties:
  5548. key:
  5549. description: |-
  5550. A key in the referenced Secret.
  5551. Some instances of this field may be defaulted, in others it may be required.
  5552. maxLength: 253
  5553. minLength: 1
  5554. pattern: ^[-._a-zA-Z0-9]+$
  5555. type: string
  5556. name:
  5557. description: The name of the Secret resource being referred to.
  5558. maxLength: 253
  5559. minLength: 1
  5560. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5561. type: string
  5562. namespace:
  5563. description: |-
  5564. The namespace of the Secret resource being referred to.
  5565. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5566. maxLength: 63
  5567. minLength: 1
  5568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5569. type: string
  5570. type: object
  5571. serviceAccountTokenPath:
  5572. description: |-
  5573. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5574. In some instances, `key` is a required field.
  5575. properties:
  5576. key:
  5577. description: |-
  5578. A key in the referenced Secret.
  5579. Some instances of this field may be defaulted, in others it may be required.
  5580. maxLength: 253
  5581. minLength: 1
  5582. pattern: ^[-._a-zA-Z0-9]+$
  5583. type: string
  5584. name:
  5585. description: The name of the Secret resource being referred to.
  5586. maxLength: 253
  5587. minLength: 1
  5588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5589. type: string
  5590. namespace:
  5591. description: |-
  5592. The namespace of the Secret resource being referred to.
  5593. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5594. maxLength: 63
  5595. minLength: 1
  5596. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5597. type: string
  5598. type: object
  5599. required:
  5600. - identityId
  5601. type: object
  5602. ldapAuthCredentials:
  5603. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  5604. properties:
  5605. identityId:
  5606. description: |-
  5607. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5608. In some instances, `key` is a required field.
  5609. properties:
  5610. key:
  5611. description: |-
  5612. A key in the referenced Secret.
  5613. Some instances of this field may be defaulted, in others it may be required.
  5614. maxLength: 253
  5615. minLength: 1
  5616. pattern: ^[-._a-zA-Z0-9]+$
  5617. type: string
  5618. name:
  5619. description: The name of the Secret resource being referred to.
  5620. maxLength: 253
  5621. minLength: 1
  5622. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5623. type: string
  5624. namespace:
  5625. description: |-
  5626. The namespace of the Secret resource being referred to.
  5627. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5628. maxLength: 63
  5629. minLength: 1
  5630. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5631. type: string
  5632. type: object
  5633. ldapPassword:
  5634. description: |-
  5635. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5636. In some instances, `key` is a required field.
  5637. properties:
  5638. key:
  5639. description: |-
  5640. A key in the referenced Secret.
  5641. Some instances of this field may be defaulted, in others it may be required.
  5642. maxLength: 253
  5643. minLength: 1
  5644. pattern: ^[-._a-zA-Z0-9]+$
  5645. type: string
  5646. name:
  5647. description: The name of the Secret resource being referred to.
  5648. maxLength: 253
  5649. minLength: 1
  5650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5651. type: string
  5652. namespace:
  5653. description: |-
  5654. The namespace of the Secret resource being referred to.
  5655. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5656. maxLength: 63
  5657. minLength: 1
  5658. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5659. type: string
  5660. type: object
  5661. ldapUsername:
  5662. description: |-
  5663. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5664. In some instances, `key` is a required field.
  5665. properties:
  5666. key:
  5667. description: |-
  5668. A key in the referenced Secret.
  5669. Some instances of this field may be defaulted, in others it may be required.
  5670. maxLength: 253
  5671. minLength: 1
  5672. pattern: ^[-._a-zA-Z0-9]+$
  5673. type: string
  5674. name:
  5675. description: The name of the Secret resource being referred to.
  5676. maxLength: 253
  5677. minLength: 1
  5678. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5679. type: string
  5680. namespace:
  5681. description: |-
  5682. The namespace of the Secret resource being referred to.
  5683. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5684. maxLength: 63
  5685. minLength: 1
  5686. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5687. type: string
  5688. type: object
  5689. required:
  5690. - identityId
  5691. - ldapPassword
  5692. - ldapUsername
  5693. type: object
  5694. ociAuthCredentials:
  5695. description: OciAuthCredentials represents the credentials for OCI authentication.
  5696. properties:
  5697. fingerprint:
  5698. description: |-
  5699. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5700. In some instances, `key` is a required field.
  5701. properties:
  5702. key:
  5703. description: |-
  5704. A key in the referenced Secret.
  5705. Some instances of this field may be defaulted, in others it may be required.
  5706. maxLength: 253
  5707. minLength: 1
  5708. pattern: ^[-._a-zA-Z0-9]+$
  5709. type: string
  5710. name:
  5711. description: The name of the Secret resource being referred to.
  5712. maxLength: 253
  5713. minLength: 1
  5714. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5715. type: string
  5716. namespace:
  5717. description: |-
  5718. The namespace of the Secret resource being referred to.
  5719. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5720. maxLength: 63
  5721. minLength: 1
  5722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5723. type: string
  5724. type: object
  5725. identityId:
  5726. description: |-
  5727. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5728. In some instances, `key` is a required field.
  5729. properties:
  5730. key:
  5731. description: |-
  5732. A key in the referenced Secret.
  5733. Some instances of this field may be defaulted, in others it may be required.
  5734. maxLength: 253
  5735. minLength: 1
  5736. pattern: ^[-._a-zA-Z0-9]+$
  5737. type: string
  5738. name:
  5739. description: The name of the Secret resource being referred to.
  5740. maxLength: 253
  5741. minLength: 1
  5742. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5743. type: string
  5744. namespace:
  5745. description: |-
  5746. The namespace of the Secret resource being referred to.
  5747. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5748. maxLength: 63
  5749. minLength: 1
  5750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5751. type: string
  5752. type: object
  5753. privateKey:
  5754. description: |-
  5755. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5756. In some instances, `key` is a required field.
  5757. properties:
  5758. key:
  5759. description: |-
  5760. A key in the referenced Secret.
  5761. Some instances of this field may be defaulted, in others it may be required.
  5762. maxLength: 253
  5763. minLength: 1
  5764. pattern: ^[-._a-zA-Z0-9]+$
  5765. type: string
  5766. name:
  5767. description: The name of the Secret resource being referred to.
  5768. maxLength: 253
  5769. minLength: 1
  5770. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5771. type: string
  5772. namespace:
  5773. description: |-
  5774. The namespace of the Secret resource being referred to.
  5775. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5776. maxLength: 63
  5777. minLength: 1
  5778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5779. type: string
  5780. type: object
  5781. privateKeyPassphrase:
  5782. description: |-
  5783. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5784. In some instances, `key` is a required field.
  5785. properties:
  5786. key:
  5787. description: |-
  5788. A key in the referenced Secret.
  5789. Some instances of this field may be defaulted, in others it may be required.
  5790. maxLength: 253
  5791. minLength: 1
  5792. pattern: ^[-._a-zA-Z0-9]+$
  5793. type: string
  5794. name:
  5795. description: The name of the Secret resource being referred to.
  5796. maxLength: 253
  5797. minLength: 1
  5798. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5799. type: string
  5800. namespace:
  5801. description: |-
  5802. The namespace of the Secret resource being referred to.
  5803. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5804. maxLength: 63
  5805. minLength: 1
  5806. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5807. type: string
  5808. type: object
  5809. region:
  5810. description: |-
  5811. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5812. In some instances, `key` is a required field.
  5813. properties:
  5814. key:
  5815. description: |-
  5816. A key in the referenced Secret.
  5817. Some instances of this field may be defaulted, in others it may be required.
  5818. maxLength: 253
  5819. minLength: 1
  5820. pattern: ^[-._a-zA-Z0-9]+$
  5821. type: string
  5822. name:
  5823. description: The name of the Secret resource being referred to.
  5824. maxLength: 253
  5825. minLength: 1
  5826. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5827. type: string
  5828. namespace:
  5829. description: |-
  5830. The namespace of the Secret resource being referred to.
  5831. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5832. maxLength: 63
  5833. minLength: 1
  5834. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5835. type: string
  5836. type: object
  5837. tenancyId:
  5838. description: |-
  5839. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5840. In some instances, `key` is a required field.
  5841. properties:
  5842. key:
  5843. description: |-
  5844. A key in the referenced Secret.
  5845. Some instances of this field may be defaulted, in others it may be required.
  5846. maxLength: 253
  5847. minLength: 1
  5848. pattern: ^[-._a-zA-Z0-9]+$
  5849. type: string
  5850. name:
  5851. description: The name of the Secret resource being referred to.
  5852. maxLength: 253
  5853. minLength: 1
  5854. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5855. type: string
  5856. namespace:
  5857. description: |-
  5858. The namespace of the Secret resource being referred to.
  5859. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5860. maxLength: 63
  5861. minLength: 1
  5862. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5863. type: string
  5864. type: object
  5865. userId:
  5866. description: |-
  5867. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5868. In some instances, `key` is a required field.
  5869. properties:
  5870. key:
  5871. description: |-
  5872. A key in the referenced Secret.
  5873. Some instances of this field may be defaulted, in others it may be required.
  5874. maxLength: 253
  5875. minLength: 1
  5876. pattern: ^[-._a-zA-Z0-9]+$
  5877. type: string
  5878. name:
  5879. description: The name of the Secret resource being referred to.
  5880. maxLength: 253
  5881. minLength: 1
  5882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5883. type: string
  5884. namespace:
  5885. description: |-
  5886. The namespace of the Secret resource being referred to.
  5887. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5888. maxLength: 63
  5889. minLength: 1
  5890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5891. type: string
  5892. type: object
  5893. required:
  5894. - fingerprint
  5895. - identityId
  5896. - privateKey
  5897. - region
  5898. - tenancyId
  5899. - userId
  5900. type: object
  5901. tokenAuthCredentials:
  5902. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  5903. properties:
  5904. accessToken:
  5905. description: |-
  5906. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5907. In some instances, `key` is a required field.
  5908. properties:
  5909. key:
  5910. description: |-
  5911. A key in the referenced Secret.
  5912. Some instances of this field may be defaulted, in others it may be required.
  5913. maxLength: 253
  5914. minLength: 1
  5915. pattern: ^[-._a-zA-Z0-9]+$
  5916. type: string
  5917. name:
  5918. description: The name of the Secret resource being referred to.
  5919. maxLength: 253
  5920. minLength: 1
  5921. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5922. type: string
  5923. namespace:
  5924. description: |-
  5925. The namespace of the Secret resource being referred to.
  5926. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5927. maxLength: 63
  5928. minLength: 1
  5929. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5930. type: string
  5931. type: object
  5932. required:
  5933. - accessToken
  5934. type: object
  5935. universalAuthCredentials:
  5936. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  5937. properties:
  5938. clientId:
  5939. description: |-
  5940. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5941. In some instances, `key` is a required field.
  5942. properties:
  5943. key:
  5944. description: |-
  5945. A key in the referenced Secret.
  5946. Some instances of this field may be defaulted, in others it may be required.
  5947. maxLength: 253
  5948. minLength: 1
  5949. pattern: ^[-._a-zA-Z0-9]+$
  5950. type: string
  5951. name:
  5952. description: The name of the Secret resource being referred to.
  5953. maxLength: 253
  5954. minLength: 1
  5955. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5956. type: string
  5957. namespace:
  5958. description: |-
  5959. The namespace of the Secret resource being referred to.
  5960. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5961. maxLength: 63
  5962. minLength: 1
  5963. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5964. type: string
  5965. type: object
  5966. clientSecret:
  5967. description: |-
  5968. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5969. In some instances, `key` is a required field.
  5970. properties:
  5971. key:
  5972. description: |-
  5973. A key in the referenced Secret.
  5974. Some instances of this field may be defaulted, in others it may be required.
  5975. maxLength: 253
  5976. minLength: 1
  5977. pattern: ^[-._a-zA-Z0-9]+$
  5978. type: string
  5979. name:
  5980. description: The name of the Secret resource being referred to.
  5981. maxLength: 253
  5982. minLength: 1
  5983. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5984. type: string
  5985. namespace:
  5986. description: |-
  5987. The namespace of the Secret resource being referred to.
  5988. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5989. maxLength: 63
  5990. minLength: 1
  5991. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5992. type: string
  5993. type: object
  5994. required:
  5995. - clientId
  5996. - clientSecret
  5997. type: object
  5998. type: object
  5999. caBundle:
  6000. description: |-
  6001. CABundle is a PEM-encoded CA certificate bundle used to validate
  6002. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  6003. format: byte
  6004. type: string
  6005. caProvider:
  6006. description: |-
  6007. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  6008. The certificate is used to validate the Infisical server's TLS certificate.
  6009. Mutually exclusive with CABundle.
  6010. properties:
  6011. key:
  6012. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6013. maxLength: 253
  6014. minLength: 1
  6015. pattern: ^[-._a-zA-Z0-9]+$
  6016. type: string
  6017. name:
  6018. description: The name of the object located at the provider type.
  6019. maxLength: 253
  6020. minLength: 1
  6021. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6022. type: string
  6023. namespace:
  6024. description: |-
  6025. The namespace the Provider type is in.
  6026. Can only be defined when used in a ClusterSecretStore.
  6027. maxLength: 63
  6028. minLength: 1
  6029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6030. type: string
  6031. type:
  6032. description: The type of provider to use such as "Secret", or "ConfigMap".
  6033. enum:
  6034. - Secret
  6035. - ConfigMap
  6036. type: string
  6037. required:
  6038. - name
  6039. - type
  6040. type: object
  6041. hostAPI:
  6042. default: https://app.infisical.com/api
  6043. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  6044. type: string
  6045. secretsScope:
  6046. description: SecretsScope defines the scope of the secrets within the workspace
  6047. properties:
  6048. environmentSlug:
  6049. description: EnvironmentSlug is the required slug identifier for the environment.
  6050. type: string
  6051. expandSecretReferences:
  6052. default: true
  6053. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  6054. type: boolean
  6055. includeSecretPath:
  6056. default: false
  6057. description: |-
  6058. IncludeSecretPath indicates whether the secret path should be included as a prefix
  6059. in the secret key. Secrets at the root path (/) are not prefixed.
  6060. type: boolean
  6061. organizationSlug:
  6062. description: |-
  6063. OrganizationSlug is the optional slug that identifies the organization that will be used
  6064. during authentication. Useful for sub-organization setups
  6065. type: string
  6066. projectSlug:
  6067. description: ProjectSlug is the required slug identifier for the project.
  6068. type: string
  6069. recursive:
  6070. default: false
  6071. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  6072. type: boolean
  6073. secretsPath:
  6074. default: /
  6075. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  6076. type: string
  6077. required:
  6078. - environmentSlug
  6079. - projectSlug
  6080. type: object
  6081. required:
  6082. - auth
  6083. - secretsScope
  6084. type: object
  6085. keepersecurity:
  6086. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  6087. properties:
  6088. authRef:
  6089. description: |-
  6090. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6091. In some instances, `key` is a required field.
  6092. properties:
  6093. key:
  6094. description: |-
  6095. A key in the referenced Secret.
  6096. Some instances of this field may be defaulted, in others it may be required.
  6097. maxLength: 253
  6098. minLength: 1
  6099. pattern: ^[-._a-zA-Z0-9]+$
  6100. type: string
  6101. name:
  6102. description: The name of the Secret resource being referred to.
  6103. maxLength: 253
  6104. minLength: 1
  6105. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6106. type: string
  6107. namespace:
  6108. description: |-
  6109. The namespace of the Secret resource being referred to.
  6110. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6111. maxLength: 63
  6112. minLength: 1
  6113. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6114. type: string
  6115. type: object
  6116. folderID:
  6117. type: string
  6118. getByTitleFallback:
  6119. type: boolean
  6120. required:
  6121. - authRef
  6122. type: object
  6123. kubernetes:
  6124. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  6125. properties:
  6126. auth:
  6127. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  6128. maxProperties: 1
  6129. minProperties: 1
  6130. properties:
  6131. cert:
  6132. description: has both clientCert and clientKey as secretKeySelector
  6133. properties:
  6134. clientCert:
  6135. description: |-
  6136. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6137. In some instances, `key` is a required field.
  6138. properties:
  6139. key:
  6140. description: |-
  6141. A key in the referenced Secret.
  6142. Some instances of this field may be defaulted, in others it may be required.
  6143. maxLength: 253
  6144. minLength: 1
  6145. pattern: ^[-._a-zA-Z0-9]+$
  6146. type: string
  6147. name:
  6148. description: The name of the Secret resource being referred to.
  6149. maxLength: 253
  6150. minLength: 1
  6151. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6152. type: string
  6153. namespace:
  6154. description: |-
  6155. The namespace of the Secret resource being referred to.
  6156. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6157. maxLength: 63
  6158. minLength: 1
  6159. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6160. type: string
  6161. type: object
  6162. clientKey:
  6163. description: |-
  6164. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6165. In some instances, `key` is a required field.
  6166. properties:
  6167. key:
  6168. description: |-
  6169. A key in the referenced Secret.
  6170. Some instances of this field may be defaulted, in others it may be required.
  6171. maxLength: 253
  6172. minLength: 1
  6173. pattern: ^[-._a-zA-Z0-9]+$
  6174. type: string
  6175. name:
  6176. description: The name of the Secret resource being referred to.
  6177. maxLength: 253
  6178. minLength: 1
  6179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6180. type: string
  6181. namespace:
  6182. description: |-
  6183. The namespace of the Secret resource being referred to.
  6184. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6185. maxLength: 63
  6186. minLength: 1
  6187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6188. type: string
  6189. type: object
  6190. required:
  6191. - clientCert
  6192. - clientKey
  6193. type: object
  6194. serviceAccount:
  6195. description: points to a service account that should be used for authentication
  6196. properties:
  6197. audiences:
  6198. description: |-
  6199. Audience specifies the `aud` claim for the service account token
  6200. Some providers automatically extend the audience field based on well-known annotations for workload
  6201. identity (e.g. IRSA or GCP Workload Identity)
  6202. items:
  6203. type: string
  6204. type: array
  6205. name:
  6206. description: The name of the ServiceAccount resource being referred to.
  6207. maxLength: 253
  6208. minLength: 1
  6209. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6210. type: string
  6211. namespace:
  6212. description: |-
  6213. Namespace of the resource being referred to.
  6214. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6215. maxLength: 63
  6216. minLength: 1
  6217. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6218. type: string
  6219. required:
  6220. - name
  6221. type: object
  6222. token:
  6223. description: use static token to authenticate with
  6224. properties:
  6225. bearerToken:
  6226. description: |-
  6227. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6228. In some instances, `key` is a required field.
  6229. properties:
  6230. key:
  6231. description: |-
  6232. A key in the referenced Secret.
  6233. Some instances of this field may be defaulted, in others it may be required.
  6234. maxLength: 253
  6235. minLength: 1
  6236. pattern: ^[-._a-zA-Z0-9]+$
  6237. type: string
  6238. name:
  6239. description: The name of the Secret resource being referred to.
  6240. maxLength: 253
  6241. minLength: 1
  6242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6243. type: string
  6244. namespace:
  6245. description: |-
  6246. The namespace of the Secret resource being referred to.
  6247. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6248. maxLength: 63
  6249. minLength: 1
  6250. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6251. type: string
  6252. type: object
  6253. required:
  6254. - bearerToken
  6255. type: object
  6256. type: object
  6257. authRef:
  6258. description: A reference to a secret that contains the auth information.
  6259. properties:
  6260. key:
  6261. description: |-
  6262. A key in the referenced Secret.
  6263. Some instances of this field may be defaulted, in others it may be required.
  6264. maxLength: 253
  6265. minLength: 1
  6266. pattern: ^[-._a-zA-Z0-9]+$
  6267. type: string
  6268. name:
  6269. description: The name of the Secret resource being referred to.
  6270. maxLength: 253
  6271. minLength: 1
  6272. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6273. type: string
  6274. namespace:
  6275. description: |-
  6276. The namespace of the Secret resource being referred to.
  6277. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6278. maxLength: 63
  6279. minLength: 1
  6280. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6281. type: string
  6282. type: object
  6283. remoteNamespace:
  6284. default: default
  6285. description: Remote namespace to fetch the secrets from
  6286. maxLength: 63
  6287. minLength: 1
  6288. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6289. type: string
  6290. server:
  6291. description: configures the Kubernetes server Address.
  6292. properties:
  6293. caBundle:
  6294. description: CABundle is a base64-encoded CA certificate
  6295. format: byte
  6296. type: string
  6297. caProvider:
  6298. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  6299. properties:
  6300. key:
  6301. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6302. maxLength: 253
  6303. minLength: 1
  6304. pattern: ^[-._a-zA-Z0-9]+$
  6305. type: string
  6306. name:
  6307. description: The name of the object located at the provider type.
  6308. maxLength: 253
  6309. minLength: 1
  6310. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6311. type: string
  6312. namespace:
  6313. description: |-
  6314. The namespace the Provider type is in.
  6315. Can only be defined when used in a ClusterSecretStore.
  6316. maxLength: 63
  6317. minLength: 1
  6318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6319. type: string
  6320. type:
  6321. description: The type of provider to use such as "Secret", or "ConfigMap".
  6322. enum:
  6323. - Secret
  6324. - ConfigMap
  6325. type: string
  6326. required:
  6327. - name
  6328. - type
  6329. type: object
  6330. url:
  6331. default: kubernetes.default
  6332. description: configures the Kubernetes server Address.
  6333. type: string
  6334. type: object
  6335. type: object
  6336. nebiusmysterybox:
  6337. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  6338. properties:
  6339. apiDomain:
  6340. description: NebiusMysterybox API endpoint
  6341. type: string
  6342. auth:
  6343. description: Auth defines parameters to authenticate in MysteryBox
  6344. properties:
  6345. serviceAccountCredsSecretRef:
  6346. description: |-
  6347. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  6348. document with service account credentials used to get an IAM token.
  6349. Expected JSON structure:
  6350. {
  6351. "subject-credentials": {
  6352. "alg": "RS256",
  6353. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  6354. "kid": "<public-key-id>",
  6355. "iss": "<issuer-service-account-id>",
  6356. "sub": "<subject-service-account-id>"
  6357. }
  6358. }
  6359. properties:
  6360. key:
  6361. description: |-
  6362. A key in the referenced Secret.
  6363. Some instances of this field may be defaulted, in others it may be required.
  6364. maxLength: 253
  6365. minLength: 1
  6366. pattern: ^[-._a-zA-Z0-9]+$
  6367. type: string
  6368. name:
  6369. description: The name of the Secret resource being referred to.
  6370. maxLength: 253
  6371. minLength: 1
  6372. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6373. type: string
  6374. namespace:
  6375. description: |-
  6376. The namespace of the Secret resource being referred to.
  6377. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6378. maxLength: 63
  6379. minLength: 1
  6380. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6381. type: string
  6382. type: object
  6383. tokenSecretRef:
  6384. description: Token authenticates with Nebius Mysterybox by presenting a token.
  6385. properties:
  6386. key:
  6387. description: |-
  6388. A key in the referenced Secret.
  6389. Some instances of this field may be defaulted, in others it may be required.
  6390. maxLength: 253
  6391. minLength: 1
  6392. pattern: ^[-._a-zA-Z0-9]+$
  6393. type: string
  6394. name:
  6395. description: The name of the Secret resource being referred to.
  6396. maxLength: 253
  6397. minLength: 1
  6398. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6399. type: string
  6400. namespace:
  6401. description: |-
  6402. The namespace of the Secret resource being referred to.
  6403. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6404. maxLength: 63
  6405. minLength: 1
  6406. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6407. type: string
  6408. type: object
  6409. workloadIdentity:
  6410. description: WorkloadIdentity defines configuration for workload identity authentication to Nebius IAM.
  6411. properties:
  6412. iamServiceAccountID:
  6413. description: |-
  6414. IAMServiceAccountID is the Nebius IAM service account identifier that the
  6415. federated Kubernetes service account should impersonate during token exchange.
  6416. example: serviceaccount-e00example
  6417. minLength: 1
  6418. pattern: ^serviceaccount-[a-z][a-z0-9]{2}
  6419. type: string
  6420. serviceAccountRef:
  6421. description: |-
  6422. ServiceAccountRef references a Kubernetes ServiceAccount used to request a
  6423. temporary JWT via the TokenRequest API. The JWT is then exchanged for a
  6424. Nebius IAM token using workload federation.
  6425. properties:
  6426. audiences:
  6427. description: |-
  6428. Audience specifies the `aud` claim for the service account token
  6429. Some providers automatically extend the audience field based on well-known annotations for workload
  6430. identity (e.g. IRSA or GCP Workload Identity)
  6431. items:
  6432. type: string
  6433. type: array
  6434. name:
  6435. description: The name of the ServiceAccount resource being referred to.
  6436. maxLength: 253
  6437. minLength: 1
  6438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6439. type: string
  6440. namespace:
  6441. description: |-
  6442. Namespace of the resource being referred to.
  6443. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6444. maxLength: 63
  6445. minLength: 1
  6446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6447. type: string
  6448. required:
  6449. - name
  6450. type: object
  6451. required:
  6452. - iamServiceAccountID
  6453. - serviceAccountRef
  6454. type: object
  6455. type: object
  6456. x-kubernetes-validations:
  6457. - message: exactly one of serviceAccountCredsSecretRef, tokenSecretRef, or workloadIdentity must be set
  6458. rule: '(has(self.serviceAccountCredsSecretRef) && has(self.serviceAccountCredsSecretRef.name) && size(self.serviceAccountCredsSecretRef.name) > 0 ? 1 : 0) + (has(self.tokenSecretRef) && has(self.tokenSecretRef.name) && size(self.tokenSecretRef.name) > 0 ? 1 : 0) + (has(self.workloadIdentity) ? 1 : 0) == 1'
  6459. caProvider:
  6460. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  6461. properties:
  6462. certSecretRef:
  6463. description: |-
  6464. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6465. In some instances, `key` is a required field.
  6466. properties:
  6467. key:
  6468. description: |-
  6469. A key in the referenced Secret.
  6470. Some instances of this field may be defaulted, in others it may be required.
  6471. maxLength: 253
  6472. minLength: 1
  6473. pattern: ^[-._a-zA-Z0-9]+$
  6474. type: string
  6475. name:
  6476. description: The name of the Secret resource being referred to.
  6477. maxLength: 253
  6478. minLength: 1
  6479. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6480. type: string
  6481. namespace:
  6482. description: |-
  6483. The namespace of the Secret resource being referred to.
  6484. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6485. maxLength: 63
  6486. minLength: 1
  6487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6488. type: string
  6489. type: object
  6490. type: object
  6491. required:
  6492. - apiDomain
  6493. - auth
  6494. type: object
  6495. ngrok:
  6496. description: Ngrok configures this store to sync secrets using the ngrok provider.
  6497. properties:
  6498. apiUrl:
  6499. default: https://api.ngrok.com
  6500. description: APIURL is the URL of the ngrok API.
  6501. type: string
  6502. auth:
  6503. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  6504. maxProperties: 1
  6505. minProperties: 1
  6506. properties:
  6507. apiKey:
  6508. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  6509. properties:
  6510. secretRef:
  6511. description: SecretRef is a reference to a secret containing the ngrok API key.
  6512. properties:
  6513. key:
  6514. description: |-
  6515. A key in the referenced Secret.
  6516. Some instances of this field may be defaulted, in others it may be required.
  6517. maxLength: 253
  6518. minLength: 1
  6519. pattern: ^[-._a-zA-Z0-9]+$
  6520. type: string
  6521. name:
  6522. description: The name of the Secret resource being referred to.
  6523. maxLength: 253
  6524. minLength: 1
  6525. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6526. type: string
  6527. namespace:
  6528. description: |-
  6529. The namespace of the Secret resource being referred to.
  6530. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6531. maxLength: 63
  6532. minLength: 1
  6533. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6534. type: string
  6535. type: object
  6536. type: object
  6537. type: object
  6538. vault:
  6539. description: Vault configures the ngrok vault to sync secrets with.
  6540. properties:
  6541. name:
  6542. description: Name is the name of the ngrok vault to sync secrets with.
  6543. type: string
  6544. required:
  6545. - name
  6546. type: object
  6547. required:
  6548. - auth
  6549. - vault
  6550. type: object
  6551. onboardbase:
  6552. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  6553. properties:
  6554. apiHost:
  6555. default: https://public.onboardbase.com/api/v1/
  6556. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  6557. type: string
  6558. auth:
  6559. description: Auth configures how the Operator authenticates with the Onboardbase API
  6560. properties:
  6561. apiKeyRef:
  6562. description: |-
  6563. OnboardbaseAPIKey is the APIKey generated by an admin account.
  6564. It is used to recognize and authorize access to a project and environment within onboardbase
  6565. properties:
  6566. key:
  6567. description: |-
  6568. A key in the referenced Secret.
  6569. Some instances of this field may be defaulted, in others it may be required.
  6570. maxLength: 253
  6571. minLength: 1
  6572. pattern: ^[-._a-zA-Z0-9]+$
  6573. type: string
  6574. name:
  6575. description: The name of the Secret resource being referred to.
  6576. maxLength: 253
  6577. minLength: 1
  6578. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6579. type: string
  6580. namespace:
  6581. description: |-
  6582. The namespace of the Secret resource being referred to.
  6583. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6584. maxLength: 63
  6585. minLength: 1
  6586. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6587. type: string
  6588. type: object
  6589. passcodeRef:
  6590. description: OnboardbasePasscode is the passcode attached to the API Key
  6591. properties:
  6592. key:
  6593. description: |-
  6594. A key in the referenced Secret.
  6595. Some instances of this field may be defaulted, in others it may be required.
  6596. maxLength: 253
  6597. minLength: 1
  6598. pattern: ^[-._a-zA-Z0-9]+$
  6599. type: string
  6600. name:
  6601. description: The name of the Secret resource being referred to.
  6602. maxLength: 253
  6603. minLength: 1
  6604. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6605. type: string
  6606. namespace:
  6607. description: |-
  6608. The namespace of the Secret resource being referred to.
  6609. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6610. maxLength: 63
  6611. minLength: 1
  6612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6613. type: string
  6614. type: object
  6615. required:
  6616. - apiKeyRef
  6617. - passcodeRef
  6618. type: object
  6619. environment:
  6620. default: development
  6621. description: Environment is the name of an environmnent within a project to pull the secrets from
  6622. type: string
  6623. project:
  6624. default: development
  6625. description: Project is an onboardbase project that the secrets should be pulled from
  6626. type: string
  6627. required:
  6628. - apiHost
  6629. - auth
  6630. - environment
  6631. - project
  6632. type: object
  6633. onepassword:
  6634. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  6635. properties:
  6636. auth:
  6637. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  6638. properties:
  6639. secretRef:
  6640. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  6641. properties:
  6642. connectTokenSecretRef:
  6643. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  6644. properties:
  6645. key:
  6646. description: |-
  6647. A key in the referenced Secret.
  6648. Some instances of this field may be defaulted, in others it may be required.
  6649. maxLength: 253
  6650. minLength: 1
  6651. pattern: ^[-._a-zA-Z0-9]+$
  6652. type: string
  6653. name:
  6654. description: The name of the Secret resource being referred to.
  6655. maxLength: 253
  6656. minLength: 1
  6657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6658. type: string
  6659. namespace:
  6660. description: |-
  6661. The namespace of the Secret resource being referred to.
  6662. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6663. maxLength: 63
  6664. minLength: 1
  6665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6666. type: string
  6667. type: object
  6668. required:
  6669. - connectTokenSecretRef
  6670. type: object
  6671. required:
  6672. - secretRef
  6673. type: object
  6674. connectHost:
  6675. description: ConnectHost defines the OnePassword Connect Server to connect to
  6676. type: string
  6677. vaults:
  6678. additionalProperties:
  6679. type: integer
  6680. description: Vaults defines which OnePassword vaults to search in which order
  6681. type: object
  6682. required:
  6683. - auth
  6684. - connectHost
  6685. - vaults
  6686. type: object
  6687. onepasswordSDK:
  6688. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  6689. properties:
  6690. auth:
  6691. description: Auth defines the information necessary to authenticate against OnePassword API.
  6692. properties:
  6693. serviceAccountSecretRef:
  6694. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  6695. properties:
  6696. key:
  6697. description: |-
  6698. A key in the referenced Secret.
  6699. Some instances of this field may be defaulted, in others it may be required.
  6700. maxLength: 253
  6701. minLength: 1
  6702. pattern: ^[-._a-zA-Z0-9]+$
  6703. type: string
  6704. name:
  6705. description: The name of the Secret resource being referred to.
  6706. maxLength: 253
  6707. minLength: 1
  6708. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6709. type: string
  6710. namespace:
  6711. description: |-
  6712. The namespace of the Secret resource being referred to.
  6713. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6714. maxLength: 63
  6715. minLength: 1
  6716. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6717. type: string
  6718. type: object
  6719. required:
  6720. - serviceAccountSecretRef
  6721. type: object
  6722. cache:
  6723. description: |-
  6724. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  6725. When enabled, secrets are cached with the specified TTL.
  6726. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  6727. If omitted, caching is disabled (default).
  6728. cache: {} is a valid option to set.
  6729. properties:
  6730. maxSize:
  6731. default: 100
  6732. description: |-
  6733. MaxSize is the maximum number of secrets to cache.
  6734. When the cache is full, least-recently-used entries are evicted.
  6735. minimum: 1
  6736. type: integer
  6737. ttl:
  6738. default: 5m
  6739. description: |-
  6740. TTL is the time-to-live for cached secrets.
  6741. Format: duration string (e.g., "5m", "1h", "30s")
  6742. type: string
  6743. type: object
  6744. environment:
  6745. description: |-
  6746. Environment defines the 1Password Environment ID to read variables from.
  6747. Environments are read-only: PushSecret, DeleteSecret, and SecretExists return an error when set.
  6748. Mutually exclusive with Vault.
  6749. type: string
  6750. integrationInfo:
  6751. description: |-
  6752. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  6753. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  6754. properties:
  6755. name:
  6756. default: 1Password SDK
  6757. description: Name defaults to "1Password SDK".
  6758. type: string
  6759. version:
  6760. default: v1.0.0
  6761. description: Version defaults to "v1.0.0".
  6762. type: string
  6763. type: object
  6764. vault:
  6765. description: |-
  6766. Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  6767. Mutually exclusive with Environment.
  6768. type: string
  6769. required:
  6770. - auth
  6771. type: object
  6772. x-kubernetes-validations:
  6773. - message: at most one of the fields in [vault environment] may be set
  6774. rule: '[has(self.vault),has(self.environment)].filter(x,x==true).size() <= 1'
  6775. openBao:
  6776. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  6777. properties:
  6778. auth:
  6779. description: Auth configures how secret-manager authenticates with the OpenBao server.
  6780. properties:
  6781. appRole:
  6782. description: |-
  6783. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  6784. with the role and secret stored in a Kubernetes Secret resource.
  6785. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  6786. properties:
  6787. path:
  6788. default: approle
  6789. description: |-
  6790. Path where the App Role authentication backend is mounted
  6791. in OpenBao, e.g: "approle"
  6792. type: string
  6793. roleId:
  6794. description: |-
  6795. RoleID configured in the App Role authentication backend when setting
  6796. up the authentication backend in OpenBao.
  6797. minLength: 1
  6798. type: string
  6799. roleRef:
  6800. description: |-
  6801. Reference to a key in a Secret that contains the App Role ID used
  6802. to authenticate with OpenBao.
  6803. The `key` field must be specified and denotes which entry within the Secret
  6804. resource is used as the app role id.
  6805. properties:
  6806. key:
  6807. description: |-
  6808. A key in the referenced Secret.
  6809. Some instances of this field may be defaulted, in others it may be required.
  6810. maxLength: 253
  6811. minLength: 1
  6812. pattern: ^[-._a-zA-Z0-9]+$
  6813. type: string
  6814. name:
  6815. description: The name of the Secret resource being referred to.
  6816. maxLength: 253
  6817. minLength: 1
  6818. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6819. type: string
  6820. namespace:
  6821. description: |-
  6822. The namespace of the Secret resource being referred to.
  6823. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6824. maxLength: 63
  6825. minLength: 1
  6826. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6827. type: string
  6828. type: object
  6829. secretRef:
  6830. description: |-
  6831. Reference to a key in a Secret that contains the App Role secret used
  6832. to authenticate with OpenBao.
  6833. The `key` field must be specified and denotes which entry within the Secret
  6834. resource is used as the app role secret.
  6835. properties:
  6836. key:
  6837. description: |-
  6838. A key in the referenced Secret.
  6839. Some instances of this field may be defaulted, in others it may be required.
  6840. maxLength: 253
  6841. minLength: 1
  6842. pattern: ^[-._a-zA-Z0-9]+$
  6843. type: string
  6844. name:
  6845. description: The name of the Secret resource being referred to.
  6846. maxLength: 253
  6847. minLength: 1
  6848. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6849. type: string
  6850. namespace:
  6851. description: |-
  6852. The namespace of the Secret resource being referred to.
  6853. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6854. maxLength: 63
  6855. minLength: 1
  6856. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6857. type: string
  6858. type: object
  6859. required:
  6860. - path
  6861. - secretRef
  6862. type: object
  6863. x-kubernetes-validations:
  6864. - message: exactly one of the fields in [roleId roleRef] must be set
  6865. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  6866. kubernetes:
  6867. description: |-
  6868. Kubernetes authenticates with OpenBao by passing a ServiceAccount
  6869. token to the [Kubernetes auth mechanism].
  6870. [Kubernetes auth mechanism]: https://openbao.org/docs/auth/kubernetes/
  6871. properties:
  6872. path:
  6873. default: kubernetes
  6874. description: |-
  6875. Path where the Kubernetes authentication backend is mounted in OpenBao, e.g:
  6876. "kubernetes"
  6877. type: string
  6878. role:
  6879. description: |-
  6880. A required field containing the OpenBao Role to assume. A Role binds a
  6881. Kubernetes ServiceAccount with a set of OpenBao policies.
  6882. minLength: 1
  6883. type: string
  6884. secretRef:
  6885. description: |-
  6886. Optional secret field containing a Kubernetes ServiceAccount JWT used
  6887. for authenticating with OpenBao. If a name is specified without a key,
  6888. `token` is the default.
  6889. properties:
  6890. key:
  6891. description: |-
  6892. A key in the referenced Secret.
  6893. Some instances of this field may be defaulted, in others it may be required.
  6894. maxLength: 253
  6895. minLength: 1
  6896. pattern: ^[-._a-zA-Z0-9]+$
  6897. type: string
  6898. name:
  6899. description: The name of the Secret resource being referred to.
  6900. maxLength: 253
  6901. minLength: 1
  6902. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6903. type: string
  6904. namespace:
  6905. description: |-
  6906. The namespace of the Secret resource being referred to.
  6907. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6908. maxLength: 63
  6909. minLength: 1
  6910. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6911. type: string
  6912. type: object
  6913. serviceAccountRef:
  6914. description: |-
  6915. Optional service account field containing the name of a Kubernetes ServiceAccount.
  6916. If the service account is specified, a token will be requested from the Kubernetes
  6917. TokenRequest API for authenticating with OpenBao.
  6918. Any configured audiences will be passed to the TokenRequest as-is.
  6919. properties:
  6920. audiences:
  6921. description: |-
  6922. Audience specifies the `aud` claim for the service account token
  6923. Some providers automatically extend the audience field based on well-known annotations for workload
  6924. identity (e.g. IRSA or GCP Workload Identity)
  6925. items:
  6926. type: string
  6927. type: array
  6928. name:
  6929. description: The name of the ServiceAccount resource being referred to.
  6930. maxLength: 253
  6931. minLength: 1
  6932. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6933. type: string
  6934. namespace:
  6935. description: |-
  6936. Namespace of the resource being referred to.
  6937. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6938. maxLength: 63
  6939. minLength: 1
  6940. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6941. type: string
  6942. required:
  6943. - name
  6944. type: object
  6945. required:
  6946. - path
  6947. - role
  6948. type: object
  6949. x-kubernetes-validations:
  6950. - message: exactly one of the fields in [serviceAccountRef secretRef] must be set
  6951. rule: '[has(self.serviceAccountRef),has(self.secretRef)].filter(x,x==true).size() == 1'
  6952. namespace:
  6953. description: |-
  6954. Name of the [OpenBao Namespace] to authenticate to. This can be different
  6955. than the namespace your secret is in. Namespaces is a set of features
  6956. within OpenBao that allows OpenBao environments to support secure
  6957. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  6958. if set, or empty otherwise
  6959. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6960. type: string
  6961. tokenSecretRef:
  6962. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  6963. properties:
  6964. key:
  6965. description: |-
  6966. A key in the referenced Secret.
  6967. Some instances of this field may be defaulted, in others it may be required.
  6968. maxLength: 253
  6969. minLength: 1
  6970. pattern: ^[-._a-zA-Z0-9]+$
  6971. type: string
  6972. name:
  6973. description: The name of the Secret resource being referred to.
  6974. maxLength: 253
  6975. minLength: 1
  6976. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6977. type: string
  6978. namespace:
  6979. description: |-
  6980. The namespace of the Secret resource being referred to.
  6981. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6982. maxLength: 63
  6983. minLength: 1
  6984. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6985. type: string
  6986. type: object
  6987. userPass:
  6988. description: UserPass authenticates with OpenBao by passing a username/password pair
  6989. properties:
  6990. path:
  6991. default: userpass
  6992. description: |-
  6993. Path where the UserPassword authentication backend is mounted
  6994. in OpenBao, e.g: "userpass"
  6995. type: string
  6996. secretRef:
  6997. description: |-
  6998. SecretRef to a key in a Secret resource containing password for the user
  6999. used to authenticate with OpenBao using the [UserPass authentication
  7000. method]
  7001. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  7002. properties:
  7003. key:
  7004. description: |-
  7005. A key in the referenced Secret.
  7006. Some instances of this field may be defaulted, in others it may be required.
  7007. maxLength: 253
  7008. minLength: 1
  7009. pattern: ^[-._a-zA-Z0-9]+$
  7010. type: string
  7011. name:
  7012. description: The name of the Secret resource being referred to.
  7013. maxLength: 253
  7014. minLength: 1
  7015. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7016. type: string
  7017. namespace:
  7018. description: |-
  7019. The namespace of the Secret resource being referred to.
  7020. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7021. maxLength: 63
  7022. minLength: 1
  7023. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7024. type: string
  7025. type: object
  7026. username:
  7027. description: |-
  7028. Username is a username used to authenticate using the [UserPass
  7029. authentication method]
  7030. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  7031. type: string
  7032. required:
  7033. - path
  7034. - username
  7035. type: object
  7036. type: object
  7037. x-kubernetes-validations:
  7038. - message: exactly one of the fields in [appRole tokenSecretRef userPass kubernetes] must be set
  7039. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass),has(self.kubernetes)].filter(x,x==true).size() == 1'
  7040. caBundle:
  7041. description: |-
  7042. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  7043. this and `caProvider` are not set the system root certificates are used
  7044. to validate the TLS connection.
  7045. format: byte
  7046. type: string
  7047. caProvider:
  7048. description: |-
  7049. The provider for the CA bundle to use to validate OpenBao server
  7050. certificate. If this and `caBundle` are not set the system root
  7051. certificates are used to validate the TLS connection.
  7052. properties:
  7053. key:
  7054. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7055. maxLength: 253
  7056. minLength: 1
  7057. pattern: ^[-._a-zA-Z0-9]+$
  7058. type: string
  7059. name:
  7060. description: The name of the object located at the provider type.
  7061. maxLength: 253
  7062. minLength: 1
  7063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7064. type: string
  7065. namespace:
  7066. description: |-
  7067. The namespace the Provider type is in.
  7068. Can only be defined when used in a ClusterSecretStore.
  7069. maxLength: 63
  7070. minLength: 1
  7071. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7072. type: string
  7073. type:
  7074. description: The type of provider to use such as "Secret", or "ConfigMap".
  7075. enum:
  7076. - Secret
  7077. - ConfigMap
  7078. type: string
  7079. required:
  7080. - name
  7081. - type
  7082. type: object
  7083. namespace:
  7084. description: |-
  7085. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  7086. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  7087. e.g: "ns1".
  7088. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  7089. type: string
  7090. path:
  7091. description: |-
  7092. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  7093. "secret". The v2 KV secret engine version specific "/data" path suffix
  7094. for fetching secrets from OpenBao is optional and will be appended
  7095. if not present in specified path.
  7096. type: string
  7097. server:
  7098. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  7099. type: string
  7100. version:
  7101. default: v2
  7102. description: |-
  7103. Version is the OpenBao KV secret engine version. This can be either "v1" or
  7104. "v2". Version defaults to "v2".
  7105. enum:
  7106. - v1
  7107. - v2
  7108. type: string
  7109. required:
  7110. - server
  7111. type: object
  7112. x-kubernetes-validations:
  7113. - message: at most one of the fields in [caBundle caProvider] may be set
  7114. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  7115. oracle:
  7116. description: Oracle configures this store to sync secrets using Oracle Vault provider
  7117. properties:
  7118. auth:
  7119. description: |-
  7120. Auth configures how secret-manager authenticates with the Oracle Vault.
  7121. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  7122. properties:
  7123. secretRef:
  7124. description: SecretRef to pass through sensitive information.
  7125. properties:
  7126. fingerprint:
  7127. description: Fingerprint is the fingerprint of the API private key.
  7128. properties:
  7129. key:
  7130. description: |-
  7131. A key in the referenced Secret.
  7132. Some instances of this field may be defaulted, in others it may be required.
  7133. maxLength: 253
  7134. minLength: 1
  7135. pattern: ^[-._a-zA-Z0-9]+$
  7136. type: string
  7137. name:
  7138. description: The name of the Secret resource being referred to.
  7139. maxLength: 253
  7140. minLength: 1
  7141. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7142. type: string
  7143. namespace:
  7144. description: |-
  7145. The namespace of the Secret resource being referred to.
  7146. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7147. maxLength: 63
  7148. minLength: 1
  7149. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7150. type: string
  7151. type: object
  7152. privatekey:
  7153. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  7154. properties:
  7155. key:
  7156. description: |-
  7157. A key in the referenced Secret.
  7158. Some instances of this field may be defaulted, in others it may be required.
  7159. maxLength: 253
  7160. minLength: 1
  7161. pattern: ^[-._a-zA-Z0-9]+$
  7162. type: string
  7163. name:
  7164. description: The name of the Secret resource being referred to.
  7165. maxLength: 253
  7166. minLength: 1
  7167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7168. type: string
  7169. namespace:
  7170. description: |-
  7171. The namespace of the Secret resource being referred to.
  7172. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7173. maxLength: 63
  7174. minLength: 1
  7175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7176. type: string
  7177. type: object
  7178. required:
  7179. - fingerprint
  7180. - privatekey
  7181. type: object
  7182. tenancy:
  7183. description: Tenancy is the tenancy OCID where user is located.
  7184. type: string
  7185. user:
  7186. description: User is an access OCID specific to the account.
  7187. type: string
  7188. required:
  7189. - secretRef
  7190. - tenancy
  7191. - user
  7192. type: object
  7193. compartment:
  7194. description: |-
  7195. Compartment is the vault compartment OCID.
  7196. Required for PushSecret
  7197. type: string
  7198. encryptionKey:
  7199. description: |-
  7200. EncryptionKey is the OCID of the encryption key within the vault.
  7201. Required for PushSecret
  7202. type: string
  7203. principalType:
  7204. description: |-
  7205. The type of principal to use for authentication. If left blank, the Auth struct will
  7206. determine the principal type. This optional field must be specified if using
  7207. workload identity.
  7208. enum:
  7209. - ""
  7210. - UserPrincipal
  7211. - InstancePrincipal
  7212. - Workload
  7213. type: string
  7214. region:
  7215. description: Region is the region where vault is located.
  7216. type: string
  7217. serviceAccountRef:
  7218. description: |-
  7219. ServiceAccountRef specified the service account
  7220. that should be used when authenticating with WorkloadIdentity.
  7221. properties:
  7222. audiences:
  7223. description: |-
  7224. Audience specifies the `aud` claim for the service account token
  7225. Some providers automatically extend the audience field based on well-known annotations for workload
  7226. identity (e.g. IRSA or GCP Workload Identity)
  7227. items:
  7228. type: string
  7229. type: array
  7230. name:
  7231. description: The name of the ServiceAccount resource being referred to.
  7232. maxLength: 253
  7233. minLength: 1
  7234. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7235. type: string
  7236. namespace:
  7237. description: |-
  7238. Namespace of the resource being referred to.
  7239. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7240. maxLength: 63
  7241. minLength: 1
  7242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7243. type: string
  7244. required:
  7245. - name
  7246. type: object
  7247. vault:
  7248. description: Vault is the vault's OCID of the specific vault where secret is located.
  7249. type: string
  7250. required:
  7251. - region
  7252. - vault
  7253. type: object
  7254. ovh:
  7255. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  7256. properties:
  7257. auth:
  7258. description: Authentication method (mtls or token).
  7259. properties:
  7260. mtls:
  7261. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  7262. properties:
  7263. caBundle:
  7264. format: byte
  7265. type: string
  7266. caProvider:
  7267. description: |-
  7268. CAProvider provides a custom certificate authority for accessing the provider's store.
  7269. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  7270. properties:
  7271. key:
  7272. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7273. maxLength: 253
  7274. minLength: 1
  7275. pattern: ^[-._a-zA-Z0-9]+$
  7276. type: string
  7277. name:
  7278. description: The name of the object located at the provider type.
  7279. maxLength: 253
  7280. minLength: 1
  7281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7282. type: string
  7283. namespace:
  7284. description: |-
  7285. The namespace the Provider type is in.
  7286. Can only be defined when used in a ClusterSecretStore.
  7287. maxLength: 63
  7288. minLength: 1
  7289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7290. type: string
  7291. type:
  7292. description: The type of provider to use such as "Secret", or "ConfigMap".
  7293. enum:
  7294. - Secret
  7295. - ConfigMap
  7296. type: string
  7297. required:
  7298. - name
  7299. - type
  7300. type: object
  7301. certSecretRef:
  7302. description: |-
  7303. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7304. In some instances, `key` is a required field.
  7305. properties:
  7306. key:
  7307. description: |-
  7308. A key in the referenced Secret.
  7309. Some instances of this field may be defaulted, in others it may be required.
  7310. maxLength: 253
  7311. minLength: 1
  7312. pattern: ^[-._a-zA-Z0-9]+$
  7313. type: string
  7314. name:
  7315. description: The name of the Secret resource being referred to.
  7316. maxLength: 253
  7317. minLength: 1
  7318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7319. type: string
  7320. namespace:
  7321. description: |-
  7322. The namespace of the Secret resource being referred to.
  7323. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7324. maxLength: 63
  7325. minLength: 1
  7326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7327. type: string
  7328. type: object
  7329. keySecretRef:
  7330. description: |-
  7331. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7332. In some instances, `key` is a required field.
  7333. properties:
  7334. key:
  7335. description: |-
  7336. A key in the referenced Secret.
  7337. Some instances of this field may be defaulted, in others it may be required.
  7338. maxLength: 253
  7339. minLength: 1
  7340. pattern: ^[-._a-zA-Z0-9]+$
  7341. type: string
  7342. name:
  7343. description: The name of the Secret resource being referred to.
  7344. maxLength: 253
  7345. minLength: 1
  7346. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7347. type: string
  7348. namespace:
  7349. description: |-
  7350. The namespace of the Secret resource being referred to.
  7351. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7352. maxLength: 63
  7353. minLength: 1
  7354. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7355. type: string
  7356. type: object
  7357. required:
  7358. - certSecretRef
  7359. - keySecretRef
  7360. type: object
  7361. token:
  7362. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  7363. properties:
  7364. tokenSecretRef:
  7365. description: |-
  7366. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7367. In some instances, `key` is a required field.
  7368. properties:
  7369. key:
  7370. description: |-
  7371. A key in the referenced Secret.
  7372. Some instances of this field may be defaulted, in others it may be required.
  7373. maxLength: 253
  7374. minLength: 1
  7375. pattern: ^[-._a-zA-Z0-9]+$
  7376. type: string
  7377. name:
  7378. description: The name of the Secret resource being referred to.
  7379. maxLength: 253
  7380. minLength: 1
  7381. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7382. type: string
  7383. namespace:
  7384. description: |-
  7385. The namespace of the Secret resource being referred to.
  7386. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7387. maxLength: 63
  7388. minLength: 1
  7389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7390. type: string
  7391. type: object
  7392. required:
  7393. - tokenSecretRef
  7394. type: object
  7395. type: object
  7396. casRequired:
  7397. description: 'Enables or disables check-and-set (CAS) (default: false).'
  7398. type: boolean
  7399. okmsTimeout:
  7400. default: 30
  7401. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  7402. format: int32
  7403. minimum: 1
  7404. type: integer
  7405. okmsid:
  7406. description: specifies the OKMS ID.
  7407. type: string
  7408. server:
  7409. description: specifies the OKMS server endpoint.
  7410. type: string
  7411. required:
  7412. - auth
  7413. - okmsid
  7414. - server
  7415. type: object
  7416. passbolt:
  7417. description: |-
  7418. PassboltProvider provides access to Passbolt secrets manager.
  7419. See: https://www.passbolt.com.
  7420. properties:
  7421. auth:
  7422. description: Auth defines the information necessary to authenticate against Passbolt Server
  7423. properties:
  7424. passwordSecretRef:
  7425. description: |-
  7426. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7427. In some instances, `key` is a required field.
  7428. properties:
  7429. key:
  7430. description: |-
  7431. A key in the referenced Secret.
  7432. Some instances of this field may be defaulted, in others it may be required.
  7433. maxLength: 253
  7434. minLength: 1
  7435. pattern: ^[-._a-zA-Z0-9]+$
  7436. type: string
  7437. name:
  7438. description: The name of the Secret resource being referred to.
  7439. maxLength: 253
  7440. minLength: 1
  7441. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7442. type: string
  7443. namespace:
  7444. description: |-
  7445. The namespace of the Secret resource being referred to.
  7446. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7447. maxLength: 63
  7448. minLength: 1
  7449. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7450. type: string
  7451. type: object
  7452. privateKeySecretRef:
  7453. description: |-
  7454. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7455. In some instances, `key` is a required field.
  7456. properties:
  7457. key:
  7458. description: |-
  7459. A key in the referenced Secret.
  7460. Some instances of this field may be defaulted, in others it may be required.
  7461. maxLength: 253
  7462. minLength: 1
  7463. pattern: ^[-._a-zA-Z0-9]+$
  7464. type: string
  7465. name:
  7466. description: The name of the Secret resource being referred to.
  7467. maxLength: 253
  7468. minLength: 1
  7469. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7470. type: string
  7471. namespace:
  7472. description: |-
  7473. The namespace of the Secret resource being referred to.
  7474. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7475. maxLength: 63
  7476. minLength: 1
  7477. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7478. type: string
  7479. type: object
  7480. required:
  7481. - passwordSecretRef
  7482. - privateKeySecretRef
  7483. type: object
  7484. caBundle:
  7485. description: |-
  7486. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  7487. if the Host URL is using HTTPS protocol. If not set the system root certificates
  7488. are used to validate the TLS connection.
  7489. format: byte
  7490. type: string
  7491. caProvider:
  7492. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  7493. properties:
  7494. key:
  7495. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7496. maxLength: 253
  7497. minLength: 1
  7498. pattern: ^[-._a-zA-Z0-9]+$
  7499. type: string
  7500. name:
  7501. description: The name of the object located at the provider type.
  7502. maxLength: 253
  7503. minLength: 1
  7504. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7505. type: string
  7506. namespace:
  7507. description: |-
  7508. The namespace the Provider type is in.
  7509. Can only be defined when used in a ClusterSecretStore.
  7510. maxLength: 63
  7511. minLength: 1
  7512. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7513. type: string
  7514. type:
  7515. description: The type of provider to use such as "Secret", or "ConfigMap".
  7516. enum:
  7517. - Secret
  7518. - ConfigMap
  7519. type: string
  7520. required:
  7521. - name
  7522. - type
  7523. type: object
  7524. host:
  7525. description: Host defines the Passbolt Server to connect to
  7526. type: string
  7527. required:
  7528. - auth
  7529. - host
  7530. type: object
  7531. passworddepot:
  7532. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  7533. properties:
  7534. auth:
  7535. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  7536. properties:
  7537. secretRef:
  7538. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  7539. properties:
  7540. credentials:
  7541. description: Username / Password is used for authentication.
  7542. properties:
  7543. key:
  7544. description: |-
  7545. A key in the referenced Secret.
  7546. Some instances of this field may be defaulted, in others it may be required.
  7547. maxLength: 253
  7548. minLength: 1
  7549. pattern: ^[-._a-zA-Z0-9]+$
  7550. type: string
  7551. name:
  7552. description: The name of the Secret resource being referred to.
  7553. maxLength: 253
  7554. minLength: 1
  7555. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7556. type: string
  7557. namespace:
  7558. description: |-
  7559. The namespace of the Secret resource being referred to.
  7560. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7561. maxLength: 63
  7562. minLength: 1
  7563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7564. type: string
  7565. type: object
  7566. type: object
  7567. required:
  7568. - secretRef
  7569. type: object
  7570. database:
  7571. description: Database to use as source
  7572. type: string
  7573. host:
  7574. description: URL configures the Password Depot instance URL.
  7575. type: string
  7576. required:
  7577. - auth
  7578. - database
  7579. - host
  7580. type: object
  7581. previder:
  7582. description: Previder configures this store to sync secrets using the Previder provider
  7583. properties:
  7584. auth:
  7585. description: PreviderAuth contains a secretRef for credentials.
  7586. properties:
  7587. secretRef:
  7588. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  7589. properties:
  7590. accessToken:
  7591. description: The AccessToken is used for authentication
  7592. properties:
  7593. key:
  7594. description: |-
  7595. A key in the referenced Secret.
  7596. Some instances of this field may be defaulted, in others it may be required.
  7597. maxLength: 253
  7598. minLength: 1
  7599. pattern: ^[-._a-zA-Z0-9]+$
  7600. type: string
  7601. name:
  7602. description: The name of the Secret resource being referred to.
  7603. maxLength: 253
  7604. minLength: 1
  7605. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7606. type: string
  7607. namespace:
  7608. description: |-
  7609. The namespace of the Secret resource being referred to.
  7610. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7611. maxLength: 63
  7612. minLength: 1
  7613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7614. type: string
  7615. type: object
  7616. required:
  7617. - accessToken
  7618. type: object
  7619. type: object
  7620. baseUri:
  7621. type: string
  7622. required:
  7623. - auth
  7624. type: object
  7625. pulumi:
  7626. description: Pulumi configures this store to sync secrets using the Pulumi provider
  7627. properties:
  7628. accessToken:
  7629. description: |-
  7630. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  7631. Deprecated: Use auth.accessToken instead.
  7632. properties:
  7633. secretRef:
  7634. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7635. properties:
  7636. key:
  7637. description: |-
  7638. A key in the referenced Secret.
  7639. Some instances of this field may be defaulted, in others it may be required.
  7640. maxLength: 253
  7641. minLength: 1
  7642. pattern: ^[-._a-zA-Z0-9]+$
  7643. type: string
  7644. name:
  7645. description: The name of the Secret resource being referred to.
  7646. maxLength: 253
  7647. minLength: 1
  7648. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7649. type: string
  7650. namespace:
  7651. description: |-
  7652. The namespace of the Secret resource being referred to.
  7653. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7654. maxLength: 63
  7655. minLength: 1
  7656. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7657. type: string
  7658. type: object
  7659. type: object
  7660. apiUrl:
  7661. default: https://api.pulumi.com/api/esc
  7662. description: APIURL is the URL of the Pulumi API.
  7663. type: string
  7664. auth:
  7665. description: |-
  7666. Auth configures how the Operator authenticates with the Pulumi API.
  7667. Either auth or the deprecated accessToken field must be specified.
  7668. properties:
  7669. accessToken:
  7670. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  7671. properties:
  7672. secretRef:
  7673. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7674. properties:
  7675. key:
  7676. description: |-
  7677. A key in the referenced Secret.
  7678. Some instances of this field may be defaulted, in others it may be required.
  7679. maxLength: 253
  7680. minLength: 1
  7681. pattern: ^[-._a-zA-Z0-9]+$
  7682. type: string
  7683. name:
  7684. description: The name of the Secret resource being referred to.
  7685. maxLength: 253
  7686. minLength: 1
  7687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7688. type: string
  7689. namespace:
  7690. description: |-
  7691. The namespace of the Secret resource being referred to.
  7692. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7693. maxLength: 63
  7694. minLength: 1
  7695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7696. type: string
  7697. type: object
  7698. type: object
  7699. oidcConfig:
  7700. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  7701. properties:
  7702. expirationSeconds:
  7703. default: 600
  7704. description: |-
  7705. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  7706. Defaults to 10 minutes.
  7707. format: int64
  7708. minimum: 600
  7709. type: integer
  7710. organization:
  7711. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  7712. type: string
  7713. serviceAccountRef:
  7714. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  7715. properties:
  7716. audiences:
  7717. description: |-
  7718. Audience specifies the `aud` claim for the service account token
  7719. Some providers automatically extend the audience field based on well-known annotations for workload
  7720. identity (e.g. IRSA or GCP Workload Identity)
  7721. items:
  7722. type: string
  7723. type: array
  7724. name:
  7725. description: The name of the ServiceAccount resource being referred to.
  7726. maxLength: 253
  7727. minLength: 1
  7728. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7729. type: string
  7730. namespace:
  7731. description: |-
  7732. Namespace of the resource being referred to.
  7733. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7734. maxLength: 63
  7735. minLength: 1
  7736. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7737. type: string
  7738. required:
  7739. - name
  7740. type: object
  7741. required:
  7742. - organization
  7743. - serviceAccountRef
  7744. type: object
  7745. type: object
  7746. x-kubernetes-validations:
  7747. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  7748. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  7749. environment:
  7750. description: |-
  7751. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  7752. dynamically retrieved values from supported providers including all major clouds,
  7753. and other Pulumi ESC environments.
  7754. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  7755. type: string
  7756. organization:
  7757. description: |-
  7758. Organization are a space to collaborate on shared projects and stacks.
  7759. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  7760. type: string
  7761. project:
  7762. description: Project is the name of the Pulumi ESC project the environment belongs to.
  7763. type: string
  7764. required:
  7765. - environment
  7766. - organization
  7767. - project
  7768. type: object
  7769. x-kubernetes-validations:
  7770. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  7771. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  7772. scaleway:
  7773. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  7774. properties:
  7775. accessKey:
  7776. description: AccessKey is the non-secret part of the api key.
  7777. properties:
  7778. secretRef:
  7779. description: SecretRef references a key in a secret that will be used as value.
  7780. properties:
  7781. key:
  7782. description: |-
  7783. A key in the referenced Secret.
  7784. Some instances of this field may be defaulted, in others it may be required.
  7785. maxLength: 253
  7786. minLength: 1
  7787. pattern: ^[-._a-zA-Z0-9]+$
  7788. type: string
  7789. name:
  7790. description: The name of the Secret resource being referred to.
  7791. maxLength: 253
  7792. minLength: 1
  7793. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7794. type: string
  7795. namespace:
  7796. description: |-
  7797. The namespace of the Secret resource being referred to.
  7798. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7799. maxLength: 63
  7800. minLength: 1
  7801. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7802. type: string
  7803. type: object
  7804. value:
  7805. description: Value can be specified directly to set a value without using a secret.
  7806. type: string
  7807. type: object
  7808. apiUrl:
  7809. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  7810. type: string
  7811. projectId:
  7812. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  7813. type: string
  7814. region:
  7815. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  7816. type: string
  7817. secretKey:
  7818. description: SecretKey is the non-secret part of the api key.
  7819. properties:
  7820. secretRef:
  7821. description: SecretRef references a key in a secret that will be used as value.
  7822. properties:
  7823. key:
  7824. description: |-
  7825. A key in the referenced Secret.
  7826. Some instances of this field may be defaulted, in others it may be required.
  7827. maxLength: 253
  7828. minLength: 1
  7829. pattern: ^[-._a-zA-Z0-9]+$
  7830. type: string
  7831. name:
  7832. description: The name of the Secret resource being referred to.
  7833. maxLength: 253
  7834. minLength: 1
  7835. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7836. type: string
  7837. namespace:
  7838. description: |-
  7839. The namespace of the Secret resource being referred to.
  7840. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7841. maxLength: 63
  7842. minLength: 1
  7843. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7844. type: string
  7845. type: object
  7846. value:
  7847. description: Value can be specified directly to set a value without using a secret.
  7848. type: string
  7849. type: object
  7850. required:
  7851. - accessKey
  7852. - projectId
  7853. - region
  7854. - secretKey
  7855. type: object
  7856. secretserver:
  7857. description: |-
  7858. SecretServer configures this store to sync secrets using SecretServer provider
  7859. https://docs.delinea.com/online-help/secret-server/start.htm
  7860. properties:
  7861. caBundle:
  7862. description: |-
  7863. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  7864. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  7865. are used to validate the TLS connection.
  7866. format: byte
  7867. type: string
  7868. caProvider:
  7869. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  7870. properties:
  7871. key:
  7872. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7873. maxLength: 253
  7874. minLength: 1
  7875. pattern: ^[-._a-zA-Z0-9]+$
  7876. type: string
  7877. name:
  7878. description: The name of the object located at the provider type.
  7879. maxLength: 253
  7880. minLength: 1
  7881. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7882. type: string
  7883. namespace:
  7884. description: |-
  7885. The namespace the Provider type is in.
  7886. Can only be defined when used in a ClusterSecretStore.
  7887. maxLength: 63
  7888. minLength: 1
  7889. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7890. type: string
  7891. type:
  7892. description: The type of provider to use such as "Secret", or "ConfigMap".
  7893. enum:
  7894. - Secret
  7895. - ConfigMap
  7896. type: string
  7897. required:
  7898. - name
  7899. - type
  7900. type: object
  7901. disableSiteIDValidation:
  7902. description: |-
  7903. DisableSiteIDValidation permits a missing site ID for new secrets.
  7904. The provider sends 0 if no site ID is set.
  7905. type: boolean
  7906. domain:
  7907. description: Domain is the secret server domain.
  7908. type: string
  7909. password:
  7910. description: |-
  7911. Password is the secret server account password.
  7912. Required unless Token is set.
  7913. properties:
  7914. secretRef:
  7915. description: SecretRef references a key in a secret that will be used as value.
  7916. properties:
  7917. key:
  7918. description: |-
  7919. A key in the referenced Secret.
  7920. Some instances of this field may be defaulted, in others it may be required.
  7921. maxLength: 253
  7922. minLength: 1
  7923. pattern: ^[-._a-zA-Z0-9]+$
  7924. type: string
  7925. name:
  7926. description: The name of the Secret resource being referred to.
  7927. maxLength: 253
  7928. minLength: 1
  7929. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7930. type: string
  7931. namespace:
  7932. description: |-
  7933. The namespace of the Secret resource being referred to.
  7934. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7935. maxLength: 63
  7936. minLength: 1
  7937. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7938. type: string
  7939. type: object
  7940. value:
  7941. description: Value can be specified directly to set a value without using a secret.
  7942. minLength: 1
  7943. type: string
  7944. type: object
  7945. x-kubernetes-validations:
  7946. - message: exactly one of value or secretRef must be set
  7947. rule: has(self.value) != has(self.secretRef)
  7948. serverURL:
  7949. description: |-
  7950. ServerURL
  7951. URL to your secret server installation
  7952. type: string
  7953. siteId:
  7954. description: |-
  7955. SiteID is the ID of the Secret Server site for new secrets.
  7956. PushSecret metadata can override this value for one secret.
  7957. The provider uses 1 if this field is not set.
  7958. minimum: 1
  7959. type: integer
  7960. token:
  7961. description: |-
  7962. Token is an access token used to authenticate to the secret server,
  7963. as an alternative to Username and Password. When set, Username and
  7964. Password are not required and are ignored.
  7965. properties:
  7966. secretRef:
  7967. description: SecretRef references a key in a secret that will be used as value.
  7968. properties:
  7969. key:
  7970. description: |-
  7971. A key in the referenced Secret.
  7972. Some instances of this field may be defaulted, in others it may be required.
  7973. maxLength: 253
  7974. minLength: 1
  7975. pattern: ^[-._a-zA-Z0-9]+$
  7976. type: string
  7977. name:
  7978. description: The name of the Secret resource being referred to.
  7979. maxLength: 253
  7980. minLength: 1
  7981. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7982. type: string
  7983. namespace:
  7984. description: |-
  7985. The namespace of the Secret resource being referred to.
  7986. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7987. maxLength: 63
  7988. minLength: 1
  7989. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7990. type: string
  7991. type: object
  7992. value:
  7993. description: Value can be specified directly to set a value without using a secret.
  7994. minLength: 1
  7995. type: string
  7996. type: object
  7997. x-kubernetes-validations:
  7998. - message: exactly one of value or secretRef must be set
  7999. rule: has(self.value) != has(self.secretRef)
  8000. username:
  8001. description: |-
  8002. Username is the secret server account username.
  8003. Required unless Token is set.
  8004. properties:
  8005. secretRef:
  8006. description: SecretRef references a key in a secret that will be used as value.
  8007. properties:
  8008. key:
  8009. description: |-
  8010. A key in the referenced Secret.
  8011. Some instances of this field may be defaulted, in others it may be required.
  8012. maxLength: 253
  8013. minLength: 1
  8014. pattern: ^[-._a-zA-Z0-9]+$
  8015. type: string
  8016. name:
  8017. description: The name of the Secret resource being referred to.
  8018. maxLength: 253
  8019. minLength: 1
  8020. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8021. type: string
  8022. namespace:
  8023. description: |-
  8024. The namespace of the Secret resource being referred to.
  8025. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8026. maxLength: 63
  8027. minLength: 1
  8028. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8029. type: string
  8030. type: object
  8031. value:
  8032. description: Value can be specified directly to set a value without using a secret.
  8033. minLength: 1
  8034. type: string
  8035. type: object
  8036. x-kubernetes-validations:
  8037. - message: exactly one of value or secretRef must be set
  8038. rule: has(self.value) != has(self.secretRef)
  8039. required:
  8040. - serverURL
  8041. type: object
  8042. x-kubernetes-validations:
  8043. - message: either token, or both username and password, must be set
  8044. rule: has(self.token) || (has(self.username) && has(self.password))
  8045. senhasegura:
  8046. description: Senhasegura configures this store to sync secrets using senhasegura provider
  8047. properties:
  8048. auth:
  8049. description: Auth defines parameters to authenticate in senhasegura
  8050. properties:
  8051. clientId:
  8052. type: string
  8053. clientSecretSecretRef:
  8054. description: |-
  8055. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8056. In some instances, `key` is a required field.
  8057. properties:
  8058. key:
  8059. description: |-
  8060. A key in the referenced Secret.
  8061. Some instances of this field may be defaulted, in others it may be required.
  8062. maxLength: 253
  8063. minLength: 1
  8064. pattern: ^[-._a-zA-Z0-9]+$
  8065. type: string
  8066. name:
  8067. description: The name of the Secret resource being referred to.
  8068. maxLength: 253
  8069. minLength: 1
  8070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8071. type: string
  8072. namespace:
  8073. description: |-
  8074. The namespace of the Secret resource being referred to.
  8075. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8076. maxLength: 63
  8077. minLength: 1
  8078. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8079. type: string
  8080. type: object
  8081. required:
  8082. - clientId
  8083. - clientSecretSecretRef
  8084. type: object
  8085. ignoreSslCertificate:
  8086. default: false
  8087. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  8088. type: boolean
  8089. module:
  8090. description: Module defines which senhasegura module should be used to get secrets
  8091. type: string
  8092. url:
  8093. description: URL of senhasegura
  8094. type: string
  8095. required:
  8096. - auth
  8097. - module
  8098. - url
  8099. type: object
  8100. vault:
  8101. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  8102. properties:
  8103. auth:
  8104. description: Auth configures how secret-manager authenticates with the Vault server.
  8105. properties:
  8106. appRole:
  8107. description: |-
  8108. AppRole authenticates with Vault using the App Role auth mechanism,
  8109. with the role and secret stored in a Kubernetes Secret resource.
  8110. properties:
  8111. path:
  8112. default: approle
  8113. description: |-
  8114. Path where the App Role authentication backend is mounted
  8115. in Vault, e.g: "approle"
  8116. type: string
  8117. roleId:
  8118. description: |-
  8119. RoleID configured in the App Role authentication backend when setting
  8120. up the authentication backend in Vault.
  8121. type: string
  8122. roleRef:
  8123. description: |-
  8124. Reference to a key in a Secret that contains the App Role ID used
  8125. to authenticate with Vault.
  8126. The `key` field must be specified and denotes which entry within the Secret
  8127. resource is used as the app role id.
  8128. properties:
  8129. key:
  8130. description: |-
  8131. A key in the referenced Secret.
  8132. Some instances of this field may be defaulted, in others it may be required.
  8133. maxLength: 253
  8134. minLength: 1
  8135. pattern: ^[-._a-zA-Z0-9]+$
  8136. type: string
  8137. name:
  8138. description: The name of the Secret resource being referred to.
  8139. maxLength: 253
  8140. minLength: 1
  8141. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8142. type: string
  8143. namespace:
  8144. description: |-
  8145. The namespace of the Secret resource being referred to.
  8146. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8147. maxLength: 63
  8148. minLength: 1
  8149. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8150. type: string
  8151. type: object
  8152. secretRef:
  8153. description: |-
  8154. Reference to a key in a Secret that contains the App Role secret used
  8155. to authenticate with Vault.
  8156. The `key` field must be specified and denotes which entry within the Secret
  8157. resource is used as the app role secret.
  8158. properties:
  8159. key:
  8160. description: |-
  8161. A key in the referenced Secret.
  8162. Some instances of this field may be defaulted, in others it may be required.
  8163. maxLength: 253
  8164. minLength: 1
  8165. pattern: ^[-._a-zA-Z0-9]+$
  8166. type: string
  8167. name:
  8168. description: The name of the Secret resource being referred to.
  8169. maxLength: 253
  8170. minLength: 1
  8171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8172. type: string
  8173. namespace:
  8174. description: |-
  8175. The namespace of the Secret resource being referred to.
  8176. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8177. maxLength: 63
  8178. minLength: 1
  8179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8180. type: string
  8181. type: object
  8182. required:
  8183. - path
  8184. - secretRef
  8185. type: object
  8186. cert:
  8187. description: |-
  8188. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  8189. Cert authentication method
  8190. properties:
  8191. clientCert:
  8192. description: |-
  8193. ClientCert is a certificate to authenticate using the Cert Vault
  8194. authentication method
  8195. properties:
  8196. key:
  8197. description: |-
  8198. A key in the referenced Secret.
  8199. Some instances of this field may be defaulted, in others it may be required.
  8200. maxLength: 253
  8201. minLength: 1
  8202. pattern: ^[-._a-zA-Z0-9]+$
  8203. type: string
  8204. name:
  8205. description: The name of the Secret resource being referred to.
  8206. maxLength: 253
  8207. minLength: 1
  8208. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8209. type: string
  8210. namespace:
  8211. description: |-
  8212. The namespace of the Secret resource being referred to.
  8213. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8214. maxLength: 63
  8215. minLength: 1
  8216. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8217. type: string
  8218. type: object
  8219. path:
  8220. default: cert
  8221. description: |-
  8222. Path where the Certificate authentication backend is mounted
  8223. in Vault, e.g: "cert"
  8224. type: string
  8225. secretRef:
  8226. description: |-
  8227. SecretRef to a key in a Secret resource containing client private key to
  8228. authenticate with Vault using the Cert authentication method
  8229. properties:
  8230. key:
  8231. description: |-
  8232. A key in the referenced Secret.
  8233. Some instances of this field may be defaulted, in others it may be required.
  8234. maxLength: 253
  8235. minLength: 1
  8236. pattern: ^[-._a-zA-Z0-9]+$
  8237. type: string
  8238. name:
  8239. description: The name of the Secret resource being referred to.
  8240. maxLength: 253
  8241. minLength: 1
  8242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8243. type: string
  8244. namespace:
  8245. description: |-
  8246. The namespace of the Secret resource being referred to.
  8247. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8248. maxLength: 63
  8249. minLength: 1
  8250. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8251. type: string
  8252. type: object
  8253. vaultRole:
  8254. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  8255. type: string
  8256. type: object
  8257. gcp:
  8258. description: |-
  8259. Gcp authenticates with Vault using Google Cloud Platform authentication method
  8260. GCP authentication method
  8261. properties:
  8262. location:
  8263. description: Location optionally defines a location/region for the secret
  8264. type: string
  8265. path:
  8266. default: gcp
  8267. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  8268. type: string
  8269. projectID:
  8270. description: Project ID of the Google Cloud Platform project
  8271. type: string
  8272. role:
  8273. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  8274. type: string
  8275. secretRef:
  8276. description: Specify credentials in a Secret object
  8277. properties:
  8278. secretAccessKeySecretRef:
  8279. description: The SecretAccessKey is used for authentication
  8280. properties:
  8281. key:
  8282. description: |-
  8283. A key in the referenced Secret.
  8284. Some instances of this field may be defaulted, in others it may be required.
  8285. maxLength: 253
  8286. minLength: 1
  8287. pattern: ^[-._a-zA-Z0-9]+$
  8288. type: string
  8289. name:
  8290. description: The name of the Secret resource being referred to.
  8291. maxLength: 253
  8292. minLength: 1
  8293. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8294. type: string
  8295. namespace:
  8296. description: |-
  8297. The namespace of the Secret resource being referred to.
  8298. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8299. maxLength: 63
  8300. minLength: 1
  8301. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8302. type: string
  8303. type: object
  8304. type: object
  8305. serviceAccountRef:
  8306. description: ServiceAccountRef to a service account for impersonation
  8307. properties:
  8308. audiences:
  8309. description: |-
  8310. Audience specifies the `aud` claim for the service account token
  8311. Some providers automatically extend the audience field based on well-known annotations for workload
  8312. identity (e.g. IRSA or GCP Workload Identity)
  8313. items:
  8314. type: string
  8315. type: array
  8316. name:
  8317. description: The name of the ServiceAccount resource being referred to.
  8318. maxLength: 253
  8319. minLength: 1
  8320. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8321. type: string
  8322. namespace:
  8323. description: |-
  8324. Namespace of the resource being referred to.
  8325. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8326. maxLength: 63
  8327. minLength: 1
  8328. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8329. type: string
  8330. required:
  8331. - name
  8332. type: object
  8333. workloadIdentity:
  8334. description: Specify a service account with Workload Identity
  8335. properties:
  8336. clusterLocation:
  8337. description: |-
  8338. ClusterLocation is the location of the cluster
  8339. If not specified, it fetches information from the metadata server
  8340. type: string
  8341. clusterName:
  8342. description: |-
  8343. ClusterName is the name of the cluster
  8344. If not specified, it fetches information from the metadata server
  8345. type: string
  8346. clusterProjectID:
  8347. description: |-
  8348. ClusterProjectID is the project ID of the cluster
  8349. If not specified, it fetches information from the metadata server
  8350. type: string
  8351. serviceAccountRef:
  8352. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  8353. properties:
  8354. audiences:
  8355. description: |-
  8356. Audience specifies the `aud` claim for the service account token
  8357. Some providers automatically extend the audience field based on well-known annotations for workload
  8358. identity (e.g. IRSA or GCP Workload Identity)
  8359. items:
  8360. type: string
  8361. type: array
  8362. name:
  8363. description: The name of the ServiceAccount resource being referred to.
  8364. maxLength: 253
  8365. minLength: 1
  8366. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8367. type: string
  8368. namespace:
  8369. description: |-
  8370. Namespace of the resource being referred to.
  8371. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8372. maxLength: 63
  8373. minLength: 1
  8374. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8375. type: string
  8376. required:
  8377. - name
  8378. type: object
  8379. required:
  8380. - serviceAccountRef
  8381. type: object
  8382. required:
  8383. - role
  8384. type: object
  8385. iam:
  8386. description: |-
  8387. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  8388. AWS IAM authentication method
  8389. properties:
  8390. externalID:
  8391. description: AWS External ID set on assumed IAM roles
  8392. type: string
  8393. jwt:
  8394. description: Specify a service account with IRSA enabled
  8395. properties:
  8396. serviceAccountRef:
  8397. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  8398. properties:
  8399. audiences:
  8400. description: |-
  8401. Audience specifies the `aud` claim for the service account token
  8402. Some providers automatically extend the audience field based on well-known annotations for workload
  8403. identity (e.g. IRSA or GCP Workload Identity)
  8404. items:
  8405. type: string
  8406. type: array
  8407. name:
  8408. description: The name of the ServiceAccount resource being referred to.
  8409. maxLength: 253
  8410. minLength: 1
  8411. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8412. type: string
  8413. namespace:
  8414. description: |-
  8415. Namespace of the resource being referred to.
  8416. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8417. maxLength: 63
  8418. minLength: 1
  8419. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8420. type: string
  8421. required:
  8422. - name
  8423. type: object
  8424. type: object
  8425. path:
  8426. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  8427. type: string
  8428. region:
  8429. description: AWS region
  8430. type: string
  8431. role:
  8432. description: This is the AWS role to be assumed before talking to vault
  8433. type: string
  8434. secretRef:
  8435. description: Specify credentials in a Secret object
  8436. properties:
  8437. accessKeyIDSecretRef:
  8438. description: The AccessKeyID is used for authentication
  8439. properties:
  8440. key:
  8441. description: |-
  8442. A key in the referenced Secret.
  8443. Some instances of this field may be defaulted, in others it may be required.
  8444. maxLength: 253
  8445. minLength: 1
  8446. pattern: ^[-._a-zA-Z0-9]+$
  8447. type: string
  8448. name:
  8449. description: The name of the Secret resource being referred to.
  8450. maxLength: 253
  8451. minLength: 1
  8452. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8453. type: string
  8454. namespace:
  8455. description: |-
  8456. The namespace of the Secret resource being referred to.
  8457. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8458. maxLength: 63
  8459. minLength: 1
  8460. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8461. type: string
  8462. type: object
  8463. secretAccessKeySecretRef:
  8464. description: The SecretAccessKey is used for authentication
  8465. properties:
  8466. key:
  8467. description: |-
  8468. A key in the referenced Secret.
  8469. Some instances of this field may be defaulted, in others it may be required.
  8470. maxLength: 253
  8471. minLength: 1
  8472. pattern: ^[-._a-zA-Z0-9]+$
  8473. type: string
  8474. name:
  8475. description: The name of the Secret resource being referred to.
  8476. maxLength: 253
  8477. minLength: 1
  8478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8479. type: string
  8480. namespace:
  8481. description: |-
  8482. The namespace of the Secret resource being referred to.
  8483. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8484. maxLength: 63
  8485. minLength: 1
  8486. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8487. type: string
  8488. type: object
  8489. sessionTokenSecretRef:
  8490. description: |-
  8491. The SessionToken used for authentication
  8492. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  8493. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  8494. properties:
  8495. key:
  8496. description: |-
  8497. A key in the referenced Secret.
  8498. Some instances of this field may be defaulted, in others it may be required.
  8499. maxLength: 253
  8500. minLength: 1
  8501. pattern: ^[-._a-zA-Z0-9]+$
  8502. type: string
  8503. name:
  8504. description: The name of the Secret resource being referred to.
  8505. maxLength: 253
  8506. minLength: 1
  8507. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8508. type: string
  8509. namespace:
  8510. description: |-
  8511. The namespace of the Secret resource being referred to.
  8512. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8513. maxLength: 63
  8514. minLength: 1
  8515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8516. type: string
  8517. type: object
  8518. type: object
  8519. vaultAwsIamServerID:
  8520. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  8521. type: string
  8522. vaultRole:
  8523. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  8524. type: string
  8525. required:
  8526. - vaultRole
  8527. type: object
  8528. jwt:
  8529. description: |-
  8530. Jwt authenticates with Vault by passing role and JWT token using the
  8531. JWT/OIDC authentication method
  8532. properties:
  8533. kubernetesServiceAccountToken:
  8534. description: |-
  8535. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  8536. a token for with the `TokenRequest` API.
  8537. properties:
  8538. audiences:
  8539. description: |-
  8540. Optional audiences field that will be used to request a temporary Kubernetes service
  8541. account token for the service account referenced by `serviceAccountRef`.
  8542. Defaults to a single audience `vault` it not specified.
  8543. Deprecated: use serviceAccountRef.Audiences instead
  8544. items:
  8545. type: string
  8546. type: array
  8547. expirationSeconds:
  8548. description: |-
  8549. Optional expiration time in seconds that will be used to request a temporary
  8550. Kubernetes service account token for the service account referenced by
  8551. `serviceAccountRef`.
  8552. Deprecated: this will be removed in the future.
  8553. Defaults to 10 minutes.
  8554. format: int64
  8555. type: integer
  8556. serviceAccountRef:
  8557. description: Service account field containing the name of a kubernetes ServiceAccount.
  8558. properties:
  8559. audiences:
  8560. description: |-
  8561. Audience specifies the `aud` claim for the service account token
  8562. Some providers automatically extend the audience field based on well-known annotations for workload
  8563. identity (e.g. IRSA or GCP Workload Identity)
  8564. items:
  8565. type: string
  8566. type: array
  8567. name:
  8568. description: The name of the ServiceAccount resource being referred to.
  8569. maxLength: 253
  8570. minLength: 1
  8571. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8572. type: string
  8573. namespace:
  8574. description: |-
  8575. Namespace of the resource being referred to.
  8576. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8577. maxLength: 63
  8578. minLength: 1
  8579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8580. type: string
  8581. required:
  8582. - name
  8583. type: object
  8584. required:
  8585. - serviceAccountRef
  8586. type: object
  8587. path:
  8588. default: jwt
  8589. description: |-
  8590. Path where the JWT authentication backend is mounted
  8591. in Vault, e.g: "jwt"
  8592. type: string
  8593. role:
  8594. description: |-
  8595. Role is a JWT role to authenticate using the JWT/OIDC Vault
  8596. authentication method
  8597. type: string
  8598. secretRef:
  8599. description: |-
  8600. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  8601. authenticate with Vault using the JWT/OIDC authentication method.
  8602. properties:
  8603. key:
  8604. description: |-
  8605. A key in the referenced Secret.
  8606. Some instances of this field may be defaulted, in others it may be required.
  8607. maxLength: 253
  8608. minLength: 1
  8609. pattern: ^[-._a-zA-Z0-9]+$
  8610. type: string
  8611. name:
  8612. description: The name of the Secret resource being referred to.
  8613. maxLength: 253
  8614. minLength: 1
  8615. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8616. type: string
  8617. namespace:
  8618. description: |-
  8619. The namespace of the Secret resource being referred to.
  8620. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8621. maxLength: 63
  8622. minLength: 1
  8623. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8624. type: string
  8625. type: object
  8626. required:
  8627. - path
  8628. type: object
  8629. kubernetes:
  8630. description: |-
  8631. Kubernetes authenticates with Vault by passing the ServiceAccount
  8632. token stored in the named Secret resource to the Vault server.
  8633. properties:
  8634. mountPath:
  8635. default: kubernetes
  8636. description: |-
  8637. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  8638. "kubernetes"
  8639. type: string
  8640. role:
  8641. description: |-
  8642. A required field containing the Vault Role to assume. A Role binds a
  8643. Kubernetes ServiceAccount with a set of Vault policies.
  8644. type: string
  8645. secretRef:
  8646. description: |-
  8647. Optional secret field containing a Kubernetes ServiceAccount JWT used
  8648. for authenticating with Vault. If a name is specified without a key,
  8649. `token` is the default. If one is not specified, the one bound to
  8650. the controller will be used.
  8651. properties:
  8652. key:
  8653. description: |-
  8654. A key in the referenced Secret.
  8655. Some instances of this field may be defaulted, in others it may be required.
  8656. maxLength: 253
  8657. minLength: 1
  8658. pattern: ^[-._a-zA-Z0-9]+$
  8659. type: string
  8660. name:
  8661. description: The name of the Secret resource being referred to.
  8662. maxLength: 253
  8663. minLength: 1
  8664. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8665. type: string
  8666. namespace:
  8667. description: |-
  8668. The namespace of the Secret resource being referred to.
  8669. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8670. maxLength: 63
  8671. minLength: 1
  8672. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8673. type: string
  8674. type: object
  8675. serviceAccountRef:
  8676. description: |-
  8677. Optional service account field containing the name of a kubernetes ServiceAccount.
  8678. If the service account is specified, the service account secret token JWT will be used
  8679. for authenticating with Vault. If the service account selector is not supplied,
  8680. the secretRef will be used instead.
  8681. properties:
  8682. audiences:
  8683. description: |-
  8684. Audience specifies the `aud` claim for the service account token
  8685. Some providers automatically extend the audience field based on well-known annotations for workload
  8686. identity (e.g. IRSA or GCP Workload Identity)
  8687. items:
  8688. type: string
  8689. type: array
  8690. name:
  8691. description: The name of the ServiceAccount resource being referred to.
  8692. maxLength: 253
  8693. minLength: 1
  8694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8695. type: string
  8696. namespace:
  8697. description: |-
  8698. Namespace of the resource being referred to.
  8699. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8700. maxLength: 63
  8701. minLength: 1
  8702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8703. type: string
  8704. required:
  8705. - name
  8706. type: object
  8707. required:
  8708. - mountPath
  8709. - role
  8710. type: object
  8711. ldap:
  8712. description: |-
  8713. Ldap authenticates with Vault by passing username/password pair using
  8714. the LDAP authentication method
  8715. properties:
  8716. path:
  8717. default: ldap
  8718. description: |-
  8719. Path where the LDAP authentication backend is mounted
  8720. in Vault, e.g: "ldap"
  8721. type: string
  8722. secretRef:
  8723. description: |-
  8724. SecretRef to a key in a Secret resource containing password for the LDAP
  8725. user used to authenticate with Vault using the LDAP authentication
  8726. method
  8727. properties:
  8728. key:
  8729. description: |-
  8730. A key in the referenced Secret.
  8731. Some instances of this field may be defaulted, in others it may be required.
  8732. maxLength: 253
  8733. minLength: 1
  8734. pattern: ^[-._a-zA-Z0-9]+$
  8735. type: string
  8736. name:
  8737. description: The name of the Secret resource being referred to.
  8738. maxLength: 253
  8739. minLength: 1
  8740. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8741. type: string
  8742. namespace:
  8743. description: |-
  8744. The namespace of the Secret resource being referred to.
  8745. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8746. maxLength: 63
  8747. minLength: 1
  8748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8749. type: string
  8750. type: object
  8751. username:
  8752. description: |-
  8753. Username is an LDAP username used to authenticate using the LDAP Vault
  8754. authentication method
  8755. type: string
  8756. required:
  8757. - path
  8758. - username
  8759. type: object
  8760. namespace:
  8761. description: |-
  8762. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  8763. Namespaces is a set of features within Vault Enterprise that allows
  8764. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8765. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8766. This will default to Vault.Namespace field if set, or empty otherwise
  8767. type: string
  8768. tokenSecretRef:
  8769. description: TokenSecretRef authenticates with Vault by presenting a token.
  8770. properties:
  8771. key:
  8772. description: |-
  8773. A key in the referenced Secret.
  8774. Some instances of this field may be defaulted, in others it may be required.
  8775. maxLength: 253
  8776. minLength: 1
  8777. pattern: ^[-._a-zA-Z0-9]+$
  8778. type: string
  8779. name:
  8780. description: The name of the Secret resource being referred to.
  8781. maxLength: 253
  8782. minLength: 1
  8783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8784. type: string
  8785. namespace:
  8786. description: |-
  8787. The namespace of the Secret resource being referred to.
  8788. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8789. maxLength: 63
  8790. minLength: 1
  8791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8792. type: string
  8793. type: object
  8794. userPass:
  8795. description: UserPass authenticates with Vault by passing username/password pair
  8796. properties:
  8797. path:
  8798. default: userpass
  8799. description: |-
  8800. Path where the UserPassword authentication backend is mounted
  8801. in Vault, e.g: "userpass"
  8802. type: string
  8803. secretRef:
  8804. description: |-
  8805. SecretRef to a key in a Secret resource containing password for the
  8806. user used to authenticate with Vault using the UserPass authentication
  8807. method
  8808. properties:
  8809. key:
  8810. description: |-
  8811. A key in the referenced Secret.
  8812. Some instances of this field may be defaulted, in others it may be required.
  8813. maxLength: 253
  8814. minLength: 1
  8815. pattern: ^[-._a-zA-Z0-9]+$
  8816. type: string
  8817. name:
  8818. description: The name of the Secret resource being referred to.
  8819. maxLength: 253
  8820. minLength: 1
  8821. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8822. type: string
  8823. namespace:
  8824. description: |-
  8825. The namespace of the Secret resource being referred to.
  8826. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8827. maxLength: 63
  8828. minLength: 1
  8829. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8830. type: string
  8831. type: object
  8832. username:
  8833. description: |-
  8834. Username is a username used to authenticate using the UserPass Vault
  8835. authentication method
  8836. type: string
  8837. required:
  8838. - path
  8839. - username
  8840. type: object
  8841. type: object
  8842. caBundle:
  8843. description: |-
  8844. PEM encoded CA bundle used to validate Vault server certificate. Only used
  8845. if the Server URL is using HTTPS protocol. This parameter is ignored for
  8846. plain HTTP protocol connection. If not set the system root certificates
  8847. are used to validate the TLS connection.
  8848. format: byte
  8849. type: string
  8850. caProvider:
  8851. description: The provider for the CA bundle to use to validate Vault server certificate.
  8852. properties:
  8853. key:
  8854. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8855. maxLength: 253
  8856. minLength: 1
  8857. pattern: ^[-._a-zA-Z0-9]+$
  8858. type: string
  8859. name:
  8860. description: The name of the object located at the provider type.
  8861. maxLength: 253
  8862. minLength: 1
  8863. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8864. type: string
  8865. namespace:
  8866. description: |-
  8867. The namespace the Provider type is in.
  8868. Can only be defined when used in a ClusterSecretStore.
  8869. maxLength: 63
  8870. minLength: 1
  8871. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8872. type: string
  8873. type:
  8874. description: The type of provider to use such as "Secret", or "ConfigMap".
  8875. enum:
  8876. - Secret
  8877. - ConfigMap
  8878. type: string
  8879. required:
  8880. - name
  8881. - type
  8882. type: object
  8883. checkAndSet:
  8884. description: |-
  8885. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  8886. Only applies to Vault KV v2 stores. When enabled, write operations must include
  8887. the current version of the secret to prevent unintentional overwrites.
  8888. properties:
  8889. required:
  8890. description: |-
  8891. Required when true, all write operations must include a check-and-set parameter.
  8892. This helps prevent unintentional overwrites of secrets.
  8893. type: boolean
  8894. type: object
  8895. forwardInconsistent:
  8896. description: |-
  8897. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  8898. leader instead of simply retrying within a loop. This can increase performance if
  8899. the option is enabled serverside.
  8900. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  8901. type: boolean
  8902. headers:
  8903. additionalProperties:
  8904. type: string
  8905. description: Headers to be added in Vault request
  8906. type: object
  8907. namespace:
  8908. description: |-
  8909. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  8910. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8911. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8912. type: string
  8913. path:
  8914. description: |-
  8915. Path is the mount path of the Vault KV backend endpoint, e.g:
  8916. "secret". The v2 KV secret engine version specific "/data" path suffix
  8917. for fetching secrets from Vault is optional and will be appended
  8918. if not present in specified path.
  8919. type: string
  8920. readYourWrites:
  8921. description: |-
  8922. ReadYourWrites ensures isolated read-after-write semantics by
  8923. providing discovered cluster replication states in each request.
  8924. More information about eventual consistency in Vault can be found here
  8925. https://www.vaultproject.io/docs/enterprise/consistency
  8926. type: boolean
  8927. server:
  8928. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  8929. type: string
  8930. tls:
  8931. description: |-
  8932. The configuration used for client side related TLS communication, when the Vault server
  8933. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  8934. This parameter is ignored for plain HTTP protocol connection.
  8935. It's worth noting this configuration is different from the "TLS certificates auth method",
  8936. which is available under the `auth.cert` section.
  8937. properties:
  8938. certSecretRef:
  8939. description: |-
  8940. CertSecretRef is a certificate added to the transport layer
  8941. when communicating with the Vault server.
  8942. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  8943. properties:
  8944. key:
  8945. description: |-
  8946. A key in the referenced Secret.
  8947. Some instances of this field may be defaulted, in others it may be required.
  8948. maxLength: 253
  8949. minLength: 1
  8950. pattern: ^[-._a-zA-Z0-9]+$
  8951. type: string
  8952. name:
  8953. description: The name of the Secret resource being referred to.
  8954. maxLength: 253
  8955. minLength: 1
  8956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8957. type: string
  8958. namespace:
  8959. description: |-
  8960. The namespace of the Secret resource being referred to.
  8961. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8962. maxLength: 63
  8963. minLength: 1
  8964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8965. type: string
  8966. type: object
  8967. keySecretRef:
  8968. description: |-
  8969. KeySecretRef to a key in a Secret resource containing client private key
  8970. added to the transport layer when communicating with the Vault server.
  8971. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  8972. properties:
  8973. key:
  8974. description: |-
  8975. A key in the referenced Secret.
  8976. Some instances of this field may be defaulted, in others it may be required.
  8977. maxLength: 253
  8978. minLength: 1
  8979. pattern: ^[-._a-zA-Z0-9]+$
  8980. type: string
  8981. name:
  8982. description: The name of the Secret resource being referred to.
  8983. maxLength: 253
  8984. minLength: 1
  8985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8986. type: string
  8987. namespace:
  8988. description: |-
  8989. The namespace of the Secret resource being referred to.
  8990. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8991. maxLength: 63
  8992. minLength: 1
  8993. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8994. type: string
  8995. type: object
  8996. type: object
  8997. version:
  8998. default: v2
  8999. description: |-
  9000. Version is the Vault KV secret engine version. This can be either "v1" or
  9001. "v2". Version defaults to "v2".
  9002. enum:
  9003. - v1
  9004. - v2
  9005. type: string
  9006. required:
  9007. - server
  9008. type: object
  9009. volcengine:
  9010. description: Volcengine configures this store to sync secrets using the Volcengine provider
  9011. properties:
  9012. auth:
  9013. description: |-
  9014. Auth defines the authentication method to use.
  9015. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  9016. properties:
  9017. secretRef:
  9018. description: |-
  9019. SecretRef defines the static credentials to use for authentication.
  9020. If not set, IRSA is used.
  9021. properties:
  9022. accessKeyID:
  9023. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  9024. properties:
  9025. key:
  9026. description: |-
  9027. A key in the referenced Secret.
  9028. Some instances of this field may be defaulted, in others it may be required.
  9029. maxLength: 253
  9030. minLength: 1
  9031. pattern: ^[-._a-zA-Z0-9]+$
  9032. type: string
  9033. name:
  9034. description: The name of the Secret resource being referred to.
  9035. maxLength: 253
  9036. minLength: 1
  9037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9038. type: string
  9039. namespace:
  9040. description: |-
  9041. The namespace of the Secret resource being referred to.
  9042. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9043. maxLength: 63
  9044. minLength: 1
  9045. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9046. type: string
  9047. type: object
  9048. secretAccessKey:
  9049. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  9050. properties:
  9051. key:
  9052. description: |-
  9053. A key in the referenced Secret.
  9054. Some instances of this field may be defaulted, in others it may be required.
  9055. maxLength: 253
  9056. minLength: 1
  9057. pattern: ^[-._a-zA-Z0-9]+$
  9058. type: string
  9059. name:
  9060. description: The name of the Secret resource being referred to.
  9061. maxLength: 253
  9062. minLength: 1
  9063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9064. type: string
  9065. namespace:
  9066. description: |-
  9067. The namespace of the Secret resource being referred to.
  9068. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9069. maxLength: 63
  9070. minLength: 1
  9071. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9072. type: string
  9073. type: object
  9074. token:
  9075. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  9076. properties:
  9077. key:
  9078. description: |-
  9079. A key in the referenced Secret.
  9080. Some instances of this field may be defaulted, in others it may be required.
  9081. maxLength: 253
  9082. minLength: 1
  9083. pattern: ^[-._a-zA-Z0-9]+$
  9084. type: string
  9085. name:
  9086. description: The name of the Secret resource being referred to.
  9087. maxLength: 253
  9088. minLength: 1
  9089. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9090. type: string
  9091. namespace:
  9092. description: |-
  9093. The namespace of the Secret resource being referred to.
  9094. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9095. maxLength: 63
  9096. minLength: 1
  9097. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9098. type: string
  9099. type: object
  9100. required:
  9101. - accessKeyID
  9102. - secretAccessKey
  9103. type: object
  9104. type: object
  9105. region:
  9106. description: Region specifies the Volcengine region to connect to.
  9107. type: string
  9108. required:
  9109. - region
  9110. type: object
  9111. webhook:
  9112. description: Webhook configures this store to sync secrets using a generic templated webhook
  9113. properties:
  9114. auth:
  9115. description: Auth specifies a authorization protocol. Only one protocol may be set.
  9116. maxProperties: 1
  9117. minProperties: 1
  9118. properties:
  9119. ntlm:
  9120. description: NTLMProtocol configures the store to use NTLM for auth
  9121. properties:
  9122. passwordSecret:
  9123. description: |-
  9124. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9125. In some instances, `key` is a required field.
  9126. properties:
  9127. key:
  9128. description: |-
  9129. A key in the referenced Secret.
  9130. Some instances of this field may be defaulted, in others it may be required.
  9131. maxLength: 253
  9132. minLength: 1
  9133. pattern: ^[-._a-zA-Z0-9]+$
  9134. type: string
  9135. name:
  9136. description: The name of the Secret resource being referred to.
  9137. maxLength: 253
  9138. minLength: 1
  9139. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9140. type: string
  9141. namespace:
  9142. description: |-
  9143. The namespace of the Secret resource being referred to.
  9144. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9145. maxLength: 63
  9146. minLength: 1
  9147. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9148. type: string
  9149. type: object
  9150. usernameSecret:
  9151. description: |-
  9152. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9153. In some instances, `key` is a required field.
  9154. properties:
  9155. key:
  9156. description: |-
  9157. A key in the referenced Secret.
  9158. Some instances of this field may be defaulted, in others it may be required.
  9159. maxLength: 253
  9160. minLength: 1
  9161. pattern: ^[-._a-zA-Z0-9]+$
  9162. type: string
  9163. name:
  9164. description: The name of the Secret resource being referred to.
  9165. maxLength: 253
  9166. minLength: 1
  9167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9168. type: string
  9169. namespace:
  9170. description: |-
  9171. The namespace of the Secret resource being referred to.
  9172. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9173. maxLength: 63
  9174. minLength: 1
  9175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9176. type: string
  9177. type: object
  9178. required:
  9179. - passwordSecret
  9180. - usernameSecret
  9181. type: object
  9182. type: object
  9183. body:
  9184. description: Body
  9185. type: string
  9186. caBundle:
  9187. description: |-
  9188. PEM encoded CA bundle used to validate webhook server certificate. Only used
  9189. if the Server URL is using HTTPS protocol. This parameter is ignored for
  9190. plain HTTP protocol connection. If not set the system root certificates
  9191. are used to validate the TLS connection.
  9192. format: byte
  9193. type: string
  9194. caProvider:
  9195. description: The provider for the CA bundle to use to validate webhook server certificate.
  9196. properties:
  9197. key:
  9198. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9199. maxLength: 253
  9200. minLength: 1
  9201. pattern: ^[-._a-zA-Z0-9]+$
  9202. type: string
  9203. name:
  9204. description: The name of the object located at the provider type.
  9205. maxLength: 253
  9206. minLength: 1
  9207. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9208. type: string
  9209. namespace:
  9210. description: The namespace the Provider type is in.
  9211. maxLength: 63
  9212. minLength: 1
  9213. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9214. type: string
  9215. type:
  9216. description: The type of provider to use such as "Secret", or "ConfigMap".
  9217. enum:
  9218. - Secret
  9219. - ConfigMap
  9220. type: string
  9221. required:
  9222. - name
  9223. - type
  9224. type: object
  9225. headers:
  9226. additionalProperties:
  9227. type: string
  9228. description: Headers
  9229. type: object
  9230. method:
  9231. description: Webhook Method
  9232. type: string
  9233. result:
  9234. description: Result formatting
  9235. properties:
  9236. jsonPath:
  9237. description: Json path of return value
  9238. type: string
  9239. type: object
  9240. secrets:
  9241. description: |-
  9242. Secrets to fill in templates
  9243. These secrets will be passed to the templating function as key value pairs under the given name
  9244. items:
  9245. description: WebhookSecret defines a secret that will be passed to the webhook request.
  9246. properties:
  9247. name:
  9248. description: Name of this secret in templates
  9249. type: string
  9250. secretRef:
  9251. description: Secret ref to fill in credentials
  9252. properties:
  9253. key:
  9254. description: |-
  9255. A key in the referenced Secret.
  9256. Some instances of this field may be defaulted, in others it may be required.
  9257. maxLength: 253
  9258. minLength: 1
  9259. pattern: ^[-._a-zA-Z0-9]+$
  9260. type: string
  9261. name:
  9262. description: The name of the Secret resource being referred to.
  9263. maxLength: 253
  9264. minLength: 1
  9265. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9266. type: string
  9267. namespace:
  9268. description: |-
  9269. The namespace of the Secret resource being referred to.
  9270. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9271. maxLength: 63
  9272. minLength: 1
  9273. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9274. type: string
  9275. type: object
  9276. required:
  9277. - name
  9278. - secretRef
  9279. type: object
  9280. type: array
  9281. timeout:
  9282. description: Timeout
  9283. type: string
  9284. url:
  9285. description: Webhook url to call
  9286. type: string
  9287. required:
  9288. - url
  9289. type: object
  9290. yandexcertificatemanager:
  9291. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  9292. properties:
  9293. apiEndpoint:
  9294. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9295. type: string
  9296. auth:
  9297. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  9298. properties:
  9299. authorizedKeySecretRef:
  9300. description: The authorized key used for authentication
  9301. properties:
  9302. key:
  9303. description: |-
  9304. A key in the referenced Secret.
  9305. Some instances of this field may be defaulted, in others it may be required.
  9306. maxLength: 253
  9307. minLength: 1
  9308. pattern: ^[-._a-zA-Z0-9]+$
  9309. type: string
  9310. name:
  9311. description: The name of the Secret resource being referred to.
  9312. maxLength: 253
  9313. minLength: 1
  9314. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9315. type: string
  9316. namespace:
  9317. description: |-
  9318. The namespace of the Secret resource being referred to.
  9319. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9320. maxLength: 63
  9321. minLength: 1
  9322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9323. type: string
  9324. type: object
  9325. type: object
  9326. caProvider:
  9327. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9328. properties:
  9329. certSecretRef:
  9330. description: |-
  9331. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9332. In some instances, `key` is a required field.
  9333. properties:
  9334. key:
  9335. description: |-
  9336. A key in the referenced Secret.
  9337. Some instances of this field may be defaulted, in others it may be required.
  9338. maxLength: 253
  9339. minLength: 1
  9340. pattern: ^[-._a-zA-Z0-9]+$
  9341. type: string
  9342. name:
  9343. description: The name of the Secret resource being referred to.
  9344. maxLength: 253
  9345. minLength: 1
  9346. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9347. type: string
  9348. namespace:
  9349. description: |-
  9350. The namespace of the Secret resource being referred to.
  9351. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9352. maxLength: 63
  9353. minLength: 1
  9354. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9355. type: string
  9356. type: object
  9357. type: object
  9358. fetching:
  9359. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  9360. maxProperties: 1
  9361. minProperties: 1
  9362. properties:
  9363. byID:
  9364. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  9365. type: object
  9366. byName:
  9367. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  9368. properties:
  9369. folderID:
  9370. description: The folder to fetch secrets from
  9371. type: string
  9372. required:
  9373. - folderID
  9374. type: object
  9375. type: object
  9376. required:
  9377. - auth
  9378. type: object
  9379. yandexlockbox:
  9380. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  9381. properties:
  9382. apiEndpoint:
  9383. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9384. type: string
  9385. auth:
  9386. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  9387. properties:
  9388. authorizedKeySecretRef:
  9389. description: The authorized key used for authentication
  9390. properties:
  9391. key:
  9392. description: |-
  9393. A key in the referenced Secret.
  9394. Some instances of this field may be defaulted, in others it may be required.
  9395. maxLength: 253
  9396. minLength: 1
  9397. pattern: ^[-._a-zA-Z0-9]+$
  9398. type: string
  9399. name:
  9400. description: The name of the Secret resource being referred to.
  9401. maxLength: 253
  9402. minLength: 1
  9403. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9404. type: string
  9405. namespace:
  9406. description: |-
  9407. The namespace of the Secret resource being referred to.
  9408. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9409. maxLength: 63
  9410. minLength: 1
  9411. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9412. type: string
  9413. type: object
  9414. type: object
  9415. caProvider:
  9416. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9417. properties:
  9418. certSecretRef:
  9419. description: |-
  9420. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9421. In some instances, `key` is a required field.
  9422. properties:
  9423. key:
  9424. description: |-
  9425. A key in the referenced Secret.
  9426. Some instances of this field may be defaulted, in others it may be required.
  9427. maxLength: 253
  9428. minLength: 1
  9429. pattern: ^[-._a-zA-Z0-9]+$
  9430. type: string
  9431. name:
  9432. description: The name of the Secret resource being referred to.
  9433. maxLength: 253
  9434. minLength: 1
  9435. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9436. type: string
  9437. namespace:
  9438. description: |-
  9439. The namespace of the Secret resource being referred to.
  9440. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9441. maxLength: 63
  9442. minLength: 1
  9443. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9444. type: string
  9445. type: object
  9446. type: object
  9447. fetching:
  9448. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  9449. maxProperties: 1
  9450. minProperties: 1
  9451. properties:
  9452. byID:
  9453. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  9454. type: object
  9455. byName:
  9456. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  9457. properties:
  9458. folderID:
  9459. description: The folder to fetch secrets from
  9460. type: string
  9461. required:
  9462. - folderID
  9463. type: object
  9464. type: object
  9465. required:
  9466. - auth
  9467. type: object
  9468. type: object
  9469. refreshInterval:
  9470. anyOf:
  9471. - type: integer
  9472. - type: string
  9473. description: |-
  9474. Used to configure store refresh interval. Accepts either an integer number
  9475. of seconds (legacy) or a Go duration string such as "1h" or "5m". Empty or
  9476. 0 will default to the controller config.
  9477. x-kubernetes-int-or-string: true
  9478. retrySettings:
  9479. description: Used to configure HTTP retries on failures.
  9480. properties:
  9481. maxRetries:
  9482. format: int32
  9483. type: integer
  9484. retryInterval:
  9485. type: string
  9486. type: object
  9487. required:
  9488. - provider
  9489. type: object
  9490. status:
  9491. description: SecretStoreStatus defines the observed state of the SecretStore.
  9492. properties:
  9493. capabilities:
  9494. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  9495. type: string
  9496. conditions:
  9497. items:
  9498. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  9499. properties:
  9500. lastTransitionTime:
  9501. format: date-time
  9502. type: string
  9503. message:
  9504. type: string
  9505. reason:
  9506. type: string
  9507. status:
  9508. type: string
  9509. type:
  9510. description: SecretStoreConditionType represents the condition of the SecretStore.
  9511. type: string
  9512. required:
  9513. - status
  9514. - type
  9515. type: object
  9516. type: array
  9517. type: object
  9518. type: object
  9519. served: true
  9520. storage: true
  9521. subresources:
  9522. status: {}
  9523. - additionalPrinterColumns:
  9524. - jsonPath: .metadata.creationTimestamp
  9525. name: AGE
  9526. type: date
  9527. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  9528. name: Status
  9529. type: string
  9530. - jsonPath: .status.capabilities
  9531. name: Capabilities
  9532. type: string
  9533. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  9534. name: Ready
  9535. type: string
  9536. deprecated: true
  9537. name: v1beta1
  9538. schema:
  9539. openAPIV3Schema:
  9540. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  9541. properties:
  9542. apiVersion:
  9543. description: |-
  9544. APIVersion defines the versioned schema of this representation of an object.
  9545. Servers should convert recognized schemas to the latest internal value, and
  9546. may reject unrecognized values.
  9547. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  9548. type: string
  9549. kind:
  9550. description: |-
  9551. Kind is a string value representing the REST resource this object represents.
  9552. Servers may infer this from the endpoint the client submits requests to.
  9553. Cannot be updated.
  9554. In CamelCase.
  9555. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  9556. type: string
  9557. metadata:
  9558. type: object
  9559. spec:
  9560. description: SecretStoreSpec defines the desired state of SecretStore.
  9561. properties:
  9562. conditions:
  9563. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  9564. items:
  9565. description: |-
  9566. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  9567. for a ClusterSecretStore instance.
  9568. properties:
  9569. namespaceRegexes:
  9570. description: Choose namespaces by using regex matching
  9571. items:
  9572. type: string
  9573. type: array
  9574. namespaceSelector:
  9575. description: Choose namespace using a labelSelector
  9576. properties:
  9577. matchExpressions:
  9578. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  9579. items:
  9580. description: |-
  9581. A label selector requirement is a selector that contains values, a key, and an operator that
  9582. relates the key and values.
  9583. properties:
  9584. key:
  9585. description: key is the label key that the selector applies to.
  9586. type: string
  9587. operator:
  9588. description: |-
  9589. operator represents a key's relationship to a set of values.
  9590. Valid operators are In, NotIn, Exists and DoesNotExist.
  9591. type: string
  9592. values:
  9593. description: |-
  9594. values is an array of string values. If the operator is In or NotIn,
  9595. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  9596. the values array must be empty. This array is replaced during a strategic
  9597. merge patch.
  9598. items:
  9599. type: string
  9600. type: array
  9601. x-kubernetes-list-type: atomic
  9602. required:
  9603. - key
  9604. - operator
  9605. type: object
  9606. type: array
  9607. x-kubernetes-list-type: atomic
  9608. matchLabels:
  9609. additionalProperties:
  9610. type: string
  9611. description: |-
  9612. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  9613. map is equivalent to an element of matchExpressions, whose key field is "key", the
  9614. operator is "In", and the values array contains only "value". The requirements are ANDed.
  9615. type: object
  9616. type: object
  9617. x-kubernetes-map-type: atomic
  9618. namespaces:
  9619. description: Choose namespaces by name
  9620. items:
  9621. maxLength: 63
  9622. minLength: 1
  9623. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9624. type: string
  9625. type: array
  9626. type: object
  9627. type: array
  9628. controller:
  9629. description: |-
  9630. Used to select the correct ESO controller (think: ingress.ingressClassName)
  9631. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  9632. type: string
  9633. provider:
  9634. description: Used to configure the provider. Only one provider may be set
  9635. maxProperties: 1
  9636. minProperties: 1
  9637. properties:
  9638. akeyless:
  9639. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  9640. properties:
  9641. akeylessGWApiURL:
  9642. description: Akeyless GW API Url from which the secrets to be fetched from.
  9643. type: string
  9644. authSecretRef:
  9645. description: Auth configures how the operator authenticates with Akeyless.
  9646. properties:
  9647. kubernetesAuth:
  9648. description: |-
  9649. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  9650. token stored in the named Secret resource.
  9651. properties:
  9652. accessID:
  9653. description: the Akeyless Kubernetes auth-method access-id
  9654. type: string
  9655. k8sConfName:
  9656. description: Kubernetes-auth configuration name in Akeyless-Gateway
  9657. type: string
  9658. secretRef:
  9659. description: |-
  9660. Optional secret field containing a Kubernetes ServiceAccount JWT used
  9661. for authenticating with Akeyless. If a name is specified without a key,
  9662. `token` is the default. If one is not specified, the one bound to
  9663. the controller will be used.
  9664. properties:
  9665. key:
  9666. description: |-
  9667. A key in the referenced Secret.
  9668. Some instances of this field may be defaulted, in others it may be required.
  9669. maxLength: 253
  9670. minLength: 1
  9671. pattern: ^[-._a-zA-Z0-9]+$
  9672. type: string
  9673. name:
  9674. description: The name of the Secret resource being referred to.
  9675. maxLength: 253
  9676. minLength: 1
  9677. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9678. type: string
  9679. namespace:
  9680. description: |-
  9681. The namespace of the Secret resource being referred to.
  9682. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9683. maxLength: 63
  9684. minLength: 1
  9685. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9686. type: string
  9687. type: object
  9688. serviceAccountRef:
  9689. description: |-
  9690. Optional service account field containing the name of a kubernetes ServiceAccount.
  9691. If the service account is specified, the service account secret token JWT will be used
  9692. for authenticating with Akeyless. If the service account selector is not supplied,
  9693. the secretRef will be used instead.
  9694. properties:
  9695. audiences:
  9696. description: |-
  9697. Audience specifies the `aud` claim for the service account token
  9698. Some providers automatically extend the audience field based on well-known annotations for workload
  9699. identity (e.g. IRSA or GCP Workload Identity)
  9700. items:
  9701. type: string
  9702. type: array
  9703. name:
  9704. description: The name of the ServiceAccount resource being referred to.
  9705. maxLength: 253
  9706. minLength: 1
  9707. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9708. type: string
  9709. namespace:
  9710. description: |-
  9711. Namespace of the resource being referred to.
  9712. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9713. maxLength: 63
  9714. minLength: 1
  9715. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9716. type: string
  9717. required:
  9718. - name
  9719. type: object
  9720. required:
  9721. - accessID
  9722. - k8sConfName
  9723. type: object
  9724. secretRef:
  9725. description: |-
  9726. Reference to a Secret that contains the details
  9727. to authenticate with Akeyless.
  9728. properties:
  9729. accessID:
  9730. description: The SecretAccessID is used for authentication
  9731. properties:
  9732. key:
  9733. description: |-
  9734. A key in the referenced Secret.
  9735. Some instances of this field may be defaulted, in others it may be required.
  9736. maxLength: 253
  9737. minLength: 1
  9738. pattern: ^[-._a-zA-Z0-9]+$
  9739. type: string
  9740. name:
  9741. description: The name of the Secret resource being referred to.
  9742. maxLength: 253
  9743. minLength: 1
  9744. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9745. type: string
  9746. namespace:
  9747. description: |-
  9748. The namespace of the Secret resource being referred to.
  9749. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9750. maxLength: 63
  9751. minLength: 1
  9752. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9753. type: string
  9754. type: object
  9755. accessType:
  9756. description: |-
  9757. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9758. In some instances, `key` is a required field.
  9759. properties:
  9760. key:
  9761. description: |-
  9762. A key in the referenced Secret.
  9763. Some instances of this field may be defaulted, in others it may be required.
  9764. maxLength: 253
  9765. minLength: 1
  9766. pattern: ^[-._a-zA-Z0-9]+$
  9767. type: string
  9768. name:
  9769. description: The name of the Secret resource being referred to.
  9770. maxLength: 253
  9771. minLength: 1
  9772. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9773. type: string
  9774. namespace:
  9775. description: |-
  9776. The namespace of the Secret resource being referred to.
  9777. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9778. maxLength: 63
  9779. minLength: 1
  9780. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9781. type: string
  9782. type: object
  9783. accessTypeParam:
  9784. description: |-
  9785. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9786. In some instances, `key` is a required field.
  9787. properties:
  9788. key:
  9789. description: |-
  9790. A key in the referenced Secret.
  9791. Some instances of this field may be defaulted, in others it may be required.
  9792. maxLength: 253
  9793. minLength: 1
  9794. pattern: ^[-._a-zA-Z0-9]+$
  9795. type: string
  9796. name:
  9797. description: The name of the Secret resource being referred to.
  9798. maxLength: 253
  9799. minLength: 1
  9800. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9801. type: string
  9802. namespace:
  9803. description: |-
  9804. The namespace of the Secret resource being referred to.
  9805. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9806. maxLength: 63
  9807. minLength: 1
  9808. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9809. type: string
  9810. type: object
  9811. type: object
  9812. type: object
  9813. caBundle:
  9814. description: |-
  9815. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  9816. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  9817. are used to validate the TLS connection.
  9818. format: byte
  9819. type: string
  9820. caProvider:
  9821. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  9822. properties:
  9823. key:
  9824. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9825. maxLength: 253
  9826. minLength: 1
  9827. pattern: ^[-._a-zA-Z0-9]+$
  9828. type: string
  9829. name:
  9830. description: The name of the object located at the provider type.
  9831. maxLength: 253
  9832. minLength: 1
  9833. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9834. type: string
  9835. namespace:
  9836. description: |-
  9837. The namespace the Provider type is in.
  9838. Can only be defined when used in a ClusterSecretStore.
  9839. maxLength: 63
  9840. minLength: 1
  9841. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9842. type: string
  9843. type:
  9844. description: The type of provider to use such as "Secret", or "ConfigMap".
  9845. enum:
  9846. - Secret
  9847. - ConfigMap
  9848. type: string
  9849. required:
  9850. - name
  9851. - type
  9852. type: object
  9853. required:
  9854. - akeylessGWApiURL
  9855. - authSecretRef
  9856. type: object
  9857. alibaba:
  9858. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  9859. properties:
  9860. auth:
  9861. description: AlibabaAuth contains a secretRef for credentials.
  9862. properties:
  9863. rrsa:
  9864. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  9865. properties:
  9866. oidcProviderArn:
  9867. type: string
  9868. oidcTokenFilePath:
  9869. type: string
  9870. roleArn:
  9871. type: string
  9872. sessionName:
  9873. type: string
  9874. required:
  9875. - oidcProviderArn
  9876. - oidcTokenFilePath
  9877. - roleArn
  9878. - sessionName
  9879. type: object
  9880. secretRef:
  9881. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  9882. properties:
  9883. accessKeyIDSecretRef:
  9884. description: The AccessKeyID is used for authentication
  9885. properties:
  9886. key:
  9887. description: |-
  9888. A key in the referenced Secret.
  9889. Some instances of this field may be defaulted, in others it may be required.
  9890. maxLength: 253
  9891. minLength: 1
  9892. pattern: ^[-._a-zA-Z0-9]+$
  9893. type: string
  9894. name:
  9895. description: The name of the Secret resource being referred to.
  9896. maxLength: 253
  9897. minLength: 1
  9898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9899. type: string
  9900. namespace:
  9901. description: |-
  9902. The namespace of the Secret resource being referred to.
  9903. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9904. maxLength: 63
  9905. minLength: 1
  9906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9907. type: string
  9908. type: object
  9909. accessKeySecretSecretRef:
  9910. description: The AccessKeySecret is used for authentication
  9911. properties:
  9912. key:
  9913. description: |-
  9914. A key in the referenced Secret.
  9915. Some instances of this field may be defaulted, in others it may be required.
  9916. maxLength: 253
  9917. minLength: 1
  9918. pattern: ^[-._a-zA-Z0-9]+$
  9919. type: string
  9920. name:
  9921. description: The name of the Secret resource being referred to.
  9922. maxLength: 253
  9923. minLength: 1
  9924. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9925. type: string
  9926. namespace:
  9927. description: |-
  9928. The namespace of the Secret resource being referred to.
  9929. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9930. maxLength: 63
  9931. minLength: 1
  9932. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9933. type: string
  9934. type: object
  9935. required:
  9936. - accessKeyIDSecretRef
  9937. - accessKeySecretSecretRef
  9938. type: object
  9939. type: object
  9940. regionID:
  9941. description: Alibaba Region to be used for the provider
  9942. type: string
  9943. required:
  9944. - auth
  9945. - regionID
  9946. type: object
  9947. aws:
  9948. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  9949. properties:
  9950. additionalRoles:
  9951. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  9952. items:
  9953. type: string
  9954. type: array
  9955. auth:
  9956. description: |-
  9957. Auth defines the information necessary to authenticate against AWS
  9958. if not set aws sdk will infer credentials from your environment
  9959. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  9960. properties:
  9961. jwt:
  9962. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  9963. properties:
  9964. serviceAccountRef:
  9965. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  9966. properties:
  9967. audiences:
  9968. description: |-
  9969. Audience specifies the `aud` claim for the service account token
  9970. Some providers automatically extend the audience field based on well-known annotations for workload
  9971. identity (e.g. IRSA or GCP Workload Identity)
  9972. items:
  9973. type: string
  9974. type: array
  9975. name:
  9976. description: The name of the ServiceAccount resource being referred to.
  9977. maxLength: 253
  9978. minLength: 1
  9979. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9980. type: string
  9981. namespace:
  9982. description: |-
  9983. Namespace of the resource being referred to.
  9984. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9985. maxLength: 63
  9986. minLength: 1
  9987. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9988. type: string
  9989. required:
  9990. - name
  9991. type: object
  9992. type: object
  9993. secretRef:
  9994. description: |-
  9995. AWSAuthSecretRef holds secret references for AWS credentials
  9996. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  9997. properties:
  9998. accessKeyIDSecretRef:
  9999. description: The AccessKeyID is used for authentication
  10000. properties:
  10001. key:
  10002. description: |-
  10003. A key in the referenced Secret.
  10004. Some instances of this field may be defaulted, in others it may be required.
  10005. maxLength: 253
  10006. minLength: 1
  10007. pattern: ^[-._a-zA-Z0-9]+$
  10008. type: string
  10009. name:
  10010. description: The name of the Secret resource being referred to.
  10011. maxLength: 253
  10012. minLength: 1
  10013. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10014. type: string
  10015. namespace:
  10016. description: |-
  10017. The namespace of the Secret resource being referred to.
  10018. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10019. maxLength: 63
  10020. minLength: 1
  10021. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10022. type: string
  10023. type: object
  10024. secretAccessKeySecretRef:
  10025. description: The SecretAccessKey is used for authentication
  10026. properties:
  10027. key:
  10028. description: |-
  10029. A key in the referenced Secret.
  10030. Some instances of this field may be defaulted, in others it may be required.
  10031. maxLength: 253
  10032. minLength: 1
  10033. pattern: ^[-._a-zA-Z0-9]+$
  10034. type: string
  10035. name:
  10036. description: The name of the Secret resource being referred to.
  10037. maxLength: 253
  10038. minLength: 1
  10039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10040. type: string
  10041. namespace:
  10042. description: |-
  10043. The namespace of the Secret resource being referred to.
  10044. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10045. maxLength: 63
  10046. minLength: 1
  10047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10048. type: string
  10049. type: object
  10050. sessionTokenSecretRef:
  10051. description: |-
  10052. The SessionToken used for authentication
  10053. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  10054. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  10055. properties:
  10056. key:
  10057. description: |-
  10058. A key in the referenced Secret.
  10059. Some instances of this field may be defaulted, in others it may be required.
  10060. maxLength: 253
  10061. minLength: 1
  10062. pattern: ^[-._a-zA-Z0-9]+$
  10063. type: string
  10064. name:
  10065. description: The name of the Secret resource being referred to.
  10066. maxLength: 253
  10067. minLength: 1
  10068. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10069. type: string
  10070. namespace:
  10071. description: |-
  10072. The namespace of the Secret resource being referred to.
  10073. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10074. maxLength: 63
  10075. minLength: 1
  10076. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10077. type: string
  10078. type: object
  10079. type: object
  10080. type: object
  10081. externalID:
  10082. description: AWS External ID set on assumed IAM roles
  10083. type: string
  10084. prefix:
  10085. description: Prefix adds a prefix to all retrieved values.
  10086. type: string
  10087. region:
  10088. description: AWS Region to be used for the provider
  10089. type: string
  10090. role:
  10091. description: Role is a Role ARN which the provider will assume
  10092. type: string
  10093. secretsManager:
  10094. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  10095. properties:
  10096. forceDeleteWithoutRecovery:
  10097. description: |-
  10098. Specifies whether to delete the secret without any recovery window. You
  10099. can't use both this parameter and RecoveryWindowInDays in the same call.
  10100. If you don't use either, then by default Secrets Manager uses a 30 day
  10101. recovery window.
  10102. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  10103. type: boolean
  10104. recoveryWindowInDays:
  10105. description: |-
  10106. The number of days from 7 to 30 that Secrets Manager waits before
  10107. permanently deleting the secret. You can't use both this parameter and
  10108. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  10109. then by default Secrets Manager uses a 30 day recovery window.
  10110. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  10111. format: int64
  10112. type: integer
  10113. type: object
  10114. service:
  10115. description: Service defines which service should be used to fetch the secrets
  10116. enum:
  10117. - SecretsManager
  10118. - ParameterStore
  10119. type: string
  10120. sessionTags:
  10121. description: AWS STS assume role session tags
  10122. items:
  10123. description: Tag defines a tag key and value for AWS resources.
  10124. properties:
  10125. key:
  10126. type: string
  10127. value:
  10128. type: string
  10129. required:
  10130. - key
  10131. - value
  10132. type: object
  10133. type: array
  10134. transitiveTagKeys:
  10135. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  10136. items:
  10137. type: string
  10138. type: array
  10139. required:
  10140. - region
  10141. - service
  10142. type: object
  10143. azurekv:
  10144. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  10145. properties:
  10146. authSecretRef:
  10147. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  10148. properties:
  10149. clientCertificate:
  10150. description: The Azure ClientCertificate of the service principle used for authentication.
  10151. properties:
  10152. key:
  10153. description: |-
  10154. A key in the referenced Secret.
  10155. Some instances of this field may be defaulted, in others it may be required.
  10156. maxLength: 253
  10157. minLength: 1
  10158. pattern: ^[-._a-zA-Z0-9]+$
  10159. type: string
  10160. name:
  10161. description: The name of the Secret resource being referred to.
  10162. maxLength: 253
  10163. minLength: 1
  10164. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10165. type: string
  10166. namespace:
  10167. description: |-
  10168. The namespace of the Secret resource being referred to.
  10169. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10170. maxLength: 63
  10171. minLength: 1
  10172. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10173. type: string
  10174. type: object
  10175. clientId:
  10176. description: The Azure clientId of the service principle or managed identity used for authentication.
  10177. properties:
  10178. key:
  10179. description: |-
  10180. A key in the referenced Secret.
  10181. Some instances of this field may be defaulted, in others it may be required.
  10182. maxLength: 253
  10183. minLength: 1
  10184. pattern: ^[-._a-zA-Z0-9]+$
  10185. type: string
  10186. name:
  10187. description: The name of the Secret resource being referred to.
  10188. maxLength: 253
  10189. minLength: 1
  10190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10191. type: string
  10192. namespace:
  10193. description: |-
  10194. The namespace of the Secret resource being referred to.
  10195. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10196. maxLength: 63
  10197. minLength: 1
  10198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10199. type: string
  10200. type: object
  10201. clientSecret:
  10202. description: The Azure ClientSecret of the service principle used for authentication.
  10203. properties:
  10204. key:
  10205. description: |-
  10206. A key in the referenced Secret.
  10207. Some instances of this field may be defaulted, in others it may be required.
  10208. maxLength: 253
  10209. minLength: 1
  10210. pattern: ^[-._a-zA-Z0-9]+$
  10211. type: string
  10212. name:
  10213. description: The name of the Secret resource being referred to.
  10214. maxLength: 253
  10215. minLength: 1
  10216. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10217. type: string
  10218. namespace:
  10219. description: |-
  10220. The namespace of the Secret resource being referred to.
  10221. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10222. maxLength: 63
  10223. minLength: 1
  10224. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10225. type: string
  10226. type: object
  10227. tenantId:
  10228. description: The Azure tenantId of the managed identity used for authentication.
  10229. properties:
  10230. key:
  10231. description: |-
  10232. A key in the referenced Secret.
  10233. Some instances of this field may be defaulted, in others it may be required.
  10234. maxLength: 253
  10235. minLength: 1
  10236. pattern: ^[-._a-zA-Z0-9]+$
  10237. type: string
  10238. name:
  10239. description: The name of the Secret resource being referred to.
  10240. maxLength: 253
  10241. minLength: 1
  10242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10243. type: string
  10244. namespace:
  10245. description: |-
  10246. The namespace of the Secret resource being referred to.
  10247. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10248. maxLength: 63
  10249. minLength: 1
  10250. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10251. type: string
  10252. type: object
  10253. type: object
  10254. authType:
  10255. default: ServicePrincipal
  10256. description: |-
  10257. Auth type defines how to authenticate to the keyvault service.
  10258. Valid values are:
  10259. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  10260. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  10261. enum:
  10262. - ServicePrincipal
  10263. - ManagedIdentity
  10264. - WorkloadIdentity
  10265. type: string
  10266. environmentType:
  10267. default: PublicCloud
  10268. description: |-
  10269. EnvironmentType specifies the Azure cloud environment endpoints to use for
  10270. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  10271. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  10272. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  10273. enum:
  10274. - PublicCloud
  10275. - USGovernmentCloud
  10276. - ChinaCloud
  10277. - GermanCloud
  10278. type: string
  10279. identityId:
  10280. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  10281. type: string
  10282. serviceAccountRef:
  10283. description: |-
  10284. ServiceAccountRef specified the service account
  10285. that should be used when authenticating with WorkloadIdentity.
  10286. properties:
  10287. audiences:
  10288. description: |-
  10289. Audience specifies the `aud` claim for the service account token
  10290. Some providers automatically extend the audience field based on well-known annotations for workload
  10291. identity (e.g. IRSA or GCP Workload Identity)
  10292. items:
  10293. type: string
  10294. type: array
  10295. name:
  10296. description: The name of the ServiceAccount resource being referred to.
  10297. maxLength: 253
  10298. minLength: 1
  10299. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10300. type: string
  10301. namespace:
  10302. description: |-
  10303. Namespace of the resource being referred to.
  10304. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10305. maxLength: 63
  10306. minLength: 1
  10307. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10308. type: string
  10309. required:
  10310. - name
  10311. type: object
  10312. tenantId:
  10313. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  10314. type: string
  10315. vaultUrl:
  10316. description: Vault Url from which the secrets to be fetched from.
  10317. type: string
  10318. required:
  10319. - vaultUrl
  10320. type: object
  10321. beyondtrust:
  10322. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  10323. properties:
  10324. auth:
  10325. description: Auth configures how the operator authenticates with Beyondtrust.
  10326. properties:
  10327. apiKey:
  10328. description: APIKey If not provided then ClientID/ClientSecret become required.
  10329. properties:
  10330. secretRef:
  10331. description: SecretRef references a key in a secret that will be used as value.
  10332. properties:
  10333. key:
  10334. description: |-
  10335. A key in the referenced Secret.
  10336. Some instances of this field may be defaulted, in others it may be required.
  10337. maxLength: 253
  10338. minLength: 1
  10339. pattern: ^[-._a-zA-Z0-9]+$
  10340. type: string
  10341. name:
  10342. description: The name of the Secret resource being referred to.
  10343. maxLength: 253
  10344. minLength: 1
  10345. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10346. type: string
  10347. namespace:
  10348. description: |-
  10349. The namespace of the Secret resource being referred to.
  10350. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10351. maxLength: 63
  10352. minLength: 1
  10353. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10354. type: string
  10355. type: object
  10356. value:
  10357. description: Value can be specified directly to set a value without using a secret.
  10358. type: string
  10359. type: object
  10360. certificate:
  10361. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  10362. properties:
  10363. secretRef:
  10364. description: SecretRef references a key in a secret that will be used as value.
  10365. properties:
  10366. key:
  10367. description: |-
  10368. A key in the referenced Secret.
  10369. Some instances of this field may be defaulted, in others it may be required.
  10370. maxLength: 253
  10371. minLength: 1
  10372. pattern: ^[-._a-zA-Z0-9]+$
  10373. type: string
  10374. name:
  10375. description: The name of the Secret resource being referred to.
  10376. maxLength: 253
  10377. minLength: 1
  10378. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10379. type: string
  10380. namespace:
  10381. description: |-
  10382. The namespace of the Secret resource being referred to.
  10383. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10384. maxLength: 63
  10385. minLength: 1
  10386. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10387. type: string
  10388. type: object
  10389. value:
  10390. description: Value can be specified directly to set a value without using a secret.
  10391. type: string
  10392. type: object
  10393. certificateKey:
  10394. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  10395. properties:
  10396. secretRef:
  10397. description: SecretRef references a key in a secret that will be used as value.
  10398. properties:
  10399. key:
  10400. description: |-
  10401. A key in the referenced Secret.
  10402. Some instances of this field may be defaulted, in others it may be required.
  10403. maxLength: 253
  10404. minLength: 1
  10405. pattern: ^[-._a-zA-Z0-9]+$
  10406. type: string
  10407. name:
  10408. description: The name of the Secret resource being referred to.
  10409. maxLength: 253
  10410. minLength: 1
  10411. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10412. type: string
  10413. namespace:
  10414. description: |-
  10415. The namespace of the Secret resource being referred to.
  10416. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10417. maxLength: 63
  10418. minLength: 1
  10419. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10420. type: string
  10421. type: object
  10422. value:
  10423. description: Value can be specified directly to set a value without using a secret.
  10424. type: string
  10425. type: object
  10426. clientId:
  10427. description: ClientID is the API OAuth Client ID.
  10428. properties:
  10429. secretRef:
  10430. description: SecretRef references a key in a secret that will be used as value.
  10431. properties:
  10432. key:
  10433. description: |-
  10434. A key in the referenced Secret.
  10435. Some instances of this field may be defaulted, in others it may be required.
  10436. maxLength: 253
  10437. minLength: 1
  10438. pattern: ^[-._a-zA-Z0-9]+$
  10439. type: string
  10440. name:
  10441. description: The name of the Secret resource being referred to.
  10442. maxLength: 253
  10443. minLength: 1
  10444. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10445. type: string
  10446. namespace:
  10447. description: |-
  10448. The namespace of the Secret resource being referred to.
  10449. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10450. maxLength: 63
  10451. minLength: 1
  10452. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10453. type: string
  10454. type: object
  10455. value:
  10456. description: Value can be specified directly to set a value without using a secret.
  10457. type: string
  10458. type: object
  10459. clientSecret:
  10460. description: ClientSecret is the API OAuth Client Secret.
  10461. properties:
  10462. secretRef:
  10463. description: SecretRef references a key in a secret that will be used as value.
  10464. properties:
  10465. key:
  10466. description: |-
  10467. A key in the referenced Secret.
  10468. Some instances of this field may be defaulted, in others it may be required.
  10469. maxLength: 253
  10470. minLength: 1
  10471. pattern: ^[-._a-zA-Z0-9]+$
  10472. type: string
  10473. name:
  10474. description: The name of the Secret resource being referred to.
  10475. maxLength: 253
  10476. minLength: 1
  10477. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10478. type: string
  10479. namespace:
  10480. description: |-
  10481. The namespace of the Secret resource being referred to.
  10482. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10483. maxLength: 63
  10484. minLength: 1
  10485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10486. type: string
  10487. type: object
  10488. value:
  10489. description: Value can be specified directly to set a value without using a secret.
  10490. type: string
  10491. type: object
  10492. type: object
  10493. server:
  10494. description: Auth configures how API server works.
  10495. properties:
  10496. apiUrl:
  10497. type: string
  10498. apiVersion:
  10499. type: string
  10500. clientTimeOutSeconds:
  10501. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  10502. type: integer
  10503. decrypt:
  10504. default: true
  10505. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  10506. type: boolean
  10507. retrievalType:
  10508. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  10509. type: string
  10510. separator:
  10511. description: A character that separates the folder names.
  10512. type: string
  10513. verifyCA:
  10514. type: boolean
  10515. required:
  10516. - apiUrl
  10517. - verifyCA
  10518. type: object
  10519. required:
  10520. - auth
  10521. - server
  10522. type: object
  10523. bitwardensecretsmanager:
  10524. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  10525. properties:
  10526. apiURL:
  10527. type: string
  10528. auth:
  10529. description: |-
  10530. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  10531. Make sure that the token being used has permissions on the given secret.
  10532. properties:
  10533. secretRef:
  10534. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  10535. properties:
  10536. credentials:
  10537. description: AccessToken used for the bitwarden instance.
  10538. properties:
  10539. key:
  10540. description: |-
  10541. A key in the referenced Secret.
  10542. Some instances of this field may be defaulted, in others it may be required.
  10543. maxLength: 253
  10544. minLength: 1
  10545. pattern: ^[-._a-zA-Z0-9]+$
  10546. type: string
  10547. name:
  10548. description: The name of the Secret resource being referred to.
  10549. maxLength: 253
  10550. minLength: 1
  10551. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10552. type: string
  10553. namespace:
  10554. description: |-
  10555. The namespace of the Secret resource being referred to.
  10556. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10557. maxLength: 63
  10558. minLength: 1
  10559. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10560. type: string
  10561. type: object
  10562. required:
  10563. - credentials
  10564. type: object
  10565. required:
  10566. - secretRef
  10567. type: object
  10568. bitwardenServerSDKURL:
  10569. type: string
  10570. caBundle:
  10571. description: |-
  10572. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  10573. can be performed.
  10574. type: string
  10575. caProvider:
  10576. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  10577. properties:
  10578. key:
  10579. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10580. maxLength: 253
  10581. minLength: 1
  10582. pattern: ^[-._a-zA-Z0-9]+$
  10583. type: string
  10584. name:
  10585. description: The name of the object located at the provider type.
  10586. maxLength: 253
  10587. minLength: 1
  10588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10589. type: string
  10590. namespace:
  10591. description: |-
  10592. The namespace the Provider type is in.
  10593. Can only be defined when used in a ClusterSecretStore.
  10594. maxLength: 63
  10595. minLength: 1
  10596. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10597. type: string
  10598. type:
  10599. description: The type of provider to use such as "Secret", or "ConfigMap".
  10600. enum:
  10601. - Secret
  10602. - ConfigMap
  10603. type: string
  10604. required:
  10605. - name
  10606. - type
  10607. type: object
  10608. identityURL:
  10609. type: string
  10610. organizationID:
  10611. description: OrganizationID determines which organization this secret store manages.
  10612. type: string
  10613. projectID:
  10614. description: ProjectID determines which project this secret store manages.
  10615. type: string
  10616. required:
  10617. - auth
  10618. - organizationID
  10619. - projectID
  10620. type: object
  10621. chef:
  10622. description: Chef configures this store to sync secrets with chef server
  10623. properties:
  10624. auth:
  10625. description: Auth defines the information necessary to authenticate against chef Server
  10626. properties:
  10627. secretRef:
  10628. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  10629. properties:
  10630. privateKeySecretRef:
  10631. description: SecretKey is the Signing Key in PEM format, used for authentication.
  10632. properties:
  10633. key:
  10634. description: |-
  10635. A key in the referenced Secret.
  10636. Some instances of this field may be defaulted, in others it may be required.
  10637. maxLength: 253
  10638. minLength: 1
  10639. pattern: ^[-._a-zA-Z0-9]+$
  10640. type: string
  10641. name:
  10642. description: The name of the Secret resource being referred to.
  10643. maxLength: 253
  10644. minLength: 1
  10645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10646. type: string
  10647. namespace:
  10648. description: |-
  10649. The namespace of the Secret resource being referred to.
  10650. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10651. maxLength: 63
  10652. minLength: 1
  10653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10654. type: string
  10655. type: object
  10656. required:
  10657. - privateKeySecretRef
  10658. type: object
  10659. required:
  10660. - secretRef
  10661. type: object
  10662. serverUrl:
  10663. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  10664. type: string
  10665. username:
  10666. description: UserName should be the user ID on the chef server
  10667. type: string
  10668. required:
  10669. - auth
  10670. - serverUrl
  10671. - username
  10672. type: object
  10673. cloudrusm:
  10674. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  10675. properties:
  10676. auth:
  10677. description: CSMAuth contains a secretRef for credentials.
  10678. properties:
  10679. secretRef:
  10680. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  10681. properties:
  10682. accessKeyIDSecretRef:
  10683. description: The AccessKeyID is used for authentication
  10684. properties:
  10685. key:
  10686. description: |-
  10687. A key in the referenced Secret.
  10688. Some instances of this field may be defaulted, in others it may be required.
  10689. maxLength: 253
  10690. minLength: 1
  10691. pattern: ^[-._a-zA-Z0-9]+$
  10692. type: string
  10693. name:
  10694. description: The name of the Secret resource being referred to.
  10695. maxLength: 253
  10696. minLength: 1
  10697. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10698. type: string
  10699. namespace:
  10700. description: |-
  10701. The namespace of the Secret resource being referred to.
  10702. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10703. maxLength: 63
  10704. minLength: 1
  10705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10706. type: string
  10707. type: object
  10708. accessKeySecretSecretRef:
  10709. description: The AccessKeySecret is used for authentication
  10710. properties:
  10711. key:
  10712. description: |-
  10713. A key in the referenced Secret.
  10714. Some instances of this field may be defaulted, in others it may be required.
  10715. maxLength: 253
  10716. minLength: 1
  10717. pattern: ^[-._a-zA-Z0-9]+$
  10718. type: string
  10719. name:
  10720. description: The name of the Secret resource being referred to.
  10721. maxLength: 253
  10722. minLength: 1
  10723. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10724. type: string
  10725. namespace:
  10726. description: |-
  10727. The namespace of the Secret resource being referred to.
  10728. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10729. maxLength: 63
  10730. minLength: 1
  10731. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10732. type: string
  10733. type: object
  10734. required:
  10735. - accessKeyIDSecretRef
  10736. - accessKeySecretSecretRef
  10737. type: object
  10738. type: object
  10739. projectID:
  10740. description: ProjectID is the project, which the secrets are stored in.
  10741. type: string
  10742. required:
  10743. - auth
  10744. type: object
  10745. conjur:
  10746. description: Conjur configures this store to sync secrets using conjur provider
  10747. properties:
  10748. auth:
  10749. description: Defines authentication settings for connecting to Conjur.
  10750. properties:
  10751. apikey:
  10752. description: Authenticates with Conjur using an API key.
  10753. properties:
  10754. account:
  10755. description: Account is the Conjur organization account name.
  10756. type: string
  10757. apiKeyRef:
  10758. description: |-
  10759. A reference to a specific 'key' containing the Conjur API key
  10760. within a Secret resource. In some instances, `key` is a required field.
  10761. properties:
  10762. key:
  10763. description: |-
  10764. A key in the referenced Secret.
  10765. Some instances of this field may be defaulted, in others it may be required.
  10766. maxLength: 253
  10767. minLength: 1
  10768. pattern: ^[-._a-zA-Z0-9]+$
  10769. type: string
  10770. name:
  10771. description: The name of the Secret resource being referred to.
  10772. maxLength: 253
  10773. minLength: 1
  10774. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10775. type: string
  10776. namespace:
  10777. description: |-
  10778. The namespace of the Secret resource being referred to.
  10779. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10780. maxLength: 63
  10781. minLength: 1
  10782. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10783. type: string
  10784. type: object
  10785. userRef:
  10786. description: |-
  10787. A reference to a specific 'key' containing the Conjur username
  10788. within a Secret resource. In some instances, `key` is a required field.
  10789. properties:
  10790. key:
  10791. description: |-
  10792. A key in the referenced Secret.
  10793. Some instances of this field may be defaulted, in others it may be required.
  10794. maxLength: 253
  10795. minLength: 1
  10796. pattern: ^[-._a-zA-Z0-9]+$
  10797. type: string
  10798. name:
  10799. description: The name of the Secret resource being referred to.
  10800. maxLength: 253
  10801. minLength: 1
  10802. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10803. type: string
  10804. namespace:
  10805. description: |-
  10806. The namespace of the Secret resource being referred to.
  10807. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10808. maxLength: 63
  10809. minLength: 1
  10810. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10811. type: string
  10812. type: object
  10813. required:
  10814. - account
  10815. - apiKeyRef
  10816. - userRef
  10817. type: object
  10818. jwt:
  10819. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  10820. properties:
  10821. account:
  10822. description: Account is the Conjur organization account name.
  10823. type: string
  10824. hostId:
  10825. description: |-
  10826. Optional HostID for JWT authentication. This may be used depending
  10827. on how the Conjur JWT authenticator policy is configured.
  10828. type: string
  10829. secretRef:
  10830. description: |-
  10831. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  10832. authenticate with Conjur using the JWT authentication method.
  10833. properties:
  10834. key:
  10835. description: |-
  10836. A key in the referenced Secret.
  10837. Some instances of this field may be defaulted, in others it may be required.
  10838. maxLength: 253
  10839. minLength: 1
  10840. pattern: ^[-._a-zA-Z0-9]+$
  10841. type: string
  10842. name:
  10843. description: The name of the Secret resource being referred to.
  10844. maxLength: 253
  10845. minLength: 1
  10846. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10847. type: string
  10848. namespace:
  10849. description: |-
  10850. The namespace of the Secret resource being referred to.
  10851. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10852. maxLength: 63
  10853. minLength: 1
  10854. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10855. type: string
  10856. type: object
  10857. serviceAccountRef:
  10858. description: |-
  10859. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  10860. a token for with the `TokenRequest` API.
  10861. properties:
  10862. audiences:
  10863. description: |-
  10864. Audience specifies the `aud` claim for the service account token
  10865. Some providers automatically extend the audience field based on well-known annotations for workload
  10866. identity (e.g. IRSA or GCP Workload Identity)
  10867. items:
  10868. type: string
  10869. type: array
  10870. name:
  10871. description: The name of the ServiceAccount resource being referred to.
  10872. maxLength: 253
  10873. minLength: 1
  10874. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10875. type: string
  10876. namespace:
  10877. description: |-
  10878. Namespace of the resource being referred to.
  10879. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10880. maxLength: 63
  10881. minLength: 1
  10882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10883. type: string
  10884. required:
  10885. - name
  10886. type: object
  10887. serviceID:
  10888. description: The conjur authn jwt webservice id
  10889. type: string
  10890. required:
  10891. - account
  10892. - serviceID
  10893. type: object
  10894. type: object
  10895. caBundle:
  10896. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  10897. type: string
  10898. caProvider:
  10899. description: |-
  10900. Used to provide custom certificate authority (CA) certificates
  10901. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  10902. that contains a PEM-encoded certificate.
  10903. properties:
  10904. key:
  10905. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10906. maxLength: 253
  10907. minLength: 1
  10908. pattern: ^[-._a-zA-Z0-9]+$
  10909. type: string
  10910. name:
  10911. description: The name of the object located at the provider type.
  10912. maxLength: 253
  10913. minLength: 1
  10914. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10915. type: string
  10916. namespace:
  10917. description: |-
  10918. The namespace the Provider type is in.
  10919. Can only be defined when used in a ClusterSecretStore.
  10920. maxLength: 63
  10921. minLength: 1
  10922. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10923. type: string
  10924. type:
  10925. description: The type of provider to use such as "Secret", or "ConfigMap".
  10926. enum:
  10927. - Secret
  10928. - ConfigMap
  10929. type: string
  10930. required:
  10931. - name
  10932. - type
  10933. type: object
  10934. url:
  10935. description: URL is the endpoint of the Conjur instance.
  10936. type: string
  10937. required:
  10938. - auth
  10939. - url
  10940. type: object
  10941. delinea:
  10942. description: |-
  10943. Delinea DevOps Secrets Vault
  10944. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  10945. properties:
  10946. clientId:
  10947. description: ClientID is the non-secret part of the credential.
  10948. properties:
  10949. secretRef:
  10950. description: SecretRef references a key in a secret that will be used as value.
  10951. properties:
  10952. key:
  10953. description: |-
  10954. A key in the referenced Secret.
  10955. Some instances of this field may be defaulted, in others it may be required.
  10956. maxLength: 253
  10957. minLength: 1
  10958. pattern: ^[-._a-zA-Z0-9]+$
  10959. type: string
  10960. name:
  10961. description: The name of the Secret resource being referred to.
  10962. maxLength: 253
  10963. minLength: 1
  10964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10965. type: string
  10966. namespace:
  10967. description: |-
  10968. The namespace of the Secret resource being referred to.
  10969. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10970. maxLength: 63
  10971. minLength: 1
  10972. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10973. type: string
  10974. type: object
  10975. value:
  10976. description: Value can be specified directly to set a value without using a secret.
  10977. type: string
  10978. type: object
  10979. clientSecret:
  10980. description: ClientSecret is the secret part of the credential.
  10981. properties:
  10982. secretRef:
  10983. description: SecretRef references a key in a secret that will be used as value.
  10984. properties:
  10985. key:
  10986. description: |-
  10987. A key in the referenced Secret.
  10988. Some instances of this field may be defaulted, in others it may be required.
  10989. maxLength: 253
  10990. minLength: 1
  10991. pattern: ^[-._a-zA-Z0-9]+$
  10992. type: string
  10993. name:
  10994. description: The name of the Secret resource being referred to.
  10995. maxLength: 253
  10996. minLength: 1
  10997. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10998. type: string
  10999. namespace:
  11000. description: |-
  11001. The namespace of the Secret resource being referred to.
  11002. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11003. maxLength: 63
  11004. minLength: 1
  11005. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11006. type: string
  11007. type: object
  11008. value:
  11009. description: Value can be specified directly to set a value without using a secret.
  11010. type: string
  11011. type: object
  11012. tenant:
  11013. description: Tenant is the chosen hostname / site name.
  11014. type: string
  11015. tld:
  11016. description: |-
  11017. TLD is based on the server location that was chosen during provisioning.
  11018. If unset, defaults to "com".
  11019. type: string
  11020. urlTemplate:
  11021. description: |-
  11022. URLTemplate
  11023. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  11024. type: string
  11025. required:
  11026. - clientId
  11027. - clientSecret
  11028. - tenant
  11029. type: object
  11030. device42:
  11031. description: Device42 configures this store to sync secrets using the Device42 provider
  11032. properties:
  11033. auth:
  11034. description: Auth configures how secret-manager authenticates with a Device42 instance.
  11035. properties:
  11036. secretRef:
  11037. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  11038. properties:
  11039. credentials:
  11040. description: Username / Password is used for authentication.
  11041. properties:
  11042. key:
  11043. description: |-
  11044. A key in the referenced Secret.
  11045. Some instances of this field may be defaulted, in others it may be required.
  11046. maxLength: 253
  11047. minLength: 1
  11048. pattern: ^[-._a-zA-Z0-9]+$
  11049. type: string
  11050. name:
  11051. description: The name of the Secret resource being referred to.
  11052. maxLength: 253
  11053. minLength: 1
  11054. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11055. type: string
  11056. namespace:
  11057. description: |-
  11058. The namespace of the Secret resource being referred to.
  11059. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11060. maxLength: 63
  11061. minLength: 1
  11062. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11063. type: string
  11064. type: object
  11065. type: object
  11066. required:
  11067. - secretRef
  11068. type: object
  11069. host:
  11070. description: URL configures the Device42 instance URL.
  11071. type: string
  11072. required:
  11073. - auth
  11074. - host
  11075. type: object
  11076. doppler:
  11077. description: Doppler configures this store to sync secrets using the Doppler provider
  11078. properties:
  11079. auth:
  11080. description: Auth configures how the Operator authenticates with the Doppler API
  11081. properties:
  11082. secretRef:
  11083. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  11084. properties:
  11085. dopplerToken:
  11086. description: |-
  11087. The DopplerToken is used for authentication.
  11088. See https://docs.doppler.com/reference/api#authentication for auth token types.
  11089. The Key attribute defaults to dopplerToken if not specified.
  11090. properties:
  11091. key:
  11092. description: |-
  11093. A key in the referenced Secret.
  11094. Some instances of this field may be defaulted, in others it may be required.
  11095. maxLength: 253
  11096. minLength: 1
  11097. pattern: ^[-._a-zA-Z0-9]+$
  11098. type: string
  11099. name:
  11100. description: The name of the Secret resource being referred to.
  11101. maxLength: 253
  11102. minLength: 1
  11103. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11104. type: string
  11105. namespace:
  11106. description: |-
  11107. The namespace of the Secret resource being referred to.
  11108. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11109. maxLength: 63
  11110. minLength: 1
  11111. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11112. type: string
  11113. type: object
  11114. required:
  11115. - dopplerToken
  11116. type: object
  11117. required:
  11118. - secretRef
  11119. type: object
  11120. config:
  11121. description: Doppler config (required if not using a Service Token)
  11122. type: string
  11123. format:
  11124. description: Format enables the downloading of secrets as a file (string)
  11125. enum:
  11126. - json
  11127. - dotnet-json
  11128. - env
  11129. - yaml
  11130. - docker
  11131. type: string
  11132. nameTransformer:
  11133. description: Environment variable compatible name transforms that change secret names to a different format
  11134. enum:
  11135. - upper-camel
  11136. - camel
  11137. - lower-snake
  11138. - tf-var
  11139. - dotnet-env
  11140. - lower-kebab
  11141. type: string
  11142. project:
  11143. description: Doppler project (required if not using a Service Token)
  11144. type: string
  11145. required:
  11146. - auth
  11147. type: object
  11148. fake:
  11149. description: Fake configures a store with static key/value pairs
  11150. properties:
  11151. data:
  11152. items:
  11153. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  11154. properties:
  11155. key:
  11156. type: string
  11157. value:
  11158. type: string
  11159. version:
  11160. type: string
  11161. required:
  11162. - key
  11163. - value
  11164. type: object
  11165. type: array
  11166. required:
  11167. - data
  11168. type: object
  11169. fortanix:
  11170. description: Fortanix configures this store to sync secrets using the Fortanix provider
  11171. properties:
  11172. apiKey:
  11173. description: APIKey is the API token to access SDKMS Applications.
  11174. properties:
  11175. secretRef:
  11176. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  11177. properties:
  11178. key:
  11179. description: |-
  11180. A key in the referenced Secret.
  11181. Some instances of this field may be defaulted, in others it may be required.
  11182. maxLength: 253
  11183. minLength: 1
  11184. pattern: ^[-._a-zA-Z0-9]+$
  11185. type: string
  11186. name:
  11187. description: The name of the Secret resource being referred to.
  11188. maxLength: 253
  11189. minLength: 1
  11190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11191. type: string
  11192. namespace:
  11193. description: |-
  11194. The namespace of the Secret resource being referred to.
  11195. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11196. maxLength: 63
  11197. minLength: 1
  11198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11199. type: string
  11200. type: object
  11201. type: object
  11202. apiUrl:
  11203. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  11204. type: string
  11205. type: object
  11206. gcpsm:
  11207. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  11208. properties:
  11209. auth:
  11210. description: Auth defines the information necessary to authenticate against GCP
  11211. properties:
  11212. secretRef:
  11213. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  11214. properties:
  11215. secretAccessKeySecretRef:
  11216. description: The SecretAccessKey is used for authentication
  11217. properties:
  11218. key:
  11219. description: |-
  11220. A key in the referenced Secret.
  11221. Some instances of this field may be defaulted, in others it may be required.
  11222. maxLength: 253
  11223. minLength: 1
  11224. pattern: ^[-._a-zA-Z0-9]+$
  11225. type: string
  11226. name:
  11227. description: The name of the Secret resource being referred to.
  11228. maxLength: 253
  11229. minLength: 1
  11230. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11231. type: string
  11232. namespace:
  11233. description: |-
  11234. The namespace of the Secret resource being referred to.
  11235. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11236. maxLength: 63
  11237. minLength: 1
  11238. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11239. type: string
  11240. type: object
  11241. type: object
  11242. workloadIdentity:
  11243. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  11244. properties:
  11245. clusterLocation:
  11246. description: |-
  11247. ClusterLocation is the location of the cluster
  11248. If not specified, it fetches information from the metadata server
  11249. type: string
  11250. clusterName:
  11251. description: |-
  11252. ClusterName is the name of the cluster
  11253. If not specified, it fetches information from the metadata server
  11254. type: string
  11255. clusterProjectID:
  11256. description: |-
  11257. ClusterProjectID is the project ID of the cluster
  11258. If not specified, it fetches information from the metadata server
  11259. type: string
  11260. serviceAccountRef:
  11261. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  11262. properties:
  11263. audiences:
  11264. description: |-
  11265. Audience specifies the `aud` claim for the service account token
  11266. Some providers automatically extend the audience field based on well-known annotations for workload
  11267. identity (e.g. IRSA or GCP Workload Identity)
  11268. items:
  11269. type: string
  11270. type: array
  11271. name:
  11272. description: The name of the ServiceAccount resource being referred to.
  11273. maxLength: 253
  11274. minLength: 1
  11275. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11276. type: string
  11277. namespace:
  11278. description: |-
  11279. Namespace of the resource being referred to.
  11280. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11281. maxLength: 63
  11282. minLength: 1
  11283. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11284. type: string
  11285. required:
  11286. - name
  11287. type: object
  11288. required:
  11289. - serviceAccountRef
  11290. type: object
  11291. type: object
  11292. location:
  11293. description: Location optionally defines a location for a secret
  11294. type: string
  11295. projectID:
  11296. description: ProjectID project where secret is located
  11297. type: string
  11298. type: object
  11299. github:
  11300. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  11301. properties:
  11302. appID:
  11303. description: appID specifies the Github APP that will be used to authenticate the client
  11304. format: int64
  11305. type: integer
  11306. auth:
  11307. description: auth configures how secret-manager authenticates with a Github instance.
  11308. properties:
  11309. privateKey:
  11310. description: |-
  11311. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11312. In some instances, `key` is a required field.
  11313. properties:
  11314. key:
  11315. description: |-
  11316. A key in the referenced Secret.
  11317. Some instances of this field may be defaulted, in others it may be required.
  11318. maxLength: 253
  11319. minLength: 1
  11320. pattern: ^[-._a-zA-Z0-9]+$
  11321. type: string
  11322. name:
  11323. description: The name of the Secret resource being referred to.
  11324. maxLength: 253
  11325. minLength: 1
  11326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11327. type: string
  11328. namespace:
  11329. description: |-
  11330. The namespace of the Secret resource being referred to.
  11331. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11332. maxLength: 63
  11333. minLength: 1
  11334. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11335. type: string
  11336. type: object
  11337. required:
  11338. - privateKey
  11339. type: object
  11340. environment:
  11341. description: environment will be used to fetch secrets from a particular environment within a github repository
  11342. type: string
  11343. installationID:
  11344. description: installationID specifies the Github APP installation that will be used to authenticate the client
  11345. format: int64
  11346. type: integer
  11347. organization:
  11348. description: organization will be used to fetch secrets from the Github organization
  11349. type: string
  11350. repository:
  11351. description: repository will be used to fetch secrets from the Github repository within an organization
  11352. type: string
  11353. uploadURL:
  11354. description: Upload URL for enterprise instances. Default to URL.
  11355. type: string
  11356. url:
  11357. default: https://github.com/
  11358. description: URL configures the Github instance URL. Defaults to https://github.com/.
  11359. type: string
  11360. required:
  11361. - appID
  11362. - auth
  11363. - installationID
  11364. - organization
  11365. type: object
  11366. gitlab:
  11367. description: GitLab configures this store to sync secrets using GitLab Variables provider
  11368. properties:
  11369. auth:
  11370. description: Auth configures how secret-manager authenticates with a GitLab instance.
  11371. properties:
  11372. SecretRef:
  11373. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  11374. properties:
  11375. accessToken:
  11376. description: AccessToken is used for authentication.
  11377. properties:
  11378. key:
  11379. description: |-
  11380. A key in the referenced Secret.
  11381. Some instances of this field may be defaulted, in others it may be required.
  11382. maxLength: 253
  11383. minLength: 1
  11384. pattern: ^[-._a-zA-Z0-9]+$
  11385. type: string
  11386. name:
  11387. description: The name of the Secret resource being referred to.
  11388. maxLength: 253
  11389. minLength: 1
  11390. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11391. type: string
  11392. namespace:
  11393. description: |-
  11394. The namespace of the Secret resource being referred to.
  11395. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11396. maxLength: 63
  11397. minLength: 1
  11398. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11399. type: string
  11400. type: object
  11401. type: object
  11402. required:
  11403. - SecretRef
  11404. type: object
  11405. caBundle:
  11406. description: |-
  11407. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  11408. can be performed.
  11409. format: byte
  11410. type: string
  11411. caProvider:
  11412. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  11413. properties:
  11414. key:
  11415. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11416. maxLength: 253
  11417. minLength: 1
  11418. pattern: ^[-._a-zA-Z0-9]+$
  11419. type: string
  11420. name:
  11421. description: The name of the object located at the provider type.
  11422. maxLength: 253
  11423. minLength: 1
  11424. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11425. type: string
  11426. namespace:
  11427. description: |-
  11428. The namespace the Provider type is in.
  11429. Can only be defined when used in a ClusterSecretStore.
  11430. maxLength: 63
  11431. minLength: 1
  11432. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11433. type: string
  11434. type:
  11435. description: The type of provider to use such as "Secret", or "ConfigMap".
  11436. enum:
  11437. - Secret
  11438. - ConfigMap
  11439. type: string
  11440. required:
  11441. - name
  11442. - type
  11443. type: object
  11444. environment:
  11445. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  11446. type: string
  11447. groupIDs:
  11448. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  11449. items:
  11450. type: string
  11451. type: array
  11452. inheritFromGroups:
  11453. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  11454. type: boolean
  11455. projectID:
  11456. description: ProjectID specifies a project where secrets are located.
  11457. type: string
  11458. url:
  11459. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  11460. type: string
  11461. required:
  11462. - auth
  11463. type: object
  11464. ibm:
  11465. description: IBM configures this store to sync secrets using IBM Cloud provider
  11466. properties:
  11467. auth:
  11468. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  11469. maxProperties: 1
  11470. minProperties: 1
  11471. properties:
  11472. containerAuth:
  11473. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  11474. properties:
  11475. iamEndpoint:
  11476. type: string
  11477. profile:
  11478. description: the IBM Trusted Profile
  11479. type: string
  11480. tokenLocation:
  11481. description: Location the token is mounted on the pod
  11482. type: string
  11483. required:
  11484. - profile
  11485. type: object
  11486. secretRef:
  11487. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  11488. properties:
  11489. secretApiKeySecretRef:
  11490. description: The SecretAccessKey is used for authentication
  11491. properties:
  11492. key:
  11493. description: |-
  11494. A key in the referenced Secret.
  11495. Some instances of this field may be defaulted, in others it may be required.
  11496. maxLength: 253
  11497. minLength: 1
  11498. pattern: ^[-._a-zA-Z0-9]+$
  11499. type: string
  11500. name:
  11501. description: The name of the Secret resource being referred to.
  11502. maxLength: 253
  11503. minLength: 1
  11504. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11505. type: string
  11506. namespace:
  11507. description: |-
  11508. The namespace of the Secret resource being referred to.
  11509. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11510. maxLength: 63
  11511. minLength: 1
  11512. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11513. type: string
  11514. type: object
  11515. type: object
  11516. type: object
  11517. serviceUrl:
  11518. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  11519. type: string
  11520. required:
  11521. - auth
  11522. type: object
  11523. infisical:
  11524. description: Infisical configures this store to sync secrets using the Infisical provider
  11525. properties:
  11526. auth:
  11527. description: Auth configures how the Operator authenticates with the Infisical API
  11528. properties:
  11529. universalAuthCredentials:
  11530. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  11531. properties:
  11532. clientId:
  11533. description: |-
  11534. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11535. In some instances, `key` is a required field.
  11536. properties:
  11537. key:
  11538. description: |-
  11539. A key in the referenced Secret.
  11540. Some instances of this field may be defaulted, in others it may be required.
  11541. maxLength: 253
  11542. minLength: 1
  11543. pattern: ^[-._a-zA-Z0-9]+$
  11544. type: string
  11545. name:
  11546. description: The name of the Secret resource being referred to.
  11547. maxLength: 253
  11548. minLength: 1
  11549. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11550. type: string
  11551. namespace:
  11552. description: |-
  11553. The namespace of the Secret resource being referred to.
  11554. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11555. maxLength: 63
  11556. minLength: 1
  11557. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11558. type: string
  11559. type: object
  11560. clientSecret:
  11561. description: |-
  11562. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11563. In some instances, `key` is a required field.
  11564. properties:
  11565. key:
  11566. description: |-
  11567. A key in the referenced Secret.
  11568. Some instances of this field may be defaulted, in others it may be required.
  11569. maxLength: 253
  11570. minLength: 1
  11571. pattern: ^[-._a-zA-Z0-9]+$
  11572. type: string
  11573. name:
  11574. description: The name of the Secret resource being referred to.
  11575. maxLength: 253
  11576. minLength: 1
  11577. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11578. type: string
  11579. namespace:
  11580. description: |-
  11581. The namespace of the Secret resource being referred to.
  11582. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11583. maxLength: 63
  11584. minLength: 1
  11585. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11586. type: string
  11587. type: object
  11588. required:
  11589. - clientId
  11590. - clientSecret
  11591. type: object
  11592. type: object
  11593. hostAPI:
  11594. default: https://app.infisical.com/api
  11595. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  11596. type: string
  11597. secretsScope:
  11598. description: SecretsScope defines the scope of the secrets within the workspace
  11599. properties:
  11600. environmentSlug:
  11601. description: EnvironmentSlug is the required slug identifier for the environment.
  11602. type: string
  11603. expandSecretReferences:
  11604. default: true
  11605. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  11606. type: boolean
  11607. projectSlug:
  11608. description: ProjectSlug is the required slug identifier for the project.
  11609. type: string
  11610. recursive:
  11611. default: false
  11612. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  11613. type: boolean
  11614. secretsPath:
  11615. default: /
  11616. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  11617. type: string
  11618. required:
  11619. - environmentSlug
  11620. - projectSlug
  11621. type: object
  11622. required:
  11623. - auth
  11624. - secretsScope
  11625. type: object
  11626. keepersecurity:
  11627. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  11628. properties:
  11629. authRef:
  11630. description: |-
  11631. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11632. In some instances, `key` is a required field.
  11633. properties:
  11634. key:
  11635. description: |-
  11636. A key in the referenced Secret.
  11637. Some instances of this field may be defaulted, in others it may be required.
  11638. maxLength: 253
  11639. minLength: 1
  11640. pattern: ^[-._a-zA-Z0-9]+$
  11641. type: string
  11642. name:
  11643. description: The name of the Secret resource being referred to.
  11644. maxLength: 253
  11645. minLength: 1
  11646. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11647. type: string
  11648. namespace:
  11649. description: |-
  11650. The namespace of the Secret resource being referred to.
  11651. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11652. maxLength: 63
  11653. minLength: 1
  11654. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11655. type: string
  11656. type: object
  11657. folderID:
  11658. type: string
  11659. required:
  11660. - authRef
  11661. - folderID
  11662. type: object
  11663. kubernetes:
  11664. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  11665. properties:
  11666. auth:
  11667. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  11668. maxProperties: 1
  11669. minProperties: 1
  11670. properties:
  11671. cert:
  11672. description: has both clientCert and clientKey as secretKeySelector
  11673. properties:
  11674. clientCert:
  11675. description: |-
  11676. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11677. In some instances, `key` is a required field.
  11678. properties:
  11679. key:
  11680. description: |-
  11681. A key in the referenced Secret.
  11682. Some instances of this field may be defaulted, in others it may be required.
  11683. maxLength: 253
  11684. minLength: 1
  11685. pattern: ^[-._a-zA-Z0-9]+$
  11686. type: string
  11687. name:
  11688. description: The name of the Secret resource being referred to.
  11689. maxLength: 253
  11690. minLength: 1
  11691. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11692. type: string
  11693. namespace:
  11694. description: |-
  11695. The namespace of the Secret resource being referred to.
  11696. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11697. maxLength: 63
  11698. minLength: 1
  11699. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11700. type: string
  11701. type: object
  11702. clientKey:
  11703. description: |-
  11704. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11705. In some instances, `key` is a required field.
  11706. properties:
  11707. key:
  11708. description: |-
  11709. A key in the referenced Secret.
  11710. Some instances of this field may be defaulted, in others it may be required.
  11711. maxLength: 253
  11712. minLength: 1
  11713. pattern: ^[-._a-zA-Z0-9]+$
  11714. type: string
  11715. name:
  11716. description: The name of the Secret resource being referred to.
  11717. maxLength: 253
  11718. minLength: 1
  11719. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11720. type: string
  11721. namespace:
  11722. description: |-
  11723. The namespace of the Secret resource being referred to.
  11724. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11725. maxLength: 63
  11726. minLength: 1
  11727. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11728. type: string
  11729. type: object
  11730. type: object
  11731. serviceAccount:
  11732. description: points to a service account that should be used for authentication
  11733. properties:
  11734. audiences:
  11735. description: |-
  11736. Audience specifies the `aud` claim for the service account token
  11737. Some providers automatically extend the audience field based on well-known annotations for workload
  11738. identity (e.g. IRSA or GCP Workload Identity)
  11739. items:
  11740. type: string
  11741. type: array
  11742. name:
  11743. description: The name of the ServiceAccount resource being referred to.
  11744. maxLength: 253
  11745. minLength: 1
  11746. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11747. type: string
  11748. namespace:
  11749. description: |-
  11750. Namespace of the resource being referred to.
  11751. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11752. maxLength: 63
  11753. minLength: 1
  11754. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11755. type: string
  11756. required:
  11757. - name
  11758. type: object
  11759. token:
  11760. description: use static token to authenticate with
  11761. properties:
  11762. bearerToken:
  11763. description: |-
  11764. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11765. In some instances, `key` is a required field.
  11766. properties:
  11767. key:
  11768. description: |-
  11769. A key in the referenced Secret.
  11770. Some instances of this field may be defaulted, in others it may be required.
  11771. maxLength: 253
  11772. minLength: 1
  11773. pattern: ^[-._a-zA-Z0-9]+$
  11774. type: string
  11775. name:
  11776. description: The name of the Secret resource being referred to.
  11777. maxLength: 253
  11778. minLength: 1
  11779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11780. type: string
  11781. namespace:
  11782. description: |-
  11783. The namespace of the Secret resource being referred to.
  11784. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11785. maxLength: 63
  11786. minLength: 1
  11787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11788. type: string
  11789. type: object
  11790. type: object
  11791. type: object
  11792. authRef:
  11793. description: A reference to a secret that contains the auth information.
  11794. properties:
  11795. key:
  11796. description: |-
  11797. A key in the referenced Secret.
  11798. Some instances of this field may be defaulted, in others it may be required.
  11799. maxLength: 253
  11800. minLength: 1
  11801. pattern: ^[-._a-zA-Z0-9]+$
  11802. type: string
  11803. name:
  11804. description: The name of the Secret resource being referred to.
  11805. maxLength: 253
  11806. minLength: 1
  11807. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11808. type: string
  11809. namespace:
  11810. description: |-
  11811. The namespace of the Secret resource being referred to.
  11812. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11813. maxLength: 63
  11814. minLength: 1
  11815. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11816. type: string
  11817. type: object
  11818. remoteNamespace:
  11819. default: default
  11820. description: Remote namespace to fetch the secrets from
  11821. maxLength: 63
  11822. minLength: 1
  11823. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11824. type: string
  11825. server:
  11826. description: configures the Kubernetes server Address.
  11827. properties:
  11828. caBundle:
  11829. description: CABundle is a base64-encoded CA certificate
  11830. format: byte
  11831. type: string
  11832. caProvider:
  11833. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  11834. properties:
  11835. key:
  11836. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11837. maxLength: 253
  11838. minLength: 1
  11839. pattern: ^[-._a-zA-Z0-9]+$
  11840. type: string
  11841. name:
  11842. description: The name of the object located at the provider type.
  11843. maxLength: 253
  11844. minLength: 1
  11845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11846. type: string
  11847. namespace:
  11848. description: |-
  11849. The namespace the Provider type is in.
  11850. Can only be defined when used in a ClusterSecretStore.
  11851. maxLength: 63
  11852. minLength: 1
  11853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11854. type: string
  11855. type:
  11856. description: The type of provider to use such as "Secret", or "ConfigMap".
  11857. enum:
  11858. - Secret
  11859. - ConfigMap
  11860. type: string
  11861. required:
  11862. - name
  11863. - type
  11864. type: object
  11865. url:
  11866. default: kubernetes.default
  11867. description: configures the Kubernetes server Address.
  11868. type: string
  11869. type: object
  11870. type: object
  11871. onboardbase:
  11872. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  11873. properties:
  11874. apiHost:
  11875. default: https://public.onboardbase.com/api/v1/
  11876. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  11877. type: string
  11878. auth:
  11879. description: Auth configures how the Operator authenticates with the Onboardbase API
  11880. properties:
  11881. apiKeyRef:
  11882. description: |-
  11883. OnboardbaseAPIKey is the APIKey generated by an admin account.
  11884. It is used to recognize and authorize access to a project and environment within onboardbase
  11885. properties:
  11886. key:
  11887. description: |-
  11888. A key in the referenced Secret.
  11889. Some instances of this field may be defaulted, in others it may be required.
  11890. maxLength: 253
  11891. minLength: 1
  11892. pattern: ^[-._a-zA-Z0-9]+$
  11893. type: string
  11894. name:
  11895. description: The name of the Secret resource being referred to.
  11896. maxLength: 253
  11897. minLength: 1
  11898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11899. type: string
  11900. namespace:
  11901. description: |-
  11902. The namespace of the Secret resource being referred to.
  11903. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11904. maxLength: 63
  11905. minLength: 1
  11906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11907. type: string
  11908. type: object
  11909. passcodeRef:
  11910. description: OnboardbasePasscode is the passcode attached to the API Key
  11911. properties:
  11912. key:
  11913. description: |-
  11914. A key in the referenced Secret.
  11915. Some instances of this field may be defaulted, in others it may be required.
  11916. maxLength: 253
  11917. minLength: 1
  11918. pattern: ^[-._a-zA-Z0-9]+$
  11919. type: string
  11920. name:
  11921. description: The name of the Secret resource being referred to.
  11922. maxLength: 253
  11923. minLength: 1
  11924. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11925. type: string
  11926. namespace:
  11927. description: |-
  11928. The namespace of the Secret resource being referred to.
  11929. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11930. maxLength: 63
  11931. minLength: 1
  11932. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11933. type: string
  11934. type: object
  11935. required:
  11936. - apiKeyRef
  11937. - passcodeRef
  11938. type: object
  11939. environment:
  11940. default: development
  11941. description: Environment is the name of an environmnent within a project to pull the secrets from
  11942. type: string
  11943. project:
  11944. default: development
  11945. description: Project is an onboardbase project that the secrets should be pulled from
  11946. type: string
  11947. required:
  11948. - apiHost
  11949. - auth
  11950. - environment
  11951. - project
  11952. type: object
  11953. onepassword:
  11954. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  11955. properties:
  11956. auth:
  11957. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  11958. properties:
  11959. secretRef:
  11960. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  11961. properties:
  11962. connectTokenSecretRef:
  11963. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  11964. properties:
  11965. key:
  11966. description: |-
  11967. A key in the referenced Secret.
  11968. Some instances of this field may be defaulted, in others it may be required.
  11969. maxLength: 253
  11970. minLength: 1
  11971. pattern: ^[-._a-zA-Z0-9]+$
  11972. type: string
  11973. name:
  11974. description: The name of the Secret resource being referred to.
  11975. maxLength: 253
  11976. minLength: 1
  11977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11978. type: string
  11979. namespace:
  11980. description: |-
  11981. The namespace of the Secret resource being referred to.
  11982. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11983. maxLength: 63
  11984. minLength: 1
  11985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11986. type: string
  11987. type: object
  11988. required:
  11989. - connectTokenSecretRef
  11990. type: object
  11991. required:
  11992. - secretRef
  11993. type: object
  11994. connectHost:
  11995. description: ConnectHost defines the OnePassword Connect Server to connect to
  11996. type: string
  11997. vaults:
  11998. additionalProperties:
  11999. type: integer
  12000. description: Vaults defines which OnePassword vaults to search in which order
  12001. type: object
  12002. required:
  12003. - auth
  12004. - connectHost
  12005. - vaults
  12006. type: object
  12007. oracle:
  12008. description: Oracle configures this store to sync secrets using Oracle Vault provider
  12009. properties:
  12010. auth:
  12011. description: |-
  12012. Auth configures how secret-manager authenticates with the Oracle Vault.
  12013. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  12014. properties:
  12015. secretRef:
  12016. description: SecretRef to pass through sensitive information.
  12017. properties:
  12018. fingerprint:
  12019. description: Fingerprint is the fingerprint of the API private key.
  12020. properties:
  12021. key:
  12022. description: |-
  12023. A key in the referenced Secret.
  12024. Some instances of this field may be defaulted, in others it may be required.
  12025. maxLength: 253
  12026. minLength: 1
  12027. pattern: ^[-._a-zA-Z0-9]+$
  12028. type: string
  12029. name:
  12030. description: The name of the Secret resource being referred to.
  12031. maxLength: 253
  12032. minLength: 1
  12033. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12034. type: string
  12035. namespace:
  12036. description: |-
  12037. The namespace of the Secret resource being referred to.
  12038. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12039. maxLength: 63
  12040. minLength: 1
  12041. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12042. type: string
  12043. type: object
  12044. privatekey:
  12045. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  12046. properties:
  12047. key:
  12048. description: |-
  12049. A key in the referenced Secret.
  12050. Some instances of this field may be defaulted, in others it may be required.
  12051. maxLength: 253
  12052. minLength: 1
  12053. pattern: ^[-._a-zA-Z0-9]+$
  12054. type: string
  12055. name:
  12056. description: The name of the Secret resource being referred to.
  12057. maxLength: 253
  12058. minLength: 1
  12059. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12060. type: string
  12061. namespace:
  12062. description: |-
  12063. The namespace of the Secret resource being referred to.
  12064. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12065. maxLength: 63
  12066. minLength: 1
  12067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12068. type: string
  12069. type: object
  12070. required:
  12071. - fingerprint
  12072. - privatekey
  12073. type: object
  12074. tenancy:
  12075. description: Tenancy is the tenancy OCID where user is located.
  12076. type: string
  12077. user:
  12078. description: User is an access OCID specific to the account.
  12079. type: string
  12080. required:
  12081. - secretRef
  12082. - tenancy
  12083. - user
  12084. type: object
  12085. compartment:
  12086. description: |-
  12087. Compartment is the vault compartment OCID.
  12088. Required for PushSecret
  12089. type: string
  12090. encryptionKey:
  12091. description: |-
  12092. EncryptionKey is the OCID of the encryption key within the vault.
  12093. Required for PushSecret
  12094. type: string
  12095. principalType:
  12096. description: |-
  12097. The type of principal to use for authentication. If left blank, the Auth struct will
  12098. determine the principal type. This optional field must be specified if using
  12099. workload identity.
  12100. enum:
  12101. - ""
  12102. - UserPrincipal
  12103. - InstancePrincipal
  12104. - Workload
  12105. type: string
  12106. region:
  12107. description: Region is the region where vault is located.
  12108. type: string
  12109. serviceAccountRef:
  12110. description: |-
  12111. ServiceAccountRef specified the service account
  12112. that should be used when authenticating with WorkloadIdentity.
  12113. properties:
  12114. audiences:
  12115. description: |-
  12116. Audience specifies the `aud` claim for the service account token
  12117. Some providers automatically extend the audience field based on well-known annotations for workload
  12118. identity (e.g. IRSA or GCP Workload Identity)
  12119. items:
  12120. type: string
  12121. type: array
  12122. name:
  12123. description: The name of the ServiceAccount resource being referred to.
  12124. maxLength: 253
  12125. minLength: 1
  12126. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12127. type: string
  12128. namespace:
  12129. description: |-
  12130. Namespace of the resource being referred to.
  12131. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12132. maxLength: 63
  12133. minLength: 1
  12134. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12135. type: string
  12136. required:
  12137. - name
  12138. type: object
  12139. vault:
  12140. description: Vault is the vault's OCID of the specific vault where secret is located.
  12141. type: string
  12142. required:
  12143. - region
  12144. - vault
  12145. type: object
  12146. passbolt:
  12147. description: PassboltProvider defines configuration for the Passbolt provider.
  12148. properties:
  12149. auth:
  12150. description: Auth defines the information necessary to authenticate against Passbolt Server
  12151. properties:
  12152. passwordSecretRef:
  12153. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  12154. properties:
  12155. key:
  12156. description: |-
  12157. A key in the referenced Secret.
  12158. Some instances of this field may be defaulted, in others it may be required.
  12159. maxLength: 253
  12160. minLength: 1
  12161. pattern: ^[-._a-zA-Z0-9]+$
  12162. type: string
  12163. name:
  12164. description: The name of the Secret resource being referred to.
  12165. maxLength: 253
  12166. minLength: 1
  12167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12168. type: string
  12169. namespace:
  12170. description: |-
  12171. The namespace of the Secret resource being referred to.
  12172. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12173. maxLength: 63
  12174. minLength: 1
  12175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12176. type: string
  12177. type: object
  12178. privateKeySecretRef:
  12179. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  12180. properties:
  12181. key:
  12182. description: |-
  12183. A key in the referenced Secret.
  12184. Some instances of this field may be defaulted, in others it may be required.
  12185. maxLength: 253
  12186. minLength: 1
  12187. pattern: ^[-._a-zA-Z0-9]+$
  12188. type: string
  12189. name:
  12190. description: The name of the Secret resource being referred to.
  12191. maxLength: 253
  12192. minLength: 1
  12193. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12194. type: string
  12195. namespace:
  12196. description: |-
  12197. The namespace of the Secret resource being referred to.
  12198. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12199. maxLength: 63
  12200. minLength: 1
  12201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12202. type: string
  12203. type: object
  12204. required:
  12205. - passwordSecretRef
  12206. - privateKeySecretRef
  12207. type: object
  12208. host:
  12209. description: Host defines the Passbolt Server to connect to
  12210. type: string
  12211. required:
  12212. - auth
  12213. - host
  12214. type: object
  12215. passworddepot:
  12216. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  12217. properties:
  12218. auth:
  12219. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  12220. properties:
  12221. secretRef:
  12222. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  12223. properties:
  12224. credentials:
  12225. description: Username / Password is used for authentication.
  12226. properties:
  12227. key:
  12228. description: |-
  12229. A key in the referenced Secret.
  12230. Some instances of this field may be defaulted, in others it may be required.
  12231. maxLength: 253
  12232. minLength: 1
  12233. pattern: ^[-._a-zA-Z0-9]+$
  12234. type: string
  12235. name:
  12236. description: The name of the Secret resource being referred to.
  12237. maxLength: 253
  12238. minLength: 1
  12239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12240. type: string
  12241. namespace:
  12242. description: |-
  12243. The namespace of the Secret resource being referred to.
  12244. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12245. maxLength: 63
  12246. minLength: 1
  12247. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12248. type: string
  12249. type: object
  12250. type: object
  12251. required:
  12252. - secretRef
  12253. type: object
  12254. database:
  12255. description: Database to use as source
  12256. type: string
  12257. host:
  12258. description: URL configures the Password Depot instance URL.
  12259. type: string
  12260. required:
  12261. - auth
  12262. - database
  12263. - host
  12264. type: object
  12265. previder:
  12266. description: Previder configures this store to sync secrets using the Previder provider
  12267. properties:
  12268. auth:
  12269. description: PreviderAuth contains a secretRef for credentials.
  12270. properties:
  12271. secretRef:
  12272. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  12273. properties:
  12274. accessToken:
  12275. description: The AccessToken is used for authentication
  12276. properties:
  12277. key:
  12278. description: |-
  12279. A key in the referenced Secret.
  12280. Some instances of this field may be defaulted, in others it may be required.
  12281. maxLength: 253
  12282. minLength: 1
  12283. pattern: ^[-._a-zA-Z0-9]+$
  12284. type: string
  12285. name:
  12286. description: The name of the Secret resource being referred to.
  12287. maxLength: 253
  12288. minLength: 1
  12289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12290. type: string
  12291. namespace:
  12292. description: |-
  12293. The namespace of the Secret resource being referred to.
  12294. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12295. maxLength: 63
  12296. minLength: 1
  12297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12298. type: string
  12299. type: object
  12300. required:
  12301. - accessToken
  12302. type: object
  12303. type: object
  12304. baseUri:
  12305. type: string
  12306. required:
  12307. - auth
  12308. type: object
  12309. pulumi:
  12310. description: Pulumi configures this store to sync secrets using the Pulumi provider
  12311. properties:
  12312. accessToken:
  12313. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  12314. properties:
  12315. secretRef:
  12316. description: SecretRef is a reference to a secret containing the Pulumi API token.
  12317. properties:
  12318. key:
  12319. description: |-
  12320. A key in the referenced Secret.
  12321. Some instances of this field may be defaulted, in others it may be required.
  12322. maxLength: 253
  12323. minLength: 1
  12324. pattern: ^[-._a-zA-Z0-9]+$
  12325. type: string
  12326. name:
  12327. description: The name of the Secret resource being referred to.
  12328. maxLength: 253
  12329. minLength: 1
  12330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12331. type: string
  12332. namespace:
  12333. description: |-
  12334. The namespace of the Secret resource being referred to.
  12335. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12336. maxLength: 63
  12337. minLength: 1
  12338. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12339. type: string
  12340. type: object
  12341. type: object
  12342. apiUrl:
  12343. default: https://api.pulumi.com/api/esc
  12344. description: APIURL is the URL of the Pulumi API.
  12345. type: string
  12346. environment:
  12347. description: |-
  12348. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  12349. dynamically retrieved values from supported providers including all major clouds,
  12350. and other Pulumi ESC environments.
  12351. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  12352. type: string
  12353. organization:
  12354. description: |-
  12355. Organization are a space to collaborate on shared projects and stacks.
  12356. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  12357. type: string
  12358. project:
  12359. description: Project is the name of the Pulumi ESC project the environment belongs to.
  12360. type: string
  12361. required:
  12362. - accessToken
  12363. - environment
  12364. - organization
  12365. - project
  12366. type: object
  12367. scaleway:
  12368. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  12369. properties:
  12370. accessKey:
  12371. description: AccessKey is the non-secret part of the api key.
  12372. properties:
  12373. secretRef:
  12374. description: SecretRef references a key in a secret that will be used as value.
  12375. properties:
  12376. key:
  12377. description: |-
  12378. A key in the referenced Secret.
  12379. Some instances of this field may be defaulted, in others it may be required.
  12380. maxLength: 253
  12381. minLength: 1
  12382. pattern: ^[-._a-zA-Z0-9]+$
  12383. type: string
  12384. name:
  12385. description: The name of the Secret resource being referred to.
  12386. maxLength: 253
  12387. minLength: 1
  12388. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12389. type: string
  12390. namespace:
  12391. description: |-
  12392. The namespace of the Secret resource being referred to.
  12393. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12394. maxLength: 63
  12395. minLength: 1
  12396. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12397. type: string
  12398. type: object
  12399. value:
  12400. description: Value can be specified directly to set a value without using a secret.
  12401. type: string
  12402. type: object
  12403. apiUrl:
  12404. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  12405. type: string
  12406. projectId:
  12407. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  12408. type: string
  12409. region:
  12410. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  12411. type: string
  12412. secretKey:
  12413. description: SecretKey is the non-secret part of the api key.
  12414. properties:
  12415. secretRef:
  12416. description: SecretRef references a key in a secret that will be used as value.
  12417. properties:
  12418. key:
  12419. description: |-
  12420. A key in the referenced Secret.
  12421. Some instances of this field may be defaulted, in others it may be required.
  12422. maxLength: 253
  12423. minLength: 1
  12424. pattern: ^[-._a-zA-Z0-9]+$
  12425. type: string
  12426. name:
  12427. description: The name of the Secret resource being referred to.
  12428. maxLength: 253
  12429. minLength: 1
  12430. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12431. type: string
  12432. namespace:
  12433. description: |-
  12434. The namespace of the Secret resource being referred to.
  12435. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12436. maxLength: 63
  12437. minLength: 1
  12438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12439. type: string
  12440. type: object
  12441. value:
  12442. description: Value can be specified directly to set a value without using a secret.
  12443. type: string
  12444. type: object
  12445. required:
  12446. - accessKey
  12447. - projectId
  12448. - region
  12449. - secretKey
  12450. type: object
  12451. secretserver:
  12452. description: |-
  12453. SecretServer configures this store to sync secrets using SecretServer provider
  12454. https://docs.delinea.com/online-help/secret-server/start.htm
  12455. properties:
  12456. password:
  12457. description: Password is the secret server account password.
  12458. properties:
  12459. secretRef:
  12460. description: SecretRef references a key in a secret that will be used as value.
  12461. properties:
  12462. key:
  12463. description: |-
  12464. A key in the referenced Secret.
  12465. Some instances of this field may be defaulted, in others it may be required.
  12466. maxLength: 253
  12467. minLength: 1
  12468. pattern: ^[-._a-zA-Z0-9]+$
  12469. type: string
  12470. name:
  12471. description: The name of the Secret resource being referred to.
  12472. maxLength: 253
  12473. minLength: 1
  12474. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12475. type: string
  12476. namespace:
  12477. description: |-
  12478. The namespace of the Secret resource being referred to.
  12479. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12480. maxLength: 63
  12481. minLength: 1
  12482. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12483. type: string
  12484. type: object
  12485. value:
  12486. description: Value can be specified directly to set a value without using a secret.
  12487. type: string
  12488. type: object
  12489. serverURL:
  12490. description: |-
  12491. ServerURL
  12492. URL to your secret server installation
  12493. type: string
  12494. username:
  12495. description: Username is the secret server account username.
  12496. properties:
  12497. secretRef:
  12498. description: SecretRef references a key in a secret that will be used as value.
  12499. properties:
  12500. key:
  12501. description: |-
  12502. A key in the referenced Secret.
  12503. Some instances of this field may be defaulted, in others it may be required.
  12504. maxLength: 253
  12505. minLength: 1
  12506. pattern: ^[-._a-zA-Z0-9]+$
  12507. type: string
  12508. name:
  12509. description: The name of the Secret resource being referred to.
  12510. maxLength: 253
  12511. minLength: 1
  12512. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12513. type: string
  12514. namespace:
  12515. description: |-
  12516. The namespace of the Secret resource being referred to.
  12517. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12518. maxLength: 63
  12519. minLength: 1
  12520. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12521. type: string
  12522. type: object
  12523. value:
  12524. description: Value can be specified directly to set a value without using a secret.
  12525. type: string
  12526. type: object
  12527. required:
  12528. - password
  12529. - serverURL
  12530. - username
  12531. type: object
  12532. senhasegura:
  12533. description: Senhasegura configures this store to sync secrets using senhasegura provider
  12534. properties:
  12535. auth:
  12536. description: Auth defines parameters to authenticate in senhasegura
  12537. properties:
  12538. clientId:
  12539. type: string
  12540. clientSecretSecretRef:
  12541. description: |-
  12542. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  12543. In some instances, `key` is a required field.
  12544. properties:
  12545. key:
  12546. description: |-
  12547. A key in the referenced Secret.
  12548. Some instances of this field may be defaulted, in others it may be required.
  12549. maxLength: 253
  12550. minLength: 1
  12551. pattern: ^[-._a-zA-Z0-9]+$
  12552. type: string
  12553. name:
  12554. description: The name of the Secret resource being referred to.
  12555. maxLength: 253
  12556. minLength: 1
  12557. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12558. type: string
  12559. namespace:
  12560. description: |-
  12561. The namespace of the Secret resource being referred to.
  12562. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12563. maxLength: 63
  12564. minLength: 1
  12565. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12566. type: string
  12567. type: object
  12568. required:
  12569. - clientId
  12570. - clientSecretSecretRef
  12571. type: object
  12572. ignoreSslCertificate:
  12573. default: false
  12574. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  12575. type: boolean
  12576. module:
  12577. description: Module defines which senhasegura module should be used to get secrets
  12578. type: string
  12579. url:
  12580. description: URL of senhasegura
  12581. type: string
  12582. required:
  12583. - auth
  12584. - module
  12585. - url
  12586. type: object
  12587. vault:
  12588. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  12589. properties:
  12590. auth:
  12591. description: Auth configures how secret-manager authenticates with the Vault server.
  12592. properties:
  12593. appRole:
  12594. description: |-
  12595. AppRole authenticates with Vault using the App Role auth mechanism,
  12596. with the role and secret stored in a Kubernetes Secret resource.
  12597. properties:
  12598. path:
  12599. default: approle
  12600. description: |-
  12601. Path where the App Role authentication backend is mounted
  12602. in Vault, e.g: "approle"
  12603. type: string
  12604. roleId:
  12605. description: |-
  12606. RoleID configured in the App Role authentication backend when setting
  12607. up the authentication backend in Vault.
  12608. type: string
  12609. roleRef:
  12610. description: |-
  12611. Reference to a key in a Secret that contains the App Role ID used
  12612. to authenticate with Vault.
  12613. The `key` field must be specified and denotes which entry within the Secret
  12614. resource is used as the app role id.
  12615. properties:
  12616. key:
  12617. description: |-
  12618. A key in the referenced Secret.
  12619. Some instances of this field may be defaulted, in others it may be required.
  12620. maxLength: 253
  12621. minLength: 1
  12622. pattern: ^[-._a-zA-Z0-9]+$
  12623. type: string
  12624. name:
  12625. description: The name of the Secret resource being referred to.
  12626. maxLength: 253
  12627. minLength: 1
  12628. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12629. type: string
  12630. namespace:
  12631. description: |-
  12632. The namespace of the Secret resource being referred to.
  12633. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12634. maxLength: 63
  12635. minLength: 1
  12636. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12637. type: string
  12638. type: object
  12639. secretRef:
  12640. description: |-
  12641. Reference to a key in a Secret that contains the App Role secret used
  12642. to authenticate with Vault.
  12643. The `key` field must be specified and denotes which entry within the Secret
  12644. resource is used as the app role secret.
  12645. properties:
  12646. key:
  12647. description: |-
  12648. A key in the referenced Secret.
  12649. Some instances of this field may be defaulted, in others it may be required.
  12650. maxLength: 253
  12651. minLength: 1
  12652. pattern: ^[-._a-zA-Z0-9]+$
  12653. type: string
  12654. name:
  12655. description: The name of the Secret resource being referred to.
  12656. maxLength: 253
  12657. minLength: 1
  12658. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12659. type: string
  12660. namespace:
  12661. description: |-
  12662. The namespace of the Secret resource being referred to.
  12663. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12664. maxLength: 63
  12665. minLength: 1
  12666. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12667. type: string
  12668. type: object
  12669. required:
  12670. - path
  12671. - secretRef
  12672. type: object
  12673. cert:
  12674. description: |-
  12675. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  12676. Cert authentication method
  12677. properties:
  12678. clientCert:
  12679. description: |-
  12680. ClientCert is a certificate to authenticate using the Cert Vault
  12681. authentication method
  12682. properties:
  12683. key:
  12684. description: |-
  12685. A key in the referenced Secret.
  12686. Some instances of this field may be defaulted, in others it may be required.
  12687. maxLength: 253
  12688. minLength: 1
  12689. pattern: ^[-._a-zA-Z0-9]+$
  12690. type: string
  12691. name:
  12692. description: The name of the Secret resource being referred to.
  12693. maxLength: 253
  12694. minLength: 1
  12695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12696. type: string
  12697. namespace:
  12698. description: |-
  12699. The namespace of the Secret resource being referred to.
  12700. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12701. maxLength: 63
  12702. minLength: 1
  12703. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12704. type: string
  12705. type: object
  12706. secretRef:
  12707. description: |-
  12708. SecretRef to a key in a Secret resource containing client private key to
  12709. authenticate with Vault using the Cert authentication method
  12710. properties:
  12711. key:
  12712. description: |-
  12713. A key in the referenced Secret.
  12714. Some instances of this field may be defaulted, in others it may be required.
  12715. maxLength: 253
  12716. minLength: 1
  12717. pattern: ^[-._a-zA-Z0-9]+$
  12718. type: string
  12719. name:
  12720. description: The name of the Secret resource being referred to.
  12721. maxLength: 253
  12722. minLength: 1
  12723. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12724. type: string
  12725. namespace:
  12726. description: |-
  12727. The namespace of the Secret resource being referred to.
  12728. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12729. maxLength: 63
  12730. minLength: 1
  12731. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12732. type: string
  12733. type: object
  12734. type: object
  12735. iam:
  12736. description: |-
  12737. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  12738. AWS IAM authentication method
  12739. properties:
  12740. externalID:
  12741. description: AWS External ID set on assumed IAM roles
  12742. type: string
  12743. jwt:
  12744. description: Specify a service account with IRSA enabled
  12745. properties:
  12746. serviceAccountRef:
  12747. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  12748. properties:
  12749. audiences:
  12750. description: |-
  12751. Audience specifies the `aud` claim for the service account token
  12752. Some providers automatically extend the audience field based on well-known annotations for workload
  12753. identity (e.g. IRSA or GCP Workload Identity)
  12754. items:
  12755. type: string
  12756. type: array
  12757. name:
  12758. description: The name of the ServiceAccount resource being referred to.
  12759. maxLength: 253
  12760. minLength: 1
  12761. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12762. type: string
  12763. namespace:
  12764. description: |-
  12765. Namespace of the resource being referred to.
  12766. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12767. maxLength: 63
  12768. minLength: 1
  12769. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12770. type: string
  12771. required:
  12772. - name
  12773. type: object
  12774. type: object
  12775. path:
  12776. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  12777. type: string
  12778. region:
  12779. description: AWS region
  12780. type: string
  12781. role:
  12782. description: This is the AWS role to be assumed before talking to vault
  12783. type: string
  12784. secretRef:
  12785. description: Specify credentials in a Secret object
  12786. properties:
  12787. accessKeyIDSecretRef:
  12788. description: The AccessKeyID is used for authentication
  12789. properties:
  12790. key:
  12791. description: |-
  12792. A key in the referenced Secret.
  12793. Some instances of this field may be defaulted, in others it may be required.
  12794. maxLength: 253
  12795. minLength: 1
  12796. pattern: ^[-._a-zA-Z0-9]+$
  12797. type: string
  12798. name:
  12799. description: The name of the Secret resource being referred to.
  12800. maxLength: 253
  12801. minLength: 1
  12802. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12803. type: string
  12804. namespace:
  12805. description: |-
  12806. The namespace of the Secret resource being referred to.
  12807. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12808. maxLength: 63
  12809. minLength: 1
  12810. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12811. type: string
  12812. type: object
  12813. secretAccessKeySecretRef:
  12814. description: The SecretAccessKey is used for authentication
  12815. properties:
  12816. key:
  12817. description: |-
  12818. A key in the referenced Secret.
  12819. Some instances of this field may be defaulted, in others it may be required.
  12820. maxLength: 253
  12821. minLength: 1
  12822. pattern: ^[-._a-zA-Z0-9]+$
  12823. type: string
  12824. name:
  12825. description: The name of the Secret resource being referred to.
  12826. maxLength: 253
  12827. minLength: 1
  12828. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12829. type: string
  12830. namespace:
  12831. description: |-
  12832. The namespace of the Secret resource being referred to.
  12833. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12834. maxLength: 63
  12835. minLength: 1
  12836. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12837. type: string
  12838. type: object
  12839. sessionTokenSecretRef:
  12840. description: |-
  12841. The SessionToken used for authentication
  12842. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  12843. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  12844. properties:
  12845. key:
  12846. description: |-
  12847. A key in the referenced Secret.
  12848. Some instances of this field may be defaulted, in others it may be required.
  12849. maxLength: 253
  12850. minLength: 1
  12851. pattern: ^[-._a-zA-Z0-9]+$
  12852. type: string
  12853. name:
  12854. description: The name of the Secret resource being referred to.
  12855. maxLength: 253
  12856. minLength: 1
  12857. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12858. type: string
  12859. namespace:
  12860. description: |-
  12861. The namespace of the Secret resource being referred to.
  12862. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12863. maxLength: 63
  12864. minLength: 1
  12865. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12866. type: string
  12867. type: object
  12868. type: object
  12869. vaultAwsIamServerID:
  12870. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  12871. type: string
  12872. vaultRole:
  12873. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  12874. type: string
  12875. required:
  12876. - vaultRole
  12877. type: object
  12878. jwt:
  12879. description: |-
  12880. Jwt authenticates with Vault by passing role and JWT token using the
  12881. JWT/OIDC authentication method
  12882. properties:
  12883. kubernetesServiceAccountToken:
  12884. description: |-
  12885. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  12886. a token for with the `TokenRequest` API.
  12887. properties:
  12888. audiences:
  12889. description: |-
  12890. Optional audiences field that will be used to request a temporary Kubernetes service
  12891. account token for the service account referenced by `serviceAccountRef`.
  12892. Defaults to a single audience `vault` it not specified.
  12893. Deprecated: use serviceAccountRef.Audiences instead
  12894. items:
  12895. type: string
  12896. type: array
  12897. expirationSeconds:
  12898. description: |-
  12899. Optional expiration time in seconds that will be used to request a temporary
  12900. Kubernetes service account token for the service account referenced by
  12901. `serviceAccountRef`.
  12902. Deprecated: this will be removed in the future.
  12903. Defaults to 10 minutes.
  12904. format: int64
  12905. type: integer
  12906. serviceAccountRef:
  12907. description: Service account field containing the name of a kubernetes ServiceAccount.
  12908. properties:
  12909. audiences:
  12910. description: |-
  12911. Audience specifies the `aud` claim for the service account token
  12912. Some providers automatically extend the audience field based on well-known annotations for workload
  12913. identity (e.g. IRSA or GCP Workload Identity)
  12914. items:
  12915. type: string
  12916. type: array
  12917. name:
  12918. description: The name of the ServiceAccount resource being referred to.
  12919. maxLength: 253
  12920. minLength: 1
  12921. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12922. type: string
  12923. namespace:
  12924. description: |-
  12925. Namespace of the resource being referred to.
  12926. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12927. maxLength: 63
  12928. minLength: 1
  12929. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12930. type: string
  12931. required:
  12932. - name
  12933. type: object
  12934. required:
  12935. - serviceAccountRef
  12936. type: object
  12937. path:
  12938. default: jwt
  12939. description: |-
  12940. Path where the JWT authentication backend is mounted
  12941. in Vault, e.g: "jwt"
  12942. type: string
  12943. role:
  12944. description: |-
  12945. Role is a JWT role to authenticate using the JWT/OIDC Vault
  12946. authentication method
  12947. type: string
  12948. secretRef:
  12949. description: |-
  12950. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  12951. authenticate with Vault using the JWT/OIDC authentication method.
  12952. properties:
  12953. key:
  12954. description: |-
  12955. A key in the referenced Secret.
  12956. Some instances of this field may be defaulted, in others it may be required.
  12957. maxLength: 253
  12958. minLength: 1
  12959. pattern: ^[-._a-zA-Z0-9]+$
  12960. type: string
  12961. name:
  12962. description: The name of the Secret resource being referred to.
  12963. maxLength: 253
  12964. minLength: 1
  12965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12966. type: string
  12967. namespace:
  12968. description: |-
  12969. The namespace of the Secret resource being referred to.
  12970. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12971. maxLength: 63
  12972. minLength: 1
  12973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12974. type: string
  12975. type: object
  12976. required:
  12977. - path
  12978. type: object
  12979. kubernetes:
  12980. description: |-
  12981. Kubernetes authenticates with Vault by passing the ServiceAccount
  12982. token stored in the named Secret resource to the Vault server.
  12983. properties:
  12984. mountPath:
  12985. default: kubernetes
  12986. description: |-
  12987. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  12988. "kubernetes"
  12989. type: string
  12990. role:
  12991. description: |-
  12992. A required field containing the Vault Role to assume. A Role binds a
  12993. Kubernetes ServiceAccount with a set of Vault policies.
  12994. type: string
  12995. secretRef:
  12996. description: |-
  12997. Optional secret field containing a Kubernetes ServiceAccount JWT used
  12998. for authenticating with Vault. If a name is specified without a key,
  12999. `token` is the default. If one is not specified, the one bound to
  13000. the controller will be used.
  13001. properties:
  13002. key:
  13003. description: |-
  13004. A key in the referenced Secret.
  13005. Some instances of this field may be defaulted, in others it may be required.
  13006. maxLength: 253
  13007. minLength: 1
  13008. pattern: ^[-._a-zA-Z0-9]+$
  13009. type: string
  13010. name:
  13011. description: The name of the Secret resource being referred to.
  13012. maxLength: 253
  13013. minLength: 1
  13014. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13015. type: string
  13016. namespace:
  13017. description: |-
  13018. The namespace of the Secret resource being referred to.
  13019. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13020. maxLength: 63
  13021. minLength: 1
  13022. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13023. type: string
  13024. type: object
  13025. serviceAccountRef:
  13026. description: |-
  13027. Optional service account field containing the name of a kubernetes ServiceAccount.
  13028. If the service account is specified, the service account secret token JWT will be used
  13029. for authenticating with Vault. If the service account selector is not supplied,
  13030. the secretRef will be used instead.
  13031. properties:
  13032. audiences:
  13033. description: |-
  13034. Audience specifies the `aud` claim for the service account token
  13035. Some providers automatically extend the audience field based on well-known annotations for workload
  13036. identity (e.g. IRSA or GCP Workload Identity)
  13037. items:
  13038. type: string
  13039. type: array
  13040. name:
  13041. description: The name of the ServiceAccount resource being referred to.
  13042. maxLength: 253
  13043. minLength: 1
  13044. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13045. type: string
  13046. namespace:
  13047. description: |-
  13048. Namespace of the resource being referred to.
  13049. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13050. maxLength: 63
  13051. minLength: 1
  13052. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13053. type: string
  13054. required:
  13055. - name
  13056. type: object
  13057. required:
  13058. - mountPath
  13059. - role
  13060. type: object
  13061. ldap:
  13062. description: |-
  13063. Ldap authenticates with Vault by passing username/password pair using
  13064. the LDAP authentication method
  13065. properties:
  13066. path:
  13067. default: ldap
  13068. description: |-
  13069. Path where the LDAP authentication backend is mounted
  13070. in Vault, e.g: "ldap"
  13071. type: string
  13072. secretRef:
  13073. description: |-
  13074. SecretRef to a key in a Secret resource containing password for the LDAP
  13075. user used to authenticate with Vault using the LDAP authentication
  13076. method
  13077. properties:
  13078. key:
  13079. description: |-
  13080. A key in the referenced Secret.
  13081. Some instances of this field may be defaulted, in others it may be required.
  13082. maxLength: 253
  13083. minLength: 1
  13084. pattern: ^[-._a-zA-Z0-9]+$
  13085. type: string
  13086. name:
  13087. description: The name of the Secret resource being referred to.
  13088. maxLength: 253
  13089. minLength: 1
  13090. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13091. type: string
  13092. namespace:
  13093. description: |-
  13094. The namespace of the Secret resource being referred to.
  13095. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13096. maxLength: 63
  13097. minLength: 1
  13098. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13099. type: string
  13100. type: object
  13101. username:
  13102. description: |-
  13103. Username is an LDAP username used to authenticate using the LDAP Vault
  13104. authentication method
  13105. type: string
  13106. required:
  13107. - path
  13108. - username
  13109. type: object
  13110. namespace:
  13111. description: |-
  13112. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  13113. Namespaces is a set of features within Vault Enterprise that allows
  13114. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  13115. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  13116. This will default to Vault.Namespace field if set, or empty otherwise
  13117. type: string
  13118. tokenSecretRef:
  13119. description: TokenSecretRef authenticates with Vault by presenting a token.
  13120. properties:
  13121. key:
  13122. description: |-
  13123. A key in the referenced Secret.
  13124. Some instances of this field may be defaulted, in others it may be required.
  13125. maxLength: 253
  13126. minLength: 1
  13127. pattern: ^[-._a-zA-Z0-9]+$
  13128. type: string
  13129. name:
  13130. description: The name of the Secret resource being referred to.
  13131. maxLength: 253
  13132. minLength: 1
  13133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13134. type: string
  13135. namespace:
  13136. description: |-
  13137. The namespace of the Secret resource being referred to.
  13138. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13139. maxLength: 63
  13140. minLength: 1
  13141. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13142. type: string
  13143. type: object
  13144. userPass:
  13145. description: UserPass authenticates with Vault by passing username/password pair
  13146. properties:
  13147. path:
  13148. default: userpass
  13149. description: |-
  13150. Path where the UserPassword authentication backend is mounted
  13151. in Vault, e.g: "userpass"
  13152. type: string
  13153. secretRef:
  13154. description: |-
  13155. SecretRef to a key in a Secret resource containing password for the
  13156. user used to authenticate with Vault using the UserPass authentication
  13157. method
  13158. properties:
  13159. key:
  13160. description: |-
  13161. A key in the referenced Secret.
  13162. Some instances of this field may be defaulted, in others it may be required.
  13163. maxLength: 253
  13164. minLength: 1
  13165. pattern: ^[-._a-zA-Z0-9]+$
  13166. type: string
  13167. name:
  13168. description: The name of the Secret resource being referred to.
  13169. maxLength: 253
  13170. minLength: 1
  13171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13172. type: string
  13173. namespace:
  13174. description: |-
  13175. The namespace of the Secret resource being referred to.
  13176. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13177. maxLength: 63
  13178. minLength: 1
  13179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13180. type: string
  13181. type: object
  13182. username:
  13183. description: |-
  13184. Username is a username used to authenticate using the UserPass Vault
  13185. authentication method
  13186. type: string
  13187. required:
  13188. - path
  13189. - username
  13190. type: object
  13191. type: object
  13192. caBundle:
  13193. description: |-
  13194. PEM encoded CA bundle used to validate Vault server certificate. Only used
  13195. if the Server URL is using HTTPS protocol. This parameter is ignored for
  13196. plain HTTP protocol connection. If not set the system root certificates
  13197. are used to validate the TLS connection.
  13198. format: byte
  13199. type: string
  13200. caProvider:
  13201. description: The provider for the CA bundle to use to validate Vault server certificate.
  13202. properties:
  13203. key:
  13204. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  13205. maxLength: 253
  13206. minLength: 1
  13207. pattern: ^[-._a-zA-Z0-9]+$
  13208. type: string
  13209. name:
  13210. description: The name of the object located at the provider type.
  13211. maxLength: 253
  13212. minLength: 1
  13213. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13214. type: string
  13215. namespace:
  13216. description: |-
  13217. The namespace the Provider type is in.
  13218. Can only be defined when used in a ClusterSecretStore.
  13219. maxLength: 63
  13220. minLength: 1
  13221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13222. type: string
  13223. type:
  13224. description: The type of provider to use such as "Secret", or "ConfigMap".
  13225. enum:
  13226. - Secret
  13227. - ConfigMap
  13228. type: string
  13229. required:
  13230. - name
  13231. - type
  13232. type: object
  13233. forwardInconsistent:
  13234. description: |-
  13235. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  13236. leader instead of simply retrying within a loop. This can increase performance if
  13237. the option is enabled serverside.
  13238. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  13239. type: boolean
  13240. headers:
  13241. additionalProperties:
  13242. type: string
  13243. description: Headers to be added in Vault request
  13244. type: object
  13245. namespace:
  13246. description: |-
  13247. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  13248. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  13249. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  13250. type: string
  13251. path:
  13252. description: |-
  13253. Path is the mount path of the Vault KV backend endpoint, e.g:
  13254. "secret". The v2 KV secret engine version specific "/data" path suffix
  13255. for fetching secrets from Vault is optional and will be appended
  13256. if not present in specified path.
  13257. type: string
  13258. readYourWrites:
  13259. description: |-
  13260. ReadYourWrites ensures isolated read-after-write semantics by
  13261. providing discovered cluster replication states in each request.
  13262. More information about eventual consistency in Vault can be found here
  13263. https://www.vaultproject.io/docs/enterprise/consistency
  13264. type: boolean
  13265. server:
  13266. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  13267. type: string
  13268. tls:
  13269. description: |-
  13270. The configuration used for client side related TLS communication, when the Vault server
  13271. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  13272. This parameter is ignored for plain HTTP protocol connection.
  13273. It's worth noting this configuration is different from the "TLS certificates auth method",
  13274. which is available under the `auth.cert` section.
  13275. properties:
  13276. certSecretRef:
  13277. description: |-
  13278. CertSecretRef is a certificate added to the transport layer
  13279. when communicating with the Vault server.
  13280. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  13281. properties:
  13282. key:
  13283. description: |-
  13284. A key in the referenced Secret.
  13285. Some instances of this field may be defaulted, in others it may be required.
  13286. maxLength: 253
  13287. minLength: 1
  13288. pattern: ^[-._a-zA-Z0-9]+$
  13289. type: string
  13290. name:
  13291. description: The name of the Secret resource being referred to.
  13292. maxLength: 253
  13293. minLength: 1
  13294. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13295. type: string
  13296. namespace:
  13297. description: |-
  13298. The namespace of the Secret resource being referred to.
  13299. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13300. maxLength: 63
  13301. minLength: 1
  13302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13303. type: string
  13304. type: object
  13305. keySecretRef:
  13306. description: |-
  13307. KeySecretRef to a key in a Secret resource containing client private key
  13308. added to the transport layer when communicating with the Vault server.
  13309. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  13310. properties:
  13311. key:
  13312. description: |-
  13313. A key in the referenced Secret.
  13314. Some instances of this field may be defaulted, in others it may be required.
  13315. maxLength: 253
  13316. minLength: 1
  13317. pattern: ^[-._a-zA-Z0-9]+$
  13318. type: string
  13319. name:
  13320. description: The name of the Secret resource being referred to.
  13321. maxLength: 253
  13322. minLength: 1
  13323. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13324. type: string
  13325. namespace:
  13326. description: |-
  13327. The namespace of the Secret resource being referred to.
  13328. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13329. maxLength: 63
  13330. minLength: 1
  13331. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13332. type: string
  13333. type: object
  13334. type: object
  13335. version:
  13336. default: v2
  13337. description: |-
  13338. Version is the Vault KV secret engine version. This can be either "v1" or
  13339. "v2". Version defaults to "v2".
  13340. enum:
  13341. - v1
  13342. - v2
  13343. type: string
  13344. required:
  13345. - server
  13346. type: object
  13347. webhook:
  13348. description: Webhook configures this store to sync secrets using a generic templated webhook
  13349. properties:
  13350. auth:
  13351. description: Auth specifies a authorization protocol. Only one protocol may be set.
  13352. maxProperties: 1
  13353. minProperties: 1
  13354. properties:
  13355. ntlm:
  13356. description: NTLMProtocol configures the store to use NTLM for auth
  13357. properties:
  13358. passwordSecret:
  13359. description: |-
  13360. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13361. In some instances, `key` is a required field.
  13362. properties:
  13363. key:
  13364. description: |-
  13365. A key in the referenced Secret.
  13366. Some instances of this field may be defaulted, in others it may be required.
  13367. maxLength: 253
  13368. minLength: 1
  13369. pattern: ^[-._a-zA-Z0-9]+$
  13370. type: string
  13371. name:
  13372. description: The name of the Secret resource being referred to.
  13373. maxLength: 253
  13374. minLength: 1
  13375. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13376. type: string
  13377. namespace:
  13378. description: |-
  13379. The namespace of the Secret resource being referred to.
  13380. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13381. maxLength: 63
  13382. minLength: 1
  13383. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13384. type: string
  13385. type: object
  13386. usernameSecret:
  13387. description: |-
  13388. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13389. In some instances, `key` is a required field.
  13390. properties:
  13391. key:
  13392. description: |-
  13393. A key in the referenced Secret.
  13394. Some instances of this field may be defaulted, in others it may be required.
  13395. maxLength: 253
  13396. minLength: 1
  13397. pattern: ^[-._a-zA-Z0-9]+$
  13398. type: string
  13399. name:
  13400. description: The name of the Secret resource being referred to.
  13401. maxLength: 253
  13402. minLength: 1
  13403. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13404. type: string
  13405. namespace:
  13406. description: |-
  13407. The namespace of the Secret resource being referred to.
  13408. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13409. maxLength: 63
  13410. minLength: 1
  13411. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13412. type: string
  13413. type: object
  13414. required:
  13415. - passwordSecret
  13416. - usernameSecret
  13417. type: object
  13418. type: object
  13419. body:
  13420. description: Body
  13421. type: string
  13422. caBundle:
  13423. description: |-
  13424. PEM encoded CA bundle used to validate webhook server certificate. Only used
  13425. if the Server URL is using HTTPS protocol. This parameter is ignored for
  13426. plain HTTP protocol connection. If not set the system root certificates
  13427. are used to validate the TLS connection.
  13428. format: byte
  13429. type: string
  13430. caProvider:
  13431. description: The provider for the CA bundle to use to validate webhook server certificate.
  13432. properties:
  13433. key:
  13434. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  13435. maxLength: 253
  13436. minLength: 1
  13437. pattern: ^[-._a-zA-Z0-9]+$
  13438. type: string
  13439. name:
  13440. description: The name of the object located at the provider type.
  13441. maxLength: 253
  13442. minLength: 1
  13443. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13444. type: string
  13445. namespace:
  13446. description: The namespace the Provider type is in.
  13447. maxLength: 63
  13448. minLength: 1
  13449. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13450. type: string
  13451. type:
  13452. description: The type of provider to use such as "Secret", or "ConfigMap".
  13453. enum:
  13454. - Secret
  13455. - ConfigMap
  13456. type: string
  13457. required:
  13458. - name
  13459. - type
  13460. type: object
  13461. headers:
  13462. additionalProperties:
  13463. type: string
  13464. description: Headers
  13465. type: object
  13466. method:
  13467. description: Webhook Method
  13468. type: string
  13469. result:
  13470. description: Result formatting
  13471. properties:
  13472. jsonPath:
  13473. description: Json path of return value
  13474. type: string
  13475. type: object
  13476. secrets:
  13477. description: |-
  13478. Secrets to fill in templates
  13479. These secrets will be passed to the templating function as key value pairs under the given name
  13480. items:
  13481. description: WebhookSecret defines a secret to be used in webhook templates.
  13482. properties:
  13483. name:
  13484. description: Name of this secret in templates
  13485. type: string
  13486. secretRef:
  13487. description: Secret ref to fill in credentials
  13488. properties:
  13489. key:
  13490. description: |-
  13491. A key in the referenced Secret.
  13492. Some instances of this field may be defaulted, in others it may be required.
  13493. maxLength: 253
  13494. minLength: 1
  13495. pattern: ^[-._a-zA-Z0-9]+$
  13496. type: string
  13497. name:
  13498. description: The name of the Secret resource being referred to.
  13499. maxLength: 253
  13500. minLength: 1
  13501. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13502. type: string
  13503. namespace:
  13504. description: |-
  13505. The namespace of the Secret resource being referred to.
  13506. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13507. maxLength: 63
  13508. minLength: 1
  13509. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13510. type: string
  13511. type: object
  13512. required:
  13513. - name
  13514. - secretRef
  13515. type: object
  13516. type: array
  13517. timeout:
  13518. description: Timeout
  13519. type: string
  13520. url:
  13521. description: Webhook url to call
  13522. type: string
  13523. required:
  13524. - result
  13525. - url
  13526. type: object
  13527. yandexcertificatemanager:
  13528. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  13529. properties:
  13530. apiEndpoint:
  13531. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13532. type: string
  13533. auth:
  13534. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  13535. properties:
  13536. authorizedKeySecretRef:
  13537. description: The authorized key used for authentication
  13538. properties:
  13539. key:
  13540. description: |-
  13541. A key in the referenced Secret.
  13542. Some instances of this field may be defaulted, in others it may be required.
  13543. maxLength: 253
  13544. minLength: 1
  13545. pattern: ^[-._a-zA-Z0-9]+$
  13546. type: string
  13547. name:
  13548. description: The name of the Secret resource being referred to.
  13549. maxLength: 253
  13550. minLength: 1
  13551. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13552. type: string
  13553. namespace:
  13554. description: |-
  13555. The namespace of the Secret resource being referred to.
  13556. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13557. maxLength: 63
  13558. minLength: 1
  13559. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13560. type: string
  13561. type: object
  13562. type: object
  13563. caProvider:
  13564. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13565. properties:
  13566. certSecretRef:
  13567. description: |-
  13568. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13569. In some instances, `key` is a required field.
  13570. properties:
  13571. key:
  13572. description: |-
  13573. A key in the referenced Secret.
  13574. Some instances of this field may be defaulted, in others it may be required.
  13575. maxLength: 253
  13576. minLength: 1
  13577. pattern: ^[-._a-zA-Z0-9]+$
  13578. type: string
  13579. name:
  13580. description: The name of the Secret resource being referred to.
  13581. maxLength: 253
  13582. minLength: 1
  13583. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13584. type: string
  13585. namespace:
  13586. description: |-
  13587. The namespace of the Secret resource being referred to.
  13588. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13589. maxLength: 63
  13590. minLength: 1
  13591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13592. type: string
  13593. type: object
  13594. type: object
  13595. required:
  13596. - auth
  13597. type: object
  13598. yandexlockbox:
  13599. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  13600. properties:
  13601. apiEndpoint:
  13602. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13603. type: string
  13604. auth:
  13605. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  13606. properties:
  13607. authorizedKeySecretRef:
  13608. description: The authorized key used for authentication
  13609. properties:
  13610. key:
  13611. description: |-
  13612. A key in the referenced Secret.
  13613. Some instances of this field may be defaulted, in others it may be required.
  13614. maxLength: 253
  13615. minLength: 1
  13616. pattern: ^[-._a-zA-Z0-9]+$
  13617. type: string
  13618. name:
  13619. description: The name of the Secret resource being referred to.
  13620. maxLength: 253
  13621. minLength: 1
  13622. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13623. type: string
  13624. namespace:
  13625. description: |-
  13626. The namespace of the Secret resource being referred to.
  13627. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13628. maxLength: 63
  13629. minLength: 1
  13630. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13631. type: string
  13632. type: object
  13633. type: object
  13634. caProvider:
  13635. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13636. properties:
  13637. certSecretRef:
  13638. description: |-
  13639. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13640. In some instances, `key` is a required field.
  13641. properties:
  13642. key:
  13643. description: |-
  13644. A key in the referenced Secret.
  13645. Some instances of this field may be defaulted, in others it may be required.
  13646. maxLength: 253
  13647. minLength: 1
  13648. pattern: ^[-._a-zA-Z0-9]+$
  13649. type: string
  13650. name:
  13651. description: The name of the Secret resource being referred to.
  13652. maxLength: 253
  13653. minLength: 1
  13654. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13655. type: string
  13656. namespace:
  13657. description: |-
  13658. The namespace of the Secret resource being referred to.
  13659. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13660. maxLength: 63
  13661. minLength: 1
  13662. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13663. type: string
  13664. type: object
  13665. type: object
  13666. required:
  13667. - auth
  13668. type: object
  13669. type: object
  13670. refreshInterval:
  13671. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  13672. type: integer
  13673. retrySettings:
  13674. description: Used to configure HTTP retries on failures.
  13675. properties:
  13676. maxRetries:
  13677. description: MaxRetries is the maximum number of retry attempts.
  13678. format: int32
  13679. type: integer
  13680. retryInterval:
  13681. description: RetryInterval is the interval between retry attempts.
  13682. type: string
  13683. type: object
  13684. required:
  13685. - provider
  13686. type: object
  13687. status:
  13688. description: SecretStoreStatus defines the observed state of the SecretStore.
  13689. properties:
  13690. capabilities:
  13691. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  13692. type: string
  13693. conditions:
  13694. items:
  13695. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  13696. properties:
  13697. lastTransitionTime:
  13698. format: date-time
  13699. type: string
  13700. message:
  13701. type: string
  13702. reason:
  13703. type: string
  13704. status:
  13705. type: string
  13706. type:
  13707. description: SecretStoreConditionType represents the condition type of the SecretStore.
  13708. type: string
  13709. required:
  13710. - status
  13711. - type
  13712. type: object
  13713. type: array
  13714. type: object
  13715. type: object
  13716. served: false
  13717. storage: false
  13718. subresources:
  13719. status: {}
  13720. ---
  13721. apiVersion: apiextensions.k8s.io/v1
  13722. kind: CustomResourceDefinition
  13723. metadata:
  13724. annotations:
  13725. controller-gen.kubebuilder.io/version: v0.19.0
  13726. labels:
  13727. external-secrets.io/component: controller
  13728. name: externalsecrets.external-secrets.io
  13729. spec:
  13730. group: external-secrets.io
  13731. names:
  13732. categories:
  13733. - external-secrets
  13734. kind: ExternalSecret
  13735. listKind: ExternalSecretList
  13736. plural: externalsecrets
  13737. shortNames:
  13738. - es
  13739. singular: externalsecret
  13740. scope: Namespaced
  13741. versions:
  13742. - additionalPrinterColumns:
  13743. - jsonPath: .spec.secretStoreRef.kind
  13744. name: StoreType
  13745. type: string
  13746. - jsonPath: .spec.secretStoreRef.name
  13747. name: Store
  13748. type: string
  13749. - jsonPath: .spec.refreshInterval
  13750. name: Refresh Interval
  13751. type: string
  13752. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  13753. name: Status
  13754. type: string
  13755. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  13756. name: Ready
  13757. type: string
  13758. - jsonPath: .status.refreshTime
  13759. name: Last Sync
  13760. type: date
  13761. name: v1
  13762. schema:
  13763. openAPIV3Schema:
  13764. description: |-
  13765. ExternalSecret is the Schema for the external-secrets API.
  13766. It defines how to fetch data from external APIs and make it available as Kubernetes Secrets.
  13767. properties:
  13768. apiVersion:
  13769. description: |-
  13770. APIVersion defines the versioned schema of this representation of an object.
  13771. Servers should convert recognized schemas to the latest internal value, and
  13772. may reject unrecognized values.
  13773. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  13774. type: string
  13775. kind:
  13776. description: |-
  13777. Kind is a string value representing the REST resource this object represents.
  13778. Servers may infer this from the endpoint the client submits requests to.
  13779. Cannot be updated.
  13780. In CamelCase.
  13781. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  13782. type: string
  13783. metadata:
  13784. type: object
  13785. spec:
  13786. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  13787. properties:
  13788. data:
  13789. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  13790. items:
  13791. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  13792. properties:
  13793. remoteRef:
  13794. description: |-
  13795. RemoteRef points to the remote secret and defines
  13796. which secret (version/property/..) to fetch.
  13797. properties:
  13798. conversionStrategy:
  13799. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  13800. enum:
  13801. - Default
  13802. - Unicode
  13803. type: string
  13804. decodingStrategy:
  13805. description: Used to define a decoding Strategy. Defaults to None when omitted.
  13806. enum:
  13807. - Auto
  13808. - Base64
  13809. - Base64URL
  13810. - None
  13811. type: string
  13812. key:
  13813. description: Key is the key used in the Provider, mandatory
  13814. type: string
  13815. metadataPolicy:
  13816. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13817. enum:
  13818. - None
  13819. - Fetch
  13820. type: string
  13821. nullBytePolicy:
  13822. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13823. enum:
  13824. - Ignore
  13825. - Fail
  13826. type: string
  13827. property:
  13828. description: Used to select a specific property of the Provider value (if a map), if supported
  13829. type: string
  13830. version:
  13831. description: Used to select a specific version of the Provider value, if supported
  13832. type: string
  13833. required:
  13834. - key
  13835. type: object
  13836. secretKey:
  13837. description: The key in the Kubernetes Secret to store the value.
  13838. maxLength: 253
  13839. minLength: 1
  13840. pattern: ^[-._a-zA-Z0-9]+$
  13841. type: string
  13842. sourceRef:
  13843. description: |-
  13844. SourceRef allows you to override the source
  13845. from which the value will be pulled.
  13846. maxProperties: 1
  13847. minProperties: 1
  13848. properties:
  13849. generatorRef:
  13850. description: |-
  13851. GeneratorRef points to a generator custom resource.
  13852. Deprecated: The generatorRef is not implemented in .data[].
  13853. this will be removed with v1.
  13854. properties:
  13855. apiVersion:
  13856. default: generators.external-secrets.io/v1alpha1
  13857. description: Specify the apiVersion of the generator resource
  13858. type: string
  13859. kind:
  13860. description: Specify the Kind of the generator resource
  13861. enum:
  13862. - ACRAccessToken
  13863. - BeyondtrustWorkloadCredentialsDynamicSecret
  13864. - ClusterGenerator
  13865. - CloudsmithAccessToken
  13866. - ECRAuthorizationToken
  13867. - Fake
  13868. - GCRAccessToken
  13869. - GithubAccessToken
  13870. - GitlabDeployToken
  13871. - QuayAccessToken
  13872. - Password
  13873. - SSHKey
  13874. - STSSessionToken
  13875. - UUID
  13876. - VaultDynamicSecret
  13877. - Webhook
  13878. - Grafana
  13879. - MFA
  13880. type: string
  13881. name:
  13882. description: Specify the name of the generator resource
  13883. maxLength: 253
  13884. minLength: 1
  13885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13886. type: string
  13887. required:
  13888. - kind
  13889. - name
  13890. type: object
  13891. storeRef:
  13892. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13893. properties:
  13894. kind:
  13895. description: |-
  13896. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13897. Defaults to `SecretStore`
  13898. enum:
  13899. - SecretStore
  13900. - ClusterSecretStore
  13901. type: string
  13902. name:
  13903. description: Name of the SecretStore resource
  13904. maxLength: 253
  13905. minLength: 1
  13906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13907. type: string
  13908. type: object
  13909. type: object
  13910. required:
  13911. - remoteRef
  13912. - secretKey
  13913. type: object
  13914. type: array
  13915. dataFrom:
  13916. description: |-
  13917. DataFrom is used to fetch all properties from a specific Provider data
  13918. If multiple entries are specified, the Secret keys are merged in the specified order
  13919. items:
  13920. description: |-
  13921. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  13922. when using DataFrom to fetch multiple values from a Provider.
  13923. properties:
  13924. extract:
  13925. description: |-
  13926. Used to extract multiple key/value pairs from one secret
  13927. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13928. properties:
  13929. conversionStrategy:
  13930. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  13931. enum:
  13932. - Default
  13933. - Unicode
  13934. type: string
  13935. decodingStrategy:
  13936. description: Used to define a decoding Strategy. Defaults to None when omitted.
  13937. enum:
  13938. - Auto
  13939. - Base64
  13940. - Base64URL
  13941. - None
  13942. type: string
  13943. key:
  13944. description: Key is the key used in the Provider, mandatory
  13945. type: string
  13946. metadataPolicy:
  13947. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13948. enum:
  13949. - None
  13950. - Fetch
  13951. type: string
  13952. nullBytePolicy:
  13953. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13954. enum:
  13955. - Ignore
  13956. - Fail
  13957. type: string
  13958. property:
  13959. description: Used to select a specific property of the Provider value (if a map), if supported
  13960. type: string
  13961. version:
  13962. description: Used to select a specific version of the Provider value, if supported
  13963. type: string
  13964. required:
  13965. - key
  13966. type: object
  13967. find:
  13968. description: |-
  13969. Used to find secrets based on tags or regular expressions
  13970. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13971. properties:
  13972. conversionStrategy:
  13973. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  13974. enum:
  13975. - Default
  13976. - Unicode
  13977. type: string
  13978. decodingStrategy:
  13979. description: Used to define a decoding Strategy. Defaults to None when omitted.
  13980. enum:
  13981. - Auto
  13982. - Base64
  13983. - Base64URL
  13984. - None
  13985. type: string
  13986. name:
  13987. description: Finds secrets based on the name.
  13988. properties:
  13989. regexp:
  13990. description: Finds secrets base
  13991. type: string
  13992. type: object
  13993. nullBytePolicy:
  13994. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  13995. enum:
  13996. - Ignore
  13997. - Fail
  13998. type: string
  13999. path:
  14000. description: A root path to start the find operations.
  14001. type: string
  14002. tags:
  14003. additionalProperties:
  14004. type: string
  14005. description: Find secrets based on tags.
  14006. type: object
  14007. type: object
  14008. rewrite:
  14009. description: |-
  14010. Used to rewrite secret Keys after getting them from the secret Provider
  14011. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  14012. items:
  14013. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  14014. maxProperties: 1
  14015. minProperties: 1
  14016. properties:
  14017. merge:
  14018. description: |-
  14019. Used to merge key/values in one single Secret
  14020. The resulting key will contain all values from the specified secrets
  14021. properties:
  14022. conflictPolicy:
  14023. default: Error
  14024. description: Used to define the policy to use in conflict resolution.
  14025. enum:
  14026. - Ignore
  14027. - Error
  14028. type: string
  14029. into:
  14030. default: ""
  14031. description: |-
  14032. Used to define the target key of the merge operation.
  14033. Required if strategy is JSON. Ignored otherwise.
  14034. type: string
  14035. priority:
  14036. description: Used to define key priority in conflict resolution.
  14037. items:
  14038. type: string
  14039. type: array
  14040. priorityPolicy:
  14041. default: Strict
  14042. description: Used to define the policy when a key in the priority list does not exist in the input.
  14043. enum:
  14044. - IgnoreNotFound
  14045. - Strict
  14046. type: string
  14047. strategy:
  14048. default: Extract
  14049. description: Used to define the strategy to use in the merge operation.
  14050. enum:
  14051. - Extract
  14052. - JSON
  14053. type: string
  14054. type: object
  14055. regexp:
  14056. description: |-
  14057. Used to rewrite with regular expressions.
  14058. The resulting key will be the output of a regexp.ReplaceAll operation.
  14059. properties:
  14060. source:
  14061. description: Used to define the regular expression of a re.Compiler.
  14062. type: string
  14063. target:
  14064. description: Used to define the target pattern of a ReplaceAll operation.
  14065. type: string
  14066. required:
  14067. - source
  14068. - target
  14069. type: object
  14070. transform:
  14071. description: |-
  14072. Used to apply string transformation on the secrets.
  14073. The resulting key will be the output of the template applied by the operation.
  14074. properties:
  14075. template:
  14076. description: |-
  14077. Used to define the template to apply on the secret name.
  14078. `.value ` will specify the secret name in the template.
  14079. type: string
  14080. required:
  14081. - template
  14082. type: object
  14083. type: object
  14084. type: array
  14085. sourceRef:
  14086. description: |-
  14087. SourceRef points to a store or generator
  14088. which contains secret values ready to use.
  14089. Use this in combination with Extract or Find pull values out of
  14090. a specific SecretStore.
  14091. When sourceRef points to a generator Extract or Find is not supported.
  14092. The generator returns a static map of values
  14093. maxProperties: 1
  14094. minProperties: 1
  14095. properties:
  14096. generatorRef:
  14097. description: GeneratorRef points to a generator custom resource.
  14098. properties:
  14099. apiVersion:
  14100. default: generators.external-secrets.io/v1alpha1
  14101. description: Specify the apiVersion of the generator resource
  14102. type: string
  14103. kind:
  14104. description: Specify the Kind of the generator resource
  14105. enum:
  14106. - ACRAccessToken
  14107. - BeyondtrustWorkloadCredentialsDynamicSecret
  14108. - ClusterGenerator
  14109. - CloudsmithAccessToken
  14110. - ECRAuthorizationToken
  14111. - Fake
  14112. - GCRAccessToken
  14113. - GithubAccessToken
  14114. - GitlabDeployToken
  14115. - QuayAccessToken
  14116. - Password
  14117. - SSHKey
  14118. - STSSessionToken
  14119. - UUID
  14120. - VaultDynamicSecret
  14121. - Webhook
  14122. - Grafana
  14123. - MFA
  14124. type: string
  14125. name:
  14126. description: Specify the name of the generator resource
  14127. maxLength: 253
  14128. minLength: 1
  14129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14130. type: string
  14131. required:
  14132. - kind
  14133. - name
  14134. type: object
  14135. storeRef:
  14136. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14137. properties:
  14138. kind:
  14139. description: |-
  14140. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14141. Defaults to `SecretStore`
  14142. enum:
  14143. - SecretStore
  14144. - ClusterSecretStore
  14145. type: string
  14146. name:
  14147. description: Name of the SecretStore resource
  14148. maxLength: 253
  14149. minLength: 1
  14150. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14151. type: string
  14152. type: object
  14153. type: object
  14154. type: object
  14155. type: array
  14156. refreshInterval:
  14157. default: 1h0m0s
  14158. description: |-
  14159. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  14160. specified as Golang Duration strings.
  14161. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  14162. Example values: "1h0m0s", "2h30m0s", "10m0s"
  14163. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  14164. type: string
  14165. refreshPolicy:
  14166. description: |-
  14167. RefreshPolicy determines how the ExternalSecret should be refreshed:
  14168. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  14169. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  14170. No periodic updates occur if refreshInterval is 0.
  14171. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  14172. enum:
  14173. - CreatedOnce
  14174. - Periodic
  14175. - OnChange
  14176. type: string
  14177. secretStoreRef:
  14178. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14179. properties:
  14180. kind:
  14181. description: |-
  14182. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14183. Defaults to `SecretStore`
  14184. enum:
  14185. - SecretStore
  14186. - ClusterSecretStore
  14187. type: string
  14188. name:
  14189. description: Name of the SecretStore resource
  14190. maxLength: 253
  14191. minLength: 1
  14192. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14193. type: string
  14194. type: object
  14195. syncWindows:
  14196. description: |-
  14197. SyncWindows optionally restricts when periodic refreshes may occur.
  14198. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  14199. properties:
  14200. kind:
  14201. description: |-
  14202. Kind applies to every window in the list.
  14203. "allow" -- syncs are permitted only while at least one window is active;
  14204. all other times are blocked.
  14205. "deny" -- syncs are blocked while any window is active;
  14206. all other times are permitted.
  14207. enum:
  14208. - allow
  14209. - deny
  14210. type: string
  14211. windows:
  14212. description: Windows is the list of schedule+duration pairs.
  14213. items:
  14214. description: |-
  14215. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  14216. within a SyncWindows block.
  14217. properties:
  14218. duration:
  14219. description: |-
  14220. Duration specifies how long the window stays open after each Schedule
  14221. firing. Example: "8h".
  14222. type: string
  14223. schedule:
  14224. description: |-
  14225. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  14226. named shorthand such as @daily or @every 1h. It marks the start time of
  14227. each window occurrence.
  14228. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  14229. minLength: 1
  14230. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  14231. type: string
  14232. required:
  14233. - duration
  14234. - schedule
  14235. type: object
  14236. minItems: 1
  14237. type: array
  14238. required:
  14239. - kind
  14240. - windows
  14241. type: object
  14242. target:
  14243. default:
  14244. creationPolicy: Owner
  14245. deletionPolicy: Retain
  14246. description: |-
  14247. ExternalSecretTarget defines the Kubernetes Secret to be created,
  14248. there can be only one target per ExternalSecret.
  14249. properties:
  14250. creationPolicy:
  14251. default: Owner
  14252. description: |-
  14253. CreationPolicy defines rules on how to create the resulting Secret.
  14254. Defaults to "Owner"
  14255. enum:
  14256. - Owner
  14257. - Orphan
  14258. - Merge
  14259. - None
  14260. - CreateOrMerge
  14261. type: string
  14262. deletionPolicy:
  14263. default: Retain
  14264. description: |-
  14265. DeletionPolicy defines rules on how to delete the resulting Secret.
  14266. Defaults to "Retain"
  14267. enum:
  14268. - Delete
  14269. - Merge
  14270. - Retain
  14271. type: string
  14272. immutable:
  14273. description: Immutable defines if the final secret will be immutable
  14274. type: boolean
  14275. manifest:
  14276. description: |-
  14277. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  14278. When specified, ExternalSecret will create the resource type defined here
  14279. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  14280. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  14281. properties:
  14282. apiVersion:
  14283. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  14284. minLength: 1
  14285. type: string
  14286. kind:
  14287. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  14288. minLength: 1
  14289. type: string
  14290. required:
  14291. - apiVersion
  14292. - kind
  14293. type: object
  14294. name:
  14295. description: |-
  14296. The name of the Secret resource to be managed.
  14297. Defaults to the .metadata.name of the ExternalSecret resource
  14298. maxLength: 253
  14299. minLength: 1
  14300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14301. type: string
  14302. template:
  14303. description: Template defines a blueprint for the created Secret resource.
  14304. properties:
  14305. data:
  14306. additionalProperties:
  14307. type: string
  14308. type: object
  14309. engineVersion:
  14310. default: v2
  14311. description: |-
  14312. EngineVersion specifies the template engine version
  14313. that should be used to compile/execute the
  14314. template specified in .data and .templateFrom[].
  14315. enum:
  14316. - v2
  14317. type: string
  14318. mergePolicy:
  14319. default: Replace
  14320. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  14321. enum:
  14322. - Replace
  14323. - Merge
  14324. type: string
  14325. metadata:
  14326. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14327. properties:
  14328. annotations:
  14329. additionalProperties:
  14330. type: string
  14331. type: object
  14332. finalizers:
  14333. items:
  14334. type: string
  14335. type: array
  14336. labels:
  14337. additionalProperties:
  14338. type: string
  14339. type: object
  14340. type: object
  14341. templateFrom:
  14342. items:
  14343. description: |-
  14344. TemplateFrom specifies a source for templates.
  14345. Each item in the list can either reference a ConfigMap or a Secret resource.
  14346. properties:
  14347. configMap:
  14348. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14349. properties:
  14350. items:
  14351. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14352. items:
  14353. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14354. properties:
  14355. key:
  14356. description: A key in the ConfigMap/Secret
  14357. maxLength: 253
  14358. minLength: 1
  14359. pattern: ^[-._a-zA-Z0-9]+$
  14360. type: string
  14361. templateAs:
  14362. default: Values
  14363. description: TemplateScope specifies how the template keys should be interpreted.
  14364. enum:
  14365. - Values
  14366. - KeysAndValues
  14367. type: string
  14368. required:
  14369. - key
  14370. type: object
  14371. type: array
  14372. name:
  14373. description: The name of the ConfigMap/Secret resource
  14374. maxLength: 253
  14375. minLength: 1
  14376. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14377. type: string
  14378. required:
  14379. - items
  14380. - name
  14381. type: object
  14382. literal:
  14383. type: string
  14384. secret:
  14385. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14386. properties:
  14387. items:
  14388. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14389. items:
  14390. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14391. properties:
  14392. key:
  14393. description: A key in the ConfigMap/Secret
  14394. maxLength: 253
  14395. minLength: 1
  14396. pattern: ^[-._a-zA-Z0-9]+$
  14397. type: string
  14398. templateAs:
  14399. default: Values
  14400. description: TemplateScope specifies how the template keys should be interpreted.
  14401. enum:
  14402. - Values
  14403. - KeysAndValues
  14404. type: string
  14405. required:
  14406. - key
  14407. type: object
  14408. type: array
  14409. name:
  14410. description: The name of the ConfigMap/Secret resource
  14411. maxLength: 253
  14412. minLength: 1
  14413. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14414. type: string
  14415. required:
  14416. - items
  14417. - name
  14418. type: object
  14419. target:
  14420. default: Data
  14421. description: |-
  14422. Target specifies where to place the template result.
  14423. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  14424. any other value is rejected because it would allow writes to privileged Secret fields.
  14425. For custom resources (when spec.target.manifest is set), this supports
  14426. nested paths like "spec.database.config" or "data".
  14427. type: string
  14428. valuesDecodingStrategy:
  14429. description: |-
  14430. Used to define a decoding Strategy for the rendered template values.
  14431. Defaults to None when omitted.
  14432. enum:
  14433. - Auto
  14434. - Base64
  14435. - Base64URL
  14436. - None
  14437. type: string
  14438. type: object
  14439. type: array
  14440. type:
  14441. type: string
  14442. type: object
  14443. type: object
  14444. type: object
  14445. status:
  14446. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  14447. properties:
  14448. binding:
  14449. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  14450. properties:
  14451. name:
  14452. default: ""
  14453. description: |-
  14454. Name of the referent.
  14455. This field is effectively required, but due to backwards compatibility is
  14456. allowed to be empty. Instances of this type with an empty value here are
  14457. almost certainly wrong.
  14458. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  14459. type: string
  14460. type: object
  14461. x-kubernetes-map-type: atomic
  14462. conditions:
  14463. items:
  14464. description: ExternalSecretStatusCondition defines a status condition of an ExternalSecret resource.
  14465. properties:
  14466. lastTransitionTime:
  14467. format: date-time
  14468. type: string
  14469. message:
  14470. type: string
  14471. reason:
  14472. type: string
  14473. status:
  14474. type: string
  14475. type:
  14476. description: ExternalSecretConditionType defines a value type for ExternalSecret conditions.
  14477. enum:
  14478. - Ready
  14479. - Deleted
  14480. type: string
  14481. required:
  14482. - status
  14483. - type
  14484. type: object
  14485. type: array
  14486. refreshTime:
  14487. description: |-
  14488. refreshTime is the time and date the external secret was fetched and
  14489. the target secret updated
  14490. format: date-time
  14491. nullable: true
  14492. type: string
  14493. syncedResourceVersion:
  14494. description: SyncedResourceVersion keeps track of the last synced version
  14495. type: string
  14496. type: object
  14497. type: object
  14498. selectableFields:
  14499. - jsonPath: .spec.secretStoreRef.name
  14500. - jsonPath: .spec.secretStoreRef.kind
  14501. - jsonPath: .spec.target.name
  14502. - jsonPath: .spec.refreshInterval
  14503. served: true
  14504. storage: true
  14505. subresources:
  14506. status: {}
  14507. - additionalPrinterColumns:
  14508. - jsonPath: .spec.secretStoreRef.kind
  14509. name: StoreType
  14510. type: string
  14511. - jsonPath: .spec.secretStoreRef.name
  14512. name: Store
  14513. type: string
  14514. - jsonPath: .spec.refreshInterval
  14515. name: Refresh Interval
  14516. type: string
  14517. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  14518. name: Status
  14519. type: string
  14520. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  14521. name: Ready
  14522. type: string
  14523. - jsonPath: .status.refreshTime
  14524. name: Last Sync
  14525. type: date
  14526. deprecated: true
  14527. name: v1beta1
  14528. schema:
  14529. openAPIV3Schema:
  14530. description: ExternalSecret is the schema for the external-secrets API.
  14531. properties:
  14532. apiVersion:
  14533. description: |-
  14534. APIVersion defines the versioned schema of this representation of an object.
  14535. Servers should convert recognized schemas to the latest internal value, and
  14536. may reject unrecognized values.
  14537. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  14538. type: string
  14539. kind:
  14540. description: |-
  14541. Kind is a string value representing the REST resource this object represents.
  14542. Servers may infer this from the endpoint the client submits requests to.
  14543. Cannot be updated.
  14544. In CamelCase.
  14545. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  14546. type: string
  14547. metadata:
  14548. type: object
  14549. spec:
  14550. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  14551. properties:
  14552. data:
  14553. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  14554. items:
  14555. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  14556. properties:
  14557. remoteRef:
  14558. description: |-
  14559. RemoteRef points to the remote secret and defines
  14560. which secret (version/property/..) to fetch.
  14561. properties:
  14562. conversionStrategy:
  14563. default: Default
  14564. description: Used to define a conversion Strategy
  14565. enum:
  14566. - Default
  14567. - Unicode
  14568. type: string
  14569. decodingStrategy:
  14570. default: None
  14571. description: Used to define a decoding Strategy
  14572. enum:
  14573. - Auto
  14574. - Base64
  14575. - Base64URL
  14576. - None
  14577. type: string
  14578. key:
  14579. description: Key is the key used in the Provider, mandatory
  14580. type: string
  14581. metadataPolicy:
  14582. default: None
  14583. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14584. enum:
  14585. - None
  14586. - Fetch
  14587. type: string
  14588. property:
  14589. description: Used to select a specific property of the Provider value (if a map), if supported
  14590. type: string
  14591. version:
  14592. description: Used to select a specific version of the Provider value, if supported
  14593. type: string
  14594. required:
  14595. - key
  14596. type: object
  14597. secretKey:
  14598. description: The key in the Kubernetes Secret to store the value.
  14599. maxLength: 253
  14600. minLength: 1
  14601. pattern: ^[-._a-zA-Z0-9]+$
  14602. type: string
  14603. sourceRef:
  14604. description: |-
  14605. SourceRef allows you to override the source
  14606. from which the value will be pulled.
  14607. maxProperties: 1
  14608. minProperties: 1
  14609. properties:
  14610. generatorRef:
  14611. description: |-
  14612. GeneratorRef points to a generator custom resource.
  14613. Deprecated: The generatorRef is not implemented in .data[].
  14614. this will be removed with v1.
  14615. properties:
  14616. apiVersion:
  14617. default: generators.external-secrets.io/v1alpha1
  14618. description: Specify the apiVersion of the generator resource
  14619. type: string
  14620. kind:
  14621. description: Specify the Kind of the generator resource
  14622. enum:
  14623. - ACRAccessToken
  14624. - ClusterGenerator
  14625. - ECRAuthorizationToken
  14626. - Fake
  14627. - GCRAccessToken
  14628. - GithubAccessToken
  14629. - QuayAccessToken
  14630. - Password
  14631. - SSHKey
  14632. - STSSessionToken
  14633. - UUID
  14634. - VaultDynamicSecret
  14635. - Webhook
  14636. - Grafana
  14637. type: string
  14638. name:
  14639. description: Specify the name of the generator resource
  14640. maxLength: 253
  14641. minLength: 1
  14642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14643. type: string
  14644. required:
  14645. - kind
  14646. - name
  14647. type: object
  14648. storeRef:
  14649. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14650. properties:
  14651. kind:
  14652. description: |-
  14653. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14654. Defaults to `SecretStore`
  14655. enum:
  14656. - SecretStore
  14657. - ClusterSecretStore
  14658. type: string
  14659. name:
  14660. description: Name of the SecretStore resource
  14661. maxLength: 253
  14662. minLength: 1
  14663. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14664. type: string
  14665. type: object
  14666. type: object
  14667. required:
  14668. - remoteRef
  14669. - secretKey
  14670. type: object
  14671. type: array
  14672. dataFrom:
  14673. description: |-
  14674. DataFrom is used to fetch all properties from a specific Provider data
  14675. If multiple entries are specified, the Secret keys are merged in the specified order
  14676. items:
  14677. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  14678. properties:
  14679. extract:
  14680. description: |-
  14681. Used to extract multiple key/value pairs from one secret
  14682. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14683. properties:
  14684. conversionStrategy:
  14685. default: Default
  14686. description: Used to define a conversion Strategy
  14687. enum:
  14688. - Default
  14689. - Unicode
  14690. type: string
  14691. decodingStrategy:
  14692. default: None
  14693. description: Used to define a decoding Strategy
  14694. enum:
  14695. - Auto
  14696. - Base64
  14697. - Base64URL
  14698. - None
  14699. type: string
  14700. key:
  14701. description: Key is the key used in the Provider, mandatory
  14702. type: string
  14703. metadataPolicy:
  14704. default: None
  14705. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14706. enum:
  14707. - None
  14708. - Fetch
  14709. type: string
  14710. property:
  14711. description: Used to select a specific property of the Provider value (if a map), if supported
  14712. type: string
  14713. version:
  14714. description: Used to select a specific version of the Provider value, if supported
  14715. type: string
  14716. required:
  14717. - key
  14718. type: object
  14719. find:
  14720. description: |-
  14721. Used to find secrets based on tags or regular expressions
  14722. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14723. properties:
  14724. conversionStrategy:
  14725. default: Default
  14726. description: Used to define a conversion Strategy
  14727. enum:
  14728. - Default
  14729. - Unicode
  14730. type: string
  14731. decodingStrategy:
  14732. default: None
  14733. description: Used to define a decoding Strategy
  14734. enum:
  14735. - Auto
  14736. - Base64
  14737. - Base64URL
  14738. - None
  14739. type: string
  14740. name:
  14741. description: Finds secrets based on the name.
  14742. properties:
  14743. regexp:
  14744. description: Finds secrets base
  14745. type: string
  14746. type: object
  14747. path:
  14748. description: A root path to start the find operations.
  14749. type: string
  14750. tags:
  14751. additionalProperties:
  14752. type: string
  14753. description: Find secrets based on tags.
  14754. type: object
  14755. type: object
  14756. rewrite:
  14757. description: |-
  14758. Used to rewrite secret Keys after getting them from the secret Provider
  14759. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  14760. items:
  14761. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  14762. maxProperties: 1
  14763. minProperties: 1
  14764. properties:
  14765. regexp:
  14766. description: |-
  14767. Used to rewrite with regular expressions.
  14768. The resulting key will be the output of a regexp.ReplaceAll operation.
  14769. properties:
  14770. source:
  14771. description: Used to define the regular expression of a re.Compiler.
  14772. type: string
  14773. target:
  14774. description: Used to define the target pattern of a ReplaceAll operation.
  14775. type: string
  14776. required:
  14777. - source
  14778. - target
  14779. type: object
  14780. transform:
  14781. description: |-
  14782. Used to apply string transformation on the secrets.
  14783. The resulting key will be the output of the template applied by the operation.
  14784. properties:
  14785. template:
  14786. description: |-
  14787. Used to define the template to apply on the secret name.
  14788. `.value ` will specify the secret name in the template.
  14789. type: string
  14790. required:
  14791. - template
  14792. type: object
  14793. type: object
  14794. type: array
  14795. sourceRef:
  14796. description: |-
  14797. SourceRef points to a store or generator
  14798. which contains secret values ready to use.
  14799. Use this in combination with Extract or Find pull values out of
  14800. a specific SecretStore.
  14801. When sourceRef points to a generator Extract or Find is not supported.
  14802. The generator returns a static map of values
  14803. maxProperties: 1
  14804. minProperties: 1
  14805. properties:
  14806. generatorRef:
  14807. description: GeneratorRef points to a generator custom resource.
  14808. properties:
  14809. apiVersion:
  14810. default: generators.external-secrets.io/v1alpha1
  14811. description: Specify the apiVersion of the generator resource
  14812. type: string
  14813. kind:
  14814. description: Specify the Kind of the generator resource
  14815. enum:
  14816. - ACRAccessToken
  14817. - ClusterGenerator
  14818. - ECRAuthorizationToken
  14819. - Fake
  14820. - GCRAccessToken
  14821. - GithubAccessToken
  14822. - QuayAccessToken
  14823. - Password
  14824. - SSHKey
  14825. - STSSessionToken
  14826. - UUID
  14827. - VaultDynamicSecret
  14828. - Webhook
  14829. - Grafana
  14830. type: string
  14831. name:
  14832. description: Specify the name of the generator resource
  14833. maxLength: 253
  14834. minLength: 1
  14835. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14836. type: string
  14837. required:
  14838. - kind
  14839. - name
  14840. type: object
  14841. storeRef:
  14842. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14843. properties:
  14844. kind:
  14845. description: |-
  14846. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14847. Defaults to `SecretStore`
  14848. enum:
  14849. - SecretStore
  14850. - ClusterSecretStore
  14851. type: string
  14852. name:
  14853. description: Name of the SecretStore resource
  14854. maxLength: 253
  14855. minLength: 1
  14856. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14857. type: string
  14858. type: object
  14859. type: object
  14860. type: object
  14861. type: array
  14862. refreshInterval:
  14863. default: 1h0m0s
  14864. description: |-
  14865. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  14866. specified as Golang Duration strings.
  14867. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  14868. Example values: "1h0m0s", "2h30m0s", "10m0s"
  14869. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  14870. type: string
  14871. refreshPolicy:
  14872. description: |-
  14873. RefreshPolicy determines how the ExternalSecret should be refreshed:
  14874. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  14875. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  14876. No periodic updates occur if refreshInterval is 0.
  14877. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  14878. enum:
  14879. - CreatedOnce
  14880. - Periodic
  14881. - OnChange
  14882. type: string
  14883. secretStoreRef:
  14884. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14885. properties:
  14886. kind:
  14887. description: |-
  14888. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14889. Defaults to `SecretStore`
  14890. enum:
  14891. - SecretStore
  14892. - ClusterSecretStore
  14893. type: string
  14894. name:
  14895. description: Name of the SecretStore resource
  14896. maxLength: 253
  14897. minLength: 1
  14898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14899. type: string
  14900. type: object
  14901. target:
  14902. default:
  14903. creationPolicy: Owner
  14904. deletionPolicy: Retain
  14905. description: |-
  14906. ExternalSecretTarget defines the Kubernetes Secret to be created
  14907. There can be only one target per ExternalSecret.
  14908. properties:
  14909. creationPolicy:
  14910. default: Owner
  14911. description: |-
  14912. CreationPolicy defines rules on how to create the resulting Secret.
  14913. Defaults to "Owner"
  14914. enum:
  14915. - Owner
  14916. - Orphan
  14917. - Merge
  14918. - None
  14919. type: string
  14920. deletionPolicy:
  14921. default: Retain
  14922. description: |-
  14923. DeletionPolicy defines rules on how to delete the resulting Secret.
  14924. Defaults to "Retain"
  14925. enum:
  14926. - Delete
  14927. - Merge
  14928. - Retain
  14929. type: string
  14930. immutable:
  14931. description: Immutable defines if the final secret will be immutable
  14932. type: boolean
  14933. name:
  14934. description: |-
  14935. The name of the Secret resource to be managed.
  14936. Defaults to the .metadata.name of the ExternalSecret resource
  14937. maxLength: 253
  14938. minLength: 1
  14939. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14940. type: string
  14941. template:
  14942. description: Template defines a blueprint for the created Secret resource.
  14943. properties:
  14944. data:
  14945. additionalProperties:
  14946. type: string
  14947. type: object
  14948. engineVersion:
  14949. default: v2
  14950. description: |-
  14951. EngineVersion specifies the template engine version
  14952. that should be used to compile/execute the
  14953. template specified in .data and .templateFrom[].
  14954. enum:
  14955. - v2
  14956. type: string
  14957. mergePolicy:
  14958. default: Replace
  14959. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  14960. enum:
  14961. - Replace
  14962. - Merge
  14963. type: string
  14964. metadata:
  14965. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14966. properties:
  14967. annotations:
  14968. additionalProperties:
  14969. type: string
  14970. type: object
  14971. labels:
  14972. additionalProperties:
  14973. type: string
  14974. type: object
  14975. type: object
  14976. templateFrom:
  14977. items:
  14978. description: TemplateFrom defines a source for template data.
  14979. properties:
  14980. configMap:
  14981. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14982. properties:
  14983. items:
  14984. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14985. items:
  14986. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14987. properties:
  14988. key:
  14989. description: A key in the ConfigMap/Secret
  14990. maxLength: 253
  14991. minLength: 1
  14992. pattern: ^[-._a-zA-Z0-9]+$
  14993. type: string
  14994. templateAs:
  14995. default: Values
  14996. description: TemplateScope defines the scope of the template when processing template data.
  14997. enum:
  14998. - Values
  14999. - KeysAndValues
  15000. type: string
  15001. required:
  15002. - key
  15003. type: object
  15004. type: array
  15005. name:
  15006. description: The name of the ConfigMap/Secret resource
  15007. maxLength: 253
  15008. minLength: 1
  15009. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15010. type: string
  15011. required:
  15012. - items
  15013. - name
  15014. type: object
  15015. literal:
  15016. type: string
  15017. secret:
  15018. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  15019. properties:
  15020. items:
  15021. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15022. items:
  15023. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  15024. properties:
  15025. key:
  15026. description: A key in the ConfigMap/Secret
  15027. maxLength: 253
  15028. minLength: 1
  15029. pattern: ^[-._a-zA-Z0-9]+$
  15030. type: string
  15031. templateAs:
  15032. default: Values
  15033. description: TemplateScope defines the scope of the template when processing template data.
  15034. enum:
  15035. - Values
  15036. - KeysAndValues
  15037. type: string
  15038. required:
  15039. - key
  15040. type: object
  15041. type: array
  15042. name:
  15043. description: The name of the ConfigMap/Secret resource
  15044. maxLength: 253
  15045. minLength: 1
  15046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15047. type: string
  15048. required:
  15049. - items
  15050. - name
  15051. type: object
  15052. target:
  15053. default: Data
  15054. description: TemplateTarget defines the target field where the template result will be stored.
  15055. enum:
  15056. - Data
  15057. - Annotations
  15058. - Labels
  15059. type: string
  15060. type: object
  15061. type: array
  15062. type:
  15063. type: string
  15064. type: object
  15065. type: object
  15066. type: object
  15067. status:
  15068. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  15069. properties:
  15070. binding:
  15071. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  15072. properties:
  15073. name:
  15074. default: ""
  15075. description: |-
  15076. Name of the referent.
  15077. This field is effectively required, but due to backwards compatibility is
  15078. allowed to be empty. Instances of this type with an empty value here are
  15079. almost certainly wrong.
  15080. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  15081. type: string
  15082. type: object
  15083. x-kubernetes-map-type: atomic
  15084. conditions:
  15085. items:
  15086. description: ExternalSecretStatusCondition contains condition information for an ExternalSecret.
  15087. properties:
  15088. lastTransitionTime:
  15089. format: date-time
  15090. type: string
  15091. message:
  15092. type: string
  15093. reason:
  15094. type: string
  15095. status:
  15096. type: string
  15097. type:
  15098. description: ExternalSecretConditionType defines the condition type for an ExternalSecret.
  15099. type: string
  15100. required:
  15101. - status
  15102. - type
  15103. type: object
  15104. type: array
  15105. refreshTime:
  15106. description: |-
  15107. refreshTime is the time and date the external secret was fetched and
  15108. the target secret updated
  15109. format: date-time
  15110. nullable: true
  15111. type: string
  15112. syncedResourceVersion:
  15113. description: SyncedResourceVersion keeps track of the last synced version
  15114. type: string
  15115. type: object
  15116. type: object
  15117. served: false
  15118. storage: false
  15119. subresources:
  15120. status: {}
  15121. ---
  15122. apiVersion: apiextensions.k8s.io/v1
  15123. kind: CustomResourceDefinition
  15124. metadata:
  15125. annotations:
  15126. controller-gen.kubebuilder.io/version: v0.19.0
  15127. labels:
  15128. external-secrets.io/component: controller
  15129. name: pushsecrets.external-secrets.io
  15130. spec:
  15131. group: external-secrets.io
  15132. names:
  15133. categories:
  15134. - external-secrets
  15135. kind: PushSecret
  15136. listKind: PushSecretList
  15137. plural: pushsecrets
  15138. shortNames:
  15139. - ps
  15140. singular: pushsecret
  15141. scope: Namespaced
  15142. versions:
  15143. - additionalPrinterColumns:
  15144. - jsonPath: .metadata.creationTimestamp
  15145. name: AGE
  15146. type: date
  15147. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  15148. name: Status
  15149. type: string
  15150. - jsonPath: .status.refreshTime
  15151. name: Last Sync
  15152. type: date
  15153. name: v1alpha1
  15154. schema:
  15155. openAPIV3Schema:
  15156. description: PushSecret is the Schema for the PushSecrets API that enables pushing Kubernetes secrets to external secret providers.
  15157. properties:
  15158. apiVersion:
  15159. description: |-
  15160. APIVersion defines the versioned schema of this representation of an object.
  15161. Servers should convert recognized schemas to the latest internal value, and
  15162. may reject unrecognized values.
  15163. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15164. type: string
  15165. kind:
  15166. description: |-
  15167. Kind is a string value representing the REST resource this object represents.
  15168. Servers may infer this from the endpoint the client submits requests to.
  15169. Cannot be updated.
  15170. In CamelCase.
  15171. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15172. type: string
  15173. metadata:
  15174. type: object
  15175. spec:
  15176. description: PushSecretSpec configures the behavior of the PushSecret.
  15177. properties:
  15178. data:
  15179. description: Secret Data that should be pushed to providers
  15180. items:
  15181. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  15182. properties:
  15183. conversionStrategy:
  15184. default: None
  15185. description: Used to define a conversion Strategy for the secret keys
  15186. enum:
  15187. - None
  15188. - ReverseUnicode
  15189. type: string
  15190. match:
  15191. description: Match a given Secret Key to be pushed to the provider.
  15192. properties:
  15193. remoteRef:
  15194. description: Remote Refs to push to providers.
  15195. properties:
  15196. property:
  15197. description: Name of the property in the resulting secret
  15198. type: string
  15199. remoteKey:
  15200. description: Name of the resulting provider secret.
  15201. type: string
  15202. required:
  15203. - remoteKey
  15204. type: object
  15205. secretKey:
  15206. description: Secret Key to be pushed
  15207. type: string
  15208. required:
  15209. - remoteRef
  15210. type: object
  15211. metadata:
  15212. description: |-
  15213. Metadata is metadata attached to the secret.
  15214. The structure of metadata is provider specific, please look it up in the provider documentation.
  15215. x-kubernetes-preserve-unknown-fields: true
  15216. required:
  15217. - match
  15218. type: object
  15219. type: array
  15220. dataTo:
  15221. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  15222. items:
  15223. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  15224. properties:
  15225. conversionStrategy:
  15226. default: None
  15227. description: Used to define a conversion Strategy for the secret keys
  15228. enum:
  15229. - None
  15230. - ReverseUnicode
  15231. type: string
  15232. match:
  15233. description: |-
  15234. Match pattern for selecting keys from the source Secret.
  15235. If not specified, all keys are selected.
  15236. properties:
  15237. regexp:
  15238. description: |-
  15239. Regexp matches keys by regular expression.
  15240. If not specified, all keys are matched.
  15241. type: string
  15242. type: object
  15243. metadata:
  15244. description: |-
  15245. Metadata is metadata attached to the secret.
  15246. The structure of metadata is provider specific, please look it up in the provider documentation.
  15247. x-kubernetes-preserve-unknown-fields: true
  15248. remoteKey:
  15249. description: |-
  15250. RemoteKey is the name of the single provider secret that will receive ALL
  15251. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  15252. When set, per-key expansion is skipped and a single push is performed.
  15253. The provider's store prefix (if any) is still prepended to this value.
  15254. When not set, each matched key is pushed as its own individual provider secret.
  15255. type: string
  15256. rewrite:
  15257. description: |-
  15258. Rewrite operations to transform keys before pushing to the provider.
  15259. Operations are applied sequentially.
  15260. items:
  15261. description: PushSecretRewrite defines how to transform secret keys before pushing.
  15262. properties:
  15263. regexp:
  15264. description: Used to rewrite with regular expressions.
  15265. properties:
  15266. source:
  15267. description: Used to define the regular expression of a re.Compiler.
  15268. type: string
  15269. target:
  15270. description: Used to define the target pattern of a ReplaceAll operation.
  15271. type: string
  15272. required:
  15273. - source
  15274. - target
  15275. type: object
  15276. transform:
  15277. description: Used to apply string transformation on the secrets.
  15278. properties:
  15279. template:
  15280. description: |-
  15281. Used to define the template to apply on the secret name.
  15282. `.value ` will specify the secret name in the template.
  15283. type: string
  15284. required:
  15285. - template
  15286. type: object
  15287. type: object
  15288. x-kubernetes-validations:
  15289. - message: exactly one of regexp or transform must be set
  15290. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  15291. type: array
  15292. storeRef:
  15293. description: StoreRef specifies which SecretStore to push to. Required.
  15294. properties:
  15295. kind:
  15296. default: SecretStore
  15297. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  15298. enum:
  15299. - SecretStore
  15300. - ClusterSecretStore
  15301. type: string
  15302. labelSelector:
  15303. description: Optionally, sync to secret stores with label selector
  15304. properties:
  15305. matchExpressions:
  15306. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15307. items:
  15308. description: |-
  15309. A label selector requirement is a selector that contains values, a key, and an operator that
  15310. relates the key and values.
  15311. properties:
  15312. key:
  15313. description: key is the label key that the selector applies to.
  15314. type: string
  15315. operator:
  15316. description: |-
  15317. operator represents a key's relationship to a set of values.
  15318. Valid operators are In, NotIn, Exists and DoesNotExist.
  15319. type: string
  15320. values:
  15321. description: |-
  15322. values is an array of string values. If the operator is In or NotIn,
  15323. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15324. the values array must be empty. This array is replaced during a strategic
  15325. merge patch.
  15326. items:
  15327. type: string
  15328. type: array
  15329. x-kubernetes-list-type: atomic
  15330. required:
  15331. - key
  15332. - operator
  15333. type: object
  15334. type: array
  15335. x-kubernetes-list-type: atomic
  15336. matchLabels:
  15337. additionalProperties:
  15338. type: string
  15339. description: |-
  15340. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15341. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15342. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15343. type: object
  15344. type: object
  15345. x-kubernetes-map-type: atomic
  15346. name:
  15347. description: Optionally, sync to the SecretStore of the given name
  15348. maxLength: 253
  15349. minLength: 1
  15350. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15351. type: string
  15352. type: object
  15353. type: object
  15354. x-kubernetes-validations:
  15355. - message: storeRef must specify either name or labelSelector
  15356. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  15357. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  15358. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  15359. type: array
  15360. deletionPolicy:
  15361. default: None
  15362. description: Deletion Policy to handle Secrets in the provider.
  15363. enum:
  15364. - Delete
  15365. - None
  15366. type: string
  15367. refreshInterval:
  15368. default: 1h0m0s
  15369. description: The Interval to which External Secrets will try to push a secret definition
  15370. type: string
  15371. secretStoreRefs:
  15372. items:
  15373. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  15374. properties:
  15375. kind:
  15376. default: SecretStore
  15377. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  15378. enum:
  15379. - SecretStore
  15380. - ClusterSecretStore
  15381. type: string
  15382. labelSelector:
  15383. description: Optionally, sync to secret stores with label selector
  15384. properties:
  15385. matchExpressions:
  15386. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15387. items:
  15388. description: |-
  15389. A label selector requirement is a selector that contains values, a key, and an operator that
  15390. relates the key and values.
  15391. properties:
  15392. key:
  15393. description: key is the label key that the selector applies to.
  15394. type: string
  15395. operator:
  15396. description: |-
  15397. operator represents a key's relationship to a set of values.
  15398. Valid operators are In, NotIn, Exists and DoesNotExist.
  15399. type: string
  15400. values:
  15401. description: |-
  15402. values is an array of string values. If the operator is In or NotIn,
  15403. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15404. the values array must be empty. This array is replaced during a strategic
  15405. merge patch.
  15406. items:
  15407. type: string
  15408. type: array
  15409. x-kubernetes-list-type: atomic
  15410. required:
  15411. - key
  15412. - operator
  15413. type: object
  15414. type: array
  15415. x-kubernetes-list-type: atomic
  15416. matchLabels:
  15417. additionalProperties:
  15418. type: string
  15419. description: |-
  15420. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15421. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15422. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15423. type: object
  15424. type: object
  15425. x-kubernetes-map-type: atomic
  15426. name:
  15427. description: Optionally, sync to the SecretStore of the given name
  15428. maxLength: 253
  15429. minLength: 1
  15430. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15431. type: string
  15432. type: object
  15433. type: array
  15434. selector:
  15435. description: The Secret Selector (k8s source) for the Push Secret
  15436. maxProperties: 1
  15437. minProperties: 1
  15438. properties:
  15439. generatorRef:
  15440. description: Point to a generator to create a Secret.
  15441. properties:
  15442. apiVersion:
  15443. default: generators.external-secrets.io/v1alpha1
  15444. description: Specify the apiVersion of the generator resource
  15445. type: string
  15446. kind:
  15447. description: Specify the Kind of the generator resource
  15448. enum:
  15449. - ACRAccessToken
  15450. - BeyondtrustWorkloadCredentialsDynamicSecret
  15451. - ClusterGenerator
  15452. - CloudsmithAccessToken
  15453. - ECRAuthorizationToken
  15454. - Fake
  15455. - GCRAccessToken
  15456. - GithubAccessToken
  15457. - GitlabDeployToken
  15458. - QuayAccessToken
  15459. - Password
  15460. - SSHKey
  15461. - STSSessionToken
  15462. - UUID
  15463. - VaultDynamicSecret
  15464. - Webhook
  15465. - Grafana
  15466. - MFA
  15467. type: string
  15468. name:
  15469. description: Specify the name of the generator resource
  15470. maxLength: 253
  15471. minLength: 1
  15472. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15473. type: string
  15474. required:
  15475. - kind
  15476. - name
  15477. type: object
  15478. secret:
  15479. description: Select a Secret to Push.
  15480. properties:
  15481. name:
  15482. description: |-
  15483. Name of the Secret.
  15484. The Secret must exist in the same namespace as the PushSecret manifest.
  15485. maxLength: 253
  15486. minLength: 1
  15487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15488. type: string
  15489. selector:
  15490. description: |-
  15491. Selector chooses secrets using a labelSelector.
  15492. It must not be empty: an empty selector resolves to labels.Everything(),
  15493. which would push every Secret in the namespace to the provider.
  15494. properties:
  15495. matchExpressions:
  15496. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15497. items:
  15498. description: |-
  15499. A label selector requirement is a selector that contains values, a key, and an operator that
  15500. relates the key and values.
  15501. properties:
  15502. key:
  15503. description: key is the label key that the selector applies to.
  15504. type: string
  15505. operator:
  15506. description: |-
  15507. operator represents a key's relationship to a set of values.
  15508. Valid operators are In, NotIn, Exists and DoesNotExist.
  15509. type: string
  15510. values:
  15511. description: |-
  15512. values is an array of string values. If the operator is In or NotIn,
  15513. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15514. the values array must be empty. This array is replaced during a strategic
  15515. merge patch.
  15516. items:
  15517. type: string
  15518. type: array
  15519. x-kubernetes-list-type: atomic
  15520. required:
  15521. - key
  15522. - operator
  15523. type: object
  15524. type: array
  15525. x-kubernetes-list-type: atomic
  15526. matchLabels:
  15527. additionalProperties:
  15528. type: string
  15529. description: |-
  15530. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15531. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15532. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15533. type: object
  15534. type: object
  15535. x-kubernetes-map-type: atomic
  15536. x-kubernetes-validations:
  15537. - message: selector must set matchLabels or matchExpressions
  15538. rule: has(self.matchLabels) && size(self.matchLabels) > 0 || has(self.matchExpressions) && size(self.matchExpressions) > 0
  15539. type: object
  15540. x-kubernetes-validations:
  15541. - message: exactly one of name or selector must be set
  15542. rule: has(self.name) != has(self.selector)
  15543. type: object
  15544. template:
  15545. description: Template defines a blueprint for the created Secret resource.
  15546. properties:
  15547. data:
  15548. additionalProperties:
  15549. type: string
  15550. type: object
  15551. engineVersion:
  15552. default: v2
  15553. description: |-
  15554. EngineVersion specifies the template engine version
  15555. that should be used to compile/execute the
  15556. template specified in .data and .templateFrom[].
  15557. enum:
  15558. - v2
  15559. type: string
  15560. mergePolicy:
  15561. default: Replace
  15562. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  15563. enum:
  15564. - Replace
  15565. - Merge
  15566. type: string
  15567. metadata:
  15568. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  15569. properties:
  15570. annotations:
  15571. additionalProperties:
  15572. type: string
  15573. type: object
  15574. finalizers:
  15575. items:
  15576. type: string
  15577. type: array
  15578. labels:
  15579. additionalProperties:
  15580. type: string
  15581. type: object
  15582. type: object
  15583. templateFrom:
  15584. items:
  15585. description: |-
  15586. TemplateFrom specifies a source for templates.
  15587. Each item in the list can either reference a ConfigMap or a Secret resource.
  15588. properties:
  15589. configMap:
  15590. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15591. properties:
  15592. items:
  15593. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15594. items:
  15595. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15596. properties:
  15597. key:
  15598. description: A key in the ConfigMap/Secret
  15599. maxLength: 253
  15600. minLength: 1
  15601. pattern: ^[-._a-zA-Z0-9]+$
  15602. type: string
  15603. templateAs:
  15604. default: Values
  15605. description: TemplateScope specifies how the template keys should be interpreted.
  15606. enum:
  15607. - Values
  15608. - KeysAndValues
  15609. type: string
  15610. required:
  15611. - key
  15612. type: object
  15613. type: array
  15614. name:
  15615. description: The name of the ConfigMap/Secret resource
  15616. maxLength: 253
  15617. minLength: 1
  15618. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15619. type: string
  15620. required:
  15621. - items
  15622. - name
  15623. type: object
  15624. literal:
  15625. type: string
  15626. secret:
  15627. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15628. properties:
  15629. items:
  15630. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15631. items:
  15632. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15633. properties:
  15634. key:
  15635. description: A key in the ConfigMap/Secret
  15636. maxLength: 253
  15637. minLength: 1
  15638. pattern: ^[-._a-zA-Z0-9]+$
  15639. type: string
  15640. templateAs:
  15641. default: Values
  15642. description: TemplateScope specifies how the template keys should be interpreted.
  15643. enum:
  15644. - Values
  15645. - KeysAndValues
  15646. type: string
  15647. required:
  15648. - key
  15649. type: object
  15650. type: array
  15651. name:
  15652. description: The name of the ConfigMap/Secret resource
  15653. maxLength: 253
  15654. minLength: 1
  15655. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15656. type: string
  15657. required:
  15658. - items
  15659. - name
  15660. type: object
  15661. target:
  15662. default: Data
  15663. description: |-
  15664. Target specifies where to place the template result.
  15665. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  15666. any other value is rejected because it would allow writes to privileged Secret fields.
  15667. For custom resources (when spec.target.manifest is set), this supports
  15668. nested paths like "spec.database.config" or "data".
  15669. type: string
  15670. valuesDecodingStrategy:
  15671. description: |-
  15672. Used to define a decoding Strategy for the rendered template values.
  15673. Defaults to None when omitted.
  15674. enum:
  15675. - Auto
  15676. - Base64
  15677. - Base64URL
  15678. - None
  15679. type: string
  15680. type: object
  15681. type: array
  15682. type:
  15683. type: string
  15684. type: object
  15685. updatePolicy:
  15686. default: Replace
  15687. description: UpdatePolicy to handle Secrets in the provider.
  15688. enum:
  15689. - Replace
  15690. - IfNotExists
  15691. type: string
  15692. required:
  15693. - secretStoreRefs
  15694. - selector
  15695. type: object
  15696. status:
  15697. description: PushSecretStatus indicates the history of the status of PushSecret.
  15698. properties:
  15699. conditions:
  15700. items:
  15701. description: PushSecretStatusCondition indicates the status of the PushSecret.
  15702. properties:
  15703. lastTransitionTime:
  15704. format: date-time
  15705. type: string
  15706. message:
  15707. type: string
  15708. reason:
  15709. type: string
  15710. status:
  15711. type: string
  15712. type:
  15713. description: PushSecretConditionType indicates the condition of the PushSecret.
  15714. type: string
  15715. required:
  15716. - status
  15717. - type
  15718. type: object
  15719. type: array
  15720. refreshTime:
  15721. description: |-
  15722. refreshTime is the time and date the external secret was fetched and
  15723. the target secret updated
  15724. format: date-time
  15725. nullable: true
  15726. type: string
  15727. syncedPushSecrets:
  15728. additionalProperties:
  15729. additionalProperties:
  15730. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  15731. properties:
  15732. conversionStrategy:
  15733. default: None
  15734. description: Used to define a conversion Strategy for the secret keys
  15735. enum:
  15736. - None
  15737. - ReverseUnicode
  15738. type: string
  15739. match:
  15740. description: Match a given Secret Key to be pushed to the provider.
  15741. properties:
  15742. remoteRef:
  15743. description: Remote Refs to push to providers.
  15744. properties:
  15745. property:
  15746. description: Name of the property in the resulting secret
  15747. type: string
  15748. remoteKey:
  15749. description: Name of the resulting provider secret.
  15750. type: string
  15751. required:
  15752. - remoteKey
  15753. type: object
  15754. secretKey:
  15755. description: Secret Key to be pushed
  15756. type: string
  15757. required:
  15758. - remoteRef
  15759. type: object
  15760. metadata:
  15761. description: |-
  15762. Metadata is metadata attached to the secret.
  15763. The structure of metadata is provider specific, please look it up in the provider documentation.
  15764. x-kubernetes-preserve-unknown-fields: true
  15765. required:
  15766. - match
  15767. type: object
  15768. type: object
  15769. description: |-
  15770. Synced PushSecrets, including secrets that already exist in provider.
  15771. Matches secret stores to PushSecretData that was stored to that secret store.
  15772. type: object
  15773. syncedResourceVersion:
  15774. description: SyncedResourceVersion keeps track of the last synced version.
  15775. type: string
  15776. type: object
  15777. type: object
  15778. served: true
  15779. storage: true
  15780. subresources:
  15781. status: {}
  15782. ---
  15783. apiVersion: apiextensions.k8s.io/v1
  15784. kind: CustomResourceDefinition
  15785. metadata:
  15786. annotations:
  15787. controller-gen.kubebuilder.io/version: v0.19.0
  15788. labels:
  15789. external-secrets.io/component: controller
  15790. name: secretstores.external-secrets.io
  15791. spec:
  15792. group: external-secrets.io
  15793. names:
  15794. categories:
  15795. - external-secrets
  15796. kind: SecretStore
  15797. listKind: SecretStoreList
  15798. plural: secretstores
  15799. shortNames:
  15800. - ss
  15801. singular: secretstore
  15802. scope: Namespaced
  15803. versions:
  15804. - additionalPrinterColumns:
  15805. - jsonPath: .metadata.creationTimestamp
  15806. name: AGE
  15807. type: date
  15808. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  15809. name: Status
  15810. type: string
  15811. - jsonPath: .status.capabilities
  15812. name: Capabilities
  15813. type: string
  15814. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  15815. name: Ready
  15816. type: string
  15817. name: v1
  15818. schema:
  15819. openAPIV3Schema:
  15820. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  15821. properties:
  15822. apiVersion:
  15823. description: |-
  15824. APIVersion defines the versioned schema of this representation of an object.
  15825. Servers should convert recognized schemas to the latest internal value, and
  15826. may reject unrecognized values.
  15827. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15828. type: string
  15829. kind:
  15830. description: |-
  15831. Kind is a string value representing the REST resource this object represents.
  15832. Servers may infer this from the endpoint the client submits requests to.
  15833. Cannot be updated.
  15834. In CamelCase.
  15835. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15836. type: string
  15837. metadata:
  15838. type: object
  15839. spec:
  15840. description: SecretStoreSpec defines the desired state of SecretStore.
  15841. properties:
  15842. conditions:
  15843. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  15844. items:
  15845. description: |-
  15846. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  15847. for a ClusterSecretStore instance.
  15848. properties:
  15849. namespaceRegexes:
  15850. description: Choose namespaces by using regex matching
  15851. items:
  15852. type: string
  15853. type: array
  15854. namespaceSelector:
  15855. description: Choose namespace using a labelSelector
  15856. properties:
  15857. matchExpressions:
  15858. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15859. items:
  15860. description: |-
  15861. A label selector requirement is a selector that contains values, a key, and an operator that
  15862. relates the key and values.
  15863. properties:
  15864. key:
  15865. description: key is the label key that the selector applies to.
  15866. type: string
  15867. operator:
  15868. description: |-
  15869. operator represents a key's relationship to a set of values.
  15870. Valid operators are In, NotIn, Exists and DoesNotExist.
  15871. type: string
  15872. values:
  15873. description: |-
  15874. values is an array of string values. If the operator is In or NotIn,
  15875. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15876. the values array must be empty. This array is replaced during a strategic
  15877. merge patch.
  15878. items:
  15879. type: string
  15880. type: array
  15881. x-kubernetes-list-type: atomic
  15882. required:
  15883. - key
  15884. - operator
  15885. type: object
  15886. type: array
  15887. x-kubernetes-list-type: atomic
  15888. matchLabels:
  15889. additionalProperties:
  15890. type: string
  15891. description: |-
  15892. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15893. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15894. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15895. type: object
  15896. type: object
  15897. x-kubernetes-map-type: atomic
  15898. namespaces:
  15899. description: Choose namespaces by name
  15900. items:
  15901. maxLength: 63
  15902. minLength: 1
  15903. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15904. type: string
  15905. type: array
  15906. type: object
  15907. type: array
  15908. controller:
  15909. description: |-
  15910. Used to select the correct ESO controller (think: ingress.ingressClassName)
  15911. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  15912. type: string
  15913. provider:
  15914. description: Used to configure the provider. Only one provider may be set
  15915. maxProperties: 1
  15916. minProperties: 1
  15917. properties:
  15918. akeyless:
  15919. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  15920. properties:
  15921. akeylessGWApiURL:
  15922. description: Akeyless GW API Url from which the secrets to be fetched from.
  15923. type: string
  15924. authSecretRef:
  15925. description: Auth configures how the operator authenticates with Akeyless.
  15926. properties:
  15927. kubernetesAuth:
  15928. description: |-
  15929. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  15930. token stored in the named Secret resource.
  15931. properties:
  15932. accessID:
  15933. description: the Akeyless Kubernetes auth-method access-id
  15934. type: string
  15935. k8sConfName:
  15936. description: Kubernetes-auth configuration name in Akeyless-Gateway
  15937. type: string
  15938. secretRef:
  15939. description: |-
  15940. Optional secret field containing a Kubernetes ServiceAccount JWT used
  15941. for authenticating with Akeyless. If a name is specified without a key,
  15942. `token` is the default. If one is not specified, the one bound to
  15943. the controller will be used.
  15944. properties:
  15945. key:
  15946. description: |-
  15947. A key in the referenced Secret.
  15948. Some instances of this field may be defaulted, in others it may be required.
  15949. maxLength: 253
  15950. minLength: 1
  15951. pattern: ^[-._a-zA-Z0-9]+$
  15952. type: string
  15953. name:
  15954. description: The name of the Secret resource being referred to.
  15955. maxLength: 253
  15956. minLength: 1
  15957. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15958. type: string
  15959. namespace:
  15960. description: |-
  15961. The namespace of the Secret resource being referred to.
  15962. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15963. maxLength: 63
  15964. minLength: 1
  15965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15966. type: string
  15967. type: object
  15968. serviceAccountRef:
  15969. description: |-
  15970. Optional service account field containing the name of a kubernetes ServiceAccount.
  15971. If the service account is specified, the service account secret token JWT will be used
  15972. for authenticating with Akeyless. If the service account selector is not supplied,
  15973. the secretRef will be used instead.
  15974. properties:
  15975. audiences:
  15976. description: |-
  15977. Audience specifies the `aud` claim for the service account token
  15978. Some providers automatically extend the audience field based on well-known annotations for workload
  15979. identity (e.g. IRSA or GCP Workload Identity)
  15980. items:
  15981. type: string
  15982. type: array
  15983. name:
  15984. description: The name of the ServiceAccount resource being referred to.
  15985. maxLength: 253
  15986. minLength: 1
  15987. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15988. type: string
  15989. namespace:
  15990. description: |-
  15991. Namespace of the resource being referred to.
  15992. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15993. maxLength: 63
  15994. minLength: 1
  15995. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15996. type: string
  15997. required:
  15998. - name
  15999. type: object
  16000. required:
  16001. - accessID
  16002. - k8sConfName
  16003. type: object
  16004. secretRef:
  16005. description: |-
  16006. Reference to a Secret that contains the details
  16007. to authenticate with Akeyless.
  16008. properties:
  16009. accessID:
  16010. description: The SecretAccessID is used for authentication
  16011. properties:
  16012. key:
  16013. description: |-
  16014. A key in the referenced Secret.
  16015. Some instances of this field may be defaulted, in others it may be required.
  16016. maxLength: 253
  16017. minLength: 1
  16018. pattern: ^[-._a-zA-Z0-9]+$
  16019. type: string
  16020. name:
  16021. description: The name of the Secret resource being referred to.
  16022. maxLength: 253
  16023. minLength: 1
  16024. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16025. type: string
  16026. namespace:
  16027. description: |-
  16028. The namespace of the Secret resource being referred to.
  16029. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16030. maxLength: 63
  16031. minLength: 1
  16032. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16033. type: string
  16034. type: object
  16035. accessType:
  16036. description: |-
  16037. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16038. In some instances, `key` is a required field.
  16039. properties:
  16040. key:
  16041. description: |-
  16042. A key in the referenced Secret.
  16043. Some instances of this field may be defaulted, in others it may be required.
  16044. maxLength: 253
  16045. minLength: 1
  16046. pattern: ^[-._a-zA-Z0-9]+$
  16047. type: string
  16048. name:
  16049. description: The name of the Secret resource being referred to.
  16050. maxLength: 253
  16051. minLength: 1
  16052. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16053. type: string
  16054. namespace:
  16055. description: |-
  16056. The namespace of the Secret resource being referred to.
  16057. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16058. maxLength: 63
  16059. minLength: 1
  16060. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16061. type: string
  16062. type: object
  16063. accessTypeParam:
  16064. description: |-
  16065. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16066. In some instances, `key` is a required field.
  16067. properties:
  16068. key:
  16069. description: |-
  16070. A key in the referenced Secret.
  16071. Some instances of this field may be defaulted, in others it may be required.
  16072. maxLength: 253
  16073. minLength: 1
  16074. pattern: ^[-._a-zA-Z0-9]+$
  16075. type: string
  16076. name:
  16077. description: The name of the Secret resource being referred to.
  16078. maxLength: 253
  16079. minLength: 1
  16080. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16081. type: string
  16082. namespace:
  16083. description: |-
  16084. The namespace of the Secret resource being referred to.
  16085. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16086. maxLength: 63
  16087. minLength: 1
  16088. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16089. type: string
  16090. type: object
  16091. type: object
  16092. serviceAccountRef:
  16093. description: |-
  16094. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  16095. authentication on AKS Workload Identity. The operator obtains a federated
  16096. identity token from this ServiceAccount via the TokenRequest API instead
  16097. of using the ESO controller pod identity. Ignored for other access types.
  16098. properties:
  16099. audiences:
  16100. description: |-
  16101. Audience specifies the `aud` claim for the service account token
  16102. Some providers automatically extend the audience field based on well-known annotations for workload
  16103. identity (e.g. IRSA or GCP Workload Identity)
  16104. items:
  16105. type: string
  16106. type: array
  16107. name:
  16108. description: The name of the ServiceAccount resource being referred to.
  16109. maxLength: 253
  16110. minLength: 1
  16111. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16112. type: string
  16113. namespace:
  16114. description: |-
  16115. Namespace of the resource being referred to.
  16116. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16117. maxLength: 63
  16118. minLength: 1
  16119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16120. type: string
  16121. required:
  16122. - name
  16123. type: object
  16124. type: object
  16125. caBundle:
  16126. description: |-
  16127. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  16128. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  16129. are used to validate the TLS connection.
  16130. format: byte
  16131. type: string
  16132. caProvider:
  16133. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  16134. properties:
  16135. key:
  16136. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16137. maxLength: 253
  16138. minLength: 1
  16139. pattern: ^[-._a-zA-Z0-9]+$
  16140. type: string
  16141. name:
  16142. description: The name of the object located at the provider type.
  16143. maxLength: 253
  16144. minLength: 1
  16145. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16146. type: string
  16147. namespace:
  16148. description: |-
  16149. The namespace the Provider type is in.
  16150. Can only be defined when used in a ClusterSecretStore.
  16151. maxLength: 63
  16152. minLength: 1
  16153. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16154. type: string
  16155. type:
  16156. description: The type of provider to use such as "Secret", or "ConfigMap".
  16157. enum:
  16158. - Secret
  16159. - ConfigMap
  16160. type: string
  16161. required:
  16162. - name
  16163. - type
  16164. type: object
  16165. ignoreCache:
  16166. description: |-
  16167. IgnoreCache bypasses the Gateway cache for secret reads when true.
  16168. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  16169. type: boolean
  16170. required:
  16171. - akeylessGWApiURL
  16172. - authSecretRef
  16173. type: object
  16174. aws:
  16175. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  16176. properties:
  16177. additionalRoles:
  16178. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  16179. items:
  16180. type: string
  16181. type: array
  16182. auth:
  16183. description: |-
  16184. Auth defines the information necessary to authenticate against AWS
  16185. if not set aws sdk will infer credentials from your environment
  16186. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  16187. properties:
  16188. jwt:
  16189. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  16190. properties:
  16191. serviceAccountRef:
  16192. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  16193. properties:
  16194. audiences:
  16195. description: |-
  16196. Audience specifies the `aud` claim for the service account token
  16197. Some providers automatically extend the audience field based on well-known annotations for workload
  16198. identity (e.g. IRSA or GCP Workload Identity)
  16199. items:
  16200. type: string
  16201. type: array
  16202. name:
  16203. description: The name of the ServiceAccount resource being referred to.
  16204. maxLength: 253
  16205. minLength: 1
  16206. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16207. type: string
  16208. namespace:
  16209. description: |-
  16210. Namespace of the resource being referred to.
  16211. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16212. maxLength: 63
  16213. minLength: 1
  16214. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16215. type: string
  16216. required:
  16217. - name
  16218. type: object
  16219. type: object
  16220. secretRef:
  16221. description: |-
  16222. AWSAuthSecretRef holds secret references for AWS credentials
  16223. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  16224. properties:
  16225. accessKeyIDSecretRef:
  16226. description: The AccessKeyID is used for authentication
  16227. properties:
  16228. key:
  16229. description: |-
  16230. A key in the referenced Secret.
  16231. Some instances of this field may be defaulted, in others it may be required.
  16232. maxLength: 253
  16233. minLength: 1
  16234. pattern: ^[-._a-zA-Z0-9]+$
  16235. type: string
  16236. name:
  16237. description: The name of the Secret resource being referred to.
  16238. maxLength: 253
  16239. minLength: 1
  16240. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16241. type: string
  16242. namespace:
  16243. description: |-
  16244. The namespace of the Secret resource being referred to.
  16245. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16246. maxLength: 63
  16247. minLength: 1
  16248. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16249. type: string
  16250. type: object
  16251. secretAccessKeySecretRef:
  16252. description: The SecretAccessKey is used for authentication
  16253. properties:
  16254. key:
  16255. description: |-
  16256. A key in the referenced Secret.
  16257. Some instances of this field may be defaulted, in others it may be required.
  16258. maxLength: 253
  16259. minLength: 1
  16260. pattern: ^[-._a-zA-Z0-9]+$
  16261. type: string
  16262. name:
  16263. description: The name of the Secret resource being referred to.
  16264. maxLength: 253
  16265. minLength: 1
  16266. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16267. type: string
  16268. namespace:
  16269. description: |-
  16270. The namespace of the Secret resource being referred to.
  16271. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16272. maxLength: 63
  16273. minLength: 1
  16274. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16275. type: string
  16276. type: object
  16277. sessionTokenSecretRef:
  16278. description: |-
  16279. The SessionToken used for authentication
  16280. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  16281. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  16282. properties:
  16283. key:
  16284. description: |-
  16285. A key in the referenced Secret.
  16286. Some instances of this field may be defaulted, in others it may be required.
  16287. maxLength: 253
  16288. minLength: 1
  16289. pattern: ^[-._a-zA-Z0-9]+$
  16290. type: string
  16291. name:
  16292. description: The name of the Secret resource being referred to.
  16293. maxLength: 253
  16294. minLength: 1
  16295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16296. type: string
  16297. namespace:
  16298. description: |-
  16299. The namespace of the Secret resource being referred to.
  16300. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16301. maxLength: 63
  16302. minLength: 1
  16303. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16304. type: string
  16305. type: object
  16306. type: object
  16307. type: object
  16308. customSessionTags:
  16309. additionalProperties:
  16310. type: string
  16311. description: |-
  16312. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  16313. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  16314. type: object
  16315. x-kubernetes-validations:
  16316. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  16317. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  16318. externalID:
  16319. description: AWS External ID set on assumed IAM roles
  16320. type: string
  16321. prefix:
  16322. description: Prefix adds a prefix to all retrieved values.
  16323. type: string
  16324. region:
  16325. description: AWS Region to be used for the provider
  16326. type: string
  16327. role:
  16328. description: Role is a Role ARN which the provider will assume
  16329. type: string
  16330. secretsManager:
  16331. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  16332. properties:
  16333. forceDeleteWithoutRecovery:
  16334. description: |-
  16335. Specifies whether to delete the secret without any recovery window. You
  16336. can't use both this parameter and RecoveryWindowInDays in the same call.
  16337. If you don't use either, then by default Secrets Manager uses a 30 day
  16338. recovery window.
  16339. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  16340. type: boolean
  16341. recoveryWindowInDays:
  16342. description: |-
  16343. The number of days from 7 to 30 that Secrets Manager waits before
  16344. permanently deleting the secret. You can't use both this parameter and
  16345. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  16346. then by default Secrets Manager uses a 30-day recovery window.
  16347. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  16348. format: int64
  16349. type: integer
  16350. type: object
  16351. service:
  16352. description: Service defines which service should be used to fetch the secrets
  16353. enum:
  16354. - SecretsManager
  16355. - ParameterStore
  16356. - CertificateManager
  16357. type: string
  16358. sessionTags:
  16359. description: AWS STS assume role session tags
  16360. items:
  16361. description: |-
  16362. Tag is a key-value pair that can be attached to an AWS resource.
  16363. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  16364. properties:
  16365. key:
  16366. type: string
  16367. value:
  16368. type: string
  16369. required:
  16370. - key
  16371. - value
  16372. type: object
  16373. type: array
  16374. sessionTagsPolicy:
  16375. default: None
  16376. description: |-
  16377. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  16378. None (default): no tags are added.
  16379. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  16380. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  16381. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  16382. enum:
  16383. - None
  16384. - Simple
  16385. - Custom
  16386. type: string
  16387. transitiveTagKeys:
  16388. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  16389. items:
  16390. type: string
  16391. type: array
  16392. required:
  16393. - region
  16394. - service
  16395. type: object
  16396. azurekv:
  16397. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  16398. properties:
  16399. authSecretRef:
  16400. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16401. properties:
  16402. clientCertificate:
  16403. description: The Azure ClientCertificate of the service principle used for authentication.
  16404. properties:
  16405. key:
  16406. description: |-
  16407. A key in the referenced Secret.
  16408. Some instances of this field may be defaulted, in others it may be required.
  16409. maxLength: 253
  16410. minLength: 1
  16411. pattern: ^[-._a-zA-Z0-9]+$
  16412. type: string
  16413. name:
  16414. description: The name of the Secret resource being referred to.
  16415. maxLength: 253
  16416. minLength: 1
  16417. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16418. type: string
  16419. namespace:
  16420. description: |-
  16421. The namespace of the Secret resource being referred to.
  16422. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16423. maxLength: 63
  16424. minLength: 1
  16425. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16426. type: string
  16427. type: object
  16428. clientId:
  16429. description: The Azure clientId of the service principle or managed identity used for authentication.
  16430. properties:
  16431. key:
  16432. description: |-
  16433. A key in the referenced Secret.
  16434. Some instances of this field may be defaulted, in others it may be required.
  16435. maxLength: 253
  16436. minLength: 1
  16437. pattern: ^[-._a-zA-Z0-9]+$
  16438. type: string
  16439. name:
  16440. description: The name of the Secret resource being referred to.
  16441. maxLength: 253
  16442. minLength: 1
  16443. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16444. type: string
  16445. namespace:
  16446. description: |-
  16447. The namespace of the Secret resource being referred to.
  16448. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16449. maxLength: 63
  16450. minLength: 1
  16451. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16452. type: string
  16453. type: object
  16454. clientSecret:
  16455. description: The Azure ClientSecret of the service principle used for authentication.
  16456. properties:
  16457. key:
  16458. description: |-
  16459. A key in the referenced Secret.
  16460. Some instances of this field may be defaulted, in others it may be required.
  16461. maxLength: 253
  16462. minLength: 1
  16463. pattern: ^[-._a-zA-Z0-9]+$
  16464. type: string
  16465. name:
  16466. description: The name of the Secret resource being referred to.
  16467. maxLength: 253
  16468. minLength: 1
  16469. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16470. type: string
  16471. namespace:
  16472. description: |-
  16473. The namespace of the Secret resource being referred to.
  16474. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16475. maxLength: 63
  16476. minLength: 1
  16477. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16478. type: string
  16479. type: object
  16480. tenantId:
  16481. description: The Azure tenantId of the managed identity used for authentication.
  16482. properties:
  16483. key:
  16484. description: |-
  16485. A key in the referenced Secret.
  16486. Some instances of this field may be defaulted, in others it may be required.
  16487. maxLength: 253
  16488. minLength: 1
  16489. pattern: ^[-._a-zA-Z0-9]+$
  16490. type: string
  16491. name:
  16492. description: The name of the Secret resource being referred to.
  16493. maxLength: 253
  16494. minLength: 1
  16495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16496. type: string
  16497. namespace:
  16498. description: |-
  16499. The namespace of the Secret resource being referred to.
  16500. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16501. maxLength: 63
  16502. minLength: 1
  16503. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16504. type: string
  16505. type: object
  16506. type: object
  16507. authType:
  16508. default: ServicePrincipal
  16509. description: |-
  16510. Auth type defines how to authenticate to the keyvault service.
  16511. Valid values are:
  16512. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  16513. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  16514. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  16515. enum:
  16516. - ServicePrincipal
  16517. - ManagedIdentity
  16518. - WorkloadIdentity
  16519. type: string
  16520. customCloudConfig:
  16521. description: |-
  16522. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  16523. Required when EnvironmentType is AzureStackCloud.
  16524. Optional for other environment types - useful for Azure China when using Workload Identity
  16525. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  16526. standard China Cloud endpoint (login.chinacloudapi.cn).
  16527. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  16528. configuration is not supported with the legacy go-autorest SDK.
  16529. properties:
  16530. activeDirectoryEndpoint:
  16531. description: |-
  16532. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  16533. Required when using custom cloud configuration
  16534. type: string
  16535. keyVaultDNSSuffix:
  16536. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  16537. type: string
  16538. keyVaultEndpoint:
  16539. description: KeyVaultEndpoint is the Key Vault service endpoint
  16540. type: string
  16541. resourceManagerEndpoint:
  16542. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  16543. type: string
  16544. required:
  16545. - activeDirectoryEndpoint
  16546. type: object
  16547. environmentType:
  16548. default: PublicCloud
  16549. description: |-
  16550. EnvironmentType specifies the Azure cloud environment endpoints to use for
  16551. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  16552. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  16553. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  16554. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  16555. enum:
  16556. - PublicCloud
  16557. - USGovernmentCloud
  16558. - ChinaCloud
  16559. - GermanCloud
  16560. - AzureStackCloud
  16561. type: string
  16562. identityId:
  16563. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  16564. type: string
  16565. serviceAccountRef:
  16566. description: |-
  16567. ServiceAccountRef specified the service account
  16568. that should be used when authenticating with WorkloadIdentity.
  16569. properties:
  16570. audiences:
  16571. description: |-
  16572. Audience specifies the `aud` claim for the service account token
  16573. Some providers automatically extend the audience field based on well-known annotations for workload
  16574. identity (e.g. IRSA or GCP Workload Identity)
  16575. items:
  16576. type: string
  16577. type: array
  16578. name:
  16579. description: The name of the ServiceAccount resource being referred to.
  16580. maxLength: 253
  16581. minLength: 1
  16582. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16583. type: string
  16584. namespace:
  16585. description: |-
  16586. Namespace of the resource being referred to.
  16587. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16588. maxLength: 63
  16589. minLength: 1
  16590. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16591. type: string
  16592. required:
  16593. - name
  16594. type: object
  16595. tenantId:
  16596. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16597. type: string
  16598. useAzureSDK:
  16599. default: false
  16600. description: |-
  16601. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  16602. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  16603. type: boolean
  16604. vaultUrl:
  16605. description: Vault Url from which the secrets to be fetched from.
  16606. type: string
  16607. required:
  16608. - vaultUrl
  16609. type: object
  16610. barbican:
  16611. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  16612. properties:
  16613. auth:
  16614. description: BarbicanAuth contains the authentication information for Barbican.
  16615. properties:
  16616. applicationCredentialID:
  16617. description: ID of the application credential used for authentication.
  16618. maxProperties: 1
  16619. minProperties: 1
  16620. properties:
  16621. secretRef:
  16622. description: |-
  16623. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16624. In some instances, `key` is a required field.
  16625. properties:
  16626. key:
  16627. description: |-
  16628. A key in the referenced Secret.
  16629. Some instances of this field may be defaulted, in others it may be required.
  16630. maxLength: 253
  16631. minLength: 1
  16632. pattern: ^[-._a-zA-Z0-9]+$
  16633. type: string
  16634. name:
  16635. description: The name of the Secret resource being referred to.
  16636. maxLength: 253
  16637. minLength: 1
  16638. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16639. type: string
  16640. namespace:
  16641. description: |-
  16642. The namespace of the Secret resource being referred to.
  16643. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16644. maxLength: 63
  16645. minLength: 1
  16646. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16647. type: string
  16648. type: object
  16649. value:
  16650. minLength: 1
  16651. type: string
  16652. type: object
  16653. applicationCredentialSecret:
  16654. description: BarbicanProviderAppCredSecretRef defines a reference to an Application Credential Secret.
  16655. properties:
  16656. secretRef:
  16657. description: |-
  16658. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16659. In some instances, `key` is a required field.
  16660. properties:
  16661. key:
  16662. description: |-
  16663. A key in the referenced Secret.
  16664. Some instances of this field may be defaulted, in others it may be required.
  16665. maxLength: 253
  16666. minLength: 1
  16667. pattern: ^[-._a-zA-Z0-9]+$
  16668. type: string
  16669. name:
  16670. description: The name of the Secret resource being referred to.
  16671. maxLength: 253
  16672. minLength: 1
  16673. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16674. type: string
  16675. namespace:
  16676. description: |-
  16677. The namespace of the Secret resource being referred to.
  16678. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16679. maxLength: 63
  16680. minLength: 1
  16681. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16682. type: string
  16683. type: object
  16684. required:
  16685. - secretRef
  16686. type: object
  16687. authType:
  16688. default: password
  16689. description: |-
  16690. AuthType selects how Barbican authenticates.
  16691. - "password": use username and password.
  16692. - "applicationCredential": use application credential ID and secret.
  16693. Defaults to "password".
  16694. enum:
  16695. - password
  16696. - applicationCredential
  16697. type: string
  16698. password:
  16699. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  16700. properties:
  16701. secretRef:
  16702. description: |-
  16703. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16704. In some instances, `key` is a required field.
  16705. properties:
  16706. key:
  16707. description: |-
  16708. A key in the referenced Secret.
  16709. Some instances of this field may be defaulted, in others it may be required.
  16710. maxLength: 253
  16711. minLength: 1
  16712. pattern: ^[-._a-zA-Z0-9]+$
  16713. type: string
  16714. name:
  16715. description: The name of the Secret resource being referred to.
  16716. maxLength: 253
  16717. minLength: 1
  16718. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16719. type: string
  16720. namespace:
  16721. description: |-
  16722. The namespace of the Secret resource being referred to.
  16723. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16724. maxLength: 63
  16725. minLength: 1
  16726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16727. type: string
  16728. type: object
  16729. required:
  16730. - secretRef
  16731. type: object
  16732. username:
  16733. description: Username / Password authentication fields.
  16734. maxProperties: 1
  16735. minProperties: 1
  16736. properties:
  16737. secretRef:
  16738. description: |-
  16739. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16740. In some instances, `key` is a required field.
  16741. properties:
  16742. key:
  16743. description: |-
  16744. A key in the referenced Secret.
  16745. Some instances of this field may be defaulted, in others it may be required.
  16746. maxLength: 253
  16747. minLength: 1
  16748. pattern: ^[-._a-zA-Z0-9]+$
  16749. type: string
  16750. name:
  16751. description: The name of the Secret resource being referred to.
  16752. maxLength: 253
  16753. minLength: 1
  16754. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16755. type: string
  16756. namespace:
  16757. description: |-
  16758. The namespace of the Secret resource being referred to.
  16759. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16760. maxLength: 63
  16761. minLength: 1
  16762. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16763. type: string
  16764. type: object
  16765. value:
  16766. minLength: 1
  16767. type: string
  16768. type: object
  16769. type: object
  16770. x-kubernetes-validations:
  16771. - message: password auth requires both username and password
  16772. rule: (has(self.authType) && self.authType == 'applicationCredential') || (has(self.username) && has(self.password))
  16773. - message: applicationCredential auth requires both applicationCredentialID and applicationCredentialSecret
  16774. rule: self.authType != 'applicationCredential' || (has(self.applicationCredentialID) && has(self.applicationCredentialSecret))
  16775. - message: password auth should not include applicationCredential fields
  16776. rule: (has(self.authType) && self.authType == 'applicationCredential') || (!has(self.applicationCredentialID) && !has(self.applicationCredentialSecret))
  16777. - message: applicationCredential auth should not include password fields
  16778. rule: self.authType != 'applicationCredential' || (!has(self.username) && !has(self.password))
  16779. authURL:
  16780. type: string
  16781. domainName:
  16782. type: string
  16783. region:
  16784. type: string
  16785. tenantName:
  16786. type: string
  16787. required:
  16788. - auth
  16789. type: object
  16790. beyondtrust:
  16791. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  16792. properties:
  16793. auth:
  16794. description: Auth configures how the operator authenticates with Beyondtrust.
  16795. properties:
  16796. apiKey:
  16797. description: APIKey If not provided then ClientID/ClientSecret become required.
  16798. properties:
  16799. secretRef:
  16800. description: SecretRef references a key in a secret that will be used as value.
  16801. properties:
  16802. key:
  16803. description: |-
  16804. A key in the referenced Secret.
  16805. Some instances of this field may be defaulted, in others it may be required.
  16806. maxLength: 253
  16807. minLength: 1
  16808. pattern: ^[-._a-zA-Z0-9]+$
  16809. type: string
  16810. name:
  16811. description: The name of the Secret resource being referred to.
  16812. maxLength: 253
  16813. minLength: 1
  16814. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16815. type: string
  16816. namespace:
  16817. description: |-
  16818. The namespace of the Secret resource being referred to.
  16819. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16820. maxLength: 63
  16821. minLength: 1
  16822. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16823. type: string
  16824. type: object
  16825. value:
  16826. description: Value can be specified directly to set a value without using a secret.
  16827. type: string
  16828. type: object
  16829. certificate:
  16830. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  16831. properties:
  16832. secretRef:
  16833. description: SecretRef references a key in a secret that will be used as value.
  16834. properties:
  16835. key:
  16836. description: |-
  16837. A key in the referenced Secret.
  16838. Some instances of this field may be defaulted, in others it may be required.
  16839. maxLength: 253
  16840. minLength: 1
  16841. pattern: ^[-._a-zA-Z0-9]+$
  16842. type: string
  16843. name:
  16844. description: The name of the Secret resource being referred to.
  16845. maxLength: 253
  16846. minLength: 1
  16847. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16848. type: string
  16849. namespace:
  16850. description: |-
  16851. The namespace of the Secret resource being referred to.
  16852. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16853. maxLength: 63
  16854. minLength: 1
  16855. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16856. type: string
  16857. type: object
  16858. value:
  16859. description: Value can be specified directly to set a value without using a secret.
  16860. type: string
  16861. type: object
  16862. certificateKey:
  16863. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  16864. properties:
  16865. secretRef:
  16866. description: SecretRef references a key in a secret that will be used as value.
  16867. properties:
  16868. key:
  16869. description: |-
  16870. A key in the referenced Secret.
  16871. Some instances of this field may be defaulted, in others it may be required.
  16872. maxLength: 253
  16873. minLength: 1
  16874. pattern: ^[-._a-zA-Z0-9]+$
  16875. type: string
  16876. name:
  16877. description: The name of the Secret resource being referred to.
  16878. maxLength: 253
  16879. minLength: 1
  16880. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16881. type: string
  16882. namespace:
  16883. description: |-
  16884. The namespace of the Secret resource being referred to.
  16885. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16886. maxLength: 63
  16887. minLength: 1
  16888. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16889. type: string
  16890. type: object
  16891. value:
  16892. description: Value can be specified directly to set a value without using a secret.
  16893. type: string
  16894. type: object
  16895. clientId:
  16896. description: ClientID is the API OAuth Client ID.
  16897. properties:
  16898. secretRef:
  16899. description: SecretRef references a key in a secret that will be used as value.
  16900. properties:
  16901. key:
  16902. description: |-
  16903. A key in the referenced Secret.
  16904. Some instances of this field may be defaulted, in others it may be required.
  16905. maxLength: 253
  16906. minLength: 1
  16907. pattern: ^[-._a-zA-Z0-9]+$
  16908. type: string
  16909. name:
  16910. description: The name of the Secret resource being referred to.
  16911. maxLength: 253
  16912. minLength: 1
  16913. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16914. type: string
  16915. namespace:
  16916. description: |-
  16917. The namespace of the Secret resource being referred to.
  16918. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16919. maxLength: 63
  16920. minLength: 1
  16921. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16922. type: string
  16923. type: object
  16924. value:
  16925. description: Value can be specified directly to set a value without using a secret.
  16926. type: string
  16927. type: object
  16928. clientSecret:
  16929. description: ClientSecret is the API OAuth Client Secret.
  16930. properties:
  16931. secretRef:
  16932. description: SecretRef references a key in a secret that will be used as value.
  16933. properties:
  16934. key:
  16935. description: |-
  16936. A key in the referenced Secret.
  16937. Some instances of this field may be defaulted, in others it may be required.
  16938. maxLength: 253
  16939. minLength: 1
  16940. pattern: ^[-._a-zA-Z0-9]+$
  16941. type: string
  16942. name:
  16943. description: The name of the Secret resource being referred to.
  16944. maxLength: 253
  16945. minLength: 1
  16946. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16947. type: string
  16948. namespace:
  16949. description: |-
  16950. The namespace of the Secret resource being referred to.
  16951. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16952. maxLength: 63
  16953. minLength: 1
  16954. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16955. type: string
  16956. type: object
  16957. value:
  16958. description: Value can be specified directly to set a value without using a secret.
  16959. type: string
  16960. type: object
  16961. type: object
  16962. server:
  16963. description: Auth configures how API server works.
  16964. properties:
  16965. apiUrl:
  16966. type: string
  16967. apiVersion:
  16968. type: string
  16969. clientTimeOutSeconds:
  16970. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  16971. type: integer
  16972. decrypt:
  16973. default: true
  16974. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  16975. type: boolean
  16976. retrievalType:
  16977. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  16978. type: string
  16979. separator:
  16980. description: A character that separates the folder names.
  16981. type: string
  16982. verifyCA:
  16983. type: boolean
  16984. required:
  16985. - apiUrl
  16986. - verifyCA
  16987. type: object
  16988. required:
  16989. - auth
  16990. - server
  16991. type: object
  16992. beyondtrustworkloadcredentials:
  16993. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  16994. properties:
  16995. auth:
  16996. description: |-
  16997. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  16998. Currently supports API key authentication via Kubernetes secret reference.
  16999. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  17000. properties:
  17001. apikey:
  17002. description: |-
  17003. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  17004. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  17005. properties:
  17006. token:
  17007. description: |-
  17008. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  17009. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  17010. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  17011. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  17012. properties:
  17013. key:
  17014. description: |-
  17015. A key in the referenced Secret.
  17016. Some instances of this field may be defaulted, in others it may be required.
  17017. maxLength: 253
  17018. minLength: 1
  17019. pattern: ^[-._a-zA-Z0-9]+$
  17020. type: string
  17021. name:
  17022. description: The name of the Secret resource being referred to.
  17023. maxLength: 253
  17024. minLength: 1
  17025. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17026. type: string
  17027. namespace:
  17028. description: |-
  17029. The namespace of the Secret resource being referred to.
  17030. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17031. maxLength: 63
  17032. minLength: 1
  17033. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17034. type: string
  17035. type: object
  17036. required:
  17037. - token
  17038. type: object
  17039. required:
  17040. - apikey
  17041. type: object
  17042. caBundle:
  17043. description: |-
  17044. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  17045. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  17046. If not set, the system's trusted root certificates are used.
  17047. format: byte
  17048. type: string
  17049. caProvider:
  17050. description: |-
  17051. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  17052. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  17053. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  17054. properties:
  17055. key:
  17056. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17057. maxLength: 253
  17058. minLength: 1
  17059. pattern: ^[-._a-zA-Z0-9]+$
  17060. type: string
  17061. name:
  17062. description: The name of the object located at the provider type.
  17063. maxLength: 253
  17064. minLength: 1
  17065. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17066. type: string
  17067. namespace:
  17068. description: |-
  17069. The namespace the Provider type is in.
  17070. Can only be defined when used in a ClusterSecretStore.
  17071. maxLength: 63
  17072. minLength: 1
  17073. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17074. type: string
  17075. type:
  17076. description: The type of provider to use such as "Secret", or "ConfigMap".
  17077. enum:
  17078. - Secret
  17079. - ConfigMap
  17080. type: string
  17081. required:
  17082. - name
  17083. - type
  17084. type: object
  17085. folderPath:
  17086. description: |-
  17087. FolderPath specifies the default folder path for secret retrieval.
  17088. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  17089. Example: "production/database" or "dev/api-keys"
  17090. Leave empty to retrieve secrets from the root folder.
  17091. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  17092. type: string
  17093. server:
  17094. description: |-
  17095. Server configures the BeyondTrust Workload Credentials server connection details.
  17096. Includes the API URL and Site ID for your BeyondTrust instance.
  17097. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  17098. properties:
  17099. apiUrl:
  17100. description: |-
  17101. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  17102. This should be the full URL to your BeyondTrust instance.
  17103. Example: https://api.beyondtrust.io/siie
  17104. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  17105. type: string
  17106. siteId:
  17107. description: |-
  17108. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  17109. This identifier is unique to your BeyondTrust Workload Credentials instance.
  17110. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  17111. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  17112. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  17113. type: string
  17114. required:
  17115. - apiUrl
  17116. - siteId
  17117. type: object
  17118. required:
  17119. - auth
  17120. - server
  17121. type: object
  17122. bitwardensecretsmanager:
  17123. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  17124. properties:
  17125. apiURL:
  17126. type: string
  17127. auth:
  17128. description: |-
  17129. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  17130. Make sure that the token being used has permissions on the given secret.
  17131. properties:
  17132. secretRef:
  17133. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  17134. properties:
  17135. credentials:
  17136. description: AccessToken used for the bitwarden instance.
  17137. properties:
  17138. key:
  17139. description: |-
  17140. A key in the referenced Secret.
  17141. Some instances of this field may be defaulted, in others it may be required.
  17142. maxLength: 253
  17143. minLength: 1
  17144. pattern: ^[-._a-zA-Z0-9]+$
  17145. type: string
  17146. name:
  17147. description: The name of the Secret resource being referred to.
  17148. maxLength: 253
  17149. minLength: 1
  17150. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17151. type: string
  17152. namespace:
  17153. description: |-
  17154. The namespace of the Secret resource being referred to.
  17155. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17156. maxLength: 63
  17157. minLength: 1
  17158. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17159. type: string
  17160. type: object
  17161. required:
  17162. - credentials
  17163. type: object
  17164. required:
  17165. - secretRef
  17166. type: object
  17167. bitwardenServerSDKURL:
  17168. type: string
  17169. caBundle:
  17170. description: |-
  17171. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  17172. can be performed.
  17173. type: string
  17174. caProvider:
  17175. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  17176. properties:
  17177. key:
  17178. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17179. maxLength: 253
  17180. minLength: 1
  17181. pattern: ^[-._a-zA-Z0-9]+$
  17182. type: string
  17183. name:
  17184. description: The name of the object located at the provider type.
  17185. maxLength: 253
  17186. minLength: 1
  17187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17188. type: string
  17189. namespace:
  17190. description: |-
  17191. The namespace the Provider type is in.
  17192. Can only be defined when used in a ClusterSecretStore.
  17193. maxLength: 63
  17194. minLength: 1
  17195. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17196. type: string
  17197. type:
  17198. description: The type of provider to use such as "Secret", or "ConfigMap".
  17199. enum:
  17200. - Secret
  17201. - ConfigMap
  17202. type: string
  17203. required:
  17204. - name
  17205. - type
  17206. type: object
  17207. identityURL:
  17208. type: string
  17209. organizationID:
  17210. description: OrganizationID determines which organization this secret store manages.
  17211. type: string
  17212. projectID:
  17213. description: ProjectID determines which project this secret store manages.
  17214. type: string
  17215. required:
  17216. - auth
  17217. - organizationID
  17218. - projectID
  17219. type: object
  17220. chef:
  17221. description: Chef configures this store to sync secrets with chef server
  17222. properties:
  17223. auth:
  17224. description: Auth defines the information necessary to authenticate against chef Server
  17225. properties:
  17226. secretRef:
  17227. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  17228. properties:
  17229. privateKeySecretRef:
  17230. description: SecretKey is the Signing Key in PEM format, used for authentication.
  17231. properties:
  17232. key:
  17233. description: |-
  17234. A key in the referenced Secret.
  17235. Some instances of this field may be defaulted, in others it may be required.
  17236. maxLength: 253
  17237. minLength: 1
  17238. pattern: ^[-._a-zA-Z0-9]+$
  17239. type: string
  17240. name:
  17241. description: The name of the Secret resource being referred to.
  17242. maxLength: 253
  17243. minLength: 1
  17244. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17245. type: string
  17246. namespace:
  17247. description: |-
  17248. The namespace of the Secret resource being referred to.
  17249. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17250. maxLength: 63
  17251. minLength: 1
  17252. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17253. type: string
  17254. type: object
  17255. required:
  17256. - privateKeySecretRef
  17257. type: object
  17258. required:
  17259. - secretRef
  17260. type: object
  17261. serverUrl:
  17262. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  17263. type: string
  17264. username:
  17265. description: UserName should be the user ID on the chef server
  17266. type: string
  17267. required:
  17268. - auth
  17269. - serverUrl
  17270. - username
  17271. type: object
  17272. cloudrusm:
  17273. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  17274. properties:
  17275. auth:
  17276. description: CSMAuth contains a secretRef for credentials.
  17277. properties:
  17278. secretRef:
  17279. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  17280. properties:
  17281. accessKeyIDSecretRef:
  17282. description: The AccessKeyID is used for authentication
  17283. properties:
  17284. key:
  17285. description: |-
  17286. A key in the referenced Secret.
  17287. Some instances of this field may be defaulted, in others it may be required.
  17288. maxLength: 253
  17289. minLength: 1
  17290. pattern: ^[-._a-zA-Z0-9]+$
  17291. type: string
  17292. name:
  17293. description: The name of the Secret resource being referred to.
  17294. maxLength: 253
  17295. minLength: 1
  17296. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17297. type: string
  17298. namespace:
  17299. description: |-
  17300. The namespace of the Secret resource being referred to.
  17301. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17302. maxLength: 63
  17303. minLength: 1
  17304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17305. type: string
  17306. type: object
  17307. accessKeySecretSecretRef:
  17308. description: The AccessKeySecret is used for authentication
  17309. properties:
  17310. key:
  17311. description: |-
  17312. A key in the referenced Secret.
  17313. Some instances of this field may be defaulted, in others it may be required.
  17314. maxLength: 253
  17315. minLength: 1
  17316. pattern: ^[-._a-zA-Z0-9]+$
  17317. type: string
  17318. name:
  17319. description: The name of the Secret resource being referred to.
  17320. maxLength: 253
  17321. minLength: 1
  17322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17323. type: string
  17324. namespace:
  17325. description: |-
  17326. The namespace of the Secret resource being referred to.
  17327. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17328. maxLength: 63
  17329. minLength: 1
  17330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17331. type: string
  17332. type: object
  17333. required:
  17334. - accessKeyIDSecretRef
  17335. - accessKeySecretSecretRef
  17336. type: object
  17337. type: object
  17338. projectID:
  17339. description: ProjectID is the project, which the secrets are stored in.
  17340. type: string
  17341. required:
  17342. - auth
  17343. type: object
  17344. conjur:
  17345. description: Conjur configures this store to sync secrets using conjur provider
  17346. properties:
  17347. auth:
  17348. description: Defines authentication settings for connecting to Conjur.
  17349. maxProperties: 1
  17350. minProperties: 1
  17351. properties:
  17352. apikey:
  17353. description: Authenticates with Conjur using an API key.
  17354. properties:
  17355. account:
  17356. description: Account is the Conjur organization account name.
  17357. type: string
  17358. apiKeyRef:
  17359. description: |-
  17360. A reference to a specific 'key' containing the Conjur API key
  17361. within a Secret resource. In some instances, `key` is a required field.
  17362. properties:
  17363. key:
  17364. description: |-
  17365. A key in the referenced Secret.
  17366. Some instances of this field may be defaulted, in others it may be required.
  17367. maxLength: 253
  17368. minLength: 1
  17369. pattern: ^[-._a-zA-Z0-9]+$
  17370. type: string
  17371. name:
  17372. description: The name of the Secret resource being referred to.
  17373. maxLength: 253
  17374. minLength: 1
  17375. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17376. type: string
  17377. namespace:
  17378. description: |-
  17379. The namespace of the Secret resource being referred to.
  17380. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17381. maxLength: 63
  17382. minLength: 1
  17383. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17384. type: string
  17385. type: object
  17386. userRef:
  17387. description: |-
  17388. A reference to a specific 'key' containing the Conjur username
  17389. within a Secret resource. In some instances, `key` is a required field.
  17390. properties:
  17391. key:
  17392. description: |-
  17393. A key in the referenced Secret.
  17394. Some instances of this field may be defaulted, in others it may be required.
  17395. maxLength: 253
  17396. minLength: 1
  17397. pattern: ^[-._a-zA-Z0-9]+$
  17398. type: string
  17399. name:
  17400. description: The name of the Secret resource being referred to.
  17401. maxLength: 253
  17402. minLength: 1
  17403. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17404. type: string
  17405. namespace:
  17406. description: |-
  17407. The namespace of the Secret resource being referred to.
  17408. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17409. maxLength: 63
  17410. minLength: 1
  17411. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17412. type: string
  17413. type: object
  17414. required:
  17415. - account
  17416. - apiKeyRef
  17417. - userRef
  17418. type: object
  17419. cert:
  17420. description: Cert enables certificate-based authentication using a client certificate and key.
  17421. properties:
  17422. account:
  17423. description: Account is the Conjur organization account name.
  17424. type: string
  17425. clientCertRef:
  17426. description: |-
  17427. ClientCertRef is a reference to a specific 'key' containing the client certificate
  17428. within a Secret resource. The certificate must be PEM-encoded.
  17429. properties:
  17430. key:
  17431. description: |-
  17432. A key in the referenced Secret.
  17433. Some instances of this field may be defaulted, in others it may be required.
  17434. maxLength: 253
  17435. minLength: 1
  17436. pattern: ^[-._a-zA-Z0-9]+$
  17437. type: string
  17438. name:
  17439. description: The name of the Secret resource being referred to.
  17440. maxLength: 253
  17441. minLength: 1
  17442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17443. type: string
  17444. namespace:
  17445. description: |-
  17446. The namespace of the Secret resource being referred to.
  17447. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17448. maxLength: 63
  17449. minLength: 1
  17450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17451. type: string
  17452. type: object
  17453. clientKeyRef:
  17454. description: |-
  17455. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  17456. within a Secret resource. The key must be PEM-encoded.
  17457. properties:
  17458. key:
  17459. description: |-
  17460. A key in the referenced Secret.
  17461. Some instances of this field may be defaulted, in others it may be required.
  17462. maxLength: 253
  17463. minLength: 1
  17464. pattern: ^[-._a-zA-Z0-9]+$
  17465. type: string
  17466. name:
  17467. description: The name of the Secret resource being referred to.
  17468. maxLength: 253
  17469. minLength: 1
  17470. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17471. type: string
  17472. namespace:
  17473. description: |-
  17474. The namespace of the Secret resource being referred to.
  17475. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17476. maxLength: 63
  17477. minLength: 1
  17478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17479. type: string
  17480. type: object
  17481. hostId:
  17482. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  17483. type: string
  17484. serviceID:
  17485. description: The conjur authn cert webservice id
  17486. type: string
  17487. required:
  17488. - account
  17489. - clientCertRef
  17490. - clientKeyRef
  17491. - serviceID
  17492. type: object
  17493. jwt:
  17494. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  17495. properties:
  17496. account:
  17497. description: Account is the Conjur organization account name.
  17498. type: string
  17499. hostId:
  17500. description: |-
  17501. Optional HostID for JWT authentication. This may be used depending
  17502. on how the Conjur JWT authenticator policy is configured.
  17503. type: string
  17504. secretRef:
  17505. description: |-
  17506. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  17507. authenticate with Conjur using the JWT authentication method.
  17508. properties:
  17509. key:
  17510. description: |-
  17511. A key in the referenced Secret.
  17512. Some instances of this field may be defaulted, in others it may be required.
  17513. maxLength: 253
  17514. minLength: 1
  17515. pattern: ^[-._a-zA-Z0-9]+$
  17516. type: string
  17517. name:
  17518. description: The name of the Secret resource being referred to.
  17519. maxLength: 253
  17520. minLength: 1
  17521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17522. type: string
  17523. namespace:
  17524. description: |-
  17525. The namespace of the Secret resource being referred to.
  17526. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17527. maxLength: 63
  17528. minLength: 1
  17529. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17530. type: string
  17531. type: object
  17532. serviceAccountRef:
  17533. description: |-
  17534. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  17535. a token for with the `TokenRequest` API.
  17536. properties:
  17537. audiences:
  17538. description: |-
  17539. Audience specifies the `aud` claim for the service account token
  17540. Some providers automatically extend the audience field based on well-known annotations for workload
  17541. identity (e.g. IRSA or GCP Workload Identity)
  17542. items:
  17543. type: string
  17544. type: array
  17545. name:
  17546. description: The name of the ServiceAccount resource being referred to.
  17547. maxLength: 253
  17548. minLength: 1
  17549. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17550. type: string
  17551. namespace:
  17552. description: |-
  17553. Namespace of the resource being referred to.
  17554. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17555. maxLength: 63
  17556. minLength: 1
  17557. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17558. type: string
  17559. required:
  17560. - name
  17561. type: object
  17562. serviceID:
  17563. description: The conjur authn jwt webservice id
  17564. type: string
  17565. required:
  17566. - account
  17567. - serviceID
  17568. type: object
  17569. type: object
  17570. caBundle:
  17571. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  17572. type: string
  17573. caProvider:
  17574. description: |-
  17575. Used to provide custom certificate authority (CA) certificates
  17576. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  17577. that contains a PEM-encoded certificate.
  17578. properties:
  17579. key:
  17580. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17581. maxLength: 253
  17582. minLength: 1
  17583. pattern: ^[-._a-zA-Z0-9]+$
  17584. type: string
  17585. name:
  17586. description: The name of the object located at the provider type.
  17587. maxLength: 253
  17588. minLength: 1
  17589. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17590. type: string
  17591. namespace:
  17592. description: |-
  17593. The namespace the Provider type is in.
  17594. Can only be defined when used in a ClusterSecretStore.
  17595. maxLength: 63
  17596. minLength: 1
  17597. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17598. type: string
  17599. type:
  17600. description: The type of provider to use such as "Secret", or "ConfigMap".
  17601. enum:
  17602. - Secret
  17603. - ConfigMap
  17604. type: string
  17605. required:
  17606. - name
  17607. - type
  17608. type: object
  17609. url:
  17610. description: URL is the endpoint of the Conjur instance.
  17611. type: string
  17612. required:
  17613. - auth
  17614. - url
  17615. type: object
  17616. crd:
  17617. description: |-
  17618. CRD configures this store to sync secrets from arbitrary Kubernetes resources,
  17619. including both custom resources (CRDs) and core API resources. Resources are
  17620. selected by API group, version and kind, where group can be "" (empty string)
  17621. for core resources such as ConfigMap. Reading the core v1 Secret is
  17622. intentionally blocked — use the Kubernetes provider for that.
  17623. properties:
  17624. auth:
  17625. description: |-
  17626. Auth configures authentication to the Kubernetes API, same as the
  17627. Kubernetes provider. Required when Server.URL is set (unless using AuthRef).
  17628. maxProperties: 1
  17629. minProperties: 1
  17630. properties:
  17631. cert:
  17632. description: has both clientCert and clientKey as secretKeySelector
  17633. properties:
  17634. clientCert:
  17635. description: |-
  17636. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17637. In some instances, `key` is a required field.
  17638. properties:
  17639. key:
  17640. description: |-
  17641. A key in the referenced Secret.
  17642. Some instances of this field may be defaulted, in others it may be required.
  17643. maxLength: 253
  17644. minLength: 1
  17645. pattern: ^[-._a-zA-Z0-9]+$
  17646. type: string
  17647. name:
  17648. description: The name of the Secret resource being referred to.
  17649. maxLength: 253
  17650. minLength: 1
  17651. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17652. type: string
  17653. namespace:
  17654. description: |-
  17655. The namespace of the Secret resource being referred to.
  17656. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17657. maxLength: 63
  17658. minLength: 1
  17659. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17660. type: string
  17661. type: object
  17662. clientKey:
  17663. description: |-
  17664. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17665. In some instances, `key` is a required field.
  17666. properties:
  17667. key:
  17668. description: |-
  17669. A key in the referenced Secret.
  17670. Some instances of this field may be defaulted, in others it may be required.
  17671. maxLength: 253
  17672. minLength: 1
  17673. pattern: ^[-._a-zA-Z0-9]+$
  17674. type: string
  17675. name:
  17676. description: The name of the Secret resource being referred to.
  17677. maxLength: 253
  17678. minLength: 1
  17679. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17680. type: string
  17681. namespace:
  17682. description: |-
  17683. The namespace of the Secret resource being referred to.
  17684. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17685. maxLength: 63
  17686. minLength: 1
  17687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17688. type: string
  17689. type: object
  17690. required:
  17691. - clientCert
  17692. - clientKey
  17693. type: object
  17694. serviceAccount:
  17695. description: points to a service account that should be used for authentication
  17696. properties:
  17697. audiences:
  17698. description: |-
  17699. Audience specifies the `aud` claim for the service account token
  17700. Some providers automatically extend the audience field based on well-known annotations for workload
  17701. identity (e.g. IRSA or GCP Workload Identity)
  17702. items:
  17703. type: string
  17704. type: array
  17705. name:
  17706. description: The name of the ServiceAccount resource being referred to.
  17707. maxLength: 253
  17708. minLength: 1
  17709. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17710. type: string
  17711. namespace:
  17712. description: |-
  17713. Namespace of the resource being referred to.
  17714. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17715. maxLength: 63
  17716. minLength: 1
  17717. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17718. type: string
  17719. required:
  17720. - name
  17721. type: object
  17722. token:
  17723. description: use static token to authenticate with
  17724. properties:
  17725. bearerToken:
  17726. description: |-
  17727. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17728. In some instances, `key` is a required field.
  17729. properties:
  17730. key:
  17731. description: |-
  17732. A key in the referenced Secret.
  17733. Some instances of this field may be defaulted, in others it may be required.
  17734. maxLength: 253
  17735. minLength: 1
  17736. pattern: ^[-._a-zA-Z0-9]+$
  17737. type: string
  17738. name:
  17739. description: The name of the Secret resource being referred to.
  17740. maxLength: 253
  17741. minLength: 1
  17742. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17743. type: string
  17744. namespace:
  17745. description: |-
  17746. The namespace of the Secret resource being referred to.
  17747. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17748. maxLength: 63
  17749. minLength: 1
  17750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17751. type: string
  17752. type: object
  17753. required:
  17754. - bearerToken
  17755. type: object
  17756. type: object
  17757. authRef:
  17758. description: |-
  17759. AuthRef references a Secret containing a kubeconfig. Same semantics as the
  17760. Kubernetes provider.
  17761. properties:
  17762. key:
  17763. description: |-
  17764. A key in the referenced Secret.
  17765. Some instances of this field may be defaulted, in others it may be required.
  17766. maxLength: 253
  17767. minLength: 1
  17768. pattern: ^[-._a-zA-Z0-9]+$
  17769. type: string
  17770. name:
  17771. description: The name of the Secret resource being referred to.
  17772. maxLength: 253
  17773. minLength: 1
  17774. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17775. type: string
  17776. namespace:
  17777. description: |-
  17778. The namespace of the Secret resource being referred to.
  17779. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17780. maxLength: 63
  17781. minLength: 1
  17782. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17783. type: string
  17784. type: object
  17785. resource:
  17786. description: Resource identifies the CRD by its API group, version and kind.
  17787. properties:
  17788. group:
  17789. description: |-
  17790. Group is the API group of the resource. Use "" (empty string) for core
  17791. Kubernetes resources such as ConfigMap; use e.g. "config.example.io"
  17792. for a CRD. The field is required to be present in the manifest — write
  17793. `group: ""` explicitly for core resources so typos fail at admission
  17794. time rather than later at discovery.
  17795. type: string
  17796. kind:
  17797. description: Kind is the Kubernetes resource kind (e.g. "MyCustomResource").
  17798. minLength: 1
  17799. type: string
  17800. version:
  17801. description: Version is the API version of the resource (e.g. "v1alpha1").
  17802. minLength: 1
  17803. type: string
  17804. required:
  17805. - group
  17806. - kind
  17807. - version
  17808. type: object
  17809. server:
  17810. description: |-
  17811. Server configures the Kubernetes API address and TLS trust, same as the
  17812. Kubernetes provider. When omitted, the URL defaults to the in-cluster API.
  17813. properties:
  17814. caBundle:
  17815. description: CABundle is a base64-encoded CA certificate
  17816. format: byte
  17817. type: string
  17818. caProvider:
  17819. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  17820. properties:
  17821. key:
  17822. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17823. maxLength: 253
  17824. minLength: 1
  17825. pattern: ^[-._a-zA-Z0-9]+$
  17826. type: string
  17827. name:
  17828. description: The name of the object located at the provider type.
  17829. maxLength: 253
  17830. minLength: 1
  17831. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17832. type: string
  17833. namespace:
  17834. description: |-
  17835. The namespace the Provider type is in.
  17836. Can only be defined when used in a ClusterSecretStore.
  17837. maxLength: 63
  17838. minLength: 1
  17839. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17840. type: string
  17841. type:
  17842. description: The type of provider to use such as "Secret", or "ConfigMap".
  17843. enum:
  17844. - Secret
  17845. - ConfigMap
  17846. type: string
  17847. required:
  17848. - name
  17849. - type
  17850. type: object
  17851. url:
  17852. default: kubernetes.default
  17853. description: configures the Kubernetes server Address.
  17854. type: string
  17855. type: object
  17856. whitelist:
  17857. description: |-
  17858. Whitelist optionally restricts which object names and requested properties
  17859. are allowed to be read.
  17860. properties:
  17861. rules:
  17862. description: |-
  17863. Rules is a list of allow rules. If rules are set, at least one rule must
  17864. match for a request to be allowed.
  17865. items:
  17866. description: CRDProviderWhitelistRule defines a single allow rule for CRD reads.
  17867. properties:
  17868. name:
  17869. description: |-
  17870. Name is an optional regular expression matched against the bare object name.
  17871. For both SecretStore and ClusterSecretStore this is always the object name
  17872. without any namespace prefix (e.g. "my-db-spec", not "prod/my-db-spec").
  17873. type: string
  17874. namespace:
  17875. description: |-
  17876. Namespace is an optional regular expression matched against the namespace of
  17877. the object. Applies only when a ClusterSecretStore is used; it is ignored
  17878. for SecretStore (where the namespace is fixed to the store namespace).
  17879. type: string
  17880. properties:
  17881. description: |-
  17882. Properties is an optional list of regular expressions matched against
  17883. requested property keys (for example: "spec.secretValue").
  17884. items:
  17885. type: string
  17886. type: array
  17887. type: object
  17888. type: array
  17889. type: object
  17890. required:
  17891. - resource
  17892. type: object
  17893. x-kubernetes-validations:
  17894. - message: one of auth or authRef is required
  17895. rule: has(self.auth) || has(self.authRef)
  17896. - message: at most one of the fields in [auth authRef] may be set
  17897. rule: '[has(self.auth),has(self.authRef)].filter(x,x==true).size() <= 1'
  17898. delinea:
  17899. description: |-
  17900. Delinea DevOps Secrets Vault
  17901. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  17902. properties:
  17903. clientId:
  17904. description: ClientID is the non-secret part of the credential.
  17905. properties:
  17906. secretRef:
  17907. description: SecretRef references a key in a secret that will be used as value.
  17908. properties:
  17909. key:
  17910. description: |-
  17911. A key in the referenced Secret.
  17912. Some instances of this field may be defaulted, in others it may be required.
  17913. maxLength: 253
  17914. minLength: 1
  17915. pattern: ^[-._a-zA-Z0-9]+$
  17916. type: string
  17917. name:
  17918. description: The name of the Secret resource being referred to.
  17919. maxLength: 253
  17920. minLength: 1
  17921. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17922. type: string
  17923. namespace:
  17924. description: |-
  17925. The namespace of the Secret resource being referred to.
  17926. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17927. maxLength: 63
  17928. minLength: 1
  17929. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17930. type: string
  17931. type: object
  17932. value:
  17933. description: Value can be specified directly to set a value without using a secret.
  17934. type: string
  17935. type: object
  17936. clientSecret:
  17937. description: ClientSecret is the secret part of the credential.
  17938. properties:
  17939. secretRef:
  17940. description: SecretRef references a key in a secret that will be used as value.
  17941. properties:
  17942. key:
  17943. description: |-
  17944. A key in the referenced Secret.
  17945. Some instances of this field may be defaulted, in others it may be required.
  17946. maxLength: 253
  17947. minLength: 1
  17948. pattern: ^[-._a-zA-Z0-9]+$
  17949. type: string
  17950. name:
  17951. description: The name of the Secret resource being referred to.
  17952. maxLength: 253
  17953. minLength: 1
  17954. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17955. type: string
  17956. namespace:
  17957. description: |-
  17958. The namespace of the Secret resource being referred to.
  17959. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17960. maxLength: 63
  17961. minLength: 1
  17962. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17963. type: string
  17964. type: object
  17965. value:
  17966. description: Value can be specified directly to set a value without using a secret.
  17967. type: string
  17968. type: object
  17969. tenant:
  17970. description: Tenant is the chosen hostname / site name.
  17971. type: string
  17972. tld:
  17973. description: |-
  17974. TLD is based on the server location that was chosen during provisioning.
  17975. If unset, defaults to "com".
  17976. type: string
  17977. urlTemplate:
  17978. description: |-
  17979. URLTemplate
  17980. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  17981. type: string
  17982. required:
  17983. - clientId
  17984. - clientSecret
  17985. - tenant
  17986. type: object
  17987. doppler:
  17988. description: Doppler configures this store to sync secrets using the Doppler provider
  17989. properties:
  17990. auth:
  17991. description: Auth configures how the Operator authenticates with the Doppler API
  17992. properties:
  17993. oidcConfig:
  17994. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  17995. properties:
  17996. expirationSeconds:
  17997. default: 600
  17998. description: |-
  17999. ExpirationSeconds sets the ServiceAccount token validity duration.
  18000. Defaults to 10 minutes.
  18001. format: int64
  18002. type: integer
  18003. identity:
  18004. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  18005. type: string
  18006. serviceAccountRef:
  18007. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  18008. properties:
  18009. audiences:
  18010. description: |-
  18011. Audience specifies the `aud` claim for the service account token
  18012. Some providers automatically extend the audience field based on well-known annotations for workload
  18013. identity (e.g. IRSA or GCP Workload Identity)
  18014. items:
  18015. type: string
  18016. type: array
  18017. name:
  18018. description: The name of the ServiceAccount resource being referred to.
  18019. maxLength: 253
  18020. minLength: 1
  18021. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18022. type: string
  18023. namespace:
  18024. description: |-
  18025. Namespace of the resource being referred to.
  18026. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18027. maxLength: 63
  18028. minLength: 1
  18029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18030. type: string
  18031. required:
  18032. - name
  18033. type: object
  18034. required:
  18035. - identity
  18036. - serviceAccountRef
  18037. type: object
  18038. secretRef:
  18039. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  18040. properties:
  18041. dopplerToken:
  18042. description: |-
  18043. The DopplerToken is used for authentication.
  18044. See https://docs.doppler.com/reference/api#authentication for auth token types.
  18045. The Key attribute defaults to dopplerToken if not specified.
  18046. properties:
  18047. key:
  18048. description: |-
  18049. A key in the referenced Secret.
  18050. Some instances of this field may be defaulted, in others it may be required.
  18051. maxLength: 253
  18052. minLength: 1
  18053. pattern: ^[-._a-zA-Z0-9]+$
  18054. type: string
  18055. name:
  18056. description: The name of the Secret resource being referred to.
  18057. maxLength: 253
  18058. minLength: 1
  18059. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18060. type: string
  18061. namespace:
  18062. description: |-
  18063. The namespace of the Secret resource being referred to.
  18064. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18065. maxLength: 63
  18066. minLength: 1
  18067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18068. type: string
  18069. type: object
  18070. required:
  18071. - dopplerToken
  18072. type: object
  18073. type: object
  18074. x-kubernetes-validations:
  18075. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  18076. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  18077. config:
  18078. description: Doppler config (required if not using a Service Token)
  18079. type: string
  18080. format:
  18081. description: Format enables the downloading of secrets as a file (string)
  18082. enum:
  18083. - json
  18084. - dotnet-json
  18085. - env
  18086. - yaml
  18087. - docker
  18088. type: string
  18089. nameTransformer:
  18090. description: Environment variable compatible name transforms that change secret names to a different format
  18091. enum:
  18092. - upper-camel
  18093. - camel
  18094. - lower-snake
  18095. - tf-var
  18096. - dotnet-env
  18097. - lower-kebab
  18098. type: string
  18099. project:
  18100. description: Doppler project (required if not using a Service Token)
  18101. type: string
  18102. required:
  18103. - auth
  18104. type: object
  18105. dvls:
  18106. description: DVLS configures this store to sync secrets using Devolutions Server provider
  18107. properties:
  18108. auth:
  18109. description: Auth defines the authentication method to use.
  18110. properties:
  18111. secretRef:
  18112. description: SecretRef contains the Application ID and Application Secret for authentication.
  18113. properties:
  18114. appId:
  18115. description: AppID is the reference to the secret containing the Application ID.
  18116. properties:
  18117. key:
  18118. description: |-
  18119. A key in the referenced Secret.
  18120. Some instances of this field may be defaulted, in others it may be required.
  18121. maxLength: 253
  18122. minLength: 1
  18123. pattern: ^[-._a-zA-Z0-9]+$
  18124. type: string
  18125. name:
  18126. description: The name of the Secret resource being referred to.
  18127. maxLength: 253
  18128. minLength: 1
  18129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18130. type: string
  18131. namespace:
  18132. description: |-
  18133. The namespace of the Secret resource being referred to.
  18134. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18135. maxLength: 63
  18136. minLength: 1
  18137. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18138. type: string
  18139. type: object
  18140. appSecret:
  18141. description: AppSecret is the reference to the secret containing the Application Secret.
  18142. properties:
  18143. key:
  18144. description: |-
  18145. A key in the referenced Secret.
  18146. Some instances of this field may be defaulted, in others it may be required.
  18147. maxLength: 253
  18148. minLength: 1
  18149. pattern: ^[-._a-zA-Z0-9]+$
  18150. type: string
  18151. name:
  18152. description: The name of the Secret resource being referred to.
  18153. maxLength: 253
  18154. minLength: 1
  18155. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18156. type: string
  18157. namespace:
  18158. description: |-
  18159. The namespace of the Secret resource being referred to.
  18160. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18161. maxLength: 63
  18162. minLength: 1
  18163. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18164. type: string
  18165. type: object
  18166. required:
  18167. - appId
  18168. - appSecret
  18169. type: object
  18170. required:
  18171. - secretRef
  18172. type: object
  18173. insecure:
  18174. description: |-
  18175. Insecure allows connecting to DVLS over plain HTTP.
  18176. This is NOT RECOMMENDED for production use.
  18177. Set to true only if you understand the security implications.
  18178. type: boolean
  18179. serverUrl:
  18180. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  18181. type: string
  18182. vault:
  18183. description: |-
  18184. Vault is the name or UUID of the vault to fetch secrets from.
  18185. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  18186. type: string
  18187. required:
  18188. - auth
  18189. - serverUrl
  18190. type: object
  18191. fake:
  18192. description: Fake configures a store with static key/value pairs
  18193. properties:
  18194. data:
  18195. items:
  18196. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  18197. properties:
  18198. key:
  18199. type: string
  18200. value:
  18201. type: string
  18202. version:
  18203. type: string
  18204. required:
  18205. - key
  18206. - value
  18207. type: object
  18208. type: array
  18209. validationResult:
  18210. description: ValidationResult is defined type for the number of validation results.
  18211. type: integer
  18212. required:
  18213. - data
  18214. type: object
  18215. fortanix:
  18216. description: Fortanix configures this store to sync secrets using the Fortanix provider
  18217. properties:
  18218. apiKey:
  18219. description: APIKey is the API token to access SDKMS Applications.
  18220. properties:
  18221. secretRef:
  18222. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  18223. properties:
  18224. key:
  18225. description: |-
  18226. A key in the referenced Secret.
  18227. Some instances of this field may be defaulted, in others it may be required.
  18228. maxLength: 253
  18229. minLength: 1
  18230. pattern: ^[-._a-zA-Z0-9]+$
  18231. type: string
  18232. name:
  18233. description: The name of the Secret resource being referred to.
  18234. maxLength: 253
  18235. minLength: 1
  18236. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18237. type: string
  18238. namespace:
  18239. description: |-
  18240. The namespace of the Secret resource being referred to.
  18241. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18242. maxLength: 63
  18243. minLength: 1
  18244. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18245. type: string
  18246. type: object
  18247. type: object
  18248. apiUrl:
  18249. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  18250. type: string
  18251. type: object
  18252. gcpsm:
  18253. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  18254. properties:
  18255. auth:
  18256. description: Auth defines the information necessary to authenticate against GCP
  18257. properties:
  18258. secretRef:
  18259. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  18260. properties:
  18261. secretAccessKeySecretRef:
  18262. description: The SecretAccessKey is used for authentication
  18263. properties:
  18264. key:
  18265. description: |-
  18266. A key in the referenced Secret.
  18267. Some instances of this field may be defaulted, in others it may be required.
  18268. maxLength: 253
  18269. minLength: 1
  18270. pattern: ^[-._a-zA-Z0-9]+$
  18271. type: string
  18272. name:
  18273. description: The name of the Secret resource being referred to.
  18274. maxLength: 253
  18275. minLength: 1
  18276. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18277. type: string
  18278. namespace:
  18279. description: |-
  18280. The namespace of the Secret resource being referred to.
  18281. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18282. maxLength: 63
  18283. minLength: 1
  18284. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18285. type: string
  18286. type: object
  18287. type: object
  18288. workloadIdentity:
  18289. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  18290. properties:
  18291. clusterLocation:
  18292. description: |-
  18293. ClusterLocation is the location of the cluster
  18294. If not specified, it fetches information from the metadata server
  18295. type: string
  18296. clusterName:
  18297. description: |-
  18298. ClusterName is the name of the cluster
  18299. If not specified, it fetches information from the metadata server
  18300. type: string
  18301. clusterProjectID:
  18302. description: |-
  18303. ClusterProjectID is the project ID of the cluster
  18304. If not specified, it fetches information from the metadata server
  18305. type: string
  18306. serviceAccountRef:
  18307. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  18308. properties:
  18309. audiences:
  18310. description: |-
  18311. Audience specifies the `aud` claim for the service account token
  18312. Some providers automatically extend the audience field based on well-known annotations for workload
  18313. identity (e.g. IRSA or GCP Workload Identity)
  18314. items:
  18315. type: string
  18316. type: array
  18317. name:
  18318. description: The name of the ServiceAccount resource being referred to.
  18319. maxLength: 253
  18320. minLength: 1
  18321. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18322. type: string
  18323. namespace:
  18324. description: |-
  18325. Namespace of the resource being referred to.
  18326. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18327. maxLength: 63
  18328. minLength: 1
  18329. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18330. type: string
  18331. required:
  18332. - name
  18333. type: object
  18334. required:
  18335. - serviceAccountRef
  18336. type: object
  18337. workloadIdentityFederation:
  18338. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  18339. properties:
  18340. audience:
  18341. description: |-
  18342. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  18343. If specified, Audience found in the external account credential config will be overridden with the configured value.
  18344. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  18345. type: string
  18346. awsSecurityCredentials:
  18347. description: |-
  18348. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  18349. when using the AWS metadata server is not an option.
  18350. properties:
  18351. awsCredentialsSecretRef:
  18352. description: |-
  18353. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  18354. Secret should be created with below names for keys
  18355. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  18356. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  18357. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  18358. properties:
  18359. name:
  18360. description: name of the secret.
  18361. maxLength: 253
  18362. minLength: 1
  18363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18364. type: string
  18365. namespace:
  18366. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  18367. maxLength: 63
  18368. minLength: 1
  18369. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18370. type: string
  18371. required:
  18372. - name
  18373. type: object
  18374. region:
  18375. description: region is for configuring the AWS region to be used.
  18376. example: ap-south-1
  18377. maxLength: 50
  18378. minLength: 1
  18379. pattern: ^[a-z0-9-]+$
  18380. type: string
  18381. required:
  18382. - awsCredentialsSecretRef
  18383. - region
  18384. type: object
  18385. credConfig:
  18386. description: |-
  18387. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  18388. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  18389. serviceAccountRef must be used by providing operators service account details.
  18390. properties:
  18391. key:
  18392. description: key name holding the external account credential config.
  18393. maxLength: 253
  18394. minLength: 1
  18395. pattern: ^[-._a-zA-Z0-9]+$
  18396. type: string
  18397. name:
  18398. description: name of the configmap.
  18399. maxLength: 253
  18400. minLength: 1
  18401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18402. type: string
  18403. namespace:
  18404. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  18405. maxLength: 63
  18406. minLength: 1
  18407. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18408. type: string
  18409. required:
  18410. - key
  18411. - name
  18412. type: object
  18413. externalTokenEndpoint:
  18414. description: |-
  18415. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  18416. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  18417. URL is having the expected value.
  18418. type: string
  18419. gcpServiceAccountEmail:
  18420. description: |-
  18421. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  18422. after Workload Identity Federation. Use this to grant access through the service account's
  18423. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  18424. service_account_impersonation_url in the external account JSON from credConfig;
  18425. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  18426. on that ServiceAccount.
  18427. example: my-gsa@my-project.iam.gserviceaccount.com
  18428. minLength: 1
  18429. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  18430. type: string
  18431. serviceAccountRef:
  18432. description: |-
  18433. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  18434. when Kubernetes is configured as provider in workload identity pool.
  18435. properties:
  18436. audiences:
  18437. description: |-
  18438. Audience specifies the `aud` claim for the service account token
  18439. Some providers automatically extend the audience field based on well-known annotations for workload
  18440. identity (e.g. IRSA or GCP Workload Identity)
  18441. items:
  18442. type: string
  18443. type: array
  18444. name:
  18445. description: The name of the ServiceAccount resource being referred to.
  18446. maxLength: 253
  18447. minLength: 1
  18448. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18449. type: string
  18450. namespace:
  18451. description: |-
  18452. Namespace of the resource being referred to.
  18453. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18454. maxLength: 63
  18455. minLength: 1
  18456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18457. type: string
  18458. required:
  18459. - name
  18460. type: object
  18461. type: object
  18462. type: object
  18463. location:
  18464. description: Location optionally defines a location for a secret
  18465. type: string
  18466. projectID:
  18467. description: ProjectID project where secret is located
  18468. type: string
  18469. secretVersionSelectionPolicy:
  18470. default: LatestOrFail
  18471. description: |-
  18472. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  18473. when "latest" is disabled or destroyed.
  18474. Possible values are:
  18475. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  18476. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  18477. type: string
  18478. type: object
  18479. github:
  18480. description: |-
  18481. Github configures this store to push GitHub Actions or Dependabot secrets using the GitHub API provider.
  18482. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  18483. properties:
  18484. appID:
  18485. description: appID specifies the Github APP that will be used to authenticate the client
  18486. format: int64
  18487. type: integer
  18488. auth:
  18489. description: auth configures how secret-manager authenticates with a Github instance.
  18490. properties:
  18491. privateKey:
  18492. description: |-
  18493. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18494. In some instances, `key` is a required field.
  18495. properties:
  18496. key:
  18497. description: |-
  18498. A key in the referenced Secret.
  18499. Some instances of this field may be defaulted, in others it may be required.
  18500. maxLength: 253
  18501. minLength: 1
  18502. pattern: ^[-._a-zA-Z0-9]+$
  18503. type: string
  18504. name:
  18505. description: The name of the Secret resource being referred to.
  18506. maxLength: 253
  18507. minLength: 1
  18508. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18509. type: string
  18510. namespace:
  18511. description: |-
  18512. The namespace of the Secret resource being referred to.
  18513. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18514. maxLength: 63
  18515. minLength: 1
  18516. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18517. type: string
  18518. type: object
  18519. required:
  18520. - privateKey
  18521. type: object
  18522. environment:
  18523. description: environment will be used to fetch secrets from a particular environment within a github repository
  18524. type: string
  18525. installationID:
  18526. description: installationID specifies the Github APP installation that will be used to authenticate the client
  18527. format: int64
  18528. type: integer
  18529. orgSecretVisibility:
  18530. description: |-
  18531. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  18532. Valid values are "all" or "private".
  18533. When unset, new secrets are created with visibility "all" and existing secrets preserve
  18534. whatever visibility they already have in GitHub.
  18535. enum:
  18536. - all
  18537. - private
  18538. type: string
  18539. organization:
  18540. description: organization will be used to fetch secrets from the Github organization
  18541. type: string
  18542. repository:
  18543. description: repository will be used to fetch secrets from the Github repository within an organization
  18544. type: string
  18545. secretType:
  18546. default: Actions
  18547. description: |-
  18548. secretType specifies which GitHub secret service to use.
  18549. Defaults to Actions for backwards compatibility.
  18550. enum:
  18551. - Actions
  18552. - Dependabot
  18553. type: string
  18554. uploadURL:
  18555. description: Upload URL for enterprise instances. Default to URL.
  18556. type: string
  18557. url:
  18558. default: https://github.com/
  18559. description: URL configures the Github instance URL. Defaults to https://github.com/.
  18560. type: string
  18561. required:
  18562. - appID
  18563. - auth
  18564. - installationID
  18565. - organization
  18566. type: object
  18567. x-kubernetes-validations:
  18568. - message: Dependabot secrets do not support environments
  18569. rule: self.secretType != 'Dependabot' || !has(self.environment) || size(self.environment) == 0
  18570. gitlab:
  18571. description: GitLab configures this store to sync secrets using GitLab Variables provider
  18572. properties:
  18573. auth:
  18574. description: Auth configures how secret-manager authenticates with a GitLab instance.
  18575. properties:
  18576. SecretRef:
  18577. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  18578. properties:
  18579. accessToken:
  18580. description: AccessToken is used for authentication.
  18581. properties:
  18582. key:
  18583. description: |-
  18584. A key in the referenced Secret.
  18585. Some instances of this field may be defaulted, in others it may be required.
  18586. maxLength: 253
  18587. minLength: 1
  18588. pattern: ^[-._a-zA-Z0-9]+$
  18589. type: string
  18590. name:
  18591. description: The name of the Secret resource being referred to.
  18592. maxLength: 253
  18593. minLength: 1
  18594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18595. type: string
  18596. namespace:
  18597. description: |-
  18598. The namespace of the Secret resource being referred to.
  18599. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18600. maxLength: 63
  18601. minLength: 1
  18602. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18603. type: string
  18604. type: object
  18605. type: object
  18606. required:
  18607. - SecretRef
  18608. type: object
  18609. caBundle:
  18610. description: |-
  18611. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  18612. can be performed.
  18613. format: byte
  18614. type: string
  18615. caProvider:
  18616. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  18617. properties:
  18618. key:
  18619. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  18620. maxLength: 253
  18621. minLength: 1
  18622. pattern: ^[-._a-zA-Z0-9]+$
  18623. type: string
  18624. name:
  18625. description: The name of the object located at the provider type.
  18626. maxLength: 253
  18627. minLength: 1
  18628. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18629. type: string
  18630. namespace:
  18631. description: |-
  18632. The namespace the Provider type is in.
  18633. Can only be defined when used in a ClusterSecretStore.
  18634. maxLength: 63
  18635. minLength: 1
  18636. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18637. type: string
  18638. type:
  18639. description: The type of provider to use such as "Secret", or "ConfigMap".
  18640. enum:
  18641. - Secret
  18642. - ConfigMap
  18643. type: string
  18644. required:
  18645. - name
  18646. - type
  18647. type: object
  18648. environment:
  18649. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  18650. type: string
  18651. groupIDs:
  18652. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  18653. items:
  18654. type: string
  18655. type: array
  18656. inheritFromGroups:
  18657. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  18658. type: boolean
  18659. projectID:
  18660. description: ProjectID specifies a project where secrets are located.
  18661. type: string
  18662. url:
  18663. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  18664. type: string
  18665. required:
  18666. - auth
  18667. type: object
  18668. ibm:
  18669. description: IBM configures this store to sync secrets using IBM Cloud provider
  18670. properties:
  18671. auth:
  18672. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  18673. maxProperties: 1
  18674. minProperties: 1
  18675. properties:
  18676. containerAuth:
  18677. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  18678. properties:
  18679. iamEndpoint:
  18680. type: string
  18681. profile:
  18682. description: the IBM Trusted Profile
  18683. type: string
  18684. tokenLocation:
  18685. description: Location the token is mounted on the pod
  18686. type: string
  18687. required:
  18688. - profile
  18689. type: object
  18690. secretRef:
  18691. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  18692. properties:
  18693. iamEndpoint:
  18694. description: The IAM endpoint used to obain a token
  18695. type: string
  18696. secretApiKeySecretRef:
  18697. description: The SecretAccessKey is used for authentication
  18698. properties:
  18699. key:
  18700. description: |-
  18701. A key in the referenced Secret.
  18702. Some instances of this field may be defaulted, in others it may be required.
  18703. maxLength: 253
  18704. minLength: 1
  18705. pattern: ^[-._a-zA-Z0-9]+$
  18706. type: string
  18707. name:
  18708. description: The name of the Secret resource being referred to.
  18709. maxLength: 253
  18710. minLength: 1
  18711. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18712. type: string
  18713. namespace:
  18714. description: |-
  18715. The namespace of the Secret resource being referred to.
  18716. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18717. maxLength: 63
  18718. minLength: 1
  18719. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18720. type: string
  18721. type: object
  18722. type: object
  18723. type: object
  18724. serviceUrl:
  18725. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  18726. type: string
  18727. required:
  18728. - auth
  18729. type: object
  18730. infisical:
  18731. description: Infisical configures this store to sync secrets using the Infisical provider
  18732. properties:
  18733. auth:
  18734. description: Auth configures how the Operator authenticates with the Infisical API
  18735. properties:
  18736. awsAuthCredentials:
  18737. description: AwsAuthCredentials represents the credentials for AWS authentication.
  18738. properties:
  18739. identityId:
  18740. description: |-
  18741. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18742. In some instances, `key` is a required field.
  18743. properties:
  18744. key:
  18745. description: |-
  18746. A key in the referenced Secret.
  18747. Some instances of this field may be defaulted, in others it may be required.
  18748. maxLength: 253
  18749. minLength: 1
  18750. pattern: ^[-._a-zA-Z0-9]+$
  18751. type: string
  18752. name:
  18753. description: The name of the Secret resource being referred to.
  18754. maxLength: 253
  18755. minLength: 1
  18756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18757. type: string
  18758. namespace:
  18759. description: |-
  18760. The namespace of the Secret resource being referred to.
  18761. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18762. maxLength: 63
  18763. minLength: 1
  18764. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18765. type: string
  18766. type: object
  18767. required:
  18768. - identityId
  18769. type: object
  18770. azureAuthCredentials:
  18771. description: AzureAuthCredentials represents the credentials for Azure authentication.
  18772. properties:
  18773. identityId:
  18774. description: |-
  18775. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18776. In some instances, `key` is a required field.
  18777. properties:
  18778. key:
  18779. description: |-
  18780. A key in the referenced Secret.
  18781. Some instances of this field may be defaulted, in others it may be required.
  18782. maxLength: 253
  18783. minLength: 1
  18784. pattern: ^[-._a-zA-Z0-9]+$
  18785. type: string
  18786. name:
  18787. description: The name of the Secret resource being referred to.
  18788. maxLength: 253
  18789. minLength: 1
  18790. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18791. type: string
  18792. namespace:
  18793. description: |-
  18794. The namespace of the Secret resource being referred to.
  18795. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18796. maxLength: 63
  18797. minLength: 1
  18798. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18799. type: string
  18800. type: object
  18801. resource:
  18802. description: |-
  18803. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18804. In some instances, `key` is a required field.
  18805. properties:
  18806. key:
  18807. description: |-
  18808. A key in the referenced Secret.
  18809. Some instances of this field may be defaulted, in others it may be required.
  18810. maxLength: 253
  18811. minLength: 1
  18812. pattern: ^[-._a-zA-Z0-9]+$
  18813. type: string
  18814. name:
  18815. description: The name of the Secret resource being referred to.
  18816. maxLength: 253
  18817. minLength: 1
  18818. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18819. type: string
  18820. namespace:
  18821. description: |-
  18822. The namespace of the Secret resource being referred to.
  18823. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18824. maxLength: 63
  18825. minLength: 1
  18826. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18827. type: string
  18828. type: object
  18829. required:
  18830. - identityId
  18831. type: object
  18832. gcpIamAuthCredentials:
  18833. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  18834. properties:
  18835. identityId:
  18836. description: |-
  18837. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18838. In some instances, `key` is a required field.
  18839. properties:
  18840. key:
  18841. description: |-
  18842. A key in the referenced Secret.
  18843. Some instances of this field may be defaulted, in others it may be required.
  18844. maxLength: 253
  18845. minLength: 1
  18846. pattern: ^[-._a-zA-Z0-9]+$
  18847. type: string
  18848. name:
  18849. description: The name of the Secret resource being referred to.
  18850. maxLength: 253
  18851. minLength: 1
  18852. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18853. type: string
  18854. namespace:
  18855. description: |-
  18856. The namespace of the Secret resource being referred to.
  18857. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18858. maxLength: 63
  18859. minLength: 1
  18860. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18861. type: string
  18862. type: object
  18863. serviceAccountKeyFilePath:
  18864. description: |-
  18865. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18866. In some instances, `key` is a required field.
  18867. properties:
  18868. key:
  18869. description: |-
  18870. A key in the referenced Secret.
  18871. Some instances of this field may be defaulted, in others it may be required.
  18872. maxLength: 253
  18873. minLength: 1
  18874. pattern: ^[-._a-zA-Z0-9]+$
  18875. type: string
  18876. name:
  18877. description: The name of the Secret resource being referred to.
  18878. maxLength: 253
  18879. minLength: 1
  18880. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18881. type: string
  18882. namespace:
  18883. description: |-
  18884. The namespace of the Secret resource being referred to.
  18885. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18886. maxLength: 63
  18887. minLength: 1
  18888. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18889. type: string
  18890. type: object
  18891. required:
  18892. - identityId
  18893. - serviceAccountKeyFilePath
  18894. type: object
  18895. gcpIdTokenAuthCredentials:
  18896. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  18897. properties:
  18898. identityId:
  18899. description: |-
  18900. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18901. In some instances, `key` is a required field.
  18902. properties:
  18903. key:
  18904. description: |-
  18905. A key in the referenced Secret.
  18906. Some instances of this field may be defaulted, in others it may be required.
  18907. maxLength: 253
  18908. minLength: 1
  18909. pattern: ^[-._a-zA-Z0-9]+$
  18910. type: string
  18911. name:
  18912. description: The name of the Secret resource being referred to.
  18913. maxLength: 253
  18914. minLength: 1
  18915. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18916. type: string
  18917. namespace:
  18918. description: |-
  18919. The namespace of the Secret resource being referred to.
  18920. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18921. maxLength: 63
  18922. minLength: 1
  18923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18924. type: string
  18925. type: object
  18926. required:
  18927. - identityId
  18928. type: object
  18929. jwtAuthCredentials:
  18930. description: JwtAuthCredentials represents the credentials for JWT authentication.
  18931. properties:
  18932. identityId:
  18933. description: |-
  18934. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18935. In some instances, `key` is a required field.
  18936. properties:
  18937. key:
  18938. description: |-
  18939. A key in the referenced Secret.
  18940. Some instances of this field may be defaulted, in others it may be required.
  18941. maxLength: 253
  18942. minLength: 1
  18943. pattern: ^[-._a-zA-Z0-9]+$
  18944. type: string
  18945. name:
  18946. description: The name of the Secret resource being referred to.
  18947. maxLength: 253
  18948. minLength: 1
  18949. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18950. type: string
  18951. namespace:
  18952. description: |-
  18953. The namespace of the Secret resource being referred to.
  18954. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18955. maxLength: 63
  18956. minLength: 1
  18957. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18958. type: string
  18959. type: object
  18960. jwt:
  18961. description: |-
  18962. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18963. In some instances, `key` is a required field.
  18964. properties:
  18965. key:
  18966. description: |-
  18967. A key in the referenced Secret.
  18968. Some instances of this field may be defaulted, in others it may be required.
  18969. maxLength: 253
  18970. minLength: 1
  18971. pattern: ^[-._a-zA-Z0-9]+$
  18972. type: string
  18973. name:
  18974. description: The name of the Secret resource being referred to.
  18975. maxLength: 253
  18976. minLength: 1
  18977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18978. type: string
  18979. namespace:
  18980. description: |-
  18981. The namespace of the Secret resource being referred to.
  18982. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18983. maxLength: 63
  18984. minLength: 1
  18985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18986. type: string
  18987. type: object
  18988. required:
  18989. - identityId
  18990. - jwt
  18991. type: object
  18992. kubernetesAuthCredentials:
  18993. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  18994. properties:
  18995. identityId:
  18996. description: |-
  18997. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18998. In some instances, `key` is a required field.
  18999. properties:
  19000. key:
  19001. description: |-
  19002. A key in the referenced Secret.
  19003. Some instances of this field may be defaulted, in others it may be required.
  19004. maxLength: 253
  19005. minLength: 1
  19006. pattern: ^[-._a-zA-Z0-9]+$
  19007. type: string
  19008. name:
  19009. description: The name of the Secret resource being referred to.
  19010. maxLength: 253
  19011. minLength: 1
  19012. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19013. type: string
  19014. namespace:
  19015. description: |-
  19016. The namespace of the Secret resource being referred to.
  19017. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19018. maxLength: 63
  19019. minLength: 1
  19020. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19021. type: string
  19022. type: object
  19023. serviceAccountTokenPath:
  19024. description: |-
  19025. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19026. In some instances, `key` is a required field.
  19027. properties:
  19028. key:
  19029. description: |-
  19030. A key in the referenced Secret.
  19031. Some instances of this field may be defaulted, in others it may be required.
  19032. maxLength: 253
  19033. minLength: 1
  19034. pattern: ^[-._a-zA-Z0-9]+$
  19035. type: string
  19036. name:
  19037. description: The name of the Secret resource being referred to.
  19038. maxLength: 253
  19039. minLength: 1
  19040. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19041. type: string
  19042. namespace:
  19043. description: |-
  19044. The namespace of the Secret resource being referred to.
  19045. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19046. maxLength: 63
  19047. minLength: 1
  19048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19049. type: string
  19050. type: object
  19051. required:
  19052. - identityId
  19053. type: object
  19054. ldapAuthCredentials:
  19055. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  19056. properties:
  19057. identityId:
  19058. description: |-
  19059. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19060. In some instances, `key` is a required field.
  19061. properties:
  19062. key:
  19063. description: |-
  19064. A key in the referenced Secret.
  19065. Some instances of this field may be defaulted, in others it may be required.
  19066. maxLength: 253
  19067. minLength: 1
  19068. pattern: ^[-._a-zA-Z0-9]+$
  19069. type: string
  19070. name:
  19071. description: The name of the Secret resource being referred to.
  19072. maxLength: 253
  19073. minLength: 1
  19074. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19075. type: string
  19076. namespace:
  19077. description: |-
  19078. The namespace of the Secret resource being referred to.
  19079. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19080. maxLength: 63
  19081. minLength: 1
  19082. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19083. type: string
  19084. type: object
  19085. ldapPassword:
  19086. description: |-
  19087. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19088. In some instances, `key` is a required field.
  19089. properties:
  19090. key:
  19091. description: |-
  19092. A key in the referenced Secret.
  19093. Some instances of this field may be defaulted, in others it may be required.
  19094. maxLength: 253
  19095. minLength: 1
  19096. pattern: ^[-._a-zA-Z0-9]+$
  19097. type: string
  19098. name:
  19099. description: The name of the Secret resource being referred to.
  19100. maxLength: 253
  19101. minLength: 1
  19102. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19103. type: string
  19104. namespace:
  19105. description: |-
  19106. The namespace of the Secret resource being referred to.
  19107. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19108. maxLength: 63
  19109. minLength: 1
  19110. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19111. type: string
  19112. type: object
  19113. ldapUsername:
  19114. description: |-
  19115. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19116. In some instances, `key` is a required field.
  19117. properties:
  19118. key:
  19119. description: |-
  19120. A key in the referenced Secret.
  19121. Some instances of this field may be defaulted, in others it may be required.
  19122. maxLength: 253
  19123. minLength: 1
  19124. pattern: ^[-._a-zA-Z0-9]+$
  19125. type: string
  19126. name:
  19127. description: The name of the Secret resource being referred to.
  19128. maxLength: 253
  19129. minLength: 1
  19130. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19131. type: string
  19132. namespace:
  19133. description: |-
  19134. The namespace of the Secret resource being referred to.
  19135. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19136. maxLength: 63
  19137. minLength: 1
  19138. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19139. type: string
  19140. type: object
  19141. required:
  19142. - identityId
  19143. - ldapPassword
  19144. - ldapUsername
  19145. type: object
  19146. ociAuthCredentials:
  19147. description: OciAuthCredentials represents the credentials for OCI authentication.
  19148. properties:
  19149. fingerprint:
  19150. description: |-
  19151. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19152. In some instances, `key` is a required field.
  19153. properties:
  19154. key:
  19155. description: |-
  19156. A key in the referenced Secret.
  19157. Some instances of this field may be defaulted, in others it may be required.
  19158. maxLength: 253
  19159. minLength: 1
  19160. pattern: ^[-._a-zA-Z0-9]+$
  19161. type: string
  19162. name:
  19163. description: The name of the Secret resource being referred to.
  19164. maxLength: 253
  19165. minLength: 1
  19166. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19167. type: string
  19168. namespace:
  19169. description: |-
  19170. The namespace of the Secret resource being referred to.
  19171. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19172. maxLength: 63
  19173. minLength: 1
  19174. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19175. type: string
  19176. type: object
  19177. identityId:
  19178. description: |-
  19179. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19180. In some instances, `key` is a required field.
  19181. properties:
  19182. key:
  19183. description: |-
  19184. A key in the referenced Secret.
  19185. Some instances of this field may be defaulted, in others it may be required.
  19186. maxLength: 253
  19187. minLength: 1
  19188. pattern: ^[-._a-zA-Z0-9]+$
  19189. type: string
  19190. name:
  19191. description: The name of the Secret resource being referred to.
  19192. maxLength: 253
  19193. minLength: 1
  19194. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19195. type: string
  19196. namespace:
  19197. description: |-
  19198. The namespace of the Secret resource being referred to.
  19199. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19200. maxLength: 63
  19201. minLength: 1
  19202. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19203. type: string
  19204. type: object
  19205. privateKey:
  19206. description: |-
  19207. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19208. In some instances, `key` is a required field.
  19209. properties:
  19210. key:
  19211. description: |-
  19212. A key in the referenced Secret.
  19213. Some instances of this field may be defaulted, in others it may be required.
  19214. maxLength: 253
  19215. minLength: 1
  19216. pattern: ^[-._a-zA-Z0-9]+$
  19217. type: string
  19218. name:
  19219. description: The name of the Secret resource being referred to.
  19220. maxLength: 253
  19221. minLength: 1
  19222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19223. type: string
  19224. namespace:
  19225. description: |-
  19226. The namespace of the Secret resource being referred to.
  19227. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19228. maxLength: 63
  19229. minLength: 1
  19230. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19231. type: string
  19232. type: object
  19233. privateKeyPassphrase:
  19234. description: |-
  19235. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19236. In some instances, `key` is a required field.
  19237. properties:
  19238. key:
  19239. description: |-
  19240. A key in the referenced Secret.
  19241. Some instances of this field may be defaulted, in others it may be required.
  19242. maxLength: 253
  19243. minLength: 1
  19244. pattern: ^[-._a-zA-Z0-9]+$
  19245. type: string
  19246. name:
  19247. description: The name of the Secret resource being referred to.
  19248. maxLength: 253
  19249. minLength: 1
  19250. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19251. type: string
  19252. namespace:
  19253. description: |-
  19254. The namespace of the Secret resource being referred to.
  19255. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19256. maxLength: 63
  19257. minLength: 1
  19258. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19259. type: string
  19260. type: object
  19261. region:
  19262. description: |-
  19263. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19264. In some instances, `key` is a required field.
  19265. properties:
  19266. key:
  19267. description: |-
  19268. A key in the referenced Secret.
  19269. Some instances of this field may be defaulted, in others it may be required.
  19270. maxLength: 253
  19271. minLength: 1
  19272. pattern: ^[-._a-zA-Z0-9]+$
  19273. type: string
  19274. name:
  19275. description: The name of the Secret resource being referred to.
  19276. maxLength: 253
  19277. minLength: 1
  19278. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19279. type: string
  19280. namespace:
  19281. description: |-
  19282. The namespace of the Secret resource being referred to.
  19283. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19284. maxLength: 63
  19285. minLength: 1
  19286. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19287. type: string
  19288. type: object
  19289. tenancyId:
  19290. description: |-
  19291. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19292. In some instances, `key` is a required field.
  19293. properties:
  19294. key:
  19295. description: |-
  19296. A key in the referenced Secret.
  19297. Some instances of this field may be defaulted, in others it may be required.
  19298. maxLength: 253
  19299. minLength: 1
  19300. pattern: ^[-._a-zA-Z0-9]+$
  19301. type: string
  19302. name:
  19303. description: The name of the Secret resource being referred to.
  19304. maxLength: 253
  19305. minLength: 1
  19306. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19307. type: string
  19308. namespace:
  19309. description: |-
  19310. The namespace of the Secret resource being referred to.
  19311. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19312. maxLength: 63
  19313. minLength: 1
  19314. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19315. type: string
  19316. type: object
  19317. userId:
  19318. description: |-
  19319. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19320. In some instances, `key` is a required field.
  19321. properties:
  19322. key:
  19323. description: |-
  19324. A key in the referenced Secret.
  19325. Some instances of this field may be defaulted, in others it may be required.
  19326. maxLength: 253
  19327. minLength: 1
  19328. pattern: ^[-._a-zA-Z0-9]+$
  19329. type: string
  19330. name:
  19331. description: The name of the Secret resource being referred to.
  19332. maxLength: 253
  19333. minLength: 1
  19334. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19335. type: string
  19336. namespace:
  19337. description: |-
  19338. The namespace of the Secret resource being referred to.
  19339. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19340. maxLength: 63
  19341. minLength: 1
  19342. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19343. type: string
  19344. type: object
  19345. required:
  19346. - fingerprint
  19347. - identityId
  19348. - privateKey
  19349. - region
  19350. - tenancyId
  19351. - userId
  19352. type: object
  19353. tokenAuthCredentials:
  19354. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  19355. properties:
  19356. accessToken:
  19357. description: |-
  19358. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19359. In some instances, `key` is a required field.
  19360. properties:
  19361. key:
  19362. description: |-
  19363. A key in the referenced Secret.
  19364. Some instances of this field may be defaulted, in others it may be required.
  19365. maxLength: 253
  19366. minLength: 1
  19367. pattern: ^[-._a-zA-Z0-9]+$
  19368. type: string
  19369. name:
  19370. description: The name of the Secret resource being referred to.
  19371. maxLength: 253
  19372. minLength: 1
  19373. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19374. type: string
  19375. namespace:
  19376. description: |-
  19377. The namespace of the Secret resource being referred to.
  19378. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19379. maxLength: 63
  19380. minLength: 1
  19381. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19382. type: string
  19383. type: object
  19384. required:
  19385. - accessToken
  19386. type: object
  19387. universalAuthCredentials:
  19388. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  19389. properties:
  19390. clientId:
  19391. description: |-
  19392. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19393. In some instances, `key` is a required field.
  19394. properties:
  19395. key:
  19396. description: |-
  19397. A key in the referenced Secret.
  19398. Some instances of this field may be defaulted, in others it may be required.
  19399. maxLength: 253
  19400. minLength: 1
  19401. pattern: ^[-._a-zA-Z0-9]+$
  19402. type: string
  19403. name:
  19404. description: The name of the Secret resource being referred to.
  19405. maxLength: 253
  19406. minLength: 1
  19407. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19408. type: string
  19409. namespace:
  19410. description: |-
  19411. The namespace of the Secret resource being referred to.
  19412. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19413. maxLength: 63
  19414. minLength: 1
  19415. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19416. type: string
  19417. type: object
  19418. clientSecret:
  19419. description: |-
  19420. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19421. In some instances, `key` is a required field.
  19422. properties:
  19423. key:
  19424. description: |-
  19425. A key in the referenced Secret.
  19426. Some instances of this field may be defaulted, in others it may be required.
  19427. maxLength: 253
  19428. minLength: 1
  19429. pattern: ^[-._a-zA-Z0-9]+$
  19430. type: string
  19431. name:
  19432. description: The name of the Secret resource being referred to.
  19433. maxLength: 253
  19434. minLength: 1
  19435. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19436. type: string
  19437. namespace:
  19438. description: |-
  19439. The namespace of the Secret resource being referred to.
  19440. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19441. maxLength: 63
  19442. minLength: 1
  19443. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19444. type: string
  19445. type: object
  19446. required:
  19447. - clientId
  19448. - clientSecret
  19449. type: object
  19450. type: object
  19451. caBundle:
  19452. description: |-
  19453. CABundle is a PEM-encoded CA certificate bundle used to validate
  19454. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  19455. format: byte
  19456. type: string
  19457. caProvider:
  19458. description: |-
  19459. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  19460. The certificate is used to validate the Infisical server's TLS certificate.
  19461. Mutually exclusive with CABundle.
  19462. properties:
  19463. key:
  19464. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19465. maxLength: 253
  19466. minLength: 1
  19467. pattern: ^[-._a-zA-Z0-9]+$
  19468. type: string
  19469. name:
  19470. description: The name of the object located at the provider type.
  19471. maxLength: 253
  19472. minLength: 1
  19473. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19474. type: string
  19475. namespace:
  19476. description: |-
  19477. The namespace the Provider type is in.
  19478. Can only be defined when used in a ClusterSecretStore.
  19479. maxLength: 63
  19480. minLength: 1
  19481. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19482. type: string
  19483. type:
  19484. description: The type of provider to use such as "Secret", or "ConfigMap".
  19485. enum:
  19486. - Secret
  19487. - ConfigMap
  19488. type: string
  19489. required:
  19490. - name
  19491. - type
  19492. type: object
  19493. hostAPI:
  19494. default: https://app.infisical.com/api
  19495. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  19496. type: string
  19497. secretsScope:
  19498. description: SecretsScope defines the scope of the secrets within the workspace
  19499. properties:
  19500. environmentSlug:
  19501. description: EnvironmentSlug is the required slug identifier for the environment.
  19502. type: string
  19503. expandSecretReferences:
  19504. default: true
  19505. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  19506. type: boolean
  19507. includeSecretPath:
  19508. default: false
  19509. description: |-
  19510. IncludeSecretPath indicates whether the secret path should be included as a prefix
  19511. in the secret key. Secrets at the root path (/) are not prefixed.
  19512. type: boolean
  19513. organizationSlug:
  19514. description: |-
  19515. OrganizationSlug is the optional slug that identifies the organization that will be used
  19516. during authentication. Useful for sub-organization setups
  19517. type: string
  19518. projectSlug:
  19519. description: ProjectSlug is the required slug identifier for the project.
  19520. type: string
  19521. recursive:
  19522. default: false
  19523. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  19524. type: boolean
  19525. secretsPath:
  19526. default: /
  19527. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  19528. type: string
  19529. required:
  19530. - environmentSlug
  19531. - projectSlug
  19532. type: object
  19533. required:
  19534. - auth
  19535. - secretsScope
  19536. type: object
  19537. keepersecurity:
  19538. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  19539. properties:
  19540. authRef:
  19541. description: |-
  19542. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19543. In some instances, `key` is a required field.
  19544. properties:
  19545. key:
  19546. description: |-
  19547. A key in the referenced Secret.
  19548. Some instances of this field may be defaulted, in others it may be required.
  19549. maxLength: 253
  19550. minLength: 1
  19551. pattern: ^[-._a-zA-Z0-9]+$
  19552. type: string
  19553. name:
  19554. description: The name of the Secret resource being referred to.
  19555. maxLength: 253
  19556. minLength: 1
  19557. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19558. type: string
  19559. namespace:
  19560. description: |-
  19561. The namespace of the Secret resource being referred to.
  19562. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19563. maxLength: 63
  19564. minLength: 1
  19565. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19566. type: string
  19567. type: object
  19568. folderID:
  19569. type: string
  19570. getByTitleFallback:
  19571. type: boolean
  19572. required:
  19573. - authRef
  19574. type: object
  19575. kubernetes:
  19576. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  19577. properties:
  19578. auth:
  19579. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  19580. maxProperties: 1
  19581. minProperties: 1
  19582. properties:
  19583. cert:
  19584. description: has both clientCert and clientKey as secretKeySelector
  19585. properties:
  19586. clientCert:
  19587. description: |-
  19588. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19589. In some instances, `key` is a required field.
  19590. properties:
  19591. key:
  19592. description: |-
  19593. A key in the referenced Secret.
  19594. Some instances of this field may be defaulted, in others it may be required.
  19595. maxLength: 253
  19596. minLength: 1
  19597. pattern: ^[-._a-zA-Z0-9]+$
  19598. type: string
  19599. name:
  19600. description: The name of the Secret resource being referred to.
  19601. maxLength: 253
  19602. minLength: 1
  19603. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19604. type: string
  19605. namespace:
  19606. description: |-
  19607. The namespace of the Secret resource being referred to.
  19608. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19609. maxLength: 63
  19610. minLength: 1
  19611. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19612. type: string
  19613. type: object
  19614. clientKey:
  19615. description: |-
  19616. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19617. In some instances, `key` is a required field.
  19618. properties:
  19619. key:
  19620. description: |-
  19621. A key in the referenced Secret.
  19622. Some instances of this field may be defaulted, in others it may be required.
  19623. maxLength: 253
  19624. minLength: 1
  19625. pattern: ^[-._a-zA-Z0-9]+$
  19626. type: string
  19627. name:
  19628. description: The name of the Secret resource being referred to.
  19629. maxLength: 253
  19630. minLength: 1
  19631. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19632. type: string
  19633. namespace:
  19634. description: |-
  19635. The namespace of the Secret resource being referred to.
  19636. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19637. maxLength: 63
  19638. minLength: 1
  19639. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19640. type: string
  19641. type: object
  19642. required:
  19643. - clientCert
  19644. - clientKey
  19645. type: object
  19646. serviceAccount:
  19647. description: points to a service account that should be used for authentication
  19648. properties:
  19649. audiences:
  19650. description: |-
  19651. Audience specifies the `aud` claim for the service account token
  19652. Some providers automatically extend the audience field based on well-known annotations for workload
  19653. identity (e.g. IRSA or GCP Workload Identity)
  19654. items:
  19655. type: string
  19656. type: array
  19657. name:
  19658. description: The name of the ServiceAccount resource being referred to.
  19659. maxLength: 253
  19660. minLength: 1
  19661. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19662. type: string
  19663. namespace:
  19664. description: |-
  19665. Namespace of the resource being referred to.
  19666. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19667. maxLength: 63
  19668. minLength: 1
  19669. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19670. type: string
  19671. required:
  19672. - name
  19673. type: object
  19674. token:
  19675. description: use static token to authenticate with
  19676. properties:
  19677. bearerToken:
  19678. description: |-
  19679. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19680. In some instances, `key` is a required field.
  19681. properties:
  19682. key:
  19683. description: |-
  19684. A key in the referenced Secret.
  19685. Some instances of this field may be defaulted, in others it may be required.
  19686. maxLength: 253
  19687. minLength: 1
  19688. pattern: ^[-._a-zA-Z0-9]+$
  19689. type: string
  19690. name:
  19691. description: The name of the Secret resource being referred to.
  19692. maxLength: 253
  19693. minLength: 1
  19694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19695. type: string
  19696. namespace:
  19697. description: |-
  19698. The namespace of the Secret resource being referred to.
  19699. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19700. maxLength: 63
  19701. minLength: 1
  19702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19703. type: string
  19704. type: object
  19705. required:
  19706. - bearerToken
  19707. type: object
  19708. type: object
  19709. authRef:
  19710. description: A reference to a secret that contains the auth information.
  19711. properties:
  19712. key:
  19713. description: |-
  19714. A key in the referenced Secret.
  19715. Some instances of this field may be defaulted, in others it may be required.
  19716. maxLength: 253
  19717. minLength: 1
  19718. pattern: ^[-._a-zA-Z0-9]+$
  19719. type: string
  19720. name:
  19721. description: The name of the Secret resource being referred to.
  19722. maxLength: 253
  19723. minLength: 1
  19724. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19725. type: string
  19726. namespace:
  19727. description: |-
  19728. The namespace of the Secret resource being referred to.
  19729. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19730. maxLength: 63
  19731. minLength: 1
  19732. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19733. type: string
  19734. type: object
  19735. remoteNamespace:
  19736. default: default
  19737. description: Remote namespace to fetch the secrets from
  19738. maxLength: 63
  19739. minLength: 1
  19740. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19741. type: string
  19742. server:
  19743. description: configures the Kubernetes server Address.
  19744. properties:
  19745. caBundle:
  19746. description: CABundle is a base64-encoded CA certificate
  19747. format: byte
  19748. type: string
  19749. caProvider:
  19750. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  19751. properties:
  19752. key:
  19753. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19754. maxLength: 253
  19755. minLength: 1
  19756. pattern: ^[-._a-zA-Z0-9]+$
  19757. type: string
  19758. name:
  19759. description: The name of the object located at the provider type.
  19760. maxLength: 253
  19761. minLength: 1
  19762. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19763. type: string
  19764. namespace:
  19765. description: |-
  19766. The namespace the Provider type is in.
  19767. Can only be defined when used in a ClusterSecretStore.
  19768. maxLength: 63
  19769. minLength: 1
  19770. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19771. type: string
  19772. type:
  19773. description: The type of provider to use such as "Secret", or "ConfigMap".
  19774. enum:
  19775. - Secret
  19776. - ConfigMap
  19777. type: string
  19778. required:
  19779. - name
  19780. - type
  19781. type: object
  19782. url:
  19783. default: kubernetes.default
  19784. description: configures the Kubernetes server Address.
  19785. type: string
  19786. type: object
  19787. type: object
  19788. nebiusmysterybox:
  19789. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  19790. properties:
  19791. apiDomain:
  19792. description: NebiusMysterybox API endpoint
  19793. type: string
  19794. auth:
  19795. description: Auth defines parameters to authenticate in MysteryBox
  19796. properties:
  19797. serviceAccountCredsSecretRef:
  19798. description: |-
  19799. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  19800. document with service account credentials used to get an IAM token.
  19801. Expected JSON structure:
  19802. {
  19803. "subject-credentials": {
  19804. "alg": "RS256",
  19805. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  19806. "kid": "<public-key-id>",
  19807. "iss": "<issuer-service-account-id>",
  19808. "sub": "<subject-service-account-id>"
  19809. }
  19810. }
  19811. properties:
  19812. key:
  19813. description: |-
  19814. A key in the referenced Secret.
  19815. Some instances of this field may be defaulted, in others it may be required.
  19816. maxLength: 253
  19817. minLength: 1
  19818. pattern: ^[-._a-zA-Z0-9]+$
  19819. type: string
  19820. name:
  19821. description: The name of the Secret resource being referred to.
  19822. maxLength: 253
  19823. minLength: 1
  19824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19825. type: string
  19826. namespace:
  19827. description: |-
  19828. The namespace of the Secret resource being referred to.
  19829. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19830. maxLength: 63
  19831. minLength: 1
  19832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19833. type: string
  19834. type: object
  19835. tokenSecretRef:
  19836. description: Token authenticates with Nebius Mysterybox by presenting a token.
  19837. properties:
  19838. key:
  19839. description: |-
  19840. A key in the referenced Secret.
  19841. Some instances of this field may be defaulted, in others it may be required.
  19842. maxLength: 253
  19843. minLength: 1
  19844. pattern: ^[-._a-zA-Z0-9]+$
  19845. type: string
  19846. name:
  19847. description: The name of the Secret resource being referred to.
  19848. maxLength: 253
  19849. minLength: 1
  19850. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19851. type: string
  19852. namespace:
  19853. description: |-
  19854. The namespace of the Secret resource being referred to.
  19855. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19856. maxLength: 63
  19857. minLength: 1
  19858. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19859. type: string
  19860. type: object
  19861. workloadIdentity:
  19862. description: WorkloadIdentity defines configuration for workload identity authentication to Nebius IAM.
  19863. properties:
  19864. iamServiceAccountID:
  19865. description: |-
  19866. IAMServiceAccountID is the Nebius IAM service account identifier that the
  19867. federated Kubernetes service account should impersonate during token exchange.
  19868. example: serviceaccount-e00example
  19869. minLength: 1
  19870. pattern: ^serviceaccount-[a-z][a-z0-9]{2}
  19871. type: string
  19872. serviceAccountRef:
  19873. description: |-
  19874. ServiceAccountRef references a Kubernetes ServiceAccount used to request a
  19875. temporary JWT via the TokenRequest API. The JWT is then exchanged for a
  19876. Nebius IAM token using workload federation.
  19877. properties:
  19878. audiences:
  19879. description: |-
  19880. Audience specifies the `aud` claim for the service account token
  19881. Some providers automatically extend the audience field based on well-known annotations for workload
  19882. identity (e.g. IRSA or GCP Workload Identity)
  19883. items:
  19884. type: string
  19885. type: array
  19886. name:
  19887. description: The name of the ServiceAccount resource being referred to.
  19888. maxLength: 253
  19889. minLength: 1
  19890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19891. type: string
  19892. namespace:
  19893. description: |-
  19894. Namespace of the resource being referred to.
  19895. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19896. maxLength: 63
  19897. minLength: 1
  19898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19899. type: string
  19900. required:
  19901. - name
  19902. type: object
  19903. required:
  19904. - iamServiceAccountID
  19905. - serviceAccountRef
  19906. type: object
  19907. type: object
  19908. x-kubernetes-validations:
  19909. - message: exactly one of serviceAccountCredsSecretRef, tokenSecretRef, or workloadIdentity must be set
  19910. rule: '(has(self.serviceAccountCredsSecretRef) && has(self.serviceAccountCredsSecretRef.name) && size(self.serviceAccountCredsSecretRef.name) > 0 ? 1 : 0) + (has(self.tokenSecretRef) && has(self.tokenSecretRef.name) && size(self.tokenSecretRef.name) > 0 ? 1 : 0) + (has(self.workloadIdentity) ? 1 : 0) == 1'
  19911. caProvider:
  19912. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  19913. properties:
  19914. certSecretRef:
  19915. description: |-
  19916. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19917. In some instances, `key` is a required field.
  19918. properties:
  19919. key:
  19920. description: |-
  19921. A key in the referenced Secret.
  19922. Some instances of this field may be defaulted, in others it may be required.
  19923. maxLength: 253
  19924. minLength: 1
  19925. pattern: ^[-._a-zA-Z0-9]+$
  19926. type: string
  19927. name:
  19928. description: The name of the Secret resource being referred to.
  19929. maxLength: 253
  19930. minLength: 1
  19931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19932. type: string
  19933. namespace:
  19934. description: |-
  19935. The namespace of the Secret resource being referred to.
  19936. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19937. maxLength: 63
  19938. minLength: 1
  19939. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19940. type: string
  19941. type: object
  19942. type: object
  19943. required:
  19944. - apiDomain
  19945. - auth
  19946. type: object
  19947. ngrok:
  19948. description: Ngrok configures this store to sync secrets using the ngrok provider.
  19949. properties:
  19950. apiUrl:
  19951. default: https://api.ngrok.com
  19952. description: APIURL is the URL of the ngrok API.
  19953. type: string
  19954. auth:
  19955. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  19956. maxProperties: 1
  19957. minProperties: 1
  19958. properties:
  19959. apiKey:
  19960. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  19961. properties:
  19962. secretRef:
  19963. description: SecretRef is a reference to a secret containing the ngrok API key.
  19964. properties:
  19965. key:
  19966. description: |-
  19967. A key in the referenced Secret.
  19968. Some instances of this field may be defaulted, in others it may be required.
  19969. maxLength: 253
  19970. minLength: 1
  19971. pattern: ^[-._a-zA-Z0-9]+$
  19972. type: string
  19973. name:
  19974. description: The name of the Secret resource being referred to.
  19975. maxLength: 253
  19976. minLength: 1
  19977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19978. type: string
  19979. namespace:
  19980. description: |-
  19981. The namespace of the Secret resource being referred to.
  19982. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19983. maxLength: 63
  19984. minLength: 1
  19985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19986. type: string
  19987. type: object
  19988. type: object
  19989. type: object
  19990. vault:
  19991. description: Vault configures the ngrok vault to sync secrets with.
  19992. properties:
  19993. name:
  19994. description: Name is the name of the ngrok vault to sync secrets with.
  19995. type: string
  19996. required:
  19997. - name
  19998. type: object
  19999. required:
  20000. - auth
  20001. - vault
  20002. type: object
  20003. onboardbase:
  20004. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  20005. properties:
  20006. apiHost:
  20007. default: https://public.onboardbase.com/api/v1/
  20008. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  20009. type: string
  20010. auth:
  20011. description: Auth configures how the Operator authenticates with the Onboardbase API
  20012. properties:
  20013. apiKeyRef:
  20014. description: |-
  20015. OnboardbaseAPIKey is the APIKey generated by an admin account.
  20016. It is used to recognize and authorize access to a project and environment within onboardbase
  20017. properties:
  20018. key:
  20019. description: |-
  20020. A key in the referenced Secret.
  20021. Some instances of this field may be defaulted, in others it may be required.
  20022. maxLength: 253
  20023. minLength: 1
  20024. pattern: ^[-._a-zA-Z0-9]+$
  20025. type: string
  20026. name:
  20027. description: The name of the Secret resource being referred to.
  20028. maxLength: 253
  20029. minLength: 1
  20030. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20031. type: string
  20032. namespace:
  20033. description: |-
  20034. The namespace of the Secret resource being referred to.
  20035. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20036. maxLength: 63
  20037. minLength: 1
  20038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20039. type: string
  20040. type: object
  20041. passcodeRef:
  20042. description: OnboardbasePasscode is the passcode attached to the API Key
  20043. properties:
  20044. key:
  20045. description: |-
  20046. A key in the referenced Secret.
  20047. Some instances of this field may be defaulted, in others it may be required.
  20048. maxLength: 253
  20049. minLength: 1
  20050. pattern: ^[-._a-zA-Z0-9]+$
  20051. type: string
  20052. name:
  20053. description: The name of the Secret resource being referred to.
  20054. maxLength: 253
  20055. minLength: 1
  20056. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20057. type: string
  20058. namespace:
  20059. description: |-
  20060. The namespace of the Secret resource being referred to.
  20061. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20062. maxLength: 63
  20063. minLength: 1
  20064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20065. type: string
  20066. type: object
  20067. required:
  20068. - apiKeyRef
  20069. - passcodeRef
  20070. type: object
  20071. environment:
  20072. default: development
  20073. description: Environment is the name of an environmnent within a project to pull the secrets from
  20074. type: string
  20075. project:
  20076. default: development
  20077. description: Project is an onboardbase project that the secrets should be pulled from
  20078. type: string
  20079. required:
  20080. - apiHost
  20081. - auth
  20082. - environment
  20083. - project
  20084. type: object
  20085. onepassword:
  20086. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  20087. properties:
  20088. auth:
  20089. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  20090. properties:
  20091. secretRef:
  20092. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  20093. properties:
  20094. connectTokenSecretRef:
  20095. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  20096. properties:
  20097. key:
  20098. description: |-
  20099. A key in the referenced Secret.
  20100. Some instances of this field may be defaulted, in others it may be required.
  20101. maxLength: 253
  20102. minLength: 1
  20103. pattern: ^[-._a-zA-Z0-9]+$
  20104. type: string
  20105. name:
  20106. description: The name of the Secret resource being referred to.
  20107. maxLength: 253
  20108. minLength: 1
  20109. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20110. type: string
  20111. namespace:
  20112. description: |-
  20113. The namespace of the Secret resource being referred to.
  20114. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20115. maxLength: 63
  20116. minLength: 1
  20117. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20118. type: string
  20119. type: object
  20120. required:
  20121. - connectTokenSecretRef
  20122. type: object
  20123. required:
  20124. - secretRef
  20125. type: object
  20126. connectHost:
  20127. description: ConnectHost defines the OnePassword Connect Server to connect to
  20128. type: string
  20129. vaults:
  20130. additionalProperties:
  20131. type: integer
  20132. description: Vaults defines which OnePassword vaults to search in which order
  20133. type: object
  20134. required:
  20135. - auth
  20136. - connectHost
  20137. - vaults
  20138. type: object
  20139. onepasswordSDK:
  20140. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  20141. properties:
  20142. auth:
  20143. description: Auth defines the information necessary to authenticate against OnePassword API.
  20144. properties:
  20145. serviceAccountSecretRef:
  20146. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  20147. properties:
  20148. key:
  20149. description: |-
  20150. A key in the referenced Secret.
  20151. Some instances of this field may be defaulted, in others it may be required.
  20152. maxLength: 253
  20153. minLength: 1
  20154. pattern: ^[-._a-zA-Z0-9]+$
  20155. type: string
  20156. name:
  20157. description: The name of the Secret resource being referred to.
  20158. maxLength: 253
  20159. minLength: 1
  20160. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20161. type: string
  20162. namespace:
  20163. description: |-
  20164. The namespace of the Secret resource being referred to.
  20165. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20166. maxLength: 63
  20167. minLength: 1
  20168. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20169. type: string
  20170. type: object
  20171. required:
  20172. - serviceAccountSecretRef
  20173. type: object
  20174. cache:
  20175. description: |-
  20176. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  20177. When enabled, secrets are cached with the specified TTL.
  20178. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  20179. If omitted, caching is disabled (default).
  20180. cache: {} is a valid option to set.
  20181. properties:
  20182. maxSize:
  20183. default: 100
  20184. description: |-
  20185. MaxSize is the maximum number of secrets to cache.
  20186. When the cache is full, least-recently-used entries are evicted.
  20187. minimum: 1
  20188. type: integer
  20189. ttl:
  20190. default: 5m
  20191. description: |-
  20192. TTL is the time-to-live for cached secrets.
  20193. Format: duration string (e.g., "5m", "1h", "30s")
  20194. type: string
  20195. type: object
  20196. environment:
  20197. description: |-
  20198. Environment defines the 1Password Environment ID to read variables from.
  20199. Environments are read-only: PushSecret, DeleteSecret, and SecretExists return an error when set.
  20200. Mutually exclusive with Vault.
  20201. type: string
  20202. integrationInfo:
  20203. description: |-
  20204. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  20205. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  20206. properties:
  20207. name:
  20208. default: 1Password SDK
  20209. description: Name defaults to "1Password SDK".
  20210. type: string
  20211. version:
  20212. default: v1.0.0
  20213. description: Version defaults to "v1.0.0".
  20214. type: string
  20215. type: object
  20216. vault:
  20217. description: |-
  20218. Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  20219. Mutually exclusive with Environment.
  20220. type: string
  20221. required:
  20222. - auth
  20223. type: object
  20224. x-kubernetes-validations:
  20225. - message: at most one of the fields in [vault environment] may be set
  20226. rule: '[has(self.vault),has(self.environment)].filter(x,x==true).size() <= 1'
  20227. openBao:
  20228. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  20229. properties:
  20230. auth:
  20231. description: Auth configures how secret-manager authenticates with the OpenBao server.
  20232. properties:
  20233. appRole:
  20234. description: |-
  20235. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  20236. with the role and secret stored in a Kubernetes Secret resource.
  20237. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  20238. properties:
  20239. path:
  20240. default: approle
  20241. description: |-
  20242. Path where the App Role authentication backend is mounted
  20243. in OpenBao, e.g: "approle"
  20244. type: string
  20245. roleId:
  20246. description: |-
  20247. RoleID configured in the App Role authentication backend when setting
  20248. up the authentication backend in OpenBao.
  20249. minLength: 1
  20250. type: string
  20251. roleRef:
  20252. description: |-
  20253. Reference to a key in a Secret that contains the App Role ID used
  20254. to authenticate with OpenBao.
  20255. The `key` field must be specified and denotes which entry within the Secret
  20256. resource is used as the app role id.
  20257. properties:
  20258. key:
  20259. description: |-
  20260. A key in the referenced Secret.
  20261. Some instances of this field may be defaulted, in others it may be required.
  20262. maxLength: 253
  20263. minLength: 1
  20264. pattern: ^[-._a-zA-Z0-9]+$
  20265. type: string
  20266. name:
  20267. description: The name of the Secret resource being referred to.
  20268. maxLength: 253
  20269. minLength: 1
  20270. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20271. type: string
  20272. namespace:
  20273. description: |-
  20274. The namespace of the Secret resource being referred to.
  20275. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20276. maxLength: 63
  20277. minLength: 1
  20278. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20279. type: string
  20280. type: object
  20281. secretRef:
  20282. description: |-
  20283. Reference to a key in a Secret that contains the App Role secret used
  20284. to authenticate with OpenBao.
  20285. The `key` field must be specified and denotes which entry within the Secret
  20286. resource is used as the app role secret.
  20287. properties:
  20288. key:
  20289. description: |-
  20290. A key in the referenced Secret.
  20291. Some instances of this field may be defaulted, in others it may be required.
  20292. maxLength: 253
  20293. minLength: 1
  20294. pattern: ^[-._a-zA-Z0-9]+$
  20295. type: string
  20296. name:
  20297. description: The name of the Secret resource being referred to.
  20298. maxLength: 253
  20299. minLength: 1
  20300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20301. type: string
  20302. namespace:
  20303. description: |-
  20304. The namespace of the Secret resource being referred to.
  20305. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20306. maxLength: 63
  20307. minLength: 1
  20308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20309. type: string
  20310. type: object
  20311. required:
  20312. - path
  20313. - secretRef
  20314. type: object
  20315. x-kubernetes-validations:
  20316. - message: exactly one of the fields in [roleId roleRef] must be set
  20317. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  20318. kubernetes:
  20319. description: |-
  20320. Kubernetes authenticates with OpenBao by passing a ServiceAccount
  20321. token to the [Kubernetes auth mechanism].
  20322. [Kubernetes auth mechanism]: https://openbao.org/docs/auth/kubernetes/
  20323. properties:
  20324. path:
  20325. default: kubernetes
  20326. description: |-
  20327. Path where the Kubernetes authentication backend is mounted in OpenBao, e.g:
  20328. "kubernetes"
  20329. type: string
  20330. role:
  20331. description: |-
  20332. A required field containing the OpenBao Role to assume. A Role binds a
  20333. Kubernetes ServiceAccount with a set of OpenBao policies.
  20334. minLength: 1
  20335. type: string
  20336. secretRef:
  20337. description: |-
  20338. Optional secret field containing a Kubernetes ServiceAccount JWT used
  20339. for authenticating with OpenBao. If a name is specified without a key,
  20340. `token` is the default.
  20341. properties:
  20342. key:
  20343. description: |-
  20344. A key in the referenced Secret.
  20345. Some instances of this field may be defaulted, in others it may be required.
  20346. maxLength: 253
  20347. minLength: 1
  20348. pattern: ^[-._a-zA-Z0-9]+$
  20349. type: string
  20350. name:
  20351. description: The name of the Secret resource being referred to.
  20352. maxLength: 253
  20353. minLength: 1
  20354. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20355. type: string
  20356. namespace:
  20357. description: |-
  20358. The namespace of the Secret resource being referred to.
  20359. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20360. maxLength: 63
  20361. minLength: 1
  20362. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20363. type: string
  20364. type: object
  20365. serviceAccountRef:
  20366. description: |-
  20367. Optional service account field containing the name of a Kubernetes ServiceAccount.
  20368. If the service account is specified, a token will be requested from the Kubernetes
  20369. TokenRequest API for authenticating with OpenBao.
  20370. Any configured audiences will be passed to the TokenRequest as-is.
  20371. properties:
  20372. audiences:
  20373. description: |-
  20374. Audience specifies the `aud` claim for the service account token
  20375. Some providers automatically extend the audience field based on well-known annotations for workload
  20376. identity (e.g. IRSA or GCP Workload Identity)
  20377. items:
  20378. type: string
  20379. type: array
  20380. name:
  20381. description: The name of the ServiceAccount resource being referred to.
  20382. maxLength: 253
  20383. minLength: 1
  20384. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20385. type: string
  20386. namespace:
  20387. description: |-
  20388. Namespace of the resource being referred to.
  20389. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20390. maxLength: 63
  20391. minLength: 1
  20392. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20393. type: string
  20394. required:
  20395. - name
  20396. type: object
  20397. required:
  20398. - path
  20399. - role
  20400. type: object
  20401. x-kubernetes-validations:
  20402. - message: exactly one of the fields in [serviceAccountRef secretRef] must be set
  20403. rule: '[has(self.serviceAccountRef),has(self.secretRef)].filter(x,x==true).size() == 1'
  20404. namespace:
  20405. description: |-
  20406. Name of the [OpenBao Namespace] to authenticate to. This can be different
  20407. than the namespace your secret is in. Namespaces is a set of features
  20408. within OpenBao that allows OpenBao environments to support secure
  20409. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  20410. if set, or empty otherwise
  20411. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  20412. type: string
  20413. tokenSecretRef:
  20414. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  20415. properties:
  20416. key:
  20417. description: |-
  20418. A key in the referenced Secret.
  20419. Some instances of this field may be defaulted, in others it may be required.
  20420. maxLength: 253
  20421. minLength: 1
  20422. pattern: ^[-._a-zA-Z0-9]+$
  20423. type: string
  20424. name:
  20425. description: The name of the Secret resource being referred to.
  20426. maxLength: 253
  20427. minLength: 1
  20428. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20429. type: string
  20430. namespace:
  20431. description: |-
  20432. The namespace of the Secret resource being referred to.
  20433. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20434. maxLength: 63
  20435. minLength: 1
  20436. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20437. type: string
  20438. type: object
  20439. userPass:
  20440. description: UserPass authenticates with OpenBao by passing a username/password pair
  20441. properties:
  20442. path:
  20443. default: userpass
  20444. description: |-
  20445. Path where the UserPassword authentication backend is mounted
  20446. in OpenBao, e.g: "userpass"
  20447. type: string
  20448. secretRef:
  20449. description: |-
  20450. SecretRef to a key in a Secret resource containing password for the user
  20451. used to authenticate with OpenBao using the [UserPass authentication
  20452. method]
  20453. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  20454. properties:
  20455. key:
  20456. description: |-
  20457. A key in the referenced Secret.
  20458. Some instances of this field may be defaulted, in others it may be required.
  20459. maxLength: 253
  20460. minLength: 1
  20461. pattern: ^[-._a-zA-Z0-9]+$
  20462. type: string
  20463. name:
  20464. description: The name of the Secret resource being referred to.
  20465. maxLength: 253
  20466. minLength: 1
  20467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20468. type: string
  20469. namespace:
  20470. description: |-
  20471. The namespace of the Secret resource being referred to.
  20472. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20473. maxLength: 63
  20474. minLength: 1
  20475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20476. type: string
  20477. type: object
  20478. username:
  20479. description: |-
  20480. Username is a username used to authenticate using the [UserPass
  20481. authentication method]
  20482. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  20483. type: string
  20484. required:
  20485. - path
  20486. - username
  20487. type: object
  20488. type: object
  20489. x-kubernetes-validations:
  20490. - message: exactly one of the fields in [appRole tokenSecretRef userPass kubernetes] must be set
  20491. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass),has(self.kubernetes)].filter(x,x==true).size() == 1'
  20492. caBundle:
  20493. description: |-
  20494. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  20495. this and `caProvider` are not set the system root certificates are used
  20496. to validate the TLS connection.
  20497. format: byte
  20498. type: string
  20499. caProvider:
  20500. description: |-
  20501. The provider for the CA bundle to use to validate OpenBao server
  20502. certificate. If this and `caBundle` are not set the system root
  20503. certificates are used to validate the TLS connection.
  20504. properties:
  20505. key:
  20506. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20507. maxLength: 253
  20508. minLength: 1
  20509. pattern: ^[-._a-zA-Z0-9]+$
  20510. type: string
  20511. name:
  20512. description: The name of the object located at the provider type.
  20513. maxLength: 253
  20514. minLength: 1
  20515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20516. type: string
  20517. namespace:
  20518. description: |-
  20519. The namespace the Provider type is in.
  20520. Can only be defined when used in a ClusterSecretStore.
  20521. maxLength: 63
  20522. minLength: 1
  20523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20524. type: string
  20525. type:
  20526. description: The type of provider to use such as "Secret", or "ConfigMap".
  20527. enum:
  20528. - Secret
  20529. - ConfigMap
  20530. type: string
  20531. required:
  20532. - name
  20533. - type
  20534. type: object
  20535. namespace:
  20536. description: |-
  20537. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  20538. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  20539. e.g: "ns1".
  20540. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  20541. type: string
  20542. path:
  20543. description: |-
  20544. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  20545. "secret". The v2 KV secret engine version specific "/data" path suffix
  20546. for fetching secrets from OpenBao is optional and will be appended
  20547. if not present in specified path.
  20548. type: string
  20549. server:
  20550. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  20551. type: string
  20552. version:
  20553. default: v2
  20554. description: |-
  20555. Version is the OpenBao KV secret engine version. This can be either "v1" or
  20556. "v2". Version defaults to "v2".
  20557. enum:
  20558. - v1
  20559. - v2
  20560. type: string
  20561. required:
  20562. - server
  20563. type: object
  20564. x-kubernetes-validations:
  20565. - message: at most one of the fields in [caBundle caProvider] may be set
  20566. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  20567. oracle:
  20568. description: Oracle configures this store to sync secrets using Oracle Vault provider
  20569. properties:
  20570. auth:
  20571. description: |-
  20572. Auth configures how secret-manager authenticates with the Oracle Vault.
  20573. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  20574. properties:
  20575. secretRef:
  20576. description: SecretRef to pass through sensitive information.
  20577. properties:
  20578. fingerprint:
  20579. description: Fingerprint is the fingerprint of the API private key.
  20580. properties:
  20581. key:
  20582. description: |-
  20583. A key in the referenced Secret.
  20584. Some instances of this field may be defaulted, in others it may be required.
  20585. maxLength: 253
  20586. minLength: 1
  20587. pattern: ^[-._a-zA-Z0-9]+$
  20588. type: string
  20589. name:
  20590. description: The name of the Secret resource being referred to.
  20591. maxLength: 253
  20592. minLength: 1
  20593. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20594. type: string
  20595. namespace:
  20596. description: |-
  20597. The namespace of the Secret resource being referred to.
  20598. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20599. maxLength: 63
  20600. minLength: 1
  20601. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20602. type: string
  20603. type: object
  20604. privatekey:
  20605. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  20606. properties:
  20607. key:
  20608. description: |-
  20609. A key in the referenced Secret.
  20610. Some instances of this field may be defaulted, in others it may be required.
  20611. maxLength: 253
  20612. minLength: 1
  20613. pattern: ^[-._a-zA-Z0-9]+$
  20614. type: string
  20615. name:
  20616. description: The name of the Secret resource being referred to.
  20617. maxLength: 253
  20618. minLength: 1
  20619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20620. type: string
  20621. namespace:
  20622. description: |-
  20623. The namespace of the Secret resource being referred to.
  20624. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20625. maxLength: 63
  20626. minLength: 1
  20627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20628. type: string
  20629. type: object
  20630. required:
  20631. - fingerprint
  20632. - privatekey
  20633. type: object
  20634. tenancy:
  20635. description: Tenancy is the tenancy OCID where user is located.
  20636. type: string
  20637. user:
  20638. description: User is an access OCID specific to the account.
  20639. type: string
  20640. required:
  20641. - secretRef
  20642. - tenancy
  20643. - user
  20644. type: object
  20645. compartment:
  20646. description: |-
  20647. Compartment is the vault compartment OCID.
  20648. Required for PushSecret
  20649. type: string
  20650. encryptionKey:
  20651. description: |-
  20652. EncryptionKey is the OCID of the encryption key within the vault.
  20653. Required for PushSecret
  20654. type: string
  20655. principalType:
  20656. description: |-
  20657. The type of principal to use for authentication. If left blank, the Auth struct will
  20658. determine the principal type. This optional field must be specified if using
  20659. workload identity.
  20660. enum:
  20661. - ""
  20662. - UserPrincipal
  20663. - InstancePrincipal
  20664. - Workload
  20665. type: string
  20666. region:
  20667. description: Region is the region where vault is located.
  20668. type: string
  20669. serviceAccountRef:
  20670. description: |-
  20671. ServiceAccountRef specified the service account
  20672. that should be used when authenticating with WorkloadIdentity.
  20673. properties:
  20674. audiences:
  20675. description: |-
  20676. Audience specifies the `aud` claim for the service account token
  20677. Some providers automatically extend the audience field based on well-known annotations for workload
  20678. identity (e.g. IRSA or GCP Workload Identity)
  20679. items:
  20680. type: string
  20681. type: array
  20682. name:
  20683. description: The name of the ServiceAccount resource being referred to.
  20684. maxLength: 253
  20685. minLength: 1
  20686. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20687. type: string
  20688. namespace:
  20689. description: |-
  20690. Namespace of the resource being referred to.
  20691. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20692. maxLength: 63
  20693. minLength: 1
  20694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20695. type: string
  20696. required:
  20697. - name
  20698. type: object
  20699. vault:
  20700. description: Vault is the vault's OCID of the specific vault where secret is located.
  20701. type: string
  20702. required:
  20703. - region
  20704. - vault
  20705. type: object
  20706. ovh:
  20707. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  20708. properties:
  20709. auth:
  20710. description: Authentication method (mtls or token).
  20711. properties:
  20712. mtls:
  20713. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  20714. properties:
  20715. caBundle:
  20716. format: byte
  20717. type: string
  20718. caProvider:
  20719. description: |-
  20720. CAProvider provides a custom certificate authority for accessing the provider's store.
  20721. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  20722. properties:
  20723. key:
  20724. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20725. maxLength: 253
  20726. minLength: 1
  20727. pattern: ^[-._a-zA-Z0-9]+$
  20728. type: string
  20729. name:
  20730. description: The name of the object located at the provider type.
  20731. maxLength: 253
  20732. minLength: 1
  20733. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20734. type: string
  20735. namespace:
  20736. description: |-
  20737. The namespace the Provider type is in.
  20738. Can only be defined when used in a ClusterSecretStore.
  20739. maxLength: 63
  20740. minLength: 1
  20741. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20742. type: string
  20743. type:
  20744. description: The type of provider to use such as "Secret", or "ConfigMap".
  20745. enum:
  20746. - Secret
  20747. - ConfigMap
  20748. type: string
  20749. required:
  20750. - name
  20751. - type
  20752. type: object
  20753. certSecretRef:
  20754. description: |-
  20755. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20756. In some instances, `key` is a required field.
  20757. properties:
  20758. key:
  20759. description: |-
  20760. A key in the referenced Secret.
  20761. Some instances of this field may be defaulted, in others it may be required.
  20762. maxLength: 253
  20763. minLength: 1
  20764. pattern: ^[-._a-zA-Z0-9]+$
  20765. type: string
  20766. name:
  20767. description: The name of the Secret resource being referred to.
  20768. maxLength: 253
  20769. minLength: 1
  20770. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20771. type: string
  20772. namespace:
  20773. description: |-
  20774. The namespace of the Secret resource being referred to.
  20775. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20776. maxLength: 63
  20777. minLength: 1
  20778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20779. type: string
  20780. type: object
  20781. keySecretRef:
  20782. description: |-
  20783. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20784. In some instances, `key` is a required field.
  20785. properties:
  20786. key:
  20787. description: |-
  20788. A key in the referenced Secret.
  20789. Some instances of this field may be defaulted, in others it may be required.
  20790. maxLength: 253
  20791. minLength: 1
  20792. pattern: ^[-._a-zA-Z0-9]+$
  20793. type: string
  20794. name:
  20795. description: The name of the Secret resource being referred to.
  20796. maxLength: 253
  20797. minLength: 1
  20798. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20799. type: string
  20800. namespace:
  20801. description: |-
  20802. The namespace of the Secret resource being referred to.
  20803. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20804. maxLength: 63
  20805. minLength: 1
  20806. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20807. type: string
  20808. type: object
  20809. required:
  20810. - certSecretRef
  20811. - keySecretRef
  20812. type: object
  20813. token:
  20814. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  20815. properties:
  20816. tokenSecretRef:
  20817. description: |-
  20818. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20819. In some instances, `key` is a required field.
  20820. properties:
  20821. key:
  20822. description: |-
  20823. A key in the referenced Secret.
  20824. Some instances of this field may be defaulted, in others it may be required.
  20825. maxLength: 253
  20826. minLength: 1
  20827. pattern: ^[-._a-zA-Z0-9]+$
  20828. type: string
  20829. name:
  20830. description: The name of the Secret resource being referred to.
  20831. maxLength: 253
  20832. minLength: 1
  20833. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20834. type: string
  20835. namespace:
  20836. description: |-
  20837. The namespace of the Secret resource being referred to.
  20838. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20839. maxLength: 63
  20840. minLength: 1
  20841. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20842. type: string
  20843. type: object
  20844. required:
  20845. - tokenSecretRef
  20846. type: object
  20847. type: object
  20848. casRequired:
  20849. description: 'Enables or disables check-and-set (CAS) (default: false).'
  20850. type: boolean
  20851. okmsTimeout:
  20852. default: 30
  20853. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  20854. format: int32
  20855. minimum: 1
  20856. type: integer
  20857. okmsid:
  20858. description: specifies the OKMS ID.
  20859. type: string
  20860. server:
  20861. description: specifies the OKMS server endpoint.
  20862. type: string
  20863. required:
  20864. - auth
  20865. - okmsid
  20866. - server
  20867. type: object
  20868. passbolt:
  20869. description: |-
  20870. PassboltProvider provides access to Passbolt secrets manager.
  20871. See: https://www.passbolt.com.
  20872. properties:
  20873. auth:
  20874. description: Auth defines the information necessary to authenticate against Passbolt Server
  20875. properties:
  20876. passwordSecretRef:
  20877. description: |-
  20878. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20879. In some instances, `key` is a required field.
  20880. properties:
  20881. key:
  20882. description: |-
  20883. A key in the referenced Secret.
  20884. Some instances of this field may be defaulted, in others it may be required.
  20885. maxLength: 253
  20886. minLength: 1
  20887. pattern: ^[-._a-zA-Z0-9]+$
  20888. type: string
  20889. name:
  20890. description: The name of the Secret resource being referred to.
  20891. maxLength: 253
  20892. minLength: 1
  20893. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20894. type: string
  20895. namespace:
  20896. description: |-
  20897. The namespace of the Secret resource being referred to.
  20898. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20899. maxLength: 63
  20900. minLength: 1
  20901. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20902. type: string
  20903. type: object
  20904. privateKeySecretRef:
  20905. description: |-
  20906. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20907. In some instances, `key` is a required field.
  20908. properties:
  20909. key:
  20910. description: |-
  20911. A key in the referenced Secret.
  20912. Some instances of this field may be defaulted, in others it may be required.
  20913. maxLength: 253
  20914. minLength: 1
  20915. pattern: ^[-._a-zA-Z0-9]+$
  20916. type: string
  20917. name:
  20918. description: The name of the Secret resource being referred to.
  20919. maxLength: 253
  20920. minLength: 1
  20921. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20922. type: string
  20923. namespace:
  20924. description: |-
  20925. The namespace of the Secret resource being referred to.
  20926. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20927. maxLength: 63
  20928. minLength: 1
  20929. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20930. type: string
  20931. type: object
  20932. required:
  20933. - passwordSecretRef
  20934. - privateKeySecretRef
  20935. type: object
  20936. caBundle:
  20937. description: |-
  20938. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  20939. if the Host URL is using HTTPS protocol. If not set the system root certificates
  20940. are used to validate the TLS connection.
  20941. format: byte
  20942. type: string
  20943. caProvider:
  20944. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  20945. properties:
  20946. key:
  20947. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20948. maxLength: 253
  20949. minLength: 1
  20950. pattern: ^[-._a-zA-Z0-9]+$
  20951. type: string
  20952. name:
  20953. description: The name of the object located at the provider type.
  20954. maxLength: 253
  20955. minLength: 1
  20956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20957. type: string
  20958. namespace:
  20959. description: |-
  20960. The namespace the Provider type is in.
  20961. Can only be defined when used in a ClusterSecretStore.
  20962. maxLength: 63
  20963. minLength: 1
  20964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20965. type: string
  20966. type:
  20967. description: The type of provider to use such as "Secret", or "ConfigMap".
  20968. enum:
  20969. - Secret
  20970. - ConfigMap
  20971. type: string
  20972. required:
  20973. - name
  20974. - type
  20975. type: object
  20976. host:
  20977. description: Host defines the Passbolt Server to connect to
  20978. type: string
  20979. required:
  20980. - auth
  20981. - host
  20982. type: object
  20983. passworddepot:
  20984. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  20985. properties:
  20986. auth:
  20987. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  20988. properties:
  20989. secretRef:
  20990. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  20991. properties:
  20992. credentials:
  20993. description: Username / Password is used for authentication.
  20994. properties:
  20995. key:
  20996. description: |-
  20997. A key in the referenced Secret.
  20998. Some instances of this field may be defaulted, in others it may be required.
  20999. maxLength: 253
  21000. minLength: 1
  21001. pattern: ^[-._a-zA-Z0-9]+$
  21002. type: string
  21003. name:
  21004. description: The name of the Secret resource being referred to.
  21005. maxLength: 253
  21006. minLength: 1
  21007. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21008. type: string
  21009. namespace:
  21010. description: |-
  21011. The namespace of the Secret resource being referred to.
  21012. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21013. maxLength: 63
  21014. minLength: 1
  21015. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21016. type: string
  21017. type: object
  21018. type: object
  21019. required:
  21020. - secretRef
  21021. type: object
  21022. database:
  21023. description: Database to use as source
  21024. type: string
  21025. host:
  21026. description: URL configures the Password Depot instance URL.
  21027. type: string
  21028. required:
  21029. - auth
  21030. - database
  21031. - host
  21032. type: object
  21033. previder:
  21034. description: Previder configures this store to sync secrets using the Previder provider
  21035. properties:
  21036. auth:
  21037. description: PreviderAuth contains a secretRef for credentials.
  21038. properties:
  21039. secretRef:
  21040. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  21041. properties:
  21042. accessToken:
  21043. description: The AccessToken is used for authentication
  21044. properties:
  21045. key:
  21046. description: |-
  21047. A key in the referenced Secret.
  21048. Some instances of this field may be defaulted, in others it may be required.
  21049. maxLength: 253
  21050. minLength: 1
  21051. pattern: ^[-._a-zA-Z0-9]+$
  21052. type: string
  21053. name:
  21054. description: The name of the Secret resource being referred to.
  21055. maxLength: 253
  21056. minLength: 1
  21057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21058. type: string
  21059. namespace:
  21060. description: |-
  21061. The namespace of the Secret resource being referred to.
  21062. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21063. maxLength: 63
  21064. minLength: 1
  21065. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21066. type: string
  21067. type: object
  21068. required:
  21069. - accessToken
  21070. type: object
  21071. type: object
  21072. baseUri:
  21073. type: string
  21074. required:
  21075. - auth
  21076. type: object
  21077. pulumi:
  21078. description: Pulumi configures this store to sync secrets using the Pulumi provider
  21079. properties:
  21080. accessToken:
  21081. description: |-
  21082. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  21083. Deprecated: Use auth.accessToken instead.
  21084. properties:
  21085. secretRef:
  21086. description: SecretRef is a reference to a secret containing the Pulumi API token.
  21087. properties:
  21088. key:
  21089. description: |-
  21090. A key in the referenced Secret.
  21091. Some instances of this field may be defaulted, in others it may be required.
  21092. maxLength: 253
  21093. minLength: 1
  21094. pattern: ^[-._a-zA-Z0-9]+$
  21095. type: string
  21096. name:
  21097. description: The name of the Secret resource being referred to.
  21098. maxLength: 253
  21099. minLength: 1
  21100. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21101. type: string
  21102. namespace:
  21103. description: |-
  21104. The namespace of the Secret resource being referred to.
  21105. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21106. maxLength: 63
  21107. minLength: 1
  21108. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21109. type: string
  21110. type: object
  21111. type: object
  21112. apiUrl:
  21113. default: https://api.pulumi.com/api/esc
  21114. description: APIURL is the URL of the Pulumi API.
  21115. type: string
  21116. auth:
  21117. description: |-
  21118. Auth configures how the Operator authenticates with the Pulumi API.
  21119. Either auth or the deprecated accessToken field must be specified.
  21120. properties:
  21121. accessToken:
  21122. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  21123. properties:
  21124. secretRef:
  21125. description: SecretRef is a reference to a secret containing the Pulumi API token.
  21126. properties:
  21127. key:
  21128. description: |-
  21129. A key in the referenced Secret.
  21130. Some instances of this field may be defaulted, in others it may be required.
  21131. maxLength: 253
  21132. minLength: 1
  21133. pattern: ^[-._a-zA-Z0-9]+$
  21134. type: string
  21135. name:
  21136. description: The name of the Secret resource being referred to.
  21137. maxLength: 253
  21138. minLength: 1
  21139. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21140. type: string
  21141. namespace:
  21142. description: |-
  21143. The namespace of the Secret resource being referred to.
  21144. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21145. maxLength: 63
  21146. minLength: 1
  21147. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21148. type: string
  21149. type: object
  21150. type: object
  21151. oidcConfig:
  21152. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  21153. properties:
  21154. expirationSeconds:
  21155. default: 600
  21156. description: |-
  21157. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  21158. Defaults to 10 minutes.
  21159. format: int64
  21160. minimum: 600
  21161. type: integer
  21162. organization:
  21163. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  21164. type: string
  21165. serviceAccountRef:
  21166. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  21167. properties:
  21168. audiences:
  21169. description: |-
  21170. Audience specifies the `aud` claim for the service account token
  21171. Some providers automatically extend the audience field based on well-known annotations for workload
  21172. identity (e.g. IRSA or GCP Workload Identity)
  21173. items:
  21174. type: string
  21175. type: array
  21176. name:
  21177. description: The name of the ServiceAccount resource being referred to.
  21178. maxLength: 253
  21179. minLength: 1
  21180. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21181. type: string
  21182. namespace:
  21183. description: |-
  21184. Namespace of the resource being referred to.
  21185. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21186. maxLength: 63
  21187. minLength: 1
  21188. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21189. type: string
  21190. required:
  21191. - name
  21192. type: object
  21193. required:
  21194. - organization
  21195. - serviceAccountRef
  21196. type: object
  21197. type: object
  21198. x-kubernetes-validations:
  21199. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  21200. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  21201. environment:
  21202. description: |-
  21203. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  21204. dynamically retrieved values from supported providers including all major clouds,
  21205. and other Pulumi ESC environments.
  21206. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  21207. type: string
  21208. organization:
  21209. description: |-
  21210. Organization are a space to collaborate on shared projects and stacks.
  21211. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  21212. type: string
  21213. project:
  21214. description: Project is the name of the Pulumi ESC project the environment belongs to.
  21215. type: string
  21216. required:
  21217. - environment
  21218. - organization
  21219. - project
  21220. type: object
  21221. x-kubernetes-validations:
  21222. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  21223. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  21224. scaleway:
  21225. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  21226. properties:
  21227. accessKey:
  21228. description: AccessKey is the non-secret part of the api key.
  21229. properties:
  21230. secretRef:
  21231. description: SecretRef references a key in a secret that will be used as value.
  21232. properties:
  21233. key:
  21234. description: |-
  21235. A key in the referenced Secret.
  21236. Some instances of this field may be defaulted, in others it may be required.
  21237. maxLength: 253
  21238. minLength: 1
  21239. pattern: ^[-._a-zA-Z0-9]+$
  21240. type: string
  21241. name:
  21242. description: The name of the Secret resource being referred to.
  21243. maxLength: 253
  21244. minLength: 1
  21245. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21246. type: string
  21247. namespace:
  21248. description: |-
  21249. The namespace of the Secret resource being referred to.
  21250. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21251. maxLength: 63
  21252. minLength: 1
  21253. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21254. type: string
  21255. type: object
  21256. value:
  21257. description: Value can be specified directly to set a value without using a secret.
  21258. type: string
  21259. type: object
  21260. apiUrl:
  21261. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  21262. type: string
  21263. projectId:
  21264. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  21265. type: string
  21266. region:
  21267. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  21268. type: string
  21269. secretKey:
  21270. description: SecretKey is the non-secret part of the api key.
  21271. properties:
  21272. secretRef:
  21273. description: SecretRef references a key in a secret that will be used as value.
  21274. properties:
  21275. key:
  21276. description: |-
  21277. A key in the referenced Secret.
  21278. Some instances of this field may be defaulted, in others it may be required.
  21279. maxLength: 253
  21280. minLength: 1
  21281. pattern: ^[-._a-zA-Z0-9]+$
  21282. type: string
  21283. name:
  21284. description: The name of the Secret resource being referred to.
  21285. maxLength: 253
  21286. minLength: 1
  21287. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21288. type: string
  21289. namespace:
  21290. description: |-
  21291. The namespace of the Secret resource being referred to.
  21292. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21293. maxLength: 63
  21294. minLength: 1
  21295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21296. type: string
  21297. type: object
  21298. value:
  21299. description: Value can be specified directly to set a value without using a secret.
  21300. type: string
  21301. type: object
  21302. required:
  21303. - accessKey
  21304. - projectId
  21305. - region
  21306. - secretKey
  21307. type: object
  21308. secretserver:
  21309. description: |-
  21310. SecretServer configures this store to sync secrets using SecretServer provider
  21311. https://docs.delinea.com/online-help/secret-server/start.htm
  21312. properties:
  21313. caBundle:
  21314. description: |-
  21315. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  21316. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  21317. are used to validate the TLS connection.
  21318. format: byte
  21319. type: string
  21320. caProvider:
  21321. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  21322. properties:
  21323. key:
  21324. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  21325. maxLength: 253
  21326. minLength: 1
  21327. pattern: ^[-._a-zA-Z0-9]+$
  21328. type: string
  21329. name:
  21330. description: The name of the object located at the provider type.
  21331. maxLength: 253
  21332. minLength: 1
  21333. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21334. type: string
  21335. namespace:
  21336. description: |-
  21337. The namespace the Provider type is in.
  21338. Can only be defined when used in a ClusterSecretStore.
  21339. maxLength: 63
  21340. minLength: 1
  21341. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21342. type: string
  21343. type:
  21344. description: The type of provider to use such as "Secret", or "ConfigMap".
  21345. enum:
  21346. - Secret
  21347. - ConfigMap
  21348. type: string
  21349. required:
  21350. - name
  21351. - type
  21352. type: object
  21353. disableSiteIDValidation:
  21354. description: |-
  21355. DisableSiteIDValidation permits a missing site ID for new secrets.
  21356. The provider sends 0 if no site ID is set.
  21357. type: boolean
  21358. domain:
  21359. description: Domain is the secret server domain.
  21360. type: string
  21361. password:
  21362. description: |-
  21363. Password is the secret server account password.
  21364. Required unless Token is set.
  21365. properties:
  21366. secretRef:
  21367. description: SecretRef references a key in a secret that will be used as value.
  21368. properties:
  21369. key:
  21370. description: |-
  21371. A key in the referenced Secret.
  21372. Some instances of this field may be defaulted, in others it may be required.
  21373. maxLength: 253
  21374. minLength: 1
  21375. pattern: ^[-._a-zA-Z0-9]+$
  21376. type: string
  21377. name:
  21378. description: The name of the Secret resource being referred to.
  21379. maxLength: 253
  21380. minLength: 1
  21381. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21382. type: string
  21383. namespace:
  21384. description: |-
  21385. The namespace of the Secret resource being referred to.
  21386. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21387. maxLength: 63
  21388. minLength: 1
  21389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21390. type: string
  21391. type: object
  21392. value:
  21393. description: Value can be specified directly to set a value without using a secret.
  21394. minLength: 1
  21395. type: string
  21396. type: object
  21397. x-kubernetes-validations:
  21398. - message: exactly one of value or secretRef must be set
  21399. rule: has(self.value) != has(self.secretRef)
  21400. serverURL:
  21401. description: |-
  21402. ServerURL
  21403. URL to your secret server installation
  21404. type: string
  21405. siteId:
  21406. description: |-
  21407. SiteID is the ID of the Secret Server site for new secrets.
  21408. PushSecret metadata can override this value for one secret.
  21409. The provider uses 1 if this field is not set.
  21410. minimum: 1
  21411. type: integer
  21412. token:
  21413. description: |-
  21414. Token is an access token used to authenticate to the secret server,
  21415. as an alternative to Username and Password. When set, Username and
  21416. Password are not required and are ignored.
  21417. properties:
  21418. secretRef:
  21419. description: SecretRef references a key in a secret that will be used as value.
  21420. properties:
  21421. key:
  21422. description: |-
  21423. A key in the referenced Secret.
  21424. Some instances of this field may be defaulted, in others it may be required.
  21425. maxLength: 253
  21426. minLength: 1
  21427. pattern: ^[-._a-zA-Z0-9]+$
  21428. type: string
  21429. name:
  21430. description: The name of the Secret resource being referred to.
  21431. maxLength: 253
  21432. minLength: 1
  21433. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21434. type: string
  21435. namespace:
  21436. description: |-
  21437. The namespace of the Secret resource being referred to.
  21438. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21439. maxLength: 63
  21440. minLength: 1
  21441. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21442. type: string
  21443. type: object
  21444. value:
  21445. description: Value can be specified directly to set a value without using a secret.
  21446. minLength: 1
  21447. type: string
  21448. type: object
  21449. x-kubernetes-validations:
  21450. - message: exactly one of value or secretRef must be set
  21451. rule: has(self.value) != has(self.secretRef)
  21452. username:
  21453. description: |-
  21454. Username is the secret server account username.
  21455. Required unless Token is set.
  21456. properties:
  21457. secretRef:
  21458. description: SecretRef references a key in a secret that will be used as value.
  21459. properties:
  21460. key:
  21461. description: |-
  21462. A key in the referenced Secret.
  21463. Some instances of this field may be defaulted, in others it may be required.
  21464. maxLength: 253
  21465. minLength: 1
  21466. pattern: ^[-._a-zA-Z0-9]+$
  21467. type: string
  21468. name:
  21469. description: The name of the Secret resource being referred to.
  21470. maxLength: 253
  21471. minLength: 1
  21472. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21473. type: string
  21474. namespace:
  21475. description: |-
  21476. The namespace of the Secret resource being referred to.
  21477. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21478. maxLength: 63
  21479. minLength: 1
  21480. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21481. type: string
  21482. type: object
  21483. value:
  21484. description: Value can be specified directly to set a value without using a secret.
  21485. minLength: 1
  21486. type: string
  21487. type: object
  21488. x-kubernetes-validations:
  21489. - message: exactly one of value or secretRef must be set
  21490. rule: has(self.value) != has(self.secretRef)
  21491. required:
  21492. - serverURL
  21493. type: object
  21494. x-kubernetes-validations:
  21495. - message: either token, or both username and password, must be set
  21496. rule: has(self.token) || (has(self.username) && has(self.password))
  21497. senhasegura:
  21498. description: Senhasegura configures this store to sync secrets using senhasegura provider
  21499. properties:
  21500. auth:
  21501. description: Auth defines parameters to authenticate in senhasegura
  21502. properties:
  21503. clientId:
  21504. type: string
  21505. clientSecretSecretRef:
  21506. description: |-
  21507. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  21508. In some instances, `key` is a required field.
  21509. properties:
  21510. key:
  21511. description: |-
  21512. A key in the referenced Secret.
  21513. Some instances of this field may be defaulted, in others it may be required.
  21514. maxLength: 253
  21515. minLength: 1
  21516. pattern: ^[-._a-zA-Z0-9]+$
  21517. type: string
  21518. name:
  21519. description: The name of the Secret resource being referred to.
  21520. maxLength: 253
  21521. minLength: 1
  21522. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21523. type: string
  21524. namespace:
  21525. description: |-
  21526. The namespace of the Secret resource being referred to.
  21527. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21528. maxLength: 63
  21529. minLength: 1
  21530. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21531. type: string
  21532. type: object
  21533. required:
  21534. - clientId
  21535. - clientSecretSecretRef
  21536. type: object
  21537. ignoreSslCertificate:
  21538. default: false
  21539. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  21540. type: boolean
  21541. module:
  21542. description: Module defines which senhasegura module should be used to get secrets
  21543. type: string
  21544. url:
  21545. description: URL of senhasegura
  21546. type: string
  21547. required:
  21548. - auth
  21549. - module
  21550. - url
  21551. type: object
  21552. vault:
  21553. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  21554. properties:
  21555. auth:
  21556. description: Auth configures how secret-manager authenticates with the Vault server.
  21557. properties:
  21558. appRole:
  21559. description: |-
  21560. AppRole authenticates with Vault using the App Role auth mechanism,
  21561. with the role and secret stored in a Kubernetes Secret resource.
  21562. properties:
  21563. path:
  21564. default: approle
  21565. description: |-
  21566. Path where the App Role authentication backend is mounted
  21567. in Vault, e.g: "approle"
  21568. type: string
  21569. roleId:
  21570. description: |-
  21571. RoleID configured in the App Role authentication backend when setting
  21572. up the authentication backend in Vault.
  21573. type: string
  21574. roleRef:
  21575. description: |-
  21576. Reference to a key in a Secret that contains the App Role ID used
  21577. to authenticate with Vault.
  21578. The `key` field must be specified and denotes which entry within the Secret
  21579. resource is used as the app role id.
  21580. properties:
  21581. key:
  21582. description: |-
  21583. A key in the referenced Secret.
  21584. Some instances of this field may be defaulted, in others it may be required.
  21585. maxLength: 253
  21586. minLength: 1
  21587. pattern: ^[-._a-zA-Z0-9]+$
  21588. type: string
  21589. name:
  21590. description: The name of the Secret resource being referred to.
  21591. maxLength: 253
  21592. minLength: 1
  21593. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21594. type: string
  21595. namespace:
  21596. description: |-
  21597. The namespace of the Secret resource being referred to.
  21598. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21599. maxLength: 63
  21600. minLength: 1
  21601. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21602. type: string
  21603. type: object
  21604. secretRef:
  21605. description: |-
  21606. Reference to a key in a Secret that contains the App Role secret used
  21607. to authenticate with Vault.
  21608. The `key` field must be specified and denotes which entry within the Secret
  21609. resource is used as the app role secret.
  21610. properties:
  21611. key:
  21612. description: |-
  21613. A key in the referenced Secret.
  21614. Some instances of this field may be defaulted, in others it may be required.
  21615. maxLength: 253
  21616. minLength: 1
  21617. pattern: ^[-._a-zA-Z0-9]+$
  21618. type: string
  21619. name:
  21620. description: The name of the Secret resource being referred to.
  21621. maxLength: 253
  21622. minLength: 1
  21623. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21624. type: string
  21625. namespace:
  21626. description: |-
  21627. The namespace of the Secret resource being referred to.
  21628. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21629. maxLength: 63
  21630. minLength: 1
  21631. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21632. type: string
  21633. type: object
  21634. required:
  21635. - path
  21636. - secretRef
  21637. type: object
  21638. cert:
  21639. description: |-
  21640. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  21641. Cert authentication method
  21642. properties:
  21643. clientCert:
  21644. description: |-
  21645. ClientCert is a certificate to authenticate using the Cert Vault
  21646. authentication method
  21647. properties:
  21648. key:
  21649. description: |-
  21650. A key in the referenced Secret.
  21651. Some instances of this field may be defaulted, in others it may be required.
  21652. maxLength: 253
  21653. minLength: 1
  21654. pattern: ^[-._a-zA-Z0-9]+$
  21655. type: string
  21656. name:
  21657. description: The name of the Secret resource being referred to.
  21658. maxLength: 253
  21659. minLength: 1
  21660. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21661. type: string
  21662. namespace:
  21663. description: |-
  21664. The namespace of the Secret resource being referred to.
  21665. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21666. maxLength: 63
  21667. minLength: 1
  21668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21669. type: string
  21670. type: object
  21671. path:
  21672. default: cert
  21673. description: |-
  21674. Path where the Certificate authentication backend is mounted
  21675. in Vault, e.g: "cert"
  21676. type: string
  21677. secretRef:
  21678. description: |-
  21679. SecretRef to a key in a Secret resource containing client private key to
  21680. authenticate with Vault using the Cert authentication method
  21681. properties:
  21682. key:
  21683. description: |-
  21684. A key in the referenced Secret.
  21685. Some instances of this field may be defaulted, in others it may be required.
  21686. maxLength: 253
  21687. minLength: 1
  21688. pattern: ^[-._a-zA-Z0-9]+$
  21689. type: string
  21690. name:
  21691. description: The name of the Secret resource being referred to.
  21692. maxLength: 253
  21693. minLength: 1
  21694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21695. type: string
  21696. namespace:
  21697. description: |-
  21698. The namespace of the Secret resource being referred to.
  21699. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21700. maxLength: 63
  21701. minLength: 1
  21702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21703. type: string
  21704. type: object
  21705. vaultRole:
  21706. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  21707. type: string
  21708. type: object
  21709. gcp:
  21710. description: |-
  21711. Gcp authenticates with Vault using Google Cloud Platform authentication method
  21712. GCP authentication method
  21713. properties:
  21714. location:
  21715. description: Location optionally defines a location/region for the secret
  21716. type: string
  21717. path:
  21718. default: gcp
  21719. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  21720. type: string
  21721. projectID:
  21722. description: Project ID of the Google Cloud Platform project
  21723. type: string
  21724. role:
  21725. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  21726. type: string
  21727. secretRef:
  21728. description: Specify credentials in a Secret object
  21729. properties:
  21730. secretAccessKeySecretRef:
  21731. description: The SecretAccessKey is used for authentication
  21732. properties:
  21733. key:
  21734. description: |-
  21735. A key in the referenced Secret.
  21736. Some instances of this field may be defaulted, in others it may be required.
  21737. maxLength: 253
  21738. minLength: 1
  21739. pattern: ^[-._a-zA-Z0-9]+$
  21740. type: string
  21741. name:
  21742. description: The name of the Secret resource being referred to.
  21743. maxLength: 253
  21744. minLength: 1
  21745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21746. type: string
  21747. namespace:
  21748. description: |-
  21749. The namespace of the Secret resource being referred to.
  21750. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21751. maxLength: 63
  21752. minLength: 1
  21753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21754. type: string
  21755. type: object
  21756. type: object
  21757. serviceAccountRef:
  21758. description: ServiceAccountRef to a service account for impersonation
  21759. properties:
  21760. audiences:
  21761. description: |-
  21762. Audience specifies the `aud` claim for the service account token
  21763. Some providers automatically extend the audience field based on well-known annotations for workload
  21764. identity (e.g. IRSA or GCP Workload Identity)
  21765. items:
  21766. type: string
  21767. type: array
  21768. name:
  21769. description: The name of the ServiceAccount resource being referred to.
  21770. maxLength: 253
  21771. minLength: 1
  21772. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21773. type: string
  21774. namespace:
  21775. description: |-
  21776. Namespace of the resource being referred to.
  21777. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21778. maxLength: 63
  21779. minLength: 1
  21780. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21781. type: string
  21782. required:
  21783. - name
  21784. type: object
  21785. workloadIdentity:
  21786. description: Specify a service account with Workload Identity
  21787. properties:
  21788. clusterLocation:
  21789. description: |-
  21790. ClusterLocation is the location of the cluster
  21791. If not specified, it fetches information from the metadata server
  21792. type: string
  21793. clusterName:
  21794. description: |-
  21795. ClusterName is the name of the cluster
  21796. If not specified, it fetches information from the metadata server
  21797. type: string
  21798. clusterProjectID:
  21799. description: |-
  21800. ClusterProjectID is the project ID of the cluster
  21801. If not specified, it fetches information from the metadata server
  21802. type: string
  21803. serviceAccountRef:
  21804. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  21805. properties:
  21806. audiences:
  21807. description: |-
  21808. Audience specifies the `aud` claim for the service account token
  21809. Some providers automatically extend the audience field based on well-known annotations for workload
  21810. identity (e.g. IRSA or GCP Workload Identity)
  21811. items:
  21812. type: string
  21813. type: array
  21814. name:
  21815. description: The name of the ServiceAccount resource being referred to.
  21816. maxLength: 253
  21817. minLength: 1
  21818. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21819. type: string
  21820. namespace:
  21821. description: |-
  21822. Namespace of the resource being referred to.
  21823. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21824. maxLength: 63
  21825. minLength: 1
  21826. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21827. type: string
  21828. required:
  21829. - name
  21830. type: object
  21831. required:
  21832. - serviceAccountRef
  21833. type: object
  21834. required:
  21835. - role
  21836. type: object
  21837. iam:
  21838. description: |-
  21839. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  21840. AWS IAM authentication method
  21841. properties:
  21842. externalID:
  21843. description: AWS External ID set on assumed IAM roles
  21844. type: string
  21845. jwt:
  21846. description: Specify a service account with IRSA enabled
  21847. properties:
  21848. serviceAccountRef:
  21849. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  21850. properties:
  21851. audiences:
  21852. description: |-
  21853. Audience specifies the `aud` claim for the service account token
  21854. Some providers automatically extend the audience field based on well-known annotations for workload
  21855. identity (e.g. IRSA or GCP Workload Identity)
  21856. items:
  21857. type: string
  21858. type: array
  21859. name:
  21860. description: The name of the ServiceAccount resource being referred to.
  21861. maxLength: 253
  21862. minLength: 1
  21863. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21864. type: string
  21865. namespace:
  21866. description: |-
  21867. Namespace of the resource being referred to.
  21868. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21869. maxLength: 63
  21870. minLength: 1
  21871. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21872. type: string
  21873. required:
  21874. - name
  21875. type: object
  21876. type: object
  21877. path:
  21878. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  21879. type: string
  21880. region:
  21881. description: AWS region
  21882. type: string
  21883. role:
  21884. description: This is the AWS role to be assumed before talking to vault
  21885. type: string
  21886. secretRef:
  21887. description: Specify credentials in a Secret object
  21888. properties:
  21889. accessKeyIDSecretRef:
  21890. description: The AccessKeyID is used for authentication
  21891. properties:
  21892. key:
  21893. description: |-
  21894. A key in the referenced Secret.
  21895. Some instances of this field may be defaulted, in others it may be required.
  21896. maxLength: 253
  21897. minLength: 1
  21898. pattern: ^[-._a-zA-Z0-9]+$
  21899. type: string
  21900. name:
  21901. description: The name of the Secret resource being referred to.
  21902. maxLength: 253
  21903. minLength: 1
  21904. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21905. type: string
  21906. namespace:
  21907. description: |-
  21908. The namespace of the Secret resource being referred to.
  21909. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21910. maxLength: 63
  21911. minLength: 1
  21912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21913. type: string
  21914. type: object
  21915. secretAccessKeySecretRef:
  21916. description: The SecretAccessKey is used for authentication
  21917. properties:
  21918. key:
  21919. description: |-
  21920. A key in the referenced Secret.
  21921. Some instances of this field may be defaulted, in others it may be required.
  21922. maxLength: 253
  21923. minLength: 1
  21924. pattern: ^[-._a-zA-Z0-9]+$
  21925. type: string
  21926. name:
  21927. description: The name of the Secret resource being referred to.
  21928. maxLength: 253
  21929. minLength: 1
  21930. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21931. type: string
  21932. namespace:
  21933. description: |-
  21934. The namespace of the Secret resource being referred to.
  21935. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21936. maxLength: 63
  21937. minLength: 1
  21938. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21939. type: string
  21940. type: object
  21941. sessionTokenSecretRef:
  21942. description: |-
  21943. The SessionToken used for authentication
  21944. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  21945. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  21946. properties:
  21947. key:
  21948. description: |-
  21949. A key in the referenced Secret.
  21950. Some instances of this field may be defaulted, in others it may be required.
  21951. maxLength: 253
  21952. minLength: 1
  21953. pattern: ^[-._a-zA-Z0-9]+$
  21954. type: string
  21955. name:
  21956. description: The name of the Secret resource being referred to.
  21957. maxLength: 253
  21958. minLength: 1
  21959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21960. type: string
  21961. namespace:
  21962. description: |-
  21963. The namespace of the Secret resource being referred to.
  21964. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21965. maxLength: 63
  21966. minLength: 1
  21967. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21968. type: string
  21969. type: object
  21970. type: object
  21971. vaultAwsIamServerID:
  21972. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  21973. type: string
  21974. vaultRole:
  21975. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  21976. type: string
  21977. required:
  21978. - vaultRole
  21979. type: object
  21980. jwt:
  21981. description: |-
  21982. Jwt authenticates with Vault by passing role and JWT token using the
  21983. JWT/OIDC authentication method
  21984. properties:
  21985. kubernetesServiceAccountToken:
  21986. description: |-
  21987. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  21988. a token for with the `TokenRequest` API.
  21989. properties:
  21990. audiences:
  21991. description: |-
  21992. Optional audiences field that will be used to request a temporary Kubernetes service
  21993. account token for the service account referenced by `serviceAccountRef`.
  21994. Defaults to a single audience `vault` it not specified.
  21995. Deprecated: use serviceAccountRef.Audiences instead
  21996. items:
  21997. type: string
  21998. type: array
  21999. expirationSeconds:
  22000. description: |-
  22001. Optional expiration time in seconds that will be used to request a temporary
  22002. Kubernetes service account token for the service account referenced by
  22003. `serviceAccountRef`.
  22004. Deprecated: this will be removed in the future.
  22005. Defaults to 10 minutes.
  22006. format: int64
  22007. type: integer
  22008. serviceAccountRef:
  22009. description: Service account field containing the name of a kubernetes ServiceAccount.
  22010. properties:
  22011. audiences:
  22012. description: |-
  22013. Audience specifies the `aud` claim for the service account token
  22014. Some providers automatically extend the audience field based on well-known annotations for workload
  22015. identity (e.g. IRSA or GCP Workload Identity)
  22016. items:
  22017. type: string
  22018. type: array
  22019. name:
  22020. description: The name of the ServiceAccount resource being referred to.
  22021. maxLength: 253
  22022. minLength: 1
  22023. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22024. type: string
  22025. namespace:
  22026. description: |-
  22027. Namespace of the resource being referred to.
  22028. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22029. maxLength: 63
  22030. minLength: 1
  22031. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22032. type: string
  22033. required:
  22034. - name
  22035. type: object
  22036. required:
  22037. - serviceAccountRef
  22038. type: object
  22039. path:
  22040. default: jwt
  22041. description: |-
  22042. Path where the JWT authentication backend is mounted
  22043. in Vault, e.g: "jwt"
  22044. type: string
  22045. role:
  22046. description: |-
  22047. Role is a JWT role to authenticate using the JWT/OIDC Vault
  22048. authentication method
  22049. type: string
  22050. secretRef:
  22051. description: |-
  22052. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  22053. authenticate with Vault using the JWT/OIDC authentication method.
  22054. properties:
  22055. key:
  22056. description: |-
  22057. A key in the referenced Secret.
  22058. Some instances of this field may be defaulted, in others it may be required.
  22059. maxLength: 253
  22060. minLength: 1
  22061. pattern: ^[-._a-zA-Z0-9]+$
  22062. type: string
  22063. name:
  22064. description: The name of the Secret resource being referred to.
  22065. maxLength: 253
  22066. minLength: 1
  22067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22068. type: string
  22069. namespace:
  22070. description: |-
  22071. The namespace of the Secret resource being referred to.
  22072. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22073. maxLength: 63
  22074. minLength: 1
  22075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22076. type: string
  22077. type: object
  22078. required:
  22079. - path
  22080. type: object
  22081. kubernetes:
  22082. description: |-
  22083. Kubernetes authenticates with Vault by passing the ServiceAccount
  22084. token stored in the named Secret resource to the Vault server.
  22085. properties:
  22086. mountPath:
  22087. default: kubernetes
  22088. description: |-
  22089. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  22090. "kubernetes"
  22091. type: string
  22092. role:
  22093. description: |-
  22094. A required field containing the Vault Role to assume. A Role binds a
  22095. Kubernetes ServiceAccount with a set of Vault policies.
  22096. type: string
  22097. secretRef:
  22098. description: |-
  22099. Optional secret field containing a Kubernetes ServiceAccount JWT used
  22100. for authenticating with Vault. If a name is specified without a key,
  22101. `token` is the default. If one is not specified, the one bound to
  22102. the controller will be used.
  22103. properties:
  22104. key:
  22105. description: |-
  22106. A key in the referenced Secret.
  22107. Some instances of this field may be defaulted, in others it may be required.
  22108. maxLength: 253
  22109. minLength: 1
  22110. pattern: ^[-._a-zA-Z0-9]+$
  22111. type: string
  22112. name:
  22113. description: The name of the Secret resource being referred to.
  22114. maxLength: 253
  22115. minLength: 1
  22116. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22117. type: string
  22118. namespace:
  22119. description: |-
  22120. The namespace of the Secret resource being referred to.
  22121. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22122. maxLength: 63
  22123. minLength: 1
  22124. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22125. type: string
  22126. type: object
  22127. serviceAccountRef:
  22128. description: |-
  22129. Optional service account field containing the name of a kubernetes ServiceAccount.
  22130. If the service account is specified, the service account secret token JWT will be used
  22131. for authenticating with Vault. If the service account selector is not supplied,
  22132. the secretRef will be used instead.
  22133. properties:
  22134. audiences:
  22135. description: |-
  22136. Audience specifies the `aud` claim for the service account token
  22137. Some providers automatically extend the audience field based on well-known annotations for workload
  22138. identity (e.g. IRSA or GCP Workload Identity)
  22139. items:
  22140. type: string
  22141. type: array
  22142. name:
  22143. description: The name of the ServiceAccount resource being referred to.
  22144. maxLength: 253
  22145. minLength: 1
  22146. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22147. type: string
  22148. namespace:
  22149. description: |-
  22150. Namespace of the resource being referred to.
  22151. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22152. maxLength: 63
  22153. minLength: 1
  22154. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22155. type: string
  22156. required:
  22157. - name
  22158. type: object
  22159. required:
  22160. - mountPath
  22161. - role
  22162. type: object
  22163. ldap:
  22164. description: |-
  22165. Ldap authenticates with Vault by passing username/password pair using
  22166. the LDAP authentication method
  22167. properties:
  22168. path:
  22169. default: ldap
  22170. description: |-
  22171. Path where the LDAP authentication backend is mounted
  22172. in Vault, e.g: "ldap"
  22173. type: string
  22174. secretRef:
  22175. description: |-
  22176. SecretRef to a key in a Secret resource containing password for the LDAP
  22177. user used to authenticate with Vault using the LDAP authentication
  22178. method
  22179. properties:
  22180. key:
  22181. description: |-
  22182. A key in the referenced Secret.
  22183. Some instances of this field may be defaulted, in others it may be required.
  22184. maxLength: 253
  22185. minLength: 1
  22186. pattern: ^[-._a-zA-Z0-9]+$
  22187. type: string
  22188. name:
  22189. description: The name of the Secret resource being referred to.
  22190. maxLength: 253
  22191. minLength: 1
  22192. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22193. type: string
  22194. namespace:
  22195. description: |-
  22196. The namespace of the Secret resource being referred to.
  22197. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22198. maxLength: 63
  22199. minLength: 1
  22200. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22201. type: string
  22202. type: object
  22203. username:
  22204. description: |-
  22205. Username is an LDAP username used to authenticate using the LDAP Vault
  22206. authentication method
  22207. type: string
  22208. required:
  22209. - path
  22210. - username
  22211. type: object
  22212. namespace:
  22213. description: |-
  22214. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  22215. Namespaces is a set of features within Vault Enterprise that allows
  22216. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  22217. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  22218. This will default to Vault.Namespace field if set, or empty otherwise
  22219. type: string
  22220. tokenSecretRef:
  22221. description: TokenSecretRef authenticates with Vault by presenting a token.
  22222. properties:
  22223. key:
  22224. description: |-
  22225. A key in the referenced Secret.
  22226. Some instances of this field may be defaulted, in others it may be required.
  22227. maxLength: 253
  22228. minLength: 1
  22229. pattern: ^[-._a-zA-Z0-9]+$
  22230. type: string
  22231. name:
  22232. description: The name of the Secret resource being referred to.
  22233. maxLength: 253
  22234. minLength: 1
  22235. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22236. type: string
  22237. namespace:
  22238. description: |-
  22239. The namespace of the Secret resource being referred to.
  22240. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22241. maxLength: 63
  22242. minLength: 1
  22243. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22244. type: string
  22245. type: object
  22246. userPass:
  22247. description: UserPass authenticates with Vault by passing username/password pair
  22248. properties:
  22249. path:
  22250. default: userpass
  22251. description: |-
  22252. Path where the UserPassword authentication backend is mounted
  22253. in Vault, e.g: "userpass"
  22254. type: string
  22255. secretRef:
  22256. description: |-
  22257. SecretRef to a key in a Secret resource containing password for the
  22258. user used to authenticate with Vault using the UserPass authentication
  22259. method
  22260. properties:
  22261. key:
  22262. description: |-
  22263. A key in the referenced Secret.
  22264. Some instances of this field may be defaulted, in others it may be required.
  22265. maxLength: 253
  22266. minLength: 1
  22267. pattern: ^[-._a-zA-Z0-9]+$
  22268. type: string
  22269. name:
  22270. description: The name of the Secret resource being referred to.
  22271. maxLength: 253
  22272. minLength: 1
  22273. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22274. type: string
  22275. namespace:
  22276. description: |-
  22277. The namespace of the Secret resource being referred to.
  22278. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22279. maxLength: 63
  22280. minLength: 1
  22281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22282. type: string
  22283. type: object
  22284. username:
  22285. description: |-
  22286. Username is a username used to authenticate using the UserPass Vault
  22287. authentication method
  22288. type: string
  22289. required:
  22290. - path
  22291. - username
  22292. type: object
  22293. type: object
  22294. caBundle:
  22295. description: |-
  22296. PEM encoded CA bundle used to validate Vault server certificate. Only used
  22297. if the Server URL is using HTTPS protocol. This parameter is ignored for
  22298. plain HTTP protocol connection. If not set the system root certificates
  22299. are used to validate the TLS connection.
  22300. format: byte
  22301. type: string
  22302. caProvider:
  22303. description: The provider for the CA bundle to use to validate Vault server certificate.
  22304. properties:
  22305. key:
  22306. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22307. maxLength: 253
  22308. minLength: 1
  22309. pattern: ^[-._a-zA-Z0-9]+$
  22310. type: string
  22311. name:
  22312. description: The name of the object located at the provider type.
  22313. maxLength: 253
  22314. minLength: 1
  22315. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22316. type: string
  22317. namespace:
  22318. description: |-
  22319. The namespace the Provider type is in.
  22320. Can only be defined when used in a ClusterSecretStore.
  22321. maxLength: 63
  22322. minLength: 1
  22323. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22324. type: string
  22325. type:
  22326. description: The type of provider to use such as "Secret", or "ConfigMap".
  22327. enum:
  22328. - Secret
  22329. - ConfigMap
  22330. type: string
  22331. required:
  22332. - name
  22333. - type
  22334. type: object
  22335. checkAndSet:
  22336. description: |-
  22337. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  22338. Only applies to Vault KV v2 stores. When enabled, write operations must include
  22339. the current version of the secret to prevent unintentional overwrites.
  22340. properties:
  22341. required:
  22342. description: |-
  22343. Required when true, all write operations must include a check-and-set parameter.
  22344. This helps prevent unintentional overwrites of secrets.
  22345. type: boolean
  22346. type: object
  22347. forwardInconsistent:
  22348. description: |-
  22349. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  22350. leader instead of simply retrying within a loop. This can increase performance if
  22351. the option is enabled serverside.
  22352. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  22353. type: boolean
  22354. headers:
  22355. additionalProperties:
  22356. type: string
  22357. description: Headers to be added in Vault request
  22358. type: object
  22359. namespace:
  22360. description: |-
  22361. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  22362. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  22363. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  22364. type: string
  22365. path:
  22366. description: |-
  22367. Path is the mount path of the Vault KV backend endpoint, e.g:
  22368. "secret". The v2 KV secret engine version specific "/data" path suffix
  22369. for fetching secrets from Vault is optional and will be appended
  22370. if not present in specified path.
  22371. type: string
  22372. readYourWrites:
  22373. description: |-
  22374. ReadYourWrites ensures isolated read-after-write semantics by
  22375. providing discovered cluster replication states in each request.
  22376. More information about eventual consistency in Vault can be found here
  22377. https://www.vaultproject.io/docs/enterprise/consistency
  22378. type: boolean
  22379. server:
  22380. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  22381. type: string
  22382. tls:
  22383. description: |-
  22384. The configuration used for client side related TLS communication, when the Vault server
  22385. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  22386. This parameter is ignored for plain HTTP protocol connection.
  22387. It's worth noting this configuration is different from the "TLS certificates auth method",
  22388. which is available under the `auth.cert` section.
  22389. properties:
  22390. certSecretRef:
  22391. description: |-
  22392. CertSecretRef is a certificate added to the transport layer
  22393. when communicating with the Vault server.
  22394. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  22395. properties:
  22396. key:
  22397. description: |-
  22398. A key in the referenced Secret.
  22399. Some instances of this field may be defaulted, in others it may be required.
  22400. maxLength: 253
  22401. minLength: 1
  22402. pattern: ^[-._a-zA-Z0-9]+$
  22403. type: string
  22404. name:
  22405. description: The name of the Secret resource being referred to.
  22406. maxLength: 253
  22407. minLength: 1
  22408. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22409. type: string
  22410. namespace:
  22411. description: |-
  22412. The namespace of the Secret resource being referred to.
  22413. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22414. maxLength: 63
  22415. minLength: 1
  22416. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22417. type: string
  22418. type: object
  22419. keySecretRef:
  22420. description: |-
  22421. KeySecretRef to a key in a Secret resource containing client private key
  22422. added to the transport layer when communicating with the Vault server.
  22423. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  22424. properties:
  22425. key:
  22426. description: |-
  22427. A key in the referenced Secret.
  22428. Some instances of this field may be defaulted, in others it may be required.
  22429. maxLength: 253
  22430. minLength: 1
  22431. pattern: ^[-._a-zA-Z0-9]+$
  22432. type: string
  22433. name:
  22434. description: The name of the Secret resource being referred to.
  22435. maxLength: 253
  22436. minLength: 1
  22437. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22438. type: string
  22439. namespace:
  22440. description: |-
  22441. The namespace of the Secret resource being referred to.
  22442. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22443. maxLength: 63
  22444. minLength: 1
  22445. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22446. type: string
  22447. type: object
  22448. type: object
  22449. version:
  22450. default: v2
  22451. description: |-
  22452. Version is the Vault KV secret engine version. This can be either "v1" or
  22453. "v2". Version defaults to "v2".
  22454. enum:
  22455. - v1
  22456. - v2
  22457. type: string
  22458. required:
  22459. - server
  22460. type: object
  22461. volcengine:
  22462. description: Volcengine configures this store to sync secrets using the Volcengine provider
  22463. properties:
  22464. auth:
  22465. description: |-
  22466. Auth defines the authentication method to use.
  22467. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  22468. properties:
  22469. secretRef:
  22470. description: |-
  22471. SecretRef defines the static credentials to use for authentication.
  22472. If not set, IRSA is used.
  22473. properties:
  22474. accessKeyID:
  22475. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  22476. properties:
  22477. key:
  22478. description: |-
  22479. A key in the referenced Secret.
  22480. Some instances of this field may be defaulted, in others it may be required.
  22481. maxLength: 253
  22482. minLength: 1
  22483. pattern: ^[-._a-zA-Z0-9]+$
  22484. type: string
  22485. name:
  22486. description: The name of the Secret resource being referred to.
  22487. maxLength: 253
  22488. minLength: 1
  22489. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22490. type: string
  22491. namespace:
  22492. description: |-
  22493. The namespace of the Secret resource being referred to.
  22494. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22495. maxLength: 63
  22496. minLength: 1
  22497. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22498. type: string
  22499. type: object
  22500. secretAccessKey:
  22501. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  22502. properties:
  22503. key:
  22504. description: |-
  22505. A key in the referenced Secret.
  22506. Some instances of this field may be defaulted, in others it may be required.
  22507. maxLength: 253
  22508. minLength: 1
  22509. pattern: ^[-._a-zA-Z0-9]+$
  22510. type: string
  22511. name:
  22512. description: The name of the Secret resource being referred to.
  22513. maxLength: 253
  22514. minLength: 1
  22515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22516. type: string
  22517. namespace:
  22518. description: |-
  22519. The namespace of the Secret resource being referred to.
  22520. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22521. maxLength: 63
  22522. minLength: 1
  22523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22524. type: string
  22525. type: object
  22526. token:
  22527. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  22528. properties:
  22529. key:
  22530. description: |-
  22531. A key in the referenced Secret.
  22532. Some instances of this field may be defaulted, in others it may be required.
  22533. maxLength: 253
  22534. minLength: 1
  22535. pattern: ^[-._a-zA-Z0-9]+$
  22536. type: string
  22537. name:
  22538. description: The name of the Secret resource being referred to.
  22539. maxLength: 253
  22540. minLength: 1
  22541. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22542. type: string
  22543. namespace:
  22544. description: |-
  22545. The namespace of the Secret resource being referred to.
  22546. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22547. maxLength: 63
  22548. minLength: 1
  22549. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22550. type: string
  22551. type: object
  22552. required:
  22553. - accessKeyID
  22554. - secretAccessKey
  22555. type: object
  22556. type: object
  22557. region:
  22558. description: Region specifies the Volcengine region to connect to.
  22559. type: string
  22560. required:
  22561. - region
  22562. type: object
  22563. webhook:
  22564. description: Webhook configures this store to sync secrets using a generic templated webhook
  22565. properties:
  22566. auth:
  22567. description: Auth specifies a authorization protocol. Only one protocol may be set.
  22568. maxProperties: 1
  22569. minProperties: 1
  22570. properties:
  22571. ntlm:
  22572. description: NTLMProtocol configures the store to use NTLM for auth
  22573. properties:
  22574. passwordSecret:
  22575. description: |-
  22576. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22577. In some instances, `key` is a required field.
  22578. properties:
  22579. key:
  22580. description: |-
  22581. A key in the referenced Secret.
  22582. Some instances of this field may be defaulted, in others it may be required.
  22583. maxLength: 253
  22584. minLength: 1
  22585. pattern: ^[-._a-zA-Z0-9]+$
  22586. type: string
  22587. name:
  22588. description: The name of the Secret resource being referred to.
  22589. maxLength: 253
  22590. minLength: 1
  22591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22592. type: string
  22593. namespace:
  22594. description: |-
  22595. The namespace of the Secret resource being referred to.
  22596. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22597. maxLength: 63
  22598. minLength: 1
  22599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22600. type: string
  22601. type: object
  22602. usernameSecret:
  22603. description: |-
  22604. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22605. In some instances, `key` is a required field.
  22606. properties:
  22607. key:
  22608. description: |-
  22609. A key in the referenced Secret.
  22610. Some instances of this field may be defaulted, in others it may be required.
  22611. maxLength: 253
  22612. minLength: 1
  22613. pattern: ^[-._a-zA-Z0-9]+$
  22614. type: string
  22615. name:
  22616. description: The name of the Secret resource being referred to.
  22617. maxLength: 253
  22618. minLength: 1
  22619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22620. type: string
  22621. namespace:
  22622. description: |-
  22623. The namespace of the Secret resource being referred to.
  22624. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22625. maxLength: 63
  22626. minLength: 1
  22627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22628. type: string
  22629. type: object
  22630. required:
  22631. - passwordSecret
  22632. - usernameSecret
  22633. type: object
  22634. type: object
  22635. body:
  22636. description: Body
  22637. type: string
  22638. caBundle:
  22639. description: |-
  22640. PEM encoded CA bundle used to validate webhook server certificate. Only used
  22641. if the Server URL is using HTTPS protocol. This parameter is ignored for
  22642. plain HTTP protocol connection. If not set the system root certificates
  22643. are used to validate the TLS connection.
  22644. format: byte
  22645. type: string
  22646. caProvider:
  22647. description: The provider for the CA bundle to use to validate webhook server certificate.
  22648. properties:
  22649. key:
  22650. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22651. maxLength: 253
  22652. minLength: 1
  22653. pattern: ^[-._a-zA-Z0-9]+$
  22654. type: string
  22655. name:
  22656. description: The name of the object located at the provider type.
  22657. maxLength: 253
  22658. minLength: 1
  22659. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22660. type: string
  22661. namespace:
  22662. description: The namespace the Provider type is in.
  22663. maxLength: 63
  22664. minLength: 1
  22665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22666. type: string
  22667. type:
  22668. description: The type of provider to use such as "Secret", or "ConfigMap".
  22669. enum:
  22670. - Secret
  22671. - ConfigMap
  22672. type: string
  22673. required:
  22674. - name
  22675. - type
  22676. type: object
  22677. headers:
  22678. additionalProperties:
  22679. type: string
  22680. description: Headers
  22681. type: object
  22682. method:
  22683. description: Webhook Method
  22684. type: string
  22685. result:
  22686. description: Result formatting
  22687. properties:
  22688. jsonPath:
  22689. description: Json path of return value
  22690. type: string
  22691. type: object
  22692. secrets:
  22693. description: |-
  22694. Secrets to fill in templates
  22695. These secrets will be passed to the templating function as key value pairs under the given name
  22696. items:
  22697. description: WebhookSecret defines a secret that will be passed to the webhook request.
  22698. properties:
  22699. name:
  22700. description: Name of this secret in templates
  22701. type: string
  22702. secretRef:
  22703. description: Secret ref to fill in credentials
  22704. properties:
  22705. key:
  22706. description: |-
  22707. A key in the referenced Secret.
  22708. Some instances of this field may be defaulted, in others it may be required.
  22709. maxLength: 253
  22710. minLength: 1
  22711. pattern: ^[-._a-zA-Z0-9]+$
  22712. type: string
  22713. name:
  22714. description: The name of the Secret resource being referred to.
  22715. maxLength: 253
  22716. minLength: 1
  22717. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22718. type: string
  22719. namespace:
  22720. description: |-
  22721. The namespace of the Secret resource being referred to.
  22722. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22723. maxLength: 63
  22724. minLength: 1
  22725. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22726. type: string
  22727. type: object
  22728. required:
  22729. - name
  22730. - secretRef
  22731. type: object
  22732. type: array
  22733. timeout:
  22734. description: Timeout
  22735. type: string
  22736. url:
  22737. description: Webhook url to call
  22738. type: string
  22739. required:
  22740. - url
  22741. type: object
  22742. yandexcertificatemanager:
  22743. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  22744. properties:
  22745. apiEndpoint:
  22746. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  22747. type: string
  22748. auth:
  22749. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  22750. properties:
  22751. authorizedKeySecretRef:
  22752. description: The authorized key used for authentication
  22753. properties:
  22754. key:
  22755. description: |-
  22756. A key in the referenced Secret.
  22757. Some instances of this field may be defaulted, in others it may be required.
  22758. maxLength: 253
  22759. minLength: 1
  22760. pattern: ^[-._a-zA-Z0-9]+$
  22761. type: string
  22762. name:
  22763. description: The name of the Secret resource being referred to.
  22764. maxLength: 253
  22765. minLength: 1
  22766. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22767. type: string
  22768. namespace:
  22769. description: |-
  22770. The namespace of the Secret resource being referred to.
  22771. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22772. maxLength: 63
  22773. minLength: 1
  22774. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22775. type: string
  22776. type: object
  22777. type: object
  22778. caProvider:
  22779. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  22780. properties:
  22781. certSecretRef:
  22782. description: |-
  22783. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22784. In some instances, `key` is a required field.
  22785. properties:
  22786. key:
  22787. description: |-
  22788. A key in the referenced Secret.
  22789. Some instances of this field may be defaulted, in others it may be required.
  22790. maxLength: 253
  22791. minLength: 1
  22792. pattern: ^[-._a-zA-Z0-9]+$
  22793. type: string
  22794. name:
  22795. description: The name of the Secret resource being referred to.
  22796. maxLength: 253
  22797. minLength: 1
  22798. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22799. type: string
  22800. namespace:
  22801. description: |-
  22802. The namespace of the Secret resource being referred to.
  22803. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22804. maxLength: 63
  22805. minLength: 1
  22806. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22807. type: string
  22808. type: object
  22809. type: object
  22810. fetching:
  22811. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  22812. maxProperties: 1
  22813. minProperties: 1
  22814. properties:
  22815. byID:
  22816. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  22817. type: object
  22818. byName:
  22819. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  22820. properties:
  22821. folderID:
  22822. description: The folder to fetch secrets from
  22823. type: string
  22824. required:
  22825. - folderID
  22826. type: object
  22827. type: object
  22828. required:
  22829. - auth
  22830. type: object
  22831. yandexlockbox:
  22832. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  22833. properties:
  22834. apiEndpoint:
  22835. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  22836. type: string
  22837. auth:
  22838. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  22839. properties:
  22840. authorizedKeySecretRef:
  22841. description: The authorized key used for authentication
  22842. properties:
  22843. key:
  22844. description: |-
  22845. A key in the referenced Secret.
  22846. Some instances of this field may be defaulted, in others it may be required.
  22847. maxLength: 253
  22848. minLength: 1
  22849. pattern: ^[-._a-zA-Z0-9]+$
  22850. type: string
  22851. name:
  22852. description: The name of the Secret resource being referred to.
  22853. maxLength: 253
  22854. minLength: 1
  22855. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22856. type: string
  22857. namespace:
  22858. description: |-
  22859. The namespace of the Secret resource being referred to.
  22860. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22861. maxLength: 63
  22862. minLength: 1
  22863. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22864. type: string
  22865. type: object
  22866. type: object
  22867. caProvider:
  22868. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  22869. properties:
  22870. certSecretRef:
  22871. description: |-
  22872. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22873. In some instances, `key` is a required field.
  22874. properties:
  22875. key:
  22876. description: |-
  22877. A key in the referenced Secret.
  22878. Some instances of this field may be defaulted, in others it may be required.
  22879. maxLength: 253
  22880. minLength: 1
  22881. pattern: ^[-._a-zA-Z0-9]+$
  22882. type: string
  22883. name:
  22884. description: The name of the Secret resource being referred to.
  22885. maxLength: 253
  22886. minLength: 1
  22887. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22888. type: string
  22889. namespace:
  22890. description: |-
  22891. The namespace of the Secret resource being referred to.
  22892. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22893. maxLength: 63
  22894. minLength: 1
  22895. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22896. type: string
  22897. type: object
  22898. type: object
  22899. fetching:
  22900. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  22901. maxProperties: 1
  22902. minProperties: 1
  22903. properties:
  22904. byID:
  22905. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  22906. type: object
  22907. byName:
  22908. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  22909. properties:
  22910. folderID:
  22911. description: The folder to fetch secrets from
  22912. type: string
  22913. required:
  22914. - folderID
  22915. type: object
  22916. type: object
  22917. required:
  22918. - auth
  22919. type: object
  22920. type: object
  22921. refreshInterval:
  22922. anyOf:
  22923. - type: integer
  22924. - type: string
  22925. description: |-
  22926. Used to configure store refresh interval. Accepts either an integer number
  22927. of seconds (legacy) or a Go duration string such as "1h" or "5m". Empty or
  22928. 0 will default to the controller config.
  22929. x-kubernetes-int-or-string: true
  22930. retrySettings:
  22931. description: Used to configure HTTP retries on failures.
  22932. properties:
  22933. maxRetries:
  22934. format: int32
  22935. type: integer
  22936. retryInterval:
  22937. type: string
  22938. type: object
  22939. required:
  22940. - provider
  22941. type: object
  22942. status:
  22943. description: SecretStoreStatus defines the observed state of the SecretStore.
  22944. properties:
  22945. capabilities:
  22946. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  22947. type: string
  22948. conditions:
  22949. items:
  22950. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  22951. properties:
  22952. lastTransitionTime:
  22953. format: date-time
  22954. type: string
  22955. message:
  22956. type: string
  22957. reason:
  22958. type: string
  22959. status:
  22960. type: string
  22961. type:
  22962. description: SecretStoreConditionType represents the condition of the SecretStore.
  22963. type: string
  22964. required:
  22965. - status
  22966. - type
  22967. type: object
  22968. type: array
  22969. type: object
  22970. type: object
  22971. served: true
  22972. storage: true
  22973. subresources:
  22974. status: {}
  22975. - additionalPrinterColumns:
  22976. - jsonPath: .metadata.creationTimestamp
  22977. name: AGE
  22978. type: date
  22979. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  22980. name: Status
  22981. type: string
  22982. - jsonPath: .status.capabilities
  22983. name: Capabilities
  22984. type: string
  22985. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  22986. name: Ready
  22987. type: string
  22988. deprecated: true
  22989. name: v1beta1
  22990. schema:
  22991. openAPIV3Schema:
  22992. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  22993. properties:
  22994. apiVersion:
  22995. description: |-
  22996. APIVersion defines the versioned schema of this representation of an object.
  22997. Servers should convert recognized schemas to the latest internal value, and
  22998. may reject unrecognized values.
  22999. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  23000. type: string
  23001. kind:
  23002. description: |-
  23003. Kind is a string value representing the REST resource this object represents.
  23004. Servers may infer this from the endpoint the client submits requests to.
  23005. Cannot be updated.
  23006. In CamelCase.
  23007. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  23008. type: string
  23009. metadata:
  23010. type: object
  23011. spec:
  23012. description: SecretStoreSpec defines the desired state of SecretStore.
  23013. properties:
  23014. conditions:
  23015. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  23016. items:
  23017. description: |-
  23018. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  23019. for a ClusterSecretStore instance.
  23020. properties:
  23021. namespaceRegexes:
  23022. description: Choose namespaces by using regex matching
  23023. items:
  23024. type: string
  23025. type: array
  23026. namespaceSelector:
  23027. description: Choose namespace using a labelSelector
  23028. properties:
  23029. matchExpressions:
  23030. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  23031. items:
  23032. description: |-
  23033. A label selector requirement is a selector that contains values, a key, and an operator that
  23034. relates the key and values.
  23035. properties:
  23036. key:
  23037. description: key is the label key that the selector applies to.
  23038. type: string
  23039. operator:
  23040. description: |-
  23041. operator represents a key's relationship to a set of values.
  23042. Valid operators are In, NotIn, Exists and DoesNotExist.
  23043. type: string
  23044. values:
  23045. description: |-
  23046. values is an array of string values. If the operator is In or NotIn,
  23047. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  23048. the values array must be empty. This array is replaced during a strategic
  23049. merge patch.
  23050. items:
  23051. type: string
  23052. type: array
  23053. x-kubernetes-list-type: atomic
  23054. required:
  23055. - key
  23056. - operator
  23057. type: object
  23058. type: array
  23059. x-kubernetes-list-type: atomic
  23060. matchLabels:
  23061. additionalProperties:
  23062. type: string
  23063. description: |-
  23064. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  23065. map is equivalent to an element of matchExpressions, whose key field is "key", the
  23066. operator is "In", and the values array contains only "value". The requirements are ANDed.
  23067. type: object
  23068. type: object
  23069. x-kubernetes-map-type: atomic
  23070. namespaces:
  23071. description: Choose namespaces by name
  23072. items:
  23073. maxLength: 63
  23074. minLength: 1
  23075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23076. type: string
  23077. type: array
  23078. type: object
  23079. type: array
  23080. controller:
  23081. description: |-
  23082. Used to select the correct ESO controller (think: ingress.ingressClassName)
  23083. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  23084. type: string
  23085. provider:
  23086. description: Used to configure the provider. Only one provider may be set
  23087. maxProperties: 1
  23088. minProperties: 1
  23089. properties:
  23090. akeyless:
  23091. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  23092. properties:
  23093. akeylessGWApiURL:
  23094. description: Akeyless GW API Url from which the secrets to be fetched from.
  23095. type: string
  23096. authSecretRef:
  23097. description: Auth configures how the operator authenticates with Akeyless.
  23098. properties:
  23099. kubernetesAuth:
  23100. description: |-
  23101. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  23102. token stored in the named Secret resource.
  23103. properties:
  23104. accessID:
  23105. description: the Akeyless Kubernetes auth-method access-id
  23106. type: string
  23107. k8sConfName:
  23108. description: Kubernetes-auth configuration name in Akeyless-Gateway
  23109. type: string
  23110. secretRef:
  23111. description: |-
  23112. Optional secret field containing a Kubernetes ServiceAccount JWT used
  23113. for authenticating with Akeyless. If a name is specified without a key,
  23114. `token` is the default. If one is not specified, the one bound to
  23115. the controller will be used.
  23116. properties:
  23117. key:
  23118. description: |-
  23119. A key in the referenced Secret.
  23120. Some instances of this field may be defaulted, in others it may be required.
  23121. maxLength: 253
  23122. minLength: 1
  23123. pattern: ^[-._a-zA-Z0-9]+$
  23124. type: string
  23125. name:
  23126. description: The name of the Secret resource being referred to.
  23127. maxLength: 253
  23128. minLength: 1
  23129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23130. type: string
  23131. namespace:
  23132. description: |-
  23133. The namespace of the Secret resource being referred to.
  23134. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23135. maxLength: 63
  23136. minLength: 1
  23137. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23138. type: string
  23139. type: object
  23140. serviceAccountRef:
  23141. description: |-
  23142. Optional service account field containing the name of a kubernetes ServiceAccount.
  23143. If the service account is specified, the service account secret token JWT will be used
  23144. for authenticating with Akeyless. If the service account selector is not supplied,
  23145. the secretRef will be used instead.
  23146. properties:
  23147. audiences:
  23148. description: |-
  23149. Audience specifies the `aud` claim for the service account token
  23150. Some providers automatically extend the audience field based on well-known annotations for workload
  23151. identity (e.g. IRSA or GCP Workload Identity)
  23152. items:
  23153. type: string
  23154. type: array
  23155. name:
  23156. description: The name of the ServiceAccount resource being referred to.
  23157. maxLength: 253
  23158. minLength: 1
  23159. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23160. type: string
  23161. namespace:
  23162. description: |-
  23163. Namespace of the resource being referred to.
  23164. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23165. maxLength: 63
  23166. minLength: 1
  23167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23168. type: string
  23169. required:
  23170. - name
  23171. type: object
  23172. required:
  23173. - accessID
  23174. - k8sConfName
  23175. type: object
  23176. secretRef:
  23177. description: |-
  23178. Reference to a Secret that contains the details
  23179. to authenticate with Akeyless.
  23180. properties:
  23181. accessID:
  23182. description: The SecretAccessID is used for authentication
  23183. properties:
  23184. key:
  23185. description: |-
  23186. A key in the referenced Secret.
  23187. Some instances of this field may be defaulted, in others it may be required.
  23188. maxLength: 253
  23189. minLength: 1
  23190. pattern: ^[-._a-zA-Z0-9]+$
  23191. type: string
  23192. name:
  23193. description: The name of the Secret resource being referred to.
  23194. maxLength: 253
  23195. minLength: 1
  23196. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23197. type: string
  23198. namespace:
  23199. description: |-
  23200. The namespace of the Secret resource being referred to.
  23201. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23202. maxLength: 63
  23203. minLength: 1
  23204. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23205. type: string
  23206. type: object
  23207. accessType:
  23208. description: |-
  23209. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23210. In some instances, `key` is a required field.
  23211. properties:
  23212. key:
  23213. description: |-
  23214. A key in the referenced Secret.
  23215. Some instances of this field may be defaulted, in others it may be required.
  23216. maxLength: 253
  23217. minLength: 1
  23218. pattern: ^[-._a-zA-Z0-9]+$
  23219. type: string
  23220. name:
  23221. description: The name of the Secret resource being referred to.
  23222. maxLength: 253
  23223. minLength: 1
  23224. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23225. type: string
  23226. namespace:
  23227. description: |-
  23228. The namespace of the Secret resource being referred to.
  23229. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23230. maxLength: 63
  23231. minLength: 1
  23232. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23233. type: string
  23234. type: object
  23235. accessTypeParam:
  23236. description: |-
  23237. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23238. In some instances, `key` is a required field.
  23239. properties:
  23240. key:
  23241. description: |-
  23242. A key in the referenced Secret.
  23243. Some instances of this field may be defaulted, in others it may be required.
  23244. maxLength: 253
  23245. minLength: 1
  23246. pattern: ^[-._a-zA-Z0-9]+$
  23247. type: string
  23248. name:
  23249. description: The name of the Secret resource being referred to.
  23250. maxLength: 253
  23251. minLength: 1
  23252. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23253. type: string
  23254. namespace:
  23255. description: |-
  23256. The namespace of the Secret resource being referred to.
  23257. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23258. maxLength: 63
  23259. minLength: 1
  23260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23261. type: string
  23262. type: object
  23263. type: object
  23264. type: object
  23265. caBundle:
  23266. description: |-
  23267. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  23268. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  23269. are used to validate the TLS connection.
  23270. format: byte
  23271. type: string
  23272. caProvider:
  23273. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  23274. properties:
  23275. key:
  23276. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23277. maxLength: 253
  23278. minLength: 1
  23279. pattern: ^[-._a-zA-Z0-9]+$
  23280. type: string
  23281. name:
  23282. description: The name of the object located at the provider type.
  23283. maxLength: 253
  23284. minLength: 1
  23285. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23286. type: string
  23287. namespace:
  23288. description: |-
  23289. The namespace the Provider type is in.
  23290. Can only be defined when used in a ClusterSecretStore.
  23291. maxLength: 63
  23292. minLength: 1
  23293. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23294. type: string
  23295. type:
  23296. description: The type of provider to use such as "Secret", or "ConfigMap".
  23297. enum:
  23298. - Secret
  23299. - ConfigMap
  23300. type: string
  23301. required:
  23302. - name
  23303. - type
  23304. type: object
  23305. required:
  23306. - akeylessGWApiURL
  23307. - authSecretRef
  23308. type: object
  23309. alibaba:
  23310. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  23311. properties:
  23312. auth:
  23313. description: AlibabaAuth contains a secretRef for credentials.
  23314. properties:
  23315. rrsa:
  23316. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  23317. properties:
  23318. oidcProviderArn:
  23319. type: string
  23320. oidcTokenFilePath:
  23321. type: string
  23322. roleArn:
  23323. type: string
  23324. sessionName:
  23325. type: string
  23326. required:
  23327. - oidcProviderArn
  23328. - oidcTokenFilePath
  23329. - roleArn
  23330. - sessionName
  23331. type: object
  23332. secretRef:
  23333. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  23334. properties:
  23335. accessKeyIDSecretRef:
  23336. description: The AccessKeyID is used for authentication
  23337. properties:
  23338. key:
  23339. description: |-
  23340. A key in the referenced Secret.
  23341. Some instances of this field may be defaulted, in others it may be required.
  23342. maxLength: 253
  23343. minLength: 1
  23344. pattern: ^[-._a-zA-Z0-9]+$
  23345. type: string
  23346. name:
  23347. description: The name of the Secret resource being referred to.
  23348. maxLength: 253
  23349. minLength: 1
  23350. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23351. type: string
  23352. namespace:
  23353. description: |-
  23354. The namespace of the Secret resource being referred to.
  23355. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23356. maxLength: 63
  23357. minLength: 1
  23358. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23359. type: string
  23360. type: object
  23361. accessKeySecretSecretRef:
  23362. description: The AccessKeySecret is used for authentication
  23363. properties:
  23364. key:
  23365. description: |-
  23366. A key in the referenced Secret.
  23367. Some instances of this field may be defaulted, in others it may be required.
  23368. maxLength: 253
  23369. minLength: 1
  23370. pattern: ^[-._a-zA-Z0-9]+$
  23371. type: string
  23372. name:
  23373. description: The name of the Secret resource being referred to.
  23374. maxLength: 253
  23375. minLength: 1
  23376. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23377. type: string
  23378. namespace:
  23379. description: |-
  23380. The namespace of the Secret resource being referred to.
  23381. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23382. maxLength: 63
  23383. minLength: 1
  23384. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23385. type: string
  23386. type: object
  23387. required:
  23388. - accessKeyIDSecretRef
  23389. - accessKeySecretSecretRef
  23390. type: object
  23391. type: object
  23392. regionID:
  23393. description: Alibaba Region to be used for the provider
  23394. type: string
  23395. required:
  23396. - auth
  23397. - regionID
  23398. type: object
  23399. aws:
  23400. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  23401. properties:
  23402. additionalRoles:
  23403. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  23404. items:
  23405. type: string
  23406. type: array
  23407. auth:
  23408. description: |-
  23409. Auth defines the information necessary to authenticate against AWS
  23410. if not set aws sdk will infer credentials from your environment
  23411. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  23412. properties:
  23413. jwt:
  23414. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  23415. properties:
  23416. serviceAccountRef:
  23417. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  23418. properties:
  23419. audiences:
  23420. description: |-
  23421. Audience specifies the `aud` claim for the service account token
  23422. Some providers automatically extend the audience field based on well-known annotations for workload
  23423. identity (e.g. IRSA or GCP Workload Identity)
  23424. items:
  23425. type: string
  23426. type: array
  23427. name:
  23428. description: The name of the ServiceAccount resource being referred to.
  23429. maxLength: 253
  23430. minLength: 1
  23431. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23432. type: string
  23433. namespace:
  23434. description: |-
  23435. Namespace of the resource being referred to.
  23436. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23437. maxLength: 63
  23438. minLength: 1
  23439. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23440. type: string
  23441. required:
  23442. - name
  23443. type: object
  23444. type: object
  23445. secretRef:
  23446. description: |-
  23447. AWSAuthSecretRef holds secret references for AWS credentials
  23448. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  23449. properties:
  23450. accessKeyIDSecretRef:
  23451. description: The AccessKeyID is used for authentication
  23452. properties:
  23453. key:
  23454. description: |-
  23455. A key in the referenced Secret.
  23456. Some instances of this field may be defaulted, in others it may be required.
  23457. maxLength: 253
  23458. minLength: 1
  23459. pattern: ^[-._a-zA-Z0-9]+$
  23460. type: string
  23461. name:
  23462. description: The name of the Secret resource being referred to.
  23463. maxLength: 253
  23464. minLength: 1
  23465. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23466. type: string
  23467. namespace:
  23468. description: |-
  23469. The namespace of the Secret resource being referred to.
  23470. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23471. maxLength: 63
  23472. minLength: 1
  23473. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23474. type: string
  23475. type: object
  23476. secretAccessKeySecretRef:
  23477. description: The SecretAccessKey is used for authentication
  23478. properties:
  23479. key:
  23480. description: |-
  23481. A key in the referenced Secret.
  23482. Some instances of this field may be defaulted, in others it may be required.
  23483. maxLength: 253
  23484. minLength: 1
  23485. pattern: ^[-._a-zA-Z0-9]+$
  23486. type: string
  23487. name:
  23488. description: The name of the Secret resource being referred to.
  23489. maxLength: 253
  23490. minLength: 1
  23491. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23492. type: string
  23493. namespace:
  23494. description: |-
  23495. The namespace of the Secret resource being referred to.
  23496. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23497. maxLength: 63
  23498. minLength: 1
  23499. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23500. type: string
  23501. type: object
  23502. sessionTokenSecretRef:
  23503. description: |-
  23504. The SessionToken used for authentication
  23505. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  23506. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  23507. properties:
  23508. key:
  23509. description: |-
  23510. A key in the referenced Secret.
  23511. Some instances of this field may be defaulted, in others it may be required.
  23512. maxLength: 253
  23513. minLength: 1
  23514. pattern: ^[-._a-zA-Z0-9]+$
  23515. type: string
  23516. name:
  23517. description: The name of the Secret resource being referred to.
  23518. maxLength: 253
  23519. minLength: 1
  23520. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23521. type: string
  23522. namespace:
  23523. description: |-
  23524. The namespace of the Secret resource being referred to.
  23525. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23526. maxLength: 63
  23527. minLength: 1
  23528. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23529. type: string
  23530. type: object
  23531. type: object
  23532. type: object
  23533. externalID:
  23534. description: AWS External ID set on assumed IAM roles
  23535. type: string
  23536. prefix:
  23537. description: Prefix adds a prefix to all retrieved values.
  23538. type: string
  23539. region:
  23540. description: AWS Region to be used for the provider
  23541. type: string
  23542. role:
  23543. description: Role is a Role ARN which the provider will assume
  23544. type: string
  23545. secretsManager:
  23546. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  23547. properties:
  23548. forceDeleteWithoutRecovery:
  23549. description: |-
  23550. Specifies whether to delete the secret without any recovery window. You
  23551. can't use both this parameter and RecoveryWindowInDays in the same call.
  23552. If you don't use either, then by default Secrets Manager uses a 30 day
  23553. recovery window.
  23554. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  23555. type: boolean
  23556. recoveryWindowInDays:
  23557. description: |-
  23558. The number of days from 7 to 30 that Secrets Manager waits before
  23559. permanently deleting the secret. You can't use both this parameter and
  23560. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  23561. then by default Secrets Manager uses a 30 day recovery window.
  23562. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  23563. format: int64
  23564. type: integer
  23565. type: object
  23566. service:
  23567. description: Service defines which service should be used to fetch the secrets
  23568. enum:
  23569. - SecretsManager
  23570. - ParameterStore
  23571. type: string
  23572. sessionTags:
  23573. description: AWS STS assume role session tags
  23574. items:
  23575. description: Tag defines a tag key and value for AWS resources.
  23576. properties:
  23577. key:
  23578. type: string
  23579. value:
  23580. type: string
  23581. required:
  23582. - key
  23583. - value
  23584. type: object
  23585. type: array
  23586. transitiveTagKeys:
  23587. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  23588. items:
  23589. type: string
  23590. type: array
  23591. required:
  23592. - region
  23593. - service
  23594. type: object
  23595. azurekv:
  23596. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  23597. properties:
  23598. authSecretRef:
  23599. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  23600. properties:
  23601. clientCertificate:
  23602. description: The Azure ClientCertificate of the service principle used for authentication.
  23603. properties:
  23604. key:
  23605. description: |-
  23606. A key in the referenced Secret.
  23607. Some instances of this field may be defaulted, in others it may be required.
  23608. maxLength: 253
  23609. minLength: 1
  23610. pattern: ^[-._a-zA-Z0-9]+$
  23611. type: string
  23612. name:
  23613. description: The name of the Secret resource being referred to.
  23614. maxLength: 253
  23615. minLength: 1
  23616. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23617. type: string
  23618. namespace:
  23619. description: |-
  23620. The namespace of the Secret resource being referred to.
  23621. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23622. maxLength: 63
  23623. minLength: 1
  23624. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23625. type: string
  23626. type: object
  23627. clientId:
  23628. description: The Azure clientId of the service principle or managed identity used for authentication.
  23629. properties:
  23630. key:
  23631. description: |-
  23632. A key in the referenced Secret.
  23633. Some instances of this field may be defaulted, in others it may be required.
  23634. maxLength: 253
  23635. minLength: 1
  23636. pattern: ^[-._a-zA-Z0-9]+$
  23637. type: string
  23638. name:
  23639. description: The name of the Secret resource being referred to.
  23640. maxLength: 253
  23641. minLength: 1
  23642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23643. type: string
  23644. namespace:
  23645. description: |-
  23646. The namespace of the Secret resource being referred to.
  23647. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23648. maxLength: 63
  23649. minLength: 1
  23650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23651. type: string
  23652. type: object
  23653. clientSecret:
  23654. description: The Azure ClientSecret of the service principle used for authentication.
  23655. properties:
  23656. key:
  23657. description: |-
  23658. A key in the referenced Secret.
  23659. Some instances of this field may be defaulted, in others it may be required.
  23660. maxLength: 253
  23661. minLength: 1
  23662. pattern: ^[-._a-zA-Z0-9]+$
  23663. type: string
  23664. name:
  23665. description: The name of the Secret resource being referred to.
  23666. maxLength: 253
  23667. minLength: 1
  23668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23669. type: string
  23670. namespace:
  23671. description: |-
  23672. The namespace of the Secret resource being referred to.
  23673. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23674. maxLength: 63
  23675. minLength: 1
  23676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23677. type: string
  23678. type: object
  23679. tenantId:
  23680. description: The Azure tenantId of the managed identity used for authentication.
  23681. properties:
  23682. key:
  23683. description: |-
  23684. A key in the referenced Secret.
  23685. Some instances of this field may be defaulted, in others it may be required.
  23686. maxLength: 253
  23687. minLength: 1
  23688. pattern: ^[-._a-zA-Z0-9]+$
  23689. type: string
  23690. name:
  23691. description: The name of the Secret resource being referred to.
  23692. maxLength: 253
  23693. minLength: 1
  23694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23695. type: string
  23696. namespace:
  23697. description: |-
  23698. The namespace of the Secret resource being referred to.
  23699. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23700. maxLength: 63
  23701. minLength: 1
  23702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23703. type: string
  23704. type: object
  23705. type: object
  23706. authType:
  23707. default: ServicePrincipal
  23708. description: |-
  23709. Auth type defines how to authenticate to the keyvault service.
  23710. Valid values are:
  23711. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  23712. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  23713. enum:
  23714. - ServicePrincipal
  23715. - ManagedIdentity
  23716. - WorkloadIdentity
  23717. type: string
  23718. environmentType:
  23719. default: PublicCloud
  23720. description: |-
  23721. EnvironmentType specifies the Azure cloud environment endpoints to use for
  23722. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  23723. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  23724. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  23725. enum:
  23726. - PublicCloud
  23727. - USGovernmentCloud
  23728. - ChinaCloud
  23729. - GermanCloud
  23730. type: string
  23731. identityId:
  23732. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  23733. type: string
  23734. serviceAccountRef:
  23735. description: |-
  23736. ServiceAccountRef specified the service account
  23737. that should be used when authenticating with WorkloadIdentity.
  23738. properties:
  23739. audiences:
  23740. description: |-
  23741. Audience specifies the `aud` claim for the service account token
  23742. Some providers automatically extend the audience field based on well-known annotations for workload
  23743. identity (e.g. IRSA or GCP Workload Identity)
  23744. items:
  23745. type: string
  23746. type: array
  23747. name:
  23748. description: The name of the ServiceAccount resource being referred to.
  23749. maxLength: 253
  23750. minLength: 1
  23751. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23752. type: string
  23753. namespace:
  23754. description: |-
  23755. Namespace of the resource being referred to.
  23756. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23757. maxLength: 63
  23758. minLength: 1
  23759. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23760. type: string
  23761. required:
  23762. - name
  23763. type: object
  23764. tenantId:
  23765. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  23766. type: string
  23767. vaultUrl:
  23768. description: Vault Url from which the secrets to be fetched from.
  23769. type: string
  23770. required:
  23771. - vaultUrl
  23772. type: object
  23773. beyondtrust:
  23774. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  23775. properties:
  23776. auth:
  23777. description: Auth configures how the operator authenticates with Beyondtrust.
  23778. properties:
  23779. apiKey:
  23780. description: APIKey If not provided then ClientID/ClientSecret become required.
  23781. properties:
  23782. secretRef:
  23783. description: SecretRef references a key in a secret that will be used as value.
  23784. properties:
  23785. key:
  23786. description: |-
  23787. A key in the referenced Secret.
  23788. Some instances of this field may be defaulted, in others it may be required.
  23789. maxLength: 253
  23790. minLength: 1
  23791. pattern: ^[-._a-zA-Z0-9]+$
  23792. type: string
  23793. name:
  23794. description: The name of the Secret resource being referred to.
  23795. maxLength: 253
  23796. minLength: 1
  23797. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23798. type: string
  23799. namespace:
  23800. description: |-
  23801. The namespace of the Secret resource being referred to.
  23802. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23803. maxLength: 63
  23804. minLength: 1
  23805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23806. type: string
  23807. type: object
  23808. value:
  23809. description: Value can be specified directly to set a value without using a secret.
  23810. type: string
  23811. type: object
  23812. certificate:
  23813. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  23814. properties:
  23815. secretRef:
  23816. description: SecretRef references a key in a secret that will be used as value.
  23817. properties:
  23818. key:
  23819. description: |-
  23820. A key in the referenced Secret.
  23821. Some instances of this field may be defaulted, in others it may be required.
  23822. maxLength: 253
  23823. minLength: 1
  23824. pattern: ^[-._a-zA-Z0-9]+$
  23825. type: string
  23826. name:
  23827. description: The name of the Secret resource being referred to.
  23828. maxLength: 253
  23829. minLength: 1
  23830. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23831. type: string
  23832. namespace:
  23833. description: |-
  23834. The namespace of the Secret resource being referred to.
  23835. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23836. maxLength: 63
  23837. minLength: 1
  23838. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23839. type: string
  23840. type: object
  23841. value:
  23842. description: Value can be specified directly to set a value without using a secret.
  23843. type: string
  23844. type: object
  23845. certificateKey:
  23846. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  23847. properties:
  23848. secretRef:
  23849. description: SecretRef references a key in a secret that will be used as value.
  23850. properties:
  23851. key:
  23852. description: |-
  23853. A key in the referenced Secret.
  23854. Some instances of this field may be defaulted, in others it may be required.
  23855. maxLength: 253
  23856. minLength: 1
  23857. pattern: ^[-._a-zA-Z0-9]+$
  23858. type: string
  23859. name:
  23860. description: The name of the Secret resource being referred to.
  23861. maxLength: 253
  23862. minLength: 1
  23863. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23864. type: string
  23865. namespace:
  23866. description: |-
  23867. The namespace of the Secret resource being referred to.
  23868. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23869. maxLength: 63
  23870. minLength: 1
  23871. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23872. type: string
  23873. type: object
  23874. value:
  23875. description: Value can be specified directly to set a value without using a secret.
  23876. type: string
  23877. type: object
  23878. clientId:
  23879. description: ClientID is the API OAuth Client ID.
  23880. properties:
  23881. secretRef:
  23882. description: SecretRef references a key in a secret that will be used as value.
  23883. properties:
  23884. key:
  23885. description: |-
  23886. A key in the referenced Secret.
  23887. Some instances of this field may be defaulted, in others it may be required.
  23888. maxLength: 253
  23889. minLength: 1
  23890. pattern: ^[-._a-zA-Z0-9]+$
  23891. type: string
  23892. name:
  23893. description: The name of the Secret resource being referred to.
  23894. maxLength: 253
  23895. minLength: 1
  23896. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23897. type: string
  23898. namespace:
  23899. description: |-
  23900. The namespace of the Secret resource being referred to.
  23901. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23902. maxLength: 63
  23903. minLength: 1
  23904. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23905. type: string
  23906. type: object
  23907. value:
  23908. description: Value can be specified directly to set a value without using a secret.
  23909. type: string
  23910. type: object
  23911. clientSecret:
  23912. description: ClientSecret is the API OAuth Client Secret.
  23913. properties:
  23914. secretRef:
  23915. description: SecretRef references a key in a secret that will be used as value.
  23916. properties:
  23917. key:
  23918. description: |-
  23919. A key in the referenced Secret.
  23920. Some instances of this field may be defaulted, in others it may be required.
  23921. maxLength: 253
  23922. minLength: 1
  23923. pattern: ^[-._a-zA-Z0-9]+$
  23924. type: string
  23925. name:
  23926. description: The name of the Secret resource being referred to.
  23927. maxLength: 253
  23928. minLength: 1
  23929. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23930. type: string
  23931. namespace:
  23932. description: |-
  23933. The namespace of the Secret resource being referred to.
  23934. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23935. maxLength: 63
  23936. minLength: 1
  23937. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23938. type: string
  23939. type: object
  23940. value:
  23941. description: Value can be specified directly to set a value without using a secret.
  23942. type: string
  23943. type: object
  23944. type: object
  23945. server:
  23946. description: Auth configures how API server works.
  23947. properties:
  23948. apiUrl:
  23949. type: string
  23950. apiVersion:
  23951. type: string
  23952. clientTimeOutSeconds:
  23953. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  23954. type: integer
  23955. decrypt:
  23956. default: true
  23957. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  23958. type: boolean
  23959. retrievalType:
  23960. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  23961. type: string
  23962. separator:
  23963. description: A character that separates the folder names.
  23964. type: string
  23965. verifyCA:
  23966. type: boolean
  23967. required:
  23968. - apiUrl
  23969. - verifyCA
  23970. type: object
  23971. required:
  23972. - auth
  23973. - server
  23974. type: object
  23975. bitwardensecretsmanager:
  23976. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  23977. properties:
  23978. apiURL:
  23979. type: string
  23980. auth:
  23981. description: |-
  23982. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  23983. Make sure that the token being used has permissions on the given secret.
  23984. properties:
  23985. secretRef:
  23986. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  23987. properties:
  23988. credentials:
  23989. description: AccessToken used for the bitwarden instance.
  23990. properties:
  23991. key:
  23992. description: |-
  23993. A key in the referenced Secret.
  23994. Some instances of this field may be defaulted, in others it may be required.
  23995. maxLength: 253
  23996. minLength: 1
  23997. pattern: ^[-._a-zA-Z0-9]+$
  23998. type: string
  23999. name:
  24000. description: The name of the Secret resource being referred to.
  24001. maxLength: 253
  24002. minLength: 1
  24003. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24004. type: string
  24005. namespace:
  24006. description: |-
  24007. The namespace of the Secret resource being referred to.
  24008. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24009. maxLength: 63
  24010. minLength: 1
  24011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24012. type: string
  24013. type: object
  24014. required:
  24015. - credentials
  24016. type: object
  24017. required:
  24018. - secretRef
  24019. type: object
  24020. bitwardenServerSDKURL:
  24021. type: string
  24022. caBundle:
  24023. description: |-
  24024. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  24025. can be performed.
  24026. type: string
  24027. caProvider:
  24028. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  24029. properties:
  24030. key:
  24031. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24032. maxLength: 253
  24033. minLength: 1
  24034. pattern: ^[-._a-zA-Z0-9]+$
  24035. type: string
  24036. name:
  24037. description: The name of the object located at the provider type.
  24038. maxLength: 253
  24039. minLength: 1
  24040. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24041. type: string
  24042. namespace:
  24043. description: |-
  24044. The namespace the Provider type is in.
  24045. Can only be defined when used in a ClusterSecretStore.
  24046. maxLength: 63
  24047. minLength: 1
  24048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24049. type: string
  24050. type:
  24051. description: The type of provider to use such as "Secret", or "ConfigMap".
  24052. enum:
  24053. - Secret
  24054. - ConfigMap
  24055. type: string
  24056. required:
  24057. - name
  24058. - type
  24059. type: object
  24060. identityURL:
  24061. type: string
  24062. organizationID:
  24063. description: OrganizationID determines which organization this secret store manages.
  24064. type: string
  24065. projectID:
  24066. description: ProjectID determines which project this secret store manages.
  24067. type: string
  24068. required:
  24069. - auth
  24070. - organizationID
  24071. - projectID
  24072. type: object
  24073. chef:
  24074. description: Chef configures this store to sync secrets with chef server
  24075. properties:
  24076. auth:
  24077. description: Auth defines the information necessary to authenticate against chef Server
  24078. properties:
  24079. secretRef:
  24080. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  24081. properties:
  24082. privateKeySecretRef:
  24083. description: SecretKey is the Signing Key in PEM format, used for authentication.
  24084. properties:
  24085. key:
  24086. description: |-
  24087. A key in the referenced Secret.
  24088. Some instances of this field may be defaulted, in others it may be required.
  24089. maxLength: 253
  24090. minLength: 1
  24091. pattern: ^[-._a-zA-Z0-9]+$
  24092. type: string
  24093. name:
  24094. description: The name of the Secret resource being referred to.
  24095. maxLength: 253
  24096. minLength: 1
  24097. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24098. type: string
  24099. namespace:
  24100. description: |-
  24101. The namespace of the Secret resource being referred to.
  24102. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24103. maxLength: 63
  24104. minLength: 1
  24105. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24106. type: string
  24107. type: object
  24108. required:
  24109. - privateKeySecretRef
  24110. type: object
  24111. required:
  24112. - secretRef
  24113. type: object
  24114. serverUrl:
  24115. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  24116. type: string
  24117. username:
  24118. description: UserName should be the user ID on the chef server
  24119. type: string
  24120. required:
  24121. - auth
  24122. - serverUrl
  24123. - username
  24124. type: object
  24125. cloudrusm:
  24126. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  24127. properties:
  24128. auth:
  24129. description: CSMAuth contains a secretRef for credentials.
  24130. properties:
  24131. secretRef:
  24132. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  24133. properties:
  24134. accessKeyIDSecretRef:
  24135. description: The AccessKeyID is used for authentication
  24136. properties:
  24137. key:
  24138. description: |-
  24139. A key in the referenced Secret.
  24140. Some instances of this field may be defaulted, in others it may be required.
  24141. maxLength: 253
  24142. minLength: 1
  24143. pattern: ^[-._a-zA-Z0-9]+$
  24144. type: string
  24145. name:
  24146. description: The name of the Secret resource being referred to.
  24147. maxLength: 253
  24148. minLength: 1
  24149. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24150. type: string
  24151. namespace:
  24152. description: |-
  24153. The namespace of the Secret resource being referred to.
  24154. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24155. maxLength: 63
  24156. minLength: 1
  24157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24158. type: string
  24159. type: object
  24160. accessKeySecretSecretRef:
  24161. description: The AccessKeySecret is used for authentication
  24162. properties:
  24163. key:
  24164. description: |-
  24165. A key in the referenced Secret.
  24166. Some instances of this field may be defaulted, in others it may be required.
  24167. maxLength: 253
  24168. minLength: 1
  24169. pattern: ^[-._a-zA-Z0-9]+$
  24170. type: string
  24171. name:
  24172. description: The name of the Secret resource being referred to.
  24173. maxLength: 253
  24174. minLength: 1
  24175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24176. type: string
  24177. namespace:
  24178. description: |-
  24179. The namespace of the Secret resource being referred to.
  24180. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24181. maxLength: 63
  24182. minLength: 1
  24183. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24184. type: string
  24185. type: object
  24186. required:
  24187. - accessKeyIDSecretRef
  24188. - accessKeySecretSecretRef
  24189. type: object
  24190. type: object
  24191. projectID:
  24192. description: ProjectID is the project, which the secrets are stored in.
  24193. type: string
  24194. required:
  24195. - auth
  24196. type: object
  24197. conjur:
  24198. description: Conjur configures this store to sync secrets using conjur provider
  24199. properties:
  24200. auth:
  24201. description: Defines authentication settings for connecting to Conjur.
  24202. properties:
  24203. apikey:
  24204. description: Authenticates with Conjur using an API key.
  24205. properties:
  24206. account:
  24207. description: Account is the Conjur organization account name.
  24208. type: string
  24209. apiKeyRef:
  24210. description: |-
  24211. A reference to a specific 'key' containing the Conjur API key
  24212. within a Secret resource. In some instances, `key` is a required field.
  24213. properties:
  24214. key:
  24215. description: |-
  24216. A key in the referenced Secret.
  24217. Some instances of this field may be defaulted, in others it may be required.
  24218. maxLength: 253
  24219. minLength: 1
  24220. pattern: ^[-._a-zA-Z0-9]+$
  24221. type: string
  24222. name:
  24223. description: The name of the Secret resource being referred to.
  24224. maxLength: 253
  24225. minLength: 1
  24226. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24227. type: string
  24228. namespace:
  24229. description: |-
  24230. The namespace of the Secret resource being referred to.
  24231. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24232. maxLength: 63
  24233. minLength: 1
  24234. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24235. type: string
  24236. type: object
  24237. userRef:
  24238. description: |-
  24239. A reference to a specific 'key' containing the Conjur username
  24240. within a Secret resource. In some instances, `key` is a required field.
  24241. properties:
  24242. key:
  24243. description: |-
  24244. A key in the referenced Secret.
  24245. Some instances of this field may be defaulted, in others it may be required.
  24246. maxLength: 253
  24247. minLength: 1
  24248. pattern: ^[-._a-zA-Z0-9]+$
  24249. type: string
  24250. name:
  24251. description: The name of the Secret resource being referred to.
  24252. maxLength: 253
  24253. minLength: 1
  24254. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24255. type: string
  24256. namespace:
  24257. description: |-
  24258. The namespace of the Secret resource being referred to.
  24259. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24260. maxLength: 63
  24261. minLength: 1
  24262. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24263. type: string
  24264. type: object
  24265. required:
  24266. - account
  24267. - apiKeyRef
  24268. - userRef
  24269. type: object
  24270. jwt:
  24271. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  24272. properties:
  24273. account:
  24274. description: Account is the Conjur organization account name.
  24275. type: string
  24276. hostId:
  24277. description: |-
  24278. Optional HostID for JWT authentication. This may be used depending
  24279. on how the Conjur JWT authenticator policy is configured.
  24280. type: string
  24281. secretRef:
  24282. description: |-
  24283. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  24284. authenticate with Conjur using the JWT authentication method.
  24285. properties:
  24286. key:
  24287. description: |-
  24288. A key in the referenced Secret.
  24289. Some instances of this field may be defaulted, in others it may be required.
  24290. maxLength: 253
  24291. minLength: 1
  24292. pattern: ^[-._a-zA-Z0-9]+$
  24293. type: string
  24294. name:
  24295. description: The name of the Secret resource being referred to.
  24296. maxLength: 253
  24297. minLength: 1
  24298. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24299. type: string
  24300. namespace:
  24301. description: |-
  24302. The namespace of the Secret resource being referred to.
  24303. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24304. maxLength: 63
  24305. minLength: 1
  24306. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24307. type: string
  24308. type: object
  24309. serviceAccountRef:
  24310. description: |-
  24311. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  24312. a token for with the `TokenRequest` API.
  24313. properties:
  24314. audiences:
  24315. description: |-
  24316. Audience specifies the `aud` claim for the service account token
  24317. Some providers automatically extend the audience field based on well-known annotations for workload
  24318. identity (e.g. IRSA or GCP Workload Identity)
  24319. items:
  24320. type: string
  24321. type: array
  24322. name:
  24323. description: The name of the ServiceAccount resource being referred to.
  24324. maxLength: 253
  24325. minLength: 1
  24326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24327. type: string
  24328. namespace:
  24329. description: |-
  24330. Namespace of the resource being referred to.
  24331. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24332. maxLength: 63
  24333. minLength: 1
  24334. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24335. type: string
  24336. required:
  24337. - name
  24338. type: object
  24339. serviceID:
  24340. description: The conjur authn jwt webservice id
  24341. type: string
  24342. required:
  24343. - account
  24344. - serviceID
  24345. type: object
  24346. type: object
  24347. caBundle:
  24348. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  24349. type: string
  24350. caProvider:
  24351. description: |-
  24352. Used to provide custom certificate authority (CA) certificates
  24353. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  24354. that contains a PEM-encoded certificate.
  24355. properties:
  24356. key:
  24357. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24358. maxLength: 253
  24359. minLength: 1
  24360. pattern: ^[-._a-zA-Z0-9]+$
  24361. type: string
  24362. name:
  24363. description: The name of the object located at the provider type.
  24364. maxLength: 253
  24365. minLength: 1
  24366. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24367. type: string
  24368. namespace:
  24369. description: |-
  24370. The namespace the Provider type is in.
  24371. Can only be defined when used in a ClusterSecretStore.
  24372. maxLength: 63
  24373. minLength: 1
  24374. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24375. type: string
  24376. type:
  24377. description: The type of provider to use such as "Secret", or "ConfigMap".
  24378. enum:
  24379. - Secret
  24380. - ConfigMap
  24381. type: string
  24382. required:
  24383. - name
  24384. - type
  24385. type: object
  24386. url:
  24387. description: URL is the endpoint of the Conjur instance.
  24388. type: string
  24389. required:
  24390. - auth
  24391. - url
  24392. type: object
  24393. delinea:
  24394. description: |-
  24395. Delinea DevOps Secrets Vault
  24396. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  24397. properties:
  24398. clientId:
  24399. description: ClientID is the non-secret part of the credential.
  24400. properties:
  24401. secretRef:
  24402. description: SecretRef references a key in a secret that will be used as value.
  24403. properties:
  24404. key:
  24405. description: |-
  24406. A key in the referenced Secret.
  24407. Some instances of this field may be defaulted, in others it may be required.
  24408. maxLength: 253
  24409. minLength: 1
  24410. pattern: ^[-._a-zA-Z0-9]+$
  24411. type: string
  24412. name:
  24413. description: The name of the Secret resource being referred to.
  24414. maxLength: 253
  24415. minLength: 1
  24416. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24417. type: string
  24418. namespace:
  24419. description: |-
  24420. The namespace of the Secret resource being referred to.
  24421. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24422. maxLength: 63
  24423. minLength: 1
  24424. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24425. type: string
  24426. type: object
  24427. value:
  24428. description: Value can be specified directly to set a value without using a secret.
  24429. type: string
  24430. type: object
  24431. clientSecret:
  24432. description: ClientSecret is the secret part of the credential.
  24433. properties:
  24434. secretRef:
  24435. description: SecretRef references a key in a secret that will be used as value.
  24436. properties:
  24437. key:
  24438. description: |-
  24439. A key in the referenced Secret.
  24440. Some instances of this field may be defaulted, in others it may be required.
  24441. maxLength: 253
  24442. minLength: 1
  24443. pattern: ^[-._a-zA-Z0-9]+$
  24444. type: string
  24445. name:
  24446. description: The name of the Secret resource being referred to.
  24447. maxLength: 253
  24448. minLength: 1
  24449. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24450. type: string
  24451. namespace:
  24452. description: |-
  24453. The namespace of the Secret resource being referred to.
  24454. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24455. maxLength: 63
  24456. minLength: 1
  24457. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24458. type: string
  24459. type: object
  24460. value:
  24461. description: Value can be specified directly to set a value without using a secret.
  24462. type: string
  24463. type: object
  24464. tenant:
  24465. description: Tenant is the chosen hostname / site name.
  24466. type: string
  24467. tld:
  24468. description: |-
  24469. TLD is based on the server location that was chosen during provisioning.
  24470. If unset, defaults to "com".
  24471. type: string
  24472. urlTemplate:
  24473. description: |-
  24474. URLTemplate
  24475. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  24476. type: string
  24477. required:
  24478. - clientId
  24479. - clientSecret
  24480. - tenant
  24481. type: object
  24482. device42:
  24483. description: Device42 configures this store to sync secrets using the Device42 provider
  24484. properties:
  24485. auth:
  24486. description: Auth configures how secret-manager authenticates with a Device42 instance.
  24487. properties:
  24488. secretRef:
  24489. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  24490. properties:
  24491. credentials:
  24492. description: Username / Password is used for authentication.
  24493. properties:
  24494. key:
  24495. description: |-
  24496. A key in the referenced Secret.
  24497. Some instances of this field may be defaulted, in others it may be required.
  24498. maxLength: 253
  24499. minLength: 1
  24500. pattern: ^[-._a-zA-Z0-9]+$
  24501. type: string
  24502. name:
  24503. description: The name of the Secret resource being referred to.
  24504. maxLength: 253
  24505. minLength: 1
  24506. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24507. type: string
  24508. namespace:
  24509. description: |-
  24510. The namespace of the Secret resource being referred to.
  24511. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24512. maxLength: 63
  24513. minLength: 1
  24514. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24515. type: string
  24516. type: object
  24517. type: object
  24518. required:
  24519. - secretRef
  24520. type: object
  24521. host:
  24522. description: URL configures the Device42 instance URL.
  24523. type: string
  24524. required:
  24525. - auth
  24526. - host
  24527. type: object
  24528. doppler:
  24529. description: Doppler configures this store to sync secrets using the Doppler provider
  24530. properties:
  24531. auth:
  24532. description: Auth configures how the Operator authenticates with the Doppler API
  24533. properties:
  24534. secretRef:
  24535. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  24536. properties:
  24537. dopplerToken:
  24538. description: |-
  24539. The DopplerToken is used for authentication.
  24540. See https://docs.doppler.com/reference/api#authentication for auth token types.
  24541. The Key attribute defaults to dopplerToken if not specified.
  24542. properties:
  24543. key:
  24544. description: |-
  24545. A key in the referenced Secret.
  24546. Some instances of this field may be defaulted, in others it may be required.
  24547. maxLength: 253
  24548. minLength: 1
  24549. pattern: ^[-._a-zA-Z0-9]+$
  24550. type: string
  24551. name:
  24552. description: The name of the Secret resource being referred to.
  24553. maxLength: 253
  24554. minLength: 1
  24555. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24556. type: string
  24557. namespace:
  24558. description: |-
  24559. The namespace of the Secret resource being referred to.
  24560. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24561. maxLength: 63
  24562. minLength: 1
  24563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24564. type: string
  24565. type: object
  24566. required:
  24567. - dopplerToken
  24568. type: object
  24569. required:
  24570. - secretRef
  24571. type: object
  24572. config:
  24573. description: Doppler config (required if not using a Service Token)
  24574. type: string
  24575. format:
  24576. description: Format enables the downloading of secrets as a file (string)
  24577. enum:
  24578. - json
  24579. - dotnet-json
  24580. - env
  24581. - yaml
  24582. - docker
  24583. type: string
  24584. nameTransformer:
  24585. description: Environment variable compatible name transforms that change secret names to a different format
  24586. enum:
  24587. - upper-camel
  24588. - camel
  24589. - lower-snake
  24590. - tf-var
  24591. - dotnet-env
  24592. - lower-kebab
  24593. type: string
  24594. project:
  24595. description: Doppler project (required if not using a Service Token)
  24596. type: string
  24597. required:
  24598. - auth
  24599. type: object
  24600. fake:
  24601. description: Fake configures a store with static key/value pairs
  24602. properties:
  24603. data:
  24604. items:
  24605. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  24606. properties:
  24607. key:
  24608. type: string
  24609. value:
  24610. type: string
  24611. version:
  24612. type: string
  24613. required:
  24614. - key
  24615. - value
  24616. type: object
  24617. type: array
  24618. required:
  24619. - data
  24620. type: object
  24621. fortanix:
  24622. description: Fortanix configures this store to sync secrets using the Fortanix provider
  24623. properties:
  24624. apiKey:
  24625. description: APIKey is the API token to access SDKMS Applications.
  24626. properties:
  24627. secretRef:
  24628. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  24629. properties:
  24630. key:
  24631. description: |-
  24632. A key in the referenced Secret.
  24633. Some instances of this field may be defaulted, in others it may be required.
  24634. maxLength: 253
  24635. minLength: 1
  24636. pattern: ^[-._a-zA-Z0-9]+$
  24637. type: string
  24638. name:
  24639. description: The name of the Secret resource being referred to.
  24640. maxLength: 253
  24641. minLength: 1
  24642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24643. type: string
  24644. namespace:
  24645. description: |-
  24646. The namespace of the Secret resource being referred to.
  24647. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24648. maxLength: 63
  24649. minLength: 1
  24650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24651. type: string
  24652. type: object
  24653. type: object
  24654. apiUrl:
  24655. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  24656. type: string
  24657. type: object
  24658. gcpsm:
  24659. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  24660. properties:
  24661. auth:
  24662. description: Auth defines the information necessary to authenticate against GCP
  24663. properties:
  24664. secretRef:
  24665. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  24666. properties:
  24667. secretAccessKeySecretRef:
  24668. description: The SecretAccessKey is used for authentication
  24669. properties:
  24670. key:
  24671. description: |-
  24672. A key in the referenced Secret.
  24673. Some instances of this field may be defaulted, in others it may be required.
  24674. maxLength: 253
  24675. minLength: 1
  24676. pattern: ^[-._a-zA-Z0-9]+$
  24677. type: string
  24678. name:
  24679. description: The name of the Secret resource being referred to.
  24680. maxLength: 253
  24681. minLength: 1
  24682. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24683. type: string
  24684. namespace:
  24685. description: |-
  24686. The namespace of the Secret resource being referred to.
  24687. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24688. maxLength: 63
  24689. minLength: 1
  24690. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24691. type: string
  24692. type: object
  24693. type: object
  24694. workloadIdentity:
  24695. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  24696. properties:
  24697. clusterLocation:
  24698. description: |-
  24699. ClusterLocation is the location of the cluster
  24700. If not specified, it fetches information from the metadata server
  24701. type: string
  24702. clusterName:
  24703. description: |-
  24704. ClusterName is the name of the cluster
  24705. If not specified, it fetches information from the metadata server
  24706. type: string
  24707. clusterProjectID:
  24708. description: |-
  24709. ClusterProjectID is the project ID of the cluster
  24710. If not specified, it fetches information from the metadata server
  24711. type: string
  24712. serviceAccountRef:
  24713. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  24714. properties:
  24715. audiences:
  24716. description: |-
  24717. Audience specifies the `aud` claim for the service account token
  24718. Some providers automatically extend the audience field based on well-known annotations for workload
  24719. identity (e.g. IRSA or GCP Workload Identity)
  24720. items:
  24721. type: string
  24722. type: array
  24723. name:
  24724. description: The name of the ServiceAccount resource being referred to.
  24725. maxLength: 253
  24726. minLength: 1
  24727. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24728. type: string
  24729. namespace:
  24730. description: |-
  24731. Namespace of the resource being referred to.
  24732. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24733. maxLength: 63
  24734. minLength: 1
  24735. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24736. type: string
  24737. required:
  24738. - name
  24739. type: object
  24740. required:
  24741. - serviceAccountRef
  24742. type: object
  24743. type: object
  24744. location:
  24745. description: Location optionally defines a location for a secret
  24746. type: string
  24747. projectID:
  24748. description: ProjectID project where secret is located
  24749. type: string
  24750. type: object
  24751. github:
  24752. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  24753. properties:
  24754. appID:
  24755. description: appID specifies the Github APP that will be used to authenticate the client
  24756. format: int64
  24757. type: integer
  24758. auth:
  24759. description: auth configures how secret-manager authenticates with a Github instance.
  24760. properties:
  24761. privateKey:
  24762. description: |-
  24763. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24764. In some instances, `key` is a required field.
  24765. properties:
  24766. key:
  24767. description: |-
  24768. A key in the referenced Secret.
  24769. Some instances of this field may be defaulted, in others it may be required.
  24770. maxLength: 253
  24771. minLength: 1
  24772. pattern: ^[-._a-zA-Z0-9]+$
  24773. type: string
  24774. name:
  24775. description: The name of the Secret resource being referred to.
  24776. maxLength: 253
  24777. minLength: 1
  24778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24779. type: string
  24780. namespace:
  24781. description: |-
  24782. The namespace of the Secret resource being referred to.
  24783. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24784. maxLength: 63
  24785. minLength: 1
  24786. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24787. type: string
  24788. type: object
  24789. required:
  24790. - privateKey
  24791. type: object
  24792. environment:
  24793. description: environment will be used to fetch secrets from a particular environment within a github repository
  24794. type: string
  24795. installationID:
  24796. description: installationID specifies the Github APP installation that will be used to authenticate the client
  24797. format: int64
  24798. type: integer
  24799. organization:
  24800. description: organization will be used to fetch secrets from the Github organization
  24801. type: string
  24802. repository:
  24803. description: repository will be used to fetch secrets from the Github repository within an organization
  24804. type: string
  24805. uploadURL:
  24806. description: Upload URL for enterprise instances. Default to URL.
  24807. type: string
  24808. url:
  24809. default: https://github.com/
  24810. description: URL configures the Github instance URL. Defaults to https://github.com/.
  24811. type: string
  24812. required:
  24813. - appID
  24814. - auth
  24815. - installationID
  24816. - organization
  24817. type: object
  24818. gitlab:
  24819. description: GitLab configures this store to sync secrets using GitLab Variables provider
  24820. properties:
  24821. auth:
  24822. description: Auth configures how secret-manager authenticates with a GitLab instance.
  24823. properties:
  24824. SecretRef:
  24825. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  24826. properties:
  24827. accessToken:
  24828. description: AccessToken is used for authentication.
  24829. properties:
  24830. key:
  24831. description: |-
  24832. A key in the referenced Secret.
  24833. Some instances of this field may be defaulted, in others it may be required.
  24834. maxLength: 253
  24835. minLength: 1
  24836. pattern: ^[-._a-zA-Z0-9]+$
  24837. type: string
  24838. name:
  24839. description: The name of the Secret resource being referred to.
  24840. maxLength: 253
  24841. minLength: 1
  24842. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24843. type: string
  24844. namespace:
  24845. description: |-
  24846. The namespace of the Secret resource being referred to.
  24847. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24848. maxLength: 63
  24849. minLength: 1
  24850. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24851. type: string
  24852. type: object
  24853. type: object
  24854. required:
  24855. - SecretRef
  24856. type: object
  24857. caBundle:
  24858. description: |-
  24859. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  24860. can be performed.
  24861. format: byte
  24862. type: string
  24863. caProvider:
  24864. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  24865. properties:
  24866. key:
  24867. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24868. maxLength: 253
  24869. minLength: 1
  24870. pattern: ^[-._a-zA-Z0-9]+$
  24871. type: string
  24872. name:
  24873. description: The name of the object located at the provider type.
  24874. maxLength: 253
  24875. minLength: 1
  24876. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24877. type: string
  24878. namespace:
  24879. description: |-
  24880. The namespace the Provider type is in.
  24881. Can only be defined when used in a ClusterSecretStore.
  24882. maxLength: 63
  24883. minLength: 1
  24884. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24885. type: string
  24886. type:
  24887. description: The type of provider to use such as "Secret", or "ConfigMap".
  24888. enum:
  24889. - Secret
  24890. - ConfigMap
  24891. type: string
  24892. required:
  24893. - name
  24894. - type
  24895. type: object
  24896. environment:
  24897. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  24898. type: string
  24899. groupIDs:
  24900. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  24901. items:
  24902. type: string
  24903. type: array
  24904. inheritFromGroups:
  24905. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  24906. type: boolean
  24907. projectID:
  24908. description: ProjectID specifies a project where secrets are located.
  24909. type: string
  24910. url:
  24911. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  24912. type: string
  24913. required:
  24914. - auth
  24915. type: object
  24916. ibm:
  24917. description: IBM configures this store to sync secrets using IBM Cloud provider
  24918. properties:
  24919. auth:
  24920. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  24921. maxProperties: 1
  24922. minProperties: 1
  24923. properties:
  24924. containerAuth:
  24925. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  24926. properties:
  24927. iamEndpoint:
  24928. type: string
  24929. profile:
  24930. description: the IBM Trusted Profile
  24931. type: string
  24932. tokenLocation:
  24933. description: Location the token is mounted on the pod
  24934. type: string
  24935. required:
  24936. - profile
  24937. type: object
  24938. secretRef:
  24939. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  24940. properties:
  24941. secretApiKeySecretRef:
  24942. description: The SecretAccessKey is used for authentication
  24943. properties:
  24944. key:
  24945. description: |-
  24946. A key in the referenced Secret.
  24947. Some instances of this field may be defaulted, in others it may be required.
  24948. maxLength: 253
  24949. minLength: 1
  24950. pattern: ^[-._a-zA-Z0-9]+$
  24951. type: string
  24952. name:
  24953. description: The name of the Secret resource being referred to.
  24954. maxLength: 253
  24955. minLength: 1
  24956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24957. type: string
  24958. namespace:
  24959. description: |-
  24960. The namespace of the Secret resource being referred to.
  24961. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24962. maxLength: 63
  24963. minLength: 1
  24964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24965. type: string
  24966. type: object
  24967. type: object
  24968. type: object
  24969. serviceUrl:
  24970. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  24971. type: string
  24972. required:
  24973. - auth
  24974. type: object
  24975. infisical:
  24976. description: Infisical configures this store to sync secrets using the Infisical provider
  24977. properties:
  24978. auth:
  24979. description: Auth configures how the Operator authenticates with the Infisical API
  24980. properties:
  24981. universalAuthCredentials:
  24982. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  24983. properties:
  24984. clientId:
  24985. description: |-
  24986. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24987. In some instances, `key` is a required field.
  24988. properties:
  24989. key:
  24990. description: |-
  24991. A key in the referenced Secret.
  24992. Some instances of this field may be defaulted, in others it may be required.
  24993. maxLength: 253
  24994. minLength: 1
  24995. pattern: ^[-._a-zA-Z0-9]+$
  24996. type: string
  24997. name:
  24998. description: The name of the Secret resource being referred to.
  24999. maxLength: 253
  25000. minLength: 1
  25001. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25002. type: string
  25003. namespace:
  25004. description: |-
  25005. The namespace of the Secret resource being referred to.
  25006. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25007. maxLength: 63
  25008. minLength: 1
  25009. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25010. type: string
  25011. type: object
  25012. clientSecret:
  25013. description: |-
  25014. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25015. In some instances, `key` is a required field.
  25016. properties:
  25017. key:
  25018. description: |-
  25019. A key in the referenced Secret.
  25020. Some instances of this field may be defaulted, in others it may be required.
  25021. maxLength: 253
  25022. minLength: 1
  25023. pattern: ^[-._a-zA-Z0-9]+$
  25024. type: string
  25025. name:
  25026. description: The name of the Secret resource being referred to.
  25027. maxLength: 253
  25028. minLength: 1
  25029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25030. type: string
  25031. namespace:
  25032. description: |-
  25033. The namespace of the Secret resource being referred to.
  25034. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25035. maxLength: 63
  25036. minLength: 1
  25037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25038. type: string
  25039. type: object
  25040. required:
  25041. - clientId
  25042. - clientSecret
  25043. type: object
  25044. type: object
  25045. hostAPI:
  25046. default: https://app.infisical.com/api
  25047. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  25048. type: string
  25049. secretsScope:
  25050. description: SecretsScope defines the scope of the secrets within the workspace
  25051. properties:
  25052. environmentSlug:
  25053. description: EnvironmentSlug is the required slug identifier for the environment.
  25054. type: string
  25055. expandSecretReferences:
  25056. default: true
  25057. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  25058. type: boolean
  25059. projectSlug:
  25060. description: ProjectSlug is the required slug identifier for the project.
  25061. type: string
  25062. recursive:
  25063. default: false
  25064. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  25065. type: boolean
  25066. secretsPath:
  25067. default: /
  25068. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  25069. type: string
  25070. required:
  25071. - environmentSlug
  25072. - projectSlug
  25073. type: object
  25074. required:
  25075. - auth
  25076. - secretsScope
  25077. type: object
  25078. keepersecurity:
  25079. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  25080. properties:
  25081. authRef:
  25082. description: |-
  25083. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25084. In some instances, `key` is a required field.
  25085. properties:
  25086. key:
  25087. description: |-
  25088. A key in the referenced Secret.
  25089. Some instances of this field may be defaulted, in others it may be required.
  25090. maxLength: 253
  25091. minLength: 1
  25092. pattern: ^[-._a-zA-Z0-9]+$
  25093. type: string
  25094. name:
  25095. description: The name of the Secret resource being referred to.
  25096. maxLength: 253
  25097. minLength: 1
  25098. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25099. type: string
  25100. namespace:
  25101. description: |-
  25102. The namespace of the Secret resource being referred to.
  25103. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25104. maxLength: 63
  25105. minLength: 1
  25106. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25107. type: string
  25108. type: object
  25109. folderID:
  25110. type: string
  25111. required:
  25112. - authRef
  25113. - folderID
  25114. type: object
  25115. kubernetes:
  25116. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  25117. properties:
  25118. auth:
  25119. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  25120. maxProperties: 1
  25121. minProperties: 1
  25122. properties:
  25123. cert:
  25124. description: has both clientCert and clientKey as secretKeySelector
  25125. properties:
  25126. clientCert:
  25127. description: |-
  25128. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25129. In some instances, `key` is a required field.
  25130. properties:
  25131. key:
  25132. description: |-
  25133. A key in the referenced Secret.
  25134. Some instances of this field may be defaulted, in others it may be required.
  25135. maxLength: 253
  25136. minLength: 1
  25137. pattern: ^[-._a-zA-Z0-9]+$
  25138. type: string
  25139. name:
  25140. description: The name of the Secret resource being referred to.
  25141. maxLength: 253
  25142. minLength: 1
  25143. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25144. type: string
  25145. namespace:
  25146. description: |-
  25147. The namespace of the Secret resource being referred to.
  25148. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25149. maxLength: 63
  25150. minLength: 1
  25151. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25152. type: string
  25153. type: object
  25154. clientKey:
  25155. description: |-
  25156. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25157. In some instances, `key` is a required field.
  25158. properties:
  25159. key:
  25160. description: |-
  25161. A key in the referenced Secret.
  25162. Some instances of this field may be defaulted, in others it may be required.
  25163. maxLength: 253
  25164. minLength: 1
  25165. pattern: ^[-._a-zA-Z0-9]+$
  25166. type: string
  25167. name:
  25168. description: The name of the Secret resource being referred to.
  25169. maxLength: 253
  25170. minLength: 1
  25171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25172. type: string
  25173. namespace:
  25174. description: |-
  25175. The namespace of the Secret resource being referred to.
  25176. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25177. maxLength: 63
  25178. minLength: 1
  25179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25180. type: string
  25181. type: object
  25182. type: object
  25183. serviceAccount:
  25184. description: points to a service account that should be used for authentication
  25185. properties:
  25186. audiences:
  25187. description: |-
  25188. Audience specifies the `aud` claim for the service account token
  25189. Some providers automatically extend the audience field based on well-known annotations for workload
  25190. identity (e.g. IRSA or GCP Workload Identity)
  25191. items:
  25192. type: string
  25193. type: array
  25194. name:
  25195. description: The name of the ServiceAccount resource being referred to.
  25196. maxLength: 253
  25197. minLength: 1
  25198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25199. type: string
  25200. namespace:
  25201. description: |-
  25202. Namespace of the resource being referred to.
  25203. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25204. maxLength: 63
  25205. minLength: 1
  25206. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25207. type: string
  25208. required:
  25209. - name
  25210. type: object
  25211. token:
  25212. description: use static token to authenticate with
  25213. properties:
  25214. bearerToken:
  25215. description: |-
  25216. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25217. In some instances, `key` is a required field.
  25218. properties:
  25219. key:
  25220. description: |-
  25221. A key in the referenced Secret.
  25222. Some instances of this field may be defaulted, in others it may be required.
  25223. maxLength: 253
  25224. minLength: 1
  25225. pattern: ^[-._a-zA-Z0-9]+$
  25226. type: string
  25227. name:
  25228. description: The name of the Secret resource being referred to.
  25229. maxLength: 253
  25230. minLength: 1
  25231. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25232. type: string
  25233. namespace:
  25234. description: |-
  25235. The namespace of the Secret resource being referred to.
  25236. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25237. maxLength: 63
  25238. minLength: 1
  25239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25240. type: string
  25241. type: object
  25242. type: object
  25243. type: object
  25244. authRef:
  25245. description: A reference to a secret that contains the auth information.
  25246. properties:
  25247. key:
  25248. description: |-
  25249. A key in the referenced Secret.
  25250. Some instances of this field may be defaulted, in others it may be required.
  25251. maxLength: 253
  25252. minLength: 1
  25253. pattern: ^[-._a-zA-Z0-9]+$
  25254. type: string
  25255. name:
  25256. description: The name of the Secret resource being referred to.
  25257. maxLength: 253
  25258. minLength: 1
  25259. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25260. type: string
  25261. namespace:
  25262. description: |-
  25263. The namespace of the Secret resource being referred to.
  25264. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25265. maxLength: 63
  25266. minLength: 1
  25267. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25268. type: string
  25269. type: object
  25270. remoteNamespace:
  25271. default: default
  25272. description: Remote namespace to fetch the secrets from
  25273. maxLength: 63
  25274. minLength: 1
  25275. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25276. type: string
  25277. server:
  25278. description: configures the Kubernetes server Address.
  25279. properties:
  25280. caBundle:
  25281. description: CABundle is a base64-encoded CA certificate
  25282. format: byte
  25283. type: string
  25284. caProvider:
  25285. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  25286. properties:
  25287. key:
  25288. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  25289. maxLength: 253
  25290. minLength: 1
  25291. pattern: ^[-._a-zA-Z0-9]+$
  25292. type: string
  25293. name:
  25294. description: The name of the object located at the provider type.
  25295. maxLength: 253
  25296. minLength: 1
  25297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25298. type: string
  25299. namespace:
  25300. description: |-
  25301. The namespace the Provider type is in.
  25302. Can only be defined when used in a ClusterSecretStore.
  25303. maxLength: 63
  25304. minLength: 1
  25305. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25306. type: string
  25307. type:
  25308. description: The type of provider to use such as "Secret", or "ConfigMap".
  25309. enum:
  25310. - Secret
  25311. - ConfigMap
  25312. type: string
  25313. required:
  25314. - name
  25315. - type
  25316. type: object
  25317. url:
  25318. default: kubernetes.default
  25319. description: configures the Kubernetes server Address.
  25320. type: string
  25321. type: object
  25322. type: object
  25323. onboardbase:
  25324. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  25325. properties:
  25326. apiHost:
  25327. default: https://public.onboardbase.com/api/v1/
  25328. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  25329. type: string
  25330. auth:
  25331. description: Auth configures how the Operator authenticates with the Onboardbase API
  25332. properties:
  25333. apiKeyRef:
  25334. description: |-
  25335. OnboardbaseAPIKey is the APIKey generated by an admin account.
  25336. It is used to recognize and authorize access to a project and environment within onboardbase
  25337. properties:
  25338. key:
  25339. description: |-
  25340. A key in the referenced Secret.
  25341. Some instances of this field may be defaulted, in others it may be required.
  25342. maxLength: 253
  25343. minLength: 1
  25344. pattern: ^[-._a-zA-Z0-9]+$
  25345. type: string
  25346. name:
  25347. description: The name of the Secret resource being referred to.
  25348. maxLength: 253
  25349. minLength: 1
  25350. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25351. type: string
  25352. namespace:
  25353. description: |-
  25354. The namespace of the Secret resource being referred to.
  25355. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25356. maxLength: 63
  25357. minLength: 1
  25358. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25359. type: string
  25360. type: object
  25361. passcodeRef:
  25362. description: OnboardbasePasscode is the passcode attached to the API Key
  25363. properties:
  25364. key:
  25365. description: |-
  25366. A key in the referenced Secret.
  25367. Some instances of this field may be defaulted, in others it may be required.
  25368. maxLength: 253
  25369. minLength: 1
  25370. pattern: ^[-._a-zA-Z0-9]+$
  25371. type: string
  25372. name:
  25373. description: The name of the Secret resource being referred to.
  25374. maxLength: 253
  25375. minLength: 1
  25376. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25377. type: string
  25378. namespace:
  25379. description: |-
  25380. The namespace of the Secret resource being referred to.
  25381. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25382. maxLength: 63
  25383. minLength: 1
  25384. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25385. type: string
  25386. type: object
  25387. required:
  25388. - apiKeyRef
  25389. - passcodeRef
  25390. type: object
  25391. environment:
  25392. default: development
  25393. description: Environment is the name of an environmnent within a project to pull the secrets from
  25394. type: string
  25395. project:
  25396. default: development
  25397. description: Project is an onboardbase project that the secrets should be pulled from
  25398. type: string
  25399. required:
  25400. - apiHost
  25401. - auth
  25402. - environment
  25403. - project
  25404. type: object
  25405. onepassword:
  25406. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  25407. properties:
  25408. auth:
  25409. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  25410. properties:
  25411. secretRef:
  25412. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  25413. properties:
  25414. connectTokenSecretRef:
  25415. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  25416. properties:
  25417. key:
  25418. description: |-
  25419. A key in the referenced Secret.
  25420. Some instances of this field may be defaulted, in others it may be required.
  25421. maxLength: 253
  25422. minLength: 1
  25423. pattern: ^[-._a-zA-Z0-9]+$
  25424. type: string
  25425. name:
  25426. description: The name of the Secret resource being referred to.
  25427. maxLength: 253
  25428. minLength: 1
  25429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25430. type: string
  25431. namespace:
  25432. description: |-
  25433. The namespace of the Secret resource being referred to.
  25434. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25435. maxLength: 63
  25436. minLength: 1
  25437. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25438. type: string
  25439. type: object
  25440. required:
  25441. - connectTokenSecretRef
  25442. type: object
  25443. required:
  25444. - secretRef
  25445. type: object
  25446. connectHost:
  25447. description: ConnectHost defines the OnePassword Connect Server to connect to
  25448. type: string
  25449. vaults:
  25450. additionalProperties:
  25451. type: integer
  25452. description: Vaults defines which OnePassword vaults to search in which order
  25453. type: object
  25454. required:
  25455. - auth
  25456. - connectHost
  25457. - vaults
  25458. type: object
  25459. oracle:
  25460. description: Oracle configures this store to sync secrets using Oracle Vault provider
  25461. properties:
  25462. auth:
  25463. description: |-
  25464. Auth configures how secret-manager authenticates with the Oracle Vault.
  25465. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  25466. properties:
  25467. secretRef:
  25468. description: SecretRef to pass through sensitive information.
  25469. properties:
  25470. fingerprint:
  25471. description: Fingerprint is the fingerprint of the API private key.
  25472. properties:
  25473. key:
  25474. description: |-
  25475. A key in the referenced Secret.
  25476. Some instances of this field may be defaulted, in others it may be required.
  25477. maxLength: 253
  25478. minLength: 1
  25479. pattern: ^[-._a-zA-Z0-9]+$
  25480. type: string
  25481. name:
  25482. description: The name of the Secret resource being referred to.
  25483. maxLength: 253
  25484. minLength: 1
  25485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25486. type: string
  25487. namespace:
  25488. description: |-
  25489. The namespace of the Secret resource being referred to.
  25490. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25491. maxLength: 63
  25492. minLength: 1
  25493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25494. type: string
  25495. type: object
  25496. privatekey:
  25497. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  25498. properties:
  25499. key:
  25500. description: |-
  25501. A key in the referenced Secret.
  25502. Some instances of this field may be defaulted, in others it may be required.
  25503. maxLength: 253
  25504. minLength: 1
  25505. pattern: ^[-._a-zA-Z0-9]+$
  25506. type: string
  25507. name:
  25508. description: The name of the Secret resource being referred to.
  25509. maxLength: 253
  25510. minLength: 1
  25511. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25512. type: string
  25513. namespace:
  25514. description: |-
  25515. The namespace of the Secret resource being referred to.
  25516. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25517. maxLength: 63
  25518. minLength: 1
  25519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25520. type: string
  25521. type: object
  25522. required:
  25523. - fingerprint
  25524. - privatekey
  25525. type: object
  25526. tenancy:
  25527. description: Tenancy is the tenancy OCID where user is located.
  25528. type: string
  25529. user:
  25530. description: User is an access OCID specific to the account.
  25531. type: string
  25532. required:
  25533. - secretRef
  25534. - tenancy
  25535. - user
  25536. type: object
  25537. compartment:
  25538. description: |-
  25539. Compartment is the vault compartment OCID.
  25540. Required for PushSecret
  25541. type: string
  25542. encryptionKey:
  25543. description: |-
  25544. EncryptionKey is the OCID of the encryption key within the vault.
  25545. Required for PushSecret
  25546. type: string
  25547. principalType:
  25548. description: |-
  25549. The type of principal to use for authentication. If left blank, the Auth struct will
  25550. determine the principal type. This optional field must be specified if using
  25551. workload identity.
  25552. enum:
  25553. - ""
  25554. - UserPrincipal
  25555. - InstancePrincipal
  25556. - Workload
  25557. type: string
  25558. region:
  25559. description: Region is the region where vault is located.
  25560. type: string
  25561. serviceAccountRef:
  25562. description: |-
  25563. ServiceAccountRef specified the service account
  25564. that should be used when authenticating with WorkloadIdentity.
  25565. properties:
  25566. audiences:
  25567. description: |-
  25568. Audience specifies the `aud` claim for the service account token
  25569. Some providers automatically extend the audience field based on well-known annotations for workload
  25570. identity (e.g. IRSA or GCP Workload Identity)
  25571. items:
  25572. type: string
  25573. type: array
  25574. name:
  25575. description: The name of the ServiceAccount resource being referred to.
  25576. maxLength: 253
  25577. minLength: 1
  25578. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25579. type: string
  25580. namespace:
  25581. description: |-
  25582. Namespace of the resource being referred to.
  25583. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25584. maxLength: 63
  25585. minLength: 1
  25586. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25587. type: string
  25588. required:
  25589. - name
  25590. type: object
  25591. vault:
  25592. description: Vault is the vault's OCID of the specific vault where secret is located.
  25593. type: string
  25594. required:
  25595. - region
  25596. - vault
  25597. type: object
  25598. passbolt:
  25599. description: PassboltProvider defines configuration for the Passbolt provider.
  25600. properties:
  25601. auth:
  25602. description: Auth defines the information necessary to authenticate against Passbolt Server
  25603. properties:
  25604. passwordSecretRef:
  25605. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  25606. properties:
  25607. key:
  25608. description: |-
  25609. A key in the referenced Secret.
  25610. Some instances of this field may be defaulted, in others it may be required.
  25611. maxLength: 253
  25612. minLength: 1
  25613. pattern: ^[-._a-zA-Z0-9]+$
  25614. type: string
  25615. name:
  25616. description: The name of the Secret resource being referred to.
  25617. maxLength: 253
  25618. minLength: 1
  25619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25620. type: string
  25621. namespace:
  25622. description: |-
  25623. The namespace of the Secret resource being referred to.
  25624. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25625. maxLength: 63
  25626. minLength: 1
  25627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25628. type: string
  25629. type: object
  25630. privateKeySecretRef:
  25631. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  25632. properties:
  25633. key:
  25634. description: |-
  25635. A key in the referenced Secret.
  25636. Some instances of this field may be defaulted, in others it may be required.
  25637. maxLength: 253
  25638. minLength: 1
  25639. pattern: ^[-._a-zA-Z0-9]+$
  25640. type: string
  25641. name:
  25642. description: The name of the Secret resource being referred to.
  25643. maxLength: 253
  25644. minLength: 1
  25645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25646. type: string
  25647. namespace:
  25648. description: |-
  25649. The namespace of the Secret resource being referred to.
  25650. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25651. maxLength: 63
  25652. minLength: 1
  25653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25654. type: string
  25655. type: object
  25656. required:
  25657. - passwordSecretRef
  25658. - privateKeySecretRef
  25659. type: object
  25660. host:
  25661. description: Host defines the Passbolt Server to connect to
  25662. type: string
  25663. required:
  25664. - auth
  25665. - host
  25666. type: object
  25667. passworddepot:
  25668. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  25669. properties:
  25670. auth:
  25671. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  25672. properties:
  25673. secretRef:
  25674. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  25675. properties:
  25676. credentials:
  25677. description: Username / Password is used for authentication.
  25678. properties:
  25679. key:
  25680. description: |-
  25681. A key in the referenced Secret.
  25682. Some instances of this field may be defaulted, in others it may be required.
  25683. maxLength: 253
  25684. minLength: 1
  25685. pattern: ^[-._a-zA-Z0-9]+$
  25686. type: string
  25687. name:
  25688. description: The name of the Secret resource being referred to.
  25689. maxLength: 253
  25690. minLength: 1
  25691. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25692. type: string
  25693. namespace:
  25694. description: |-
  25695. The namespace of the Secret resource being referred to.
  25696. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25697. maxLength: 63
  25698. minLength: 1
  25699. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25700. type: string
  25701. type: object
  25702. type: object
  25703. required:
  25704. - secretRef
  25705. type: object
  25706. database:
  25707. description: Database to use as source
  25708. type: string
  25709. host:
  25710. description: URL configures the Password Depot instance URL.
  25711. type: string
  25712. required:
  25713. - auth
  25714. - database
  25715. - host
  25716. type: object
  25717. previder:
  25718. description: Previder configures this store to sync secrets using the Previder provider
  25719. properties:
  25720. auth:
  25721. description: PreviderAuth contains a secretRef for credentials.
  25722. properties:
  25723. secretRef:
  25724. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  25725. properties:
  25726. accessToken:
  25727. description: The AccessToken is used for authentication
  25728. properties:
  25729. key:
  25730. description: |-
  25731. A key in the referenced Secret.
  25732. Some instances of this field may be defaulted, in others it may be required.
  25733. maxLength: 253
  25734. minLength: 1
  25735. pattern: ^[-._a-zA-Z0-9]+$
  25736. type: string
  25737. name:
  25738. description: The name of the Secret resource being referred to.
  25739. maxLength: 253
  25740. minLength: 1
  25741. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25742. type: string
  25743. namespace:
  25744. description: |-
  25745. The namespace of the Secret resource being referred to.
  25746. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25747. maxLength: 63
  25748. minLength: 1
  25749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25750. type: string
  25751. type: object
  25752. required:
  25753. - accessToken
  25754. type: object
  25755. type: object
  25756. baseUri:
  25757. type: string
  25758. required:
  25759. - auth
  25760. type: object
  25761. pulumi:
  25762. description: Pulumi configures this store to sync secrets using the Pulumi provider
  25763. properties:
  25764. accessToken:
  25765. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  25766. properties:
  25767. secretRef:
  25768. description: SecretRef is a reference to a secret containing the Pulumi API token.
  25769. properties:
  25770. key:
  25771. description: |-
  25772. A key in the referenced Secret.
  25773. Some instances of this field may be defaulted, in others it may be required.
  25774. maxLength: 253
  25775. minLength: 1
  25776. pattern: ^[-._a-zA-Z0-9]+$
  25777. type: string
  25778. name:
  25779. description: The name of the Secret resource being referred to.
  25780. maxLength: 253
  25781. minLength: 1
  25782. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25783. type: string
  25784. namespace:
  25785. description: |-
  25786. The namespace of the Secret resource being referred to.
  25787. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25788. maxLength: 63
  25789. minLength: 1
  25790. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25791. type: string
  25792. type: object
  25793. type: object
  25794. apiUrl:
  25795. default: https://api.pulumi.com/api/esc
  25796. description: APIURL is the URL of the Pulumi API.
  25797. type: string
  25798. environment:
  25799. description: |-
  25800. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  25801. dynamically retrieved values from supported providers including all major clouds,
  25802. and other Pulumi ESC environments.
  25803. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  25804. type: string
  25805. organization:
  25806. description: |-
  25807. Organization are a space to collaborate on shared projects and stacks.
  25808. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  25809. type: string
  25810. project:
  25811. description: Project is the name of the Pulumi ESC project the environment belongs to.
  25812. type: string
  25813. required:
  25814. - accessToken
  25815. - environment
  25816. - organization
  25817. - project
  25818. type: object
  25819. scaleway:
  25820. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  25821. properties:
  25822. accessKey:
  25823. description: AccessKey is the non-secret part of the api key.
  25824. properties:
  25825. secretRef:
  25826. description: SecretRef references a key in a secret that will be used as value.
  25827. properties:
  25828. key:
  25829. description: |-
  25830. A key in the referenced Secret.
  25831. Some instances of this field may be defaulted, in others it may be required.
  25832. maxLength: 253
  25833. minLength: 1
  25834. pattern: ^[-._a-zA-Z0-9]+$
  25835. type: string
  25836. name:
  25837. description: The name of the Secret resource being referred to.
  25838. maxLength: 253
  25839. minLength: 1
  25840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25841. type: string
  25842. namespace:
  25843. description: |-
  25844. The namespace of the Secret resource being referred to.
  25845. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25846. maxLength: 63
  25847. minLength: 1
  25848. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25849. type: string
  25850. type: object
  25851. value:
  25852. description: Value can be specified directly to set a value without using a secret.
  25853. type: string
  25854. type: object
  25855. apiUrl:
  25856. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  25857. type: string
  25858. projectId:
  25859. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  25860. type: string
  25861. region:
  25862. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  25863. type: string
  25864. secretKey:
  25865. description: SecretKey is the non-secret part of the api key.
  25866. properties:
  25867. secretRef:
  25868. description: SecretRef references a key in a secret that will be used as value.
  25869. properties:
  25870. key:
  25871. description: |-
  25872. A key in the referenced Secret.
  25873. Some instances of this field may be defaulted, in others it may be required.
  25874. maxLength: 253
  25875. minLength: 1
  25876. pattern: ^[-._a-zA-Z0-9]+$
  25877. type: string
  25878. name:
  25879. description: The name of the Secret resource being referred to.
  25880. maxLength: 253
  25881. minLength: 1
  25882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25883. type: string
  25884. namespace:
  25885. description: |-
  25886. The namespace of the Secret resource being referred to.
  25887. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25888. maxLength: 63
  25889. minLength: 1
  25890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25891. type: string
  25892. type: object
  25893. value:
  25894. description: Value can be specified directly to set a value without using a secret.
  25895. type: string
  25896. type: object
  25897. required:
  25898. - accessKey
  25899. - projectId
  25900. - region
  25901. - secretKey
  25902. type: object
  25903. secretserver:
  25904. description: |-
  25905. SecretServer configures this store to sync secrets using SecretServer provider
  25906. https://docs.delinea.com/online-help/secret-server/start.htm
  25907. properties:
  25908. password:
  25909. description: Password is the secret server account password.
  25910. properties:
  25911. secretRef:
  25912. description: SecretRef references a key in a secret that will be used as value.
  25913. properties:
  25914. key:
  25915. description: |-
  25916. A key in the referenced Secret.
  25917. Some instances of this field may be defaulted, in others it may be required.
  25918. maxLength: 253
  25919. minLength: 1
  25920. pattern: ^[-._a-zA-Z0-9]+$
  25921. type: string
  25922. name:
  25923. description: The name of the Secret resource being referred to.
  25924. maxLength: 253
  25925. minLength: 1
  25926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25927. type: string
  25928. namespace:
  25929. description: |-
  25930. The namespace of the Secret resource being referred to.
  25931. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25932. maxLength: 63
  25933. minLength: 1
  25934. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25935. type: string
  25936. type: object
  25937. value:
  25938. description: Value can be specified directly to set a value without using a secret.
  25939. type: string
  25940. type: object
  25941. serverURL:
  25942. description: |-
  25943. ServerURL
  25944. URL to your secret server installation
  25945. type: string
  25946. username:
  25947. description: Username is the secret server account username.
  25948. properties:
  25949. secretRef:
  25950. description: SecretRef references a key in a secret that will be used as value.
  25951. properties:
  25952. key:
  25953. description: |-
  25954. A key in the referenced Secret.
  25955. Some instances of this field may be defaulted, in others it may be required.
  25956. maxLength: 253
  25957. minLength: 1
  25958. pattern: ^[-._a-zA-Z0-9]+$
  25959. type: string
  25960. name:
  25961. description: The name of the Secret resource being referred to.
  25962. maxLength: 253
  25963. minLength: 1
  25964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25965. type: string
  25966. namespace:
  25967. description: |-
  25968. The namespace of the Secret resource being referred to.
  25969. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25970. maxLength: 63
  25971. minLength: 1
  25972. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25973. type: string
  25974. type: object
  25975. value:
  25976. description: Value can be specified directly to set a value without using a secret.
  25977. type: string
  25978. type: object
  25979. required:
  25980. - password
  25981. - serverURL
  25982. - username
  25983. type: object
  25984. senhasegura:
  25985. description: Senhasegura configures this store to sync secrets using senhasegura provider
  25986. properties:
  25987. auth:
  25988. description: Auth defines parameters to authenticate in senhasegura
  25989. properties:
  25990. clientId:
  25991. type: string
  25992. clientSecretSecretRef:
  25993. description: |-
  25994. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25995. In some instances, `key` is a required field.
  25996. properties:
  25997. key:
  25998. description: |-
  25999. A key in the referenced Secret.
  26000. Some instances of this field may be defaulted, in others it may be required.
  26001. maxLength: 253
  26002. minLength: 1
  26003. pattern: ^[-._a-zA-Z0-9]+$
  26004. type: string
  26005. name:
  26006. description: The name of the Secret resource being referred to.
  26007. maxLength: 253
  26008. minLength: 1
  26009. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26010. type: string
  26011. namespace:
  26012. description: |-
  26013. The namespace of the Secret resource being referred to.
  26014. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26015. maxLength: 63
  26016. minLength: 1
  26017. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26018. type: string
  26019. type: object
  26020. required:
  26021. - clientId
  26022. - clientSecretSecretRef
  26023. type: object
  26024. ignoreSslCertificate:
  26025. default: false
  26026. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  26027. type: boolean
  26028. module:
  26029. description: Module defines which senhasegura module should be used to get secrets
  26030. type: string
  26031. url:
  26032. description: URL of senhasegura
  26033. type: string
  26034. required:
  26035. - auth
  26036. - module
  26037. - url
  26038. type: object
  26039. vault:
  26040. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  26041. properties:
  26042. auth:
  26043. description: Auth configures how secret-manager authenticates with the Vault server.
  26044. properties:
  26045. appRole:
  26046. description: |-
  26047. AppRole authenticates with Vault using the App Role auth mechanism,
  26048. with the role and secret stored in a Kubernetes Secret resource.
  26049. properties:
  26050. path:
  26051. default: approle
  26052. description: |-
  26053. Path where the App Role authentication backend is mounted
  26054. in Vault, e.g: "approle"
  26055. type: string
  26056. roleId:
  26057. description: |-
  26058. RoleID configured in the App Role authentication backend when setting
  26059. up the authentication backend in Vault.
  26060. type: string
  26061. roleRef:
  26062. description: |-
  26063. Reference to a key in a Secret that contains the App Role ID used
  26064. to authenticate with Vault.
  26065. The `key` field must be specified and denotes which entry within the Secret
  26066. resource is used as the app role id.
  26067. properties:
  26068. key:
  26069. description: |-
  26070. A key in the referenced Secret.
  26071. Some instances of this field may be defaulted, in others it may be required.
  26072. maxLength: 253
  26073. minLength: 1
  26074. pattern: ^[-._a-zA-Z0-9]+$
  26075. type: string
  26076. name:
  26077. description: The name of the Secret resource being referred to.
  26078. maxLength: 253
  26079. minLength: 1
  26080. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26081. type: string
  26082. namespace:
  26083. description: |-
  26084. The namespace of the Secret resource being referred to.
  26085. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26086. maxLength: 63
  26087. minLength: 1
  26088. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26089. type: string
  26090. type: object
  26091. secretRef:
  26092. description: |-
  26093. Reference to a key in a Secret that contains the App Role secret used
  26094. to authenticate with Vault.
  26095. The `key` field must be specified and denotes which entry within the Secret
  26096. resource is used as the app role secret.
  26097. properties:
  26098. key:
  26099. description: |-
  26100. A key in the referenced Secret.
  26101. Some instances of this field may be defaulted, in others it may be required.
  26102. maxLength: 253
  26103. minLength: 1
  26104. pattern: ^[-._a-zA-Z0-9]+$
  26105. type: string
  26106. name:
  26107. description: The name of the Secret resource being referred to.
  26108. maxLength: 253
  26109. minLength: 1
  26110. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26111. type: string
  26112. namespace:
  26113. description: |-
  26114. The namespace of the Secret resource being referred to.
  26115. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26116. maxLength: 63
  26117. minLength: 1
  26118. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26119. type: string
  26120. type: object
  26121. required:
  26122. - path
  26123. - secretRef
  26124. type: object
  26125. cert:
  26126. description: |-
  26127. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  26128. Cert authentication method
  26129. properties:
  26130. clientCert:
  26131. description: |-
  26132. ClientCert is a certificate to authenticate using the Cert Vault
  26133. authentication method
  26134. properties:
  26135. key:
  26136. description: |-
  26137. A key in the referenced Secret.
  26138. Some instances of this field may be defaulted, in others it may be required.
  26139. maxLength: 253
  26140. minLength: 1
  26141. pattern: ^[-._a-zA-Z0-9]+$
  26142. type: string
  26143. name:
  26144. description: The name of the Secret resource being referred to.
  26145. maxLength: 253
  26146. minLength: 1
  26147. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26148. type: string
  26149. namespace:
  26150. description: |-
  26151. The namespace of the Secret resource being referred to.
  26152. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26153. maxLength: 63
  26154. minLength: 1
  26155. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26156. type: string
  26157. type: object
  26158. secretRef:
  26159. description: |-
  26160. SecretRef to a key in a Secret resource containing client private key to
  26161. authenticate with Vault using the Cert authentication method
  26162. properties:
  26163. key:
  26164. description: |-
  26165. A key in the referenced Secret.
  26166. Some instances of this field may be defaulted, in others it may be required.
  26167. maxLength: 253
  26168. minLength: 1
  26169. pattern: ^[-._a-zA-Z0-9]+$
  26170. type: string
  26171. name:
  26172. description: The name of the Secret resource being referred to.
  26173. maxLength: 253
  26174. minLength: 1
  26175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26176. type: string
  26177. namespace:
  26178. description: |-
  26179. The namespace of the Secret resource being referred to.
  26180. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26181. maxLength: 63
  26182. minLength: 1
  26183. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26184. type: string
  26185. type: object
  26186. type: object
  26187. iam:
  26188. description: |-
  26189. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  26190. AWS IAM authentication method
  26191. properties:
  26192. externalID:
  26193. description: AWS External ID set on assumed IAM roles
  26194. type: string
  26195. jwt:
  26196. description: Specify a service account with IRSA enabled
  26197. properties:
  26198. serviceAccountRef:
  26199. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  26200. properties:
  26201. audiences:
  26202. description: |-
  26203. Audience specifies the `aud` claim for the service account token
  26204. Some providers automatically extend the audience field based on well-known annotations for workload
  26205. identity (e.g. IRSA or GCP Workload Identity)
  26206. items:
  26207. type: string
  26208. type: array
  26209. name:
  26210. description: The name of the ServiceAccount resource being referred to.
  26211. maxLength: 253
  26212. minLength: 1
  26213. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26214. type: string
  26215. namespace:
  26216. description: |-
  26217. Namespace of the resource being referred to.
  26218. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26219. maxLength: 63
  26220. minLength: 1
  26221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26222. type: string
  26223. required:
  26224. - name
  26225. type: object
  26226. type: object
  26227. path:
  26228. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  26229. type: string
  26230. region:
  26231. description: AWS region
  26232. type: string
  26233. role:
  26234. description: This is the AWS role to be assumed before talking to vault
  26235. type: string
  26236. secretRef:
  26237. description: Specify credentials in a Secret object
  26238. properties:
  26239. accessKeyIDSecretRef:
  26240. description: The AccessKeyID is used for authentication
  26241. properties:
  26242. key:
  26243. description: |-
  26244. A key in the referenced Secret.
  26245. Some instances of this field may be defaulted, in others it may be required.
  26246. maxLength: 253
  26247. minLength: 1
  26248. pattern: ^[-._a-zA-Z0-9]+$
  26249. type: string
  26250. name:
  26251. description: The name of the Secret resource being referred to.
  26252. maxLength: 253
  26253. minLength: 1
  26254. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26255. type: string
  26256. namespace:
  26257. description: |-
  26258. The namespace of the Secret resource being referred to.
  26259. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26260. maxLength: 63
  26261. minLength: 1
  26262. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26263. type: string
  26264. type: object
  26265. secretAccessKeySecretRef:
  26266. description: The SecretAccessKey is used for authentication
  26267. properties:
  26268. key:
  26269. description: |-
  26270. A key in the referenced Secret.
  26271. Some instances of this field may be defaulted, in others it may be required.
  26272. maxLength: 253
  26273. minLength: 1
  26274. pattern: ^[-._a-zA-Z0-9]+$
  26275. type: string
  26276. name:
  26277. description: The name of the Secret resource being referred to.
  26278. maxLength: 253
  26279. minLength: 1
  26280. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26281. type: string
  26282. namespace:
  26283. description: |-
  26284. The namespace of the Secret resource being referred to.
  26285. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26286. maxLength: 63
  26287. minLength: 1
  26288. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26289. type: string
  26290. type: object
  26291. sessionTokenSecretRef:
  26292. description: |-
  26293. The SessionToken used for authentication
  26294. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  26295. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  26296. properties:
  26297. key:
  26298. description: |-
  26299. A key in the referenced Secret.
  26300. Some instances of this field may be defaulted, in others it may be required.
  26301. maxLength: 253
  26302. minLength: 1
  26303. pattern: ^[-._a-zA-Z0-9]+$
  26304. type: string
  26305. name:
  26306. description: The name of the Secret resource being referred to.
  26307. maxLength: 253
  26308. minLength: 1
  26309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26310. type: string
  26311. namespace:
  26312. description: |-
  26313. The namespace of the Secret resource being referred to.
  26314. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26315. maxLength: 63
  26316. minLength: 1
  26317. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26318. type: string
  26319. type: object
  26320. type: object
  26321. vaultAwsIamServerID:
  26322. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  26323. type: string
  26324. vaultRole:
  26325. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  26326. type: string
  26327. required:
  26328. - vaultRole
  26329. type: object
  26330. jwt:
  26331. description: |-
  26332. Jwt authenticates with Vault by passing role and JWT token using the
  26333. JWT/OIDC authentication method
  26334. properties:
  26335. kubernetesServiceAccountToken:
  26336. description: |-
  26337. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  26338. a token for with the `TokenRequest` API.
  26339. properties:
  26340. audiences:
  26341. description: |-
  26342. Optional audiences field that will be used to request a temporary Kubernetes service
  26343. account token for the service account referenced by `serviceAccountRef`.
  26344. Defaults to a single audience `vault` it not specified.
  26345. Deprecated: use serviceAccountRef.Audiences instead
  26346. items:
  26347. type: string
  26348. type: array
  26349. expirationSeconds:
  26350. description: |-
  26351. Optional expiration time in seconds that will be used to request a temporary
  26352. Kubernetes service account token for the service account referenced by
  26353. `serviceAccountRef`.
  26354. Deprecated: this will be removed in the future.
  26355. Defaults to 10 minutes.
  26356. format: int64
  26357. type: integer
  26358. serviceAccountRef:
  26359. description: Service account field containing the name of a kubernetes ServiceAccount.
  26360. properties:
  26361. audiences:
  26362. description: |-
  26363. Audience specifies the `aud` claim for the service account token
  26364. Some providers automatically extend the audience field based on well-known annotations for workload
  26365. identity (e.g. IRSA or GCP Workload Identity)
  26366. items:
  26367. type: string
  26368. type: array
  26369. name:
  26370. description: The name of the ServiceAccount resource being referred to.
  26371. maxLength: 253
  26372. minLength: 1
  26373. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26374. type: string
  26375. namespace:
  26376. description: |-
  26377. Namespace of the resource being referred to.
  26378. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26379. maxLength: 63
  26380. minLength: 1
  26381. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26382. type: string
  26383. required:
  26384. - name
  26385. type: object
  26386. required:
  26387. - serviceAccountRef
  26388. type: object
  26389. path:
  26390. default: jwt
  26391. description: |-
  26392. Path where the JWT authentication backend is mounted
  26393. in Vault, e.g: "jwt"
  26394. type: string
  26395. role:
  26396. description: |-
  26397. Role is a JWT role to authenticate using the JWT/OIDC Vault
  26398. authentication method
  26399. type: string
  26400. secretRef:
  26401. description: |-
  26402. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  26403. authenticate with Vault using the JWT/OIDC authentication method.
  26404. properties:
  26405. key:
  26406. description: |-
  26407. A key in the referenced Secret.
  26408. Some instances of this field may be defaulted, in others it may be required.
  26409. maxLength: 253
  26410. minLength: 1
  26411. pattern: ^[-._a-zA-Z0-9]+$
  26412. type: string
  26413. name:
  26414. description: The name of the Secret resource being referred to.
  26415. maxLength: 253
  26416. minLength: 1
  26417. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26418. type: string
  26419. namespace:
  26420. description: |-
  26421. The namespace of the Secret resource being referred to.
  26422. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26423. maxLength: 63
  26424. minLength: 1
  26425. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26426. type: string
  26427. type: object
  26428. required:
  26429. - path
  26430. type: object
  26431. kubernetes:
  26432. description: |-
  26433. Kubernetes authenticates with Vault by passing the ServiceAccount
  26434. token stored in the named Secret resource to the Vault server.
  26435. properties:
  26436. mountPath:
  26437. default: kubernetes
  26438. description: |-
  26439. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  26440. "kubernetes"
  26441. type: string
  26442. role:
  26443. description: |-
  26444. A required field containing the Vault Role to assume. A Role binds a
  26445. Kubernetes ServiceAccount with a set of Vault policies.
  26446. type: string
  26447. secretRef:
  26448. description: |-
  26449. Optional secret field containing a Kubernetes ServiceAccount JWT used
  26450. for authenticating with Vault. If a name is specified without a key,
  26451. `token` is the default. If one is not specified, the one bound to
  26452. the controller will be used.
  26453. properties:
  26454. key:
  26455. description: |-
  26456. A key in the referenced Secret.
  26457. Some instances of this field may be defaulted, in others it may be required.
  26458. maxLength: 253
  26459. minLength: 1
  26460. pattern: ^[-._a-zA-Z0-9]+$
  26461. type: string
  26462. name:
  26463. description: The name of the Secret resource being referred to.
  26464. maxLength: 253
  26465. minLength: 1
  26466. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26467. type: string
  26468. namespace:
  26469. description: |-
  26470. The namespace of the Secret resource being referred to.
  26471. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26472. maxLength: 63
  26473. minLength: 1
  26474. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26475. type: string
  26476. type: object
  26477. serviceAccountRef:
  26478. description: |-
  26479. Optional service account field containing the name of a kubernetes ServiceAccount.
  26480. If the service account is specified, the service account secret token JWT will be used
  26481. for authenticating with Vault. If the service account selector is not supplied,
  26482. the secretRef will be used instead.
  26483. properties:
  26484. audiences:
  26485. description: |-
  26486. Audience specifies the `aud` claim for the service account token
  26487. Some providers automatically extend the audience field based on well-known annotations for workload
  26488. identity (e.g. IRSA or GCP Workload Identity)
  26489. items:
  26490. type: string
  26491. type: array
  26492. name:
  26493. description: The name of the ServiceAccount resource being referred to.
  26494. maxLength: 253
  26495. minLength: 1
  26496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26497. type: string
  26498. namespace:
  26499. description: |-
  26500. Namespace of the resource being referred to.
  26501. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26502. maxLength: 63
  26503. minLength: 1
  26504. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26505. type: string
  26506. required:
  26507. - name
  26508. type: object
  26509. required:
  26510. - mountPath
  26511. - role
  26512. type: object
  26513. ldap:
  26514. description: |-
  26515. Ldap authenticates with Vault by passing username/password pair using
  26516. the LDAP authentication method
  26517. properties:
  26518. path:
  26519. default: ldap
  26520. description: |-
  26521. Path where the LDAP authentication backend is mounted
  26522. in Vault, e.g: "ldap"
  26523. type: string
  26524. secretRef:
  26525. description: |-
  26526. SecretRef to a key in a Secret resource containing password for the LDAP
  26527. user used to authenticate with Vault using the LDAP authentication
  26528. method
  26529. properties:
  26530. key:
  26531. description: |-
  26532. A key in the referenced Secret.
  26533. Some instances of this field may be defaulted, in others it may be required.
  26534. maxLength: 253
  26535. minLength: 1
  26536. pattern: ^[-._a-zA-Z0-9]+$
  26537. type: string
  26538. name:
  26539. description: The name of the Secret resource being referred to.
  26540. maxLength: 253
  26541. minLength: 1
  26542. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26543. type: string
  26544. namespace:
  26545. description: |-
  26546. The namespace of the Secret resource being referred to.
  26547. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26548. maxLength: 63
  26549. minLength: 1
  26550. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26551. type: string
  26552. type: object
  26553. username:
  26554. description: |-
  26555. Username is an LDAP username used to authenticate using the LDAP Vault
  26556. authentication method
  26557. type: string
  26558. required:
  26559. - path
  26560. - username
  26561. type: object
  26562. namespace:
  26563. description: |-
  26564. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  26565. Namespaces is a set of features within Vault Enterprise that allows
  26566. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  26567. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  26568. This will default to Vault.Namespace field if set, or empty otherwise
  26569. type: string
  26570. tokenSecretRef:
  26571. description: TokenSecretRef authenticates with Vault by presenting a token.
  26572. properties:
  26573. key:
  26574. description: |-
  26575. A key in the referenced Secret.
  26576. Some instances of this field may be defaulted, in others it may be required.
  26577. maxLength: 253
  26578. minLength: 1
  26579. pattern: ^[-._a-zA-Z0-9]+$
  26580. type: string
  26581. name:
  26582. description: The name of the Secret resource being referred to.
  26583. maxLength: 253
  26584. minLength: 1
  26585. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26586. type: string
  26587. namespace:
  26588. description: |-
  26589. The namespace of the Secret resource being referred to.
  26590. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26591. maxLength: 63
  26592. minLength: 1
  26593. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26594. type: string
  26595. type: object
  26596. userPass:
  26597. description: UserPass authenticates with Vault by passing username/password pair
  26598. properties:
  26599. path:
  26600. default: userpass
  26601. description: |-
  26602. Path where the UserPassword authentication backend is mounted
  26603. in Vault, e.g: "userpass"
  26604. type: string
  26605. secretRef:
  26606. description: |-
  26607. SecretRef to a key in a Secret resource containing password for the
  26608. user used to authenticate with Vault using the UserPass authentication
  26609. method
  26610. properties:
  26611. key:
  26612. description: |-
  26613. A key in the referenced Secret.
  26614. Some instances of this field may be defaulted, in others it may be required.
  26615. maxLength: 253
  26616. minLength: 1
  26617. pattern: ^[-._a-zA-Z0-9]+$
  26618. type: string
  26619. name:
  26620. description: The name of the Secret resource being referred to.
  26621. maxLength: 253
  26622. minLength: 1
  26623. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26624. type: string
  26625. namespace:
  26626. description: |-
  26627. The namespace of the Secret resource being referred to.
  26628. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26629. maxLength: 63
  26630. minLength: 1
  26631. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26632. type: string
  26633. type: object
  26634. username:
  26635. description: |-
  26636. Username is a username used to authenticate using the UserPass Vault
  26637. authentication method
  26638. type: string
  26639. required:
  26640. - path
  26641. - username
  26642. type: object
  26643. type: object
  26644. caBundle:
  26645. description: |-
  26646. PEM encoded CA bundle used to validate Vault server certificate. Only used
  26647. if the Server URL is using HTTPS protocol. This parameter is ignored for
  26648. plain HTTP protocol connection. If not set the system root certificates
  26649. are used to validate the TLS connection.
  26650. format: byte
  26651. type: string
  26652. caProvider:
  26653. description: The provider for the CA bundle to use to validate Vault server certificate.
  26654. properties:
  26655. key:
  26656. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26657. maxLength: 253
  26658. minLength: 1
  26659. pattern: ^[-._a-zA-Z0-9]+$
  26660. type: string
  26661. name:
  26662. description: The name of the object located at the provider type.
  26663. maxLength: 253
  26664. minLength: 1
  26665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26666. type: string
  26667. namespace:
  26668. description: |-
  26669. The namespace the Provider type is in.
  26670. Can only be defined when used in a ClusterSecretStore.
  26671. maxLength: 63
  26672. minLength: 1
  26673. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26674. type: string
  26675. type:
  26676. description: The type of provider to use such as "Secret", or "ConfigMap".
  26677. enum:
  26678. - Secret
  26679. - ConfigMap
  26680. type: string
  26681. required:
  26682. - name
  26683. - type
  26684. type: object
  26685. forwardInconsistent:
  26686. description: |-
  26687. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  26688. leader instead of simply retrying within a loop. This can increase performance if
  26689. the option is enabled serverside.
  26690. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  26691. type: boolean
  26692. headers:
  26693. additionalProperties:
  26694. type: string
  26695. description: Headers to be added in Vault request
  26696. type: object
  26697. namespace:
  26698. description: |-
  26699. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  26700. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  26701. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  26702. type: string
  26703. path:
  26704. description: |-
  26705. Path is the mount path of the Vault KV backend endpoint, e.g:
  26706. "secret". The v2 KV secret engine version specific "/data" path suffix
  26707. for fetching secrets from Vault is optional and will be appended
  26708. if not present in specified path.
  26709. type: string
  26710. readYourWrites:
  26711. description: |-
  26712. ReadYourWrites ensures isolated read-after-write semantics by
  26713. providing discovered cluster replication states in each request.
  26714. More information about eventual consistency in Vault can be found here
  26715. https://www.vaultproject.io/docs/enterprise/consistency
  26716. type: boolean
  26717. server:
  26718. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  26719. type: string
  26720. tls:
  26721. description: |-
  26722. The configuration used for client side related TLS communication, when the Vault server
  26723. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  26724. This parameter is ignored for plain HTTP protocol connection.
  26725. It's worth noting this configuration is different from the "TLS certificates auth method",
  26726. which is available under the `auth.cert` section.
  26727. properties:
  26728. certSecretRef:
  26729. description: |-
  26730. CertSecretRef is a certificate added to the transport layer
  26731. when communicating with the Vault server.
  26732. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  26733. properties:
  26734. key:
  26735. description: |-
  26736. A key in the referenced Secret.
  26737. Some instances of this field may be defaulted, in others it may be required.
  26738. maxLength: 253
  26739. minLength: 1
  26740. pattern: ^[-._a-zA-Z0-9]+$
  26741. type: string
  26742. name:
  26743. description: The name of the Secret resource being referred to.
  26744. maxLength: 253
  26745. minLength: 1
  26746. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26747. type: string
  26748. namespace:
  26749. description: |-
  26750. The namespace of the Secret resource being referred to.
  26751. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26752. maxLength: 63
  26753. minLength: 1
  26754. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26755. type: string
  26756. type: object
  26757. keySecretRef:
  26758. description: |-
  26759. KeySecretRef to a key in a Secret resource containing client private key
  26760. added to the transport layer when communicating with the Vault server.
  26761. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  26762. properties:
  26763. key:
  26764. description: |-
  26765. A key in the referenced Secret.
  26766. Some instances of this field may be defaulted, in others it may be required.
  26767. maxLength: 253
  26768. minLength: 1
  26769. pattern: ^[-._a-zA-Z0-9]+$
  26770. type: string
  26771. name:
  26772. description: The name of the Secret resource being referred to.
  26773. maxLength: 253
  26774. minLength: 1
  26775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26776. type: string
  26777. namespace:
  26778. description: |-
  26779. The namespace of the Secret resource being referred to.
  26780. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26781. maxLength: 63
  26782. minLength: 1
  26783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26784. type: string
  26785. type: object
  26786. type: object
  26787. version:
  26788. default: v2
  26789. description: |-
  26790. Version is the Vault KV secret engine version. This can be either "v1" or
  26791. "v2". Version defaults to "v2".
  26792. enum:
  26793. - v1
  26794. - v2
  26795. type: string
  26796. required:
  26797. - server
  26798. type: object
  26799. webhook:
  26800. description: Webhook configures this store to sync secrets using a generic templated webhook
  26801. properties:
  26802. auth:
  26803. description: Auth specifies a authorization protocol. Only one protocol may be set.
  26804. maxProperties: 1
  26805. minProperties: 1
  26806. properties:
  26807. ntlm:
  26808. description: NTLMProtocol configures the store to use NTLM for auth
  26809. properties:
  26810. passwordSecret:
  26811. description: |-
  26812. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26813. In some instances, `key` is a required field.
  26814. properties:
  26815. key:
  26816. description: |-
  26817. A key in the referenced Secret.
  26818. Some instances of this field may be defaulted, in others it may be required.
  26819. maxLength: 253
  26820. minLength: 1
  26821. pattern: ^[-._a-zA-Z0-9]+$
  26822. type: string
  26823. name:
  26824. description: The name of the Secret resource being referred to.
  26825. maxLength: 253
  26826. minLength: 1
  26827. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26828. type: string
  26829. namespace:
  26830. description: |-
  26831. The namespace of the Secret resource being referred to.
  26832. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26833. maxLength: 63
  26834. minLength: 1
  26835. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26836. type: string
  26837. type: object
  26838. usernameSecret:
  26839. description: |-
  26840. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26841. In some instances, `key` is a required field.
  26842. properties:
  26843. key:
  26844. description: |-
  26845. A key in the referenced Secret.
  26846. Some instances of this field may be defaulted, in others it may be required.
  26847. maxLength: 253
  26848. minLength: 1
  26849. pattern: ^[-._a-zA-Z0-9]+$
  26850. type: string
  26851. name:
  26852. description: The name of the Secret resource being referred to.
  26853. maxLength: 253
  26854. minLength: 1
  26855. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26856. type: string
  26857. namespace:
  26858. description: |-
  26859. The namespace of the Secret resource being referred to.
  26860. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26861. maxLength: 63
  26862. minLength: 1
  26863. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26864. type: string
  26865. type: object
  26866. required:
  26867. - passwordSecret
  26868. - usernameSecret
  26869. type: object
  26870. type: object
  26871. body:
  26872. description: Body
  26873. type: string
  26874. caBundle:
  26875. description: |-
  26876. PEM encoded CA bundle used to validate webhook server certificate. Only used
  26877. if the Server URL is using HTTPS protocol. This parameter is ignored for
  26878. plain HTTP protocol connection. If not set the system root certificates
  26879. are used to validate the TLS connection.
  26880. format: byte
  26881. type: string
  26882. caProvider:
  26883. description: The provider for the CA bundle to use to validate webhook server certificate.
  26884. properties:
  26885. key:
  26886. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26887. maxLength: 253
  26888. minLength: 1
  26889. pattern: ^[-._a-zA-Z0-9]+$
  26890. type: string
  26891. name:
  26892. description: The name of the object located at the provider type.
  26893. maxLength: 253
  26894. minLength: 1
  26895. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26896. type: string
  26897. namespace:
  26898. description: The namespace the Provider type is in.
  26899. maxLength: 63
  26900. minLength: 1
  26901. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26902. type: string
  26903. type:
  26904. description: The type of provider to use such as "Secret", or "ConfigMap".
  26905. enum:
  26906. - Secret
  26907. - ConfigMap
  26908. type: string
  26909. required:
  26910. - name
  26911. - type
  26912. type: object
  26913. headers:
  26914. additionalProperties:
  26915. type: string
  26916. description: Headers
  26917. type: object
  26918. method:
  26919. description: Webhook Method
  26920. type: string
  26921. result:
  26922. description: Result formatting
  26923. properties:
  26924. jsonPath:
  26925. description: Json path of return value
  26926. type: string
  26927. type: object
  26928. secrets:
  26929. description: |-
  26930. Secrets to fill in templates
  26931. These secrets will be passed to the templating function as key value pairs under the given name
  26932. items:
  26933. description: WebhookSecret defines a secret to be used in webhook templates.
  26934. properties:
  26935. name:
  26936. description: Name of this secret in templates
  26937. type: string
  26938. secretRef:
  26939. description: Secret ref to fill in credentials
  26940. properties:
  26941. key:
  26942. description: |-
  26943. A key in the referenced Secret.
  26944. Some instances of this field may be defaulted, in others it may be required.
  26945. maxLength: 253
  26946. minLength: 1
  26947. pattern: ^[-._a-zA-Z0-9]+$
  26948. type: string
  26949. name:
  26950. description: The name of the Secret resource being referred to.
  26951. maxLength: 253
  26952. minLength: 1
  26953. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26954. type: string
  26955. namespace:
  26956. description: |-
  26957. The namespace of the Secret resource being referred to.
  26958. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26959. maxLength: 63
  26960. minLength: 1
  26961. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26962. type: string
  26963. type: object
  26964. required:
  26965. - name
  26966. - secretRef
  26967. type: object
  26968. type: array
  26969. timeout:
  26970. description: Timeout
  26971. type: string
  26972. url:
  26973. description: Webhook url to call
  26974. type: string
  26975. required:
  26976. - result
  26977. - url
  26978. type: object
  26979. yandexcertificatemanager:
  26980. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  26981. properties:
  26982. apiEndpoint:
  26983. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  26984. type: string
  26985. auth:
  26986. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  26987. properties:
  26988. authorizedKeySecretRef:
  26989. description: The authorized key used for authentication
  26990. properties:
  26991. key:
  26992. description: |-
  26993. A key in the referenced Secret.
  26994. Some instances of this field may be defaulted, in others it may be required.
  26995. maxLength: 253
  26996. minLength: 1
  26997. pattern: ^[-._a-zA-Z0-9]+$
  26998. type: string
  26999. name:
  27000. description: The name of the Secret resource being referred to.
  27001. maxLength: 253
  27002. minLength: 1
  27003. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27004. type: string
  27005. namespace:
  27006. description: |-
  27007. The namespace of the Secret resource being referred to.
  27008. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27009. maxLength: 63
  27010. minLength: 1
  27011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27012. type: string
  27013. type: object
  27014. type: object
  27015. caProvider:
  27016. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  27017. properties:
  27018. certSecretRef:
  27019. description: |-
  27020. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  27021. In some instances, `key` is a required field.
  27022. properties:
  27023. key:
  27024. description: |-
  27025. A key in the referenced Secret.
  27026. Some instances of this field may be defaulted, in others it may be required.
  27027. maxLength: 253
  27028. minLength: 1
  27029. pattern: ^[-._a-zA-Z0-9]+$
  27030. type: string
  27031. name:
  27032. description: The name of the Secret resource being referred to.
  27033. maxLength: 253
  27034. minLength: 1
  27035. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27036. type: string
  27037. namespace:
  27038. description: |-
  27039. The namespace of the Secret resource being referred to.
  27040. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27041. maxLength: 63
  27042. minLength: 1
  27043. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27044. type: string
  27045. type: object
  27046. type: object
  27047. required:
  27048. - auth
  27049. type: object
  27050. yandexlockbox:
  27051. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  27052. properties:
  27053. apiEndpoint:
  27054. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  27055. type: string
  27056. auth:
  27057. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  27058. properties:
  27059. authorizedKeySecretRef:
  27060. description: The authorized key used for authentication
  27061. properties:
  27062. key:
  27063. description: |-
  27064. A key in the referenced Secret.
  27065. Some instances of this field may be defaulted, in others it may be required.
  27066. maxLength: 253
  27067. minLength: 1
  27068. pattern: ^[-._a-zA-Z0-9]+$
  27069. type: string
  27070. name:
  27071. description: The name of the Secret resource being referred to.
  27072. maxLength: 253
  27073. minLength: 1
  27074. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27075. type: string
  27076. namespace:
  27077. description: |-
  27078. The namespace of the Secret resource being referred to.
  27079. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27080. maxLength: 63
  27081. minLength: 1
  27082. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27083. type: string
  27084. type: object
  27085. type: object
  27086. caProvider:
  27087. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  27088. properties:
  27089. certSecretRef:
  27090. description: |-
  27091. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  27092. In some instances, `key` is a required field.
  27093. properties:
  27094. key:
  27095. description: |-
  27096. A key in the referenced Secret.
  27097. Some instances of this field may be defaulted, in others it may be required.
  27098. maxLength: 253
  27099. minLength: 1
  27100. pattern: ^[-._a-zA-Z0-9]+$
  27101. type: string
  27102. name:
  27103. description: The name of the Secret resource being referred to.
  27104. maxLength: 253
  27105. minLength: 1
  27106. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27107. type: string
  27108. namespace:
  27109. description: |-
  27110. The namespace of the Secret resource being referred to.
  27111. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27112. maxLength: 63
  27113. minLength: 1
  27114. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27115. type: string
  27116. type: object
  27117. type: object
  27118. required:
  27119. - auth
  27120. type: object
  27121. type: object
  27122. refreshInterval:
  27123. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  27124. type: integer
  27125. retrySettings:
  27126. description: Used to configure HTTP retries on failures.
  27127. properties:
  27128. maxRetries:
  27129. description: MaxRetries is the maximum number of retry attempts.
  27130. format: int32
  27131. type: integer
  27132. retryInterval:
  27133. description: RetryInterval is the interval between retry attempts.
  27134. type: string
  27135. type: object
  27136. required:
  27137. - provider
  27138. type: object
  27139. status:
  27140. description: SecretStoreStatus defines the observed state of the SecretStore.
  27141. properties:
  27142. capabilities:
  27143. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  27144. type: string
  27145. conditions:
  27146. items:
  27147. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  27148. properties:
  27149. lastTransitionTime:
  27150. format: date-time
  27151. type: string
  27152. message:
  27153. type: string
  27154. reason:
  27155. type: string
  27156. status:
  27157. type: string
  27158. type:
  27159. description: SecretStoreConditionType represents the condition type of the SecretStore.
  27160. type: string
  27161. required:
  27162. - status
  27163. - type
  27164. type: object
  27165. type: array
  27166. type: object
  27167. type: object
  27168. served: false
  27169. storage: false
  27170. subresources:
  27171. status: {}
  27172. ---
  27173. apiVersion: apiextensions.k8s.io/v1
  27174. kind: CustomResourceDefinition
  27175. metadata:
  27176. annotations:
  27177. controller-gen.kubebuilder.io/version: v0.19.0
  27178. labels:
  27179. external-secrets.io/component: controller
  27180. name: acraccesstokens.generators.external-secrets.io
  27181. spec:
  27182. group: generators.external-secrets.io
  27183. names:
  27184. categories:
  27185. - external-secrets
  27186. - external-secrets-generators
  27187. kind: ACRAccessToken
  27188. listKind: ACRAccessTokenList
  27189. plural: acraccesstokens
  27190. singular: acraccesstoken
  27191. scope: Namespaced
  27192. versions:
  27193. - name: v1alpha1
  27194. schema:
  27195. openAPIV3Schema:
  27196. description: |-
  27197. ACRAccessToken returns an Azure Container Registry token
  27198. that can be used for pushing/pulling images.
  27199. Note: by default it will return an ACR Refresh Token with full access
  27200. (depending on the identity).
  27201. This can be scoped down to the repository level using .spec.scope.
  27202. In case scope is defined it will return an ACR Access Token.
  27203. See docs: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md
  27204. properties:
  27205. apiVersion:
  27206. description: |-
  27207. APIVersion defines the versioned schema of this representation of an object.
  27208. Servers should convert recognized schemas to the latest internal value, and
  27209. may reject unrecognized values.
  27210. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27211. type: string
  27212. kind:
  27213. description: |-
  27214. Kind is a string value representing the REST resource this object represents.
  27215. Servers may infer this from the endpoint the client submits requests to.
  27216. Cannot be updated.
  27217. In CamelCase.
  27218. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27219. type: string
  27220. metadata:
  27221. type: object
  27222. spec:
  27223. description: |-
  27224. ACRAccessTokenSpec defines how to generate the access token
  27225. e.g. how to authenticate and which registry to use.
  27226. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  27227. properties:
  27228. auth:
  27229. description: ACRAuth defines the authentication methods for Azure Container Registry.
  27230. properties:
  27231. managedIdentity:
  27232. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  27233. properties:
  27234. identityId:
  27235. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  27236. type: string
  27237. type: object
  27238. servicePrincipal:
  27239. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  27240. properties:
  27241. secretRef:
  27242. description: |-
  27243. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  27244. It uses static credentials stored in a Kind=Secret.
  27245. properties:
  27246. clientId:
  27247. description: The Azure clientId of the service principle used for authentication.
  27248. properties:
  27249. key:
  27250. description: |-
  27251. A key in the referenced Secret.
  27252. Some instances of this field may be defaulted, in others it may be required.
  27253. maxLength: 253
  27254. minLength: 1
  27255. pattern: ^[-._a-zA-Z0-9]+$
  27256. type: string
  27257. name:
  27258. description: The name of the Secret resource being referred to.
  27259. maxLength: 253
  27260. minLength: 1
  27261. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27262. type: string
  27263. namespace:
  27264. description: |-
  27265. The namespace of the Secret resource being referred to.
  27266. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27267. maxLength: 63
  27268. minLength: 1
  27269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27270. type: string
  27271. type: object
  27272. clientSecret:
  27273. description: The Azure ClientSecret of the service principle used for authentication.
  27274. properties:
  27275. key:
  27276. description: |-
  27277. A key in the referenced Secret.
  27278. Some instances of this field may be defaulted, in others it may be required.
  27279. maxLength: 253
  27280. minLength: 1
  27281. pattern: ^[-._a-zA-Z0-9]+$
  27282. type: string
  27283. name:
  27284. description: The name of the Secret resource being referred to.
  27285. maxLength: 253
  27286. minLength: 1
  27287. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27288. type: string
  27289. namespace:
  27290. description: |-
  27291. The namespace of the Secret resource being referred to.
  27292. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27293. maxLength: 63
  27294. minLength: 1
  27295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27296. type: string
  27297. type: object
  27298. type: object
  27299. required:
  27300. - secretRef
  27301. type: object
  27302. workloadIdentity:
  27303. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  27304. properties:
  27305. serviceAccountRef:
  27306. description: |-
  27307. ServiceAccountRef specified the service account
  27308. that should be used when authenticating with WorkloadIdentity.
  27309. properties:
  27310. audiences:
  27311. description: |-
  27312. Audience specifies the `aud` claim for the service account token
  27313. Some providers automatically extend the audience field based on well-known annotations for workload
  27314. identity (e.g. IRSA or GCP Workload Identity)
  27315. items:
  27316. type: string
  27317. type: array
  27318. name:
  27319. description: The name of the ServiceAccount resource being referred to.
  27320. maxLength: 253
  27321. minLength: 1
  27322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27323. type: string
  27324. namespace:
  27325. description: |-
  27326. Namespace of the resource being referred to.
  27327. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27328. maxLength: 63
  27329. minLength: 1
  27330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27331. type: string
  27332. required:
  27333. - name
  27334. type: object
  27335. type: object
  27336. type: object
  27337. environmentType:
  27338. default: PublicCloud
  27339. description: |-
  27340. EnvironmentType specifies the Azure cloud environment endpoints to use for
  27341. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  27342. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  27343. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  27344. enum:
  27345. - PublicCloud
  27346. - USGovernmentCloud
  27347. - ChinaCloud
  27348. - GermanCloud
  27349. - AzureStackCloud
  27350. type: string
  27351. registry:
  27352. description: |-
  27353. the domain name of the ACR registry
  27354. e.g. foobarexample.azurecr.io
  27355. type: string
  27356. scope:
  27357. description: |-
  27358. Define the scope for the access token, e.g. pull/push access for a repository.
  27359. if not provided it will return a refresh token that has full scope.
  27360. Note: you need to pin it down to the repository level, there is no wildcard available.
  27361. examples:
  27362. repository:my-repository:pull,push
  27363. repository:my-repository:pull
  27364. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  27365. type: string
  27366. tenantId:
  27367. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  27368. type: string
  27369. required:
  27370. - auth
  27371. - registry
  27372. type: object
  27373. type: object
  27374. served: true
  27375. storage: true
  27376. subresources:
  27377. status: {}
  27378. ---
  27379. apiVersion: apiextensions.k8s.io/v1
  27380. kind: CustomResourceDefinition
  27381. metadata:
  27382. annotations:
  27383. controller-gen.kubebuilder.io/version: v0.19.0
  27384. labels:
  27385. external-secrets.io/component: controller
  27386. name: beyondtrustworkloadcredentialsdynamicsecrets.generators.external-secrets.io
  27387. spec:
  27388. group: generators.external-secrets.io
  27389. names:
  27390. categories:
  27391. - external-secrets
  27392. - external-secrets-generators
  27393. kind: BeyondtrustWorkloadCredentialsDynamicSecret
  27394. listKind: BeyondtrustWorkloadCredentialsDynamicSecretList
  27395. plural: beyondtrustworkloadcredentialsdynamicsecrets
  27396. singular: beyondtrustworkloadcredentialsdynamicsecret
  27397. scope: Namespaced
  27398. versions:
  27399. - name: v1alpha1
  27400. schema:
  27401. openAPIV3Schema:
  27402. description: |-
  27403. BeyondtrustWorkloadCredentialsDynamicSecret represents a generator that requests dynamic credentials from BeyondTrust Workload Credentials.
  27404. This generator calls the BeyondTrust Workload Credentials API to generate fresh, temporary credentials
  27405. (such as AWS STS credentials) each time an ExternalSecret is refreshed.
  27406. Dynamic secret definitions must be created in BeyondTrust Workload Credentials before they can be referenced.
  27407. For complete documentation, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27408. properties:
  27409. apiVersion:
  27410. description: |-
  27411. APIVersion defines the versioned schema of this representation of an object.
  27412. Servers should convert recognized schemas to the latest internal value, and
  27413. may reject unrecognized values.
  27414. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27415. type: string
  27416. kind:
  27417. description: |-
  27418. Kind is a string value representing the REST resource this object represents.
  27419. Servers may infer this from the endpoint the client submits requests to.
  27420. Cannot be updated.
  27421. In CamelCase.
  27422. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27423. type: string
  27424. metadata:
  27425. type: object
  27426. spec:
  27427. description: |-
  27428. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  27429. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  27430. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27431. properties:
  27432. controller:
  27433. description: |-
  27434. Controller selects the controller that should handle this generator.
  27435. Leave empty to use the default controller.
  27436. type: string
  27437. provider:
  27438. description: |-
  27439. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  27440. server connection details, and the folder path to the dynamic secret definition.
  27441. The folderPath should point to a dynamic secret definition that has been created in
  27442. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  27443. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27444. properties:
  27445. auth:
  27446. description: |-
  27447. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  27448. Currently supports API key authentication via Kubernetes secret reference.
  27449. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27450. properties:
  27451. apikey:
  27452. description: |-
  27453. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  27454. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  27455. properties:
  27456. token:
  27457. description: |-
  27458. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  27459. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  27460. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  27461. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27462. properties:
  27463. key:
  27464. description: |-
  27465. A key in the referenced Secret.
  27466. Some instances of this field may be defaulted, in others it may be required.
  27467. maxLength: 253
  27468. minLength: 1
  27469. pattern: ^[-._a-zA-Z0-9]+$
  27470. type: string
  27471. name:
  27472. description: The name of the Secret resource being referred to.
  27473. maxLength: 253
  27474. minLength: 1
  27475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27476. type: string
  27477. namespace:
  27478. description: |-
  27479. The namespace of the Secret resource being referred to.
  27480. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27481. maxLength: 63
  27482. minLength: 1
  27483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27484. type: string
  27485. type: object
  27486. required:
  27487. - token
  27488. type: object
  27489. required:
  27490. - apikey
  27491. type: object
  27492. caBundle:
  27493. description: |-
  27494. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27495. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  27496. If not set, the system's trusted root certificates are used.
  27497. format: byte
  27498. type: string
  27499. caProvider:
  27500. description: |-
  27501. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  27502. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27503. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  27504. properties:
  27505. key:
  27506. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  27507. maxLength: 253
  27508. minLength: 1
  27509. pattern: ^[-._a-zA-Z0-9]+$
  27510. type: string
  27511. name:
  27512. description: The name of the object located at the provider type.
  27513. maxLength: 253
  27514. minLength: 1
  27515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27516. type: string
  27517. namespace:
  27518. description: |-
  27519. The namespace the Provider type is in.
  27520. Can only be defined when used in a ClusterSecretStore.
  27521. maxLength: 63
  27522. minLength: 1
  27523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27524. type: string
  27525. type:
  27526. description: The type of provider to use such as "Secret", or "ConfigMap".
  27527. enum:
  27528. - Secret
  27529. - ConfigMap
  27530. type: string
  27531. required:
  27532. - name
  27533. - type
  27534. type: object
  27535. folderPath:
  27536. description: |-
  27537. FolderPath specifies the default folder path for secret retrieval.
  27538. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  27539. Example: "production/database" or "dev/api-keys"
  27540. Leave empty to retrieve secrets from the root folder.
  27541. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  27542. type: string
  27543. server:
  27544. description: |-
  27545. Server configures the BeyondTrust Workload Credentials server connection details.
  27546. Includes the API URL and Site ID for your BeyondTrust instance.
  27547. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27548. properties:
  27549. apiUrl:
  27550. description: |-
  27551. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  27552. This should be the full URL to your BeyondTrust instance.
  27553. Example: https://api.beyondtrust.io/siie
  27554. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  27555. type: string
  27556. siteId:
  27557. description: |-
  27558. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  27559. This identifier is unique to your BeyondTrust Workload Credentials instance.
  27560. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  27561. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  27562. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27563. type: string
  27564. required:
  27565. - apiUrl
  27566. - siteId
  27567. type: object
  27568. required:
  27569. - auth
  27570. - server
  27571. type: object
  27572. retrySettings:
  27573. description: |-
  27574. RetrySettings configures exponential backoff for failed API requests.
  27575. If not specified, uses the default retry settings.
  27576. properties:
  27577. maxRetries:
  27578. format: int32
  27579. type: integer
  27580. retryInterval:
  27581. type: string
  27582. type: object
  27583. required:
  27584. - provider
  27585. type: object
  27586. type: object
  27587. served: true
  27588. storage: true
  27589. subresources:
  27590. status: {}
  27591. ---
  27592. apiVersion: apiextensions.k8s.io/v1
  27593. kind: CustomResourceDefinition
  27594. metadata:
  27595. annotations:
  27596. controller-gen.kubebuilder.io/version: v0.19.0
  27597. labels:
  27598. external-secrets.io/component: controller
  27599. name: cloudsmithaccesstokens.generators.external-secrets.io
  27600. spec:
  27601. group: generators.external-secrets.io
  27602. names:
  27603. categories:
  27604. - external-secrets
  27605. - external-secrets-generators
  27606. kind: CloudsmithAccessToken
  27607. listKind: CloudsmithAccessTokenList
  27608. plural: cloudsmithaccesstokens
  27609. singular: cloudsmithaccesstoken
  27610. scope: Namespaced
  27611. versions:
  27612. - name: v1alpha1
  27613. schema:
  27614. openAPIV3Schema:
  27615. description: CloudsmithAccessToken generates Cloudsmith access token using OIDC authentication
  27616. properties:
  27617. apiVersion:
  27618. description: |-
  27619. APIVersion defines the versioned schema of this representation of an object.
  27620. Servers should convert recognized schemas to the latest internal value, and
  27621. may reject unrecognized values.
  27622. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27623. type: string
  27624. kind:
  27625. description: |-
  27626. Kind is a string value representing the REST resource this object represents.
  27627. Servers may infer this from the endpoint the client submits requests to.
  27628. Cannot be updated.
  27629. In CamelCase.
  27630. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27631. type: string
  27632. metadata:
  27633. type: object
  27634. spec:
  27635. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  27636. properties:
  27637. apiUrl:
  27638. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  27639. type: string
  27640. orgSlug:
  27641. description: OrgSlug is the organization slug in Cloudsmith
  27642. type: string
  27643. serviceAccountRef:
  27644. description: Name of the service account you are federating with
  27645. properties:
  27646. audiences:
  27647. description: |-
  27648. Audience specifies the `aud` claim for the service account token
  27649. Some providers automatically extend the audience field based on well-known annotations for workload
  27650. identity (e.g. IRSA or GCP Workload Identity)
  27651. items:
  27652. type: string
  27653. type: array
  27654. name:
  27655. description: The name of the ServiceAccount resource being referred to.
  27656. maxLength: 253
  27657. minLength: 1
  27658. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27659. type: string
  27660. namespace:
  27661. description: |-
  27662. Namespace of the resource being referred to.
  27663. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27664. maxLength: 63
  27665. minLength: 1
  27666. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27667. type: string
  27668. required:
  27669. - name
  27670. type: object
  27671. serviceSlug:
  27672. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  27673. type: string
  27674. required:
  27675. - orgSlug
  27676. - serviceAccountRef
  27677. - serviceSlug
  27678. type: object
  27679. type: object
  27680. served: true
  27681. storage: true
  27682. subresources:
  27683. status: {}
  27684. ---
  27685. apiVersion: apiextensions.k8s.io/v1
  27686. kind: CustomResourceDefinition
  27687. metadata:
  27688. annotations:
  27689. controller-gen.kubebuilder.io/version: v0.19.0
  27690. labels:
  27691. external-secrets.io/component: controller
  27692. name: clustergenerators.generators.external-secrets.io
  27693. spec:
  27694. group: generators.external-secrets.io
  27695. names:
  27696. categories:
  27697. - external-secrets
  27698. - external-secrets-generators
  27699. kind: ClusterGenerator
  27700. listKind: ClusterGeneratorList
  27701. plural: clustergenerators
  27702. singular: clustergenerator
  27703. scope: Cluster
  27704. versions:
  27705. - name: v1alpha1
  27706. schema:
  27707. openAPIV3Schema:
  27708. description: ClusterGenerator represents a cluster-wide generator which can be referenced as part of `generatorRef` fields.
  27709. properties:
  27710. apiVersion:
  27711. description: |-
  27712. APIVersion defines the versioned schema of this representation of an object.
  27713. Servers should convert recognized schemas to the latest internal value, and
  27714. may reject unrecognized values.
  27715. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27716. type: string
  27717. kind:
  27718. description: |-
  27719. Kind is a string value representing the REST resource this object represents.
  27720. Servers may infer this from the endpoint the client submits requests to.
  27721. Cannot be updated.
  27722. In CamelCase.
  27723. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27724. type: string
  27725. metadata:
  27726. type: object
  27727. spec:
  27728. description: ClusterGeneratorSpec defines the desired state of a ClusterGenerator.
  27729. properties:
  27730. generator:
  27731. description: Generator the spec for this generator, must match the kind.
  27732. maxProperties: 1
  27733. minProperties: 1
  27734. properties:
  27735. acrAccessTokenSpec:
  27736. description: |-
  27737. ACRAccessTokenSpec defines how to generate the access token
  27738. e.g. how to authenticate and which registry to use.
  27739. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  27740. properties:
  27741. auth:
  27742. description: ACRAuth defines the authentication methods for Azure Container Registry.
  27743. properties:
  27744. managedIdentity:
  27745. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  27746. properties:
  27747. identityId:
  27748. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  27749. type: string
  27750. type: object
  27751. servicePrincipal:
  27752. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  27753. properties:
  27754. secretRef:
  27755. description: |-
  27756. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  27757. It uses static credentials stored in a Kind=Secret.
  27758. properties:
  27759. clientId:
  27760. description: The Azure clientId of the service principle used for authentication.
  27761. properties:
  27762. key:
  27763. description: |-
  27764. A key in the referenced Secret.
  27765. Some instances of this field may be defaulted, in others it may be required.
  27766. maxLength: 253
  27767. minLength: 1
  27768. pattern: ^[-._a-zA-Z0-9]+$
  27769. type: string
  27770. name:
  27771. description: The name of the Secret resource being referred to.
  27772. maxLength: 253
  27773. minLength: 1
  27774. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27775. type: string
  27776. namespace:
  27777. description: |-
  27778. The namespace of the Secret resource being referred to.
  27779. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27780. maxLength: 63
  27781. minLength: 1
  27782. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27783. type: string
  27784. type: object
  27785. clientSecret:
  27786. description: The Azure ClientSecret of the service principle used for authentication.
  27787. properties:
  27788. key:
  27789. description: |-
  27790. A key in the referenced Secret.
  27791. Some instances of this field may be defaulted, in others it may be required.
  27792. maxLength: 253
  27793. minLength: 1
  27794. pattern: ^[-._a-zA-Z0-9]+$
  27795. type: string
  27796. name:
  27797. description: The name of the Secret resource being referred to.
  27798. maxLength: 253
  27799. minLength: 1
  27800. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27801. type: string
  27802. namespace:
  27803. description: |-
  27804. The namespace of the Secret resource being referred to.
  27805. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27806. maxLength: 63
  27807. minLength: 1
  27808. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27809. type: string
  27810. type: object
  27811. type: object
  27812. required:
  27813. - secretRef
  27814. type: object
  27815. workloadIdentity:
  27816. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  27817. properties:
  27818. serviceAccountRef:
  27819. description: |-
  27820. ServiceAccountRef specified the service account
  27821. that should be used when authenticating with WorkloadIdentity.
  27822. properties:
  27823. audiences:
  27824. description: |-
  27825. Audience specifies the `aud` claim for the service account token
  27826. Some providers automatically extend the audience field based on well-known annotations for workload
  27827. identity (e.g. IRSA or GCP Workload Identity)
  27828. items:
  27829. type: string
  27830. type: array
  27831. name:
  27832. description: The name of the ServiceAccount resource being referred to.
  27833. maxLength: 253
  27834. minLength: 1
  27835. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27836. type: string
  27837. namespace:
  27838. description: |-
  27839. Namespace of the resource being referred to.
  27840. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27841. maxLength: 63
  27842. minLength: 1
  27843. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27844. type: string
  27845. required:
  27846. - name
  27847. type: object
  27848. type: object
  27849. type: object
  27850. environmentType:
  27851. default: PublicCloud
  27852. description: |-
  27853. EnvironmentType specifies the Azure cloud environment endpoints to use for
  27854. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  27855. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  27856. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  27857. enum:
  27858. - PublicCloud
  27859. - USGovernmentCloud
  27860. - ChinaCloud
  27861. - GermanCloud
  27862. - AzureStackCloud
  27863. type: string
  27864. registry:
  27865. description: |-
  27866. the domain name of the ACR registry
  27867. e.g. foobarexample.azurecr.io
  27868. type: string
  27869. scope:
  27870. description: |-
  27871. Define the scope for the access token, e.g. pull/push access for a repository.
  27872. if not provided it will return a refresh token that has full scope.
  27873. Note: you need to pin it down to the repository level, there is no wildcard available.
  27874. examples:
  27875. repository:my-repository:pull,push
  27876. repository:my-repository:pull
  27877. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  27878. type: string
  27879. tenantId:
  27880. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  27881. type: string
  27882. required:
  27883. - auth
  27884. - registry
  27885. type: object
  27886. beyondtrustWorkloadCredentialsDynamicSecretSpec:
  27887. description: |-
  27888. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  27889. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  27890. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27891. properties:
  27892. controller:
  27893. description: |-
  27894. Controller selects the controller that should handle this generator.
  27895. Leave empty to use the default controller.
  27896. type: string
  27897. provider:
  27898. description: |-
  27899. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  27900. server connection details, and the folder path to the dynamic secret definition.
  27901. The folderPath should point to a dynamic secret definition that has been created in
  27902. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  27903. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27904. properties:
  27905. auth:
  27906. description: |-
  27907. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  27908. Currently supports API key authentication via Kubernetes secret reference.
  27909. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27910. properties:
  27911. apikey:
  27912. description: |-
  27913. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  27914. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  27915. properties:
  27916. token:
  27917. description: |-
  27918. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  27919. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  27920. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  27921. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27922. properties:
  27923. key:
  27924. description: |-
  27925. A key in the referenced Secret.
  27926. Some instances of this field may be defaulted, in others it may be required.
  27927. maxLength: 253
  27928. minLength: 1
  27929. pattern: ^[-._a-zA-Z0-9]+$
  27930. type: string
  27931. name:
  27932. description: The name of the Secret resource being referred to.
  27933. maxLength: 253
  27934. minLength: 1
  27935. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27936. type: string
  27937. namespace:
  27938. description: |-
  27939. The namespace of the Secret resource being referred to.
  27940. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27941. maxLength: 63
  27942. minLength: 1
  27943. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27944. type: string
  27945. type: object
  27946. required:
  27947. - token
  27948. type: object
  27949. required:
  27950. - apikey
  27951. type: object
  27952. caBundle:
  27953. description: |-
  27954. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27955. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  27956. If not set, the system's trusted root certificates are used.
  27957. format: byte
  27958. type: string
  27959. caProvider:
  27960. description: |-
  27961. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  27962. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27963. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  27964. properties:
  27965. key:
  27966. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  27967. maxLength: 253
  27968. minLength: 1
  27969. pattern: ^[-._a-zA-Z0-9]+$
  27970. type: string
  27971. name:
  27972. description: The name of the object located at the provider type.
  27973. maxLength: 253
  27974. minLength: 1
  27975. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27976. type: string
  27977. namespace:
  27978. description: |-
  27979. The namespace the Provider type is in.
  27980. Can only be defined when used in a ClusterSecretStore.
  27981. maxLength: 63
  27982. minLength: 1
  27983. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27984. type: string
  27985. type:
  27986. description: The type of provider to use such as "Secret", or "ConfigMap".
  27987. enum:
  27988. - Secret
  27989. - ConfigMap
  27990. type: string
  27991. required:
  27992. - name
  27993. - type
  27994. type: object
  27995. folderPath:
  27996. description: |-
  27997. FolderPath specifies the default folder path for secret retrieval.
  27998. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  27999. Example: "production/database" or "dev/api-keys"
  28000. Leave empty to retrieve secrets from the root folder.
  28001. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  28002. type: string
  28003. server:
  28004. description: |-
  28005. Server configures the BeyondTrust Workload Credentials server connection details.
  28006. Includes the API URL and Site ID for your BeyondTrust instance.
  28007. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  28008. properties:
  28009. apiUrl:
  28010. description: |-
  28011. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  28012. This should be the full URL to your BeyondTrust instance.
  28013. Example: https://api.beyondtrust.io/siie
  28014. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  28015. type: string
  28016. siteId:
  28017. description: |-
  28018. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  28019. This identifier is unique to your BeyondTrust Workload Credentials instance.
  28020. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  28021. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  28022. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  28023. type: string
  28024. required:
  28025. - apiUrl
  28026. - siteId
  28027. type: object
  28028. required:
  28029. - auth
  28030. - server
  28031. type: object
  28032. retrySettings:
  28033. description: |-
  28034. RetrySettings configures exponential backoff for failed API requests.
  28035. If not specified, uses the default retry settings.
  28036. properties:
  28037. maxRetries:
  28038. format: int32
  28039. type: integer
  28040. retryInterval:
  28041. type: string
  28042. type: object
  28043. required:
  28044. - provider
  28045. type: object
  28046. cloudsmithAccessTokenSpec:
  28047. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  28048. properties:
  28049. apiUrl:
  28050. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  28051. type: string
  28052. orgSlug:
  28053. description: OrgSlug is the organization slug in Cloudsmith
  28054. type: string
  28055. serviceAccountRef:
  28056. description: Name of the service account you are federating with
  28057. properties:
  28058. audiences:
  28059. description: |-
  28060. Audience specifies the `aud` claim for the service account token
  28061. Some providers automatically extend the audience field based on well-known annotations for workload
  28062. identity (e.g. IRSA or GCP Workload Identity)
  28063. items:
  28064. type: string
  28065. type: array
  28066. name:
  28067. description: The name of the ServiceAccount resource being referred to.
  28068. maxLength: 253
  28069. minLength: 1
  28070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28071. type: string
  28072. namespace:
  28073. description: |-
  28074. Namespace of the resource being referred to.
  28075. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28076. maxLength: 63
  28077. minLength: 1
  28078. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28079. type: string
  28080. required:
  28081. - name
  28082. type: object
  28083. serviceSlug:
  28084. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  28085. type: string
  28086. required:
  28087. - orgSlug
  28088. - serviceAccountRef
  28089. - serviceSlug
  28090. type: object
  28091. ecrAuthorizationTokenSpec:
  28092. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  28093. properties:
  28094. auth:
  28095. description: Auth defines how to authenticate with AWS
  28096. properties:
  28097. jwt:
  28098. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  28099. properties:
  28100. serviceAccountRef:
  28101. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28102. properties:
  28103. audiences:
  28104. description: |-
  28105. Audience specifies the `aud` claim for the service account token
  28106. Some providers automatically extend the audience field based on well-known annotations for workload
  28107. identity (e.g. IRSA or GCP Workload Identity)
  28108. items:
  28109. type: string
  28110. type: array
  28111. name:
  28112. description: The name of the ServiceAccount resource being referred to.
  28113. maxLength: 253
  28114. minLength: 1
  28115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28116. type: string
  28117. namespace:
  28118. description: |-
  28119. Namespace of the resource being referred to.
  28120. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28121. maxLength: 63
  28122. minLength: 1
  28123. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28124. type: string
  28125. required:
  28126. - name
  28127. type: object
  28128. type: object
  28129. secretRef:
  28130. description: |-
  28131. AWSAuthSecretRef holds secret references for AWS credentials
  28132. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  28133. properties:
  28134. accessKeyIDSecretRef:
  28135. description: The AccessKeyID is used for authentication
  28136. properties:
  28137. key:
  28138. description: |-
  28139. A key in the referenced Secret.
  28140. Some instances of this field may be defaulted, in others it may be required.
  28141. maxLength: 253
  28142. minLength: 1
  28143. pattern: ^[-._a-zA-Z0-9]+$
  28144. type: string
  28145. name:
  28146. description: The name of the Secret resource being referred to.
  28147. maxLength: 253
  28148. minLength: 1
  28149. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28150. type: string
  28151. namespace:
  28152. description: |-
  28153. The namespace of the Secret resource being referred to.
  28154. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28155. maxLength: 63
  28156. minLength: 1
  28157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28158. type: string
  28159. type: object
  28160. secretAccessKeySecretRef:
  28161. description: The SecretAccessKey is used for authentication
  28162. properties:
  28163. key:
  28164. description: |-
  28165. A key in the referenced Secret.
  28166. Some instances of this field may be defaulted, in others it may be required.
  28167. maxLength: 253
  28168. minLength: 1
  28169. pattern: ^[-._a-zA-Z0-9]+$
  28170. type: string
  28171. name:
  28172. description: The name of the Secret resource being referred to.
  28173. maxLength: 253
  28174. minLength: 1
  28175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28176. type: string
  28177. namespace:
  28178. description: |-
  28179. The namespace of the Secret resource being referred to.
  28180. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28181. maxLength: 63
  28182. minLength: 1
  28183. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28184. type: string
  28185. type: object
  28186. sessionTokenSecretRef:
  28187. description: |-
  28188. The SessionToken used for authentication
  28189. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28190. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28191. properties:
  28192. key:
  28193. description: |-
  28194. A key in the referenced Secret.
  28195. Some instances of this field may be defaulted, in others it may be required.
  28196. maxLength: 253
  28197. minLength: 1
  28198. pattern: ^[-._a-zA-Z0-9]+$
  28199. type: string
  28200. name:
  28201. description: The name of the Secret resource being referred to.
  28202. maxLength: 253
  28203. minLength: 1
  28204. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28205. type: string
  28206. namespace:
  28207. description: |-
  28208. The namespace of the Secret resource being referred to.
  28209. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28210. maxLength: 63
  28211. minLength: 1
  28212. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28213. type: string
  28214. type: object
  28215. type: object
  28216. type: object
  28217. region:
  28218. description: Region specifies the region to operate in.
  28219. type: string
  28220. role:
  28221. description: |-
  28222. You can assume a role before making calls to the
  28223. desired AWS service.
  28224. type: string
  28225. scope:
  28226. description: |-
  28227. Scope specifies the ECR service scope.
  28228. Valid options are private and public.
  28229. type: string
  28230. required:
  28231. - region
  28232. type: object
  28233. fakeSpec:
  28234. description: FakeSpec contains the static data.
  28235. properties:
  28236. controller:
  28237. description: |-
  28238. Used to select the correct ESO controller (think: ingress.ingressClassName)
  28239. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  28240. type: string
  28241. data:
  28242. additionalProperties:
  28243. type: string
  28244. description: |-
  28245. Data defines the static data returned
  28246. by this generator.
  28247. type: object
  28248. type: object
  28249. gcrAccessTokenSpec:
  28250. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  28251. properties:
  28252. auth:
  28253. description: Auth defines the means for authenticating with GCP
  28254. properties:
  28255. secretRef:
  28256. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  28257. properties:
  28258. secretAccessKeySecretRef:
  28259. description: The SecretAccessKey is used for authentication
  28260. properties:
  28261. key:
  28262. description: |-
  28263. A key in the referenced Secret.
  28264. Some instances of this field may be defaulted, in others it may be required.
  28265. maxLength: 253
  28266. minLength: 1
  28267. pattern: ^[-._a-zA-Z0-9]+$
  28268. type: string
  28269. name:
  28270. description: The name of the Secret resource being referred to.
  28271. maxLength: 253
  28272. minLength: 1
  28273. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28274. type: string
  28275. namespace:
  28276. description: |-
  28277. The namespace of the Secret resource being referred to.
  28278. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28279. maxLength: 63
  28280. minLength: 1
  28281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28282. type: string
  28283. type: object
  28284. type: object
  28285. workloadIdentity:
  28286. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  28287. properties:
  28288. clusterLocation:
  28289. type: string
  28290. clusterName:
  28291. type: string
  28292. clusterProjectID:
  28293. type: string
  28294. serviceAccountRef:
  28295. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28296. properties:
  28297. audiences:
  28298. description: |-
  28299. Audience specifies the `aud` claim for the service account token
  28300. Some providers automatically extend the audience field based on well-known annotations for workload
  28301. identity (e.g. IRSA or GCP Workload Identity)
  28302. items:
  28303. type: string
  28304. type: array
  28305. name:
  28306. description: The name of the ServiceAccount resource being referred to.
  28307. maxLength: 253
  28308. minLength: 1
  28309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28310. type: string
  28311. namespace:
  28312. description: |-
  28313. Namespace of the resource being referred to.
  28314. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28315. maxLength: 63
  28316. minLength: 1
  28317. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28318. type: string
  28319. required:
  28320. - name
  28321. type: object
  28322. required:
  28323. - clusterLocation
  28324. - clusterName
  28325. - serviceAccountRef
  28326. type: object
  28327. workloadIdentityFederation:
  28328. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  28329. properties:
  28330. audience:
  28331. description: |-
  28332. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  28333. If specified, Audience found in the external account credential config will be overridden with the configured value.
  28334. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  28335. type: string
  28336. awsSecurityCredentials:
  28337. description: |-
  28338. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  28339. when using the AWS metadata server is not an option.
  28340. properties:
  28341. awsCredentialsSecretRef:
  28342. description: |-
  28343. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  28344. Secret should be created with below names for keys
  28345. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  28346. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  28347. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  28348. properties:
  28349. name:
  28350. description: name of the secret.
  28351. maxLength: 253
  28352. minLength: 1
  28353. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28354. type: string
  28355. namespace:
  28356. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  28357. maxLength: 63
  28358. minLength: 1
  28359. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28360. type: string
  28361. required:
  28362. - name
  28363. type: object
  28364. region:
  28365. description: region is for configuring the AWS region to be used.
  28366. example: ap-south-1
  28367. maxLength: 50
  28368. minLength: 1
  28369. pattern: ^[a-z0-9-]+$
  28370. type: string
  28371. required:
  28372. - awsCredentialsSecretRef
  28373. - region
  28374. type: object
  28375. credConfig:
  28376. description: |-
  28377. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  28378. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  28379. serviceAccountRef must be used by providing operators service account details.
  28380. properties:
  28381. key:
  28382. description: key name holding the external account credential config.
  28383. maxLength: 253
  28384. minLength: 1
  28385. pattern: ^[-._a-zA-Z0-9]+$
  28386. type: string
  28387. name:
  28388. description: name of the configmap.
  28389. maxLength: 253
  28390. minLength: 1
  28391. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28392. type: string
  28393. namespace:
  28394. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  28395. maxLength: 63
  28396. minLength: 1
  28397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28398. type: string
  28399. required:
  28400. - key
  28401. - name
  28402. type: object
  28403. externalTokenEndpoint:
  28404. description: |-
  28405. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  28406. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  28407. URL is having the expected value.
  28408. type: string
  28409. gcpServiceAccountEmail:
  28410. description: |-
  28411. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  28412. after Workload Identity Federation. Use this to grant access through the service account's
  28413. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  28414. service_account_impersonation_url in the external account JSON from credConfig;
  28415. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  28416. on that ServiceAccount.
  28417. example: my-gsa@my-project.iam.gserviceaccount.com
  28418. minLength: 1
  28419. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  28420. type: string
  28421. serviceAccountRef:
  28422. description: |-
  28423. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  28424. when Kubernetes is configured as provider in workload identity pool.
  28425. properties:
  28426. audiences:
  28427. description: |-
  28428. Audience specifies the `aud` claim for the service account token
  28429. Some providers automatically extend the audience field based on well-known annotations for workload
  28430. identity (e.g. IRSA or GCP Workload Identity)
  28431. items:
  28432. type: string
  28433. type: array
  28434. name:
  28435. description: The name of the ServiceAccount resource being referred to.
  28436. maxLength: 253
  28437. minLength: 1
  28438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28439. type: string
  28440. namespace:
  28441. description: |-
  28442. Namespace of the resource being referred to.
  28443. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28444. maxLength: 63
  28445. minLength: 1
  28446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28447. type: string
  28448. required:
  28449. - name
  28450. type: object
  28451. type: object
  28452. type: object
  28453. projectID:
  28454. description: ProjectID defines which project to use to authenticate with
  28455. type: string
  28456. required:
  28457. - auth
  28458. - projectID
  28459. type: object
  28460. githubAccessTokenSpec:
  28461. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  28462. properties:
  28463. appID:
  28464. type: string
  28465. auth:
  28466. description: Auth configures how ESO authenticates with a Github instance.
  28467. properties:
  28468. privateKey:
  28469. description: GithubSecretRef references a secret containing GitHub credentials.
  28470. properties:
  28471. secretRef:
  28472. description: |-
  28473. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28474. In some instances, `key` is a required field.
  28475. properties:
  28476. key:
  28477. description: |-
  28478. A key in the referenced Secret.
  28479. Some instances of this field may be defaulted, in others it may be required.
  28480. maxLength: 253
  28481. minLength: 1
  28482. pattern: ^[-._a-zA-Z0-9]+$
  28483. type: string
  28484. name:
  28485. description: The name of the Secret resource being referred to.
  28486. maxLength: 253
  28487. minLength: 1
  28488. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28489. type: string
  28490. namespace:
  28491. description: |-
  28492. The namespace of the Secret resource being referred to.
  28493. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28494. maxLength: 63
  28495. minLength: 1
  28496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28497. type: string
  28498. type: object
  28499. required:
  28500. - secretRef
  28501. type: object
  28502. required:
  28503. - privateKey
  28504. type: object
  28505. installID:
  28506. type: string
  28507. permissions:
  28508. additionalProperties:
  28509. type: string
  28510. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  28511. type: object
  28512. repositories:
  28513. description: |-
  28514. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  28515. is installed to.
  28516. items:
  28517. type: string
  28518. type: array
  28519. url:
  28520. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  28521. type: string
  28522. required:
  28523. - appID
  28524. - auth
  28525. - installID
  28526. type: object
  28527. gitlabDeployTokenSpec:
  28528. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  28529. properties:
  28530. auth:
  28531. description: Auth configures how ESO authenticates with the GitLab API.
  28532. properties:
  28533. token:
  28534. description: |-
  28535. Token references a secret containing a GitLab access token (personal, group, or
  28536. project) with the api scope and at least the Maintainer role on the target.
  28537. properties:
  28538. secretRef:
  28539. description: |-
  28540. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28541. In some instances, `key` is a required field.
  28542. properties:
  28543. key:
  28544. description: |-
  28545. A key in the referenced Secret.
  28546. Some instances of this field may be defaulted, in others it may be required.
  28547. maxLength: 253
  28548. minLength: 1
  28549. pattern: ^[-._a-zA-Z0-9]+$
  28550. type: string
  28551. name:
  28552. description: The name of the Secret resource being referred to.
  28553. maxLength: 253
  28554. minLength: 1
  28555. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28556. type: string
  28557. namespace:
  28558. description: |-
  28559. The namespace of the Secret resource being referred to.
  28560. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28561. maxLength: 63
  28562. minLength: 1
  28563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28564. type: string
  28565. type: object
  28566. required:
  28567. - secretRef
  28568. type: object
  28569. required:
  28570. - token
  28571. type: object
  28572. expiresAt:
  28573. description: |-
  28574. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  28575. not expire on the GitLab side and is revoked only when the generator state is
  28576. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  28577. format: date-time
  28578. type: string
  28579. groupID:
  28580. description: |-
  28581. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  28582. create the deploy token in. The generator URL-escapes paths before calling the
  28583. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  28584. minLength: 1
  28585. type: string
  28586. name:
  28587. description: Name of the deploy token.
  28588. minLength: 1
  28589. type: string
  28590. projectID:
  28591. description: |-
  28592. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  28593. project to create the deploy token in. The generator URL-escapes paths before
  28594. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  28595. minLength: 1
  28596. type: string
  28597. scopes:
  28598. description: Scopes granted to the deploy token. At least one scope is required.
  28599. items:
  28600. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  28601. enum:
  28602. - read_repository
  28603. - read_registry
  28604. - write_registry
  28605. - read_package_registry
  28606. - write_package_registry
  28607. - read_virtual_registry
  28608. - write_virtual_registry
  28609. type: string
  28610. minItems: 1
  28611. type: array
  28612. url:
  28613. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  28614. type: string
  28615. username:
  28616. description: |-
  28617. Username is an optional username for the deploy token. GitLab defaults it to
  28618. gitlab+deploy-token-{n} when omitted.
  28619. type: string
  28620. required:
  28621. - auth
  28622. - name
  28623. - scopes
  28624. type: object
  28625. x-kubernetes-validations:
  28626. - message: exactly one of projectID or groupID must be set
  28627. rule: has(self.projectID) != has(self.groupID)
  28628. grafanaSpec:
  28629. description: GrafanaSpec controls the behavior of the grafana generator.
  28630. properties:
  28631. auth:
  28632. description: |-
  28633. Auth is the authentication configuration to authenticate
  28634. against the Grafana instance.
  28635. properties:
  28636. basic:
  28637. description: |-
  28638. Basic auth credentials used to authenticate against the Grafana instance.
  28639. Note: you need a token which has elevated permissions to create service accounts.
  28640. See here for the documentation on basic roles offered by Grafana:
  28641. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28642. properties:
  28643. password:
  28644. description: A basic auth password used to authenticate against the Grafana instance.
  28645. properties:
  28646. key:
  28647. description: The key where the token is found.
  28648. maxLength: 253
  28649. minLength: 1
  28650. pattern: ^[-._a-zA-Z0-9]+$
  28651. type: string
  28652. name:
  28653. description: The name of the Secret resource being referred to.
  28654. maxLength: 253
  28655. minLength: 1
  28656. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28657. type: string
  28658. type: object
  28659. username:
  28660. description: A basic auth username used to authenticate against the Grafana instance.
  28661. type: string
  28662. required:
  28663. - password
  28664. - username
  28665. type: object
  28666. token:
  28667. description: |-
  28668. A service account token used to authenticate against the Grafana instance.
  28669. Note: you need a token which has elevated permissions to create service accounts.
  28670. See here for the documentation on basic roles offered by Grafana:
  28671. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28672. properties:
  28673. key:
  28674. description: The key where the token is found.
  28675. maxLength: 253
  28676. minLength: 1
  28677. pattern: ^[-._a-zA-Z0-9]+$
  28678. type: string
  28679. name:
  28680. description: The name of the Secret resource being referred to.
  28681. maxLength: 253
  28682. minLength: 1
  28683. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28684. type: string
  28685. type: object
  28686. type: object
  28687. serviceAccount:
  28688. description: |-
  28689. ServiceAccount is the configuration for the service account that
  28690. is supposed to be generated by the generator.
  28691. properties:
  28692. name:
  28693. description: Name is the name of the service account that will be created by ESO.
  28694. type: string
  28695. role:
  28696. description: |-
  28697. Role is the role of the service account.
  28698. See here for the documentation on basic roles offered by Grafana:
  28699. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28700. type: string
  28701. secondsToLive:
  28702. description: |-
  28703. SecondsToLive is the number of seconds before the generated service account token will expire.
  28704. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  28705. format: int64
  28706. minimum: 1
  28707. type: integer
  28708. required:
  28709. - name
  28710. - role
  28711. type: object
  28712. url:
  28713. description: URL is the URL of the Grafana instance.
  28714. type: string
  28715. required:
  28716. - auth
  28717. - serviceAccount
  28718. - url
  28719. type: object
  28720. mfaSpec:
  28721. description: MFASpec controls the behavior of the mfa generator.
  28722. properties:
  28723. algorithm:
  28724. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  28725. type: string
  28726. length:
  28727. description: Length defines the token length. Defaults to 6 characters.
  28728. type: integer
  28729. secret:
  28730. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  28731. properties:
  28732. key:
  28733. description: |-
  28734. A key in the referenced Secret.
  28735. Some instances of this field may be defaulted, in others it may be required.
  28736. maxLength: 253
  28737. minLength: 1
  28738. pattern: ^[-._a-zA-Z0-9]+$
  28739. type: string
  28740. name:
  28741. description: The name of the Secret resource being referred to.
  28742. maxLength: 253
  28743. minLength: 1
  28744. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28745. type: string
  28746. namespace:
  28747. description: |-
  28748. The namespace of the Secret resource being referred to.
  28749. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28750. maxLength: 63
  28751. minLength: 1
  28752. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28753. type: string
  28754. type: object
  28755. timePeriod:
  28756. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  28757. type: integer
  28758. when:
  28759. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  28760. format: date-time
  28761. type: string
  28762. required:
  28763. - secret
  28764. type: object
  28765. passwordSpec:
  28766. description: PasswordSpec controls the behavior of the password generator.
  28767. properties:
  28768. allowRepeat:
  28769. default: false
  28770. description: set AllowRepeat to true to allow repeating characters.
  28771. type: boolean
  28772. digits:
  28773. description: |-
  28774. Digits specifies the number of digits in the generated
  28775. password. If omitted it defaults to 25% of the length of the password
  28776. type: integer
  28777. encoding:
  28778. default: raw
  28779. description: |-
  28780. Encoding specifies the encoding of the generated password.
  28781. Valid values are:
  28782. - "raw" (default): no encoding
  28783. - "base64": standard base64 encoding
  28784. - "base64url": base64url encoding
  28785. - "base32": base32 encoding
  28786. - "hex": hexadecimal encoding
  28787. enum:
  28788. - base64
  28789. - base64url
  28790. - base32
  28791. - hex
  28792. - raw
  28793. type: string
  28794. length:
  28795. default: 24
  28796. description: |-
  28797. Length of the password to be generated.
  28798. Defaults to 24
  28799. type: integer
  28800. noUpper:
  28801. default: false
  28802. description: Set NoUpper to disable uppercase characters
  28803. type: boolean
  28804. secretKeys:
  28805. description: |-
  28806. SecretKeys defines the keys that will be populated with generated passwords.
  28807. Defaults to "password" when not set.
  28808. items:
  28809. type: string
  28810. minItems: 1
  28811. type: array
  28812. symbolCharacters:
  28813. description: |-
  28814. SymbolCharacters specifies the special characters that should be used
  28815. in the generated password.
  28816. type: string
  28817. symbols:
  28818. description: |-
  28819. Symbols specifies the number of symbol characters in the generated
  28820. password. If omitted it defaults to 25% of the length of the password
  28821. type: integer
  28822. required:
  28823. - allowRepeat
  28824. - length
  28825. - noUpper
  28826. type: object
  28827. quayAccessTokenSpec:
  28828. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  28829. properties:
  28830. robotAccount:
  28831. description: Name of the robot account you are federating with
  28832. type: string
  28833. serviceAccountRef:
  28834. description: Name of the service account you are federating with
  28835. properties:
  28836. audiences:
  28837. description: |-
  28838. Audience specifies the `aud` claim for the service account token
  28839. Some providers automatically extend the audience field based on well-known annotations for workload
  28840. identity (e.g. IRSA or GCP Workload Identity)
  28841. items:
  28842. type: string
  28843. type: array
  28844. name:
  28845. description: The name of the ServiceAccount resource being referred to.
  28846. maxLength: 253
  28847. minLength: 1
  28848. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28849. type: string
  28850. namespace:
  28851. description: |-
  28852. Namespace of the resource being referred to.
  28853. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28854. maxLength: 63
  28855. minLength: 1
  28856. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28857. type: string
  28858. required:
  28859. - name
  28860. type: object
  28861. url:
  28862. description: URL configures the Quay instance URL. Defaults to quay.io.
  28863. type: string
  28864. required:
  28865. - robotAccount
  28866. - serviceAccountRef
  28867. type: object
  28868. sshKeySpec:
  28869. description: SSHKeySpec controls the behavior of the ssh key generator.
  28870. properties:
  28871. comment:
  28872. description: Comment specifies an optional comment for the SSH key
  28873. type: string
  28874. keySize:
  28875. description: |-
  28876. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  28877. For RSA keys: 2048, 3072, 4096
  28878. For ECDSA keys: 256, 384, 521
  28879. Ignored for ed25519 keys
  28880. maximum: 8192
  28881. minimum: 256
  28882. type: integer
  28883. keyType:
  28884. default: rsa
  28885. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  28886. enum:
  28887. - rsa
  28888. - ecdsa
  28889. - ed25519
  28890. type: string
  28891. type: object
  28892. stsSessionTokenSpec:
  28893. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  28894. properties:
  28895. auth:
  28896. description: Auth defines how to authenticate with AWS
  28897. properties:
  28898. jwt:
  28899. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  28900. properties:
  28901. serviceAccountRef:
  28902. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28903. properties:
  28904. audiences:
  28905. description: |-
  28906. Audience specifies the `aud` claim for the service account token
  28907. Some providers automatically extend the audience field based on well-known annotations for workload
  28908. identity (e.g. IRSA or GCP Workload Identity)
  28909. items:
  28910. type: string
  28911. type: array
  28912. name:
  28913. description: The name of the ServiceAccount resource being referred to.
  28914. maxLength: 253
  28915. minLength: 1
  28916. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28917. type: string
  28918. namespace:
  28919. description: |-
  28920. Namespace of the resource being referred to.
  28921. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28922. maxLength: 63
  28923. minLength: 1
  28924. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28925. type: string
  28926. required:
  28927. - name
  28928. type: object
  28929. type: object
  28930. secretRef:
  28931. description: |-
  28932. AWSAuthSecretRef holds secret references for AWS credentials
  28933. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  28934. properties:
  28935. accessKeyIDSecretRef:
  28936. description: The AccessKeyID is used for authentication
  28937. properties:
  28938. key:
  28939. description: |-
  28940. A key in the referenced Secret.
  28941. Some instances of this field may be defaulted, in others it may be required.
  28942. maxLength: 253
  28943. minLength: 1
  28944. pattern: ^[-._a-zA-Z0-9]+$
  28945. type: string
  28946. name:
  28947. description: The name of the Secret resource being referred to.
  28948. maxLength: 253
  28949. minLength: 1
  28950. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28951. type: string
  28952. namespace:
  28953. description: |-
  28954. The namespace of the Secret resource being referred to.
  28955. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28956. maxLength: 63
  28957. minLength: 1
  28958. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28959. type: string
  28960. type: object
  28961. secretAccessKeySecretRef:
  28962. description: The SecretAccessKey is used for authentication
  28963. properties:
  28964. key:
  28965. description: |-
  28966. A key in the referenced Secret.
  28967. Some instances of this field may be defaulted, in others it may be required.
  28968. maxLength: 253
  28969. minLength: 1
  28970. pattern: ^[-._a-zA-Z0-9]+$
  28971. type: string
  28972. name:
  28973. description: The name of the Secret resource being referred to.
  28974. maxLength: 253
  28975. minLength: 1
  28976. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28977. type: string
  28978. namespace:
  28979. description: |-
  28980. The namespace of the Secret resource being referred to.
  28981. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28982. maxLength: 63
  28983. minLength: 1
  28984. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28985. type: string
  28986. type: object
  28987. sessionTokenSecretRef:
  28988. description: |-
  28989. The SessionToken used for authentication
  28990. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28991. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28992. properties:
  28993. key:
  28994. description: |-
  28995. A key in the referenced Secret.
  28996. Some instances of this field may be defaulted, in others it may be required.
  28997. maxLength: 253
  28998. minLength: 1
  28999. pattern: ^[-._a-zA-Z0-9]+$
  29000. type: string
  29001. name:
  29002. description: The name of the Secret resource being referred to.
  29003. maxLength: 253
  29004. minLength: 1
  29005. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29006. type: string
  29007. namespace:
  29008. description: |-
  29009. The namespace of the Secret resource being referred to.
  29010. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29011. maxLength: 63
  29012. minLength: 1
  29013. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29014. type: string
  29015. type: object
  29016. type: object
  29017. type: object
  29018. region:
  29019. description: Region specifies the region to operate in.
  29020. type: string
  29021. requestParameters:
  29022. description: RequestParameters contains parameters that can be passed to the STS service.
  29023. properties:
  29024. serialNumber:
  29025. description: |-
  29026. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  29027. the GetSessionToken call.
  29028. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  29029. (such as arn:aws:iam::123456789012:mfa/user)
  29030. type: string
  29031. sessionDuration:
  29032. format: int32
  29033. type: integer
  29034. tokenCode:
  29035. description: TokenCode is the value provided by the MFA device, if MFA is required.
  29036. type: string
  29037. type: object
  29038. role:
  29039. description: |-
  29040. You can assume a role before making calls to the
  29041. desired AWS service.
  29042. type: string
  29043. required:
  29044. - region
  29045. type: object
  29046. uuidSpec:
  29047. description: UUIDSpec controls the behavior of the uuid generator.
  29048. type: object
  29049. vaultDynamicSecretSpec:
  29050. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  29051. properties:
  29052. allowEmptyResponse:
  29053. default: false
  29054. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  29055. type: boolean
  29056. controller:
  29057. description: |-
  29058. Used to select the correct ESO controller (think: ingress.ingressClassName)
  29059. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  29060. type: string
  29061. getParameters:
  29062. additionalProperties:
  29063. items:
  29064. type: string
  29065. type: array
  29066. description: |-
  29067. GetParameters are query-string parameters passed to Vault on GET calls.
  29068. Each key may map to multiple values, matching HTTP query-string semantics.
  29069. Ignored for non-GET methods; use Parameters for write bodies.
  29070. type: object
  29071. method:
  29072. description: Vault API method to use (GET/POST/other)
  29073. type: string
  29074. parameters:
  29075. description: Parameters to pass to Vault write (for non-GET methods)
  29076. x-kubernetes-preserve-unknown-fields: true
  29077. path:
  29078. description: Vault path to obtain the dynamic secret from
  29079. type: string
  29080. provider:
  29081. description: Vault provider common spec
  29082. properties:
  29083. auth:
  29084. description: Auth configures how secret-manager authenticates with the Vault server.
  29085. properties:
  29086. appRole:
  29087. description: |-
  29088. AppRole authenticates with Vault using the App Role auth mechanism,
  29089. with the role and secret stored in a Kubernetes Secret resource.
  29090. properties:
  29091. path:
  29092. default: approle
  29093. description: |-
  29094. Path where the App Role authentication backend is mounted
  29095. in Vault, e.g: "approle"
  29096. type: string
  29097. roleId:
  29098. description: |-
  29099. RoleID configured in the App Role authentication backend when setting
  29100. up the authentication backend in Vault.
  29101. type: string
  29102. roleRef:
  29103. description: |-
  29104. Reference to a key in a Secret that contains the App Role ID used
  29105. to authenticate with Vault.
  29106. The `key` field must be specified and denotes which entry within the Secret
  29107. resource is used as the app role id.
  29108. properties:
  29109. key:
  29110. description: |-
  29111. A key in the referenced Secret.
  29112. Some instances of this field may be defaulted, in others it may be required.
  29113. maxLength: 253
  29114. minLength: 1
  29115. pattern: ^[-._a-zA-Z0-9]+$
  29116. type: string
  29117. name:
  29118. description: The name of the Secret resource being referred to.
  29119. maxLength: 253
  29120. minLength: 1
  29121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29122. type: string
  29123. namespace:
  29124. description: |-
  29125. The namespace of the Secret resource being referred to.
  29126. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29127. maxLength: 63
  29128. minLength: 1
  29129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29130. type: string
  29131. type: object
  29132. secretRef:
  29133. description: |-
  29134. Reference to a key in a Secret that contains the App Role secret used
  29135. to authenticate with Vault.
  29136. The `key` field must be specified and denotes which entry within the Secret
  29137. resource is used as the app role secret.
  29138. properties:
  29139. key:
  29140. description: |-
  29141. A key in the referenced Secret.
  29142. Some instances of this field may be defaulted, in others it may be required.
  29143. maxLength: 253
  29144. minLength: 1
  29145. pattern: ^[-._a-zA-Z0-9]+$
  29146. type: string
  29147. name:
  29148. description: The name of the Secret resource being referred to.
  29149. maxLength: 253
  29150. minLength: 1
  29151. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29152. type: string
  29153. namespace:
  29154. description: |-
  29155. The namespace of the Secret resource being referred to.
  29156. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29157. maxLength: 63
  29158. minLength: 1
  29159. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29160. type: string
  29161. type: object
  29162. required:
  29163. - path
  29164. - secretRef
  29165. type: object
  29166. cert:
  29167. description: |-
  29168. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  29169. Cert authentication method
  29170. properties:
  29171. clientCert:
  29172. description: |-
  29173. ClientCert is a certificate to authenticate using the Cert Vault
  29174. authentication method
  29175. properties:
  29176. key:
  29177. description: |-
  29178. A key in the referenced Secret.
  29179. Some instances of this field may be defaulted, in others it may be required.
  29180. maxLength: 253
  29181. minLength: 1
  29182. pattern: ^[-._a-zA-Z0-9]+$
  29183. type: string
  29184. name:
  29185. description: The name of the Secret resource being referred to.
  29186. maxLength: 253
  29187. minLength: 1
  29188. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29189. type: string
  29190. namespace:
  29191. description: |-
  29192. The namespace of the Secret resource being referred to.
  29193. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29194. maxLength: 63
  29195. minLength: 1
  29196. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29197. type: string
  29198. type: object
  29199. path:
  29200. default: cert
  29201. description: |-
  29202. Path where the Certificate authentication backend is mounted
  29203. in Vault, e.g: "cert"
  29204. type: string
  29205. secretRef:
  29206. description: |-
  29207. SecretRef to a key in a Secret resource containing client private key to
  29208. authenticate with Vault using the Cert authentication method
  29209. properties:
  29210. key:
  29211. description: |-
  29212. A key in the referenced Secret.
  29213. Some instances of this field may be defaulted, in others it may be required.
  29214. maxLength: 253
  29215. minLength: 1
  29216. pattern: ^[-._a-zA-Z0-9]+$
  29217. type: string
  29218. name:
  29219. description: The name of the Secret resource being referred to.
  29220. maxLength: 253
  29221. minLength: 1
  29222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29223. type: string
  29224. namespace:
  29225. description: |-
  29226. The namespace of the Secret resource being referred to.
  29227. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29228. maxLength: 63
  29229. minLength: 1
  29230. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29231. type: string
  29232. type: object
  29233. vaultRole:
  29234. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  29235. type: string
  29236. type: object
  29237. gcp:
  29238. description: |-
  29239. Gcp authenticates with Vault using Google Cloud Platform authentication method
  29240. GCP authentication method
  29241. properties:
  29242. location:
  29243. description: Location optionally defines a location/region for the secret
  29244. type: string
  29245. path:
  29246. default: gcp
  29247. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  29248. type: string
  29249. projectID:
  29250. description: Project ID of the Google Cloud Platform project
  29251. type: string
  29252. role:
  29253. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  29254. type: string
  29255. secretRef:
  29256. description: Specify credentials in a Secret object
  29257. properties:
  29258. secretAccessKeySecretRef:
  29259. description: The SecretAccessKey is used for authentication
  29260. properties:
  29261. key:
  29262. description: |-
  29263. A key in the referenced Secret.
  29264. Some instances of this field may be defaulted, in others it may be required.
  29265. maxLength: 253
  29266. minLength: 1
  29267. pattern: ^[-._a-zA-Z0-9]+$
  29268. type: string
  29269. name:
  29270. description: The name of the Secret resource being referred to.
  29271. maxLength: 253
  29272. minLength: 1
  29273. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29274. type: string
  29275. namespace:
  29276. description: |-
  29277. The namespace of the Secret resource being referred to.
  29278. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29279. maxLength: 63
  29280. minLength: 1
  29281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29282. type: string
  29283. type: object
  29284. type: object
  29285. serviceAccountRef:
  29286. description: ServiceAccountRef to a service account for impersonation
  29287. properties:
  29288. audiences:
  29289. description: |-
  29290. Audience specifies the `aud` claim for the service account token
  29291. Some providers automatically extend the audience field based on well-known annotations for workload
  29292. identity (e.g. IRSA or GCP Workload Identity)
  29293. items:
  29294. type: string
  29295. type: array
  29296. name:
  29297. description: The name of the ServiceAccount resource being referred to.
  29298. maxLength: 253
  29299. minLength: 1
  29300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29301. type: string
  29302. namespace:
  29303. description: |-
  29304. Namespace of the resource being referred to.
  29305. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29306. maxLength: 63
  29307. minLength: 1
  29308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29309. type: string
  29310. required:
  29311. - name
  29312. type: object
  29313. workloadIdentity:
  29314. description: Specify a service account with Workload Identity
  29315. properties:
  29316. clusterLocation:
  29317. description: |-
  29318. ClusterLocation is the location of the cluster
  29319. If not specified, it fetches information from the metadata server
  29320. type: string
  29321. clusterName:
  29322. description: |-
  29323. ClusterName is the name of the cluster
  29324. If not specified, it fetches information from the metadata server
  29325. type: string
  29326. clusterProjectID:
  29327. description: |-
  29328. ClusterProjectID is the project ID of the cluster
  29329. If not specified, it fetches information from the metadata server
  29330. type: string
  29331. serviceAccountRef:
  29332. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29333. properties:
  29334. audiences:
  29335. description: |-
  29336. Audience specifies the `aud` claim for the service account token
  29337. Some providers automatically extend the audience field based on well-known annotations for workload
  29338. identity (e.g. IRSA or GCP Workload Identity)
  29339. items:
  29340. type: string
  29341. type: array
  29342. name:
  29343. description: The name of the ServiceAccount resource being referred to.
  29344. maxLength: 253
  29345. minLength: 1
  29346. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29347. type: string
  29348. namespace:
  29349. description: |-
  29350. Namespace of the resource being referred to.
  29351. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29352. maxLength: 63
  29353. minLength: 1
  29354. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29355. type: string
  29356. required:
  29357. - name
  29358. type: object
  29359. required:
  29360. - serviceAccountRef
  29361. type: object
  29362. required:
  29363. - role
  29364. type: object
  29365. iam:
  29366. description: |-
  29367. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  29368. AWS IAM authentication method
  29369. properties:
  29370. externalID:
  29371. description: AWS External ID set on assumed IAM roles
  29372. type: string
  29373. jwt:
  29374. description: Specify a service account with IRSA enabled
  29375. properties:
  29376. serviceAccountRef:
  29377. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29378. properties:
  29379. audiences:
  29380. description: |-
  29381. Audience specifies the `aud` claim for the service account token
  29382. Some providers automatically extend the audience field based on well-known annotations for workload
  29383. identity (e.g. IRSA or GCP Workload Identity)
  29384. items:
  29385. type: string
  29386. type: array
  29387. name:
  29388. description: The name of the ServiceAccount resource being referred to.
  29389. maxLength: 253
  29390. minLength: 1
  29391. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29392. type: string
  29393. namespace:
  29394. description: |-
  29395. Namespace of the resource being referred to.
  29396. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29397. maxLength: 63
  29398. minLength: 1
  29399. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29400. type: string
  29401. required:
  29402. - name
  29403. type: object
  29404. type: object
  29405. path:
  29406. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  29407. type: string
  29408. region:
  29409. description: AWS region
  29410. type: string
  29411. role:
  29412. description: This is the AWS role to be assumed before talking to vault
  29413. type: string
  29414. secretRef:
  29415. description: Specify credentials in a Secret object
  29416. properties:
  29417. accessKeyIDSecretRef:
  29418. description: The AccessKeyID is used for authentication
  29419. properties:
  29420. key:
  29421. description: |-
  29422. A key in the referenced Secret.
  29423. Some instances of this field may be defaulted, in others it may be required.
  29424. maxLength: 253
  29425. minLength: 1
  29426. pattern: ^[-._a-zA-Z0-9]+$
  29427. type: string
  29428. name:
  29429. description: The name of the Secret resource being referred to.
  29430. maxLength: 253
  29431. minLength: 1
  29432. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29433. type: string
  29434. namespace:
  29435. description: |-
  29436. The namespace of the Secret resource being referred to.
  29437. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29438. maxLength: 63
  29439. minLength: 1
  29440. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29441. type: string
  29442. type: object
  29443. secretAccessKeySecretRef:
  29444. description: The SecretAccessKey is used for authentication
  29445. properties:
  29446. key:
  29447. description: |-
  29448. A key in the referenced Secret.
  29449. Some instances of this field may be defaulted, in others it may be required.
  29450. maxLength: 253
  29451. minLength: 1
  29452. pattern: ^[-._a-zA-Z0-9]+$
  29453. type: string
  29454. name:
  29455. description: The name of the Secret resource being referred to.
  29456. maxLength: 253
  29457. minLength: 1
  29458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29459. type: string
  29460. namespace:
  29461. description: |-
  29462. The namespace of the Secret resource being referred to.
  29463. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29464. maxLength: 63
  29465. minLength: 1
  29466. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29467. type: string
  29468. type: object
  29469. sessionTokenSecretRef:
  29470. description: |-
  29471. The SessionToken used for authentication
  29472. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  29473. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  29474. properties:
  29475. key:
  29476. description: |-
  29477. A key in the referenced Secret.
  29478. Some instances of this field may be defaulted, in others it may be required.
  29479. maxLength: 253
  29480. minLength: 1
  29481. pattern: ^[-._a-zA-Z0-9]+$
  29482. type: string
  29483. name:
  29484. description: The name of the Secret resource being referred to.
  29485. maxLength: 253
  29486. minLength: 1
  29487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29488. type: string
  29489. namespace:
  29490. description: |-
  29491. The namespace of the Secret resource being referred to.
  29492. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29493. maxLength: 63
  29494. minLength: 1
  29495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29496. type: string
  29497. type: object
  29498. type: object
  29499. vaultAwsIamServerID:
  29500. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  29501. type: string
  29502. vaultRole:
  29503. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  29504. type: string
  29505. required:
  29506. - vaultRole
  29507. type: object
  29508. jwt:
  29509. description: |-
  29510. Jwt authenticates with Vault by passing role and JWT token using the
  29511. JWT/OIDC authentication method
  29512. properties:
  29513. kubernetesServiceAccountToken:
  29514. description: |-
  29515. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  29516. a token for with the `TokenRequest` API.
  29517. properties:
  29518. audiences:
  29519. description: |-
  29520. Optional audiences field that will be used to request a temporary Kubernetes service
  29521. account token for the service account referenced by `serviceAccountRef`.
  29522. Defaults to a single audience `vault` it not specified.
  29523. Deprecated: use serviceAccountRef.Audiences instead
  29524. items:
  29525. type: string
  29526. type: array
  29527. expirationSeconds:
  29528. description: |-
  29529. Optional expiration time in seconds that will be used to request a temporary
  29530. Kubernetes service account token for the service account referenced by
  29531. `serviceAccountRef`.
  29532. Deprecated: this will be removed in the future.
  29533. Defaults to 10 minutes.
  29534. format: int64
  29535. type: integer
  29536. serviceAccountRef:
  29537. description: Service account field containing the name of a kubernetes ServiceAccount.
  29538. properties:
  29539. audiences:
  29540. description: |-
  29541. Audience specifies the `aud` claim for the service account token
  29542. Some providers automatically extend the audience field based on well-known annotations for workload
  29543. identity (e.g. IRSA or GCP Workload Identity)
  29544. items:
  29545. type: string
  29546. type: array
  29547. name:
  29548. description: The name of the ServiceAccount resource being referred to.
  29549. maxLength: 253
  29550. minLength: 1
  29551. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29552. type: string
  29553. namespace:
  29554. description: |-
  29555. Namespace of the resource being referred to.
  29556. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29557. maxLength: 63
  29558. minLength: 1
  29559. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29560. type: string
  29561. required:
  29562. - name
  29563. type: object
  29564. required:
  29565. - serviceAccountRef
  29566. type: object
  29567. path:
  29568. default: jwt
  29569. description: |-
  29570. Path where the JWT authentication backend is mounted
  29571. in Vault, e.g: "jwt"
  29572. type: string
  29573. role:
  29574. description: |-
  29575. Role is a JWT role to authenticate using the JWT/OIDC Vault
  29576. authentication method
  29577. type: string
  29578. secretRef:
  29579. description: |-
  29580. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  29581. authenticate with Vault using the JWT/OIDC authentication method.
  29582. properties:
  29583. key:
  29584. description: |-
  29585. A key in the referenced Secret.
  29586. Some instances of this field may be defaulted, in others it may be required.
  29587. maxLength: 253
  29588. minLength: 1
  29589. pattern: ^[-._a-zA-Z0-9]+$
  29590. type: string
  29591. name:
  29592. description: The name of the Secret resource being referred to.
  29593. maxLength: 253
  29594. minLength: 1
  29595. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29596. type: string
  29597. namespace:
  29598. description: |-
  29599. The namespace of the Secret resource being referred to.
  29600. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29601. maxLength: 63
  29602. minLength: 1
  29603. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29604. type: string
  29605. type: object
  29606. required:
  29607. - path
  29608. type: object
  29609. kubernetes:
  29610. description: |-
  29611. Kubernetes authenticates with Vault by passing the ServiceAccount
  29612. token stored in the named Secret resource to the Vault server.
  29613. properties:
  29614. mountPath:
  29615. default: kubernetes
  29616. description: |-
  29617. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  29618. "kubernetes"
  29619. type: string
  29620. role:
  29621. description: |-
  29622. A required field containing the Vault Role to assume. A Role binds a
  29623. Kubernetes ServiceAccount with a set of Vault policies.
  29624. type: string
  29625. secretRef:
  29626. description: |-
  29627. Optional secret field containing a Kubernetes ServiceAccount JWT used
  29628. for authenticating with Vault. If a name is specified without a key,
  29629. `token` is the default. If one is not specified, the one bound to
  29630. the controller will be used.
  29631. properties:
  29632. key:
  29633. description: |-
  29634. A key in the referenced Secret.
  29635. Some instances of this field may be defaulted, in others it may be required.
  29636. maxLength: 253
  29637. minLength: 1
  29638. pattern: ^[-._a-zA-Z0-9]+$
  29639. type: string
  29640. name:
  29641. description: The name of the Secret resource being referred to.
  29642. maxLength: 253
  29643. minLength: 1
  29644. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29645. type: string
  29646. namespace:
  29647. description: |-
  29648. The namespace of the Secret resource being referred to.
  29649. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29650. maxLength: 63
  29651. minLength: 1
  29652. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29653. type: string
  29654. type: object
  29655. serviceAccountRef:
  29656. description: |-
  29657. Optional service account field containing the name of a kubernetes ServiceAccount.
  29658. If the service account is specified, the service account secret token JWT will be used
  29659. for authenticating with Vault. If the service account selector is not supplied,
  29660. the secretRef will be used instead.
  29661. properties:
  29662. audiences:
  29663. description: |-
  29664. Audience specifies the `aud` claim for the service account token
  29665. Some providers automatically extend the audience field based on well-known annotations for workload
  29666. identity (e.g. IRSA or GCP Workload Identity)
  29667. items:
  29668. type: string
  29669. type: array
  29670. name:
  29671. description: The name of the ServiceAccount resource being referred to.
  29672. maxLength: 253
  29673. minLength: 1
  29674. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29675. type: string
  29676. namespace:
  29677. description: |-
  29678. Namespace of the resource being referred to.
  29679. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29680. maxLength: 63
  29681. minLength: 1
  29682. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29683. type: string
  29684. required:
  29685. - name
  29686. type: object
  29687. required:
  29688. - mountPath
  29689. - role
  29690. type: object
  29691. ldap:
  29692. description: |-
  29693. Ldap authenticates with Vault by passing username/password pair using
  29694. the LDAP authentication method
  29695. properties:
  29696. path:
  29697. default: ldap
  29698. description: |-
  29699. Path where the LDAP authentication backend is mounted
  29700. in Vault, e.g: "ldap"
  29701. type: string
  29702. secretRef:
  29703. description: |-
  29704. SecretRef to a key in a Secret resource containing password for the LDAP
  29705. user used to authenticate with Vault using the LDAP authentication
  29706. method
  29707. properties:
  29708. key:
  29709. description: |-
  29710. A key in the referenced Secret.
  29711. Some instances of this field may be defaulted, in others it may be required.
  29712. maxLength: 253
  29713. minLength: 1
  29714. pattern: ^[-._a-zA-Z0-9]+$
  29715. type: string
  29716. name:
  29717. description: The name of the Secret resource being referred to.
  29718. maxLength: 253
  29719. minLength: 1
  29720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29721. type: string
  29722. namespace:
  29723. description: |-
  29724. The namespace of the Secret resource being referred to.
  29725. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29726. maxLength: 63
  29727. minLength: 1
  29728. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29729. type: string
  29730. type: object
  29731. username:
  29732. description: |-
  29733. Username is an LDAP username used to authenticate using the LDAP Vault
  29734. authentication method
  29735. type: string
  29736. required:
  29737. - path
  29738. - username
  29739. type: object
  29740. namespace:
  29741. description: |-
  29742. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  29743. Namespaces is a set of features within Vault Enterprise that allows
  29744. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  29745. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  29746. This will default to Vault.Namespace field if set, or empty otherwise
  29747. type: string
  29748. tokenSecretRef:
  29749. description: TokenSecretRef authenticates with Vault by presenting a token.
  29750. properties:
  29751. key:
  29752. description: |-
  29753. A key in the referenced Secret.
  29754. Some instances of this field may be defaulted, in others it may be required.
  29755. maxLength: 253
  29756. minLength: 1
  29757. pattern: ^[-._a-zA-Z0-9]+$
  29758. type: string
  29759. name:
  29760. description: The name of the Secret resource being referred to.
  29761. maxLength: 253
  29762. minLength: 1
  29763. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29764. type: string
  29765. namespace:
  29766. description: |-
  29767. The namespace of the Secret resource being referred to.
  29768. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29769. maxLength: 63
  29770. minLength: 1
  29771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29772. type: string
  29773. type: object
  29774. userPass:
  29775. description: UserPass authenticates with Vault by passing username/password pair
  29776. properties:
  29777. path:
  29778. default: userpass
  29779. description: |-
  29780. Path where the UserPassword authentication backend is mounted
  29781. in Vault, e.g: "userpass"
  29782. type: string
  29783. secretRef:
  29784. description: |-
  29785. SecretRef to a key in a Secret resource containing password for the
  29786. user used to authenticate with Vault using the UserPass authentication
  29787. method
  29788. properties:
  29789. key:
  29790. description: |-
  29791. A key in the referenced Secret.
  29792. Some instances of this field may be defaulted, in others it may be required.
  29793. maxLength: 253
  29794. minLength: 1
  29795. pattern: ^[-._a-zA-Z0-9]+$
  29796. type: string
  29797. name:
  29798. description: The name of the Secret resource being referred to.
  29799. maxLength: 253
  29800. minLength: 1
  29801. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29802. type: string
  29803. namespace:
  29804. description: |-
  29805. The namespace of the Secret resource being referred to.
  29806. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29807. maxLength: 63
  29808. minLength: 1
  29809. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29810. type: string
  29811. type: object
  29812. username:
  29813. description: |-
  29814. Username is a username used to authenticate using the UserPass Vault
  29815. authentication method
  29816. type: string
  29817. required:
  29818. - path
  29819. - username
  29820. type: object
  29821. type: object
  29822. caBundle:
  29823. description: |-
  29824. PEM encoded CA bundle used to validate Vault server certificate. Only used
  29825. if the Server URL is using HTTPS protocol. This parameter is ignored for
  29826. plain HTTP protocol connection. If not set the system root certificates
  29827. are used to validate the TLS connection.
  29828. format: byte
  29829. type: string
  29830. caProvider:
  29831. description: The provider for the CA bundle to use to validate Vault server certificate.
  29832. properties:
  29833. key:
  29834. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  29835. maxLength: 253
  29836. minLength: 1
  29837. pattern: ^[-._a-zA-Z0-9]+$
  29838. type: string
  29839. name:
  29840. description: The name of the object located at the provider type.
  29841. maxLength: 253
  29842. minLength: 1
  29843. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29844. type: string
  29845. namespace:
  29846. description: |-
  29847. The namespace the Provider type is in.
  29848. Can only be defined when used in a ClusterSecretStore.
  29849. maxLength: 63
  29850. minLength: 1
  29851. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29852. type: string
  29853. type:
  29854. description: The type of provider to use such as "Secret", or "ConfigMap".
  29855. enum:
  29856. - Secret
  29857. - ConfigMap
  29858. type: string
  29859. required:
  29860. - name
  29861. - type
  29862. type: object
  29863. checkAndSet:
  29864. description: |-
  29865. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  29866. Only applies to Vault KV v2 stores. When enabled, write operations must include
  29867. the current version of the secret to prevent unintentional overwrites.
  29868. properties:
  29869. required:
  29870. description: |-
  29871. Required when true, all write operations must include a check-and-set parameter.
  29872. This helps prevent unintentional overwrites of secrets.
  29873. type: boolean
  29874. type: object
  29875. forwardInconsistent:
  29876. description: |-
  29877. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  29878. leader instead of simply retrying within a loop. This can increase performance if
  29879. the option is enabled serverside.
  29880. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  29881. type: boolean
  29882. headers:
  29883. additionalProperties:
  29884. type: string
  29885. description: Headers to be added in Vault request
  29886. type: object
  29887. namespace:
  29888. description: |-
  29889. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  29890. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  29891. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  29892. type: string
  29893. path:
  29894. description: |-
  29895. Path is the mount path of the Vault KV backend endpoint, e.g:
  29896. "secret". The v2 KV secret engine version specific "/data" path suffix
  29897. for fetching secrets from Vault is optional and will be appended
  29898. if not present in specified path.
  29899. type: string
  29900. readYourWrites:
  29901. description: |-
  29902. ReadYourWrites ensures isolated read-after-write semantics by
  29903. providing discovered cluster replication states in each request.
  29904. More information about eventual consistency in Vault can be found here
  29905. https://www.vaultproject.io/docs/enterprise/consistency
  29906. type: boolean
  29907. server:
  29908. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  29909. type: string
  29910. tls:
  29911. description: |-
  29912. The configuration used for client side related TLS communication, when the Vault server
  29913. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  29914. This parameter is ignored for plain HTTP protocol connection.
  29915. It's worth noting this configuration is different from the "TLS certificates auth method",
  29916. which is available under the `auth.cert` section.
  29917. properties:
  29918. certSecretRef:
  29919. description: |-
  29920. CertSecretRef is a certificate added to the transport layer
  29921. when communicating with the Vault server.
  29922. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  29923. properties:
  29924. key:
  29925. description: |-
  29926. A key in the referenced Secret.
  29927. Some instances of this field may be defaulted, in others it may be required.
  29928. maxLength: 253
  29929. minLength: 1
  29930. pattern: ^[-._a-zA-Z0-9]+$
  29931. type: string
  29932. name:
  29933. description: The name of the Secret resource being referred to.
  29934. maxLength: 253
  29935. minLength: 1
  29936. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29937. type: string
  29938. namespace:
  29939. description: |-
  29940. The namespace of the Secret resource being referred to.
  29941. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29942. maxLength: 63
  29943. minLength: 1
  29944. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29945. type: string
  29946. type: object
  29947. keySecretRef:
  29948. description: |-
  29949. KeySecretRef to a key in a Secret resource containing client private key
  29950. added to the transport layer when communicating with the Vault server.
  29951. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  29952. properties:
  29953. key:
  29954. description: |-
  29955. A key in the referenced Secret.
  29956. Some instances of this field may be defaulted, in others it may be required.
  29957. maxLength: 253
  29958. minLength: 1
  29959. pattern: ^[-._a-zA-Z0-9]+$
  29960. type: string
  29961. name:
  29962. description: The name of the Secret resource being referred to.
  29963. maxLength: 253
  29964. minLength: 1
  29965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29966. type: string
  29967. namespace:
  29968. description: |-
  29969. The namespace of the Secret resource being referred to.
  29970. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29971. maxLength: 63
  29972. minLength: 1
  29973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29974. type: string
  29975. type: object
  29976. type: object
  29977. version:
  29978. default: v2
  29979. description: |-
  29980. Version is the Vault KV secret engine version. This can be either "v1" or
  29981. "v2". Version defaults to "v2".
  29982. enum:
  29983. - v1
  29984. - v2
  29985. type: string
  29986. required:
  29987. - server
  29988. type: object
  29989. resultType:
  29990. default: Data
  29991. description: |-
  29992. Result type defines which data is returned from the generator.
  29993. By default, it is the "data" section of the Vault API response.
  29994. When using e.g. /auth/token/create the "data" section is empty but
  29995. the "auth" section contains the generated token.
  29996. Please refer to the vault docs regarding the result data structure.
  29997. Additionally, accessing the raw response is possibly by using "Raw" result type.
  29998. enum:
  29999. - Data
  30000. - Auth
  30001. - Raw
  30002. type: string
  30003. retrySettings:
  30004. description: Used to configure http retries if failed
  30005. properties:
  30006. maxRetries:
  30007. format: int32
  30008. type: integer
  30009. retryInterval:
  30010. type: string
  30011. type: object
  30012. required:
  30013. - path
  30014. - provider
  30015. type: object
  30016. webhookSpec:
  30017. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  30018. properties:
  30019. auth:
  30020. description: Auth specifies a authorization protocol. Only one protocol may be set.
  30021. maxProperties: 1
  30022. minProperties: 1
  30023. properties:
  30024. ntlm:
  30025. description: NTLMProtocol configures the store to use NTLM for auth
  30026. properties:
  30027. passwordSecret:
  30028. description: |-
  30029. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30030. In some instances, `key` is a required field.
  30031. properties:
  30032. key:
  30033. description: |-
  30034. A key in the referenced Secret.
  30035. Some instances of this field may be defaulted, in others it may be required.
  30036. maxLength: 253
  30037. minLength: 1
  30038. pattern: ^[-._a-zA-Z0-9]+$
  30039. type: string
  30040. name:
  30041. description: The name of the Secret resource being referred to.
  30042. maxLength: 253
  30043. minLength: 1
  30044. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30045. type: string
  30046. namespace:
  30047. description: |-
  30048. The namespace of the Secret resource being referred to.
  30049. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30050. maxLength: 63
  30051. minLength: 1
  30052. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30053. type: string
  30054. type: object
  30055. usernameSecret:
  30056. description: |-
  30057. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30058. In some instances, `key` is a required field.
  30059. properties:
  30060. key:
  30061. description: |-
  30062. A key in the referenced Secret.
  30063. Some instances of this field may be defaulted, in others it may be required.
  30064. maxLength: 253
  30065. minLength: 1
  30066. pattern: ^[-._a-zA-Z0-9]+$
  30067. type: string
  30068. name:
  30069. description: The name of the Secret resource being referred to.
  30070. maxLength: 253
  30071. minLength: 1
  30072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30073. type: string
  30074. namespace:
  30075. description: |-
  30076. The namespace of the Secret resource being referred to.
  30077. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30078. maxLength: 63
  30079. minLength: 1
  30080. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30081. type: string
  30082. type: object
  30083. required:
  30084. - passwordSecret
  30085. - usernameSecret
  30086. type: object
  30087. type: object
  30088. body:
  30089. description: Body
  30090. type: string
  30091. caBundle:
  30092. description: |-
  30093. PEM encoded CA bundle used to validate webhook server certificate. Only used
  30094. if the Server URL is using HTTPS protocol. This parameter is ignored for
  30095. plain HTTP protocol connection. If not set the system root certificates
  30096. are used to validate the TLS connection.
  30097. format: byte
  30098. type: string
  30099. caProvider:
  30100. description: The provider for the CA bundle to use to validate webhook server certificate.
  30101. properties:
  30102. key:
  30103. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  30104. maxLength: 253
  30105. minLength: 1
  30106. pattern: ^[-._a-zA-Z0-9]+$
  30107. type: string
  30108. name:
  30109. description: The name of the object located at the provider type.
  30110. maxLength: 253
  30111. minLength: 1
  30112. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30113. type: string
  30114. namespace:
  30115. description: The namespace the Provider type is in.
  30116. maxLength: 63
  30117. minLength: 1
  30118. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30119. type: string
  30120. type:
  30121. description: The type of provider to use such as "Secret", or "ConfigMap".
  30122. enum:
  30123. - Secret
  30124. - ConfigMap
  30125. type: string
  30126. required:
  30127. - name
  30128. - type
  30129. type: object
  30130. headers:
  30131. additionalProperties:
  30132. type: string
  30133. description: Headers
  30134. type: object
  30135. method:
  30136. description: Webhook Method
  30137. type: string
  30138. result:
  30139. description: Result formatting
  30140. properties:
  30141. jsonPath:
  30142. description: Json path of return value
  30143. type: string
  30144. type: object
  30145. secrets:
  30146. description: |-
  30147. Secrets to fill in templates
  30148. These secrets will be passed to the templating function as key value pairs under the given name
  30149. items:
  30150. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  30151. properties:
  30152. name:
  30153. description: Name of this secret in templates
  30154. type: string
  30155. secretRef:
  30156. description: Secret ref to fill in credentials
  30157. properties:
  30158. key:
  30159. description: The key where the token is found.
  30160. maxLength: 253
  30161. minLength: 1
  30162. pattern: ^[-._a-zA-Z0-9]+$
  30163. type: string
  30164. name:
  30165. description: The name of the Secret resource being referred to.
  30166. maxLength: 253
  30167. minLength: 1
  30168. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30169. type: string
  30170. type: object
  30171. required:
  30172. - name
  30173. - secretRef
  30174. type: object
  30175. type: array
  30176. timeout:
  30177. description: Timeout
  30178. type: string
  30179. url:
  30180. description: Webhook url to call
  30181. type: string
  30182. required:
  30183. - result
  30184. - url
  30185. type: object
  30186. type: object
  30187. kind:
  30188. description: Kind the kind of this generator.
  30189. enum:
  30190. - ACRAccessToken
  30191. - BeyondtrustWorkloadCredentialsDynamicSecret
  30192. - CloudsmithAccessToken
  30193. - ECRAuthorizationToken
  30194. - Fake
  30195. - GCRAccessToken
  30196. - GithubAccessToken
  30197. - GitlabDeployToken
  30198. - QuayAccessToken
  30199. - Password
  30200. - SSHKey
  30201. - STSSessionToken
  30202. - UUID
  30203. - VaultDynamicSecret
  30204. - Webhook
  30205. - Grafana
  30206. - MFA
  30207. type: string
  30208. required:
  30209. - generator
  30210. - kind
  30211. type: object
  30212. type: object
  30213. served: true
  30214. storage: true
  30215. subresources:
  30216. status: {}
  30217. ---
  30218. apiVersion: apiextensions.k8s.io/v1
  30219. kind: CustomResourceDefinition
  30220. metadata:
  30221. annotations:
  30222. controller-gen.kubebuilder.io/version: v0.19.0
  30223. labels:
  30224. external-secrets.io/component: controller
  30225. name: ecrauthorizationtokens.generators.external-secrets.io
  30226. spec:
  30227. group: generators.external-secrets.io
  30228. names:
  30229. categories:
  30230. - external-secrets
  30231. - external-secrets-generators
  30232. kind: ECRAuthorizationToken
  30233. listKind: ECRAuthorizationTokenList
  30234. plural: ecrauthorizationtokens
  30235. singular: ecrauthorizationtoken
  30236. scope: Namespaced
  30237. versions:
  30238. - name: v1alpha1
  30239. schema:
  30240. openAPIV3Schema:
  30241. description: |-
  30242. ECRAuthorizationToken uses the GetAuthorizationToken API to retrieve an authorization token.
  30243. The authorization token is valid for 12 hours.
  30244. The authorizationToken returned is a base64 encoded string that can be decoded
  30245. and used in a docker login command to authenticate to a registry.
  30246. For more information, see Registry authentication (https://docs.aws.amazon.com/AmazonECR/latest/userguide/Registries.html#registry_auth) in the Amazon Elastic Container Registry User Guide.
  30247. properties:
  30248. apiVersion:
  30249. description: |-
  30250. APIVersion defines the versioned schema of this representation of an object.
  30251. Servers should convert recognized schemas to the latest internal value, and
  30252. may reject unrecognized values.
  30253. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30254. type: string
  30255. kind:
  30256. description: |-
  30257. Kind is a string value representing the REST resource this object represents.
  30258. Servers may infer this from the endpoint the client submits requests to.
  30259. Cannot be updated.
  30260. In CamelCase.
  30261. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30262. type: string
  30263. metadata:
  30264. type: object
  30265. spec:
  30266. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  30267. properties:
  30268. auth:
  30269. description: Auth defines how to authenticate with AWS
  30270. properties:
  30271. jwt:
  30272. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  30273. properties:
  30274. serviceAccountRef:
  30275. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  30276. properties:
  30277. audiences:
  30278. description: |-
  30279. Audience specifies the `aud` claim for the service account token
  30280. Some providers automatically extend the audience field based on well-known annotations for workload
  30281. identity (e.g. IRSA or GCP Workload Identity)
  30282. items:
  30283. type: string
  30284. type: array
  30285. name:
  30286. description: The name of the ServiceAccount resource being referred to.
  30287. maxLength: 253
  30288. minLength: 1
  30289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30290. type: string
  30291. namespace:
  30292. description: |-
  30293. Namespace of the resource being referred to.
  30294. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30295. maxLength: 63
  30296. minLength: 1
  30297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30298. type: string
  30299. required:
  30300. - name
  30301. type: object
  30302. type: object
  30303. secretRef:
  30304. description: |-
  30305. AWSAuthSecretRef holds secret references for AWS credentials
  30306. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  30307. properties:
  30308. accessKeyIDSecretRef:
  30309. description: The AccessKeyID is used for authentication
  30310. properties:
  30311. key:
  30312. description: |-
  30313. A key in the referenced Secret.
  30314. Some instances of this field may be defaulted, in others it may be required.
  30315. maxLength: 253
  30316. minLength: 1
  30317. pattern: ^[-._a-zA-Z0-9]+$
  30318. type: string
  30319. name:
  30320. description: The name of the Secret resource being referred to.
  30321. maxLength: 253
  30322. minLength: 1
  30323. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30324. type: string
  30325. namespace:
  30326. description: |-
  30327. The namespace of the Secret resource being referred to.
  30328. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30329. maxLength: 63
  30330. minLength: 1
  30331. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30332. type: string
  30333. type: object
  30334. secretAccessKeySecretRef:
  30335. description: The SecretAccessKey is used for authentication
  30336. properties:
  30337. key:
  30338. description: |-
  30339. A key in the referenced Secret.
  30340. Some instances of this field may be defaulted, in others it may be required.
  30341. maxLength: 253
  30342. minLength: 1
  30343. pattern: ^[-._a-zA-Z0-9]+$
  30344. type: string
  30345. name:
  30346. description: The name of the Secret resource being referred to.
  30347. maxLength: 253
  30348. minLength: 1
  30349. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30350. type: string
  30351. namespace:
  30352. description: |-
  30353. The namespace of the Secret resource being referred to.
  30354. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30355. maxLength: 63
  30356. minLength: 1
  30357. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30358. type: string
  30359. type: object
  30360. sessionTokenSecretRef:
  30361. description: |-
  30362. The SessionToken used for authentication
  30363. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  30364. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  30365. properties:
  30366. key:
  30367. description: |-
  30368. A key in the referenced Secret.
  30369. Some instances of this field may be defaulted, in others it may be required.
  30370. maxLength: 253
  30371. minLength: 1
  30372. pattern: ^[-._a-zA-Z0-9]+$
  30373. type: string
  30374. name:
  30375. description: The name of the Secret resource being referred to.
  30376. maxLength: 253
  30377. minLength: 1
  30378. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30379. type: string
  30380. namespace:
  30381. description: |-
  30382. The namespace of the Secret resource being referred to.
  30383. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30384. maxLength: 63
  30385. minLength: 1
  30386. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30387. type: string
  30388. type: object
  30389. type: object
  30390. type: object
  30391. region:
  30392. description: Region specifies the region to operate in.
  30393. type: string
  30394. role:
  30395. description: |-
  30396. You can assume a role before making calls to the
  30397. desired AWS service.
  30398. type: string
  30399. scope:
  30400. description: |-
  30401. Scope specifies the ECR service scope.
  30402. Valid options are private and public.
  30403. type: string
  30404. required:
  30405. - region
  30406. type: object
  30407. type: object
  30408. served: true
  30409. storage: true
  30410. subresources:
  30411. status: {}
  30412. ---
  30413. apiVersion: apiextensions.k8s.io/v1
  30414. kind: CustomResourceDefinition
  30415. metadata:
  30416. annotations:
  30417. controller-gen.kubebuilder.io/version: v0.19.0
  30418. labels:
  30419. external-secrets.io/component: controller
  30420. name: fakes.generators.external-secrets.io
  30421. spec:
  30422. group: generators.external-secrets.io
  30423. names:
  30424. categories:
  30425. - external-secrets
  30426. - external-secrets-generators
  30427. kind: Fake
  30428. listKind: FakeList
  30429. plural: fakes
  30430. singular: fake
  30431. scope: Namespaced
  30432. versions:
  30433. - name: v1alpha1
  30434. schema:
  30435. openAPIV3Schema:
  30436. description: |-
  30437. Fake generator is used for testing. It lets you define
  30438. a static set of credentials that is always returned.
  30439. properties:
  30440. apiVersion:
  30441. description: |-
  30442. APIVersion defines the versioned schema of this representation of an object.
  30443. Servers should convert recognized schemas to the latest internal value, and
  30444. may reject unrecognized values.
  30445. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30446. type: string
  30447. kind:
  30448. description: |-
  30449. Kind is a string value representing the REST resource this object represents.
  30450. Servers may infer this from the endpoint the client submits requests to.
  30451. Cannot be updated.
  30452. In CamelCase.
  30453. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30454. type: string
  30455. metadata:
  30456. type: object
  30457. spec:
  30458. description: FakeSpec contains the static data.
  30459. properties:
  30460. controller:
  30461. description: |-
  30462. Used to select the correct ESO controller (think: ingress.ingressClassName)
  30463. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  30464. type: string
  30465. data:
  30466. additionalProperties:
  30467. type: string
  30468. description: |-
  30469. Data defines the static data returned
  30470. by this generator.
  30471. type: object
  30472. type: object
  30473. type: object
  30474. served: true
  30475. storage: true
  30476. subresources:
  30477. status: {}
  30478. ---
  30479. apiVersion: apiextensions.k8s.io/v1
  30480. kind: CustomResourceDefinition
  30481. metadata:
  30482. annotations:
  30483. controller-gen.kubebuilder.io/version: v0.19.0
  30484. labels:
  30485. external-secrets.io/component: controller
  30486. name: gcraccesstokens.generators.external-secrets.io
  30487. spec:
  30488. group: generators.external-secrets.io
  30489. names:
  30490. categories:
  30491. - external-secrets
  30492. - external-secrets-generators
  30493. kind: GCRAccessToken
  30494. listKind: GCRAccessTokenList
  30495. plural: gcraccesstokens
  30496. singular: gcraccesstoken
  30497. scope: Namespaced
  30498. versions:
  30499. - name: v1alpha1
  30500. schema:
  30501. openAPIV3Schema:
  30502. description: |-
  30503. GCRAccessToken generates an GCP access token
  30504. that can be used to authenticate with GCR.
  30505. properties:
  30506. apiVersion:
  30507. description: |-
  30508. APIVersion defines the versioned schema of this representation of an object.
  30509. Servers should convert recognized schemas to the latest internal value, and
  30510. may reject unrecognized values.
  30511. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30512. type: string
  30513. kind:
  30514. description: |-
  30515. Kind is a string value representing the REST resource this object represents.
  30516. Servers may infer this from the endpoint the client submits requests to.
  30517. Cannot be updated.
  30518. In CamelCase.
  30519. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30520. type: string
  30521. metadata:
  30522. type: object
  30523. spec:
  30524. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  30525. properties:
  30526. auth:
  30527. description: Auth defines the means for authenticating with GCP
  30528. properties:
  30529. secretRef:
  30530. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  30531. properties:
  30532. secretAccessKeySecretRef:
  30533. description: The SecretAccessKey is used for authentication
  30534. properties:
  30535. key:
  30536. description: |-
  30537. A key in the referenced Secret.
  30538. Some instances of this field may be defaulted, in others it may be required.
  30539. maxLength: 253
  30540. minLength: 1
  30541. pattern: ^[-._a-zA-Z0-9]+$
  30542. type: string
  30543. name:
  30544. description: The name of the Secret resource being referred to.
  30545. maxLength: 253
  30546. minLength: 1
  30547. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30548. type: string
  30549. namespace:
  30550. description: |-
  30551. The namespace of the Secret resource being referred to.
  30552. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30553. maxLength: 63
  30554. minLength: 1
  30555. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30556. type: string
  30557. type: object
  30558. type: object
  30559. workloadIdentity:
  30560. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  30561. properties:
  30562. clusterLocation:
  30563. type: string
  30564. clusterName:
  30565. type: string
  30566. clusterProjectID:
  30567. type: string
  30568. serviceAccountRef:
  30569. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  30570. properties:
  30571. audiences:
  30572. description: |-
  30573. Audience specifies the `aud` claim for the service account token
  30574. Some providers automatically extend the audience field based on well-known annotations for workload
  30575. identity (e.g. IRSA or GCP Workload Identity)
  30576. items:
  30577. type: string
  30578. type: array
  30579. name:
  30580. description: The name of the ServiceAccount resource being referred to.
  30581. maxLength: 253
  30582. minLength: 1
  30583. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30584. type: string
  30585. namespace:
  30586. description: |-
  30587. Namespace of the resource being referred to.
  30588. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30589. maxLength: 63
  30590. minLength: 1
  30591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30592. type: string
  30593. required:
  30594. - name
  30595. type: object
  30596. required:
  30597. - clusterLocation
  30598. - clusterName
  30599. - serviceAccountRef
  30600. type: object
  30601. workloadIdentityFederation:
  30602. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  30603. properties:
  30604. audience:
  30605. description: |-
  30606. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  30607. If specified, Audience found in the external account credential config will be overridden with the configured value.
  30608. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  30609. type: string
  30610. awsSecurityCredentials:
  30611. description: |-
  30612. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  30613. when using the AWS metadata server is not an option.
  30614. properties:
  30615. awsCredentialsSecretRef:
  30616. description: |-
  30617. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  30618. Secret should be created with below names for keys
  30619. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  30620. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  30621. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  30622. properties:
  30623. name:
  30624. description: name of the secret.
  30625. maxLength: 253
  30626. minLength: 1
  30627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30628. type: string
  30629. namespace:
  30630. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  30631. maxLength: 63
  30632. minLength: 1
  30633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30634. type: string
  30635. required:
  30636. - name
  30637. type: object
  30638. region:
  30639. description: region is for configuring the AWS region to be used.
  30640. example: ap-south-1
  30641. maxLength: 50
  30642. minLength: 1
  30643. pattern: ^[a-z0-9-]+$
  30644. type: string
  30645. required:
  30646. - awsCredentialsSecretRef
  30647. - region
  30648. type: object
  30649. credConfig:
  30650. description: |-
  30651. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  30652. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  30653. serviceAccountRef must be used by providing operators service account details.
  30654. properties:
  30655. key:
  30656. description: key name holding the external account credential config.
  30657. maxLength: 253
  30658. minLength: 1
  30659. pattern: ^[-._a-zA-Z0-9]+$
  30660. type: string
  30661. name:
  30662. description: name of the configmap.
  30663. maxLength: 253
  30664. minLength: 1
  30665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30666. type: string
  30667. namespace:
  30668. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  30669. maxLength: 63
  30670. minLength: 1
  30671. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30672. type: string
  30673. required:
  30674. - key
  30675. - name
  30676. type: object
  30677. externalTokenEndpoint:
  30678. description: |-
  30679. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  30680. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  30681. URL is having the expected value.
  30682. type: string
  30683. gcpServiceAccountEmail:
  30684. description: |-
  30685. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  30686. after Workload Identity Federation. Use this to grant access through the service account's
  30687. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  30688. service_account_impersonation_url in the external account JSON from credConfig;
  30689. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  30690. on that ServiceAccount.
  30691. example: my-gsa@my-project.iam.gserviceaccount.com
  30692. minLength: 1
  30693. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  30694. type: string
  30695. serviceAccountRef:
  30696. description: |-
  30697. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  30698. when Kubernetes is configured as provider in workload identity pool.
  30699. properties:
  30700. audiences:
  30701. description: |-
  30702. Audience specifies the `aud` claim for the service account token
  30703. Some providers automatically extend the audience field based on well-known annotations for workload
  30704. identity (e.g. IRSA or GCP Workload Identity)
  30705. items:
  30706. type: string
  30707. type: array
  30708. name:
  30709. description: The name of the ServiceAccount resource being referred to.
  30710. maxLength: 253
  30711. minLength: 1
  30712. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30713. type: string
  30714. namespace:
  30715. description: |-
  30716. Namespace of the resource being referred to.
  30717. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30718. maxLength: 63
  30719. minLength: 1
  30720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30721. type: string
  30722. required:
  30723. - name
  30724. type: object
  30725. type: object
  30726. type: object
  30727. projectID:
  30728. description: ProjectID defines which project to use to authenticate with
  30729. type: string
  30730. required:
  30731. - auth
  30732. - projectID
  30733. type: object
  30734. type: object
  30735. served: true
  30736. storage: true
  30737. subresources:
  30738. status: {}
  30739. ---
  30740. apiVersion: apiextensions.k8s.io/v1
  30741. kind: CustomResourceDefinition
  30742. metadata:
  30743. annotations:
  30744. controller-gen.kubebuilder.io/version: v0.19.0
  30745. labels:
  30746. external-secrets.io/component: controller
  30747. name: generatorstates.generators.external-secrets.io
  30748. spec:
  30749. group: generators.external-secrets.io
  30750. names:
  30751. categories:
  30752. - external-secrets
  30753. - external-secrets-generators
  30754. kind: GeneratorState
  30755. listKind: GeneratorStateList
  30756. plural: generatorstates
  30757. shortNames:
  30758. - gs
  30759. singular: generatorstate
  30760. scope: Namespaced
  30761. versions:
  30762. - additionalPrinterColumns:
  30763. - jsonPath: .spec.garbageCollectionDeadline
  30764. name: GC Deadline
  30765. type: string
  30766. - jsonPath: .metadata.creationTimestamp
  30767. name: Age
  30768. type: date
  30769. name: v1alpha1
  30770. schema:
  30771. openAPIV3Schema:
  30772. description: GeneratorState represents the state created and managed by a generator resource.
  30773. properties:
  30774. apiVersion:
  30775. description: |-
  30776. APIVersion defines the versioned schema of this representation of an object.
  30777. Servers should convert recognized schemas to the latest internal value, and
  30778. may reject unrecognized values.
  30779. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30780. type: string
  30781. kind:
  30782. description: |-
  30783. Kind is a string value representing the REST resource this object represents.
  30784. Servers may infer this from the endpoint the client submits requests to.
  30785. Cannot be updated.
  30786. In CamelCase.
  30787. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30788. type: string
  30789. metadata:
  30790. type: object
  30791. spec:
  30792. description: GeneratorStateSpec defines the desired state of a generator state resource.
  30793. properties:
  30794. garbageCollectionDeadline:
  30795. description: |-
  30796. GarbageCollectionDeadline is the time after which the generator state
  30797. will be deleted.
  30798. It is set by the controller which creates the generator state and
  30799. can be set configured by the user.
  30800. If the garbage collection deadline is not set the generator state will not be deleted.
  30801. format: date-time
  30802. type: string
  30803. resource:
  30804. description: |-
  30805. Resource is the generator manifest that produced the state.
  30806. It is a snapshot of the generator manifest at the time the state was produced.
  30807. This manifest will be used to delete the resource. Any configuration that is referenced
  30808. in the manifest should be available at the time of garbage collection. If that is not the case deletion will
  30809. be blocked by a finalizer.
  30810. x-kubernetes-preserve-unknown-fields: true
  30811. state:
  30812. description: State is the state that was produced by the generator implementation.
  30813. x-kubernetes-preserve-unknown-fields: true
  30814. required:
  30815. - resource
  30816. - state
  30817. type: object
  30818. status:
  30819. description: GeneratorStateStatus defines the observed state of a generator state resource.
  30820. properties:
  30821. conditions:
  30822. items:
  30823. description: GeneratorStateStatusCondition represents the observed condition of a generator state.
  30824. properties:
  30825. lastTransitionTime:
  30826. format: date-time
  30827. type: string
  30828. message:
  30829. type: string
  30830. reason:
  30831. type: string
  30832. status:
  30833. type: string
  30834. type:
  30835. description: GeneratorStateConditionType represents the type of condition for a generator state.
  30836. type: string
  30837. required:
  30838. - status
  30839. - type
  30840. type: object
  30841. type: array
  30842. type: object
  30843. type: object
  30844. served: true
  30845. storage: true
  30846. subresources: {}
  30847. ---
  30848. apiVersion: apiextensions.k8s.io/v1
  30849. kind: CustomResourceDefinition
  30850. metadata:
  30851. annotations:
  30852. controller-gen.kubebuilder.io/version: v0.19.0
  30853. labels:
  30854. external-secrets.io/component: controller
  30855. name: githubaccesstokens.generators.external-secrets.io
  30856. spec:
  30857. group: generators.external-secrets.io
  30858. names:
  30859. categories:
  30860. - external-secrets
  30861. - external-secrets-generators
  30862. kind: GithubAccessToken
  30863. listKind: GithubAccessTokenList
  30864. plural: githubaccesstokens
  30865. singular: githubaccesstoken
  30866. scope: Namespaced
  30867. versions:
  30868. - name: v1alpha1
  30869. schema:
  30870. openAPIV3Schema:
  30871. description: GithubAccessToken generates ghs_ accessToken
  30872. properties:
  30873. apiVersion:
  30874. description: |-
  30875. APIVersion defines the versioned schema of this representation of an object.
  30876. Servers should convert recognized schemas to the latest internal value, and
  30877. may reject unrecognized values.
  30878. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30879. type: string
  30880. kind:
  30881. description: |-
  30882. Kind is a string value representing the REST resource this object represents.
  30883. Servers may infer this from the endpoint the client submits requests to.
  30884. Cannot be updated.
  30885. In CamelCase.
  30886. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30887. type: string
  30888. metadata:
  30889. type: object
  30890. spec:
  30891. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  30892. properties:
  30893. appID:
  30894. type: string
  30895. auth:
  30896. description: Auth configures how ESO authenticates with a Github instance.
  30897. properties:
  30898. privateKey:
  30899. description: GithubSecretRef references a secret containing GitHub credentials.
  30900. properties:
  30901. secretRef:
  30902. description: |-
  30903. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30904. In some instances, `key` is a required field.
  30905. properties:
  30906. key:
  30907. description: |-
  30908. A key in the referenced Secret.
  30909. Some instances of this field may be defaulted, in others it may be required.
  30910. maxLength: 253
  30911. minLength: 1
  30912. pattern: ^[-._a-zA-Z0-9]+$
  30913. type: string
  30914. name:
  30915. description: The name of the Secret resource being referred to.
  30916. maxLength: 253
  30917. minLength: 1
  30918. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30919. type: string
  30920. namespace:
  30921. description: |-
  30922. The namespace of the Secret resource being referred to.
  30923. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30924. maxLength: 63
  30925. minLength: 1
  30926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30927. type: string
  30928. type: object
  30929. required:
  30930. - secretRef
  30931. type: object
  30932. required:
  30933. - privateKey
  30934. type: object
  30935. installID:
  30936. type: string
  30937. permissions:
  30938. additionalProperties:
  30939. type: string
  30940. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  30941. type: object
  30942. repositories:
  30943. description: |-
  30944. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  30945. is installed to.
  30946. items:
  30947. type: string
  30948. type: array
  30949. url:
  30950. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  30951. type: string
  30952. required:
  30953. - appID
  30954. - auth
  30955. - installID
  30956. type: object
  30957. type: object
  30958. served: true
  30959. storage: true
  30960. subresources:
  30961. status: {}
  30962. ---
  30963. apiVersion: apiextensions.k8s.io/v1
  30964. kind: CustomResourceDefinition
  30965. metadata:
  30966. annotations:
  30967. controller-gen.kubebuilder.io/version: v0.19.0
  30968. labels:
  30969. external-secrets.io/component: controller
  30970. name: gitlabdeploytokens.generators.external-secrets.io
  30971. spec:
  30972. group: generators.external-secrets.io
  30973. names:
  30974. categories:
  30975. - external-secrets
  30976. - external-secrets-generators
  30977. kind: GitlabDeployToken
  30978. listKind: GitlabDeployTokenList
  30979. plural: gitlabdeploytokens
  30980. singular: gitlabdeploytoken
  30981. scope: Namespaced
  30982. versions:
  30983. - name: v1alpha1
  30984. schema:
  30985. openAPIV3Schema:
  30986. description: GitlabDeployToken generates a GitLab deploy token.
  30987. properties:
  30988. apiVersion:
  30989. description: |-
  30990. APIVersion defines the versioned schema of this representation of an object.
  30991. Servers should convert recognized schemas to the latest internal value, and
  30992. may reject unrecognized values.
  30993. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30994. type: string
  30995. kind:
  30996. description: |-
  30997. Kind is a string value representing the REST resource this object represents.
  30998. Servers may infer this from the endpoint the client submits requests to.
  30999. Cannot be updated.
  31000. In CamelCase.
  31001. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31002. type: string
  31003. metadata:
  31004. type: object
  31005. spec:
  31006. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  31007. properties:
  31008. auth:
  31009. description: Auth configures how ESO authenticates with the GitLab API.
  31010. properties:
  31011. token:
  31012. description: |-
  31013. Token references a secret containing a GitLab access token (personal, group, or
  31014. project) with the api scope and at least the Maintainer role on the target.
  31015. properties:
  31016. secretRef:
  31017. description: |-
  31018. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  31019. In some instances, `key` is a required field.
  31020. properties:
  31021. key:
  31022. description: |-
  31023. A key in the referenced Secret.
  31024. Some instances of this field may be defaulted, in others it may be required.
  31025. maxLength: 253
  31026. minLength: 1
  31027. pattern: ^[-._a-zA-Z0-9]+$
  31028. type: string
  31029. name:
  31030. description: The name of the Secret resource being referred to.
  31031. maxLength: 253
  31032. minLength: 1
  31033. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31034. type: string
  31035. namespace:
  31036. description: |-
  31037. The namespace of the Secret resource being referred to.
  31038. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31039. maxLength: 63
  31040. minLength: 1
  31041. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31042. type: string
  31043. type: object
  31044. required:
  31045. - secretRef
  31046. type: object
  31047. required:
  31048. - token
  31049. type: object
  31050. expiresAt:
  31051. description: |-
  31052. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  31053. not expire on the GitLab side and is revoked only when the generator state is
  31054. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  31055. format: date-time
  31056. type: string
  31057. groupID:
  31058. description: |-
  31059. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  31060. create the deploy token in. The generator URL-escapes paths before calling the
  31061. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  31062. minLength: 1
  31063. type: string
  31064. name:
  31065. description: Name of the deploy token.
  31066. minLength: 1
  31067. type: string
  31068. projectID:
  31069. description: |-
  31070. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  31071. project to create the deploy token in. The generator URL-escapes paths before
  31072. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  31073. minLength: 1
  31074. type: string
  31075. scopes:
  31076. description: Scopes granted to the deploy token. At least one scope is required.
  31077. items:
  31078. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  31079. enum:
  31080. - read_repository
  31081. - read_registry
  31082. - write_registry
  31083. - read_package_registry
  31084. - write_package_registry
  31085. - read_virtual_registry
  31086. - write_virtual_registry
  31087. type: string
  31088. minItems: 1
  31089. type: array
  31090. url:
  31091. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  31092. type: string
  31093. username:
  31094. description: |-
  31095. Username is an optional username for the deploy token. GitLab defaults it to
  31096. gitlab+deploy-token-{n} when omitted.
  31097. type: string
  31098. required:
  31099. - auth
  31100. - name
  31101. - scopes
  31102. type: object
  31103. x-kubernetes-validations:
  31104. - message: exactly one of projectID or groupID must be set
  31105. rule: has(self.projectID) != has(self.groupID)
  31106. type: object
  31107. served: true
  31108. storage: true
  31109. subresources:
  31110. status: {}
  31111. ---
  31112. apiVersion: apiextensions.k8s.io/v1
  31113. kind: CustomResourceDefinition
  31114. metadata:
  31115. annotations:
  31116. controller-gen.kubebuilder.io/version: v0.19.0
  31117. labels:
  31118. external-secrets.io/component: controller
  31119. name: grafanas.generators.external-secrets.io
  31120. spec:
  31121. group: generators.external-secrets.io
  31122. names:
  31123. categories:
  31124. - external-secrets
  31125. - external-secrets-generators
  31126. kind: Grafana
  31127. listKind: GrafanaList
  31128. plural: grafanas
  31129. singular: grafana
  31130. scope: Namespaced
  31131. versions:
  31132. - name: v1alpha1
  31133. schema:
  31134. openAPIV3Schema:
  31135. description: Grafana represents a generator for Grafana service account tokens.
  31136. properties:
  31137. apiVersion:
  31138. description: |-
  31139. APIVersion defines the versioned schema of this representation of an object.
  31140. Servers should convert recognized schemas to the latest internal value, and
  31141. may reject unrecognized values.
  31142. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31143. type: string
  31144. kind:
  31145. description: |-
  31146. Kind is a string value representing the REST resource this object represents.
  31147. Servers may infer this from the endpoint the client submits requests to.
  31148. Cannot be updated.
  31149. In CamelCase.
  31150. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31151. type: string
  31152. metadata:
  31153. type: object
  31154. spec:
  31155. description: GrafanaSpec controls the behavior of the grafana generator.
  31156. properties:
  31157. auth:
  31158. description: |-
  31159. Auth is the authentication configuration to authenticate
  31160. against the Grafana instance.
  31161. properties:
  31162. basic:
  31163. description: |-
  31164. Basic auth credentials used to authenticate against the Grafana instance.
  31165. Note: you need a token which has elevated permissions to create service accounts.
  31166. See here for the documentation on basic roles offered by Grafana:
  31167. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  31168. properties:
  31169. password:
  31170. description: A basic auth password used to authenticate against the Grafana instance.
  31171. properties:
  31172. key:
  31173. description: The key where the token is found.
  31174. maxLength: 253
  31175. minLength: 1
  31176. pattern: ^[-._a-zA-Z0-9]+$
  31177. type: string
  31178. name:
  31179. description: The name of the Secret resource being referred to.
  31180. maxLength: 253
  31181. minLength: 1
  31182. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31183. type: string
  31184. type: object
  31185. username:
  31186. description: A basic auth username used to authenticate against the Grafana instance.
  31187. type: string
  31188. required:
  31189. - password
  31190. - username
  31191. type: object
  31192. token:
  31193. description: |-
  31194. A service account token used to authenticate against the Grafana instance.
  31195. Note: you need a token which has elevated permissions to create service accounts.
  31196. See here for the documentation on basic roles offered by Grafana:
  31197. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  31198. properties:
  31199. key:
  31200. description: The key where the token is found.
  31201. maxLength: 253
  31202. minLength: 1
  31203. pattern: ^[-._a-zA-Z0-9]+$
  31204. type: string
  31205. name:
  31206. description: The name of the Secret resource being referred to.
  31207. maxLength: 253
  31208. minLength: 1
  31209. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31210. type: string
  31211. type: object
  31212. type: object
  31213. serviceAccount:
  31214. description: |-
  31215. ServiceAccount is the configuration for the service account that
  31216. is supposed to be generated by the generator.
  31217. properties:
  31218. name:
  31219. description: Name is the name of the service account that will be created by ESO.
  31220. type: string
  31221. role:
  31222. description: |-
  31223. Role is the role of the service account.
  31224. See here for the documentation on basic roles offered by Grafana:
  31225. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  31226. type: string
  31227. secondsToLive:
  31228. description: |-
  31229. SecondsToLive is the number of seconds before the generated service account token will expire.
  31230. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  31231. format: int64
  31232. minimum: 1
  31233. type: integer
  31234. required:
  31235. - name
  31236. - role
  31237. type: object
  31238. url:
  31239. description: URL is the URL of the Grafana instance.
  31240. type: string
  31241. required:
  31242. - auth
  31243. - serviceAccount
  31244. - url
  31245. type: object
  31246. type: object
  31247. served: true
  31248. storage: true
  31249. subresources:
  31250. status: {}
  31251. ---
  31252. apiVersion: apiextensions.k8s.io/v1
  31253. kind: CustomResourceDefinition
  31254. metadata:
  31255. annotations:
  31256. controller-gen.kubebuilder.io/version: v0.19.0
  31257. labels:
  31258. external-secrets.io/component: controller
  31259. name: mfas.generators.external-secrets.io
  31260. spec:
  31261. group: generators.external-secrets.io
  31262. names:
  31263. categories:
  31264. - external-secrets
  31265. - external-secrets-generators
  31266. kind: MFA
  31267. listKind: MFAList
  31268. plural: mfas
  31269. singular: mfa
  31270. scope: Namespaced
  31271. versions:
  31272. - name: v1alpha1
  31273. schema:
  31274. openAPIV3Schema:
  31275. description: MFA generates a new TOTP token that is compliant with RFC 6238.
  31276. properties:
  31277. apiVersion:
  31278. description: |-
  31279. APIVersion defines the versioned schema of this representation of an object.
  31280. Servers should convert recognized schemas to the latest internal value, and
  31281. may reject unrecognized values.
  31282. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31283. type: string
  31284. kind:
  31285. description: |-
  31286. Kind is a string value representing the REST resource this object represents.
  31287. Servers may infer this from the endpoint the client submits requests to.
  31288. Cannot be updated.
  31289. In CamelCase.
  31290. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31291. type: string
  31292. metadata:
  31293. type: object
  31294. spec:
  31295. description: MFASpec controls the behavior of the mfa generator.
  31296. properties:
  31297. algorithm:
  31298. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  31299. type: string
  31300. length:
  31301. description: Length defines the token length. Defaults to 6 characters.
  31302. type: integer
  31303. secret:
  31304. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  31305. properties:
  31306. key:
  31307. description: |-
  31308. A key in the referenced Secret.
  31309. Some instances of this field may be defaulted, in others it may be required.
  31310. maxLength: 253
  31311. minLength: 1
  31312. pattern: ^[-._a-zA-Z0-9]+$
  31313. type: string
  31314. name:
  31315. description: The name of the Secret resource being referred to.
  31316. maxLength: 253
  31317. minLength: 1
  31318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31319. type: string
  31320. namespace:
  31321. description: |-
  31322. The namespace of the Secret resource being referred to.
  31323. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31324. maxLength: 63
  31325. minLength: 1
  31326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31327. type: string
  31328. type: object
  31329. timePeriod:
  31330. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  31331. type: integer
  31332. when:
  31333. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  31334. format: date-time
  31335. type: string
  31336. required:
  31337. - secret
  31338. type: object
  31339. type: object
  31340. served: true
  31341. storage: true
  31342. subresources:
  31343. status: {}
  31344. ---
  31345. apiVersion: apiextensions.k8s.io/v1
  31346. kind: CustomResourceDefinition
  31347. metadata:
  31348. annotations:
  31349. controller-gen.kubebuilder.io/version: v0.19.0
  31350. labels:
  31351. external-secrets.io/component: controller
  31352. name: passwords.generators.external-secrets.io
  31353. spec:
  31354. group: generators.external-secrets.io
  31355. names:
  31356. categories:
  31357. - external-secrets
  31358. - external-secrets-generators
  31359. kind: Password
  31360. listKind: PasswordList
  31361. plural: passwords
  31362. singular: password
  31363. scope: Namespaced
  31364. versions:
  31365. - name: v1alpha1
  31366. schema:
  31367. openAPIV3Schema:
  31368. description: |-
  31369. Password generates a random password based on the
  31370. configuration parameters in spec.
  31371. You can specify the length, characterset and other attributes.
  31372. properties:
  31373. apiVersion:
  31374. description: |-
  31375. APIVersion defines the versioned schema of this representation of an object.
  31376. Servers should convert recognized schemas to the latest internal value, and
  31377. may reject unrecognized values.
  31378. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31379. type: string
  31380. kind:
  31381. description: |-
  31382. Kind is a string value representing the REST resource this object represents.
  31383. Servers may infer this from the endpoint the client submits requests to.
  31384. Cannot be updated.
  31385. In CamelCase.
  31386. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31387. type: string
  31388. metadata:
  31389. type: object
  31390. spec:
  31391. description: PasswordSpec controls the behavior of the password generator.
  31392. properties:
  31393. allowRepeat:
  31394. default: false
  31395. description: set AllowRepeat to true to allow repeating characters.
  31396. type: boolean
  31397. digits:
  31398. description: |-
  31399. Digits specifies the number of digits in the generated
  31400. password. If omitted it defaults to 25% of the length of the password
  31401. type: integer
  31402. encoding:
  31403. default: raw
  31404. description: |-
  31405. Encoding specifies the encoding of the generated password.
  31406. Valid values are:
  31407. - "raw" (default): no encoding
  31408. - "base64": standard base64 encoding
  31409. - "base64url": base64url encoding
  31410. - "base32": base32 encoding
  31411. - "hex": hexadecimal encoding
  31412. enum:
  31413. - base64
  31414. - base64url
  31415. - base32
  31416. - hex
  31417. - raw
  31418. type: string
  31419. length:
  31420. default: 24
  31421. description: |-
  31422. Length of the password to be generated.
  31423. Defaults to 24
  31424. type: integer
  31425. noUpper:
  31426. default: false
  31427. description: Set NoUpper to disable uppercase characters
  31428. type: boolean
  31429. secretKeys:
  31430. description: |-
  31431. SecretKeys defines the keys that will be populated with generated passwords.
  31432. Defaults to "password" when not set.
  31433. items:
  31434. type: string
  31435. minItems: 1
  31436. type: array
  31437. symbolCharacters:
  31438. description: |-
  31439. SymbolCharacters specifies the special characters that should be used
  31440. in the generated password.
  31441. type: string
  31442. symbols:
  31443. description: |-
  31444. Symbols specifies the number of symbol characters in the generated
  31445. password. If omitted it defaults to 25% of the length of the password
  31446. type: integer
  31447. required:
  31448. - allowRepeat
  31449. - length
  31450. - noUpper
  31451. type: object
  31452. type: object
  31453. served: true
  31454. storage: true
  31455. subresources:
  31456. status: {}
  31457. ---
  31458. apiVersion: apiextensions.k8s.io/v1
  31459. kind: CustomResourceDefinition
  31460. metadata:
  31461. annotations:
  31462. controller-gen.kubebuilder.io/version: v0.19.0
  31463. labels:
  31464. external-secrets.io/component: controller
  31465. name: quayaccesstokens.generators.external-secrets.io
  31466. spec:
  31467. group: generators.external-secrets.io
  31468. names:
  31469. categories:
  31470. - external-secrets
  31471. - external-secrets-generators
  31472. kind: QuayAccessToken
  31473. listKind: QuayAccessTokenList
  31474. plural: quayaccesstokens
  31475. singular: quayaccesstoken
  31476. scope: Namespaced
  31477. versions:
  31478. - name: v1alpha1
  31479. schema:
  31480. openAPIV3Schema:
  31481. description: QuayAccessToken generates Quay oauth token for pulling/pushing images
  31482. properties:
  31483. apiVersion:
  31484. description: |-
  31485. APIVersion defines the versioned schema of this representation of an object.
  31486. Servers should convert recognized schemas to the latest internal value, and
  31487. may reject unrecognized values.
  31488. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31489. type: string
  31490. kind:
  31491. description: |-
  31492. Kind is a string value representing the REST resource this object represents.
  31493. Servers may infer this from the endpoint the client submits requests to.
  31494. Cannot be updated.
  31495. In CamelCase.
  31496. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31497. type: string
  31498. metadata:
  31499. type: object
  31500. spec:
  31501. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  31502. properties:
  31503. robotAccount:
  31504. description: Name of the robot account you are federating with
  31505. type: string
  31506. serviceAccountRef:
  31507. description: Name of the service account you are federating with
  31508. properties:
  31509. audiences:
  31510. description: |-
  31511. Audience specifies the `aud` claim for the service account token
  31512. Some providers automatically extend the audience field based on well-known annotations for workload
  31513. identity (e.g. IRSA or GCP Workload Identity)
  31514. items:
  31515. type: string
  31516. type: array
  31517. name:
  31518. description: The name of the ServiceAccount resource being referred to.
  31519. maxLength: 253
  31520. minLength: 1
  31521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31522. type: string
  31523. namespace:
  31524. description: |-
  31525. Namespace of the resource being referred to.
  31526. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31527. maxLength: 63
  31528. minLength: 1
  31529. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31530. type: string
  31531. required:
  31532. - name
  31533. type: object
  31534. url:
  31535. description: URL configures the Quay instance URL. Defaults to quay.io.
  31536. type: string
  31537. required:
  31538. - robotAccount
  31539. - serviceAccountRef
  31540. type: object
  31541. type: object
  31542. served: true
  31543. storage: true
  31544. subresources:
  31545. status: {}
  31546. ---
  31547. apiVersion: apiextensions.k8s.io/v1
  31548. kind: CustomResourceDefinition
  31549. metadata:
  31550. annotations:
  31551. controller-gen.kubebuilder.io/version: v0.19.0
  31552. labels:
  31553. external-secrets.io/component: controller
  31554. name: sshkeys.generators.external-secrets.io
  31555. spec:
  31556. group: generators.external-secrets.io
  31557. names:
  31558. categories:
  31559. - external-secrets
  31560. - external-secrets-generators
  31561. kind: SSHKey
  31562. listKind: SSHKeyList
  31563. plural: sshkeys
  31564. singular: sshkey
  31565. scope: Namespaced
  31566. versions:
  31567. - name: v1alpha1
  31568. schema:
  31569. openAPIV3Schema:
  31570. description: SSHKey generates SSH key pairs.
  31571. properties:
  31572. apiVersion:
  31573. description: |-
  31574. APIVersion defines the versioned schema of this representation of an object.
  31575. Servers should convert recognized schemas to the latest internal value, and
  31576. may reject unrecognized values.
  31577. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31578. type: string
  31579. kind:
  31580. description: |-
  31581. Kind is a string value representing the REST resource this object represents.
  31582. Servers may infer this from the endpoint the client submits requests to.
  31583. Cannot be updated.
  31584. In CamelCase.
  31585. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31586. type: string
  31587. metadata:
  31588. type: object
  31589. spec:
  31590. description: SSHKeySpec controls the behavior of the ssh key generator.
  31591. properties:
  31592. comment:
  31593. description: Comment specifies an optional comment for the SSH key
  31594. type: string
  31595. keySize:
  31596. description: |-
  31597. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  31598. For RSA keys: 2048, 3072, 4096
  31599. For ECDSA keys: 256, 384, 521
  31600. Ignored for ed25519 keys
  31601. maximum: 8192
  31602. minimum: 256
  31603. type: integer
  31604. keyType:
  31605. default: rsa
  31606. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  31607. enum:
  31608. - rsa
  31609. - ecdsa
  31610. - ed25519
  31611. type: string
  31612. type: object
  31613. type: object
  31614. served: true
  31615. storage: true
  31616. subresources:
  31617. status: {}
  31618. ---
  31619. apiVersion: apiextensions.k8s.io/v1
  31620. kind: CustomResourceDefinition
  31621. metadata:
  31622. annotations:
  31623. controller-gen.kubebuilder.io/version: v0.19.0
  31624. labels:
  31625. external-secrets.io/component: controller
  31626. name: stssessiontokens.generators.external-secrets.io
  31627. spec:
  31628. group: generators.external-secrets.io
  31629. names:
  31630. categories:
  31631. - external-secrets
  31632. - external-secrets-generators
  31633. kind: STSSessionToken
  31634. listKind: STSSessionTokenList
  31635. plural: stssessiontokens
  31636. singular: stssessiontoken
  31637. scope: Namespaced
  31638. versions:
  31639. - name: v1alpha1
  31640. schema:
  31641. openAPIV3Schema:
  31642. description: |-
  31643. STSSessionToken uses the GetSessionToken API to retrieve an authorization token.
  31644. The authorization token is valid for 12 hours.
  31645. The authorizationToken returned is a base64 encoded string that can be decoded.
  31646. For more information, see GetSessionToken (https://docs.aws.amazon.com/STS/latest/APIReference/API_GetSessionToken.html).
  31647. properties:
  31648. apiVersion:
  31649. description: |-
  31650. APIVersion defines the versioned schema of this representation of an object.
  31651. Servers should convert recognized schemas to the latest internal value, and
  31652. may reject unrecognized values.
  31653. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31654. type: string
  31655. kind:
  31656. description: |-
  31657. Kind is a string value representing the REST resource this object represents.
  31658. Servers may infer this from the endpoint the client submits requests to.
  31659. Cannot be updated.
  31660. In CamelCase.
  31661. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31662. type: string
  31663. metadata:
  31664. type: object
  31665. spec:
  31666. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  31667. properties:
  31668. auth:
  31669. description: Auth defines how to authenticate with AWS
  31670. properties:
  31671. jwt:
  31672. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  31673. properties:
  31674. serviceAccountRef:
  31675. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31676. properties:
  31677. audiences:
  31678. description: |-
  31679. Audience specifies the `aud` claim for the service account token
  31680. Some providers automatically extend the audience field based on well-known annotations for workload
  31681. identity (e.g. IRSA or GCP Workload Identity)
  31682. items:
  31683. type: string
  31684. type: array
  31685. name:
  31686. description: The name of the ServiceAccount resource being referred to.
  31687. maxLength: 253
  31688. minLength: 1
  31689. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31690. type: string
  31691. namespace:
  31692. description: |-
  31693. Namespace of the resource being referred to.
  31694. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31695. maxLength: 63
  31696. minLength: 1
  31697. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31698. type: string
  31699. required:
  31700. - name
  31701. type: object
  31702. type: object
  31703. secretRef:
  31704. description: |-
  31705. AWSAuthSecretRef holds secret references for AWS credentials
  31706. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  31707. properties:
  31708. accessKeyIDSecretRef:
  31709. description: The AccessKeyID is used for authentication
  31710. properties:
  31711. key:
  31712. description: |-
  31713. A key in the referenced Secret.
  31714. Some instances of this field may be defaulted, in others it may be required.
  31715. maxLength: 253
  31716. minLength: 1
  31717. pattern: ^[-._a-zA-Z0-9]+$
  31718. type: string
  31719. name:
  31720. description: The name of the Secret resource being referred to.
  31721. maxLength: 253
  31722. minLength: 1
  31723. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31724. type: string
  31725. namespace:
  31726. description: |-
  31727. The namespace of the Secret resource being referred to.
  31728. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31729. maxLength: 63
  31730. minLength: 1
  31731. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31732. type: string
  31733. type: object
  31734. secretAccessKeySecretRef:
  31735. description: The SecretAccessKey is used for authentication
  31736. properties:
  31737. key:
  31738. description: |-
  31739. A key in the referenced Secret.
  31740. Some instances of this field may be defaulted, in others it may be required.
  31741. maxLength: 253
  31742. minLength: 1
  31743. pattern: ^[-._a-zA-Z0-9]+$
  31744. type: string
  31745. name:
  31746. description: The name of the Secret resource being referred to.
  31747. maxLength: 253
  31748. minLength: 1
  31749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31750. type: string
  31751. namespace:
  31752. description: |-
  31753. The namespace of the Secret resource being referred to.
  31754. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31755. maxLength: 63
  31756. minLength: 1
  31757. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31758. type: string
  31759. type: object
  31760. sessionTokenSecretRef:
  31761. description: |-
  31762. The SessionToken used for authentication
  31763. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  31764. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  31765. properties:
  31766. key:
  31767. description: |-
  31768. A key in the referenced Secret.
  31769. Some instances of this field may be defaulted, in others it may be required.
  31770. maxLength: 253
  31771. minLength: 1
  31772. pattern: ^[-._a-zA-Z0-9]+$
  31773. type: string
  31774. name:
  31775. description: The name of the Secret resource being referred to.
  31776. maxLength: 253
  31777. minLength: 1
  31778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31779. type: string
  31780. namespace:
  31781. description: |-
  31782. The namespace of the Secret resource being referred to.
  31783. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31784. maxLength: 63
  31785. minLength: 1
  31786. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31787. type: string
  31788. type: object
  31789. type: object
  31790. type: object
  31791. region:
  31792. description: Region specifies the region to operate in.
  31793. type: string
  31794. requestParameters:
  31795. description: RequestParameters contains parameters that can be passed to the STS service.
  31796. properties:
  31797. serialNumber:
  31798. description: |-
  31799. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  31800. the GetSessionToken call.
  31801. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  31802. (such as arn:aws:iam::123456789012:mfa/user)
  31803. type: string
  31804. sessionDuration:
  31805. format: int32
  31806. type: integer
  31807. tokenCode:
  31808. description: TokenCode is the value provided by the MFA device, if MFA is required.
  31809. type: string
  31810. type: object
  31811. role:
  31812. description: |-
  31813. You can assume a role before making calls to the
  31814. desired AWS service.
  31815. type: string
  31816. required:
  31817. - region
  31818. type: object
  31819. type: object
  31820. served: true
  31821. storage: true
  31822. subresources:
  31823. status: {}
  31824. ---
  31825. apiVersion: apiextensions.k8s.io/v1
  31826. kind: CustomResourceDefinition
  31827. metadata:
  31828. annotations:
  31829. controller-gen.kubebuilder.io/version: v0.19.0
  31830. labels:
  31831. external-secrets.io/component: controller
  31832. name: uuids.generators.external-secrets.io
  31833. spec:
  31834. group: generators.external-secrets.io
  31835. names:
  31836. categories:
  31837. - external-secrets
  31838. - external-secrets-generators
  31839. kind: UUID
  31840. listKind: UUIDList
  31841. plural: uuids
  31842. singular: uuid
  31843. scope: Namespaced
  31844. versions:
  31845. - name: v1alpha1
  31846. schema:
  31847. openAPIV3Schema:
  31848. description: UUID generates a version 1 UUID (e56657e3-764f-11ef-a397-65231a88c216).
  31849. properties:
  31850. apiVersion:
  31851. description: |-
  31852. APIVersion defines the versioned schema of this representation of an object.
  31853. Servers should convert recognized schemas to the latest internal value, and
  31854. may reject unrecognized values.
  31855. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31856. type: string
  31857. kind:
  31858. description: |-
  31859. Kind is a string value representing the REST resource this object represents.
  31860. Servers may infer this from the endpoint the client submits requests to.
  31861. Cannot be updated.
  31862. In CamelCase.
  31863. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31864. type: string
  31865. metadata:
  31866. type: object
  31867. spec:
  31868. description: UUIDSpec controls the behavior of the uuid generator.
  31869. type: object
  31870. type: object
  31871. served: true
  31872. storage: true
  31873. subresources:
  31874. status: {}
  31875. ---
  31876. apiVersion: apiextensions.k8s.io/v1
  31877. kind: CustomResourceDefinition
  31878. metadata:
  31879. annotations:
  31880. controller-gen.kubebuilder.io/version: v0.19.0
  31881. labels:
  31882. external-secrets.io/component: controller
  31883. name: vaultdynamicsecrets.generators.external-secrets.io
  31884. spec:
  31885. group: generators.external-secrets.io
  31886. names:
  31887. categories:
  31888. - external-secrets
  31889. - external-secrets-generators
  31890. kind: VaultDynamicSecret
  31891. listKind: VaultDynamicSecretList
  31892. plural: vaultdynamicsecrets
  31893. singular: vaultdynamicsecret
  31894. scope: Namespaced
  31895. versions:
  31896. - name: v1alpha1
  31897. schema:
  31898. openAPIV3Schema:
  31899. description: VaultDynamicSecret represents a generator that can create dynamic secrets from HashiCorp Vault.
  31900. properties:
  31901. apiVersion:
  31902. description: |-
  31903. APIVersion defines the versioned schema of this representation of an object.
  31904. Servers should convert recognized schemas to the latest internal value, and
  31905. may reject unrecognized values.
  31906. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31907. type: string
  31908. kind:
  31909. description: |-
  31910. Kind is a string value representing the REST resource this object represents.
  31911. Servers may infer this from the endpoint the client submits requests to.
  31912. Cannot be updated.
  31913. In CamelCase.
  31914. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31915. type: string
  31916. metadata:
  31917. type: object
  31918. spec:
  31919. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  31920. properties:
  31921. allowEmptyResponse:
  31922. default: false
  31923. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  31924. type: boolean
  31925. controller:
  31926. description: |-
  31927. Used to select the correct ESO controller (think: ingress.ingressClassName)
  31928. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  31929. type: string
  31930. getParameters:
  31931. additionalProperties:
  31932. items:
  31933. type: string
  31934. type: array
  31935. description: |-
  31936. GetParameters are query-string parameters passed to Vault on GET calls.
  31937. Each key may map to multiple values, matching HTTP query-string semantics.
  31938. Ignored for non-GET methods; use Parameters for write bodies.
  31939. type: object
  31940. method:
  31941. description: Vault API method to use (GET/POST/other)
  31942. type: string
  31943. parameters:
  31944. description: Parameters to pass to Vault write (for non-GET methods)
  31945. x-kubernetes-preserve-unknown-fields: true
  31946. path:
  31947. description: Vault path to obtain the dynamic secret from
  31948. type: string
  31949. provider:
  31950. description: Vault provider common spec
  31951. properties:
  31952. auth:
  31953. description: Auth configures how secret-manager authenticates with the Vault server.
  31954. properties:
  31955. appRole:
  31956. description: |-
  31957. AppRole authenticates with Vault using the App Role auth mechanism,
  31958. with the role and secret stored in a Kubernetes Secret resource.
  31959. properties:
  31960. path:
  31961. default: approle
  31962. description: |-
  31963. Path where the App Role authentication backend is mounted
  31964. in Vault, e.g: "approle"
  31965. type: string
  31966. roleId:
  31967. description: |-
  31968. RoleID configured in the App Role authentication backend when setting
  31969. up the authentication backend in Vault.
  31970. type: string
  31971. roleRef:
  31972. description: |-
  31973. Reference to a key in a Secret that contains the App Role ID used
  31974. to authenticate with Vault.
  31975. The `key` field must be specified and denotes which entry within the Secret
  31976. resource is used as the app role id.
  31977. properties:
  31978. key:
  31979. description: |-
  31980. A key in the referenced Secret.
  31981. Some instances of this field may be defaulted, in others it may be required.
  31982. maxLength: 253
  31983. minLength: 1
  31984. pattern: ^[-._a-zA-Z0-9]+$
  31985. type: string
  31986. name:
  31987. description: The name of the Secret resource being referred to.
  31988. maxLength: 253
  31989. minLength: 1
  31990. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31991. type: string
  31992. namespace:
  31993. description: |-
  31994. The namespace of the Secret resource being referred to.
  31995. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31996. maxLength: 63
  31997. minLength: 1
  31998. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31999. type: string
  32000. type: object
  32001. secretRef:
  32002. description: |-
  32003. Reference to a key in a Secret that contains the App Role secret used
  32004. to authenticate with Vault.
  32005. The `key` field must be specified and denotes which entry within the Secret
  32006. resource is used as the app role secret.
  32007. properties:
  32008. key:
  32009. description: |-
  32010. A key in the referenced Secret.
  32011. Some instances of this field may be defaulted, in others it may be required.
  32012. maxLength: 253
  32013. minLength: 1
  32014. pattern: ^[-._a-zA-Z0-9]+$
  32015. type: string
  32016. name:
  32017. description: The name of the Secret resource being referred to.
  32018. maxLength: 253
  32019. minLength: 1
  32020. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32021. type: string
  32022. namespace:
  32023. description: |-
  32024. The namespace of the Secret resource being referred to.
  32025. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32026. maxLength: 63
  32027. minLength: 1
  32028. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32029. type: string
  32030. type: object
  32031. required:
  32032. - path
  32033. - secretRef
  32034. type: object
  32035. cert:
  32036. description: |-
  32037. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  32038. Cert authentication method
  32039. properties:
  32040. clientCert:
  32041. description: |-
  32042. ClientCert is a certificate to authenticate using the Cert Vault
  32043. authentication method
  32044. properties:
  32045. key:
  32046. description: |-
  32047. A key in the referenced Secret.
  32048. Some instances of this field may be defaulted, in others it may be required.
  32049. maxLength: 253
  32050. minLength: 1
  32051. pattern: ^[-._a-zA-Z0-9]+$
  32052. type: string
  32053. name:
  32054. description: The name of the Secret resource being referred to.
  32055. maxLength: 253
  32056. minLength: 1
  32057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32058. type: string
  32059. namespace:
  32060. description: |-
  32061. The namespace of the Secret resource being referred to.
  32062. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32063. maxLength: 63
  32064. minLength: 1
  32065. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32066. type: string
  32067. type: object
  32068. path:
  32069. default: cert
  32070. description: |-
  32071. Path where the Certificate authentication backend is mounted
  32072. in Vault, e.g: "cert"
  32073. type: string
  32074. secretRef:
  32075. description: |-
  32076. SecretRef to a key in a Secret resource containing client private key to
  32077. authenticate with Vault using the Cert authentication method
  32078. properties:
  32079. key:
  32080. description: |-
  32081. A key in the referenced Secret.
  32082. Some instances of this field may be defaulted, in others it may be required.
  32083. maxLength: 253
  32084. minLength: 1
  32085. pattern: ^[-._a-zA-Z0-9]+$
  32086. type: string
  32087. name:
  32088. description: The name of the Secret resource being referred to.
  32089. maxLength: 253
  32090. minLength: 1
  32091. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32092. type: string
  32093. namespace:
  32094. description: |-
  32095. The namespace of the Secret resource being referred to.
  32096. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32097. maxLength: 63
  32098. minLength: 1
  32099. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32100. type: string
  32101. type: object
  32102. vaultRole:
  32103. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  32104. type: string
  32105. type: object
  32106. gcp:
  32107. description: |-
  32108. Gcp authenticates with Vault using Google Cloud Platform authentication method
  32109. GCP authentication method
  32110. properties:
  32111. location:
  32112. description: Location optionally defines a location/region for the secret
  32113. type: string
  32114. path:
  32115. default: gcp
  32116. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  32117. type: string
  32118. projectID:
  32119. description: Project ID of the Google Cloud Platform project
  32120. type: string
  32121. role:
  32122. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  32123. type: string
  32124. secretRef:
  32125. description: Specify credentials in a Secret object
  32126. properties:
  32127. secretAccessKeySecretRef:
  32128. description: The SecretAccessKey is used for authentication
  32129. properties:
  32130. key:
  32131. description: |-
  32132. A key in the referenced Secret.
  32133. Some instances of this field may be defaulted, in others it may be required.
  32134. maxLength: 253
  32135. minLength: 1
  32136. pattern: ^[-._a-zA-Z0-9]+$
  32137. type: string
  32138. name:
  32139. description: The name of the Secret resource being referred to.
  32140. maxLength: 253
  32141. minLength: 1
  32142. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32143. type: string
  32144. namespace:
  32145. description: |-
  32146. The namespace of the Secret resource being referred to.
  32147. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32148. maxLength: 63
  32149. minLength: 1
  32150. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32151. type: string
  32152. type: object
  32153. type: object
  32154. serviceAccountRef:
  32155. description: ServiceAccountRef to a service account for impersonation
  32156. properties:
  32157. audiences:
  32158. description: |-
  32159. Audience specifies the `aud` claim for the service account token
  32160. Some providers automatically extend the audience field based on well-known annotations for workload
  32161. identity (e.g. IRSA or GCP Workload Identity)
  32162. items:
  32163. type: string
  32164. type: array
  32165. name:
  32166. description: The name of the ServiceAccount resource being referred to.
  32167. maxLength: 253
  32168. minLength: 1
  32169. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32170. type: string
  32171. namespace:
  32172. description: |-
  32173. Namespace of the resource being referred to.
  32174. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32175. maxLength: 63
  32176. minLength: 1
  32177. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32178. type: string
  32179. required:
  32180. - name
  32181. type: object
  32182. workloadIdentity:
  32183. description: Specify a service account with Workload Identity
  32184. properties:
  32185. clusterLocation:
  32186. description: |-
  32187. ClusterLocation is the location of the cluster
  32188. If not specified, it fetches information from the metadata server
  32189. type: string
  32190. clusterName:
  32191. description: |-
  32192. ClusterName is the name of the cluster
  32193. If not specified, it fetches information from the metadata server
  32194. type: string
  32195. clusterProjectID:
  32196. description: |-
  32197. ClusterProjectID is the project ID of the cluster
  32198. If not specified, it fetches information from the metadata server
  32199. type: string
  32200. serviceAccountRef:
  32201. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  32202. properties:
  32203. audiences:
  32204. description: |-
  32205. Audience specifies the `aud` claim for the service account token
  32206. Some providers automatically extend the audience field based on well-known annotations for workload
  32207. identity (e.g. IRSA or GCP Workload Identity)
  32208. items:
  32209. type: string
  32210. type: array
  32211. name:
  32212. description: The name of the ServiceAccount resource being referred to.
  32213. maxLength: 253
  32214. minLength: 1
  32215. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32216. type: string
  32217. namespace:
  32218. description: |-
  32219. Namespace of the resource being referred to.
  32220. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32221. maxLength: 63
  32222. minLength: 1
  32223. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32224. type: string
  32225. required:
  32226. - name
  32227. type: object
  32228. required:
  32229. - serviceAccountRef
  32230. type: object
  32231. required:
  32232. - role
  32233. type: object
  32234. iam:
  32235. description: |-
  32236. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  32237. AWS IAM authentication method
  32238. properties:
  32239. externalID:
  32240. description: AWS External ID set on assumed IAM roles
  32241. type: string
  32242. jwt:
  32243. description: Specify a service account with IRSA enabled
  32244. properties:
  32245. serviceAccountRef:
  32246. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  32247. properties:
  32248. audiences:
  32249. description: |-
  32250. Audience specifies the `aud` claim for the service account token
  32251. Some providers automatically extend the audience field based on well-known annotations for workload
  32252. identity (e.g. IRSA or GCP Workload Identity)
  32253. items:
  32254. type: string
  32255. type: array
  32256. name:
  32257. description: The name of the ServiceAccount resource being referred to.
  32258. maxLength: 253
  32259. minLength: 1
  32260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32261. type: string
  32262. namespace:
  32263. description: |-
  32264. Namespace of the resource being referred to.
  32265. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32266. maxLength: 63
  32267. minLength: 1
  32268. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32269. type: string
  32270. required:
  32271. - name
  32272. type: object
  32273. type: object
  32274. path:
  32275. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  32276. type: string
  32277. region:
  32278. description: AWS region
  32279. type: string
  32280. role:
  32281. description: This is the AWS role to be assumed before talking to vault
  32282. type: string
  32283. secretRef:
  32284. description: Specify credentials in a Secret object
  32285. properties:
  32286. accessKeyIDSecretRef:
  32287. description: The AccessKeyID is used for authentication
  32288. properties:
  32289. key:
  32290. description: |-
  32291. A key in the referenced Secret.
  32292. Some instances of this field may be defaulted, in others it may be required.
  32293. maxLength: 253
  32294. minLength: 1
  32295. pattern: ^[-._a-zA-Z0-9]+$
  32296. type: string
  32297. name:
  32298. description: The name of the Secret resource being referred to.
  32299. maxLength: 253
  32300. minLength: 1
  32301. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32302. type: string
  32303. namespace:
  32304. description: |-
  32305. The namespace of the Secret resource being referred to.
  32306. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32307. maxLength: 63
  32308. minLength: 1
  32309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32310. type: string
  32311. type: object
  32312. secretAccessKeySecretRef:
  32313. description: The SecretAccessKey is used for authentication
  32314. properties:
  32315. key:
  32316. description: |-
  32317. A key in the referenced Secret.
  32318. Some instances of this field may be defaulted, in others it may be required.
  32319. maxLength: 253
  32320. minLength: 1
  32321. pattern: ^[-._a-zA-Z0-9]+$
  32322. type: string
  32323. name:
  32324. description: The name of the Secret resource being referred to.
  32325. maxLength: 253
  32326. minLength: 1
  32327. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32328. type: string
  32329. namespace:
  32330. description: |-
  32331. The namespace of the Secret resource being referred to.
  32332. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32333. maxLength: 63
  32334. minLength: 1
  32335. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32336. type: string
  32337. type: object
  32338. sessionTokenSecretRef:
  32339. description: |-
  32340. The SessionToken used for authentication
  32341. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  32342. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  32343. properties:
  32344. key:
  32345. description: |-
  32346. A key in the referenced Secret.
  32347. Some instances of this field may be defaulted, in others it may be required.
  32348. maxLength: 253
  32349. minLength: 1
  32350. pattern: ^[-._a-zA-Z0-9]+$
  32351. type: string
  32352. name:
  32353. description: The name of the Secret resource being referred to.
  32354. maxLength: 253
  32355. minLength: 1
  32356. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32357. type: string
  32358. namespace:
  32359. description: |-
  32360. The namespace of the Secret resource being referred to.
  32361. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32362. maxLength: 63
  32363. minLength: 1
  32364. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32365. type: string
  32366. type: object
  32367. type: object
  32368. vaultAwsIamServerID:
  32369. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  32370. type: string
  32371. vaultRole:
  32372. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  32373. type: string
  32374. required:
  32375. - vaultRole
  32376. type: object
  32377. jwt:
  32378. description: |-
  32379. Jwt authenticates with Vault by passing role and JWT token using the
  32380. JWT/OIDC authentication method
  32381. properties:
  32382. kubernetesServiceAccountToken:
  32383. description: |-
  32384. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  32385. a token for with the `TokenRequest` API.
  32386. properties:
  32387. audiences:
  32388. description: |-
  32389. Optional audiences field that will be used to request a temporary Kubernetes service
  32390. account token for the service account referenced by `serviceAccountRef`.
  32391. Defaults to a single audience `vault` it not specified.
  32392. Deprecated: use serviceAccountRef.Audiences instead
  32393. items:
  32394. type: string
  32395. type: array
  32396. expirationSeconds:
  32397. description: |-
  32398. Optional expiration time in seconds that will be used to request a temporary
  32399. Kubernetes service account token for the service account referenced by
  32400. `serviceAccountRef`.
  32401. Deprecated: this will be removed in the future.
  32402. Defaults to 10 minutes.
  32403. format: int64
  32404. type: integer
  32405. serviceAccountRef:
  32406. description: Service account field containing the name of a kubernetes ServiceAccount.
  32407. properties:
  32408. audiences:
  32409. description: |-
  32410. Audience specifies the `aud` claim for the service account token
  32411. Some providers automatically extend the audience field based on well-known annotations for workload
  32412. identity (e.g. IRSA or GCP Workload Identity)
  32413. items:
  32414. type: string
  32415. type: array
  32416. name:
  32417. description: The name of the ServiceAccount resource being referred to.
  32418. maxLength: 253
  32419. minLength: 1
  32420. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32421. type: string
  32422. namespace:
  32423. description: |-
  32424. Namespace of the resource being referred to.
  32425. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32426. maxLength: 63
  32427. minLength: 1
  32428. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32429. type: string
  32430. required:
  32431. - name
  32432. type: object
  32433. required:
  32434. - serviceAccountRef
  32435. type: object
  32436. path:
  32437. default: jwt
  32438. description: |-
  32439. Path where the JWT authentication backend is mounted
  32440. in Vault, e.g: "jwt"
  32441. type: string
  32442. role:
  32443. description: |-
  32444. Role is a JWT role to authenticate using the JWT/OIDC Vault
  32445. authentication method
  32446. type: string
  32447. secretRef:
  32448. description: |-
  32449. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  32450. authenticate with Vault using the JWT/OIDC authentication method.
  32451. properties:
  32452. key:
  32453. description: |-
  32454. A key in the referenced Secret.
  32455. Some instances of this field may be defaulted, in others it may be required.
  32456. maxLength: 253
  32457. minLength: 1
  32458. pattern: ^[-._a-zA-Z0-9]+$
  32459. type: string
  32460. name:
  32461. description: The name of the Secret resource being referred to.
  32462. maxLength: 253
  32463. minLength: 1
  32464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32465. type: string
  32466. namespace:
  32467. description: |-
  32468. The namespace of the Secret resource being referred to.
  32469. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32470. maxLength: 63
  32471. minLength: 1
  32472. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32473. type: string
  32474. type: object
  32475. required:
  32476. - path
  32477. type: object
  32478. kubernetes:
  32479. description: |-
  32480. Kubernetes authenticates with Vault by passing the ServiceAccount
  32481. token stored in the named Secret resource to the Vault server.
  32482. properties:
  32483. mountPath:
  32484. default: kubernetes
  32485. description: |-
  32486. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  32487. "kubernetes"
  32488. type: string
  32489. role:
  32490. description: |-
  32491. A required field containing the Vault Role to assume. A Role binds a
  32492. Kubernetes ServiceAccount with a set of Vault policies.
  32493. type: string
  32494. secretRef:
  32495. description: |-
  32496. Optional secret field containing a Kubernetes ServiceAccount JWT used
  32497. for authenticating with Vault. If a name is specified without a key,
  32498. `token` is the default. If one is not specified, the one bound to
  32499. the controller will be used.
  32500. properties:
  32501. key:
  32502. description: |-
  32503. A key in the referenced Secret.
  32504. Some instances of this field may be defaulted, in others it may be required.
  32505. maxLength: 253
  32506. minLength: 1
  32507. pattern: ^[-._a-zA-Z0-9]+$
  32508. type: string
  32509. name:
  32510. description: The name of the Secret resource being referred to.
  32511. maxLength: 253
  32512. minLength: 1
  32513. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32514. type: string
  32515. namespace:
  32516. description: |-
  32517. The namespace of the Secret resource being referred to.
  32518. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32519. maxLength: 63
  32520. minLength: 1
  32521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32522. type: string
  32523. type: object
  32524. serviceAccountRef:
  32525. description: |-
  32526. Optional service account field containing the name of a kubernetes ServiceAccount.
  32527. If the service account is specified, the service account secret token JWT will be used
  32528. for authenticating with Vault. If the service account selector is not supplied,
  32529. the secretRef will be used instead.
  32530. properties:
  32531. audiences:
  32532. description: |-
  32533. Audience specifies the `aud` claim for the service account token
  32534. Some providers automatically extend the audience field based on well-known annotations for workload
  32535. identity (e.g. IRSA or GCP Workload Identity)
  32536. items:
  32537. type: string
  32538. type: array
  32539. name:
  32540. description: The name of the ServiceAccount resource being referred to.
  32541. maxLength: 253
  32542. minLength: 1
  32543. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32544. type: string
  32545. namespace:
  32546. description: |-
  32547. Namespace of the resource being referred to.
  32548. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32549. maxLength: 63
  32550. minLength: 1
  32551. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32552. type: string
  32553. required:
  32554. - name
  32555. type: object
  32556. required:
  32557. - mountPath
  32558. - role
  32559. type: object
  32560. ldap:
  32561. description: |-
  32562. Ldap authenticates with Vault by passing username/password pair using
  32563. the LDAP authentication method
  32564. properties:
  32565. path:
  32566. default: ldap
  32567. description: |-
  32568. Path where the LDAP authentication backend is mounted
  32569. in Vault, e.g: "ldap"
  32570. type: string
  32571. secretRef:
  32572. description: |-
  32573. SecretRef to a key in a Secret resource containing password for the LDAP
  32574. user used to authenticate with Vault using the LDAP authentication
  32575. method
  32576. properties:
  32577. key:
  32578. description: |-
  32579. A key in the referenced Secret.
  32580. Some instances of this field may be defaulted, in others it may be required.
  32581. maxLength: 253
  32582. minLength: 1
  32583. pattern: ^[-._a-zA-Z0-9]+$
  32584. type: string
  32585. name:
  32586. description: The name of the Secret resource being referred to.
  32587. maxLength: 253
  32588. minLength: 1
  32589. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32590. type: string
  32591. namespace:
  32592. description: |-
  32593. The namespace of the Secret resource being referred to.
  32594. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32595. maxLength: 63
  32596. minLength: 1
  32597. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32598. type: string
  32599. type: object
  32600. username:
  32601. description: |-
  32602. Username is an LDAP username used to authenticate using the LDAP Vault
  32603. authentication method
  32604. type: string
  32605. required:
  32606. - path
  32607. - username
  32608. type: object
  32609. namespace:
  32610. description: |-
  32611. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  32612. Namespaces is a set of features within Vault Enterprise that allows
  32613. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  32614. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  32615. This will default to Vault.Namespace field if set, or empty otherwise
  32616. type: string
  32617. tokenSecretRef:
  32618. description: TokenSecretRef authenticates with Vault by presenting a token.
  32619. properties:
  32620. key:
  32621. description: |-
  32622. A key in the referenced Secret.
  32623. Some instances of this field may be defaulted, in others it may be required.
  32624. maxLength: 253
  32625. minLength: 1
  32626. pattern: ^[-._a-zA-Z0-9]+$
  32627. type: string
  32628. name:
  32629. description: The name of the Secret resource being referred to.
  32630. maxLength: 253
  32631. minLength: 1
  32632. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32633. type: string
  32634. namespace:
  32635. description: |-
  32636. The namespace of the Secret resource being referred to.
  32637. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32638. maxLength: 63
  32639. minLength: 1
  32640. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32641. type: string
  32642. type: object
  32643. userPass:
  32644. description: UserPass authenticates with Vault by passing username/password pair
  32645. properties:
  32646. path:
  32647. default: userpass
  32648. description: |-
  32649. Path where the UserPassword authentication backend is mounted
  32650. in Vault, e.g: "userpass"
  32651. type: string
  32652. secretRef:
  32653. description: |-
  32654. SecretRef to a key in a Secret resource containing password for the
  32655. user used to authenticate with Vault using the UserPass authentication
  32656. method
  32657. properties:
  32658. key:
  32659. description: |-
  32660. A key in the referenced Secret.
  32661. Some instances of this field may be defaulted, in others it may be required.
  32662. maxLength: 253
  32663. minLength: 1
  32664. pattern: ^[-._a-zA-Z0-9]+$
  32665. type: string
  32666. name:
  32667. description: The name of the Secret resource being referred to.
  32668. maxLength: 253
  32669. minLength: 1
  32670. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32671. type: string
  32672. namespace:
  32673. description: |-
  32674. The namespace of the Secret resource being referred to.
  32675. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32676. maxLength: 63
  32677. minLength: 1
  32678. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32679. type: string
  32680. type: object
  32681. username:
  32682. description: |-
  32683. Username is a username used to authenticate using the UserPass Vault
  32684. authentication method
  32685. type: string
  32686. required:
  32687. - path
  32688. - username
  32689. type: object
  32690. type: object
  32691. caBundle:
  32692. description: |-
  32693. PEM encoded CA bundle used to validate Vault server certificate. Only used
  32694. if the Server URL is using HTTPS protocol. This parameter is ignored for
  32695. plain HTTP protocol connection. If not set the system root certificates
  32696. are used to validate the TLS connection.
  32697. format: byte
  32698. type: string
  32699. caProvider:
  32700. description: The provider for the CA bundle to use to validate Vault server certificate.
  32701. properties:
  32702. key:
  32703. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  32704. maxLength: 253
  32705. minLength: 1
  32706. pattern: ^[-._a-zA-Z0-9]+$
  32707. type: string
  32708. name:
  32709. description: The name of the object located at the provider type.
  32710. maxLength: 253
  32711. minLength: 1
  32712. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32713. type: string
  32714. namespace:
  32715. description: |-
  32716. The namespace the Provider type is in.
  32717. Can only be defined when used in a ClusterSecretStore.
  32718. maxLength: 63
  32719. minLength: 1
  32720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32721. type: string
  32722. type:
  32723. description: The type of provider to use such as "Secret", or "ConfigMap".
  32724. enum:
  32725. - Secret
  32726. - ConfigMap
  32727. type: string
  32728. required:
  32729. - name
  32730. - type
  32731. type: object
  32732. checkAndSet:
  32733. description: |-
  32734. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  32735. Only applies to Vault KV v2 stores. When enabled, write operations must include
  32736. the current version of the secret to prevent unintentional overwrites.
  32737. properties:
  32738. required:
  32739. description: |-
  32740. Required when true, all write operations must include a check-and-set parameter.
  32741. This helps prevent unintentional overwrites of secrets.
  32742. type: boolean
  32743. type: object
  32744. forwardInconsistent:
  32745. description: |-
  32746. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  32747. leader instead of simply retrying within a loop. This can increase performance if
  32748. the option is enabled serverside.
  32749. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  32750. type: boolean
  32751. headers:
  32752. additionalProperties:
  32753. type: string
  32754. description: Headers to be added in Vault request
  32755. type: object
  32756. namespace:
  32757. description: |-
  32758. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  32759. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  32760. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  32761. type: string
  32762. path:
  32763. description: |-
  32764. Path is the mount path of the Vault KV backend endpoint, e.g:
  32765. "secret". The v2 KV secret engine version specific "/data" path suffix
  32766. for fetching secrets from Vault is optional and will be appended
  32767. if not present in specified path.
  32768. type: string
  32769. readYourWrites:
  32770. description: |-
  32771. ReadYourWrites ensures isolated read-after-write semantics by
  32772. providing discovered cluster replication states in each request.
  32773. More information about eventual consistency in Vault can be found here
  32774. https://www.vaultproject.io/docs/enterprise/consistency
  32775. type: boolean
  32776. server:
  32777. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  32778. type: string
  32779. tls:
  32780. description: |-
  32781. The configuration used for client side related TLS communication, when the Vault server
  32782. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  32783. This parameter is ignored for plain HTTP protocol connection.
  32784. It's worth noting this configuration is different from the "TLS certificates auth method",
  32785. which is available under the `auth.cert` section.
  32786. properties:
  32787. certSecretRef:
  32788. description: |-
  32789. CertSecretRef is a certificate added to the transport layer
  32790. when communicating with the Vault server.
  32791. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  32792. properties:
  32793. key:
  32794. description: |-
  32795. A key in the referenced Secret.
  32796. Some instances of this field may be defaulted, in others it may be required.
  32797. maxLength: 253
  32798. minLength: 1
  32799. pattern: ^[-._a-zA-Z0-9]+$
  32800. type: string
  32801. name:
  32802. description: The name of the Secret resource being referred to.
  32803. maxLength: 253
  32804. minLength: 1
  32805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32806. type: string
  32807. namespace:
  32808. description: |-
  32809. The namespace of the Secret resource being referred to.
  32810. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32811. maxLength: 63
  32812. minLength: 1
  32813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32814. type: string
  32815. type: object
  32816. keySecretRef:
  32817. description: |-
  32818. KeySecretRef to a key in a Secret resource containing client private key
  32819. added to the transport layer when communicating with the Vault server.
  32820. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  32821. properties:
  32822. key:
  32823. description: |-
  32824. A key in the referenced Secret.
  32825. Some instances of this field may be defaulted, in others it may be required.
  32826. maxLength: 253
  32827. minLength: 1
  32828. pattern: ^[-._a-zA-Z0-9]+$
  32829. type: string
  32830. name:
  32831. description: The name of the Secret resource being referred to.
  32832. maxLength: 253
  32833. minLength: 1
  32834. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32835. type: string
  32836. namespace:
  32837. description: |-
  32838. The namespace of the Secret resource being referred to.
  32839. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32840. maxLength: 63
  32841. minLength: 1
  32842. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32843. type: string
  32844. type: object
  32845. type: object
  32846. version:
  32847. default: v2
  32848. description: |-
  32849. Version is the Vault KV secret engine version. This can be either "v1" or
  32850. "v2". Version defaults to "v2".
  32851. enum:
  32852. - v1
  32853. - v2
  32854. type: string
  32855. required:
  32856. - server
  32857. type: object
  32858. resultType:
  32859. default: Data
  32860. description: |-
  32861. Result type defines which data is returned from the generator.
  32862. By default, it is the "data" section of the Vault API response.
  32863. When using e.g. /auth/token/create the "data" section is empty but
  32864. the "auth" section contains the generated token.
  32865. Please refer to the vault docs regarding the result data structure.
  32866. Additionally, accessing the raw response is possibly by using "Raw" result type.
  32867. enum:
  32868. - Data
  32869. - Auth
  32870. - Raw
  32871. type: string
  32872. retrySettings:
  32873. description: Used to configure http retries if failed
  32874. properties:
  32875. maxRetries:
  32876. format: int32
  32877. type: integer
  32878. retryInterval:
  32879. type: string
  32880. type: object
  32881. required:
  32882. - path
  32883. - provider
  32884. type: object
  32885. type: object
  32886. served: true
  32887. storage: true
  32888. subresources:
  32889. status: {}
  32890. ---
  32891. apiVersion: apiextensions.k8s.io/v1
  32892. kind: CustomResourceDefinition
  32893. metadata:
  32894. annotations:
  32895. controller-gen.kubebuilder.io/version: v0.19.0
  32896. labels:
  32897. external-secrets.io/component: controller
  32898. name: webhooks.generators.external-secrets.io
  32899. spec:
  32900. group: generators.external-secrets.io
  32901. names:
  32902. categories:
  32903. - external-secrets
  32904. - external-secrets-generators
  32905. kind: Webhook
  32906. listKind: WebhookList
  32907. plural: webhooks
  32908. singular: webhook
  32909. scope: Namespaced
  32910. versions:
  32911. - name: v1alpha1
  32912. schema:
  32913. openAPIV3Schema:
  32914. description: |-
  32915. Webhook connects to a third party API server to handle the secrets generation
  32916. configuration parameters in spec.
  32917. You can specify the server, the token, and additional body parameters.
  32918. See documentation for the full API specification for requests and responses.
  32919. properties:
  32920. apiVersion:
  32921. description: |-
  32922. APIVersion defines the versioned schema of this representation of an object.
  32923. Servers should convert recognized schemas to the latest internal value, and
  32924. may reject unrecognized values.
  32925. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  32926. type: string
  32927. kind:
  32928. description: |-
  32929. Kind is a string value representing the REST resource this object represents.
  32930. Servers may infer this from the endpoint the client submits requests to.
  32931. Cannot be updated.
  32932. In CamelCase.
  32933. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  32934. type: string
  32935. metadata:
  32936. type: object
  32937. spec:
  32938. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  32939. properties:
  32940. auth:
  32941. description: Auth specifies a authorization protocol. Only one protocol may be set.
  32942. maxProperties: 1
  32943. minProperties: 1
  32944. properties:
  32945. ntlm:
  32946. description: NTLMProtocol configures the store to use NTLM for auth
  32947. properties:
  32948. passwordSecret:
  32949. description: |-
  32950. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  32951. In some instances, `key` is a required field.
  32952. properties:
  32953. key:
  32954. description: |-
  32955. A key in the referenced Secret.
  32956. Some instances of this field may be defaulted, in others it may be required.
  32957. maxLength: 253
  32958. minLength: 1
  32959. pattern: ^[-._a-zA-Z0-9]+$
  32960. type: string
  32961. name:
  32962. description: The name of the Secret resource being referred to.
  32963. maxLength: 253
  32964. minLength: 1
  32965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32966. type: string
  32967. namespace:
  32968. description: |-
  32969. The namespace of the Secret resource being referred to.
  32970. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32971. maxLength: 63
  32972. minLength: 1
  32973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32974. type: string
  32975. type: object
  32976. usernameSecret:
  32977. description: |-
  32978. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  32979. In some instances, `key` is a required field.
  32980. properties:
  32981. key:
  32982. description: |-
  32983. A key in the referenced Secret.
  32984. Some instances of this field may be defaulted, in others it may be required.
  32985. maxLength: 253
  32986. minLength: 1
  32987. pattern: ^[-._a-zA-Z0-9]+$
  32988. type: string
  32989. name:
  32990. description: The name of the Secret resource being referred to.
  32991. maxLength: 253
  32992. minLength: 1
  32993. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32994. type: string
  32995. namespace:
  32996. description: |-
  32997. The namespace of the Secret resource being referred to.
  32998. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32999. maxLength: 63
  33000. minLength: 1
  33001. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  33002. type: string
  33003. type: object
  33004. required:
  33005. - passwordSecret
  33006. - usernameSecret
  33007. type: object
  33008. type: object
  33009. body:
  33010. description: Body
  33011. type: string
  33012. caBundle:
  33013. description: |-
  33014. PEM encoded CA bundle used to validate webhook server certificate. Only used
  33015. if the Server URL is using HTTPS protocol. This parameter is ignored for
  33016. plain HTTP protocol connection. If not set the system root certificates
  33017. are used to validate the TLS connection.
  33018. format: byte
  33019. type: string
  33020. caProvider:
  33021. description: The provider for the CA bundle to use to validate webhook server certificate.
  33022. properties:
  33023. key:
  33024. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  33025. maxLength: 253
  33026. minLength: 1
  33027. pattern: ^[-._a-zA-Z0-9]+$
  33028. type: string
  33029. name:
  33030. description: The name of the object located at the provider type.
  33031. maxLength: 253
  33032. minLength: 1
  33033. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  33034. type: string
  33035. namespace:
  33036. description: The namespace the Provider type is in.
  33037. maxLength: 63
  33038. minLength: 1
  33039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  33040. type: string
  33041. type:
  33042. description: The type of provider to use such as "Secret", or "ConfigMap".
  33043. enum:
  33044. - Secret
  33045. - ConfigMap
  33046. type: string
  33047. required:
  33048. - name
  33049. - type
  33050. type: object
  33051. headers:
  33052. additionalProperties:
  33053. type: string
  33054. description: Headers
  33055. type: object
  33056. method:
  33057. description: Webhook Method
  33058. type: string
  33059. result:
  33060. description: Result formatting
  33061. properties:
  33062. jsonPath:
  33063. description: Json path of return value
  33064. type: string
  33065. type: object
  33066. secrets:
  33067. description: |-
  33068. Secrets to fill in templates
  33069. These secrets will be passed to the templating function as key value pairs under the given name
  33070. items:
  33071. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  33072. properties:
  33073. name:
  33074. description: Name of this secret in templates
  33075. type: string
  33076. secretRef:
  33077. description: Secret ref to fill in credentials
  33078. properties:
  33079. key:
  33080. description: The key where the token is found.
  33081. maxLength: 253
  33082. minLength: 1
  33083. pattern: ^[-._a-zA-Z0-9]+$
  33084. type: string
  33085. name:
  33086. description: The name of the Secret resource being referred to.
  33087. maxLength: 253
  33088. minLength: 1
  33089. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  33090. type: string
  33091. type: object
  33092. required:
  33093. - name
  33094. - secretRef
  33095. type: object
  33096. type: array
  33097. timeout:
  33098. description: Timeout
  33099. type: string
  33100. url:
  33101. description: Webhook url to call
  33102. type: string
  33103. required:
  33104. - result
  33105. - url
  33106. type: object
  33107. type: object
  33108. served: true
  33109. storage: true
  33110. subresources:
  33111. status: {}