| 12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117211821192120212121222123212421252126212721282129213021312132213321342135213621372138213921402141214221432144214521462147214821492150215121522153215421552156215721582159216021612162216321642165216621672168216921702171217221732174217521762177217821792180218121822183218421852186218721882189219021912192219321942195219621972198219922002201220222032204220522062207220822092210221122122213221422152216221722182219222022212222222322242225222622272228222922302231223222332234223522362237223822392240224122422243224422452246224722482249225022512252225322542255225622572258225922602261226222632264226522662267226822692270227122722273227422752276227722782279228022812282228322842285228622872288228922902291229222932294229522962297229822992300230123022303230423052306230723082309231023112312231323142315231623172318231923202321232223232324232523262327232823292330233123322333233423352336233723382339234023412342234323442345234623472348234923502351235223532354235523562357235823592360236123622363236423652366236723682369237023712372237323742375237623772378237923802381238223832384238523862387238823892390239123922393239423952396239723982399240024012402240324042405240624072408240924102411241224132414241524162417241824192420242124222423242424252426242724282429243024312432243324342435243624372438243924402441244224432444244524462447244824492450245124522453245424552456245724582459246024612462246324642465246624672468246924702471247224732474247524762477247824792480248124822483248424852486248724882489249024912492249324942495249624972498249925002501250225032504250525062507250825092510251125122513251425152516251725182519252025212522252325242525252625272528252925302531253225332534253525362537253825392540254125422543254425452546254725482549255025512552255325542555255625572558255925602561256225632564256525662567256825692570257125722573257425752576257725782579258025812582258325842585258625872588258925902591259225932594259525962597259825992600260126022603260426052606260726082609261026112612261326142615261626172618261926202621262226232624262526262627262826292630263126322633263426352636263726382639264026412642264326442645264626472648264926502651265226532654265526562657265826592660266126622663266426652666266726682669267026712672267326742675267626772678267926802681268226832684268526862687268826892690269126922693269426952696269726982699270027012702270327042705270627072708270927102711271227132714271527162717271827192720272127222723272427252726272727282729273027312732273327342735273627372738273927402741274227432744274527462747274827492750275127522753275427552756275727582759276027612762276327642765276627672768276927702771277227732774277527762777277827792780278127822783278427852786278727882789279027912792279327942795279627972798279928002801280228032804280528062807280828092810281128122813281428152816281728182819282028212822282328242825282628272828282928302831283228332834283528362837283828392840284128422843284428452846284728482849285028512852285328542855285628572858285928602861286228632864286528662867286828692870287128722873287428752876287728782879288028812882288328842885288628872888288928902891289228932894289528962897289828992900290129022903290429052906290729082909291029112912291329142915291629172918291929202921292229232924292529262927292829292930293129322933293429352936293729382939294029412942294329442945294629472948294929502951295229532954295529562957295829592960296129622963296429652966296729682969297029712972297329742975297629772978297929802981298229832984298529862987298829892990299129922993299429952996299729982999300030013002300330043005300630073008300930103011301230133014301530163017301830193020302130223023302430253026302730283029303030313032303330343035303630373038303930403041304230433044304530463047304830493050305130523053305430553056305730583059306030613062306330643065306630673068306930703071307230733074307530763077307830793080308130823083308430853086308730883089309030913092309330943095309630973098309931003101310231033104310531063107310831093110311131123113311431153116311731183119312031213122312331243125312631273128312931303131313231333134313531363137313831393140314131423143314431453146314731483149315031513152315331543155315631573158315931603161316231633164316531663167316831693170317131723173317431753176317731783179318031813182318331843185318631873188318931903191319231933194319531963197319831993200320132023203320432053206320732083209321032113212321332143215321632173218321932203221322232233224322532263227322832293230323132323233323432353236323732383239324032413242324332443245324632473248324932503251325232533254325532563257325832593260326132623263326432653266326732683269327032713272327332743275327632773278327932803281328232833284328532863287328832893290329132923293329432953296329732983299330033013302330333043305330633073308330933103311331233133314331533163317331833193320332133223323332433253326332733283329333033313332333333343335333633373338333933403341334233433344334533463347334833493350335133523353335433553356335733583359336033613362336333643365336633673368336933703371337233733374337533763377337833793380338133823383338433853386338733883389339033913392339333943395339633973398339934003401340234033404340534063407340834093410341134123413341434153416341734183419342034213422342334243425342634273428342934303431343234333434343534363437343834393440344134423443344434453446344734483449345034513452345334543455345634573458345934603461346234633464346534663467346834693470347134723473347434753476347734783479348034813482348334843485348634873488348934903491349234933494349534963497349834993500350135023503350435053506350735083509351035113512351335143515351635173518351935203521352235233524352535263527352835293530353135323533353435353536353735383539354035413542354335443545354635473548354935503551355235533554355535563557355835593560356135623563356435653566356735683569357035713572357335743575357635773578357935803581358235833584358535863587358835893590359135923593359435953596359735983599360036013602360336043605360636073608360936103611361236133614361536163617361836193620362136223623362436253626362736283629363036313632363336343635363636373638363936403641364236433644364536463647364836493650365136523653365436553656365736583659366036613662366336643665366636673668366936703671367236733674367536763677367836793680368136823683368436853686368736883689369036913692369336943695369636973698369937003701370237033704370537063707370837093710371137123713371437153716371737183719372037213722372337243725372637273728372937303731373237333734373537363737373837393740374137423743374437453746374737483749375037513752375337543755375637573758375937603761376237633764376537663767376837693770377137723773377437753776377737783779378037813782378337843785378637873788378937903791379237933794379537963797379837993800380138023803380438053806380738083809381038113812381338143815381638173818381938203821382238233824382538263827382838293830383138323833383438353836383738383839384038413842384338443845384638473848384938503851385238533854385538563857385838593860386138623863386438653866386738683869387038713872387338743875387638773878387938803881388238833884388538863887388838893890389138923893389438953896389738983899390039013902390339043905390639073908390939103911391239133914391539163917391839193920392139223923392439253926392739283929393039313932393339343935393639373938393939403941394239433944394539463947394839493950395139523953395439553956395739583959396039613962396339643965396639673968396939703971397239733974397539763977397839793980398139823983398439853986398739883989399039913992399339943995399639973998399940004001400240034004400540064007400840094010401140124013401440154016401740184019402040214022402340244025402640274028402940304031403240334034403540364037403840394040404140424043404440454046404740484049405040514052405340544055405640574058405940604061406240634064406540664067406840694070407140724073407440754076407740784079408040814082408340844085408640874088408940904091409240934094409540964097409840994100410141024103410441054106410741084109411041114112411341144115411641174118411941204121412241234124412541264127412841294130413141324133413441354136413741384139414041414142414341444145414641474148414941504151415241534154415541564157415841594160416141624163416441654166416741684169417041714172417341744175417641774178417941804181418241834184418541864187418841894190419141924193419441954196419741984199420042014202420342044205420642074208420942104211421242134214421542164217421842194220422142224223422442254226422742284229423042314232423342344235423642374238423942404241424242434244424542464247424842494250425142524253425442554256425742584259426042614262426342644265426642674268426942704271427242734274427542764277427842794280428142824283428442854286428742884289429042914292429342944295429642974298429943004301430243034304430543064307430843094310431143124313431443154316431743184319432043214322432343244325432643274328432943304331433243334334433543364337433843394340434143424343434443454346434743484349435043514352435343544355435643574358435943604361436243634364436543664367436843694370437143724373437443754376437743784379438043814382438343844385438643874388438943904391439243934394439543964397439843994400440144024403440444054406440744084409441044114412441344144415441644174418441944204421442244234424442544264427442844294430443144324433443444354436443744384439444044414442444344444445444644474448444944504451445244534454445544564457445844594460446144624463446444654466446744684469447044714472447344744475447644774478447944804481448244834484448544864487448844894490449144924493449444954496449744984499450045014502450345044505450645074508450945104511451245134514451545164517451845194520452145224523452445254526452745284529453045314532453345344535453645374538453945404541454245434544454545464547454845494550455145524553455445554556455745584559456045614562456345644565456645674568456945704571457245734574457545764577457845794580458145824583458445854586458745884589459045914592459345944595459645974598459946004601460246034604460546064607460846094610461146124613461446154616461746184619462046214622462346244625462646274628462946304631463246334634463546364637463846394640464146424643464446454646464746484649465046514652465346544655465646574658465946604661466246634664466546664667466846694670467146724673467446754676467746784679468046814682468346844685468646874688468946904691469246934694469546964697469846994700470147024703470447054706470747084709471047114712471347144715471647174718471947204721472247234724472547264727472847294730473147324733473447354736473747384739474047414742474347444745474647474748474947504751475247534754475547564757475847594760476147624763476447654766476747684769477047714772477347744775477647774778477947804781478247834784478547864787478847894790479147924793479447954796479747984799480048014802480348044805480648074808480948104811481248134814481548164817481848194820482148224823482448254826482748284829483048314832483348344835483648374838483948404841484248434844484548464847484848494850485148524853485448554856485748584859486048614862486348644865486648674868486948704871487248734874487548764877487848794880488148824883488448854886488748884889489048914892489348944895489648974898489949004901490249034904490549064907490849094910491149124913491449154916491749184919492049214922492349244925492649274928492949304931493249334934493549364937493849394940494149424943494449454946494749484949495049514952495349544955495649574958495949604961496249634964496549664967496849694970497149724973497449754976497749784979498049814982498349844985498649874988498949904991499249934994499549964997499849995000500150025003500450055006500750085009501050115012501350145015501650175018501950205021502250235024502550265027502850295030503150325033503450355036503750385039504050415042504350445045504650475048504950505051505250535054505550565057505850595060506150625063506450655066506750685069507050715072507350745075507650775078507950805081508250835084508550865087508850895090509150925093509450955096509750985099510051015102510351045105510651075108510951105111511251135114511551165117511851195120512151225123512451255126512751285129513051315132513351345135513651375138513951405141514251435144514551465147514851495150515151525153515451555156515751585159516051615162516351645165516651675168516951705171517251735174517551765177517851795180518151825183518451855186518751885189519051915192519351945195519651975198519952005201520252035204520552065207520852095210521152125213521452155216521752185219522052215222522352245225522652275228522952305231523252335234523552365237523852395240524152425243524452455246524752485249525052515252525352545255525652575258525952605261526252635264526552665267526852695270527152725273527452755276527752785279528052815282528352845285528652875288528952905291529252935294529552965297529852995300530153025303530453055306530753085309531053115312531353145315531653175318531953205321532253235324532553265327532853295330533153325333533453355336533753385339534053415342534353445345534653475348534953505351535253535354535553565357535853595360536153625363536453655366536753685369537053715372537353745375537653775378537953805381538253835384538553865387538853895390539153925393539453955396539753985399540054015402540354045405540654075408540954105411541254135414541554165417541854195420542154225423542454255426542754285429543054315432543354345435543654375438543954405441544254435444544554465447544854495450545154525453545454555456545754585459546054615462546354645465546654675468546954705471547254735474547554765477547854795480548154825483548454855486548754885489549054915492549354945495549654975498549955005501550255035504550555065507550855095510551155125513551455155516551755185519552055215522552355245525552655275528552955305531553255335534553555365537553855395540554155425543554455455546554755485549555055515552555355545555555655575558555955605561556255635564556555665567556855695570557155725573557455755576557755785579558055815582558355845585558655875588558955905591559255935594559555965597559855995600560156025603560456055606560756085609561056115612561356145615561656175618561956205621562256235624562556265627562856295630563156325633563456355636563756385639564056415642564356445645564656475648564956505651565256535654565556565657565856595660566156625663566456655666566756685669567056715672567356745675567656775678567956805681568256835684568556865687568856895690569156925693569456955696569756985699570057015702570357045705570657075708570957105711571257135714571557165717571857195720572157225723572457255726572757285729573057315732573357345735573657375738573957405741574257435744574557465747574857495750575157525753575457555756575757585759576057615762576357645765576657675768576957705771577257735774577557765777577857795780578157825783578457855786578757885789579057915792579357945795579657975798579958005801580258035804580558065807580858095810581158125813581458155816581758185819582058215822582358245825582658275828582958305831583258335834583558365837583858395840584158425843584458455846584758485849585058515852585358545855585658575858585958605861586258635864586558665867586858695870587158725873587458755876587758785879588058815882588358845885588658875888588958905891589258935894589558965897589858995900590159025903590459055906590759085909591059115912591359145915591659175918591959205921592259235924592559265927592859295930593159325933593459355936593759385939594059415942594359445945594659475948594959505951595259535954595559565957595859595960596159625963596459655966596759685969597059715972597359745975597659775978597959805981598259835984598559865987598859895990599159925993599459955996599759985999600060016002600360046005600660076008600960106011601260136014601560166017601860196020602160226023602460256026602760286029603060316032603360346035603660376038603960406041604260436044604560466047604860496050605160526053605460556056605760586059606060616062606360646065606660676068606960706071607260736074607560766077607860796080608160826083608460856086608760886089609060916092609360946095609660976098609961006101610261036104610561066107610861096110611161126113611461156116611761186119612061216122612361246125612661276128612961306131613261336134613561366137613861396140614161426143614461456146614761486149615061516152615361546155615661576158615961606161616261636164616561666167616861696170617161726173617461756176617761786179618061816182618361846185618661876188618961906191619261936194619561966197619861996200620162026203620462056206620762086209621062116212621362146215621662176218621962206221622262236224622562266227622862296230623162326233623462356236623762386239624062416242624362446245624662476248624962506251625262536254625562566257625862596260626162626263626462656266626762686269627062716272627362746275627662776278627962806281628262836284628562866287628862896290629162926293629462956296629762986299630063016302630363046305630663076308630963106311631263136314631563166317631863196320632163226323632463256326632763286329633063316332633363346335633663376338633963406341634263436344634563466347634863496350635163526353635463556356635763586359636063616362636363646365636663676368636963706371637263736374637563766377637863796380638163826383638463856386638763886389639063916392639363946395639663976398639964006401640264036404640564066407640864096410641164126413641464156416641764186419642064216422642364246425642664276428642964306431643264336434643564366437643864396440644164426443644464456446644764486449645064516452645364546455645664576458645964606461646264636464646564666467646864696470647164726473647464756476647764786479648064816482648364846485648664876488648964906491649264936494649564966497649864996500650165026503650465056506650765086509651065116512651365146515651665176518651965206521652265236524652565266527652865296530653165326533653465356536653765386539654065416542654365446545654665476548654965506551655265536554655565566557655865596560656165626563656465656566656765686569657065716572657365746575657665776578657965806581658265836584658565866587658865896590659165926593659465956596659765986599660066016602660366046605660666076608660966106611661266136614661566166617661866196620662166226623662466256626662766286629663066316632663366346635663666376638663966406641664266436644664566466647664866496650665166526653665466556656665766586659666066616662666366646665666666676668666966706671667266736674667566766677667866796680668166826683668466856686668766886689669066916692669366946695669666976698669967006701670267036704670567066707670867096710671167126713671467156716671767186719672067216722672367246725672667276728672967306731673267336734673567366737673867396740674167426743674467456746674767486749675067516752675367546755675667576758675967606761676267636764676567666767676867696770677167726773677467756776677767786779678067816782678367846785678667876788678967906791679267936794679567966797679867996800680168026803680468056806680768086809681068116812681368146815681668176818681968206821682268236824682568266827682868296830683168326833683468356836683768386839684068416842684368446845684668476848684968506851685268536854685568566857685868596860686168626863686468656866686768686869687068716872687368746875687668776878687968806881688268836884688568866887688868896890689168926893689468956896689768986899690069016902690369046905690669076908690969106911691269136914691569166917691869196920692169226923692469256926692769286929693069316932693369346935693669376938693969406941694269436944694569466947694869496950695169526953695469556956695769586959696069616962696369646965696669676968696969706971697269736974697569766977697869796980698169826983698469856986698769886989699069916992699369946995699669976998699970007001700270037004700570067007700870097010701170127013701470157016701770187019702070217022702370247025702670277028702970307031703270337034703570367037703870397040704170427043704470457046704770487049705070517052705370547055705670577058705970607061706270637064706570667067706870697070707170727073707470757076707770787079708070817082708370847085708670877088708970907091709270937094709570967097709870997100710171027103710471057106710771087109711071117112711371147115711671177118711971207121712271237124712571267127712871297130713171327133713471357136713771387139714071417142714371447145714671477148714971507151715271537154715571567157715871597160716171627163716471657166716771687169717071717172717371747175717671777178717971807181718271837184718571867187718871897190719171927193719471957196719771987199720072017202720372047205720672077208720972107211721272137214721572167217721872197220722172227223722472257226722772287229723072317232723372347235723672377238723972407241724272437244724572467247724872497250725172527253725472557256725772587259726072617262726372647265726672677268726972707271727272737274727572767277727872797280728172827283728472857286728772887289729072917292729372947295729672977298729973007301730273037304730573067307730873097310731173127313731473157316731773187319732073217322732373247325732673277328732973307331733273337334733573367337733873397340734173427343734473457346734773487349735073517352735373547355735673577358735973607361736273637364736573667367736873697370737173727373737473757376737773787379738073817382738373847385738673877388738973907391739273937394739573967397739873997400740174027403740474057406740774087409741074117412741374147415741674177418741974207421742274237424742574267427742874297430743174327433743474357436743774387439744074417442744374447445744674477448744974507451745274537454745574567457745874597460746174627463746474657466746774687469747074717472747374747475747674777478747974807481748274837484748574867487748874897490749174927493749474957496749774987499750075017502750375047505750675077508750975107511751275137514751575167517751875197520752175227523752475257526752775287529753075317532753375347535753675377538753975407541754275437544754575467547754875497550755175527553755475557556755775587559756075617562756375647565756675677568756975707571757275737574757575767577757875797580758175827583758475857586758775887589759075917592759375947595759675977598759976007601760276037604760576067607760876097610761176127613761476157616761776187619762076217622762376247625762676277628762976307631763276337634763576367637763876397640764176427643764476457646764776487649765076517652765376547655765676577658765976607661766276637664766576667667766876697670767176727673767476757676767776787679768076817682768376847685768676877688768976907691769276937694769576967697769876997700770177027703770477057706770777087709771077117712771377147715771677177718771977207721772277237724772577267727772877297730773177327733773477357736773777387739774077417742774377447745774677477748774977507751775277537754775577567757775877597760776177627763776477657766776777687769777077717772777377747775777677777778777977807781778277837784778577867787778877897790779177927793779477957796779777987799780078017802780378047805780678077808780978107811781278137814781578167817781878197820782178227823782478257826782778287829783078317832783378347835783678377838783978407841784278437844784578467847784878497850785178527853785478557856785778587859786078617862786378647865786678677868786978707871787278737874787578767877787878797880788178827883788478857886788778887889789078917892789378947895789678977898789979007901790279037904790579067907790879097910791179127913791479157916791779187919792079217922792379247925792679277928792979307931793279337934793579367937793879397940794179427943794479457946794779487949795079517952795379547955795679577958795979607961796279637964796579667967796879697970797179727973797479757976797779787979798079817982798379847985798679877988798979907991799279937994799579967997799879998000800180028003800480058006800780088009801080118012801380148015801680178018801980208021802280238024802580268027802880298030803180328033803480358036803780388039804080418042804380448045804680478048804980508051805280538054805580568057805880598060806180628063806480658066806780688069807080718072807380748075807680778078807980808081808280838084808580868087808880898090809180928093809480958096809780988099810081018102810381048105810681078108810981108111811281138114811581168117811881198120812181228123812481258126812781288129813081318132813381348135813681378138813981408141814281438144814581468147814881498150815181528153815481558156815781588159816081618162816381648165816681678168816981708171817281738174817581768177817881798180818181828183818481858186818781888189819081918192819381948195819681978198819982008201820282038204820582068207820882098210821182128213821482158216821782188219822082218222822382248225822682278228822982308231823282338234823582368237823882398240824182428243824482458246824782488249825082518252825382548255825682578258825982608261826282638264826582668267826882698270827182728273827482758276827782788279828082818282828382848285828682878288828982908291829282938294829582968297829882998300830183028303830483058306830783088309831083118312831383148315831683178318831983208321832283238324832583268327832883298330833183328333833483358336833783388339834083418342834383448345834683478348834983508351835283538354835583568357835883598360836183628363836483658366836783688369837083718372837383748375837683778378837983808381838283838384838583868387838883898390839183928393839483958396839783988399840084018402840384048405840684078408840984108411841284138414841584168417841884198420842184228423842484258426842784288429843084318432843384348435843684378438843984408441844284438444844584468447844884498450845184528453845484558456845784588459846084618462846384648465846684678468846984708471847284738474847584768477847884798480848184828483848484858486848784888489849084918492849384948495849684978498849985008501850285038504850585068507850885098510851185128513851485158516851785188519852085218522852385248525852685278528852985308531853285338534853585368537853885398540854185428543854485458546854785488549855085518552855385548555855685578558855985608561856285638564856585668567856885698570857185728573857485758576857785788579858085818582858385848585858685878588858985908591859285938594859585968597859885998600860186028603860486058606860786088609861086118612861386148615861686178618861986208621862286238624862586268627862886298630863186328633863486358636863786388639864086418642864386448645864686478648864986508651865286538654865586568657865886598660866186628663866486658666866786688669867086718672867386748675867686778678867986808681868286838684868586868687868886898690869186928693869486958696869786988699870087018702870387048705870687078708870987108711871287138714871587168717871887198720872187228723872487258726872787288729873087318732873387348735873687378738873987408741874287438744874587468747874887498750875187528753875487558756875787588759876087618762876387648765876687678768876987708771877287738774877587768777877887798780878187828783878487858786878787888789879087918792879387948795879687978798879988008801880288038804880588068807880888098810881188128813881488158816881788188819882088218822882388248825882688278828882988308831883288338834883588368837883888398840884188428843884488458846884788488849885088518852885388548855885688578858885988608861886288638864886588668867886888698870887188728873887488758876887788788879888088818882888388848885888688878888888988908891889288938894889588968897889888998900890189028903890489058906890789088909891089118912891389148915891689178918891989208921892289238924892589268927892889298930893189328933893489358936893789388939894089418942894389448945894689478948894989508951895289538954895589568957895889598960896189628963896489658966896789688969897089718972897389748975897689778978897989808981898289838984898589868987898889898990899189928993899489958996899789988999900090019002900390049005900690079008900990109011901290139014901590169017901890199020902190229023902490259026902790289029903090319032903390349035903690379038903990409041904290439044904590469047904890499050905190529053905490559056905790589059906090619062906390649065906690679068906990709071907290739074907590769077907890799080908190829083908490859086908790889089909090919092909390949095909690979098909991009101910291039104910591069107910891099110911191129113911491159116911791189119912091219122912391249125912691279128912991309131913291339134913591369137913891399140914191429143914491459146914791489149915091519152915391549155915691579158915991609161916291639164916591669167916891699170917191729173917491759176917791789179918091819182918391849185918691879188918991909191919291939194919591969197919891999200920192029203920492059206920792089209921092119212921392149215921692179218921992209221922292239224922592269227922892299230923192329233923492359236923792389239924092419242924392449245924692479248924992509251925292539254925592569257925892599260926192629263926492659266926792689269927092719272927392749275927692779278927992809281928292839284928592869287928892899290929192929293929492959296929792989299930093019302930393049305930693079308930993109311931293139314931593169317931893199320932193229323932493259326932793289329933093319332933393349335933693379338933993409341934293439344934593469347934893499350935193529353935493559356935793589359936093619362936393649365936693679368936993709371937293739374937593769377937893799380938193829383938493859386938793889389939093919392939393949395939693979398939994009401940294039404940594069407940894099410941194129413941494159416941794189419942094219422942394249425942694279428942994309431943294339434943594369437943894399440944194429443944494459446944794489449945094519452945394549455945694579458945994609461946294639464946594669467946894699470947194729473947494759476947794789479948094819482948394849485948694879488948994909491949294939494949594969497949894999500950195029503950495059506950795089509951095119512951395149515951695179518951995209521952295239524952595269527952895299530953195329533953495359536953795389539954095419542954395449545954695479548954995509551955295539554955595569557955895599560956195629563956495659566956795689569957095719572957395749575957695779578957995809581958295839584958595869587958895899590959195929593959495959596959795989599960096019602960396049605960696079608960996109611961296139614961596169617961896199620962196229623962496259626962796289629963096319632963396349635963696379638963996409641964296439644964596469647964896499650965196529653965496559656965796589659966096619662966396649665966696679668966996709671967296739674967596769677967896799680968196829683968496859686968796889689969096919692969396949695969696979698969997009701970297039704970597069707970897099710971197129713971497159716971797189719972097219722972397249725972697279728972997309731973297339734973597369737973897399740974197429743974497459746974797489749975097519752975397549755975697579758975997609761976297639764976597669767976897699770977197729773977497759776977797789779978097819782978397849785978697879788978997909791979297939794979597969797979897999800980198029803980498059806980798089809981098119812981398149815981698179818981998209821982298239824982598269827982898299830983198329833983498359836983798389839984098419842984398449845984698479848984998509851985298539854985598569857985898599860986198629863986498659866986798689869987098719872987398749875987698779878987998809881988298839884988598869887988898899890989198929893989498959896989798989899990099019902990399049905990699079908990999109911991299139914991599169917991899199920992199229923992499259926992799289929993099319932993399349935993699379938993999409941994299439944994599469947994899499950995199529953995499559956995799589959996099619962996399649965996699679968996999709971997299739974997599769977997899799980998199829983998499859986998799889989999099919992999399949995999699979998999910000100011000210003100041000510006100071000810009100101001110012100131001410015100161001710018100191002010021100221002310024100251002610027100281002910030100311003210033100341003510036100371003810039100401004110042100431004410045100461004710048100491005010051100521005310054100551005610057100581005910060100611006210063100641006510066100671006810069100701007110072100731007410075100761007710078100791008010081100821008310084100851008610087100881008910090100911009210093100941009510096100971009810099101001010110102101031010410105101061010710108101091011010111101121011310114101151011610117101181011910120101211012210123101241012510126101271012810129101301013110132101331013410135101361013710138101391014010141101421014310144101451014610147101481014910150101511015210153101541015510156101571015810159101601016110162101631016410165101661016710168101691017010171101721017310174101751017610177101781017910180101811018210183101841018510186101871018810189101901019110192101931019410195101961019710198101991020010201102021020310204102051020610207102081020910210102111021210213102141021510216102171021810219102201022110222102231022410225102261022710228102291023010231102321023310234102351023610237102381023910240102411024210243102441024510246102471024810249102501025110252102531025410255102561025710258102591026010261102621026310264102651026610267102681026910270102711027210273102741027510276102771027810279102801028110282102831028410285102861028710288102891029010291102921029310294102951029610297102981029910300103011030210303103041030510306103071030810309103101031110312103131031410315103161031710318103191032010321103221032310324103251032610327103281032910330103311033210333103341033510336103371033810339103401034110342103431034410345103461034710348103491035010351103521035310354103551035610357103581035910360103611036210363103641036510366103671036810369103701037110372103731037410375103761037710378103791038010381103821038310384103851038610387103881038910390103911039210393103941039510396103971039810399104001040110402104031040410405104061040710408104091041010411104121041310414104151041610417104181041910420104211042210423104241042510426104271042810429104301043110432104331043410435104361043710438104391044010441104421044310444104451044610447104481044910450104511045210453104541045510456104571045810459104601046110462104631046410465104661046710468104691047010471104721047310474104751047610477104781047910480104811048210483104841048510486104871048810489104901049110492104931049410495104961049710498104991050010501105021050310504105051050610507105081050910510105111051210513105141051510516105171051810519105201052110522105231052410525105261052710528105291053010531105321053310534105351053610537105381053910540105411054210543105441054510546105471054810549105501055110552105531055410555105561055710558105591056010561105621056310564105651056610567105681056910570105711057210573105741057510576105771057810579105801058110582105831058410585105861058710588105891059010591105921059310594105951059610597105981059910600106011060210603106041060510606106071060810609106101061110612106131061410615106161061710618106191062010621106221062310624106251062610627106281062910630106311063210633106341063510636106371063810639106401064110642106431064410645106461064710648106491065010651106521065310654106551065610657106581065910660106611066210663106641066510666106671066810669106701067110672106731067410675106761067710678106791068010681106821068310684106851068610687106881068910690106911069210693106941069510696106971069810699107001070110702107031070410705107061070710708107091071010711107121071310714107151071610717107181071910720107211072210723107241072510726107271072810729107301073110732107331073410735107361073710738107391074010741107421074310744107451074610747107481074910750107511075210753107541075510756107571075810759107601076110762107631076410765107661076710768107691077010771107721077310774107751077610777107781077910780107811078210783107841078510786107871078810789107901079110792107931079410795107961079710798107991080010801108021080310804108051080610807108081080910810108111081210813108141081510816108171081810819108201082110822108231082410825108261082710828108291083010831108321083310834108351083610837108381083910840108411084210843108441084510846108471084810849108501085110852108531085410855108561085710858108591086010861108621086310864108651086610867108681086910870108711087210873108741087510876108771087810879108801088110882108831088410885108861088710888108891089010891108921089310894108951089610897108981089910900109011090210903109041090510906109071090810909109101091110912109131091410915109161091710918109191092010921109221092310924109251092610927109281092910930109311093210933109341093510936109371093810939109401094110942109431094410945109461094710948109491095010951109521095310954109551095610957109581095910960109611096210963109641096510966109671096810969109701097110972109731097410975109761097710978109791098010981109821098310984109851098610987109881098910990109911099210993109941099510996109971099810999110001100111002110031100411005110061100711008110091101011011110121101311014110151101611017110181101911020110211102211023110241102511026110271102811029110301103111032110331103411035110361103711038110391104011041110421104311044110451104611047110481104911050110511105211053110541105511056110571105811059110601106111062110631106411065110661106711068110691107011071110721107311074110751107611077110781107911080110811108211083110841108511086110871108811089110901109111092110931109411095110961109711098110991110011101111021110311104111051110611107111081110911110111111111211113111141111511116111171111811119111201112111122111231112411125111261112711128111291113011131111321113311134111351113611137111381113911140111411114211143111441114511146111471114811149111501115111152111531115411155111561115711158111591116011161111621116311164111651116611167111681116911170111711117211173111741117511176111771117811179111801118111182111831118411185111861118711188111891119011191111921119311194111951119611197111981119911200112011120211203112041120511206112071120811209112101121111212112131121411215112161121711218112191122011221112221122311224112251122611227112281122911230112311123211233112341123511236112371123811239112401124111242112431124411245112461124711248112491125011251112521125311254112551125611257112581125911260112611126211263112641126511266112671126811269112701127111272112731127411275112761127711278112791128011281112821128311284112851128611287112881128911290112911129211293112941129511296112971129811299113001130111302113031130411305113061130711308113091131011311113121131311314113151131611317113181131911320113211132211323113241132511326113271132811329113301133111332113331133411335113361133711338113391134011341113421134311344113451134611347113481134911350113511135211353113541135511356113571135811359113601136111362113631136411365113661136711368113691137011371113721137311374113751137611377113781137911380113811138211383113841138511386113871138811389113901139111392113931139411395113961139711398113991140011401114021140311404114051140611407114081140911410114111141211413114141141511416114171141811419114201142111422114231142411425114261142711428114291143011431114321143311434114351143611437114381143911440114411144211443114441144511446114471144811449114501145111452114531145411455114561145711458114591146011461114621146311464114651146611467114681146911470114711147211473114741147511476114771147811479114801148111482114831148411485114861148711488114891149011491114921149311494114951149611497114981149911500115011150211503115041150511506115071150811509115101151111512115131151411515115161151711518115191152011521115221152311524115251152611527115281152911530115311153211533115341153511536115371153811539115401154111542115431154411545115461154711548115491155011551115521155311554115551155611557115581155911560115611156211563115641156511566115671156811569115701157111572115731157411575115761157711578115791158011581115821158311584115851158611587115881158911590115911159211593115941159511596115971159811599116001160111602116031160411605116061160711608116091161011611116121161311614116151161611617116181161911620116211162211623116241162511626116271162811629116301163111632116331163411635116361163711638116391164011641116421164311644116451164611647116481164911650116511165211653116541165511656116571165811659116601166111662116631166411665116661166711668116691167011671116721167311674116751167611677116781167911680116811168211683116841168511686116871168811689116901169111692116931169411695116961169711698116991170011701117021170311704117051170611707117081170911710117111171211713117141171511716117171171811719117201172111722117231172411725117261172711728117291173011731117321173311734117351173611737117381173911740117411174211743117441174511746117471174811749117501175111752117531175411755117561175711758117591176011761117621176311764117651176611767117681176911770117711177211773117741177511776117771177811779117801178111782117831178411785117861178711788117891179011791117921179311794117951179611797117981179911800118011180211803118041180511806118071180811809118101181111812118131181411815118161181711818118191182011821118221182311824118251182611827118281182911830118311183211833118341183511836118371183811839118401184111842118431184411845118461184711848118491185011851118521185311854118551185611857118581185911860118611186211863118641186511866118671186811869118701187111872118731187411875118761187711878118791188011881118821188311884118851188611887118881188911890118911189211893118941189511896118971189811899119001190111902119031190411905119061190711908119091191011911119121191311914119151191611917119181191911920119211192211923119241192511926119271192811929119301193111932119331193411935119361193711938119391194011941119421194311944119451194611947119481194911950119511195211953119541195511956119571195811959119601196111962119631196411965119661196711968119691197011971119721197311974119751197611977119781197911980119811198211983119841198511986119871198811989119901199111992119931199411995119961199711998119991200012001120021200312004120051200612007120081200912010120111201212013120141201512016120171201812019120201202112022120231202412025120261202712028120291203012031120321203312034120351203612037120381203912040120411204212043120441204512046120471204812049120501205112052120531205412055120561205712058120591206012061120621206312064120651206612067120681206912070120711207212073120741207512076120771207812079120801208112082120831208412085120861208712088120891209012091120921209312094120951209612097120981209912100121011210212103121041210512106121071210812109121101211112112121131211412115121161211712118121191212012121121221212312124121251212612127121281212912130121311213212133121341213512136121371213812139121401214112142121431214412145121461214712148121491215012151121521215312154121551215612157121581215912160121611216212163121641216512166121671216812169121701217112172121731217412175121761217712178121791218012181121821218312184121851218612187121881218912190121911219212193121941219512196121971219812199122001220112202122031220412205122061220712208122091221012211122121221312214122151221612217122181221912220122211222212223122241222512226122271222812229122301223112232122331223412235122361223712238122391224012241122421224312244122451224612247122481224912250122511225212253122541225512256122571225812259122601226112262122631226412265122661226712268122691227012271122721227312274122751227612277122781227912280122811228212283122841228512286122871228812289122901229112292122931229412295122961229712298122991230012301123021230312304123051230612307123081230912310123111231212313123141231512316123171231812319123201232112322123231232412325123261232712328123291233012331123321233312334123351233612337123381233912340123411234212343123441234512346123471234812349123501235112352123531235412355123561235712358123591236012361123621236312364123651236612367123681236912370123711237212373123741237512376123771237812379123801238112382123831238412385123861238712388123891239012391123921239312394123951239612397123981239912400124011240212403124041240512406124071240812409124101241112412124131241412415124161241712418124191242012421124221242312424124251242612427124281242912430124311243212433124341243512436124371243812439124401244112442124431244412445124461244712448124491245012451124521245312454124551245612457124581245912460124611246212463124641246512466124671246812469124701247112472124731247412475124761247712478124791248012481124821248312484124851248612487124881248912490124911249212493124941249512496124971249812499125001250112502125031250412505125061250712508125091251012511125121251312514125151251612517125181251912520125211252212523125241252512526125271252812529125301253112532125331253412535125361253712538125391254012541125421254312544125451254612547125481254912550125511255212553125541255512556125571255812559125601256112562125631256412565125661256712568125691257012571125721257312574125751257612577125781257912580125811258212583125841258512586125871258812589125901259112592125931259412595125961259712598125991260012601126021260312604126051260612607126081260912610126111261212613126141261512616126171261812619126201262112622126231262412625126261262712628126291263012631126321263312634126351263612637126381263912640126411264212643126441264512646126471264812649126501265112652126531265412655126561265712658126591266012661126621266312664126651266612667126681266912670126711267212673126741267512676126771267812679126801268112682126831268412685126861268712688126891269012691126921269312694126951269612697126981269912700127011270212703127041270512706127071270812709127101271112712127131271412715127161271712718127191272012721127221272312724127251272612727127281272912730127311273212733127341273512736127371273812739127401274112742127431274412745127461274712748127491275012751127521275312754127551275612757127581275912760127611276212763127641276512766127671276812769127701277112772127731277412775127761277712778127791278012781127821278312784127851278612787127881278912790127911279212793127941279512796127971279812799128001280112802128031280412805128061280712808128091281012811128121281312814128151281612817128181281912820128211282212823128241282512826128271282812829128301283112832128331283412835128361283712838128391284012841128421284312844128451284612847128481284912850128511285212853128541285512856128571285812859128601286112862128631286412865128661286712868128691287012871128721287312874128751287612877128781287912880128811288212883128841288512886128871288812889128901289112892128931289412895128961289712898128991290012901129021290312904129051290612907129081290912910129111291212913129141291512916129171291812919129201292112922129231292412925129261292712928129291293012931129321293312934129351293612937129381293912940129411294212943129441294512946129471294812949129501295112952129531295412955129561295712958129591296012961129621296312964129651296612967129681296912970129711297212973129741297512976129771297812979129801298112982129831298412985129861298712988129891299012991129921299312994129951299612997129981299913000130011300213003130041300513006130071300813009130101301113012130131301413015130161301713018130191302013021130221302313024130251302613027130281302913030130311303213033130341303513036130371303813039130401304113042130431304413045130461304713048130491305013051130521305313054130551305613057130581305913060130611306213063130641306513066130671306813069130701307113072130731307413075130761307713078130791308013081130821308313084130851308613087130881308913090130911309213093130941309513096130971309813099131001310113102131031310413105131061310713108131091311013111131121311313114131151311613117131181311913120131211312213123131241312513126131271312813129131301313113132131331313413135131361313713138131391314013141131421314313144131451314613147131481314913150131511315213153131541315513156131571315813159131601316113162131631316413165131661316713168131691317013171131721317313174131751317613177131781317913180131811318213183131841318513186131871318813189131901319113192131931319413195131961319713198131991320013201132021320313204132051320613207132081320913210132111321213213132141321513216132171321813219132201322113222132231322413225132261322713228132291323013231132321323313234132351323613237132381323913240132411324213243132441324513246132471324813249132501325113252132531325413255132561325713258132591326013261132621326313264132651326613267132681326913270132711327213273132741327513276132771327813279132801328113282132831328413285132861328713288132891329013291132921329313294132951329613297132981329913300133011330213303133041330513306133071330813309133101331113312133131331413315133161331713318133191332013321133221332313324133251332613327133281332913330133311333213333133341333513336133371333813339133401334113342133431334413345133461334713348133491335013351133521335313354133551335613357133581335913360133611336213363133641336513366133671336813369133701337113372133731337413375133761337713378133791338013381133821338313384133851338613387133881338913390133911339213393133941339513396133971339813399134001340113402134031340413405134061340713408134091341013411134121341313414134151341613417134181341913420134211342213423134241342513426134271342813429134301343113432134331343413435134361343713438134391344013441134421344313444134451344613447134481344913450134511345213453134541345513456134571345813459134601346113462134631346413465134661346713468134691347013471134721347313474134751347613477134781347913480134811348213483134841348513486134871348813489134901349113492134931349413495134961349713498134991350013501135021350313504135051350613507135081350913510135111351213513135141351513516135171351813519135201352113522135231352413525135261352713528135291353013531135321353313534135351353613537135381353913540135411354213543135441354513546135471354813549135501355113552135531355413555135561355713558135591356013561135621356313564135651356613567135681356913570135711357213573135741357513576135771357813579135801358113582135831358413585135861358713588135891359013591135921359313594135951359613597135981359913600136011360213603136041360513606136071360813609136101361113612136131361413615136161361713618136191362013621136221362313624136251362613627136281362913630136311363213633136341363513636136371363813639136401364113642136431364413645136461364713648136491365013651136521365313654136551365613657136581365913660136611366213663136641366513666136671366813669136701367113672136731367413675136761367713678136791368013681136821368313684136851368613687136881368913690136911369213693136941369513696136971369813699137001370113702137031370413705137061370713708137091371013711137121371313714137151371613717137181371913720137211372213723137241372513726137271372813729137301373113732137331373413735137361373713738137391374013741137421374313744137451374613747137481374913750137511375213753137541375513756137571375813759137601376113762137631376413765137661376713768137691377013771137721377313774137751377613777137781377913780137811378213783137841378513786137871378813789137901379113792137931379413795137961379713798137991380013801138021380313804138051380613807138081380913810138111381213813138141381513816138171381813819138201382113822138231382413825138261382713828138291383013831138321383313834138351383613837138381383913840138411384213843138441384513846138471384813849138501385113852138531385413855138561385713858138591386013861138621386313864138651386613867138681386913870138711387213873138741387513876138771387813879138801388113882138831388413885138861388713888138891389013891138921389313894138951389613897138981389913900139011390213903139041390513906139071390813909139101391113912139131391413915139161391713918139191392013921139221392313924139251392613927139281392913930139311393213933139341393513936139371393813939139401394113942139431394413945139461394713948139491395013951139521395313954139551395613957139581395913960139611396213963139641396513966139671396813969139701397113972139731397413975139761397713978139791398013981139821398313984139851398613987139881398913990139911399213993139941399513996139971399813999140001400114002140031400414005140061400714008140091401014011140121401314014140151401614017140181401914020140211402214023140241402514026140271402814029140301403114032140331403414035140361403714038140391404014041140421404314044140451404614047140481404914050140511405214053140541405514056140571405814059140601406114062140631406414065140661406714068140691407014071140721407314074140751407614077140781407914080140811408214083140841408514086140871408814089140901409114092140931409414095140961409714098140991410014101141021410314104141051410614107141081410914110141111411214113141141411514116141171411814119141201412114122141231412414125141261412714128141291413014131141321413314134141351413614137141381413914140141411414214143141441414514146141471414814149141501415114152141531415414155141561415714158141591416014161141621416314164141651416614167141681416914170141711417214173141741417514176141771417814179141801418114182141831418414185141861418714188141891419014191141921419314194141951419614197141981419914200142011420214203142041420514206142071420814209142101421114212142131421414215142161421714218142191422014221142221422314224142251422614227142281422914230142311423214233142341423514236142371423814239142401424114242142431424414245142461424714248142491425014251142521425314254142551425614257142581425914260142611426214263142641426514266142671426814269142701427114272142731427414275142761427714278142791428014281142821428314284142851428614287142881428914290142911429214293142941429514296142971429814299143001430114302143031430414305143061430714308143091431014311143121431314314143151431614317143181431914320143211432214323143241432514326143271432814329143301433114332143331433414335143361433714338143391434014341143421434314344143451434614347143481434914350143511435214353143541435514356143571435814359143601436114362143631436414365143661436714368143691437014371143721437314374143751437614377143781437914380143811438214383143841438514386143871438814389143901439114392143931439414395143961439714398143991440014401144021440314404144051440614407144081440914410144111441214413144141441514416144171441814419144201442114422144231442414425144261442714428144291443014431144321443314434144351443614437144381443914440144411444214443144441444514446144471444814449144501445114452144531445414455144561445714458144591446014461144621446314464144651446614467144681446914470144711447214473144741447514476144771447814479144801448114482144831448414485144861448714488144891449014491144921449314494144951449614497144981449914500145011450214503145041450514506145071450814509145101451114512145131451414515145161451714518145191452014521145221452314524145251452614527145281452914530145311453214533145341453514536145371453814539145401454114542145431454414545145461454714548145491455014551145521455314554145551455614557145581455914560145611456214563145641456514566145671456814569145701457114572145731457414575145761457714578145791458014581145821458314584145851458614587145881458914590145911459214593145941459514596145971459814599146001460114602146031460414605146061460714608146091461014611146121461314614146151461614617146181461914620146211462214623146241462514626146271462814629146301463114632146331463414635146361463714638146391464014641146421464314644146451464614647146481464914650146511465214653146541465514656146571465814659146601466114662146631466414665146661466714668146691467014671146721467314674146751467614677146781467914680146811468214683146841468514686146871468814689146901469114692146931469414695146961469714698146991470014701147021470314704147051470614707147081470914710147111471214713147141471514716147171471814719147201472114722147231472414725147261472714728147291473014731147321473314734147351473614737147381473914740147411474214743147441474514746147471474814749147501475114752147531475414755147561475714758147591476014761147621476314764147651476614767147681476914770147711477214773147741477514776147771477814779147801478114782147831478414785147861478714788147891479014791147921479314794147951479614797147981479914800148011480214803148041480514806148071480814809148101481114812148131481414815148161481714818148191482014821148221482314824148251482614827148281482914830148311483214833148341483514836148371483814839148401484114842148431484414845148461484714848148491485014851148521485314854148551485614857148581485914860148611486214863148641486514866148671486814869148701487114872148731487414875148761487714878148791488014881148821488314884148851488614887148881488914890148911489214893148941489514896148971489814899149001490114902149031490414905149061490714908149091491014911149121491314914149151491614917149181491914920149211492214923149241492514926149271492814929149301493114932149331493414935149361493714938149391494014941149421494314944149451494614947149481494914950149511495214953149541495514956149571495814959149601496114962149631496414965149661496714968149691497014971149721497314974149751497614977149781497914980149811498214983149841498514986149871498814989149901499114992149931499414995149961499714998149991500015001150021500315004150051500615007150081500915010150111501215013150141501515016150171501815019150201502115022150231502415025150261502715028150291503015031150321503315034150351503615037150381503915040150411504215043150441504515046150471504815049150501505115052150531505415055150561505715058150591506015061150621506315064150651506615067150681506915070150711507215073150741507515076150771507815079150801508115082150831508415085150861508715088150891509015091150921509315094150951509615097150981509915100151011510215103151041510515106151071510815109151101511115112151131511415115151161511715118151191512015121151221512315124151251512615127151281512915130151311513215133151341513515136151371513815139151401514115142151431514415145151461514715148151491515015151151521515315154151551515615157151581515915160151611516215163151641516515166151671516815169151701517115172151731517415175151761517715178151791518015181151821518315184151851518615187151881518915190151911519215193151941519515196151971519815199152001520115202152031520415205152061520715208152091521015211152121521315214152151521615217152181521915220152211522215223152241522515226152271522815229152301523115232152331523415235152361523715238152391524015241152421524315244152451524615247152481524915250152511525215253152541525515256152571525815259152601526115262152631526415265152661526715268152691527015271152721527315274152751527615277152781527915280152811528215283152841528515286152871528815289152901529115292152931529415295152961529715298152991530015301153021530315304153051530615307153081530915310153111531215313153141531515316153171531815319153201532115322153231532415325153261532715328153291533015331153321533315334153351533615337153381533915340153411534215343153441534515346153471534815349153501535115352153531535415355153561535715358153591536015361153621536315364153651536615367153681536915370153711537215373153741537515376153771537815379153801538115382153831538415385153861538715388153891539015391153921539315394153951539615397153981539915400154011540215403154041540515406154071540815409154101541115412154131541415415154161541715418154191542015421154221542315424154251542615427154281542915430154311543215433154341543515436154371543815439154401544115442154431544415445154461544715448154491545015451154521545315454154551545615457154581545915460154611546215463154641546515466154671546815469154701547115472154731547415475154761547715478154791548015481154821548315484154851548615487154881548915490154911549215493154941549515496154971549815499155001550115502155031550415505155061550715508155091551015511155121551315514155151551615517155181551915520155211552215523155241552515526155271552815529155301553115532155331553415535155361553715538155391554015541155421554315544155451554615547155481554915550155511555215553155541555515556155571555815559155601556115562155631556415565155661556715568155691557015571155721557315574155751557615577155781557915580155811558215583155841558515586155871558815589155901559115592155931559415595155961559715598155991560015601156021560315604156051560615607156081560915610156111561215613156141561515616156171561815619156201562115622156231562415625156261562715628156291563015631156321563315634156351563615637156381563915640156411564215643156441564515646156471564815649156501565115652156531565415655156561565715658156591566015661156621566315664156651566615667156681566915670156711567215673156741567515676156771567815679156801568115682156831568415685156861568715688156891569015691156921569315694156951569615697156981569915700157011570215703157041570515706157071570815709157101571115712157131571415715157161571715718157191572015721157221572315724157251572615727157281572915730157311573215733157341573515736157371573815739157401574115742157431574415745157461574715748157491575015751157521575315754157551575615757157581575915760157611576215763157641576515766157671576815769157701577115772157731577415775157761577715778157791578015781157821578315784157851578615787157881578915790157911579215793157941579515796157971579815799158001580115802158031580415805158061580715808158091581015811158121581315814158151581615817158181581915820158211582215823158241582515826158271582815829158301583115832158331583415835158361583715838158391584015841158421584315844158451584615847158481584915850158511585215853158541585515856158571585815859158601586115862158631586415865158661586715868158691587015871158721587315874158751587615877158781587915880158811588215883158841588515886158871588815889158901589115892158931589415895158961589715898158991590015901159021590315904159051590615907159081590915910159111591215913159141591515916159171591815919159201592115922159231592415925159261592715928159291593015931159321593315934159351593615937159381593915940159411594215943159441594515946159471594815949159501595115952159531595415955159561595715958159591596015961159621596315964159651596615967159681596915970159711597215973159741597515976159771597815979159801598115982159831598415985 |
- <!doctype html>
- <html lang="en" class="no-js">
- <head>
-
- <meta charset="utf-8">
- <meta name="viewport" content="width=device-width,initial-scale=1">
-
-
-
-
- <link rel="prev" href="../generator/sshkey/">
-
-
- <link rel="next" href="../controller-options/">
-
-
- <link rel="icon" href="../../pictures/eso-round-logo.svg">
- <meta name="generator" content="mkdocs-1.6.1, mkdocs-material-9.6.20">
-
-
-
- <title>API specification - External Secrets Operator</title>
-
-
-
- <link rel="stylesheet" href="../../assets/stylesheets/main.e53b48f4.min.css">
-
-
- <link rel="stylesheet" href="../../assets/stylesheets/palette.06af60db.min.css">
-
-
-
-
-
-
-
-
-
-
- <link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
- <link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Roboto:300,300i,400,400i,700,700i%7CRoboto+Mono:400,400i,700,700i&display=fallback">
- <style>:root{--md-text-font:"Roboto";--md-code-font:"Roboto Mono"}</style>
-
-
-
- <script>__md_scope=new URL("../..",location),__md_hash=e=>[...e].reduce(((e,_)=>(e<<5)-e+_.charCodeAt(0)),0),__md_get=(e,_=localStorage,t=__md_scope)=>JSON.parse(_.getItem(t.pathname+"."+e)),__md_set=(e,_,t=localStorage,a=__md_scope)=>{try{t.setItem(a.pathname+"."+e,JSON.stringify(_))}catch(e){}}</script>
-
-
-
-
-
- <script id="__analytics">function __md_analytics(){function e(){dataLayer.push(arguments)}window.dataLayer=window.dataLayer||[],e("js",new Date),e("config","G-QP38TD8K7V"),document.addEventListener("DOMContentLoaded",(function(){document.forms.search&&document.forms.search.query.addEventListener("blur",(function(){this.value&&e("event","search",{search_term:this.value})}));document$.subscribe((function(){var t=document.forms.feedback;if(void 0!==t)for(var a of t.querySelectorAll("[type=submit]"))a.addEventListener("click",(function(a){a.preventDefault();var n=document.location.pathname,d=this.getAttribute("data-md-value");e("event","feedback",{page:n,data:d}),t.firstElementChild.disabled=!0;var r=t.querySelector(".md-feedback__note [data-md-value='"+d+"']");r&&(r.hidden=!1)})),t.hidden=!1})),location$.subscribe((function(t){e("config","G-QP38TD8K7V",{page_path:t.pathname})}))}));var t=document.createElement("script");t.async=!0,t.src="https://www.googletagmanager.com/gtag/js?id=G-QP38TD8K7V",document.getElementById("__analytics").insertAdjacentElement("afterEnd",t)}</script>
-
- <script>"undefined"!=typeof __md_analytics&&__md_analytics()</script>
-
-
-
-
- </head>
-
-
-
-
-
-
-
-
-
- <body dir="ltr" data-md-color-scheme="default" data-md-color-primary="indigo" data-md-color-accent="indigo">
-
-
- <input class="md-toggle" data-md-toggle="drawer" type="checkbox" id="__drawer" autocomplete="off">
- <input class="md-toggle" data-md-toggle="search" type="checkbox" id="__search" autocomplete="off">
- <label class="md-overlay" for="__drawer"></label>
- <div data-md-component="skip">
-
- </div>
- <div data-md-component="announce">
-
- </div>
-
- <div data-md-color-scheme="default" data-md-component="outdated" hidden>
-
- <aside class="md-banner md-banner--warning">
- <div class="md-banner__inner md-grid md-typeset">
-
- You're not viewing the latest version.
- <a href="../../..">
- <strong>Click here to go to latest.</strong>
- </a>
- </div>
- <script>var el=document.querySelector("[data-md-component=outdated]"),base=new URL("../.."),outdated=__md_get("__outdated",sessionStorage,base);!0===outdated&&el&&(el.hidden=!1)</script>
- </aside>
-
- </div>
-
-
-
- <header class="md-header" data-md-component="header">
- <nav class="md-header__inner md-grid" aria-label="Header">
- <a href="../.." title="External Secrets Operator" class="md-header__button md-logo" aria-label="External Secrets Operator" data-md-component="logo">
-
- <img src="../../pictures/eso-round-logo.svg" alt="logo">
- </a>
- <label class="md-header__button md-icon" for="__drawer">
-
- <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M3 6h18v2H3zm0 5h18v2H3zm0 5h18v2H3z"/></svg>
- </label>
- <div class="md-header__title" data-md-component="header-title">
- <div class="md-header__ellipsis">
- <div class="md-header__topic">
- <span class="md-ellipsis">
- External Secrets Operator
- </span>
- </div>
- <div class="md-header__topic" data-md-component="header-topic">
- <span class="md-ellipsis">
-
- API specification
-
- </span>
- </div>
- </div>
- </div>
-
-
- <form class="md-header__option" data-md-component="palette">
-
-
-
-
- <input class="md-option" data-md-color-media="(prefers-color-scheme: light)" data-md-color-scheme="default" data-md-color-primary="indigo" data-md-color-accent="indigo" aria-label="Switch to dark mode" type="radio" name="__palette" id="__palette_0">
-
- <label class="md-header__button md-icon" title="Switch to dark mode" for="__palette_1" hidden>
- <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M12 8a4 4 0 0 0-4 4 4 4 0 0 0 4 4 4 4 0 0 0 4-4 4 4 0 0 0-4-4m0 10a6 6 0 0 1-6-6 6 6 0 0 1 6-6 6 6 0 0 1 6 6 6 6 0 0 1-6 6m8-9.31V4h-4.69L12 .69 8.69 4H4v4.69L.69 12 4 15.31V20h4.69L12 23.31 15.31 20H20v-4.69L23.31 12z"/></svg>
- </label>
-
-
-
-
-
- <input class="md-option" data-md-color-media="(prefers-color-scheme: dark)" data-md-color-scheme="slate" data-md-color-primary="indigo" data-md-color-accent="indigo" aria-label="Switch to light mode" type="radio" name="__palette" id="__palette_1">
-
- <label class="md-header__button md-icon" title="Switch to light mode" for="__palette_0" hidden>
- <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M12 18c-.89 0-1.74-.2-2.5-.55C11.56 16.5 13 14.42 13 12s-1.44-4.5-3.5-5.45C10.26 6.2 11.11 6 12 6a6 6 0 0 1 6 6 6 6 0 0 1-6 6m8-9.31V4h-4.69L12 .69 8.69 4H4v4.69L.69 12 4 15.31V20h4.69L12 23.31 15.31 20H20v-4.69L23.31 12z"/></svg>
- </label>
-
-
- </form>
-
-
-
- <script>var palette=__md_get("__palette");if(palette&&palette.color){if("(prefers-color-scheme)"===palette.color.media){var media=matchMedia("(prefers-color-scheme: light)"),input=document.querySelector(media.matches?"[data-md-color-media='(prefers-color-scheme: light)']":"[data-md-color-media='(prefers-color-scheme: dark)']");palette.color.media=input.getAttribute("data-md-color-media"),palette.color.scheme=input.getAttribute("data-md-color-scheme"),palette.color.primary=input.getAttribute("data-md-color-primary"),palette.color.accent=input.getAttribute("data-md-color-accent")}for(var[key,value]of Object.entries(palette.color))document.body.setAttribute("data-md-color-"+key,value)}</script>
-
-
-
-
-
- <label class="md-header__button md-icon" for="__search">
-
- <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M9.5 3A6.5 6.5 0 0 1 16 9.5c0 1.61-.59 3.09-1.56 4.23l.27.27h.79l5 5-1.5 1.5-5-5v-.79l-.27-.27A6.52 6.52 0 0 1 9.5 16 6.5 6.5 0 0 1 3 9.5 6.5 6.5 0 0 1 9.5 3m0 2C7 5 5 7 5 9.5S7 14 9.5 14 14 12 14 9.5 12 5 9.5 5"/></svg>
- </label>
- <div class="md-search" data-md-component="search" role="dialog">
- <label class="md-search__overlay" for="__search"></label>
- <div class="md-search__inner" role="search">
- <form class="md-search__form" name="search">
- <input type="text" class="md-search__input" name="query" aria-label="Search" placeholder="Search" autocapitalize="off" autocorrect="off" autocomplete="off" spellcheck="false" data-md-component="search-query" required>
- <label class="md-search__icon md-icon" for="__search">
-
- <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M9.5 3A6.5 6.5 0 0 1 16 9.5c0 1.61-.59 3.09-1.56 4.23l.27.27h.79l5 5-1.5 1.5-5-5v-.79l-.27-.27A6.52 6.52 0 0 1 9.5 16 6.5 6.5 0 0 1 3 9.5 6.5 6.5 0 0 1 9.5 3m0 2C7 5 5 7 5 9.5S7 14 9.5 14 14 12 14 9.5 12 5 9.5 5"/></svg>
-
- <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M20 11v2H8l5.5 5.5-1.42 1.42L4.16 12l7.92-7.92L13.5 5.5 8 11z"/></svg>
- </label>
- <nav class="md-search__options" aria-label="Search">
-
- <button type="reset" class="md-search__icon md-icon" title="Clear" aria-label="Clear" tabindex="-1">
-
- <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M19 6.41 17.59 5 12 10.59 6.41 5 5 6.41 10.59 12 5 17.59 6.41 19 12 13.41 17.59 19 19 17.59 13.41 12z"/></svg>
- </button>
- </nav>
-
- </form>
- <div class="md-search__output">
- <div class="md-search__scrollwrap" tabindex="0" data-md-scrollfix>
- <div class="md-search-result" data-md-component="search-result">
- <div class="md-search-result__meta">
- Initializing search
- </div>
- <ol class="md-search-result__list" role="presentation"></ol>
- </div>
- </div>
- </div>
- </div>
- </div>
-
-
-
- <div class="md-header__source">
- <a href="https://github.com/external-secrets/external-secrets" title="Go to repository" class="md-source" data-md-component="source">
- <div class="md-source__icon md-icon">
-
- <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 448 512"><!--! Font Awesome Free 7.0.0 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license/free (Icons: CC BY 4.0, Fonts: SIL OFL 1.1, Code: MIT License) Copyright 2025 Fonticons, Inc.--><path d="M439.6 236.1 244 40.5c-5.4-5.5-12.8-8.5-20.4-8.5s-15 3-20.4 8.4L162.5 81l51.5 51.5c27.1-9.1 52.7 16.8 43.4 43.7l49.7 49.7c34.2-11.8 61.2 31 35.5 56.7-26.5 26.5-70.2-2.9-56-37.3L240.3 199v121.9c25.3 12.5 22.3 41.8 9.1 55-6.4 6.4-15.2 10.1-24.3 10.1s-17.8-3.6-24.3-10.1c-17.6-17.6-11.1-46.9 11.2-56v-123c-20.8-8.5-24.6-30.7-18.6-45L142.6 101 8.5 235.1C3 240.6 0 247.9 0 255.5s3 15 8.5 20.4l195.6 195.7c5.4 5.4 12.7 8.4 20.4 8.4s15-3 20.4-8.4l194.7-194.7c5.4-5.4 8.4-12.8 8.4-20.4s-3-15-8.4-20.4"/></svg>
- </div>
- <div class="md-source__repository">
- External Secrets Operator
- </div>
- </a>
- </div>
-
- </nav>
-
- </header>
-
- <div class="md-container" data-md-component="container">
-
-
-
-
-
- <nav class="md-tabs" aria-label="Tabs" data-md-component="tabs">
- <div class="md-grid">
- <ul class="md-tabs__list">
-
-
-
-
-
-
-
-
- <li class="md-tabs__item">
- <a href="../.." class="md-tabs__link">
-
-
-
-
-
- Introduction
- </a>
- </li>
-
-
-
-
-
-
-
-
-
-
-
-
- <li class="md-tabs__item md-tabs__item--active">
- <a href="../components/" class="md-tabs__link">
-
-
-
-
-
- API
- </a>
- </li>
-
-
-
-
-
-
-
-
-
-
- <li class="md-tabs__item">
- <a href="../../guides/introduction/" class="md-tabs__link">
-
-
-
-
-
- Guides
- </a>
- </li>
-
-
-
-
-
-
-
-
-
-
- <li class="md-tabs__item">
- <a href="../../provider/aws-secrets-manager/" class="md-tabs__link">
-
-
-
-
-
- Provider
- </a>
- </li>
-
-
-
-
-
-
-
-
-
-
- <li class="md-tabs__item">
- <a href="../../examples/gitops-using-fluxcd/" class="md-tabs__link">
-
-
-
-
-
- Examples
- </a>
- </li>
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- <li class="md-tabs__item">
- <a href="../../contributing/devguide/" class="md-tabs__link">
-
-
-
-
-
- Community
- </a>
- </li>
-
-
-
-
-
- </ul>
- </div>
- </nav>
-
-
-
- <main class="md-main" data-md-component="main">
- <div class="md-main__inner md-grid">
-
-
-
- <div class="md-sidebar md-sidebar--primary" data-md-component="sidebar" data-md-type="navigation" >
- <div class="md-sidebar__scrollwrap">
- <div class="md-sidebar__inner">
-
-
- <nav class="md-nav md-nav--primary md-nav--lifted" aria-label="Navigation" data-md-level="0">
- <label class="md-nav__title" for="__drawer">
- <a href="../.." title="External Secrets Operator" class="md-nav__button md-logo" aria-label="External Secrets Operator" data-md-component="logo">
-
- <img src="../../pictures/eso-round-logo.svg" alt="logo">
- </a>
- External Secrets Operator
- </label>
-
- <div class="md-nav__source">
- <a href="https://github.com/external-secrets/external-secrets" title="Go to repository" class="md-source" data-md-component="source">
- <div class="md-source__icon md-icon">
-
- <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 448 512"><!--! Font Awesome Free 7.0.0 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license/free (Icons: CC BY 4.0, Fonts: SIL OFL 1.1, Code: MIT License) Copyright 2025 Fonticons, Inc.--><path d="M439.6 236.1 244 40.5c-5.4-5.5-12.8-8.5-20.4-8.5s-15 3-20.4 8.4L162.5 81l51.5 51.5c27.1-9.1 52.7 16.8 43.4 43.7l49.7 49.7c34.2-11.8 61.2 31 35.5 56.7-26.5 26.5-70.2-2.9-56-37.3L240.3 199v121.9c25.3 12.5 22.3 41.8 9.1 55-6.4 6.4-15.2 10.1-24.3 10.1s-17.8-3.6-24.3-10.1c-17.6-17.6-11.1-46.9 11.2-56v-123c-20.8-8.5-24.6-30.7-18.6-45L142.6 101 8.5 235.1C3 240.6 0 247.9 0 255.5s3 15 8.5 20.4l195.6 195.7c5.4 5.4 12.7 8.4 20.4 8.4s15-3 20.4-8.4l194.7-194.7c5.4-5.4 8.4-12.8 8.4-20.4s-3-15-8.4-20.4"/></svg>
- </div>
- <div class="md-source__repository">
- External Secrets Operator
- </div>
- </a>
- </div>
-
- <ul class="md-nav__list" data-md-scrollfix>
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item md-nav__item--nested">
-
-
-
-
-
- <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_1" >
-
-
- <div class="md-nav__link md-nav__container">
- <a href="../.." class="md-nav__link ">
-
-
-
- <span class="md-ellipsis">
- Introduction
-
- </span>
-
- </a>
-
-
- <label class="md-nav__link " for="__nav_1" id="__nav_1_label" tabindex="0">
- <span class="md-nav__icon md-icon"></span>
- </label>
-
- </div>
-
- <nav class="md-nav" data-md-level="1" aria-labelledby="__nav_1_label" aria-expanded="false">
- <label class="md-nav__title" for="__nav_1">
- <span class="md-nav__icon md-icon"></span>
- Introduction
- </label>
- <ul class="md-nav__list" data-md-scrollfix>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../introduction/overview/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Overview
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../introduction/glossary/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Glossary
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../introduction/prerequisites/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Prerequisites
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../introduction/getting-started/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Getting started
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../introduction/faq/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- FAQ
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../introduction/stability-support/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Stability and Support
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../introduction/deprecation-policy/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Deprecation Policy
-
- </span>
-
- </a>
- </li>
-
-
-
- </ul>
- </nav>
-
- </li>
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item md-nav__item--active md-nav__item--section md-nav__item--nested">
-
-
-
- <input class="md-nav__toggle md-toggle " type="checkbox" id="__nav_2" checked>
-
-
- <label class="md-nav__link" for="__nav_2" id="__nav_2_label" tabindex="">
-
-
-
- <span class="md-ellipsis">
- API
-
- </span>
-
- <span class="md-nav__icon md-icon"></span>
- </label>
-
- <nav class="md-nav" data-md-level="1" aria-labelledby="__nav_2_label" aria-expanded="true">
- <label class="md-nav__title" for="__nav_2">
- <span class="md-nav__icon md-icon"></span>
- API
- </label>
- <ul class="md-nav__list" data-md-scrollfix>
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../components/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Components
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item md-nav__item--nested">
-
-
-
-
-
- <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_2_2" >
-
-
- <label class="md-nav__link" for="__nav_2_2" id="__nav_2_2_label" tabindex="0">
-
-
-
- <span class="md-ellipsis">
- Core Resources
-
- </span>
-
- <span class="md-nav__icon md-icon"></span>
- </label>
-
- <nav class="md-nav" data-md-level="2" aria-labelledby="__nav_2_2_label" aria-expanded="false">
- <label class="md-nav__title" for="__nav_2_2">
- <span class="md-nav__icon md-icon"></span>
- Core Resources
- </label>
- <ul class="md-nav__list" data-md-scrollfix>
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../externalsecret/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- ExternalSecret
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../secretstore/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- SecretStore
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../clustersecretstore/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- ClusterSecretStore
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../clusterexternalsecret/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- ClusterExternalSecret
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../clusterpushsecret/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- ClusterPushSecret
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../pushsecret/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- PushSecret
-
- </span>
-
- </a>
- </li>
-
-
-
- </ul>
- </nav>
-
- </li>
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item md-nav__item--nested">
-
-
-
-
-
- <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_2_3" >
-
-
- <div class="md-nav__link md-nav__container">
- <a href="../generator/" class="md-nav__link ">
-
-
-
- <span class="md-ellipsis">
- Generators
-
- </span>
-
- </a>
-
-
- <label class="md-nav__link " for="__nav_2_3" id="__nav_2_3_label" tabindex="0">
- <span class="md-nav__icon md-icon"></span>
- </label>
-
- </div>
-
- <nav class="md-nav" data-md-level="2" aria-labelledby="__nav_2_3_label" aria-expanded="false">
- <label class="md-nav__title" for="__nav_2_3">
- <span class="md-nav__icon md-icon"></span>
- Generators
- </label>
- <ul class="md-nav__list" data-md-scrollfix>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../generator/acr/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Azure Container Registry
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../generator/ecr/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- AWS Elastic Container Registry
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../generator/sts/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- AWS STS Session Token
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../generator/cloudsmith/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Cloudsmith
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../generator/cluster/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Cluster Generator
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../generator/gcr/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Google Container Registry
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../generator/quay/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Quay
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../generator/vault/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Vault Dynamic Secret
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../generator/password/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Password
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../generator/fake/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Fake
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../generator/webhook/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Webhook
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../generator/github/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Github
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../generator/uuid/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- UUID
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../generator/mfa/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- MFA
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../generator/sshkey/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- SSHKey
-
- </span>
-
- </a>
- </li>
-
-
-
- </ul>
- </nav>
-
- </li>
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item md-nav__item--active md-nav__item--nested">
-
-
-
- <input class="md-nav__toggle md-toggle " type="checkbox" id="__nav_2_4" checked>
-
-
- <label class="md-nav__link" for="__nav_2_4" id="__nav_2_4_label" tabindex="0">
-
-
-
- <span class="md-ellipsis">
- Reference Docs
-
- </span>
-
- <span class="md-nav__icon md-icon"></span>
- </label>
-
- <nav class="md-nav" data-md-level="2" aria-labelledby="__nav_2_4_label" aria-expanded="true">
- <label class="md-nav__title" for="__nav_2_4">
- <span class="md-nav__icon md-icon"></span>
- Reference Docs
- </label>
- <ul class="md-nav__list" data-md-scrollfix>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item md-nav__item--active">
-
- <input class="md-nav__toggle md-toggle" type="checkbox" id="__toc">
-
-
-
- <a href="./" class="md-nav__link md-nav__link--active">
-
-
-
- <span class="md-ellipsis">
- API specification
-
- </span>
-
- </a>
-
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../controller-options/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Controller Options
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../metrics/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Metrics
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../selectable-fields/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Selectable Fields
-
- </span>
-
- </a>
- </li>
-
-
-
- </ul>
- </nav>
-
- </li>
-
-
-
- </ul>
- </nav>
-
- </li>
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item md-nav__item--nested">
-
-
-
-
-
- <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_3" >
-
-
- <label class="md-nav__link" for="__nav_3" id="__nav_3_label" tabindex="0">
-
-
-
- <span class="md-ellipsis">
- Guides
-
- </span>
-
- <span class="md-nav__icon md-icon"></span>
- </label>
-
- <nav class="md-nav" data-md-level="1" aria-labelledby="__nav_3_label" aria-expanded="false">
- <label class="md-nav__title" for="__nav_3">
- <span class="md-nav__icon md-icon"></span>
- Guides
- </label>
- <ul class="md-nav__list" data-md-scrollfix>
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../guides/introduction/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Introduction
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item md-nav__item--nested">
-
-
-
-
-
- <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_3_2" >
-
-
- <label class="md-nav__link" for="__nav_3_2" id="__nav_3_2_label" tabindex="0">
-
-
-
- <span class="md-ellipsis">
- External Secrets
-
- </span>
-
- <span class="md-nav__icon md-icon"></span>
- </label>
-
- <nav class="md-nav" data-md-level="2" aria-labelledby="__nav_3_2_label" aria-expanded="false">
- <label class="md-nav__title" for="__nav_3_2">
- <span class="md-nav__icon md-icon"></span>
- External Secrets
- </label>
- <ul class="md-nav__list" data-md-scrollfix>
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../guides/all-keys-one-secret/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Extract structured data
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../guides/getallsecrets/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Find Secrets by Name or Metadata
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../guides/datafrom-rewrite/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Rewriting Keys
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item md-nav__item--nested">
-
-
-
-
-
- <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_3_2_4" >
-
-
- <label class="md-nav__link" for="__nav_3_2_4" id="__nav_3_2_4_label" tabindex="0">
-
-
-
- <span class="md-ellipsis">
- Advanced Templating
-
- </span>
-
- <span class="md-nav__icon md-icon"></span>
- </label>
-
- <nav class="md-nav" data-md-level="3" aria-labelledby="__nav_3_2_4_label" aria-expanded="false">
- <label class="md-nav__title" for="__nav_3_2_4">
- <span class="md-nav__icon md-icon"></span>
- Advanced Templating
- </label>
- <ul class="md-nav__list" data-md-scrollfix>
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../guides/templating/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- v2
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../guides/templating-v1/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- v1
-
- </span>
-
- </a>
- </li>
-
-
-
- </ul>
- </nav>
-
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../guides/common-k8s-secret-types/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Kubernetes Secret Types
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../guides/ownership-deletion-policy/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Lifecycle: ownership & deletion
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../guides/decoding-strategy/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Decoding Strategies
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../guides/controller-class/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Controller Classes
-
- </span>
-
- </a>
- </li>
-
-
-
- </ul>
- </nav>
-
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../guides/generator/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Generators
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../guides/pushsecrets/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Push Secrets
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item md-nav__item--nested">
-
-
-
-
-
- <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_3_5" >
-
-
- <label class="md-nav__link" for="__nav_3_5" id="__nav_3_5_label" tabindex="0">
-
-
-
- <span class="md-ellipsis">
- Operations
-
- </span>
-
- <span class="md-nav__icon md-icon"></span>
- </label>
-
- <nav class="md-nav" data-md-level="2" aria-labelledby="__nav_3_5_label" aria-expanded="false">
- <label class="md-nav__title" for="__nav_3_5">
- <span class="md-nav__icon md-icon"></span>
- Operations
- </label>
- <ul class="md-nav__list" data-md-scrollfix>
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../guides/multi-tenancy/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Multi Tenancy
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../guides/security-best-practices/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Security Best Practices
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../guides/threat-model/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Threat Model
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../guides/v1beta1/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Upgrading to v1beta1
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../guides/using-latest-image/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Using Latest Image
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../guides/disable-cluster-features/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Disable Cluster Features
-
- </span>
-
- </a>
- </li>
-
-
-
- </ul>
- </nav>
-
- </li>
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item md-nav__item--nested">
-
-
-
-
-
- <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_3_6" >
-
-
- <label class="md-nav__link" for="__nav_3_6" id="__nav_3_6_label" tabindex="0">
-
-
-
- <span class="md-ellipsis">
- Tooling
-
- </span>
-
- <span class="md-nav__icon md-icon"></span>
- </label>
-
- <nav class="md-nav" data-md-level="2" aria-labelledby="__nav_3_6_label" aria-expanded="false">
- <label class="md-nav__title" for="__nav_3_6">
- <span class="md-nav__icon md-icon"></span>
- Tooling
- </label>
- <ul class="md-nav__list" data-md-scrollfix>
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../guides/using-esoctl-tool/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Using the esoctl tool
-
- </span>
-
- </a>
- </li>
-
-
-
- </ul>
- </nav>
-
- </li>
-
-
-
- </ul>
- </nav>
-
- </li>
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item md-nav__item--nested">
-
-
-
-
-
- <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_4" >
-
-
- <label class="md-nav__link" for="__nav_4" id="__nav_4_label" tabindex="0">
-
-
-
- <span class="md-ellipsis">
- Provider
-
- </span>
-
- <span class="md-nav__icon md-icon"></span>
- </label>
-
- <nav class="md-nav" data-md-level="1" aria-labelledby="__nav_4_label" aria-expanded="false">
- <label class="md-nav__title" for="__nav_4">
- <span class="md-nav__icon md-icon"></span>
- Provider
- </label>
- <ul class="md-nav__list" data-md-scrollfix>
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/aws-secrets-manager/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- AWS Secrets Manager
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/aws-parameter-store/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- AWS Parameter Store
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/azure-key-vault/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Azure Key Vault
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/beyondtrust/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- BeyondTrust
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/bitwarden-secrets-manager/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Bitwarden Secrets Manager
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/chef/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Chef
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/cloudru/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Cloud.ru Secret Manager
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/conjur/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- CyberArk Conjur
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/device42/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Device42
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/google-secrets-manager/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Google Cloud Secret Manager
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/hashicorp-vault/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- HashiCorp Vault
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/kubernetes/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Kubernetes
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/ibm-secrets-manager/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- IBM Secrets Manager
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/akeyless/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Akeyless
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/yandex-certificate-manager/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Yandex Certificate Manager
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/yandex-lockbox/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Yandex Lockbox
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/alibaba/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Alibaba Cloud
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/gitlab-variables/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- GitLab Variables
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/github/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Github Actions Secrets
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/oracle-vault/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Oracle Vault
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/1password-automation/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- 1Password Connect Server
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/1password-sdk/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- 1Password SDK
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/webhook/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Webhook
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/fake/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Fake
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/senhasegura-dsm/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- senhasegura DevOps Secrets Management (DSM)
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/doppler/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Doppler
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/keeper-security/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Keeper Security
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/cloak/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Cloak End 2 End Encrypted Secrets
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/scaleway/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Scaleway
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/delinea/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Delinea
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/secretserver/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Secret Server
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/passbolt/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Passbolt
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/pulumi/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Pulumi ESC
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/onboardbase/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Onboardbase
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider-passworddepot/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Password Depot
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/fortanix/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Fortanix
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/infisical/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Infisical
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/previder/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Previder
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/openbao/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- OpenBao
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/volcengine/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Volcengine
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../provider/ngrok/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- ngrok
-
- </span>
-
- </a>
- </li>
-
-
-
- </ul>
- </nav>
-
- </li>
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item md-nav__item--nested">
-
-
-
-
-
- <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_5" >
-
-
- <label class="md-nav__link" for="__nav_5" id="__nav_5_label" tabindex="0">
-
-
-
- <span class="md-ellipsis">
- Examples
-
- </span>
-
- <span class="md-nav__icon md-icon"></span>
- </label>
-
- <nav class="md-nav" data-md-level="1" aria-labelledby="__nav_5_label" aria-expanded="false">
- <label class="md-nav__title" for="__nav_5">
- <span class="md-nav__icon md-icon"></span>
- Examples
- </label>
- <ul class="md-nav__list" data-md-scrollfix>
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../examples/gitops-using-fluxcd/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- FluxCD
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../examples/anchore-engine-credentials/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Anchore Engine
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../examples/jenkins-kubernetes-credentials/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Jenkins
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../examples/bitwarden/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Bitwarden
-
- </span>
-
- </a>
- </li>
-
-
-
- </ul>
- </nav>
-
- </li>
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item md-nav__item--nested">
-
-
-
-
-
- <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_6" >
-
-
- <label class="md-nav__link" for="__nav_6" id="__nav_6_label" tabindex="0">
-
-
-
- <span class="md-ellipsis">
- Community
-
- </span>
-
- <span class="md-nav__icon md-icon"></span>
- </label>
-
- <nav class="md-nav" data-md-level="1" aria-labelledby="__nav_6_label" aria-expanded="false">
- <label class="md-nav__title" for="__nav_6">
- <span class="md-nav__icon md-icon"></span>
- Community
- </label>
- <ul class="md-nav__list" data-md-scrollfix>
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item md-nav__item--nested">
-
-
-
-
-
- <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_6_1" >
-
-
- <label class="md-nav__link" for="__nav_6_1" id="__nav_6_1_label" tabindex="0">
-
-
-
- <span class="md-ellipsis">
- Contributing
-
- </span>
-
- <span class="md-nav__icon md-icon"></span>
- </label>
-
- <nav class="md-nav" data-md-level="2" aria-labelledby="__nav_6_1_label" aria-expanded="false">
- <label class="md-nav__title" for="__nav_6_1">
- <span class="md-nav__icon md-icon"></span>
- Contributing
- </label>
- <ul class="md-nav__list" data-md-scrollfix>
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../contributing/devguide/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Developer guide
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../contributing/process/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Contributing Process
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../contributing/release/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Release Process
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../contributing/coc/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Code of Conduct
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../contributing/calendar/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Community meetings calendar
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../contributing/roadmap/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Roadmap
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../contributing/burnout-mitigation/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Burnout Prevention
-
- </span>
-
- </a>
- </li>
-
-
-
- </ul>
- </nav>
-
- </li>
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item md-nav__item--nested">
-
-
-
-
-
- <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_6_2" >
-
-
- <label class="md-nav__link" for="__nav_6_2" id="__nav_6_2_label" tabindex="0">
-
-
-
- <span class="md-ellipsis">
- External Resources
-
- </span>
-
- <span class="md-nav__icon md-icon"></span>
- </label>
-
- <nav class="md-nav" data-md-level="2" aria-labelledby="__nav_6_2_label" aria-expanded="false">
- <label class="md-nav__title" for="__nav_6_2">
- <span class="md-nav__icon md-icon"></span>
- External Resources
- </label>
- <ul class="md-nav__list" data-md-scrollfix>
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../eso-talks/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Talks
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../eso-demos/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Demos
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../eso-blogs/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Blogs
-
- </span>
-
- </a>
- </li>
-
-
-
-
-
-
-
-
-
- <li class="md-nav__item">
- <a href="../../eso-tools/" class="md-nav__link">
-
-
-
- <span class="md-ellipsis">
- Tools
-
- </span>
-
- </a>
- </li>
-
-
-
- </ul>
- </nav>
-
- </li>
-
-
-
- </ul>
- </nav>
-
- </li>
-
-
- </ul>
- </nav>
- </div>
- </div>
- </div>
-
-
-
- <div class="md-sidebar md-sidebar--secondary" data-md-component="sidebar" data-md-type="toc" >
- <div class="md-sidebar__scrollwrap">
- <div class="md-sidebar__inner">
-
- <nav class="md-nav md-nav--secondary" aria-label="Table of contents">
-
-
-
-
- </nav>
- </div>
- </div>
- </div>
-
-
-
- <div class="md-content" data-md-component="content">
- <article class="md-content__inner md-typeset">
-
-
-
-
- <h1>API specification</h1>
- <p>Packages:</p>
- <ul>
- <li>
- <a href="#external-secrets.io%2fv1">external-secrets.io/v1</a>
- </li>
- </ul>
- <h2 id="external-secrets.io/v1">external-secrets.io/v1</h2>
- <p>
- <p>Package v1 contains resources for external-secrets</p>
- </p>
- <p>Resource Types:</p>
- <ul></ul>
- <h3 id="external-secrets.io/v1.AWSAuth">AWSAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.AWSProvider">AWSProvider</a>)
- </p>
- <p>
- <p>AWSAuth tells the controller how to do authentication with aws.
- Only one of secretRef or jwt can be specified.
- if none is specified the controller will load credentials using the aws sdk defaults.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.AWSAuthSecretRef">
- AWSAuthSecretRef
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>jwt</code></br>
- <em>
- <a href="#external-secrets.io/v1.AWSJWTAuth">
- AWSJWTAuth
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.AWSAuthSecretRef">AWSAuthSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.AWSAuth">AWSAuth</a>)
- </p>
- <p>
- <p>AWSAuthSecretRef holds secret references for AWS credentials
- both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>accessKeyIDSecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>The AccessKeyID is used for authentication</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretAccessKeySecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>The SecretAccessKey is used for authentication</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>sessionTokenSecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>The SessionToken used for authentication
- This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
- see: <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html">https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html</a></p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.AWSJWTAuth">AWSJWTAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.AWSAuth">AWSAuth</a>)
- </p>
- <p>
- <p>Authenticate against AWS using service account tokens.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>serviceAccountRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#ServiceAccountSelector">
- External Secrets meta/v1.ServiceAccountSelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.AWSProvider">AWSProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>AWSProvider configures a store to sync secrets with AWS.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>service</code></br>
- <em>
- <a href="#external-secrets.io/v1.AWSServiceType">
- AWSServiceType
- </a>
- </em>
- </td>
- <td>
- <p>Service defines which service should be used to fetch the secrets</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.AWSAuth">
- AWSAuth
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Auth defines the information necessary to authenticate against AWS
- if not set aws sdk will infer credentials from your environment
- see: <a href="https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials">https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials</a></p>
- </td>
- </tr>
- <tr>
- <td>
- <code>role</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Role is a Role ARN which the provider will assume</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>region</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>AWS Region to be used for the provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>additionalRoles</code></br>
- <em>
- []string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>externalID</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>AWS External ID set on assumed IAM roles</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>sessionTags</code></br>
- <em>
- <a href="#external-secrets.io/v1.*github.com/external-secrets/external-secrets/apis/externalsecrets/v1.Tag">
- []*github.com/external-secrets/external-secrets/apis/externalsecrets/v1.Tag
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>AWS STS assume role session tags</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretsManager</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretsManager">
- SecretsManager
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>SecretsManager defines how the provider behaves when interacting with AWS SecretsManager</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>transitiveTagKeys</code></br>
- <em>
- []string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>AWS STS assume role transitive session tags. Required when multiple rules are used with the provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>prefix</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Prefix adds a prefix to all retrieved values.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.AWSServiceType">AWSServiceType
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.AWSProvider">AWSProvider</a>)
- </p>
- <p>
- <p>AWSServiceType is a enum that defines the service/API that is used to fetch the secrets.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"ParameterStore"</p></td>
- <td><p>AWSServiceParameterStore is the AWS SystemsManager ParameterStore service.
- see: <a href="https://docs.aws.amazon.com/systems-manager/latest/userguide/systems-manager-parameter-store.html">https://docs.aws.amazon.com/systems-manager/latest/userguide/systems-manager-parameter-store.html</a></p>
- </td>
- </tr><tr><td><p>"SecretsManager"</p></td>
- <td><p>AWSServiceSecretsManager is the AWS SecretsManager service.
- see: <a href="https://docs.aws.amazon.com/secretsmanager/latest/userguide/intro.html">https://docs.aws.amazon.com/secretsmanager/latest/userguide/intro.html</a></p>
- </td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.AkeylessAuth">AkeylessAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.AkeylessProvider">AkeylessProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.AkeylessAuthSecretRef">
- AkeylessAuthSecretRef
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Reference to a Secret that contains the details
- to authenticate with Akeyless.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>kubernetesAuth</code></br>
- <em>
- <a href="#external-secrets.io/v1.AkeylessKubernetesAuth">
- AkeylessKubernetesAuth
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Kubernetes authenticates with Akeyless by passing the ServiceAccount
- token stored in the named Secret resource.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.AkeylessAuthSecretRef">AkeylessAuthSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.AkeylessAuth">AkeylessAuth</a>)
- </p>
- <p>
- <p>AkeylessAuthSecretRef
- AKEYLESS_ACCESS_TYPE_PARAM: AZURE_OBJ_ID OR GCP_AUDIENCE OR ACCESS_KEY OR KUB_CONFIG_NAME.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>accessID</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>The SecretAccessID is used for authentication</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>accessType</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>accessTypeParam</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.AkeylessKubernetesAuth">AkeylessKubernetesAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.AkeylessAuth">AkeylessAuth</a>)
- </p>
- <p>
- <p>Authenticate with Kubernetes ServiceAccount token stored.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>accessID</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>the Akeyless Kubernetes auth-method access-id</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>k8sConfName</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Kubernetes-auth configuration name in Akeyless-Gateway</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>serviceAccountRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#ServiceAccountSelector">
- External Secrets meta/v1.ServiceAccountSelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Optional service account field containing the name of a kubernetes ServiceAccount.
- If the service account is specified, the service account secret token JWT will be used
- for authenticating with Akeyless. If the service account selector is not supplied,
- the secretRef will be used instead.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Optional secret field containing a Kubernetes ServiceAccount JWT used
- for authenticating with Akeyless. If a name is specified without a key,
- <code>token</code> is the default. If one is not specified, the one bound to
- the controller will be used.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.AkeylessProvider">AkeylessProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>AkeylessProvider Configures an store to sync secrets using Akeyless KV.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>akeylessGWApiURL</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Akeyless GW API Url from which the secrets to be fetched from.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>authSecretRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.AkeylessAuth">
- AkeylessAuth
- </a>
- </em>
- </td>
- <td>
- <p>Auth configures how the operator authenticates with Akeyless.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>caBundle</code></br>
- <em>
- []byte
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
- if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
- are used to validate the TLS connection.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>caProvider</code></br>
- <em>
- <a href="#external-secrets.io/v1.CAProvider">
- CAProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The provider for the CA bundle to use to validate Akeyless Gateway certificate.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.AlibabaAuth">AlibabaAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.AlibabaProvider">AlibabaProvider</a>)
- </p>
- <p>
- <p>AlibabaAuth contains a secretRef for credentials.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.AlibabaAuthSecretRef">
- AlibabaAuthSecretRef
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>rrsa</code></br>
- <em>
- <a href="#external-secrets.io/v1.AlibabaRRSAAuth">
- AlibabaRRSAAuth
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.AlibabaAuthSecretRef">AlibabaAuthSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.AlibabaAuth">AlibabaAuth</a>)
- </p>
- <p>
- <p>AlibabaAuthSecretRef holds secret references for Alibaba credentials.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>accessKeyIDSecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>The AccessKeyID is used for authentication</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>accessKeySecretSecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>The AccessKeySecret is used for authentication</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.AlibabaProvider">AlibabaProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>AlibabaProvider configures a store to sync secrets using the Alibaba Secret Manager provider.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.AlibabaAuth">
- AlibabaAuth
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>regionID</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Alibaba Region to be used for the provider</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.AlibabaRRSAAuth">AlibabaRRSAAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.AlibabaAuth">AlibabaAuth</a>)
- </p>
- <p>
- <p>Authenticate against Alibaba using RRSA.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>oidcProviderArn</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>oidcTokenFilePath</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>roleArn</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>sessionName</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.AuthorizationProtocol">AuthorizationProtocol
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.WebhookProvider">WebhookProvider</a>)
- </p>
- <p>
- <p>AuthorizationProtocol contains the protocol-specific configuration</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>ntlm</code></br>
- <em>
- <a href="#external-secrets.io/v1.NTLMProtocol">
- NTLMProtocol
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>NTLMProtocol configures the store to use NTLM for auth</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.AwsAuthCredentials">AwsAuthCredentials
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.InfisicalAuth">InfisicalAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>identityId</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.AwsCredentialsConfig">AwsCredentialsConfig
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.GCPWorkloadIdentityFederation">GCPWorkloadIdentityFederation</a>)
- </p>
- <p>
- <p>AwsCredentialsConfig holds the region and the Secret reference which contains the AWS credentials.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>region</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>region is for configuring the AWS region to be used.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>awsCredentialsSecretRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretReference">
- SecretReference
- </a>
- </em>
- </td>
- <td>
- <p>awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
- Secret should be created with below names for keys
- - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
- - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
- - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.AzureAuthCredentials">AzureAuthCredentials
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.InfisicalAuth">InfisicalAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>identityId</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>resource</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.AzureAuthType">AzureAuthType
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.AzureKVProvider">AzureKVProvider</a>)
- </p>
- <p>
- <p>AuthType describes how to authenticate to the Azure Keyvault
- Only one of the following auth types may be specified.
- If none of the following auth type is specified, the default one
- is ServicePrincipal.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"ManagedIdentity"</p></td>
- <td><p>Using Managed Identity to authenticate. Used with aad-pod-identity installed in the cluster.</p>
- </td>
- </tr><tr><td><p>"ServicePrincipal"</p></td>
- <td><p>Using service principal to authenticate, which needs a tenantId, a clientId and a clientSecret.</p>
- </td>
- </tr><tr><td><p>"WorkloadIdentity"</p></td>
- <td><p>Using Workload Identity service accounts to authenticate.</p>
- </td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.AzureCustomCloudConfig">AzureCustomCloudConfig
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.AzureKVProvider">AzureKVProvider</a>)
- </p>
- <p>
- <p>AzureCustomCloudConfig specifies custom cloud configuration for private Azure environments
- IMPORTANT: Custom cloud configuration is ONLY supported when UseAzureSDK is true.
- The legacy go-autorest SDK does not support custom cloud endpoints.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>activeDirectoryEndpoint</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>ActiveDirectoryEndpoint is the AAD endpoint for authentication
- Required when using custom cloud configuration</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>keyVaultEndpoint</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>KeyVaultEndpoint is the Key Vault service endpoint</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>keyVaultDNSSuffix</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>resourceManagerEndpoint</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>ResourceManagerEndpoint is the Azure Resource Manager endpoint</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.AzureEnvironmentType">AzureEnvironmentType
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.AzureKVProvider">AzureKVProvider</a>)
- </p>
- <p>
- <p>AzureEnvironmentType specifies the Azure cloud environment endpoints to use for
- connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
- The following endpoints are available, also see here: <a href="https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152">https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152</a>
- PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"AzureStackCloud"</p></td>
- <td></td>
- </tr><tr><td><p>"ChinaCloud"</p></td>
- <td></td>
- </tr><tr><td><p>"GermanCloud"</p></td>
- <td></td>
- </tr><tr><td><p>"PublicCloud"</p></td>
- <td></td>
- </tr><tr><td><p>"USGovernmentCloud"</p></td>
- <td></td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.AzureKVAuth">AzureKVAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.AzureKVProvider">AzureKVProvider</a>)
- </p>
- <p>
- <p>Configuration used to authenticate with Azure.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>clientId</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The Azure clientId of the service principle or managed identity used for authentication.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>tenantId</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The Azure tenantId of the managed identity used for authentication.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>clientSecret</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The Azure ClientSecret of the service principle used for authentication.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>clientCertificate</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The Azure ClientCertificate of the service principle used for authentication.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.AzureKVProvider">AzureKVProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>Configures an store to sync secrets using Azure KV.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>authType</code></br>
- <em>
- <a href="#external-secrets.io/v1.AzureAuthType">
- AzureAuthType
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Auth type defines how to authenticate to the keyvault service.
- Valid values are:
- - “ServicePrincipal” (default): Using a service principal (tenantId, clientId, clientSecret)
- - “ManagedIdentity”: Using Managed Identity assigned to the pod (see aad-pod-identity)</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>vaultUrl</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Vault Url from which the secrets to be fetched from.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>tenantId</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>environmentType</code></br>
- <em>
- <a href="#external-secrets.io/v1.AzureEnvironmentType">
- AzureEnvironmentType
- </a>
- </em>
- </td>
- <td>
- <p>EnvironmentType specifies the Azure cloud environment endpoints to use for
- connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
- The following endpoints are available, also see here: <a href="https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152">https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152</a>
- PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
- Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>authSecretRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.AzureKVAuth">
- AzureKVAuth
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>serviceAccountRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#ServiceAccountSelector">
- External Secrets meta/v1.ServiceAccountSelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>ServiceAccountRef specified the service account
- that should be used when authenticating with WorkloadIdentity.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>identityId</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>If multiple Managed Identity is assigned to the pod, you can select the one to be used</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>useAzureSDK</code></br>
- <em>
- bool
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
- This is experimental and may have behavioral differences. Defaults to false (legacy SDK).</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>customCloudConfig</code></br>
- <em>
- <a href="#external-secrets.io/v1.AzureCustomCloudConfig">
- AzureCustomCloudConfig
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>CustomCloudConfig defines custom Azure Stack Hub or Azure Stack Edge endpoints.
- Required when EnvironmentType is AzureStackCloud.
- IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
- configuration is not supported with the legacy go-autorest SDK.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.BeyondTrustProviderSecretRef">BeyondTrustProviderSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.BeyondtrustAuth">BeyondtrustAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>value</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Value can be specified directly to set a value without using a secret.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>SecretRef references a key in a secret that will be used as value.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.BeyondtrustAuth">BeyondtrustAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.BeyondtrustProvider">BeyondtrustProvider</a>)
- </p>
- <p>
- <p>Configures a store to sync secrets using BeyondTrust Password Safe.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>apiKey</code></br>
- <em>
- <a href="#external-secrets.io/v1.BeyondTrustProviderSecretRef">
- BeyondTrustProviderSecretRef
- </a>
- </em>
- </td>
- <td>
- <p>APIKey If not provided then ClientID/ClientSecret become required.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>clientId</code></br>
- <em>
- <a href="#external-secrets.io/v1.BeyondTrustProviderSecretRef">
- BeyondTrustProviderSecretRef
- </a>
- </em>
- </td>
- <td>
- <p>ClientID is the API OAuth Client ID.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>clientSecret</code></br>
- <em>
- <a href="#external-secrets.io/v1.BeyondTrustProviderSecretRef">
- BeyondTrustProviderSecretRef
- </a>
- </em>
- </td>
- <td>
- <p>ClientSecret is the API OAuth Client Secret.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>certificate</code></br>
- <em>
- <a href="#external-secrets.io/v1.BeyondTrustProviderSecretRef">
- BeyondTrustProviderSecretRef
- </a>
- </em>
- </td>
- <td>
- <p>Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>certificateKey</code></br>
- <em>
- <a href="#external-secrets.io/v1.BeyondTrustProviderSecretRef">
- BeyondTrustProviderSecretRef
- </a>
- </em>
- </td>
- <td>
- <p>Certificate private key (key.pem). For use when authenticating with an OAuth client Id</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.BeyondtrustProvider">BeyondtrustProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.BeyondtrustAuth">
- BeyondtrustAuth
- </a>
- </em>
- </td>
- <td>
- <p>Auth configures how the operator authenticates with Beyondtrust.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>server</code></br>
- <em>
- <a href="#external-secrets.io/v1.BeyondtrustServer">
- BeyondtrustServer
- </a>
- </em>
- </td>
- <td>
- <p>Auth configures how API server works.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.BeyondtrustServer">BeyondtrustServer
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.BeyondtrustProvider">BeyondtrustProvider</a>)
- </p>
- <p>
- <p>Configures a store to sync secrets using BeyondTrust Password Safe.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>apiUrl</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>apiVersion</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>retrievalType</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>separator</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>A character that separates the folder names.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>verifyCA</code></br>
- <em>
- bool
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>clientTimeOutSeconds</code></br>
- <em>
- int
- </em>
- </td>
- <td>
- <p>Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.BitwardenSecretsManagerAuth">BitwardenSecretsManagerAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.BitwardenSecretsManagerProvider">BitwardenSecretsManagerProvider</a>)
- </p>
- <p>
- <p>BitwardenSecretsManagerAuth contains the ref to the secret that contains the machine account token.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.BitwardenSecretsManagerSecretRef">
- BitwardenSecretsManagerSecretRef
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.BitwardenSecretsManagerProvider">BitwardenSecretsManagerProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>BitwardenSecretsManagerProvider configures a store to sync secrets with a Bitwarden Secrets Manager instance.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>apiURL</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>identityURL</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>bitwardenServerSDKURL</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>caBundle</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
- can be performed.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>caProvider</code></br>
- <em>
- <a href="#external-secrets.io/v1.CAProvider">
- CAProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>see: <a href="https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider">https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider</a></p>
- </td>
- </tr>
- <tr>
- <td>
- <code>organizationID</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>OrganizationID determines which organization this secret store manages.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>projectID</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>ProjectID determines which project this secret store manages.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.BitwardenSecretsManagerAuth">
- BitwardenSecretsManagerAuth
- </a>
- </em>
- </td>
- <td>
- <p>Auth configures how secret-manager authenticates with a bitwarden machine account instance.
- Make sure that the token being used has permissions on the given secret.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.BitwardenSecretsManagerSecretRef">BitwardenSecretsManagerSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.BitwardenSecretsManagerAuth">BitwardenSecretsManagerAuth</a>)
- </p>
- <p>
- <p>BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>credentials</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>AccessToken used for the bitwarden instance.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ByID">ByID
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.FetchingPolicy">FetchingPolicy</a>)
- </p>
- <p>
- <p>ByID configures the provider to interpret the <code>data.secretKey.remoteRef.key</code> field in ExternalSecret as secret ID.</p>
- </p>
- <h3 id="external-secrets.io/v1.ByName">ByName
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.FetchingPolicy">FetchingPolicy</a>)
- </p>
- <p>
- <p>ByName configures the provider to interpret the <code>data.secretKey.remoteRef.key</code> field in ExternalSecret as secret name.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>folderID</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>The folder to fetch secrets from</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.CAProvider">CAProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.AkeylessProvider">AkeylessProvider</a>,
- <a href="#external-secrets.io/v1.BitwardenSecretsManagerProvider">BitwardenSecretsManagerProvider</a>,
- <a href="#external-secrets.io/v1.ConjurProvider">ConjurProvider</a>,
- <a href="#external-secrets.io/v1.GitlabProvider">GitlabProvider</a>,
- <a href="#external-secrets.io/v1.KubernetesServer">KubernetesServer</a>,
- <a href="#external-secrets.io/v1.VaultProvider">VaultProvider</a>)
- </p>
- <p>
- <p>Used to provide custom certificate authority (CA) certificates
- for a secret store. The CAProvider points to a Secret or ConfigMap resource
- that contains a PEM-encoded certificate.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>type</code></br>
- <em>
- <a href="#external-secrets.io/v1.CAProviderType">
- CAProviderType
- </a>
- </em>
- </td>
- <td>
- <p>The type of provider to use such as “Secret”, or “ConfigMap”.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>name</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>The name of the object located at the provider type.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>key</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>The key where the CA certificate can be found in the Secret or ConfigMap.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>namespace</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The namespace the Provider type is in.
- Can only be defined when used in a ClusterSecretStore.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.CAProviderType">CAProviderType
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.CAProvider">CAProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"ConfigMap"</p></td>
- <td></td>
- </tr><tr><td><p>"Secret"</p></td>
- <td></td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.CSMAuth">CSMAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.CloudruSMProvider">CloudruSMProvider</a>)
- </p>
- <p>
- <p>CSMAuth contains a secretRef for credentials.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.CSMAuthSecretRef">
- CSMAuthSecretRef
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.CSMAuthSecretRef">CSMAuthSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.CSMAuth">CSMAuth</a>)
- </p>
- <p>
- <p>CSMAuthSecretRef holds secret references for Cloud.ru credentials.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>accessKeyIDSecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>The AccessKeyID is used for authentication</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>accessKeySecretSecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>The AccessKeySecret is used for authentication</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.CertAuth">CertAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.KubernetesAuth">KubernetesAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>clientCert</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>clientKey</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ChefAuth">ChefAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ChefProvider">ChefProvider</a>)
- </p>
- <p>
- <p>ChefAuth contains a secretRef for credentials.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.ChefAuthSecretRef">
- ChefAuthSecretRef
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ChefAuthSecretRef">ChefAuthSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ChefAuth">ChefAuth</a>)
- </p>
- <p>
- <p>ChefAuthSecretRef holds secret references for chef server login credentials.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>privateKeySecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>SecretKey is the Signing Key in PEM format, used for authentication.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ChefProvider">ChefProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>ChefProvider configures a store to sync secrets using basic chef server connection credentials.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.ChefAuth">
- ChefAuth
- </a>
- </em>
- </td>
- <td>
- <p>Auth defines the information necessary to authenticate against chef Server</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>username</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>UserName should be the user ID on the chef server</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>serverUrl</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a “/”</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.CloudruSMProvider">CloudruSMProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>CloudruSMProvider configures a store to sync secrets using the Cloud.ru Secret Manager provider.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.CSMAuth">
- CSMAuth
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>projectID</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>ProjectID is the project, which the secrets are stored in.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ClusterExternalSecret">ClusterExternalSecret
- </h3>
- <p>
- <p>ClusterExternalSecret is the Schema for the clusterexternalsecrets API.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>metadata</code></br>
- <em>
- <a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.25/#objectmeta-v1-meta">
- Kubernetes meta/v1.ObjectMeta
- </a>
- </em>
- </td>
- <td>
- Refer to the Kubernetes API documentation for the fields of the
- <code>metadata</code> field.
- </td>
- </tr>
- <tr>
- <td>
- <code>spec</code></br>
- <em>
- <a href="#external-secrets.io/v1.ClusterExternalSecretSpec">
- ClusterExternalSecretSpec
- </a>
- </em>
- </td>
- <td>
- <br/>
- <br/>
- <table>
- <tr>
- <td>
- <code>externalSecretSpec</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretSpec">
- ExternalSecretSpec
- </a>
- </em>
- </td>
- <td>
- <p>The spec for the ExternalSecrets to be created</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>externalSecretName</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The name of the external secrets to be created.
- Defaults to the name of the ClusterExternalSecret</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>externalSecretMetadata</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretMetadata">
- ExternalSecretMetadata
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The metadata of the external secrets to be created</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>namespaceSelector</code></br>
- <em>
- <a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.25/#labelselector-v1-meta">
- Kubernetes meta/v1.LabelSelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The labels to select by to find the Namespaces to create the ExternalSecrets in.
- Deprecated: Use NamespaceSelectors instead.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>namespaceSelectors</code></br>
- <em>
- <a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.25/#*k8s.io/apimachinery/pkg/apis/meta/v1.labelselector--">
- []*k8s.io/apimachinery/pkg/apis/meta/v1.LabelSelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>namespaces</code></br>
- <em>
- []string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
- Deprecated: Use NamespaceSelectors instead.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>refreshTime</code></br>
- <em>
- <a href="https://pkg.go.dev/k8s.io/apimachinery/pkg/apis/meta/v1#Duration">
- Kubernetes meta/v1.Duration
- </a>
- </em>
- </td>
- <td>
- <p>The time in which the controller should reconcile its objects and recheck namespaces for labels.</p>
- </td>
- </tr>
- </table>
- </td>
- </tr>
- <tr>
- <td>
- <code>status</code></br>
- <em>
- <a href="#external-secrets.io/v1.ClusterExternalSecretStatus">
- ClusterExternalSecretStatus
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ClusterExternalSecretConditionType">ClusterExternalSecretConditionType
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ClusterExternalSecretStatusCondition">ClusterExternalSecretStatusCondition</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"Ready"</p></td>
- <td></td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.ClusterExternalSecretNamespaceFailure">ClusterExternalSecretNamespaceFailure
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ClusterExternalSecretStatus">ClusterExternalSecretStatus</a>)
- </p>
- <p>
- <p>ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it’s reason.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>namespace</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Namespace is the namespace that failed when trying to apply an ExternalSecret</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>reason</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Reason is why the ExternalSecret failed to apply to the namespace</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ClusterExternalSecretSpec">ClusterExternalSecretSpec
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ClusterExternalSecret">ClusterExternalSecret</a>)
- </p>
- <p>
- <p>ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>externalSecretSpec</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretSpec">
- ExternalSecretSpec
- </a>
- </em>
- </td>
- <td>
- <p>The spec for the ExternalSecrets to be created</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>externalSecretName</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The name of the external secrets to be created.
- Defaults to the name of the ClusterExternalSecret</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>externalSecretMetadata</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretMetadata">
- ExternalSecretMetadata
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The metadata of the external secrets to be created</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>namespaceSelector</code></br>
- <em>
- <a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.25/#labelselector-v1-meta">
- Kubernetes meta/v1.LabelSelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The labels to select by to find the Namespaces to create the ExternalSecrets in.
- Deprecated: Use NamespaceSelectors instead.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>namespaceSelectors</code></br>
- <em>
- <a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.25/#*k8s.io/apimachinery/pkg/apis/meta/v1.labelselector--">
- []*k8s.io/apimachinery/pkg/apis/meta/v1.LabelSelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>namespaces</code></br>
- <em>
- []string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
- Deprecated: Use NamespaceSelectors instead.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>refreshTime</code></br>
- <em>
- <a href="https://pkg.go.dev/k8s.io/apimachinery/pkg/apis/meta/v1#Duration">
- Kubernetes meta/v1.Duration
- </a>
- </em>
- </td>
- <td>
- <p>The time in which the controller should reconcile its objects and recheck namespaces for labels.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ClusterExternalSecretStatus">ClusterExternalSecretStatus
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ClusterExternalSecret">ClusterExternalSecret</a>)
- </p>
- <p>
- <p>ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>externalSecretName</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>failedNamespaces</code></br>
- <em>
- <a href="#external-secrets.io/v1.ClusterExternalSecretNamespaceFailure">
- []ClusterExternalSecretNamespaceFailure
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Failed namespaces are the namespaces that failed to apply an ExternalSecret</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>provisionedNamespaces</code></br>
- <em>
- []string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>conditions</code></br>
- <em>
- <a href="#external-secrets.io/v1.ClusterExternalSecretStatusCondition">
- []ClusterExternalSecretStatusCondition
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ClusterExternalSecretStatusCondition">ClusterExternalSecretStatusCondition
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ClusterExternalSecretStatus">ClusterExternalSecretStatus</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>type</code></br>
- <em>
- <a href="#external-secrets.io/v1.ClusterExternalSecretConditionType">
- ClusterExternalSecretConditionType
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>status</code></br>
- <em>
- <a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.25/#conditionstatus-v1-core">
- Kubernetes core/v1.ConditionStatus
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>message</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ClusterSecretStore">ClusterSecretStore
- </h3>
- <p>
- <p>ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of <code>storeRef</code> fields.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>metadata</code></br>
- <em>
- <a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.25/#objectmeta-v1-meta">
- Kubernetes meta/v1.ObjectMeta
- </a>
- </em>
- </td>
- <td>
- Refer to the Kubernetes API documentation for the fields of the
- <code>metadata</code> field.
- </td>
- </tr>
- <tr>
- <td>
- <code>spec</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretStoreSpec">
- SecretStoreSpec
- </a>
- </em>
- </td>
- <td>
- <br/>
- <br/>
- <table>
- <tr>
- <td>
- <code>controller</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to select the correct ESO controller (think: ingress.ingressClassName)
- The ESO controller is instantiated with a specific controller name and filters ES based on this property</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>provider</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">
- SecretStoreProvider
- </a>
- </em>
- </td>
- <td>
- <p>Used to configure the provider. Only one provider may be set</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>retrySettings</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretStoreRetrySettings">
- SecretStoreRetrySettings
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to configure http retries if failed</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>refreshInterval</code></br>
- <em>
- int
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>conditions</code></br>
- <em>
- <a href="#external-secrets.io/v1.ClusterSecretStoreCondition">
- []ClusterSecretStoreCondition
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to constraint a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore</p>
- </td>
- </tr>
- </table>
- </td>
- </tr>
- <tr>
- <td>
- <code>status</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretStoreStatus">
- SecretStoreStatus
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ClusterSecretStoreCondition">ClusterSecretStoreCondition
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreSpec">SecretStoreSpec</a>)
- </p>
- <p>
- <p>ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
- for a ClusterSecretStore instance.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>namespaceSelector</code></br>
- <em>
- <a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.25/#labelselector-v1-meta">
- Kubernetes meta/v1.LabelSelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Choose namespace using a labelSelector</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>namespaces</code></br>
- <em>
- []string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Choose namespaces by name</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>namespaceRegexes</code></br>
- <em>
- []string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Choose namespaces by using regex matching</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ConfigMapReference">ConfigMapReference
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.GCPWorkloadIdentityFederation">GCPWorkloadIdentityFederation</a>)
- </p>
- <p>
- <p>ConfigMapReference holds the details of a configmap.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>name</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>name of the configmap.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>namespace</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>namespace in which the configmap exists. If empty, configmap will looked up in local namespace.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>key</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>key name holding the external account credential config.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ConjurAPIKey">ConjurAPIKey
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ConjurAuth">ConjurAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>account</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Account is the Conjur organization account name.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>userRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>A reference to a specific ‘key’ containing the Conjur username
- within a Secret resource. In some instances, <code>key</code> is a required field.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>apiKeyRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>A reference to a specific ‘key’ containing the Conjur API key
- within a Secret resource. In some instances, <code>key</code> is a required field.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ConjurAuth">ConjurAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ConjurProvider">ConjurProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>apikey</code></br>
- <em>
- <a href="#external-secrets.io/v1.ConjurAPIKey">
- ConjurAPIKey
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Authenticates with Conjur using an API key.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>jwt</code></br>
- <em>
- <a href="#external-secrets.io/v1.ConjurJWT">
- ConjurJWT
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Jwt enables JWT authentication using Kubernetes service account tokens.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ConjurJWT">ConjurJWT
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ConjurAuth">ConjurAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>account</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Account is the Conjur organization account name.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>serviceID</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>The conjur authn jwt webservice id</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>hostId</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Optional HostID for JWT authentication. This may be used depending
- on how the Conjur JWT authenticator policy is configured.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Optional SecretRef that refers to a key in a Secret resource containing JWT token to
- authenticate with Conjur using the JWT authentication method.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>serviceAccountRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#ServiceAccountSelector">
- External Secrets meta/v1.ServiceAccountSelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Optional ServiceAccountRef specifies the Kubernetes service account for which to request
- a token for with the <code>TokenRequest</code> API.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ConjurProvider">ConjurProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>url</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>URL is the endpoint of the Conjur instance.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>caBundle</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>caProvider</code></br>
- <em>
- <a href="#external-secrets.io/v1.CAProvider">
- CAProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to provide custom certificate authority (CA) certificates
- for a secret store. The CAProvider points to a Secret or ConfigMap resource
- that contains a PEM-encoded certificate.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.ConjurAuth">
- ConjurAuth
- </a>
- </em>
- </td>
- <td>
- <p>Defines authentication settings for connecting to Conjur.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.DelineaProvider">DelineaProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>See <a href="https://github.com/DelineaXPM/dsv-sdk-go/blob/main/vault/vault.go">https://github.com/DelineaXPM/dsv-sdk-go/blob/main/vault/vault.go</a>.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>clientId</code></br>
- <em>
- <a href="#external-secrets.io/v1.DelineaProviderSecretRef">
- DelineaProviderSecretRef
- </a>
- </em>
- </td>
- <td>
- <p>ClientID is the non-secret part of the credential.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>clientSecret</code></br>
- <em>
- <a href="#external-secrets.io/v1.DelineaProviderSecretRef">
- DelineaProviderSecretRef
- </a>
- </em>
- </td>
- <td>
- <p>ClientSecret is the secret part of the credential.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>tenant</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Tenant is the chosen hostname / site name.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>urlTemplate</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>URLTemplate
- If unset, defaults to “https://%s.secretsvaultcloud.%s/v1/%s%s”.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>tld</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>TLD is based on the server location that was chosen during provisioning.
- If unset, defaults to “com”.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.DelineaProviderSecretRef">DelineaProviderSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.DelineaProvider">DelineaProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>value</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Value can be specified directly to set a value without using a secret.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>SecretRef references a key in a secret that will be used as value.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.Device42Auth">Device42Auth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.Device42Provider">Device42Provider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.Device42SecretRef">
- Device42SecretRef
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.Device42Provider">Device42Provider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>Device42Provider configures a store to sync secrets with a Device42 instance.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>host</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>URL configures the Device42 instance URL.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.Device42Auth">
- Device42Auth
- </a>
- </em>
- </td>
- <td>
- <p>Auth configures how secret-manager authenticates with a Device42 instance.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.Device42SecretRef">Device42SecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.Device42Auth">Device42Auth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>credentials</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Username / Password is used for authentication.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.DopplerAuth">DopplerAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.DopplerProvider">DopplerProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.DopplerAuthSecretRef">
- DopplerAuthSecretRef
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.DopplerAuthSecretRef">DopplerAuthSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.DopplerAuth">DopplerAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>dopplerToken</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>The DopplerToken is used for authentication.
- See <a href="https://docs.doppler.com/reference/api#authentication">https://docs.doppler.com/reference/api#authentication</a> for auth token types.
- The Key attribute defaults to dopplerToken if not specified.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.DopplerProvider">DopplerProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>DopplerProvider configures a store to sync secrets using the Doppler provider.
- Project and Config are required if not using a Service Token.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.DopplerAuth">
- DopplerAuth
- </a>
- </em>
- </td>
- <td>
- <p>Auth configures how the Operator authenticates with the Doppler API</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>project</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Doppler project (required if not using a Service Token)</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>config</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Doppler config (required if not using a Service Token)</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>nameTransformer</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Environment variable compatible name transforms that change secret names to a different format</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>format</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Format enables the downloading of secrets as a file (string)</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecret">ExternalSecret
- </h3>
- <p>
- <p>ExternalSecret is the Schema for the external-secrets API.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>metadata</code></br>
- <em>
- <a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.25/#objectmeta-v1-meta">
- Kubernetes meta/v1.ObjectMeta
- </a>
- </em>
- </td>
- <td>
- Refer to the Kubernetes API documentation for the fields of the
- <code>metadata</code> field.
- </td>
- </tr>
- <tr>
- <td>
- <code>spec</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretSpec">
- ExternalSecretSpec
- </a>
- </em>
- </td>
- <td>
- <br/>
- <br/>
- <table>
- <tr>
- <td>
- <code>secretStoreRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretStoreRef">
- SecretStoreRef
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>target</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretTarget">
- ExternalSecretTarget
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>refreshPolicy</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretRefreshPolicy">
- ExternalSecretRefreshPolicy
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>RefreshPolicy determines how the ExternalSecret should be refreshed:
- - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
- - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
- No periodic updates occur if refreshInterval is 0.
- - OnChange: Only synchronizes the Secret when the ExternalSecret’s metadata or specification changes</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>refreshInterval</code></br>
- <em>
- <a href="https://pkg.go.dev/k8s.io/apimachinery/pkg/apis/meta/v1#Duration">
- Kubernetes meta/v1.Duration
- </a>
- </em>
- </td>
- <td>
- <p>RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
- specified as Golang Duration strings.
- Valid time units are “ns”, “us” (or “µs”), “ms”, “s”, “m”, “h”
- Example values: “1h”, “2h30m”, “10s”
- May be set to zero to fetch and create it once. Defaults to 1h.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>data</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretData">
- []ExternalSecretData
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Data defines the connection between the Kubernetes Secret keys and the Provider data</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>dataFrom</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretDataFromRemoteRef">
- []ExternalSecretDataFromRemoteRef
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>DataFrom is used to fetch all properties from a specific Provider data
- If multiple entries are specified, the Secret keys are merged in the specified order</p>
- </td>
- </tr>
- </table>
- </td>
- </tr>
- <tr>
- <td>
- <code>status</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretStatus">
- ExternalSecretStatus
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretConditionType">ExternalSecretConditionType
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretStatusCondition">ExternalSecretStatusCondition</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"Deleted"</p></td>
- <td></td>
- </tr><tr><td><p>"Ready"</p></td>
- <td></td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretConversionStrategy">ExternalSecretConversionStrategy
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretDataRemoteRef">ExternalSecretDataRemoteRef</a>,
- <a href="#external-secrets.io/v1.ExternalSecretFind">ExternalSecretFind</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"Default"</p></td>
- <td></td>
- </tr><tr><td><p>"Unicode"</p></td>
- <td></td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretCreationPolicy">ExternalSecretCreationPolicy
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretTarget">ExternalSecretTarget</a>)
- </p>
- <p>
- <p>ExternalSecretCreationPolicy defines rules on how to create the resulting Secret.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"Merge"</p></td>
- <td><p>Merge does not create the Secret, but merges the data fields to the Secret.</p>
- </td>
- </tr><tr><td><p>"None"</p></td>
- <td><p>None does not create a Secret (future use with injector).</p>
- </td>
- </tr><tr><td><p>"Orphan"</p></td>
- <td><p>Orphan creates the Secret and does not set the ownerReference.
- I.e. it will be orphaned after the deletion of the ExternalSecret.</p>
- </td>
- </tr><tr><td><p>"Owner"</p></td>
- <td><p>Owner creates the Secret and sets .metadata.ownerReferences to the ExternalSecret resource.</p>
- </td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretData">ExternalSecretData
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretSpec">ExternalSecretSpec</a>)
- </p>
- <p>
- <p>ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretKey</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>The key in the Kubernetes Secret to store the value.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>remoteRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretDataRemoteRef">
- ExternalSecretDataRemoteRef
- </a>
- </em>
- </td>
- <td>
- <p>RemoteRef points to the remote secret and defines
- which secret (version/property/..) to fetch.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>sourceRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.StoreSourceRef">
- StoreSourceRef
- </a>
- </em>
- </td>
- <td>
- <p>SourceRef allows you to override the source
- from which the value will be pulled.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretDataFromRemoteRef">ExternalSecretDataFromRemoteRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretSpec">ExternalSecretSpec</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>extract</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretDataRemoteRef">
- ExternalSecretDataRemoteRef
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to extract multiple key/value pairs from one secret
- Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>find</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretFind">
- ExternalSecretFind
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to find secrets based on tags or regular expressions
- Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>rewrite</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretRewrite">
- []ExternalSecretRewrite
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to rewrite secret Keys after getting them from the secret Provider
- Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>sourceRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.StoreGeneratorSourceRef">
- StoreGeneratorSourceRef
- </a>
- </em>
- </td>
- <td>
- <p>SourceRef points to a store or generator
- which contains secret values ready to use.
- Use this in combination with Extract or Find pull values out of
- a specific SecretStore.
- When sourceRef points to a generator Extract or Find is not supported.
- The generator returns a static map of values</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretDataRemoteRef">ExternalSecretDataRemoteRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretData">ExternalSecretData</a>,
- <a href="#external-secrets.io/v1.ExternalSecretDataFromRemoteRef">ExternalSecretDataFromRemoteRef</a>)
- </p>
- <p>
- <p>ExternalSecretDataRemoteRef defines Provider data location.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>key</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Key is the key used in the Provider, mandatory</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>metadataPolicy</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretMetadataPolicy">
- ExternalSecretMetadataPolicy
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>property</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to select a specific property of the Provider value (if a map), if supported</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>version</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to select a specific version of the Provider value, if supported</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>conversionStrategy</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretConversionStrategy">
- ExternalSecretConversionStrategy
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to define a conversion Strategy</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>decodingStrategy</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretDecodingStrategy">
- ExternalSecretDecodingStrategy
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to define a decoding Strategy</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretDecodingStrategy">ExternalSecretDecodingStrategy
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretDataRemoteRef">ExternalSecretDataRemoteRef</a>,
- <a href="#external-secrets.io/v1.ExternalSecretFind">ExternalSecretFind</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"Auto"</p></td>
- <td></td>
- </tr><tr><td><p>"Base64"</p></td>
- <td></td>
- </tr><tr><td><p>"Base64URL"</p></td>
- <td></td>
- </tr><tr><td><p>"None"</p></td>
- <td></td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretDeletionPolicy">ExternalSecretDeletionPolicy
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretTarget">ExternalSecretTarget</a>)
- </p>
- <p>
- <p>ExternalSecretDeletionPolicy defines rules on how to delete the resulting Secret.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"Delete"</p></td>
- <td><p>Delete deletes the secret if all provider secrets are deleted.
- If a secret gets deleted on the provider side and is not accessible
- anymore this is not considered an error and the ExternalSecret
- does not go into SecretSyncedError status.</p>
- </td>
- </tr><tr><td><p>"Merge"</p></td>
- <td><p>Merge removes keys in the secret, but not the secret itself.
- If a secret gets deleted on the provider side and is not accessible
- anymore this is not considered an error and the ExternalSecret
- does not go into SecretSyncedError status.</p>
- </td>
- </tr><tr><td><p>"Retain"</p></td>
- <td><p>Retain will retain the secret if all provider secrets have been deleted.
- If a provider secret does not exist the ExternalSecret gets into the
- SecretSyncedError status.</p>
- </td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretFind">ExternalSecretFind
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretDataFromRemoteRef">ExternalSecretDataFromRemoteRef</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>path</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>A root path to start the find operations.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>name</code></br>
- <em>
- <a href="#external-secrets.io/v1.FindName">
- FindName
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Finds secrets based on the name.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>tags</code></br>
- <em>
- map[string]string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Find secrets based on tags.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>conversionStrategy</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretConversionStrategy">
- ExternalSecretConversionStrategy
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to define a conversion Strategy</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>decodingStrategy</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretDecodingStrategy">
- ExternalSecretDecodingStrategy
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to define a decoding Strategy</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretMetadata">ExternalSecretMetadata
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ClusterExternalSecretSpec">ClusterExternalSecretSpec</a>)
- </p>
- <p>
- <p>ExternalSecretMetadata defines metadata fields for the ExternalSecret generated by the ClusterExternalSecret.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>annotations</code></br>
- <em>
- map[string]string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>labels</code></br>
- <em>
- map[string]string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretMetadataPolicy">ExternalSecretMetadataPolicy
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretDataRemoteRef">ExternalSecretDataRemoteRef</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"Fetch"</p></td>
- <td></td>
- </tr><tr><td><p>"None"</p></td>
- <td></td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretRefreshPolicy">ExternalSecretRefreshPolicy
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretSpec">ExternalSecretSpec</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"CreatedOnce"</p></td>
- <td></td>
- </tr><tr><td><p>"OnChange"</p></td>
- <td></td>
- </tr><tr><td><p>"Periodic"</p></td>
- <td></td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretRewrite">ExternalSecretRewrite
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretDataFromRemoteRef">ExternalSecretDataFromRemoteRef</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>merge</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretRewriteMerge">
- ExternalSecretRewriteMerge
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to merge key/values in one single Secret
- The resulting key will contain all values from the specified secrets</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>regexp</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretRewriteRegexp">
- ExternalSecretRewriteRegexp
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to rewrite with regular expressions.
- The resulting key will be the output of a regexp.ReplaceAll operation.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>transform</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretRewriteTransform">
- ExternalSecretRewriteTransform
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to apply string transformation on the secrets.
- The resulting key will be the output of the template applied by the operation.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretRewriteMerge">ExternalSecretRewriteMerge
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretRewrite">ExternalSecretRewrite</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>into</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to define the target key of the merge operation.
- Required if strategy is JSON. Ignored otherwise.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>priority</code></br>
- <em>
- []string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to define key priority in conflict resolution.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>priorityPolicy</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretRewriteMergePriorityPolicy">
- ExternalSecretRewriteMergePriorityPolicy
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to define the policy when a key in the priority list does not exist in the input.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>conflictPolicy</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretRewriteMergeConflictPolicy">
- ExternalSecretRewriteMergeConflictPolicy
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to define the policy to use in conflict resolution.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>strategy</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretRewriteMergeStrategy">
- ExternalSecretRewriteMergeStrategy
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to define the strategy to use in the merge operation.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretRewriteMergeConflictPolicy">ExternalSecretRewriteMergeConflictPolicy
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretRewriteMerge">ExternalSecretRewriteMerge</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"Error"</p></td>
- <td></td>
- </tr><tr><td><p>"Ignore"</p></td>
- <td></td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretRewriteMergePriorityPolicy">ExternalSecretRewriteMergePriorityPolicy
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretRewriteMerge">ExternalSecretRewriteMerge</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"IgnoreNotFound"</p></td>
- <td></td>
- </tr><tr><td><p>"Strict"</p></td>
- <td></td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretRewriteMergeStrategy">ExternalSecretRewriteMergeStrategy
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretRewriteMerge">ExternalSecretRewriteMerge</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"Extract"</p></td>
- <td></td>
- </tr><tr><td><p>"JSON"</p></td>
- <td></td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretRewriteRegexp">ExternalSecretRewriteRegexp
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretRewrite">ExternalSecretRewrite</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>source</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Used to define the regular expression of a re.Compiler.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>target</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Used to define the target pattern of a ReplaceAll operation.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretRewriteTransform">ExternalSecretRewriteTransform
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretRewrite">ExternalSecretRewrite</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>template</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Used to define the template to apply on the secret name.
- <code>.value</code> will specify the secret name in the template.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretSpec">ExternalSecretSpec
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ClusterExternalSecretSpec">ClusterExternalSecretSpec</a>,
- <a href="#external-secrets.io/v1.ExternalSecret">ExternalSecret</a>)
- </p>
- <p>
- <p>ExternalSecretSpec defines the desired state of ExternalSecret.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretStoreRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretStoreRef">
- SecretStoreRef
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>target</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretTarget">
- ExternalSecretTarget
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>refreshPolicy</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretRefreshPolicy">
- ExternalSecretRefreshPolicy
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>RefreshPolicy determines how the ExternalSecret should be refreshed:
- - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
- - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
- No periodic updates occur if refreshInterval is 0.
- - OnChange: Only synchronizes the Secret when the ExternalSecret’s metadata or specification changes</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>refreshInterval</code></br>
- <em>
- <a href="https://pkg.go.dev/k8s.io/apimachinery/pkg/apis/meta/v1#Duration">
- Kubernetes meta/v1.Duration
- </a>
- </em>
- </td>
- <td>
- <p>RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
- specified as Golang Duration strings.
- Valid time units are “ns”, “us” (or “µs”), “ms”, “s”, “m”, “h”
- Example values: “1h”, “2h30m”, “10s”
- May be set to zero to fetch and create it once. Defaults to 1h.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>data</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretData">
- []ExternalSecretData
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Data defines the connection between the Kubernetes Secret keys and the Provider data</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>dataFrom</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretDataFromRemoteRef">
- []ExternalSecretDataFromRemoteRef
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>DataFrom is used to fetch all properties from a specific Provider data
- If multiple entries are specified, the Secret keys are merged in the specified order</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretStatus">ExternalSecretStatus
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecret">ExternalSecret</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>refreshTime</code></br>
- <em>
- <a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.25/#time-v1-meta">
- Kubernetes meta/v1.Time
- </a>
- </em>
- </td>
- <td>
- <p>refreshTime is the time and date the external secret was fetched and
- the target secret updated</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>syncedResourceVersion</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>SyncedResourceVersion keeps track of the last synced version</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>conditions</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretStatusCondition">
- []ExternalSecretStatusCondition
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>binding</code></br>
- <em>
- <a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.25/#localobjectreference-v1-core">
- Kubernetes core/v1.LocalObjectReference
- </a>
- </em>
- </td>
- <td>
- <p>Binding represents a servicebinding.io Provisioned Service reference to the secret</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretStatusCondition">ExternalSecretStatusCondition
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretStatus">ExternalSecretStatus</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>type</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretConditionType">
- ExternalSecretConditionType
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>status</code></br>
- <em>
- <a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.25/#conditionstatus-v1-core">
- Kubernetes core/v1.ConditionStatus
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>reason</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>message</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>lastTransitionTime</code></br>
- <em>
- <a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.25/#time-v1-meta">
- Kubernetes meta/v1.Time
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretTarget">ExternalSecretTarget
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretSpec">ExternalSecretSpec</a>)
- </p>
- <p>
- <p>ExternalSecretTarget defines the Kubernetes Secret to be created
- There can be only one target per ExternalSecret.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>name</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The name of the Secret resource to be managed.
- Defaults to the .metadata.name of the ExternalSecret resource</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>creationPolicy</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretCreationPolicy">
- ExternalSecretCreationPolicy
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>CreationPolicy defines rules on how to create the resulting Secret.
- Defaults to “Owner”</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>deletionPolicy</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretDeletionPolicy">
- ExternalSecretDeletionPolicy
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>DeletionPolicy defines rules on how to delete the resulting Secret.
- Defaults to “Retain”</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>template</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretTemplate">
- ExternalSecretTemplate
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Template defines a blueprint for the created Secret resource.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>immutable</code></br>
- <em>
- bool
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Immutable defines if the final secret will be immutable</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretTemplate">ExternalSecretTemplate
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretTarget">ExternalSecretTarget</a>)
- </p>
- <p>
- <p>ExternalSecretTemplate defines a blueprint for the created Secret resource.
- we can not use native corev1.Secret, it will have empty ObjectMeta values: <a href="https://github.com/kubernetes-sigs/controller-tools/issues/448">https://github.com/kubernetes-sigs/controller-tools/issues/448</a></p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>type</code></br>
- <em>
- <a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.25/#secrettype-v1-core">
- Kubernetes core/v1.SecretType
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>engineVersion</code></br>
- <em>
- <a href="#external-secrets.io/v1.TemplateEngineVersion">
- TemplateEngineVersion
- </a>
- </em>
- </td>
- <td>
- <p>EngineVersion specifies the template engine version
- that should be used to compile/execute the
- template specified in .data and .templateFrom[].</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>metadata</code></br>
- <em>
- <a href="#external-secrets.io/v1.ExternalSecretTemplateMetadata">
- ExternalSecretTemplateMetadata
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>mergePolicy</code></br>
- <em>
- <a href="#external-secrets.io/v1.TemplateMergePolicy">
- TemplateMergePolicy
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>data</code></br>
- <em>
- map[string]string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>templateFrom</code></br>
- <em>
- <a href="#external-secrets.io/v1.TemplateFrom">
- []TemplateFrom
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretTemplateMetadata">ExternalSecretTemplateMetadata
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretTemplate">ExternalSecretTemplate</a>)
- </p>
- <p>
- <p>ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>annotations</code></br>
- <em>
- map[string]string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>labels</code></br>
- <em>
- map[string]string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>finalizers</code></br>
- <em>
- []string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ExternalSecretValidator">ExternalSecretValidator
- </h3>
- <p>
- </p>
- <h3 id="external-secrets.io/v1.FakeProvider">FakeProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>FakeProvider configures a fake provider that returns static values.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>data</code></br>
- <em>
- <a href="#external-secrets.io/v1.FakeProviderData">
- []FakeProviderData
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>validationResult</code></br>
- <em>
- <a href="#external-secrets.io/v1.ValidationResult">
- ValidationResult
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.FakeProviderData">FakeProviderData
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.FakeProvider">FakeProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>key</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>value</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>version</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.FetchingPolicy">FetchingPolicy
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.YandexCertificateManagerProvider">YandexCertificateManagerProvider</a>,
- <a href="#external-secrets.io/v1.YandexLockboxProvider">YandexLockboxProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>byID</code></br>
- <em>
- <a href="#external-secrets.io/v1.ByID">
- ByID
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>byName</code></br>
- <em>
- <a href="#external-secrets.io/v1.ByName">
- ByName
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.FindName">FindName
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretFind">ExternalSecretFind</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>regexp</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Finds secrets base</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.FortanixProvider">FortanixProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>apiUrl</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>APIURL is the URL of SDKMS API. Defaults to <code>sdkms.fortanix.com</code>.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>apiKey</code></br>
- <em>
- <a href="#external-secrets.io/v1.FortanixProviderSecretRef">
- FortanixProviderSecretRef
- </a>
- </em>
- </td>
- <td>
- <p>APIKey is the API token to access SDKMS Applications.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.FortanixProviderSecretRef">FortanixProviderSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.FortanixProvider">FortanixProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>SecretRef is a reference to a secret containing the SDKMS API Key.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.GCPSMAuth">GCPSMAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.GCPSMProvider">GCPSMProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.GCPSMAuthSecretRef">
- GCPSMAuthSecretRef
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>workloadIdentity</code></br>
- <em>
- <a href="#external-secrets.io/v1.GCPWorkloadIdentity">
- GCPWorkloadIdentity
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>workloadIdentityFederation</code></br>
- <em>
- <a href="#external-secrets.io/v1.GCPWorkloadIdentityFederation">
- GCPWorkloadIdentityFederation
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.GCPSMAuthSecretRef">GCPSMAuthSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.GCPSMAuth">GCPSMAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretAccessKeySecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The SecretAccessKey is used for authentication</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.GCPSMProvider">GCPSMProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>GCPSMProvider Configures a store to sync secrets using the GCP Secret Manager provider.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.GCPSMAuth">
- GCPSMAuth
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Auth defines the information necessary to authenticate against GCP</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>projectID</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>ProjectID project where secret is located</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>location</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Location optionally defines a location for a secret</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretVersionSelectionPolicy</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretVersionSelectionPolicy">
- SecretVersionSelectionPolicy
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>SecretVersionSelectionPolicy specifies how the provider selects a secret version
- when “latest” is disabled or destroyed.
- Possible values are:
- - LatestOrFail: the provider always uses “latest”, or fails if that version is disabled/destroyed.
- - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.GCPWorkloadIdentity">GCPWorkloadIdentity
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.GCPSMAuth">GCPSMAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>serviceAccountRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#ServiceAccountSelector">
- External Secrets meta/v1.ServiceAccountSelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>clusterLocation</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>ClusterLocation is the location of the cluster
- If not specified, it fetches information from the metadata server</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>clusterName</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>ClusterName is the name of the cluster
- If not specified, it fetches information from the metadata server</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>clusterProjectID</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>ClusterProjectID is the project ID of the cluster
- If not specified, it fetches information from the metadata server</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.GCPWorkloadIdentityFederation">GCPWorkloadIdentityFederation
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.GCPSMAuth">GCPSMAuth</a>)
- </p>
- <p>
- <p>GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>credConfig</code></br>
- <em>
- <a href="#external-secrets.io/v1.ConfigMapReference">
- ConfigMapReference
- </a>
- </em>
- </td>
- <td>
- <p>credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
- For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
- serviceAccountRef must be used by providing operators service account details.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>serviceAccountRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#ServiceAccountSelector">
- External Secrets meta/v1.ServiceAccountSelector
- </a>
- </em>
- </td>
- <td>
- <p>serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
- when Kubernetes is configured as provider in workload identity pool.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>awsSecurityCredentials</code></br>
- <em>
- <a href="#external-secrets.io/v1.AwsCredentialsConfig">
- AwsCredentialsConfig
- </a>
- </em>
- </td>
- <td>
- <p>awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
- when using the AWS metadata server is not an option.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>audience</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
- If specified, Audience found in the external account credential config will be overridden with the configured value.
- audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>externalTokenEndpoint</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
- credential_source.url in the provided credConfig. This field is merely to double-check the external token source
- URL is having the expected value.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.GcpIamAuthCredentials">GcpIamAuthCredentials
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.InfisicalAuth">InfisicalAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>identityId</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>serviceAccountKeyFilePath</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.GcpIdTokenAuthCredentials">GcpIdTokenAuthCredentials
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.InfisicalAuth">InfisicalAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>identityId</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.GeneratorRef">GeneratorRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.StoreGeneratorSourceRef">StoreGeneratorSourceRef</a>,
- <a href="#external-secrets.io/v1.StoreSourceRef">StoreSourceRef</a>)
- </p>
- <p>
- <p>GeneratorRef points to a generator custom resource.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>apiVersion</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Specify the apiVersion of the generator resource</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>kind</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Specify the Kind of the generator resource</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>name</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Specify the name of the generator resource</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.GenericStore">GenericStore
- </h3>
- <p>
- <p>GenericStore is a common interface for interacting with ClusterSecretStore
- or a namespaced SecretStore.</p>
- </p>
- <h3 id="external-secrets.io/v1.GenericStoreValidator">GenericStoreValidator
- </h3>
- <p>
- </p>
- <h3 id="external-secrets.io/v1.GithubAppAuth">GithubAppAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.GithubProvider">GithubProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>privateKey</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.GithubProvider">GithubProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>Configures a store to push secrets to Github Actions.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>url</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>URL configures the Github instance URL. Defaults to <a href="https://github.com/">https://github.com/</a>.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>uploadURL</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Upload URL for enterprise instances. Default to URL.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.GithubAppAuth">
- GithubAppAuth
- </a>
- </em>
- </td>
- <td>
- <p>auth configures how secret-manager authenticates with a Github instance.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>appID</code></br>
- <em>
- int64
- </em>
- </td>
- <td>
- <p>appID specifies the Github APP that will be used to authenticate the client</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>installationID</code></br>
- <em>
- int64
- </em>
- </td>
- <td>
- <p>installationID specifies the Github APP installation that will be used to authenticate the client</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>organization</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>organization will be used to fetch secrets from the Github organization</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>repository</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>repository will be used to fetch secrets from the Github repository within an organization</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>environment</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>environment will be used to fetch secrets from a particular environment within a github repository</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.GitlabAuth">GitlabAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.GitlabProvider">GitlabProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>SecretRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.GitlabSecretRef">
- GitlabSecretRef
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.GitlabProvider">GitlabProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>Configures a store to sync secrets with a GitLab instance.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>url</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>URL configures the GitLab instance URL. Defaults to <a href="https://gitlab.com/">https://gitlab.com/</a>.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.GitlabAuth">
- GitlabAuth
- </a>
- </em>
- </td>
- <td>
- <p>Auth configures how secret-manager authenticates with a GitLab instance.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>projectID</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>ProjectID specifies a project where secrets are located.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>inheritFromGroups</code></br>
- <em>
- bool
- </em>
- </td>
- <td>
- <p>InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>groupIDs</code></br>
- <em>
- []string
- </em>
- </td>
- <td>
- <p>GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>environment</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Environment environment_scope of gitlab CI/CD variables (Please see <a href="https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment">https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment</a> on how to create environments)</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>caBundle</code></br>
- <em>
- []byte
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
- can be performed.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>caProvider</code></br>
- <em>
- <a href="#external-secrets.io/v1.CAProvider">
- CAProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>see: <a href="https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider">https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider</a></p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.GitlabSecretRef">GitlabSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.GitlabAuth">GitlabAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>accessToken</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>AccessToken is used for authentication.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.IBMAuth">IBMAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.IBMProvider">IBMProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.IBMAuthSecretRef">
- IBMAuthSecretRef
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>containerAuth</code></br>
- <em>
- <a href="#external-secrets.io/v1.IBMAuthContainerAuth">
- IBMAuthContainerAuth
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.IBMAuthContainerAuth">IBMAuthContainerAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.IBMAuth">IBMAuth</a>)
- </p>
- <p>
- <p>IBM Container-based auth with IAM Trusted Profile.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>profile</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>the IBM Trusted Profile</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>tokenLocation</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Location the token is mounted on the pod</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>iamEndpoint</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.IBMAuthSecretRef">IBMAuthSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.IBMAuth">IBMAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretApiKeySecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>The SecretAccessKey is used for authentication</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.IBMProvider">IBMProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>Configures an store to sync secrets using a IBM Cloud Secrets Manager
- backend.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.IBMAuth">
- IBMAuth
- </a>
- </em>
- </td>
- <td>
- <p>Auth configures how secret-manager authenticates with the IBM secrets manager.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>serviceUrl</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.InfisicalAuth">InfisicalAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.InfisicalProvider">InfisicalProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>universalAuthCredentials</code></br>
- <em>
- <a href="#external-secrets.io/v1.UniversalAuthCredentials">
- UniversalAuthCredentials
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>azureAuthCredentials</code></br>
- <em>
- <a href="#external-secrets.io/v1.AzureAuthCredentials">
- AzureAuthCredentials
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>gcpIdTokenAuthCredentials</code></br>
- <em>
- <a href="#external-secrets.io/v1.GcpIdTokenAuthCredentials">
- GcpIdTokenAuthCredentials
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>gcpIamAuthCredentials</code></br>
- <em>
- <a href="#external-secrets.io/v1.GcpIamAuthCredentials">
- GcpIamAuthCredentials
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>jwtAuthCredentials</code></br>
- <em>
- <a href="#external-secrets.io/v1.JwtAuthCredentials">
- JwtAuthCredentials
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>ldapAuthCredentials</code></br>
- <em>
- <a href="#external-secrets.io/v1.LdapAuthCredentials">
- LdapAuthCredentials
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>ociAuthCredentials</code></br>
- <em>
- <a href="#external-secrets.io/v1.OciAuthCredentials">
- OciAuthCredentials
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>kubernetesAuthCredentials</code></br>
- <em>
- <a href="#external-secrets.io/v1.KubernetesAuthCredentials">
- KubernetesAuthCredentials
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>awsAuthCredentials</code></br>
- <em>
- <a href="#external-secrets.io/v1.AwsAuthCredentials">
- AwsAuthCredentials
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>tokenAuthCredentials</code></br>
- <em>
- <a href="#external-secrets.io/v1.TokenAuthCredentials">
- TokenAuthCredentials
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.InfisicalProvider">InfisicalProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>InfisicalProvider configures a store to sync secrets using the Infisical provider.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.InfisicalAuth">
- InfisicalAuth
- </a>
- </em>
- </td>
- <td>
- <p>Auth configures how the Operator authenticates with the Infisical API</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretsScope</code></br>
- <em>
- <a href="#external-secrets.io/v1.MachineIdentityScopeInWorkspace">
- MachineIdentityScopeInWorkspace
- </a>
- </em>
- </td>
- <td>
- <p>SecretsScope defines the scope of the secrets within the workspace</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>hostAPI</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to “<a href="https://app.infisical.com/api"">https://app.infisical.com/api”</a>.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.IntegrationInfo">IntegrationInfo
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.OnePasswordSDKProvider">OnePasswordSDKProvider</a>)
- </p>
- <p>
- <p>IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>name</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Name defaults to “1Password SDK”.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>version</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Version defaults to “v1.0.0”.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.JwtAuthCredentials">JwtAuthCredentials
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.InfisicalAuth">InfisicalAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>identityId</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>jwt</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.KeeperSecurityProvider">KeeperSecurityProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>KeeperSecurityProvider Configures a store to sync secrets using Keeper Security.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>authRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>folderID</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.KubernetesAuth">KubernetesAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.KubernetesProvider">KubernetesProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>cert</code></br>
- <em>
- <a href="#external-secrets.io/v1.CertAuth">
- CertAuth
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>has both clientCert and clientKey as secretKeySelector</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>token</code></br>
- <em>
- <a href="#external-secrets.io/v1.TokenAuth">
- TokenAuth
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>use static token to authenticate with</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>serviceAccount</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#ServiceAccountSelector">
- External Secrets meta/v1.ServiceAccountSelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>points to a service account that should be used for authentication</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.KubernetesAuthCredentials">KubernetesAuthCredentials
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.InfisicalAuth">InfisicalAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>identityId</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>serviceAccountTokenPath</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.KubernetesProvider">KubernetesProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>Configures a store to sync secrets with a Kubernetes instance.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>server</code></br>
- <em>
- <a href="#external-secrets.io/v1.KubernetesServer">
- KubernetesServer
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>configures the Kubernetes server Address.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.KubernetesAuth">
- KubernetesAuth
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Auth configures how secret-manager authenticates with a Kubernetes instance.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>authRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>A reference to a secret that contains the auth information.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>remoteNamespace</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Remote namespace to fetch the secrets from</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.KubernetesServer">KubernetesServer
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.KubernetesProvider">KubernetesProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>url</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>configures the Kubernetes server Address.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>caBundle</code></br>
- <em>
- []byte
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>CABundle is a base64-encoded CA certificate</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>caProvider</code></br>
- <em>
- <a href="#external-secrets.io/v1.CAProvider">
- CAProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>see: <a href="https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider">https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider</a></p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.LdapAuthCredentials">LdapAuthCredentials
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.InfisicalAuth">InfisicalAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>identityId</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>ldapPassword</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>ldapUsername</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.MachineIdentityScopeInWorkspace">MachineIdentityScopeInWorkspace
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.InfisicalProvider">InfisicalProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretsPath</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>SecretsPath specifies the path to the secrets within the workspace. Defaults to “/” if not provided.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>recursive</code></br>
- <em>
- bool
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>environmentSlug</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>EnvironmentSlug is the required slug identifier for the environment.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>projectSlug</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>ProjectSlug is the required slug identifier for the project.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>expandSecretReferences</code></br>
- <em>
- bool
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.MaintenanceStatus">MaintenanceStatus
- (<code>bool</code> alias)</p></h3>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>true</p></td>
- <td></td>
- </tr><tr><td><p>false</p></td>
- <td></td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.NTLMProtocol">NTLMProtocol
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.AuthorizationProtocol">AuthorizationProtocol</a>)
- </p>
- <p>
- <p>NTLMProtocol contains the NTLM-specific configuration.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>usernameSecret</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>passwordSecret</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.NgrokAuth">NgrokAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.NgrokProvider">NgrokProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>apiKey</code></br>
- <em>
- <a href="#external-secrets.io/v1.NgrokProviderSecretRef">
- NgrokProviderSecretRef
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>APIKey is the API Key used to authenticate with ngrok. See <a href="https://ngrok.com/docs/api/#authentication">https://ngrok.com/docs/api/#authentication</a></p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.NgrokProvider">NgrokProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>NgrokProvider configures a store to sync secrets with a ngrok vault to use in traffic policies.
- See: <a href="https://ngrok.com/blog-post/secrets-for-traffic-policy">https://ngrok.com/blog-post/secrets-for-traffic-policy</a></p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>apiUrl</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>APIURL is the URL of the ngrok API.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.NgrokAuth">
- NgrokAuth
- </a>
- </em>
- </td>
- <td>
- <p>Auth configures how the ngrok provider authenticates with the ngrok API.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>vault</code></br>
- <em>
- <a href="#external-secrets.io/v1.NgrokVault">
- NgrokVault
- </a>
- </em>
- </td>
- <td>
- <p>Vault configures the ngrok vault to sync secrets with.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.NgrokProviderSecretRef">NgrokProviderSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.NgrokAuth">NgrokAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>SecretRef is a reference to a secret containing the ngrok API key.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.NgrokVault">NgrokVault
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.NgrokProvider">NgrokProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>name</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Name is the name of the ngrok vault to sync secrets with.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.NoSecretError">NoSecretError
- </h3>
- <p>
- <p>NoSecretError shall be returned when a GetSecret can not find the
- desired secret. This is used for deletionPolicy.</p>
- </p>
- <h3 id="external-secrets.io/v1.NotModifiedError">NotModifiedError
- </h3>
- <p>
- <p>NotModifiedError to signal that the webhook received no changes,
- and it should just return without doing anything.</p>
- </p>
- <h3 id="external-secrets.io/v1.OciAuthCredentials">OciAuthCredentials
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.InfisicalAuth">InfisicalAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>identityId</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>privateKey</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>privateKeyPassphrase</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>fingerprint</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>userId</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>tenancyId</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>region</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.OnboardbaseAuthSecretRef">OnboardbaseAuthSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.OnboardbaseProvider">OnboardbaseProvider</a>)
- </p>
- <p>
- <p>OnboardbaseAuthSecretRef holds secret references for onboardbase API Key credentials.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>apiKeyRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>OnboardbaseAPIKey is the APIKey generated by an admin account.
- It is used to recognize and authorize access to a project and environment within onboardbase</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>passcodeRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>OnboardbasePasscode is the passcode attached to the API Key</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.OnboardbaseProvider">OnboardbaseProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>OnboardbaseProvider configures a store to sync secrets using the Onboardbase provider.
- Project and Config are required if not using a Service Token.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.OnboardbaseAuthSecretRef">
- OnboardbaseAuthSecretRef
- </a>
- </em>
- </td>
- <td>
- <p>Auth configures how the Operator authenticates with the Onboardbase API</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>apiHost</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>APIHost use this to configure the host url for the API for selfhosted installation, default is <a href="https://public.onboardbase.com/api/v1/">https://public.onboardbase.com/api/v1/</a></p>
- </td>
- </tr>
- <tr>
- <td>
- <code>project</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Project is an onboardbase project that the secrets should be pulled from</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>environment</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Environment is the name of an environmnent within a project to pull the secrets from</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.OnePasswordAuth">OnePasswordAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.OnePasswordProvider">OnePasswordProvider</a>)
- </p>
- <p>
- <p>OnePasswordAuth contains a secretRef for credentials.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.OnePasswordAuthSecretRef">
- OnePasswordAuthSecretRef
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.OnePasswordAuthSecretRef">OnePasswordAuthSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.OnePasswordAuth">OnePasswordAuth</a>)
- </p>
- <p>
- <p>OnePasswordAuthSecretRef holds secret references for 1Password credentials.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>connectTokenSecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>The ConnectToken is used for authentication to a 1Password Connect Server.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.OnePasswordProvider">OnePasswordProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>OnePasswordProvider configures a store to sync secrets using the 1Password Secret Manager provider.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.OnePasswordAuth">
- OnePasswordAuth
- </a>
- </em>
- </td>
- <td>
- <p>Auth defines the information necessary to authenticate against OnePassword Connect Server</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>connectHost</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>ConnectHost defines the OnePassword Connect Server to connect to</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>vaults</code></br>
- <em>
- map[string]int
- </em>
- </td>
- <td>
- <p>Vaults defines which OnePassword vaults to search in which order</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.OnePasswordSDKAuth">OnePasswordSDKAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.OnePasswordSDKProvider">OnePasswordSDKProvider</a>)
- </p>
- <p>
- <p>OnePasswordSDKAuth contains a secretRef for the service account token.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>serviceAccountSecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.OnePasswordSDKProvider">OnePasswordSDKProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>OnePasswordSDKProvider configures a store to sync secrets using the 1Password sdk.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>vault</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Vault defines the vault’s name or uuid to access. Do NOT add op:// prefix. This will be done automatically.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>integrationInfo</code></br>
- <em>
- <a href="#external-secrets.io/v1.IntegrationInfo">
- IntegrationInfo
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
- If you don’t know which name and version to use, use <code>DefaultIntegrationName</code> and <code>DefaultIntegrationVersion</code>, respectively.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.OnePasswordSDKAuth">
- OnePasswordSDKAuth
- </a>
- </em>
- </td>
- <td>
- <p>Auth defines the information necessary to authenticate against OnePassword API.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.OracleAuth">OracleAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.OracleProvider">OracleProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>tenancy</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Tenancy is the tenancy OCID where user is located.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>user</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>User is an access OCID specific to the account.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.OracleSecretRef">
- OracleSecretRef
- </a>
- </em>
- </td>
- <td>
- <p>SecretRef to pass through sensitive information.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.OraclePrincipalType">OraclePrincipalType
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.OracleProvider">OracleProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"InstancePrincipal"</p></td>
- <td><p>InstancePrincipal represents a instance principal.</p>
- </td>
- </tr><tr><td><p>"UserPrincipal"</p></td>
- <td><p>UserPrincipal represents a user principal.</p>
- </td>
- </tr><tr><td><p>"Workload"</p></td>
- <td><p>WorkloadPrincipal represents a workload principal.</p>
- </td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.OracleProvider">OracleProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>Configures an store to sync secrets using a Oracle Vault
- backend.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>region</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Region is the region where vault is located.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>vault</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Vault is the vault’s OCID of the specific vault where secret is located.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>compartment</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Compartment is the vault compartment OCID.
- Required for PushSecret</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>encryptionKey</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>EncryptionKey is the OCID of the encryption key within the vault.
- Required for PushSecret</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>principalType</code></br>
- <em>
- <a href="#external-secrets.io/v1.OraclePrincipalType">
- OraclePrincipalType
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The type of principal to use for authentication. If left blank, the Auth struct will
- determine the principal type. This optional field must be specified if using
- workload identity.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.OracleAuth">
- OracleAuth
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Auth configures how secret-manager authenticates with the Oracle Vault.
- If empty, use the instance principal, otherwise the user credentials specified in Auth.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>serviceAccountRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#ServiceAccountSelector">
- External Secrets meta/v1.ServiceAccountSelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>ServiceAccountRef specified the service account
- that should be used when authenticating with WorkloadIdentity.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.OracleSecretRef">OracleSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.OracleAuth">OracleAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>privatekey</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>PrivateKey is the user’s API Signing Key in PEM format, used for authentication.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>fingerprint</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>Fingerprint is the fingerprint of the API private key.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.PassboltAuth">PassboltAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.PassboltProvider">PassboltProvider</a>)
- </p>
- <p>
- <p>Passbolt contains a secretRef for the passbolt credentials.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>passwordSecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>privateKeySecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.PassboltProvider">PassboltProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.PassboltAuth">
- PassboltAuth
- </a>
- </em>
- </td>
- <td>
- <p>Auth defines the information necessary to authenticate against Passbolt Server</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>host</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Host defines the Passbolt Server to connect to</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.PasswordDepotAuth">PasswordDepotAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.PasswordDepotProvider">PasswordDepotProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.PasswordDepotSecretRef">
- PasswordDepotSecretRef
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.PasswordDepotProvider">PasswordDepotProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>Configures a store to sync secrets with a Password Depot instance.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>host</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>URL configures the Password Depot instance URL.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>database</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Database to use as source</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.PasswordDepotAuth">
- PasswordDepotAuth
- </a>
- </em>
- </td>
- <td>
- <p>Auth configures how secret-manager authenticates with a Password Depot instance.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.PasswordDepotSecretRef">PasswordDepotSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.PasswordDepotAuth">PasswordDepotAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>credentials</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Username / Password is used for authentication.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.PreviderAuth">PreviderAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.PreviderProvider">PreviderProvider</a>)
- </p>
- <p>
- <p>PreviderAuth contains a secretRef for credentials.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.PreviderAuthSecretRef">
- PreviderAuthSecretRef
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.PreviderAuthSecretRef">PreviderAuthSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.PreviderAuth">PreviderAuth</a>)
- </p>
- <p>
- <p>PreviderAuthSecretRef holds secret references for Previder Vault credentials.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>accessToken</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>The AccessToken is used for authentication</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.PreviderProvider">PreviderProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>PreviderProvider configures a store to sync secrets using the Previder Secret Manager provider.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.PreviderAuth">
- PreviderAuth
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>baseUri</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.Provider">Provider
- </h3>
- <p>
- <p>Provider is a common interface for interacting with secret backends.</p>
- </p>
- <h3 id="external-secrets.io/v1.PulumiProvider">PulumiProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>apiUrl</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>APIURL is the URL of the Pulumi API.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>accessToken</code></br>
- <em>
- <a href="#external-secrets.io/v1.PulumiProviderSecretRef">
- PulumiProviderSecretRef
- </a>
- </em>
- </td>
- <td>
- <p>AccessToken is the access tokens to sign in to the Pulumi Cloud Console.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>organization</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Organization are a space to collaborate on shared projects and stacks.
- To create a new organization, visit <a href="https://app.pulumi.com/">https://app.pulumi.com/</a> and click “New Organization”.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>project</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Project is the name of the Pulumi ESC project the environment belongs to.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>environment</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Environment are YAML documents composed of static key-value pairs, programmatic expressions,
- dynamically retrieved values from supported providers including all major clouds,
- and other Pulumi ESC environments.
- To create a new environment, visit <a href="https://www.pulumi.com/docs/esc/environments/">https://www.pulumi.com/docs/esc/environments/</a> for more information.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.PulumiProviderSecretRef">PulumiProviderSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.PulumiProvider">PulumiProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>SecretRef is a reference to a secret containing the Pulumi API token.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.PushSecretData">PushSecretData
- </h3>
- <p>
- <p>PushSecretData is an interface to allow using v1alpha1.PushSecretData content in Provider registered in v1.</p>
- </p>
- <h3 id="external-secrets.io/v1.PushSecretRemoteRef">PushSecretRemoteRef
- </h3>
- <p>
- <p>PushSecretRemoteRef is an interface to allow using v1alpha1.PushSecretRemoteRef in Provider registered in v1.</p>
- </p>
- <h3 id="external-secrets.io/v1.ScalewayProvider">ScalewayProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>apiUrl</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>APIURL is the url of the api to use. Defaults to <a href="https://api.scaleway.com">https://api.scaleway.com</a></p>
- </td>
- </tr>
- <tr>
- <td>
- <code>region</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Region where your secrets are located: <a href="https://developers.scaleway.com/en/quickstart/#region-and-zone">https://developers.scaleway.com/en/quickstart/#region-and-zone</a></p>
- </td>
- </tr>
- <tr>
- <td>
- <code>projectId</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>ProjectID is the id of your project, which you can find in the console: <a href="https://console.scaleway.com/project/settings">https://console.scaleway.com/project/settings</a></p>
- </td>
- </tr>
- <tr>
- <td>
- <code>accessKey</code></br>
- <em>
- <a href="#external-secrets.io/v1.ScalewayProviderSecretRef">
- ScalewayProviderSecretRef
- </a>
- </em>
- </td>
- <td>
- <p>AccessKey is the non-secret part of the api key.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretKey</code></br>
- <em>
- <a href="#external-secrets.io/v1.ScalewayProviderSecretRef">
- ScalewayProviderSecretRef
- </a>
- </em>
- </td>
- <td>
- <p>SecretKey is the non-secret part of the api key.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ScalewayProviderSecretRef">ScalewayProviderSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ScalewayProvider">ScalewayProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>value</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Value can be specified directly to set a value without using a secret.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>SecretRef references a key in a secret that will be used as value.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.SecretReference">SecretReference
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.AwsCredentialsConfig">AwsCredentialsConfig</a>)
- </p>
- <p>
- <p>SecretReference holds the details of a secret.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>name</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>name of the secret.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>namespace</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>namespace in which the secret exists. If empty, secret will looked up in local namespace.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.SecretServerProvider">SecretServerProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>See <a href="https://github.com/DelineaXPM/tss-sdk-go/blob/main/server/server.go">https://github.com/DelineaXPM/tss-sdk-go/blob/main/server/server.go</a>.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>username</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretServerProviderRef">
- SecretServerProviderRef
- </a>
- </em>
- </td>
- <td>
- <p>Username is the secret server account username.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>password</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretServerProviderRef">
- SecretServerProviderRef
- </a>
- </em>
- </td>
- <td>
- <p>Password is the secret server account password.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>domain</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Domain is the secret server domain.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>serverURL</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>ServerURL
- URL to your secret server installation</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.SecretServerProviderRef">SecretServerProviderRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretServerProvider">SecretServerProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>value</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Value can be specified directly to set a value without using a secret.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>SecretRef references a key in a secret that will be used as value.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.SecretStore">SecretStore
- </h3>
- <p>
- <p>SecretStore represents a secure external location for storing secrets, which can be referenced as part of <code>storeRef</code> fields.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>metadata</code></br>
- <em>
- <a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.25/#objectmeta-v1-meta">
- Kubernetes meta/v1.ObjectMeta
- </a>
- </em>
- </td>
- <td>
- Refer to the Kubernetes API documentation for the fields of the
- <code>metadata</code> field.
- </td>
- </tr>
- <tr>
- <td>
- <code>spec</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretStoreSpec">
- SecretStoreSpec
- </a>
- </em>
- </td>
- <td>
- <br/>
- <br/>
- <table>
- <tr>
- <td>
- <code>controller</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to select the correct ESO controller (think: ingress.ingressClassName)
- The ESO controller is instantiated with a specific controller name and filters ES based on this property</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>provider</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">
- SecretStoreProvider
- </a>
- </em>
- </td>
- <td>
- <p>Used to configure the provider. Only one provider may be set</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>retrySettings</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretStoreRetrySettings">
- SecretStoreRetrySettings
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to configure http retries if failed</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>refreshInterval</code></br>
- <em>
- int
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>conditions</code></br>
- <em>
- <a href="#external-secrets.io/v1.ClusterSecretStoreCondition">
- []ClusterSecretStoreCondition
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to constraint a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore</p>
- </td>
- </tr>
- </table>
- </td>
- </tr>
- <tr>
- <td>
- <code>status</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretStoreStatus">
- SecretStoreStatus
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.SecretStoreCapabilities">SecretStoreCapabilities
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreStatus">SecretStoreStatus</a>)
- </p>
- <p>
- <p>SecretStoreCapabilities defines the possible operations a SecretStore can do.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"ReadOnly"</p></td>
- <td></td>
- </tr><tr><td><p>"ReadWrite"</p></td>
- <td></td>
- </tr><tr><td><p>"WriteOnly"</p></td>
- <td></td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.SecretStoreConditionType">SecretStoreConditionType
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreStatusCondition">SecretStoreStatusCondition</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"Ready"</p></td>
- <td></td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreSpec">SecretStoreSpec</a>)
- </p>
- <p>
- <p>SecretStoreProvider contains the provider-specific configuration.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>aws</code></br>
- <em>
- <a href="#external-secrets.io/v1.AWSProvider">
- AWSProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>AWS configures this store to sync secrets using AWS Secret Manager provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>azurekv</code></br>
- <em>
- <a href="#external-secrets.io/v1.AzureKVProvider">
- AzureKVProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>AzureKV configures this store to sync secrets using Azure Key Vault provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>akeyless</code></br>
- <em>
- <a href="#external-secrets.io/v1.AkeylessProvider">
- AkeylessProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Akeyless configures this store to sync secrets using Akeyless Vault provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>bitwardensecretsmanager</code></br>
- <em>
- <a href="#external-secrets.io/v1.BitwardenSecretsManagerProvider">
- BitwardenSecretsManagerProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>vault</code></br>
- <em>
- <a href="#external-secrets.io/v1.VaultProvider">
- VaultProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Vault configures this store to sync secrets using Hashi provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>gcpsm</code></br>
- <em>
- <a href="#external-secrets.io/v1.GCPSMProvider">
- GCPSMProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>oracle</code></br>
- <em>
- <a href="#external-secrets.io/v1.OracleProvider">
- OracleProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Oracle configures this store to sync secrets using Oracle Vault provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>ibm</code></br>
- <em>
- <a href="#external-secrets.io/v1.IBMProvider">
- IBMProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>IBM configures this store to sync secrets using IBM Cloud provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>yandexcertificatemanager</code></br>
- <em>
- <a href="#external-secrets.io/v1.YandexCertificateManagerProvider">
- YandexCertificateManagerProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>yandexlockbox</code></br>
- <em>
- <a href="#external-secrets.io/v1.YandexLockboxProvider">
- YandexLockboxProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>YandexLockbox configures this store to sync secrets using Yandex Lockbox provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>github</code></br>
- <em>
- <a href="#external-secrets.io/v1.GithubProvider">
- GithubProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Github configures this store to push GitHub Action secrets using GitHub API provider.
- Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>gitlab</code></br>
- <em>
- <a href="#external-secrets.io/v1.GitlabProvider">
- GitlabProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>GitLab configures this store to sync secrets using GitLab Variables provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>alibaba</code></br>
- <em>
- <a href="#external-secrets.io/v1.AlibabaProvider">
- AlibabaProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Alibaba configures this store to sync secrets using Alibaba Cloud provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>onepassword</code></br>
- <em>
- <a href="#external-secrets.io/v1.OnePasswordProvider">
- OnePasswordProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>OnePassword configures this store to sync secrets using the 1Password Cloud provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>onepasswordSDK</code></br>
- <em>
- <a href="#external-secrets.io/v1.OnePasswordSDKProvider">
- OnePasswordSDKProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>OnePasswordSDK configures this store to use 1Password’s new Go SDK to sync secrets.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>webhook</code></br>
- <em>
- <a href="#external-secrets.io/v1.WebhookProvider">
- WebhookProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Webhook configures this store to sync secrets using a generic templated webhook</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>kubernetes</code></br>
- <em>
- <a href="#external-secrets.io/v1.KubernetesProvider">
- KubernetesProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Kubernetes configures this store to sync secrets using a Kubernetes cluster provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>fake</code></br>
- <em>
- <a href="#external-secrets.io/v1.FakeProvider">
- FakeProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Fake configures a store with static key/value pairs</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>senhasegura</code></br>
- <em>
- <a href="#external-secrets.io/v1.SenhaseguraProvider">
- SenhaseguraProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Senhasegura configures this store to sync secrets using senhasegura provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>scaleway</code></br>
- <em>
- <a href="#external-secrets.io/v1.ScalewayProvider">
- ScalewayProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Scaleway</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>doppler</code></br>
- <em>
- <a href="#external-secrets.io/v1.DopplerProvider">
- DopplerProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Doppler configures this store to sync secrets using the Doppler provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>previder</code></br>
- <em>
- <a href="#external-secrets.io/v1.PreviderProvider">
- PreviderProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Previder configures this store to sync secrets using the Previder provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>onboardbase</code></br>
- <em>
- <a href="#external-secrets.io/v1.OnboardbaseProvider">
- OnboardbaseProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Onboardbase configures this store to sync secrets using the Onboardbase provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>keepersecurity</code></br>
- <em>
- <a href="#external-secrets.io/v1.KeeperSecurityProvider">
- KeeperSecurityProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>conjur</code></br>
- <em>
- <a href="#external-secrets.io/v1.ConjurProvider">
- ConjurProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Conjur configures this store to sync secrets using conjur provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>delinea</code></br>
- <em>
- <a href="#external-secrets.io/v1.DelineaProvider">
- DelineaProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Delinea DevOps Secrets Vault
- <a href="https://docs.delinea.com/online-help/products/devops-secrets-vault/current">https://docs.delinea.com/online-help/products/devops-secrets-vault/current</a></p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretserver</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretServerProvider">
- SecretServerProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>SecretServer configures this store to sync secrets using SecretServer provider
- <a href="https://docs.delinea.com/online-help/secret-server/start.htm">https://docs.delinea.com/online-help/secret-server/start.htm</a></p>
- </td>
- </tr>
- <tr>
- <td>
- <code>chef</code></br>
- <em>
- <a href="#external-secrets.io/v1.ChefProvider">
- ChefProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Chef configures this store to sync secrets with chef server</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>pulumi</code></br>
- <em>
- <a href="#external-secrets.io/v1.PulumiProvider">
- PulumiProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Pulumi configures this store to sync secrets using the Pulumi provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>fortanix</code></br>
- <em>
- <a href="#external-secrets.io/v1.FortanixProvider">
- FortanixProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Fortanix configures this store to sync secrets using the Fortanix provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>passworddepot</code></br>
- <em>
- <a href="#external-secrets.io/v1.PasswordDepotProvider">
- PasswordDepotProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>passbolt</code></br>
- <em>
- <a href="#external-secrets.io/v1.PassboltProvider">
- PassboltProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>device42</code></br>
- <em>
- <a href="#external-secrets.io/v1.Device42Provider">
- Device42Provider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Device42 configures this store to sync secrets using the Device42 provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>infisical</code></br>
- <em>
- <a href="#external-secrets.io/v1.InfisicalProvider">
- InfisicalProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Infisical configures this store to sync secrets using the Infisical provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>beyondtrust</code></br>
- <em>
- <a href="#external-secrets.io/v1.BeyondtrustProvider">
- BeyondtrustProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Beyondtrust configures this store to sync secrets using Password Safe provider.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>cloudrusm</code></br>
- <em>
- <a href="#external-secrets.io/v1.CloudruSMProvider">
- CloudruSMProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>volcengine</code></br>
- <em>
- <a href="#external-secrets.io/v1.VolcengineProvider">
- VolcengineProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Volcengine configures this store to sync secrets using the Volcengine provider</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>ngrok</code></br>
- <em>
- <a href="#external-secrets.io/v1.NgrokProvider">
- NgrokProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Ngrok configures this store to sync secrets using the ngrok provider.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.SecretStoreRef">SecretStoreRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretSpec">ExternalSecretSpec</a>,
- <a href="#external-secrets.io/v1.StoreGeneratorSourceRef">StoreGeneratorSourceRef</a>,
- <a href="#external-secrets.io/v1.StoreSourceRef">StoreSourceRef</a>)
- </p>
- <p>
- <p>SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>name</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Name of the SecretStore resource</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>kind</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
- Defaults to <code>SecretStore</code></p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.SecretStoreRetrySettings">SecretStoreRetrySettings
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreSpec">SecretStoreSpec</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>maxRetries</code></br>
- <em>
- int32
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>retryInterval</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.SecretStoreSpec">SecretStoreSpec
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ClusterSecretStore">ClusterSecretStore</a>,
- <a href="#external-secrets.io/v1.SecretStore">SecretStore</a>)
- </p>
- <p>
- <p>SecretStoreSpec defines the desired state of SecretStore.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>controller</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to select the correct ESO controller (think: ingress.ingressClassName)
- The ESO controller is instantiated with a specific controller name and filters ES based on this property</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>provider</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">
- SecretStoreProvider
- </a>
- </em>
- </td>
- <td>
- <p>Used to configure the provider. Only one provider may be set</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>retrySettings</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretStoreRetrySettings">
- SecretStoreRetrySettings
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to configure http retries if failed</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>refreshInterval</code></br>
- <em>
- int
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>conditions</code></br>
- <em>
- <a href="#external-secrets.io/v1.ClusterSecretStoreCondition">
- []ClusterSecretStoreCondition
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Used to constraint a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.SecretStoreStatus">SecretStoreStatus
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ClusterSecretStore">ClusterSecretStore</a>,
- <a href="#external-secrets.io/v1.SecretStore">SecretStore</a>)
- </p>
- <p>
- <p>SecretStoreStatus defines the observed state of the SecretStore.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>conditions</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretStoreStatusCondition">
- []SecretStoreStatusCondition
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>capabilities</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretStoreCapabilities">
- SecretStoreCapabilities
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.SecretStoreStatusCondition">SecretStoreStatusCondition
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreStatus">SecretStoreStatus</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>type</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretStoreConditionType">
- SecretStoreConditionType
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>status</code></br>
- <em>
- <a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.25/#conditionstatus-v1-core">
- Kubernetes core/v1.ConditionStatus
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>reason</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>message</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>lastTransitionTime</code></br>
- <em>
- <a href="https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.25/#time-v1-meta">
- Kubernetes meta/v1.Time
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.SecretVersionSelectionPolicy">SecretVersionSelectionPolicy
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.GCPSMProvider">GCPSMProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"LatestOrFail"</p></td>
- <td><p>SecretVersionSelectionPolicyLatestOrFail means the provider always uses “latest”, or fails if that version is disabled/destroyed.</p>
- </td>
- </tr><tr><td><p>"LatestOrFetch"</p></td>
- <td><p>SecretVersionSelectionPolicyLatestOrFetch behaves like SecretVersionSelectionPolicyLatestOrFail but falls back to fetching the latest version if the version is DESTROYED or DISABLED.</p>
- </td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.SecretsClient">SecretsClient
- </h3>
- <p>
- <p>SecretsClient provides access to secrets.</p>
- </p>
- <h3 id="external-secrets.io/v1.SecretsManager">SecretsManager
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.AWSProvider">AWSProvider</a>)
- </p>
- <p>
- <p>SecretsManager defines how the provider behaves when interacting with AWS
- SecretsManager. Some of these settings are only applicable to controlling how
- secrets are deleted, and hence only apply to PushSecret (and only when
- deletionPolicy is set to Delete).</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>forceDeleteWithoutRecovery</code></br>
- <em>
- bool
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Specifies whether to delete the secret without any recovery window. You
- can’t use both this parameter and RecoveryWindowInDays in the same call.
- If you don’t use either, then by default Secrets Manager uses a 30 day
- recovery window.
- see: <a href="https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery">https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery</a></p>
- </td>
- </tr>
- <tr>
- <td>
- <code>recoveryWindowInDays</code></br>
- <em>
- int64
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The number of days from 7 to 30 that Secrets Manager waits before
- permanently deleting the secret. You can’t use both this parameter and
- ForceDeleteWithoutRecovery in the same call. If you don’t use either,
- then by default Secrets Manager uses a 30 day recovery window.
- see: <a href="https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays">https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays</a></p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.SenhaseguraAuth">SenhaseguraAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SenhaseguraProvider">SenhaseguraProvider</a>)
- </p>
- <p>
- <p>SenhaseguraAuth tells the controller how to do auth in senhasegura.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>clientId</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>clientSecretSecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.SenhaseguraModuleType">SenhaseguraModuleType
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SenhaseguraProvider">SenhaseguraProvider</a>)
- </p>
- <p>
- <p>SenhaseguraModuleType enum defines senhasegura target module to fetch secrets</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"DSM"</p></td>
- <td><pre><code> SenhaseguraModuleDSM is the senhasegura DevOps Secrets Management module
- see: https://senhasegura.com/devops
- </code></pre>
- </td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.SenhaseguraProvider">SenhaseguraProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>SenhaseguraProvider setup a store to sync secrets with senhasegura.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>url</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>URL of senhasegura</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>module</code></br>
- <em>
- <a href="#external-secrets.io/v1.SenhaseguraModuleType">
- SenhaseguraModuleType
- </a>
- </em>
- </td>
- <td>
- <p>Module defines which senhasegura module should be used to get secrets</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.SenhaseguraAuth">
- SenhaseguraAuth
- </a>
- </em>
- </td>
- <td>
- <p>Auth defines parameters to authenticate in senhasegura</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>ignoreSslCertificate</code></br>
- <em>
- bool
- </em>
- </td>
- <td>
- <p>IgnoreSslCertificate defines if SSL certificate must be ignored</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.StoreGeneratorSourceRef">StoreGeneratorSourceRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretDataFromRemoteRef">ExternalSecretDataFromRemoteRef</a>)
- </p>
- <p>
- <p>StoreGeneratorSourceRef allows you to override the source
- from which the secret will be pulled from.
- You can define at maximum one property.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>storeRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretStoreRef">
- SecretStoreRef
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>generatorRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.GeneratorRef">
- GeneratorRef
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>GeneratorRef points to a generator custom resource.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.StoreSourceRef">StoreSourceRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretData">ExternalSecretData</a>)
- </p>
- <p>
- <p>StoreSourceRef allows you to override the SecretStore source
- from which the secret will be pulled from.
- You can define at maximum one property.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>storeRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.SecretStoreRef">
- SecretStoreRef
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>generatorRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.GeneratorRef">
- GeneratorRef
- </a>
- </em>
- </td>
- <td>
- <p>GeneratorRef points to a generator custom resource.</p>
- <p>Deprecated: The generatorRef is not implemented in .data[].
- this will be removed with v1.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.Tag">Tag
- </h3>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>key</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>value</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.TemplateEngineVersion">TemplateEngineVersion
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretTemplate">ExternalSecretTemplate</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"v2"</p></td>
- <td></td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.TemplateFrom">TemplateFrom
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretTemplate">ExternalSecretTemplate</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>configMap</code></br>
- <em>
- <a href="#external-secrets.io/v1.TemplateRef">
- TemplateRef
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>secret</code></br>
- <em>
- <a href="#external-secrets.io/v1.TemplateRef">
- TemplateRef
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>target</code></br>
- <em>
- <a href="#external-secrets.io/v1.TemplateTarget">
- TemplateTarget
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>literal</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.TemplateMergePolicy">TemplateMergePolicy
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.ExternalSecretTemplate">ExternalSecretTemplate</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"Merge"</p></td>
- <td></td>
- </tr><tr><td><p>"Replace"</p></td>
- <td></td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.TemplateRef">TemplateRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.TemplateFrom">TemplateFrom</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>name</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>The name of the ConfigMap/Secret resource</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>items</code></br>
- <em>
- <a href="#external-secrets.io/v1.TemplateRefItem">
- []TemplateRefItem
- </a>
- </em>
- </td>
- <td>
- <p>A list of keys in the ConfigMap/Secret to use as templates for Secret data</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.TemplateRefItem">TemplateRefItem
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.TemplateRef">TemplateRef</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>key</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>A key in the ConfigMap/Secret</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>templateAs</code></br>
- <em>
- <a href="#external-secrets.io/v1.TemplateScope">
- TemplateScope
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.TemplateScope">TemplateScope
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.TemplateRefItem">TemplateRefItem</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"KeysAndValues"</p></td>
- <td></td>
- </tr><tr><td><p>"Values"</p></td>
- <td></td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.TemplateTarget">TemplateTarget
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.TemplateFrom">TemplateFrom</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"Annotations"</p></td>
- <td></td>
- </tr><tr><td><p>"Data"</p></td>
- <td></td>
- </tr><tr><td><p>"Labels"</p></td>
- <td></td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.TokenAuth">TokenAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.KubernetesAuth">KubernetesAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>bearerToken</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.TokenAuthCredentials">TokenAuthCredentials
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.InfisicalAuth">InfisicalAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>accessToken</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.UniversalAuthCredentials">UniversalAuthCredentials
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.InfisicalAuth">InfisicalAuth</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>clientId</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- <tr>
- <td>
- <code>clientSecret</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.ValidationResult">ValidationResult
- (<code>byte</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.FakeProvider">FakeProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>2</p></td>
- <td><p>Error indicates that there is a misconfiguration.</p>
- </td>
- </tr><tr><td><p>0</p></td>
- <td><p>Ready indicates that the client is configured correctly
- and can be used.</p>
- </td>
- </tr><tr><td><p>1</p></td>
- <td><p>Unknown indicates that the client can be used
- but information is missing and it can not be validated.</p>
- </td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.VaultAppRole">VaultAppRole
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.VaultAuth">VaultAuth</a>)
- </p>
- <p>
- <p>VaultAppRole authenticates with Vault using the App Role auth mechanism,
- with the role and secret stored in a Kubernetes Secret resource.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>path</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Path where the App Role authentication backend is mounted
- in Vault, e.g: “approle”</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>roleId</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>RoleID configured in the App Role authentication backend when setting
- up the authentication backend in Vault.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>roleRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Reference to a key in a Secret that contains the App Role ID used
- to authenticate with Vault.
- The <code>key</code> field must be specified and denotes which entry within the Secret
- resource is used as the app role id.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>Reference to a key in a Secret that contains the App Role secret used
- to authenticate with Vault.
- The <code>key</code> field must be specified and denotes which entry within the Secret
- resource is used as the app role secret.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.VaultAuth">VaultAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.VaultProvider">VaultProvider</a>)
- </p>
- <p>
- <p>VaultAuth is the configuration used to authenticate with a Vault server.
- Only one of <code>tokenSecretRef</code>, <code>appRole</code>, <code>kubernetes</code>, <code>ldap</code>, <code>userPass</code>, <code>jwt</code> or <code>cert</code>
- can be specified. A namespace to authenticate against can optionally be specified.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>namespace</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
- Namespaces is a set of features within Vault Enterprise that allows
- Vault environments to support Secure Multi-tenancy. e.g: “ns1”.
- More about namespaces can be found here <a href="https://www.vaultproject.io/docs/enterprise/namespaces">https://www.vaultproject.io/docs/enterprise/namespaces</a>
- This will default to Vault.Namespace field if set, or empty otherwise</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>tokenSecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>TokenSecretRef authenticates with Vault by presenting a token.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>appRole</code></br>
- <em>
- <a href="#external-secrets.io/v1.VaultAppRole">
- VaultAppRole
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>AppRole authenticates with Vault using the App Role auth mechanism,
- with the role and secret stored in a Kubernetes Secret resource.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>kubernetes</code></br>
- <em>
- <a href="#external-secrets.io/v1.VaultKubernetesAuth">
- VaultKubernetesAuth
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Kubernetes authenticates with Vault by passing the ServiceAccount
- token stored in the named Secret resource to the Vault server.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>ldap</code></br>
- <em>
- <a href="#external-secrets.io/v1.VaultLdapAuth">
- VaultLdapAuth
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Ldap authenticates with Vault by passing username/password pair using
- the LDAP authentication method</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>jwt</code></br>
- <em>
- <a href="#external-secrets.io/v1.VaultJwtAuth">
- VaultJwtAuth
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Jwt authenticates with Vault by passing role and JWT token using the
- JWT/OIDC authentication method</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>cert</code></br>
- <em>
- <a href="#external-secrets.io/v1.VaultCertAuth">
- VaultCertAuth
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
- Cert authentication method</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>iam</code></br>
- <em>
- <a href="#external-secrets.io/v1.VaultIamAuth">
- VaultIamAuth
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
- AWS IAM authentication method</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>userPass</code></br>
- <em>
- <a href="#external-secrets.io/v1.VaultUserPassAuth">
- VaultUserPassAuth
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>UserPass authenticates with Vault by passing username/password pair</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.VaultAwsAuth">VaultAwsAuth
- </h3>
- <p>
- <p>VaultAwsAuth tells the controller how to do authentication with aws.
- Only one of secretRef or jwt can be specified.
- if none is specified the controller will try to load credentials from its own service account assuming it is IRSA enabled.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.VaultAwsAuthSecretRef">
- VaultAwsAuthSecretRef
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- <tr>
- <td>
- <code>jwt</code></br>
- <em>
- <a href="#external-secrets.io/v1.VaultAwsJWTAuth">
- VaultAwsJWTAuth
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.VaultAwsAuthSecretRef">VaultAwsAuthSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.VaultAwsAuth">VaultAwsAuth</a>,
- <a href="#external-secrets.io/v1.VaultIamAuth">VaultIamAuth</a>)
- </p>
- <p>
- <p>VaultAWSAuthSecretRef holds secret references for AWS credentials
- both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>accessKeyIDSecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The AccessKeyID is used for authentication</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretAccessKeySecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The SecretAccessKey is used for authentication</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>sessionTokenSecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The SessionToken used for authentication
- This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
- see: <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html">https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html</a></p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.VaultAwsJWTAuth">VaultAwsJWTAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.VaultAwsAuth">VaultAwsAuth</a>,
- <a href="#external-secrets.io/v1.VaultIamAuth">VaultIamAuth</a>)
- </p>
- <p>
- <p>VaultAwsJWTAuth Authenticate against AWS using service account tokens.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>serviceAccountRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#ServiceAccountSelector">
- External Secrets meta/v1.ServiceAccountSelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.VaultCertAuth">VaultCertAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.VaultAuth">VaultAuth</a>)
- </p>
- <p>
- <p>VaultCertAuth authenticates with Vault using the JWT/OIDC authentication
- method, with the role name and token stored in a Kubernetes Secret resource.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>path</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Path where the Certificate authentication backend is mounted
- in Vault, e.g: “cert”</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>clientCert</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>ClientCert is a certificate to authenticate using the Cert Vault
- authentication method</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>SecretRef to a key in a Secret resource containing client private key to
- authenticate with Vault using the Cert authentication method</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.VaultCheckAndSet">VaultCheckAndSet
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.VaultProvider">VaultProvider</a>)
- </p>
- <p>
- <p>VaultCheckAndSet defines the Check-And-Set (CAS) settings for Vault KV v2 PushSecret operations.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>required</code></br>
- <em>
- bool
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Required when true, all write operations must include a check-and-set parameter.
- This helps prevent unintentional overwrites of secrets.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.VaultClientTLS">VaultClientTLS
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.VaultProvider">VaultProvider</a>)
- </p>
- <p>
- <p>VaultClientTLS is the configuration used for client side related TLS communication,
- when the Vault server requires mutual authentication.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>certSecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>CertSecretRef is a certificate added to the transport layer
- when communicating with the Vault server.
- If no key for the Secret is specified, external-secret will default to ‘tls.crt’.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>keySecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>KeySecretRef to a key in a Secret resource containing client private key
- added to the transport layer when communicating with the Vault server.
- If no key for the Secret is specified, external-secret will default to ‘tls.key’.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.VaultIamAuth">VaultIamAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.VaultAuth">VaultAuth</a>)
- </p>
- <p>
- <p>VaultIamAuth authenticates with Vault using the Vault’s AWS IAM authentication method. Refer: <a href="https://developer.hashicorp.com/vault/docs/auth/aws">https://developer.hashicorp.com/vault/docs/auth/aws</a></p>
- <p>When JWTAuth and SecretRef are not specified, the provider will use the controller pod’s
- identity to authenticate with AWS. This supports both IRSA and EKS Pod Identity.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>path</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Path where the AWS auth method is enabled in Vault, e.g: “aws”</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>region</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>AWS region</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>role</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>This is the AWS role to be assumed before talking to vault</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>vaultRole</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>externalID</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>AWS External ID set on assumed IAM roles</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>vaultAwsIamServerID</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: <a href="https://developer.hashicorp.com/vault/docs/auth/aws">https://developer.hashicorp.com/vault/docs/auth/aws</a></p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.VaultAwsAuthSecretRef">
- VaultAwsAuthSecretRef
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Specify credentials in a Secret object</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>jwt</code></br>
- <em>
- <a href="#external-secrets.io/v1.VaultAwsJWTAuth">
- VaultAwsJWTAuth
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Specify a service account with IRSA enabled</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.VaultJwtAuth">VaultJwtAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.VaultAuth">VaultAuth</a>)
- </p>
- <p>
- <p>VaultJwtAuth authenticates with Vault using the JWT/OIDC authentication
- method, with the role name and a token stored in a Kubernetes Secret resource or
- a Kubernetes service account token retrieved via <code>TokenRequest</code>.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>path</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Path where the JWT authentication backend is mounted
- in Vault, e.g: “jwt”</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>role</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Role is a JWT role to authenticate using the JWT/OIDC Vault
- authentication method</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Optional SecretRef that refers to a key in a Secret resource containing JWT token to
- authenticate with Vault using the JWT/OIDC authentication method.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>kubernetesServiceAccountToken</code></br>
- <em>
- <a href="#external-secrets.io/v1.VaultKubernetesServiceAccountTokenAuth">
- VaultKubernetesServiceAccountTokenAuth
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Optional ServiceAccountToken specifies the Kubernetes service account for which to request
- a token for with the <code>TokenRequest</code> API.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.VaultKVStoreVersion">VaultKVStoreVersion
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.VaultProvider">VaultProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"v1"</p></td>
- <td></td>
- </tr><tr><td><p>"v2"</p></td>
- <td></td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.VaultKubernetesAuth">VaultKubernetesAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.VaultAuth">VaultAuth</a>)
- </p>
- <p>
- <p>Authenticate against Vault using a Kubernetes ServiceAccount token stored in
- a Secret.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>mountPath</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Path where the Kubernetes authentication backend is mounted in Vault, e.g:
- “kubernetes”</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>serviceAccountRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#ServiceAccountSelector">
- External Secrets meta/v1.ServiceAccountSelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Optional service account field containing the name of a kubernetes ServiceAccount.
- If the service account is specified, the service account secret token JWT will be used
- for authenticating with Vault. If the service account selector is not supplied,
- the secretRef will be used instead.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Optional secret field containing a Kubernetes ServiceAccount JWT used
- for authenticating with Vault. If a name is specified without a key,
- <code>token</code> is the default. If one is not specified, the one bound to
- the controller will be used.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>role</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>A required field containing the Vault Role to assume. A Role binds a
- Kubernetes ServiceAccount with a set of Vault policies.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.VaultKubernetesServiceAccountTokenAuth">VaultKubernetesServiceAccountTokenAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.VaultJwtAuth">VaultJwtAuth</a>)
- </p>
- <p>
- <p>VaultKubernetesServiceAccountTokenAuth authenticates with Vault using a temporary
- Kubernetes service account token retrieved by the <code>TokenRequest</code> API.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>serviceAccountRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#ServiceAccountSelector">
- External Secrets meta/v1.ServiceAccountSelector
- </a>
- </em>
- </td>
- <td>
- <p>Service account field containing the name of a kubernetes ServiceAccount.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>audiences</code></br>
- <em>
- []string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Optional audiences field that will be used to request a temporary Kubernetes service
- account token for the service account referenced by <code>serviceAccountRef</code>.
- Defaults to a single audience <code>vault</code> it not specified.
- Deprecated: use serviceAccountRef.Audiences instead</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>expirationSeconds</code></br>
- <em>
- int64
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Optional expiration time in seconds that will be used to request a temporary
- Kubernetes service account token for the service account referenced by
- <code>serviceAccountRef</code>.
- Deprecated: this will be removed in the future.
- Defaults to 10 minutes.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.VaultLdapAuth">VaultLdapAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.VaultAuth">VaultAuth</a>)
- </p>
- <p>
- <p>VaultLdapAuth authenticates with Vault using the LDAP authentication method,
- with the username and password stored in a Kubernetes Secret resource.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>path</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Path where the LDAP authentication backend is mounted
- in Vault, e.g: “ldap”</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>username</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Username is an LDAP username used to authenticate using the LDAP Vault
- authentication method</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>SecretRef to a key in a Secret resource containing password for the LDAP
- user used to authenticate with Vault using the LDAP authentication
- method</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.VaultProvider">VaultProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>Configures an store to sync secrets using a HashiCorp Vault
- KV backend.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.VaultAuth">
- VaultAuth
- </a>
- </em>
- </td>
- <td>
- <p>Auth configures how secret-manager authenticates with the Vault server.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>server</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Server is the connection address for the Vault server, e.g: “<a href="https://vault.example.com:8200"">https://vault.example.com:8200”</a>.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>path</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Path is the mount path of the Vault KV backend endpoint, e.g:
- “secret”. The v2 KV secret engine version specific “/data” path suffix
- for fetching secrets from Vault is optional and will be appended
- if not present in specified path.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>version</code></br>
- <em>
- <a href="#external-secrets.io/v1.VaultKVStoreVersion">
- VaultKVStoreVersion
- </a>
- </em>
- </td>
- <td>
- <p>Version is the Vault KV secret engine version. This can be either “v1” or
- “v2”. Version defaults to “v2”.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>namespace</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
- Vault environments to support Secure Multi-tenancy. e.g: “ns1”.
- More about namespaces can be found here <a href="https://www.vaultproject.io/docs/enterprise/namespaces">https://www.vaultproject.io/docs/enterprise/namespaces</a></p>
- </td>
- </tr>
- <tr>
- <td>
- <code>caBundle</code></br>
- <em>
- []byte
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>PEM encoded CA bundle used to validate Vault server certificate. Only used
- if the Server URL is using HTTPS protocol. This parameter is ignored for
- plain HTTP protocol connection. If not set the system root certificates
- are used to validate the TLS connection.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>tls</code></br>
- <em>
- <a href="#external-secrets.io/v1.VaultClientTLS">
- VaultClientTLS
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The configuration used for client side related TLS communication, when the Vault server
- requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
- This parameter is ignored for plain HTTP protocol connection.
- It’s worth noting this configuration is different from the “TLS certificates auth method”,
- which is available under the <code>auth.cert</code> section.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>caProvider</code></br>
- <em>
- <a href="#external-secrets.io/v1.CAProvider">
- CAProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The provider for the CA bundle to use to validate Vault server certificate.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>readYourWrites</code></br>
- <em>
- bool
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>ReadYourWrites ensures isolated read-after-write semantics by
- providing discovered cluster replication states in each request.
- More information about eventual consistency in Vault can be found here
- <a href="https://www.vaultproject.io/docs/enterprise/consistency">https://www.vaultproject.io/docs/enterprise/consistency</a></p>
- </td>
- </tr>
- <tr>
- <td>
- <code>forwardInconsistent</code></br>
- <em>
- bool
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
- leader instead of simply retrying within a loop. This can increase performance if
- the option is enabled serverside.
- <a href="https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header">https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header</a></p>
- </td>
- </tr>
- <tr>
- <td>
- <code>headers</code></br>
- <em>
- map[string]string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Headers to be added in Vault request</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>checkAndSet</code></br>
- <em>
- <a href="#external-secrets.io/v1.VaultCheckAndSet">
- VaultCheckAndSet
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
- Only applies to Vault KV v2 stores. When enabled, write operations must include
- the current version of the secret to prevent unintentional overwrites.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.VaultUserPassAuth">VaultUserPassAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.VaultAuth">VaultAuth</a>)
- </p>
- <p>
- <p>VaultUserPassAuth authenticates with Vault using UserPass authentication method,
- with the username and password stored in a Kubernetes Secret resource.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>path</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Path where the UserPassword authentication backend is mounted
- in Vault, e.g: “userpass”</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>username</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Username is a username used to authenticate using the UserPass Vault
- authentication method</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>SecretRef to a key in a Secret resource containing password for the
- user used to authenticate with Vault using the UserPass authentication
- method</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.VolcengineAuth">VolcengineAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.VolcengineProvider">VolcengineProvider</a>)
- </p>
- <p>
- <p>VolcengineAuth defines the authentication method for the Volcengine provider.
- Only one of the fields should be set.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="#external-secrets.io/v1.VolcengineAuthSecretRef">
- VolcengineAuthSecretRef
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>SecretRef defines the static credentials to use for authentication.
- If not set, IRSA is used.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.VolcengineAuthSecretRef">VolcengineAuthSecretRef
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.VolcengineAuth">VolcengineAuth</a>)
- </p>
- <p>
- <p>VolcengineAuthSecretRef defines the secret reference for static credentials.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>accessKeyID</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>AccessKeyID is the reference to the secret containing the Access Key ID.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretAccessKey</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>SecretAccessKey is the reference to the secret containing the Secret Access Key.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>token</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Token is the reference to the secret containing the STS(Security Token Service) Token.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.VolcengineProvider">VolcengineProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>VolcengineProvider defines the configuration for the Volcengine provider.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>region</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Region specifies the Volcengine region to connect to.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.VolcengineAuth">
- VolcengineAuth
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Auth defines the authentication method to use.
- If not specified, the provider will try to use IRSA (IAM Role for Service Account).</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.WebhookCAProvider">WebhookCAProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.WebhookProvider">WebhookProvider</a>)
- </p>
- <p>
- <p>Defines a location to fetch the cert for the webhook provider from.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>type</code></br>
- <em>
- <a href="#external-secrets.io/v1.WebhookCAProviderType">
- WebhookCAProviderType
- </a>
- </em>
- </td>
- <td>
- <p>The type of provider to use such as “Secret”, or “ConfigMap”.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>name</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>The name of the object located at the provider type.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>key</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>The key where the CA certificate can be found in the Secret or ConfigMap.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>namespace</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The namespace the Provider type is in.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.WebhookCAProviderType">WebhookCAProviderType
- (<code>string</code> alias)</p></h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.WebhookCAProvider">WebhookCAProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Value</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody><tr><td><p>"ConfigMap"</p></td>
- <td></td>
- </tr><tr><td><p>"Secret"</p></td>
- <td></td>
- </tr></tbody>
- </table>
- <h3 id="external-secrets.io/v1.WebhookProvider">WebhookProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>WebHookProvider Configures an store to sync secrets from simple web apis.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>method</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Webhook Method</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>url</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Webhook url to call</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>headers</code></br>
- <em>
- map[string]string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Headers</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.AuthorizationProtocol">
- AuthorizationProtocol
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Auth specifies a authorization protocol. Only one protocol may be set.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>body</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Body</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>timeout</code></br>
- <em>
- <a href="https://pkg.go.dev/k8s.io/apimachinery/pkg/apis/meta/v1#Duration">
- Kubernetes meta/v1.Duration
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Timeout</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>result</code></br>
- <em>
- <a href="#external-secrets.io/v1.WebhookResult">
- WebhookResult
- </a>
- </em>
- </td>
- <td>
- <p>Result formatting</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secrets</code></br>
- <em>
- <a href="#external-secrets.io/v1.WebhookSecret">
- []WebhookSecret
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Secrets to fill in templates
- These secrets will be passed to the templating function as key value pairs under the given name</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>caBundle</code></br>
- <em>
- []byte
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>PEM encoded CA bundle used to validate webhook server certificate. Only used
- if the Server URL is using HTTPS protocol. This parameter is ignored for
- plain HTTP protocol connection. If not set the system root certificates
- are used to validate the TLS connection.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>caProvider</code></br>
- <em>
- <a href="#external-secrets.io/v1.WebhookCAProvider">
- WebhookCAProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The provider for the CA bundle to use to validate webhook server certificate.</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.WebhookResult">WebhookResult
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.WebhookProvider">WebhookProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>jsonPath</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Json path of return value</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.WebhookSecret">WebhookSecret
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.WebhookProvider">WebhookProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>name</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <p>Name of this secret in templates</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>secretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <p>Secret ref to fill in credentials</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.YandexAuth">YandexAuth
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.YandexCertificateManagerProvider">YandexCertificateManagerProvider</a>,
- <a href="#external-secrets.io/v1.YandexLockboxProvider">YandexLockboxProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>authorizedKeySecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The authorized key used for authentication</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.YandexCAProvider">YandexCAProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.YandexCertificateManagerProvider">YandexCertificateManagerProvider</a>,
- <a href="#external-secrets.io/v1.YandexLockboxProvider">YandexLockboxProvider</a>)
- </p>
- <p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>certSecretRef</code></br>
- <em>
- <a href="https://pkg.go.dev/github.com/external-secrets/external-secrets/apis/meta/v1#SecretKeySelector">
- External Secrets meta/v1.SecretKeySelector
- </a>
- </em>
- </td>
- <td>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.YandexCertificateManagerProvider">YandexCertificateManagerProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>YandexCertificateManagerProvider Configures a store to sync secrets using the Yandex Certificate Manager provider.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>apiEndpoint</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Yandex.Cloud API endpoint (e.g. ‘api.cloud.yandex.net:443’)</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.YandexAuth">
- YandexAuth
- </a>
- </em>
- </td>
- <td>
- <p>Auth defines the information necessary to authenticate against Yandex.Cloud</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>caProvider</code></br>
- <em>
- <a href="#external-secrets.io/v1.YandexCAProvider">
- YandexCAProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The provider for the CA bundle to use to validate Yandex.Cloud server certificate.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>fetching</code></br>
- <em>
- <a href="#external-secrets.io/v1.FetchingPolicy">
- FetchingPolicy
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>FetchingPolicy configures the provider to interpret the <code>data.secretKey.remoteRef.key</code> field in ExternalSecret as certificate ID or certificate name</p>
- </td>
- </tr>
- </tbody>
- </table>
- <h3 id="external-secrets.io/v1.YandexLockboxProvider">YandexLockboxProvider
- </h3>
- <p>
- (<em>Appears on:</em>
- <a href="#external-secrets.io/v1.SecretStoreProvider">SecretStoreProvider</a>)
- </p>
- <p>
- <p>YandexLockboxProvider Configures a store to sync secrets using the Yandex Lockbox provider.</p>
- </p>
- <table>
- <thead>
- <tr>
- <th>Field</th>
- <th>Description</th>
- </tr>
- </thead>
- <tbody>
- <tr>
- <td>
- <code>apiEndpoint</code></br>
- <em>
- string
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>Yandex.Cloud API endpoint (e.g. ‘api.cloud.yandex.net:443’)</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>auth</code></br>
- <em>
- <a href="#external-secrets.io/v1.YandexAuth">
- YandexAuth
- </a>
- </em>
- </td>
- <td>
- <p>Auth defines the information necessary to authenticate against Yandex.Cloud</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>caProvider</code></br>
- <em>
- <a href="#external-secrets.io/v1.YandexCAProvider">
- YandexCAProvider
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>The provider for the CA bundle to use to validate Yandex.Cloud server certificate.</p>
- </td>
- </tr>
- <tr>
- <td>
- <code>fetching</code></br>
- <em>
- <a href="#external-secrets.io/v1.FetchingPolicy">
- FetchingPolicy
- </a>
- </em>
- </td>
- <td>
- <em>(Optional)</em>
- <p>FetchingPolicy configures the provider to interpret the <code>data.secretKey.remoteRef.key</code> field in ExternalSecret as secret ID or secret name</p>
- </td>
- </tr>
- </tbody>
- </table>
- <hr/>
- <p><em>
- Generated with <code>gen-crd-api-reference-docs</code>.
- </em></p>
-
-
- </article>
- </div>
-
-
- <script>var target=document.getElementById(location.hash.slice(1));target&&target.name&&(target.checked=target.name.startsWith("__tabbed_"))</script>
- </div>
-
- </main>
-
- <img referrerpolicy="no-referrer-when-downgrade" src="https://static.scarf.sh/a.png?x-pxid=6658a9eb-067d-49f1-94f2-b8b00f21451e" alt=""/>
-
- <footer class="md-footer">
-
- <div class="md-footer-meta md-typeset">
- <div class="md-footer-meta__inner md-grid">
- <div class="md-copyright">
-
- <div class="md-copyright__highlight">
- © 2025 The external-secrets Authors.<br/>
- © 2025 The Linux Foundation. All rights reserved.<br/><br/>
- The Linux Foundation has registered trademarks and uses trademarks.<br/>
- For a list of trademarks of The Linux Foundation, please see our <a href="https://www.linuxfoundation.org/trademark-usage/">Trademark Usage page</a>.
- </div>
-
-
- Made with
- <a href="https://squidfunk.github.io/mkdocs-material/" target="_blank" rel="noopener">
- Material for MkDocs
- </a>
-
- </div>
-
- </div>
- </div>
- </footer>
-
- </div>
- <div class="md-dialog" data-md-component="dialog">
- <div class="md-dialog__inner md-typeset"></div>
- </div>
-
-
-
-
- <script id="__config" type="application/json">{"base": "../..", "features": ["navigation.tabs", "navigation.indexes", "navigation.expand"], "search": "../../assets/javascripts/workers/search.973d3a69.min.js", "tags": null, "translations": {"clipboard.copied": "Copied to clipboard", "clipboard.copy": "Copy to clipboard", "search.result.more.one": "1 more on this page", "search.result.more.other": "# more on this page", "search.result.none": "No matching documents", "search.result.one": "1 matching document", "search.result.other": "# matching documents", "search.result.placeholder": "Type to start searching", "search.result.term.missing": "Missing", "select.version": "Select version"}, "version": {"provider": "mike"}}</script>
-
-
- <script src="../../assets/javascripts/bundle.f55a23d4.min.js"></script>
-
-
- </body>
- </html>
|