bundle.yaml 1.9 MB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986498749884989499049914992499349944995499649974998499950005001500250035004500550065007500850095010501150125013501450155016501750185019502050215022502350245025502650275028502950305031503250335034503550365037503850395040504150425043504450455046504750485049505050515052505350545055505650575058505950605061506250635064506550665067506850695070507150725073507450755076507750785079508050815082508350845085508650875088508950905091509250935094509550965097509850995100510151025103510451055106510751085109511051115112511351145115511651175118511951205121512251235124512551265127512851295130513151325133513451355136513751385139514051415142514351445145514651475148514951505151515251535154515551565157515851595160516151625163516451655166516751685169517051715172517351745175517651775178517951805181518251835184518551865187518851895190519151925193519451955196519751985199520052015202520352045205520652075208520952105211521252135214521552165217521852195220522152225223522452255226522752285229523052315232523352345235523652375238523952405241524252435244524552465247524852495250525152525253525452555256525752585259526052615262526352645265526652675268526952705271527252735274527552765277527852795280528152825283528452855286528752885289529052915292529352945295529652975298529953005301530253035304530553065307530853095310531153125313531453155316531753185319532053215322532353245325532653275328532953305331533253335334533553365337533853395340534153425343534453455346534753485349535053515352535353545355535653575358535953605361536253635364536553665367536853695370537153725373537453755376537753785379538053815382538353845385538653875388538953905391539253935394539553965397539853995400540154025403540454055406540754085409541054115412541354145415541654175418541954205421542254235424542554265427542854295430543154325433543454355436543754385439544054415442544354445445544654475448544954505451545254535454545554565457545854595460546154625463546454655466546754685469547054715472547354745475547654775478547954805481548254835484548554865487548854895490549154925493549454955496549754985499550055015502550355045505550655075508550955105511551255135514551555165517551855195520552155225523552455255526552755285529553055315532553355345535553655375538553955405541554255435544554555465547554855495550555155525553555455555556555755585559556055615562556355645565556655675568556955705571557255735574557555765577557855795580558155825583558455855586558755885589559055915592559355945595559655975598559956005601560256035604560556065607560856095610561156125613561456155616561756185619562056215622562356245625562656275628562956305631563256335634563556365637563856395640564156425643564456455646564756485649565056515652565356545655565656575658565956605661566256635664566556665667566856695670567156725673567456755676567756785679568056815682568356845685568656875688568956905691569256935694569556965697569856995700570157025703570457055706570757085709571057115712571357145715571657175718571957205721572257235724572557265727572857295730573157325733573457355736573757385739574057415742574357445745574657475748574957505751575257535754575557565757575857595760576157625763576457655766576757685769577057715772577357745775577657775778577957805781578257835784578557865787578857895790579157925793579457955796579757985799580058015802580358045805580658075808580958105811581258135814581558165817581858195820582158225823582458255826582758285829583058315832583358345835583658375838583958405841584258435844584558465847584858495850585158525853585458555856585758585859586058615862586358645865586658675868586958705871587258735874587558765877587858795880588158825883588458855886588758885889589058915892589358945895589658975898589959005901590259035904590559065907590859095910591159125913591459155916591759185919592059215922592359245925592659275928592959305931593259335934593559365937593859395940594159425943594459455946594759485949595059515952595359545955595659575958595959605961596259635964596559665967596859695970597159725973597459755976597759785979598059815982598359845985598659875988598959905991599259935994599559965997599859996000600160026003600460056006600760086009601060116012601360146015601660176018601960206021602260236024602560266027602860296030603160326033603460356036603760386039604060416042604360446045604660476048604960506051605260536054605560566057605860596060606160626063606460656066606760686069607060716072607360746075607660776078607960806081608260836084608560866087608860896090609160926093609460956096609760986099610061016102610361046105610661076108610961106111611261136114611561166117611861196120612161226123612461256126612761286129613061316132613361346135613661376138613961406141614261436144614561466147614861496150615161526153615461556156615761586159616061616162616361646165616661676168616961706171617261736174617561766177617861796180618161826183618461856186618761886189619061916192619361946195619661976198619962006201620262036204620562066207620862096210621162126213621462156216621762186219622062216222622362246225622662276228622962306231623262336234623562366237623862396240624162426243624462456246624762486249625062516252625362546255625662576258625962606261626262636264626562666267626862696270627162726273627462756276627762786279628062816282628362846285628662876288628962906291629262936294629562966297629862996300630163026303630463056306630763086309631063116312631363146315631663176318631963206321632263236324632563266327632863296330633163326333633463356336633763386339634063416342634363446345634663476348634963506351635263536354635563566357635863596360636163626363636463656366636763686369637063716372637363746375637663776378637963806381638263836384638563866387638863896390639163926393639463956396639763986399640064016402640364046405640664076408640964106411641264136414641564166417641864196420642164226423642464256426642764286429643064316432643364346435643664376438643964406441644264436444644564466447644864496450645164526453645464556456645764586459646064616462646364646465646664676468646964706471647264736474647564766477647864796480648164826483648464856486648764886489649064916492649364946495649664976498649965006501650265036504650565066507650865096510651165126513651465156516651765186519652065216522652365246525652665276528652965306531653265336534653565366537653865396540654165426543654465456546654765486549655065516552655365546555655665576558655965606561656265636564656565666567656865696570657165726573657465756576657765786579658065816582658365846585658665876588658965906591659265936594659565966597659865996600660166026603660466056606660766086609661066116612661366146615661666176618661966206621662266236624662566266627662866296630663166326633663466356636663766386639664066416642664366446645664666476648664966506651665266536654665566566657665866596660666166626663666466656666666766686669667066716672667366746675667666776678667966806681668266836684668566866687668866896690669166926693669466956696669766986699670067016702670367046705670667076708670967106711671267136714671567166717671867196720672167226723672467256726672767286729673067316732673367346735673667376738673967406741674267436744674567466747674867496750675167526753675467556756675767586759676067616762676367646765676667676768676967706771677267736774677567766777677867796780678167826783678467856786678767886789679067916792679367946795679667976798679968006801680268036804680568066807680868096810681168126813681468156816681768186819682068216822682368246825682668276828682968306831683268336834683568366837683868396840684168426843684468456846684768486849685068516852685368546855685668576858685968606861686268636864686568666867686868696870687168726873687468756876687768786879688068816882688368846885688668876888688968906891689268936894689568966897689868996900690169026903690469056906690769086909691069116912691369146915691669176918691969206921692269236924692569266927692869296930693169326933693469356936693769386939694069416942694369446945694669476948694969506951695269536954695569566957695869596960696169626963696469656966696769686969697069716972697369746975697669776978697969806981698269836984698569866987698869896990699169926993699469956996699769986999700070017002700370047005700670077008700970107011701270137014701570167017701870197020702170227023702470257026702770287029703070317032703370347035703670377038703970407041704270437044704570467047704870497050705170527053705470557056705770587059706070617062706370647065706670677068706970707071707270737074707570767077707870797080708170827083708470857086708770887089709070917092709370947095709670977098709971007101710271037104710571067107710871097110711171127113711471157116711771187119712071217122712371247125712671277128712971307131713271337134713571367137713871397140714171427143714471457146714771487149715071517152715371547155715671577158715971607161716271637164716571667167716871697170717171727173717471757176717771787179718071817182718371847185718671877188718971907191719271937194719571967197719871997200720172027203720472057206720772087209721072117212721372147215721672177218721972207221722272237224722572267227722872297230723172327233723472357236723772387239724072417242724372447245724672477248724972507251725272537254725572567257725872597260726172627263726472657266726772687269727072717272727372747275727672777278727972807281728272837284728572867287728872897290729172927293729472957296729772987299730073017302730373047305730673077308730973107311731273137314731573167317731873197320732173227323732473257326732773287329733073317332733373347335733673377338733973407341734273437344734573467347734873497350735173527353735473557356735773587359736073617362736373647365736673677368736973707371737273737374737573767377737873797380738173827383738473857386738773887389739073917392739373947395739673977398739974007401740274037404740574067407740874097410741174127413741474157416741774187419742074217422742374247425742674277428742974307431743274337434743574367437743874397440744174427443744474457446744774487449745074517452745374547455745674577458745974607461746274637464746574667467746874697470747174727473747474757476747774787479748074817482748374847485748674877488748974907491749274937494749574967497749874997500750175027503750475057506750775087509751075117512751375147515751675177518751975207521752275237524752575267527752875297530753175327533753475357536753775387539754075417542754375447545754675477548754975507551755275537554755575567557755875597560756175627563756475657566756775687569757075717572757375747575757675777578757975807581758275837584758575867587758875897590759175927593759475957596759775987599760076017602760376047605760676077608760976107611761276137614761576167617761876197620762176227623762476257626762776287629763076317632763376347635763676377638763976407641764276437644764576467647764876497650765176527653765476557656765776587659766076617662766376647665766676677668766976707671767276737674767576767677767876797680768176827683768476857686768776887689769076917692769376947695769676977698769977007701770277037704770577067707770877097710771177127713771477157716771777187719772077217722772377247725772677277728772977307731773277337734773577367737773877397740774177427743774477457746774777487749775077517752775377547755775677577758775977607761776277637764776577667767776877697770777177727773777477757776777777787779778077817782778377847785778677877788778977907791779277937794779577967797779877997800780178027803780478057806780778087809781078117812781378147815781678177818781978207821782278237824782578267827782878297830783178327833783478357836783778387839784078417842784378447845784678477848784978507851785278537854785578567857785878597860786178627863786478657866786778687869787078717872787378747875787678777878787978807881788278837884788578867887788878897890789178927893789478957896789778987899790079017902790379047905790679077908790979107911791279137914791579167917791879197920792179227923792479257926792779287929793079317932793379347935793679377938793979407941794279437944794579467947794879497950795179527953795479557956795779587959796079617962796379647965796679677968796979707971797279737974797579767977797879797980798179827983798479857986798779887989799079917992799379947995799679977998799980008001800280038004800580068007800880098010801180128013801480158016801780188019802080218022802380248025802680278028802980308031803280338034803580368037803880398040804180428043804480458046804780488049805080518052805380548055805680578058805980608061806280638064806580668067806880698070807180728073807480758076807780788079808080818082808380848085808680878088808980908091809280938094809580968097809880998100810181028103810481058106810781088109811081118112811381148115811681178118811981208121812281238124812581268127812881298130813181328133813481358136813781388139814081418142814381448145814681478148814981508151815281538154815581568157815881598160816181628163816481658166816781688169817081718172817381748175817681778178817981808181818281838184818581868187818881898190819181928193819481958196819781988199820082018202820382048205820682078208820982108211821282138214821582168217821882198220822182228223822482258226822782288229823082318232823382348235823682378238823982408241824282438244824582468247824882498250825182528253825482558256825782588259826082618262826382648265826682678268826982708271827282738274827582768277827882798280828182828283828482858286828782888289829082918292829382948295829682978298829983008301830283038304830583068307830883098310831183128313831483158316831783188319832083218322832383248325832683278328832983308331833283338334833583368337833883398340834183428343834483458346834783488349835083518352835383548355835683578358835983608361836283638364836583668367836883698370837183728373837483758376837783788379838083818382838383848385838683878388838983908391839283938394839583968397839883998400840184028403840484058406840784088409841084118412841384148415841684178418841984208421842284238424842584268427842884298430843184328433843484358436843784388439844084418442844384448445844684478448844984508451845284538454845584568457845884598460846184628463846484658466846784688469847084718472847384748475847684778478847984808481848284838484848584868487848884898490849184928493849484958496849784988499850085018502850385048505850685078508850985108511851285138514851585168517851885198520852185228523852485258526852785288529853085318532853385348535853685378538853985408541854285438544854585468547854885498550855185528553855485558556855785588559856085618562856385648565856685678568856985708571857285738574857585768577857885798580858185828583858485858586858785888589859085918592859385948595859685978598859986008601860286038604860586068607860886098610861186128613861486158616861786188619862086218622862386248625862686278628862986308631863286338634863586368637863886398640864186428643864486458646864786488649865086518652865386548655865686578658865986608661866286638664866586668667866886698670867186728673867486758676867786788679868086818682868386848685868686878688868986908691869286938694869586968697869886998700870187028703870487058706870787088709871087118712871387148715871687178718871987208721872287238724872587268727872887298730873187328733873487358736873787388739874087418742874387448745874687478748874987508751875287538754875587568757875887598760876187628763876487658766876787688769877087718772877387748775877687778778877987808781878287838784878587868787878887898790879187928793879487958796879787988799880088018802880388048805880688078808880988108811881288138814881588168817881888198820882188228823882488258826882788288829883088318832883388348835883688378838883988408841884288438844884588468847884888498850885188528853885488558856885788588859886088618862886388648865886688678868886988708871887288738874887588768877887888798880888188828883888488858886888788888889889088918892889388948895889688978898889989008901890289038904890589068907890889098910891189128913891489158916891789188919892089218922892389248925892689278928892989308931893289338934893589368937893889398940894189428943894489458946894789488949895089518952895389548955895689578958895989608961896289638964896589668967896889698970897189728973897489758976897789788979898089818982898389848985898689878988898989908991899289938994899589968997899889999000900190029003900490059006900790089009901090119012901390149015901690179018901990209021902290239024902590269027902890299030903190329033903490359036903790389039904090419042904390449045904690479048904990509051905290539054905590569057905890599060906190629063906490659066906790689069907090719072907390749075907690779078907990809081908290839084908590869087908890899090909190929093909490959096909790989099910091019102910391049105910691079108910991109111911291139114911591169117911891199120912191229123912491259126912791289129913091319132913391349135913691379138913991409141914291439144914591469147914891499150915191529153915491559156915791589159916091619162916391649165916691679168916991709171917291739174917591769177917891799180918191829183918491859186918791889189919091919192919391949195919691979198919992009201920292039204920592069207920892099210921192129213921492159216921792189219922092219222922392249225922692279228922992309231923292339234923592369237923892399240924192429243924492459246924792489249925092519252925392549255925692579258925992609261926292639264926592669267926892699270927192729273927492759276927792789279928092819282928392849285928692879288928992909291929292939294929592969297929892999300930193029303930493059306930793089309931093119312931393149315931693179318931993209321932293239324932593269327932893299330933193329333933493359336933793389339934093419342934393449345934693479348934993509351935293539354935593569357935893599360936193629363936493659366936793689369937093719372937393749375937693779378937993809381938293839384938593869387938893899390939193929393939493959396939793989399940094019402940394049405940694079408940994109411941294139414941594169417941894199420942194229423942494259426942794289429943094319432943394349435943694379438943994409441944294439444944594469447944894499450945194529453945494559456945794589459946094619462946394649465946694679468946994709471947294739474947594769477947894799480948194829483948494859486948794889489949094919492949394949495949694979498949995009501950295039504950595069507950895099510951195129513951495159516951795189519952095219522952395249525952695279528952995309531953295339534953595369537953895399540954195429543954495459546954795489549955095519552955395549555955695579558955995609561956295639564956595669567956895699570957195729573957495759576957795789579958095819582958395849585958695879588958995909591959295939594959595969597959895999600960196029603960496059606960796089609961096119612961396149615961696179618961996209621962296239624962596269627962896299630963196329633963496359636963796389639964096419642964396449645964696479648964996509651965296539654965596569657965896599660966196629663966496659666966796689669967096719672967396749675967696779678967996809681968296839684968596869687968896899690969196929693969496959696969796989699970097019702970397049705970697079708970997109711971297139714971597169717971897199720972197229723972497259726972797289729973097319732973397349735973697379738973997409741974297439744974597469747974897499750975197529753975497559756975797589759976097619762976397649765976697679768976997709771977297739774977597769777977897799780978197829783978497859786978797889789979097919792979397949795979697979798979998009801980298039804980598069807980898099810981198129813981498159816981798189819982098219822982398249825982698279828982998309831983298339834983598369837983898399840984198429843984498459846984798489849985098519852985398549855985698579858985998609861986298639864986598669867986898699870987198729873987498759876987798789879988098819882988398849885988698879888988998909891989298939894989598969897989898999900990199029903990499059906990799089909991099119912991399149915991699179918991999209921992299239924992599269927992899299930993199329933993499359936993799389939994099419942994399449945994699479948994999509951995299539954995599569957995899599960996199629963996499659966996799689969997099719972997399749975997699779978997999809981998299839984998599869987998899899990999199929993999499959996999799989999100001000110002100031000410005100061000710008100091001010011100121001310014100151001610017100181001910020100211002210023100241002510026100271002810029100301003110032100331003410035100361003710038100391004010041100421004310044100451004610047100481004910050100511005210053100541005510056100571005810059100601006110062100631006410065100661006710068100691007010071100721007310074100751007610077100781007910080100811008210083100841008510086100871008810089100901009110092100931009410095100961009710098100991010010101101021010310104101051010610107101081010910110101111011210113101141011510116101171011810119101201012110122101231012410125101261012710128101291013010131101321013310134101351013610137101381013910140101411014210143101441014510146101471014810149101501015110152101531015410155101561015710158101591016010161101621016310164101651016610167101681016910170101711017210173101741017510176101771017810179101801018110182101831018410185101861018710188101891019010191101921019310194101951019610197101981019910200102011020210203102041020510206102071020810209102101021110212102131021410215102161021710218102191022010221102221022310224102251022610227102281022910230102311023210233102341023510236102371023810239102401024110242102431024410245102461024710248102491025010251102521025310254102551025610257102581025910260102611026210263102641026510266102671026810269102701027110272102731027410275102761027710278102791028010281102821028310284102851028610287102881028910290102911029210293102941029510296102971029810299103001030110302103031030410305103061030710308103091031010311103121031310314103151031610317103181031910320103211032210323103241032510326103271032810329103301033110332103331033410335103361033710338103391034010341103421034310344103451034610347103481034910350103511035210353103541035510356103571035810359103601036110362103631036410365103661036710368103691037010371103721037310374103751037610377103781037910380103811038210383103841038510386103871038810389103901039110392103931039410395103961039710398103991040010401104021040310404104051040610407104081040910410104111041210413104141041510416104171041810419104201042110422104231042410425104261042710428104291043010431104321043310434104351043610437104381043910440104411044210443104441044510446104471044810449104501045110452104531045410455104561045710458104591046010461104621046310464104651046610467104681046910470104711047210473104741047510476104771047810479104801048110482104831048410485104861048710488104891049010491104921049310494104951049610497104981049910500105011050210503105041050510506105071050810509105101051110512105131051410515105161051710518105191052010521105221052310524105251052610527105281052910530105311053210533105341053510536105371053810539105401054110542105431054410545105461054710548105491055010551105521055310554105551055610557105581055910560105611056210563105641056510566105671056810569105701057110572105731057410575105761057710578105791058010581105821058310584105851058610587105881058910590105911059210593105941059510596105971059810599106001060110602106031060410605106061060710608106091061010611106121061310614106151061610617106181061910620106211062210623106241062510626106271062810629106301063110632106331063410635106361063710638106391064010641106421064310644106451064610647106481064910650106511065210653106541065510656106571065810659106601066110662106631066410665106661066710668106691067010671106721067310674106751067610677106781067910680106811068210683106841068510686106871068810689106901069110692106931069410695106961069710698106991070010701107021070310704107051070610707107081070910710107111071210713107141071510716107171071810719107201072110722107231072410725107261072710728107291073010731107321073310734107351073610737107381073910740107411074210743107441074510746107471074810749107501075110752107531075410755107561075710758107591076010761107621076310764107651076610767107681076910770107711077210773107741077510776107771077810779107801078110782107831078410785107861078710788107891079010791107921079310794107951079610797107981079910800108011080210803108041080510806108071080810809108101081110812108131081410815108161081710818108191082010821108221082310824108251082610827108281082910830108311083210833108341083510836108371083810839108401084110842108431084410845108461084710848108491085010851108521085310854108551085610857108581085910860108611086210863108641086510866108671086810869108701087110872108731087410875108761087710878108791088010881108821088310884108851088610887108881088910890108911089210893108941089510896108971089810899109001090110902109031090410905109061090710908109091091010911109121091310914109151091610917109181091910920109211092210923109241092510926109271092810929109301093110932109331093410935109361093710938109391094010941109421094310944109451094610947109481094910950109511095210953109541095510956109571095810959109601096110962109631096410965109661096710968109691097010971109721097310974109751097610977109781097910980109811098210983109841098510986109871098810989109901099110992109931099410995109961099710998109991100011001110021100311004110051100611007110081100911010110111101211013110141101511016110171101811019110201102111022110231102411025110261102711028110291103011031110321103311034110351103611037110381103911040110411104211043110441104511046110471104811049110501105111052110531105411055110561105711058110591106011061110621106311064110651106611067110681106911070110711107211073110741107511076110771107811079110801108111082110831108411085110861108711088110891109011091110921109311094110951109611097110981109911100111011110211103111041110511106111071110811109111101111111112111131111411115111161111711118111191112011121111221112311124111251112611127111281112911130111311113211133111341113511136111371113811139111401114111142111431114411145111461114711148111491115011151111521115311154111551115611157111581115911160111611116211163111641116511166111671116811169111701117111172111731117411175111761117711178111791118011181111821118311184111851118611187111881118911190111911119211193111941119511196111971119811199112001120111202112031120411205112061120711208112091121011211112121121311214112151121611217112181121911220112211122211223112241122511226112271122811229112301123111232112331123411235112361123711238112391124011241112421124311244112451124611247112481124911250112511125211253112541125511256112571125811259112601126111262112631126411265112661126711268112691127011271112721127311274112751127611277112781127911280112811128211283112841128511286112871128811289112901129111292112931129411295112961129711298112991130011301113021130311304113051130611307113081130911310113111131211313113141131511316113171131811319113201132111322113231132411325113261132711328113291133011331113321133311334113351133611337113381133911340113411134211343113441134511346113471134811349113501135111352113531135411355113561135711358113591136011361113621136311364113651136611367113681136911370113711137211373113741137511376113771137811379113801138111382113831138411385113861138711388113891139011391113921139311394113951139611397113981139911400114011140211403114041140511406114071140811409114101141111412114131141411415114161141711418114191142011421114221142311424114251142611427114281142911430114311143211433114341143511436114371143811439114401144111442114431144411445114461144711448114491145011451114521145311454114551145611457114581145911460114611146211463114641146511466114671146811469114701147111472114731147411475114761147711478114791148011481114821148311484114851148611487114881148911490114911149211493114941149511496114971149811499115001150111502115031150411505115061150711508115091151011511115121151311514115151151611517115181151911520115211152211523115241152511526115271152811529115301153111532115331153411535115361153711538115391154011541115421154311544115451154611547115481154911550115511155211553115541155511556115571155811559115601156111562115631156411565115661156711568115691157011571115721157311574115751157611577115781157911580115811158211583115841158511586115871158811589115901159111592115931159411595115961159711598115991160011601116021160311604116051160611607116081160911610116111161211613116141161511616116171161811619116201162111622116231162411625116261162711628116291163011631116321163311634116351163611637116381163911640116411164211643116441164511646116471164811649116501165111652116531165411655116561165711658116591166011661116621166311664116651166611667116681166911670116711167211673116741167511676116771167811679116801168111682116831168411685116861168711688116891169011691116921169311694116951169611697116981169911700117011170211703117041170511706117071170811709117101171111712117131171411715117161171711718117191172011721117221172311724117251172611727117281172911730117311173211733117341173511736117371173811739117401174111742117431174411745117461174711748117491175011751117521175311754117551175611757117581175911760117611176211763117641176511766117671176811769117701177111772117731177411775117761177711778117791178011781117821178311784117851178611787117881178911790117911179211793117941179511796117971179811799118001180111802118031180411805118061180711808118091181011811118121181311814118151181611817118181181911820118211182211823118241182511826118271182811829118301183111832118331183411835118361183711838118391184011841118421184311844118451184611847118481184911850118511185211853118541185511856118571185811859118601186111862118631186411865118661186711868118691187011871118721187311874118751187611877118781187911880118811188211883118841188511886118871188811889118901189111892118931189411895118961189711898118991190011901119021190311904119051190611907119081190911910119111191211913119141191511916119171191811919119201192111922119231192411925119261192711928119291193011931119321193311934119351193611937119381193911940119411194211943119441194511946119471194811949119501195111952119531195411955119561195711958119591196011961119621196311964119651196611967119681196911970119711197211973119741197511976119771197811979119801198111982119831198411985119861198711988119891199011991119921199311994119951199611997119981199912000120011200212003120041200512006120071200812009120101201112012120131201412015120161201712018120191202012021120221202312024120251202612027120281202912030120311203212033120341203512036120371203812039120401204112042120431204412045120461204712048120491205012051120521205312054120551205612057120581205912060120611206212063120641206512066120671206812069120701207112072120731207412075120761207712078120791208012081120821208312084120851208612087120881208912090120911209212093120941209512096120971209812099121001210112102121031210412105121061210712108121091211012111121121211312114121151211612117121181211912120121211212212123121241212512126121271212812129121301213112132121331213412135121361213712138121391214012141121421214312144121451214612147121481214912150121511215212153121541215512156121571215812159121601216112162121631216412165121661216712168121691217012171121721217312174121751217612177121781217912180121811218212183121841218512186121871218812189121901219112192121931219412195121961219712198121991220012201122021220312204122051220612207122081220912210122111221212213122141221512216122171221812219122201222112222122231222412225122261222712228122291223012231122321223312234122351223612237122381223912240122411224212243122441224512246122471224812249122501225112252122531225412255122561225712258122591226012261122621226312264122651226612267122681226912270122711227212273122741227512276122771227812279122801228112282122831228412285122861228712288122891229012291122921229312294122951229612297122981229912300123011230212303123041230512306123071230812309123101231112312123131231412315123161231712318123191232012321123221232312324123251232612327123281232912330123311233212333123341233512336123371233812339123401234112342123431234412345123461234712348123491235012351123521235312354123551235612357123581235912360123611236212363123641236512366123671236812369123701237112372123731237412375123761237712378123791238012381123821238312384123851238612387123881238912390123911239212393123941239512396123971239812399124001240112402124031240412405124061240712408124091241012411124121241312414124151241612417124181241912420124211242212423124241242512426124271242812429124301243112432124331243412435124361243712438124391244012441124421244312444124451244612447124481244912450124511245212453124541245512456124571245812459124601246112462124631246412465124661246712468124691247012471124721247312474124751247612477124781247912480124811248212483124841248512486124871248812489124901249112492124931249412495124961249712498124991250012501125021250312504125051250612507125081250912510125111251212513125141251512516125171251812519125201252112522125231252412525125261252712528125291253012531125321253312534125351253612537125381253912540125411254212543125441254512546125471254812549125501255112552125531255412555125561255712558125591256012561125621256312564125651256612567125681256912570125711257212573125741257512576125771257812579125801258112582125831258412585125861258712588125891259012591125921259312594125951259612597125981259912600126011260212603126041260512606126071260812609126101261112612126131261412615126161261712618126191262012621126221262312624126251262612627126281262912630126311263212633126341263512636126371263812639126401264112642126431264412645126461264712648126491265012651126521265312654126551265612657126581265912660126611266212663126641266512666126671266812669126701267112672126731267412675126761267712678126791268012681126821268312684126851268612687126881268912690126911269212693126941269512696126971269812699127001270112702127031270412705127061270712708127091271012711127121271312714127151271612717127181271912720127211272212723127241272512726127271272812729127301273112732127331273412735127361273712738127391274012741127421274312744127451274612747127481274912750127511275212753127541275512756127571275812759127601276112762127631276412765127661276712768127691277012771127721277312774127751277612777127781277912780127811278212783127841278512786127871278812789127901279112792127931279412795127961279712798127991280012801128021280312804128051280612807128081280912810128111281212813128141281512816128171281812819128201282112822128231282412825128261282712828128291283012831128321283312834128351283612837128381283912840128411284212843128441284512846128471284812849128501285112852128531285412855128561285712858128591286012861128621286312864128651286612867128681286912870128711287212873128741287512876128771287812879128801288112882128831288412885128861288712888128891289012891128921289312894128951289612897128981289912900129011290212903129041290512906129071290812909129101291112912129131291412915129161291712918129191292012921129221292312924129251292612927129281292912930129311293212933129341293512936129371293812939129401294112942129431294412945129461294712948129491295012951129521295312954129551295612957129581295912960129611296212963129641296512966129671296812969129701297112972129731297412975129761297712978129791298012981129821298312984129851298612987129881298912990129911299212993129941299512996129971299812999130001300113002130031300413005130061300713008130091301013011130121301313014130151301613017130181301913020130211302213023130241302513026130271302813029130301303113032130331303413035130361303713038130391304013041130421304313044130451304613047130481304913050130511305213053130541305513056130571305813059130601306113062130631306413065130661306713068130691307013071130721307313074130751307613077130781307913080130811308213083130841308513086130871308813089130901309113092130931309413095130961309713098130991310013101131021310313104131051310613107131081310913110131111311213113131141311513116131171311813119131201312113122131231312413125131261312713128131291313013131131321313313134131351313613137131381313913140131411314213143131441314513146131471314813149131501315113152131531315413155131561315713158131591316013161131621316313164131651316613167131681316913170131711317213173131741317513176131771317813179131801318113182131831318413185131861318713188131891319013191131921319313194131951319613197131981319913200132011320213203132041320513206132071320813209132101321113212132131321413215132161321713218132191322013221132221322313224132251322613227132281322913230132311323213233132341323513236132371323813239132401324113242132431324413245132461324713248132491325013251132521325313254132551325613257132581325913260132611326213263132641326513266132671326813269132701327113272132731327413275132761327713278132791328013281132821328313284132851328613287132881328913290132911329213293132941329513296132971329813299133001330113302133031330413305133061330713308133091331013311133121331313314133151331613317133181331913320133211332213323133241332513326133271332813329133301333113332133331333413335133361333713338133391334013341133421334313344133451334613347133481334913350133511335213353133541335513356133571335813359133601336113362133631336413365133661336713368133691337013371133721337313374133751337613377133781337913380133811338213383133841338513386133871338813389133901339113392133931339413395133961339713398133991340013401134021340313404134051340613407134081340913410134111341213413134141341513416134171341813419134201342113422134231342413425134261342713428134291343013431134321343313434134351343613437134381343913440134411344213443134441344513446134471344813449134501345113452134531345413455134561345713458134591346013461134621346313464134651346613467134681346913470134711347213473134741347513476134771347813479134801348113482134831348413485134861348713488134891349013491134921349313494134951349613497134981349913500135011350213503135041350513506135071350813509135101351113512135131351413515135161351713518135191352013521135221352313524135251352613527135281352913530135311353213533135341353513536135371353813539135401354113542135431354413545135461354713548135491355013551135521355313554135551355613557135581355913560135611356213563135641356513566135671356813569135701357113572135731357413575135761357713578135791358013581135821358313584135851358613587135881358913590135911359213593135941359513596135971359813599136001360113602136031360413605136061360713608136091361013611136121361313614136151361613617136181361913620136211362213623136241362513626136271362813629136301363113632136331363413635136361363713638136391364013641136421364313644136451364613647136481364913650136511365213653136541365513656136571365813659136601366113662136631366413665136661366713668136691367013671136721367313674136751367613677136781367913680136811368213683136841368513686136871368813689136901369113692136931369413695136961369713698136991370013701137021370313704137051370613707137081370913710137111371213713137141371513716137171371813719137201372113722137231372413725137261372713728137291373013731137321373313734137351373613737137381373913740137411374213743137441374513746137471374813749137501375113752137531375413755137561375713758137591376013761137621376313764137651376613767137681376913770137711377213773137741377513776137771377813779137801378113782137831378413785137861378713788137891379013791137921379313794137951379613797137981379913800138011380213803138041380513806138071380813809138101381113812138131381413815138161381713818138191382013821138221382313824138251382613827138281382913830138311383213833138341383513836138371383813839138401384113842138431384413845138461384713848138491385013851138521385313854138551385613857138581385913860138611386213863138641386513866138671386813869138701387113872138731387413875138761387713878138791388013881138821388313884138851388613887138881388913890138911389213893138941389513896138971389813899139001390113902139031390413905139061390713908139091391013911139121391313914139151391613917139181391913920139211392213923139241392513926139271392813929139301393113932139331393413935139361393713938139391394013941139421394313944139451394613947139481394913950139511395213953139541395513956139571395813959139601396113962139631396413965139661396713968139691397013971139721397313974139751397613977139781397913980139811398213983139841398513986139871398813989139901399113992139931399413995139961399713998139991400014001140021400314004140051400614007140081400914010140111401214013140141401514016140171401814019140201402114022140231402414025140261402714028140291403014031140321403314034140351403614037140381403914040140411404214043140441404514046140471404814049140501405114052140531405414055140561405714058140591406014061140621406314064140651406614067140681406914070140711407214073140741407514076140771407814079140801408114082140831408414085140861408714088140891409014091140921409314094140951409614097140981409914100141011410214103141041410514106141071410814109141101411114112141131411414115141161411714118141191412014121141221412314124141251412614127141281412914130141311413214133141341413514136141371413814139141401414114142141431414414145141461414714148141491415014151141521415314154141551415614157141581415914160141611416214163141641416514166141671416814169141701417114172141731417414175141761417714178141791418014181141821418314184141851418614187141881418914190141911419214193141941419514196141971419814199142001420114202142031420414205142061420714208142091421014211142121421314214142151421614217142181421914220142211422214223142241422514226142271422814229142301423114232142331423414235142361423714238142391424014241142421424314244142451424614247142481424914250142511425214253142541425514256142571425814259142601426114262142631426414265142661426714268142691427014271142721427314274142751427614277142781427914280142811428214283142841428514286142871428814289142901429114292142931429414295142961429714298142991430014301143021430314304143051430614307143081430914310143111431214313143141431514316143171431814319143201432114322143231432414325143261432714328143291433014331143321433314334143351433614337143381433914340143411434214343143441434514346143471434814349143501435114352143531435414355143561435714358143591436014361143621436314364143651436614367143681436914370143711437214373143741437514376143771437814379143801438114382143831438414385143861438714388143891439014391143921439314394143951439614397143981439914400144011440214403144041440514406144071440814409144101441114412144131441414415144161441714418144191442014421144221442314424144251442614427144281442914430144311443214433144341443514436144371443814439144401444114442144431444414445144461444714448144491445014451144521445314454144551445614457144581445914460144611446214463144641446514466144671446814469144701447114472144731447414475144761447714478144791448014481144821448314484144851448614487144881448914490144911449214493144941449514496144971449814499145001450114502145031450414505145061450714508145091451014511145121451314514145151451614517145181451914520145211452214523145241452514526145271452814529145301453114532145331453414535145361453714538145391454014541145421454314544145451454614547145481454914550145511455214553145541455514556145571455814559145601456114562145631456414565145661456714568145691457014571145721457314574145751457614577145781457914580145811458214583145841458514586145871458814589145901459114592145931459414595145961459714598145991460014601146021460314604146051460614607146081460914610146111461214613146141461514616146171461814619146201462114622146231462414625146261462714628146291463014631146321463314634146351463614637146381463914640146411464214643146441464514646146471464814649146501465114652146531465414655146561465714658146591466014661146621466314664146651466614667146681466914670146711467214673146741467514676146771467814679146801468114682146831468414685146861468714688146891469014691146921469314694146951469614697146981469914700147011470214703147041470514706147071470814709147101471114712147131471414715147161471714718147191472014721147221472314724147251472614727147281472914730147311473214733147341473514736147371473814739147401474114742147431474414745147461474714748147491475014751147521475314754147551475614757147581475914760147611476214763147641476514766147671476814769147701477114772147731477414775147761477714778147791478014781147821478314784147851478614787147881478914790147911479214793147941479514796147971479814799148001480114802148031480414805148061480714808148091481014811148121481314814148151481614817148181481914820148211482214823148241482514826148271482814829148301483114832148331483414835148361483714838148391484014841148421484314844148451484614847148481484914850148511485214853148541485514856148571485814859148601486114862148631486414865148661486714868148691487014871148721487314874148751487614877148781487914880148811488214883148841488514886148871488814889148901489114892148931489414895148961489714898148991490014901149021490314904149051490614907149081490914910149111491214913149141491514916149171491814919149201492114922149231492414925149261492714928149291493014931149321493314934149351493614937149381493914940149411494214943149441494514946149471494814949149501495114952149531495414955149561495714958149591496014961149621496314964149651496614967149681496914970149711497214973149741497514976149771497814979149801498114982149831498414985149861498714988149891499014991149921499314994149951499614997149981499915000150011500215003150041500515006150071500815009150101501115012150131501415015150161501715018150191502015021150221502315024150251502615027150281502915030150311503215033150341503515036150371503815039150401504115042150431504415045150461504715048150491505015051150521505315054150551505615057150581505915060150611506215063150641506515066150671506815069150701507115072150731507415075150761507715078150791508015081150821508315084150851508615087150881508915090150911509215093150941509515096150971509815099151001510115102151031510415105151061510715108151091511015111151121511315114151151511615117151181511915120151211512215123151241512515126151271512815129151301513115132151331513415135151361513715138151391514015141151421514315144151451514615147151481514915150151511515215153151541515515156151571515815159151601516115162151631516415165151661516715168151691517015171151721517315174151751517615177151781517915180151811518215183151841518515186151871518815189151901519115192151931519415195151961519715198151991520015201152021520315204152051520615207152081520915210152111521215213152141521515216152171521815219152201522115222152231522415225152261522715228152291523015231152321523315234152351523615237152381523915240152411524215243152441524515246152471524815249152501525115252152531525415255152561525715258152591526015261152621526315264152651526615267152681526915270152711527215273152741527515276152771527815279152801528115282152831528415285152861528715288152891529015291152921529315294152951529615297152981529915300153011530215303153041530515306153071530815309153101531115312153131531415315153161531715318153191532015321153221532315324153251532615327153281532915330153311533215333153341533515336153371533815339153401534115342153431534415345153461534715348153491535015351153521535315354153551535615357153581535915360153611536215363153641536515366153671536815369153701537115372153731537415375153761537715378153791538015381153821538315384153851538615387153881538915390153911539215393153941539515396153971539815399154001540115402154031540415405154061540715408154091541015411154121541315414154151541615417154181541915420154211542215423154241542515426154271542815429154301543115432154331543415435154361543715438154391544015441154421544315444154451544615447154481544915450154511545215453154541545515456154571545815459154601546115462154631546415465154661546715468154691547015471154721547315474154751547615477154781547915480154811548215483154841548515486154871548815489154901549115492154931549415495154961549715498154991550015501155021550315504155051550615507155081550915510155111551215513155141551515516155171551815519155201552115522155231552415525155261552715528155291553015531155321553315534155351553615537155381553915540155411554215543155441554515546155471554815549155501555115552155531555415555155561555715558155591556015561155621556315564155651556615567155681556915570155711557215573155741557515576155771557815579155801558115582155831558415585155861558715588155891559015591155921559315594155951559615597155981559915600156011560215603156041560515606156071560815609156101561115612156131561415615156161561715618156191562015621156221562315624156251562615627156281562915630156311563215633156341563515636156371563815639156401564115642156431564415645156461564715648156491565015651156521565315654156551565615657156581565915660156611566215663156641566515666156671566815669156701567115672156731567415675156761567715678156791568015681156821568315684156851568615687156881568915690156911569215693156941569515696156971569815699157001570115702157031570415705157061570715708157091571015711157121571315714157151571615717157181571915720157211572215723157241572515726157271572815729157301573115732157331573415735157361573715738157391574015741157421574315744157451574615747157481574915750157511575215753157541575515756157571575815759157601576115762157631576415765157661576715768157691577015771157721577315774157751577615777157781577915780157811578215783157841578515786157871578815789157901579115792157931579415795157961579715798157991580015801158021580315804158051580615807158081580915810158111581215813158141581515816158171581815819158201582115822158231582415825158261582715828158291583015831158321583315834158351583615837158381583915840158411584215843158441584515846158471584815849158501585115852158531585415855158561585715858158591586015861158621586315864158651586615867158681586915870158711587215873158741587515876158771587815879158801588115882158831588415885158861588715888158891589015891158921589315894158951589615897158981589915900159011590215903159041590515906159071590815909159101591115912159131591415915159161591715918159191592015921159221592315924159251592615927159281592915930159311593215933159341593515936159371593815939159401594115942159431594415945159461594715948159491595015951159521595315954159551595615957159581595915960159611596215963159641596515966159671596815969159701597115972159731597415975159761597715978159791598015981159821598315984159851598615987159881598915990159911599215993159941599515996159971599815999160001600116002160031600416005160061600716008160091601016011160121601316014160151601616017160181601916020160211602216023160241602516026160271602816029160301603116032160331603416035160361603716038160391604016041160421604316044160451604616047160481604916050160511605216053160541605516056160571605816059160601606116062160631606416065160661606716068160691607016071160721607316074160751607616077160781607916080160811608216083160841608516086160871608816089160901609116092160931609416095160961609716098160991610016101161021610316104161051610616107161081610916110161111611216113161141611516116161171611816119161201612116122161231612416125161261612716128161291613016131161321613316134161351613616137161381613916140161411614216143161441614516146161471614816149161501615116152161531615416155161561615716158161591616016161161621616316164161651616616167161681616916170161711617216173161741617516176161771617816179161801618116182161831618416185161861618716188161891619016191161921619316194161951619616197161981619916200162011620216203162041620516206162071620816209162101621116212162131621416215162161621716218162191622016221162221622316224162251622616227162281622916230162311623216233162341623516236162371623816239162401624116242162431624416245162461624716248162491625016251162521625316254162551625616257162581625916260162611626216263162641626516266162671626816269162701627116272162731627416275162761627716278162791628016281162821628316284162851628616287162881628916290162911629216293162941629516296162971629816299163001630116302163031630416305163061630716308163091631016311163121631316314163151631616317163181631916320163211632216323163241632516326163271632816329163301633116332163331633416335163361633716338163391634016341163421634316344163451634616347163481634916350163511635216353163541635516356163571635816359163601636116362163631636416365163661636716368163691637016371163721637316374163751637616377163781637916380163811638216383163841638516386163871638816389163901639116392163931639416395163961639716398163991640016401164021640316404164051640616407164081640916410164111641216413164141641516416164171641816419164201642116422164231642416425164261642716428164291643016431164321643316434164351643616437164381643916440164411644216443164441644516446164471644816449164501645116452164531645416455164561645716458164591646016461164621646316464164651646616467164681646916470164711647216473164741647516476164771647816479164801648116482164831648416485164861648716488164891649016491164921649316494164951649616497164981649916500165011650216503165041650516506165071650816509165101651116512165131651416515165161651716518165191652016521165221652316524165251652616527165281652916530165311653216533165341653516536165371653816539165401654116542165431654416545165461654716548165491655016551165521655316554165551655616557165581655916560165611656216563165641656516566165671656816569165701657116572165731657416575165761657716578165791658016581165821658316584165851658616587165881658916590165911659216593165941659516596165971659816599166001660116602166031660416605166061660716608166091661016611166121661316614166151661616617166181661916620166211662216623166241662516626166271662816629166301663116632166331663416635166361663716638166391664016641166421664316644166451664616647166481664916650166511665216653166541665516656166571665816659166601666116662166631666416665166661666716668166691667016671166721667316674166751667616677166781667916680166811668216683166841668516686166871668816689166901669116692166931669416695166961669716698166991670016701167021670316704167051670616707167081670916710167111671216713167141671516716167171671816719167201672116722167231672416725167261672716728167291673016731167321673316734167351673616737167381673916740167411674216743167441674516746167471674816749167501675116752167531675416755167561675716758167591676016761167621676316764167651676616767167681676916770167711677216773167741677516776167771677816779167801678116782167831678416785167861678716788167891679016791167921679316794167951679616797167981679916800168011680216803168041680516806168071680816809168101681116812168131681416815168161681716818168191682016821168221682316824168251682616827168281682916830168311683216833168341683516836168371683816839168401684116842168431684416845168461684716848168491685016851168521685316854168551685616857168581685916860168611686216863168641686516866168671686816869168701687116872168731687416875168761687716878168791688016881168821688316884168851688616887168881688916890168911689216893168941689516896168971689816899169001690116902169031690416905169061690716908169091691016911169121691316914169151691616917169181691916920169211692216923169241692516926169271692816929169301693116932169331693416935169361693716938169391694016941169421694316944169451694616947169481694916950169511695216953169541695516956169571695816959169601696116962169631696416965169661696716968169691697016971169721697316974169751697616977169781697916980169811698216983169841698516986169871698816989169901699116992169931699416995169961699716998169991700017001170021700317004170051700617007170081700917010170111701217013170141701517016170171701817019170201702117022170231702417025170261702717028170291703017031170321703317034170351703617037170381703917040170411704217043170441704517046170471704817049170501705117052170531705417055170561705717058170591706017061170621706317064170651706617067170681706917070170711707217073170741707517076170771707817079170801708117082170831708417085170861708717088170891709017091170921709317094170951709617097170981709917100171011710217103171041710517106171071710817109171101711117112171131711417115171161711717118171191712017121171221712317124171251712617127171281712917130171311713217133171341713517136171371713817139171401714117142171431714417145171461714717148171491715017151171521715317154171551715617157171581715917160171611716217163171641716517166171671716817169171701717117172171731717417175171761717717178171791718017181171821718317184171851718617187171881718917190171911719217193171941719517196171971719817199172001720117202172031720417205172061720717208172091721017211172121721317214172151721617217172181721917220172211722217223172241722517226172271722817229172301723117232172331723417235172361723717238172391724017241172421724317244172451724617247172481724917250172511725217253172541725517256172571725817259172601726117262172631726417265172661726717268172691727017271172721727317274172751727617277172781727917280172811728217283172841728517286172871728817289172901729117292172931729417295172961729717298172991730017301173021730317304173051730617307173081730917310173111731217313173141731517316173171731817319173201732117322173231732417325173261732717328173291733017331173321733317334173351733617337173381733917340173411734217343173441734517346173471734817349173501735117352173531735417355173561735717358173591736017361173621736317364173651736617367173681736917370173711737217373173741737517376173771737817379173801738117382173831738417385173861738717388173891739017391173921739317394173951739617397173981739917400174011740217403174041740517406174071740817409174101741117412174131741417415174161741717418174191742017421174221742317424174251742617427174281742917430174311743217433174341743517436174371743817439174401744117442174431744417445174461744717448174491745017451174521745317454174551745617457174581745917460174611746217463174641746517466174671746817469174701747117472174731747417475174761747717478174791748017481174821748317484174851748617487174881748917490174911749217493174941749517496174971749817499175001750117502175031750417505175061750717508175091751017511175121751317514175151751617517175181751917520175211752217523175241752517526175271752817529175301753117532175331753417535175361753717538175391754017541175421754317544175451754617547175481754917550175511755217553175541755517556175571755817559175601756117562175631756417565175661756717568175691757017571175721757317574175751757617577175781757917580175811758217583175841758517586175871758817589175901759117592175931759417595175961759717598175991760017601176021760317604176051760617607176081760917610176111761217613176141761517616176171761817619176201762117622176231762417625176261762717628176291763017631176321763317634176351763617637176381763917640176411764217643176441764517646176471764817649176501765117652176531765417655176561765717658176591766017661176621766317664176651766617667176681766917670176711767217673176741767517676176771767817679176801768117682176831768417685176861768717688176891769017691176921769317694176951769617697176981769917700177011770217703177041770517706177071770817709177101771117712177131771417715177161771717718177191772017721177221772317724177251772617727177281772917730177311773217733177341773517736177371773817739177401774117742177431774417745177461774717748177491775017751177521775317754177551775617757177581775917760177611776217763177641776517766177671776817769177701777117772177731777417775177761777717778177791778017781177821778317784177851778617787177881778917790177911779217793177941779517796177971779817799178001780117802178031780417805178061780717808178091781017811178121781317814178151781617817178181781917820178211782217823178241782517826178271782817829178301783117832178331783417835178361783717838178391784017841178421784317844178451784617847178481784917850178511785217853178541785517856178571785817859178601786117862178631786417865178661786717868178691787017871178721787317874178751787617877178781787917880178811788217883178841788517886178871788817889178901789117892178931789417895178961789717898178991790017901179021790317904179051790617907179081790917910179111791217913179141791517916179171791817919179201792117922179231792417925179261792717928179291793017931179321793317934179351793617937179381793917940179411794217943179441794517946179471794817949179501795117952179531795417955179561795717958179591796017961179621796317964179651796617967179681796917970179711797217973179741797517976179771797817979179801798117982179831798417985179861798717988179891799017991179921799317994179951799617997179981799918000180011800218003180041800518006180071800818009180101801118012180131801418015180161801718018180191802018021180221802318024180251802618027180281802918030180311803218033180341803518036180371803818039180401804118042180431804418045180461804718048180491805018051180521805318054180551805618057180581805918060180611806218063180641806518066180671806818069180701807118072180731807418075180761807718078180791808018081180821808318084180851808618087180881808918090180911809218093180941809518096180971809818099181001810118102181031810418105181061810718108181091811018111181121811318114181151811618117181181811918120181211812218123181241812518126181271812818129181301813118132181331813418135181361813718138181391814018141181421814318144181451814618147181481814918150181511815218153181541815518156181571815818159181601816118162181631816418165181661816718168181691817018171181721817318174181751817618177181781817918180181811818218183181841818518186181871818818189181901819118192181931819418195181961819718198181991820018201182021820318204182051820618207182081820918210182111821218213182141821518216182171821818219182201822118222182231822418225182261822718228182291823018231182321823318234182351823618237182381823918240182411824218243182441824518246182471824818249182501825118252182531825418255182561825718258182591826018261182621826318264182651826618267182681826918270182711827218273182741827518276182771827818279182801828118282182831828418285182861828718288182891829018291182921829318294182951829618297182981829918300183011830218303183041830518306183071830818309183101831118312183131831418315183161831718318183191832018321183221832318324183251832618327183281832918330183311833218333183341833518336183371833818339183401834118342183431834418345183461834718348183491835018351183521835318354183551835618357183581835918360183611836218363183641836518366183671836818369183701837118372183731837418375183761837718378183791838018381183821838318384183851838618387183881838918390183911839218393183941839518396183971839818399184001840118402184031840418405184061840718408184091841018411184121841318414184151841618417184181841918420184211842218423184241842518426184271842818429184301843118432184331843418435184361843718438184391844018441184421844318444184451844618447184481844918450184511845218453184541845518456184571845818459184601846118462184631846418465184661846718468184691847018471184721847318474184751847618477184781847918480184811848218483184841848518486184871848818489184901849118492184931849418495184961849718498184991850018501185021850318504185051850618507185081850918510185111851218513185141851518516185171851818519185201852118522185231852418525185261852718528185291853018531185321853318534185351853618537185381853918540185411854218543185441854518546185471854818549185501855118552185531855418555185561855718558185591856018561185621856318564185651856618567185681856918570185711857218573185741857518576185771857818579185801858118582185831858418585185861858718588185891859018591185921859318594185951859618597185981859918600186011860218603186041860518606186071860818609186101861118612186131861418615186161861718618186191862018621186221862318624186251862618627186281862918630186311863218633186341863518636186371863818639186401864118642186431864418645186461864718648186491865018651186521865318654186551865618657186581865918660186611866218663186641866518666186671866818669186701867118672186731867418675186761867718678186791868018681186821868318684186851868618687186881868918690186911869218693186941869518696186971869818699187001870118702187031870418705187061870718708187091871018711187121871318714187151871618717187181871918720187211872218723187241872518726187271872818729187301873118732187331873418735187361873718738187391874018741187421874318744187451874618747187481874918750187511875218753187541875518756187571875818759187601876118762187631876418765187661876718768187691877018771187721877318774187751877618777187781877918780187811878218783187841878518786187871878818789187901879118792187931879418795187961879718798187991880018801188021880318804188051880618807188081880918810188111881218813188141881518816188171881818819188201882118822188231882418825188261882718828188291883018831188321883318834188351883618837188381883918840188411884218843188441884518846188471884818849188501885118852188531885418855188561885718858188591886018861188621886318864188651886618867188681886918870188711887218873188741887518876188771887818879188801888118882188831888418885188861888718888188891889018891188921889318894188951889618897188981889918900189011890218903189041890518906189071890818909189101891118912189131891418915189161891718918189191892018921189221892318924189251892618927189281892918930189311893218933189341893518936189371893818939189401894118942189431894418945189461894718948189491895018951189521895318954189551895618957189581895918960189611896218963189641896518966189671896818969189701897118972189731897418975189761897718978189791898018981189821898318984189851898618987189881898918990189911899218993189941899518996189971899818999190001900119002190031900419005190061900719008190091901019011190121901319014190151901619017190181901919020190211902219023190241902519026190271902819029190301903119032190331903419035190361903719038190391904019041190421904319044190451904619047190481904919050190511905219053190541905519056190571905819059190601906119062190631906419065190661906719068190691907019071190721907319074190751907619077190781907919080190811908219083190841908519086190871908819089190901909119092190931909419095190961909719098190991910019101191021910319104191051910619107191081910919110191111911219113191141911519116191171911819119191201912119122191231912419125191261912719128191291913019131191321913319134191351913619137191381913919140191411914219143191441914519146191471914819149191501915119152191531915419155191561915719158191591916019161191621916319164191651916619167191681916919170191711917219173191741917519176191771917819179191801918119182191831918419185191861918719188191891919019191191921919319194191951919619197191981919919200192011920219203192041920519206192071920819209192101921119212192131921419215192161921719218192191922019221192221922319224192251922619227192281922919230192311923219233192341923519236192371923819239192401924119242192431924419245192461924719248192491925019251192521925319254192551925619257192581925919260192611926219263192641926519266192671926819269192701927119272192731927419275192761927719278192791928019281192821928319284192851928619287192881928919290192911929219293192941929519296192971929819299193001930119302193031930419305193061930719308193091931019311193121931319314193151931619317193181931919320193211932219323193241932519326193271932819329193301933119332193331933419335193361933719338193391934019341193421934319344193451934619347193481934919350193511935219353193541935519356193571935819359193601936119362193631936419365193661936719368193691937019371193721937319374193751937619377193781937919380193811938219383193841938519386193871938819389193901939119392193931939419395193961939719398193991940019401194021940319404194051940619407194081940919410194111941219413194141941519416194171941819419194201942119422194231942419425194261942719428194291943019431194321943319434194351943619437194381943919440194411944219443194441944519446194471944819449194501945119452194531945419455194561945719458194591946019461194621946319464194651946619467194681946919470194711947219473194741947519476194771947819479194801948119482194831948419485194861948719488194891949019491194921949319494194951949619497194981949919500195011950219503195041950519506195071950819509195101951119512195131951419515195161951719518195191952019521195221952319524195251952619527195281952919530195311953219533195341953519536195371953819539195401954119542195431954419545195461954719548195491955019551195521955319554195551955619557195581955919560195611956219563195641956519566195671956819569195701957119572195731957419575195761957719578195791958019581195821958319584195851958619587195881958919590195911959219593195941959519596195971959819599196001960119602196031960419605196061960719608196091961019611196121961319614196151961619617196181961919620196211962219623196241962519626196271962819629196301963119632196331963419635196361963719638196391964019641196421964319644196451964619647196481964919650196511965219653196541965519656196571965819659196601966119662196631966419665196661966719668196691967019671196721967319674196751967619677196781967919680196811968219683196841968519686196871968819689196901969119692196931969419695196961969719698196991970019701197021970319704197051970619707197081970919710197111971219713197141971519716197171971819719197201972119722197231972419725197261972719728197291973019731197321973319734197351973619737197381973919740197411974219743197441974519746197471974819749197501975119752197531975419755197561975719758197591976019761197621976319764197651976619767197681976919770197711977219773197741977519776197771977819779197801978119782197831978419785197861978719788197891979019791197921979319794197951979619797197981979919800198011980219803198041980519806198071980819809198101981119812198131981419815198161981719818198191982019821198221982319824198251982619827198281982919830198311983219833198341983519836198371983819839198401984119842198431984419845198461984719848198491985019851198521985319854198551985619857198581985919860198611986219863198641986519866198671986819869198701987119872198731987419875198761987719878198791988019881198821988319884198851988619887198881988919890198911989219893198941989519896198971989819899199001990119902199031990419905199061990719908199091991019911199121991319914199151991619917199181991919920199211992219923199241992519926199271992819929199301993119932199331993419935199361993719938199391994019941199421994319944199451994619947199481994919950199511995219953199541995519956199571995819959199601996119962199631996419965199661996719968199691997019971199721997319974199751997619977199781997919980199811998219983199841998519986199871998819989199901999119992199931999419995199961999719998199992000020001200022000320004200052000620007200082000920010200112001220013200142001520016200172001820019200202002120022200232002420025200262002720028200292003020031200322003320034200352003620037200382003920040200412004220043200442004520046200472004820049200502005120052200532005420055200562005720058200592006020061200622006320064200652006620067200682006920070200712007220073200742007520076200772007820079200802008120082200832008420085200862008720088200892009020091200922009320094200952009620097200982009920100201012010220103201042010520106201072010820109201102011120112201132011420115201162011720118201192012020121201222012320124201252012620127201282012920130201312013220133201342013520136201372013820139201402014120142201432014420145201462014720148201492015020151201522015320154201552015620157201582015920160201612016220163201642016520166201672016820169201702017120172201732017420175201762017720178201792018020181201822018320184201852018620187201882018920190201912019220193201942019520196201972019820199202002020120202202032020420205202062020720208202092021020211202122021320214202152021620217202182021920220202212022220223202242022520226202272022820229202302023120232202332023420235202362023720238202392024020241202422024320244202452024620247202482024920250202512025220253202542025520256202572025820259202602026120262202632026420265202662026720268202692027020271202722027320274202752027620277202782027920280202812028220283202842028520286202872028820289202902029120292202932029420295202962029720298202992030020301203022030320304203052030620307203082030920310203112031220313203142031520316203172031820319203202032120322203232032420325203262032720328203292033020331203322033320334203352033620337203382033920340203412034220343203442034520346203472034820349203502035120352203532035420355203562035720358203592036020361203622036320364203652036620367203682036920370203712037220373203742037520376203772037820379203802038120382203832038420385203862038720388203892039020391203922039320394203952039620397203982039920400204012040220403204042040520406204072040820409204102041120412204132041420415204162041720418204192042020421204222042320424204252042620427204282042920430204312043220433204342043520436204372043820439204402044120442204432044420445204462044720448204492045020451204522045320454204552045620457204582045920460204612046220463204642046520466204672046820469204702047120472204732047420475204762047720478204792048020481204822048320484204852048620487204882048920490204912049220493204942049520496204972049820499205002050120502205032050420505205062050720508205092051020511205122051320514205152051620517205182051920520205212052220523205242052520526205272052820529205302053120532205332053420535205362053720538205392054020541205422054320544205452054620547205482054920550205512055220553205542055520556205572055820559205602056120562205632056420565205662056720568205692057020571205722057320574205752057620577205782057920580205812058220583205842058520586205872058820589205902059120592205932059420595205962059720598205992060020601206022060320604206052060620607206082060920610206112061220613206142061520616206172061820619206202062120622206232062420625206262062720628206292063020631206322063320634206352063620637206382063920640206412064220643206442064520646206472064820649206502065120652206532065420655206562065720658206592066020661206622066320664206652066620667206682066920670206712067220673206742067520676206772067820679206802068120682206832068420685206862068720688206892069020691206922069320694206952069620697206982069920700207012070220703207042070520706207072070820709207102071120712207132071420715207162071720718207192072020721207222072320724207252072620727207282072920730207312073220733207342073520736207372073820739207402074120742207432074420745207462074720748207492075020751207522075320754207552075620757207582075920760207612076220763207642076520766207672076820769207702077120772207732077420775207762077720778207792078020781207822078320784207852078620787207882078920790207912079220793207942079520796207972079820799208002080120802208032080420805208062080720808208092081020811208122081320814208152081620817208182081920820208212082220823208242082520826208272082820829208302083120832208332083420835208362083720838208392084020841208422084320844208452084620847208482084920850208512085220853208542085520856208572085820859208602086120862208632086420865208662086720868208692087020871208722087320874208752087620877208782087920880208812088220883208842088520886208872088820889208902089120892208932089420895208962089720898208992090020901209022090320904209052090620907209082090920910209112091220913209142091520916209172091820919209202092120922209232092420925209262092720928209292093020931209322093320934209352093620937209382093920940209412094220943209442094520946209472094820949209502095120952209532095420955209562095720958209592096020961209622096320964209652096620967209682096920970209712097220973209742097520976209772097820979209802098120982209832098420985209862098720988209892099020991209922099320994209952099620997209982099921000210012100221003210042100521006210072100821009210102101121012210132101421015210162101721018210192102021021210222102321024210252102621027210282102921030210312103221033210342103521036210372103821039210402104121042210432104421045210462104721048210492105021051210522105321054210552105621057210582105921060210612106221063210642106521066210672106821069210702107121072210732107421075210762107721078210792108021081210822108321084210852108621087210882108921090210912109221093210942109521096210972109821099211002110121102211032110421105211062110721108211092111021111211122111321114211152111621117211182111921120211212112221123211242112521126211272112821129211302113121132211332113421135211362113721138211392114021141211422114321144211452114621147211482114921150211512115221153211542115521156211572115821159211602116121162211632116421165211662116721168211692117021171211722117321174211752117621177211782117921180211812118221183211842118521186211872118821189211902119121192211932119421195211962119721198211992120021201212022120321204212052120621207212082120921210212112121221213212142121521216212172121821219212202122121222212232122421225212262122721228212292123021231212322123321234212352123621237212382123921240212412124221243212442124521246212472124821249212502125121252212532125421255212562125721258212592126021261212622126321264212652126621267212682126921270212712127221273212742127521276212772127821279212802128121282212832128421285212862128721288212892129021291212922129321294212952129621297212982129921300213012130221303213042130521306213072130821309213102131121312213132131421315213162131721318213192132021321213222132321324213252132621327213282132921330213312133221333213342133521336213372133821339213402134121342213432134421345213462134721348213492135021351213522135321354213552135621357213582135921360213612136221363213642136521366213672136821369213702137121372213732137421375213762137721378213792138021381213822138321384213852138621387213882138921390213912139221393213942139521396213972139821399214002140121402214032140421405214062140721408214092141021411214122141321414214152141621417214182141921420214212142221423214242142521426214272142821429214302143121432214332143421435214362143721438214392144021441214422144321444214452144621447214482144921450214512145221453214542145521456214572145821459214602146121462214632146421465214662146721468214692147021471214722147321474214752147621477214782147921480214812148221483214842148521486214872148821489214902149121492214932149421495214962149721498214992150021501215022150321504215052150621507215082150921510215112151221513215142151521516215172151821519215202152121522215232152421525215262152721528215292153021531215322153321534215352153621537215382153921540215412154221543215442154521546215472154821549215502155121552215532155421555215562155721558215592156021561215622156321564215652156621567215682156921570215712157221573215742157521576215772157821579215802158121582215832158421585215862158721588215892159021591215922159321594215952159621597215982159921600216012160221603216042160521606216072160821609216102161121612216132161421615216162161721618216192162021621216222162321624216252162621627216282162921630216312163221633216342163521636216372163821639216402164121642216432164421645216462164721648216492165021651216522165321654216552165621657216582165921660216612166221663216642166521666216672166821669216702167121672216732167421675216762167721678216792168021681216822168321684216852168621687216882168921690216912169221693216942169521696216972169821699217002170121702217032170421705217062170721708217092171021711217122171321714217152171621717217182171921720217212172221723217242172521726217272172821729217302173121732217332173421735217362173721738217392174021741217422174321744217452174621747217482174921750217512175221753217542175521756217572175821759217602176121762217632176421765217662176721768217692177021771217722177321774217752177621777217782177921780217812178221783217842178521786217872178821789217902179121792217932179421795217962179721798217992180021801218022180321804218052180621807218082180921810218112181221813218142181521816218172181821819218202182121822218232182421825218262182721828218292183021831218322183321834218352183621837218382183921840218412184221843218442184521846218472184821849218502185121852218532185421855218562185721858218592186021861218622186321864218652186621867218682186921870218712187221873218742187521876218772187821879218802188121882218832188421885218862188721888218892189021891218922189321894218952189621897218982189921900219012190221903219042190521906219072190821909219102191121912219132191421915219162191721918219192192021921219222192321924219252192621927219282192921930219312193221933219342193521936219372193821939219402194121942219432194421945219462194721948219492195021951219522195321954219552195621957219582195921960219612196221963219642196521966219672196821969219702197121972219732197421975219762197721978219792198021981219822198321984219852198621987219882198921990219912199221993219942199521996219972199821999220002200122002220032200422005220062200722008220092201022011220122201322014220152201622017220182201922020220212202222023220242202522026220272202822029220302203122032220332203422035220362203722038220392204022041220422204322044220452204622047220482204922050220512205222053220542205522056220572205822059220602206122062220632206422065220662206722068220692207022071220722207322074220752207622077220782207922080220812208222083220842208522086220872208822089220902209122092220932209422095220962209722098220992210022101221022210322104221052210622107221082210922110221112211222113221142211522116221172211822119221202212122122221232212422125221262212722128221292213022131221322213322134221352213622137221382213922140221412214222143221442214522146221472214822149221502215122152221532215422155221562215722158221592216022161221622216322164221652216622167221682216922170221712217222173221742217522176221772217822179221802218122182221832218422185221862218722188221892219022191221922219322194221952219622197221982219922200222012220222203222042220522206222072220822209222102221122212222132221422215222162221722218222192222022221222222222322224222252222622227222282222922230222312223222233222342223522236222372223822239222402224122242222432224422245222462224722248222492225022251222522225322254222552225622257222582225922260222612226222263222642226522266222672226822269222702227122272222732227422275222762227722278222792228022281222822228322284222852228622287222882228922290222912229222293222942229522296222972229822299223002230122302223032230422305223062230722308223092231022311223122231322314223152231622317223182231922320223212232222323223242232522326223272232822329223302233122332223332233422335223362233722338223392234022341223422234322344223452234622347223482234922350223512235222353223542235522356223572235822359223602236122362223632236422365223662236722368223692237022371223722237322374223752237622377223782237922380223812238222383223842238522386223872238822389223902239122392223932239422395223962239722398223992240022401224022240322404224052240622407224082240922410224112241222413224142241522416224172241822419224202242122422224232242422425224262242722428224292243022431224322243322434224352243622437224382243922440224412244222443224442244522446224472244822449224502245122452224532245422455224562245722458224592246022461224622246322464224652246622467224682246922470224712247222473224742247522476224772247822479224802248122482224832248422485224862248722488224892249022491224922249322494224952249622497224982249922500225012250222503225042250522506225072250822509225102251122512225132251422515225162251722518225192252022521225222252322524225252252622527225282252922530225312253222533225342253522536225372253822539225402254122542225432254422545225462254722548225492255022551225522255322554225552255622557225582255922560225612256222563225642256522566225672256822569225702257122572225732257422575225762257722578225792258022581225822258322584225852258622587225882258922590225912259222593225942259522596225972259822599226002260122602226032260422605226062260722608226092261022611226122261322614226152261622617226182261922620226212262222623226242262522626226272262822629226302263122632226332263422635226362263722638226392264022641226422264322644226452264622647226482264922650226512265222653226542265522656226572265822659226602266122662226632266422665226662266722668226692267022671226722267322674226752267622677226782267922680226812268222683226842268522686226872268822689226902269122692226932269422695226962269722698226992270022701227022270322704227052270622707227082270922710227112271222713227142271522716227172271822719227202272122722227232272422725227262272722728227292273022731227322273322734227352273622737227382273922740227412274222743227442274522746227472274822749227502275122752227532275422755227562275722758227592276022761227622276322764227652276622767227682276922770227712277222773227742277522776227772277822779227802278122782227832278422785227862278722788227892279022791227922279322794227952279622797227982279922800228012280222803228042280522806228072280822809228102281122812228132281422815228162281722818228192282022821228222282322824228252282622827228282282922830228312283222833228342283522836228372283822839228402284122842228432284422845228462284722848228492285022851228522285322854228552285622857228582285922860228612286222863228642286522866228672286822869228702287122872228732287422875228762287722878228792288022881228822288322884228852288622887228882288922890228912289222893228942289522896228972289822899229002290122902229032290422905229062290722908229092291022911229122291322914229152291622917229182291922920229212292222923229242292522926229272292822929229302293122932229332293422935229362293722938229392294022941229422294322944229452294622947229482294922950229512295222953229542295522956229572295822959229602296122962229632296422965229662296722968229692297022971229722297322974229752297622977229782297922980229812298222983229842298522986229872298822989229902299122992229932299422995229962299722998229992300023001230022300323004230052300623007230082300923010230112301223013230142301523016230172301823019230202302123022230232302423025230262302723028230292303023031230322303323034230352303623037230382303923040230412304223043230442304523046230472304823049230502305123052230532305423055230562305723058230592306023061230622306323064230652306623067230682306923070230712307223073230742307523076230772307823079230802308123082230832308423085230862308723088230892309023091230922309323094230952309623097230982309923100231012310223103231042310523106231072310823109231102311123112231132311423115231162311723118231192312023121231222312323124231252312623127231282312923130231312313223133231342313523136231372313823139231402314123142231432314423145231462314723148231492315023151231522315323154231552315623157231582315923160231612316223163231642316523166231672316823169231702317123172231732317423175231762317723178231792318023181231822318323184231852318623187231882318923190231912319223193231942319523196231972319823199232002320123202232032320423205232062320723208232092321023211232122321323214232152321623217232182321923220232212322223223232242322523226232272322823229232302323123232232332323423235232362323723238232392324023241232422324323244232452324623247232482324923250232512325223253232542325523256232572325823259232602326123262232632326423265232662326723268232692327023271232722327323274232752327623277232782327923280232812328223283232842328523286232872328823289232902329123292232932329423295232962329723298232992330023301233022330323304233052330623307233082330923310233112331223313233142331523316233172331823319233202332123322233232332423325233262332723328233292333023331233322333323334233352333623337233382333923340233412334223343233442334523346233472334823349233502335123352233532335423355233562335723358233592336023361233622336323364233652336623367233682336923370233712337223373233742337523376233772337823379233802338123382233832338423385233862338723388233892339023391233922339323394233952339623397233982339923400234012340223403234042340523406234072340823409234102341123412234132341423415234162341723418234192342023421234222342323424234252342623427234282342923430234312343223433234342343523436234372343823439234402344123442234432344423445234462344723448234492345023451234522345323454234552345623457234582345923460234612346223463234642346523466234672346823469234702347123472234732347423475234762347723478234792348023481234822348323484234852348623487234882348923490234912349223493234942349523496234972349823499235002350123502235032350423505235062350723508235092351023511235122351323514235152351623517235182351923520235212352223523235242352523526235272352823529235302353123532235332353423535235362353723538235392354023541235422354323544235452354623547235482354923550235512355223553235542355523556235572355823559235602356123562235632356423565235662356723568235692357023571235722357323574235752357623577235782357923580235812358223583235842358523586235872358823589235902359123592235932359423595235962359723598235992360023601236022360323604236052360623607236082360923610236112361223613236142361523616236172361823619236202362123622236232362423625236262362723628236292363023631236322363323634236352363623637236382363923640236412364223643236442364523646236472364823649236502365123652236532365423655236562365723658236592366023661236622366323664236652366623667236682366923670236712367223673236742367523676236772367823679236802368123682236832368423685236862368723688236892369023691236922369323694236952369623697236982369923700237012370223703237042370523706237072370823709237102371123712237132371423715237162371723718237192372023721237222372323724237252372623727237282372923730237312373223733237342373523736237372373823739237402374123742237432374423745237462374723748237492375023751237522375323754237552375623757237582375923760237612376223763237642376523766237672376823769237702377123772237732377423775237762377723778237792378023781237822378323784237852378623787237882378923790237912379223793237942379523796237972379823799238002380123802238032380423805238062380723808238092381023811238122381323814238152381623817238182381923820238212382223823238242382523826238272382823829238302383123832238332383423835238362383723838238392384023841238422384323844238452384623847238482384923850238512385223853238542385523856238572385823859238602386123862238632386423865238662386723868238692387023871238722387323874238752387623877238782387923880238812388223883238842388523886238872388823889238902389123892238932389423895238962389723898238992390023901239022390323904239052390623907239082390923910239112391223913239142391523916239172391823919239202392123922239232392423925239262392723928239292393023931239322393323934239352393623937239382393923940239412394223943239442394523946239472394823949239502395123952239532395423955239562395723958239592396023961239622396323964239652396623967239682396923970239712397223973239742397523976239772397823979239802398123982239832398423985239862398723988239892399023991239922399323994239952399623997239982399924000240012400224003240042400524006240072400824009240102401124012240132401424015240162401724018240192402024021240222402324024240252402624027240282402924030240312403224033240342403524036240372403824039240402404124042240432404424045240462404724048240492405024051240522405324054240552405624057240582405924060240612406224063240642406524066240672406824069240702407124072240732407424075240762407724078240792408024081240822408324084240852408624087240882408924090240912409224093240942409524096240972409824099241002410124102241032410424105241062410724108241092411024111241122411324114241152411624117241182411924120241212412224123241242412524126241272412824129241302413124132241332413424135241362413724138241392414024141241422414324144241452414624147241482414924150241512415224153241542415524156241572415824159241602416124162241632416424165241662416724168241692417024171241722417324174241752417624177241782417924180241812418224183241842418524186241872418824189241902419124192241932419424195241962419724198241992420024201242022420324204242052420624207242082420924210242112421224213242142421524216242172421824219242202422124222242232422424225242262422724228242292423024231242322423324234242352423624237242382423924240242412424224243242442424524246242472424824249242502425124252242532425424255242562425724258242592426024261242622426324264242652426624267242682426924270242712427224273242742427524276242772427824279242802428124282242832428424285242862428724288242892429024291242922429324294242952429624297242982429924300243012430224303243042430524306243072430824309243102431124312243132431424315243162431724318243192432024321243222432324324243252432624327243282432924330243312433224333243342433524336243372433824339243402434124342243432434424345243462434724348243492435024351243522435324354243552435624357243582435924360243612436224363243642436524366243672436824369243702437124372243732437424375243762437724378243792438024381243822438324384243852438624387243882438924390243912439224393243942439524396243972439824399244002440124402244032440424405244062440724408244092441024411244122441324414244152441624417244182441924420244212442224423244242442524426244272442824429244302443124432244332443424435244362443724438244392444024441244422444324444244452444624447244482444924450244512445224453244542445524456244572445824459244602446124462244632446424465244662446724468244692447024471244722447324474244752447624477244782447924480244812448224483244842448524486244872448824489244902449124492244932449424495244962449724498244992450024501245022450324504245052450624507245082450924510245112451224513245142451524516245172451824519245202452124522245232452424525245262452724528245292453024531245322453324534245352453624537245382453924540245412454224543245442454524546245472454824549245502455124552245532455424555245562455724558245592456024561245622456324564245652456624567245682456924570245712457224573245742457524576245772457824579245802458124582245832458424585245862458724588245892459024591245922459324594245952459624597245982459924600246012460224603246042460524606246072460824609246102461124612246132461424615246162461724618246192462024621246222462324624246252462624627246282462924630246312463224633246342463524636246372463824639246402464124642246432464424645246462464724648246492465024651246522465324654246552465624657246582465924660246612466224663246642466524666246672466824669246702467124672246732467424675246762467724678246792468024681246822468324684246852468624687246882468924690246912469224693246942469524696246972469824699247002470124702247032470424705247062470724708247092471024711247122471324714247152471624717247182471924720247212472224723247242472524726247272472824729247302473124732247332473424735247362473724738247392474024741247422474324744247452474624747247482474924750247512475224753247542475524756247572475824759247602476124762247632476424765247662476724768247692477024771247722477324774247752477624777247782477924780247812478224783247842478524786247872478824789247902479124792247932479424795247962479724798247992480024801248022480324804248052480624807248082480924810248112481224813248142481524816248172481824819248202482124822248232482424825248262482724828248292483024831248322483324834248352483624837248382483924840248412484224843248442484524846248472484824849248502485124852248532485424855248562485724858248592486024861248622486324864248652486624867248682486924870248712487224873248742487524876248772487824879248802488124882248832488424885248862488724888248892489024891248922489324894248952489624897248982489924900249012490224903249042490524906249072490824909249102491124912249132491424915249162491724918249192492024921249222492324924249252492624927249282492924930249312493224933249342493524936249372493824939249402494124942249432494424945249462494724948249492495024951249522495324954249552495624957249582495924960249612496224963249642496524966249672496824969249702497124972249732497424975249762497724978249792498024981249822498324984249852498624987249882498924990249912499224993249942499524996249972499824999250002500125002250032500425005250062500725008250092501025011250122501325014250152501625017250182501925020250212502225023250242502525026250272502825029250302503125032250332503425035250362503725038250392504025041250422504325044250452504625047250482504925050250512505225053250542505525056250572505825059250602506125062250632506425065250662506725068250692507025071250722507325074250752507625077250782507925080250812508225083250842508525086250872508825089250902509125092250932509425095250962509725098250992510025101251022510325104251052510625107251082510925110251112511225113251142511525116251172511825119251202512125122251232512425125251262512725128251292513025131251322513325134251352513625137251382513925140251412514225143251442514525146251472514825149251502515125152251532515425155251562515725158251592516025161251622516325164251652516625167251682516925170251712517225173251742517525176251772517825179251802518125182251832518425185251862518725188251892519025191251922519325194251952519625197251982519925200252012520225203252042520525206252072520825209252102521125212252132521425215252162521725218252192522025221252222522325224252252522625227252282522925230252312523225233252342523525236252372523825239252402524125242252432524425245252462524725248252492525025251252522525325254252552525625257252582525925260252612526225263252642526525266252672526825269252702527125272252732527425275252762527725278252792528025281252822528325284252852528625287252882528925290252912529225293252942529525296252972529825299253002530125302253032530425305253062530725308253092531025311253122531325314253152531625317253182531925320253212532225323253242532525326253272532825329253302533125332253332533425335253362533725338253392534025341253422534325344253452534625347253482534925350253512535225353253542535525356253572535825359253602536125362253632536425365253662536725368253692537025371253722537325374253752537625377253782537925380253812538225383253842538525386253872538825389253902539125392253932539425395253962539725398253992540025401254022540325404254052540625407254082540925410254112541225413254142541525416254172541825419254202542125422254232542425425254262542725428254292543025431254322543325434254352543625437254382543925440254412544225443254442544525446254472544825449254502545125452254532545425455254562545725458254592546025461254622546325464254652546625467254682546925470254712547225473254742547525476254772547825479254802548125482254832548425485254862548725488254892549025491254922549325494254952549625497254982549925500255012550225503255042550525506255072550825509255102551125512255132551425515255162551725518255192552025521255222552325524255252552625527255282552925530255312553225533255342553525536255372553825539255402554125542255432554425545255462554725548255492555025551255522555325554255552555625557255582555925560255612556225563255642556525566255672556825569255702557125572255732557425575255762557725578255792558025581255822558325584255852558625587255882558925590255912559225593255942559525596255972559825599256002560125602256032560425605256062560725608256092561025611256122561325614256152561625617256182561925620256212562225623256242562525626256272562825629256302563125632256332563425635256362563725638256392564025641256422564325644256452564625647256482564925650256512565225653256542565525656256572565825659256602566125662256632566425665256662566725668256692567025671256722567325674256752567625677256782567925680256812568225683256842568525686256872568825689256902569125692256932569425695256962569725698256992570025701257022570325704257052570625707257082570925710257112571225713257142571525716257172571825719257202572125722257232572425725257262572725728257292573025731257322573325734257352573625737257382573925740257412574225743257442574525746257472574825749257502575125752257532575425755257562575725758257592576025761257622576325764257652576625767257682576925770257712577225773257742577525776257772577825779257802578125782257832578425785257862578725788257892579025791257922579325794257952579625797257982579925800258012580225803258042580525806258072580825809258102581125812258132581425815258162581725818258192582025821258222582325824258252582625827258282582925830258312583225833258342583525836258372583825839258402584125842258432584425845258462584725848258492585025851258522585325854258552585625857258582585925860258612586225863258642586525866258672586825869258702587125872258732587425875258762587725878258792588025881258822588325884258852588625887258882588925890258912589225893258942589525896258972589825899259002590125902259032590425905259062590725908259092591025911259122591325914259152591625917259182591925920259212592225923259242592525926259272592825929259302593125932259332593425935259362593725938259392594025941259422594325944259452594625947259482594925950259512595225953259542595525956259572595825959259602596125962259632596425965259662596725968259692597025971259722597325974259752597625977259782597925980259812598225983259842598525986259872598825989259902599125992259932599425995259962599725998259992600026001260022600326004260052600626007260082600926010260112601226013260142601526016260172601826019260202602126022260232602426025260262602726028260292603026031260322603326034260352603626037260382603926040260412604226043260442604526046260472604826049260502605126052260532605426055260562605726058260592606026061260622606326064260652606626067260682606926070260712607226073260742607526076260772607826079260802608126082260832608426085260862608726088260892609026091260922609326094260952609626097260982609926100261012610226103261042610526106261072610826109261102611126112261132611426115261162611726118261192612026121261222612326124261252612626127261282612926130261312613226133261342613526136261372613826139261402614126142261432614426145261462614726148261492615026151261522615326154261552615626157261582615926160261612616226163261642616526166261672616826169261702617126172261732617426175261762617726178261792618026181261822618326184261852618626187261882618926190261912619226193261942619526196261972619826199262002620126202262032620426205262062620726208262092621026211262122621326214262152621626217262182621926220262212622226223262242622526226262272622826229262302623126232262332623426235262362623726238262392624026241262422624326244262452624626247262482624926250262512625226253262542625526256262572625826259262602626126262262632626426265262662626726268262692627026271262722627326274262752627626277262782627926280262812628226283262842628526286262872628826289262902629126292262932629426295262962629726298262992630026301263022630326304263052630626307263082630926310263112631226313263142631526316263172631826319263202632126322263232632426325263262632726328263292633026331263322633326334263352633626337263382633926340263412634226343263442634526346263472634826349263502635126352263532635426355263562635726358263592636026361263622636326364263652636626367263682636926370263712637226373263742637526376263772637826379263802638126382263832638426385263862638726388263892639026391263922639326394263952639626397263982639926400264012640226403264042640526406264072640826409264102641126412264132641426415264162641726418264192642026421264222642326424264252642626427264282642926430264312643226433264342643526436264372643826439264402644126442264432644426445264462644726448264492645026451264522645326454264552645626457264582645926460264612646226463264642646526466264672646826469264702647126472264732647426475264762647726478264792648026481264822648326484264852648626487264882648926490264912649226493264942649526496264972649826499265002650126502265032650426505265062650726508265092651026511265122651326514265152651626517265182651926520265212652226523265242652526526265272652826529265302653126532265332653426535265362653726538265392654026541265422654326544265452654626547265482654926550265512655226553265542655526556265572655826559265602656126562265632656426565265662656726568265692657026571265722657326574265752657626577265782657926580265812658226583265842658526586265872658826589265902659126592265932659426595265962659726598265992660026601266022660326604266052660626607266082660926610266112661226613266142661526616266172661826619266202662126622266232662426625266262662726628266292663026631266322663326634266352663626637266382663926640266412664226643266442664526646266472664826649266502665126652266532665426655266562665726658266592666026661266622666326664266652666626667266682666926670266712667226673266742667526676266772667826679266802668126682266832668426685266862668726688266892669026691266922669326694266952669626697266982669926700267012670226703267042670526706267072670826709267102671126712267132671426715267162671726718267192672026721267222672326724267252672626727267282672926730267312673226733267342673526736267372673826739267402674126742267432674426745267462674726748267492675026751267522675326754267552675626757267582675926760267612676226763267642676526766267672676826769267702677126772267732677426775267762677726778267792678026781267822678326784267852678626787267882678926790267912679226793267942679526796267972679826799268002680126802268032680426805268062680726808268092681026811268122681326814268152681626817268182681926820268212682226823268242682526826268272682826829268302683126832268332683426835268362683726838268392684026841268422684326844268452684626847268482684926850268512685226853268542685526856268572685826859268602686126862268632686426865268662686726868268692687026871268722687326874268752687626877268782687926880268812688226883268842688526886268872688826889268902689126892268932689426895268962689726898268992690026901269022690326904269052690626907269082690926910269112691226913269142691526916269172691826919269202692126922269232692426925269262692726928269292693026931269322693326934269352693626937269382693926940269412694226943269442694526946269472694826949269502695126952269532695426955269562695726958269592696026961269622696326964269652696626967269682696926970269712697226973269742697526976269772697826979269802698126982269832698426985269862698726988269892699026991269922699326994269952699626997269982699927000270012700227003270042700527006270072700827009270102701127012270132701427015270162701727018270192702027021270222702327024270252702627027270282702927030270312703227033270342703527036270372703827039270402704127042270432704427045270462704727048270492705027051270522705327054270552705627057270582705927060270612706227063270642706527066270672706827069270702707127072270732707427075270762707727078270792708027081270822708327084270852708627087270882708927090270912709227093270942709527096270972709827099271002710127102271032710427105271062710727108271092711027111271122711327114271152711627117271182711927120271212712227123271242712527126271272712827129271302713127132271332713427135271362713727138271392714027141271422714327144271452714627147271482714927150271512715227153271542715527156271572715827159271602716127162271632716427165271662716727168271692717027171271722717327174271752717627177271782717927180271812718227183271842718527186271872718827189271902719127192271932719427195271962719727198271992720027201272022720327204272052720627207272082720927210272112721227213272142721527216272172721827219272202722127222272232722427225272262722727228272292723027231272322723327234272352723627237272382723927240272412724227243272442724527246272472724827249272502725127252272532725427255272562725727258272592726027261272622726327264272652726627267272682726927270272712727227273272742727527276272772727827279272802728127282272832728427285272862728727288272892729027291272922729327294272952729627297272982729927300273012730227303273042730527306273072730827309273102731127312273132731427315273162731727318273192732027321273222732327324273252732627327273282732927330273312733227333273342733527336273372733827339273402734127342273432734427345273462734727348273492735027351273522735327354273552735627357273582735927360273612736227363273642736527366273672736827369273702737127372273732737427375273762737727378273792738027381273822738327384273852738627387273882738927390273912739227393273942739527396273972739827399274002740127402274032740427405274062740727408274092741027411274122741327414274152741627417274182741927420274212742227423274242742527426274272742827429274302743127432274332743427435274362743727438274392744027441274422744327444274452744627447274482744927450274512745227453274542745527456274572745827459274602746127462274632746427465274662746727468274692747027471274722747327474274752747627477274782747927480274812748227483274842748527486274872748827489274902749127492274932749427495274962749727498274992750027501275022750327504275052750627507275082750927510275112751227513275142751527516275172751827519275202752127522275232752427525275262752727528275292753027531275322753327534275352753627537275382753927540275412754227543275442754527546275472754827549275502755127552275532755427555275562755727558275592756027561275622756327564275652756627567275682756927570275712757227573275742757527576275772757827579275802758127582275832758427585275862758727588275892759027591275922759327594275952759627597275982759927600276012760227603276042760527606276072760827609276102761127612276132761427615276162761727618276192762027621276222762327624276252762627627276282762927630276312763227633276342763527636276372763827639276402764127642276432764427645276462764727648276492765027651276522765327654276552765627657276582765927660276612766227663276642766527666276672766827669276702767127672276732767427675276762767727678276792768027681276822768327684276852768627687276882768927690276912769227693276942769527696276972769827699277002770127702277032770427705277062770727708277092771027711277122771327714277152771627717277182771927720277212772227723277242772527726277272772827729277302773127732277332773427735277362773727738277392774027741277422774327744277452774627747277482774927750277512775227753277542775527756277572775827759277602776127762277632776427765277662776727768277692777027771277722777327774277752777627777277782777927780277812778227783277842778527786277872778827789277902779127792277932779427795277962779727798277992780027801278022780327804278052780627807278082780927810278112781227813278142781527816278172781827819278202782127822278232782427825278262782727828278292783027831278322783327834278352783627837278382783927840278412784227843278442784527846278472784827849278502785127852278532785427855278562785727858278592786027861278622786327864278652786627867278682786927870278712787227873278742787527876278772787827879278802788127882278832788427885278862788727888278892789027891278922789327894278952789627897278982789927900279012790227903279042790527906279072790827909279102791127912279132791427915279162791727918279192792027921279222792327924279252792627927279282792927930279312793227933279342793527936279372793827939279402794127942279432794427945279462794727948279492795027951279522795327954279552795627957279582795927960279612796227963279642796527966279672796827969279702797127972279732797427975279762797727978279792798027981279822798327984279852798627987279882798927990279912799227993279942799527996279972799827999280002800128002280032800428005280062800728008280092801028011280122801328014280152801628017280182801928020280212802228023280242802528026280272802828029280302803128032280332803428035280362803728038280392804028041280422804328044280452804628047280482804928050280512805228053280542805528056280572805828059280602806128062280632806428065280662806728068280692807028071280722807328074280752807628077280782807928080280812808228083280842808528086280872808828089280902809128092280932809428095280962809728098280992810028101281022810328104281052810628107281082810928110281112811228113281142811528116281172811828119281202812128122281232812428125281262812728128281292813028131281322813328134281352813628137281382813928140281412814228143281442814528146281472814828149281502815128152281532815428155281562815728158281592816028161281622816328164281652816628167281682816928170281712817228173281742817528176281772817828179281802818128182281832818428185281862818728188281892819028191281922819328194281952819628197281982819928200282012820228203282042820528206282072820828209282102821128212282132821428215282162821728218282192822028221282222822328224282252822628227282282822928230282312823228233282342823528236282372823828239282402824128242282432824428245282462824728248282492825028251282522825328254282552825628257282582825928260282612826228263282642826528266282672826828269282702827128272282732827428275282762827728278282792828028281282822828328284282852828628287282882828928290282912829228293282942829528296282972829828299283002830128302283032830428305283062830728308283092831028311283122831328314283152831628317283182831928320283212832228323283242832528326283272832828329283302833128332283332833428335283362833728338283392834028341283422834328344283452834628347283482834928350283512835228353283542835528356283572835828359283602836128362283632836428365283662836728368283692837028371283722837328374283752837628377283782837928380283812838228383283842838528386283872838828389283902839128392283932839428395283962839728398283992840028401284022840328404284052840628407284082840928410284112841228413284142841528416284172841828419284202842128422284232842428425284262842728428284292843028431284322843328434284352843628437284382843928440284412844228443284442844528446284472844828449284502845128452284532845428455284562845728458284592846028461284622846328464284652846628467284682846928470284712847228473284742847528476284772847828479284802848128482284832848428485284862848728488284892849028491284922849328494284952849628497284982849928500285012850228503285042850528506285072850828509285102851128512285132851428515285162851728518285192852028521285222852328524285252852628527285282852928530285312853228533285342853528536285372853828539285402854128542285432854428545285462854728548285492855028551285522855328554285552855628557285582855928560285612856228563285642856528566285672856828569285702857128572285732857428575285762857728578285792858028581285822858328584285852858628587285882858928590285912859228593285942859528596285972859828599286002860128602286032860428605286062860728608286092861028611286122861328614286152861628617286182861928620286212862228623286242862528626286272862828629286302863128632286332863428635286362863728638286392864028641286422864328644286452864628647286482864928650286512865228653286542865528656286572865828659286602866128662286632866428665286662866728668286692867028671286722867328674286752867628677286782867928680286812868228683286842868528686286872868828689286902869128692286932869428695286962869728698286992870028701287022870328704287052870628707287082870928710287112871228713287142871528716287172871828719287202872128722287232872428725287262872728728287292873028731287322873328734287352873628737287382873928740287412874228743287442874528746287472874828749287502875128752287532875428755287562875728758287592876028761287622876328764287652876628767287682876928770287712877228773287742877528776287772877828779287802878128782287832878428785287862878728788287892879028791287922879328794287952879628797287982879928800288012880228803288042880528806288072880828809288102881128812288132881428815288162881728818288192882028821288222882328824288252882628827288282882928830288312883228833288342883528836288372883828839288402884128842288432884428845288462884728848288492885028851288522885328854288552885628857288582885928860288612886228863288642886528866288672886828869288702887128872288732887428875288762887728878288792888028881288822888328884288852888628887288882888928890288912889228893288942889528896288972889828899289002890128902289032890428905289062890728908289092891028911289122891328914289152891628917289182891928920289212892228923289242892528926289272892828929289302893128932289332893428935289362893728938289392894028941289422894328944289452894628947289482894928950289512895228953289542895528956289572895828959289602896128962289632896428965289662896728968289692897028971289722897328974289752897628977289782897928980289812898228983289842898528986289872898828989289902899128992289932899428995289962899728998289992900029001290022900329004290052900629007290082900929010290112901229013290142901529016290172901829019290202902129022290232902429025290262902729028290292903029031290322903329034290352903629037290382903929040290412904229043290442904529046290472904829049290502905129052290532905429055290562905729058290592906029061290622906329064290652906629067290682906929070290712907229073290742907529076290772907829079290802908129082290832908429085290862908729088290892909029091290922909329094290952909629097290982909929100291012910229103291042910529106291072910829109291102911129112291132911429115291162911729118291192912029121291222912329124291252912629127291282912929130291312913229133291342913529136291372913829139291402914129142291432914429145291462914729148291492915029151291522915329154291552915629157291582915929160291612916229163291642916529166291672916829169291702917129172291732917429175291762917729178291792918029181291822918329184291852918629187291882918929190291912919229193291942919529196291972919829199292002920129202292032920429205292062920729208292092921029211292122921329214292152921629217292182921929220292212922229223292242922529226292272922829229292302923129232292332923429235292362923729238292392924029241292422924329244292452924629247292482924929250292512925229253292542925529256292572925829259292602926129262292632926429265292662926729268292692927029271292722927329274292752927629277292782927929280292812928229283292842928529286292872928829289292902929129292292932929429295292962929729298292992930029301293022930329304293052930629307293082930929310293112931229313293142931529316293172931829319293202932129322293232932429325293262932729328293292933029331293322933329334293352933629337293382933929340293412934229343293442934529346293472934829349293502935129352293532935429355293562935729358293592936029361293622936329364293652936629367293682936929370293712937229373293742937529376293772937829379293802938129382293832938429385293862938729388293892939029391293922939329394293952939629397293982939929400294012940229403294042940529406294072940829409294102941129412294132941429415294162941729418294192942029421294222942329424294252942629427294282942929430294312943229433294342943529436294372943829439294402944129442294432944429445294462944729448294492945029451294522945329454294552945629457294582945929460294612946229463294642946529466294672946829469294702947129472294732947429475294762947729478294792948029481294822948329484294852948629487294882948929490294912949229493294942949529496294972949829499295002950129502295032950429505295062950729508295092951029511295122951329514295152951629517295182951929520295212952229523295242952529526295272952829529295302953129532295332953429535295362953729538295392954029541295422954329544295452954629547295482954929550295512955229553295542955529556295572955829559295602956129562295632956429565295662956729568295692957029571295722957329574295752957629577295782957929580295812958229583295842958529586295872958829589295902959129592295932959429595295962959729598295992960029601296022960329604296052960629607296082960929610296112961229613296142961529616296172961829619296202962129622296232962429625296262962729628296292963029631296322963329634296352963629637296382963929640296412964229643296442964529646296472964829649296502965129652296532965429655296562965729658296592966029661296622966329664296652966629667296682966929670296712967229673296742967529676296772967829679296802968129682296832968429685296862968729688296892969029691296922969329694296952969629697296982969929700297012970229703297042970529706297072970829709297102971129712297132971429715297162971729718297192972029721297222972329724297252972629727297282972929730297312973229733297342973529736297372973829739297402974129742297432974429745297462974729748297492975029751297522975329754297552975629757297582975929760297612976229763297642976529766297672976829769297702977129772297732977429775297762977729778297792978029781297822978329784297852978629787297882978929790297912979229793297942979529796297972979829799298002980129802298032980429805298062980729808298092981029811298122981329814298152981629817298182981929820298212982229823298242982529826298272982829829298302983129832298332983429835298362983729838298392984029841298422984329844298452984629847298482984929850298512985229853298542985529856298572985829859298602986129862298632986429865298662986729868298692987029871298722987329874298752987629877298782987929880298812988229883298842988529886298872988829889298902989129892298932989429895298962989729898298992990029901299022990329904299052990629907299082990929910299112991229913299142991529916299172991829919299202992129922299232992429925299262992729928299292993029931299322993329934299352993629937299382993929940299412994229943299442994529946299472994829949299502995129952299532995429955299562995729958299592996029961299622996329964299652996629967299682996929970299712997229973299742997529976299772997829979299802998129982299832998429985299862998729988299892999029991299922999329994299952999629997299982999930000300013000230003300043000530006300073000830009300103001130012300133001430015300163001730018300193002030021300223002330024300253002630027300283002930030300313003230033300343003530036300373003830039300403004130042300433004430045300463004730048300493005030051300523005330054300553005630057300583005930060300613006230063300643006530066300673006830069300703007130072300733007430075300763007730078300793008030081300823008330084300853008630087300883008930090300913009230093300943009530096300973009830099301003010130102301033010430105301063010730108301093011030111301123011330114301153011630117301183011930120301213012230123301243012530126301273012830129301303013130132301333013430135301363013730138301393014030141301423014330144301453014630147301483014930150301513015230153301543015530156301573015830159301603016130162301633016430165301663016730168301693017030171301723017330174301753017630177301783017930180301813018230183301843018530186301873018830189301903019130192301933019430195301963019730198301993020030201302023020330204302053020630207302083020930210302113021230213302143021530216302173021830219302203022130222302233022430225302263022730228302293023030231302323023330234302353023630237302383023930240302413024230243302443024530246302473024830249302503025130252302533025430255302563025730258302593026030261302623026330264302653026630267302683026930270302713027230273302743027530276302773027830279302803028130282302833028430285302863028730288302893029030291302923029330294302953029630297302983029930300303013030230303303043030530306303073030830309303103031130312303133031430315303163031730318303193032030321303223032330324303253032630327303283032930330303313033230333303343033530336303373033830339303403034130342303433034430345303463034730348303493035030351303523035330354303553035630357303583035930360303613036230363303643036530366303673036830369303703037130372303733037430375303763037730378303793038030381303823038330384303853038630387303883038930390303913039230393303943039530396303973039830399304003040130402304033040430405304063040730408304093041030411304123041330414304153041630417304183041930420304213042230423304243042530426304273042830429304303043130432304333043430435304363043730438304393044030441304423044330444304453044630447304483044930450304513045230453304543045530456304573045830459304603046130462304633046430465304663046730468304693047030471304723047330474304753047630477304783047930480304813048230483304843048530486304873048830489304903049130492304933049430495304963049730498304993050030501305023050330504305053050630507305083050930510305113051230513305143051530516305173051830519305203052130522305233052430525305263052730528305293053030531305323053330534305353053630537305383053930540305413054230543305443054530546305473054830549305503055130552305533055430555305563055730558305593056030561305623056330564305653056630567305683056930570305713057230573305743057530576305773057830579305803058130582305833058430585305863058730588305893059030591305923059330594305953059630597305983059930600306013060230603306043060530606306073060830609306103061130612306133061430615306163061730618306193062030621306223062330624306253062630627306283062930630306313063230633306343063530636306373063830639306403064130642306433064430645306463064730648306493065030651306523065330654306553065630657306583065930660306613066230663306643066530666306673066830669306703067130672306733067430675306763067730678306793068030681306823068330684306853068630687306883068930690306913069230693306943069530696306973069830699307003070130702307033070430705307063070730708307093071030711307123071330714307153071630717307183071930720307213072230723307243072530726307273072830729307303073130732307333073430735307363073730738307393074030741307423074330744307453074630747307483074930750307513075230753307543075530756307573075830759307603076130762307633076430765307663076730768307693077030771307723077330774307753077630777307783077930780307813078230783307843078530786307873078830789307903079130792307933079430795307963079730798307993080030801308023080330804308053080630807308083080930810308113081230813308143081530816308173081830819308203082130822308233082430825308263082730828308293083030831308323083330834308353083630837308383083930840308413084230843308443084530846308473084830849308503085130852308533085430855308563085730858308593086030861308623086330864308653086630867308683086930870308713087230873308743087530876308773087830879308803088130882308833088430885308863088730888308893089030891308923089330894308953089630897308983089930900309013090230903309043090530906309073090830909309103091130912309133091430915309163091730918309193092030921309223092330924309253092630927309283092930930309313093230933309343093530936309373093830939309403094130942309433094430945309463094730948309493095030951309523095330954309553095630957309583095930960309613096230963309643096530966309673096830969309703097130972309733097430975309763097730978309793098030981309823098330984309853098630987309883098930990309913099230993309943099530996309973099830999310003100131002310033100431005310063100731008310093101031011310123101331014310153101631017310183101931020310213102231023310243102531026310273102831029310303103131032310333103431035310363103731038310393104031041310423104331044310453104631047310483104931050310513105231053310543105531056310573105831059310603106131062310633106431065310663106731068310693107031071310723107331074310753107631077310783107931080310813108231083310843108531086310873108831089310903109131092310933109431095310963109731098310993110031101311023110331104311053110631107311083110931110311113111231113311143111531116311173111831119311203112131122311233112431125311263112731128311293113031131311323113331134311353113631137311383113931140311413114231143311443114531146311473114831149311503115131152311533115431155311563115731158311593116031161311623116331164311653116631167311683116931170311713117231173311743117531176311773117831179311803118131182311833118431185311863118731188311893119031191311923119331194311953119631197311983119931200312013120231203312043120531206312073120831209312103121131212312133121431215312163121731218312193122031221312223122331224312253122631227312283122931230312313123231233312343123531236312373123831239312403124131242312433124431245312463124731248312493125031251312523125331254312553125631257312583125931260312613126231263312643126531266312673126831269312703127131272312733127431275312763127731278312793128031281312823128331284312853128631287312883128931290312913129231293312943129531296312973129831299313003130131302313033130431305313063130731308313093131031311313123131331314313153131631317313183131931320313213132231323313243132531326313273132831329313303133131332313333133431335313363133731338313393134031341313423134331344313453134631347313483134931350313513135231353313543135531356313573135831359313603136131362313633136431365313663136731368313693137031371313723137331374313753137631377313783137931380313813138231383313843138531386313873138831389313903139131392313933139431395313963139731398313993140031401314023140331404314053140631407314083140931410314113141231413314143141531416314173141831419314203142131422314233142431425314263142731428314293143031431314323143331434314353143631437314383143931440314413144231443314443144531446314473144831449314503145131452314533145431455314563145731458314593146031461314623146331464314653146631467314683146931470314713147231473314743147531476314773147831479314803148131482314833148431485314863148731488314893149031491314923149331494314953149631497314983149931500315013150231503315043150531506315073150831509315103151131512315133151431515315163151731518315193152031521315223152331524315253152631527315283152931530315313153231533315343153531536315373153831539315403154131542315433154431545315463154731548315493155031551315523155331554315553155631557315583155931560315613156231563315643156531566315673156831569315703157131572315733157431575315763157731578315793158031581315823158331584315853158631587315883158931590315913159231593315943159531596315973159831599316003160131602316033160431605316063160731608316093161031611316123161331614316153161631617316183161931620316213162231623316243162531626316273162831629316303163131632316333163431635316363163731638316393164031641316423164331644316453164631647316483164931650316513165231653316543165531656316573165831659316603166131662316633166431665316663166731668316693167031671316723167331674316753167631677316783167931680316813168231683316843168531686316873168831689316903169131692316933169431695316963169731698316993170031701317023170331704317053170631707317083170931710317113171231713317143171531716317173171831719317203172131722317233172431725317263172731728317293173031731317323173331734317353173631737317383173931740317413174231743317443174531746317473174831749317503175131752317533175431755317563175731758317593176031761317623176331764317653176631767317683176931770317713177231773317743177531776317773177831779317803178131782317833178431785317863178731788317893179031791317923179331794317953179631797317983179931800318013180231803318043180531806318073180831809318103181131812318133181431815318163181731818318193182031821318223182331824318253182631827318283182931830318313183231833318343183531836318373183831839318403184131842318433184431845318463184731848318493185031851318523185331854318553185631857318583185931860318613186231863318643186531866318673186831869318703187131872318733187431875318763187731878318793188031881318823188331884318853188631887318883188931890318913189231893318943189531896318973189831899319003190131902319033190431905319063190731908319093191031911319123191331914319153191631917319183191931920319213192231923319243192531926319273192831929319303193131932319333193431935319363193731938319393194031941319423194331944319453194631947319483194931950319513195231953319543195531956319573195831959319603196131962319633196431965319663196731968319693197031971319723197331974319753197631977319783197931980319813198231983319843198531986319873198831989319903199131992319933199431995319963199731998319993200032001320023200332004320053200632007320083200932010320113201232013320143201532016320173201832019320203202132022320233202432025320263202732028320293203032031320323203332034320353203632037320383203932040320413204232043320443204532046320473204832049320503205132052320533205432055320563205732058320593206032061320623206332064320653206632067320683206932070320713207232073320743207532076320773207832079320803208132082320833208432085320863208732088320893209032091320923209332094320953209632097320983209932100321013210232103321043210532106321073210832109321103211132112321133211432115321163211732118321193212032121321223212332124321253212632127321283212932130321313213232133321343213532136321373213832139321403214132142321433214432145321463214732148321493215032151321523215332154321553215632157321583215932160321613216232163321643216532166321673216832169321703217132172321733217432175321763217732178321793218032181321823218332184321853218632187321883218932190321913219232193321943219532196321973219832199322003220132202322033220432205322063220732208322093221032211322123221332214322153221632217322183221932220322213222232223322243222532226322273222832229322303223132232322333223432235322363223732238322393224032241322423224332244322453224632247322483224932250322513225232253322543225532256322573225832259322603226132262322633226432265322663226732268322693227032271322723227332274322753227632277322783227932280322813228232283322843228532286322873228832289322903229132292322933229432295322963229732298322993230032301323023230332304323053230632307323083230932310323113231232313323143231532316323173231832319323203232132322323233232432325323263232732328323293233032331323323233332334323353233632337323383233932340323413234232343323443234532346323473234832349323503235132352323533235432355323563235732358323593236032361323623236332364323653236632367323683236932370323713237232373323743237532376323773237832379323803238132382323833238432385323863238732388323893239032391323923239332394323953239632397323983239932400324013240232403324043240532406324073240832409324103241132412324133241432415324163241732418324193242032421324223242332424324253242632427324283242932430324313243232433324343243532436324373243832439324403244132442324433244432445324463244732448324493245032451324523245332454324553245632457324583245932460324613246232463324643246532466324673246832469324703247132472324733247432475324763247732478324793248032481324823248332484324853248632487324883248932490324913249232493324943249532496324973249832499325003250132502325033250432505325063250732508325093251032511325123251332514325153251632517325183251932520325213252232523325243252532526325273252832529325303253132532325333253432535325363253732538325393254032541325423254332544325453254632547325483254932550325513255232553325543255532556325573255832559325603256132562325633256432565325663256732568325693257032571325723257332574325753257632577325783257932580325813258232583325843258532586325873258832589325903259132592325933259432595325963259732598325993260032601326023260332604326053260632607326083260932610326113261232613326143261532616326173261832619326203262132622326233262432625326263262732628326293263032631
  1. apiVersion: apiextensions.k8s.io/v1
  2. kind: CustomResourceDefinition
  3. metadata:
  4. annotations:
  5. controller-gen.kubebuilder.io/version: v0.19.0
  6. labels:
  7. external-secrets.io/component: controller
  8. name: clusterexternalsecrets.external-secrets.io
  9. spec:
  10. group: external-secrets.io
  11. names:
  12. categories:
  13. - external-secrets
  14. kind: ClusterExternalSecret
  15. listKind: ClusterExternalSecretList
  16. plural: clusterexternalsecrets
  17. shortNames:
  18. - ces
  19. singular: clusterexternalsecret
  20. scope: Cluster
  21. versions:
  22. - additionalPrinterColumns:
  23. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  24. name: Store
  25. type: string
  26. - jsonPath: .spec.refreshTime
  27. name: Refresh Interval
  28. type: string
  29. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  30. name: Ready
  31. type: string
  32. name: v1
  33. schema:
  34. openAPIV3Schema:
  35. description: ClusterExternalSecret is the Schema for the clusterexternalsecrets API.
  36. properties:
  37. apiVersion:
  38. description: |-
  39. APIVersion defines the versioned schema of this representation of an object.
  40. Servers should convert recognized schemas to the latest internal value, and
  41. may reject unrecognized values.
  42. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  43. type: string
  44. kind:
  45. description: |-
  46. Kind is a string value representing the REST resource this object represents.
  47. Servers may infer this from the endpoint the client submits requests to.
  48. Cannot be updated.
  49. In CamelCase.
  50. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  51. type: string
  52. metadata:
  53. type: object
  54. spec:
  55. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  56. properties:
  57. externalSecretMetadata:
  58. description: The metadata of the external secrets to be created
  59. properties:
  60. annotations:
  61. additionalProperties:
  62. type: string
  63. type: object
  64. labels:
  65. additionalProperties:
  66. type: string
  67. type: object
  68. type: object
  69. externalSecretName:
  70. description: |-
  71. The name of the external secrets to be created.
  72. Defaults to the name of the ClusterExternalSecret
  73. maxLength: 253
  74. minLength: 1
  75. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  76. type: string
  77. externalSecretSpec:
  78. description: The spec for the ExternalSecrets to be created
  79. properties:
  80. data:
  81. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  82. items:
  83. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  84. properties:
  85. remoteRef:
  86. description: |-
  87. RemoteRef points to the remote secret and defines
  88. which secret (version/property/..) to fetch.
  89. properties:
  90. conversionStrategy:
  91. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  92. enum:
  93. - Default
  94. - Unicode
  95. type: string
  96. decodingStrategy:
  97. description: Used to define a decoding Strategy. Defaults to None when omitted.
  98. enum:
  99. - Auto
  100. - Base64
  101. - Base64URL
  102. - None
  103. type: string
  104. key:
  105. description: Key is the key used in the Provider, mandatory
  106. type: string
  107. metadataPolicy:
  108. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  109. enum:
  110. - None
  111. - Fetch
  112. type: string
  113. nullBytePolicy:
  114. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  115. enum:
  116. - Ignore
  117. - Fail
  118. type: string
  119. property:
  120. description: Used to select a specific property of the Provider value (if a map), if supported
  121. type: string
  122. version:
  123. description: Used to select a specific version of the Provider value, if supported
  124. type: string
  125. required:
  126. - key
  127. type: object
  128. secretKey:
  129. description: The key in the Kubernetes Secret to store the value.
  130. maxLength: 253
  131. minLength: 1
  132. pattern: ^[-._a-zA-Z0-9]+$
  133. type: string
  134. sourceRef:
  135. description: |-
  136. SourceRef allows you to override the source
  137. from which the value will be pulled.
  138. maxProperties: 1
  139. minProperties: 1
  140. properties:
  141. generatorRef:
  142. description: |-
  143. GeneratorRef points to a generator custom resource.
  144. Deprecated: The generatorRef is not implemented in .data[].
  145. this will be removed with v1.
  146. properties:
  147. apiVersion:
  148. default: generators.external-secrets.io/v1alpha1
  149. description: Specify the apiVersion of the generator resource
  150. type: string
  151. kind:
  152. description: Specify the Kind of the generator resource
  153. enum:
  154. - ACRAccessToken
  155. - BeyondtrustWorkloadCredentialsDynamicSecret
  156. - ClusterGenerator
  157. - CloudsmithAccessToken
  158. - ECRAuthorizationToken
  159. - Fake
  160. - GCRAccessToken
  161. - GithubAccessToken
  162. - GitlabDeployToken
  163. - QuayAccessToken
  164. - Password
  165. - SSHKey
  166. - STSSessionToken
  167. - UUID
  168. - VaultDynamicSecret
  169. - Webhook
  170. - Grafana
  171. - MFA
  172. type: string
  173. name:
  174. description: Specify the name of the generator resource
  175. maxLength: 253
  176. minLength: 1
  177. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  178. type: string
  179. required:
  180. - kind
  181. - name
  182. type: object
  183. storeRef:
  184. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  185. properties:
  186. kind:
  187. description: |-
  188. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  189. Defaults to `SecretStore`
  190. enum:
  191. - SecretStore
  192. - ClusterSecretStore
  193. type: string
  194. name:
  195. description: Name of the SecretStore resource
  196. maxLength: 253
  197. minLength: 1
  198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  199. type: string
  200. type: object
  201. type: object
  202. required:
  203. - remoteRef
  204. - secretKey
  205. type: object
  206. type: array
  207. dataFrom:
  208. description: |-
  209. DataFrom is used to fetch all properties from a specific Provider data
  210. If multiple entries are specified, the Secret keys are merged in the specified order
  211. items:
  212. description: |-
  213. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  214. when using DataFrom to fetch multiple values from a Provider.
  215. properties:
  216. extract:
  217. description: |-
  218. Used to extract multiple key/value pairs from one secret
  219. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  220. properties:
  221. conversionStrategy:
  222. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  223. enum:
  224. - Default
  225. - Unicode
  226. type: string
  227. decodingStrategy:
  228. description: Used to define a decoding Strategy. Defaults to None when omitted.
  229. enum:
  230. - Auto
  231. - Base64
  232. - Base64URL
  233. - None
  234. type: string
  235. key:
  236. description: Key is the key used in the Provider, mandatory
  237. type: string
  238. metadataPolicy:
  239. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  240. enum:
  241. - None
  242. - Fetch
  243. type: string
  244. nullBytePolicy:
  245. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  246. enum:
  247. - Ignore
  248. - Fail
  249. type: string
  250. property:
  251. description: Used to select a specific property of the Provider value (if a map), if supported
  252. type: string
  253. version:
  254. description: Used to select a specific version of the Provider value, if supported
  255. type: string
  256. required:
  257. - key
  258. type: object
  259. find:
  260. description: |-
  261. Used to find secrets based on tags or regular expressions
  262. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  263. properties:
  264. conversionStrategy:
  265. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  266. enum:
  267. - Default
  268. - Unicode
  269. type: string
  270. decodingStrategy:
  271. description: Used to define a decoding Strategy. Defaults to None when omitted.
  272. enum:
  273. - Auto
  274. - Base64
  275. - Base64URL
  276. - None
  277. type: string
  278. name:
  279. description: Finds secrets based on the name.
  280. properties:
  281. regexp:
  282. description: Finds secrets base
  283. type: string
  284. type: object
  285. nullBytePolicy:
  286. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  287. enum:
  288. - Ignore
  289. - Fail
  290. type: string
  291. path:
  292. description: A root path to start the find operations.
  293. type: string
  294. tags:
  295. additionalProperties:
  296. type: string
  297. description: Find secrets based on tags.
  298. type: object
  299. type: object
  300. rewrite:
  301. description: |-
  302. Used to rewrite secret Keys after getting them from the secret Provider
  303. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  304. items:
  305. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  306. maxProperties: 1
  307. minProperties: 1
  308. properties:
  309. merge:
  310. description: |-
  311. Used to merge key/values in one single Secret
  312. The resulting key will contain all values from the specified secrets
  313. properties:
  314. conflictPolicy:
  315. default: Error
  316. description: Used to define the policy to use in conflict resolution.
  317. enum:
  318. - Ignore
  319. - Error
  320. type: string
  321. into:
  322. default: ""
  323. description: |-
  324. Used to define the target key of the merge operation.
  325. Required if strategy is JSON. Ignored otherwise.
  326. type: string
  327. priority:
  328. description: Used to define key priority in conflict resolution.
  329. items:
  330. type: string
  331. type: array
  332. priorityPolicy:
  333. default: Strict
  334. description: Used to define the policy when a key in the priority list does not exist in the input.
  335. enum:
  336. - IgnoreNotFound
  337. - Strict
  338. type: string
  339. strategy:
  340. default: Extract
  341. description: Used to define the strategy to use in the merge operation.
  342. enum:
  343. - Extract
  344. - JSON
  345. type: string
  346. type: object
  347. regexp:
  348. description: |-
  349. Used to rewrite with regular expressions.
  350. The resulting key will be the output of a regexp.ReplaceAll operation.
  351. properties:
  352. source:
  353. description: Used to define the regular expression of a re.Compiler.
  354. type: string
  355. target:
  356. description: Used to define the target pattern of a ReplaceAll operation.
  357. type: string
  358. required:
  359. - source
  360. - target
  361. type: object
  362. transform:
  363. description: |-
  364. Used to apply string transformation on the secrets.
  365. The resulting key will be the output of the template applied by the operation.
  366. properties:
  367. template:
  368. description: |-
  369. Used to define the template to apply on the secret name.
  370. `.value ` will specify the secret name in the template.
  371. type: string
  372. required:
  373. - template
  374. type: object
  375. type: object
  376. type: array
  377. sourceRef:
  378. description: |-
  379. SourceRef points to a store or generator
  380. which contains secret values ready to use.
  381. Use this in combination with Extract or Find pull values out of
  382. a specific SecretStore.
  383. When sourceRef points to a generator Extract or Find is not supported.
  384. The generator returns a static map of values
  385. maxProperties: 1
  386. minProperties: 1
  387. properties:
  388. generatorRef:
  389. description: GeneratorRef points to a generator custom resource.
  390. properties:
  391. apiVersion:
  392. default: generators.external-secrets.io/v1alpha1
  393. description: Specify the apiVersion of the generator resource
  394. type: string
  395. kind:
  396. description: Specify the Kind of the generator resource
  397. enum:
  398. - ACRAccessToken
  399. - BeyondtrustWorkloadCredentialsDynamicSecret
  400. - ClusterGenerator
  401. - CloudsmithAccessToken
  402. - ECRAuthorizationToken
  403. - Fake
  404. - GCRAccessToken
  405. - GithubAccessToken
  406. - GitlabDeployToken
  407. - QuayAccessToken
  408. - Password
  409. - SSHKey
  410. - STSSessionToken
  411. - UUID
  412. - VaultDynamicSecret
  413. - Webhook
  414. - Grafana
  415. - MFA
  416. type: string
  417. name:
  418. description: Specify the name of the generator resource
  419. maxLength: 253
  420. minLength: 1
  421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  422. type: string
  423. required:
  424. - kind
  425. - name
  426. type: object
  427. storeRef:
  428. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  429. properties:
  430. kind:
  431. description: |-
  432. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  433. Defaults to `SecretStore`
  434. enum:
  435. - SecretStore
  436. - ClusterSecretStore
  437. type: string
  438. name:
  439. description: Name of the SecretStore resource
  440. maxLength: 253
  441. minLength: 1
  442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  443. type: string
  444. type: object
  445. type: object
  446. type: object
  447. type: array
  448. refreshInterval:
  449. default: 1h0m0s
  450. description: |-
  451. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  452. specified as Golang Duration strings.
  453. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  454. Example values: "1h0m0s", "2h30m0s", "10m0s"
  455. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  456. type: string
  457. refreshPolicy:
  458. description: |-
  459. RefreshPolicy determines how the ExternalSecret should be refreshed:
  460. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  461. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  462. No periodic updates occur if refreshInterval is 0.
  463. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  464. enum:
  465. - CreatedOnce
  466. - Periodic
  467. - OnChange
  468. type: string
  469. secretStoreRef:
  470. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  471. properties:
  472. kind:
  473. description: |-
  474. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  475. Defaults to `SecretStore`
  476. enum:
  477. - SecretStore
  478. - ClusterSecretStore
  479. type: string
  480. name:
  481. description: Name of the SecretStore resource
  482. maxLength: 253
  483. minLength: 1
  484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  485. type: string
  486. type: object
  487. syncWindows:
  488. description: |-
  489. SyncWindows optionally restricts when periodic refreshes may occur.
  490. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  491. properties:
  492. kind:
  493. description: |-
  494. Kind applies to every window in the list.
  495. "allow" -- syncs are permitted only while at least one window is active;
  496. all other times are blocked.
  497. "deny" -- syncs are blocked while any window is active;
  498. all other times are permitted.
  499. enum:
  500. - allow
  501. - deny
  502. type: string
  503. windows:
  504. description: Windows is the list of schedule+duration pairs.
  505. items:
  506. description: |-
  507. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  508. within a SyncWindows block.
  509. properties:
  510. duration:
  511. description: |-
  512. Duration specifies how long the window stays open after each Schedule
  513. firing. Example: "8h".
  514. type: string
  515. schedule:
  516. description: |-
  517. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  518. named shorthand such as @daily or @every 1h. It marks the start time of
  519. each window occurrence.
  520. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  521. minLength: 1
  522. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  523. type: string
  524. required:
  525. - duration
  526. - schedule
  527. type: object
  528. minItems: 1
  529. type: array
  530. required:
  531. - kind
  532. - windows
  533. type: object
  534. target:
  535. default:
  536. creationPolicy: Owner
  537. deletionPolicy: Retain
  538. description: |-
  539. ExternalSecretTarget defines the Kubernetes Secret to be created,
  540. there can be only one target per ExternalSecret.
  541. properties:
  542. creationPolicy:
  543. default: Owner
  544. description: |-
  545. CreationPolicy defines rules on how to create the resulting Secret.
  546. Defaults to "Owner"
  547. enum:
  548. - Owner
  549. - Orphan
  550. - Merge
  551. - None
  552. - CreateOrMerge
  553. type: string
  554. deletionPolicy:
  555. default: Retain
  556. description: |-
  557. DeletionPolicy defines rules on how to delete the resulting Secret.
  558. Defaults to "Retain"
  559. enum:
  560. - Delete
  561. - Merge
  562. - Retain
  563. type: string
  564. immutable:
  565. description: Immutable defines if the final secret will be immutable
  566. type: boolean
  567. manifest:
  568. description: |-
  569. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  570. When specified, ExternalSecret will create the resource type defined here
  571. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  572. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  573. properties:
  574. apiVersion:
  575. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  576. minLength: 1
  577. type: string
  578. kind:
  579. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  580. minLength: 1
  581. type: string
  582. required:
  583. - apiVersion
  584. - kind
  585. type: object
  586. name:
  587. description: |-
  588. The name of the Secret resource to be managed.
  589. Defaults to the .metadata.name of the ExternalSecret resource
  590. maxLength: 253
  591. minLength: 1
  592. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  593. type: string
  594. template:
  595. description: Template defines a blueprint for the created Secret resource.
  596. properties:
  597. data:
  598. additionalProperties:
  599. type: string
  600. type: object
  601. engineVersion:
  602. default: v2
  603. description: |-
  604. EngineVersion specifies the template engine version
  605. that should be used to compile/execute the
  606. template specified in .data and .templateFrom[].
  607. enum:
  608. - v2
  609. type: string
  610. mergePolicy:
  611. default: Replace
  612. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  613. enum:
  614. - Replace
  615. - Merge
  616. type: string
  617. metadata:
  618. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  619. properties:
  620. annotations:
  621. additionalProperties:
  622. type: string
  623. type: object
  624. finalizers:
  625. items:
  626. type: string
  627. type: array
  628. labels:
  629. additionalProperties:
  630. type: string
  631. type: object
  632. type: object
  633. templateFrom:
  634. items:
  635. description: |-
  636. TemplateFrom specifies a source for templates.
  637. Each item in the list can either reference a ConfigMap or a Secret resource.
  638. properties:
  639. configMap:
  640. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  641. properties:
  642. items:
  643. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  644. items:
  645. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  646. properties:
  647. key:
  648. description: A key in the ConfigMap/Secret
  649. maxLength: 253
  650. minLength: 1
  651. pattern: ^[-._a-zA-Z0-9]+$
  652. type: string
  653. templateAs:
  654. default: Values
  655. description: TemplateScope specifies how the template keys should be interpreted.
  656. enum:
  657. - Values
  658. - KeysAndValues
  659. type: string
  660. required:
  661. - key
  662. type: object
  663. type: array
  664. name:
  665. description: The name of the ConfigMap/Secret resource
  666. maxLength: 253
  667. minLength: 1
  668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  669. type: string
  670. required:
  671. - items
  672. - name
  673. type: object
  674. literal:
  675. type: string
  676. secret:
  677. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  678. properties:
  679. items:
  680. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  681. items:
  682. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  683. properties:
  684. key:
  685. description: A key in the ConfigMap/Secret
  686. maxLength: 253
  687. minLength: 1
  688. pattern: ^[-._a-zA-Z0-9]+$
  689. type: string
  690. templateAs:
  691. default: Values
  692. description: TemplateScope specifies how the template keys should be interpreted.
  693. enum:
  694. - Values
  695. - KeysAndValues
  696. type: string
  697. required:
  698. - key
  699. type: object
  700. type: array
  701. name:
  702. description: The name of the ConfigMap/Secret resource
  703. maxLength: 253
  704. minLength: 1
  705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  706. type: string
  707. required:
  708. - items
  709. - name
  710. type: object
  711. target:
  712. default: Data
  713. description: |-
  714. Target specifies where to place the template result.
  715. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  716. any other value is rejected because it would allow writes to privileged Secret fields.
  717. For custom resources (when spec.target.manifest is set), this supports
  718. nested paths like "spec.database.config" or "data".
  719. type: string
  720. valuesDecodingStrategy:
  721. description: |-
  722. Used to define a decoding Strategy for the rendered template values.
  723. Defaults to None when omitted.
  724. enum:
  725. - Auto
  726. - Base64
  727. - Base64URL
  728. - None
  729. type: string
  730. type: object
  731. type: array
  732. type:
  733. type: string
  734. type: object
  735. type: object
  736. type: object
  737. namespaceSelector:
  738. description: |-
  739. The labels to select by to find the Namespaces to create the ExternalSecrets in.
  740. Deprecated: Use NamespaceSelectors instead.
  741. properties:
  742. matchExpressions:
  743. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  744. items:
  745. description: |-
  746. A label selector requirement is a selector that contains values, a key, and an operator that
  747. relates the key and values.
  748. properties:
  749. key:
  750. description: key is the label key that the selector applies to.
  751. type: string
  752. operator:
  753. description: |-
  754. operator represents a key's relationship to a set of values.
  755. Valid operators are In, NotIn, Exists and DoesNotExist.
  756. type: string
  757. values:
  758. description: |-
  759. values is an array of string values. If the operator is In or NotIn,
  760. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  761. the values array must be empty. This array is replaced during a strategic
  762. merge patch.
  763. items:
  764. type: string
  765. type: array
  766. x-kubernetes-list-type: atomic
  767. required:
  768. - key
  769. - operator
  770. type: object
  771. type: array
  772. x-kubernetes-list-type: atomic
  773. matchLabels:
  774. additionalProperties:
  775. type: string
  776. description: |-
  777. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  778. map is equivalent to an element of matchExpressions, whose key field is "key", the
  779. operator is "In", and the values array contains only "value". The requirements are ANDed.
  780. type: object
  781. type: object
  782. x-kubernetes-map-type: atomic
  783. namespaceSelectors:
  784. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  785. items:
  786. description: |-
  787. A label selector is a label query over a set of resources. The result of matchLabels and
  788. matchExpressions are ANDed. An empty label selector matches all objects. A null
  789. label selector matches no objects.
  790. properties:
  791. matchExpressions:
  792. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  793. items:
  794. description: |-
  795. A label selector requirement is a selector that contains values, a key, and an operator that
  796. relates the key and values.
  797. properties:
  798. key:
  799. description: key is the label key that the selector applies to.
  800. type: string
  801. operator:
  802. description: |-
  803. operator represents a key's relationship to a set of values.
  804. Valid operators are In, NotIn, Exists and DoesNotExist.
  805. type: string
  806. values:
  807. description: |-
  808. values is an array of string values. If the operator is In or NotIn,
  809. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  810. the values array must be empty. This array is replaced during a strategic
  811. merge patch.
  812. items:
  813. type: string
  814. type: array
  815. x-kubernetes-list-type: atomic
  816. required:
  817. - key
  818. - operator
  819. type: object
  820. type: array
  821. x-kubernetes-list-type: atomic
  822. matchLabels:
  823. additionalProperties:
  824. type: string
  825. description: |-
  826. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  827. map is equivalent to an element of matchExpressions, whose key field is "key", the
  828. operator is "In", and the values array contains only "value". The requirements are ANDed.
  829. type: object
  830. type: object
  831. x-kubernetes-map-type: atomic
  832. type: array
  833. namespaces:
  834. description: |-
  835. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  836. Deprecated: Use NamespaceSelectors instead.
  837. items:
  838. maxLength: 63
  839. minLength: 1
  840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  841. type: string
  842. type: array
  843. refreshTime:
  844. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  845. type: string
  846. required:
  847. - externalSecretSpec
  848. type: object
  849. status:
  850. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  851. properties:
  852. conditions:
  853. items:
  854. description: ClusterExternalSecretStatusCondition defines the observed state of a ClusterExternalSecret resource.
  855. properties:
  856. message:
  857. type: string
  858. status:
  859. type: string
  860. type:
  861. description: ClusterExternalSecretConditionType defines a value type for ClusterExternalSecret conditions.
  862. type: string
  863. required:
  864. - status
  865. - type
  866. type: object
  867. type: array
  868. externalSecretName:
  869. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  870. type: string
  871. failedNamespaces:
  872. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  873. items:
  874. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  875. properties:
  876. namespace:
  877. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  878. type: string
  879. reason:
  880. description: Reason is why the ExternalSecret failed to apply to the namespace
  881. type: string
  882. required:
  883. - namespace
  884. type: object
  885. type: array
  886. provisionedNamespaces:
  887. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  888. items:
  889. type: string
  890. type: array
  891. type: object
  892. type: object
  893. served: true
  894. storage: true
  895. subresources:
  896. status: {}
  897. - additionalPrinterColumns:
  898. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  899. name: Store
  900. type: string
  901. - jsonPath: .spec.refreshTime
  902. name: Refresh Interval
  903. type: string
  904. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  905. name: Ready
  906. type: string
  907. deprecated: true
  908. name: v1beta1
  909. schema:
  910. openAPIV3Schema:
  911. description: ClusterExternalSecret is the schema for the clusterexternalsecrets API.
  912. properties:
  913. apiVersion:
  914. description: |-
  915. APIVersion defines the versioned schema of this representation of an object.
  916. Servers should convert recognized schemas to the latest internal value, and
  917. may reject unrecognized values.
  918. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  919. type: string
  920. kind:
  921. description: |-
  922. Kind is a string value representing the REST resource this object represents.
  923. Servers may infer this from the endpoint the client submits requests to.
  924. Cannot be updated.
  925. In CamelCase.
  926. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  927. type: string
  928. metadata:
  929. type: object
  930. spec:
  931. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  932. properties:
  933. externalSecretMetadata:
  934. description: The metadata of the external secrets to be created
  935. properties:
  936. annotations:
  937. additionalProperties:
  938. type: string
  939. type: object
  940. labels:
  941. additionalProperties:
  942. type: string
  943. type: object
  944. type: object
  945. externalSecretName:
  946. description: |-
  947. The name of the external secrets to be created.
  948. Defaults to the name of the ClusterExternalSecret
  949. maxLength: 253
  950. minLength: 1
  951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  952. type: string
  953. externalSecretSpec:
  954. description: The spec for the ExternalSecrets to be created
  955. properties:
  956. data:
  957. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  958. items:
  959. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  960. properties:
  961. remoteRef:
  962. description: |-
  963. RemoteRef points to the remote secret and defines
  964. which secret (version/property/..) to fetch.
  965. properties:
  966. conversionStrategy:
  967. default: Default
  968. description: Used to define a conversion Strategy
  969. enum:
  970. - Default
  971. - Unicode
  972. type: string
  973. decodingStrategy:
  974. default: None
  975. description: Used to define a decoding Strategy
  976. enum:
  977. - Auto
  978. - Base64
  979. - Base64URL
  980. - None
  981. type: string
  982. key:
  983. description: Key is the key used in the Provider, mandatory
  984. type: string
  985. metadataPolicy:
  986. default: None
  987. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  988. enum:
  989. - None
  990. - Fetch
  991. type: string
  992. property:
  993. description: Used to select a specific property of the Provider value (if a map), if supported
  994. type: string
  995. version:
  996. description: Used to select a specific version of the Provider value, if supported
  997. type: string
  998. required:
  999. - key
  1000. type: object
  1001. secretKey:
  1002. description: The key in the Kubernetes Secret to store the value.
  1003. maxLength: 253
  1004. minLength: 1
  1005. pattern: ^[-._a-zA-Z0-9]+$
  1006. type: string
  1007. sourceRef:
  1008. description: |-
  1009. SourceRef allows you to override the source
  1010. from which the value will be pulled.
  1011. maxProperties: 1
  1012. minProperties: 1
  1013. properties:
  1014. generatorRef:
  1015. description: |-
  1016. GeneratorRef points to a generator custom resource.
  1017. Deprecated: The generatorRef is not implemented in .data[].
  1018. this will be removed with v1.
  1019. properties:
  1020. apiVersion:
  1021. default: generators.external-secrets.io/v1alpha1
  1022. description: Specify the apiVersion of the generator resource
  1023. type: string
  1024. kind:
  1025. description: Specify the Kind of the generator resource
  1026. enum:
  1027. - ACRAccessToken
  1028. - ClusterGenerator
  1029. - ECRAuthorizationToken
  1030. - Fake
  1031. - GCRAccessToken
  1032. - GithubAccessToken
  1033. - QuayAccessToken
  1034. - Password
  1035. - SSHKey
  1036. - STSSessionToken
  1037. - UUID
  1038. - VaultDynamicSecret
  1039. - Webhook
  1040. - Grafana
  1041. type: string
  1042. name:
  1043. description: Specify the name of the generator resource
  1044. maxLength: 253
  1045. minLength: 1
  1046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1047. type: string
  1048. required:
  1049. - kind
  1050. - name
  1051. type: object
  1052. storeRef:
  1053. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1054. properties:
  1055. kind:
  1056. description: |-
  1057. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1058. Defaults to `SecretStore`
  1059. enum:
  1060. - SecretStore
  1061. - ClusterSecretStore
  1062. type: string
  1063. name:
  1064. description: Name of the SecretStore resource
  1065. maxLength: 253
  1066. minLength: 1
  1067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1068. type: string
  1069. type: object
  1070. type: object
  1071. required:
  1072. - remoteRef
  1073. - secretKey
  1074. type: object
  1075. type: array
  1076. dataFrom:
  1077. description: |-
  1078. DataFrom is used to fetch all properties from a specific Provider data
  1079. If multiple entries are specified, the Secret keys are merged in the specified order
  1080. items:
  1081. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  1082. properties:
  1083. extract:
  1084. description: |-
  1085. Used to extract multiple key/value pairs from one secret
  1086. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1087. properties:
  1088. conversionStrategy:
  1089. default: Default
  1090. description: Used to define a conversion Strategy
  1091. enum:
  1092. - Default
  1093. - Unicode
  1094. type: string
  1095. decodingStrategy:
  1096. default: None
  1097. description: Used to define a decoding Strategy
  1098. enum:
  1099. - Auto
  1100. - Base64
  1101. - Base64URL
  1102. - None
  1103. type: string
  1104. key:
  1105. description: Key is the key used in the Provider, mandatory
  1106. type: string
  1107. metadataPolicy:
  1108. default: None
  1109. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  1110. enum:
  1111. - None
  1112. - Fetch
  1113. type: string
  1114. property:
  1115. description: Used to select a specific property of the Provider value (if a map), if supported
  1116. type: string
  1117. version:
  1118. description: Used to select a specific version of the Provider value, if supported
  1119. type: string
  1120. required:
  1121. - key
  1122. type: object
  1123. find:
  1124. description: |-
  1125. Used to find secrets based on tags or regular expressions
  1126. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1127. properties:
  1128. conversionStrategy:
  1129. default: Default
  1130. description: Used to define a conversion Strategy
  1131. enum:
  1132. - Default
  1133. - Unicode
  1134. type: string
  1135. decodingStrategy:
  1136. default: None
  1137. description: Used to define a decoding Strategy
  1138. enum:
  1139. - Auto
  1140. - Base64
  1141. - Base64URL
  1142. - None
  1143. type: string
  1144. name:
  1145. description: Finds secrets based on the name.
  1146. properties:
  1147. regexp:
  1148. description: Finds secrets base
  1149. type: string
  1150. type: object
  1151. path:
  1152. description: A root path to start the find operations.
  1153. type: string
  1154. tags:
  1155. additionalProperties:
  1156. type: string
  1157. description: Find secrets based on tags.
  1158. type: object
  1159. type: object
  1160. rewrite:
  1161. description: |-
  1162. Used to rewrite secret Keys after getting them from the secret Provider
  1163. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  1164. items:
  1165. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  1166. maxProperties: 1
  1167. minProperties: 1
  1168. properties:
  1169. regexp:
  1170. description: |-
  1171. Used to rewrite with regular expressions.
  1172. The resulting key will be the output of a regexp.ReplaceAll operation.
  1173. properties:
  1174. source:
  1175. description: Used to define the regular expression of a re.Compiler.
  1176. type: string
  1177. target:
  1178. description: Used to define the target pattern of a ReplaceAll operation.
  1179. type: string
  1180. required:
  1181. - source
  1182. - target
  1183. type: object
  1184. transform:
  1185. description: |-
  1186. Used to apply string transformation on the secrets.
  1187. The resulting key will be the output of the template applied by the operation.
  1188. properties:
  1189. template:
  1190. description: |-
  1191. Used to define the template to apply on the secret name.
  1192. `.value ` will specify the secret name in the template.
  1193. type: string
  1194. required:
  1195. - template
  1196. type: object
  1197. type: object
  1198. type: array
  1199. sourceRef:
  1200. description: |-
  1201. SourceRef points to a store or generator
  1202. which contains secret values ready to use.
  1203. Use this in combination with Extract or Find pull values out of
  1204. a specific SecretStore.
  1205. When sourceRef points to a generator Extract or Find is not supported.
  1206. The generator returns a static map of values
  1207. maxProperties: 1
  1208. minProperties: 1
  1209. properties:
  1210. generatorRef:
  1211. description: GeneratorRef points to a generator custom resource.
  1212. properties:
  1213. apiVersion:
  1214. default: generators.external-secrets.io/v1alpha1
  1215. description: Specify the apiVersion of the generator resource
  1216. type: string
  1217. kind:
  1218. description: Specify the Kind of the generator resource
  1219. enum:
  1220. - ACRAccessToken
  1221. - ClusterGenerator
  1222. - ECRAuthorizationToken
  1223. - Fake
  1224. - GCRAccessToken
  1225. - GithubAccessToken
  1226. - QuayAccessToken
  1227. - Password
  1228. - SSHKey
  1229. - STSSessionToken
  1230. - UUID
  1231. - VaultDynamicSecret
  1232. - Webhook
  1233. - Grafana
  1234. type: string
  1235. name:
  1236. description: Specify the name of the generator resource
  1237. maxLength: 253
  1238. minLength: 1
  1239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1240. type: string
  1241. required:
  1242. - kind
  1243. - name
  1244. type: object
  1245. storeRef:
  1246. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1247. properties:
  1248. kind:
  1249. description: |-
  1250. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1251. Defaults to `SecretStore`
  1252. enum:
  1253. - SecretStore
  1254. - ClusterSecretStore
  1255. type: string
  1256. name:
  1257. description: Name of the SecretStore resource
  1258. maxLength: 253
  1259. minLength: 1
  1260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1261. type: string
  1262. type: object
  1263. type: object
  1264. type: object
  1265. type: array
  1266. refreshInterval:
  1267. default: 1h0m0s
  1268. description: |-
  1269. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  1270. specified as Golang Duration strings.
  1271. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  1272. Example values: "1h0m0s", "2h30m0s", "10m0s"
  1273. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  1274. type: string
  1275. refreshPolicy:
  1276. description: |-
  1277. RefreshPolicy determines how the ExternalSecret should be refreshed:
  1278. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  1279. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  1280. No periodic updates occur if refreshInterval is 0.
  1281. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  1282. enum:
  1283. - CreatedOnce
  1284. - Periodic
  1285. - OnChange
  1286. type: string
  1287. secretStoreRef:
  1288. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1289. properties:
  1290. kind:
  1291. description: |-
  1292. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1293. Defaults to `SecretStore`
  1294. enum:
  1295. - SecretStore
  1296. - ClusterSecretStore
  1297. type: string
  1298. name:
  1299. description: Name of the SecretStore resource
  1300. maxLength: 253
  1301. minLength: 1
  1302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1303. type: string
  1304. type: object
  1305. target:
  1306. default:
  1307. creationPolicy: Owner
  1308. deletionPolicy: Retain
  1309. description: |-
  1310. ExternalSecretTarget defines the Kubernetes Secret to be created
  1311. There can be only one target per ExternalSecret.
  1312. properties:
  1313. creationPolicy:
  1314. default: Owner
  1315. description: |-
  1316. CreationPolicy defines rules on how to create the resulting Secret.
  1317. Defaults to "Owner"
  1318. enum:
  1319. - Owner
  1320. - Orphan
  1321. - Merge
  1322. - None
  1323. type: string
  1324. deletionPolicy:
  1325. default: Retain
  1326. description: |-
  1327. DeletionPolicy defines rules on how to delete the resulting Secret.
  1328. Defaults to "Retain"
  1329. enum:
  1330. - Delete
  1331. - Merge
  1332. - Retain
  1333. type: string
  1334. immutable:
  1335. description: Immutable defines if the final secret will be immutable
  1336. type: boolean
  1337. name:
  1338. description: |-
  1339. The name of the Secret resource to be managed.
  1340. Defaults to the .metadata.name of the ExternalSecret resource
  1341. maxLength: 253
  1342. minLength: 1
  1343. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1344. type: string
  1345. template:
  1346. description: Template defines a blueprint for the created Secret resource.
  1347. properties:
  1348. data:
  1349. additionalProperties:
  1350. type: string
  1351. type: object
  1352. engineVersion:
  1353. default: v2
  1354. description: |-
  1355. EngineVersion specifies the template engine version
  1356. that should be used to compile/execute the
  1357. template specified in .data and .templateFrom[].
  1358. enum:
  1359. - v2
  1360. type: string
  1361. mergePolicy:
  1362. default: Replace
  1363. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  1364. enum:
  1365. - Replace
  1366. - Merge
  1367. type: string
  1368. metadata:
  1369. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  1370. properties:
  1371. annotations:
  1372. additionalProperties:
  1373. type: string
  1374. type: object
  1375. labels:
  1376. additionalProperties:
  1377. type: string
  1378. type: object
  1379. type: object
  1380. templateFrom:
  1381. items:
  1382. description: TemplateFrom defines a source for template data.
  1383. properties:
  1384. configMap:
  1385. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1386. properties:
  1387. items:
  1388. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1389. items:
  1390. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1391. properties:
  1392. key:
  1393. description: A key in the ConfigMap/Secret
  1394. maxLength: 253
  1395. minLength: 1
  1396. pattern: ^[-._a-zA-Z0-9]+$
  1397. type: string
  1398. templateAs:
  1399. default: Values
  1400. description: TemplateScope defines the scope of the template when processing template data.
  1401. enum:
  1402. - Values
  1403. - KeysAndValues
  1404. type: string
  1405. required:
  1406. - key
  1407. type: object
  1408. type: array
  1409. name:
  1410. description: The name of the ConfigMap/Secret resource
  1411. maxLength: 253
  1412. minLength: 1
  1413. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1414. type: string
  1415. required:
  1416. - items
  1417. - name
  1418. type: object
  1419. literal:
  1420. type: string
  1421. secret:
  1422. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1423. properties:
  1424. items:
  1425. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1426. items:
  1427. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1428. properties:
  1429. key:
  1430. description: A key in the ConfigMap/Secret
  1431. maxLength: 253
  1432. minLength: 1
  1433. pattern: ^[-._a-zA-Z0-9]+$
  1434. type: string
  1435. templateAs:
  1436. default: Values
  1437. description: TemplateScope defines the scope of the template when processing template data.
  1438. enum:
  1439. - Values
  1440. - KeysAndValues
  1441. type: string
  1442. required:
  1443. - key
  1444. type: object
  1445. type: array
  1446. name:
  1447. description: The name of the ConfigMap/Secret resource
  1448. maxLength: 253
  1449. minLength: 1
  1450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1451. type: string
  1452. required:
  1453. - items
  1454. - name
  1455. type: object
  1456. target:
  1457. default: Data
  1458. description: TemplateTarget defines the target field where the template result will be stored.
  1459. enum:
  1460. - Data
  1461. - Annotations
  1462. - Labels
  1463. type: string
  1464. type: object
  1465. type: array
  1466. type:
  1467. type: string
  1468. type: object
  1469. type: object
  1470. type: object
  1471. namespaceSelector:
  1472. description: The labels to select by to find the Namespaces to create the ExternalSecrets in
  1473. properties:
  1474. matchExpressions:
  1475. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1476. items:
  1477. description: |-
  1478. A label selector requirement is a selector that contains values, a key, and an operator that
  1479. relates the key and values.
  1480. properties:
  1481. key:
  1482. description: key is the label key that the selector applies to.
  1483. type: string
  1484. operator:
  1485. description: |-
  1486. operator represents a key's relationship to a set of values.
  1487. Valid operators are In, NotIn, Exists and DoesNotExist.
  1488. type: string
  1489. values:
  1490. description: |-
  1491. values is an array of string values. If the operator is In or NotIn,
  1492. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1493. the values array must be empty. This array is replaced during a strategic
  1494. merge patch.
  1495. items:
  1496. type: string
  1497. type: array
  1498. x-kubernetes-list-type: atomic
  1499. required:
  1500. - key
  1501. - operator
  1502. type: object
  1503. type: array
  1504. x-kubernetes-list-type: atomic
  1505. matchLabels:
  1506. additionalProperties:
  1507. type: string
  1508. description: |-
  1509. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1510. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1511. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1512. type: object
  1513. type: object
  1514. x-kubernetes-map-type: atomic
  1515. namespaceSelectors:
  1516. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1517. items:
  1518. description: |-
  1519. A label selector is a label query over a set of resources. The result of matchLabels and
  1520. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1521. label selector matches no objects.
  1522. properties:
  1523. matchExpressions:
  1524. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1525. items:
  1526. description: |-
  1527. A label selector requirement is a selector that contains values, a key, and an operator that
  1528. relates the key and values.
  1529. properties:
  1530. key:
  1531. description: key is the label key that the selector applies to.
  1532. type: string
  1533. operator:
  1534. description: |-
  1535. operator represents a key's relationship to a set of values.
  1536. Valid operators are In, NotIn, Exists and DoesNotExist.
  1537. type: string
  1538. values:
  1539. description: |-
  1540. values is an array of string values. If the operator is In or NotIn,
  1541. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1542. the values array must be empty. This array is replaced during a strategic
  1543. merge patch.
  1544. items:
  1545. type: string
  1546. type: array
  1547. x-kubernetes-list-type: atomic
  1548. required:
  1549. - key
  1550. - operator
  1551. type: object
  1552. type: array
  1553. x-kubernetes-list-type: atomic
  1554. matchLabels:
  1555. additionalProperties:
  1556. type: string
  1557. description: |-
  1558. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1559. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1560. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1561. type: object
  1562. type: object
  1563. x-kubernetes-map-type: atomic
  1564. type: array
  1565. namespaces:
  1566. description: |-
  1567. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  1568. Deprecated: Use NamespaceSelectors instead.
  1569. items:
  1570. maxLength: 63
  1571. minLength: 1
  1572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1573. type: string
  1574. type: array
  1575. refreshTime:
  1576. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  1577. type: string
  1578. required:
  1579. - externalSecretSpec
  1580. type: object
  1581. status:
  1582. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  1583. properties:
  1584. conditions:
  1585. items:
  1586. description: ClusterExternalSecretStatusCondition indicates the status of the ClusterExternalSecret.
  1587. properties:
  1588. message:
  1589. type: string
  1590. status:
  1591. type: string
  1592. type:
  1593. description: ClusterExternalSecretConditionType indicates the condition of the ClusterExternalSecret.
  1594. type: string
  1595. required:
  1596. - status
  1597. - type
  1598. type: object
  1599. type: array
  1600. externalSecretName:
  1601. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  1602. type: string
  1603. failedNamespaces:
  1604. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  1605. items:
  1606. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  1607. properties:
  1608. namespace:
  1609. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  1610. type: string
  1611. reason:
  1612. description: Reason is why the ExternalSecret failed to apply to the namespace
  1613. type: string
  1614. required:
  1615. - namespace
  1616. type: object
  1617. type: array
  1618. provisionedNamespaces:
  1619. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  1620. items:
  1621. type: string
  1622. type: array
  1623. type: object
  1624. type: object
  1625. served: false
  1626. storage: false
  1627. subresources:
  1628. status: {}
  1629. ---
  1630. apiVersion: apiextensions.k8s.io/v1
  1631. kind: CustomResourceDefinition
  1632. metadata:
  1633. annotations:
  1634. controller-gen.kubebuilder.io/version: v0.19.0
  1635. labels:
  1636. external-secrets.io/component: controller
  1637. name: clusterpushsecrets.external-secrets.io
  1638. spec:
  1639. group: external-secrets.io
  1640. names:
  1641. categories:
  1642. - external-secrets
  1643. kind: ClusterPushSecret
  1644. listKind: ClusterPushSecretList
  1645. plural: clusterpushsecrets
  1646. singular: clusterpushsecret
  1647. scope: Cluster
  1648. versions:
  1649. - additionalPrinterColumns:
  1650. - jsonPath: .metadata.creationTimestamp
  1651. name: AGE
  1652. type: date
  1653. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  1654. name: Status
  1655. type: string
  1656. name: v1alpha1
  1657. schema:
  1658. openAPIV3Schema:
  1659. description: ClusterPushSecret is the Schema for the ClusterPushSecrets API that enables cluster-wide management of pushing Kubernetes secrets to external providers.
  1660. properties:
  1661. apiVersion:
  1662. description: |-
  1663. APIVersion defines the versioned schema of this representation of an object.
  1664. Servers should convert recognized schemas to the latest internal value, and
  1665. may reject unrecognized values.
  1666. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  1667. type: string
  1668. kind:
  1669. description: |-
  1670. Kind is a string value representing the REST resource this object represents.
  1671. Servers may infer this from the endpoint the client submits requests to.
  1672. Cannot be updated.
  1673. In CamelCase.
  1674. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  1675. type: string
  1676. metadata:
  1677. type: object
  1678. spec:
  1679. description: ClusterPushSecretSpec defines the configuration for a ClusterPushSecret resource.
  1680. properties:
  1681. namespaceSelectors:
  1682. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1683. items:
  1684. description: |-
  1685. A label selector is a label query over a set of resources. The result of matchLabels and
  1686. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1687. label selector matches no objects.
  1688. properties:
  1689. matchExpressions:
  1690. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1691. items:
  1692. description: |-
  1693. A label selector requirement is a selector that contains values, a key, and an operator that
  1694. relates the key and values.
  1695. properties:
  1696. key:
  1697. description: key is the label key that the selector applies to.
  1698. type: string
  1699. operator:
  1700. description: |-
  1701. operator represents a key's relationship to a set of values.
  1702. Valid operators are In, NotIn, Exists and DoesNotExist.
  1703. type: string
  1704. values:
  1705. description: |-
  1706. values is an array of string values. If the operator is In or NotIn,
  1707. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1708. the values array must be empty. This array is replaced during a strategic
  1709. merge patch.
  1710. items:
  1711. type: string
  1712. type: array
  1713. x-kubernetes-list-type: atomic
  1714. required:
  1715. - key
  1716. - operator
  1717. type: object
  1718. type: array
  1719. x-kubernetes-list-type: atomic
  1720. matchLabels:
  1721. additionalProperties:
  1722. type: string
  1723. description: |-
  1724. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1725. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1726. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1727. type: object
  1728. type: object
  1729. x-kubernetes-map-type: atomic
  1730. type: array
  1731. pushSecretMetadata:
  1732. description: The metadata of the external secrets to be created
  1733. properties:
  1734. annotations:
  1735. additionalProperties:
  1736. type: string
  1737. type: object
  1738. labels:
  1739. additionalProperties:
  1740. type: string
  1741. type: object
  1742. type: object
  1743. pushSecretName:
  1744. description: |-
  1745. The name of the push secrets to be created.
  1746. Defaults to the name of the ClusterPushSecret
  1747. maxLength: 253
  1748. minLength: 1
  1749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1750. type: string
  1751. pushSecretSpec:
  1752. description: PushSecretSpec defines what to do with the secrets.
  1753. properties:
  1754. data:
  1755. description: Secret Data that should be pushed to providers
  1756. items:
  1757. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  1758. properties:
  1759. conversionStrategy:
  1760. default: None
  1761. description: Used to define a conversion Strategy for the secret keys
  1762. enum:
  1763. - None
  1764. - ReverseUnicode
  1765. type: string
  1766. match:
  1767. description: Match a given Secret Key to be pushed to the provider.
  1768. properties:
  1769. remoteRef:
  1770. description: Remote Refs to push to providers.
  1771. properties:
  1772. property:
  1773. description: Name of the property in the resulting secret
  1774. type: string
  1775. remoteKey:
  1776. description: Name of the resulting provider secret.
  1777. type: string
  1778. required:
  1779. - remoteKey
  1780. type: object
  1781. secretKey:
  1782. description: Secret Key to be pushed
  1783. type: string
  1784. required:
  1785. - remoteRef
  1786. type: object
  1787. metadata:
  1788. description: |-
  1789. Metadata is metadata attached to the secret.
  1790. The structure of metadata is provider specific, please look it up in the provider documentation.
  1791. x-kubernetes-preserve-unknown-fields: true
  1792. required:
  1793. - match
  1794. type: object
  1795. type: array
  1796. dataTo:
  1797. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  1798. items:
  1799. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  1800. properties:
  1801. conversionStrategy:
  1802. default: None
  1803. description: Used to define a conversion Strategy for the secret keys
  1804. enum:
  1805. - None
  1806. - ReverseUnicode
  1807. type: string
  1808. match:
  1809. description: |-
  1810. Match pattern for selecting keys from the source Secret.
  1811. If not specified, all keys are selected.
  1812. properties:
  1813. regexp:
  1814. description: |-
  1815. Regexp matches keys by regular expression.
  1816. If not specified, all keys are matched.
  1817. type: string
  1818. type: object
  1819. metadata:
  1820. description: |-
  1821. Metadata is metadata attached to the secret.
  1822. The structure of metadata is provider specific, please look it up in the provider documentation.
  1823. x-kubernetes-preserve-unknown-fields: true
  1824. remoteKey:
  1825. description: |-
  1826. RemoteKey is the name of the single provider secret that will receive ALL
  1827. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  1828. When set, per-key expansion is skipped and a single push is performed.
  1829. The provider's store prefix (if any) is still prepended to this value.
  1830. When not set, each matched key is pushed as its own individual provider secret.
  1831. type: string
  1832. rewrite:
  1833. description: |-
  1834. Rewrite operations to transform keys before pushing to the provider.
  1835. Operations are applied sequentially.
  1836. items:
  1837. description: PushSecretRewrite defines how to transform secret keys before pushing.
  1838. properties:
  1839. regexp:
  1840. description: Used to rewrite with regular expressions.
  1841. properties:
  1842. source:
  1843. description: Used to define the regular expression of a re.Compiler.
  1844. type: string
  1845. target:
  1846. description: Used to define the target pattern of a ReplaceAll operation.
  1847. type: string
  1848. required:
  1849. - source
  1850. - target
  1851. type: object
  1852. transform:
  1853. description: Used to apply string transformation on the secrets.
  1854. properties:
  1855. template:
  1856. description: |-
  1857. Used to define the template to apply on the secret name.
  1858. `.value ` will specify the secret name in the template.
  1859. type: string
  1860. required:
  1861. - template
  1862. type: object
  1863. type: object
  1864. x-kubernetes-validations:
  1865. - message: exactly one of regexp or transform must be set
  1866. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  1867. type: array
  1868. storeRef:
  1869. description: StoreRef specifies which SecretStore to push to. Required.
  1870. properties:
  1871. kind:
  1872. default: SecretStore
  1873. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1874. enum:
  1875. - SecretStore
  1876. - ClusterSecretStore
  1877. type: string
  1878. labelSelector:
  1879. description: Optionally, sync to secret stores with label selector
  1880. properties:
  1881. matchExpressions:
  1882. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1883. items:
  1884. description: |-
  1885. A label selector requirement is a selector that contains values, a key, and an operator that
  1886. relates the key and values.
  1887. properties:
  1888. key:
  1889. description: key is the label key that the selector applies to.
  1890. type: string
  1891. operator:
  1892. description: |-
  1893. operator represents a key's relationship to a set of values.
  1894. Valid operators are In, NotIn, Exists and DoesNotExist.
  1895. type: string
  1896. values:
  1897. description: |-
  1898. values is an array of string values. If the operator is In or NotIn,
  1899. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1900. the values array must be empty. This array is replaced during a strategic
  1901. merge patch.
  1902. items:
  1903. type: string
  1904. type: array
  1905. x-kubernetes-list-type: atomic
  1906. required:
  1907. - key
  1908. - operator
  1909. type: object
  1910. type: array
  1911. x-kubernetes-list-type: atomic
  1912. matchLabels:
  1913. additionalProperties:
  1914. type: string
  1915. description: |-
  1916. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1917. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1918. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1919. type: object
  1920. type: object
  1921. x-kubernetes-map-type: atomic
  1922. name:
  1923. description: Optionally, sync to the SecretStore of the given name
  1924. maxLength: 253
  1925. minLength: 1
  1926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1927. type: string
  1928. type: object
  1929. type: object
  1930. x-kubernetes-validations:
  1931. - message: storeRef must specify either name or labelSelector
  1932. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  1933. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  1934. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  1935. type: array
  1936. deletionPolicy:
  1937. default: None
  1938. description: Deletion Policy to handle Secrets in the provider.
  1939. enum:
  1940. - Delete
  1941. - None
  1942. type: string
  1943. refreshInterval:
  1944. default: 1h0m0s
  1945. description: The Interval to which External Secrets will try to push a secret definition
  1946. type: string
  1947. secretStoreRefs:
  1948. items:
  1949. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  1950. properties:
  1951. kind:
  1952. default: SecretStore
  1953. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1954. enum:
  1955. - SecretStore
  1956. - ClusterSecretStore
  1957. type: string
  1958. labelSelector:
  1959. description: Optionally, sync to secret stores with label selector
  1960. properties:
  1961. matchExpressions:
  1962. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1963. items:
  1964. description: |-
  1965. A label selector requirement is a selector that contains values, a key, and an operator that
  1966. relates the key and values.
  1967. properties:
  1968. key:
  1969. description: key is the label key that the selector applies to.
  1970. type: string
  1971. operator:
  1972. description: |-
  1973. operator represents a key's relationship to a set of values.
  1974. Valid operators are In, NotIn, Exists and DoesNotExist.
  1975. type: string
  1976. values:
  1977. description: |-
  1978. values is an array of string values. If the operator is In or NotIn,
  1979. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1980. the values array must be empty. This array is replaced during a strategic
  1981. merge patch.
  1982. items:
  1983. type: string
  1984. type: array
  1985. x-kubernetes-list-type: atomic
  1986. required:
  1987. - key
  1988. - operator
  1989. type: object
  1990. type: array
  1991. x-kubernetes-list-type: atomic
  1992. matchLabels:
  1993. additionalProperties:
  1994. type: string
  1995. description: |-
  1996. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1997. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1998. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1999. type: object
  2000. type: object
  2001. x-kubernetes-map-type: atomic
  2002. name:
  2003. description: Optionally, sync to the SecretStore of the given name
  2004. maxLength: 253
  2005. minLength: 1
  2006. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2007. type: string
  2008. type: object
  2009. type: array
  2010. selector:
  2011. description: The Secret Selector (k8s source) for the Push Secret
  2012. maxProperties: 1
  2013. minProperties: 1
  2014. properties:
  2015. generatorRef:
  2016. description: Point to a generator to create a Secret.
  2017. properties:
  2018. apiVersion:
  2019. default: generators.external-secrets.io/v1alpha1
  2020. description: Specify the apiVersion of the generator resource
  2021. type: string
  2022. kind:
  2023. description: Specify the Kind of the generator resource
  2024. enum:
  2025. - ACRAccessToken
  2026. - BeyondtrustWorkloadCredentialsDynamicSecret
  2027. - ClusterGenerator
  2028. - CloudsmithAccessToken
  2029. - ECRAuthorizationToken
  2030. - Fake
  2031. - GCRAccessToken
  2032. - GithubAccessToken
  2033. - GitlabDeployToken
  2034. - QuayAccessToken
  2035. - Password
  2036. - SSHKey
  2037. - STSSessionToken
  2038. - UUID
  2039. - VaultDynamicSecret
  2040. - Webhook
  2041. - Grafana
  2042. - MFA
  2043. type: string
  2044. name:
  2045. description: Specify the name of the generator resource
  2046. maxLength: 253
  2047. minLength: 1
  2048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2049. type: string
  2050. required:
  2051. - kind
  2052. - name
  2053. type: object
  2054. secret:
  2055. description: Select a Secret to Push.
  2056. properties:
  2057. name:
  2058. description: |-
  2059. Name of the Secret.
  2060. The Secret must exist in the same namespace as the PushSecret manifest.
  2061. maxLength: 253
  2062. minLength: 1
  2063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2064. type: string
  2065. selector:
  2066. description: Selector chooses secrets using a labelSelector.
  2067. properties:
  2068. matchExpressions:
  2069. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2070. items:
  2071. description: |-
  2072. A label selector requirement is a selector that contains values, a key, and an operator that
  2073. relates the key and values.
  2074. properties:
  2075. key:
  2076. description: key is the label key that the selector applies to.
  2077. type: string
  2078. operator:
  2079. description: |-
  2080. operator represents a key's relationship to a set of values.
  2081. Valid operators are In, NotIn, Exists and DoesNotExist.
  2082. type: string
  2083. values:
  2084. description: |-
  2085. values is an array of string values. If the operator is In or NotIn,
  2086. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2087. the values array must be empty. This array is replaced during a strategic
  2088. merge patch.
  2089. items:
  2090. type: string
  2091. type: array
  2092. x-kubernetes-list-type: atomic
  2093. required:
  2094. - key
  2095. - operator
  2096. type: object
  2097. type: array
  2098. x-kubernetes-list-type: atomic
  2099. matchLabels:
  2100. additionalProperties:
  2101. type: string
  2102. description: |-
  2103. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2104. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2105. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2106. type: object
  2107. type: object
  2108. x-kubernetes-map-type: atomic
  2109. type: object
  2110. type: object
  2111. template:
  2112. description: Template defines a blueprint for the created Secret resource.
  2113. properties:
  2114. data:
  2115. additionalProperties:
  2116. type: string
  2117. type: object
  2118. engineVersion:
  2119. default: v2
  2120. description: |-
  2121. EngineVersion specifies the template engine version
  2122. that should be used to compile/execute the
  2123. template specified in .data and .templateFrom[].
  2124. enum:
  2125. - v2
  2126. type: string
  2127. mergePolicy:
  2128. default: Replace
  2129. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  2130. enum:
  2131. - Replace
  2132. - Merge
  2133. type: string
  2134. metadata:
  2135. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  2136. properties:
  2137. annotations:
  2138. additionalProperties:
  2139. type: string
  2140. type: object
  2141. finalizers:
  2142. items:
  2143. type: string
  2144. type: array
  2145. labels:
  2146. additionalProperties:
  2147. type: string
  2148. type: object
  2149. type: object
  2150. templateFrom:
  2151. items:
  2152. description: |-
  2153. TemplateFrom specifies a source for templates.
  2154. Each item in the list can either reference a ConfigMap or a Secret resource.
  2155. properties:
  2156. configMap:
  2157. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2158. properties:
  2159. items:
  2160. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2161. items:
  2162. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2163. properties:
  2164. key:
  2165. description: A key in the ConfigMap/Secret
  2166. maxLength: 253
  2167. minLength: 1
  2168. pattern: ^[-._a-zA-Z0-9]+$
  2169. type: string
  2170. templateAs:
  2171. default: Values
  2172. description: TemplateScope specifies how the template keys should be interpreted.
  2173. enum:
  2174. - Values
  2175. - KeysAndValues
  2176. type: string
  2177. required:
  2178. - key
  2179. type: object
  2180. type: array
  2181. name:
  2182. description: The name of the ConfigMap/Secret resource
  2183. maxLength: 253
  2184. minLength: 1
  2185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2186. type: string
  2187. required:
  2188. - items
  2189. - name
  2190. type: object
  2191. literal:
  2192. type: string
  2193. secret:
  2194. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2195. properties:
  2196. items:
  2197. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2198. items:
  2199. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2200. properties:
  2201. key:
  2202. description: A key in the ConfigMap/Secret
  2203. maxLength: 253
  2204. minLength: 1
  2205. pattern: ^[-._a-zA-Z0-9]+$
  2206. type: string
  2207. templateAs:
  2208. default: Values
  2209. description: TemplateScope specifies how the template keys should be interpreted.
  2210. enum:
  2211. - Values
  2212. - KeysAndValues
  2213. type: string
  2214. required:
  2215. - key
  2216. type: object
  2217. type: array
  2218. name:
  2219. description: The name of the ConfigMap/Secret resource
  2220. maxLength: 253
  2221. minLength: 1
  2222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2223. type: string
  2224. required:
  2225. - items
  2226. - name
  2227. type: object
  2228. target:
  2229. default: Data
  2230. description: |-
  2231. Target specifies where to place the template result.
  2232. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  2233. any other value is rejected because it would allow writes to privileged Secret fields.
  2234. For custom resources (when spec.target.manifest is set), this supports
  2235. nested paths like "spec.database.config" or "data".
  2236. type: string
  2237. valuesDecodingStrategy:
  2238. description: |-
  2239. Used to define a decoding Strategy for the rendered template values.
  2240. Defaults to None when omitted.
  2241. enum:
  2242. - Auto
  2243. - Base64
  2244. - Base64URL
  2245. - None
  2246. type: string
  2247. type: object
  2248. type: array
  2249. type:
  2250. type: string
  2251. type: object
  2252. updatePolicy:
  2253. default: Replace
  2254. description: UpdatePolicy to handle Secrets in the provider.
  2255. enum:
  2256. - Replace
  2257. - IfNotExists
  2258. type: string
  2259. required:
  2260. - secretStoreRefs
  2261. - selector
  2262. type: object
  2263. refreshTime:
  2264. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  2265. type: string
  2266. required:
  2267. - pushSecretSpec
  2268. type: object
  2269. status:
  2270. description: ClusterPushSecretStatus contains the status information for the ClusterPushSecret resource.
  2271. properties:
  2272. conditions:
  2273. items:
  2274. description: PushSecretStatusCondition indicates the status of the PushSecret.
  2275. properties:
  2276. lastTransitionTime:
  2277. format: date-time
  2278. type: string
  2279. message:
  2280. type: string
  2281. reason:
  2282. type: string
  2283. status:
  2284. type: string
  2285. type:
  2286. description: PushSecretConditionType indicates the condition of the PushSecret.
  2287. type: string
  2288. required:
  2289. - status
  2290. - type
  2291. type: object
  2292. type: array
  2293. failedNamespaces:
  2294. description: Failed namespaces are the namespaces that failed to apply an PushSecret
  2295. items:
  2296. description: ClusterPushSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  2297. properties:
  2298. namespace:
  2299. description: Namespace is the namespace that failed when trying to apply an PushSecret
  2300. type: string
  2301. reason:
  2302. description: Reason is why the PushSecret failed to apply to the namespace
  2303. type: string
  2304. required:
  2305. - namespace
  2306. type: object
  2307. type: array
  2308. provisionedNamespaces:
  2309. description: ProvisionedNamespaces are the namespaces where the ClusterPushSecret has secrets
  2310. items:
  2311. type: string
  2312. type: array
  2313. pushSecretName:
  2314. type: string
  2315. type: object
  2316. type: object
  2317. served: true
  2318. storage: true
  2319. subresources:
  2320. status: {}
  2321. ---
  2322. apiVersion: apiextensions.k8s.io/v1
  2323. kind: CustomResourceDefinition
  2324. metadata:
  2325. annotations:
  2326. controller-gen.kubebuilder.io/version: v0.19.0
  2327. labels:
  2328. external-secrets.io/component: controller
  2329. name: clustersecretstores.external-secrets.io
  2330. spec:
  2331. group: external-secrets.io
  2332. names:
  2333. categories:
  2334. - external-secrets
  2335. kind: ClusterSecretStore
  2336. listKind: ClusterSecretStoreList
  2337. plural: clustersecretstores
  2338. shortNames:
  2339. - css
  2340. singular: clustersecretstore
  2341. scope: Cluster
  2342. versions:
  2343. - additionalPrinterColumns:
  2344. - jsonPath: .metadata.creationTimestamp
  2345. name: AGE
  2346. type: date
  2347. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  2348. name: Status
  2349. type: string
  2350. - jsonPath: .status.capabilities
  2351. name: Capabilities
  2352. type: string
  2353. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  2354. name: Ready
  2355. type: string
  2356. name: v1
  2357. schema:
  2358. openAPIV3Schema:
  2359. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  2360. properties:
  2361. apiVersion:
  2362. description: |-
  2363. APIVersion defines the versioned schema of this representation of an object.
  2364. Servers should convert recognized schemas to the latest internal value, and
  2365. may reject unrecognized values.
  2366. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  2367. type: string
  2368. kind:
  2369. description: |-
  2370. Kind is a string value representing the REST resource this object represents.
  2371. Servers may infer this from the endpoint the client submits requests to.
  2372. Cannot be updated.
  2373. In CamelCase.
  2374. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  2375. type: string
  2376. metadata:
  2377. type: object
  2378. spec:
  2379. description: SecretStoreSpec defines the desired state of SecretStore.
  2380. properties:
  2381. conditions:
  2382. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  2383. items:
  2384. description: |-
  2385. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  2386. for a ClusterSecretStore instance.
  2387. properties:
  2388. namespaceRegexes:
  2389. description: Choose namespaces by using regex matching
  2390. items:
  2391. type: string
  2392. type: array
  2393. namespaceSelector:
  2394. description: Choose namespace using a labelSelector
  2395. properties:
  2396. matchExpressions:
  2397. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2398. items:
  2399. description: |-
  2400. A label selector requirement is a selector that contains values, a key, and an operator that
  2401. relates the key and values.
  2402. properties:
  2403. key:
  2404. description: key is the label key that the selector applies to.
  2405. type: string
  2406. operator:
  2407. description: |-
  2408. operator represents a key's relationship to a set of values.
  2409. Valid operators are In, NotIn, Exists and DoesNotExist.
  2410. type: string
  2411. values:
  2412. description: |-
  2413. values is an array of string values. If the operator is In or NotIn,
  2414. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2415. the values array must be empty. This array is replaced during a strategic
  2416. merge patch.
  2417. items:
  2418. type: string
  2419. type: array
  2420. x-kubernetes-list-type: atomic
  2421. required:
  2422. - key
  2423. - operator
  2424. type: object
  2425. type: array
  2426. x-kubernetes-list-type: atomic
  2427. matchLabels:
  2428. additionalProperties:
  2429. type: string
  2430. description: |-
  2431. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2432. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2433. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2434. type: object
  2435. type: object
  2436. x-kubernetes-map-type: atomic
  2437. namespaces:
  2438. description: Choose namespaces by name
  2439. items:
  2440. maxLength: 63
  2441. minLength: 1
  2442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2443. type: string
  2444. type: array
  2445. type: object
  2446. type: array
  2447. controller:
  2448. description: |-
  2449. Used to select the correct ESO controller (think: ingress.ingressClassName)
  2450. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  2451. type: string
  2452. provider:
  2453. description: Used to configure the provider. Only one provider may be set
  2454. maxProperties: 1
  2455. minProperties: 1
  2456. properties:
  2457. akeyless:
  2458. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  2459. properties:
  2460. akeylessGWApiURL:
  2461. description: Akeyless GW API Url from which the secrets to be fetched from.
  2462. type: string
  2463. authSecretRef:
  2464. description: Auth configures how the operator authenticates with Akeyless.
  2465. properties:
  2466. kubernetesAuth:
  2467. description: |-
  2468. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  2469. token stored in the named Secret resource.
  2470. properties:
  2471. accessID:
  2472. description: the Akeyless Kubernetes auth-method access-id
  2473. type: string
  2474. k8sConfName:
  2475. description: Kubernetes-auth configuration name in Akeyless-Gateway
  2476. type: string
  2477. secretRef:
  2478. description: |-
  2479. Optional secret field containing a Kubernetes ServiceAccount JWT used
  2480. for authenticating with Akeyless. If a name is specified without a key,
  2481. `token` is the default. If one is not specified, the one bound to
  2482. the controller will be used.
  2483. properties:
  2484. key:
  2485. description: |-
  2486. A key in the referenced Secret.
  2487. Some instances of this field may be defaulted, in others it may be required.
  2488. maxLength: 253
  2489. minLength: 1
  2490. pattern: ^[-._a-zA-Z0-9]+$
  2491. type: string
  2492. name:
  2493. description: The name of the Secret resource being referred to.
  2494. maxLength: 253
  2495. minLength: 1
  2496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2497. type: string
  2498. namespace:
  2499. description: |-
  2500. The namespace of the Secret resource being referred to.
  2501. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2502. maxLength: 63
  2503. minLength: 1
  2504. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2505. type: string
  2506. type: object
  2507. serviceAccountRef:
  2508. description: |-
  2509. Optional service account field containing the name of a kubernetes ServiceAccount.
  2510. If the service account is specified, the service account secret token JWT will be used
  2511. for authenticating with Akeyless. If the service account selector is not supplied,
  2512. the secretRef will be used instead.
  2513. properties:
  2514. audiences:
  2515. description: |-
  2516. Audience specifies the `aud` claim for the service account token
  2517. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2518. then this audiences will be appended to the list
  2519. items:
  2520. type: string
  2521. type: array
  2522. name:
  2523. description: The name of the ServiceAccount resource being referred to.
  2524. maxLength: 253
  2525. minLength: 1
  2526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2527. type: string
  2528. namespace:
  2529. description: |-
  2530. Namespace of the resource being referred to.
  2531. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2532. maxLength: 63
  2533. minLength: 1
  2534. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2535. type: string
  2536. required:
  2537. - name
  2538. type: object
  2539. required:
  2540. - accessID
  2541. - k8sConfName
  2542. type: object
  2543. secretRef:
  2544. description: |-
  2545. Reference to a Secret that contains the details
  2546. to authenticate with Akeyless.
  2547. properties:
  2548. accessID:
  2549. description: The SecretAccessID is used for authentication
  2550. properties:
  2551. key:
  2552. description: |-
  2553. A key in the referenced Secret.
  2554. Some instances of this field may be defaulted, in others it may be required.
  2555. maxLength: 253
  2556. minLength: 1
  2557. pattern: ^[-._a-zA-Z0-9]+$
  2558. type: string
  2559. name:
  2560. description: The name of the Secret resource being referred to.
  2561. maxLength: 253
  2562. minLength: 1
  2563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2564. type: string
  2565. namespace:
  2566. description: |-
  2567. The namespace of the Secret resource being referred to.
  2568. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2569. maxLength: 63
  2570. minLength: 1
  2571. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2572. type: string
  2573. type: object
  2574. accessType:
  2575. description: |-
  2576. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2577. In some instances, `key` is a required field.
  2578. properties:
  2579. key:
  2580. description: |-
  2581. A key in the referenced Secret.
  2582. Some instances of this field may be defaulted, in others it may be required.
  2583. maxLength: 253
  2584. minLength: 1
  2585. pattern: ^[-._a-zA-Z0-9]+$
  2586. type: string
  2587. name:
  2588. description: The name of the Secret resource being referred to.
  2589. maxLength: 253
  2590. minLength: 1
  2591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2592. type: string
  2593. namespace:
  2594. description: |-
  2595. The namespace of the Secret resource being referred to.
  2596. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2597. maxLength: 63
  2598. minLength: 1
  2599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2600. type: string
  2601. type: object
  2602. accessTypeParam:
  2603. description: |-
  2604. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2605. In some instances, `key` is a required field.
  2606. properties:
  2607. key:
  2608. description: |-
  2609. A key in the referenced Secret.
  2610. Some instances of this field may be defaulted, in others it may be required.
  2611. maxLength: 253
  2612. minLength: 1
  2613. pattern: ^[-._a-zA-Z0-9]+$
  2614. type: string
  2615. name:
  2616. description: The name of the Secret resource being referred to.
  2617. maxLength: 253
  2618. minLength: 1
  2619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2620. type: string
  2621. namespace:
  2622. description: |-
  2623. The namespace of the Secret resource being referred to.
  2624. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2625. maxLength: 63
  2626. minLength: 1
  2627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2628. type: string
  2629. type: object
  2630. type: object
  2631. serviceAccountRef:
  2632. description: |-
  2633. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  2634. authentication on AKS Workload Identity. The operator obtains a federated
  2635. identity token from this ServiceAccount via the TokenRequest API instead
  2636. of using the ESO controller pod identity. Ignored for other access types.
  2637. properties:
  2638. audiences:
  2639. description: |-
  2640. Audience specifies the `aud` claim for the service account token
  2641. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2642. then this audiences will be appended to the list
  2643. items:
  2644. type: string
  2645. type: array
  2646. name:
  2647. description: The name of the ServiceAccount resource being referred to.
  2648. maxLength: 253
  2649. minLength: 1
  2650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2651. type: string
  2652. namespace:
  2653. description: |-
  2654. Namespace of the resource being referred to.
  2655. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2656. maxLength: 63
  2657. minLength: 1
  2658. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2659. type: string
  2660. required:
  2661. - name
  2662. type: object
  2663. type: object
  2664. caBundle:
  2665. description: |-
  2666. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  2667. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  2668. are used to validate the TLS connection.
  2669. format: byte
  2670. type: string
  2671. caProvider:
  2672. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  2673. properties:
  2674. key:
  2675. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  2676. maxLength: 253
  2677. minLength: 1
  2678. pattern: ^[-._a-zA-Z0-9]+$
  2679. type: string
  2680. name:
  2681. description: The name of the object located at the provider type.
  2682. maxLength: 253
  2683. minLength: 1
  2684. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2685. type: string
  2686. namespace:
  2687. description: |-
  2688. The namespace the Provider type is in.
  2689. Can only be defined when used in a ClusterSecretStore.
  2690. maxLength: 63
  2691. minLength: 1
  2692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2693. type: string
  2694. type:
  2695. description: The type of provider to use such as "Secret", or "ConfigMap".
  2696. enum:
  2697. - Secret
  2698. - ConfigMap
  2699. type: string
  2700. required:
  2701. - name
  2702. - type
  2703. type: object
  2704. ignoreCache:
  2705. description: |-
  2706. IgnoreCache bypasses the Gateway cache for secret reads when true.
  2707. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  2708. type: boolean
  2709. required:
  2710. - akeylessGWApiURL
  2711. - authSecretRef
  2712. type: object
  2713. aws:
  2714. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  2715. properties:
  2716. additionalRoles:
  2717. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  2718. items:
  2719. type: string
  2720. type: array
  2721. auth:
  2722. description: |-
  2723. Auth defines the information necessary to authenticate against AWS
  2724. if not set aws sdk will infer credentials from your environment
  2725. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  2726. properties:
  2727. jwt:
  2728. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  2729. properties:
  2730. serviceAccountRef:
  2731. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  2732. properties:
  2733. audiences:
  2734. description: |-
  2735. Audience specifies the `aud` claim for the service account token
  2736. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2737. then this audiences will be appended to the list
  2738. items:
  2739. type: string
  2740. type: array
  2741. name:
  2742. description: The name of the ServiceAccount resource being referred to.
  2743. maxLength: 253
  2744. minLength: 1
  2745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2746. type: string
  2747. namespace:
  2748. description: |-
  2749. Namespace of the resource being referred to.
  2750. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2751. maxLength: 63
  2752. minLength: 1
  2753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2754. type: string
  2755. required:
  2756. - name
  2757. type: object
  2758. type: object
  2759. secretRef:
  2760. description: |-
  2761. AWSAuthSecretRef holds secret references for AWS credentials
  2762. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  2763. properties:
  2764. accessKeyIDSecretRef:
  2765. description: The AccessKeyID is used for authentication
  2766. properties:
  2767. key:
  2768. description: |-
  2769. A key in the referenced Secret.
  2770. Some instances of this field may be defaulted, in others it may be required.
  2771. maxLength: 253
  2772. minLength: 1
  2773. pattern: ^[-._a-zA-Z0-9]+$
  2774. type: string
  2775. name:
  2776. description: The name of the Secret resource being referred to.
  2777. maxLength: 253
  2778. minLength: 1
  2779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2780. type: string
  2781. namespace:
  2782. description: |-
  2783. The namespace of the Secret resource being referred to.
  2784. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2785. maxLength: 63
  2786. minLength: 1
  2787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2788. type: string
  2789. type: object
  2790. secretAccessKeySecretRef:
  2791. description: The SecretAccessKey is used for authentication
  2792. properties:
  2793. key:
  2794. description: |-
  2795. A key in the referenced Secret.
  2796. Some instances of this field may be defaulted, in others it may be required.
  2797. maxLength: 253
  2798. minLength: 1
  2799. pattern: ^[-._a-zA-Z0-9]+$
  2800. type: string
  2801. name:
  2802. description: The name of the Secret resource being referred to.
  2803. maxLength: 253
  2804. minLength: 1
  2805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2806. type: string
  2807. namespace:
  2808. description: |-
  2809. The namespace of the Secret resource being referred to.
  2810. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2811. maxLength: 63
  2812. minLength: 1
  2813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2814. type: string
  2815. type: object
  2816. sessionTokenSecretRef:
  2817. description: |-
  2818. The SessionToken used for authentication
  2819. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  2820. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  2821. properties:
  2822. key:
  2823. description: |-
  2824. A key in the referenced Secret.
  2825. Some instances of this field may be defaulted, in others it may be required.
  2826. maxLength: 253
  2827. minLength: 1
  2828. pattern: ^[-._a-zA-Z0-9]+$
  2829. type: string
  2830. name:
  2831. description: The name of the Secret resource being referred to.
  2832. maxLength: 253
  2833. minLength: 1
  2834. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2835. type: string
  2836. namespace:
  2837. description: |-
  2838. The namespace of the Secret resource being referred to.
  2839. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2840. maxLength: 63
  2841. minLength: 1
  2842. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2843. type: string
  2844. type: object
  2845. type: object
  2846. type: object
  2847. customSessionTags:
  2848. additionalProperties:
  2849. type: string
  2850. description: |-
  2851. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  2852. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  2853. type: object
  2854. x-kubernetes-validations:
  2855. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  2856. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  2857. externalID:
  2858. description: AWS External ID set on assumed IAM roles
  2859. type: string
  2860. prefix:
  2861. description: Prefix adds a prefix to all retrieved values.
  2862. type: string
  2863. region:
  2864. description: AWS Region to be used for the provider
  2865. type: string
  2866. role:
  2867. description: Role is a Role ARN which the provider will assume
  2868. type: string
  2869. secretsManager:
  2870. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  2871. properties:
  2872. forceDeleteWithoutRecovery:
  2873. description: |-
  2874. Specifies whether to delete the secret without any recovery window. You
  2875. can't use both this parameter and RecoveryWindowInDays in the same call.
  2876. If you don't use either, then by default Secrets Manager uses a 30 day
  2877. recovery window.
  2878. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  2879. type: boolean
  2880. recoveryWindowInDays:
  2881. description: |-
  2882. The number of days from 7 to 30 that Secrets Manager waits before
  2883. permanently deleting the secret. You can't use both this parameter and
  2884. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  2885. then by default Secrets Manager uses a 30-day recovery window.
  2886. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  2887. format: int64
  2888. type: integer
  2889. type: object
  2890. service:
  2891. description: Service defines which service should be used to fetch the secrets
  2892. enum:
  2893. - SecretsManager
  2894. - ParameterStore
  2895. - CertificateManager
  2896. type: string
  2897. sessionTags:
  2898. description: AWS STS assume role session tags
  2899. items:
  2900. description: |-
  2901. Tag is a key-value pair that can be attached to an AWS resource.
  2902. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  2903. properties:
  2904. key:
  2905. type: string
  2906. value:
  2907. type: string
  2908. required:
  2909. - key
  2910. - value
  2911. type: object
  2912. type: array
  2913. sessionTagsPolicy:
  2914. default: None
  2915. description: |-
  2916. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  2917. None (default): no tags are added.
  2918. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  2919. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  2920. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  2921. enum:
  2922. - None
  2923. - Simple
  2924. - Custom
  2925. type: string
  2926. transitiveTagKeys:
  2927. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  2928. items:
  2929. type: string
  2930. type: array
  2931. required:
  2932. - region
  2933. - service
  2934. type: object
  2935. azurekv:
  2936. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  2937. properties:
  2938. authSecretRef:
  2939. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  2940. properties:
  2941. clientCertificate:
  2942. description: The Azure ClientCertificate of the service principle used for authentication.
  2943. properties:
  2944. key:
  2945. description: |-
  2946. A key in the referenced Secret.
  2947. Some instances of this field may be defaulted, in others it may be required.
  2948. maxLength: 253
  2949. minLength: 1
  2950. pattern: ^[-._a-zA-Z0-9]+$
  2951. type: string
  2952. name:
  2953. description: The name of the Secret resource being referred to.
  2954. maxLength: 253
  2955. minLength: 1
  2956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2957. type: string
  2958. namespace:
  2959. description: |-
  2960. The namespace of the Secret resource being referred to.
  2961. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2962. maxLength: 63
  2963. minLength: 1
  2964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2965. type: string
  2966. type: object
  2967. clientId:
  2968. description: The Azure clientId of the service principle or managed identity used for authentication.
  2969. properties:
  2970. key:
  2971. description: |-
  2972. A key in the referenced Secret.
  2973. Some instances of this field may be defaulted, in others it may be required.
  2974. maxLength: 253
  2975. minLength: 1
  2976. pattern: ^[-._a-zA-Z0-9]+$
  2977. type: string
  2978. name:
  2979. description: The name of the Secret resource being referred to.
  2980. maxLength: 253
  2981. minLength: 1
  2982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2983. type: string
  2984. namespace:
  2985. description: |-
  2986. The namespace of the Secret resource being referred to.
  2987. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2988. maxLength: 63
  2989. minLength: 1
  2990. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2991. type: string
  2992. type: object
  2993. clientSecret:
  2994. description: The Azure ClientSecret of the service principle used for authentication.
  2995. properties:
  2996. key:
  2997. description: |-
  2998. A key in the referenced Secret.
  2999. Some instances of this field may be defaulted, in others it may be required.
  3000. maxLength: 253
  3001. minLength: 1
  3002. pattern: ^[-._a-zA-Z0-9]+$
  3003. type: string
  3004. name:
  3005. description: The name of the Secret resource being referred to.
  3006. maxLength: 253
  3007. minLength: 1
  3008. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3009. type: string
  3010. namespace:
  3011. description: |-
  3012. The namespace of the Secret resource being referred to.
  3013. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3014. maxLength: 63
  3015. minLength: 1
  3016. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3017. type: string
  3018. type: object
  3019. tenantId:
  3020. description: The Azure tenantId of the managed identity used for authentication.
  3021. properties:
  3022. key:
  3023. description: |-
  3024. A key in the referenced Secret.
  3025. Some instances of this field may be defaulted, in others it may be required.
  3026. maxLength: 253
  3027. minLength: 1
  3028. pattern: ^[-._a-zA-Z0-9]+$
  3029. type: string
  3030. name:
  3031. description: The name of the Secret resource being referred to.
  3032. maxLength: 253
  3033. minLength: 1
  3034. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3035. type: string
  3036. namespace:
  3037. description: |-
  3038. The namespace of the Secret resource being referred to.
  3039. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3040. maxLength: 63
  3041. minLength: 1
  3042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3043. type: string
  3044. type: object
  3045. type: object
  3046. authType:
  3047. default: ServicePrincipal
  3048. description: |-
  3049. Auth type defines how to authenticate to the keyvault service.
  3050. Valid values are:
  3051. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  3052. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  3053. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  3054. enum:
  3055. - ServicePrincipal
  3056. - ManagedIdentity
  3057. - WorkloadIdentity
  3058. type: string
  3059. customCloudConfig:
  3060. description: |-
  3061. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  3062. Required when EnvironmentType is AzureStackCloud.
  3063. Optional for other environment types - useful for Azure China when using Workload Identity
  3064. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  3065. standard China Cloud endpoint (login.chinacloudapi.cn).
  3066. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  3067. configuration is not supported with the legacy go-autorest SDK.
  3068. properties:
  3069. activeDirectoryEndpoint:
  3070. description: |-
  3071. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  3072. Required when using custom cloud configuration
  3073. type: string
  3074. keyVaultDNSSuffix:
  3075. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  3076. type: string
  3077. keyVaultEndpoint:
  3078. description: KeyVaultEndpoint is the Key Vault service endpoint
  3079. type: string
  3080. resourceManagerEndpoint:
  3081. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  3082. type: string
  3083. required:
  3084. - activeDirectoryEndpoint
  3085. type: object
  3086. environmentType:
  3087. default: PublicCloud
  3088. description: |-
  3089. EnvironmentType specifies the Azure cloud environment endpoints to use for
  3090. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  3091. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  3092. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  3093. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  3094. enum:
  3095. - PublicCloud
  3096. - USGovernmentCloud
  3097. - ChinaCloud
  3098. - GermanCloud
  3099. - AzureStackCloud
  3100. type: string
  3101. identityId:
  3102. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  3103. type: string
  3104. serviceAccountRef:
  3105. description: |-
  3106. ServiceAccountRef specified the service account
  3107. that should be used when authenticating with WorkloadIdentity.
  3108. properties:
  3109. audiences:
  3110. description: |-
  3111. Audience specifies the `aud` claim for the service account token
  3112. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  3113. then this audiences will be appended to the list
  3114. items:
  3115. type: string
  3116. type: array
  3117. name:
  3118. description: The name of the ServiceAccount resource being referred to.
  3119. maxLength: 253
  3120. minLength: 1
  3121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3122. type: string
  3123. namespace:
  3124. description: |-
  3125. Namespace of the resource being referred to.
  3126. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3127. maxLength: 63
  3128. minLength: 1
  3129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3130. type: string
  3131. required:
  3132. - name
  3133. type: object
  3134. tenantId:
  3135. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  3136. type: string
  3137. useAzureSDK:
  3138. default: false
  3139. description: |-
  3140. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  3141. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  3142. type: boolean
  3143. vaultUrl:
  3144. description: Vault Url from which the secrets to be fetched from.
  3145. type: string
  3146. required:
  3147. - vaultUrl
  3148. type: object
  3149. barbican:
  3150. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  3151. properties:
  3152. auth:
  3153. description: BarbicanAuth contains the authentication information for Barbican.
  3154. properties:
  3155. password:
  3156. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  3157. properties:
  3158. secretRef:
  3159. description: |-
  3160. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3161. In some instances, `key` is a required field.
  3162. properties:
  3163. key:
  3164. description: |-
  3165. A key in the referenced Secret.
  3166. Some instances of this field may be defaulted, in others it may be required.
  3167. maxLength: 253
  3168. minLength: 1
  3169. pattern: ^[-._a-zA-Z0-9]+$
  3170. type: string
  3171. name:
  3172. description: The name of the Secret resource being referred to.
  3173. maxLength: 253
  3174. minLength: 1
  3175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3176. type: string
  3177. namespace:
  3178. description: |-
  3179. The namespace of the Secret resource being referred to.
  3180. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3181. maxLength: 63
  3182. minLength: 1
  3183. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3184. type: string
  3185. type: object
  3186. required:
  3187. - secretRef
  3188. type: object
  3189. username:
  3190. description: BarbicanProviderUsernameRef defines a reference to a secret containing username for the Barbican provider.
  3191. maxProperties: 1
  3192. minProperties: 1
  3193. properties:
  3194. secretRef:
  3195. description: |-
  3196. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3197. In some instances, `key` is a required field.
  3198. properties:
  3199. key:
  3200. description: |-
  3201. A key in the referenced Secret.
  3202. Some instances of this field may be defaulted, in others it may be required.
  3203. maxLength: 253
  3204. minLength: 1
  3205. pattern: ^[-._a-zA-Z0-9]+$
  3206. type: string
  3207. name:
  3208. description: The name of the Secret resource being referred to.
  3209. maxLength: 253
  3210. minLength: 1
  3211. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3212. type: string
  3213. namespace:
  3214. description: |-
  3215. The namespace of the Secret resource being referred to.
  3216. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3217. maxLength: 63
  3218. minLength: 1
  3219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3220. type: string
  3221. type: object
  3222. value:
  3223. type: string
  3224. type: object
  3225. required:
  3226. - password
  3227. - username
  3228. type: object
  3229. authURL:
  3230. type: string
  3231. domainName:
  3232. type: string
  3233. region:
  3234. type: string
  3235. tenantName:
  3236. type: string
  3237. required:
  3238. - auth
  3239. type: object
  3240. beyondtrust:
  3241. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  3242. properties:
  3243. auth:
  3244. description: Auth configures how the operator authenticates with Beyondtrust.
  3245. properties:
  3246. apiKey:
  3247. description: APIKey If not provided then ClientID/ClientSecret become required.
  3248. properties:
  3249. secretRef:
  3250. description: SecretRef references a key in a secret that will be used as value.
  3251. properties:
  3252. key:
  3253. description: |-
  3254. A key in the referenced Secret.
  3255. Some instances of this field may be defaulted, in others it may be required.
  3256. maxLength: 253
  3257. minLength: 1
  3258. pattern: ^[-._a-zA-Z0-9]+$
  3259. type: string
  3260. name:
  3261. description: The name of the Secret resource being referred to.
  3262. maxLength: 253
  3263. minLength: 1
  3264. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3265. type: string
  3266. namespace:
  3267. description: |-
  3268. The namespace of the Secret resource being referred to.
  3269. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3270. maxLength: 63
  3271. minLength: 1
  3272. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3273. type: string
  3274. type: object
  3275. value:
  3276. description: Value can be specified directly to set a value without using a secret.
  3277. type: string
  3278. type: object
  3279. certificate:
  3280. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  3281. properties:
  3282. secretRef:
  3283. description: SecretRef references a key in a secret that will be used as value.
  3284. properties:
  3285. key:
  3286. description: |-
  3287. A key in the referenced Secret.
  3288. Some instances of this field may be defaulted, in others it may be required.
  3289. maxLength: 253
  3290. minLength: 1
  3291. pattern: ^[-._a-zA-Z0-9]+$
  3292. type: string
  3293. name:
  3294. description: The name of the Secret resource being referred to.
  3295. maxLength: 253
  3296. minLength: 1
  3297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3298. type: string
  3299. namespace:
  3300. description: |-
  3301. The namespace of the Secret resource being referred to.
  3302. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3303. maxLength: 63
  3304. minLength: 1
  3305. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3306. type: string
  3307. type: object
  3308. value:
  3309. description: Value can be specified directly to set a value without using a secret.
  3310. type: string
  3311. type: object
  3312. certificateKey:
  3313. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  3314. properties:
  3315. secretRef:
  3316. description: SecretRef references a key in a secret that will be used as value.
  3317. properties:
  3318. key:
  3319. description: |-
  3320. A key in the referenced Secret.
  3321. Some instances of this field may be defaulted, in others it may be required.
  3322. maxLength: 253
  3323. minLength: 1
  3324. pattern: ^[-._a-zA-Z0-9]+$
  3325. type: string
  3326. name:
  3327. description: The name of the Secret resource being referred to.
  3328. maxLength: 253
  3329. minLength: 1
  3330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3331. type: string
  3332. namespace:
  3333. description: |-
  3334. The namespace of the Secret resource being referred to.
  3335. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3336. maxLength: 63
  3337. minLength: 1
  3338. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3339. type: string
  3340. type: object
  3341. value:
  3342. description: Value can be specified directly to set a value without using a secret.
  3343. type: string
  3344. type: object
  3345. clientId:
  3346. description: ClientID is the API OAuth Client ID.
  3347. properties:
  3348. secretRef:
  3349. description: SecretRef references a key in a secret that will be used as value.
  3350. properties:
  3351. key:
  3352. description: |-
  3353. A key in the referenced Secret.
  3354. Some instances of this field may be defaulted, in others it may be required.
  3355. maxLength: 253
  3356. minLength: 1
  3357. pattern: ^[-._a-zA-Z0-9]+$
  3358. type: string
  3359. name:
  3360. description: The name of the Secret resource being referred to.
  3361. maxLength: 253
  3362. minLength: 1
  3363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3364. type: string
  3365. namespace:
  3366. description: |-
  3367. The namespace of the Secret resource being referred to.
  3368. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3369. maxLength: 63
  3370. minLength: 1
  3371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3372. type: string
  3373. type: object
  3374. value:
  3375. description: Value can be specified directly to set a value without using a secret.
  3376. type: string
  3377. type: object
  3378. clientSecret:
  3379. description: ClientSecret is the API OAuth Client Secret.
  3380. properties:
  3381. secretRef:
  3382. description: SecretRef references a key in a secret that will be used as value.
  3383. properties:
  3384. key:
  3385. description: |-
  3386. A key in the referenced Secret.
  3387. Some instances of this field may be defaulted, in others it may be required.
  3388. maxLength: 253
  3389. minLength: 1
  3390. pattern: ^[-._a-zA-Z0-9]+$
  3391. type: string
  3392. name:
  3393. description: The name of the Secret resource being referred to.
  3394. maxLength: 253
  3395. minLength: 1
  3396. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3397. type: string
  3398. namespace:
  3399. description: |-
  3400. The namespace of the Secret resource being referred to.
  3401. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3402. maxLength: 63
  3403. minLength: 1
  3404. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3405. type: string
  3406. type: object
  3407. value:
  3408. description: Value can be specified directly to set a value without using a secret.
  3409. type: string
  3410. type: object
  3411. type: object
  3412. server:
  3413. description: Auth configures how API server works.
  3414. properties:
  3415. apiUrl:
  3416. type: string
  3417. apiVersion:
  3418. type: string
  3419. clientTimeOutSeconds:
  3420. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  3421. type: integer
  3422. decrypt:
  3423. default: true
  3424. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  3425. type: boolean
  3426. retrievalType:
  3427. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  3428. type: string
  3429. separator:
  3430. description: A character that separates the folder names.
  3431. type: string
  3432. verifyCA:
  3433. type: boolean
  3434. required:
  3435. - apiUrl
  3436. - verifyCA
  3437. type: object
  3438. required:
  3439. - auth
  3440. - server
  3441. type: object
  3442. beyondtrustworkloadcredentials:
  3443. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  3444. properties:
  3445. auth:
  3446. description: |-
  3447. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  3448. Currently supports API key authentication via Kubernetes secret reference.
  3449. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3450. properties:
  3451. apikey:
  3452. description: |-
  3453. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  3454. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  3455. properties:
  3456. token:
  3457. description: |-
  3458. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  3459. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  3460. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  3461. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3462. properties:
  3463. key:
  3464. description: |-
  3465. A key in the referenced Secret.
  3466. Some instances of this field may be defaulted, in others it may be required.
  3467. maxLength: 253
  3468. minLength: 1
  3469. pattern: ^[-._a-zA-Z0-9]+$
  3470. type: string
  3471. name:
  3472. description: The name of the Secret resource being referred to.
  3473. maxLength: 253
  3474. minLength: 1
  3475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3476. type: string
  3477. namespace:
  3478. description: |-
  3479. The namespace of the Secret resource being referred to.
  3480. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3481. maxLength: 63
  3482. minLength: 1
  3483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3484. type: string
  3485. type: object
  3486. required:
  3487. - token
  3488. type: object
  3489. required:
  3490. - apikey
  3491. type: object
  3492. caBundle:
  3493. description: |-
  3494. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3495. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  3496. If not set, the system's trusted root certificates are used.
  3497. format: byte
  3498. type: string
  3499. caProvider:
  3500. description: |-
  3501. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  3502. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3503. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  3504. properties:
  3505. key:
  3506. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3507. maxLength: 253
  3508. minLength: 1
  3509. pattern: ^[-._a-zA-Z0-9]+$
  3510. type: string
  3511. name:
  3512. description: The name of the object located at the provider type.
  3513. maxLength: 253
  3514. minLength: 1
  3515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3516. type: string
  3517. namespace:
  3518. description: |-
  3519. The namespace the Provider type is in.
  3520. Can only be defined when used in a ClusterSecretStore.
  3521. maxLength: 63
  3522. minLength: 1
  3523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3524. type: string
  3525. type:
  3526. description: The type of provider to use such as "Secret", or "ConfigMap".
  3527. enum:
  3528. - Secret
  3529. - ConfigMap
  3530. type: string
  3531. required:
  3532. - name
  3533. - type
  3534. type: object
  3535. folderPath:
  3536. description: |-
  3537. FolderPath specifies the default folder path for secret retrieval.
  3538. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  3539. Example: "production/database" or "dev/api-keys"
  3540. Leave empty to retrieve secrets from the root folder.
  3541. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  3542. type: string
  3543. server:
  3544. description: |-
  3545. Server configures the BeyondTrust Workload Credentials server connection details.
  3546. Includes the API URL and Site ID for your BeyondTrust instance.
  3547. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3548. properties:
  3549. apiUrl:
  3550. description: |-
  3551. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  3552. This should be the full URL to your BeyondTrust instance.
  3553. Example: https://api.beyondtrust.io/siie
  3554. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  3555. type: string
  3556. siteId:
  3557. description: |-
  3558. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  3559. This identifier is unique to your BeyondTrust Workload Credentials instance.
  3560. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  3561. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  3562. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3563. type: string
  3564. required:
  3565. - apiUrl
  3566. - siteId
  3567. type: object
  3568. required:
  3569. - auth
  3570. - server
  3571. type: object
  3572. bitwardensecretsmanager:
  3573. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  3574. properties:
  3575. apiURL:
  3576. type: string
  3577. auth:
  3578. description: |-
  3579. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  3580. Make sure that the token being used has permissions on the given secret.
  3581. properties:
  3582. secretRef:
  3583. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  3584. properties:
  3585. credentials:
  3586. description: AccessToken used for the bitwarden instance.
  3587. properties:
  3588. key:
  3589. description: |-
  3590. A key in the referenced Secret.
  3591. Some instances of this field may be defaulted, in others it may be required.
  3592. maxLength: 253
  3593. minLength: 1
  3594. pattern: ^[-._a-zA-Z0-9]+$
  3595. type: string
  3596. name:
  3597. description: The name of the Secret resource being referred to.
  3598. maxLength: 253
  3599. minLength: 1
  3600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3601. type: string
  3602. namespace:
  3603. description: |-
  3604. The namespace of the Secret resource being referred to.
  3605. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3606. maxLength: 63
  3607. minLength: 1
  3608. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3609. type: string
  3610. type: object
  3611. required:
  3612. - credentials
  3613. type: object
  3614. required:
  3615. - secretRef
  3616. type: object
  3617. bitwardenServerSDKURL:
  3618. type: string
  3619. caBundle:
  3620. description: |-
  3621. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  3622. can be performed.
  3623. type: string
  3624. caProvider:
  3625. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  3626. properties:
  3627. key:
  3628. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3629. maxLength: 253
  3630. minLength: 1
  3631. pattern: ^[-._a-zA-Z0-9]+$
  3632. type: string
  3633. name:
  3634. description: The name of the object located at the provider type.
  3635. maxLength: 253
  3636. minLength: 1
  3637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3638. type: string
  3639. namespace:
  3640. description: |-
  3641. The namespace the Provider type is in.
  3642. Can only be defined when used in a ClusterSecretStore.
  3643. maxLength: 63
  3644. minLength: 1
  3645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3646. type: string
  3647. type:
  3648. description: The type of provider to use such as "Secret", or "ConfigMap".
  3649. enum:
  3650. - Secret
  3651. - ConfigMap
  3652. type: string
  3653. required:
  3654. - name
  3655. - type
  3656. type: object
  3657. identityURL:
  3658. type: string
  3659. organizationID:
  3660. description: OrganizationID determines which organization this secret store manages.
  3661. type: string
  3662. projectID:
  3663. description: ProjectID determines which project this secret store manages.
  3664. type: string
  3665. required:
  3666. - auth
  3667. - organizationID
  3668. - projectID
  3669. type: object
  3670. chef:
  3671. description: Chef configures this store to sync secrets with chef server
  3672. properties:
  3673. auth:
  3674. description: Auth defines the information necessary to authenticate against chef Server
  3675. properties:
  3676. secretRef:
  3677. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  3678. properties:
  3679. privateKeySecretRef:
  3680. description: SecretKey is the Signing Key in PEM format, used for authentication.
  3681. properties:
  3682. key:
  3683. description: |-
  3684. A key in the referenced Secret.
  3685. Some instances of this field may be defaulted, in others it may be required.
  3686. maxLength: 253
  3687. minLength: 1
  3688. pattern: ^[-._a-zA-Z0-9]+$
  3689. type: string
  3690. name:
  3691. description: The name of the Secret resource being referred to.
  3692. maxLength: 253
  3693. minLength: 1
  3694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3695. type: string
  3696. namespace:
  3697. description: |-
  3698. The namespace of the Secret resource being referred to.
  3699. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3700. maxLength: 63
  3701. minLength: 1
  3702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3703. type: string
  3704. type: object
  3705. required:
  3706. - privateKeySecretRef
  3707. type: object
  3708. required:
  3709. - secretRef
  3710. type: object
  3711. serverUrl:
  3712. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  3713. type: string
  3714. username:
  3715. description: UserName should be the user ID on the chef server
  3716. type: string
  3717. required:
  3718. - auth
  3719. - serverUrl
  3720. - username
  3721. type: object
  3722. cloudrusm:
  3723. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  3724. properties:
  3725. auth:
  3726. description: CSMAuth contains a secretRef for credentials.
  3727. properties:
  3728. secretRef:
  3729. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  3730. properties:
  3731. accessKeyIDSecretRef:
  3732. description: The AccessKeyID is used for authentication
  3733. properties:
  3734. key:
  3735. description: |-
  3736. A key in the referenced Secret.
  3737. Some instances of this field may be defaulted, in others it may be required.
  3738. maxLength: 253
  3739. minLength: 1
  3740. pattern: ^[-._a-zA-Z0-9]+$
  3741. type: string
  3742. name:
  3743. description: The name of the Secret resource being referred to.
  3744. maxLength: 253
  3745. minLength: 1
  3746. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3747. type: string
  3748. namespace:
  3749. description: |-
  3750. The namespace of the Secret resource being referred to.
  3751. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3752. maxLength: 63
  3753. minLength: 1
  3754. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3755. type: string
  3756. type: object
  3757. accessKeySecretSecretRef:
  3758. description: The AccessKeySecret is used for authentication
  3759. properties:
  3760. key:
  3761. description: |-
  3762. A key in the referenced Secret.
  3763. Some instances of this field may be defaulted, in others it may be required.
  3764. maxLength: 253
  3765. minLength: 1
  3766. pattern: ^[-._a-zA-Z0-9]+$
  3767. type: string
  3768. name:
  3769. description: The name of the Secret resource being referred to.
  3770. maxLength: 253
  3771. minLength: 1
  3772. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3773. type: string
  3774. namespace:
  3775. description: |-
  3776. The namespace of the Secret resource being referred to.
  3777. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3778. maxLength: 63
  3779. minLength: 1
  3780. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3781. type: string
  3782. type: object
  3783. required:
  3784. - accessKeyIDSecretRef
  3785. - accessKeySecretSecretRef
  3786. type: object
  3787. type: object
  3788. projectID:
  3789. description: ProjectID is the project, which the secrets are stored in.
  3790. type: string
  3791. required:
  3792. - auth
  3793. type: object
  3794. conjur:
  3795. description: Conjur configures this store to sync secrets using conjur provider
  3796. properties:
  3797. auth:
  3798. description: Defines authentication settings for connecting to Conjur.
  3799. maxProperties: 1
  3800. minProperties: 1
  3801. properties:
  3802. apikey:
  3803. description: Authenticates with Conjur using an API key.
  3804. properties:
  3805. account:
  3806. description: Account is the Conjur organization account name.
  3807. type: string
  3808. apiKeyRef:
  3809. description: |-
  3810. A reference to a specific 'key' containing the Conjur API key
  3811. within a Secret resource. In some instances, `key` is a required field.
  3812. properties:
  3813. key:
  3814. description: |-
  3815. A key in the referenced Secret.
  3816. Some instances of this field may be defaulted, in others it may be required.
  3817. maxLength: 253
  3818. minLength: 1
  3819. pattern: ^[-._a-zA-Z0-9]+$
  3820. type: string
  3821. name:
  3822. description: The name of the Secret resource being referred to.
  3823. maxLength: 253
  3824. minLength: 1
  3825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3826. type: string
  3827. namespace:
  3828. description: |-
  3829. The namespace of the Secret resource being referred to.
  3830. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3831. maxLength: 63
  3832. minLength: 1
  3833. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3834. type: string
  3835. type: object
  3836. userRef:
  3837. description: |-
  3838. A reference to a specific 'key' containing the Conjur username
  3839. within a Secret resource. In some instances, `key` is a required field.
  3840. properties:
  3841. key:
  3842. description: |-
  3843. A key in the referenced Secret.
  3844. Some instances of this field may be defaulted, in others it may be required.
  3845. maxLength: 253
  3846. minLength: 1
  3847. pattern: ^[-._a-zA-Z0-9]+$
  3848. type: string
  3849. name:
  3850. description: The name of the Secret resource being referred to.
  3851. maxLength: 253
  3852. minLength: 1
  3853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3854. type: string
  3855. namespace:
  3856. description: |-
  3857. The namespace of the Secret resource being referred to.
  3858. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3859. maxLength: 63
  3860. minLength: 1
  3861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3862. type: string
  3863. type: object
  3864. required:
  3865. - account
  3866. - apiKeyRef
  3867. - userRef
  3868. type: object
  3869. cert:
  3870. description: Cert enables certificate-based authentication using a client certificate and key.
  3871. properties:
  3872. account:
  3873. description: Account is the Conjur organization account name.
  3874. type: string
  3875. clientCertRef:
  3876. description: |-
  3877. ClientCertRef is a reference to a specific 'key' containing the client certificate
  3878. within a Secret resource. The certificate must be PEM-encoded.
  3879. properties:
  3880. key:
  3881. description: |-
  3882. A key in the referenced Secret.
  3883. Some instances of this field may be defaulted, in others it may be required.
  3884. maxLength: 253
  3885. minLength: 1
  3886. pattern: ^[-._a-zA-Z0-9]+$
  3887. type: string
  3888. name:
  3889. description: The name of the Secret resource being referred to.
  3890. maxLength: 253
  3891. minLength: 1
  3892. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3893. type: string
  3894. namespace:
  3895. description: |-
  3896. The namespace of the Secret resource being referred to.
  3897. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3898. maxLength: 63
  3899. minLength: 1
  3900. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3901. type: string
  3902. type: object
  3903. clientKeyRef:
  3904. description: |-
  3905. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  3906. within a Secret resource. The key must be PEM-encoded.
  3907. properties:
  3908. key:
  3909. description: |-
  3910. A key in the referenced Secret.
  3911. Some instances of this field may be defaulted, in others it may be required.
  3912. maxLength: 253
  3913. minLength: 1
  3914. pattern: ^[-._a-zA-Z0-9]+$
  3915. type: string
  3916. name:
  3917. description: The name of the Secret resource being referred to.
  3918. maxLength: 253
  3919. minLength: 1
  3920. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3921. type: string
  3922. namespace:
  3923. description: |-
  3924. The namespace of the Secret resource being referred to.
  3925. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3926. maxLength: 63
  3927. minLength: 1
  3928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3929. type: string
  3930. type: object
  3931. hostId:
  3932. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  3933. type: string
  3934. serviceID:
  3935. description: The conjur authn cert webservice id
  3936. type: string
  3937. required:
  3938. - account
  3939. - clientCertRef
  3940. - clientKeyRef
  3941. - serviceID
  3942. type: object
  3943. jwt:
  3944. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  3945. properties:
  3946. account:
  3947. description: Account is the Conjur organization account name.
  3948. type: string
  3949. hostId:
  3950. description: |-
  3951. Optional HostID for JWT authentication. This may be used depending
  3952. on how the Conjur JWT authenticator policy is configured.
  3953. type: string
  3954. secretRef:
  3955. description: |-
  3956. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  3957. authenticate with Conjur using the JWT authentication method.
  3958. properties:
  3959. key:
  3960. description: |-
  3961. A key in the referenced Secret.
  3962. Some instances of this field may be defaulted, in others it may be required.
  3963. maxLength: 253
  3964. minLength: 1
  3965. pattern: ^[-._a-zA-Z0-9]+$
  3966. type: string
  3967. name:
  3968. description: The name of the Secret resource being referred to.
  3969. maxLength: 253
  3970. minLength: 1
  3971. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3972. type: string
  3973. namespace:
  3974. description: |-
  3975. The namespace of the Secret resource being referred to.
  3976. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3977. maxLength: 63
  3978. minLength: 1
  3979. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3980. type: string
  3981. type: object
  3982. serviceAccountRef:
  3983. description: |-
  3984. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  3985. a token for with the `TokenRequest` API.
  3986. properties:
  3987. audiences:
  3988. description: |-
  3989. Audience specifies the `aud` claim for the service account token
  3990. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  3991. then this audiences will be appended to the list
  3992. items:
  3993. type: string
  3994. type: array
  3995. name:
  3996. description: The name of the ServiceAccount resource being referred to.
  3997. maxLength: 253
  3998. minLength: 1
  3999. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4000. type: string
  4001. namespace:
  4002. description: |-
  4003. Namespace of the resource being referred to.
  4004. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4005. maxLength: 63
  4006. minLength: 1
  4007. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4008. type: string
  4009. required:
  4010. - name
  4011. type: object
  4012. serviceID:
  4013. description: The conjur authn jwt webservice id
  4014. type: string
  4015. required:
  4016. - account
  4017. - serviceID
  4018. type: object
  4019. type: object
  4020. caBundle:
  4021. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  4022. type: string
  4023. caProvider:
  4024. description: |-
  4025. Used to provide custom certificate authority (CA) certificates
  4026. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  4027. that contains a PEM-encoded certificate.
  4028. properties:
  4029. key:
  4030. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4031. maxLength: 253
  4032. minLength: 1
  4033. pattern: ^[-._a-zA-Z0-9]+$
  4034. type: string
  4035. name:
  4036. description: The name of the object located at the provider type.
  4037. maxLength: 253
  4038. minLength: 1
  4039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4040. type: string
  4041. namespace:
  4042. description: |-
  4043. The namespace the Provider type is in.
  4044. Can only be defined when used in a ClusterSecretStore.
  4045. maxLength: 63
  4046. minLength: 1
  4047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4048. type: string
  4049. type:
  4050. description: The type of provider to use such as "Secret", or "ConfigMap".
  4051. enum:
  4052. - Secret
  4053. - ConfigMap
  4054. type: string
  4055. required:
  4056. - name
  4057. - type
  4058. type: object
  4059. url:
  4060. description: URL is the endpoint of the Conjur instance.
  4061. type: string
  4062. required:
  4063. - auth
  4064. - url
  4065. type: object
  4066. crd:
  4067. description: |-
  4068. CRD configures this store to sync secrets from arbitrary Kubernetes resources,
  4069. including both custom resources (CRDs) and core API resources. Resources are
  4070. selected by API group, version and kind, where group can be "" (empty string)
  4071. for core resources such as ConfigMap. Reading the core v1 Secret is
  4072. intentionally blocked — use the Kubernetes provider for that.
  4073. properties:
  4074. auth:
  4075. description: |-
  4076. Auth configures authentication to the Kubernetes API, same as the
  4077. Kubernetes provider. Required when Server.URL is set (unless using AuthRef).
  4078. maxProperties: 1
  4079. minProperties: 1
  4080. properties:
  4081. cert:
  4082. description: has both clientCert and clientKey as secretKeySelector
  4083. properties:
  4084. clientCert:
  4085. description: |-
  4086. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4087. In some instances, `key` is a required field.
  4088. properties:
  4089. key:
  4090. description: |-
  4091. A key in the referenced Secret.
  4092. Some instances of this field may be defaulted, in others it may be required.
  4093. maxLength: 253
  4094. minLength: 1
  4095. pattern: ^[-._a-zA-Z0-9]+$
  4096. type: string
  4097. name:
  4098. description: The name of the Secret resource being referred to.
  4099. maxLength: 253
  4100. minLength: 1
  4101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4102. type: string
  4103. namespace:
  4104. description: |-
  4105. The namespace of the Secret resource being referred to.
  4106. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4107. maxLength: 63
  4108. minLength: 1
  4109. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4110. type: string
  4111. type: object
  4112. clientKey:
  4113. description: |-
  4114. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4115. In some instances, `key` is a required field.
  4116. properties:
  4117. key:
  4118. description: |-
  4119. A key in the referenced Secret.
  4120. Some instances of this field may be defaulted, in others it may be required.
  4121. maxLength: 253
  4122. minLength: 1
  4123. pattern: ^[-._a-zA-Z0-9]+$
  4124. type: string
  4125. name:
  4126. description: The name of the Secret resource being referred to.
  4127. maxLength: 253
  4128. minLength: 1
  4129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4130. type: string
  4131. namespace:
  4132. description: |-
  4133. The namespace of the Secret resource being referred to.
  4134. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4135. maxLength: 63
  4136. minLength: 1
  4137. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4138. type: string
  4139. type: object
  4140. required:
  4141. - clientCert
  4142. - clientKey
  4143. type: object
  4144. serviceAccount:
  4145. description: points to a service account that should be used for authentication
  4146. properties:
  4147. audiences:
  4148. description: |-
  4149. Audience specifies the `aud` claim for the service account token
  4150. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4151. then this audiences will be appended to the list
  4152. items:
  4153. type: string
  4154. type: array
  4155. name:
  4156. description: The name of the ServiceAccount resource being referred to.
  4157. maxLength: 253
  4158. minLength: 1
  4159. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4160. type: string
  4161. namespace:
  4162. description: |-
  4163. Namespace of the resource being referred to.
  4164. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4165. maxLength: 63
  4166. minLength: 1
  4167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4168. type: string
  4169. required:
  4170. - name
  4171. type: object
  4172. token:
  4173. description: use static token to authenticate with
  4174. properties:
  4175. bearerToken:
  4176. description: |-
  4177. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4178. In some instances, `key` is a required field.
  4179. properties:
  4180. key:
  4181. description: |-
  4182. A key in the referenced Secret.
  4183. Some instances of this field may be defaulted, in others it may be required.
  4184. maxLength: 253
  4185. minLength: 1
  4186. pattern: ^[-._a-zA-Z0-9]+$
  4187. type: string
  4188. name:
  4189. description: The name of the Secret resource being referred to.
  4190. maxLength: 253
  4191. minLength: 1
  4192. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4193. type: string
  4194. namespace:
  4195. description: |-
  4196. The namespace of the Secret resource being referred to.
  4197. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4198. maxLength: 63
  4199. minLength: 1
  4200. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4201. type: string
  4202. type: object
  4203. required:
  4204. - bearerToken
  4205. type: object
  4206. type: object
  4207. authRef:
  4208. description: |-
  4209. AuthRef references a Secret containing a kubeconfig. Same semantics as the
  4210. Kubernetes provider.
  4211. properties:
  4212. key:
  4213. description: |-
  4214. A key in the referenced Secret.
  4215. Some instances of this field may be defaulted, in others it may be required.
  4216. maxLength: 253
  4217. minLength: 1
  4218. pattern: ^[-._a-zA-Z0-9]+$
  4219. type: string
  4220. name:
  4221. description: The name of the Secret resource being referred to.
  4222. maxLength: 253
  4223. minLength: 1
  4224. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4225. type: string
  4226. namespace:
  4227. description: |-
  4228. The namespace of the Secret resource being referred to.
  4229. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4230. maxLength: 63
  4231. minLength: 1
  4232. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4233. type: string
  4234. type: object
  4235. resource:
  4236. description: Resource identifies the CRD by its API group, version and kind.
  4237. properties:
  4238. group:
  4239. description: |-
  4240. Group is the API group of the resource. Use "" (empty string) for core
  4241. Kubernetes resources such as ConfigMap; use e.g. "config.example.io"
  4242. for a CRD. The field is required to be present in the manifest — write
  4243. `group: ""` explicitly for core resources so typos fail at admission
  4244. time rather than later at discovery.
  4245. type: string
  4246. kind:
  4247. description: Kind is the Kubernetes resource kind (e.g. "MyCustomResource").
  4248. minLength: 1
  4249. type: string
  4250. version:
  4251. description: Version is the API version of the resource (e.g. "v1alpha1").
  4252. minLength: 1
  4253. type: string
  4254. required:
  4255. - group
  4256. - kind
  4257. - version
  4258. type: object
  4259. server:
  4260. description: |-
  4261. Server configures the Kubernetes API address and TLS trust, same as the
  4262. Kubernetes provider. When omitted, the URL defaults to the in-cluster API.
  4263. properties:
  4264. caBundle:
  4265. description: CABundle is a base64-encoded CA certificate
  4266. format: byte
  4267. type: string
  4268. caProvider:
  4269. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  4270. properties:
  4271. key:
  4272. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4273. maxLength: 253
  4274. minLength: 1
  4275. pattern: ^[-._a-zA-Z0-9]+$
  4276. type: string
  4277. name:
  4278. description: The name of the object located at the provider type.
  4279. maxLength: 253
  4280. minLength: 1
  4281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4282. type: string
  4283. namespace:
  4284. description: |-
  4285. The namespace the Provider type is in.
  4286. Can only be defined when used in a ClusterSecretStore.
  4287. maxLength: 63
  4288. minLength: 1
  4289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4290. type: string
  4291. type:
  4292. description: The type of provider to use such as "Secret", or "ConfigMap".
  4293. enum:
  4294. - Secret
  4295. - ConfigMap
  4296. type: string
  4297. required:
  4298. - name
  4299. - type
  4300. type: object
  4301. url:
  4302. default: kubernetes.default
  4303. description: configures the Kubernetes server Address.
  4304. type: string
  4305. type: object
  4306. whitelist:
  4307. description: |-
  4308. Whitelist optionally restricts which object names and requested properties
  4309. are allowed to be read.
  4310. properties:
  4311. rules:
  4312. description: |-
  4313. Rules is a list of allow rules. If rules are set, at least one rule must
  4314. match for a request to be allowed.
  4315. items:
  4316. description: CRDProviderWhitelistRule defines a single allow rule for CRD reads.
  4317. properties:
  4318. name:
  4319. description: |-
  4320. Name is an optional regular expression matched against the bare object name.
  4321. For both SecretStore and ClusterSecretStore this is always the object name
  4322. without any namespace prefix (e.g. "my-db-spec", not "prod/my-db-spec").
  4323. type: string
  4324. namespace:
  4325. description: |-
  4326. Namespace is an optional regular expression matched against the namespace of
  4327. the object. Applies only when a ClusterSecretStore is used; it is ignored
  4328. for SecretStore (where the namespace is fixed to the store namespace).
  4329. type: string
  4330. properties:
  4331. description: |-
  4332. Properties is an optional list of regular expressions matched against
  4333. requested property keys (for example: "spec.secretValue").
  4334. items:
  4335. type: string
  4336. type: array
  4337. type: object
  4338. type: array
  4339. type: object
  4340. required:
  4341. - resource
  4342. type: object
  4343. x-kubernetes-validations:
  4344. - message: one of auth or authRef is required
  4345. rule: has(self.auth) || has(self.authRef)
  4346. - message: at most one of the fields in [auth authRef] may be set
  4347. rule: '[has(self.auth),has(self.authRef)].filter(x,x==true).size() <= 1'
  4348. delinea:
  4349. description: |-
  4350. Delinea DevOps Secrets Vault
  4351. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  4352. properties:
  4353. clientId:
  4354. description: ClientID is the non-secret part of the credential.
  4355. properties:
  4356. secretRef:
  4357. description: SecretRef references a key in a secret that will be used as value.
  4358. properties:
  4359. key:
  4360. description: |-
  4361. A key in the referenced Secret.
  4362. Some instances of this field may be defaulted, in others it may be required.
  4363. maxLength: 253
  4364. minLength: 1
  4365. pattern: ^[-._a-zA-Z0-9]+$
  4366. type: string
  4367. name:
  4368. description: The name of the Secret resource being referred to.
  4369. maxLength: 253
  4370. minLength: 1
  4371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4372. type: string
  4373. namespace:
  4374. description: |-
  4375. The namespace of the Secret resource being referred to.
  4376. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4377. maxLength: 63
  4378. minLength: 1
  4379. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4380. type: string
  4381. type: object
  4382. value:
  4383. description: Value can be specified directly to set a value without using a secret.
  4384. type: string
  4385. type: object
  4386. clientSecret:
  4387. description: ClientSecret is the secret part of the credential.
  4388. properties:
  4389. secretRef:
  4390. description: SecretRef references a key in a secret that will be used as value.
  4391. properties:
  4392. key:
  4393. description: |-
  4394. A key in the referenced Secret.
  4395. Some instances of this field may be defaulted, in others it may be required.
  4396. maxLength: 253
  4397. minLength: 1
  4398. pattern: ^[-._a-zA-Z0-9]+$
  4399. type: string
  4400. name:
  4401. description: The name of the Secret resource being referred to.
  4402. maxLength: 253
  4403. minLength: 1
  4404. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4405. type: string
  4406. namespace:
  4407. description: |-
  4408. The namespace of the Secret resource being referred to.
  4409. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4410. maxLength: 63
  4411. minLength: 1
  4412. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4413. type: string
  4414. type: object
  4415. value:
  4416. description: Value can be specified directly to set a value without using a secret.
  4417. type: string
  4418. type: object
  4419. tenant:
  4420. description: Tenant is the chosen hostname / site name.
  4421. type: string
  4422. tld:
  4423. description: |-
  4424. TLD is based on the server location that was chosen during provisioning.
  4425. If unset, defaults to "com".
  4426. type: string
  4427. urlTemplate:
  4428. description: |-
  4429. URLTemplate
  4430. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  4431. type: string
  4432. required:
  4433. - clientId
  4434. - clientSecret
  4435. - tenant
  4436. type: object
  4437. doppler:
  4438. description: Doppler configures this store to sync secrets using the Doppler provider
  4439. properties:
  4440. auth:
  4441. description: Auth configures how the Operator authenticates with the Doppler API
  4442. properties:
  4443. oidcConfig:
  4444. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  4445. properties:
  4446. expirationSeconds:
  4447. default: 600
  4448. description: |-
  4449. ExpirationSeconds sets the ServiceAccount token validity duration.
  4450. Defaults to 10 minutes.
  4451. format: int64
  4452. type: integer
  4453. identity:
  4454. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  4455. type: string
  4456. serviceAccountRef:
  4457. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  4458. properties:
  4459. audiences:
  4460. description: |-
  4461. Audience specifies the `aud` claim for the service account token
  4462. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4463. then this audiences will be appended to the list
  4464. items:
  4465. type: string
  4466. type: array
  4467. name:
  4468. description: The name of the ServiceAccount resource being referred to.
  4469. maxLength: 253
  4470. minLength: 1
  4471. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4472. type: string
  4473. namespace:
  4474. description: |-
  4475. Namespace of the resource being referred to.
  4476. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4477. maxLength: 63
  4478. minLength: 1
  4479. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4480. type: string
  4481. required:
  4482. - name
  4483. type: object
  4484. required:
  4485. - identity
  4486. - serviceAccountRef
  4487. type: object
  4488. secretRef:
  4489. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  4490. properties:
  4491. dopplerToken:
  4492. description: |-
  4493. The DopplerToken is used for authentication.
  4494. See https://docs.doppler.com/reference/api#authentication for auth token types.
  4495. The Key attribute defaults to dopplerToken if not specified.
  4496. properties:
  4497. key:
  4498. description: |-
  4499. A key in the referenced Secret.
  4500. Some instances of this field may be defaulted, in others it may be required.
  4501. maxLength: 253
  4502. minLength: 1
  4503. pattern: ^[-._a-zA-Z0-9]+$
  4504. type: string
  4505. name:
  4506. description: The name of the Secret resource being referred to.
  4507. maxLength: 253
  4508. minLength: 1
  4509. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4510. type: string
  4511. namespace:
  4512. description: |-
  4513. The namespace of the Secret resource being referred to.
  4514. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4515. maxLength: 63
  4516. minLength: 1
  4517. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4518. type: string
  4519. type: object
  4520. required:
  4521. - dopplerToken
  4522. type: object
  4523. type: object
  4524. x-kubernetes-validations:
  4525. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  4526. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  4527. config:
  4528. description: Doppler config (required if not using a Service Token)
  4529. type: string
  4530. format:
  4531. description: Format enables the downloading of secrets as a file (string)
  4532. enum:
  4533. - json
  4534. - dotnet-json
  4535. - env
  4536. - yaml
  4537. - docker
  4538. type: string
  4539. nameTransformer:
  4540. description: Environment variable compatible name transforms that change secret names to a different format
  4541. enum:
  4542. - upper-camel
  4543. - camel
  4544. - lower-snake
  4545. - tf-var
  4546. - dotnet-env
  4547. - lower-kebab
  4548. type: string
  4549. project:
  4550. description: Doppler project (required if not using a Service Token)
  4551. type: string
  4552. required:
  4553. - auth
  4554. type: object
  4555. dvls:
  4556. description: DVLS configures this store to sync secrets using Devolutions Server provider
  4557. properties:
  4558. auth:
  4559. description: Auth defines the authentication method to use.
  4560. properties:
  4561. secretRef:
  4562. description: SecretRef contains the Application ID and Application Secret for authentication.
  4563. properties:
  4564. appId:
  4565. description: AppID is the reference to the secret containing the Application ID.
  4566. properties:
  4567. key:
  4568. description: |-
  4569. A key in the referenced Secret.
  4570. Some instances of this field may be defaulted, in others it may be required.
  4571. maxLength: 253
  4572. minLength: 1
  4573. pattern: ^[-._a-zA-Z0-9]+$
  4574. type: string
  4575. name:
  4576. description: The name of the Secret resource being referred to.
  4577. maxLength: 253
  4578. minLength: 1
  4579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4580. type: string
  4581. namespace:
  4582. description: |-
  4583. The namespace of the Secret resource being referred to.
  4584. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4585. maxLength: 63
  4586. minLength: 1
  4587. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4588. type: string
  4589. type: object
  4590. appSecret:
  4591. description: AppSecret is the reference to the secret containing the Application Secret.
  4592. properties:
  4593. key:
  4594. description: |-
  4595. A key in the referenced Secret.
  4596. Some instances of this field may be defaulted, in others it may be required.
  4597. maxLength: 253
  4598. minLength: 1
  4599. pattern: ^[-._a-zA-Z0-9]+$
  4600. type: string
  4601. name:
  4602. description: The name of the Secret resource being referred to.
  4603. maxLength: 253
  4604. minLength: 1
  4605. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4606. type: string
  4607. namespace:
  4608. description: |-
  4609. The namespace of the Secret resource being referred to.
  4610. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4611. maxLength: 63
  4612. minLength: 1
  4613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4614. type: string
  4615. type: object
  4616. required:
  4617. - appId
  4618. - appSecret
  4619. type: object
  4620. required:
  4621. - secretRef
  4622. type: object
  4623. insecure:
  4624. description: |-
  4625. Insecure allows connecting to DVLS over plain HTTP.
  4626. This is NOT RECOMMENDED for production use.
  4627. Set to true only if you understand the security implications.
  4628. type: boolean
  4629. serverUrl:
  4630. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  4631. type: string
  4632. vault:
  4633. description: |-
  4634. Vault is the name or UUID of the vault to fetch secrets from.
  4635. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  4636. type: string
  4637. required:
  4638. - auth
  4639. - serverUrl
  4640. type: object
  4641. fake:
  4642. description: Fake configures a store with static key/value pairs
  4643. properties:
  4644. data:
  4645. items:
  4646. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  4647. properties:
  4648. key:
  4649. type: string
  4650. value:
  4651. type: string
  4652. version:
  4653. type: string
  4654. required:
  4655. - key
  4656. - value
  4657. type: object
  4658. type: array
  4659. validationResult:
  4660. description: ValidationResult is defined type for the number of validation results.
  4661. type: integer
  4662. required:
  4663. - data
  4664. type: object
  4665. fortanix:
  4666. description: Fortanix configures this store to sync secrets using the Fortanix provider
  4667. properties:
  4668. apiKey:
  4669. description: APIKey is the API token to access SDKMS Applications.
  4670. properties:
  4671. secretRef:
  4672. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  4673. properties:
  4674. key:
  4675. description: |-
  4676. A key in the referenced Secret.
  4677. Some instances of this field may be defaulted, in others it may be required.
  4678. maxLength: 253
  4679. minLength: 1
  4680. pattern: ^[-._a-zA-Z0-9]+$
  4681. type: string
  4682. name:
  4683. description: The name of the Secret resource being referred to.
  4684. maxLength: 253
  4685. minLength: 1
  4686. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4687. type: string
  4688. namespace:
  4689. description: |-
  4690. The namespace of the Secret resource being referred to.
  4691. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4692. maxLength: 63
  4693. minLength: 1
  4694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4695. type: string
  4696. type: object
  4697. type: object
  4698. apiUrl:
  4699. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  4700. type: string
  4701. type: object
  4702. gcpsm:
  4703. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  4704. properties:
  4705. auth:
  4706. description: Auth defines the information necessary to authenticate against GCP
  4707. properties:
  4708. secretRef:
  4709. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  4710. properties:
  4711. secretAccessKeySecretRef:
  4712. description: The SecretAccessKey is used for authentication
  4713. properties:
  4714. key:
  4715. description: |-
  4716. A key in the referenced Secret.
  4717. Some instances of this field may be defaulted, in others it may be required.
  4718. maxLength: 253
  4719. minLength: 1
  4720. pattern: ^[-._a-zA-Z0-9]+$
  4721. type: string
  4722. name:
  4723. description: The name of the Secret resource being referred to.
  4724. maxLength: 253
  4725. minLength: 1
  4726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4727. type: string
  4728. namespace:
  4729. description: |-
  4730. The namespace of the Secret resource being referred to.
  4731. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4732. maxLength: 63
  4733. minLength: 1
  4734. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4735. type: string
  4736. type: object
  4737. type: object
  4738. workloadIdentity:
  4739. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  4740. properties:
  4741. clusterLocation:
  4742. description: |-
  4743. ClusterLocation is the location of the cluster
  4744. If not specified, it fetches information from the metadata server
  4745. type: string
  4746. clusterName:
  4747. description: |-
  4748. ClusterName is the name of the cluster
  4749. If not specified, it fetches information from the metadata server
  4750. type: string
  4751. clusterProjectID:
  4752. description: |-
  4753. ClusterProjectID is the project ID of the cluster
  4754. If not specified, it fetches information from the metadata server
  4755. type: string
  4756. serviceAccountRef:
  4757. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  4758. properties:
  4759. audiences:
  4760. description: |-
  4761. Audience specifies the `aud` claim for the service account token
  4762. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4763. then this audiences will be appended to the list
  4764. items:
  4765. type: string
  4766. type: array
  4767. name:
  4768. description: The name of the ServiceAccount resource being referred to.
  4769. maxLength: 253
  4770. minLength: 1
  4771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4772. type: string
  4773. namespace:
  4774. description: |-
  4775. Namespace of the resource being referred to.
  4776. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4777. maxLength: 63
  4778. minLength: 1
  4779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4780. type: string
  4781. required:
  4782. - name
  4783. type: object
  4784. required:
  4785. - serviceAccountRef
  4786. type: object
  4787. workloadIdentityFederation:
  4788. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  4789. properties:
  4790. audience:
  4791. description: |-
  4792. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  4793. If specified, Audience found in the external account credential config will be overridden with the configured value.
  4794. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  4795. type: string
  4796. awsSecurityCredentials:
  4797. description: |-
  4798. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  4799. when using the AWS metadata server is not an option.
  4800. properties:
  4801. awsCredentialsSecretRef:
  4802. description: |-
  4803. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  4804. Secret should be created with below names for keys
  4805. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  4806. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  4807. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  4808. properties:
  4809. name:
  4810. description: name of the secret.
  4811. maxLength: 253
  4812. minLength: 1
  4813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4814. type: string
  4815. namespace:
  4816. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  4817. maxLength: 63
  4818. minLength: 1
  4819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4820. type: string
  4821. required:
  4822. - name
  4823. type: object
  4824. region:
  4825. description: region is for configuring the AWS region to be used.
  4826. example: ap-south-1
  4827. maxLength: 50
  4828. minLength: 1
  4829. pattern: ^[a-z0-9-]+$
  4830. type: string
  4831. required:
  4832. - awsCredentialsSecretRef
  4833. - region
  4834. type: object
  4835. credConfig:
  4836. description: |-
  4837. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  4838. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  4839. serviceAccountRef must be used by providing operators service account details.
  4840. properties:
  4841. key:
  4842. description: key name holding the external account credential config.
  4843. maxLength: 253
  4844. minLength: 1
  4845. pattern: ^[-._a-zA-Z0-9]+$
  4846. type: string
  4847. name:
  4848. description: name of the configmap.
  4849. maxLength: 253
  4850. minLength: 1
  4851. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4852. type: string
  4853. namespace:
  4854. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  4855. maxLength: 63
  4856. minLength: 1
  4857. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4858. type: string
  4859. required:
  4860. - key
  4861. - name
  4862. type: object
  4863. externalTokenEndpoint:
  4864. description: |-
  4865. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  4866. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  4867. URL is having the expected value.
  4868. type: string
  4869. gcpServiceAccountEmail:
  4870. description: |-
  4871. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  4872. after Workload Identity Federation. Use this to grant access through the service account's
  4873. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  4874. service_account_impersonation_url in the external account JSON from credConfig;
  4875. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  4876. on that ServiceAccount.
  4877. example: my-gsa@my-project.iam.gserviceaccount.com
  4878. minLength: 1
  4879. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  4880. type: string
  4881. serviceAccountRef:
  4882. description: |-
  4883. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  4884. when Kubernetes is configured as provider in workload identity pool.
  4885. properties:
  4886. audiences:
  4887. description: |-
  4888. Audience specifies the `aud` claim for the service account token
  4889. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4890. then this audiences will be appended to the list
  4891. items:
  4892. type: string
  4893. type: array
  4894. name:
  4895. description: The name of the ServiceAccount resource being referred to.
  4896. maxLength: 253
  4897. minLength: 1
  4898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4899. type: string
  4900. namespace:
  4901. description: |-
  4902. Namespace of the resource being referred to.
  4903. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4904. maxLength: 63
  4905. minLength: 1
  4906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4907. type: string
  4908. required:
  4909. - name
  4910. type: object
  4911. type: object
  4912. type: object
  4913. location:
  4914. description: Location optionally defines a location for a secret
  4915. type: string
  4916. projectID:
  4917. description: ProjectID project where secret is located
  4918. type: string
  4919. secretVersionSelectionPolicy:
  4920. default: LatestOrFail
  4921. description: |-
  4922. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  4923. when "latest" is disabled or destroyed.
  4924. Possible values are:
  4925. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  4926. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  4927. type: string
  4928. type: object
  4929. github:
  4930. description: |-
  4931. Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  4932. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  4933. properties:
  4934. appID:
  4935. description: appID specifies the Github APP that will be used to authenticate the client
  4936. format: int64
  4937. type: integer
  4938. auth:
  4939. description: auth configures how secret-manager authenticates with a Github instance.
  4940. properties:
  4941. privateKey:
  4942. description: |-
  4943. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4944. In some instances, `key` is a required field.
  4945. properties:
  4946. key:
  4947. description: |-
  4948. A key in the referenced Secret.
  4949. Some instances of this field may be defaulted, in others it may be required.
  4950. maxLength: 253
  4951. minLength: 1
  4952. pattern: ^[-._a-zA-Z0-9]+$
  4953. type: string
  4954. name:
  4955. description: The name of the Secret resource being referred to.
  4956. maxLength: 253
  4957. minLength: 1
  4958. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4959. type: string
  4960. namespace:
  4961. description: |-
  4962. The namespace of the Secret resource being referred to.
  4963. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4964. maxLength: 63
  4965. minLength: 1
  4966. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4967. type: string
  4968. type: object
  4969. required:
  4970. - privateKey
  4971. type: object
  4972. environment:
  4973. description: environment will be used to fetch secrets from a particular environment within a github repository
  4974. type: string
  4975. installationID:
  4976. description: installationID specifies the Github APP installation that will be used to authenticate the client
  4977. format: int64
  4978. type: integer
  4979. orgSecretVisibility:
  4980. description: |-
  4981. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  4982. Valid values are "all" or "private".
  4983. When unset, new secrets are created with visibility "all" and existing secrets preserve
  4984. whatever visibility they already have in GitHub.
  4985. enum:
  4986. - all
  4987. - private
  4988. type: string
  4989. organization:
  4990. description: organization will be used to fetch secrets from the Github organization
  4991. type: string
  4992. repository:
  4993. description: repository will be used to fetch secrets from the Github repository within an organization
  4994. type: string
  4995. uploadURL:
  4996. description: Upload URL for enterprise instances. Default to URL.
  4997. type: string
  4998. url:
  4999. default: https://github.com/
  5000. description: URL configures the Github instance URL. Defaults to https://github.com/.
  5001. type: string
  5002. required:
  5003. - appID
  5004. - auth
  5005. - installationID
  5006. - organization
  5007. type: object
  5008. gitlab:
  5009. description: GitLab configures this store to sync secrets using GitLab Variables provider
  5010. properties:
  5011. auth:
  5012. description: Auth configures how secret-manager authenticates with a GitLab instance.
  5013. properties:
  5014. SecretRef:
  5015. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  5016. properties:
  5017. accessToken:
  5018. description: AccessToken is used for authentication.
  5019. properties:
  5020. key:
  5021. description: |-
  5022. A key in the referenced Secret.
  5023. Some instances of this field may be defaulted, in others it may be required.
  5024. maxLength: 253
  5025. minLength: 1
  5026. pattern: ^[-._a-zA-Z0-9]+$
  5027. type: string
  5028. name:
  5029. description: The name of the Secret resource being referred to.
  5030. maxLength: 253
  5031. minLength: 1
  5032. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5033. type: string
  5034. namespace:
  5035. description: |-
  5036. The namespace of the Secret resource being referred to.
  5037. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5038. maxLength: 63
  5039. minLength: 1
  5040. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5041. type: string
  5042. type: object
  5043. type: object
  5044. required:
  5045. - SecretRef
  5046. type: object
  5047. caBundle:
  5048. description: |-
  5049. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  5050. can be performed.
  5051. format: byte
  5052. type: string
  5053. caProvider:
  5054. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  5055. properties:
  5056. key:
  5057. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5058. maxLength: 253
  5059. minLength: 1
  5060. pattern: ^[-._a-zA-Z0-9]+$
  5061. type: string
  5062. name:
  5063. description: The name of the object located at the provider type.
  5064. maxLength: 253
  5065. minLength: 1
  5066. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5067. type: string
  5068. namespace:
  5069. description: |-
  5070. The namespace the Provider type is in.
  5071. Can only be defined when used in a ClusterSecretStore.
  5072. maxLength: 63
  5073. minLength: 1
  5074. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5075. type: string
  5076. type:
  5077. description: The type of provider to use such as "Secret", or "ConfigMap".
  5078. enum:
  5079. - Secret
  5080. - ConfigMap
  5081. type: string
  5082. required:
  5083. - name
  5084. - type
  5085. type: object
  5086. environment:
  5087. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  5088. type: string
  5089. groupIDs:
  5090. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  5091. items:
  5092. type: string
  5093. type: array
  5094. inheritFromGroups:
  5095. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  5096. type: boolean
  5097. projectID:
  5098. description: ProjectID specifies a project where secrets are located.
  5099. type: string
  5100. url:
  5101. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  5102. type: string
  5103. required:
  5104. - auth
  5105. type: object
  5106. ibm:
  5107. description: IBM configures this store to sync secrets using IBM Cloud provider
  5108. properties:
  5109. auth:
  5110. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  5111. maxProperties: 1
  5112. minProperties: 1
  5113. properties:
  5114. containerAuth:
  5115. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  5116. properties:
  5117. iamEndpoint:
  5118. type: string
  5119. profile:
  5120. description: the IBM Trusted Profile
  5121. type: string
  5122. tokenLocation:
  5123. description: Location the token is mounted on the pod
  5124. type: string
  5125. required:
  5126. - profile
  5127. type: object
  5128. secretRef:
  5129. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  5130. properties:
  5131. iamEndpoint:
  5132. description: The IAM endpoint used to obain a token
  5133. type: string
  5134. secretApiKeySecretRef:
  5135. description: The SecretAccessKey is used for authentication
  5136. properties:
  5137. key:
  5138. description: |-
  5139. A key in the referenced Secret.
  5140. Some instances of this field may be defaulted, in others it may be required.
  5141. maxLength: 253
  5142. minLength: 1
  5143. pattern: ^[-._a-zA-Z0-9]+$
  5144. type: string
  5145. name:
  5146. description: The name of the Secret resource being referred to.
  5147. maxLength: 253
  5148. minLength: 1
  5149. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5150. type: string
  5151. namespace:
  5152. description: |-
  5153. The namespace of the Secret resource being referred to.
  5154. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5155. maxLength: 63
  5156. minLength: 1
  5157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5158. type: string
  5159. type: object
  5160. type: object
  5161. type: object
  5162. serviceUrl:
  5163. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  5164. type: string
  5165. required:
  5166. - auth
  5167. type: object
  5168. infisical:
  5169. description: Infisical configures this store to sync secrets using the Infisical provider
  5170. properties:
  5171. auth:
  5172. description: Auth configures how the Operator authenticates with the Infisical API
  5173. properties:
  5174. awsAuthCredentials:
  5175. description: AwsAuthCredentials represents the credentials for AWS authentication.
  5176. properties:
  5177. identityId:
  5178. description: |-
  5179. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5180. In some instances, `key` is a required field.
  5181. properties:
  5182. key:
  5183. description: |-
  5184. A key in the referenced Secret.
  5185. Some instances of this field may be defaulted, in others it may be required.
  5186. maxLength: 253
  5187. minLength: 1
  5188. pattern: ^[-._a-zA-Z0-9]+$
  5189. type: string
  5190. name:
  5191. description: The name of the Secret resource being referred to.
  5192. maxLength: 253
  5193. minLength: 1
  5194. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5195. type: string
  5196. namespace:
  5197. description: |-
  5198. The namespace of the Secret resource being referred to.
  5199. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5200. maxLength: 63
  5201. minLength: 1
  5202. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5203. type: string
  5204. type: object
  5205. required:
  5206. - identityId
  5207. type: object
  5208. azureAuthCredentials:
  5209. description: AzureAuthCredentials represents the credentials for Azure authentication.
  5210. properties:
  5211. identityId:
  5212. description: |-
  5213. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5214. In some instances, `key` is a required field.
  5215. properties:
  5216. key:
  5217. description: |-
  5218. A key in the referenced Secret.
  5219. Some instances of this field may be defaulted, in others it may be required.
  5220. maxLength: 253
  5221. minLength: 1
  5222. pattern: ^[-._a-zA-Z0-9]+$
  5223. type: string
  5224. name:
  5225. description: The name of the Secret resource being referred to.
  5226. maxLength: 253
  5227. minLength: 1
  5228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5229. type: string
  5230. namespace:
  5231. description: |-
  5232. The namespace of the Secret resource being referred to.
  5233. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5234. maxLength: 63
  5235. minLength: 1
  5236. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5237. type: string
  5238. type: object
  5239. resource:
  5240. description: |-
  5241. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5242. In some instances, `key` is a required field.
  5243. properties:
  5244. key:
  5245. description: |-
  5246. A key in the referenced Secret.
  5247. Some instances of this field may be defaulted, in others it may be required.
  5248. maxLength: 253
  5249. minLength: 1
  5250. pattern: ^[-._a-zA-Z0-9]+$
  5251. type: string
  5252. name:
  5253. description: The name of the Secret resource being referred to.
  5254. maxLength: 253
  5255. minLength: 1
  5256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5257. type: string
  5258. namespace:
  5259. description: |-
  5260. The namespace of the Secret resource being referred to.
  5261. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5262. maxLength: 63
  5263. minLength: 1
  5264. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5265. type: string
  5266. type: object
  5267. required:
  5268. - identityId
  5269. type: object
  5270. gcpIamAuthCredentials:
  5271. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  5272. properties:
  5273. identityId:
  5274. description: |-
  5275. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5276. In some instances, `key` is a required field.
  5277. properties:
  5278. key:
  5279. description: |-
  5280. A key in the referenced Secret.
  5281. Some instances of this field may be defaulted, in others it may be required.
  5282. maxLength: 253
  5283. minLength: 1
  5284. pattern: ^[-._a-zA-Z0-9]+$
  5285. type: string
  5286. name:
  5287. description: The name of the Secret resource being referred to.
  5288. maxLength: 253
  5289. minLength: 1
  5290. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5291. type: string
  5292. namespace:
  5293. description: |-
  5294. The namespace of the Secret resource being referred to.
  5295. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5296. maxLength: 63
  5297. minLength: 1
  5298. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5299. type: string
  5300. type: object
  5301. serviceAccountKeyFilePath:
  5302. description: |-
  5303. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5304. In some instances, `key` is a required field.
  5305. properties:
  5306. key:
  5307. description: |-
  5308. A key in the referenced Secret.
  5309. Some instances of this field may be defaulted, in others it may be required.
  5310. maxLength: 253
  5311. minLength: 1
  5312. pattern: ^[-._a-zA-Z0-9]+$
  5313. type: string
  5314. name:
  5315. description: The name of the Secret resource being referred to.
  5316. maxLength: 253
  5317. minLength: 1
  5318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5319. type: string
  5320. namespace:
  5321. description: |-
  5322. The namespace of the Secret resource being referred to.
  5323. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5324. maxLength: 63
  5325. minLength: 1
  5326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5327. type: string
  5328. type: object
  5329. required:
  5330. - identityId
  5331. - serviceAccountKeyFilePath
  5332. type: object
  5333. gcpIdTokenAuthCredentials:
  5334. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  5335. properties:
  5336. identityId:
  5337. description: |-
  5338. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5339. In some instances, `key` is a required field.
  5340. properties:
  5341. key:
  5342. description: |-
  5343. A key in the referenced Secret.
  5344. Some instances of this field may be defaulted, in others it may be required.
  5345. maxLength: 253
  5346. minLength: 1
  5347. pattern: ^[-._a-zA-Z0-9]+$
  5348. type: string
  5349. name:
  5350. description: The name of the Secret resource being referred to.
  5351. maxLength: 253
  5352. minLength: 1
  5353. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5354. type: string
  5355. namespace:
  5356. description: |-
  5357. The namespace of the Secret resource being referred to.
  5358. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5359. maxLength: 63
  5360. minLength: 1
  5361. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5362. type: string
  5363. type: object
  5364. required:
  5365. - identityId
  5366. type: object
  5367. jwtAuthCredentials:
  5368. description: JwtAuthCredentials represents the credentials for JWT authentication.
  5369. properties:
  5370. identityId:
  5371. description: |-
  5372. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5373. In some instances, `key` is a required field.
  5374. properties:
  5375. key:
  5376. description: |-
  5377. A key in the referenced Secret.
  5378. Some instances of this field may be defaulted, in others it may be required.
  5379. maxLength: 253
  5380. minLength: 1
  5381. pattern: ^[-._a-zA-Z0-9]+$
  5382. type: string
  5383. name:
  5384. description: The name of the Secret resource being referred to.
  5385. maxLength: 253
  5386. minLength: 1
  5387. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5388. type: string
  5389. namespace:
  5390. description: |-
  5391. The namespace of the Secret resource being referred to.
  5392. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5393. maxLength: 63
  5394. minLength: 1
  5395. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5396. type: string
  5397. type: object
  5398. jwt:
  5399. description: |-
  5400. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5401. In some instances, `key` is a required field.
  5402. properties:
  5403. key:
  5404. description: |-
  5405. A key in the referenced Secret.
  5406. Some instances of this field may be defaulted, in others it may be required.
  5407. maxLength: 253
  5408. minLength: 1
  5409. pattern: ^[-._a-zA-Z0-9]+$
  5410. type: string
  5411. name:
  5412. description: The name of the Secret resource being referred to.
  5413. maxLength: 253
  5414. minLength: 1
  5415. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5416. type: string
  5417. namespace:
  5418. description: |-
  5419. The namespace of the Secret resource being referred to.
  5420. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5421. maxLength: 63
  5422. minLength: 1
  5423. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5424. type: string
  5425. type: object
  5426. required:
  5427. - identityId
  5428. - jwt
  5429. type: object
  5430. kubernetesAuthCredentials:
  5431. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  5432. properties:
  5433. identityId:
  5434. description: |-
  5435. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5436. In some instances, `key` is a required field.
  5437. properties:
  5438. key:
  5439. description: |-
  5440. A key in the referenced Secret.
  5441. Some instances of this field may be defaulted, in others it may be required.
  5442. maxLength: 253
  5443. minLength: 1
  5444. pattern: ^[-._a-zA-Z0-9]+$
  5445. type: string
  5446. name:
  5447. description: The name of the Secret resource being referred to.
  5448. maxLength: 253
  5449. minLength: 1
  5450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5451. type: string
  5452. namespace:
  5453. description: |-
  5454. The namespace of the Secret resource being referred to.
  5455. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5456. maxLength: 63
  5457. minLength: 1
  5458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5459. type: string
  5460. type: object
  5461. serviceAccountTokenPath:
  5462. description: |-
  5463. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5464. In some instances, `key` is a required field.
  5465. properties:
  5466. key:
  5467. description: |-
  5468. A key in the referenced Secret.
  5469. Some instances of this field may be defaulted, in others it may be required.
  5470. maxLength: 253
  5471. minLength: 1
  5472. pattern: ^[-._a-zA-Z0-9]+$
  5473. type: string
  5474. name:
  5475. description: The name of the Secret resource being referred to.
  5476. maxLength: 253
  5477. minLength: 1
  5478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5479. type: string
  5480. namespace:
  5481. description: |-
  5482. The namespace of the Secret resource being referred to.
  5483. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5484. maxLength: 63
  5485. minLength: 1
  5486. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5487. type: string
  5488. type: object
  5489. required:
  5490. - identityId
  5491. type: object
  5492. ldapAuthCredentials:
  5493. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  5494. properties:
  5495. identityId:
  5496. description: |-
  5497. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5498. In some instances, `key` is a required field.
  5499. properties:
  5500. key:
  5501. description: |-
  5502. A key in the referenced Secret.
  5503. Some instances of this field may be defaulted, in others it may be required.
  5504. maxLength: 253
  5505. minLength: 1
  5506. pattern: ^[-._a-zA-Z0-9]+$
  5507. type: string
  5508. name:
  5509. description: The name of the Secret resource being referred to.
  5510. maxLength: 253
  5511. minLength: 1
  5512. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5513. type: string
  5514. namespace:
  5515. description: |-
  5516. The namespace of the Secret resource being referred to.
  5517. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5518. maxLength: 63
  5519. minLength: 1
  5520. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5521. type: string
  5522. type: object
  5523. ldapPassword:
  5524. description: |-
  5525. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5526. In some instances, `key` is a required field.
  5527. properties:
  5528. key:
  5529. description: |-
  5530. A key in the referenced Secret.
  5531. Some instances of this field may be defaulted, in others it may be required.
  5532. maxLength: 253
  5533. minLength: 1
  5534. pattern: ^[-._a-zA-Z0-9]+$
  5535. type: string
  5536. name:
  5537. description: The name of the Secret resource being referred to.
  5538. maxLength: 253
  5539. minLength: 1
  5540. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5541. type: string
  5542. namespace:
  5543. description: |-
  5544. The namespace of the Secret resource being referred to.
  5545. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5546. maxLength: 63
  5547. minLength: 1
  5548. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5549. type: string
  5550. type: object
  5551. ldapUsername:
  5552. description: |-
  5553. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5554. In some instances, `key` is a required field.
  5555. properties:
  5556. key:
  5557. description: |-
  5558. A key in the referenced Secret.
  5559. Some instances of this field may be defaulted, in others it may be required.
  5560. maxLength: 253
  5561. minLength: 1
  5562. pattern: ^[-._a-zA-Z0-9]+$
  5563. type: string
  5564. name:
  5565. description: The name of the Secret resource being referred to.
  5566. maxLength: 253
  5567. minLength: 1
  5568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5569. type: string
  5570. namespace:
  5571. description: |-
  5572. The namespace of the Secret resource being referred to.
  5573. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5574. maxLength: 63
  5575. minLength: 1
  5576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5577. type: string
  5578. type: object
  5579. required:
  5580. - identityId
  5581. - ldapPassword
  5582. - ldapUsername
  5583. type: object
  5584. ociAuthCredentials:
  5585. description: OciAuthCredentials represents the credentials for OCI authentication.
  5586. properties:
  5587. fingerprint:
  5588. description: |-
  5589. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5590. In some instances, `key` is a required field.
  5591. properties:
  5592. key:
  5593. description: |-
  5594. A key in the referenced Secret.
  5595. Some instances of this field may be defaulted, in others it may be required.
  5596. maxLength: 253
  5597. minLength: 1
  5598. pattern: ^[-._a-zA-Z0-9]+$
  5599. type: string
  5600. name:
  5601. description: The name of the Secret resource being referred to.
  5602. maxLength: 253
  5603. minLength: 1
  5604. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5605. type: string
  5606. namespace:
  5607. description: |-
  5608. The namespace of the Secret resource being referred to.
  5609. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5610. maxLength: 63
  5611. minLength: 1
  5612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5613. type: string
  5614. type: object
  5615. identityId:
  5616. description: |-
  5617. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5618. In some instances, `key` is a required field.
  5619. properties:
  5620. key:
  5621. description: |-
  5622. A key in the referenced Secret.
  5623. Some instances of this field may be defaulted, in others it may be required.
  5624. maxLength: 253
  5625. minLength: 1
  5626. pattern: ^[-._a-zA-Z0-9]+$
  5627. type: string
  5628. name:
  5629. description: The name of the Secret resource being referred to.
  5630. maxLength: 253
  5631. minLength: 1
  5632. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5633. type: string
  5634. namespace:
  5635. description: |-
  5636. The namespace of the Secret resource being referred to.
  5637. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5638. maxLength: 63
  5639. minLength: 1
  5640. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5641. type: string
  5642. type: object
  5643. privateKey:
  5644. description: |-
  5645. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5646. In some instances, `key` is a required field.
  5647. properties:
  5648. key:
  5649. description: |-
  5650. A key in the referenced Secret.
  5651. Some instances of this field may be defaulted, in others it may be required.
  5652. maxLength: 253
  5653. minLength: 1
  5654. pattern: ^[-._a-zA-Z0-9]+$
  5655. type: string
  5656. name:
  5657. description: The name of the Secret resource being referred to.
  5658. maxLength: 253
  5659. minLength: 1
  5660. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5661. type: string
  5662. namespace:
  5663. description: |-
  5664. The namespace of the Secret resource being referred to.
  5665. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5666. maxLength: 63
  5667. minLength: 1
  5668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5669. type: string
  5670. type: object
  5671. privateKeyPassphrase:
  5672. description: |-
  5673. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5674. In some instances, `key` is a required field.
  5675. properties:
  5676. key:
  5677. description: |-
  5678. A key in the referenced Secret.
  5679. Some instances of this field may be defaulted, in others it may be required.
  5680. maxLength: 253
  5681. minLength: 1
  5682. pattern: ^[-._a-zA-Z0-9]+$
  5683. type: string
  5684. name:
  5685. description: The name of the Secret resource being referred to.
  5686. maxLength: 253
  5687. minLength: 1
  5688. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5689. type: string
  5690. namespace:
  5691. description: |-
  5692. The namespace of the Secret resource being referred to.
  5693. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5694. maxLength: 63
  5695. minLength: 1
  5696. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5697. type: string
  5698. type: object
  5699. region:
  5700. description: |-
  5701. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5702. In some instances, `key` is a required field.
  5703. properties:
  5704. key:
  5705. description: |-
  5706. A key in the referenced Secret.
  5707. Some instances of this field may be defaulted, in others it may be required.
  5708. maxLength: 253
  5709. minLength: 1
  5710. pattern: ^[-._a-zA-Z0-9]+$
  5711. type: string
  5712. name:
  5713. description: The name of the Secret resource being referred to.
  5714. maxLength: 253
  5715. minLength: 1
  5716. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5717. type: string
  5718. namespace:
  5719. description: |-
  5720. The namespace of the Secret resource being referred to.
  5721. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5722. maxLength: 63
  5723. minLength: 1
  5724. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5725. type: string
  5726. type: object
  5727. tenancyId:
  5728. description: |-
  5729. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5730. In some instances, `key` is a required field.
  5731. properties:
  5732. key:
  5733. description: |-
  5734. A key in the referenced Secret.
  5735. Some instances of this field may be defaulted, in others it may be required.
  5736. maxLength: 253
  5737. minLength: 1
  5738. pattern: ^[-._a-zA-Z0-9]+$
  5739. type: string
  5740. name:
  5741. description: The name of the Secret resource being referred to.
  5742. maxLength: 253
  5743. minLength: 1
  5744. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5745. type: string
  5746. namespace:
  5747. description: |-
  5748. The namespace of the Secret resource being referred to.
  5749. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5750. maxLength: 63
  5751. minLength: 1
  5752. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5753. type: string
  5754. type: object
  5755. userId:
  5756. description: |-
  5757. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5758. In some instances, `key` is a required field.
  5759. properties:
  5760. key:
  5761. description: |-
  5762. A key in the referenced Secret.
  5763. Some instances of this field may be defaulted, in others it may be required.
  5764. maxLength: 253
  5765. minLength: 1
  5766. pattern: ^[-._a-zA-Z0-9]+$
  5767. type: string
  5768. name:
  5769. description: The name of the Secret resource being referred to.
  5770. maxLength: 253
  5771. minLength: 1
  5772. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5773. type: string
  5774. namespace:
  5775. description: |-
  5776. The namespace of the Secret resource being referred to.
  5777. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5778. maxLength: 63
  5779. minLength: 1
  5780. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5781. type: string
  5782. type: object
  5783. required:
  5784. - fingerprint
  5785. - identityId
  5786. - privateKey
  5787. - region
  5788. - tenancyId
  5789. - userId
  5790. type: object
  5791. tokenAuthCredentials:
  5792. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  5793. properties:
  5794. accessToken:
  5795. description: |-
  5796. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5797. In some instances, `key` is a required field.
  5798. properties:
  5799. key:
  5800. description: |-
  5801. A key in the referenced Secret.
  5802. Some instances of this field may be defaulted, in others it may be required.
  5803. maxLength: 253
  5804. minLength: 1
  5805. pattern: ^[-._a-zA-Z0-9]+$
  5806. type: string
  5807. name:
  5808. description: The name of the Secret resource being referred to.
  5809. maxLength: 253
  5810. minLength: 1
  5811. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5812. type: string
  5813. namespace:
  5814. description: |-
  5815. The namespace of the Secret resource being referred to.
  5816. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5817. maxLength: 63
  5818. minLength: 1
  5819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5820. type: string
  5821. type: object
  5822. required:
  5823. - accessToken
  5824. type: object
  5825. universalAuthCredentials:
  5826. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  5827. properties:
  5828. clientId:
  5829. description: |-
  5830. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5831. In some instances, `key` is a required field.
  5832. properties:
  5833. key:
  5834. description: |-
  5835. A key in the referenced Secret.
  5836. Some instances of this field may be defaulted, in others it may be required.
  5837. maxLength: 253
  5838. minLength: 1
  5839. pattern: ^[-._a-zA-Z0-9]+$
  5840. type: string
  5841. name:
  5842. description: The name of the Secret resource being referred to.
  5843. maxLength: 253
  5844. minLength: 1
  5845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5846. type: string
  5847. namespace:
  5848. description: |-
  5849. The namespace of the Secret resource being referred to.
  5850. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5851. maxLength: 63
  5852. minLength: 1
  5853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5854. type: string
  5855. type: object
  5856. clientSecret:
  5857. description: |-
  5858. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5859. In some instances, `key` is a required field.
  5860. properties:
  5861. key:
  5862. description: |-
  5863. A key in the referenced Secret.
  5864. Some instances of this field may be defaulted, in others it may be required.
  5865. maxLength: 253
  5866. minLength: 1
  5867. pattern: ^[-._a-zA-Z0-9]+$
  5868. type: string
  5869. name:
  5870. description: The name of the Secret resource being referred to.
  5871. maxLength: 253
  5872. minLength: 1
  5873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5874. type: string
  5875. namespace:
  5876. description: |-
  5877. The namespace of the Secret resource being referred to.
  5878. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5879. maxLength: 63
  5880. minLength: 1
  5881. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5882. type: string
  5883. type: object
  5884. required:
  5885. - clientId
  5886. - clientSecret
  5887. type: object
  5888. type: object
  5889. caBundle:
  5890. description: |-
  5891. CABundle is a PEM-encoded CA certificate bundle used to validate
  5892. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  5893. format: byte
  5894. type: string
  5895. caProvider:
  5896. description: |-
  5897. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  5898. The certificate is used to validate the Infisical server's TLS certificate.
  5899. Mutually exclusive with CABundle.
  5900. properties:
  5901. key:
  5902. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5903. maxLength: 253
  5904. minLength: 1
  5905. pattern: ^[-._a-zA-Z0-9]+$
  5906. type: string
  5907. name:
  5908. description: The name of the object located at the provider type.
  5909. maxLength: 253
  5910. minLength: 1
  5911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5912. type: string
  5913. namespace:
  5914. description: |-
  5915. The namespace the Provider type is in.
  5916. Can only be defined when used in a ClusterSecretStore.
  5917. maxLength: 63
  5918. minLength: 1
  5919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5920. type: string
  5921. type:
  5922. description: The type of provider to use such as "Secret", or "ConfigMap".
  5923. enum:
  5924. - Secret
  5925. - ConfigMap
  5926. type: string
  5927. required:
  5928. - name
  5929. - type
  5930. type: object
  5931. hostAPI:
  5932. default: https://app.infisical.com/api
  5933. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  5934. type: string
  5935. secretsScope:
  5936. description: SecretsScope defines the scope of the secrets within the workspace
  5937. properties:
  5938. environmentSlug:
  5939. description: EnvironmentSlug is the required slug identifier for the environment.
  5940. type: string
  5941. expandSecretReferences:
  5942. default: true
  5943. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  5944. type: boolean
  5945. organizationSlug:
  5946. description: |-
  5947. OrganizationSlug is the optional slug that identifies the organization that will be used
  5948. during authentication. Useful for sub-organization setups
  5949. type: string
  5950. projectSlug:
  5951. description: ProjectSlug is the required slug identifier for the project.
  5952. type: string
  5953. recursive:
  5954. default: false
  5955. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  5956. type: boolean
  5957. secretsPath:
  5958. default: /
  5959. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  5960. type: string
  5961. required:
  5962. - environmentSlug
  5963. - projectSlug
  5964. type: object
  5965. required:
  5966. - auth
  5967. - secretsScope
  5968. type: object
  5969. keepersecurity:
  5970. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  5971. properties:
  5972. authRef:
  5973. description: |-
  5974. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5975. In some instances, `key` is a required field.
  5976. properties:
  5977. key:
  5978. description: |-
  5979. A key in the referenced Secret.
  5980. Some instances of this field may be defaulted, in others it may be required.
  5981. maxLength: 253
  5982. minLength: 1
  5983. pattern: ^[-._a-zA-Z0-9]+$
  5984. type: string
  5985. name:
  5986. description: The name of the Secret resource being referred to.
  5987. maxLength: 253
  5988. minLength: 1
  5989. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5990. type: string
  5991. namespace:
  5992. description: |-
  5993. The namespace of the Secret resource being referred to.
  5994. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5995. maxLength: 63
  5996. minLength: 1
  5997. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5998. type: string
  5999. type: object
  6000. folderID:
  6001. type: string
  6002. getByTitleFallback:
  6003. type: boolean
  6004. required:
  6005. - authRef
  6006. - folderID
  6007. type: object
  6008. kubernetes:
  6009. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  6010. properties:
  6011. auth:
  6012. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  6013. maxProperties: 1
  6014. minProperties: 1
  6015. properties:
  6016. cert:
  6017. description: has both clientCert and clientKey as secretKeySelector
  6018. properties:
  6019. clientCert:
  6020. description: |-
  6021. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6022. In some instances, `key` is a required field.
  6023. properties:
  6024. key:
  6025. description: |-
  6026. A key in the referenced Secret.
  6027. Some instances of this field may be defaulted, in others it may be required.
  6028. maxLength: 253
  6029. minLength: 1
  6030. pattern: ^[-._a-zA-Z0-9]+$
  6031. type: string
  6032. name:
  6033. description: The name of the Secret resource being referred to.
  6034. maxLength: 253
  6035. minLength: 1
  6036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6037. type: string
  6038. namespace:
  6039. description: |-
  6040. The namespace of the Secret resource being referred to.
  6041. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6042. maxLength: 63
  6043. minLength: 1
  6044. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6045. type: string
  6046. type: object
  6047. clientKey:
  6048. description: |-
  6049. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6050. In some instances, `key` is a required field.
  6051. properties:
  6052. key:
  6053. description: |-
  6054. A key in the referenced Secret.
  6055. Some instances of this field may be defaulted, in others it may be required.
  6056. maxLength: 253
  6057. minLength: 1
  6058. pattern: ^[-._a-zA-Z0-9]+$
  6059. type: string
  6060. name:
  6061. description: The name of the Secret resource being referred to.
  6062. maxLength: 253
  6063. minLength: 1
  6064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6065. type: string
  6066. namespace:
  6067. description: |-
  6068. The namespace of the Secret resource being referred to.
  6069. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6070. maxLength: 63
  6071. minLength: 1
  6072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6073. type: string
  6074. type: object
  6075. required:
  6076. - clientCert
  6077. - clientKey
  6078. type: object
  6079. serviceAccount:
  6080. description: points to a service account that should be used for authentication
  6081. properties:
  6082. audiences:
  6083. description: |-
  6084. Audience specifies the `aud` claim for the service account token
  6085. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  6086. then this audiences will be appended to the list
  6087. items:
  6088. type: string
  6089. type: array
  6090. name:
  6091. description: The name of the ServiceAccount resource being referred to.
  6092. maxLength: 253
  6093. minLength: 1
  6094. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6095. type: string
  6096. namespace:
  6097. description: |-
  6098. Namespace of the resource being referred to.
  6099. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6100. maxLength: 63
  6101. minLength: 1
  6102. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6103. type: string
  6104. required:
  6105. - name
  6106. type: object
  6107. token:
  6108. description: use static token to authenticate with
  6109. properties:
  6110. bearerToken:
  6111. description: |-
  6112. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6113. In some instances, `key` is a required field.
  6114. properties:
  6115. key:
  6116. description: |-
  6117. A key in the referenced Secret.
  6118. Some instances of this field may be defaulted, in others it may be required.
  6119. maxLength: 253
  6120. minLength: 1
  6121. pattern: ^[-._a-zA-Z0-9]+$
  6122. type: string
  6123. name:
  6124. description: The name of the Secret resource being referred to.
  6125. maxLength: 253
  6126. minLength: 1
  6127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6128. type: string
  6129. namespace:
  6130. description: |-
  6131. The namespace of the Secret resource being referred to.
  6132. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6133. maxLength: 63
  6134. minLength: 1
  6135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6136. type: string
  6137. type: object
  6138. required:
  6139. - bearerToken
  6140. type: object
  6141. type: object
  6142. authRef:
  6143. description: A reference to a secret that contains the auth information.
  6144. properties:
  6145. key:
  6146. description: |-
  6147. A key in the referenced Secret.
  6148. Some instances of this field may be defaulted, in others it may be required.
  6149. maxLength: 253
  6150. minLength: 1
  6151. pattern: ^[-._a-zA-Z0-9]+$
  6152. type: string
  6153. name:
  6154. description: The name of the Secret resource being referred to.
  6155. maxLength: 253
  6156. minLength: 1
  6157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6158. type: string
  6159. namespace:
  6160. description: |-
  6161. The namespace of the Secret resource being referred to.
  6162. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6163. maxLength: 63
  6164. minLength: 1
  6165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6166. type: string
  6167. type: object
  6168. remoteNamespace:
  6169. default: default
  6170. description: Remote namespace to fetch the secrets from
  6171. maxLength: 63
  6172. minLength: 1
  6173. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6174. type: string
  6175. server:
  6176. description: configures the Kubernetes server Address.
  6177. properties:
  6178. caBundle:
  6179. description: CABundle is a base64-encoded CA certificate
  6180. format: byte
  6181. type: string
  6182. caProvider:
  6183. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  6184. properties:
  6185. key:
  6186. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6187. maxLength: 253
  6188. minLength: 1
  6189. pattern: ^[-._a-zA-Z0-9]+$
  6190. type: string
  6191. name:
  6192. description: The name of the object located at the provider type.
  6193. maxLength: 253
  6194. minLength: 1
  6195. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6196. type: string
  6197. namespace:
  6198. description: |-
  6199. The namespace the Provider type is in.
  6200. Can only be defined when used in a ClusterSecretStore.
  6201. maxLength: 63
  6202. minLength: 1
  6203. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6204. type: string
  6205. type:
  6206. description: The type of provider to use such as "Secret", or "ConfigMap".
  6207. enum:
  6208. - Secret
  6209. - ConfigMap
  6210. type: string
  6211. required:
  6212. - name
  6213. - type
  6214. type: object
  6215. url:
  6216. default: kubernetes.default
  6217. description: configures the Kubernetes server Address.
  6218. type: string
  6219. type: object
  6220. type: object
  6221. nebiusmysterybox:
  6222. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  6223. properties:
  6224. apiDomain:
  6225. description: NebiusMysterybox API endpoint
  6226. type: string
  6227. auth:
  6228. description: Auth defines parameters to authenticate in MysteryBox
  6229. properties:
  6230. serviceAccountCredsSecretRef:
  6231. description: |-
  6232. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  6233. document with service account credentials used to get an IAM token.
  6234. Expected JSON structure:
  6235. {
  6236. "subject-credentials": {
  6237. "alg": "RS256",
  6238. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  6239. "kid": "<public-key-id>",
  6240. "iss": "<issuer-service-account-id>",
  6241. "sub": "<subject-service-account-id>"
  6242. }
  6243. }
  6244. properties:
  6245. key:
  6246. description: |-
  6247. A key in the referenced Secret.
  6248. Some instances of this field may be defaulted, in others it may be required.
  6249. maxLength: 253
  6250. minLength: 1
  6251. pattern: ^[-._a-zA-Z0-9]+$
  6252. type: string
  6253. name:
  6254. description: The name of the Secret resource being referred to.
  6255. maxLength: 253
  6256. minLength: 1
  6257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6258. type: string
  6259. namespace:
  6260. description: |-
  6261. The namespace of the Secret resource being referred to.
  6262. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6263. maxLength: 63
  6264. minLength: 1
  6265. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6266. type: string
  6267. type: object
  6268. tokenSecretRef:
  6269. description: Token authenticates with Nebius Mysterybox by presenting a token.
  6270. properties:
  6271. key:
  6272. description: |-
  6273. A key in the referenced Secret.
  6274. Some instances of this field may be defaulted, in others it may be required.
  6275. maxLength: 253
  6276. minLength: 1
  6277. pattern: ^[-._a-zA-Z0-9]+$
  6278. type: string
  6279. name:
  6280. description: The name of the Secret resource being referred to.
  6281. maxLength: 253
  6282. minLength: 1
  6283. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6284. type: string
  6285. namespace:
  6286. description: |-
  6287. The namespace of the Secret resource being referred to.
  6288. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6289. maxLength: 63
  6290. minLength: 1
  6291. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6292. type: string
  6293. type: object
  6294. type: object
  6295. x-kubernetes-validations:
  6296. - message: either serviceAccountCredsSecretRef or tokenSecretRef must be set
  6297. rule: has(self.serviceAccountCredsSecretRef) || has(self.tokenSecretRef)
  6298. caProvider:
  6299. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  6300. properties:
  6301. certSecretRef:
  6302. description: |-
  6303. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6304. In some instances, `key` is a required field.
  6305. properties:
  6306. key:
  6307. description: |-
  6308. A key in the referenced Secret.
  6309. Some instances of this field may be defaulted, in others it may be required.
  6310. maxLength: 253
  6311. minLength: 1
  6312. pattern: ^[-._a-zA-Z0-9]+$
  6313. type: string
  6314. name:
  6315. description: The name of the Secret resource being referred to.
  6316. maxLength: 253
  6317. minLength: 1
  6318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6319. type: string
  6320. namespace:
  6321. description: |-
  6322. The namespace of the Secret resource being referred to.
  6323. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6324. maxLength: 63
  6325. minLength: 1
  6326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6327. type: string
  6328. type: object
  6329. type: object
  6330. required:
  6331. - apiDomain
  6332. - auth
  6333. type: object
  6334. ngrok:
  6335. description: Ngrok configures this store to sync secrets using the ngrok provider.
  6336. properties:
  6337. apiUrl:
  6338. default: https://api.ngrok.com
  6339. description: APIURL is the URL of the ngrok API.
  6340. type: string
  6341. auth:
  6342. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  6343. maxProperties: 1
  6344. minProperties: 1
  6345. properties:
  6346. apiKey:
  6347. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  6348. properties:
  6349. secretRef:
  6350. description: SecretRef is a reference to a secret containing the ngrok API key.
  6351. properties:
  6352. key:
  6353. description: |-
  6354. A key in the referenced Secret.
  6355. Some instances of this field may be defaulted, in others it may be required.
  6356. maxLength: 253
  6357. minLength: 1
  6358. pattern: ^[-._a-zA-Z0-9]+$
  6359. type: string
  6360. name:
  6361. description: The name of the Secret resource being referred to.
  6362. maxLength: 253
  6363. minLength: 1
  6364. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6365. type: string
  6366. namespace:
  6367. description: |-
  6368. The namespace of the Secret resource being referred to.
  6369. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6370. maxLength: 63
  6371. minLength: 1
  6372. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6373. type: string
  6374. type: object
  6375. type: object
  6376. type: object
  6377. vault:
  6378. description: Vault configures the ngrok vault to sync secrets with.
  6379. properties:
  6380. name:
  6381. description: Name is the name of the ngrok vault to sync secrets with.
  6382. type: string
  6383. required:
  6384. - name
  6385. type: object
  6386. required:
  6387. - auth
  6388. - vault
  6389. type: object
  6390. onboardbase:
  6391. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  6392. properties:
  6393. apiHost:
  6394. default: https://public.onboardbase.com/api/v1/
  6395. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  6396. type: string
  6397. auth:
  6398. description: Auth configures how the Operator authenticates with the Onboardbase API
  6399. properties:
  6400. apiKeyRef:
  6401. description: |-
  6402. OnboardbaseAPIKey is the APIKey generated by an admin account.
  6403. It is used to recognize and authorize access to a project and environment within onboardbase
  6404. properties:
  6405. key:
  6406. description: |-
  6407. A key in the referenced Secret.
  6408. Some instances of this field may be defaulted, in others it may be required.
  6409. maxLength: 253
  6410. minLength: 1
  6411. pattern: ^[-._a-zA-Z0-9]+$
  6412. type: string
  6413. name:
  6414. description: The name of the Secret resource being referred to.
  6415. maxLength: 253
  6416. minLength: 1
  6417. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6418. type: string
  6419. namespace:
  6420. description: |-
  6421. The namespace of the Secret resource being referred to.
  6422. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6423. maxLength: 63
  6424. minLength: 1
  6425. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6426. type: string
  6427. type: object
  6428. passcodeRef:
  6429. description: OnboardbasePasscode is the passcode attached to the API Key
  6430. properties:
  6431. key:
  6432. description: |-
  6433. A key in the referenced Secret.
  6434. Some instances of this field may be defaulted, in others it may be required.
  6435. maxLength: 253
  6436. minLength: 1
  6437. pattern: ^[-._a-zA-Z0-9]+$
  6438. type: string
  6439. name:
  6440. description: The name of the Secret resource being referred to.
  6441. maxLength: 253
  6442. minLength: 1
  6443. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6444. type: string
  6445. namespace:
  6446. description: |-
  6447. The namespace of the Secret resource being referred to.
  6448. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6449. maxLength: 63
  6450. minLength: 1
  6451. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6452. type: string
  6453. type: object
  6454. required:
  6455. - apiKeyRef
  6456. - passcodeRef
  6457. type: object
  6458. environment:
  6459. default: development
  6460. description: Environment is the name of an environmnent within a project to pull the secrets from
  6461. type: string
  6462. project:
  6463. default: development
  6464. description: Project is an onboardbase project that the secrets should be pulled from
  6465. type: string
  6466. required:
  6467. - apiHost
  6468. - auth
  6469. - environment
  6470. - project
  6471. type: object
  6472. onepassword:
  6473. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  6474. properties:
  6475. auth:
  6476. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  6477. properties:
  6478. secretRef:
  6479. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  6480. properties:
  6481. connectTokenSecretRef:
  6482. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  6483. properties:
  6484. key:
  6485. description: |-
  6486. A key in the referenced Secret.
  6487. Some instances of this field may be defaulted, in others it may be required.
  6488. maxLength: 253
  6489. minLength: 1
  6490. pattern: ^[-._a-zA-Z0-9]+$
  6491. type: string
  6492. name:
  6493. description: The name of the Secret resource being referred to.
  6494. maxLength: 253
  6495. minLength: 1
  6496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6497. type: string
  6498. namespace:
  6499. description: |-
  6500. The namespace of the Secret resource being referred to.
  6501. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6502. maxLength: 63
  6503. minLength: 1
  6504. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6505. type: string
  6506. type: object
  6507. required:
  6508. - connectTokenSecretRef
  6509. type: object
  6510. required:
  6511. - secretRef
  6512. type: object
  6513. connectHost:
  6514. description: ConnectHost defines the OnePassword Connect Server to connect to
  6515. type: string
  6516. vaults:
  6517. additionalProperties:
  6518. type: integer
  6519. description: Vaults defines which OnePassword vaults to search in which order
  6520. type: object
  6521. required:
  6522. - auth
  6523. - connectHost
  6524. - vaults
  6525. type: object
  6526. onepasswordSDK:
  6527. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  6528. properties:
  6529. auth:
  6530. description: Auth defines the information necessary to authenticate against OnePassword API.
  6531. properties:
  6532. serviceAccountSecretRef:
  6533. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  6534. properties:
  6535. key:
  6536. description: |-
  6537. A key in the referenced Secret.
  6538. Some instances of this field may be defaulted, in others it may be required.
  6539. maxLength: 253
  6540. minLength: 1
  6541. pattern: ^[-._a-zA-Z0-9]+$
  6542. type: string
  6543. name:
  6544. description: The name of the Secret resource being referred to.
  6545. maxLength: 253
  6546. minLength: 1
  6547. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6548. type: string
  6549. namespace:
  6550. description: |-
  6551. The namespace of the Secret resource being referred to.
  6552. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6553. maxLength: 63
  6554. minLength: 1
  6555. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6556. type: string
  6557. type: object
  6558. required:
  6559. - serviceAccountSecretRef
  6560. type: object
  6561. cache:
  6562. description: |-
  6563. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  6564. When enabled, secrets are cached with the specified TTL.
  6565. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  6566. If omitted, caching is disabled (default).
  6567. cache: {} is a valid option to set.
  6568. properties:
  6569. maxSize:
  6570. default: 100
  6571. description: |-
  6572. MaxSize is the maximum number of secrets to cache.
  6573. When the cache is full, least-recently-used entries are evicted.
  6574. minimum: 1
  6575. type: integer
  6576. ttl:
  6577. default: 5m
  6578. description: |-
  6579. TTL is the time-to-live for cached secrets.
  6580. Format: duration string (e.g., "5m", "1h", "30s")
  6581. type: string
  6582. type: object
  6583. environment:
  6584. description: |-
  6585. Environment defines the 1Password Environment ID to read variables from.
  6586. Environments are read-only: PushSecret, DeleteSecret, and SecretExists return an error when set.
  6587. Mutually exclusive with Vault.
  6588. type: string
  6589. integrationInfo:
  6590. description: |-
  6591. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  6592. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  6593. properties:
  6594. name:
  6595. default: 1Password SDK
  6596. description: Name defaults to "1Password SDK".
  6597. type: string
  6598. version:
  6599. default: v1.0.0
  6600. description: Version defaults to "v1.0.0".
  6601. type: string
  6602. type: object
  6603. vault:
  6604. description: |-
  6605. Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  6606. Mutually exclusive with Environment.
  6607. type: string
  6608. required:
  6609. - auth
  6610. type: object
  6611. x-kubernetes-validations:
  6612. - message: at most one of the fields in [vault environment] may be set
  6613. rule: '[has(self.vault),has(self.environment)].filter(x,x==true).size() <= 1'
  6614. openBao:
  6615. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  6616. properties:
  6617. auth:
  6618. description: Auth configures how secret-manager authenticates with the OpenBao server.
  6619. properties:
  6620. appRole:
  6621. description: |-
  6622. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  6623. with the role and secret stored in a Kubernetes Secret resource.
  6624. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  6625. properties:
  6626. path:
  6627. default: approle
  6628. description: |-
  6629. Path where the App Role authentication backend is mounted
  6630. in OpenBao, e.g: "approle"
  6631. type: string
  6632. roleId:
  6633. description: |-
  6634. RoleID configured in the App Role authentication backend when setting
  6635. up the authentication backend in OpenBao.
  6636. minLength: 1
  6637. type: string
  6638. roleRef:
  6639. description: |-
  6640. Reference to a key in a Secret that contains the App Role ID used
  6641. to authenticate with OpenBao.
  6642. The `key` field must be specified and denotes which entry within the Secret
  6643. resource is used as the app role id.
  6644. properties:
  6645. key:
  6646. description: |-
  6647. A key in the referenced Secret.
  6648. Some instances of this field may be defaulted, in others it may be required.
  6649. maxLength: 253
  6650. minLength: 1
  6651. pattern: ^[-._a-zA-Z0-9]+$
  6652. type: string
  6653. name:
  6654. description: The name of the Secret resource being referred to.
  6655. maxLength: 253
  6656. minLength: 1
  6657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6658. type: string
  6659. namespace:
  6660. description: |-
  6661. The namespace of the Secret resource being referred to.
  6662. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6663. maxLength: 63
  6664. minLength: 1
  6665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6666. type: string
  6667. type: object
  6668. secretRef:
  6669. description: |-
  6670. Reference to a key in a Secret that contains the App Role secret used
  6671. to authenticate with OpenBao.
  6672. The `key` field must be specified and denotes which entry within the Secret
  6673. resource is used as the app role secret.
  6674. properties:
  6675. key:
  6676. description: |-
  6677. A key in the referenced Secret.
  6678. Some instances of this field may be defaulted, in others it may be required.
  6679. maxLength: 253
  6680. minLength: 1
  6681. pattern: ^[-._a-zA-Z0-9]+$
  6682. type: string
  6683. name:
  6684. description: The name of the Secret resource being referred to.
  6685. maxLength: 253
  6686. minLength: 1
  6687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6688. type: string
  6689. namespace:
  6690. description: |-
  6691. The namespace of the Secret resource being referred to.
  6692. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6693. maxLength: 63
  6694. minLength: 1
  6695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6696. type: string
  6697. type: object
  6698. required:
  6699. - path
  6700. - secretRef
  6701. type: object
  6702. x-kubernetes-validations:
  6703. - message: exactly one of the fields in [roleId roleRef] must be set
  6704. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  6705. namespace:
  6706. description: |-
  6707. Name of the [OpenBao Namespace] to authenticate to. This can be different
  6708. than the namespace your secret is in. Namespaces is a set of features
  6709. within OpenBao that allows OpenBao environments to support secure
  6710. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  6711. if set, or empty otherwise
  6712. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6713. type: string
  6714. tokenSecretRef:
  6715. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  6716. properties:
  6717. key:
  6718. description: |-
  6719. A key in the referenced Secret.
  6720. Some instances of this field may be defaulted, in others it may be required.
  6721. maxLength: 253
  6722. minLength: 1
  6723. pattern: ^[-._a-zA-Z0-9]+$
  6724. type: string
  6725. name:
  6726. description: The name of the Secret resource being referred to.
  6727. maxLength: 253
  6728. minLength: 1
  6729. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6730. type: string
  6731. namespace:
  6732. description: |-
  6733. The namespace of the Secret resource being referred to.
  6734. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6735. maxLength: 63
  6736. minLength: 1
  6737. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6738. type: string
  6739. type: object
  6740. userPass:
  6741. description: UserPass authenticates with OpenBao by passing a username/password pair
  6742. properties:
  6743. path:
  6744. default: userpass
  6745. description: |-
  6746. Path where the UserPassword authentication backend is mounted
  6747. in OpenBao, e.g: "userpass"
  6748. type: string
  6749. secretRef:
  6750. description: |-
  6751. SecretRef to a key in a Secret resource containing password for the user
  6752. used to authenticate with OpenBao using the [UserPass authentication
  6753. method]
  6754. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6755. properties:
  6756. key:
  6757. description: |-
  6758. A key in the referenced Secret.
  6759. Some instances of this field may be defaulted, in others it may be required.
  6760. maxLength: 253
  6761. minLength: 1
  6762. pattern: ^[-._a-zA-Z0-9]+$
  6763. type: string
  6764. name:
  6765. description: The name of the Secret resource being referred to.
  6766. maxLength: 253
  6767. minLength: 1
  6768. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6769. type: string
  6770. namespace:
  6771. description: |-
  6772. The namespace of the Secret resource being referred to.
  6773. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6774. maxLength: 63
  6775. minLength: 1
  6776. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6777. type: string
  6778. type: object
  6779. username:
  6780. description: |-
  6781. Username is a username used to authenticate using the [UserPass
  6782. authentication method]
  6783. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6784. type: string
  6785. required:
  6786. - path
  6787. - username
  6788. type: object
  6789. type: object
  6790. x-kubernetes-validations:
  6791. - message: exactly one of the fields in [appRole tokenSecretRef userPass] must be set
  6792. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass)].filter(x,x==true).size() == 1'
  6793. caBundle:
  6794. description: |-
  6795. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  6796. this and `caProvider` are not set the system root certificates are used
  6797. to validate the TLS connection.
  6798. format: byte
  6799. type: string
  6800. caProvider:
  6801. description: |-
  6802. The provider for the CA bundle to use to validate OpenBao server
  6803. certificate. If this and `caBundle` are not set the system root
  6804. certificates are used to validate the TLS connection.
  6805. properties:
  6806. key:
  6807. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6808. maxLength: 253
  6809. minLength: 1
  6810. pattern: ^[-._a-zA-Z0-9]+$
  6811. type: string
  6812. name:
  6813. description: The name of the object located at the provider type.
  6814. maxLength: 253
  6815. minLength: 1
  6816. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6817. type: string
  6818. namespace:
  6819. description: |-
  6820. The namespace the Provider type is in.
  6821. Can only be defined when used in a ClusterSecretStore.
  6822. maxLength: 63
  6823. minLength: 1
  6824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6825. type: string
  6826. type:
  6827. description: The type of provider to use such as "Secret", or "ConfigMap".
  6828. enum:
  6829. - Secret
  6830. - ConfigMap
  6831. type: string
  6832. required:
  6833. - name
  6834. - type
  6835. type: object
  6836. namespace:
  6837. description: |-
  6838. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  6839. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  6840. e.g: "ns1".
  6841. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6842. type: string
  6843. path:
  6844. description: |-
  6845. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  6846. "secret". The v2 KV secret engine version specific "/data" path suffix
  6847. for fetching secrets from OpenBao is optional and will be appended
  6848. if not present in specified path.
  6849. type: string
  6850. server:
  6851. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  6852. type: string
  6853. version:
  6854. default: v2
  6855. description: |-
  6856. Version is the OpenBao KV secret engine version. This can be either "v1" or
  6857. "v2". Version defaults to "v2".
  6858. enum:
  6859. - v1
  6860. - v2
  6861. type: string
  6862. required:
  6863. - server
  6864. type: object
  6865. x-kubernetes-validations:
  6866. - message: at most one of the fields in [caBundle caProvider] may be set
  6867. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  6868. oracle:
  6869. description: Oracle configures this store to sync secrets using Oracle Vault provider
  6870. properties:
  6871. auth:
  6872. description: |-
  6873. Auth configures how secret-manager authenticates with the Oracle Vault.
  6874. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  6875. properties:
  6876. secretRef:
  6877. description: SecretRef to pass through sensitive information.
  6878. properties:
  6879. fingerprint:
  6880. description: Fingerprint is the fingerprint of the API private key.
  6881. properties:
  6882. key:
  6883. description: |-
  6884. A key in the referenced Secret.
  6885. Some instances of this field may be defaulted, in others it may be required.
  6886. maxLength: 253
  6887. minLength: 1
  6888. pattern: ^[-._a-zA-Z0-9]+$
  6889. type: string
  6890. name:
  6891. description: The name of the Secret resource being referred to.
  6892. maxLength: 253
  6893. minLength: 1
  6894. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6895. type: string
  6896. namespace:
  6897. description: |-
  6898. The namespace of the Secret resource being referred to.
  6899. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6900. maxLength: 63
  6901. minLength: 1
  6902. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6903. type: string
  6904. type: object
  6905. privatekey:
  6906. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  6907. properties:
  6908. key:
  6909. description: |-
  6910. A key in the referenced Secret.
  6911. Some instances of this field may be defaulted, in others it may be required.
  6912. maxLength: 253
  6913. minLength: 1
  6914. pattern: ^[-._a-zA-Z0-9]+$
  6915. type: string
  6916. name:
  6917. description: The name of the Secret resource being referred to.
  6918. maxLength: 253
  6919. minLength: 1
  6920. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6921. type: string
  6922. namespace:
  6923. description: |-
  6924. The namespace of the Secret resource being referred to.
  6925. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6926. maxLength: 63
  6927. minLength: 1
  6928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6929. type: string
  6930. type: object
  6931. required:
  6932. - fingerprint
  6933. - privatekey
  6934. type: object
  6935. tenancy:
  6936. description: Tenancy is the tenancy OCID where user is located.
  6937. type: string
  6938. user:
  6939. description: User is an access OCID specific to the account.
  6940. type: string
  6941. required:
  6942. - secretRef
  6943. - tenancy
  6944. - user
  6945. type: object
  6946. compartment:
  6947. description: |-
  6948. Compartment is the vault compartment OCID.
  6949. Required for PushSecret
  6950. type: string
  6951. encryptionKey:
  6952. description: |-
  6953. EncryptionKey is the OCID of the encryption key within the vault.
  6954. Required for PushSecret
  6955. type: string
  6956. principalType:
  6957. description: |-
  6958. The type of principal to use for authentication. If left blank, the Auth struct will
  6959. determine the principal type. This optional field must be specified if using
  6960. workload identity.
  6961. enum:
  6962. - ""
  6963. - UserPrincipal
  6964. - InstancePrincipal
  6965. - Workload
  6966. type: string
  6967. region:
  6968. description: Region is the region where vault is located.
  6969. type: string
  6970. serviceAccountRef:
  6971. description: |-
  6972. ServiceAccountRef specified the service account
  6973. that should be used when authenticating with WorkloadIdentity.
  6974. properties:
  6975. audiences:
  6976. description: |-
  6977. Audience specifies the `aud` claim for the service account token
  6978. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  6979. then this audiences will be appended to the list
  6980. items:
  6981. type: string
  6982. type: array
  6983. name:
  6984. description: The name of the ServiceAccount resource being referred to.
  6985. maxLength: 253
  6986. minLength: 1
  6987. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6988. type: string
  6989. namespace:
  6990. description: |-
  6991. Namespace of the resource being referred to.
  6992. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6993. maxLength: 63
  6994. minLength: 1
  6995. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6996. type: string
  6997. required:
  6998. - name
  6999. type: object
  7000. vault:
  7001. description: Vault is the vault's OCID of the specific vault where secret is located.
  7002. type: string
  7003. required:
  7004. - region
  7005. - vault
  7006. type: object
  7007. ovh:
  7008. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  7009. properties:
  7010. auth:
  7011. description: Authentication method (mtls or token).
  7012. properties:
  7013. mtls:
  7014. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  7015. properties:
  7016. caBundle:
  7017. format: byte
  7018. type: string
  7019. caProvider:
  7020. description: |-
  7021. CAProvider provides a custom certificate authority for accessing the provider's store.
  7022. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  7023. properties:
  7024. key:
  7025. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7026. maxLength: 253
  7027. minLength: 1
  7028. pattern: ^[-._a-zA-Z0-9]+$
  7029. type: string
  7030. name:
  7031. description: The name of the object located at the provider type.
  7032. maxLength: 253
  7033. minLength: 1
  7034. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7035. type: string
  7036. namespace:
  7037. description: |-
  7038. The namespace the Provider type is in.
  7039. Can only be defined when used in a ClusterSecretStore.
  7040. maxLength: 63
  7041. minLength: 1
  7042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7043. type: string
  7044. type:
  7045. description: The type of provider to use such as "Secret", or "ConfigMap".
  7046. enum:
  7047. - Secret
  7048. - ConfigMap
  7049. type: string
  7050. required:
  7051. - name
  7052. - type
  7053. type: object
  7054. certSecretRef:
  7055. description: |-
  7056. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7057. In some instances, `key` is a required field.
  7058. properties:
  7059. key:
  7060. description: |-
  7061. A key in the referenced Secret.
  7062. Some instances of this field may be defaulted, in others it may be required.
  7063. maxLength: 253
  7064. minLength: 1
  7065. pattern: ^[-._a-zA-Z0-9]+$
  7066. type: string
  7067. name:
  7068. description: The name of the Secret resource being referred to.
  7069. maxLength: 253
  7070. minLength: 1
  7071. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7072. type: string
  7073. namespace:
  7074. description: |-
  7075. The namespace of the Secret resource being referred to.
  7076. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7077. maxLength: 63
  7078. minLength: 1
  7079. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7080. type: string
  7081. type: object
  7082. keySecretRef:
  7083. description: |-
  7084. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7085. In some instances, `key` is a required field.
  7086. properties:
  7087. key:
  7088. description: |-
  7089. A key in the referenced Secret.
  7090. Some instances of this field may be defaulted, in others it may be required.
  7091. maxLength: 253
  7092. minLength: 1
  7093. pattern: ^[-._a-zA-Z0-9]+$
  7094. type: string
  7095. name:
  7096. description: The name of the Secret resource being referred to.
  7097. maxLength: 253
  7098. minLength: 1
  7099. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7100. type: string
  7101. namespace:
  7102. description: |-
  7103. The namespace of the Secret resource being referred to.
  7104. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7105. maxLength: 63
  7106. minLength: 1
  7107. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7108. type: string
  7109. type: object
  7110. required:
  7111. - certSecretRef
  7112. - keySecretRef
  7113. type: object
  7114. token:
  7115. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  7116. properties:
  7117. tokenSecretRef:
  7118. description: |-
  7119. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7120. In some instances, `key` is a required field.
  7121. properties:
  7122. key:
  7123. description: |-
  7124. A key in the referenced Secret.
  7125. Some instances of this field may be defaulted, in others it may be required.
  7126. maxLength: 253
  7127. minLength: 1
  7128. pattern: ^[-._a-zA-Z0-9]+$
  7129. type: string
  7130. name:
  7131. description: The name of the Secret resource being referred to.
  7132. maxLength: 253
  7133. minLength: 1
  7134. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7135. type: string
  7136. namespace:
  7137. description: |-
  7138. The namespace of the Secret resource being referred to.
  7139. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7140. maxLength: 63
  7141. minLength: 1
  7142. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7143. type: string
  7144. type: object
  7145. required:
  7146. - tokenSecretRef
  7147. type: object
  7148. type: object
  7149. casRequired:
  7150. description: 'Enables or disables check-and-set (CAS) (default: false).'
  7151. type: boolean
  7152. okmsTimeout:
  7153. default: 30
  7154. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  7155. format: int32
  7156. minimum: 1
  7157. type: integer
  7158. okmsid:
  7159. description: specifies the OKMS ID.
  7160. type: string
  7161. server:
  7162. description: specifies the OKMS server endpoint.
  7163. type: string
  7164. required:
  7165. - auth
  7166. - okmsid
  7167. - server
  7168. type: object
  7169. passbolt:
  7170. description: |-
  7171. PassboltProvider provides access to Passbolt secrets manager.
  7172. See: https://www.passbolt.com.
  7173. properties:
  7174. auth:
  7175. description: Auth defines the information necessary to authenticate against Passbolt Server
  7176. properties:
  7177. passwordSecretRef:
  7178. description: |-
  7179. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7180. In some instances, `key` is a required field.
  7181. properties:
  7182. key:
  7183. description: |-
  7184. A key in the referenced Secret.
  7185. Some instances of this field may be defaulted, in others it may be required.
  7186. maxLength: 253
  7187. minLength: 1
  7188. pattern: ^[-._a-zA-Z0-9]+$
  7189. type: string
  7190. name:
  7191. description: The name of the Secret resource being referred to.
  7192. maxLength: 253
  7193. minLength: 1
  7194. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7195. type: string
  7196. namespace:
  7197. description: |-
  7198. The namespace of the Secret resource being referred to.
  7199. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7200. maxLength: 63
  7201. minLength: 1
  7202. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7203. type: string
  7204. type: object
  7205. privateKeySecretRef:
  7206. description: |-
  7207. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7208. In some instances, `key` is a required field.
  7209. properties:
  7210. key:
  7211. description: |-
  7212. A key in the referenced Secret.
  7213. Some instances of this field may be defaulted, in others it may be required.
  7214. maxLength: 253
  7215. minLength: 1
  7216. pattern: ^[-._a-zA-Z0-9]+$
  7217. type: string
  7218. name:
  7219. description: The name of the Secret resource being referred to.
  7220. maxLength: 253
  7221. minLength: 1
  7222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7223. type: string
  7224. namespace:
  7225. description: |-
  7226. The namespace of the Secret resource being referred to.
  7227. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7228. maxLength: 63
  7229. minLength: 1
  7230. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7231. type: string
  7232. type: object
  7233. required:
  7234. - passwordSecretRef
  7235. - privateKeySecretRef
  7236. type: object
  7237. caBundle:
  7238. description: |-
  7239. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  7240. if the Host URL is using HTTPS protocol. If not set the system root certificates
  7241. are used to validate the TLS connection.
  7242. format: byte
  7243. type: string
  7244. caProvider:
  7245. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  7246. properties:
  7247. key:
  7248. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7249. maxLength: 253
  7250. minLength: 1
  7251. pattern: ^[-._a-zA-Z0-9]+$
  7252. type: string
  7253. name:
  7254. description: The name of the object located at the provider type.
  7255. maxLength: 253
  7256. minLength: 1
  7257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7258. type: string
  7259. namespace:
  7260. description: |-
  7261. The namespace the Provider type is in.
  7262. Can only be defined when used in a ClusterSecretStore.
  7263. maxLength: 63
  7264. minLength: 1
  7265. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7266. type: string
  7267. type:
  7268. description: The type of provider to use such as "Secret", or "ConfigMap".
  7269. enum:
  7270. - Secret
  7271. - ConfigMap
  7272. type: string
  7273. required:
  7274. - name
  7275. - type
  7276. type: object
  7277. host:
  7278. description: Host defines the Passbolt Server to connect to
  7279. type: string
  7280. required:
  7281. - auth
  7282. - host
  7283. type: object
  7284. passworddepot:
  7285. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  7286. properties:
  7287. auth:
  7288. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  7289. properties:
  7290. secretRef:
  7291. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  7292. properties:
  7293. credentials:
  7294. description: Username / Password is used for authentication.
  7295. properties:
  7296. key:
  7297. description: |-
  7298. A key in the referenced Secret.
  7299. Some instances of this field may be defaulted, in others it may be required.
  7300. maxLength: 253
  7301. minLength: 1
  7302. pattern: ^[-._a-zA-Z0-9]+$
  7303. type: string
  7304. name:
  7305. description: The name of the Secret resource being referred to.
  7306. maxLength: 253
  7307. minLength: 1
  7308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7309. type: string
  7310. namespace:
  7311. description: |-
  7312. The namespace of the Secret resource being referred to.
  7313. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7314. maxLength: 63
  7315. minLength: 1
  7316. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7317. type: string
  7318. type: object
  7319. type: object
  7320. required:
  7321. - secretRef
  7322. type: object
  7323. database:
  7324. description: Database to use as source
  7325. type: string
  7326. host:
  7327. description: URL configures the Password Depot instance URL.
  7328. type: string
  7329. required:
  7330. - auth
  7331. - database
  7332. - host
  7333. type: object
  7334. previder:
  7335. description: Previder configures this store to sync secrets using the Previder provider
  7336. properties:
  7337. auth:
  7338. description: PreviderAuth contains a secretRef for credentials.
  7339. properties:
  7340. secretRef:
  7341. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  7342. properties:
  7343. accessToken:
  7344. description: The AccessToken is used for authentication
  7345. properties:
  7346. key:
  7347. description: |-
  7348. A key in the referenced Secret.
  7349. Some instances of this field may be defaulted, in others it may be required.
  7350. maxLength: 253
  7351. minLength: 1
  7352. pattern: ^[-._a-zA-Z0-9]+$
  7353. type: string
  7354. name:
  7355. description: The name of the Secret resource being referred to.
  7356. maxLength: 253
  7357. minLength: 1
  7358. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7359. type: string
  7360. namespace:
  7361. description: |-
  7362. The namespace of the Secret resource being referred to.
  7363. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7364. maxLength: 63
  7365. minLength: 1
  7366. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7367. type: string
  7368. type: object
  7369. required:
  7370. - accessToken
  7371. type: object
  7372. type: object
  7373. baseUri:
  7374. type: string
  7375. required:
  7376. - auth
  7377. type: object
  7378. pulumi:
  7379. description: Pulumi configures this store to sync secrets using the Pulumi provider
  7380. properties:
  7381. accessToken:
  7382. description: |-
  7383. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  7384. Deprecated: Use auth.accessToken instead.
  7385. properties:
  7386. secretRef:
  7387. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7388. properties:
  7389. key:
  7390. description: |-
  7391. A key in the referenced Secret.
  7392. Some instances of this field may be defaulted, in others it may be required.
  7393. maxLength: 253
  7394. minLength: 1
  7395. pattern: ^[-._a-zA-Z0-9]+$
  7396. type: string
  7397. name:
  7398. description: The name of the Secret resource being referred to.
  7399. maxLength: 253
  7400. minLength: 1
  7401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7402. type: string
  7403. namespace:
  7404. description: |-
  7405. The namespace of the Secret resource being referred to.
  7406. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7407. maxLength: 63
  7408. minLength: 1
  7409. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7410. type: string
  7411. type: object
  7412. type: object
  7413. apiUrl:
  7414. default: https://api.pulumi.com/api/esc
  7415. description: APIURL is the URL of the Pulumi API.
  7416. type: string
  7417. auth:
  7418. description: |-
  7419. Auth configures how the Operator authenticates with the Pulumi API.
  7420. Either auth or the deprecated accessToken field must be specified.
  7421. properties:
  7422. accessToken:
  7423. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  7424. properties:
  7425. secretRef:
  7426. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7427. properties:
  7428. key:
  7429. description: |-
  7430. A key in the referenced Secret.
  7431. Some instances of this field may be defaulted, in others it may be required.
  7432. maxLength: 253
  7433. minLength: 1
  7434. pattern: ^[-._a-zA-Z0-9]+$
  7435. type: string
  7436. name:
  7437. description: The name of the Secret resource being referred to.
  7438. maxLength: 253
  7439. minLength: 1
  7440. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7441. type: string
  7442. namespace:
  7443. description: |-
  7444. The namespace of the Secret resource being referred to.
  7445. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7446. maxLength: 63
  7447. minLength: 1
  7448. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7449. type: string
  7450. type: object
  7451. type: object
  7452. oidcConfig:
  7453. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  7454. properties:
  7455. expirationSeconds:
  7456. default: 600
  7457. description: |-
  7458. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  7459. Defaults to 10 minutes.
  7460. format: int64
  7461. minimum: 600
  7462. type: integer
  7463. organization:
  7464. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  7465. type: string
  7466. serviceAccountRef:
  7467. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  7468. properties:
  7469. audiences:
  7470. description: |-
  7471. Audience specifies the `aud` claim for the service account token
  7472. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  7473. then this audiences will be appended to the list
  7474. items:
  7475. type: string
  7476. type: array
  7477. name:
  7478. description: The name of the ServiceAccount resource being referred to.
  7479. maxLength: 253
  7480. minLength: 1
  7481. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7482. type: string
  7483. namespace:
  7484. description: |-
  7485. Namespace of the resource being referred to.
  7486. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7487. maxLength: 63
  7488. minLength: 1
  7489. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7490. type: string
  7491. required:
  7492. - name
  7493. type: object
  7494. required:
  7495. - organization
  7496. - serviceAccountRef
  7497. type: object
  7498. type: object
  7499. x-kubernetes-validations:
  7500. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  7501. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  7502. environment:
  7503. description: |-
  7504. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  7505. dynamically retrieved values from supported providers including all major clouds,
  7506. and other Pulumi ESC environments.
  7507. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  7508. type: string
  7509. organization:
  7510. description: |-
  7511. Organization are a space to collaborate on shared projects and stacks.
  7512. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  7513. type: string
  7514. project:
  7515. description: Project is the name of the Pulumi ESC project the environment belongs to.
  7516. type: string
  7517. required:
  7518. - environment
  7519. - organization
  7520. - project
  7521. type: object
  7522. x-kubernetes-validations:
  7523. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  7524. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  7525. scaleway:
  7526. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  7527. properties:
  7528. accessKey:
  7529. description: AccessKey is the non-secret part of the api key.
  7530. properties:
  7531. secretRef:
  7532. description: SecretRef references a key in a secret that will be used as value.
  7533. properties:
  7534. key:
  7535. description: |-
  7536. A key in the referenced Secret.
  7537. Some instances of this field may be defaulted, in others it may be required.
  7538. maxLength: 253
  7539. minLength: 1
  7540. pattern: ^[-._a-zA-Z0-9]+$
  7541. type: string
  7542. name:
  7543. description: The name of the Secret resource being referred to.
  7544. maxLength: 253
  7545. minLength: 1
  7546. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7547. type: string
  7548. namespace:
  7549. description: |-
  7550. The namespace of the Secret resource being referred to.
  7551. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7552. maxLength: 63
  7553. minLength: 1
  7554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7555. type: string
  7556. type: object
  7557. value:
  7558. description: Value can be specified directly to set a value without using a secret.
  7559. type: string
  7560. type: object
  7561. apiUrl:
  7562. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  7563. type: string
  7564. projectId:
  7565. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  7566. type: string
  7567. region:
  7568. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  7569. type: string
  7570. secretKey:
  7571. description: SecretKey is the non-secret part of the api key.
  7572. properties:
  7573. secretRef:
  7574. description: SecretRef references a key in a secret that will be used as value.
  7575. properties:
  7576. key:
  7577. description: |-
  7578. A key in the referenced Secret.
  7579. Some instances of this field may be defaulted, in others it may be required.
  7580. maxLength: 253
  7581. minLength: 1
  7582. pattern: ^[-._a-zA-Z0-9]+$
  7583. type: string
  7584. name:
  7585. description: The name of the Secret resource being referred to.
  7586. maxLength: 253
  7587. minLength: 1
  7588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7589. type: string
  7590. namespace:
  7591. description: |-
  7592. The namespace of the Secret resource being referred to.
  7593. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7594. maxLength: 63
  7595. minLength: 1
  7596. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7597. type: string
  7598. type: object
  7599. value:
  7600. description: Value can be specified directly to set a value without using a secret.
  7601. type: string
  7602. type: object
  7603. required:
  7604. - accessKey
  7605. - projectId
  7606. - region
  7607. - secretKey
  7608. type: object
  7609. secretserver:
  7610. description: |-
  7611. SecretServer configures this store to sync secrets using SecretServer provider
  7612. https://docs.delinea.com/online-help/secret-server/start.htm
  7613. properties:
  7614. caBundle:
  7615. description: |-
  7616. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  7617. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  7618. are used to validate the TLS connection.
  7619. format: byte
  7620. type: string
  7621. caProvider:
  7622. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  7623. properties:
  7624. key:
  7625. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7626. maxLength: 253
  7627. minLength: 1
  7628. pattern: ^[-._a-zA-Z0-9]+$
  7629. type: string
  7630. name:
  7631. description: The name of the object located at the provider type.
  7632. maxLength: 253
  7633. minLength: 1
  7634. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7635. type: string
  7636. namespace:
  7637. description: |-
  7638. The namespace the Provider type is in.
  7639. Can only be defined when used in a ClusterSecretStore.
  7640. maxLength: 63
  7641. minLength: 1
  7642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7643. type: string
  7644. type:
  7645. description: The type of provider to use such as "Secret", or "ConfigMap".
  7646. enum:
  7647. - Secret
  7648. - ConfigMap
  7649. type: string
  7650. required:
  7651. - name
  7652. - type
  7653. type: object
  7654. domain:
  7655. description: Domain is the secret server domain.
  7656. type: string
  7657. password:
  7658. description: |-
  7659. Password is the secret server account password.
  7660. Required unless Token is set.
  7661. properties:
  7662. secretRef:
  7663. description: SecretRef references a key in a secret that will be used as value.
  7664. properties:
  7665. key:
  7666. description: |-
  7667. A key in the referenced Secret.
  7668. Some instances of this field may be defaulted, in others it may be required.
  7669. maxLength: 253
  7670. minLength: 1
  7671. pattern: ^[-._a-zA-Z0-9]+$
  7672. type: string
  7673. name:
  7674. description: The name of the Secret resource being referred to.
  7675. maxLength: 253
  7676. minLength: 1
  7677. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7678. type: string
  7679. namespace:
  7680. description: |-
  7681. The namespace of the Secret resource being referred to.
  7682. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7683. maxLength: 63
  7684. minLength: 1
  7685. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7686. type: string
  7687. type: object
  7688. value:
  7689. description: Value can be specified directly to set a value without using a secret.
  7690. minLength: 1
  7691. type: string
  7692. type: object
  7693. x-kubernetes-validations:
  7694. - message: exactly one of value or secretRef must be set
  7695. rule: has(self.value) != has(self.secretRef)
  7696. serverURL:
  7697. description: |-
  7698. ServerURL
  7699. URL to your secret server installation
  7700. type: string
  7701. token:
  7702. description: |-
  7703. Token is an access token used to authenticate to the secret server,
  7704. as an alternative to Username and Password. When set, Username and
  7705. Password are not required and are ignored.
  7706. properties:
  7707. secretRef:
  7708. description: SecretRef references a key in a secret that will be used as value.
  7709. properties:
  7710. key:
  7711. description: |-
  7712. A key in the referenced Secret.
  7713. Some instances of this field may be defaulted, in others it may be required.
  7714. maxLength: 253
  7715. minLength: 1
  7716. pattern: ^[-._a-zA-Z0-9]+$
  7717. type: string
  7718. name:
  7719. description: The name of the Secret resource being referred to.
  7720. maxLength: 253
  7721. minLength: 1
  7722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7723. type: string
  7724. namespace:
  7725. description: |-
  7726. The namespace of the Secret resource being referred to.
  7727. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7728. maxLength: 63
  7729. minLength: 1
  7730. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7731. type: string
  7732. type: object
  7733. value:
  7734. description: Value can be specified directly to set a value without using a secret.
  7735. minLength: 1
  7736. type: string
  7737. type: object
  7738. x-kubernetes-validations:
  7739. - message: exactly one of value or secretRef must be set
  7740. rule: has(self.value) != has(self.secretRef)
  7741. username:
  7742. description: |-
  7743. Username is the secret server account username.
  7744. Required unless Token is set.
  7745. properties:
  7746. secretRef:
  7747. description: SecretRef references a key in a secret that will be used as value.
  7748. properties:
  7749. key:
  7750. description: |-
  7751. A key in the referenced Secret.
  7752. Some instances of this field may be defaulted, in others it may be required.
  7753. maxLength: 253
  7754. minLength: 1
  7755. pattern: ^[-._a-zA-Z0-9]+$
  7756. type: string
  7757. name:
  7758. description: The name of the Secret resource being referred to.
  7759. maxLength: 253
  7760. minLength: 1
  7761. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7762. type: string
  7763. namespace:
  7764. description: |-
  7765. The namespace of the Secret resource being referred to.
  7766. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7767. maxLength: 63
  7768. minLength: 1
  7769. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7770. type: string
  7771. type: object
  7772. value:
  7773. description: Value can be specified directly to set a value without using a secret.
  7774. minLength: 1
  7775. type: string
  7776. type: object
  7777. x-kubernetes-validations:
  7778. - message: exactly one of value or secretRef must be set
  7779. rule: has(self.value) != has(self.secretRef)
  7780. required:
  7781. - serverURL
  7782. type: object
  7783. x-kubernetes-validations:
  7784. - message: either token, or both username and password, must be set
  7785. rule: has(self.token) || (has(self.username) && has(self.password))
  7786. senhasegura:
  7787. description: Senhasegura configures this store to sync secrets using senhasegura provider
  7788. properties:
  7789. auth:
  7790. description: Auth defines parameters to authenticate in senhasegura
  7791. properties:
  7792. clientId:
  7793. type: string
  7794. clientSecretSecretRef:
  7795. description: |-
  7796. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7797. In some instances, `key` is a required field.
  7798. properties:
  7799. key:
  7800. description: |-
  7801. A key in the referenced Secret.
  7802. Some instances of this field may be defaulted, in others it may be required.
  7803. maxLength: 253
  7804. minLength: 1
  7805. pattern: ^[-._a-zA-Z0-9]+$
  7806. type: string
  7807. name:
  7808. description: The name of the Secret resource being referred to.
  7809. maxLength: 253
  7810. minLength: 1
  7811. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7812. type: string
  7813. namespace:
  7814. description: |-
  7815. The namespace of the Secret resource being referred to.
  7816. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7817. maxLength: 63
  7818. minLength: 1
  7819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7820. type: string
  7821. type: object
  7822. required:
  7823. - clientId
  7824. - clientSecretSecretRef
  7825. type: object
  7826. ignoreSslCertificate:
  7827. default: false
  7828. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  7829. type: boolean
  7830. module:
  7831. description: Module defines which senhasegura module should be used to get secrets
  7832. type: string
  7833. url:
  7834. description: URL of senhasegura
  7835. type: string
  7836. required:
  7837. - auth
  7838. - module
  7839. - url
  7840. type: object
  7841. vault:
  7842. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  7843. properties:
  7844. auth:
  7845. description: Auth configures how secret-manager authenticates with the Vault server.
  7846. properties:
  7847. appRole:
  7848. description: |-
  7849. AppRole authenticates with Vault using the App Role auth mechanism,
  7850. with the role and secret stored in a Kubernetes Secret resource.
  7851. properties:
  7852. path:
  7853. default: approle
  7854. description: |-
  7855. Path where the App Role authentication backend is mounted
  7856. in Vault, e.g: "approle"
  7857. type: string
  7858. roleId:
  7859. description: |-
  7860. RoleID configured in the App Role authentication backend when setting
  7861. up the authentication backend in Vault.
  7862. type: string
  7863. roleRef:
  7864. description: |-
  7865. Reference to a key in a Secret that contains the App Role ID used
  7866. to authenticate with Vault.
  7867. The `key` field must be specified and denotes which entry within the Secret
  7868. resource is used as the app role id.
  7869. properties:
  7870. key:
  7871. description: |-
  7872. A key in the referenced Secret.
  7873. Some instances of this field may be defaulted, in others it may be required.
  7874. maxLength: 253
  7875. minLength: 1
  7876. pattern: ^[-._a-zA-Z0-9]+$
  7877. type: string
  7878. name:
  7879. description: The name of the Secret resource being referred to.
  7880. maxLength: 253
  7881. minLength: 1
  7882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7883. type: string
  7884. namespace:
  7885. description: |-
  7886. The namespace of the Secret resource being referred to.
  7887. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7888. maxLength: 63
  7889. minLength: 1
  7890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7891. type: string
  7892. type: object
  7893. secretRef:
  7894. description: |-
  7895. Reference to a key in a Secret that contains the App Role secret used
  7896. to authenticate with Vault.
  7897. The `key` field must be specified and denotes which entry within the Secret
  7898. resource is used as the app role secret.
  7899. properties:
  7900. key:
  7901. description: |-
  7902. A key in the referenced Secret.
  7903. Some instances of this field may be defaulted, in others it may be required.
  7904. maxLength: 253
  7905. minLength: 1
  7906. pattern: ^[-._a-zA-Z0-9]+$
  7907. type: string
  7908. name:
  7909. description: The name of the Secret resource being referred to.
  7910. maxLength: 253
  7911. minLength: 1
  7912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7913. type: string
  7914. namespace:
  7915. description: |-
  7916. The namespace of the Secret resource being referred to.
  7917. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7918. maxLength: 63
  7919. minLength: 1
  7920. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7921. type: string
  7922. type: object
  7923. required:
  7924. - path
  7925. - secretRef
  7926. type: object
  7927. cert:
  7928. description: |-
  7929. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  7930. Cert authentication method
  7931. properties:
  7932. clientCert:
  7933. description: |-
  7934. ClientCert is a certificate to authenticate using the Cert Vault
  7935. authentication method
  7936. properties:
  7937. key:
  7938. description: |-
  7939. A key in the referenced Secret.
  7940. Some instances of this field may be defaulted, in others it may be required.
  7941. maxLength: 253
  7942. minLength: 1
  7943. pattern: ^[-._a-zA-Z0-9]+$
  7944. type: string
  7945. name:
  7946. description: The name of the Secret resource being referred to.
  7947. maxLength: 253
  7948. minLength: 1
  7949. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7950. type: string
  7951. namespace:
  7952. description: |-
  7953. The namespace of the Secret resource being referred to.
  7954. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7955. maxLength: 63
  7956. minLength: 1
  7957. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7958. type: string
  7959. type: object
  7960. path:
  7961. default: cert
  7962. description: |-
  7963. Path where the Certificate authentication backend is mounted
  7964. in Vault, e.g: "cert"
  7965. type: string
  7966. secretRef:
  7967. description: |-
  7968. SecretRef to a key in a Secret resource containing client private key to
  7969. authenticate with Vault using the Cert authentication method
  7970. properties:
  7971. key:
  7972. description: |-
  7973. A key in the referenced Secret.
  7974. Some instances of this field may be defaulted, in others it may be required.
  7975. maxLength: 253
  7976. minLength: 1
  7977. pattern: ^[-._a-zA-Z0-9]+$
  7978. type: string
  7979. name:
  7980. description: The name of the Secret resource being referred to.
  7981. maxLength: 253
  7982. minLength: 1
  7983. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7984. type: string
  7985. namespace:
  7986. description: |-
  7987. The namespace of the Secret resource being referred to.
  7988. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7989. maxLength: 63
  7990. minLength: 1
  7991. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7992. type: string
  7993. type: object
  7994. vaultRole:
  7995. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  7996. type: string
  7997. type: object
  7998. gcp:
  7999. description: |-
  8000. Gcp authenticates with Vault using Google Cloud Platform authentication method
  8001. GCP authentication method
  8002. properties:
  8003. location:
  8004. description: Location optionally defines a location/region for the secret
  8005. type: string
  8006. path:
  8007. default: gcp
  8008. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  8009. type: string
  8010. projectID:
  8011. description: Project ID of the Google Cloud Platform project
  8012. type: string
  8013. role:
  8014. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  8015. type: string
  8016. secretRef:
  8017. description: Specify credentials in a Secret object
  8018. properties:
  8019. secretAccessKeySecretRef:
  8020. description: The SecretAccessKey is used for authentication
  8021. properties:
  8022. key:
  8023. description: |-
  8024. A key in the referenced Secret.
  8025. Some instances of this field may be defaulted, in others it may be required.
  8026. maxLength: 253
  8027. minLength: 1
  8028. pattern: ^[-._a-zA-Z0-9]+$
  8029. type: string
  8030. name:
  8031. description: The name of the Secret resource being referred to.
  8032. maxLength: 253
  8033. minLength: 1
  8034. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8035. type: string
  8036. namespace:
  8037. description: |-
  8038. The namespace of the Secret resource being referred to.
  8039. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8040. maxLength: 63
  8041. minLength: 1
  8042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8043. type: string
  8044. type: object
  8045. type: object
  8046. serviceAccountRef:
  8047. description: ServiceAccountRef to a service account for impersonation
  8048. properties:
  8049. audiences:
  8050. description: |-
  8051. Audience specifies the `aud` claim for the service account token
  8052. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8053. then this audiences will be appended to the list
  8054. items:
  8055. type: string
  8056. type: array
  8057. name:
  8058. description: The name of the ServiceAccount resource being referred to.
  8059. maxLength: 253
  8060. minLength: 1
  8061. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8062. type: string
  8063. namespace:
  8064. description: |-
  8065. Namespace of the resource being referred to.
  8066. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8067. maxLength: 63
  8068. minLength: 1
  8069. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8070. type: string
  8071. required:
  8072. - name
  8073. type: object
  8074. workloadIdentity:
  8075. description: Specify a service account with Workload Identity
  8076. properties:
  8077. clusterLocation:
  8078. description: |-
  8079. ClusterLocation is the location of the cluster
  8080. If not specified, it fetches information from the metadata server
  8081. type: string
  8082. clusterName:
  8083. description: |-
  8084. ClusterName is the name of the cluster
  8085. If not specified, it fetches information from the metadata server
  8086. type: string
  8087. clusterProjectID:
  8088. description: |-
  8089. ClusterProjectID is the project ID of the cluster
  8090. If not specified, it fetches information from the metadata server
  8091. type: string
  8092. serviceAccountRef:
  8093. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  8094. properties:
  8095. audiences:
  8096. description: |-
  8097. Audience specifies the `aud` claim for the service account token
  8098. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8099. then this audiences will be appended to the list
  8100. items:
  8101. type: string
  8102. type: array
  8103. name:
  8104. description: The name of the ServiceAccount resource being referred to.
  8105. maxLength: 253
  8106. minLength: 1
  8107. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8108. type: string
  8109. namespace:
  8110. description: |-
  8111. Namespace of the resource being referred to.
  8112. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8113. maxLength: 63
  8114. minLength: 1
  8115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8116. type: string
  8117. required:
  8118. - name
  8119. type: object
  8120. required:
  8121. - serviceAccountRef
  8122. type: object
  8123. required:
  8124. - role
  8125. type: object
  8126. iam:
  8127. description: |-
  8128. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  8129. AWS IAM authentication method
  8130. properties:
  8131. externalID:
  8132. description: AWS External ID set on assumed IAM roles
  8133. type: string
  8134. jwt:
  8135. description: Specify a service account with IRSA enabled
  8136. properties:
  8137. serviceAccountRef:
  8138. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  8139. properties:
  8140. audiences:
  8141. description: |-
  8142. Audience specifies the `aud` claim for the service account token
  8143. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8144. then this audiences will be appended to the list
  8145. items:
  8146. type: string
  8147. type: array
  8148. name:
  8149. description: The name of the ServiceAccount resource being referred to.
  8150. maxLength: 253
  8151. minLength: 1
  8152. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8153. type: string
  8154. namespace:
  8155. description: |-
  8156. Namespace of the resource being referred to.
  8157. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8158. maxLength: 63
  8159. minLength: 1
  8160. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8161. type: string
  8162. required:
  8163. - name
  8164. type: object
  8165. type: object
  8166. path:
  8167. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  8168. type: string
  8169. region:
  8170. description: AWS region
  8171. type: string
  8172. role:
  8173. description: This is the AWS role to be assumed before talking to vault
  8174. type: string
  8175. secretRef:
  8176. description: Specify credentials in a Secret object
  8177. properties:
  8178. accessKeyIDSecretRef:
  8179. description: The AccessKeyID is used for authentication
  8180. properties:
  8181. key:
  8182. description: |-
  8183. A key in the referenced Secret.
  8184. Some instances of this field may be defaulted, in others it may be required.
  8185. maxLength: 253
  8186. minLength: 1
  8187. pattern: ^[-._a-zA-Z0-9]+$
  8188. type: string
  8189. name:
  8190. description: The name of the Secret resource being referred to.
  8191. maxLength: 253
  8192. minLength: 1
  8193. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8194. type: string
  8195. namespace:
  8196. description: |-
  8197. The namespace of the Secret resource being referred to.
  8198. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8199. maxLength: 63
  8200. minLength: 1
  8201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8202. type: string
  8203. type: object
  8204. secretAccessKeySecretRef:
  8205. description: The SecretAccessKey is used for authentication
  8206. properties:
  8207. key:
  8208. description: |-
  8209. A key in the referenced Secret.
  8210. Some instances of this field may be defaulted, in others it may be required.
  8211. maxLength: 253
  8212. minLength: 1
  8213. pattern: ^[-._a-zA-Z0-9]+$
  8214. type: string
  8215. name:
  8216. description: The name of the Secret resource being referred to.
  8217. maxLength: 253
  8218. minLength: 1
  8219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8220. type: string
  8221. namespace:
  8222. description: |-
  8223. The namespace of the Secret resource being referred to.
  8224. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8225. maxLength: 63
  8226. minLength: 1
  8227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8228. type: string
  8229. type: object
  8230. sessionTokenSecretRef:
  8231. description: |-
  8232. The SessionToken used for authentication
  8233. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  8234. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  8235. properties:
  8236. key:
  8237. description: |-
  8238. A key in the referenced Secret.
  8239. Some instances of this field may be defaulted, in others it may be required.
  8240. maxLength: 253
  8241. minLength: 1
  8242. pattern: ^[-._a-zA-Z0-9]+$
  8243. type: string
  8244. name:
  8245. description: The name of the Secret resource being referred to.
  8246. maxLength: 253
  8247. minLength: 1
  8248. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8249. type: string
  8250. namespace:
  8251. description: |-
  8252. The namespace of the Secret resource being referred to.
  8253. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8254. maxLength: 63
  8255. minLength: 1
  8256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8257. type: string
  8258. type: object
  8259. type: object
  8260. vaultAwsIamServerID:
  8261. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  8262. type: string
  8263. vaultRole:
  8264. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  8265. type: string
  8266. required:
  8267. - vaultRole
  8268. type: object
  8269. jwt:
  8270. description: |-
  8271. Jwt authenticates with Vault by passing role and JWT token using the
  8272. JWT/OIDC authentication method
  8273. properties:
  8274. kubernetesServiceAccountToken:
  8275. description: |-
  8276. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  8277. a token for with the `TokenRequest` API.
  8278. properties:
  8279. audiences:
  8280. description: |-
  8281. Optional audiences field that will be used to request a temporary Kubernetes service
  8282. account token for the service account referenced by `serviceAccountRef`.
  8283. Defaults to a single audience `vault` it not specified.
  8284. Deprecated: use serviceAccountRef.Audiences instead
  8285. items:
  8286. type: string
  8287. type: array
  8288. expirationSeconds:
  8289. description: |-
  8290. Optional expiration time in seconds that will be used to request a temporary
  8291. Kubernetes service account token for the service account referenced by
  8292. `serviceAccountRef`.
  8293. Deprecated: this will be removed in the future.
  8294. Defaults to 10 minutes.
  8295. format: int64
  8296. type: integer
  8297. serviceAccountRef:
  8298. description: Service account field containing the name of a kubernetes ServiceAccount.
  8299. properties:
  8300. audiences:
  8301. description: |-
  8302. Audience specifies the `aud` claim for the service account token
  8303. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8304. then this audiences will be appended to the list
  8305. items:
  8306. type: string
  8307. type: array
  8308. name:
  8309. description: The name of the ServiceAccount resource being referred to.
  8310. maxLength: 253
  8311. minLength: 1
  8312. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8313. type: string
  8314. namespace:
  8315. description: |-
  8316. Namespace of the resource being referred to.
  8317. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8318. maxLength: 63
  8319. minLength: 1
  8320. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8321. type: string
  8322. required:
  8323. - name
  8324. type: object
  8325. required:
  8326. - serviceAccountRef
  8327. type: object
  8328. path:
  8329. default: jwt
  8330. description: |-
  8331. Path where the JWT authentication backend is mounted
  8332. in Vault, e.g: "jwt"
  8333. type: string
  8334. role:
  8335. description: |-
  8336. Role is a JWT role to authenticate using the JWT/OIDC Vault
  8337. authentication method
  8338. type: string
  8339. secretRef:
  8340. description: |-
  8341. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  8342. authenticate with Vault using the JWT/OIDC authentication method.
  8343. properties:
  8344. key:
  8345. description: |-
  8346. A key in the referenced Secret.
  8347. Some instances of this field may be defaulted, in others it may be required.
  8348. maxLength: 253
  8349. minLength: 1
  8350. pattern: ^[-._a-zA-Z0-9]+$
  8351. type: string
  8352. name:
  8353. description: The name of the Secret resource being referred to.
  8354. maxLength: 253
  8355. minLength: 1
  8356. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8357. type: string
  8358. namespace:
  8359. description: |-
  8360. The namespace of the Secret resource being referred to.
  8361. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8362. maxLength: 63
  8363. minLength: 1
  8364. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8365. type: string
  8366. type: object
  8367. required:
  8368. - path
  8369. type: object
  8370. kubernetes:
  8371. description: |-
  8372. Kubernetes authenticates with Vault by passing the ServiceAccount
  8373. token stored in the named Secret resource to the Vault server.
  8374. properties:
  8375. mountPath:
  8376. default: kubernetes
  8377. description: |-
  8378. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  8379. "kubernetes"
  8380. type: string
  8381. role:
  8382. description: |-
  8383. A required field containing the Vault Role to assume. A Role binds a
  8384. Kubernetes ServiceAccount with a set of Vault policies.
  8385. type: string
  8386. secretRef:
  8387. description: |-
  8388. Optional secret field containing a Kubernetes ServiceAccount JWT used
  8389. for authenticating with Vault. If a name is specified without a key,
  8390. `token` is the default. If one is not specified, the one bound to
  8391. the controller will be used.
  8392. properties:
  8393. key:
  8394. description: |-
  8395. A key in the referenced Secret.
  8396. Some instances of this field may be defaulted, in others it may be required.
  8397. maxLength: 253
  8398. minLength: 1
  8399. pattern: ^[-._a-zA-Z0-9]+$
  8400. type: string
  8401. name:
  8402. description: The name of the Secret resource being referred to.
  8403. maxLength: 253
  8404. minLength: 1
  8405. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8406. type: string
  8407. namespace:
  8408. description: |-
  8409. The namespace of the Secret resource being referred to.
  8410. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8411. maxLength: 63
  8412. minLength: 1
  8413. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8414. type: string
  8415. type: object
  8416. serviceAccountRef:
  8417. description: |-
  8418. Optional service account field containing the name of a kubernetes ServiceAccount.
  8419. If the service account is specified, the service account secret token JWT will be used
  8420. for authenticating with Vault. If the service account selector is not supplied,
  8421. the secretRef will be used instead.
  8422. properties:
  8423. audiences:
  8424. description: |-
  8425. Audience specifies the `aud` claim for the service account token
  8426. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8427. then this audiences will be appended to the list
  8428. items:
  8429. type: string
  8430. type: array
  8431. name:
  8432. description: The name of the ServiceAccount resource being referred to.
  8433. maxLength: 253
  8434. minLength: 1
  8435. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8436. type: string
  8437. namespace:
  8438. description: |-
  8439. Namespace of the resource being referred to.
  8440. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8441. maxLength: 63
  8442. minLength: 1
  8443. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8444. type: string
  8445. required:
  8446. - name
  8447. type: object
  8448. required:
  8449. - mountPath
  8450. - role
  8451. type: object
  8452. ldap:
  8453. description: |-
  8454. Ldap authenticates with Vault by passing username/password pair using
  8455. the LDAP authentication method
  8456. properties:
  8457. path:
  8458. default: ldap
  8459. description: |-
  8460. Path where the LDAP authentication backend is mounted
  8461. in Vault, e.g: "ldap"
  8462. type: string
  8463. secretRef:
  8464. description: |-
  8465. SecretRef to a key in a Secret resource containing password for the LDAP
  8466. user used to authenticate with Vault using the LDAP authentication
  8467. method
  8468. properties:
  8469. key:
  8470. description: |-
  8471. A key in the referenced Secret.
  8472. Some instances of this field may be defaulted, in others it may be required.
  8473. maxLength: 253
  8474. minLength: 1
  8475. pattern: ^[-._a-zA-Z0-9]+$
  8476. type: string
  8477. name:
  8478. description: The name of the Secret resource being referred to.
  8479. maxLength: 253
  8480. minLength: 1
  8481. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8482. type: string
  8483. namespace:
  8484. description: |-
  8485. The namespace of the Secret resource being referred to.
  8486. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8487. maxLength: 63
  8488. minLength: 1
  8489. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8490. type: string
  8491. type: object
  8492. username:
  8493. description: |-
  8494. Username is an LDAP username used to authenticate using the LDAP Vault
  8495. authentication method
  8496. type: string
  8497. required:
  8498. - path
  8499. - username
  8500. type: object
  8501. namespace:
  8502. description: |-
  8503. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  8504. Namespaces is a set of features within Vault Enterprise that allows
  8505. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8506. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8507. This will default to Vault.Namespace field if set, or empty otherwise
  8508. type: string
  8509. tokenSecretRef:
  8510. description: TokenSecretRef authenticates with Vault by presenting a token.
  8511. properties:
  8512. key:
  8513. description: |-
  8514. A key in the referenced Secret.
  8515. Some instances of this field may be defaulted, in others it may be required.
  8516. maxLength: 253
  8517. minLength: 1
  8518. pattern: ^[-._a-zA-Z0-9]+$
  8519. type: string
  8520. name:
  8521. description: The name of the Secret resource being referred to.
  8522. maxLength: 253
  8523. minLength: 1
  8524. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8525. type: string
  8526. namespace:
  8527. description: |-
  8528. The namespace of the Secret resource being referred to.
  8529. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8530. maxLength: 63
  8531. minLength: 1
  8532. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8533. type: string
  8534. type: object
  8535. userPass:
  8536. description: UserPass authenticates with Vault by passing username/password pair
  8537. properties:
  8538. path:
  8539. default: userpass
  8540. description: |-
  8541. Path where the UserPassword authentication backend is mounted
  8542. in Vault, e.g: "userpass"
  8543. type: string
  8544. secretRef:
  8545. description: |-
  8546. SecretRef to a key in a Secret resource containing password for the
  8547. user used to authenticate with Vault using the UserPass authentication
  8548. method
  8549. properties:
  8550. key:
  8551. description: |-
  8552. A key in the referenced Secret.
  8553. Some instances of this field may be defaulted, in others it may be required.
  8554. maxLength: 253
  8555. minLength: 1
  8556. pattern: ^[-._a-zA-Z0-9]+$
  8557. type: string
  8558. name:
  8559. description: The name of the Secret resource being referred to.
  8560. maxLength: 253
  8561. minLength: 1
  8562. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8563. type: string
  8564. namespace:
  8565. description: |-
  8566. The namespace of the Secret resource being referred to.
  8567. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8568. maxLength: 63
  8569. minLength: 1
  8570. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8571. type: string
  8572. type: object
  8573. username:
  8574. description: |-
  8575. Username is a username used to authenticate using the UserPass Vault
  8576. authentication method
  8577. type: string
  8578. required:
  8579. - path
  8580. - username
  8581. type: object
  8582. type: object
  8583. caBundle:
  8584. description: |-
  8585. PEM encoded CA bundle used to validate Vault server certificate. Only used
  8586. if the Server URL is using HTTPS protocol. This parameter is ignored for
  8587. plain HTTP protocol connection. If not set the system root certificates
  8588. are used to validate the TLS connection.
  8589. format: byte
  8590. type: string
  8591. caProvider:
  8592. description: The provider for the CA bundle to use to validate Vault server certificate.
  8593. properties:
  8594. key:
  8595. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8596. maxLength: 253
  8597. minLength: 1
  8598. pattern: ^[-._a-zA-Z0-9]+$
  8599. type: string
  8600. name:
  8601. description: The name of the object located at the provider type.
  8602. maxLength: 253
  8603. minLength: 1
  8604. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8605. type: string
  8606. namespace:
  8607. description: |-
  8608. The namespace the Provider type is in.
  8609. Can only be defined when used in a ClusterSecretStore.
  8610. maxLength: 63
  8611. minLength: 1
  8612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8613. type: string
  8614. type:
  8615. description: The type of provider to use such as "Secret", or "ConfigMap".
  8616. enum:
  8617. - Secret
  8618. - ConfigMap
  8619. type: string
  8620. required:
  8621. - name
  8622. - type
  8623. type: object
  8624. checkAndSet:
  8625. description: |-
  8626. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  8627. Only applies to Vault KV v2 stores. When enabled, write operations must include
  8628. the current version of the secret to prevent unintentional overwrites.
  8629. properties:
  8630. required:
  8631. description: |-
  8632. Required when true, all write operations must include a check-and-set parameter.
  8633. This helps prevent unintentional overwrites of secrets.
  8634. type: boolean
  8635. type: object
  8636. forwardInconsistent:
  8637. description: |-
  8638. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  8639. leader instead of simply retrying within a loop. This can increase performance if
  8640. the option is enabled serverside.
  8641. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  8642. type: boolean
  8643. headers:
  8644. additionalProperties:
  8645. type: string
  8646. description: Headers to be added in Vault request
  8647. type: object
  8648. namespace:
  8649. description: |-
  8650. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  8651. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8652. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8653. type: string
  8654. path:
  8655. description: |-
  8656. Path is the mount path of the Vault KV backend endpoint, e.g:
  8657. "secret". The v2 KV secret engine version specific "/data" path suffix
  8658. for fetching secrets from Vault is optional and will be appended
  8659. if not present in specified path.
  8660. type: string
  8661. readYourWrites:
  8662. description: |-
  8663. ReadYourWrites ensures isolated read-after-write semantics by
  8664. providing discovered cluster replication states in each request.
  8665. More information about eventual consistency in Vault can be found here
  8666. https://www.vaultproject.io/docs/enterprise/consistency
  8667. type: boolean
  8668. server:
  8669. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  8670. type: string
  8671. tls:
  8672. description: |-
  8673. The configuration used for client side related TLS communication, when the Vault server
  8674. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  8675. This parameter is ignored for plain HTTP protocol connection.
  8676. It's worth noting this configuration is different from the "TLS certificates auth method",
  8677. which is available under the `auth.cert` section.
  8678. properties:
  8679. certSecretRef:
  8680. description: |-
  8681. CertSecretRef is a certificate added to the transport layer
  8682. when communicating with the Vault server.
  8683. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  8684. properties:
  8685. key:
  8686. description: |-
  8687. A key in the referenced Secret.
  8688. Some instances of this field may be defaulted, in others it may be required.
  8689. maxLength: 253
  8690. minLength: 1
  8691. pattern: ^[-._a-zA-Z0-9]+$
  8692. type: string
  8693. name:
  8694. description: The name of the Secret resource being referred to.
  8695. maxLength: 253
  8696. minLength: 1
  8697. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8698. type: string
  8699. namespace:
  8700. description: |-
  8701. The namespace of the Secret resource being referred to.
  8702. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8703. maxLength: 63
  8704. minLength: 1
  8705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8706. type: string
  8707. type: object
  8708. keySecretRef:
  8709. description: |-
  8710. KeySecretRef to a key in a Secret resource containing client private key
  8711. added to the transport layer when communicating with the Vault server.
  8712. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  8713. properties:
  8714. key:
  8715. description: |-
  8716. A key in the referenced Secret.
  8717. Some instances of this field may be defaulted, in others it may be required.
  8718. maxLength: 253
  8719. minLength: 1
  8720. pattern: ^[-._a-zA-Z0-9]+$
  8721. type: string
  8722. name:
  8723. description: The name of the Secret resource being referred to.
  8724. maxLength: 253
  8725. minLength: 1
  8726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8727. type: string
  8728. namespace:
  8729. description: |-
  8730. The namespace of the Secret resource being referred to.
  8731. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8732. maxLength: 63
  8733. minLength: 1
  8734. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8735. type: string
  8736. type: object
  8737. type: object
  8738. version:
  8739. default: v2
  8740. description: |-
  8741. Version is the Vault KV secret engine version. This can be either "v1" or
  8742. "v2". Version defaults to "v2".
  8743. enum:
  8744. - v1
  8745. - v2
  8746. type: string
  8747. required:
  8748. - server
  8749. type: object
  8750. volcengine:
  8751. description: Volcengine configures this store to sync secrets using the Volcengine provider
  8752. properties:
  8753. auth:
  8754. description: |-
  8755. Auth defines the authentication method to use.
  8756. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  8757. properties:
  8758. secretRef:
  8759. description: |-
  8760. SecretRef defines the static credentials to use for authentication.
  8761. If not set, IRSA is used.
  8762. properties:
  8763. accessKeyID:
  8764. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  8765. properties:
  8766. key:
  8767. description: |-
  8768. A key in the referenced Secret.
  8769. Some instances of this field may be defaulted, in others it may be required.
  8770. maxLength: 253
  8771. minLength: 1
  8772. pattern: ^[-._a-zA-Z0-9]+$
  8773. type: string
  8774. name:
  8775. description: The name of the Secret resource being referred to.
  8776. maxLength: 253
  8777. minLength: 1
  8778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8779. type: string
  8780. namespace:
  8781. description: |-
  8782. The namespace of the Secret resource being referred to.
  8783. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8784. maxLength: 63
  8785. minLength: 1
  8786. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8787. type: string
  8788. type: object
  8789. secretAccessKey:
  8790. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  8791. properties:
  8792. key:
  8793. description: |-
  8794. A key in the referenced Secret.
  8795. Some instances of this field may be defaulted, in others it may be required.
  8796. maxLength: 253
  8797. minLength: 1
  8798. pattern: ^[-._a-zA-Z0-9]+$
  8799. type: string
  8800. name:
  8801. description: The name of the Secret resource being referred to.
  8802. maxLength: 253
  8803. minLength: 1
  8804. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8805. type: string
  8806. namespace:
  8807. description: |-
  8808. The namespace of the Secret resource being referred to.
  8809. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8810. maxLength: 63
  8811. minLength: 1
  8812. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8813. type: string
  8814. type: object
  8815. token:
  8816. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  8817. properties:
  8818. key:
  8819. description: |-
  8820. A key in the referenced Secret.
  8821. Some instances of this field may be defaulted, in others it may be required.
  8822. maxLength: 253
  8823. minLength: 1
  8824. pattern: ^[-._a-zA-Z0-9]+$
  8825. type: string
  8826. name:
  8827. description: The name of the Secret resource being referred to.
  8828. maxLength: 253
  8829. minLength: 1
  8830. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8831. type: string
  8832. namespace:
  8833. description: |-
  8834. The namespace of the Secret resource being referred to.
  8835. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8836. maxLength: 63
  8837. minLength: 1
  8838. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8839. type: string
  8840. type: object
  8841. required:
  8842. - accessKeyID
  8843. - secretAccessKey
  8844. type: object
  8845. type: object
  8846. region:
  8847. description: Region specifies the Volcengine region to connect to.
  8848. type: string
  8849. required:
  8850. - region
  8851. type: object
  8852. webhook:
  8853. description: Webhook configures this store to sync secrets using a generic templated webhook
  8854. properties:
  8855. auth:
  8856. description: Auth specifies a authorization protocol. Only one protocol may be set.
  8857. maxProperties: 1
  8858. minProperties: 1
  8859. properties:
  8860. ntlm:
  8861. description: NTLMProtocol configures the store to use NTLM for auth
  8862. properties:
  8863. passwordSecret:
  8864. description: |-
  8865. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8866. In some instances, `key` is a required field.
  8867. properties:
  8868. key:
  8869. description: |-
  8870. A key in the referenced Secret.
  8871. Some instances of this field may be defaulted, in others it may be required.
  8872. maxLength: 253
  8873. minLength: 1
  8874. pattern: ^[-._a-zA-Z0-9]+$
  8875. type: string
  8876. name:
  8877. description: The name of the Secret resource being referred to.
  8878. maxLength: 253
  8879. minLength: 1
  8880. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8881. type: string
  8882. namespace:
  8883. description: |-
  8884. The namespace of the Secret resource being referred to.
  8885. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8886. maxLength: 63
  8887. minLength: 1
  8888. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8889. type: string
  8890. type: object
  8891. usernameSecret:
  8892. description: |-
  8893. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8894. In some instances, `key` is a required field.
  8895. properties:
  8896. key:
  8897. description: |-
  8898. A key in the referenced Secret.
  8899. Some instances of this field may be defaulted, in others it may be required.
  8900. maxLength: 253
  8901. minLength: 1
  8902. pattern: ^[-._a-zA-Z0-9]+$
  8903. type: string
  8904. name:
  8905. description: The name of the Secret resource being referred to.
  8906. maxLength: 253
  8907. minLength: 1
  8908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8909. type: string
  8910. namespace:
  8911. description: |-
  8912. The namespace of the Secret resource being referred to.
  8913. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8914. maxLength: 63
  8915. minLength: 1
  8916. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8917. type: string
  8918. type: object
  8919. required:
  8920. - passwordSecret
  8921. - usernameSecret
  8922. type: object
  8923. type: object
  8924. body:
  8925. description: Body
  8926. type: string
  8927. caBundle:
  8928. description: |-
  8929. PEM encoded CA bundle used to validate webhook server certificate. Only used
  8930. if the Server URL is using HTTPS protocol. This parameter is ignored for
  8931. plain HTTP protocol connection. If not set the system root certificates
  8932. are used to validate the TLS connection.
  8933. format: byte
  8934. type: string
  8935. caProvider:
  8936. description: The provider for the CA bundle to use to validate webhook server certificate.
  8937. properties:
  8938. key:
  8939. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8940. maxLength: 253
  8941. minLength: 1
  8942. pattern: ^[-._a-zA-Z0-9]+$
  8943. type: string
  8944. name:
  8945. description: The name of the object located at the provider type.
  8946. maxLength: 253
  8947. minLength: 1
  8948. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8949. type: string
  8950. namespace:
  8951. description: The namespace the Provider type is in.
  8952. maxLength: 63
  8953. minLength: 1
  8954. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8955. type: string
  8956. type:
  8957. description: The type of provider to use such as "Secret", or "ConfigMap".
  8958. enum:
  8959. - Secret
  8960. - ConfigMap
  8961. type: string
  8962. required:
  8963. - name
  8964. - type
  8965. type: object
  8966. headers:
  8967. additionalProperties:
  8968. type: string
  8969. description: Headers
  8970. type: object
  8971. method:
  8972. description: Webhook Method
  8973. type: string
  8974. result:
  8975. description: Result formatting
  8976. properties:
  8977. jsonPath:
  8978. description: Json path of return value
  8979. type: string
  8980. type: object
  8981. secrets:
  8982. description: |-
  8983. Secrets to fill in templates
  8984. These secrets will be passed to the templating function as key value pairs under the given name
  8985. items:
  8986. description: WebhookSecret defines a secret that will be passed to the webhook request.
  8987. properties:
  8988. name:
  8989. description: Name of this secret in templates
  8990. type: string
  8991. secretRef:
  8992. description: Secret ref to fill in credentials
  8993. properties:
  8994. key:
  8995. description: |-
  8996. A key in the referenced Secret.
  8997. Some instances of this field may be defaulted, in others it may be required.
  8998. maxLength: 253
  8999. minLength: 1
  9000. pattern: ^[-._a-zA-Z0-9]+$
  9001. type: string
  9002. name:
  9003. description: The name of the Secret resource being referred to.
  9004. maxLength: 253
  9005. minLength: 1
  9006. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9007. type: string
  9008. namespace:
  9009. description: |-
  9010. The namespace of the Secret resource being referred to.
  9011. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9012. maxLength: 63
  9013. minLength: 1
  9014. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9015. type: string
  9016. type: object
  9017. required:
  9018. - name
  9019. - secretRef
  9020. type: object
  9021. type: array
  9022. timeout:
  9023. description: Timeout
  9024. type: string
  9025. url:
  9026. description: Webhook url to call
  9027. type: string
  9028. required:
  9029. - url
  9030. type: object
  9031. yandexcertificatemanager:
  9032. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  9033. properties:
  9034. apiEndpoint:
  9035. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9036. type: string
  9037. auth:
  9038. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  9039. properties:
  9040. authorizedKeySecretRef:
  9041. description: The authorized key used for authentication
  9042. properties:
  9043. key:
  9044. description: |-
  9045. A key in the referenced Secret.
  9046. Some instances of this field may be defaulted, in others it may be required.
  9047. maxLength: 253
  9048. minLength: 1
  9049. pattern: ^[-._a-zA-Z0-9]+$
  9050. type: string
  9051. name:
  9052. description: The name of the Secret resource being referred to.
  9053. maxLength: 253
  9054. minLength: 1
  9055. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9056. type: string
  9057. namespace:
  9058. description: |-
  9059. The namespace of the Secret resource being referred to.
  9060. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9061. maxLength: 63
  9062. minLength: 1
  9063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9064. type: string
  9065. type: object
  9066. type: object
  9067. caProvider:
  9068. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9069. properties:
  9070. certSecretRef:
  9071. description: |-
  9072. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9073. In some instances, `key` is a required field.
  9074. properties:
  9075. key:
  9076. description: |-
  9077. A key in the referenced Secret.
  9078. Some instances of this field may be defaulted, in others it may be required.
  9079. maxLength: 253
  9080. minLength: 1
  9081. pattern: ^[-._a-zA-Z0-9]+$
  9082. type: string
  9083. name:
  9084. description: The name of the Secret resource being referred to.
  9085. maxLength: 253
  9086. minLength: 1
  9087. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9088. type: string
  9089. namespace:
  9090. description: |-
  9091. The namespace of the Secret resource being referred to.
  9092. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9093. maxLength: 63
  9094. minLength: 1
  9095. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9096. type: string
  9097. type: object
  9098. type: object
  9099. fetching:
  9100. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  9101. maxProperties: 1
  9102. minProperties: 1
  9103. properties:
  9104. byID:
  9105. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  9106. type: object
  9107. byName:
  9108. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  9109. properties:
  9110. folderID:
  9111. description: The folder to fetch secrets from
  9112. type: string
  9113. required:
  9114. - folderID
  9115. type: object
  9116. type: object
  9117. required:
  9118. - auth
  9119. type: object
  9120. yandexlockbox:
  9121. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  9122. properties:
  9123. apiEndpoint:
  9124. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9125. type: string
  9126. auth:
  9127. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  9128. properties:
  9129. authorizedKeySecretRef:
  9130. description: The authorized key used for authentication
  9131. properties:
  9132. key:
  9133. description: |-
  9134. A key in the referenced Secret.
  9135. Some instances of this field may be defaulted, in others it may be required.
  9136. maxLength: 253
  9137. minLength: 1
  9138. pattern: ^[-._a-zA-Z0-9]+$
  9139. type: string
  9140. name:
  9141. description: The name of the Secret resource being referred to.
  9142. maxLength: 253
  9143. minLength: 1
  9144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9145. type: string
  9146. namespace:
  9147. description: |-
  9148. The namespace of the Secret resource being referred to.
  9149. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9150. maxLength: 63
  9151. minLength: 1
  9152. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9153. type: string
  9154. type: object
  9155. type: object
  9156. caProvider:
  9157. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9158. properties:
  9159. certSecretRef:
  9160. description: |-
  9161. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9162. In some instances, `key` is a required field.
  9163. properties:
  9164. key:
  9165. description: |-
  9166. A key in the referenced Secret.
  9167. Some instances of this field may be defaulted, in others it may be required.
  9168. maxLength: 253
  9169. minLength: 1
  9170. pattern: ^[-._a-zA-Z0-9]+$
  9171. type: string
  9172. name:
  9173. description: The name of the Secret resource being referred to.
  9174. maxLength: 253
  9175. minLength: 1
  9176. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9177. type: string
  9178. namespace:
  9179. description: |-
  9180. The namespace of the Secret resource being referred to.
  9181. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9182. maxLength: 63
  9183. minLength: 1
  9184. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9185. type: string
  9186. type: object
  9187. type: object
  9188. fetching:
  9189. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  9190. maxProperties: 1
  9191. minProperties: 1
  9192. properties:
  9193. byID:
  9194. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  9195. type: object
  9196. byName:
  9197. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  9198. properties:
  9199. folderID:
  9200. description: The folder to fetch secrets from
  9201. type: string
  9202. required:
  9203. - folderID
  9204. type: object
  9205. type: object
  9206. required:
  9207. - auth
  9208. type: object
  9209. type: object
  9210. refreshInterval:
  9211. anyOf:
  9212. - type: integer
  9213. - type: string
  9214. description: |-
  9215. Used to configure store refresh interval. Accepts either an integer number
  9216. of seconds (legacy) or a Go duration string such as "1h" or "5m". Empty or
  9217. 0 will default to the controller config.
  9218. x-kubernetes-int-or-string: true
  9219. retrySettings:
  9220. description: Used to configure HTTP retries on failures.
  9221. properties:
  9222. maxRetries:
  9223. format: int32
  9224. type: integer
  9225. retryInterval:
  9226. type: string
  9227. type: object
  9228. required:
  9229. - provider
  9230. type: object
  9231. status:
  9232. description: SecretStoreStatus defines the observed state of the SecretStore.
  9233. properties:
  9234. capabilities:
  9235. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  9236. type: string
  9237. conditions:
  9238. items:
  9239. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  9240. properties:
  9241. lastTransitionTime:
  9242. format: date-time
  9243. type: string
  9244. message:
  9245. type: string
  9246. reason:
  9247. type: string
  9248. status:
  9249. type: string
  9250. type:
  9251. description: SecretStoreConditionType represents the condition of the SecretStore.
  9252. type: string
  9253. required:
  9254. - status
  9255. - type
  9256. type: object
  9257. type: array
  9258. type: object
  9259. type: object
  9260. served: true
  9261. storage: true
  9262. subresources:
  9263. status: {}
  9264. - additionalPrinterColumns:
  9265. - jsonPath: .metadata.creationTimestamp
  9266. name: AGE
  9267. type: date
  9268. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  9269. name: Status
  9270. type: string
  9271. - jsonPath: .status.capabilities
  9272. name: Capabilities
  9273. type: string
  9274. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  9275. name: Ready
  9276. type: string
  9277. deprecated: true
  9278. name: v1beta1
  9279. schema:
  9280. openAPIV3Schema:
  9281. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  9282. properties:
  9283. apiVersion:
  9284. description: |-
  9285. APIVersion defines the versioned schema of this representation of an object.
  9286. Servers should convert recognized schemas to the latest internal value, and
  9287. may reject unrecognized values.
  9288. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  9289. type: string
  9290. kind:
  9291. description: |-
  9292. Kind is a string value representing the REST resource this object represents.
  9293. Servers may infer this from the endpoint the client submits requests to.
  9294. Cannot be updated.
  9295. In CamelCase.
  9296. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  9297. type: string
  9298. metadata:
  9299. type: object
  9300. spec:
  9301. description: SecretStoreSpec defines the desired state of SecretStore.
  9302. properties:
  9303. conditions:
  9304. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  9305. items:
  9306. description: |-
  9307. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  9308. for a ClusterSecretStore instance.
  9309. properties:
  9310. namespaceRegexes:
  9311. description: Choose namespaces by using regex matching
  9312. items:
  9313. type: string
  9314. type: array
  9315. namespaceSelector:
  9316. description: Choose namespace using a labelSelector
  9317. properties:
  9318. matchExpressions:
  9319. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  9320. items:
  9321. description: |-
  9322. A label selector requirement is a selector that contains values, a key, and an operator that
  9323. relates the key and values.
  9324. properties:
  9325. key:
  9326. description: key is the label key that the selector applies to.
  9327. type: string
  9328. operator:
  9329. description: |-
  9330. operator represents a key's relationship to a set of values.
  9331. Valid operators are In, NotIn, Exists and DoesNotExist.
  9332. type: string
  9333. values:
  9334. description: |-
  9335. values is an array of string values. If the operator is In or NotIn,
  9336. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  9337. the values array must be empty. This array is replaced during a strategic
  9338. merge patch.
  9339. items:
  9340. type: string
  9341. type: array
  9342. x-kubernetes-list-type: atomic
  9343. required:
  9344. - key
  9345. - operator
  9346. type: object
  9347. type: array
  9348. x-kubernetes-list-type: atomic
  9349. matchLabels:
  9350. additionalProperties:
  9351. type: string
  9352. description: |-
  9353. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  9354. map is equivalent to an element of matchExpressions, whose key field is "key", the
  9355. operator is "In", and the values array contains only "value". The requirements are ANDed.
  9356. type: object
  9357. type: object
  9358. x-kubernetes-map-type: atomic
  9359. namespaces:
  9360. description: Choose namespaces by name
  9361. items:
  9362. maxLength: 63
  9363. minLength: 1
  9364. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9365. type: string
  9366. type: array
  9367. type: object
  9368. type: array
  9369. controller:
  9370. description: |-
  9371. Used to select the correct ESO controller (think: ingress.ingressClassName)
  9372. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  9373. type: string
  9374. provider:
  9375. description: Used to configure the provider. Only one provider may be set
  9376. maxProperties: 1
  9377. minProperties: 1
  9378. properties:
  9379. akeyless:
  9380. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  9381. properties:
  9382. akeylessGWApiURL:
  9383. description: Akeyless GW API Url from which the secrets to be fetched from.
  9384. type: string
  9385. authSecretRef:
  9386. description: Auth configures how the operator authenticates with Akeyless.
  9387. properties:
  9388. kubernetesAuth:
  9389. description: |-
  9390. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  9391. token stored in the named Secret resource.
  9392. properties:
  9393. accessID:
  9394. description: the Akeyless Kubernetes auth-method access-id
  9395. type: string
  9396. k8sConfName:
  9397. description: Kubernetes-auth configuration name in Akeyless-Gateway
  9398. type: string
  9399. secretRef:
  9400. description: |-
  9401. Optional secret field containing a Kubernetes ServiceAccount JWT used
  9402. for authenticating with Akeyless. If a name is specified without a key,
  9403. `token` is the default. If one is not specified, the one bound to
  9404. the controller will be used.
  9405. properties:
  9406. key:
  9407. description: |-
  9408. A key in the referenced Secret.
  9409. Some instances of this field may be defaulted, in others it may be required.
  9410. maxLength: 253
  9411. minLength: 1
  9412. pattern: ^[-._a-zA-Z0-9]+$
  9413. type: string
  9414. name:
  9415. description: The name of the Secret resource being referred to.
  9416. maxLength: 253
  9417. minLength: 1
  9418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9419. type: string
  9420. namespace:
  9421. description: |-
  9422. The namespace of the Secret resource being referred to.
  9423. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9424. maxLength: 63
  9425. minLength: 1
  9426. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9427. type: string
  9428. type: object
  9429. serviceAccountRef:
  9430. description: |-
  9431. Optional service account field containing the name of a kubernetes ServiceAccount.
  9432. If the service account is specified, the service account secret token JWT will be used
  9433. for authenticating with Akeyless. If the service account selector is not supplied,
  9434. the secretRef will be used instead.
  9435. properties:
  9436. audiences:
  9437. description: |-
  9438. Audience specifies the `aud` claim for the service account token
  9439. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  9440. then this audiences will be appended to the list
  9441. items:
  9442. type: string
  9443. type: array
  9444. name:
  9445. description: The name of the ServiceAccount resource being referred to.
  9446. maxLength: 253
  9447. minLength: 1
  9448. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9449. type: string
  9450. namespace:
  9451. description: |-
  9452. Namespace of the resource being referred to.
  9453. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9454. maxLength: 63
  9455. minLength: 1
  9456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9457. type: string
  9458. required:
  9459. - name
  9460. type: object
  9461. required:
  9462. - accessID
  9463. - k8sConfName
  9464. type: object
  9465. secretRef:
  9466. description: |-
  9467. Reference to a Secret that contains the details
  9468. to authenticate with Akeyless.
  9469. properties:
  9470. accessID:
  9471. description: The SecretAccessID is used for authentication
  9472. properties:
  9473. key:
  9474. description: |-
  9475. A key in the referenced Secret.
  9476. Some instances of this field may be defaulted, in others it may be required.
  9477. maxLength: 253
  9478. minLength: 1
  9479. pattern: ^[-._a-zA-Z0-9]+$
  9480. type: string
  9481. name:
  9482. description: The name of the Secret resource being referred to.
  9483. maxLength: 253
  9484. minLength: 1
  9485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9486. type: string
  9487. namespace:
  9488. description: |-
  9489. The namespace of the Secret resource being referred to.
  9490. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9491. maxLength: 63
  9492. minLength: 1
  9493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9494. type: string
  9495. type: object
  9496. accessType:
  9497. description: |-
  9498. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9499. In some instances, `key` is a required field.
  9500. properties:
  9501. key:
  9502. description: |-
  9503. A key in the referenced Secret.
  9504. Some instances of this field may be defaulted, in others it may be required.
  9505. maxLength: 253
  9506. minLength: 1
  9507. pattern: ^[-._a-zA-Z0-9]+$
  9508. type: string
  9509. name:
  9510. description: The name of the Secret resource being referred to.
  9511. maxLength: 253
  9512. minLength: 1
  9513. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9514. type: string
  9515. namespace:
  9516. description: |-
  9517. The namespace of the Secret resource being referred to.
  9518. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9519. maxLength: 63
  9520. minLength: 1
  9521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9522. type: string
  9523. type: object
  9524. accessTypeParam:
  9525. description: |-
  9526. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9527. In some instances, `key` is a required field.
  9528. properties:
  9529. key:
  9530. description: |-
  9531. A key in the referenced Secret.
  9532. Some instances of this field may be defaulted, in others it may be required.
  9533. maxLength: 253
  9534. minLength: 1
  9535. pattern: ^[-._a-zA-Z0-9]+$
  9536. type: string
  9537. name:
  9538. description: The name of the Secret resource being referred to.
  9539. maxLength: 253
  9540. minLength: 1
  9541. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9542. type: string
  9543. namespace:
  9544. description: |-
  9545. The namespace of the Secret resource being referred to.
  9546. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9547. maxLength: 63
  9548. minLength: 1
  9549. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9550. type: string
  9551. type: object
  9552. type: object
  9553. type: object
  9554. caBundle:
  9555. description: |-
  9556. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  9557. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  9558. are used to validate the TLS connection.
  9559. format: byte
  9560. type: string
  9561. caProvider:
  9562. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  9563. properties:
  9564. key:
  9565. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9566. maxLength: 253
  9567. minLength: 1
  9568. pattern: ^[-._a-zA-Z0-9]+$
  9569. type: string
  9570. name:
  9571. description: The name of the object located at the provider type.
  9572. maxLength: 253
  9573. minLength: 1
  9574. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9575. type: string
  9576. namespace:
  9577. description: |-
  9578. The namespace the Provider type is in.
  9579. Can only be defined when used in a ClusterSecretStore.
  9580. maxLength: 63
  9581. minLength: 1
  9582. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9583. type: string
  9584. type:
  9585. description: The type of provider to use such as "Secret", or "ConfigMap".
  9586. enum:
  9587. - Secret
  9588. - ConfigMap
  9589. type: string
  9590. required:
  9591. - name
  9592. - type
  9593. type: object
  9594. required:
  9595. - akeylessGWApiURL
  9596. - authSecretRef
  9597. type: object
  9598. alibaba:
  9599. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  9600. properties:
  9601. auth:
  9602. description: AlibabaAuth contains a secretRef for credentials.
  9603. properties:
  9604. rrsa:
  9605. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  9606. properties:
  9607. oidcProviderArn:
  9608. type: string
  9609. oidcTokenFilePath:
  9610. type: string
  9611. roleArn:
  9612. type: string
  9613. sessionName:
  9614. type: string
  9615. required:
  9616. - oidcProviderArn
  9617. - oidcTokenFilePath
  9618. - roleArn
  9619. - sessionName
  9620. type: object
  9621. secretRef:
  9622. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  9623. properties:
  9624. accessKeyIDSecretRef:
  9625. description: The AccessKeyID is used for authentication
  9626. properties:
  9627. key:
  9628. description: |-
  9629. A key in the referenced Secret.
  9630. Some instances of this field may be defaulted, in others it may be required.
  9631. maxLength: 253
  9632. minLength: 1
  9633. pattern: ^[-._a-zA-Z0-9]+$
  9634. type: string
  9635. name:
  9636. description: The name of the Secret resource being referred to.
  9637. maxLength: 253
  9638. minLength: 1
  9639. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9640. type: string
  9641. namespace:
  9642. description: |-
  9643. The namespace of the Secret resource being referred to.
  9644. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9645. maxLength: 63
  9646. minLength: 1
  9647. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9648. type: string
  9649. type: object
  9650. accessKeySecretSecretRef:
  9651. description: The AccessKeySecret is used for authentication
  9652. properties:
  9653. key:
  9654. description: |-
  9655. A key in the referenced Secret.
  9656. Some instances of this field may be defaulted, in others it may be required.
  9657. maxLength: 253
  9658. minLength: 1
  9659. pattern: ^[-._a-zA-Z0-9]+$
  9660. type: string
  9661. name:
  9662. description: The name of the Secret resource being referred to.
  9663. maxLength: 253
  9664. minLength: 1
  9665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9666. type: string
  9667. namespace:
  9668. description: |-
  9669. The namespace of the Secret resource being referred to.
  9670. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9671. maxLength: 63
  9672. minLength: 1
  9673. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9674. type: string
  9675. type: object
  9676. required:
  9677. - accessKeyIDSecretRef
  9678. - accessKeySecretSecretRef
  9679. type: object
  9680. type: object
  9681. regionID:
  9682. description: Alibaba Region to be used for the provider
  9683. type: string
  9684. required:
  9685. - auth
  9686. - regionID
  9687. type: object
  9688. aws:
  9689. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  9690. properties:
  9691. additionalRoles:
  9692. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  9693. items:
  9694. type: string
  9695. type: array
  9696. auth:
  9697. description: |-
  9698. Auth defines the information necessary to authenticate against AWS
  9699. if not set aws sdk will infer credentials from your environment
  9700. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  9701. properties:
  9702. jwt:
  9703. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  9704. properties:
  9705. serviceAccountRef:
  9706. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  9707. properties:
  9708. audiences:
  9709. description: |-
  9710. Audience specifies the `aud` claim for the service account token
  9711. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  9712. then this audiences will be appended to the list
  9713. items:
  9714. type: string
  9715. type: array
  9716. name:
  9717. description: The name of the ServiceAccount resource being referred to.
  9718. maxLength: 253
  9719. minLength: 1
  9720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9721. type: string
  9722. namespace:
  9723. description: |-
  9724. Namespace of the resource being referred to.
  9725. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9726. maxLength: 63
  9727. minLength: 1
  9728. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9729. type: string
  9730. required:
  9731. - name
  9732. type: object
  9733. type: object
  9734. secretRef:
  9735. description: |-
  9736. AWSAuthSecretRef holds secret references for AWS credentials
  9737. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  9738. properties:
  9739. accessKeyIDSecretRef:
  9740. description: The AccessKeyID is used for authentication
  9741. properties:
  9742. key:
  9743. description: |-
  9744. A key in the referenced Secret.
  9745. Some instances of this field may be defaulted, in others it may be required.
  9746. maxLength: 253
  9747. minLength: 1
  9748. pattern: ^[-._a-zA-Z0-9]+$
  9749. type: string
  9750. name:
  9751. description: The name of the Secret resource being referred to.
  9752. maxLength: 253
  9753. minLength: 1
  9754. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9755. type: string
  9756. namespace:
  9757. description: |-
  9758. The namespace of the Secret resource being referred to.
  9759. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9760. maxLength: 63
  9761. minLength: 1
  9762. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9763. type: string
  9764. type: object
  9765. secretAccessKeySecretRef:
  9766. description: The SecretAccessKey is used for authentication
  9767. properties:
  9768. key:
  9769. description: |-
  9770. A key in the referenced Secret.
  9771. Some instances of this field may be defaulted, in others it may be required.
  9772. maxLength: 253
  9773. minLength: 1
  9774. pattern: ^[-._a-zA-Z0-9]+$
  9775. type: string
  9776. name:
  9777. description: The name of the Secret resource being referred to.
  9778. maxLength: 253
  9779. minLength: 1
  9780. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9781. type: string
  9782. namespace:
  9783. description: |-
  9784. The namespace of the Secret resource being referred to.
  9785. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9786. maxLength: 63
  9787. minLength: 1
  9788. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9789. type: string
  9790. type: object
  9791. sessionTokenSecretRef:
  9792. description: |-
  9793. The SessionToken used for authentication
  9794. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  9795. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  9796. properties:
  9797. key:
  9798. description: |-
  9799. A key in the referenced Secret.
  9800. Some instances of this field may be defaulted, in others it may be required.
  9801. maxLength: 253
  9802. minLength: 1
  9803. pattern: ^[-._a-zA-Z0-9]+$
  9804. type: string
  9805. name:
  9806. description: The name of the Secret resource being referred to.
  9807. maxLength: 253
  9808. minLength: 1
  9809. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9810. type: string
  9811. namespace:
  9812. description: |-
  9813. The namespace of the Secret resource being referred to.
  9814. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9815. maxLength: 63
  9816. minLength: 1
  9817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9818. type: string
  9819. type: object
  9820. type: object
  9821. type: object
  9822. externalID:
  9823. description: AWS External ID set on assumed IAM roles
  9824. type: string
  9825. prefix:
  9826. description: Prefix adds a prefix to all retrieved values.
  9827. type: string
  9828. region:
  9829. description: AWS Region to be used for the provider
  9830. type: string
  9831. role:
  9832. description: Role is a Role ARN which the provider will assume
  9833. type: string
  9834. secretsManager:
  9835. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  9836. properties:
  9837. forceDeleteWithoutRecovery:
  9838. description: |-
  9839. Specifies whether to delete the secret without any recovery window. You
  9840. can't use both this parameter and RecoveryWindowInDays in the same call.
  9841. If you don't use either, then by default Secrets Manager uses a 30 day
  9842. recovery window.
  9843. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  9844. type: boolean
  9845. recoveryWindowInDays:
  9846. description: |-
  9847. The number of days from 7 to 30 that Secrets Manager waits before
  9848. permanently deleting the secret. You can't use both this parameter and
  9849. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  9850. then by default Secrets Manager uses a 30 day recovery window.
  9851. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  9852. format: int64
  9853. type: integer
  9854. type: object
  9855. service:
  9856. description: Service defines which service should be used to fetch the secrets
  9857. enum:
  9858. - SecretsManager
  9859. - ParameterStore
  9860. type: string
  9861. sessionTags:
  9862. description: AWS STS assume role session tags
  9863. items:
  9864. description: Tag defines a tag key and value for AWS resources.
  9865. properties:
  9866. key:
  9867. type: string
  9868. value:
  9869. type: string
  9870. required:
  9871. - key
  9872. - value
  9873. type: object
  9874. type: array
  9875. transitiveTagKeys:
  9876. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  9877. items:
  9878. type: string
  9879. type: array
  9880. required:
  9881. - region
  9882. - service
  9883. type: object
  9884. azurekv:
  9885. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  9886. properties:
  9887. authSecretRef:
  9888. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  9889. properties:
  9890. clientCertificate:
  9891. description: The Azure ClientCertificate of the service principle used for authentication.
  9892. properties:
  9893. key:
  9894. description: |-
  9895. A key in the referenced Secret.
  9896. Some instances of this field may be defaulted, in others it may be required.
  9897. maxLength: 253
  9898. minLength: 1
  9899. pattern: ^[-._a-zA-Z0-9]+$
  9900. type: string
  9901. name:
  9902. description: The name of the Secret resource being referred to.
  9903. maxLength: 253
  9904. minLength: 1
  9905. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9906. type: string
  9907. namespace:
  9908. description: |-
  9909. The namespace of the Secret resource being referred to.
  9910. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9911. maxLength: 63
  9912. minLength: 1
  9913. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9914. type: string
  9915. type: object
  9916. clientId:
  9917. description: The Azure clientId of the service principle or managed identity used for authentication.
  9918. properties:
  9919. key:
  9920. description: |-
  9921. A key in the referenced Secret.
  9922. Some instances of this field may be defaulted, in others it may be required.
  9923. maxLength: 253
  9924. minLength: 1
  9925. pattern: ^[-._a-zA-Z0-9]+$
  9926. type: string
  9927. name:
  9928. description: The name of the Secret resource being referred to.
  9929. maxLength: 253
  9930. minLength: 1
  9931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9932. type: string
  9933. namespace:
  9934. description: |-
  9935. The namespace of the Secret resource being referred to.
  9936. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9937. maxLength: 63
  9938. minLength: 1
  9939. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9940. type: string
  9941. type: object
  9942. clientSecret:
  9943. description: The Azure ClientSecret of the service principle used for authentication.
  9944. properties:
  9945. key:
  9946. description: |-
  9947. A key in the referenced Secret.
  9948. Some instances of this field may be defaulted, in others it may be required.
  9949. maxLength: 253
  9950. minLength: 1
  9951. pattern: ^[-._a-zA-Z0-9]+$
  9952. type: string
  9953. name:
  9954. description: The name of the Secret resource being referred to.
  9955. maxLength: 253
  9956. minLength: 1
  9957. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9958. type: string
  9959. namespace:
  9960. description: |-
  9961. The namespace of the Secret resource being referred to.
  9962. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9963. maxLength: 63
  9964. minLength: 1
  9965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9966. type: string
  9967. type: object
  9968. tenantId:
  9969. description: The Azure tenantId of the managed identity used for authentication.
  9970. properties:
  9971. key:
  9972. description: |-
  9973. A key in the referenced Secret.
  9974. Some instances of this field may be defaulted, in others it may be required.
  9975. maxLength: 253
  9976. minLength: 1
  9977. pattern: ^[-._a-zA-Z0-9]+$
  9978. type: string
  9979. name:
  9980. description: The name of the Secret resource being referred to.
  9981. maxLength: 253
  9982. minLength: 1
  9983. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9984. type: string
  9985. namespace:
  9986. description: |-
  9987. The namespace of the Secret resource being referred to.
  9988. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9989. maxLength: 63
  9990. minLength: 1
  9991. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9992. type: string
  9993. type: object
  9994. type: object
  9995. authType:
  9996. default: ServicePrincipal
  9997. description: |-
  9998. Auth type defines how to authenticate to the keyvault service.
  9999. Valid values are:
  10000. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  10001. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  10002. enum:
  10003. - ServicePrincipal
  10004. - ManagedIdentity
  10005. - WorkloadIdentity
  10006. type: string
  10007. environmentType:
  10008. default: PublicCloud
  10009. description: |-
  10010. EnvironmentType specifies the Azure cloud environment endpoints to use for
  10011. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  10012. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  10013. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  10014. enum:
  10015. - PublicCloud
  10016. - USGovernmentCloud
  10017. - ChinaCloud
  10018. - GermanCloud
  10019. type: string
  10020. identityId:
  10021. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  10022. type: string
  10023. serviceAccountRef:
  10024. description: |-
  10025. ServiceAccountRef specified the service account
  10026. that should be used when authenticating with WorkloadIdentity.
  10027. properties:
  10028. audiences:
  10029. description: |-
  10030. Audience specifies the `aud` claim for the service account token
  10031. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  10032. then this audiences will be appended to the list
  10033. items:
  10034. type: string
  10035. type: array
  10036. name:
  10037. description: The name of the ServiceAccount resource being referred to.
  10038. maxLength: 253
  10039. minLength: 1
  10040. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10041. type: string
  10042. namespace:
  10043. description: |-
  10044. Namespace of the resource being referred to.
  10045. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10046. maxLength: 63
  10047. minLength: 1
  10048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10049. type: string
  10050. required:
  10051. - name
  10052. type: object
  10053. tenantId:
  10054. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  10055. type: string
  10056. vaultUrl:
  10057. description: Vault Url from which the secrets to be fetched from.
  10058. type: string
  10059. required:
  10060. - vaultUrl
  10061. type: object
  10062. beyondtrust:
  10063. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  10064. properties:
  10065. auth:
  10066. description: Auth configures how the operator authenticates with Beyondtrust.
  10067. properties:
  10068. apiKey:
  10069. description: APIKey If not provided then ClientID/ClientSecret become required.
  10070. properties:
  10071. secretRef:
  10072. description: SecretRef references a key in a secret that will be used as value.
  10073. properties:
  10074. key:
  10075. description: |-
  10076. A key in the referenced Secret.
  10077. Some instances of this field may be defaulted, in others it may be required.
  10078. maxLength: 253
  10079. minLength: 1
  10080. pattern: ^[-._a-zA-Z0-9]+$
  10081. type: string
  10082. name:
  10083. description: The name of the Secret resource being referred to.
  10084. maxLength: 253
  10085. minLength: 1
  10086. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10087. type: string
  10088. namespace:
  10089. description: |-
  10090. The namespace of the Secret resource being referred to.
  10091. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10092. maxLength: 63
  10093. minLength: 1
  10094. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10095. type: string
  10096. type: object
  10097. value:
  10098. description: Value can be specified directly to set a value without using a secret.
  10099. type: string
  10100. type: object
  10101. certificate:
  10102. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  10103. properties:
  10104. secretRef:
  10105. description: SecretRef references a key in a secret that will be used as value.
  10106. properties:
  10107. key:
  10108. description: |-
  10109. A key in the referenced Secret.
  10110. Some instances of this field may be defaulted, in others it may be required.
  10111. maxLength: 253
  10112. minLength: 1
  10113. pattern: ^[-._a-zA-Z0-9]+$
  10114. type: string
  10115. name:
  10116. description: The name of the Secret resource being referred to.
  10117. maxLength: 253
  10118. minLength: 1
  10119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10120. type: string
  10121. namespace:
  10122. description: |-
  10123. The namespace of the Secret resource being referred to.
  10124. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10125. maxLength: 63
  10126. minLength: 1
  10127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10128. type: string
  10129. type: object
  10130. value:
  10131. description: Value can be specified directly to set a value without using a secret.
  10132. type: string
  10133. type: object
  10134. certificateKey:
  10135. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  10136. properties:
  10137. secretRef:
  10138. description: SecretRef references a key in a secret that will be used as value.
  10139. properties:
  10140. key:
  10141. description: |-
  10142. A key in the referenced Secret.
  10143. Some instances of this field may be defaulted, in others it may be required.
  10144. maxLength: 253
  10145. minLength: 1
  10146. pattern: ^[-._a-zA-Z0-9]+$
  10147. type: string
  10148. name:
  10149. description: The name of the Secret resource being referred to.
  10150. maxLength: 253
  10151. minLength: 1
  10152. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10153. type: string
  10154. namespace:
  10155. description: |-
  10156. The namespace of the Secret resource being referred to.
  10157. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10158. maxLength: 63
  10159. minLength: 1
  10160. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10161. type: string
  10162. type: object
  10163. value:
  10164. description: Value can be specified directly to set a value without using a secret.
  10165. type: string
  10166. type: object
  10167. clientId:
  10168. description: ClientID is the API OAuth Client ID.
  10169. properties:
  10170. secretRef:
  10171. description: SecretRef references a key in a secret that will be used as value.
  10172. properties:
  10173. key:
  10174. description: |-
  10175. A key in the referenced Secret.
  10176. Some instances of this field may be defaulted, in others it may be required.
  10177. maxLength: 253
  10178. minLength: 1
  10179. pattern: ^[-._a-zA-Z0-9]+$
  10180. type: string
  10181. name:
  10182. description: The name of the Secret resource being referred to.
  10183. maxLength: 253
  10184. minLength: 1
  10185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10186. type: string
  10187. namespace:
  10188. description: |-
  10189. The namespace of the Secret resource being referred to.
  10190. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10191. maxLength: 63
  10192. minLength: 1
  10193. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10194. type: string
  10195. type: object
  10196. value:
  10197. description: Value can be specified directly to set a value without using a secret.
  10198. type: string
  10199. type: object
  10200. clientSecret:
  10201. description: ClientSecret is the API OAuth Client Secret.
  10202. properties:
  10203. secretRef:
  10204. description: SecretRef references a key in a secret that will be used as value.
  10205. properties:
  10206. key:
  10207. description: |-
  10208. A key in the referenced Secret.
  10209. Some instances of this field may be defaulted, in others it may be required.
  10210. maxLength: 253
  10211. minLength: 1
  10212. pattern: ^[-._a-zA-Z0-9]+$
  10213. type: string
  10214. name:
  10215. description: The name of the Secret resource being referred to.
  10216. maxLength: 253
  10217. minLength: 1
  10218. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10219. type: string
  10220. namespace:
  10221. description: |-
  10222. The namespace of the Secret resource being referred to.
  10223. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10224. maxLength: 63
  10225. minLength: 1
  10226. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10227. type: string
  10228. type: object
  10229. value:
  10230. description: Value can be specified directly to set a value without using a secret.
  10231. type: string
  10232. type: object
  10233. type: object
  10234. server:
  10235. description: Auth configures how API server works.
  10236. properties:
  10237. apiUrl:
  10238. type: string
  10239. apiVersion:
  10240. type: string
  10241. clientTimeOutSeconds:
  10242. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  10243. type: integer
  10244. decrypt:
  10245. default: true
  10246. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  10247. type: boolean
  10248. retrievalType:
  10249. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  10250. type: string
  10251. separator:
  10252. description: A character that separates the folder names.
  10253. type: string
  10254. verifyCA:
  10255. type: boolean
  10256. required:
  10257. - apiUrl
  10258. - verifyCA
  10259. type: object
  10260. required:
  10261. - auth
  10262. - server
  10263. type: object
  10264. bitwardensecretsmanager:
  10265. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  10266. properties:
  10267. apiURL:
  10268. type: string
  10269. auth:
  10270. description: |-
  10271. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  10272. Make sure that the token being used has permissions on the given secret.
  10273. properties:
  10274. secretRef:
  10275. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  10276. properties:
  10277. credentials:
  10278. description: AccessToken used for the bitwarden instance.
  10279. properties:
  10280. key:
  10281. description: |-
  10282. A key in the referenced Secret.
  10283. Some instances of this field may be defaulted, in others it may be required.
  10284. maxLength: 253
  10285. minLength: 1
  10286. pattern: ^[-._a-zA-Z0-9]+$
  10287. type: string
  10288. name:
  10289. description: The name of the Secret resource being referred to.
  10290. maxLength: 253
  10291. minLength: 1
  10292. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10293. type: string
  10294. namespace:
  10295. description: |-
  10296. The namespace of the Secret resource being referred to.
  10297. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10298. maxLength: 63
  10299. minLength: 1
  10300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10301. type: string
  10302. type: object
  10303. required:
  10304. - credentials
  10305. type: object
  10306. required:
  10307. - secretRef
  10308. type: object
  10309. bitwardenServerSDKURL:
  10310. type: string
  10311. caBundle:
  10312. description: |-
  10313. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  10314. can be performed.
  10315. type: string
  10316. caProvider:
  10317. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  10318. properties:
  10319. key:
  10320. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10321. maxLength: 253
  10322. minLength: 1
  10323. pattern: ^[-._a-zA-Z0-9]+$
  10324. type: string
  10325. name:
  10326. description: The name of the object located at the provider type.
  10327. maxLength: 253
  10328. minLength: 1
  10329. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10330. type: string
  10331. namespace:
  10332. description: |-
  10333. The namespace the Provider type is in.
  10334. Can only be defined when used in a ClusterSecretStore.
  10335. maxLength: 63
  10336. minLength: 1
  10337. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10338. type: string
  10339. type:
  10340. description: The type of provider to use such as "Secret", or "ConfigMap".
  10341. enum:
  10342. - Secret
  10343. - ConfigMap
  10344. type: string
  10345. required:
  10346. - name
  10347. - type
  10348. type: object
  10349. identityURL:
  10350. type: string
  10351. organizationID:
  10352. description: OrganizationID determines which organization this secret store manages.
  10353. type: string
  10354. projectID:
  10355. description: ProjectID determines which project this secret store manages.
  10356. type: string
  10357. required:
  10358. - auth
  10359. - organizationID
  10360. - projectID
  10361. type: object
  10362. chef:
  10363. description: Chef configures this store to sync secrets with chef server
  10364. properties:
  10365. auth:
  10366. description: Auth defines the information necessary to authenticate against chef Server
  10367. properties:
  10368. secretRef:
  10369. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  10370. properties:
  10371. privateKeySecretRef:
  10372. description: SecretKey is the Signing Key in PEM format, used for authentication.
  10373. properties:
  10374. key:
  10375. description: |-
  10376. A key in the referenced Secret.
  10377. Some instances of this field may be defaulted, in others it may be required.
  10378. maxLength: 253
  10379. minLength: 1
  10380. pattern: ^[-._a-zA-Z0-9]+$
  10381. type: string
  10382. name:
  10383. description: The name of the Secret resource being referred to.
  10384. maxLength: 253
  10385. minLength: 1
  10386. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10387. type: string
  10388. namespace:
  10389. description: |-
  10390. The namespace of the Secret resource being referred to.
  10391. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10392. maxLength: 63
  10393. minLength: 1
  10394. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10395. type: string
  10396. type: object
  10397. required:
  10398. - privateKeySecretRef
  10399. type: object
  10400. required:
  10401. - secretRef
  10402. type: object
  10403. serverUrl:
  10404. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  10405. type: string
  10406. username:
  10407. description: UserName should be the user ID on the chef server
  10408. type: string
  10409. required:
  10410. - auth
  10411. - serverUrl
  10412. - username
  10413. type: object
  10414. cloudrusm:
  10415. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  10416. properties:
  10417. auth:
  10418. description: CSMAuth contains a secretRef for credentials.
  10419. properties:
  10420. secretRef:
  10421. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  10422. properties:
  10423. accessKeyIDSecretRef:
  10424. description: The AccessKeyID is used for authentication
  10425. properties:
  10426. key:
  10427. description: |-
  10428. A key in the referenced Secret.
  10429. Some instances of this field may be defaulted, in others it may be required.
  10430. maxLength: 253
  10431. minLength: 1
  10432. pattern: ^[-._a-zA-Z0-9]+$
  10433. type: string
  10434. name:
  10435. description: The name of the Secret resource being referred to.
  10436. maxLength: 253
  10437. minLength: 1
  10438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10439. type: string
  10440. namespace:
  10441. description: |-
  10442. The namespace of the Secret resource being referred to.
  10443. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10444. maxLength: 63
  10445. minLength: 1
  10446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10447. type: string
  10448. type: object
  10449. accessKeySecretSecretRef:
  10450. description: The AccessKeySecret is used for authentication
  10451. properties:
  10452. key:
  10453. description: |-
  10454. A key in the referenced Secret.
  10455. Some instances of this field may be defaulted, in others it may be required.
  10456. maxLength: 253
  10457. minLength: 1
  10458. pattern: ^[-._a-zA-Z0-9]+$
  10459. type: string
  10460. name:
  10461. description: The name of the Secret resource being referred to.
  10462. maxLength: 253
  10463. minLength: 1
  10464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10465. type: string
  10466. namespace:
  10467. description: |-
  10468. The namespace of the Secret resource being referred to.
  10469. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10470. maxLength: 63
  10471. minLength: 1
  10472. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10473. type: string
  10474. type: object
  10475. required:
  10476. - accessKeyIDSecretRef
  10477. - accessKeySecretSecretRef
  10478. type: object
  10479. type: object
  10480. projectID:
  10481. description: ProjectID is the project, which the secrets are stored in.
  10482. type: string
  10483. required:
  10484. - auth
  10485. type: object
  10486. conjur:
  10487. description: Conjur configures this store to sync secrets using conjur provider
  10488. properties:
  10489. auth:
  10490. description: Defines authentication settings for connecting to Conjur.
  10491. properties:
  10492. apikey:
  10493. description: Authenticates with Conjur using an API key.
  10494. properties:
  10495. account:
  10496. description: Account is the Conjur organization account name.
  10497. type: string
  10498. apiKeyRef:
  10499. description: |-
  10500. A reference to a specific 'key' containing the Conjur API key
  10501. within a Secret resource. In some instances, `key` is a required field.
  10502. properties:
  10503. key:
  10504. description: |-
  10505. A key in the referenced Secret.
  10506. Some instances of this field may be defaulted, in others it may be required.
  10507. maxLength: 253
  10508. minLength: 1
  10509. pattern: ^[-._a-zA-Z0-9]+$
  10510. type: string
  10511. name:
  10512. description: The name of the Secret resource being referred to.
  10513. maxLength: 253
  10514. minLength: 1
  10515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10516. type: string
  10517. namespace:
  10518. description: |-
  10519. The namespace of the Secret resource being referred to.
  10520. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10521. maxLength: 63
  10522. minLength: 1
  10523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10524. type: string
  10525. type: object
  10526. userRef:
  10527. description: |-
  10528. A reference to a specific 'key' containing the Conjur username
  10529. within a Secret resource. In some instances, `key` is a required field.
  10530. properties:
  10531. key:
  10532. description: |-
  10533. A key in the referenced Secret.
  10534. Some instances of this field may be defaulted, in others it may be required.
  10535. maxLength: 253
  10536. minLength: 1
  10537. pattern: ^[-._a-zA-Z0-9]+$
  10538. type: string
  10539. name:
  10540. description: The name of the Secret resource being referred to.
  10541. maxLength: 253
  10542. minLength: 1
  10543. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10544. type: string
  10545. namespace:
  10546. description: |-
  10547. The namespace of the Secret resource being referred to.
  10548. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10549. maxLength: 63
  10550. minLength: 1
  10551. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10552. type: string
  10553. type: object
  10554. required:
  10555. - account
  10556. - apiKeyRef
  10557. - userRef
  10558. type: object
  10559. jwt:
  10560. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  10561. properties:
  10562. account:
  10563. description: Account is the Conjur organization account name.
  10564. type: string
  10565. hostId:
  10566. description: |-
  10567. Optional HostID for JWT authentication. This may be used depending
  10568. on how the Conjur JWT authenticator policy is configured.
  10569. type: string
  10570. secretRef:
  10571. description: |-
  10572. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  10573. authenticate with Conjur using the JWT authentication method.
  10574. properties:
  10575. key:
  10576. description: |-
  10577. A key in the referenced Secret.
  10578. Some instances of this field may be defaulted, in others it may be required.
  10579. maxLength: 253
  10580. minLength: 1
  10581. pattern: ^[-._a-zA-Z0-9]+$
  10582. type: string
  10583. name:
  10584. description: The name of the Secret resource being referred to.
  10585. maxLength: 253
  10586. minLength: 1
  10587. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10588. type: string
  10589. namespace:
  10590. description: |-
  10591. The namespace of the Secret resource being referred to.
  10592. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10593. maxLength: 63
  10594. minLength: 1
  10595. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10596. type: string
  10597. type: object
  10598. serviceAccountRef:
  10599. description: |-
  10600. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  10601. a token for with the `TokenRequest` API.
  10602. properties:
  10603. audiences:
  10604. description: |-
  10605. Audience specifies the `aud` claim for the service account token
  10606. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  10607. then this audiences will be appended to the list
  10608. items:
  10609. type: string
  10610. type: array
  10611. name:
  10612. description: The name of the ServiceAccount resource being referred to.
  10613. maxLength: 253
  10614. minLength: 1
  10615. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10616. type: string
  10617. namespace:
  10618. description: |-
  10619. Namespace of the resource being referred to.
  10620. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10621. maxLength: 63
  10622. minLength: 1
  10623. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10624. type: string
  10625. required:
  10626. - name
  10627. type: object
  10628. serviceID:
  10629. description: The conjur authn jwt webservice id
  10630. type: string
  10631. required:
  10632. - account
  10633. - serviceID
  10634. type: object
  10635. type: object
  10636. caBundle:
  10637. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  10638. type: string
  10639. caProvider:
  10640. description: |-
  10641. Used to provide custom certificate authority (CA) certificates
  10642. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  10643. that contains a PEM-encoded certificate.
  10644. properties:
  10645. key:
  10646. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10647. maxLength: 253
  10648. minLength: 1
  10649. pattern: ^[-._a-zA-Z0-9]+$
  10650. type: string
  10651. name:
  10652. description: The name of the object located at the provider type.
  10653. maxLength: 253
  10654. minLength: 1
  10655. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10656. type: string
  10657. namespace:
  10658. description: |-
  10659. The namespace the Provider type is in.
  10660. Can only be defined when used in a ClusterSecretStore.
  10661. maxLength: 63
  10662. minLength: 1
  10663. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10664. type: string
  10665. type:
  10666. description: The type of provider to use such as "Secret", or "ConfigMap".
  10667. enum:
  10668. - Secret
  10669. - ConfigMap
  10670. type: string
  10671. required:
  10672. - name
  10673. - type
  10674. type: object
  10675. url:
  10676. description: URL is the endpoint of the Conjur instance.
  10677. type: string
  10678. required:
  10679. - auth
  10680. - url
  10681. type: object
  10682. delinea:
  10683. description: |-
  10684. Delinea DevOps Secrets Vault
  10685. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  10686. properties:
  10687. clientId:
  10688. description: ClientID is the non-secret part of the credential.
  10689. properties:
  10690. secretRef:
  10691. description: SecretRef references a key in a secret that will be used as value.
  10692. properties:
  10693. key:
  10694. description: |-
  10695. A key in the referenced Secret.
  10696. Some instances of this field may be defaulted, in others it may be required.
  10697. maxLength: 253
  10698. minLength: 1
  10699. pattern: ^[-._a-zA-Z0-9]+$
  10700. type: string
  10701. name:
  10702. description: The name of the Secret resource being referred to.
  10703. maxLength: 253
  10704. minLength: 1
  10705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10706. type: string
  10707. namespace:
  10708. description: |-
  10709. The namespace of the Secret resource being referred to.
  10710. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10711. maxLength: 63
  10712. minLength: 1
  10713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10714. type: string
  10715. type: object
  10716. value:
  10717. description: Value can be specified directly to set a value without using a secret.
  10718. type: string
  10719. type: object
  10720. clientSecret:
  10721. description: ClientSecret is the secret part of the credential.
  10722. properties:
  10723. secretRef:
  10724. description: SecretRef references a key in a secret that will be used as value.
  10725. properties:
  10726. key:
  10727. description: |-
  10728. A key in the referenced Secret.
  10729. Some instances of this field may be defaulted, in others it may be required.
  10730. maxLength: 253
  10731. minLength: 1
  10732. pattern: ^[-._a-zA-Z0-9]+$
  10733. type: string
  10734. name:
  10735. description: The name of the Secret resource being referred to.
  10736. maxLength: 253
  10737. minLength: 1
  10738. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10739. type: string
  10740. namespace:
  10741. description: |-
  10742. The namespace of the Secret resource being referred to.
  10743. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10744. maxLength: 63
  10745. minLength: 1
  10746. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10747. type: string
  10748. type: object
  10749. value:
  10750. description: Value can be specified directly to set a value without using a secret.
  10751. type: string
  10752. type: object
  10753. tenant:
  10754. description: Tenant is the chosen hostname / site name.
  10755. type: string
  10756. tld:
  10757. description: |-
  10758. TLD is based on the server location that was chosen during provisioning.
  10759. If unset, defaults to "com".
  10760. type: string
  10761. urlTemplate:
  10762. description: |-
  10763. URLTemplate
  10764. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  10765. type: string
  10766. required:
  10767. - clientId
  10768. - clientSecret
  10769. - tenant
  10770. type: object
  10771. device42:
  10772. description: Device42 configures this store to sync secrets using the Device42 provider
  10773. properties:
  10774. auth:
  10775. description: Auth configures how secret-manager authenticates with a Device42 instance.
  10776. properties:
  10777. secretRef:
  10778. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  10779. properties:
  10780. credentials:
  10781. description: Username / Password is used for authentication.
  10782. properties:
  10783. key:
  10784. description: |-
  10785. A key in the referenced Secret.
  10786. Some instances of this field may be defaulted, in others it may be required.
  10787. maxLength: 253
  10788. minLength: 1
  10789. pattern: ^[-._a-zA-Z0-9]+$
  10790. type: string
  10791. name:
  10792. description: The name of the Secret resource being referred to.
  10793. maxLength: 253
  10794. minLength: 1
  10795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10796. type: string
  10797. namespace:
  10798. description: |-
  10799. The namespace of the Secret resource being referred to.
  10800. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10801. maxLength: 63
  10802. minLength: 1
  10803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10804. type: string
  10805. type: object
  10806. type: object
  10807. required:
  10808. - secretRef
  10809. type: object
  10810. host:
  10811. description: URL configures the Device42 instance URL.
  10812. type: string
  10813. required:
  10814. - auth
  10815. - host
  10816. type: object
  10817. doppler:
  10818. description: Doppler configures this store to sync secrets using the Doppler provider
  10819. properties:
  10820. auth:
  10821. description: Auth configures how the Operator authenticates with the Doppler API
  10822. properties:
  10823. secretRef:
  10824. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  10825. properties:
  10826. dopplerToken:
  10827. description: |-
  10828. The DopplerToken is used for authentication.
  10829. See https://docs.doppler.com/reference/api#authentication for auth token types.
  10830. The Key attribute defaults to dopplerToken if not specified.
  10831. properties:
  10832. key:
  10833. description: |-
  10834. A key in the referenced Secret.
  10835. Some instances of this field may be defaulted, in others it may be required.
  10836. maxLength: 253
  10837. minLength: 1
  10838. pattern: ^[-._a-zA-Z0-9]+$
  10839. type: string
  10840. name:
  10841. description: The name of the Secret resource being referred to.
  10842. maxLength: 253
  10843. minLength: 1
  10844. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10845. type: string
  10846. namespace:
  10847. description: |-
  10848. The namespace of the Secret resource being referred to.
  10849. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10850. maxLength: 63
  10851. minLength: 1
  10852. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10853. type: string
  10854. type: object
  10855. required:
  10856. - dopplerToken
  10857. type: object
  10858. required:
  10859. - secretRef
  10860. type: object
  10861. config:
  10862. description: Doppler config (required if not using a Service Token)
  10863. type: string
  10864. format:
  10865. description: Format enables the downloading of secrets as a file (string)
  10866. enum:
  10867. - json
  10868. - dotnet-json
  10869. - env
  10870. - yaml
  10871. - docker
  10872. type: string
  10873. nameTransformer:
  10874. description: Environment variable compatible name transforms that change secret names to a different format
  10875. enum:
  10876. - upper-camel
  10877. - camel
  10878. - lower-snake
  10879. - tf-var
  10880. - dotnet-env
  10881. - lower-kebab
  10882. type: string
  10883. project:
  10884. description: Doppler project (required if not using a Service Token)
  10885. type: string
  10886. required:
  10887. - auth
  10888. type: object
  10889. fake:
  10890. description: Fake configures a store with static key/value pairs
  10891. properties:
  10892. data:
  10893. items:
  10894. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  10895. properties:
  10896. key:
  10897. type: string
  10898. value:
  10899. type: string
  10900. version:
  10901. type: string
  10902. required:
  10903. - key
  10904. - value
  10905. type: object
  10906. type: array
  10907. required:
  10908. - data
  10909. type: object
  10910. fortanix:
  10911. description: Fortanix configures this store to sync secrets using the Fortanix provider
  10912. properties:
  10913. apiKey:
  10914. description: APIKey is the API token to access SDKMS Applications.
  10915. properties:
  10916. secretRef:
  10917. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  10918. properties:
  10919. key:
  10920. description: |-
  10921. A key in the referenced Secret.
  10922. Some instances of this field may be defaulted, in others it may be required.
  10923. maxLength: 253
  10924. minLength: 1
  10925. pattern: ^[-._a-zA-Z0-9]+$
  10926. type: string
  10927. name:
  10928. description: The name of the Secret resource being referred to.
  10929. maxLength: 253
  10930. minLength: 1
  10931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10932. type: string
  10933. namespace:
  10934. description: |-
  10935. The namespace of the Secret resource being referred to.
  10936. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10937. maxLength: 63
  10938. minLength: 1
  10939. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10940. type: string
  10941. type: object
  10942. type: object
  10943. apiUrl:
  10944. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  10945. type: string
  10946. type: object
  10947. gcpsm:
  10948. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  10949. properties:
  10950. auth:
  10951. description: Auth defines the information necessary to authenticate against GCP
  10952. properties:
  10953. secretRef:
  10954. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  10955. properties:
  10956. secretAccessKeySecretRef:
  10957. description: The SecretAccessKey is used for authentication
  10958. properties:
  10959. key:
  10960. description: |-
  10961. A key in the referenced Secret.
  10962. Some instances of this field may be defaulted, in others it may be required.
  10963. maxLength: 253
  10964. minLength: 1
  10965. pattern: ^[-._a-zA-Z0-9]+$
  10966. type: string
  10967. name:
  10968. description: The name of the Secret resource being referred to.
  10969. maxLength: 253
  10970. minLength: 1
  10971. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10972. type: string
  10973. namespace:
  10974. description: |-
  10975. The namespace of the Secret resource being referred to.
  10976. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10977. maxLength: 63
  10978. minLength: 1
  10979. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10980. type: string
  10981. type: object
  10982. type: object
  10983. workloadIdentity:
  10984. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  10985. properties:
  10986. clusterLocation:
  10987. description: |-
  10988. ClusterLocation is the location of the cluster
  10989. If not specified, it fetches information from the metadata server
  10990. type: string
  10991. clusterName:
  10992. description: |-
  10993. ClusterName is the name of the cluster
  10994. If not specified, it fetches information from the metadata server
  10995. type: string
  10996. clusterProjectID:
  10997. description: |-
  10998. ClusterProjectID is the project ID of the cluster
  10999. If not specified, it fetches information from the metadata server
  11000. type: string
  11001. serviceAccountRef:
  11002. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  11003. properties:
  11004. audiences:
  11005. description: |-
  11006. Audience specifies the `aud` claim for the service account token
  11007. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11008. then this audiences will be appended to the list
  11009. items:
  11010. type: string
  11011. type: array
  11012. name:
  11013. description: The name of the ServiceAccount resource being referred to.
  11014. maxLength: 253
  11015. minLength: 1
  11016. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11017. type: string
  11018. namespace:
  11019. description: |-
  11020. Namespace of the resource being referred to.
  11021. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11022. maxLength: 63
  11023. minLength: 1
  11024. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11025. type: string
  11026. required:
  11027. - name
  11028. type: object
  11029. required:
  11030. - serviceAccountRef
  11031. type: object
  11032. type: object
  11033. location:
  11034. description: Location optionally defines a location for a secret
  11035. type: string
  11036. projectID:
  11037. description: ProjectID project where secret is located
  11038. type: string
  11039. type: object
  11040. github:
  11041. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  11042. properties:
  11043. appID:
  11044. description: appID specifies the Github APP that will be used to authenticate the client
  11045. format: int64
  11046. type: integer
  11047. auth:
  11048. description: auth configures how secret-manager authenticates with a Github instance.
  11049. properties:
  11050. privateKey:
  11051. description: |-
  11052. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11053. In some instances, `key` is a required field.
  11054. properties:
  11055. key:
  11056. description: |-
  11057. A key in the referenced Secret.
  11058. Some instances of this field may be defaulted, in others it may be required.
  11059. maxLength: 253
  11060. minLength: 1
  11061. pattern: ^[-._a-zA-Z0-9]+$
  11062. type: string
  11063. name:
  11064. description: The name of the Secret resource being referred to.
  11065. maxLength: 253
  11066. minLength: 1
  11067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11068. type: string
  11069. namespace:
  11070. description: |-
  11071. The namespace of the Secret resource being referred to.
  11072. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11073. maxLength: 63
  11074. minLength: 1
  11075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11076. type: string
  11077. type: object
  11078. required:
  11079. - privateKey
  11080. type: object
  11081. environment:
  11082. description: environment will be used to fetch secrets from a particular environment within a github repository
  11083. type: string
  11084. installationID:
  11085. description: installationID specifies the Github APP installation that will be used to authenticate the client
  11086. format: int64
  11087. type: integer
  11088. organization:
  11089. description: organization will be used to fetch secrets from the Github organization
  11090. type: string
  11091. repository:
  11092. description: repository will be used to fetch secrets from the Github repository within an organization
  11093. type: string
  11094. uploadURL:
  11095. description: Upload URL for enterprise instances. Default to URL.
  11096. type: string
  11097. url:
  11098. default: https://github.com/
  11099. description: URL configures the Github instance URL. Defaults to https://github.com/.
  11100. type: string
  11101. required:
  11102. - appID
  11103. - auth
  11104. - installationID
  11105. - organization
  11106. type: object
  11107. gitlab:
  11108. description: GitLab configures this store to sync secrets using GitLab Variables provider
  11109. properties:
  11110. auth:
  11111. description: Auth configures how secret-manager authenticates with a GitLab instance.
  11112. properties:
  11113. SecretRef:
  11114. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  11115. properties:
  11116. accessToken:
  11117. description: AccessToken is used for authentication.
  11118. properties:
  11119. key:
  11120. description: |-
  11121. A key in the referenced Secret.
  11122. Some instances of this field may be defaulted, in others it may be required.
  11123. maxLength: 253
  11124. minLength: 1
  11125. pattern: ^[-._a-zA-Z0-9]+$
  11126. type: string
  11127. name:
  11128. description: The name of the Secret resource being referred to.
  11129. maxLength: 253
  11130. minLength: 1
  11131. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11132. type: string
  11133. namespace:
  11134. description: |-
  11135. The namespace of the Secret resource being referred to.
  11136. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11137. maxLength: 63
  11138. minLength: 1
  11139. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11140. type: string
  11141. type: object
  11142. type: object
  11143. required:
  11144. - SecretRef
  11145. type: object
  11146. caBundle:
  11147. description: |-
  11148. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  11149. can be performed.
  11150. format: byte
  11151. type: string
  11152. caProvider:
  11153. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  11154. properties:
  11155. key:
  11156. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11157. maxLength: 253
  11158. minLength: 1
  11159. pattern: ^[-._a-zA-Z0-9]+$
  11160. type: string
  11161. name:
  11162. description: The name of the object located at the provider type.
  11163. maxLength: 253
  11164. minLength: 1
  11165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11166. type: string
  11167. namespace:
  11168. description: |-
  11169. The namespace the Provider type is in.
  11170. Can only be defined when used in a ClusterSecretStore.
  11171. maxLength: 63
  11172. minLength: 1
  11173. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11174. type: string
  11175. type:
  11176. description: The type of provider to use such as "Secret", or "ConfigMap".
  11177. enum:
  11178. - Secret
  11179. - ConfigMap
  11180. type: string
  11181. required:
  11182. - name
  11183. - type
  11184. type: object
  11185. environment:
  11186. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  11187. type: string
  11188. groupIDs:
  11189. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  11190. items:
  11191. type: string
  11192. type: array
  11193. inheritFromGroups:
  11194. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  11195. type: boolean
  11196. projectID:
  11197. description: ProjectID specifies a project where secrets are located.
  11198. type: string
  11199. url:
  11200. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  11201. type: string
  11202. required:
  11203. - auth
  11204. type: object
  11205. ibm:
  11206. description: IBM configures this store to sync secrets using IBM Cloud provider
  11207. properties:
  11208. auth:
  11209. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  11210. maxProperties: 1
  11211. minProperties: 1
  11212. properties:
  11213. containerAuth:
  11214. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  11215. properties:
  11216. iamEndpoint:
  11217. type: string
  11218. profile:
  11219. description: the IBM Trusted Profile
  11220. type: string
  11221. tokenLocation:
  11222. description: Location the token is mounted on the pod
  11223. type: string
  11224. required:
  11225. - profile
  11226. type: object
  11227. secretRef:
  11228. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  11229. properties:
  11230. secretApiKeySecretRef:
  11231. description: The SecretAccessKey is used for authentication
  11232. properties:
  11233. key:
  11234. description: |-
  11235. A key in the referenced Secret.
  11236. Some instances of this field may be defaulted, in others it may be required.
  11237. maxLength: 253
  11238. minLength: 1
  11239. pattern: ^[-._a-zA-Z0-9]+$
  11240. type: string
  11241. name:
  11242. description: The name of the Secret resource being referred to.
  11243. maxLength: 253
  11244. minLength: 1
  11245. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11246. type: string
  11247. namespace:
  11248. description: |-
  11249. The namespace of the Secret resource being referred to.
  11250. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11251. maxLength: 63
  11252. minLength: 1
  11253. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11254. type: string
  11255. type: object
  11256. type: object
  11257. type: object
  11258. serviceUrl:
  11259. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  11260. type: string
  11261. required:
  11262. - auth
  11263. type: object
  11264. infisical:
  11265. description: Infisical configures this store to sync secrets using the Infisical provider
  11266. properties:
  11267. auth:
  11268. description: Auth configures how the Operator authenticates with the Infisical API
  11269. properties:
  11270. universalAuthCredentials:
  11271. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  11272. properties:
  11273. clientId:
  11274. description: |-
  11275. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11276. In some instances, `key` is a required field.
  11277. properties:
  11278. key:
  11279. description: |-
  11280. A key in the referenced Secret.
  11281. Some instances of this field may be defaulted, in others it may be required.
  11282. maxLength: 253
  11283. minLength: 1
  11284. pattern: ^[-._a-zA-Z0-9]+$
  11285. type: string
  11286. name:
  11287. description: The name of the Secret resource being referred to.
  11288. maxLength: 253
  11289. minLength: 1
  11290. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11291. type: string
  11292. namespace:
  11293. description: |-
  11294. The namespace of the Secret resource being referred to.
  11295. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11296. maxLength: 63
  11297. minLength: 1
  11298. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11299. type: string
  11300. type: object
  11301. clientSecret:
  11302. description: |-
  11303. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11304. In some instances, `key` is a required field.
  11305. properties:
  11306. key:
  11307. description: |-
  11308. A key in the referenced Secret.
  11309. Some instances of this field may be defaulted, in others it may be required.
  11310. maxLength: 253
  11311. minLength: 1
  11312. pattern: ^[-._a-zA-Z0-9]+$
  11313. type: string
  11314. name:
  11315. description: The name of the Secret resource being referred to.
  11316. maxLength: 253
  11317. minLength: 1
  11318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11319. type: string
  11320. namespace:
  11321. description: |-
  11322. The namespace of the Secret resource being referred to.
  11323. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11324. maxLength: 63
  11325. minLength: 1
  11326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11327. type: string
  11328. type: object
  11329. required:
  11330. - clientId
  11331. - clientSecret
  11332. type: object
  11333. type: object
  11334. hostAPI:
  11335. default: https://app.infisical.com/api
  11336. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  11337. type: string
  11338. secretsScope:
  11339. description: SecretsScope defines the scope of the secrets within the workspace
  11340. properties:
  11341. environmentSlug:
  11342. description: EnvironmentSlug is the required slug identifier for the environment.
  11343. type: string
  11344. expandSecretReferences:
  11345. default: true
  11346. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  11347. type: boolean
  11348. projectSlug:
  11349. description: ProjectSlug is the required slug identifier for the project.
  11350. type: string
  11351. recursive:
  11352. default: false
  11353. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  11354. type: boolean
  11355. secretsPath:
  11356. default: /
  11357. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  11358. type: string
  11359. required:
  11360. - environmentSlug
  11361. - projectSlug
  11362. type: object
  11363. required:
  11364. - auth
  11365. - secretsScope
  11366. type: object
  11367. keepersecurity:
  11368. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  11369. properties:
  11370. authRef:
  11371. description: |-
  11372. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11373. In some instances, `key` is a required field.
  11374. properties:
  11375. key:
  11376. description: |-
  11377. A key in the referenced Secret.
  11378. Some instances of this field may be defaulted, in others it may be required.
  11379. maxLength: 253
  11380. minLength: 1
  11381. pattern: ^[-._a-zA-Z0-9]+$
  11382. type: string
  11383. name:
  11384. description: The name of the Secret resource being referred to.
  11385. maxLength: 253
  11386. minLength: 1
  11387. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11388. type: string
  11389. namespace:
  11390. description: |-
  11391. The namespace of the Secret resource being referred to.
  11392. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11393. maxLength: 63
  11394. minLength: 1
  11395. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11396. type: string
  11397. type: object
  11398. folderID:
  11399. type: string
  11400. required:
  11401. - authRef
  11402. - folderID
  11403. type: object
  11404. kubernetes:
  11405. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  11406. properties:
  11407. auth:
  11408. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  11409. maxProperties: 1
  11410. minProperties: 1
  11411. properties:
  11412. cert:
  11413. description: has both clientCert and clientKey as secretKeySelector
  11414. properties:
  11415. clientCert:
  11416. description: |-
  11417. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11418. In some instances, `key` is a required field.
  11419. properties:
  11420. key:
  11421. description: |-
  11422. A key in the referenced Secret.
  11423. Some instances of this field may be defaulted, in others it may be required.
  11424. maxLength: 253
  11425. minLength: 1
  11426. pattern: ^[-._a-zA-Z0-9]+$
  11427. type: string
  11428. name:
  11429. description: The name of the Secret resource being referred to.
  11430. maxLength: 253
  11431. minLength: 1
  11432. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11433. type: string
  11434. namespace:
  11435. description: |-
  11436. The namespace of the Secret resource being referred to.
  11437. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11438. maxLength: 63
  11439. minLength: 1
  11440. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11441. type: string
  11442. type: object
  11443. clientKey:
  11444. description: |-
  11445. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11446. In some instances, `key` is a required field.
  11447. properties:
  11448. key:
  11449. description: |-
  11450. A key in the referenced Secret.
  11451. Some instances of this field may be defaulted, in others it may be required.
  11452. maxLength: 253
  11453. minLength: 1
  11454. pattern: ^[-._a-zA-Z0-9]+$
  11455. type: string
  11456. name:
  11457. description: The name of the Secret resource being referred to.
  11458. maxLength: 253
  11459. minLength: 1
  11460. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11461. type: string
  11462. namespace:
  11463. description: |-
  11464. The namespace of the Secret resource being referred to.
  11465. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11466. maxLength: 63
  11467. minLength: 1
  11468. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11469. type: string
  11470. type: object
  11471. type: object
  11472. serviceAccount:
  11473. description: points to a service account that should be used for authentication
  11474. properties:
  11475. audiences:
  11476. description: |-
  11477. Audience specifies the `aud` claim for the service account token
  11478. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11479. then this audiences will be appended to the list
  11480. items:
  11481. type: string
  11482. type: array
  11483. name:
  11484. description: The name of the ServiceAccount resource being referred to.
  11485. maxLength: 253
  11486. minLength: 1
  11487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11488. type: string
  11489. namespace:
  11490. description: |-
  11491. Namespace of the resource being referred to.
  11492. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11493. maxLength: 63
  11494. minLength: 1
  11495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11496. type: string
  11497. required:
  11498. - name
  11499. type: object
  11500. token:
  11501. description: use static token to authenticate with
  11502. properties:
  11503. bearerToken:
  11504. description: |-
  11505. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11506. In some instances, `key` is a required field.
  11507. properties:
  11508. key:
  11509. description: |-
  11510. A key in the referenced Secret.
  11511. Some instances of this field may be defaulted, in others it may be required.
  11512. maxLength: 253
  11513. minLength: 1
  11514. pattern: ^[-._a-zA-Z0-9]+$
  11515. type: string
  11516. name:
  11517. description: The name of the Secret resource being referred to.
  11518. maxLength: 253
  11519. minLength: 1
  11520. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11521. type: string
  11522. namespace:
  11523. description: |-
  11524. The namespace of the Secret resource being referred to.
  11525. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11526. maxLength: 63
  11527. minLength: 1
  11528. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11529. type: string
  11530. type: object
  11531. type: object
  11532. type: object
  11533. authRef:
  11534. description: A reference to a secret that contains the auth information.
  11535. properties:
  11536. key:
  11537. description: |-
  11538. A key in the referenced Secret.
  11539. Some instances of this field may be defaulted, in others it may be required.
  11540. maxLength: 253
  11541. minLength: 1
  11542. pattern: ^[-._a-zA-Z0-9]+$
  11543. type: string
  11544. name:
  11545. description: The name of the Secret resource being referred to.
  11546. maxLength: 253
  11547. minLength: 1
  11548. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11549. type: string
  11550. namespace:
  11551. description: |-
  11552. The namespace of the Secret resource being referred to.
  11553. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11554. maxLength: 63
  11555. minLength: 1
  11556. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11557. type: string
  11558. type: object
  11559. remoteNamespace:
  11560. default: default
  11561. description: Remote namespace to fetch the secrets from
  11562. maxLength: 63
  11563. minLength: 1
  11564. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11565. type: string
  11566. server:
  11567. description: configures the Kubernetes server Address.
  11568. properties:
  11569. caBundle:
  11570. description: CABundle is a base64-encoded CA certificate
  11571. format: byte
  11572. type: string
  11573. caProvider:
  11574. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  11575. properties:
  11576. key:
  11577. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11578. maxLength: 253
  11579. minLength: 1
  11580. pattern: ^[-._a-zA-Z0-9]+$
  11581. type: string
  11582. name:
  11583. description: The name of the object located at the provider type.
  11584. maxLength: 253
  11585. minLength: 1
  11586. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11587. type: string
  11588. namespace:
  11589. description: |-
  11590. The namespace the Provider type is in.
  11591. Can only be defined when used in a ClusterSecretStore.
  11592. maxLength: 63
  11593. minLength: 1
  11594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11595. type: string
  11596. type:
  11597. description: The type of provider to use such as "Secret", or "ConfigMap".
  11598. enum:
  11599. - Secret
  11600. - ConfigMap
  11601. type: string
  11602. required:
  11603. - name
  11604. - type
  11605. type: object
  11606. url:
  11607. default: kubernetes.default
  11608. description: configures the Kubernetes server Address.
  11609. type: string
  11610. type: object
  11611. type: object
  11612. onboardbase:
  11613. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  11614. properties:
  11615. apiHost:
  11616. default: https://public.onboardbase.com/api/v1/
  11617. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  11618. type: string
  11619. auth:
  11620. description: Auth configures how the Operator authenticates with the Onboardbase API
  11621. properties:
  11622. apiKeyRef:
  11623. description: |-
  11624. OnboardbaseAPIKey is the APIKey generated by an admin account.
  11625. It is used to recognize and authorize access to a project and environment within onboardbase
  11626. properties:
  11627. key:
  11628. description: |-
  11629. A key in the referenced Secret.
  11630. Some instances of this field may be defaulted, in others it may be required.
  11631. maxLength: 253
  11632. minLength: 1
  11633. pattern: ^[-._a-zA-Z0-9]+$
  11634. type: string
  11635. name:
  11636. description: The name of the Secret resource being referred to.
  11637. maxLength: 253
  11638. minLength: 1
  11639. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11640. type: string
  11641. namespace:
  11642. description: |-
  11643. The namespace of the Secret resource being referred to.
  11644. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11645. maxLength: 63
  11646. minLength: 1
  11647. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11648. type: string
  11649. type: object
  11650. passcodeRef:
  11651. description: OnboardbasePasscode is the passcode attached to the API Key
  11652. properties:
  11653. key:
  11654. description: |-
  11655. A key in the referenced Secret.
  11656. Some instances of this field may be defaulted, in others it may be required.
  11657. maxLength: 253
  11658. minLength: 1
  11659. pattern: ^[-._a-zA-Z0-9]+$
  11660. type: string
  11661. name:
  11662. description: The name of the Secret resource being referred to.
  11663. maxLength: 253
  11664. minLength: 1
  11665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11666. type: string
  11667. namespace:
  11668. description: |-
  11669. The namespace of the Secret resource being referred to.
  11670. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11671. maxLength: 63
  11672. minLength: 1
  11673. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11674. type: string
  11675. type: object
  11676. required:
  11677. - apiKeyRef
  11678. - passcodeRef
  11679. type: object
  11680. environment:
  11681. default: development
  11682. description: Environment is the name of an environmnent within a project to pull the secrets from
  11683. type: string
  11684. project:
  11685. default: development
  11686. description: Project is an onboardbase project that the secrets should be pulled from
  11687. type: string
  11688. required:
  11689. - apiHost
  11690. - auth
  11691. - environment
  11692. - project
  11693. type: object
  11694. onepassword:
  11695. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  11696. properties:
  11697. auth:
  11698. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  11699. properties:
  11700. secretRef:
  11701. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  11702. properties:
  11703. connectTokenSecretRef:
  11704. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  11705. properties:
  11706. key:
  11707. description: |-
  11708. A key in the referenced Secret.
  11709. Some instances of this field may be defaulted, in others it may be required.
  11710. maxLength: 253
  11711. minLength: 1
  11712. pattern: ^[-._a-zA-Z0-9]+$
  11713. type: string
  11714. name:
  11715. description: The name of the Secret resource being referred to.
  11716. maxLength: 253
  11717. minLength: 1
  11718. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11719. type: string
  11720. namespace:
  11721. description: |-
  11722. The namespace of the Secret resource being referred to.
  11723. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11724. maxLength: 63
  11725. minLength: 1
  11726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11727. type: string
  11728. type: object
  11729. required:
  11730. - connectTokenSecretRef
  11731. type: object
  11732. required:
  11733. - secretRef
  11734. type: object
  11735. connectHost:
  11736. description: ConnectHost defines the OnePassword Connect Server to connect to
  11737. type: string
  11738. vaults:
  11739. additionalProperties:
  11740. type: integer
  11741. description: Vaults defines which OnePassword vaults to search in which order
  11742. type: object
  11743. required:
  11744. - auth
  11745. - connectHost
  11746. - vaults
  11747. type: object
  11748. oracle:
  11749. description: Oracle configures this store to sync secrets using Oracle Vault provider
  11750. properties:
  11751. auth:
  11752. description: |-
  11753. Auth configures how secret-manager authenticates with the Oracle Vault.
  11754. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  11755. properties:
  11756. secretRef:
  11757. description: SecretRef to pass through sensitive information.
  11758. properties:
  11759. fingerprint:
  11760. description: Fingerprint is the fingerprint of the API private key.
  11761. properties:
  11762. key:
  11763. description: |-
  11764. A key in the referenced Secret.
  11765. Some instances of this field may be defaulted, in others it may be required.
  11766. maxLength: 253
  11767. minLength: 1
  11768. pattern: ^[-._a-zA-Z0-9]+$
  11769. type: string
  11770. name:
  11771. description: The name of the Secret resource being referred to.
  11772. maxLength: 253
  11773. minLength: 1
  11774. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11775. type: string
  11776. namespace:
  11777. description: |-
  11778. The namespace of the Secret resource being referred to.
  11779. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11780. maxLength: 63
  11781. minLength: 1
  11782. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11783. type: string
  11784. type: object
  11785. privatekey:
  11786. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  11787. properties:
  11788. key:
  11789. description: |-
  11790. A key in the referenced Secret.
  11791. Some instances of this field may be defaulted, in others it may be required.
  11792. maxLength: 253
  11793. minLength: 1
  11794. pattern: ^[-._a-zA-Z0-9]+$
  11795. type: string
  11796. name:
  11797. description: The name of the Secret resource being referred to.
  11798. maxLength: 253
  11799. minLength: 1
  11800. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11801. type: string
  11802. namespace:
  11803. description: |-
  11804. The namespace of the Secret resource being referred to.
  11805. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11806. maxLength: 63
  11807. minLength: 1
  11808. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11809. type: string
  11810. type: object
  11811. required:
  11812. - fingerprint
  11813. - privatekey
  11814. type: object
  11815. tenancy:
  11816. description: Tenancy is the tenancy OCID where user is located.
  11817. type: string
  11818. user:
  11819. description: User is an access OCID specific to the account.
  11820. type: string
  11821. required:
  11822. - secretRef
  11823. - tenancy
  11824. - user
  11825. type: object
  11826. compartment:
  11827. description: |-
  11828. Compartment is the vault compartment OCID.
  11829. Required for PushSecret
  11830. type: string
  11831. encryptionKey:
  11832. description: |-
  11833. EncryptionKey is the OCID of the encryption key within the vault.
  11834. Required for PushSecret
  11835. type: string
  11836. principalType:
  11837. description: |-
  11838. The type of principal to use for authentication. If left blank, the Auth struct will
  11839. determine the principal type. This optional field must be specified if using
  11840. workload identity.
  11841. enum:
  11842. - ""
  11843. - UserPrincipal
  11844. - InstancePrincipal
  11845. - Workload
  11846. type: string
  11847. region:
  11848. description: Region is the region where vault is located.
  11849. type: string
  11850. serviceAccountRef:
  11851. description: |-
  11852. ServiceAccountRef specified the service account
  11853. that should be used when authenticating with WorkloadIdentity.
  11854. properties:
  11855. audiences:
  11856. description: |-
  11857. Audience specifies the `aud` claim for the service account token
  11858. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11859. then this audiences will be appended to the list
  11860. items:
  11861. type: string
  11862. type: array
  11863. name:
  11864. description: The name of the ServiceAccount resource being referred to.
  11865. maxLength: 253
  11866. minLength: 1
  11867. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11868. type: string
  11869. namespace:
  11870. description: |-
  11871. Namespace of the resource being referred to.
  11872. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11873. maxLength: 63
  11874. minLength: 1
  11875. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11876. type: string
  11877. required:
  11878. - name
  11879. type: object
  11880. vault:
  11881. description: Vault is the vault's OCID of the specific vault where secret is located.
  11882. type: string
  11883. required:
  11884. - region
  11885. - vault
  11886. type: object
  11887. passbolt:
  11888. description: PassboltProvider defines configuration for the Passbolt provider.
  11889. properties:
  11890. auth:
  11891. description: Auth defines the information necessary to authenticate against Passbolt Server
  11892. properties:
  11893. passwordSecretRef:
  11894. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  11895. properties:
  11896. key:
  11897. description: |-
  11898. A key in the referenced Secret.
  11899. Some instances of this field may be defaulted, in others it may be required.
  11900. maxLength: 253
  11901. minLength: 1
  11902. pattern: ^[-._a-zA-Z0-9]+$
  11903. type: string
  11904. name:
  11905. description: The name of the Secret resource being referred to.
  11906. maxLength: 253
  11907. minLength: 1
  11908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11909. type: string
  11910. namespace:
  11911. description: |-
  11912. The namespace of the Secret resource being referred to.
  11913. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11914. maxLength: 63
  11915. minLength: 1
  11916. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11917. type: string
  11918. type: object
  11919. privateKeySecretRef:
  11920. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  11921. properties:
  11922. key:
  11923. description: |-
  11924. A key in the referenced Secret.
  11925. Some instances of this field may be defaulted, in others it may be required.
  11926. maxLength: 253
  11927. minLength: 1
  11928. pattern: ^[-._a-zA-Z0-9]+$
  11929. type: string
  11930. name:
  11931. description: The name of the Secret resource being referred to.
  11932. maxLength: 253
  11933. minLength: 1
  11934. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11935. type: string
  11936. namespace:
  11937. description: |-
  11938. The namespace of the Secret resource being referred to.
  11939. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11940. maxLength: 63
  11941. minLength: 1
  11942. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11943. type: string
  11944. type: object
  11945. required:
  11946. - passwordSecretRef
  11947. - privateKeySecretRef
  11948. type: object
  11949. host:
  11950. description: Host defines the Passbolt Server to connect to
  11951. type: string
  11952. required:
  11953. - auth
  11954. - host
  11955. type: object
  11956. passworddepot:
  11957. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  11958. properties:
  11959. auth:
  11960. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  11961. properties:
  11962. secretRef:
  11963. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  11964. properties:
  11965. credentials:
  11966. description: Username / Password is used for authentication.
  11967. properties:
  11968. key:
  11969. description: |-
  11970. A key in the referenced Secret.
  11971. Some instances of this field may be defaulted, in others it may be required.
  11972. maxLength: 253
  11973. minLength: 1
  11974. pattern: ^[-._a-zA-Z0-9]+$
  11975. type: string
  11976. name:
  11977. description: The name of the Secret resource being referred to.
  11978. maxLength: 253
  11979. minLength: 1
  11980. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11981. type: string
  11982. namespace:
  11983. description: |-
  11984. The namespace of the Secret resource being referred to.
  11985. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11986. maxLength: 63
  11987. minLength: 1
  11988. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11989. type: string
  11990. type: object
  11991. type: object
  11992. required:
  11993. - secretRef
  11994. type: object
  11995. database:
  11996. description: Database to use as source
  11997. type: string
  11998. host:
  11999. description: URL configures the Password Depot instance URL.
  12000. type: string
  12001. required:
  12002. - auth
  12003. - database
  12004. - host
  12005. type: object
  12006. previder:
  12007. description: Previder configures this store to sync secrets using the Previder provider
  12008. properties:
  12009. auth:
  12010. description: PreviderAuth contains a secretRef for credentials.
  12011. properties:
  12012. secretRef:
  12013. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  12014. properties:
  12015. accessToken:
  12016. description: The AccessToken is used for authentication
  12017. properties:
  12018. key:
  12019. description: |-
  12020. A key in the referenced Secret.
  12021. Some instances of this field may be defaulted, in others it may be required.
  12022. maxLength: 253
  12023. minLength: 1
  12024. pattern: ^[-._a-zA-Z0-9]+$
  12025. type: string
  12026. name:
  12027. description: The name of the Secret resource being referred to.
  12028. maxLength: 253
  12029. minLength: 1
  12030. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12031. type: string
  12032. namespace:
  12033. description: |-
  12034. The namespace of the Secret resource being referred to.
  12035. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12036. maxLength: 63
  12037. minLength: 1
  12038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12039. type: string
  12040. type: object
  12041. required:
  12042. - accessToken
  12043. type: object
  12044. type: object
  12045. baseUri:
  12046. type: string
  12047. required:
  12048. - auth
  12049. type: object
  12050. pulumi:
  12051. description: Pulumi configures this store to sync secrets using the Pulumi provider
  12052. properties:
  12053. accessToken:
  12054. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  12055. properties:
  12056. secretRef:
  12057. description: SecretRef is a reference to a secret containing the Pulumi API token.
  12058. properties:
  12059. key:
  12060. description: |-
  12061. A key in the referenced Secret.
  12062. Some instances of this field may be defaulted, in others it may be required.
  12063. maxLength: 253
  12064. minLength: 1
  12065. pattern: ^[-._a-zA-Z0-9]+$
  12066. type: string
  12067. name:
  12068. description: The name of the Secret resource being referred to.
  12069. maxLength: 253
  12070. minLength: 1
  12071. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12072. type: string
  12073. namespace:
  12074. description: |-
  12075. The namespace of the Secret resource being referred to.
  12076. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12077. maxLength: 63
  12078. minLength: 1
  12079. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12080. type: string
  12081. type: object
  12082. type: object
  12083. apiUrl:
  12084. default: https://api.pulumi.com/api/esc
  12085. description: APIURL is the URL of the Pulumi API.
  12086. type: string
  12087. environment:
  12088. description: |-
  12089. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  12090. dynamically retrieved values from supported providers including all major clouds,
  12091. and other Pulumi ESC environments.
  12092. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  12093. type: string
  12094. organization:
  12095. description: |-
  12096. Organization are a space to collaborate on shared projects and stacks.
  12097. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  12098. type: string
  12099. project:
  12100. description: Project is the name of the Pulumi ESC project the environment belongs to.
  12101. type: string
  12102. required:
  12103. - accessToken
  12104. - environment
  12105. - organization
  12106. - project
  12107. type: object
  12108. scaleway:
  12109. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  12110. properties:
  12111. accessKey:
  12112. description: AccessKey is the non-secret part of the api key.
  12113. properties:
  12114. secretRef:
  12115. description: SecretRef references a key in a secret that will be used as value.
  12116. properties:
  12117. key:
  12118. description: |-
  12119. A key in the referenced Secret.
  12120. Some instances of this field may be defaulted, in others it may be required.
  12121. maxLength: 253
  12122. minLength: 1
  12123. pattern: ^[-._a-zA-Z0-9]+$
  12124. type: string
  12125. name:
  12126. description: The name of the Secret resource being referred to.
  12127. maxLength: 253
  12128. minLength: 1
  12129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12130. type: string
  12131. namespace:
  12132. description: |-
  12133. The namespace of the Secret resource being referred to.
  12134. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12135. maxLength: 63
  12136. minLength: 1
  12137. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12138. type: string
  12139. type: object
  12140. value:
  12141. description: Value can be specified directly to set a value without using a secret.
  12142. type: string
  12143. type: object
  12144. apiUrl:
  12145. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  12146. type: string
  12147. projectId:
  12148. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  12149. type: string
  12150. region:
  12151. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  12152. type: string
  12153. secretKey:
  12154. description: SecretKey is the non-secret part of the api key.
  12155. properties:
  12156. secretRef:
  12157. description: SecretRef references a key in a secret that will be used as value.
  12158. properties:
  12159. key:
  12160. description: |-
  12161. A key in the referenced Secret.
  12162. Some instances of this field may be defaulted, in others it may be required.
  12163. maxLength: 253
  12164. minLength: 1
  12165. pattern: ^[-._a-zA-Z0-9]+$
  12166. type: string
  12167. name:
  12168. description: The name of the Secret resource being referred to.
  12169. maxLength: 253
  12170. minLength: 1
  12171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12172. type: string
  12173. namespace:
  12174. description: |-
  12175. The namespace of the Secret resource being referred to.
  12176. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12177. maxLength: 63
  12178. minLength: 1
  12179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12180. type: string
  12181. type: object
  12182. value:
  12183. description: Value can be specified directly to set a value without using a secret.
  12184. type: string
  12185. type: object
  12186. required:
  12187. - accessKey
  12188. - projectId
  12189. - region
  12190. - secretKey
  12191. type: object
  12192. secretserver:
  12193. description: |-
  12194. SecretServer configures this store to sync secrets using SecretServer provider
  12195. https://docs.delinea.com/online-help/secret-server/start.htm
  12196. properties:
  12197. password:
  12198. description: Password is the secret server account password.
  12199. properties:
  12200. secretRef:
  12201. description: SecretRef references a key in a secret that will be used as value.
  12202. properties:
  12203. key:
  12204. description: |-
  12205. A key in the referenced Secret.
  12206. Some instances of this field may be defaulted, in others it may be required.
  12207. maxLength: 253
  12208. minLength: 1
  12209. pattern: ^[-._a-zA-Z0-9]+$
  12210. type: string
  12211. name:
  12212. description: The name of the Secret resource being referred to.
  12213. maxLength: 253
  12214. minLength: 1
  12215. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12216. type: string
  12217. namespace:
  12218. description: |-
  12219. The namespace of the Secret resource being referred to.
  12220. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12221. maxLength: 63
  12222. minLength: 1
  12223. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12224. type: string
  12225. type: object
  12226. value:
  12227. description: Value can be specified directly to set a value without using a secret.
  12228. type: string
  12229. type: object
  12230. serverURL:
  12231. description: |-
  12232. ServerURL
  12233. URL to your secret server installation
  12234. type: string
  12235. username:
  12236. description: Username is the secret server account username.
  12237. properties:
  12238. secretRef:
  12239. description: SecretRef references a key in a secret that will be used as value.
  12240. properties:
  12241. key:
  12242. description: |-
  12243. A key in the referenced Secret.
  12244. Some instances of this field may be defaulted, in others it may be required.
  12245. maxLength: 253
  12246. minLength: 1
  12247. pattern: ^[-._a-zA-Z0-9]+$
  12248. type: string
  12249. name:
  12250. description: The name of the Secret resource being referred to.
  12251. maxLength: 253
  12252. minLength: 1
  12253. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12254. type: string
  12255. namespace:
  12256. description: |-
  12257. The namespace of the Secret resource being referred to.
  12258. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12259. maxLength: 63
  12260. minLength: 1
  12261. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12262. type: string
  12263. type: object
  12264. value:
  12265. description: Value can be specified directly to set a value without using a secret.
  12266. type: string
  12267. type: object
  12268. required:
  12269. - password
  12270. - serverURL
  12271. - username
  12272. type: object
  12273. senhasegura:
  12274. description: Senhasegura configures this store to sync secrets using senhasegura provider
  12275. properties:
  12276. auth:
  12277. description: Auth defines parameters to authenticate in senhasegura
  12278. properties:
  12279. clientId:
  12280. type: string
  12281. clientSecretSecretRef:
  12282. description: |-
  12283. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  12284. In some instances, `key` is a required field.
  12285. properties:
  12286. key:
  12287. description: |-
  12288. A key in the referenced Secret.
  12289. Some instances of this field may be defaulted, in others it may be required.
  12290. maxLength: 253
  12291. minLength: 1
  12292. pattern: ^[-._a-zA-Z0-9]+$
  12293. type: string
  12294. name:
  12295. description: The name of the Secret resource being referred to.
  12296. maxLength: 253
  12297. minLength: 1
  12298. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12299. type: string
  12300. namespace:
  12301. description: |-
  12302. The namespace of the Secret resource being referred to.
  12303. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12304. maxLength: 63
  12305. minLength: 1
  12306. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12307. type: string
  12308. type: object
  12309. required:
  12310. - clientId
  12311. - clientSecretSecretRef
  12312. type: object
  12313. ignoreSslCertificate:
  12314. default: false
  12315. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  12316. type: boolean
  12317. module:
  12318. description: Module defines which senhasegura module should be used to get secrets
  12319. type: string
  12320. url:
  12321. description: URL of senhasegura
  12322. type: string
  12323. required:
  12324. - auth
  12325. - module
  12326. - url
  12327. type: object
  12328. vault:
  12329. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  12330. properties:
  12331. auth:
  12332. description: Auth configures how secret-manager authenticates with the Vault server.
  12333. properties:
  12334. appRole:
  12335. description: |-
  12336. AppRole authenticates with Vault using the App Role auth mechanism,
  12337. with the role and secret stored in a Kubernetes Secret resource.
  12338. properties:
  12339. path:
  12340. default: approle
  12341. description: |-
  12342. Path where the App Role authentication backend is mounted
  12343. in Vault, e.g: "approle"
  12344. type: string
  12345. roleId:
  12346. description: |-
  12347. RoleID configured in the App Role authentication backend when setting
  12348. up the authentication backend in Vault.
  12349. type: string
  12350. roleRef:
  12351. description: |-
  12352. Reference to a key in a Secret that contains the App Role ID used
  12353. to authenticate with Vault.
  12354. The `key` field must be specified and denotes which entry within the Secret
  12355. resource is used as the app role id.
  12356. properties:
  12357. key:
  12358. description: |-
  12359. A key in the referenced Secret.
  12360. Some instances of this field may be defaulted, in others it may be required.
  12361. maxLength: 253
  12362. minLength: 1
  12363. pattern: ^[-._a-zA-Z0-9]+$
  12364. type: string
  12365. name:
  12366. description: The name of the Secret resource being referred to.
  12367. maxLength: 253
  12368. minLength: 1
  12369. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12370. type: string
  12371. namespace:
  12372. description: |-
  12373. The namespace of the Secret resource being referred to.
  12374. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12375. maxLength: 63
  12376. minLength: 1
  12377. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12378. type: string
  12379. type: object
  12380. secretRef:
  12381. description: |-
  12382. Reference to a key in a Secret that contains the App Role secret used
  12383. to authenticate with Vault.
  12384. The `key` field must be specified and denotes which entry within the Secret
  12385. resource is used as the app role secret.
  12386. properties:
  12387. key:
  12388. description: |-
  12389. A key in the referenced Secret.
  12390. Some instances of this field may be defaulted, in others it may be required.
  12391. maxLength: 253
  12392. minLength: 1
  12393. pattern: ^[-._a-zA-Z0-9]+$
  12394. type: string
  12395. name:
  12396. description: The name of the Secret resource being referred to.
  12397. maxLength: 253
  12398. minLength: 1
  12399. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12400. type: string
  12401. namespace:
  12402. description: |-
  12403. The namespace of the Secret resource being referred to.
  12404. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12405. maxLength: 63
  12406. minLength: 1
  12407. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12408. type: string
  12409. type: object
  12410. required:
  12411. - path
  12412. - secretRef
  12413. type: object
  12414. cert:
  12415. description: |-
  12416. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  12417. Cert authentication method
  12418. properties:
  12419. clientCert:
  12420. description: |-
  12421. ClientCert is a certificate to authenticate using the Cert Vault
  12422. authentication method
  12423. properties:
  12424. key:
  12425. description: |-
  12426. A key in the referenced Secret.
  12427. Some instances of this field may be defaulted, in others it may be required.
  12428. maxLength: 253
  12429. minLength: 1
  12430. pattern: ^[-._a-zA-Z0-9]+$
  12431. type: string
  12432. name:
  12433. description: The name of the Secret resource being referred to.
  12434. maxLength: 253
  12435. minLength: 1
  12436. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12437. type: string
  12438. namespace:
  12439. description: |-
  12440. The namespace of the Secret resource being referred to.
  12441. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12442. maxLength: 63
  12443. minLength: 1
  12444. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12445. type: string
  12446. type: object
  12447. secretRef:
  12448. description: |-
  12449. SecretRef to a key in a Secret resource containing client private key to
  12450. authenticate with Vault using the Cert authentication method
  12451. properties:
  12452. key:
  12453. description: |-
  12454. A key in the referenced Secret.
  12455. Some instances of this field may be defaulted, in others it may be required.
  12456. maxLength: 253
  12457. minLength: 1
  12458. pattern: ^[-._a-zA-Z0-9]+$
  12459. type: string
  12460. name:
  12461. description: The name of the Secret resource being referred to.
  12462. maxLength: 253
  12463. minLength: 1
  12464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12465. type: string
  12466. namespace:
  12467. description: |-
  12468. The namespace of the Secret resource being referred to.
  12469. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12470. maxLength: 63
  12471. minLength: 1
  12472. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12473. type: string
  12474. type: object
  12475. type: object
  12476. iam:
  12477. description: |-
  12478. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  12479. AWS IAM authentication method
  12480. properties:
  12481. externalID:
  12482. description: AWS External ID set on assumed IAM roles
  12483. type: string
  12484. jwt:
  12485. description: Specify a service account with IRSA enabled
  12486. properties:
  12487. serviceAccountRef:
  12488. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  12489. properties:
  12490. audiences:
  12491. description: |-
  12492. Audience specifies the `aud` claim for the service account token
  12493. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12494. then this audiences will be appended to the list
  12495. items:
  12496. type: string
  12497. type: array
  12498. name:
  12499. description: The name of the ServiceAccount resource being referred to.
  12500. maxLength: 253
  12501. minLength: 1
  12502. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12503. type: string
  12504. namespace:
  12505. description: |-
  12506. Namespace of the resource being referred to.
  12507. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12508. maxLength: 63
  12509. minLength: 1
  12510. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12511. type: string
  12512. required:
  12513. - name
  12514. type: object
  12515. type: object
  12516. path:
  12517. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  12518. type: string
  12519. region:
  12520. description: AWS region
  12521. type: string
  12522. role:
  12523. description: This is the AWS role to be assumed before talking to vault
  12524. type: string
  12525. secretRef:
  12526. description: Specify credentials in a Secret object
  12527. properties:
  12528. accessKeyIDSecretRef:
  12529. description: The AccessKeyID is used for authentication
  12530. properties:
  12531. key:
  12532. description: |-
  12533. A key in the referenced Secret.
  12534. Some instances of this field may be defaulted, in others it may be required.
  12535. maxLength: 253
  12536. minLength: 1
  12537. pattern: ^[-._a-zA-Z0-9]+$
  12538. type: string
  12539. name:
  12540. description: The name of the Secret resource being referred to.
  12541. maxLength: 253
  12542. minLength: 1
  12543. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12544. type: string
  12545. namespace:
  12546. description: |-
  12547. The namespace of the Secret resource being referred to.
  12548. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12549. maxLength: 63
  12550. minLength: 1
  12551. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12552. type: string
  12553. type: object
  12554. secretAccessKeySecretRef:
  12555. description: The SecretAccessKey is used for authentication
  12556. properties:
  12557. key:
  12558. description: |-
  12559. A key in the referenced Secret.
  12560. Some instances of this field may be defaulted, in others it may be required.
  12561. maxLength: 253
  12562. minLength: 1
  12563. pattern: ^[-._a-zA-Z0-9]+$
  12564. type: string
  12565. name:
  12566. description: The name of the Secret resource being referred to.
  12567. maxLength: 253
  12568. minLength: 1
  12569. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12570. type: string
  12571. namespace:
  12572. description: |-
  12573. The namespace of the Secret resource being referred to.
  12574. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12575. maxLength: 63
  12576. minLength: 1
  12577. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12578. type: string
  12579. type: object
  12580. sessionTokenSecretRef:
  12581. description: |-
  12582. The SessionToken used for authentication
  12583. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  12584. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  12585. properties:
  12586. key:
  12587. description: |-
  12588. A key in the referenced Secret.
  12589. Some instances of this field may be defaulted, in others it may be required.
  12590. maxLength: 253
  12591. minLength: 1
  12592. pattern: ^[-._a-zA-Z0-9]+$
  12593. type: string
  12594. name:
  12595. description: The name of the Secret resource being referred to.
  12596. maxLength: 253
  12597. minLength: 1
  12598. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12599. type: string
  12600. namespace:
  12601. description: |-
  12602. The namespace of the Secret resource being referred to.
  12603. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12604. maxLength: 63
  12605. minLength: 1
  12606. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12607. type: string
  12608. type: object
  12609. type: object
  12610. vaultAwsIamServerID:
  12611. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  12612. type: string
  12613. vaultRole:
  12614. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  12615. type: string
  12616. required:
  12617. - vaultRole
  12618. type: object
  12619. jwt:
  12620. description: |-
  12621. Jwt authenticates with Vault by passing role and JWT token using the
  12622. JWT/OIDC authentication method
  12623. properties:
  12624. kubernetesServiceAccountToken:
  12625. description: |-
  12626. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  12627. a token for with the `TokenRequest` API.
  12628. properties:
  12629. audiences:
  12630. description: |-
  12631. Optional audiences field that will be used to request a temporary Kubernetes service
  12632. account token for the service account referenced by `serviceAccountRef`.
  12633. Defaults to a single audience `vault` it not specified.
  12634. Deprecated: use serviceAccountRef.Audiences instead
  12635. items:
  12636. type: string
  12637. type: array
  12638. expirationSeconds:
  12639. description: |-
  12640. Optional expiration time in seconds that will be used to request a temporary
  12641. Kubernetes service account token for the service account referenced by
  12642. `serviceAccountRef`.
  12643. Deprecated: this will be removed in the future.
  12644. Defaults to 10 minutes.
  12645. format: int64
  12646. type: integer
  12647. serviceAccountRef:
  12648. description: Service account field containing the name of a kubernetes ServiceAccount.
  12649. properties:
  12650. audiences:
  12651. description: |-
  12652. Audience specifies the `aud` claim for the service account token
  12653. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12654. then this audiences will be appended to the list
  12655. items:
  12656. type: string
  12657. type: array
  12658. name:
  12659. description: The name of the ServiceAccount resource being referred to.
  12660. maxLength: 253
  12661. minLength: 1
  12662. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12663. type: string
  12664. namespace:
  12665. description: |-
  12666. Namespace of the resource being referred to.
  12667. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12668. maxLength: 63
  12669. minLength: 1
  12670. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12671. type: string
  12672. required:
  12673. - name
  12674. type: object
  12675. required:
  12676. - serviceAccountRef
  12677. type: object
  12678. path:
  12679. default: jwt
  12680. description: |-
  12681. Path where the JWT authentication backend is mounted
  12682. in Vault, e.g: "jwt"
  12683. type: string
  12684. role:
  12685. description: |-
  12686. Role is a JWT role to authenticate using the JWT/OIDC Vault
  12687. authentication method
  12688. type: string
  12689. secretRef:
  12690. description: |-
  12691. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  12692. authenticate with Vault using the JWT/OIDC authentication method.
  12693. properties:
  12694. key:
  12695. description: |-
  12696. A key in the referenced Secret.
  12697. Some instances of this field may be defaulted, in others it may be required.
  12698. maxLength: 253
  12699. minLength: 1
  12700. pattern: ^[-._a-zA-Z0-9]+$
  12701. type: string
  12702. name:
  12703. description: The name of the Secret resource being referred to.
  12704. maxLength: 253
  12705. minLength: 1
  12706. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12707. type: string
  12708. namespace:
  12709. description: |-
  12710. The namespace of the Secret resource being referred to.
  12711. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12712. maxLength: 63
  12713. minLength: 1
  12714. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12715. type: string
  12716. type: object
  12717. required:
  12718. - path
  12719. type: object
  12720. kubernetes:
  12721. description: |-
  12722. Kubernetes authenticates with Vault by passing the ServiceAccount
  12723. token stored in the named Secret resource to the Vault server.
  12724. properties:
  12725. mountPath:
  12726. default: kubernetes
  12727. description: |-
  12728. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  12729. "kubernetes"
  12730. type: string
  12731. role:
  12732. description: |-
  12733. A required field containing the Vault Role to assume. A Role binds a
  12734. Kubernetes ServiceAccount with a set of Vault policies.
  12735. type: string
  12736. secretRef:
  12737. description: |-
  12738. Optional secret field containing a Kubernetes ServiceAccount JWT used
  12739. for authenticating with Vault. If a name is specified without a key,
  12740. `token` is the default. If one is not specified, the one bound to
  12741. the controller will be used.
  12742. properties:
  12743. key:
  12744. description: |-
  12745. A key in the referenced Secret.
  12746. Some instances of this field may be defaulted, in others it may be required.
  12747. maxLength: 253
  12748. minLength: 1
  12749. pattern: ^[-._a-zA-Z0-9]+$
  12750. type: string
  12751. name:
  12752. description: The name of the Secret resource being referred to.
  12753. maxLength: 253
  12754. minLength: 1
  12755. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12756. type: string
  12757. namespace:
  12758. description: |-
  12759. The namespace of the Secret resource being referred to.
  12760. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12761. maxLength: 63
  12762. minLength: 1
  12763. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12764. type: string
  12765. type: object
  12766. serviceAccountRef:
  12767. description: |-
  12768. Optional service account field containing the name of a kubernetes ServiceAccount.
  12769. If the service account is specified, the service account secret token JWT will be used
  12770. for authenticating with Vault. If the service account selector is not supplied,
  12771. the secretRef will be used instead.
  12772. properties:
  12773. audiences:
  12774. description: |-
  12775. Audience specifies the `aud` claim for the service account token
  12776. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12777. then this audiences will be appended to the list
  12778. items:
  12779. type: string
  12780. type: array
  12781. name:
  12782. description: The name of the ServiceAccount resource being referred to.
  12783. maxLength: 253
  12784. minLength: 1
  12785. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12786. type: string
  12787. namespace:
  12788. description: |-
  12789. Namespace of the resource being referred to.
  12790. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12791. maxLength: 63
  12792. minLength: 1
  12793. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12794. type: string
  12795. required:
  12796. - name
  12797. type: object
  12798. required:
  12799. - mountPath
  12800. - role
  12801. type: object
  12802. ldap:
  12803. description: |-
  12804. Ldap authenticates with Vault by passing username/password pair using
  12805. the LDAP authentication method
  12806. properties:
  12807. path:
  12808. default: ldap
  12809. description: |-
  12810. Path where the LDAP authentication backend is mounted
  12811. in Vault, e.g: "ldap"
  12812. type: string
  12813. secretRef:
  12814. description: |-
  12815. SecretRef to a key in a Secret resource containing password for the LDAP
  12816. user used to authenticate with Vault using the LDAP authentication
  12817. method
  12818. properties:
  12819. key:
  12820. description: |-
  12821. A key in the referenced Secret.
  12822. Some instances of this field may be defaulted, in others it may be required.
  12823. maxLength: 253
  12824. minLength: 1
  12825. pattern: ^[-._a-zA-Z0-9]+$
  12826. type: string
  12827. name:
  12828. description: The name of the Secret resource being referred to.
  12829. maxLength: 253
  12830. minLength: 1
  12831. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12832. type: string
  12833. namespace:
  12834. description: |-
  12835. The namespace of the Secret resource being referred to.
  12836. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12837. maxLength: 63
  12838. minLength: 1
  12839. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12840. type: string
  12841. type: object
  12842. username:
  12843. description: |-
  12844. Username is an LDAP username used to authenticate using the LDAP Vault
  12845. authentication method
  12846. type: string
  12847. required:
  12848. - path
  12849. - username
  12850. type: object
  12851. namespace:
  12852. description: |-
  12853. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  12854. Namespaces is a set of features within Vault Enterprise that allows
  12855. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  12856. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  12857. This will default to Vault.Namespace field if set, or empty otherwise
  12858. type: string
  12859. tokenSecretRef:
  12860. description: TokenSecretRef authenticates with Vault by presenting a token.
  12861. properties:
  12862. key:
  12863. description: |-
  12864. A key in the referenced Secret.
  12865. Some instances of this field may be defaulted, in others it may be required.
  12866. maxLength: 253
  12867. minLength: 1
  12868. pattern: ^[-._a-zA-Z0-9]+$
  12869. type: string
  12870. name:
  12871. description: The name of the Secret resource being referred to.
  12872. maxLength: 253
  12873. minLength: 1
  12874. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12875. type: string
  12876. namespace:
  12877. description: |-
  12878. The namespace of the Secret resource being referred to.
  12879. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12880. maxLength: 63
  12881. minLength: 1
  12882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12883. type: string
  12884. type: object
  12885. userPass:
  12886. description: UserPass authenticates with Vault by passing username/password pair
  12887. properties:
  12888. path:
  12889. default: userpass
  12890. description: |-
  12891. Path where the UserPassword authentication backend is mounted
  12892. in Vault, e.g: "userpass"
  12893. type: string
  12894. secretRef:
  12895. description: |-
  12896. SecretRef to a key in a Secret resource containing password for the
  12897. user used to authenticate with Vault using the UserPass authentication
  12898. method
  12899. properties:
  12900. key:
  12901. description: |-
  12902. A key in the referenced Secret.
  12903. Some instances of this field may be defaulted, in others it may be required.
  12904. maxLength: 253
  12905. minLength: 1
  12906. pattern: ^[-._a-zA-Z0-9]+$
  12907. type: string
  12908. name:
  12909. description: The name of the Secret resource being referred to.
  12910. maxLength: 253
  12911. minLength: 1
  12912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12913. type: string
  12914. namespace:
  12915. description: |-
  12916. The namespace of the Secret resource being referred to.
  12917. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12918. maxLength: 63
  12919. minLength: 1
  12920. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12921. type: string
  12922. type: object
  12923. username:
  12924. description: |-
  12925. Username is a username used to authenticate using the UserPass Vault
  12926. authentication method
  12927. type: string
  12928. required:
  12929. - path
  12930. - username
  12931. type: object
  12932. type: object
  12933. caBundle:
  12934. description: |-
  12935. PEM encoded CA bundle used to validate Vault server certificate. Only used
  12936. if the Server URL is using HTTPS protocol. This parameter is ignored for
  12937. plain HTTP protocol connection. If not set the system root certificates
  12938. are used to validate the TLS connection.
  12939. format: byte
  12940. type: string
  12941. caProvider:
  12942. description: The provider for the CA bundle to use to validate Vault server certificate.
  12943. properties:
  12944. key:
  12945. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  12946. maxLength: 253
  12947. minLength: 1
  12948. pattern: ^[-._a-zA-Z0-9]+$
  12949. type: string
  12950. name:
  12951. description: The name of the object located at the provider type.
  12952. maxLength: 253
  12953. minLength: 1
  12954. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12955. type: string
  12956. namespace:
  12957. description: |-
  12958. The namespace the Provider type is in.
  12959. Can only be defined when used in a ClusterSecretStore.
  12960. maxLength: 63
  12961. minLength: 1
  12962. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12963. type: string
  12964. type:
  12965. description: The type of provider to use such as "Secret", or "ConfigMap".
  12966. enum:
  12967. - Secret
  12968. - ConfigMap
  12969. type: string
  12970. required:
  12971. - name
  12972. - type
  12973. type: object
  12974. forwardInconsistent:
  12975. description: |-
  12976. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  12977. leader instead of simply retrying within a loop. This can increase performance if
  12978. the option is enabled serverside.
  12979. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  12980. type: boolean
  12981. headers:
  12982. additionalProperties:
  12983. type: string
  12984. description: Headers to be added in Vault request
  12985. type: object
  12986. namespace:
  12987. description: |-
  12988. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  12989. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  12990. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  12991. type: string
  12992. path:
  12993. description: |-
  12994. Path is the mount path of the Vault KV backend endpoint, e.g:
  12995. "secret". The v2 KV secret engine version specific "/data" path suffix
  12996. for fetching secrets from Vault is optional and will be appended
  12997. if not present in specified path.
  12998. type: string
  12999. readYourWrites:
  13000. description: |-
  13001. ReadYourWrites ensures isolated read-after-write semantics by
  13002. providing discovered cluster replication states in each request.
  13003. More information about eventual consistency in Vault can be found here
  13004. https://www.vaultproject.io/docs/enterprise/consistency
  13005. type: boolean
  13006. server:
  13007. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  13008. type: string
  13009. tls:
  13010. description: |-
  13011. The configuration used for client side related TLS communication, when the Vault server
  13012. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  13013. This parameter is ignored for plain HTTP protocol connection.
  13014. It's worth noting this configuration is different from the "TLS certificates auth method",
  13015. which is available under the `auth.cert` section.
  13016. properties:
  13017. certSecretRef:
  13018. description: |-
  13019. CertSecretRef is a certificate added to the transport layer
  13020. when communicating with the Vault server.
  13021. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  13022. properties:
  13023. key:
  13024. description: |-
  13025. A key in the referenced Secret.
  13026. Some instances of this field may be defaulted, in others it may be required.
  13027. maxLength: 253
  13028. minLength: 1
  13029. pattern: ^[-._a-zA-Z0-9]+$
  13030. type: string
  13031. name:
  13032. description: The name of the Secret resource being referred to.
  13033. maxLength: 253
  13034. minLength: 1
  13035. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13036. type: string
  13037. namespace:
  13038. description: |-
  13039. The namespace of the Secret resource being referred to.
  13040. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13041. maxLength: 63
  13042. minLength: 1
  13043. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13044. type: string
  13045. type: object
  13046. keySecretRef:
  13047. description: |-
  13048. KeySecretRef to a key in a Secret resource containing client private key
  13049. added to the transport layer when communicating with the Vault server.
  13050. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  13051. properties:
  13052. key:
  13053. description: |-
  13054. A key in the referenced Secret.
  13055. Some instances of this field may be defaulted, in others it may be required.
  13056. maxLength: 253
  13057. minLength: 1
  13058. pattern: ^[-._a-zA-Z0-9]+$
  13059. type: string
  13060. name:
  13061. description: The name of the Secret resource being referred to.
  13062. maxLength: 253
  13063. minLength: 1
  13064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13065. type: string
  13066. namespace:
  13067. description: |-
  13068. The namespace of the Secret resource being referred to.
  13069. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13070. maxLength: 63
  13071. minLength: 1
  13072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13073. type: string
  13074. type: object
  13075. type: object
  13076. version:
  13077. default: v2
  13078. description: |-
  13079. Version is the Vault KV secret engine version. This can be either "v1" or
  13080. "v2". Version defaults to "v2".
  13081. enum:
  13082. - v1
  13083. - v2
  13084. type: string
  13085. required:
  13086. - server
  13087. type: object
  13088. webhook:
  13089. description: Webhook configures this store to sync secrets using a generic templated webhook
  13090. properties:
  13091. auth:
  13092. description: Auth specifies a authorization protocol. Only one protocol may be set.
  13093. maxProperties: 1
  13094. minProperties: 1
  13095. properties:
  13096. ntlm:
  13097. description: NTLMProtocol configures the store to use NTLM for auth
  13098. properties:
  13099. passwordSecret:
  13100. description: |-
  13101. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13102. In some instances, `key` is a required field.
  13103. properties:
  13104. key:
  13105. description: |-
  13106. A key in the referenced Secret.
  13107. Some instances of this field may be defaulted, in others it may be required.
  13108. maxLength: 253
  13109. minLength: 1
  13110. pattern: ^[-._a-zA-Z0-9]+$
  13111. type: string
  13112. name:
  13113. description: The name of the Secret resource being referred to.
  13114. maxLength: 253
  13115. minLength: 1
  13116. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13117. type: string
  13118. namespace:
  13119. description: |-
  13120. The namespace of the Secret resource being referred to.
  13121. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13122. maxLength: 63
  13123. minLength: 1
  13124. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13125. type: string
  13126. type: object
  13127. usernameSecret:
  13128. description: |-
  13129. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13130. In some instances, `key` is a required field.
  13131. properties:
  13132. key:
  13133. description: |-
  13134. A key in the referenced Secret.
  13135. Some instances of this field may be defaulted, in others it may be required.
  13136. maxLength: 253
  13137. minLength: 1
  13138. pattern: ^[-._a-zA-Z0-9]+$
  13139. type: string
  13140. name:
  13141. description: The name of the Secret resource being referred to.
  13142. maxLength: 253
  13143. minLength: 1
  13144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13145. type: string
  13146. namespace:
  13147. description: |-
  13148. The namespace of the Secret resource being referred to.
  13149. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13150. maxLength: 63
  13151. minLength: 1
  13152. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13153. type: string
  13154. type: object
  13155. required:
  13156. - passwordSecret
  13157. - usernameSecret
  13158. type: object
  13159. type: object
  13160. body:
  13161. description: Body
  13162. type: string
  13163. caBundle:
  13164. description: |-
  13165. PEM encoded CA bundle used to validate webhook server certificate. Only used
  13166. if the Server URL is using HTTPS protocol. This parameter is ignored for
  13167. plain HTTP protocol connection. If not set the system root certificates
  13168. are used to validate the TLS connection.
  13169. format: byte
  13170. type: string
  13171. caProvider:
  13172. description: The provider for the CA bundle to use to validate webhook server certificate.
  13173. properties:
  13174. key:
  13175. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  13176. maxLength: 253
  13177. minLength: 1
  13178. pattern: ^[-._a-zA-Z0-9]+$
  13179. type: string
  13180. name:
  13181. description: The name of the object located at the provider type.
  13182. maxLength: 253
  13183. minLength: 1
  13184. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13185. type: string
  13186. namespace:
  13187. description: The namespace the Provider type is in.
  13188. maxLength: 63
  13189. minLength: 1
  13190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13191. type: string
  13192. type:
  13193. description: The type of provider to use such as "Secret", or "ConfigMap".
  13194. enum:
  13195. - Secret
  13196. - ConfigMap
  13197. type: string
  13198. required:
  13199. - name
  13200. - type
  13201. type: object
  13202. headers:
  13203. additionalProperties:
  13204. type: string
  13205. description: Headers
  13206. type: object
  13207. method:
  13208. description: Webhook Method
  13209. type: string
  13210. result:
  13211. description: Result formatting
  13212. properties:
  13213. jsonPath:
  13214. description: Json path of return value
  13215. type: string
  13216. type: object
  13217. secrets:
  13218. description: |-
  13219. Secrets to fill in templates
  13220. These secrets will be passed to the templating function as key value pairs under the given name
  13221. items:
  13222. description: WebhookSecret defines a secret to be used in webhook templates.
  13223. properties:
  13224. name:
  13225. description: Name of this secret in templates
  13226. type: string
  13227. secretRef:
  13228. description: Secret ref to fill in credentials
  13229. properties:
  13230. key:
  13231. description: |-
  13232. A key in the referenced Secret.
  13233. Some instances of this field may be defaulted, in others it may be required.
  13234. maxLength: 253
  13235. minLength: 1
  13236. pattern: ^[-._a-zA-Z0-9]+$
  13237. type: string
  13238. name:
  13239. description: The name of the Secret resource being referred to.
  13240. maxLength: 253
  13241. minLength: 1
  13242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13243. type: string
  13244. namespace:
  13245. description: |-
  13246. The namespace of the Secret resource being referred to.
  13247. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13248. maxLength: 63
  13249. minLength: 1
  13250. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13251. type: string
  13252. type: object
  13253. required:
  13254. - name
  13255. - secretRef
  13256. type: object
  13257. type: array
  13258. timeout:
  13259. description: Timeout
  13260. type: string
  13261. url:
  13262. description: Webhook url to call
  13263. type: string
  13264. required:
  13265. - result
  13266. - url
  13267. type: object
  13268. yandexcertificatemanager:
  13269. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  13270. properties:
  13271. apiEndpoint:
  13272. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13273. type: string
  13274. auth:
  13275. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  13276. properties:
  13277. authorizedKeySecretRef:
  13278. description: The authorized key used for authentication
  13279. properties:
  13280. key:
  13281. description: |-
  13282. A key in the referenced Secret.
  13283. Some instances of this field may be defaulted, in others it may be required.
  13284. maxLength: 253
  13285. minLength: 1
  13286. pattern: ^[-._a-zA-Z0-9]+$
  13287. type: string
  13288. name:
  13289. description: The name of the Secret resource being referred to.
  13290. maxLength: 253
  13291. minLength: 1
  13292. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13293. type: string
  13294. namespace:
  13295. description: |-
  13296. The namespace of the Secret resource being referred to.
  13297. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13298. maxLength: 63
  13299. minLength: 1
  13300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13301. type: string
  13302. type: object
  13303. type: object
  13304. caProvider:
  13305. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13306. properties:
  13307. certSecretRef:
  13308. description: |-
  13309. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13310. In some instances, `key` is a required field.
  13311. properties:
  13312. key:
  13313. description: |-
  13314. A key in the referenced Secret.
  13315. Some instances of this field may be defaulted, in others it may be required.
  13316. maxLength: 253
  13317. minLength: 1
  13318. pattern: ^[-._a-zA-Z0-9]+$
  13319. type: string
  13320. name:
  13321. description: The name of the Secret resource being referred to.
  13322. maxLength: 253
  13323. minLength: 1
  13324. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13325. type: string
  13326. namespace:
  13327. description: |-
  13328. The namespace of the Secret resource being referred to.
  13329. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13330. maxLength: 63
  13331. minLength: 1
  13332. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13333. type: string
  13334. type: object
  13335. type: object
  13336. required:
  13337. - auth
  13338. type: object
  13339. yandexlockbox:
  13340. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  13341. properties:
  13342. apiEndpoint:
  13343. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13344. type: string
  13345. auth:
  13346. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  13347. properties:
  13348. authorizedKeySecretRef:
  13349. description: The authorized key used for authentication
  13350. properties:
  13351. key:
  13352. description: |-
  13353. A key in the referenced Secret.
  13354. Some instances of this field may be defaulted, in others it may be required.
  13355. maxLength: 253
  13356. minLength: 1
  13357. pattern: ^[-._a-zA-Z0-9]+$
  13358. type: string
  13359. name:
  13360. description: The name of the Secret resource being referred to.
  13361. maxLength: 253
  13362. minLength: 1
  13363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13364. type: string
  13365. namespace:
  13366. description: |-
  13367. The namespace of the Secret resource being referred to.
  13368. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13369. maxLength: 63
  13370. minLength: 1
  13371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13372. type: string
  13373. type: object
  13374. type: object
  13375. caProvider:
  13376. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13377. properties:
  13378. certSecretRef:
  13379. description: |-
  13380. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13381. In some instances, `key` is a required field.
  13382. properties:
  13383. key:
  13384. description: |-
  13385. A key in the referenced Secret.
  13386. Some instances of this field may be defaulted, in others it may be required.
  13387. maxLength: 253
  13388. minLength: 1
  13389. pattern: ^[-._a-zA-Z0-9]+$
  13390. type: string
  13391. name:
  13392. description: The name of the Secret resource being referred to.
  13393. maxLength: 253
  13394. minLength: 1
  13395. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13396. type: string
  13397. namespace:
  13398. description: |-
  13399. The namespace of the Secret resource being referred to.
  13400. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13401. maxLength: 63
  13402. minLength: 1
  13403. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13404. type: string
  13405. type: object
  13406. type: object
  13407. required:
  13408. - auth
  13409. type: object
  13410. type: object
  13411. refreshInterval:
  13412. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  13413. type: integer
  13414. retrySettings:
  13415. description: Used to configure HTTP retries on failures.
  13416. properties:
  13417. maxRetries:
  13418. description: MaxRetries is the maximum number of retry attempts.
  13419. format: int32
  13420. type: integer
  13421. retryInterval:
  13422. description: RetryInterval is the interval between retry attempts.
  13423. type: string
  13424. type: object
  13425. required:
  13426. - provider
  13427. type: object
  13428. status:
  13429. description: SecretStoreStatus defines the observed state of the SecretStore.
  13430. properties:
  13431. capabilities:
  13432. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  13433. type: string
  13434. conditions:
  13435. items:
  13436. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  13437. properties:
  13438. lastTransitionTime:
  13439. format: date-time
  13440. type: string
  13441. message:
  13442. type: string
  13443. reason:
  13444. type: string
  13445. status:
  13446. type: string
  13447. type:
  13448. description: SecretStoreConditionType represents the condition type of the SecretStore.
  13449. type: string
  13450. required:
  13451. - status
  13452. - type
  13453. type: object
  13454. type: array
  13455. type: object
  13456. type: object
  13457. served: false
  13458. storage: false
  13459. subresources:
  13460. status: {}
  13461. ---
  13462. apiVersion: apiextensions.k8s.io/v1
  13463. kind: CustomResourceDefinition
  13464. metadata:
  13465. annotations:
  13466. controller-gen.kubebuilder.io/version: v0.19.0
  13467. labels:
  13468. external-secrets.io/component: controller
  13469. name: externalsecrets.external-secrets.io
  13470. spec:
  13471. group: external-secrets.io
  13472. names:
  13473. categories:
  13474. - external-secrets
  13475. kind: ExternalSecret
  13476. listKind: ExternalSecretList
  13477. plural: externalsecrets
  13478. shortNames:
  13479. - es
  13480. singular: externalsecret
  13481. scope: Namespaced
  13482. versions:
  13483. - additionalPrinterColumns:
  13484. - jsonPath: .spec.secretStoreRef.kind
  13485. name: StoreType
  13486. type: string
  13487. - jsonPath: .spec.secretStoreRef.name
  13488. name: Store
  13489. type: string
  13490. - jsonPath: .spec.refreshInterval
  13491. name: Refresh Interval
  13492. type: string
  13493. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  13494. name: Status
  13495. type: string
  13496. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  13497. name: Ready
  13498. type: string
  13499. - jsonPath: .status.refreshTime
  13500. name: Last Sync
  13501. type: date
  13502. name: v1
  13503. schema:
  13504. openAPIV3Schema:
  13505. description: |-
  13506. ExternalSecret is the Schema for the external-secrets API.
  13507. It defines how to fetch data from external APIs and make it available as Kubernetes Secrets.
  13508. properties:
  13509. apiVersion:
  13510. description: |-
  13511. APIVersion defines the versioned schema of this representation of an object.
  13512. Servers should convert recognized schemas to the latest internal value, and
  13513. may reject unrecognized values.
  13514. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  13515. type: string
  13516. kind:
  13517. description: |-
  13518. Kind is a string value representing the REST resource this object represents.
  13519. Servers may infer this from the endpoint the client submits requests to.
  13520. Cannot be updated.
  13521. In CamelCase.
  13522. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  13523. type: string
  13524. metadata:
  13525. type: object
  13526. spec:
  13527. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  13528. properties:
  13529. data:
  13530. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  13531. items:
  13532. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  13533. properties:
  13534. remoteRef:
  13535. description: |-
  13536. RemoteRef points to the remote secret and defines
  13537. which secret (version/property/..) to fetch.
  13538. properties:
  13539. conversionStrategy:
  13540. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  13541. enum:
  13542. - Default
  13543. - Unicode
  13544. type: string
  13545. decodingStrategy:
  13546. description: Used to define a decoding Strategy. Defaults to None when omitted.
  13547. enum:
  13548. - Auto
  13549. - Base64
  13550. - Base64URL
  13551. - None
  13552. type: string
  13553. key:
  13554. description: Key is the key used in the Provider, mandatory
  13555. type: string
  13556. metadataPolicy:
  13557. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13558. enum:
  13559. - None
  13560. - Fetch
  13561. type: string
  13562. nullBytePolicy:
  13563. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13564. enum:
  13565. - Ignore
  13566. - Fail
  13567. type: string
  13568. property:
  13569. description: Used to select a specific property of the Provider value (if a map), if supported
  13570. type: string
  13571. version:
  13572. description: Used to select a specific version of the Provider value, if supported
  13573. type: string
  13574. required:
  13575. - key
  13576. type: object
  13577. secretKey:
  13578. description: The key in the Kubernetes Secret to store the value.
  13579. maxLength: 253
  13580. minLength: 1
  13581. pattern: ^[-._a-zA-Z0-9]+$
  13582. type: string
  13583. sourceRef:
  13584. description: |-
  13585. SourceRef allows you to override the source
  13586. from which the value will be pulled.
  13587. maxProperties: 1
  13588. minProperties: 1
  13589. properties:
  13590. generatorRef:
  13591. description: |-
  13592. GeneratorRef points to a generator custom resource.
  13593. Deprecated: The generatorRef is not implemented in .data[].
  13594. this will be removed with v1.
  13595. properties:
  13596. apiVersion:
  13597. default: generators.external-secrets.io/v1alpha1
  13598. description: Specify the apiVersion of the generator resource
  13599. type: string
  13600. kind:
  13601. description: Specify the Kind of the generator resource
  13602. enum:
  13603. - ACRAccessToken
  13604. - BeyondtrustWorkloadCredentialsDynamicSecret
  13605. - ClusterGenerator
  13606. - CloudsmithAccessToken
  13607. - ECRAuthorizationToken
  13608. - Fake
  13609. - GCRAccessToken
  13610. - GithubAccessToken
  13611. - GitlabDeployToken
  13612. - QuayAccessToken
  13613. - Password
  13614. - SSHKey
  13615. - STSSessionToken
  13616. - UUID
  13617. - VaultDynamicSecret
  13618. - Webhook
  13619. - Grafana
  13620. - MFA
  13621. type: string
  13622. name:
  13623. description: Specify the name of the generator resource
  13624. maxLength: 253
  13625. minLength: 1
  13626. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13627. type: string
  13628. required:
  13629. - kind
  13630. - name
  13631. type: object
  13632. storeRef:
  13633. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13634. properties:
  13635. kind:
  13636. description: |-
  13637. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13638. Defaults to `SecretStore`
  13639. enum:
  13640. - SecretStore
  13641. - ClusterSecretStore
  13642. type: string
  13643. name:
  13644. description: Name of the SecretStore resource
  13645. maxLength: 253
  13646. minLength: 1
  13647. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13648. type: string
  13649. type: object
  13650. type: object
  13651. required:
  13652. - remoteRef
  13653. - secretKey
  13654. type: object
  13655. type: array
  13656. dataFrom:
  13657. description: |-
  13658. DataFrom is used to fetch all properties from a specific Provider data
  13659. If multiple entries are specified, the Secret keys are merged in the specified order
  13660. items:
  13661. description: |-
  13662. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  13663. when using DataFrom to fetch multiple values from a Provider.
  13664. properties:
  13665. extract:
  13666. description: |-
  13667. Used to extract multiple key/value pairs from one secret
  13668. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13669. properties:
  13670. conversionStrategy:
  13671. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  13672. enum:
  13673. - Default
  13674. - Unicode
  13675. type: string
  13676. decodingStrategy:
  13677. description: Used to define a decoding Strategy. Defaults to None when omitted.
  13678. enum:
  13679. - Auto
  13680. - Base64
  13681. - Base64URL
  13682. - None
  13683. type: string
  13684. key:
  13685. description: Key is the key used in the Provider, mandatory
  13686. type: string
  13687. metadataPolicy:
  13688. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13689. enum:
  13690. - None
  13691. - Fetch
  13692. type: string
  13693. nullBytePolicy:
  13694. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13695. enum:
  13696. - Ignore
  13697. - Fail
  13698. type: string
  13699. property:
  13700. description: Used to select a specific property of the Provider value (if a map), if supported
  13701. type: string
  13702. version:
  13703. description: Used to select a specific version of the Provider value, if supported
  13704. type: string
  13705. required:
  13706. - key
  13707. type: object
  13708. find:
  13709. description: |-
  13710. Used to find secrets based on tags or regular expressions
  13711. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13712. properties:
  13713. conversionStrategy:
  13714. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  13715. enum:
  13716. - Default
  13717. - Unicode
  13718. type: string
  13719. decodingStrategy:
  13720. description: Used to define a decoding Strategy. Defaults to None when omitted.
  13721. enum:
  13722. - Auto
  13723. - Base64
  13724. - Base64URL
  13725. - None
  13726. type: string
  13727. name:
  13728. description: Finds secrets based on the name.
  13729. properties:
  13730. regexp:
  13731. description: Finds secrets base
  13732. type: string
  13733. type: object
  13734. nullBytePolicy:
  13735. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  13736. enum:
  13737. - Ignore
  13738. - Fail
  13739. type: string
  13740. path:
  13741. description: A root path to start the find operations.
  13742. type: string
  13743. tags:
  13744. additionalProperties:
  13745. type: string
  13746. description: Find secrets based on tags.
  13747. type: object
  13748. type: object
  13749. rewrite:
  13750. description: |-
  13751. Used to rewrite secret Keys after getting them from the secret Provider
  13752. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  13753. items:
  13754. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  13755. maxProperties: 1
  13756. minProperties: 1
  13757. properties:
  13758. merge:
  13759. description: |-
  13760. Used to merge key/values in one single Secret
  13761. The resulting key will contain all values from the specified secrets
  13762. properties:
  13763. conflictPolicy:
  13764. default: Error
  13765. description: Used to define the policy to use in conflict resolution.
  13766. enum:
  13767. - Ignore
  13768. - Error
  13769. type: string
  13770. into:
  13771. default: ""
  13772. description: |-
  13773. Used to define the target key of the merge operation.
  13774. Required if strategy is JSON. Ignored otherwise.
  13775. type: string
  13776. priority:
  13777. description: Used to define key priority in conflict resolution.
  13778. items:
  13779. type: string
  13780. type: array
  13781. priorityPolicy:
  13782. default: Strict
  13783. description: Used to define the policy when a key in the priority list does not exist in the input.
  13784. enum:
  13785. - IgnoreNotFound
  13786. - Strict
  13787. type: string
  13788. strategy:
  13789. default: Extract
  13790. description: Used to define the strategy to use in the merge operation.
  13791. enum:
  13792. - Extract
  13793. - JSON
  13794. type: string
  13795. type: object
  13796. regexp:
  13797. description: |-
  13798. Used to rewrite with regular expressions.
  13799. The resulting key will be the output of a regexp.ReplaceAll operation.
  13800. properties:
  13801. source:
  13802. description: Used to define the regular expression of a re.Compiler.
  13803. type: string
  13804. target:
  13805. description: Used to define the target pattern of a ReplaceAll operation.
  13806. type: string
  13807. required:
  13808. - source
  13809. - target
  13810. type: object
  13811. transform:
  13812. description: |-
  13813. Used to apply string transformation on the secrets.
  13814. The resulting key will be the output of the template applied by the operation.
  13815. properties:
  13816. template:
  13817. description: |-
  13818. Used to define the template to apply on the secret name.
  13819. `.value ` will specify the secret name in the template.
  13820. type: string
  13821. required:
  13822. - template
  13823. type: object
  13824. type: object
  13825. type: array
  13826. sourceRef:
  13827. description: |-
  13828. SourceRef points to a store or generator
  13829. which contains secret values ready to use.
  13830. Use this in combination with Extract or Find pull values out of
  13831. a specific SecretStore.
  13832. When sourceRef points to a generator Extract or Find is not supported.
  13833. The generator returns a static map of values
  13834. maxProperties: 1
  13835. minProperties: 1
  13836. properties:
  13837. generatorRef:
  13838. description: GeneratorRef points to a generator custom resource.
  13839. properties:
  13840. apiVersion:
  13841. default: generators.external-secrets.io/v1alpha1
  13842. description: Specify the apiVersion of the generator resource
  13843. type: string
  13844. kind:
  13845. description: Specify the Kind of the generator resource
  13846. enum:
  13847. - ACRAccessToken
  13848. - BeyondtrustWorkloadCredentialsDynamicSecret
  13849. - ClusterGenerator
  13850. - CloudsmithAccessToken
  13851. - ECRAuthorizationToken
  13852. - Fake
  13853. - GCRAccessToken
  13854. - GithubAccessToken
  13855. - GitlabDeployToken
  13856. - QuayAccessToken
  13857. - Password
  13858. - SSHKey
  13859. - STSSessionToken
  13860. - UUID
  13861. - VaultDynamicSecret
  13862. - Webhook
  13863. - Grafana
  13864. - MFA
  13865. type: string
  13866. name:
  13867. description: Specify the name of the generator resource
  13868. maxLength: 253
  13869. minLength: 1
  13870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13871. type: string
  13872. required:
  13873. - kind
  13874. - name
  13875. type: object
  13876. storeRef:
  13877. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13878. properties:
  13879. kind:
  13880. description: |-
  13881. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13882. Defaults to `SecretStore`
  13883. enum:
  13884. - SecretStore
  13885. - ClusterSecretStore
  13886. type: string
  13887. name:
  13888. description: Name of the SecretStore resource
  13889. maxLength: 253
  13890. minLength: 1
  13891. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13892. type: string
  13893. type: object
  13894. type: object
  13895. type: object
  13896. type: array
  13897. refreshInterval:
  13898. default: 1h0m0s
  13899. description: |-
  13900. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  13901. specified as Golang Duration strings.
  13902. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  13903. Example values: "1h0m0s", "2h30m0s", "10m0s"
  13904. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  13905. type: string
  13906. refreshPolicy:
  13907. description: |-
  13908. RefreshPolicy determines how the ExternalSecret should be refreshed:
  13909. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  13910. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  13911. No periodic updates occur if refreshInterval is 0.
  13912. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  13913. enum:
  13914. - CreatedOnce
  13915. - Periodic
  13916. - OnChange
  13917. type: string
  13918. secretStoreRef:
  13919. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13920. properties:
  13921. kind:
  13922. description: |-
  13923. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13924. Defaults to `SecretStore`
  13925. enum:
  13926. - SecretStore
  13927. - ClusterSecretStore
  13928. type: string
  13929. name:
  13930. description: Name of the SecretStore resource
  13931. maxLength: 253
  13932. minLength: 1
  13933. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13934. type: string
  13935. type: object
  13936. syncWindows:
  13937. description: |-
  13938. SyncWindows optionally restricts when periodic refreshes may occur.
  13939. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  13940. properties:
  13941. kind:
  13942. description: |-
  13943. Kind applies to every window in the list.
  13944. "allow" -- syncs are permitted only while at least one window is active;
  13945. all other times are blocked.
  13946. "deny" -- syncs are blocked while any window is active;
  13947. all other times are permitted.
  13948. enum:
  13949. - allow
  13950. - deny
  13951. type: string
  13952. windows:
  13953. description: Windows is the list of schedule+duration pairs.
  13954. items:
  13955. description: |-
  13956. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  13957. within a SyncWindows block.
  13958. properties:
  13959. duration:
  13960. description: |-
  13961. Duration specifies how long the window stays open after each Schedule
  13962. firing. Example: "8h".
  13963. type: string
  13964. schedule:
  13965. description: |-
  13966. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  13967. named shorthand such as @daily or @every 1h. It marks the start time of
  13968. each window occurrence.
  13969. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  13970. minLength: 1
  13971. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  13972. type: string
  13973. required:
  13974. - duration
  13975. - schedule
  13976. type: object
  13977. minItems: 1
  13978. type: array
  13979. required:
  13980. - kind
  13981. - windows
  13982. type: object
  13983. target:
  13984. default:
  13985. creationPolicy: Owner
  13986. deletionPolicy: Retain
  13987. description: |-
  13988. ExternalSecretTarget defines the Kubernetes Secret to be created,
  13989. there can be only one target per ExternalSecret.
  13990. properties:
  13991. creationPolicy:
  13992. default: Owner
  13993. description: |-
  13994. CreationPolicy defines rules on how to create the resulting Secret.
  13995. Defaults to "Owner"
  13996. enum:
  13997. - Owner
  13998. - Orphan
  13999. - Merge
  14000. - None
  14001. - CreateOrMerge
  14002. type: string
  14003. deletionPolicy:
  14004. default: Retain
  14005. description: |-
  14006. DeletionPolicy defines rules on how to delete the resulting Secret.
  14007. Defaults to "Retain"
  14008. enum:
  14009. - Delete
  14010. - Merge
  14011. - Retain
  14012. type: string
  14013. immutable:
  14014. description: Immutable defines if the final secret will be immutable
  14015. type: boolean
  14016. manifest:
  14017. description: |-
  14018. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  14019. When specified, ExternalSecret will create the resource type defined here
  14020. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  14021. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  14022. properties:
  14023. apiVersion:
  14024. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  14025. minLength: 1
  14026. type: string
  14027. kind:
  14028. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  14029. minLength: 1
  14030. type: string
  14031. required:
  14032. - apiVersion
  14033. - kind
  14034. type: object
  14035. name:
  14036. description: |-
  14037. The name of the Secret resource to be managed.
  14038. Defaults to the .metadata.name of the ExternalSecret resource
  14039. maxLength: 253
  14040. minLength: 1
  14041. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14042. type: string
  14043. template:
  14044. description: Template defines a blueprint for the created Secret resource.
  14045. properties:
  14046. data:
  14047. additionalProperties:
  14048. type: string
  14049. type: object
  14050. engineVersion:
  14051. default: v2
  14052. description: |-
  14053. EngineVersion specifies the template engine version
  14054. that should be used to compile/execute the
  14055. template specified in .data and .templateFrom[].
  14056. enum:
  14057. - v2
  14058. type: string
  14059. mergePolicy:
  14060. default: Replace
  14061. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  14062. enum:
  14063. - Replace
  14064. - Merge
  14065. type: string
  14066. metadata:
  14067. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14068. properties:
  14069. annotations:
  14070. additionalProperties:
  14071. type: string
  14072. type: object
  14073. finalizers:
  14074. items:
  14075. type: string
  14076. type: array
  14077. labels:
  14078. additionalProperties:
  14079. type: string
  14080. type: object
  14081. type: object
  14082. templateFrom:
  14083. items:
  14084. description: |-
  14085. TemplateFrom specifies a source for templates.
  14086. Each item in the list can either reference a ConfigMap or a Secret resource.
  14087. properties:
  14088. configMap:
  14089. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14090. properties:
  14091. items:
  14092. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14093. items:
  14094. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14095. properties:
  14096. key:
  14097. description: A key in the ConfigMap/Secret
  14098. maxLength: 253
  14099. minLength: 1
  14100. pattern: ^[-._a-zA-Z0-9]+$
  14101. type: string
  14102. templateAs:
  14103. default: Values
  14104. description: TemplateScope specifies how the template keys should be interpreted.
  14105. enum:
  14106. - Values
  14107. - KeysAndValues
  14108. type: string
  14109. required:
  14110. - key
  14111. type: object
  14112. type: array
  14113. name:
  14114. description: The name of the ConfigMap/Secret resource
  14115. maxLength: 253
  14116. minLength: 1
  14117. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14118. type: string
  14119. required:
  14120. - items
  14121. - name
  14122. type: object
  14123. literal:
  14124. type: string
  14125. secret:
  14126. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14127. properties:
  14128. items:
  14129. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14130. items:
  14131. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14132. properties:
  14133. key:
  14134. description: A key in the ConfigMap/Secret
  14135. maxLength: 253
  14136. minLength: 1
  14137. pattern: ^[-._a-zA-Z0-9]+$
  14138. type: string
  14139. templateAs:
  14140. default: Values
  14141. description: TemplateScope specifies how the template keys should be interpreted.
  14142. enum:
  14143. - Values
  14144. - KeysAndValues
  14145. type: string
  14146. required:
  14147. - key
  14148. type: object
  14149. type: array
  14150. name:
  14151. description: The name of the ConfigMap/Secret resource
  14152. maxLength: 253
  14153. minLength: 1
  14154. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14155. type: string
  14156. required:
  14157. - items
  14158. - name
  14159. type: object
  14160. target:
  14161. default: Data
  14162. description: |-
  14163. Target specifies where to place the template result.
  14164. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  14165. any other value is rejected because it would allow writes to privileged Secret fields.
  14166. For custom resources (when spec.target.manifest is set), this supports
  14167. nested paths like "spec.database.config" or "data".
  14168. type: string
  14169. valuesDecodingStrategy:
  14170. description: |-
  14171. Used to define a decoding Strategy for the rendered template values.
  14172. Defaults to None when omitted.
  14173. enum:
  14174. - Auto
  14175. - Base64
  14176. - Base64URL
  14177. - None
  14178. type: string
  14179. type: object
  14180. type: array
  14181. type:
  14182. type: string
  14183. type: object
  14184. type: object
  14185. type: object
  14186. status:
  14187. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  14188. properties:
  14189. binding:
  14190. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  14191. properties:
  14192. name:
  14193. default: ""
  14194. description: |-
  14195. Name of the referent.
  14196. This field is effectively required, but due to backwards compatibility is
  14197. allowed to be empty. Instances of this type with an empty value here are
  14198. almost certainly wrong.
  14199. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  14200. type: string
  14201. type: object
  14202. x-kubernetes-map-type: atomic
  14203. conditions:
  14204. items:
  14205. description: ExternalSecretStatusCondition defines a status condition of an ExternalSecret resource.
  14206. properties:
  14207. lastTransitionTime:
  14208. format: date-time
  14209. type: string
  14210. message:
  14211. type: string
  14212. reason:
  14213. type: string
  14214. status:
  14215. type: string
  14216. type:
  14217. description: ExternalSecretConditionType defines a value type for ExternalSecret conditions.
  14218. enum:
  14219. - Ready
  14220. - Deleted
  14221. type: string
  14222. required:
  14223. - status
  14224. - type
  14225. type: object
  14226. type: array
  14227. refreshTime:
  14228. description: |-
  14229. refreshTime is the time and date the external secret was fetched and
  14230. the target secret updated
  14231. format: date-time
  14232. nullable: true
  14233. type: string
  14234. syncedResourceVersion:
  14235. description: SyncedResourceVersion keeps track of the last synced version
  14236. type: string
  14237. type: object
  14238. type: object
  14239. selectableFields:
  14240. - jsonPath: .spec.secretStoreRef.name
  14241. - jsonPath: .spec.secretStoreRef.kind
  14242. - jsonPath: .spec.target.name
  14243. - jsonPath: .spec.refreshInterval
  14244. served: true
  14245. storage: true
  14246. subresources:
  14247. status: {}
  14248. - additionalPrinterColumns:
  14249. - jsonPath: .spec.secretStoreRef.kind
  14250. name: StoreType
  14251. type: string
  14252. - jsonPath: .spec.secretStoreRef.name
  14253. name: Store
  14254. type: string
  14255. - jsonPath: .spec.refreshInterval
  14256. name: Refresh Interval
  14257. type: string
  14258. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  14259. name: Status
  14260. type: string
  14261. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  14262. name: Ready
  14263. type: string
  14264. - jsonPath: .status.refreshTime
  14265. name: Last Sync
  14266. type: date
  14267. deprecated: true
  14268. name: v1beta1
  14269. schema:
  14270. openAPIV3Schema:
  14271. description: ExternalSecret is the schema for the external-secrets API.
  14272. properties:
  14273. apiVersion:
  14274. description: |-
  14275. APIVersion defines the versioned schema of this representation of an object.
  14276. Servers should convert recognized schemas to the latest internal value, and
  14277. may reject unrecognized values.
  14278. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  14279. type: string
  14280. kind:
  14281. description: |-
  14282. Kind is a string value representing the REST resource this object represents.
  14283. Servers may infer this from the endpoint the client submits requests to.
  14284. Cannot be updated.
  14285. In CamelCase.
  14286. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  14287. type: string
  14288. metadata:
  14289. type: object
  14290. spec:
  14291. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  14292. properties:
  14293. data:
  14294. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  14295. items:
  14296. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  14297. properties:
  14298. remoteRef:
  14299. description: |-
  14300. RemoteRef points to the remote secret and defines
  14301. which secret (version/property/..) to fetch.
  14302. properties:
  14303. conversionStrategy:
  14304. default: Default
  14305. description: Used to define a conversion Strategy
  14306. enum:
  14307. - Default
  14308. - Unicode
  14309. type: string
  14310. decodingStrategy:
  14311. default: None
  14312. description: Used to define a decoding Strategy
  14313. enum:
  14314. - Auto
  14315. - Base64
  14316. - Base64URL
  14317. - None
  14318. type: string
  14319. key:
  14320. description: Key is the key used in the Provider, mandatory
  14321. type: string
  14322. metadataPolicy:
  14323. default: None
  14324. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14325. enum:
  14326. - None
  14327. - Fetch
  14328. type: string
  14329. property:
  14330. description: Used to select a specific property of the Provider value (if a map), if supported
  14331. type: string
  14332. version:
  14333. description: Used to select a specific version of the Provider value, if supported
  14334. type: string
  14335. required:
  14336. - key
  14337. type: object
  14338. secretKey:
  14339. description: The key in the Kubernetes Secret to store the value.
  14340. maxLength: 253
  14341. minLength: 1
  14342. pattern: ^[-._a-zA-Z0-9]+$
  14343. type: string
  14344. sourceRef:
  14345. description: |-
  14346. SourceRef allows you to override the source
  14347. from which the value will be pulled.
  14348. maxProperties: 1
  14349. minProperties: 1
  14350. properties:
  14351. generatorRef:
  14352. description: |-
  14353. GeneratorRef points to a generator custom resource.
  14354. Deprecated: The generatorRef is not implemented in .data[].
  14355. this will be removed with v1.
  14356. properties:
  14357. apiVersion:
  14358. default: generators.external-secrets.io/v1alpha1
  14359. description: Specify the apiVersion of the generator resource
  14360. type: string
  14361. kind:
  14362. description: Specify the Kind of the generator resource
  14363. enum:
  14364. - ACRAccessToken
  14365. - ClusterGenerator
  14366. - ECRAuthorizationToken
  14367. - Fake
  14368. - GCRAccessToken
  14369. - GithubAccessToken
  14370. - QuayAccessToken
  14371. - Password
  14372. - SSHKey
  14373. - STSSessionToken
  14374. - UUID
  14375. - VaultDynamicSecret
  14376. - Webhook
  14377. - Grafana
  14378. type: string
  14379. name:
  14380. description: Specify the name of the generator resource
  14381. maxLength: 253
  14382. minLength: 1
  14383. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14384. type: string
  14385. required:
  14386. - kind
  14387. - name
  14388. type: object
  14389. storeRef:
  14390. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14391. properties:
  14392. kind:
  14393. description: |-
  14394. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14395. Defaults to `SecretStore`
  14396. enum:
  14397. - SecretStore
  14398. - ClusterSecretStore
  14399. type: string
  14400. name:
  14401. description: Name of the SecretStore resource
  14402. maxLength: 253
  14403. minLength: 1
  14404. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14405. type: string
  14406. type: object
  14407. type: object
  14408. required:
  14409. - remoteRef
  14410. - secretKey
  14411. type: object
  14412. type: array
  14413. dataFrom:
  14414. description: |-
  14415. DataFrom is used to fetch all properties from a specific Provider data
  14416. If multiple entries are specified, the Secret keys are merged in the specified order
  14417. items:
  14418. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  14419. properties:
  14420. extract:
  14421. description: |-
  14422. Used to extract multiple key/value pairs from one secret
  14423. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14424. properties:
  14425. conversionStrategy:
  14426. default: Default
  14427. description: Used to define a conversion Strategy
  14428. enum:
  14429. - Default
  14430. - Unicode
  14431. type: string
  14432. decodingStrategy:
  14433. default: None
  14434. description: Used to define a decoding Strategy
  14435. enum:
  14436. - Auto
  14437. - Base64
  14438. - Base64URL
  14439. - None
  14440. type: string
  14441. key:
  14442. description: Key is the key used in the Provider, mandatory
  14443. type: string
  14444. metadataPolicy:
  14445. default: None
  14446. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14447. enum:
  14448. - None
  14449. - Fetch
  14450. type: string
  14451. property:
  14452. description: Used to select a specific property of the Provider value (if a map), if supported
  14453. type: string
  14454. version:
  14455. description: Used to select a specific version of the Provider value, if supported
  14456. type: string
  14457. required:
  14458. - key
  14459. type: object
  14460. find:
  14461. description: |-
  14462. Used to find secrets based on tags or regular expressions
  14463. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14464. properties:
  14465. conversionStrategy:
  14466. default: Default
  14467. description: Used to define a conversion Strategy
  14468. enum:
  14469. - Default
  14470. - Unicode
  14471. type: string
  14472. decodingStrategy:
  14473. default: None
  14474. description: Used to define a decoding Strategy
  14475. enum:
  14476. - Auto
  14477. - Base64
  14478. - Base64URL
  14479. - None
  14480. type: string
  14481. name:
  14482. description: Finds secrets based on the name.
  14483. properties:
  14484. regexp:
  14485. description: Finds secrets base
  14486. type: string
  14487. type: object
  14488. path:
  14489. description: A root path to start the find operations.
  14490. type: string
  14491. tags:
  14492. additionalProperties:
  14493. type: string
  14494. description: Find secrets based on tags.
  14495. type: object
  14496. type: object
  14497. rewrite:
  14498. description: |-
  14499. Used to rewrite secret Keys after getting them from the secret Provider
  14500. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  14501. items:
  14502. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  14503. maxProperties: 1
  14504. minProperties: 1
  14505. properties:
  14506. regexp:
  14507. description: |-
  14508. Used to rewrite with regular expressions.
  14509. The resulting key will be the output of a regexp.ReplaceAll operation.
  14510. properties:
  14511. source:
  14512. description: Used to define the regular expression of a re.Compiler.
  14513. type: string
  14514. target:
  14515. description: Used to define the target pattern of a ReplaceAll operation.
  14516. type: string
  14517. required:
  14518. - source
  14519. - target
  14520. type: object
  14521. transform:
  14522. description: |-
  14523. Used to apply string transformation on the secrets.
  14524. The resulting key will be the output of the template applied by the operation.
  14525. properties:
  14526. template:
  14527. description: |-
  14528. Used to define the template to apply on the secret name.
  14529. `.value ` will specify the secret name in the template.
  14530. type: string
  14531. required:
  14532. - template
  14533. type: object
  14534. type: object
  14535. type: array
  14536. sourceRef:
  14537. description: |-
  14538. SourceRef points to a store or generator
  14539. which contains secret values ready to use.
  14540. Use this in combination with Extract or Find pull values out of
  14541. a specific SecretStore.
  14542. When sourceRef points to a generator Extract or Find is not supported.
  14543. The generator returns a static map of values
  14544. maxProperties: 1
  14545. minProperties: 1
  14546. properties:
  14547. generatorRef:
  14548. description: GeneratorRef points to a generator custom resource.
  14549. properties:
  14550. apiVersion:
  14551. default: generators.external-secrets.io/v1alpha1
  14552. description: Specify the apiVersion of the generator resource
  14553. type: string
  14554. kind:
  14555. description: Specify the Kind of the generator resource
  14556. enum:
  14557. - ACRAccessToken
  14558. - ClusterGenerator
  14559. - ECRAuthorizationToken
  14560. - Fake
  14561. - GCRAccessToken
  14562. - GithubAccessToken
  14563. - QuayAccessToken
  14564. - Password
  14565. - SSHKey
  14566. - STSSessionToken
  14567. - UUID
  14568. - VaultDynamicSecret
  14569. - Webhook
  14570. - Grafana
  14571. type: string
  14572. name:
  14573. description: Specify the name of the generator resource
  14574. maxLength: 253
  14575. minLength: 1
  14576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14577. type: string
  14578. required:
  14579. - kind
  14580. - name
  14581. type: object
  14582. storeRef:
  14583. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14584. properties:
  14585. kind:
  14586. description: |-
  14587. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14588. Defaults to `SecretStore`
  14589. enum:
  14590. - SecretStore
  14591. - ClusterSecretStore
  14592. type: string
  14593. name:
  14594. description: Name of the SecretStore resource
  14595. maxLength: 253
  14596. minLength: 1
  14597. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14598. type: string
  14599. type: object
  14600. type: object
  14601. type: object
  14602. type: array
  14603. refreshInterval:
  14604. default: 1h0m0s
  14605. description: |-
  14606. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  14607. specified as Golang Duration strings.
  14608. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  14609. Example values: "1h0m0s", "2h30m0s", "10m0s"
  14610. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  14611. type: string
  14612. refreshPolicy:
  14613. description: |-
  14614. RefreshPolicy determines how the ExternalSecret should be refreshed:
  14615. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  14616. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  14617. No periodic updates occur if refreshInterval is 0.
  14618. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  14619. enum:
  14620. - CreatedOnce
  14621. - Periodic
  14622. - OnChange
  14623. type: string
  14624. secretStoreRef:
  14625. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14626. properties:
  14627. kind:
  14628. description: |-
  14629. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14630. Defaults to `SecretStore`
  14631. enum:
  14632. - SecretStore
  14633. - ClusterSecretStore
  14634. type: string
  14635. name:
  14636. description: Name of the SecretStore resource
  14637. maxLength: 253
  14638. minLength: 1
  14639. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14640. type: string
  14641. type: object
  14642. target:
  14643. default:
  14644. creationPolicy: Owner
  14645. deletionPolicy: Retain
  14646. description: |-
  14647. ExternalSecretTarget defines the Kubernetes Secret to be created
  14648. There can be only one target per ExternalSecret.
  14649. properties:
  14650. creationPolicy:
  14651. default: Owner
  14652. description: |-
  14653. CreationPolicy defines rules on how to create the resulting Secret.
  14654. Defaults to "Owner"
  14655. enum:
  14656. - Owner
  14657. - Orphan
  14658. - Merge
  14659. - None
  14660. type: string
  14661. deletionPolicy:
  14662. default: Retain
  14663. description: |-
  14664. DeletionPolicy defines rules on how to delete the resulting Secret.
  14665. Defaults to "Retain"
  14666. enum:
  14667. - Delete
  14668. - Merge
  14669. - Retain
  14670. type: string
  14671. immutable:
  14672. description: Immutable defines if the final secret will be immutable
  14673. type: boolean
  14674. name:
  14675. description: |-
  14676. The name of the Secret resource to be managed.
  14677. Defaults to the .metadata.name of the ExternalSecret resource
  14678. maxLength: 253
  14679. minLength: 1
  14680. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14681. type: string
  14682. template:
  14683. description: Template defines a blueprint for the created Secret resource.
  14684. properties:
  14685. data:
  14686. additionalProperties:
  14687. type: string
  14688. type: object
  14689. engineVersion:
  14690. default: v2
  14691. description: |-
  14692. EngineVersion specifies the template engine version
  14693. that should be used to compile/execute the
  14694. template specified in .data and .templateFrom[].
  14695. enum:
  14696. - v2
  14697. type: string
  14698. mergePolicy:
  14699. default: Replace
  14700. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  14701. enum:
  14702. - Replace
  14703. - Merge
  14704. type: string
  14705. metadata:
  14706. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14707. properties:
  14708. annotations:
  14709. additionalProperties:
  14710. type: string
  14711. type: object
  14712. labels:
  14713. additionalProperties:
  14714. type: string
  14715. type: object
  14716. type: object
  14717. templateFrom:
  14718. items:
  14719. description: TemplateFrom defines a source for template data.
  14720. properties:
  14721. configMap:
  14722. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14723. properties:
  14724. items:
  14725. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14726. items:
  14727. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14728. properties:
  14729. key:
  14730. description: A key in the ConfigMap/Secret
  14731. maxLength: 253
  14732. minLength: 1
  14733. pattern: ^[-._a-zA-Z0-9]+$
  14734. type: string
  14735. templateAs:
  14736. default: Values
  14737. description: TemplateScope defines the scope of the template when processing template data.
  14738. enum:
  14739. - Values
  14740. - KeysAndValues
  14741. type: string
  14742. required:
  14743. - key
  14744. type: object
  14745. type: array
  14746. name:
  14747. description: The name of the ConfigMap/Secret resource
  14748. maxLength: 253
  14749. minLength: 1
  14750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14751. type: string
  14752. required:
  14753. - items
  14754. - name
  14755. type: object
  14756. literal:
  14757. type: string
  14758. secret:
  14759. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14760. properties:
  14761. items:
  14762. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14763. items:
  14764. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14765. properties:
  14766. key:
  14767. description: A key in the ConfigMap/Secret
  14768. maxLength: 253
  14769. minLength: 1
  14770. pattern: ^[-._a-zA-Z0-9]+$
  14771. type: string
  14772. templateAs:
  14773. default: Values
  14774. description: TemplateScope defines the scope of the template when processing template data.
  14775. enum:
  14776. - Values
  14777. - KeysAndValues
  14778. type: string
  14779. required:
  14780. - key
  14781. type: object
  14782. type: array
  14783. name:
  14784. description: The name of the ConfigMap/Secret resource
  14785. maxLength: 253
  14786. minLength: 1
  14787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14788. type: string
  14789. required:
  14790. - items
  14791. - name
  14792. type: object
  14793. target:
  14794. default: Data
  14795. description: TemplateTarget defines the target field where the template result will be stored.
  14796. enum:
  14797. - Data
  14798. - Annotations
  14799. - Labels
  14800. type: string
  14801. type: object
  14802. type: array
  14803. type:
  14804. type: string
  14805. type: object
  14806. type: object
  14807. type: object
  14808. status:
  14809. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  14810. properties:
  14811. binding:
  14812. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  14813. properties:
  14814. name:
  14815. default: ""
  14816. description: |-
  14817. Name of the referent.
  14818. This field is effectively required, but due to backwards compatibility is
  14819. allowed to be empty. Instances of this type with an empty value here are
  14820. almost certainly wrong.
  14821. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  14822. type: string
  14823. type: object
  14824. x-kubernetes-map-type: atomic
  14825. conditions:
  14826. items:
  14827. description: ExternalSecretStatusCondition contains condition information for an ExternalSecret.
  14828. properties:
  14829. lastTransitionTime:
  14830. format: date-time
  14831. type: string
  14832. message:
  14833. type: string
  14834. reason:
  14835. type: string
  14836. status:
  14837. type: string
  14838. type:
  14839. description: ExternalSecretConditionType defines the condition type for an ExternalSecret.
  14840. type: string
  14841. required:
  14842. - status
  14843. - type
  14844. type: object
  14845. type: array
  14846. refreshTime:
  14847. description: |-
  14848. refreshTime is the time and date the external secret was fetched and
  14849. the target secret updated
  14850. format: date-time
  14851. nullable: true
  14852. type: string
  14853. syncedResourceVersion:
  14854. description: SyncedResourceVersion keeps track of the last synced version
  14855. type: string
  14856. type: object
  14857. type: object
  14858. served: false
  14859. storage: false
  14860. subresources:
  14861. status: {}
  14862. ---
  14863. apiVersion: apiextensions.k8s.io/v1
  14864. kind: CustomResourceDefinition
  14865. metadata:
  14866. annotations:
  14867. controller-gen.kubebuilder.io/version: v0.19.0
  14868. labels:
  14869. external-secrets.io/component: controller
  14870. name: pushsecrets.external-secrets.io
  14871. spec:
  14872. group: external-secrets.io
  14873. names:
  14874. categories:
  14875. - external-secrets
  14876. kind: PushSecret
  14877. listKind: PushSecretList
  14878. plural: pushsecrets
  14879. shortNames:
  14880. - ps
  14881. singular: pushsecret
  14882. scope: Namespaced
  14883. versions:
  14884. - additionalPrinterColumns:
  14885. - jsonPath: .metadata.creationTimestamp
  14886. name: AGE
  14887. type: date
  14888. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  14889. name: Status
  14890. type: string
  14891. - jsonPath: .status.refreshTime
  14892. name: Last Sync
  14893. type: date
  14894. name: v1alpha1
  14895. schema:
  14896. openAPIV3Schema:
  14897. description: PushSecret is the Schema for the PushSecrets API that enables pushing Kubernetes secrets to external secret providers.
  14898. properties:
  14899. apiVersion:
  14900. description: |-
  14901. APIVersion defines the versioned schema of this representation of an object.
  14902. Servers should convert recognized schemas to the latest internal value, and
  14903. may reject unrecognized values.
  14904. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  14905. type: string
  14906. kind:
  14907. description: |-
  14908. Kind is a string value representing the REST resource this object represents.
  14909. Servers may infer this from the endpoint the client submits requests to.
  14910. Cannot be updated.
  14911. In CamelCase.
  14912. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  14913. type: string
  14914. metadata:
  14915. type: object
  14916. spec:
  14917. description: PushSecretSpec configures the behavior of the PushSecret.
  14918. properties:
  14919. data:
  14920. description: Secret Data that should be pushed to providers
  14921. items:
  14922. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  14923. properties:
  14924. conversionStrategy:
  14925. default: None
  14926. description: Used to define a conversion Strategy for the secret keys
  14927. enum:
  14928. - None
  14929. - ReverseUnicode
  14930. type: string
  14931. match:
  14932. description: Match a given Secret Key to be pushed to the provider.
  14933. properties:
  14934. remoteRef:
  14935. description: Remote Refs to push to providers.
  14936. properties:
  14937. property:
  14938. description: Name of the property in the resulting secret
  14939. type: string
  14940. remoteKey:
  14941. description: Name of the resulting provider secret.
  14942. type: string
  14943. required:
  14944. - remoteKey
  14945. type: object
  14946. secretKey:
  14947. description: Secret Key to be pushed
  14948. type: string
  14949. required:
  14950. - remoteRef
  14951. type: object
  14952. metadata:
  14953. description: |-
  14954. Metadata is metadata attached to the secret.
  14955. The structure of metadata is provider specific, please look it up in the provider documentation.
  14956. x-kubernetes-preserve-unknown-fields: true
  14957. required:
  14958. - match
  14959. type: object
  14960. type: array
  14961. dataTo:
  14962. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  14963. items:
  14964. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  14965. properties:
  14966. conversionStrategy:
  14967. default: None
  14968. description: Used to define a conversion Strategy for the secret keys
  14969. enum:
  14970. - None
  14971. - ReverseUnicode
  14972. type: string
  14973. match:
  14974. description: |-
  14975. Match pattern for selecting keys from the source Secret.
  14976. If not specified, all keys are selected.
  14977. properties:
  14978. regexp:
  14979. description: |-
  14980. Regexp matches keys by regular expression.
  14981. If not specified, all keys are matched.
  14982. type: string
  14983. type: object
  14984. metadata:
  14985. description: |-
  14986. Metadata is metadata attached to the secret.
  14987. The structure of metadata is provider specific, please look it up in the provider documentation.
  14988. x-kubernetes-preserve-unknown-fields: true
  14989. remoteKey:
  14990. description: |-
  14991. RemoteKey is the name of the single provider secret that will receive ALL
  14992. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  14993. When set, per-key expansion is skipped and a single push is performed.
  14994. The provider's store prefix (if any) is still prepended to this value.
  14995. When not set, each matched key is pushed as its own individual provider secret.
  14996. type: string
  14997. rewrite:
  14998. description: |-
  14999. Rewrite operations to transform keys before pushing to the provider.
  15000. Operations are applied sequentially.
  15001. items:
  15002. description: PushSecretRewrite defines how to transform secret keys before pushing.
  15003. properties:
  15004. regexp:
  15005. description: Used to rewrite with regular expressions.
  15006. properties:
  15007. source:
  15008. description: Used to define the regular expression of a re.Compiler.
  15009. type: string
  15010. target:
  15011. description: Used to define the target pattern of a ReplaceAll operation.
  15012. type: string
  15013. required:
  15014. - source
  15015. - target
  15016. type: object
  15017. transform:
  15018. description: Used to apply string transformation on the secrets.
  15019. properties:
  15020. template:
  15021. description: |-
  15022. Used to define the template to apply on the secret name.
  15023. `.value ` will specify the secret name in the template.
  15024. type: string
  15025. required:
  15026. - template
  15027. type: object
  15028. type: object
  15029. x-kubernetes-validations:
  15030. - message: exactly one of regexp or transform must be set
  15031. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  15032. type: array
  15033. storeRef:
  15034. description: StoreRef specifies which SecretStore to push to. Required.
  15035. properties:
  15036. kind:
  15037. default: SecretStore
  15038. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  15039. enum:
  15040. - SecretStore
  15041. - ClusterSecretStore
  15042. type: string
  15043. labelSelector:
  15044. description: Optionally, sync to secret stores with label selector
  15045. properties:
  15046. matchExpressions:
  15047. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15048. items:
  15049. description: |-
  15050. A label selector requirement is a selector that contains values, a key, and an operator that
  15051. relates the key and values.
  15052. properties:
  15053. key:
  15054. description: key is the label key that the selector applies to.
  15055. type: string
  15056. operator:
  15057. description: |-
  15058. operator represents a key's relationship to a set of values.
  15059. Valid operators are In, NotIn, Exists and DoesNotExist.
  15060. type: string
  15061. values:
  15062. description: |-
  15063. values is an array of string values. If the operator is In or NotIn,
  15064. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15065. the values array must be empty. This array is replaced during a strategic
  15066. merge patch.
  15067. items:
  15068. type: string
  15069. type: array
  15070. x-kubernetes-list-type: atomic
  15071. required:
  15072. - key
  15073. - operator
  15074. type: object
  15075. type: array
  15076. x-kubernetes-list-type: atomic
  15077. matchLabels:
  15078. additionalProperties:
  15079. type: string
  15080. description: |-
  15081. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15082. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15083. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15084. type: object
  15085. type: object
  15086. x-kubernetes-map-type: atomic
  15087. name:
  15088. description: Optionally, sync to the SecretStore of the given name
  15089. maxLength: 253
  15090. minLength: 1
  15091. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15092. type: string
  15093. type: object
  15094. type: object
  15095. x-kubernetes-validations:
  15096. - message: storeRef must specify either name or labelSelector
  15097. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  15098. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  15099. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  15100. type: array
  15101. deletionPolicy:
  15102. default: None
  15103. description: Deletion Policy to handle Secrets in the provider.
  15104. enum:
  15105. - Delete
  15106. - None
  15107. type: string
  15108. refreshInterval:
  15109. default: 1h0m0s
  15110. description: The Interval to which External Secrets will try to push a secret definition
  15111. type: string
  15112. secretStoreRefs:
  15113. items:
  15114. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  15115. properties:
  15116. kind:
  15117. default: SecretStore
  15118. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  15119. enum:
  15120. - SecretStore
  15121. - ClusterSecretStore
  15122. type: string
  15123. labelSelector:
  15124. description: Optionally, sync to secret stores with label selector
  15125. properties:
  15126. matchExpressions:
  15127. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15128. items:
  15129. description: |-
  15130. A label selector requirement is a selector that contains values, a key, and an operator that
  15131. relates the key and values.
  15132. properties:
  15133. key:
  15134. description: key is the label key that the selector applies to.
  15135. type: string
  15136. operator:
  15137. description: |-
  15138. operator represents a key's relationship to a set of values.
  15139. Valid operators are In, NotIn, Exists and DoesNotExist.
  15140. type: string
  15141. values:
  15142. description: |-
  15143. values is an array of string values. If the operator is In or NotIn,
  15144. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15145. the values array must be empty. This array is replaced during a strategic
  15146. merge patch.
  15147. items:
  15148. type: string
  15149. type: array
  15150. x-kubernetes-list-type: atomic
  15151. required:
  15152. - key
  15153. - operator
  15154. type: object
  15155. type: array
  15156. x-kubernetes-list-type: atomic
  15157. matchLabels:
  15158. additionalProperties:
  15159. type: string
  15160. description: |-
  15161. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15162. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15163. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15164. type: object
  15165. type: object
  15166. x-kubernetes-map-type: atomic
  15167. name:
  15168. description: Optionally, sync to the SecretStore of the given name
  15169. maxLength: 253
  15170. minLength: 1
  15171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15172. type: string
  15173. type: object
  15174. type: array
  15175. selector:
  15176. description: The Secret Selector (k8s source) for the Push Secret
  15177. maxProperties: 1
  15178. minProperties: 1
  15179. properties:
  15180. generatorRef:
  15181. description: Point to a generator to create a Secret.
  15182. properties:
  15183. apiVersion:
  15184. default: generators.external-secrets.io/v1alpha1
  15185. description: Specify the apiVersion of the generator resource
  15186. type: string
  15187. kind:
  15188. description: Specify the Kind of the generator resource
  15189. enum:
  15190. - ACRAccessToken
  15191. - BeyondtrustWorkloadCredentialsDynamicSecret
  15192. - ClusterGenerator
  15193. - CloudsmithAccessToken
  15194. - ECRAuthorizationToken
  15195. - Fake
  15196. - GCRAccessToken
  15197. - GithubAccessToken
  15198. - GitlabDeployToken
  15199. - QuayAccessToken
  15200. - Password
  15201. - SSHKey
  15202. - STSSessionToken
  15203. - UUID
  15204. - VaultDynamicSecret
  15205. - Webhook
  15206. - Grafana
  15207. - MFA
  15208. type: string
  15209. name:
  15210. description: Specify the name of the generator resource
  15211. maxLength: 253
  15212. minLength: 1
  15213. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15214. type: string
  15215. required:
  15216. - kind
  15217. - name
  15218. type: object
  15219. secret:
  15220. description: Select a Secret to Push.
  15221. properties:
  15222. name:
  15223. description: |-
  15224. Name of the Secret.
  15225. The Secret must exist in the same namespace as the PushSecret manifest.
  15226. maxLength: 253
  15227. minLength: 1
  15228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15229. type: string
  15230. selector:
  15231. description: Selector chooses secrets using a labelSelector.
  15232. properties:
  15233. matchExpressions:
  15234. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15235. items:
  15236. description: |-
  15237. A label selector requirement is a selector that contains values, a key, and an operator that
  15238. relates the key and values.
  15239. properties:
  15240. key:
  15241. description: key is the label key that the selector applies to.
  15242. type: string
  15243. operator:
  15244. description: |-
  15245. operator represents a key's relationship to a set of values.
  15246. Valid operators are In, NotIn, Exists and DoesNotExist.
  15247. type: string
  15248. values:
  15249. description: |-
  15250. values is an array of string values. If the operator is In or NotIn,
  15251. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15252. the values array must be empty. This array is replaced during a strategic
  15253. merge patch.
  15254. items:
  15255. type: string
  15256. type: array
  15257. x-kubernetes-list-type: atomic
  15258. required:
  15259. - key
  15260. - operator
  15261. type: object
  15262. type: array
  15263. x-kubernetes-list-type: atomic
  15264. matchLabels:
  15265. additionalProperties:
  15266. type: string
  15267. description: |-
  15268. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15269. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15270. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15271. type: object
  15272. type: object
  15273. x-kubernetes-map-type: atomic
  15274. type: object
  15275. type: object
  15276. template:
  15277. description: Template defines a blueprint for the created Secret resource.
  15278. properties:
  15279. data:
  15280. additionalProperties:
  15281. type: string
  15282. type: object
  15283. engineVersion:
  15284. default: v2
  15285. description: |-
  15286. EngineVersion specifies the template engine version
  15287. that should be used to compile/execute the
  15288. template specified in .data and .templateFrom[].
  15289. enum:
  15290. - v2
  15291. type: string
  15292. mergePolicy:
  15293. default: Replace
  15294. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  15295. enum:
  15296. - Replace
  15297. - Merge
  15298. type: string
  15299. metadata:
  15300. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  15301. properties:
  15302. annotations:
  15303. additionalProperties:
  15304. type: string
  15305. type: object
  15306. finalizers:
  15307. items:
  15308. type: string
  15309. type: array
  15310. labels:
  15311. additionalProperties:
  15312. type: string
  15313. type: object
  15314. type: object
  15315. templateFrom:
  15316. items:
  15317. description: |-
  15318. TemplateFrom specifies a source for templates.
  15319. Each item in the list can either reference a ConfigMap or a Secret resource.
  15320. properties:
  15321. configMap:
  15322. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15323. properties:
  15324. items:
  15325. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15326. items:
  15327. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15328. properties:
  15329. key:
  15330. description: A key in the ConfigMap/Secret
  15331. maxLength: 253
  15332. minLength: 1
  15333. pattern: ^[-._a-zA-Z0-9]+$
  15334. type: string
  15335. templateAs:
  15336. default: Values
  15337. description: TemplateScope specifies how the template keys should be interpreted.
  15338. enum:
  15339. - Values
  15340. - KeysAndValues
  15341. type: string
  15342. required:
  15343. - key
  15344. type: object
  15345. type: array
  15346. name:
  15347. description: The name of the ConfigMap/Secret resource
  15348. maxLength: 253
  15349. minLength: 1
  15350. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15351. type: string
  15352. required:
  15353. - items
  15354. - name
  15355. type: object
  15356. literal:
  15357. type: string
  15358. secret:
  15359. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15360. properties:
  15361. items:
  15362. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15363. items:
  15364. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15365. properties:
  15366. key:
  15367. description: A key in the ConfigMap/Secret
  15368. maxLength: 253
  15369. minLength: 1
  15370. pattern: ^[-._a-zA-Z0-9]+$
  15371. type: string
  15372. templateAs:
  15373. default: Values
  15374. description: TemplateScope specifies how the template keys should be interpreted.
  15375. enum:
  15376. - Values
  15377. - KeysAndValues
  15378. type: string
  15379. required:
  15380. - key
  15381. type: object
  15382. type: array
  15383. name:
  15384. description: The name of the ConfigMap/Secret resource
  15385. maxLength: 253
  15386. minLength: 1
  15387. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15388. type: string
  15389. required:
  15390. - items
  15391. - name
  15392. type: object
  15393. target:
  15394. default: Data
  15395. description: |-
  15396. Target specifies where to place the template result.
  15397. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  15398. any other value is rejected because it would allow writes to privileged Secret fields.
  15399. For custom resources (when spec.target.manifest is set), this supports
  15400. nested paths like "spec.database.config" or "data".
  15401. type: string
  15402. valuesDecodingStrategy:
  15403. description: |-
  15404. Used to define a decoding Strategy for the rendered template values.
  15405. Defaults to None when omitted.
  15406. enum:
  15407. - Auto
  15408. - Base64
  15409. - Base64URL
  15410. - None
  15411. type: string
  15412. type: object
  15413. type: array
  15414. type:
  15415. type: string
  15416. type: object
  15417. updatePolicy:
  15418. default: Replace
  15419. description: UpdatePolicy to handle Secrets in the provider.
  15420. enum:
  15421. - Replace
  15422. - IfNotExists
  15423. type: string
  15424. required:
  15425. - secretStoreRefs
  15426. - selector
  15427. type: object
  15428. status:
  15429. description: PushSecretStatus indicates the history of the status of PushSecret.
  15430. properties:
  15431. conditions:
  15432. items:
  15433. description: PushSecretStatusCondition indicates the status of the PushSecret.
  15434. properties:
  15435. lastTransitionTime:
  15436. format: date-time
  15437. type: string
  15438. message:
  15439. type: string
  15440. reason:
  15441. type: string
  15442. status:
  15443. type: string
  15444. type:
  15445. description: PushSecretConditionType indicates the condition of the PushSecret.
  15446. type: string
  15447. required:
  15448. - status
  15449. - type
  15450. type: object
  15451. type: array
  15452. refreshTime:
  15453. description: |-
  15454. refreshTime is the time and date the external secret was fetched and
  15455. the target secret updated
  15456. format: date-time
  15457. nullable: true
  15458. type: string
  15459. syncedPushSecrets:
  15460. additionalProperties:
  15461. additionalProperties:
  15462. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  15463. properties:
  15464. conversionStrategy:
  15465. default: None
  15466. description: Used to define a conversion Strategy for the secret keys
  15467. enum:
  15468. - None
  15469. - ReverseUnicode
  15470. type: string
  15471. match:
  15472. description: Match a given Secret Key to be pushed to the provider.
  15473. properties:
  15474. remoteRef:
  15475. description: Remote Refs to push to providers.
  15476. properties:
  15477. property:
  15478. description: Name of the property in the resulting secret
  15479. type: string
  15480. remoteKey:
  15481. description: Name of the resulting provider secret.
  15482. type: string
  15483. required:
  15484. - remoteKey
  15485. type: object
  15486. secretKey:
  15487. description: Secret Key to be pushed
  15488. type: string
  15489. required:
  15490. - remoteRef
  15491. type: object
  15492. metadata:
  15493. description: |-
  15494. Metadata is metadata attached to the secret.
  15495. The structure of metadata is provider specific, please look it up in the provider documentation.
  15496. x-kubernetes-preserve-unknown-fields: true
  15497. required:
  15498. - match
  15499. type: object
  15500. type: object
  15501. description: |-
  15502. Synced PushSecrets, including secrets that already exist in provider.
  15503. Matches secret stores to PushSecretData that was stored to that secret store.
  15504. type: object
  15505. syncedResourceVersion:
  15506. description: SyncedResourceVersion keeps track of the last synced version.
  15507. type: string
  15508. type: object
  15509. type: object
  15510. served: true
  15511. storage: true
  15512. subresources:
  15513. status: {}
  15514. ---
  15515. apiVersion: apiextensions.k8s.io/v1
  15516. kind: CustomResourceDefinition
  15517. metadata:
  15518. annotations:
  15519. controller-gen.kubebuilder.io/version: v0.19.0
  15520. labels:
  15521. external-secrets.io/component: controller
  15522. name: secretstores.external-secrets.io
  15523. spec:
  15524. group: external-secrets.io
  15525. names:
  15526. categories:
  15527. - external-secrets
  15528. kind: SecretStore
  15529. listKind: SecretStoreList
  15530. plural: secretstores
  15531. shortNames:
  15532. - ss
  15533. singular: secretstore
  15534. scope: Namespaced
  15535. versions:
  15536. - additionalPrinterColumns:
  15537. - jsonPath: .metadata.creationTimestamp
  15538. name: AGE
  15539. type: date
  15540. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  15541. name: Status
  15542. type: string
  15543. - jsonPath: .status.capabilities
  15544. name: Capabilities
  15545. type: string
  15546. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  15547. name: Ready
  15548. type: string
  15549. name: v1
  15550. schema:
  15551. openAPIV3Schema:
  15552. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  15553. properties:
  15554. apiVersion:
  15555. description: |-
  15556. APIVersion defines the versioned schema of this representation of an object.
  15557. Servers should convert recognized schemas to the latest internal value, and
  15558. may reject unrecognized values.
  15559. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15560. type: string
  15561. kind:
  15562. description: |-
  15563. Kind is a string value representing the REST resource this object represents.
  15564. Servers may infer this from the endpoint the client submits requests to.
  15565. Cannot be updated.
  15566. In CamelCase.
  15567. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15568. type: string
  15569. metadata:
  15570. type: object
  15571. spec:
  15572. description: SecretStoreSpec defines the desired state of SecretStore.
  15573. properties:
  15574. conditions:
  15575. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  15576. items:
  15577. description: |-
  15578. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  15579. for a ClusterSecretStore instance.
  15580. properties:
  15581. namespaceRegexes:
  15582. description: Choose namespaces by using regex matching
  15583. items:
  15584. type: string
  15585. type: array
  15586. namespaceSelector:
  15587. description: Choose namespace using a labelSelector
  15588. properties:
  15589. matchExpressions:
  15590. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15591. items:
  15592. description: |-
  15593. A label selector requirement is a selector that contains values, a key, and an operator that
  15594. relates the key and values.
  15595. properties:
  15596. key:
  15597. description: key is the label key that the selector applies to.
  15598. type: string
  15599. operator:
  15600. description: |-
  15601. operator represents a key's relationship to a set of values.
  15602. Valid operators are In, NotIn, Exists and DoesNotExist.
  15603. type: string
  15604. values:
  15605. description: |-
  15606. values is an array of string values. If the operator is In or NotIn,
  15607. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15608. the values array must be empty. This array is replaced during a strategic
  15609. merge patch.
  15610. items:
  15611. type: string
  15612. type: array
  15613. x-kubernetes-list-type: atomic
  15614. required:
  15615. - key
  15616. - operator
  15617. type: object
  15618. type: array
  15619. x-kubernetes-list-type: atomic
  15620. matchLabels:
  15621. additionalProperties:
  15622. type: string
  15623. description: |-
  15624. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15625. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15626. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15627. type: object
  15628. type: object
  15629. x-kubernetes-map-type: atomic
  15630. namespaces:
  15631. description: Choose namespaces by name
  15632. items:
  15633. maxLength: 63
  15634. minLength: 1
  15635. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15636. type: string
  15637. type: array
  15638. type: object
  15639. type: array
  15640. controller:
  15641. description: |-
  15642. Used to select the correct ESO controller (think: ingress.ingressClassName)
  15643. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  15644. type: string
  15645. provider:
  15646. description: Used to configure the provider. Only one provider may be set
  15647. maxProperties: 1
  15648. minProperties: 1
  15649. properties:
  15650. akeyless:
  15651. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  15652. properties:
  15653. akeylessGWApiURL:
  15654. description: Akeyless GW API Url from which the secrets to be fetched from.
  15655. type: string
  15656. authSecretRef:
  15657. description: Auth configures how the operator authenticates with Akeyless.
  15658. properties:
  15659. kubernetesAuth:
  15660. description: |-
  15661. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  15662. token stored in the named Secret resource.
  15663. properties:
  15664. accessID:
  15665. description: the Akeyless Kubernetes auth-method access-id
  15666. type: string
  15667. k8sConfName:
  15668. description: Kubernetes-auth configuration name in Akeyless-Gateway
  15669. type: string
  15670. secretRef:
  15671. description: |-
  15672. Optional secret field containing a Kubernetes ServiceAccount JWT used
  15673. for authenticating with Akeyless. If a name is specified without a key,
  15674. `token` is the default. If one is not specified, the one bound to
  15675. the controller will be used.
  15676. properties:
  15677. key:
  15678. description: |-
  15679. A key in the referenced Secret.
  15680. Some instances of this field may be defaulted, in others it may be required.
  15681. maxLength: 253
  15682. minLength: 1
  15683. pattern: ^[-._a-zA-Z0-9]+$
  15684. type: string
  15685. name:
  15686. description: The name of the Secret resource being referred to.
  15687. maxLength: 253
  15688. minLength: 1
  15689. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15690. type: string
  15691. namespace:
  15692. description: |-
  15693. The namespace of the Secret resource being referred to.
  15694. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15695. maxLength: 63
  15696. minLength: 1
  15697. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15698. type: string
  15699. type: object
  15700. serviceAccountRef:
  15701. description: |-
  15702. Optional service account field containing the name of a kubernetes ServiceAccount.
  15703. If the service account is specified, the service account secret token JWT will be used
  15704. for authenticating with Akeyless. If the service account selector is not supplied,
  15705. the secretRef will be used instead.
  15706. properties:
  15707. audiences:
  15708. description: |-
  15709. Audience specifies the `aud` claim for the service account token
  15710. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15711. then this audiences will be appended to the list
  15712. items:
  15713. type: string
  15714. type: array
  15715. name:
  15716. description: The name of the ServiceAccount resource being referred to.
  15717. maxLength: 253
  15718. minLength: 1
  15719. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15720. type: string
  15721. namespace:
  15722. description: |-
  15723. Namespace of the resource being referred to.
  15724. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15725. maxLength: 63
  15726. minLength: 1
  15727. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15728. type: string
  15729. required:
  15730. - name
  15731. type: object
  15732. required:
  15733. - accessID
  15734. - k8sConfName
  15735. type: object
  15736. secretRef:
  15737. description: |-
  15738. Reference to a Secret that contains the details
  15739. to authenticate with Akeyless.
  15740. properties:
  15741. accessID:
  15742. description: The SecretAccessID is used for authentication
  15743. properties:
  15744. key:
  15745. description: |-
  15746. A key in the referenced Secret.
  15747. Some instances of this field may be defaulted, in others it may be required.
  15748. maxLength: 253
  15749. minLength: 1
  15750. pattern: ^[-._a-zA-Z0-9]+$
  15751. type: string
  15752. name:
  15753. description: The name of the Secret resource being referred to.
  15754. maxLength: 253
  15755. minLength: 1
  15756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15757. type: string
  15758. namespace:
  15759. description: |-
  15760. The namespace of the Secret resource being referred to.
  15761. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15762. maxLength: 63
  15763. minLength: 1
  15764. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15765. type: string
  15766. type: object
  15767. accessType:
  15768. description: |-
  15769. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15770. In some instances, `key` is a required field.
  15771. properties:
  15772. key:
  15773. description: |-
  15774. A key in the referenced Secret.
  15775. Some instances of this field may be defaulted, in others it may be required.
  15776. maxLength: 253
  15777. minLength: 1
  15778. pattern: ^[-._a-zA-Z0-9]+$
  15779. type: string
  15780. name:
  15781. description: The name of the Secret resource being referred to.
  15782. maxLength: 253
  15783. minLength: 1
  15784. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15785. type: string
  15786. namespace:
  15787. description: |-
  15788. The namespace of the Secret resource being referred to.
  15789. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15790. maxLength: 63
  15791. minLength: 1
  15792. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15793. type: string
  15794. type: object
  15795. accessTypeParam:
  15796. description: |-
  15797. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15798. In some instances, `key` is a required field.
  15799. properties:
  15800. key:
  15801. description: |-
  15802. A key in the referenced Secret.
  15803. Some instances of this field may be defaulted, in others it may be required.
  15804. maxLength: 253
  15805. minLength: 1
  15806. pattern: ^[-._a-zA-Z0-9]+$
  15807. type: string
  15808. name:
  15809. description: The name of the Secret resource being referred to.
  15810. maxLength: 253
  15811. minLength: 1
  15812. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15813. type: string
  15814. namespace:
  15815. description: |-
  15816. The namespace of the Secret resource being referred to.
  15817. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15818. maxLength: 63
  15819. minLength: 1
  15820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15821. type: string
  15822. type: object
  15823. type: object
  15824. serviceAccountRef:
  15825. description: |-
  15826. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  15827. authentication on AKS Workload Identity. The operator obtains a federated
  15828. identity token from this ServiceAccount via the TokenRequest API instead
  15829. of using the ESO controller pod identity. Ignored for other access types.
  15830. properties:
  15831. audiences:
  15832. description: |-
  15833. Audience specifies the `aud` claim for the service account token
  15834. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15835. then this audiences will be appended to the list
  15836. items:
  15837. type: string
  15838. type: array
  15839. name:
  15840. description: The name of the ServiceAccount resource being referred to.
  15841. maxLength: 253
  15842. minLength: 1
  15843. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15844. type: string
  15845. namespace:
  15846. description: |-
  15847. Namespace of the resource being referred to.
  15848. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15849. maxLength: 63
  15850. minLength: 1
  15851. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15852. type: string
  15853. required:
  15854. - name
  15855. type: object
  15856. type: object
  15857. caBundle:
  15858. description: |-
  15859. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  15860. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  15861. are used to validate the TLS connection.
  15862. format: byte
  15863. type: string
  15864. caProvider:
  15865. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  15866. properties:
  15867. key:
  15868. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  15869. maxLength: 253
  15870. minLength: 1
  15871. pattern: ^[-._a-zA-Z0-9]+$
  15872. type: string
  15873. name:
  15874. description: The name of the object located at the provider type.
  15875. maxLength: 253
  15876. minLength: 1
  15877. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15878. type: string
  15879. namespace:
  15880. description: |-
  15881. The namespace the Provider type is in.
  15882. Can only be defined when used in a ClusterSecretStore.
  15883. maxLength: 63
  15884. minLength: 1
  15885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15886. type: string
  15887. type:
  15888. description: The type of provider to use such as "Secret", or "ConfigMap".
  15889. enum:
  15890. - Secret
  15891. - ConfigMap
  15892. type: string
  15893. required:
  15894. - name
  15895. - type
  15896. type: object
  15897. ignoreCache:
  15898. description: |-
  15899. IgnoreCache bypasses the Gateway cache for secret reads when true.
  15900. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  15901. type: boolean
  15902. required:
  15903. - akeylessGWApiURL
  15904. - authSecretRef
  15905. type: object
  15906. aws:
  15907. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  15908. properties:
  15909. additionalRoles:
  15910. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  15911. items:
  15912. type: string
  15913. type: array
  15914. auth:
  15915. description: |-
  15916. Auth defines the information necessary to authenticate against AWS
  15917. if not set aws sdk will infer credentials from your environment
  15918. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  15919. properties:
  15920. jwt:
  15921. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  15922. properties:
  15923. serviceAccountRef:
  15924. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  15925. properties:
  15926. audiences:
  15927. description: |-
  15928. Audience specifies the `aud` claim for the service account token
  15929. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15930. then this audiences will be appended to the list
  15931. items:
  15932. type: string
  15933. type: array
  15934. name:
  15935. description: The name of the ServiceAccount resource being referred to.
  15936. maxLength: 253
  15937. minLength: 1
  15938. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15939. type: string
  15940. namespace:
  15941. description: |-
  15942. Namespace of the resource being referred to.
  15943. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15944. maxLength: 63
  15945. minLength: 1
  15946. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15947. type: string
  15948. required:
  15949. - name
  15950. type: object
  15951. type: object
  15952. secretRef:
  15953. description: |-
  15954. AWSAuthSecretRef holds secret references for AWS credentials
  15955. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  15956. properties:
  15957. accessKeyIDSecretRef:
  15958. description: The AccessKeyID is used for authentication
  15959. properties:
  15960. key:
  15961. description: |-
  15962. A key in the referenced Secret.
  15963. Some instances of this field may be defaulted, in others it may be required.
  15964. maxLength: 253
  15965. minLength: 1
  15966. pattern: ^[-._a-zA-Z0-9]+$
  15967. type: string
  15968. name:
  15969. description: The name of the Secret resource being referred to.
  15970. maxLength: 253
  15971. minLength: 1
  15972. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15973. type: string
  15974. namespace:
  15975. description: |-
  15976. The namespace of the Secret resource being referred to.
  15977. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15978. maxLength: 63
  15979. minLength: 1
  15980. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15981. type: string
  15982. type: object
  15983. secretAccessKeySecretRef:
  15984. description: The SecretAccessKey is used for authentication
  15985. properties:
  15986. key:
  15987. description: |-
  15988. A key in the referenced Secret.
  15989. Some instances of this field may be defaulted, in others it may be required.
  15990. maxLength: 253
  15991. minLength: 1
  15992. pattern: ^[-._a-zA-Z0-9]+$
  15993. type: string
  15994. name:
  15995. description: The name of the Secret resource being referred to.
  15996. maxLength: 253
  15997. minLength: 1
  15998. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15999. type: string
  16000. namespace:
  16001. description: |-
  16002. The namespace of the Secret resource being referred to.
  16003. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16004. maxLength: 63
  16005. minLength: 1
  16006. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16007. type: string
  16008. type: object
  16009. sessionTokenSecretRef:
  16010. description: |-
  16011. The SessionToken used for authentication
  16012. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  16013. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  16014. properties:
  16015. key:
  16016. description: |-
  16017. A key in the referenced Secret.
  16018. Some instances of this field may be defaulted, in others it may be required.
  16019. maxLength: 253
  16020. minLength: 1
  16021. pattern: ^[-._a-zA-Z0-9]+$
  16022. type: string
  16023. name:
  16024. description: The name of the Secret resource being referred to.
  16025. maxLength: 253
  16026. minLength: 1
  16027. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16028. type: string
  16029. namespace:
  16030. description: |-
  16031. The namespace of the Secret resource being referred to.
  16032. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16033. maxLength: 63
  16034. minLength: 1
  16035. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16036. type: string
  16037. type: object
  16038. type: object
  16039. type: object
  16040. customSessionTags:
  16041. additionalProperties:
  16042. type: string
  16043. description: |-
  16044. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  16045. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  16046. type: object
  16047. x-kubernetes-validations:
  16048. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  16049. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  16050. externalID:
  16051. description: AWS External ID set on assumed IAM roles
  16052. type: string
  16053. prefix:
  16054. description: Prefix adds a prefix to all retrieved values.
  16055. type: string
  16056. region:
  16057. description: AWS Region to be used for the provider
  16058. type: string
  16059. role:
  16060. description: Role is a Role ARN which the provider will assume
  16061. type: string
  16062. secretsManager:
  16063. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  16064. properties:
  16065. forceDeleteWithoutRecovery:
  16066. description: |-
  16067. Specifies whether to delete the secret without any recovery window. You
  16068. can't use both this parameter and RecoveryWindowInDays in the same call.
  16069. If you don't use either, then by default Secrets Manager uses a 30 day
  16070. recovery window.
  16071. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  16072. type: boolean
  16073. recoveryWindowInDays:
  16074. description: |-
  16075. The number of days from 7 to 30 that Secrets Manager waits before
  16076. permanently deleting the secret. You can't use both this parameter and
  16077. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  16078. then by default Secrets Manager uses a 30-day recovery window.
  16079. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  16080. format: int64
  16081. type: integer
  16082. type: object
  16083. service:
  16084. description: Service defines which service should be used to fetch the secrets
  16085. enum:
  16086. - SecretsManager
  16087. - ParameterStore
  16088. - CertificateManager
  16089. type: string
  16090. sessionTags:
  16091. description: AWS STS assume role session tags
  16092. items:
  16093. description: |-
  16094. Tag is a key-value pair that can be attached to an AWS resource.
  16095. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  16096. properties:
  16097. key:
  16098. type: string
  16099. value:
  16100. type: string
  16101. required:
  16102. - key
  16103. - value
  16104. type: object
  16105. type: array
  16106. sessionTagsPolicy:
  16107. default: None
  16108. description: |-
  16109. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  16110. None (default): no tags are added.
  16111. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  16112. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  16113. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  16114. enum:
  16115. - None
  16116. - Simple
  16117. - Custom
  16118. type: string
  16119. transitiveTagKeys:
  16120. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  16121. items:
  16122. type: string
  16123. type: array
  16124. required:
  16125. - region
  16126. - service
  16127. type: object
  16128. azurekv:
  16129. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  16130. properties:
  16131. authSecretRef:
  16132. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16133. properties:
  16134. clientCertificate:
  16135. description: The Azure ClientCertificate of the service principle used for authentication.
  16136. properties:
  16137. key:
  16138. description: |-
  16139. A key in the referenced Secret.
  16140. Some instances of this field may be defaulted, in others it may be required.
  16141. maxLength: 253
  16142. minLength: 1
  16143. pattern: ^[-._a-zA-Z0-9]+$
  16144. type: string
  16145. name:
  16146. description: The name of the Secret resource being referred to.
  16147. maxLength: 253
  16148. minLength: 1
  16149. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16150. type: string
  16151. namespace:
  16152. description: |-
  16153. The namespace of the Secret resource being referred to.
  16154. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16155. maxLength: 63
  16156. minLength: 1
  16157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16158. type: string
  16159. type: object
  16160. clientId:
  16161. description: The Azure clientId of the service principle or managed identity used for authentication.
  16162. properties:
  16163. key:
  16164. description: |-
  16165. A key in the referenced Secret.
  16166. Some instances of this field may be defaulted, in others it may be required.
  16167. maxLength: 253
  16168. minLength: 1
  16169. pattern: ^[-._a-zA-Z0-9]+$
  16170. type: string
  16171. name:
  16172. description: The name of the Secret resource being referred to.
  16173. maxLength: 253
  16174. minLength: 1
  16175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16176. type: string
  16177. namespace:
  16178. description: |-
  16179. The namespace of the Secret resource being referred to.
  16180. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16181. maxLength: 63
  16182. minLength: 1
  16183. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16184. type: string
  16185. type: object
  16186. clientSecret:
  16187. description: The Azure ClientSecret of the service principle used for authentication.
  16188. properties:
  16189. key:
  16190. description: |-
  16191. A key in the referenced Secret.
  16192. Some instances of this field may be defaulted, in others it may be required.
  16193. maxLength: 253
  16194. minLength: 1
  16195. pattern: ^[-._a-zA-Z0-9]+$
  16196. type: string
  16197. name:
  16198. description: The name of the Secret resource being referred to.
  16199. maxLength: 253
  16200. minLength: 1
  16201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16202. type: string
  16203. namespace:
  16204. description: |-
  16205. The namespace of the Secret resource being referred to.
  16206. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16207. maxLength: 63
  16208. minLength: 1
  16209. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16210. type: string
  16211. type: object
  16212. tenantId:
  16213. description: The Azure tenantId of the managed identity used for authentication.
  16214. properties:
  16215. key:
  16216. description: |-
  16217. A key in the referenced Secret.
  16218. Some instances of this field may be defaulted, in others it may be required.
  16219. maxLength: 253
  16220. minLength: 1
  16221. pattern: ^[-._a-zA-Z0-9]+$
  16222. type: string
  16223. name:
  16224. description: The name of the Secret resource being referred to.
  16225. maxLength: 253
  16226. minLength: 1
  16227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16228. type: string
  16229. namespace:
  16230. description: |-
  16231. The namespace of the Secret resource being referred to.
  16232. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16233. maxLength: 63
  16234. minLength: 1
  16235. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16236. type: string
  16237. type: object
  16238. type: object
  16239. authType:
  16240. default: ServicePrincipal
  16241. description: |-
  16242. Auth type defines how to authenticate to the keyvault service.
  16243. Valid values are:
  16244. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  16245. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  16246. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  16247. enum:
  16248. - ServicePrincipal
  16249. - ManagedIdentity
  16250. - WorkloadIdentity
  16251. type: string
  16252. customCloudConfig:
  16253. description: |-
  16254. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  16255. Required when EnvironmentType is AzureStackCloud.
  16256. Optional for other environment types - useful for Azure China when using Workload Identity
  16257. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  16258. standard China Cloud endpoint (login.chinacloudapi.cn).
  16259. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  16260. configuration is not supported with the legacy go-autorest SDK.
  16261. properties:
  16262. activeDirectoryEndpoint:
  16263. description: |-
  16264. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  16265. Required when using custom cloud configuration
  16266. type: string
  16267. keyVaultDNSSuffix:
  16268. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  16269. type: string
  16270. keyVaultEndpoint:
  16271. description: KeyVaultEndpoint is the Key Vault service endpoint
  16272. type: string
  16273. resourceManagerEndpoint:
  16274. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  16275. type: string
  16276. required:
  16277. - activeDirectoryEndpoint
  16278. type: object
  16279. environmentType:
  16280. default: PublicCloud
  16281. description: |-
  16282. EnvironmentType specifies the Azure cloud environment endpoints to use for
  16283. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  16284. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  16285. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  16286. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  16287. enum:
  16288. - PublicCloud
  16289. - USGovernmentCloud
  16290. - ChinaCloud
  16291. - GermanCloud
  16292. - AzureStackCloud
  16293. type: string
  16294. identityId:
  16295. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  16296. type: string
  16297. serviceAccountRef:
  16298. description: |-
  16299. ServiceAccountRef specified the service account
  16300. that should be used when authenticating with WorkloadIdentity.
  16301. properties:
  16302. audiences:
  16303. description: |-
  16304. Audience specifies the `aud` claim for the service account token
  16305. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  16306. then this audiences will be appended to the list
  16307. items:
  16308. type: string
  16309. type: array
  16310. name:
  16311. description: The name of the ServiceAccount resource being referred to.
  16312. maxLength: 253
  16313. minLength: 1
  16314. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16315. type: string
  16316. namespace:
  16317. description: |-
  16318. Namespace of the resource being referred to.
  16319. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16320. maxLength: 63
  16321. minLength: 1
  16322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16323. type: string
  16324. required:
  16325. - name
  16326. type: object
  16327. tenantId:
  16328. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16329. type: string
  16330. useAzureSDK:
  16331. default: false
  16332. description: |-
  16333. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  16334. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  16335. type: boolean
  16336. vaultUrl:
  16337. description: Vault Url from which the secrets to be fetched from.
  16338. type: string
  16339. required:
  16340. - vaultUrl
  16341. type: object
  16342. barbican:
  16343. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  16344. properties:
  16345. auth:
  16346. description: BarbicanAuth contains the authentication information for Barbican.
  16347. properties:
  16348. password:
  16349. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  16350. properties:
  16351. secretRef:
  16352. description: |-
  16353. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16354. In some instances, `key` is a required field.
  16355. properties:
  16356. key:
  16357. description: |-
  16358. A key in the referenced Secret.
  16359. Some instances of this field may be defaulted, in others it may be required.
  16360. maxLength: 253
  16361. minLength: 1
  16362. pattern: ^[-._a-zA-Z0-9]+$
  16363. type: string
  16364. name:
  16365. description: The name of the Secret resource being referred to.
  16366. maxLength: 253
  16367. minLength: 1
  16368. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16369. type: string
  16370. namespace:
  16371. description: |-
  16372. The namespace of the Secret resource being referred to.
  16373. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16374. maxLength: 63
  16375. minLength: 1
  16376. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16377. type: string
  16378. type: object
  16379. required:
  16380. - secretRef
  16381. type: object
  16382. username:
  16383. description: BarbicanProviderUsernameRef defines a reference to a secret containing username for the Barbican provider.
  16384. maxProperties: 1
  16385. minProperties: 1
  16386. properties:
  16387. secretRef:
  16388. description: |-
  16389. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16390. In some instances, `key` is a required field.
  16391. properties:
  16392. key:
  16393. description: |-
  16394. A key in the referenced Secret.
  16395. Some instances of this field may be defaulted, in others it may be required.
  16396. maxLength: 253
  16397. minLength: 1
  16398. pattern: ^[-._a-zA-Z0-9]+$
  16399. type: string
  16400. name:
  16401. description: The name of the Secret resource being referred to.
  16402. maxLength: 253
  16403. minLength: 1
  16404. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16405. type: string
  16406. namespace:
  16407. description: |-
  16408. The namespace of the Secret resource being referred to.
  16409. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16410. maxLength: 63
  16411. minLength: 1
  16412. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16413. type: string
  16414. type: object
  16415. value:
  16416. type: string
  16417. type: object
  16418. required:
  16419. - password
  16420. - username
  16421. type: object
  16422. authURL:
  16423. type: string
  16424. domainName:
  16425. type: string
  16426. region:
  16427. type: string
  16428. tenantName:
  16429. type: string
  16430. required:
  16431. - auth
  16432. type: object
  16433. beyondtrust:
  16434. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  16435. properties:
  16436. auth:
  16437. description: Auth configures how the operator authenticates with Beyondtrust.
  16438. properties:
  16439. apiKey:
  16440. description: APIKey If not provided then ClientID/ClientSecret become required.
  16441. properties:
  16442. secretRef:
  16443. description: SecretRef references a key in a secret that will be used as value.
  16444. properties:
  16445. key:
  16446. description: |-
  16447. A key in the referenced Secret.
  16448. Some instances of this field may be defaulted, in others it may be required.
  16449. maxLength: 253
  16450. minLength: 1
  16451. pattern: ^[-._a-zA-Z0-9]+$
  16452. type: string
  16453. name:
  16454. description: The name of the Secret resource being referred to.
  16455. maxLength: 253
  16456. minLength: 1
  16457. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16458. type: string
  16459. namespace:
  16460. description: |-
  16461. The namespace of the Secret resource being referred to.
  16462. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16463. maxLength: 63
  16464. minLength: 1
  16465. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16466. type: string
  16467. type: object
  16468. value:
  16469. description: Value can be specified directly to set a value without using a secret.
  16470. type: string
  16471. type: object
  16472. certificate:
  16473. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  16474. properties:
  16475. secretRef:
  16476. description: SecretRef references a key in a secret that will be used as value.
  16477. properties:
  16478. key:
  16479. description: |-
  16480. A key in the referenced Secret.
  16481. Some instances of this field may be defaulted, in others it may be required.
  16482. maxLength: 253
  16483. minLength: 1
  16484. pattern: ^[-._a-zA-Z0-9]+$
  16485. type: string
  16486. name:
  16487. description: The name of the Secret resource being referred to.
  16488. maxLength: 253
  16489. minLength: 1
  16490. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16491. type: string
  16492. namespace:
  16493. description: |-
  16494. The namespace of the Secret resource being referred to.
  16495. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16496. maxLength: 63
  16497. minLength: 1
  16498. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16499. type: string
  16500. type: object
  16501. value:
  16502. description: Value can be specified directly to set a value without using a secret.
  16503. type: string
  16504. type: object
  16505. certificateKey:
  16506. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  16507. properties:
  16508. secretRef:
  16509. description: SecretRef references a key in a secret that will be used as value.
  16510. properties:
  16511. key:
  16512. description: |-
  16513. A key in the referenced Secret.
  16514. Some instances of this field may be defaulted, in others it may be required.
  16515. maxLength: 253
  16516. minLength: 1
  16517. pattern: ^[-._a-zA-Z0-9]+$
  16518. type: string
  16519. name:
  16520. description: The name of the Secret resource being referred to.
  16521. maxLength: 253
  16522. minLength: 1
  16523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16524. type: string
  16525. namespace:
  16526. description: |-
  16527. The namespace of the Secret resource being referred to.
  16528. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16529. maxLength: 63
  16530. minLength: 1
  16531. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16532. type: string
  16533. type: object
  16534. value:
  16535. description: Value can be specified directly to set a value without using a secret.
  16536. type: string
  16537. type: object
  16538. clientId:
  16539. description: ClientID is the API OAuth Client ID.
  16540. properties:
  16541. secretRef:
  16542. description: SecretRef references a key in a secret that will be used as value.
  16543. properties:
  16544. key:
  16545. description: |-
  16546. A key in the referenced Secret.
  16547. Some instances of this field may be defaulted, in others it may be required.
  16548. maxLength: 253
  16549. minLength: 1
  16550. pattern: ^[-._a-zA-Z0-9]+$
  16551. type: string
  16552. name:
  16553. description: The name of the Secret resource being referred to.
  16554. maxLength: 253
  16555. minLength: 1
  16556. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16557. type: string
  16558. namespace:
  16559. description: |-
  16560. The namespace of the Secret resource being referred to.
  16561. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16562. maxLength: 63
  16563. minLength: 1
  16564. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16565. type: string
  16566. type: object
  16567. value:
  16568. description: Value can be specified directly to set a value without using a secret.
  16569. type: string
  16570. type: object
  16571. clientSecret:
  16572. description: ClientSecret is the API OAuth Client Secret.
  16573. properties:
  16574. secretRef:
  16575. description: SecretRef references a key in a secret that will be used as value.
  16576. properties:
  16577. key:
  16578. description: |-
  16579. A key in the referenced Secret.
  16580. Some instances of this field may be defaulted, in others it may be required.
  16581. maxLength: 253
  16582. minLength: 1
  16583. pattern: ^[-._a-zA-Z0-9]+$
  16584. type: string
  16585. name:
  16586. description: The name of the Secret resource being referred to.
  16587. maxLength: 253
  16588. minLength: 1
  16589. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16590. type: string
  16591. namespace:
  16592. description: |-
  16593. The namespace of the Secret resource being referred to.
  16594. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16595. maxLength: 63
  16596. minLength: 1
  16597. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16598. type: string
  16599. type: object
  16600. value:
  16601. description: Value can be specified directly to set a value without using a secret.
  16602. type: string
  16603. type: object
  16604. type: object
  16605. server:
  16606. description: Auth configures how API server works.
  16607. properties:
  16608. apiUrl:
  16609. type: string
  16610. apiVersion:
  16611. type: string
  16612. clientTimeOutSeconds:
  16613. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  16614. type: integer
  16615. decrypt:
  16616. default: true
  16617. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  16618. type: boolean
  16619. retrievalType:
  16620. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  16621. type: string
  16622. separator:
  16623. description: A character that separates the folder names.
  16624. type: string
  16625. verifyCA:
  16626. type: boolean
  16627. required:
  16628. - apiUrl
  16629. - verifyCA
  16630. type: object
  16631. required:
  16632. - auth
  16633. - server
  16634. type: object
  16635. beyondtrustworkloadcredentials:
  16636. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  16637. properties:
  16638. auth:
  16639. description: |-
  16640. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  16641. Currently supports API key authentication via Kubernetes secret reference.
  16642. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16643. properties:
  16644. apikey:
  16645. description: |-
  16646. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  16647. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  16648. properties:
  16649. token:
  16650. description: |-
  16651. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  16652. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  16653. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  16654. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16655. properties:
  16656. key:
  16657. description: |-
  16658. A key in the referenced Secret.
  16659. Some instances of this field may be defaulted, in others it may be required.
  16660. maxLength: 253
  16661. minLength: 1
  16662. pattern: ^[-._a-zA-Z0-9]+$
  16663. type: string
  16664. name:
  16665. description: The name of the Secret resource being referred to.
  16666. maxLength: 253
  16667. minLength: 1
  16668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16669. type: string
  16670. namespace:
  16671. description: |-
  16672. The namespace of the Secret resource being referred to.
  16673. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16674. maxLength: 63
  16675. minLength: 1
  16676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16677. type: string
  16678. type: object
  16679. required:
  16680. - token
  16681. type: object
  16682. required:
  16683. - apikey
  16684. type: object
  16685. caBundle:
  16686. description: |-
  16687. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  16688. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  16689. If not set, the system's trusted root certificates are used.
  16690. format: byte
  16691. type: string
  16692. caProvider:
  16693. description: |-
  16694. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  16695. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  16696. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  16697. properties:
  16698. key:
  16699. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16700. maxLength: 253
  16701. minLength: 1
  16702. pattern: ^[-._a-zA-Z0-9]+$
  16703. type: string
  16704. name:
  16705. description: The name of the object located at the provider type.
  16706. maxLength: 253
  16707. minLength: 1
  16708. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16709. type: string
  16710. namespace:
  16711. description: |-
  16712. The namespace the Provider type is in.
  16713. Can only be defined when used in a ClusterSecretStore.
  16714. maxLength: 63
  16715. minLength: 1
  16716. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16717. type: string
  16718. type:
  16719. description: The type of provider to use such as "Secret", or "ConfigMap".
  16720. enum:
  16721. - Secret
  16722. - ConfigMap
  16723. type: string
  16724. required:
  16725. - name
  16726. - type
  16727. type: object
  16728. folderPath:
  16729. description: |-
  16730. FolderPath specifies the default folder path for secret retrieval.
  16731. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  16732. Example: "production/database" or "dev/api-keys"
  16733. Leave empty to retrieve secrets from the root folder.
  16734. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  16735. type: string
  16736. server:
  16737. description: |-
  16738. Server configures the BeyondTrust Workload Credentials server connection details.
  16739. Includes the API URL and Site ID for your BeyondTrust instance.
  16740. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  16741. properties:
  16742. apiUrl:
  16743. description: |-
  16744. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  16745. This should be the full URL to your BeyondTrust instance.
  16746. Example: https://api.beyondtrust.io/siie
  16747. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  16748. type: string
  16749. siteId:
  16750. description: |-
  16751. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  16752. This identifier is unique to your BeyondTrust Workload Credentials instance.
  16753. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  16754. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  16755. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  16756. type: string
  16757. required:
  16758. - apiUrl
  16759. - siteId
  16760. type: object
  16761. required:
  16762. - auth
  16763. - server
  16764. type: object
  16765. bitwardensecretsmanager:
  16766. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  16767. properties:
  16768. apiURL:
  16769. type: string
  16770. auth:
  16771. description: |-
  16772. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  16773. Make sure that the token being used has permissions on the given secret.
  16774. properties:
  16775. secretRef:
  16776. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  16777. properties:
  16778. credentials:
  16779. description: AccessToken used for the bitwarden instance.
  16780. properties:
  16781. key:
  16782. description: |-
  16783. A key in the referenced Secret.
  16784. Some instances of this field may be defaulted, in others it may be required.
  16785. maxLength: 253
  16786. minLength: 1
  16787. pattern: ^[-._a-zA-Z0-9]+$
  16788. type: string
  16789. name:
  16790. description: The name of the Secret resource being referred to.
  16791. maxLength: 253
  16792. minLength: 1
  16793. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16794. type: string
  16795. namespace:
  16796. description: |-
  16797. The namespace of the Secret resource being referred to.
  16798. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16799. maxLength: 63
  16800. minLength: 1
  16801. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16802. type: string
  16803. type: object
  16804. required:
  16805. - credentials
  16806. type: object
  16807. required:
  16808. - secretRef
  16809. type: object
  16810. bitwardenServerSDKURL:
  16811. type: string
  16812. caBundle:
  16813. description: |-
  16814. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  16815. can be performed.
  16816. type: string
  16817. caProvider:
  16818. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  16819. properties:
  16820. key:
  16821. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16822. maxLength: 253
  16823. minLength: 1
  16824. pattern: ^[-._a-zA-Z0-9]+$
  16825. type: string
  16826. name:
  16827. description: The name of the object located at the provider type.
  16828. maxLength: 253
  16829. minLength: 1
  16830. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16831. type: string
  16832. namespace:
  16833. description: |-
  16834. The namespace the Provider type is in.
  16835. Can only be defined when used in a ClusterSecretStore.
  16836. maxLength: 63
  16837. minLength: 1
  16838. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16839. type: string
  16840. type:
  16841. description: The type of provider to use such as "Secret", or "ConfigMap".
  16842. enum:
  16843. - Secret
  16844. - ConfigMap
  16845. type: string
  16846. required:
  16847. - name
  16848. - type
  16849. type: object
  16850. identityURL:
  16851. type: string
  16852. organizationID:
  16853. description: OrganizationID determines which organization this secret store manages.
  16854. type: string
  16855. projectID:
  16856. description: ProjectID determines which project this secret store manages.
  16857. type: string
  16858. required:
  16859. - auth
  16860. - organizationID
  16861. - projectID
  16862. type: object
  16863. chef:
  16864. description: Chef configures this store to sync secrets with chef server
  16865. properties:
  16866. auth:
  16867. description: Auth defines the information necessary to authenticate against chef Server
  16868. properties:
  16869. secretRef:
  16870. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  16871. properties:
  16872. privateKeySecretRef:
  16873. description: SecretKey is the Signing Key in PEM format, used for authentication.
  16874. properties:
  16875. key:
  16876. description: |-
  16877. A key in the referenced Secret.
  16878. Some instances of this field may be defaulted, in others it may be required.
  16879. maxLength: 253
  16880. minLength: 1
  16881. pattern: ^[-._a-zA-Z0-9]+$
  16882. type: string
  16883. name:
  16884. description: The name of the Secret resource being referred to.
  16885. maxLength: 253
  16886. minLength: 1
  16887. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16888. type: string
  16889. namespace:
  16890. description: |-
  16891. The namespace of the Secret resource being referred to.
  16892. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16893. maxLength: 63
  16894. minLength: 1
  16895. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16896. type: string
  16897. type: object
  16898. required:
  16899. - privateKeySecretRef
  16900. type: object
  16901. required:
  16902. - secretRef
  16903. type: object
  16904. serverUrl:
  16905. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  16906. type: string
  16907. username:
  16908. description: UserName should be the user ID on the chef server
  16909. type: string
  16910. required:
  16911. - auth
  16912. - serverUrl
  16913. - username
  16914. type: object
  16915. cloudrusm:
  16916. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  16917. properties:
  16918. auth:
  16919. description: CSMAuth contains a secretRef for credentials.
  16920. properties:
  16921. secretRef:
  16922. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  16923. properties:
  16924. accessKeyIDSecretRef:
  16925. description: The AccessKeyID is used for authentication
  16926. properties:
  16927. key:
  16928. description: |-
  16929. A key in the referenced Secret.
  16930. Some instances of this field may be defaulted, in others it may be required.
  16931. maxLength: 253
  16932. minLength: 1
  16933. pattern: ^[-._a-zA-Z0-9]+$
  16934. type: string
  16935. name:
  16936. description: The name of the Secret resource being referred to.
  16937. maxLength: 253
  16938. minLength: 1
  16939. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16940. type: string
  16941. namespace:
  16942. description: |-
  16943. The namespace of the Secret resource being referred to.
  16944. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16945. maxLength: 63
  16946. minLength: 1
  16947. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16948. type: string
  16949. type: object
  16950. accessKeySecretSecretRef:
  16951. description: The AccessKeySecret is used for authentication
  16952. properties:
  16953. key:
  16954. description: |-
  16955. A key in the referenced Secret.
  16956. Some instances of this field may be defaulted, in others it may be required.
  16957. maxLength: 253
  16958. minLength: 1
  16959. pattern: ^[-._a-zA-Z0-9]+$
  16960. type: string
  16961. name:
  16962. description: The name of the Secret resource being referred to.
  16963. maxLength: 253
  16964. minLength: 1
  16965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16966. type: string
  16967. namespace:
  16968. description: |-
  16969. The namespace of the Secret resource being referred to.
  16970. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16971. maxLength: 63
  16972. minLength: 1
  16973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16974. type: string
  16975. type: object
  16976. required:
  16977. - accessKeyIDSecretRef
  16978. - accessKeySecretSecretRef
  16979. type: object
  16980. type: object
  16981. projectID:
  16982. description: ProjectID is the project, which the secrets are stored in.
  16983. type: string
  16984. required:
  16985. - auth
  16986. type: object
  16987. conjur:
  16988. description: Conjur configures this store to sync secrets using conjur provider
  16989. properties:
  16990. auth:
  16991. description: Defines authentication settings for connecting to Conjur.
  16992. maxProperties: 1
  16993. minProperties: 1
  16994. properties:
  16995. apikey:
  16996. description: Authenticates with Conjur using an API key.
  16997. properties:
  16998. account:
  16999. description: Account is the Conjur organization account name.
  17000. type: string
  17001. apiKeyRef:
  17002. description: |-
  17003. A reference to a specific 'key' containing the Conjur API key
  17004. within a Secret resource. In some instances, `key` is a required field.
  17005. properties:
  17006. key:
  17007. description: |-
  17008. A key in the referenced Secret.
  17009. Some instances of this field may be defaulted, in others it may be required.
  17010. maxLength: 253
  17011. minLength: 1
  17012. pattern: ^[-._a-zA-Z0-9]+$
  17013. type: string
  17014. name:
  17015. description: The name of the Secret resource being referred to.
  17016. maxLength: 253
  17017. minLength: 1
  17018. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17019. type: string
  17020. namespace:
  17021. description: |-
  17022. The namespace of the Secret resource being referred to.
  17023. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17024. maxLength: 63
  17025. minLength: 1
  17026. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17027. type: string
  17028. type: object
  17029. userRef:
  17030. description: |-
  17031. A reference to a specific 'key' containing the Conjur username
  17032. within a Secret resource. In some instances, `key` is a required field.
  17033. properties:
  17034. key:
  17035. description: |-
  17036. A key in the referenced Secret.
  17037. Some instances of this field may be defaulted, in others it may be required.
  17038. maxLength: 253
  17039. minLength: 1
  17040. pattern: ^[-._a-zA-Z0-9]+$
  17041. type: string
  17042. name:
  17043. description: The name of the Secret resource being referred to.
  17044. maxLength: 253
  17045. minLength: 1
  17046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17047. type: string
  17048. namespace:
  17049. description: |-
  17050. The namespace of the Secret resource being referred to.
  17051. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17052. maxLength: 63
  17053. minLength: 1
  17054. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17055. type: string
  17056. type: object
  17057. required:
  17058. - account
  17059. - apiKeyRef
  17060. - userRef
  17061. type: object
  17062. cert:
  17063. description: Cert enables certificate-based authentication using a client certificate and key.
  17064. properties:
  17065. account:
  17066. description: Account is the Conjur organization account name.
  17067. type: string
  17068. clientCertRef:
  17069. description: |-
  17070. ClientCertRef is a reference to a specific 'key' containing the client certificate
  17071. within a Secret resource. The certificate must be PEM-encoded.
  17072. properties:
  17073. key:
  17074. description: |-
  17075. A key in the referenced Secret.
  17076. Some instances of this field may be defaulted, in others it may be required.
  17077. maxLength: 253
  17078. minLength: 1
  17079. pattern: ^[-._a-zA-Z0-9]+$
  17080. type: string
  17081. name:
  17082. description: The name of the Secret resource being referred to.
  17083. maxLength: 253
  17084. minLength: 1
  17085. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17086. type: string
  17087. namespace:
  17088. description: |-
  17089. The namespace of the Secret resource being referred to.
  17090. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17091. maxLength: 63
  17092. minLength: 1
  17093. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17094. type: string
  17095. type: object
  17096. clientKeyRef:
  17097. description: |-
  17098. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  17099. within a Secret resource. The key must be PEM-encoded.
  17100. properties:
  17101. key:
  17102. description: |-
  17103. A key in the referenced Secret.
  17104. Some instances of this field may be defaulted, in others it may be required.
  17105. maxLength: 253
  17106. minLength: 1
  17107. pattern: ^[-._a-zA-Z0-9]+$
  17108. type: string
  17109. name:
  17110. description: The name of the Secret resource being referred to.
  17111. maxLength: 253
  17112. minLength: 1
  17113. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17114. type: string
  17115. namespace:
  17116. description: |-
  17117. The namespace of the Secret resource being referred to.
  17118. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17119. maxLength: 63
  17120. minLength: 1
  17121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17122. type: string
  17123. type: object
  17124. hostId:
  17125. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  17126. type: string
  17127. serviceID:
  17128. description: The conjur authn cert webservice id
  17129. type: string
  17130. required:
  17131. - account
  17132. - clientCertRef
  17133. - clientKeyRef
  17134. - serviceID
  17135. type: object
  17136. jwt:
  17137. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  17138. properties:
  17139. account:
  17140. description: Account is the Conjur organization account name.
  17141. type: string
  17142. hostId:
  17143. description: |-
  17144. Optional HostID for JWT authentication. This may be used depending
  17145. on how the Conjur JWT authenticator policy is configured.
  17146. type: string
  17147. secretRef:
  17148. description: |-
  17149. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  17150. authenticate with Conjur using the JWT authentication method.
  17151. properties:
  17152. key:
  17153. description: |-
  17154. A key in the referenced Secret.
  17155. Some instances of this field may be defaulted, in others it may be required.
  17156. maxLength: 253
  17157. minLength: 1
  17158. pattern: ^[-._a-zA-Z0-9]+$
  17159. type: string
  17160. name:
  17161. description: The name of the Secret resource being referred to.
  17162. maxLength: 253
  17163. minLength: 1
  17164. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17165. type: string
  17166. namespace:
  17167. description: |-
  17168. The namespace of the Secret resource being referred to.
  17169. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17170. maxLength: 63
  17171. minLength: 1
  17172. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17173. type: string
  17174. type: object
  17175. serviceAccountRef:
  17176. description: |-
  17177. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  17178. a token for with the `TokenRequest` API.
  17179. properties:
  17180. audiences:
  17181. description: |-
  17182. Audience specifies the `aud` claim for the service account token
  17183. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17184. then this audiences will be appended to the list
  17185. items:
  17186. type: string
  17187. type: array
  17188. name:
  17189. description: The name of the ServiceAccount resource being referred to.
  17190. maxLength: 253
  17191. minLength: 1
  17192. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17193. type: string
  17194. namespace:
  17195. description: |-
  17196. Namespace of the resource being referred to.
  17197. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17198. maxLength: 63
  17199. minLength: 1
  17200. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17201. type: string
  17202. required:
  17203. - name
  17204. type: object
  17205. serviceID:
  17206. description: The conjur authn jwt webservice id
  17207. type: string
  17208. required:
  17209. - account
  17210. - serviceID
  17211. type: object
  17212. type: object
  17213. caBundle:
  17214. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  17215. type: string
  17216. caProvider:
  17217. description: |-
  17218. Used to provide custom certificate authority (CA) certificates
  17219. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  17220. that contains a PEM-encoded certificate.
  17221. properties:
  17222. key:
  17223. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17224. maxLength: 253
  17225. minLength: 1
  17226. pattern: ^[-._a-zA-Z0-9]+$
  17227. type: string
  17228. name:
  17229. description: The name of the object located at the provider type.
  17230. maxLength: 253
  17231. minLength: 1
  17232. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17233. type: string
  17234. namespace:
  17235. description: |-
  17236. The namespace the Provider type is in.
  17237. Can only be defined when used in a ClusterSecretStore.
  17238. maxLength: 63
  17239. minLength: 1
  17240. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17241. type: string
  17242. type:
  17243. description: The type of provider to use such as "Secret", or "ConfigMap".
  17244. enum:
  17245. - Secret
  17246. - ConfigMap
  17247. type: string
  17248. required:
  17249. - name
  17250. - type
  17251. type: object
  17252. url:
  17253. description: URL is the endpoint of the Conjur instance.
  17254. type: string
  17255. required:
  17256. - auth
  17257. - url
  17258. type: object
  17259. crd:
  17260. description: |-
  17261. CRD configures this store to sync secrets from arbitrary Kubernetes resources,
  17262. including both custom resources (CRDs) and core API resources. Resources are
  17263. selected by API group, version and kind, where group can be "" (empty string)
  17264. for core resources such as ConfigMap. Reading the core v1 Secret is
  17265. intentionally blocked — use the Kubernetes provider for that.
  17266. properties:
  17267. auth:
  17268. description: |-
  17269. Auth configures authentication to the Kubernetes API, same as the
  17270. Kubernetes provider. Required when Server.URL is set (unless using AuthRef).
  17271. maxProperties: 1
  17272. minProperties: 1
  17273. properties:
  17274. cert:
  17275. description: has both clientCert and clientKey as secretKeySelector
  17276. properties:
  17277. clientCert:
  17278. description: |-
  17279. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17280. In some instances, `key` is a required field.
  17281. properties:
  17282. key:
  17283. description: |-
  17284. A key in the referenced Secret.
  17285. Some instances of this field may be defaulted, in others it may be required.
  17286. maxLength: 253
  17287. minLength: 1
  17288. pattern: ^[-._a-zA-Z0-9]+$
  17289. type: string
  17290. name:
  17291. description: The name of the Secret resource being referred to.
  17292. maxLength: 253
  17293. minLength: 1
  17294. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17295. type: string
  17296. namespace:
  17297. description: |-
  17298. The namespace of the Secret resource being referred to.
  17299. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17300. maxLength: 63
  17301. minLength: 1
  17302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17303. type: string
  17304. type: object
  17305. clientKey:
  17306. description: |-
  17307. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17308. In some instances, `key` is a required field.
  17309. properties:
  17310. key:
  17311. description: |-
  17312. A key in the referenced Secret.
  17313. Some instances of this field may be defaulted, in others it may be required.
  17314. maxLength: 253
  17315. minLength: 1
  17316. pattern: ^[-._a-zA-Z0-9]+$
  17317. type: string
  17318. name:
  17319. description: The name of the Secret resource being referred to.
  17320. maxLength: 253
  17321. minLength: 1
  17322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17323. type: string
  17324. namespace:
  17325. description: |-
  17326. The namespace of the Secret resource being referred to.
  17327. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17328. maxLength: 63
  17329. minLength: 1
  17330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17331. type: string
  17332. type: object
  17333. required:
  17334. - clientCert
  17335. - clientKey
  17336. type: object
  17337. serviceAccount:
  17338. description: points to a service account that should be used for authentication
  17339. properties:
  17340. audiences:
  17341. description: |-
  17342. Audience specifies the `aud` claim for the service account token
  17343. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17344. then this audiences will be appended to the list
  17345. items:
  17346. type: string
  17347. type: array
  17348. name:
  17349. description: The name of the ServiceAccount resource being referred to.
  17350. maxLength: 253
  17351. minLength: 1
  17352. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17353. type: string
  17354. namespace:
  17355. description: |-
  17356. Namespace of the resource being referred to.
  17357. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17358. maxLength: 63
  17359. minLength: 1
  17360. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17361. type: string
  17362. required:
  17363. - name
  17364. type: object
  17365. token:
  17366. description: use static token to authenticate with
  17367. properties:
  17368. bearerToken:
  17369. description: |-
  17370. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17371. In some instances, `key` is a required field.
  17372. properties:
  17373. key:
  17374. description: |-
  17375. A key in the referenced Secret.
  17376. Some instances of this field may be defaulted, in others it may be required.
  17377. maxLength: 253
  17378. minLength: 1
  17379. pattern: ^[-._a-zA-Z0-9]+$
  17380. type: string
  17381. name:
  17382. description: The name of the Secret resource being referred to.
  17383. maxLength: 253
  17384. minLength: 1
  17385. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17386. type: string
  17387. namespace:
  17388. description: |-
  17389. The namespace of the Secret resource being referred to.
  17390. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17391. maxLength: 63
  17392. minLength: 1
  17393. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17394. type: string
  17395. type: object
  17396. required:
  17397. - bearerToken
  17398. type: object
  17399. type: object
  17400. authRef:
  17401. description: |-
  17402. AuthRef references a Secret containing a kubeconfig. Same semantics as the
  17403. Kubernetes provider.
  17404. properties:
  17405. key:
  17406. description: |-
  17407. A key in the referenced Secret.
  17408. Some instances of this field may be defaulted, in others it may be required.
  17409. maxLength: 253
  17410. minLength: 1
  17411. pattern: ^[-._a-zA-Z0-9]+$
  17412. type: string
  17413. name:
  17414. description: The name of the Secret resource being referred to.
  17415. maxLength: 253
  17416. minLength: 1
  17417. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17418. type: string
  17419. namespace:
  17420. description: |-
  17421. The namespace of the Secret resource being referred to.
  17422. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17423. maxLength: 63
  17424. minLength: 1
  17425. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17426. type: string
  17427. type: object
  17428. resource:
  17429. description: Resource identifies the CRD by its API group, version and kind.
  17430. properties:
  17431. group:
  17432. description: |-
  17433. Group is the API group of the resource. Use "" (empty string) for core
  17434. Kubernetes resources such as ConfigMap; use e.g. "config.example.io"
  17435. for a CRD. The field is required to be present in the manifest — write
  17436. `group: ""` explicitly for core resources so typos fail at admission
  17437. time rather than later at discovery.
  17438. type: string
  17439. kind:
  17440. description: Kind is the Kubernetes resource kind (e.g. "MyCustomResource").
  17441. minLength: 1
  17442. type: string
  17443. version:
  17444. description: Version is the API version of the resource (e.g. "v1alpha1").
  17445. minLength: 1
  17446. type: string
  17447. required:
  17448. - group
  17449. - kind
  17450. - version
  17451. type: object
  17452. server:
  17453. description: |-
  17454. Server configures the Kubernetes API address and TLS trust, same as the
  17455. Kubernetes provider. When omitted, the URL defaults to the in-cluster API.
  17456. properties:
  17457. caBundle:
  17458. description: CABundle is a base64-encoded CA certificate
  17459. format: byte
  17460. type: string
  17461. caProvider:
  17462. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  17463. properties:
  17464. key:
  17465. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17466. maxLength: 253
  17467. minLength: 1
  17468. pattern: ^[-._a-zA-Z0-9]+$
  17469. type: string
  17470. name:
  17471. description: The name of the object located at the provider type.
  17472. maxLength: 253
  17473. minLength: 1
  17474. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17475. type: string
  17476. namespace:
  17477. description: |-
  17478. The namespace the Provider type is in.
  17479. Can only be defined when used in a ClusterSecretStore.
  17480. maxLength: 63
  17481. minLength: 1
  17482. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17483. type: string
  17484. type:
  17485. description: The type of provider to use such as "Secret", or "ConfigMap".
  17486. enum:
  17487. - Secret
  17488. - ConfigMap
  17489. type: string
  17490. required:
  17491. - name
  17492. - type
  17493. type: object
  17494. url:
  17495. default: kubernetes.default
  17496. description: configures the Kubernetes server Address.
  17497. type: string
  17498. type: object
  17499. whitelist:
  17500. description: |-
  17501. Whitelist optionally restricts which object names and requested properties
  17502. are allowed to be read.
  17503. properties:
  17504. rules:
  17505. description: |-
  17506. Rules is a list of allow rules. If rules are set, at least one rule must
  17507. match for a request to be allowed.
  17508. items:
  17509. description: CRDProviderWhitelistRule defines a single allow rule for CRD reads.
  17510. properties:
  17511. name:
  17512. description: |-
  17513. Name is an optional regular expression matched against the bare object name.
  17514. For both SecretStore and ClusterSecretStore this is always the object name
  17515. without any namespace prefix (e.g. "my-db-spec", not "prod/my-db-spec").
  17516. type: string
  17517. namespace:
  17518. description: |-
  17519. Namespace is an optional regular expression matched against the namespace of
  17520. the object. Applies only when a ClusterSecretStore is used; it is ignored
  17521. for SecretStore (where the namespace is fixed to the store namespace).
  17522. type: string
  17523. properties:
  17524. description: |-
  17525. Properties is an optional list of regular expressions matched against
  17526. requested property keys (for example: "spec.secretValue").
  17527. items:
  17528. type: string
  17529. type: array
  17530. type: object
  17531. type: array
  17532. type: object
  17533. required:
  17534. - resource
  17535. type: object
  17536. x-kubernetes-validations:
  17537. - message: one of auth or authRef is required
  17538. rule: has(self.auth) || has(self.authRef)
  17539. - message: at most one of the fields in [auth authRef] may be set
  17540. rule: '[has(self.auth),has(self.authRef)].filter(x,x==true).size() <= 1'
  17541. delinea:
  17542. description: |-
  17543. Delinea DevOps Secrets Vault
  17544. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  17545. properties:
  17546. clientId:
  17547. description: ClientID is the non-secret part of the credential.
  17548. properties:
  17549. secretRef:
  17550. description: SecretRef references a key in a secret that will be used as value.
  17551. properties:
  17552. key:
  17553. description: |-
  17554. A key in the referenced Secret.
  17555. Some instances of this field may be defaulted, in others it may be required.
  17556. maxLength: 253
  17557. minLength: 1
  17558. pattern: ^[-._a-zA-Z0-9]+$
  17559. type: string
  17560. name:
  17561. description: The name of the Secret resource being referred to.
  17562. maxLength: 253
  17563. minLength: 1
  17564. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17565. type: string
  17566. namespace:
  17567. description: |-
  17568. The namespace of the Secret resource being referred to.
  17569. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17570. maxLength: 63
  17571. minLength: 1
  17572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17573. type: string
  17574. type: object
  17575. value:
  17576. description: Value can be specified directly to set a value without using a secret.
  17577. type: string
  17578. type: object
  17579. clientSecret:
  17580. description: ClientSecret is the secret part of the credential.
  17581. properties:
  17582. secretRef:
  17583. description: SecretRef references a key in a secret that will be used as value.
  17584. properties:
  17585. key:
  17586. description: |-
  17587. A key in the referenced Secret.
  17588. Some instances of this field may be defaulted, in others it may be required.
  17589. maxLength: 253
  17590. minLength: 1
  17591. pattern: ^[-._a-zA-Z0-9]+$
  17592. type: string
  17593. name:
  17594. description: The name of the Secret resource being referred to.
  17595. maxLength: 253
  17596. minLength: 1
  17597. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17598. type: string
  17599. namespace:
  17600. description: |-
  17601. The namespace of the Secret resource being referred to.
  17602. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17603. maxLength: 63
  17604. minLength: 1
  17605. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17606. type: string
  17607. type: object
  17608. value:
  17609. description: Value can be specified directly to set a value without using a secret.
  17610. type: string
  17611. type: object
  17612. tenant:
  17613. description: Tenant is the chosen hostname / site name.
  17614. type: string
  17615. tld:
  17616. description: |-
  17617. TLD is based on the server location that was chosen during provisioning.
  17618. If unset, defaults to "com".
  17619. type: string
  17620. urlTemplate:
  17621. description: |-
  17622. URLTemplate
  17623. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  17624. type: string
  17625. required:
  17626. - clientId
  17627. - clientSecret
  17628. - tenant
  17629. type: object
  17630. doppler:
  17631. description: Doppler configures this store to sync secrets using the Doppler provider
  17632. properties:
  17633. auth:
  17634. description: Auth configures how the Operator authenticates with the Doppler API
  17635. properties:
  17636. oidcConfig:
  17637. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  17638. properties:
  17639. expirationSeconds:
  17640. default: 600
  17641. description: |-
  17642. ExpirationSeconds sets the ServiceAccount token validity duration.
  17643. Defaults to 10 minutes.
  17644. format: int64
  17645. type: integer
  17646. identity:
  17647. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  17648. type: string
  17649. serviceAccountRef:
  17650. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  17651. properties:
  17652. audiences:
  17653. description: |-
  17654. Audience specifies the `aud` claim for the service account token
  17655. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17656. then this audiences will be appended to the list
  17657. items:
  17658. type: string
  17659. type: array
  17660. name:
  17661. description: The name of the ServiceAccount resource being referred to.
  17662. maxLength: 253
  17663. minLength: 1
  17664. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17665. type: string
  17666. namespace:
  17667. description: |-
  17668. Namespace of the resource being referred to.
  17669. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17670. maxLength: 63
  17671. minLength: 1
  17672. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17673. type: string
  17674. required:
  17675. - name
  17676. type: object
  17677. required:
  17678. - identity
  17679. - serviceAccountRef
  17680. type: object
  17681. secretRef:
  17682. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  17683. properties:
  17684. dopplerToken:
  17685. description: |-
  17686. The DopplerToken is used for authentication.
  17687. See https://docs.doppler.com/reference/api#authentication for auth token types.
  17688. The Key attribute defaults to dopplerToken if not specified.
  17689. properties:
  17690. key:
  17691. description: |-
  17692. A key in the referenced Secret.
  17693. Some instances of this field may be defaulted, in others it may be required.
  17694. maxLength: 253
  17695. minLength: 1
  17696. pattern: ^[-._a-zA-Z0-9]+$
  17697. type: string
  17698. name:
  17699. description: The name of the Secret resource being referred to.
  17700. maxLength: 253
  17701. minLength: 1
  17702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17703. type: string
  17704. namespace:
  17705. description: |-
  17706. The namespace of the Secret resource being referred to.
  17707. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17708. maxLength: 63
  17709. minLength: 1
  17710. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17711. type: string
  17712. type: object
  17713. required:
  17714. - dopplerToken
  17715. type: object
  17716. type: object
  17717. x-kubernetes-validations:
  17718. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  17719. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  17720. config:
  17721. description: Doppler config (required if not using a Service Token)
  17722. type: string
  17723. format:
  17724. description: Format enables the downloading of secrets as a file (string)
  17725. enum:
  17726. - json
  17727. - dotnet-json
  17728. - env
  17729. - yaml
  17730. - docker
  17731. type: string
  17732. nameTransformer:
  17733. description: Environment variable compatible name transforms that change secret names to a different format
  17734. enum:
  17735. - upper-camel
  17736. - camel
  17737. - lower-snake
  17738. - tf-var
  17739. - dotnet-env
  17740. - lower-kebab
  17741. type: string
  17742. project:
  17743. description: Doppler project (required if not using a Service Token)
  17744. type: string
  17745. required:
  17746. - auth
  17747. type: object
  17748. dvls:
  17749. description: DVLS configures this store to sync secrets using Devolutions Server provider
  17750. properties:
  17751. auth:
  17752. description: Auth defines the authentication method to use.
  17753. properties:
  17754. secretRef:
  17755. description: SecretRef contains the Application ID and Application Secret for authentication.
  17756. properties:
  17757. appId:
  17758. description: AppID is the reference to the secret containing the Application ID.
  17759. properties:
  17760. key:
  17761. description: |-
  17762. A key in the referenced Secret.
  17763. Some instances of this field may be defaulted, in others it may be required.
  17764. maxLength: 253
  17765. minLength: 1
  17766. pattern: ^[-._a-zA-Z0-9]+$
  17767. type: string
  17768. name:
  17769. description: The name of the Secret resource being referred to.
  17770. maxLength: 253
  17771. minLength: 1
  17772. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17773. type: string
  17774. namespace:
  17775. description: |-
  17776. The namespace of the Secret resource being referred to.
  17777. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17778. maxLength: 63
  17779. minLength: 1
  17780. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17781. type: string
  17782. type: object
  17783. appSecret:
  17784. description: AppSecret is the reference to the secret containing the Application Secret.
  17785. properties:
  17786. key:
  17787. description: |-
  17788. A key in the referenced Secret.
  17789. Some instances of this field may be defaulted, in others it may be required.
  17790. maxLength: 253
  17791. minLength: 1
  17792. pattern: ^[-._a-zA-Z0-9]+$
  17793. type: string
  17794. name:
  17795. description: The name of the Secret resource being referred to.
  17796. maxLength: 253
  17797. minLength: 1
  17798. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17799. type: string
  17800. namespace:
  17801. description: |-
  17802. The namespace of the Secret resource being referred to.
  17803. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17804. maxLength: 63
  17805. minLength: 1
  17806. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17807. type: string
  17808. type: object
  17809. required:
  17810. - appId
  17811. - appSecret
  17812. type: object
  17813. required:
  17814. - secretRef
  17815. type: object
  17816. insecure:
  17817. description: |-
  17818. Insecure allows connecting to DVLS over plain HTTP.
  17819. This is NOT RECOMMENDED for production use.
  17820. Set to true only if you understand the security implications.
  17821. type: boolean
  17822. serverUrl:
  17823. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  17824. type: string
  17825. vault:
  17826. description: |-
  17827. Vault is the name or UUID of the vault to fetch secrets from.
  17828. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  17829. type: string
  17830. required:
  17831. - auth
  17832. - serverUrl
  17833. type: object
  17834. fake:
  17835. description: Fake configures a store with static key/value pairs
  17836. properties:
  17837. data:
  17838. items:
  17839. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  17840. properties:
  17841. key:
  17842. type: string
  17843. value:
  17844. type: string
  17845. version:
  17846. type: string
  17847. required:
  17848. - key
  17849. - value
  17850. type: object
  17851. type: array
  17852. validationResult:
  17853. description: ValidationResult is defined type for the number of validation results.
  17854. type: integer
  17855. required:
  17856. - data
  17857. type: object
  17858. fortanix:
  17859. description: Fortanix configures this store to sync secrets using the Fortanix provider
  17860. properties:
  17861. apiKey:
  17862. description: APIKey is the API token to access SDKMS Applications.
  17863. properties:
  17864. secretRef:
  17865. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  17866. properties:
  17867. key:
  17868. description: |-
  17869. A key in the referenced Secret.
  17870. Some instances of this field may be defaulted, in others it may be required.
  17871. maxLength: 253
  17872. minLength: 1
  17873. pattern: ^[-._a-zA-Z0-9]+$
  17874. type: string
  17875. name:
  17876. description: The name of the Secret resource being referred to.
  17877. maxLength: 253
  17878. minLength: 1
  17879. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17880. type: string
  17881. namespace:
  17882. description: |-
  17883. The namespace of the Secret resource being referred to.
  17884. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17885. maxLength: 63
  17886. minLength: 1
  17887. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17888. type: string
  17889. type: object
  17890. type: object
  17891. apiUrl:
  17892. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  17893. type: string
  17894. type: object
  17895. gcpsm:
  17896. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  17897. properties:
  17898. auth:
  17899. description: Auth defines the information necessary to authenticate against GCP
  17900. properties:
  17901. secretRef:
  17902. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  17903. properties:
  17904. secretAccessKeySecretRef:
  17905. description: The SecretAccessKey is used for authentication
  17906. properties:
  17907. key:
  17908. description: |-
  17909. A key in the referenced Secret.
  17910. Some instances of this field may be defaulted, in others it may be required.
  17911. maxLength: 253
  17912. minLength: 1
  17913. pattern: ^[-._a-zA-Z0-9]+$
  17914. type: string
  17915. name:
  17916. description: The name of the Secret resource being referred to.
  17917. maxLength: 253
  17918. minLength: 1
  17919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17920. type: string
  17921. namespace:
  17922. description: |-
  17923. The namespace of the Secret resource being referred to.
  17924. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17925. maxLength: 63
  17926. minLength: 1
  17927. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17928. type: string
  17929. type: object
  17930. type: object
  17931. workloadIdentity:
  17932. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  17933. properties:
  17934. clusterLocation:
  17935. description: |-
  17936. ClusterLocation is the location of the cluster
  17937. If not specified, it fetches information from the metadata server
  17938. type: string
  17939. clusterName:
  17940. description: |-
  17941. ClusterName is the name of the cluster
  17942. If not specified, it fetches information from the metadata server
  17943. type: string
  17944. clusterProjectID:
  17945. description: |-
  17946. ClusterProjectID is the project ID of the cluster
  17947. If not specified, it fetches information from the metadata server
  17948. type: string
  17949. serviceAccountRef:
  17950. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  17951. properties:
  17952. audiences:
  17953. description: |-
  17954. Audience specifies the `aud` claim for the service account token
  17955. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17956. then this audiences will be appended to the list
  17957. items:
  17958. type: string
  17959. type: array
  17960. name:
  17961. description: The name of the ServiceAccount resource being referred to.
  17962. maxLength: 253
  17963. minLength: 1
  17964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17965. type: string
  17966. namespace:
  17967. description: |-
  17968. Namespace of the resource being referred to.
  17969. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17970. maxLength: 63
  17971. minLength: 1
  17972. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17973. type: string
  17974. required:
  17975. - name
  17976. type: object
  17977. required:
  17978. - serviceAccountRef
  17979. type: object
  17980. workloadIdentityFederation:
  17981. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  17982. properties:
  17983. audience:
  17984. description: |-
  17985. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  17986. If specified, Audience found in the external account credential config will be overridden with the configured value.
  17987. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  17988. type: string
  17989. awsSecurityCredentials:
  17990. description: |-
  17991. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  17992. when using the AWS metadata server is not an option.
  17993. properties:
  17994. awsCredentialsSecretRef:
  17995. description: |-
  17996. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  17997. Secret should be created with below names for keys
  17998. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  17999. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  18000. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  18001. properties:
  18002. name:
  18003. description: name of the secret.
  18004. maxLength: 253
  18005. minLength: 1
  18006. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18007. type: string
  18008. namespace:
  18009. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  18010. maxLength: 63
  18011. minLength: 1
  18012. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18013. type: string
  18014. required:
  18015. - name
  18016. type: object
  18017. region:
  18018. description: region is for configuring the AWS region to be used.
  18019. example: ap-south-1
  18020. maxLength: 50
  18021. minLength: 1
  18022. pattern: ^[a-z0-9-]+$
  18023. type: string
  18024. required:
  18025. - awsCredentialsSecretRef
  18026. - region
  18027. type: object
  18028. credConfig:
  18029. description: |-
  18030. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  18031. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  18032. serviceAccountRef must be used by providing operators service account details.
  18033. properties:
  18034. key:
  18035. description: key name holding the external account credential config.
  18036. maxLength: 253
  18037. minLength: 1
  18038. pattern: ^[-._a-zA-Z0-9]+$
  18039. type: string
  18040. name:
  18041. description: name of the configmap.
  18042. maxLength: 253
  18043. minLength: 1
  18044. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18045. type: string
  18046. namespace:
  18047. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  18048. maxLength: 63
  18049. minLength: 1
  18050. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18051. type: string
  18052. required:
  18053. - key
  18054. - name
  18055. type: object
  18056. externalTokenEndpoint:
  18057. description: |-
  18058. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  18059. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  18060. URL is having the expected value.
  18061. type: string
  18062. gcpServiceAccountEmail:
  18063. description: |-
  18064. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  18065. after Workload Identity Federation. Use this to grant access through the service account's
  18066. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  18067. service_account_impersonation_url in the external account JSON from credConfig;
  18068. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  18069. on that ServiceAccount.
  18070. example: my-gsa@my-project.iam.gserviceaccount.com
  18071. minLength: 1
  18072. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  18073. type: string
  18074. serviceAccountRef:
  18075. description: |-
  18076. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  18077. when Kubernetes is configured as provider in workload identity pool.
  18078. properties:
  18079. audiences:
  18080. description: |-
  18081. Audience specifies the `aud` claim for the service account token
  18082. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  18083. then this audiences will be appended to the list
  18084. items:
  18085. type: string
  18086. type: array
  18087. name:
  18088. description: The name of the ServiceAccount resource being referred to.
  18089. maxLength: 253
  18090. minLength: 1
  18091. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18092. type: string
  18093. namespace:
  18094. description: |-
  18095. Namespace of the resource being referred to.
  18096. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18097. maxLength: 63
  18098. minLength: 1
  18099. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18100. type: string
  18101. required:
  18102. - name
  18103. type: object
  18104. type: object
  18105. type: object
  18106. location:
  18107. description: Location optionally defines a location for a secret
  18108. type: string
  18109. projectID:
  18110. description: ProjectID project where secret is located
  18111. type: string
  18112. secretVersionSelectionPolicy:
  18113. default: LatestOrFail
  18114. description: |-
  18115. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  18116. when "latest" is disabled or destroyed.
  18117. Possible values are:
  18118. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  18119. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  18120. type: string
  18121. type: object
  18122. github:
  18123. description: |-
  18124. Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  18125. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  18126. properties:
  18127. appID:
  18128. description: appID specifies the Github APP that will be used to authenticate the client
  18129. format: int64
  18130. type: integer
  18131. auth:
  18132. description: auth configures how secret-manager authenticates with a Github instance.
  18133. properties:
  18134. privateKey:
  18135. description: |-
  18136. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18137. In some instances, `key` is a required field.
  18138. properties:
  18139. key:
  18140. description: |-
  18141. A key in the referenced Secret.
  18142. Some instances of this field may be defaulted, in others it may be required.
  18143. maxLength: 253
  18144. minLength: 1
  18145. pattern: ^[-._a-zA-Z0-9]+$
  18146. type: string
  18147. name:
  18148. description: The name of the Secret resource being referred to.
  18149. maxLength: 253
  18150. minLength: 1
  18151. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18152. type: string
  18153. namespace:
  18154. description: |-
  18155. The namespace of the Secret resource being referred to.
  18156. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18157. maxLength: 63
  18158. minLength: 1
  18159. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18160. type: string
  18161. type: object
  18162. required:
  18163. - privateKey
  18164. type: object
  18165. environment:
  18166. description: environment will be used to fetch secrets from a particular environment within a github repository
  18167. type: string
  18168. installationID:
  18169. description: installationID specifies the Github APP installation that will be used to authenticate the client
  18170. format: int64
  18171. type: integer
  18172. orgSecretVisibility:
  18173. description: |-
  18174. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  18175. Valid values are "all" or "private".
  18176. When unset, new secrets are created with visibility "all" and existing secrets preserve
  18177. whatever visibility they already have in GitHub.
  18178. enum:
  18179. - all
  18180. - private
  18181. type: string
  18182. organization:
  18183. description: organization will be used to fetch secrets from the Github organization
  18184. type: string
  18185. repository:
  18186. description: repository will be used to fetch secrets from the Github repository within an organization
  18187. type: string
  18188. uploadURL:
  18189. description: Upload URL for enterprise instances. Default to URL.
  18190. type: string
  18191. url:
  18192. default: https://github.com/
  18193. description: URL configures the Github instance URL. Defaults to https://github.com/.
  18194. type: string
  18195. required:
  18196. - appID
  18197. - auth
  18198. - installationID
  18199. - organization
  18200. type: object
  18201. gitlab:
  18202. description: GitLab configures this store to sync secrets using GitLab Variables provider
  18203. properties:
  18204. auth:
  18205. description: Auth configures how secret-manager authenticates with a GitLab instance.
  18206. properties:
  18207. SecretRef:
  18208. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  18209. properties:
  18210. accessToken:
  18211. description: AccessToken is used for authentication.
  18212. properties:
  18213. key:
  18214. description: |-
  18215. A key in the referenced Secret.
  18216. Some instances of this field may be defaulted, in others it may be required.
  18217. maxLength: 253
  18218. minLength: 1
  18219. pattern: ^[-._a-zA-Z0-9]+$
  18220. type: string
  18221. name:
  18222. description: The name of the Secret resource being referred to.
  18223. maxLength: 253
  18224. minLength: 1
  18225. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18226. type: string
  18227. namespace:
  18228. description: |-
  18229. The namespace of the Secret resource being referred to.
  18230. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18231. maxLength: 63
  18232. minLength: 1
  18233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18234. type: string
  18235. type: object
  18236. type: object
  18237. required:
  18238. - SecretRef
  18239. type: object
  18240. caBundle:
  18241. description: |-
  18242. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  18243. can be performed.
  18244. format: byte
  18245. type: string
  18246. caProvider:
  18247. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  18248. properties:
  18249. key:
  18250. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  18251. maxLength: 253
  18252. minLength: 1
  18253. pattern: ^[-._a-zA-Z0-9]+$
  18254. type: string
  18255. name:
  18256. description: The name of the object located at the provider type.
  18257. maxLength: 253
  18258. minLength: 1
  18259. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18260. type: string
  18261. namespace:
  18262. description: |-
  18263. The namespace the Provider type is in.
  18264. Can only be defined when used in a ClusterSecretStore.
  18265. maxLength: 63
  18266. minLength: 1
  18267. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18268. type: string
  18269. type:
  18270. description: The type of provider to use such as "Secret", or "ConfigMap".
  18271. enum:
  18272. - Secret
  18273. - ConfigMap
  18274. type: string
  18275. required:
  18276. - name
  18277. - type
  18278. type: object
  18279. environment:
  18280. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  18281. type: string
  18282. groupIDs:
  18283. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  18284. items:
  18285. type: string
  18286. type: array
  18287. inheritFromGroups:
  18288. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  18289. type: boolean
  18290. projectID:
  18291. description: ProjectID specifies a project where secrets are located.
  18292. type: string
  18293. url:
  18294. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  18295. type: string
  18296. required:
  18297. - auth
  18298. type: object
  18299. ibm:
  18300. description: IBM configures this store to sync secrets using IBM Cloud provider
  18301. properties:
  18302. auth:
  18303. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  18304. maxProperties: 1
  18305. minProperties: 1
  18306. properties:
  18307. containerAuth:
  18308. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  18309. properties:
  18310. iamEndpoint:
  18311. type: string
  18312. profile:
  18313. description: the IBM Trusted Profile
  18314. type: string
  18315. tokenLocation:
  18316. description: Location the token is mounted on the pod
  18317. type: string
  18318. required:
  18319. - profile
  18320. type: object
  18321. secretRef:
  18322. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  18323. properties:
  18324. iamEndpoint:
  18325. description: The IAM endpoint used to obain a token
  18326. type: string
  18327. secretApiKeySecretRef:
  18328. description: The SecretAccessKey is used for authentication
  18329. properties:
  18330. key:
  18331. description: |-
  18332. A key in the referenced Secret.
  18333. Some instances of this field may be defaulted, in others it may be required.
  18334. maxLength: 253
  18335. minLength: 1
  18336. pattern: ^[-._a-zA-Z0-9]+$
  18337. type: string
  18338. name:
  18339. description: The name of the Secret resource being referred to.
  18340. maxLength: 253
  18341. minLength: 1
  18342. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18343. type: string
  18344. namespace:
  18345. description: |-
  18346. The namespace of the Secret resource being referred to.
  18347. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18348. maxLength: 63
  18349. minLength: 1
  18350. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18351. type: string
  18352. type: object
  18353. type: object
  18354. type: object
  18355. serviceUrl:
  18356. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  18357. type: string
  18358. required:
  18359. - auth
  18360. type: object
  18361. infisical:
  18362. description: Infisical configures this store to sync secrets using the Infisical provider
  18363. properties:
  18364. auth:
  18365. description: Auth configures how the Operator authenticates with the Infisical API
  18366. properties:
  18367. awsAuthCredentials:
  18368. description: AwsAuthCredentials represents the credentials for AWS authentication.
  18369. properties:
  18370. identityId:
  18371. description: |-
  18372. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18373. In some instances, `key` is a required field.
  18374. properties:
  18375. key:
  18376. description: |-
  18377. A key in the referenced Secret.
  18378. Some instances of this field may be defaulted, in others it may be required.
  18379. maxLength: 253
  18380. minLength: 1
  18381. pattern: ^[-._a-zA-Z0-9]+$
  18382. type: string
  18383. name:
  18384. description: The name of the Secret resource being referred to.
  18385. maxLength: 253
  18386. minLength: 1
  18387. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18388. type: string
  18389. namespace:
  18390. description: |-
  18391. The namespace of the Secret resource being referred to.
  18392. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18393. maxLength: 63
  18394. minLength: 1
  18395. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18396. type: string
  18397. type: object
  18398. required:
  18399. - identityId
  18400. type: object
  18401. azureAuthCredentials:
  18402. description: AzureAuthCredentials represents the credentials for Azure authentication.
  18403. properties:
  18404. identityId:
  18405. description: |-
  18406. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18407. In some instances, `key` is a required field.
  18408. properties:
  18409. key:
  18410. description: |-
  18411. A key in the referenced Secret.
  18412. Some instances of this field may be defaulted, in others it may be required.
  18413. maxLength: 253
  18414. minLength: 1
  18415. pattern: ^[-._a-zA-Z0-9]+$
  18416. type: string
  18417. name:
  18418. description: The name of the Secret resource being referred to.
  18419. maxLength: 253
  18420. minLength: 1
  18421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18422. type: string
  18423. namespace:
  18424. description: |-
  18425. The namespace of the Secret resource being referred to.
  18426. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18427. maxLength: 63
  18428. minLength: 1
  18429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18430. type: string
  18431. type: object
  18432. resource:
  18433. description: |-
  18434. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18435. In some instances, `key` is a required field.
  18436. properties:
  18437. key:
  18438. description: |-
  18439. A key in the referenced Secret.
  18440. Some instances of this field may be defaulted, in others it may be required.
  18441. maxLength: 253
  18442. minLength: 1
  18443. pattern: ^[-._a-zA-Z0-9]+$
  18444. type: string
  18445. name:
  18446. description: The name of the Secret resource being referred to.
  18447. maxLength: 253
  18448. minLength: 1
  18449. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18450. type: string
  18451. namespace:
  18452. description: |-
  18453. The namespace of the Secret resource being referred to.
  18454. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18455. maxLength: 63
  18456. minLength: 1
  18457. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18458. type: string
  18459. type: object
  18460. required:
  18461. - identityId
  18462. type: object
  18463. gcpIamAuthCredentials:
  18464. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  18465. properties:
  18466. identityId:
  18467. description: |-
  18468. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18469. In some instances, `key` is a required field.
  18470. properties:
  18471. key:
  18472. description: |-
  18473. A key in the referenced Secret.
  18474. Some instances of this field may be defaulted, in others it may be required.
  18475. maxLength: 253
  18476. minLength: 1
  18477. pattern: ^[-._a-zA-Z0-9]+$
  18478. type: string
  18479. name:
  18480. description: The name of the Secret resource being referred to.
  18481. maxLength: 253
  18482. minLength: 1
  18483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18484. type: string
  18485. namespace:
  18486. description: |-
  18487. The namespace of the Secret resource being referred to.
  18488. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18489. maxLength: 63
  18490. minLength: 1
  18491. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18492. type: string
  18493. type: object
  18494. serviceAccountKeyFilePath:
  18495. description: |-
  18496. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18497. In some instances, `key` is a required field.
  18498. properties:
  18499. key:
  18500. description: |-
  18501. A key in the referenced Secret.
  18502. Some instances of this field may be defaulted, in others it may be required.
  18503. maxLength: 253
  18504. minLength: 1
  18505. pattern: ^[-._a-zA-Z0-9]+$
  18506. type: string
  18507. name:
  18508. description: The name of the Secret resource being referred to.
  18509. maxLength: 253
  18510. minLength: 1
  18511. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18512. type: string
  18513. namespace:
  18514. description: |-
  18515. The namespace of the Secret resource being referred to.
  18516. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18517. maxLength: 63
  18518. minLength: 1
  18519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18520. type: string
  18521. type: object
  18522. required:
  18523. - identityId
  18524. - serviceAccountKeyFilePath
  18525. type: object
  18526. gcpIdTokenAuthCredentials:
  18527. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  18528. properties:
  18529. identityId:
  18530. description: |-
  18531. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18532. In some instances, `key` is a required field.
  18533. properties:
  18534. key:
  18535. description: |-
  18536. A key in the referenced Secret.
  18537. Some instances of this field may be defaulted, in others it may be required.
  18538. maxLength: 253
  18539. minLength: 1
  18540. pattern: ^[-._a-zA-Z0-9]+$
  18541. type: string
  18542. name:
  18543. description: The name of the Secret resource being referred to.
  18544. maxLength: 253
  18545. minLength: 1
  18546. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18547. type: string
  18548. namespace:
  18549. description: |-
  18550. The namespace of the Secret resource being referred to.
  18551. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18552. maxLength: 63
  18553. minLength: 1
  18554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18555. type: string
  18556. type: object
  18557. required:
  18558. - identityId
  18559. type: object
  18560. jwtAuthCredentials:
  18561. description: JwtAuthCredentials represents the credentials for JWT authentication.
  18562. properties:
  18563. identityId:
  18564. description: |-
  18565. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18566. In some instances, `key` is a required field.
  18567. properties:
  18568. key:
  18569. description: |-
  18570. A key in the referenced Secret.
  18571. Some instances of this field may be defaulted, in others it may be required.
  18572. maxLength: 253
  18573. minLength: 1
  18574. pattern: ^[-._a-zA-Z0-9]+$
  18575. type: string
  18576. name:
  18577. description: The name of the Secret resource being referred to.
  18578. maxLength: 253
  18579. minLength: 1
  18580. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18581. type: string
  18582. namespace:
  18583. description: |-
  18584. The namespace of the Secret resource being referred to.
  18585. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18586. maxLength: 63
  18587. minLength: 1
  18588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18589. type: string
  18590. type: object
  18591. jwt:
  18592. description: |-
  18593. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18594. In some instances, `key` is a required field.
  18595. properties:
  18596. key:
  18597. description: |-
  18598. A key in the referenced Secret.
  18599. Some instances of this field may be defaulted, in others it may be required.
  18600. maxLength: 253
  18601. minLength: 1
  18602. pattern: ^[-._a-zA-Z0-9]+$
  18603. type: string
  18604. name:
  18605. description: The name of the Secret resource being referred to.
  18606. maxLength: 253
  18607. minLength: 1
  18608. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18609. type: string
  18610. namespace:
  18611. description: |-
  18612. The namespace of the Secret resource being referred to.
  18613. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18614. maxLength: 63
  18615. minLength: 1
  18616. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18617. type: string
  18618. type: object
  18619. required:
  18620. - identityId
  18621. - jwt
  18622. type: object
  18623. kubernetesAuthCredentials:
  18624. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  18625. properties:
  18626. identityId:
  18627. description: |-
  18628. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18629. In some instances, `key` is a required field.
  18630. properties:
  18631. key:
  18632. description: |-
  18633. A key in the referenced Secret.
  18634. Some instances of this field may be defaulted, in others it may be required.
  18635. maxLength: 253
  18636. minLength: 1
  18637. pattern: ^[-._a-zA-Z0-9]+$
  18638. type: string
  18639. name:
  18640. description: The name of the Secret resource being referred to.
  18641. maxLength: 253
  18642. minLength: 1
  18643. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18644. type: string
  18645. namespace:
  18646. description: |-
  18647. The namespace of the Secret resource being referred to.
  18648. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18649. maxLength: 63
  18650. minLength: 1
  18651. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18652. type: string
  18653. type: object
  18654. serviceAccountTokenPath:
  18655. description: |-
  18656. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18657. In some instances, `key` is a required field.
  18658. properties:
  18659. key:
  18660. description: |-
  18661. A key in the referenced Secret.
  18662. Some instances of this field may be defaulted, in others it may be required.
  18663. maxLength: 253
  18664. minLength: 1
  18665. pattern: ^[-._a-zA-Z0-9]+$
  18666. type: string
  18667. name:
  18668. description: The name of the Secret resource being referred to.
  18669. maxLength: 253
  18670. minLength: 1
  18671. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18672. type: string
  18673. namespace:
  18674. description: |-
  18675. The namespace of the Secret resource being referred to.
  18676. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18677. maxLength: 63
  18678. minLength: 1
  18679. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18680. type: string
  18681. type: object
  18682. required:
  18683. - identityId
  18684. type: object
  18685. ldapAuthCredentials:
  18686. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  18687. properties:
  18688. identityId:
  18689. description: |-
  18690. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18691. In some instances, `key` is a required field.
  18692. properties:
  18693. key:
  18694. description: |-
  18695. A key in the referenced Secret.
  18696. Some instances of this field may be defaulted, in others it may be required.
  18697. maxLength: 253
  18698. minLength: 1
  18699. pattern: ^[-._a-zA-Z0-9]+$
  18700. type: string
  18701. name:
  18702. description: The name of the Secret resource being referred to.
  18703. maxLength: 253
  18704. minLength: 1
  18705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18706. type: string
  18707. namespace:
  18708. description: |-
  18709. The namespace of the Secret resource being referred to.
  18710. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18711. maxLength: 63
  18712. minLength: 1
  18713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18714. type: string
  18715. type: object
  18716. ldapPassword:
  18717. description: |-
  18718. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18719. In some instances, `key` is a required field.
  18720. properties:
  18721. key:
  18722. description: |-
  18723. A key in the referenced Secret.
  18724. Some instances of this field may be defaulted, in others it may be required.
  18725. maxLength: 253
  18726. minLength: 1
  18727. pattern: ^[-._a-zA-Z0-9]+$
  18728. type: string
  18729. name:
  18730. description: The name of the Secret resource being referred to.
  18731. maxLength: 253
  18732. minLength: 1
  18733. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18734. type: string
  18735. namespace:
  18736. description: |-
  18737. The namespace of the Secret resource being referred to.
  18738. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18739. maxLength: 63
  18740. minLength: 1
  18741. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18742. type: string
  18743. type: object
  18744. ldapUsername:
  18745. description: |-
  18746. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18747. In some instances, `key` is a required field.
  18748. properties:
  18749. key:
  18750. description: |-
  18751. A key in the referenced Secret.
  18752. Some instances of this field may be defaulted, in others it may be required.
  18753. maxLength: 253
  18754. minLength: 1
  18755. pattern: ^[-._a-zA-Z0-9]+$
  18756. type: string
  18757. name:
  18758. description: The name of the Secret resource being referred to.
  18759. maxLength: 253
  18760. minLength: 1
  18761. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18762. type: string
  18763. namespace:
  18764. description: |-
  18765. The namespace of the Secret resource being referred to.
  18766. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18767. maxLength: 63
  18768. minLength: 1
  18769. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18770. type: string
  18771. type: object
  18772. required:
  18773. - identityId
  18774. - ldapPassword
  18775. - ldapUsername
  18776. type: object
  18777. ociAuthCredentials:
  18778. description: OciAuthCredentials represents the credentials for OCI authentication.
  18779. properties:
  18780. fingerprint:
  18781. description: |-
  18782. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18783. In some instances, `key` is a required field.
  18784. properties:
  18785. key:
  18786. description: |-
  18787. A key in the referenced Secret.
  18788. Some instances of this field may be defaulted, in others it may be required.
  18789. maxLength: 253
  18790. minLength: 1
  18791. pattern: ^[-._a-zA-Z0-9]+$
  18792. type: string
  18793. name:
  18794. description: The name of the Secret resource being referred to.
  18795. maxLength: 253
  18796. minLength: 1
  18797. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18798. type: string
  18799. namespace:
  18800. description: |-
  18801. The namespace of the Secret resource being referred to.
  18802. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18803. maxLength: 63
  18804. minLength: 1
  18805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18806. type: string
  18807. type: object
  18808. identityId:
  18809. description: |-
  18810. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18811. In some instances, `key` is a required field.
  18812. properties:
  18813. key:
  18814. description: |-
  18815. A key in the referenced Secret.
  18816. Some instances of this field may be defaulted, in others it may be required.
  18817. maxLength: 253
  18818. minLength: 1
  18819. pattern: ^[-._a-zA-Z0-9]+$
  18820. type: string
  18821. name:
  18822. description: The name of the Secret resource being referred to.
  18823. maxLength: 253
  18824. minLength: 1
  18825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18826. type: string
  18827. namespace:
  18828. description: |-
  18829. The namespace of the Secret resource being referred to.
  18830. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18831. maxLength: 63
  18832. minLength: 1
  18833. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18834. type: string
  18835. type: object
  18836. privateKey:
  18837. description: |-
  18838. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18839. In some instances, `key` is a required field.
  18840. properties:
  18841. key:
  18842. description: |-
  18843. A key in the referenced Secret.
  18844. Some instances of this field may be defaulted, in others it may be required.
  18845. maxLength: 253
  18846. minLength: 1
  18847. pattern: ^[-._a-zA-Z0-9]+$
  18848. type: string
  18849. name:
  18850. description: The name of the Secret resource being referred to.
  18851. maxLength: 253
  18852. minLength: 1
  18853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18854. type: string
  18855. namespace:
  18856. description: |-
  18857. The namespace of the Secret resource being referred to.
  18858. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18859. maxLength: 63
  18860. minLength: 1
  18861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18862. type: string
  18863. type: object
  18864. privateKeyPassphrase:
  18865. description: |-
  18866. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18867. In some instances, `key` is a required field.
  18868. properties:
  18869. key:
  18870. description: |-
  18871. A key in the referenced Secret.
  18872. Some instances of this field may be defaulted, in others it may be required.
  18873. maxLength: 253
  18874. minLength: 1
  18875. pattern: ^[-._a-zA-Z0-9]+$
  18876. type: string
  18877. name:
  18878. description: The name of the Secret resource being referred to.
  18879. maxLength: 253
  18880. minLength: 1
  18881. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18882. type: string
  18883. namespace:
  18884. description: |-
  18885. The namespace of the Secret resource being referred to.
  18886. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18887. maxLength: 63
  18888. minLength: 1
  18889. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18890. type: string
  18891. type: object
  18892. region:
  18893. description: |-
  18894. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18895. In some instances, `key` is a required field.
  18896. properties:
  18897. key:
  18898. description: |-
  18899. A key in the referenced Secret.
  18900. Some instances of this field may be defaulted, in others it may be required.
  18901. maxLength: 253
  18902. minLength: 1
  18903. pattern: ^[-._a-zA-Z0-9]+$
  18904. type: string
  18905. name:
  18906. description: The name of the Secret resource being referred to.
  18907. maxLength: 253
  18908. minLength: 1
  18909. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18910. type: string
  18911. namespace:
  18912. description: |-
  18913. The namespace of the Secret resource being referred to.
  18914. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18915. maxLength: 63
  18916. minLength: 1
  18917. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18918. type: string
  18919. type: object
  18920. tenancyId:
  18921. description: |-
  18922. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18923. In some instances, `key` is a required field.
  18924. properties:
  18925. key:
  18926. description: |-
  18927. A key in the referenced Secret.
  18928. Some instances of this field may be defaulted, in others it may be required.
  18929. maxLength: 253
  18930. minLength: 1
  18931. pattern: ^[-._a-zA-Z0-9]+$
  18932. type: string
  18933. name:
  18934. description: The name of the Secret resource being referred to.
  18935. maxLength: 253
  18936. minLength: 1
  18937. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18938. type: string
  18939. namespace:
  18940. description: |-
  18941. The namespace of the Secret resource being referred to.
  18942. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18943. maxLength: 63
  18944. minLength: 1
  18945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18946. type: string
  18947. type: object
  18948. userId:
  18949. description: |-
  18950. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18951. In some instances, `key` is a required field.
  18952. properties:
  18953. key:
  18954. description: |-
  18955. A key in the referenced Secret.
  18956. Some instances of this field may be defaulted, in others it may be required.
  18957. maxLength: 253
  18958. minLength: 1
  18959. pattern: ^[-._a-zA-Z0-9]+$
  18960. type: string
  18961. name:
  18962. description: The name of the Secret resource being referred to.
  18963. maxLength: 253
  18964. minLength: 1
  18965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18966. type: string
  18967. namespace:
  18968. description: |-
  18969. The namespace of the Secret resource being referred to.
  18970. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18971. maxLength: 63
  18972. minLength: 1
  18973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18974. type: string
  18975. type: object
  18976. required:
  18977. - fingerprint
  18978. - identityId
  18979. - privateKey
  18980. - region
  18981. - tenancyId
  18982. - userId
  18983. type: object
  18984. tokenAuthCredentials:
  18985. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  18986. properties:
  18987. accessToken:
  18988. description: |-
  18989. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18990. In some instances, `key` is a required field.
  18991. properties:
  18992. key:
  18993. description: |-
  18994. A key in the referenced Secret.
  18995. Some instances of this field may be defaulted, in others it may be required.
  18996. maxLength: 253
  18997. minLength: 1
  18998. pattern: ^[-._a-zA-Z0-9]+$
  18999. type: string
  19000. name:
  19001. description: The name of the Secret resource being referred to.
  19002. maxLength: 253
  19003. minLength: 1
  19004. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19005. type: string
  19006. namespace:
  19007. description: |-
  19008. The namespace of the Secret resource being referred to.
  19009. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19010. maxLength: 63
  19011. minLength: 1
  19012. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19013. type: string
  19014. type: object
  19015. required:
  19016. - accessToken
  19017. type: object
  19018. universalAuthCredentials:
  19019. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  19020. properties:
  19021. clientId:
  19022. description: |-
  19023. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19024. In some instances, `key` is a required field.
  19025. properties:
  19026. key:
  19027. description: |-
  19028. A key in the referenced Secret.
  19029. Some instances of this field may be defaulted, in others it may be required.
  19030. maxLength: 253
  19031. minLength: 1
  19032. pattern: ^[-._a-zA-Z0-9]+$
  19033. type: string
  19034. name:
  19035. description: The name of the Secret resource being referred to.
  19036. maxLength: 253
  19037. minLength: 1
  19038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19039. type: string
  19040. namespace:
  19041. description: |-
  19042. The namespace of the Secret resource being referred to.
  19043. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19044. maxLength: 63
  19045. minLength: 1
  19046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19047. type: string
  19048. type: object
  19049. clientSecret:
  19050. description: |-
  19051. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19052. In some instances, `key` is a required field.
  19053. properties:
  19054. key:
  19055. description: |-
  19056. A key in the referenced Secret.
  19057. Some instances of this field may be defaulted, in others it may be required.
  19058. maxLength: 253
  19059. minLength: 1
  19060. pattern: ^[-._a-zA-Z0-9]+$
  19061. type: string
  19062. name:
  19063. description: The name of the Secret resource being referred to.
  19064. maxLength: 253
  19065. minLength: 1
  19066. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19067. type: string
  19068. namespace:
  19069. description: |-
  19070. The namespace of the Secret resource being referred to.
  19071. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19072. maxLength: 63
  19073. minLength: 1
  19074. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19075. type: string
  19076. type: object
  19077. required:
  19078. - clientId
  19079. - clientSecret
  19080. type: object
  19081. type: object
  19082. caBundle:
  19083. description: |-
  19084. CABundle is a PEM-encoded CA certificate bundle used to validate
  19085. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  19086. format: byte
  19087. type: string
  19088. caProvider:
  19089. description: |-
  19090. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  19091. The certificate is used to validate the Infisical server's TLS certificate.
  19092. Mutually exclusive with CABundle.
  19093. properties:
  19094. key:
  19095. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19096. maxLength: 253
  19097. minLength: 1
  19098. pattern: ^[-._a-zA-Z0-9]+$
  19099. type: string
  19100. name:
  19101. description: The name of the object located at the provider type.
  19102. maxLength: 253
  19103. minLength: 1
  19104. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19105. type: string
  19106. namespace:
  19107. description: |-
  19108. The namespace the Provider type is in.
  19109. Can only be defined when used in a ClusterSecretStore.
  19110. maxLength: 63
  19111. minLength: 1
  19112. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19113. type: string
  19114. type:
  19115. description: The type of provider to use such as "Secret", or "ConfigMap".
  19116. enum:
  19117. - Secret
  19118. - ConfigMap
  19119. type: string
  19120. required:
  19121. - name
  19122. - type
  19123. type: object
  19124. hostAPI:
  19125. default: https://app.infisical.com/api
  19126. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  19127. type: string
  19128. secretsScope:
  19129. description: SecretsScope defines the scope of the secrets within the workspace
  19130. properties:
  19131. environmentSlug:
  19132. description: EnvironmentSlug is the required slug identifier for the environment.
  19133. type: string
  19134. expandSecretReferences:
  19135. default: true
  19136. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  19137. type: boolean
  19138. organizationSlug:
  19139. description: |-
  19140. OrganizationSlug is the optional slug that identifies the organization that will be used
  19141. during authentication. Useful for sub-organization setups
  19142. type: string
  19143. projectSlug:
  19144. description: ProjectSlug is the required slug identifier for the project.
  19145. type: string
  19146. recursive:
  19147. default: false
  19148. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  19149. type: boolean
  19150. secretsPath:
  19151. default: /
  19152. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  19153. type: string
  19154. required:
  19155. - environmentSlug
  19156. - projectSlug
  19157. type: object
  19158. required:
  19159. - auth
  19160. - secretsScope
  19161. type: object
  19162. keepersecurity:
  19163. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  19164. properties:
  19165. authRef:
  19166. description: |-
  19167. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19168. In some instances, `key` is a required field.
  19169. properties:
  19170. key:
  19171. description: |-
  19172. A key in the referenced Secret.
  19173. Some instances of this field may be defaulted, in others it may be required.
  19174. maxLength: 253
  19175. minLength: 1
  19176. pattern: ^[-._a-zA-Z0-9]+$
  19177. type: string
  19178. name:
  19179. description: The name of the Secret resource being referred to.
  19180. maxLength: 253
  19181. minLength: 1
  19182. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19183. type: string
  19184. namespace:
  19185. description: |-
  19186. The namespace of the Secret resource being referred to.
  19187. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19188. maxLength: 63
  19189. minLength: 1
  19190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19191. type: string
  19192. type: object
  19193. folderID:
  19194. type: string
  19195. getByTitleFallback:
  19196. type: boolean
  19197. required:
  19198. - authRef
  19199. - folderID
  19200. type: object
  19201. kubernetes:
  19202. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  19203. properties:
  19204. auth:
  19205. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  19206. maxProperties: 1
  19207. minProperties: 1
  19208. properties:
  19209. cert:
  19210. description: has both clientCert and clientKey as secretKeySelector
  19211. properties:
  19212. clientCert:
  19213. description: |-
  19214. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19215. In some instances, `key` is a required field.
  19216. properties:
  19217. key:
  19218. description: |-
  19219. A key in the referenced Secret.
  19220. Some instances of this field may be defaulted, in others it may be required.
  19221. maxLength: 253
  19222. minLength: 1
  19223. pattern: ^[-._a-zA-Z0-9]+$
  19224. type: string
  19225. name:
  19226. description: The name of the Secret resource being referred to.
  19227. maxLength: 253
  19228. minLength: 1
  19229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19230. type: string
  19231. namespace:
  19232. description: |-
  19233. The namespace of the Secret resource being referred to.
  19234. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19235. maxLength: 63
  19236. minLength: 1
  19237. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19238. type: string
  19239. type: object
  19240. clientKey:
  19241. description: |-
  19242. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19243. In some instances, `key` is a required field.
  19244. properties:
  19245. key:
  19246. description: |-
  19247. A key in the referenced Secret.
  19248. Some instances of this field may be defaulted, in others it may be required.
  19249. maxLength: 253
  19250. minLength: 1
  19251. pattern: ^[-._a-zA-Z0-9]+$
  19252. type: string
  19253. name:
  19254. description: The name of the Secret resource being referred to.
  19255. maxLength: 253
  19256. minLength: 1
  19257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19258. type: string
  19259. namespace:
  19260. description: |-
  19261. The namespace of the Secret resource being referred to.
  19262. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19263. maxLength: 63
  19264. minLength: 1
  19265. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19266. type: string
  19267. type: object
  19268. required:
  19269. - clientCert
  19270. - clientKey
  19271. type: object
  19272. serviceAccount:
  19273. description: points to a service account that should be used for authentication
  19274. properties:
  19275. audiences:
  19276. description: |-
  19277. Audience specifies the `aud` claim for the service account token
  19278. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  19279. then this audiences will be appended to the list
  19280. items:
  19281. type: string
  19282. type: array
  19283. name:
  19284. description: The name of the ServiceAccount resource being referred to.
  19285. maxLength: 253
  19286. minLength: 1
  19287. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19288. type: string
  19289. namespace:
  19290. description: |-
  19291. Namespace of the resource being referred to.
  19292. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19293. maxLength: 63
  19294. minLength: 1
  19295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19296. type: string
  19297. required:
  19298. - name
  19299. type: object
  19300. token:
  19301. description: use static token to authenticate with
  19302. properties:
  19303. bearerToken:
  19304. description: |-
  19305. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19306. In some instances, `key` is a required field.
  19307. properties:
  19308. key:
  19309. description: |-
  19310. A key in the referenced Secret.
  19311. Some instances of this field may be defaulted, in others it may be required.
  19312. maxLength: 253
  19313. minLength: 1
  19314. pattern: ^[-._a-zA-Z0-9]+$
  19315. type: string
  19316. name:
  19317. description: The name of the Secret resource being referred to.
  19318. maxLength: 253
  19319. minLength: 1
  19320. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19321. type: string
  19322. namespace:
  19323. description: |-
  19324. The namespace of the Secret resource being referred to.
  19325. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19326. maxLength: 63
  19327. minLength: 1
  19328. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19329. type: string
  19330. type: object
  19331. required:
  19332. - bearerToken
  19333. type: object
  19334. type: object
  19335. authRef:
  19336. description: A reference to a secret that contains the auth information.
  19337. properties:
  19338. key:
  19339. description: |-
  19340. A key in the referenced Secret.
  19341. Some instances of this field may be defaulted, in others it may be required.
  19342. maxLength: 253
  19343. minLength: 1
  19344. pattern: ^[-._a-zA-Z0-9]+$
  19345. type: string
  19346. name:
  19347. description: The name of the Secret resource being referred to.
  19348. maxLength: 253
  19349. minLength: 1
  19350. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19351. type: string
  19352. namespace:
  19353. description: |-
  19354. The namespace of the Secret resource being referred to.
  19355. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19356. maxLength: 63
  19357. minLength: 1
  19358. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19359. type: string
  19360. type: object
  19361. remoteNamespace:
  19362. default: default
  19363. description: Remote namespace to fetch the secrets from
  19364. maxLength: 63
  19365. minLength: 1
  19366. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19367. type: string
  19368. server:
  19369. description: configures the Kubernetes server Address.
  19370. properties:
  19371. caBundle:
  19372. description: CABundle is a base64-encoded CA certificate
  19373. format: byte
  19374. type: string
  19375. caProvider:
  19376. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  19377. properties:
  19378. key:
  19379. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19380. maxLength: 253
  19381. minLength: 1
  19382. pattern: ^[-._a-zA-Z0-9]+$
  19383. type: string
  19384. name:
  19385. description: The name of the object located at the provider type.
  19386. maxLength: 253
  19387. minLength: 1
  19388. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19389. type: string
  19390. namespace:
  19391. description: |-
  19392. The namespace the Provider type is in.
  19393. Can only be defined when used in a ClusterSecretStore.
  19394. maxLength: 63
  19395. minLength: 1
  19396. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19397. type: string
  19398. type:
  19399. description: The type of provider to use such as "Secret", or "ConfigMap".
  19400. enum:
  19401. - Secret
  19402. - ConfigMap
  19403. type: string
  19404. required:
  19405. - name
  19406. - type
  19407. type: object
  19408. url:
  19409. default: kubernetes.default
  19410. description: configures the Kubernetes server Address.
  19411. type: string
  19412. type: object
  19413. type: object
  19414. nebiusmysterybox:
  19415. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  19416. properties:
  19417. apiDomain:
  19418. description: NebiusMysterybox API endpoint
  19419. type: string
  19420. auth:
  19421. description: Auth defines parameters to authenticate in MysteryBox
  19422. properties:
  19423. serviceAccountCredsSecretRef:
  19424. description: |-
  19425. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  19426. document with service account credentials used to get an IAM token.
  19427. Expected JSON structure:
  19428. {
  19429. "subject-credentials": {
  19430. "alg": "RS256",
  19431. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  19432. "kid": "<public-key-id>",
  19433. "iss": "<issuer-service-account-id>",
  19434. "sub": "<subject-service-account-id>"
  19435. }
  19436. }
  19437. properties:
  19438. key:
  19439. description: |-
  19440. A key in the referenced Secret.
  19441. Some instances of this field may be defaulted, in others it may be required.
  19442. maxLength: 253
  19443. minLength: 1
  19444. pattern: ^[-._a-zA-Z0-9]+$
  19445. type: string
  19446. name:
  19447. description: The name of the Secret resource being referred to.
  19448. maxLength: 253
  19449. minLength: 1
  19450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19451. type: string
  19452. namespace:
  19453. description: |-
  19454. The namespace of the Secret resource being referred to.
  19455. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19456. maxLength: 63
  19457. minLength: 1
  19458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19459. type: string
  19460. type: object
  19461. tokenSecretRef:
  19462. description: Token authenticates with Nebius Mysterybox by presenting a token.
  19463. properties:
  19464. key:
  19465. description: |-
  19466. A key in the referenced Secret.
  19467. Some instances of this field may be defaulted, in others it may be required.
  19468. maxLength: 253
  19469. minLength: 1
  19470. pattern: ^[-._a-zA-Z0-9]+$
  19471. type: string
  19472. name:
  19473. description: The name of the Secret resource being referred to.
  19474. maxLength: 253
  19475. minLength: 1
  19476. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19477. type: string
  19478. namespace:
  19479. description: |-
  19480. The namespace of the Secret resource being referred to.
  19481. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19482. maxLength: 63
  19483. minLength: 1
  19484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19485. type: string
  19486. type: object
  19487. type: object
  19488. x-kubernetes-validations:
  19489. - message: either serviceAccountCredsSecretRef or tokenSecretRef must be set
  19490. rule: has(self.serviceAccountCredsSecretRef) || has(self.tokenSecretRef)
  19491. caProvider:
  19492. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  19493. properties:
  19494. certSecretRef:
  19495. description: |-
  19496. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19497. In some instances, `key` is a required field.
  19498. properties:
  19499. key:
  19500. description: |-
  19501. A key in the referenced Secret.
  19502. Some instances of this field may be defaulted, in others it may be required.
  19503. maxLength: 253
  19504. minLength: 1
  19505. pattern: ^[-._a-zA-Z0-9]+$
  19506. type: string
  19507. name:
  19508. description: The name of the Secret resource being referred to.
  19509. maxLength: 253
  19510. minLength: 1
  19511. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19512. type: string
  19513. namespace:
  19514. description: |-
  19515. The namespace of the Secret resource being referred to.
  19516. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19517. maxLength: 63
  19518. minLength: 1
  19519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19520. type: string
  19521. type: object
  19522. type: object
  19523. required:
  19524. - apiDomain
  19525. - auth
  19526. type: object
  19527. ngrok:
  19528. description: Ngrok configures this store to sync secrets using the ngrok provider.
  19529. properties:
  19530. apiUrl:
  19531. default: https://api.ngrok.com
  19532. description: APIURL is the URL of the ngrok API.
  19533. type: string
  19534. auth:
  19535. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  19536. maxProperties: 1
  19537. minProperties: 1
  19538. properties:
  19539. apiKey:
  19540. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  19541. properties:
  19542. secretRef:
  19543. description: SecretRef is a reference to a secret containing the ngrok API key.
  19544. properties:
  19545. key:
  19546. description: |-
  19547. A key in the referenced Secret.
  19548. Some instances of this field may be defaulted, in others it may be required.
  19549. maxLength: 253
  19550. minLength: 1
  19551. pattern: ^[-._a-zA-Z0-9]+$
  19552. type: string
  19553. name:
  19554. description: The name of the Secret resource being referred to.
  19555. maxLength: 253
  19556. minLength: 1
  19557. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19558. type: string
  19559. namespace:
  19560. description: |-
  19561. The namespace of the Secret resource being referred to.
  19562. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19563. maxLength: 63
  19564. minLength: 1
  19565. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19566. type: string
  19567. type: object
  19568. type: object
  19569. type: object
  19570. vault:
  19571. description: Vault configures the ngrok vault to sync secrets with.
  19572. properties:
  19573. name:
  19574. description: Name is the name of the ngrok vault to sync secrets with.
  19575. type: string
  19576. required:
  19577. - name
  19578. type: object
  19579. required:
  19580. - auth
  19581. - vault
  19582. type: object
  19583. onboardbase:
  19584. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  19585. properties:
  19586. apiHost:
  19587. default: https://public.onboardbase.com/api/v1/
  19588. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  19589. type: string
  19590. auth:
  19591. description: Auth configures how the Operator authenticates with the Onboardbase API
  19592. properties:
  19593. apiKeyRef:
  19594. description: |-
  19595. OnboardbaseAPIKey is the APIKey generated by an admin account.
  19596. It is used to recognize and authorize access to a project and environment within onboardbase
  19597. properties:
  19598. key:
  19599. description: |-
  19600. A key in the referenced Secret.
  19601. Some instances of this field may be defaulted, in others it may be required.
  19602. maxLength: 253
  19603. minLength: 1
  19604. pattern: ^[-._a-zA-Z0-9]+$
  19605. type: string
  19606. name:
  19607. description: The name of the Secret resource being referred to.
  19608. maxLength: 253
  19609. minLength: 1
  19610. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19611. type: string
  19612. namespace:
  19613. description: |-
  19614. The namespace of the Secret resource being referred to.
  19615. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19616. maxLength: 63
  19617. minLength: 1
  19618. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19619. type: string
  19620. type: object
  19621. passcodeRef:
  19622. description: OnboardbasePasscode is the passcode attached to the API Key
  19623. properties:
  19624. key:
  19625. description: |-
  19626. A key in the referenced Secret.
  19627. Some instances of this field may be defaulted, in others it may be required.
  19628. maxLength: 253
  19629. minLength: 1
  19630. pattern: ^[-._a-zA-Z0-9]+$
  19631. type: string
  19632. name:
  19633. description: The name of the Secret resource being referred to.
  19634. maxLength: 253
  19635. minLength: 1
  19636. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19637. type: string
  19638. namespace:
  19639. description: |-
  19640. The namespace of the Secret resource being referred to.
  19641. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19642. maxLength: 63
  19643. minLength: 1
  19644. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19645. type: string
  19646. type: object
  19647. required:
  19648. - apiKeyRef
  19649. - passcodeRef
  19650. type: object
  19651. environment:
  19652. default: development
  19653. description: Environment is the name of an environmnent within a project to pull the secrets from
  19654. type: string
  19655. project:
  19656. default: development
  19657. description: Project is an onboardbase project that the secrets should be pulled from
  19658. type: string
  19659. required:
  19660. - apiHost
  19661. - auth
  19662. - environment
  19663. - project
  19664. type: object
  19665. onepassword:
  19666. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  19667. properties:
  19668. auth:
  19669. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  19670. properties:
  19671. secretRef:
  19672. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  19673. properties:
  19674. connectTokenSecretRef:
  19675. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  19676. properties:
  19677. key:
  19678. description: |-
  19679. A key in the referenced Secret.
  19680. Some instances of this field may be defaulted, in others it may be required.
  19681. maxLength: 253
  19682. minLength: 1
  19683. pattern: ^[-._a-zA-Z0-9]+$
  19684. type: string
  19685. name:
  19686. description: The name of the Secret resource being referred to.
  19687. maxLength: 253
  19688. minLength: 1
  19689. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19690. type: string
  19691. namespace:
  19692. description: |-
  19693. The namespace of the Secret resource being referred to.
  19694. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19695. maxLength: 63
  19696. minLength: 1
  19697. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19698. type: string
  19699. type: object
  19700. required:
  19701. - connectTokenSecretRef
  19702. type: object
  19703. required:
  19704. - secretRef
  19705. type: object
  19706. connectHost:
  19707. description: ConnectHost defines the OnePassword Connect Server to connect to
  19708. type: string
  19709. vaults:
  19710. additionalProperties:
  19711. type: integer
  19712. description: Vaults defines which OnePassword vaults to search in which order
  19713. type: object
  19714. required:
  19715. - auth
  19716. - connectHost
  19717. - vaults
  19718. type: object
  19719. onepasswordSDK:
  19720. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  19721. properties:
  19722. auth:
  19723. description: Auth defines the information necessary to authenticate against OnePassword API.
  19724. properties:
  19725. serviceAccountSecretRef:
  19726. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  19727. properties:
  19728. key:
  19729. description: |-
  19730. A key in the referenced Secret.
  19731. Some instances of this field may be defaulted, in others it may be required.
  19732. maxLength: 253
  19733. minLength: 1
  19734. pattern: ^[-._a-zA-Z0-9]+$
  19735. type: string
  19736. name:
  19737. description: The name of the Secret resource being referred to.
  19738. maxLength: 253
  19739. minLength: 1
  19740. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19741. type: string
  19742. namespace:
  19743. description: |-
  19744. The namespace of the Secret resource being referred to.
  19745. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19746. maxLength: 63
  19747. minLength: 1
  19748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19749. type: string
  19750. type: object
  19751. required:
  19752. - serviceAccountSecretRef
  19753. type: object
  19754. cache:
  19755. description: |-
  19756. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  19757. When enabled, secrets are cached with the specified TTL.
  19758. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  19759. If omitted, caching is disabled (default).
  19760. cache: {} is a valid option to set.
  19761. properties:
  19762. maxSize:
  19763. default: 100
  19764. description: |-
  19765. MaxSize is the maximum number of secrets to cache.
  19766. When the cache is full, least-recently-used entries are evicted.
  19767. minimum: 1
  19768. type: integer
  19769. ttl:
  19770. default: 5m
  19771. description: |-
  19772. TTL is the time-to-live for cached secrets.
  19773. Format: duration string (e.g., "5m", "1h", "30s")
  19774. type: string
  19775. type: object
  19776. environment:
  19777. description: |-
  19778. Environment defines the 1Password Environment ID to read variables from.
  19779. Environments are read-only: PushSecret, DeleteSecret, and SecretExists return an error when set.
  19780. Mutually exclusive with Vault.
  19781. type: string
  19782. integrationInfo:
  19783. description: |-
  19784. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  19785. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  19786. properties:
  19787. name:
  19788. default: 1Password SDK
  19789. description: Name defaults to "1Password SDK".
  19790. type: string
  19791. version:
  19792. default: v1.0.0
  19793. description: Version defaults to "v1.0.0".
  19794. type: string
  19795. type: object
  19796. vault:
  19797. description: |-
  19798. Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  19799. Mutually exclusive with Environment.
  19800. type: string
  19801. required:
  19802. - auth
  19803. type: object
  19804. x-kubernetes-validations:
  19805. - message: at most one of the fields in [vault environment] may be set
  19806. rule: '[has(self.vault),has(self.environment)].filter(x,x==true).size() <= 1'
  19807. openBao:
  19808. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  19809. properties:
  19810. auth:
  19811. description: Auth configures how secret-manager authenticates with the OpenBao server.
  19812. properties:
  19813. appRole:
  19814. description: |-
  19815. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  19816. with the role and secret stored in a Kubernetes Secret resource.
  19817. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  19818. properties:
  19819. path:
  19820. default: approle
  19821. description: |-
  19822. Path where the App Role authentication backend is mounted
  19823. in OpenBao, e.g: "approle"
  19824. type: string
  19825. roleId:
  19826. description: |-
  19827. RoleID configured in the App Role authentication backend when setting
  19828. up the authentication backend in OpenBao.
  19829. minLength: 1
  19830. type: string
  19831. roleRef:
  19832. description: |-
  19833. Reference to a key in a Secret that contains the App Role ID used
  19834. to authenticate with OpenBao.
  19835. The `key` field must be specified and denotes which entry within the Secret
  19836. resource is used as the app role id.
  19837. properties:
  19838. key:
  19839. description: |-
  19840. A key in the referenced Secret.
  19841. Some instances of this field may be defaulted, in others it may be required.
  19842. maxLength: 253
  19843. minLength: 1
  19844. pattern: ^[-._a-zA-Z0-9]+$
  19845. type: string
  19846. name:
  19847. description: The name of the Secret resource being referred to.
  19848. maxLength: 253
  19849. minLength: 1
  19850. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19851. type: string
  19852. namespace:
  19853. description: |-
  19854. The namespace of the Secret resource being referred to.
  19855. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19856. maxLength: 63
  19857. minLength: 1
  19858. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19859. type: string
  19860. type: object
  19861. secretRef:
  19862. description: |-
  19863. Reference to a key in a Secret that contains the App Role secret used
  19864. to authenticate with OpenBao.
  19865. The `key` field must be specified and denotes which entry within the Secret
  19866. resource is used as the app role secret.
  19867. properties:
  19868. key:
  19869. description: |-
  19870. A key in the referenced Secret.
  19871. Some instances of this field may be defaulted, in others it may be required.
  19872. maxLength: 253
  19873. minLength: 1
  19874. pattern: ^[-._a-zA-Z0-9]+$
  19875. type: string
  19876. name:
  19877. description: The name of the Secret resource being referred to.
  19878. maxLength: 253
  19879. minLength: 1
  19880. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19881. type: string
  19882. namespace:
  19883. description: |-
  19884. The namespace of the Secret resource being referred to.
  19885. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19886. maxLength: 63
  19887. minLength: 1
  19888. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19889. type: string
  19890. type: object
  19891. required:
  19892. - path
  19893. - secretRef
  19894. type: object
  19895. x-kubernetes-validations:
  19896. - message: exactly one of the fields in [roleId roleRef] must be set
  19897. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  19898. namespace:
  19899. description: |-
  19900. Name of the [OpenBao Namespace] to authenticate to. This can be different
  19901. than the namespace your secret is in. Namespaces is a set of features
  19902. within OpenBao that allows OpenBao environments to support secure
  19903. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  19904. if set, or empty otherwise
  19905. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  19906. type: string
  19907. tokenSecretRef:
  19908. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  19909. properties:
  19910. key:
  19911. description: |-
  19912. A key in the referenced Secret.
  19913. Some instances of this field may be defaulted, in others it may be required.
  19914. maxLength: 253
  19915. minLength: 1
  19916. pattern: ^[-._a-zA-Z0-9]+$
  19917. type: string
  19918. name:
  19919. description: The name of the Secret resource being referred to.
  19920. maxLength: 253
  19921. minLength: 1
  19922. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19923. type: string
  19924. namespace:
  19925. description: |-
  19926. The namespace of the Secret resource being referred to.
  19927. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19928. maxLength: 63
  19929. minLength: 1
  19930. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19931. type: string
  19932. type: object
  19933. userPass:
  19934. description: UserPass authenticates with OpenBao by passing a username/password pair
  19935. properties:
  19936. path:
  19937. default: userpass
  19938. description: |-
  19939. Path where the UserPassword authentication backend is mounted
  19940. in OpenBao, e.g: "userpass"
  19941. type: string
  19942. secretRef:
  19943. description: |-
  19944. SecretRef to a key in a Secret resource containing password for the user
  19945. used to authenticate with OpenBao using the [UserPass authentication
  19946. method]
  19947. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  19948. properties:
  19949. key:
  19950. description: |-
  19951. A key in the referenced Secret.
  19952. Some instances of this field may be defaulted, in others it may be required.
  19953. maxLength: 253
  19954. minLength: 1
  19955. pattern: ^[-._a-zA-Z0-9]+$
  19956. type: string
  19957. name:
  19958. description: The name of the Secret resource being referred to.
  19959. maxLength: 253
  19960. minLength: 1
  19961. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19962. type: string
  19963. namespace:
  19964. description: |-
  19965. The namespace of the Secret resource being referred to.
  19966. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19967. maxLength: 63
  19968. minLength: 1
  19969. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19970. type: string
  19971. type: object
  19972. username:
  19973. description: |-
  19974. Username is a username used to authenticate using the [UserPass
  19975. authentication method]
  19976. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  19977. type: string
  19978. required:
  19979. - path
  19980. - username
  19981. type: object
  19982. type: object
  19983. x-kubernetes-validations:
  19984. - message: exactly one of the fields in [appRole tokenSecretRef userPass] must be set
  19985. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass)].filter(x,x==true).size() == 1'
  19986. caBundle:
  19987. description: |-
  19988. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  19989. this and `caProvider` are not set the system root certificates are used
  19990. to validate the TLS connection.
  19991. format: byte
  19992. type: string
  19993. caProvider:
  19994. description: |-
  19995. The provider for the CA bundle to use to validate OpenBao server
  19996. certificate. If this and `caBundle` are not set the system root
  19997. certificates are used to validate the TLS connection.
  19998. properties:
  19999. key:
  20000. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20001. maxLength: 253
  20002. minLength: 1
  20003. pattern: ^[-._a-zA-Z0-9]+$
  20004. type: string
  20005. name:
  20006. description: The name of the object located at the provider type.
  20007. maxLength: 253
  20008. minLength: 1
  20009. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20010. type: string
  20011. namespace:
  20012. description: |-
  20013. The namespace the Provider type is in.
  20014. Can only be defined when used in a ClusterSecretStore.
  20015. maxLength: 63
  20016. minLength: 1
  20017. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20018. type: string
  20019. type:
  20020. description: The type of provider to use such as "Secret", or "ConfigMap".
  20021. enum:
  20022. - Secret
  20023. - ConfigMap
  20024. type: string
  20025. required:
  20026. - name
  20027. - type
  20028. type: object
  20029. namespace:
  20030. description: |-
  20031. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  20032. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  20033. e.g: "ns1".
  20034. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  20035. type: string
  20036. path:
  20037. description: |-
  20038. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  20039. "secret". The v2 KV secret engine version specific "/data" path suffix
  20040. for fetching secrets from OpenBao is optional and will be appended
  20041. if not present in specified path.
  20042. type: string
  20043. server:
  20044. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  20045. type: string
  20046. version:
  20047. default: v2
  20048. description: |-
  20049. Version is the OpenBao KV secret engine version. This can be either "v1" or
  20050. "v2". Version defaults to "v2".
  20051. enum:
  20052. - v1
  20053. - v2
  20054. type: string
  20055. required:
  20056. - server
  20057. type: object
  20058. x-kubernetes-validations:
  20059. - message: at most one of the fields in [caBundle caProvider] may be set
  20060. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  20061. oracle:
  20062. description: Oracle configures this store to sync secrets using Oracle Vault provider
  20063. properties:
  20064. auth:
  20065. description: |-
  20066. Auth configures how secret-manager authenticates with the Oracle Vault.
  20067. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  20068. properties:
  20069. secretRef:
  20070. description: SecretRef to pass through sensitive information.
  20071. properties:
  20072. fingerprint:
  20073. description: Fingerprint is the fingerprint of the API private key.
  20074. properties:
  20075. key:
  20076. description: |-
  20077. A key in the referenced Secret.
  20078. Some instances of this field may be defaulted, in others it may be required.
  20079. maxLength: 253
  20080. minLength: 1
  20081. pattern: ^[-._a-zA-Z0-9]+$
  20082. type: string
  20083. name:
  20084. description: The name of the Secret resource being referred to.
  20085. maxLength: 253
  20086. minLength: 1
  20087. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20088. type: string
  20089. namespace:
  20090. description: |-
  20091. The namespace of the Secret resource being referred to.
  20092. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20093. maxLength: 63
  20094. minLength: 1
  20095. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20096. type: string
  20097. type: object
  20098. privatekey:
  20099. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  20100. properties:
  20101. key:
  20102. description: |-
  20103. A key in the referenced Secret.
  20104. Some instances of this field may be defaulted, in others it may be required.
  20105. maxLength: 253
  20106. minLength: 1
  20107. pattern: ^[-._a-zA-Z0-9]+$
  20108. type: string
  20109. name:
  20110. description: The name of the Secret resource being referred to.
  20111. maxLength: 253
  20112. minLength: 1
  20113. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20114. type: string
  20115. namespace:
  20116. description: |-
  20117. The namespace of the Secret resource being referred to.
  20118. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20119. maxLength: 63
  20120. minLength: 1
  20121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20122. type: string
  20123. type: object
  20124. required:
  20125. - fingerprint
  20126. - privatekey
  20127. type: object
  20128. tenancy:
  20129. description: Tenancy is the tenancy OCID where user is located.
  20130. type: string
  20131. user:
  20132. description: User is an access OCID specific to the account.
  20133. type: string
  20134. required:
  20135. - secretRef
  20136. - tenancy
  20137. - user
  20138. type: object
  20139. compartment:
  20140. description: |-
  20141. Compartment is the vault compartment OCID.
  20142. Required for PushSecret
  20143. type: string
  20144. encryptionKey:
  20145. description: |-
  20146. EncryptionKey is the OCID of the encryption key within the vault.
  20147. Required for PushSecret
  20148. type: string
  20149. principalType:
  20150. description: |-
  20151. The type of principal to use for authentication. If left blank, the Auth struct will
  20152. determine the principal type. This optional field must be specified if using
  20153. workload identity.
  20154. enum:
  20155. - ""
  20156. - UserPrincipal
  20157. - InstancePrincipal
  20158. - Workload
  20159. type: string
  20160. region:
  20161. description: Region is the region where vault is located.
  20162. type: string
  20163. serviceAccountRef:
  20164. description: |-
  20165. ServiceAccountRef specified the service account
  20166. that should be used when authenticating with WorkloadIdentity.
  20167. properties:
  20168. audiences:
  20169. description: |-
  20170. Audience specifies the `aud` claim for the service account token
  20171. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20172. then this audiences will be appended to the list
  20173. items:
  20174. type: string
  20175. type: array
  20176. name:
  20177. description: The name of the ServiceAccount resource being referred to.
  20178. maxLength: 253
  20179. minLength: 1
  20180. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20181. type: string
  20182. namespace:
  20183. description: |-
  20184. Namespace of the resource being referred to.
  20185. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20186. maxLength: 63
  20187. minLength: 1
  20188. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20189. type: string
  20190. required:
  20191. - name
  20192. type: object
  20193. vault:
  20194. description: Vault is the vault's OCID of the specific vault where secret is located.
  20195. type: string
  20196. required:
  20197. - region
  20198. - vault
  20199. type: object
  20200. ovh:
  20201. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  20202. properties:
  20203. auth:
  20204. description: Authentication method (mtls or token).
  20205. properties:
  20206. mtls:
  20207. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  20208. properties:
  20209. caBundle:
  20210. format: byte
  20211. type: string
  20212. caProvider:
  20213. description: |-
  20214. CAProvider provides a custom certificate authority for accessing the provider's store.
  20215. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  20216. properties:
  20217. key:
  20218. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20219. maxLength: 253
  20220. minLength: 1
  20221. pattern: ^[-._a-zA-Z0-9]+$
  20222. type: string
  20223. name:
  20224. description: The name of the object located at the provider type.
  20225. maxLength: 253
  20226. minLength: 1
  20227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20228. type: string
  20229. namespace:
  20230. description: |-
  20231. The namespace the Provider type is in.
  20232. Can only be defined when used in a ClusterSecretStore.
  20233. maxLength: 63
  20234. minLength: 1
  20235. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20236. type: string
  20237. type:
  20238. description: The type of provider to use such as "Secret", or "ConfigMap".
  20239. enum:
  20240. - Secret
  20241. - ConfigMap
  20242. type: string
  20243. required:
  20244. - name
  20245. - type
  20246. type: object
  20247. certSecretRef:
  20248. description: |-
  20249. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20250. In some instances, `key` is a required field.
  20251. properties:
  20252. key:
  20253. description: |-
  20254. A key in the referenced Secret.
  20255. Some instances of this field may be defaulted, in others it may be required.
  20256. maxLength: 253
  20257. minLength: 1
  20258. pattern: ^[-._a-zA-Z0-9]+$
  20259. type: string
  20260. name:
  20261. description: The name of the Secret resource being referred to.
  20262. maxLength: 253
  20263. minLength: 1
  20264. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20265. type: string
  20266. namespace:
  20267. description: |-
  20268. The namespace of the Secret resource being referred to.
  20269. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20270. maxLength: 63
  20271. minLength: 1
  20272. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20273. type: string
  20274. type: object
  20275. keySecretRef:
  20276. description: |-
  20277. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20278. In some instances, `key` is a required field.
  20279. properties:
  20280. key:
  20281. description: |-
  20282. A key in the referenced Secret.
  20283. Some instances of this field may be defaulted, in others it may be required.
  20284. maxLength: 253
  20285. minLength: 1
  20286. pattern: ^[-._a-zA-Z0-9]+$
  20287. type: string
  20288. name:
  20289. description: The name of the Secret resource being referred to.
  20290. maxLength: 253
  20291. minLength: 1
  20292. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20293. type: string
  20294. namespace:
  20295. description: |-
  20296. The namespace of the Secret resource being referred to.
  20297. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20298. maxLength: 63
  20299. minLength: 1
  20300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20301. type: string
  20302. type: object
  20303. required:
  20304. - certSecretRef
  20305. - keySecretRef
  20306. type: object
  20307. token:
  20308. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  20309. properties:
  20310. tokenSecretRef:
  20311. description: |-
  20312. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20313. In some instances, `key` is a required field.
  20314. properties:
  20315. key:
  20316. description: |-
  20317. A key in the referenced Secret.
  20318. Some instances of this field may be defaulted, in others it may be required.
  20319. maxLength: 253
  20320. minLength: 1
  20321. pattern: ^[-._a-zA-Z0-9]+$
  20322. type: string
  20323. name:
  20324. description: The name of the Secret resource being referred to.
  20325. maxLength: 253
  20326. minLength: 1
  20327. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20328. type: string
  20329. namespace:
  20330. description: |-
  20331. The namespace of the Secret resource being referred to.
  20332. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20333. maxLength: 63
  20334. minLength: 1
  20335. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20336. type: string
  20337. type: object
  20338. required:
  20339. - tokenSecretRef
  20340. type: object
  20341. type: object
  20342. casRequired:
  20343. description: 'Enables or disables check-and-set (CAS) (default: false).'
  20344. type: boolean
  20345. okmsTimeout:
  20346. default: 30
  20347. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  20348. format: int32
  20349. minimum: 1
  20350. type: integer
  20351. okmsid:
  20352. description: specifies the OKMS ID.
  20353. type: string
  20354. server:
  20355. description: specifies the OKMS server endpoint.
  20356. type: string
  20357. required:
  20358. - auth
  20359. - okmsid
  20360. - server
  20361. type: object
  20362. passbolt:
  20363. description: |-
  20364. PassboltProvider provides access to Passbolt secrets manager.
  20365. See: https://www.passbolt.com.
  20366. properties:
  20367. auth:
  20368. description: Auth defines the information necessary to authenticate against Passbolt Server
  20369. properties:
  20370. passwordSecretRef:
  20371. description: |-
  20372. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20373. In some instances, `key` is a required field.
  20374. properties:
  20375. key:
  20376. description: |-
  20377. A key in the referenced Secret.
  20378. Some instances of this field may be defaulted, in others it may be required.
  20379. maxLength: 253
  20380. minLength: 1
  20381. pattern: ^[-._a-zA-Z0-9]+$
  20382. type: string
  20383. name:
  20384. description: The name of the Secret resource being referred to.
  20385. maxLength: 253
  20386. minLength: 1
  20387. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20388. type: string
  20389. namespace:
  20390. description: |-
  20391. The namespace of the Secret resource being referred to.
  20392. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20393. maxLength: 63
  20394. minLength: 1
  20395. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20396. type: string
  20397. type: object
  20398. privateKeySecretRef:
  20399. description: |-
  20400. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20401. In some instances, `key` is a required field.
  20402. properties:
  20403. key:
  20404. description: |-
  20405. A key in the referenced Secret.
  20406. Some instances of this field may be defaulted, in others it may be required.
  20407. maxLength: 253
  20408. minLength: 1
  20409. pattern: ^[-._a-zA-Z0-9]+$
  20410. type: string
  20411. name:
  20412. description: The name of the Secret resource being referred to.
  20413. maxLength: 253
  20414. minLength: 1
  20415. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20416. type: string
  20417. namespace:
  20418. description: |-
  20419. The namespace of the Secret resource being referred to.
  20420. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20421. maxLength: 63
  20422. minLength: 1
  20423. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20424. type: string
  20425. type: object
  20426. required:
  20427. - passwordSecretRef
  20428. - privateKeySecretRef
  20429. type: object
  20430. caBundle:
  20431. description: |-
  20432. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  20433. if the Host URL is using HTTPS protocol. If not set the system root certificates
  20434. are used to validate the TLS connection.
  20435. format: byte
  20436. type: string
  20437. caProvider:
  20438. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  20439. properties:
  20440. key:
  20441. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20442. maxLength: 253
  20443. minLength: 1
  20444. pattern: ^[-._a-zA-Z0-9]+$
  20445. type: string
  20446. name:
  20447. description: The name of the object located at the provider type.
  20448. maxLength: 253
  20449. minLength: 1
  20450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20451. type: string
  20452. namespace:
  20453. description: |-
  20454. The namespace the Provider type is in.
  20455. Can only be defined when used in a ClusterSecretStore.
  20456. maxLength: 63
  20457. minLength: 1
  20458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20459. type: string
  20460. type:
  20461. description: The type of provider to use such as "Secret", or "ConfigMap".
  20462. enum:
  20463. - Secret
  20464. - ConfigMap
  20465. type: string
  20466. required:
  20467. - name
  20468. - type
  20469. type: object
  20470. host:
  20471. description: Host defines the Passbolt Server to connect to
  20472. type: string
  20473. required:
  20474. - auth
  20475. - host
  20476. type: object
  20477. passworddepot:
  20478. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  20479. properties:
  20480. auth:
  20481. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  20482. properties:
  20483. secretRef:
  20484. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  20485. properties:
  20486. credentials:
  20487. description: Username / Password is used for authentication.
  20488. properties:
  20489. key:
  20490. description: |-
  20491. A key in the referenced Secret.
  20492. Some instances of this field may be defaulted, in others it may be required.
  20493. maxLength: 253
  20494. minLength: 1
  20495. pattern: ^[-._a-zA-Z0-9]+$
  20496. type: string
  20497. name:
  20498. description: The name of the Secret resource being referred to.
  20499. maxLength: 253
  20500. minLength: 1
  20501. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20502. type: string
  20503. namespace:
  20504. description: |-
  20505. The namespace of the Secret resource being referred to.
  20506. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20507. maxLength: 63
  20508. minLength: 1
  20509. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20510. type: string
  20511. type: object
  20512. type: object
  20513. required:
  20514. - secretRef
  20515. type: object
  20516. database:
  20517. description: Database to use as source
  20518. type: string
  20519. host:
  20520. description: URL configures the Password Depot instance URL.
  20521. type: string
  20522. required:
  20523. - auth
  20524. - database
  20525. - host
  20526. type: object
  20527. previder:
  20528. description: Previder configures this store to sync secrets using the Previder provider
  20529. properties:
  20530. auth:
  20531. description: PreviderAuth contains a secretRef for credentials.
  20532. properties:
  20533. secretRef:
  20534. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  20535. properties:
  20536. accessToken:
  20537. description: The AccessToken is used for authentication
  20538. properties:
  20539. key:
  20540. description: |-
  20541. A key in the referenced Secret.
  20542. Some instances of this field may be defaulted, in others it may be required.
  20543. maxLength: 253
  20544. minLength: 1
  20545. pattern: ^[-._a-zA-Z0-9]+$
  20546. type: string
  20547. name:
  20548. description: The name of the Secret resource being referred to.
  20549. maxLength: 253
  20550. minLength: 1
  20551. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20552. type: string
  20553. namespace:
  20554. description: |-
  20555. The namespace of the Secret resource being referred to.
  20556. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20557. maxLength: 63
  20558. minLength: 1
  20559. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20560. type: string
  20561. type: object
  20562. required:
  20563. - accessToken
  20564. type: object
  20565. type: object
  20566. baseUri:
  20567. type: string
  20568. required:
  20569. - auth
  20570. type: object
  20571. pulumi:
  20572. description: Pulumi configures this store to sync secrets using the Pulumi provider
  20573. properties:
  20574. accessToken:
  20575. description: |-
  20576. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  20577. Deprecated: Use auth.accessToken instead.
  20578. properties:
  20579. secretRef:
  20580. description: SecretRef is a reference to a secret containing the Pulumi API token.
  20581. properties:
  20582. key:
  20583. description: |-
  20584. A key in the referenced Secret.
  20585. Some instances of this field may be defaulted, in others it may be required.
  20586. maxLength: 253
  20587. minLength: 1
  20588. pattern: ^[-._a-zA-Z0-9]+$
  20589. type: string
  20590. name:
  20591. description: The name of the Secret resource being referred to.
  20592. maxLength: 253
  20593. minLength: 1
  20594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20595. type: string
  20596. namespace:
  20597. description: |-
  20598. The namespace of the Secret resource being referred to.
  20599. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20600. maxLength: 63
  20601. minLength: 1
  20602. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20603. type: string
  20604. type: object
  20605. type: object
  20606. apiUrl:
  20607. default: https://api.pulumi.com/api/esc
  20608. description: APIURL is the URL of the Pulumi API.
  20609. type: string
  20610. auth:
  20611. description: |-
  20612. Auth configures how the Operator authenticates with the Pulumi API.
  20613. Either auth or the deprecated accessToken field must be specified.
  20614. properties:
  20615. accessToken:
  20616. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  20617. properties:
  20618. secretRef:
  20619. description: SecretRef is a reference to a secret containing the Pulumi API token.
  20620. properties:
  20621. key:
  20622. description: |-
  20623. A key in the referenced Secret.
  20624. Some instances of this field may be defaulted, in others it may be required.
  20625. maxLength: 253
  20626. minLength: 1
  20627. pattern: ^[-._a-zA-Z0-9]+$
  20628. type: string
  20629. name:
  20630. description: The name of the Secret resource being referred to.
  20631. maxLength: 253
  20632. minLength: 1
  20633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20634. type: string
  20635. namespace:
  20636. description: |-
  20637. The namespace of the Secret resource being referred to.
  20638. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20639. maxLength: 63
  20640. minLength: 1
  20641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20642. type: string
  20643. type: object
  20644. type: object
  20645. oidcConfig:
  20646. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  20647. properties:
  20648. expirationSeconds:
  20649. default: 600
  20650. description: |-
  20651. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  20652. Defaults to 10 minutes.
  20653. format: int64
  20654. minimum: 600
  20655. type: integer
  20656. organization:
  20657. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  20658. type: string
  20659. serviceAccountRef:
  20660. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  20661. properties:
  20662. audiences:
  20663. description: |-
  20664. Audience specifies the `aud` claim for the service account token
  20665. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20666. then this audiences will be appended to the list
  20667. items:
  20668. type: string
  20669. type: array
  20670. name:
  20671. description: The name of the ServiceAccount resource being referred to.
  20672. maxLength: 253
  20673. minLength: 1
  20674. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20675. type: string
  20676. namespace:
  20677. description: |-
  20678. Namespace of the resource being referred to.
  20679. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20680. maxLength: 63
  20681. minLength: 1
  20682. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20683. type: string
  20684. required:
  20685. - name
  20686. type: object
  20687. required:
  20688. - organization
  20689. - serviceAccountRef
  20690. type: object
  20691. type: object
  20692. x-kubernetes-validations:
  20693. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  20694. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  20695. environment:
  20696. description: |-
  20697. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  20698. dynamically retrieved values from supported providers including all major clouds,
  20699. and other Pulumi ESC environments.
  20700. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  20701. type: string
  20702. organization:
  20703. description: |-
  20704. Organization are a space to collaborate on shared projects and stacks.
  20705. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  20706. type: string
  20707. project:
  20708. description: Project is the name of the Pulumi ESC project the environment belongs to.
  20709. type: string
  20710. required:
  20711. - environment
  20712. - organization
  20713. - project
  20714. type: object
  20715. x-kubernetes-validations:
  20716. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  20717. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  20718. scaleway:
  20719. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  20720. properties:
  20721. accessKey:
  20722. description: AccessKey is the non-secret part of the api key.
  20723. properties:
  20724. secretRef:
  20725. description: SecretRef references a key in a secret that will be used as value.
  20726. properties:
  20727. key:
  20728. description: |-
  20729. A key in the referenced Secret.
  20730. Some instances of this field may be defaulted, in others it may be required.
  20731. maxLength: 253
  20732. minLength: 1
  20733. pattern: ^[-._a-zA-Z0-9]+$
  20734. type: string
  20735. name:
  20736. description: The name of the Secret resource being referred to.
  20737. maxLength: 253
  20738. minLength: 1
  20739. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20740. type: string
  20741. namespace:
  20742. description: |-
  20743. The namespace of the Secret resource being referred to.
  20744. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20745. maxLength: 63
  20746. minLength: 1
  20747. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20748. type: string
  20749. type: object
  20750. value:
  20751. description: Value can be specified directly to set a value without using a secret.
  20752. type: string
  20753. type: object
  20754. apiUrl:
  20755. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  20756. type: string
  20757. projectId:
  20758. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  20759. type: string
  20760. region:
  20761. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  20762. type: string
  20763. secretKey:
  20764. description: SecretKey is the non-secret part of the api key.
  20765. properties:
  20766. secretRef:
  20767. description: SecretRef references a key in a secret that will be used as value.
  20768. properties:
  20769. key:
  20770. description: |-
  20771. A key in the referenced Secret.
  20772. Some instances of this field may be defaulted, in others it may be required.
  20773. maxLength: 253
  20774. minLength: 1
  20775. pattern: ^[-._a-zA-Z0-9]+$
  20776. type: string
  20777. name:
  20778. description: The name of the Secret resource being referred to.
  20779. maxLength: 253
  20780. minLength: 1
  20781. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20782. type: string
  20783. namespace:
  20784. description: |-
  20785. The namespace of the Secret resource being referred to.
  20786. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20787. maxLength: 63
  20788. minLength: 1
  20789. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20790. type: string
  20791. type: object
  20792. value:
  20793. description: Value can be specified directly to set a value without using a secret.
  20794. type: string
  20795. type: object
  20796. required:
  20797. - accessKey
  20798. - projectId
  20799. - region
  20800. - secretKey
  20801. type: object
  20802. secretserver:
  20803. description: |-
  20804. SecretServer configures this store to sync secrets using SecretServer provider
  20805. https://docs.delinea.com/online-help/secret-server/start.htm
  20806. properties:
  20807. caBundle:
  20808. description: |-
  20809. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  20810. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  20811. are used to validate the TLS connection.
  20812. format: byte
  20813. type: string
  20814. caProvider:
  20815. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  20816. properties:
  20817. key:
  20818. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20819. maxLength: 253
  20820. minLength: 1
  20821. pattern: ^[-._a-zA-Z0-9]+$
  20822. type: string
  20823. name:
  20824. description: The name of the object located at the provider type.
  20825. maxLength: 253
  20826. minLength: 1
  20827. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20828. type: string
  20829. namespace:
  20830. description: |-
  20831. The namespace the Provider type is in.
  20832. Can only be defined when used in a ClusterSecretStore.
  20833. maxLength: 63
  20834. minLength: 1
  20835. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20836. type: string
  20837. type:
  20838. description: The type of provider to use such as "Secret", or "ConfigMap".
  20839. enum:
  20840. - Secret
  20841. - ConfigMap
  20842. type: string
  20843. required:
  20844. - name
  20845. - type
  20846. type: object
  20847. domain:
  20848. description: Domain is the secret server domain.
  20849. type: string
  20850. password:
  20851. description: |-
  20852. Password is the secret server account password.
  20853. Required unless Token is set.
  20854. properties:
  20855. secretRef:
  20856. description: SecretRef references a key in a secret that will be used as value.
  20857. properties:
  20858. key:
  20859. description: |-
  20860. A key in the referenced Secret.
  20861. Some instances of this field may be defaulted, in others it may be required.
  20862. maxLength: 253
  20863. minLength: 1
  20864. pattern: ^[-._a-zA-Z0-9]+$
  20865. type: string
  20866. name:
  20867. description: The name of the Secret resource being referred to.
  20868. maxLength: 253
  20869. minLength: 1
  20870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20871. type: string
  20872. namespace:
  20873. description: |-
  20874. The namespace of the Secret resource being referred to.
  20875. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20876. maxLength: 63
  20877. minLength: 1
  20878. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20879. type: string
  20880. type: object
  20881. value:
  20882. description: Value can be specified directly to set a value without using a secret.
  20883. minLength: 1
  20884. type: string
  20885. type: object
  20886. x-kubernetes-validations:
  20887. - message: exactly one of value or secretRef must be set
  20888. rule: has(self.value) != has(self.secretRef)
  20889. serverURL:
  20890. description: |-
  20891. ServerURL
  20892. URL to your secret server installation
  20893. type: string
  20894. token:
  20895. description: |-
  20896. Token is an access token used to authenticate to the secret server,
  20897. as an alternative to Username and Password. When set, Username and
  20898. Password are not required and are ignored.
  20899. properties:
  20900. secretRef:
  20901. description: SecretRef references a key in a secret that will be used as value.
  20902. properties:
  20903. key:
  20904. description: |-
  20905. A key in the referenced Secret.
  20906. Some instances of this field may be defaulted, in others it may be required.
  20907. maxLength: 253
  20908. minLength: 1
  20909. pattern: ^[-._a-zA-Z0-9]+$
  20910. type: string
  20911. name:
  20912. description: The name of the Secret resource being referred to.
  20913. maxLength: 253
  20914. minLength: 1
  20915. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20916. type: string
  20917. namespace:
  20918. description: |-
  20919. The namespace of the Secret resource being referred to.
  20920. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20921. maxLength: 63
  20922. minLength: 1
  20923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20924. type: string
  20925. type: object
  20926. value:
  20927. description: Value can be specified directly to set a value without using a secret.
  20928. minLength: 1
  20929. type: string
  20930. type: object
  20931. x-kubernetes-validations:
  20932. - message: exactly one of value or secretRef must be set
  20933. rule: has(self.value) != has(self.secretRef)
  20934. username:
  20935. description: |-
  20936. Username is the secret server account username.
  20937. Required unless Token is set.
  20938. properties:
  20939. secretRef:
  20940. description: SecretRef references a key in a secret that will be used as value.
  20941. properties:
  20942. key:
  20943. description: |-
  20944. A key in the referenced Secret.
  20945. Some instances of this field may be defaulted, in others it may be required.
  20946. maxLength: 253
  20947. minLength: 1
  20948. pattern: ^[-._a-zA-Z0-9]+$
  20949. type: string
  20950. name:
  20951. description: The name of the Secret resource being referred to.
  20952. maxLength: 253
  20953. minLength: 1
  20954. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20955. type: string
  20956. namespace:
  20957. description: |-
  20958. The namespace of the Secret resource being referred to.
  20959. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20960. maxLength: 63
  20961. minLength: 1
  20962. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20963. type: string
  20964. type: object
  20965. value:
  20966. description: Value can be specified directly to set a value without using a secret.
  20967. minLength: 1
  20968. type: string
  20969. type: object
  20970. x-kubernetes-validations:
  20971. - message: exactly one of value or secretRef must be set
  20972. rule: has(self.value) != has(self.secretRef)
  20973. required:
  20974. - serverURL
  20975. type: object
  20976. x-kubernetes-validations:
  20977. - message: either token, or both username and password, must be set
  20978. rule: has(self.token) || (has(self.username) && has(self.password))
  20979. senhasegura:
  20980. description: Senhasegura configures this store to sync secrets using senhasegura provider
  20981. properties:
  20982. auth:
  20983. description: Auth defines parameters to authenticate in senhasegura
  20984. properties:
  20985. clientId:
  20986. type: string
  20987. clientSecretSecretRef:
  20988. description: |-
  20989. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20990. In some instances, `key` is a required field.
  20991. properties:
  20992. key:
  20993. description: |-
  20994. A key in the referenced Secret.
  20995. Some instances of this field may be defaulted, in others it may be required.
  20996. maxLength: 253
  20997. minLength: 1
  20998. pattern: ^[-._a-zA-Z0-9]+$
  20999. type: string
  21000. name:
  21001. description: The name of the Secret resource being referred to.
  21002. maxLength: 253
  21003. minLength: 1
  21004. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21005. type: string
  21006. namespace:
  21007. description: |-
  21008. The namespace of the Secret resource being referred to.
  21009. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21010. maxLength: 63
  21011. minLength: 1
  21012. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21013. type: string
  21014. type: object
  21015. required:
  21016. - clientId
  21017. - clientSecretSecretRef
  21018. type: object
  21019. ignoreSslCertificate:
  21020. default: false
  21021. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  21022. type: boolean
  21023. module:
  21024. description: Module defines which senhasegura module should be used to get secrets
  21025. type: string
  21026. url:
  21027. description: URL of senhasegura
  21028. type: string
  21029. required:
  21030. - auth
  21031. - module
  21032. - url
  21033. type: object
  21034. vault:
  21035. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  21036. properties:
  21037. auth:
  21038. description: Auth configures how secret-manager authenticates with the Vault server.
  21039. properties:
  21040. appRole:
  21041. description: |-
  21042. AppRole authenticates with Vault using the App Role auth mechanism,
  21043. with the role and secret stored in a Kubernetes Secret resource.
  21044. properties:
  21045. path:
  21046. default: approle
  21047. description: |-
  21048. Path where the App Role authentication backend is mounted
  21049. in Vault, e.g: "approle"
  21050. type: string
  21051. roleId:
  21052. description: |-
  21053. RoleID configured in the App Role authentication backend when setting
  21054. up the authentication backend in Vault.
  21055. type: string
  21056. roleRef:
  21057. description: |-
  21058. Reference to a key in a Secret that contains the App Role ID used
  21059. to authenticate with Vault.
  21060. The `key` field must be specified and denotes which entry within the Secret
  21061. resource is used as the app role id.
  21062. properties:
  21063. key:
  21064. description: |-
  21065. A key in the referenced Secret.
  21066. Some instances of this field may be defaulted, in others it may be required.
  21067. maxLength: 253
  21068. minLength: 1
  21069. pattern: ^[-._a-zA-Z0-9]+$
  21070. type: string
  21071. name:
  21072. description: The name of the Secret resource being referred to.
  21073. maxLength: 253
  21074. minLength: 1
  21075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21076. type: string
  21077. namespace:
  21078. description: |-
  21079. The namespace of the Secret resource being referred to.
  21080. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21081. maxLength: 63
  21082. minLength: 1
  21083. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21084. type: string
  21085. type: object
  21086. secretRef:
  21087. description: |-
  21088. Reference to a key in a Secret that contains the App Role secret used
  21089. to authenticate with Vault.
  21090. The `key` field must be specified and denotes which entry within the Secret
  21091. resource is used as the app role secret.
  21092. properties:
  21093. key:
  21094. description: |-
  21095. A key in the referenced Secret.
  21096. Some instances of this field may be defaulted, in others it may be required.
  21097. maxLength: 253
  21098. minLength: 1
  21099. pattern: ^[-._a-zA-Z0-9]+$
  21100. type: string
  21101. name:
  21102. description: The name of the Secret resource being referred to.
  21103. maxLength: 253
  21104. minLength: 1
  21105. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21106. type: string
  21107. namespace:
  21108. description: |-
  21109. The namespace of the Secret resource being referred to.
  21110. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21111. maxLength: 63
  21112. minLength: 1
  21113. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21114. type: string
  21115. type: object
  21116. required:
  21117. - path
  21118. - secretRef
  21119. type: object
  21120. cert:
  21121. description: |-
  21122. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  21123. Cert authentication method
  21124. properties:
  21125. clientCert:
  21126. description: |-
  21127. ClientCert is a certificate to authenticate using the Cert Vault
  21128. authentication method
  21129. properties:
  21130. key:
  21131. description: |-
  21132. A key in the referenced Secret.
  21133. Some instances of this field may be defaulted, in others it may be required.
  21134. maxLength: 253
  21135. minLength: 1
  21136. pattern: ^[-._a-zA-Z0-9]+$
  21137. type: string
  21138. name:
  21139. description: The name of the Secret resource being referred to.
  21140. maxLength: 253
  21141. minLength: 1
  21142. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21143. type: string
  21144. namespace:
  21145. description: |-
  21146. The namespace of the Secret resource being referred to.
  21147. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21148. maxLength: 63
  21149. minLength: 1
  21150. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21151. type: string
  21152. type: object
  21153. path:
  21154. default: cert
  21155. description: |-
  21156. Path where the Certificate authentication backend is mounted
  21157. in Vault, e.g: "cert"
  21158. type: string
  21159. secretRef:
  21160. description: |-
  21161. SecretRef to a key in a Secret resource containing client private key to
  21162. authenticate with Vault using the Cert authentication method
  21163. properties:
  21164. key:
  21165. description: |-
  21166. A key in the referenced Secret.
  21167. Some instances of this field may be defaulted, in others it may be required.
  21168. maxLength: 253
  21169. minLength: 1
  21170. pattern: ^[-._a-zA-Z0-9]+$
  21171. type: string
  21172. name:
  21173. description: The name of the Secret resource being referred to.
  21174. maxLength: 253
  21175. minLength: 1
  21176. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21177. type: string
  21178. namespace:
  21179. description: |-
  21180. The namespace of the Secret resource being referred to.
  21181. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21182. maxLength: 63
  21183. minLength: 1
  21184. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21185. type: string
  21186. type: object
  21187. vaultRole:
  21188. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  21189. type: string
  21190. type: object
  21191. gcp:
  21192. description: |-
  21193. Gcp authenticates with Vault using Google Cloud Platform authentication method
  21194. GCP authentication method
  21195. properties:
  21196. location:
  21197. description: Location optionally defines a location/region for the secret
  21198. type: string
  21199. path:
  21200. default: gcp
  21201. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  21202. type: string
  21203. projectID:
  21204. description: Project ID of the Google Cloud Platform project
  21205. type: string
  21206. role:
  21207. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  21208. type: string
  21209. secretRef:
  21210. description: Specify credentials in a Secret object
  21211. properties:
  21212. secretAccessKeySecretRef:
  21213. description: The SecretAccessKey is used for authentication
  21214. properties:
  21215. key:
  21216. description: |-
  21217. A key in the referenced Secret.
  21218. Some instances of this field may be defaulted, in others it may be required.
  21219. maxLength: 253
  21220. minLength: 1
  21221. pattern: ^[-._a-zA-Z0-9]+$
  21222. type: string
  21223. name:
  21224. description: The name of the Secret resource being referred to.
  21225. maxLength: 253
  21226. minLength: 1
  21227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21228. type: string
  21229. namespace:
  21230. description: |-
  21231. The namespace of the Secret resource being referred to.
  21232. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21233. maxLength: 63
  21234. minLength: 1
  21235. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21236. type: string
  21237. type: object
  21238. type: object
  21239. serviceAccountRef:
  21240. description: ServiceAccountRef to a service account for impersonation
  21241. properties:
  21242. audiences:
  21243. description: |-
  21244. Audience specifies the `aud` claim for the service account token
  21245. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21246. then this audiences will be appended to the list
  21247. items:
  21248. type: string
  21249. type: array
  21250. name:
  21251. description: The name of the ServiceAccount resource being referred to.
  21252. maxLength: 253
  21253. minLength: 1
  21254. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21255. type: string
  21256. namespace:
  21257. description: |-
  21258. Namespace of the resource being referred to.
  21259. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21260. maxLength: 63
  21261. minLength: 1
  21262. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21263. type: string
  21264. required:
  21265. - name
  21266. type: object
  21267. workloadIdentity:
  21268. description: Specify a service account with Workload Identity
  21269. properties:
  21270. clusterLocation:
  21271. description: |-
  21272. ClusterLocation is the location of the cluster
  21273. If not specified, it fetches information from the metadata server
  21274. type: string
  21275. clusterName:
  21276. description: |-
  21277. ClusterName is the name of the cluster
  21278. If not specified, it fetches information from the metadata server
  21279. type: string
  21280. clusterProjectID:
  21281. description: |-
  21282. ClusterProjectID is the project ID of the cluster
  21283. If not specified, it fetches information from the metadata server
  21284. type: string
  21285. serviceAccountRef:
  21286. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  21287. properties:
  21288. audiences:
  21289. description: |-
  21290. Audience specifies the `aud` claim for the service account token
  21291. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21292. then this audiences will be appended to the list
  21293. items:
  21294. type: string
  21295. type: array
  21296. name:
  21297. description: The name of the ServiceAccount resource being referred to.
  21298. maxLength: 253
  21299. minLength: 1
  21300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21301. type: string
  21302. namespace:
  21303. description: |-
  21304. Namespace of the resource being referred to.
  21305. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21306. maxLength: 63
  21307. minLength: 1
  21308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21309. type: string
  21310. required:
  21311. - name
  21312. type: object
  21313. required:
  21314. - serviceAccountRef
  21315. type: object
  21316. required:
  21317. - role
  21318. type: object
  21319. iam:
  21320. description: |-
  21321. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  21322. AWS IAM authentication method
  21323. properties:
  21324. externalID:
  21325. description: AWS External ID set on assumed IAM roles
  21326. type: string
  21327. jwt:
  21328. description: Specify a service account with IRSA enabled
  21329. properties:
  21330. serviceAccountRef:
  21331. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  21332. properties:
  21333. audiences:
  21334. description: |-
  21335. Audience specifies the `aud` claim for the service account token
  21336. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21337. then this audiences will be appended to the list
  21338. items:
  21339. type: string
  21340. type: array
  21341. name:
  21342. description: The name of the ServiceAccount resource being referred to.
  21343. maxLength: 253
  21344. minLength: 1
  21345. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21346. type: string
  21347. namespace:
  21348. description: |-
  21349. Namespace of the resource being referred to.
  21350. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21351. maxLength: 63
  21352. minLength: 1
  21353. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21354. type: string
  21355. required:
  21356. - name
  21357. type: object
  21358. type: object
  21359. path:
  21360. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  21361. type: string
  21362. region:
  21363. description: AWS region
  21364. type: string
  21365. role:
  21366. description: This is the AWS role to be assumed before talking to vault
  21367. type: string
  21368. secretRef:
  21369. description: Specify credentials in a Secret object
  21370. properties:
  21371. accessKeyIDSecretRef:
  21372. description: The AccessKeyID is used for authentication
  21373. properties:
  21374. key:
  21375. description: |-
  21376. A key in the referenced Secret.
  21377. Some instances of this field may be defaulted, in others it may be required.
  21378. maxLength: 253
  21379. minLength: 1
  21380. pattern: ^[-._a-zA-Z0-9]+$
  21381. type: string
  21382. name:
  21383. description: The name of the Secret resource being referred to.
  21384. maxLength: 253
  21385. minLength: 1
  21386. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21387. type: string
  21388. namespace:
  21389. description: |-
  21390. The namespace of the Secret resource being referred to.
  21391. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21392. maxLength: 63
  21393. minLength: 1
  21394. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21395. type: string
  21396. type: object
  21397. secretAccessKeySecretRef:
  21398. description: The SecretAccessKey is used for authentication
  21399. properties:
  21400. key:
  21401. description: |-
  21402. A key in the referenced Secret.
  21403. Some instances of this field may be defaulted, in others it may be required.
  21404. maxLength: 253
  21405. minLength: 1
  21406. pattern: ^[-._a-zA-Z0-9]+$
  21407. type: string
  21408. name:
  21409. description: The name of the Secret resource being referred to.
  21410. maxLength: 253
  21411. minLength: 1
  21412. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21413. type: string
  21414. namespace:
  21415. description: |-
  21416. The namespace of the Secret resource being referred to.
  21417. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21418. maxLength: 63
  21419. minLength: 1
  21420. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21421. type: string
  21422. type: object
  21423. sessionTokenSecretRef:
  21424. description: |-
  21425. The SessionToken used for authentication
  21426. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  21427. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  21428. properties:
  21429. key:
  21430. description: |-
  21431. A key in the referenced Secret.
  21432. Some instances of this field may be defaulted, in others it may be required.
  21433. maxLength: 253
  21434. minLength: 1
  21435. pattern: ^[-._a-zA-Z0-9]+$
  21436. type: string
  21437. name:
  21438. description: The name of the Secret resource being referred to.
  21439. maxLength: 253
  21440. minLength: 1
  21441. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21442. type: string
  21443. namespace:
  21444. description: |-
  21445. The namespace of the Secret resource being referred to.
  21446. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21447. maxLength: 63
  21448. minLength: 1
  21449. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21450. type: string
  21451. type: object
  21452. type: object
  21453. vaultAwsIamServerID:
  21454. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  21455. type: string
  21456. vaultRole:
  21457. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  21458. type: string
  21459. required:
  21460. - vaultRole
  21461. type: object
  21462. jwt:
  21463. description: |-
  21464. Jwt authenticates with Vault by passing role and JWT token using the
  21465. JWT/OIDC authentication method
  21466. properties:
  21467. kubernetesServiceAccountToken:
  21468. description: |-
  21469. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  21470. a token for with the `TokenRequest` API.
  21471. properties:
  21472. audiences:
  21473. description: |-
  21474. Optional audiences field that will be used to request a temporary Kubernetes service
  21475. account token for the service account referenced by `serviceAccountRef`.
  21476. Defaults to a single audience `vault` it not specified.
  21477. Deprecated: use serviceAccountRef.Audiences instead
  21478. items:
  21479. type: string
  21480. type: array
  21481. expirationSeconds:
  21482. description: |-
  21483. Optional expiration time in seconds that will be used to request a temporary
  21484. Kubernetes service account token for the service account referenced by
  21485. `serviceAccountRef`.
  21486. Deprecated: this will be removed in the future.
  21487. Defaults to 10 minutes.
  21488. format: int64
  21489. type: integer
  21490. serviceAccountRef:
  21491. description: Service account field containing the name of a kubernetes ServiceAccount.
  21492. properties:
  21493. audiences:
  21494. description: |-
  21495. Audience specifies the `aud` claim for the service account token
  21496. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21497. then this audiences will be appended to the list
  21498. items:
  21499. type: string
  21500. type: array
  21501. name:
  21502. description: The name of the ServiceAccount resource being referred to.
  21503. maxLength: 253
  21504. minLength: 1
  21505. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21506. type: string
  21507. namespace:
  21508. description: |-
  21509. Namespace of the resource being referred to.
  21510. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21511. maxLength: 63
  21512. minLength: 1
  21513. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21514. type: string
  21515. required:
  21516. - name
  21517. type: object
  21518. required:
  21519. - serviceAccountRef
  21520. type: object
  21521. path:
  21522. default: jwt
  21523. description: |-
  21524. Path where the JWT authentication backend is mounted
  21525. in Vault, e.g: "jwt"
  21526. type: string
  21527. role:
  21528. description: |-
  21529. Role is a JWT role to authenticate using the JWT/OIDC Vault
  21530. authentication method
  21531. type: string
  21532. secretRef:
  21533. description: |-
  21534. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  21535. authenticate with Vault using the JWT/OIDC authentication method.
  21536. properties:
  21537. key:
  21538. description: |-
  21539. A key in the referenced Secret.
  21540. Some instances of this field may be defaulted, in others it may be required.
  21541. maxLength: 253
  21542. minLength: 1
  21543. pattern: ^[-._a-zA-Z0-9]+$
  21544. type: string
  21545. name:
  21546. description: The name of the Secret resource being referred to.
  21547. maxLength: 253
  21548. minLength: 1
  21549. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21550. type: string
  21551. namespace:
  21552. description: |-
  21553. The namespace of the Secret resource being referred to.
  21554. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21555. maxLength: 63
  21556. minLength: 1
  21557. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21558. type: string
  21559. type: object
  21560. required:
  21561. - path
  21562. type: object
  21563. kubernetes:
  21564. description: |-
  21565. Kubernetes authenticates with Vault by passing the ServiceAccount
  21566. token stored in the named Secret resource to the Vault server.
  21567. properties:
  21568. mountPath:
  21569. default: kubernetes
  21570. description: |-
  21571. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  21572. "kubernetes"
  21573. type: string
  21574. role:
  21575. description: |-
  21576. A required field containing the Vault Role to assume. A Role binds a
  21577. Kubernetes ServiceAccount with a set of Vault policies.
  21578. type: string
  21579. secretRef:
  21580. description: |-
  21581. Optional secret field containing a Kubernetes ServiceAccount JWT used
  21582. for authenticating with Vault. If a name is specified without a key,
  21583. `token` is the default. If one is not specified, the one bound to
  21584. the controller will be used.
  21585. properties:
  21586. key:
  21587. description: |-
  21588. A key in the referenced Secret.
  21589. Some instances of this field may be defaulted, in others it may be required.
  21590. maxLength: 253
  21591. minLength: 1
  21592. pattern: ^[-._a-zA-Z0-9]+$
  21593. type: string
  21594. name:
  21595. description: The name of the Secret resource being referred to.
  21596. maxLength: 253
  21597. minLength: 1
  21598. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21599. type: string
  21600. namespace:
  21601. description: |-
  21602. The namespace of the Secret resource being referred to.
  21603. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21604. maxLength: 63
  21605. minLength: 1
  21606. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21607. type: string
  21608. type: object
  21609. serviceAccountRef:
  21610. description: |-
  21611. Optional service account field containing the name of a kubernetes ServiceAccount.
  21612. If the service account is specified, the service account secret token JWT will be used
  21613. for authenticating with Vault. If the service account selector is not supplied,
  21614. the secretRef will be used instead.
  21615. properties:
  21616. audiences:
  21617. description: |-
  21618. Audience specifies the `aud` claim for the service account token
  21619. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21620. then this audiences will be appended to the list
  21621. items:
  21622. type: string
  21623. type: array
  21624. name:
  21625. description: The name of the ServiceAccount resource being referred to.
  21626. maxLength: 253
  21627. minLength: 1
  21628. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21629. type: string
  21630. namespace:
  21631. description: |-
  21632. Namespace of the resource being referred to.
  21633. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21634. maxLength: 63
  21635. minLength: 1
  21636. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21637. type: string
  21638. required:
  21639. - name
  21640. type: object
  21641. required:
  21642. - mountPath
  21643. - role
  21644. type: object
  21645. ldap:
  21646. description: |-
  21647. Ldap authenticates with Vault by passing username/password pair using
  21648. the LDAP authentication method
  21649. properties:
  21650. path:
  21651. default: ldap
  21652. description: |-
  21653. Path where the LDAP authentication backend is mounted
  21654. in Vault, e.g: "ldap"
  21655. type: string
  21656. secretRef:
  21657. description: |-
  21658. SecretRef to a key in a Secret resource containing password for the LDAP
  21659. user used to authenticate with Vault using the LDAP authentication
  21660. method
  21661. properties:
  21662. key:
  21663. description: |-
  21664. A key in the referenced Secret.
  21665. Some instances of this field may be defaulted, in others it may be required.
  21666. maxLength: 253
  21667. minLength: 1
  21668. pattern: ^[-._a-zA-Z0-9]+$
  21669. type: string
  21670. name:
  21671. description: The name of the Secret resource being referred to.
  21672. maxLength: 253
  21673. minLength: 1
  21674. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21675. type: string
  21676. namespace:
  21677. description: |-
  21678. The namespace of the Secret resource being referred to.
  21679. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21680. maxLength: 63
  21681. minLength: 1
  21682. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21683. type: string
  21684. type: object
  21685. username:
  21686. description: |-
  21687. Username is an LDAP username used to authenticate using the LDAP Vault
  21688. authentication method
  21689. type: string
  21690. required:
  21691. - path
  21692. - username
  21693. type: object
  21694. namespace:
  21695. description: |-
  21696. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  21697. Namespaces is a set of features within Vault Enterprise that allows
  21698. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  21699. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  21700. This will default to Vault.Namespace field if set, or empty otherwise
  21701. type: string
  21702. tokenSecretRef:
  21703. description: TokenSecretRef authenticates with Vault by presenting a token.
  21704. properties:
  21705. key:
  21706. description: |-
  21707. A key in the referenced Secret.
  21708. Some instances of this field may be defaulted, in others it may be required.
  21709. maxLength: 253
  21710. minLength: 1
  21711. pattern: ^[-._a-zA-Z0-9]+$
  21712. type: string
  21713. name:
  21714. description: The name of the Secret resource being referred to.
  21715. maxLength: 253
  21716. minLength: 1
  21717. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21718. type: string
  21719. namespace:
  21720. description: |-
  21721. The namespace of the Secret resource being referred to.
  21722. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21723. maxLength: 63
  21724. minLength: 1
  21725. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21726. type: string
  21727. type: object
  21728. userPass:
  21729. description: UserPass authenticates with Vault by passing username/password pair
  21730. properties:
  21731. path:
  21732. default: userpass
  21733. description: |-
  21734. Path where the UserPassword authentication backend is mounted
  21735. in Vault, e.g: "userpass"
  21736. type: string
  21737. secretRef:
  21738. description: |-
  21739. SecretRef to a key in a Secret resource containing password for the
  21740. user used to authenticate with Vault using the UserPass authentication
  21741. method
  21742. properties:
  21743. key:
  21744. description: |-
  21745. A key in the referenced Secret.
  21746. Some instances of this field may be defaulted, in others it may be required.
  21747. maxLength: 253
  21748. minLength: 1
  21749. pattern: ^[-._a-zA-Z0-9]+$
  21750. type: string
  21751. name:
  21752. description: The name of the Secret resource being referred to.
  21753. maxLength: 253
  21754. minLength: 1
  21755. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21756. type: string
  21757. namespace:
  21758. description: |-
  21759. The namespace of the Secret resource being referred to.
  21760. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21761. maxLength: 63
  21762. minLength: 1
  21763. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21764. type: string
  21765. type: object
  21766. username:
  21767. description: |-
  21768. Username is a username used to authenticate using the UserPass Vault
  21769. authentication method
  21770. type: string
  21771. required:
  21772. - path
  21773. - username
  21774. type: object
  21775. type: object
  21776. caBundle:
  21777. description: |-
  21778. PEM encoded CA bundle used to validate Vault server certificate. Only used
  21779. if the Server URL is using HTTPS protocol. This parameter is ignored for
  21780. plain HTTP protocol connection. If not set the system root certificates
  21781. are used to validate the TLS connection.
  21782. format: byte
  21783. type: string
  21784. caProvider:
  21785. description: The provider for the CA bundle to use to validate Vault server certificate.
  21786. properties:
  21787. key:
  21788. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  21789. maxLength: 253
  21790. minLength: 1
  21791. pattern: ^[-._a-zA-Z0-9]+$
  21792. type: string
  21793. name:
  21794. description: The name of the object located at the provider type.
  21795. maxLength: 253
  21796. minLength: 1
  21797. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21798. type: string
  21799. namespace:
  21800. description: |-
  21801. The namespace the Provider type is in.
  21802. Can only be defined when used in a ClusterSecretStore.
  21803. maxLength: 63
  21804. minLength: 1
  21805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21806. type: string
  21807. type:
  21808. description: The type of provider to use such as "Secret", or "ConfigMap".
  21809. enum:
  21810. - Secret
  21811. - ConfigMap
  21812. type: string
  21813. required:
  21814. - name
  21815. - type
  21816. type: object
  21817. checkAndSet:
  21818. description: |-
  21819. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  21820. Only applies to Vault KV v2 stores. When enabled, write operations must include
  21821. the current version of the secret to prevent unintentional overwrites.
  21822. properties:
  21823. required:
  21824. description: |-
  21825. Required when true, all write operations must include a check-and-set parameter.
  21826. This helps prevent unintentional overwrites of secrets.
  21827. type: boolean
  21828. type: object
  21829. forwardInconsistent:
  21830. description: |-
  21831. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  21832. leader instead of simply retrying within a loop. This can increase performance if
  21833. the option is enabled serverside.
  21834. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  21835. type: boolean
  21836. headers:
  21837. additionalProperties:
  21838. type: string
  21839. description: Headers to be added in Vault request
  21840. type: object
  21841. namespace:
  21842. description: |-
  21843. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  21844. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  21845. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  21846. type: string
  21847. path:
  21848. description: |-
  21849. Path is the mount path of the Vault KV backend endpoint, e.g:
  21850. "secret". The v2 KV secret engine version specific "/data" path suffix
  21851. for fetching secrets from Vault is optional and will be appended
  21852. if not present in specified path.
  21853. type: string
  21854. readYourWrites:
  21855. description: |-
  21856. ReadYourWrites ensures isolated read-after-write semantics by
  21857. providing discovered cluster replication states in each request.
  21858. More information about eventual consistency in Vault can be found here
  21859. https://www.vaultproject.io/docs/enterprise/consistency
  21860. type: boolean
  21861. server:
  21862. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  21863. type: string
  21864. tls:
  21865. description: |-
  21866. The configuration used for client side related TLS communication, when the Vault server
  21867. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  21868. This parameter is ignored for plain HTTP protocol connection.
  21869. It's worth noting this configuration is different from the "TLS certificates auth method",
  21870. which is available under the `auth.cert` section.
  21871. properties:
  21872. certSecretRef:
  21873. description: |-
  21874. CertSecretRef is a certificate added to the transport layer
  21875. when communicating with the Vault server.
  21876. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  21877. properties:
  21878. key:
  21879. description: |-
  21880. A key in the referenced Secret.
  21881. Some instances of this field may be defaulted, in others it may be required.
  21882. maxLength: 253
  21883. minLength: 1
  21884. pattern: ^[-._a-zA-Z0-9]+$
  21885. type: string
  21886. name:
  21887. description: The name of the Secret resource being referred to.
  21888. maxLength: 253
  21889. minLength: 1
  21890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21891. type: string
  21892. namespace:
  21893. description: |-
  21894. The namespace of the Secret resource being referred to.
  21895. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21896. maxLength: 63
  21897. minLength: 1
  21898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21899. type: string
  21900. type: object
  21901. keySecretRef:
  21902. description: |-
  21903. KeySecretRef to a key in a Secret resource containing client private key
  21904. added to the transport layer when communicating with the Vault server.
  21905. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  21906. properties:
  21907. key:
  21908. description: |-
  21909. A key in the referenced Secret.
  21910. Some instances of this field may be defaulted, in others it may be required.
  21911. maxLength: 253
  21912. minLength: 1
  21913. pattern: ^[-._a-zA-Z0-9]+$
  21914. type: string
  21915. name:
  21916. description: The name of the Secret resource being referred to.
  21917. maxLength: 253
  21918. minLength: 1
  21919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21920. type: string
  21921. namespace:
  21922. description: |-
  21923. The namespace of the Secret resource being referred to.
  21924. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21925. maxLength: 63
  21926. minLength: 1
  21927. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21928. type: string
  21929. type: object
  21930. type: object
  21931. version:
  21932. default: v2
  21933. description: |-
  21934. Version is the Vault KV secret engine version. This can be either "v1" or
  21935. "v2". Version defaults to "v2".
  21936. enum:
  21937. - v1
  21938. - v2
  21939. type: string
  21940. required:
  21941. - server
  21942. type: object
  21943. volcengine:
  21944. description: Volcengine configures this store to sync secrets using the Volcengine provider
  21945. properties:
  21946. auth:
  21947. description: |-
  21948. Auth defines the authentication method to use.
  21949. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  21950. properties:
  21951. secretRef:
  21952. description: |-
  21953. SecretRef defines the static credentials to use for authentication.
  21954. If not set, IRSA is used.
  21955. properties:
  21956. accessKeyID:
  21957. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  21958. properties:
  21959. key:
  21960. description: |-
  21961. A key in the referenced Secret.
  21962. Some instances of this field may be defaulted, in others it may be required.
  21963. maxLength: 253
  21964. minLength: 1
  21965. pattern: ^[-._a-zA-Z0-9]+$
  21966. type: string
  21967. name:
  21968. description: The name of the Secret resource being referred to.
  21969. maxLength: 253
  21970. minLength: 1
  21971. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21972. type: string
  21973. namespace:
  21974. description: |-
  21975. The namespace of the Secret resource being referred to.
  21976. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21977. maxLength: 63
  21978. minLength: 1
  21979. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21980. type: string
  21981. type: object
  21982. secretAccessKey:
  21983. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  21984. properties:
  21985. key:
  21986. description: |-
  21987. A key in the referenced Secret.
  21988. Some instances of this field may be defaulted, in others it may be required.
  21989. maxLength: 253
  21990. minLength: 1
  21991. pattern: ^[-._a-zA-Z0-9]+$
  21992. type: string
  21993. name:
  21994. description: The name of the Secret resource being referred to.
  21995. maxLength: 253
  21996. minLength: 1
  21997. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21998. type: string
  21999. namespace:
  22000. description: |-
  22001. The namespace of the Secret resource being referred to.
  22002. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22003. maxLength: 63
  22004. minLength: 1
  22005. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22006. type: string
  22007. type: object
  22008. token:
  22009. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  22010. properties:
  22011. key:
  22012. description: |-
  22013. A key in the referenced Secret.
  22014. Some instances of this field may be defaulted, in others it may be required.
  22015. maxLength: 253
  22016. minLength: 1
  22017. pattern: ^[-._a-zA-Z0-9]+$
  22018. type: string
  22019. name:
  22020. description: The name of the Secret resource being referred to.
  22021. maxLength: 253
  22022. minLength: 1
  22023. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22024. type: string
  22025. namespace:
  22026. description: |-
  22027. The namespace of the Secret resource being referred to.
  22028. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22029. maxLength: 63
  22030. minLength: 1
  22031. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22032. type: string
  22033. type: object
  22034. required:
  22035. - accessKeyID
  22036. - secretAccessKey
  22037. type: object
  22038. type: object
  22039. region:
  22040. description: Region specifies the Volcengine region to connect to.
  22041. type: string
  22042. required:
  22043. - region
  22044. type: object
  22045. webhook:
  22046. description: Webhook configures this store to sync secrets using a generic templated webhook
  22047. properties:
  22048. auth:
  22049. description: Auth specifies a authorization protocol. Only one protocol may be set.
  22050. maxProperties: 1
  22051. minProperties: 1
  22052. properties:
  22053. ntlm:
  22054. description: NTLMProtocol configures the store to use NTLM for auth
  22055. properties:
  22056. passwordSecret:
  22057. description: |-
  22058. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22059. In some instances, `key` is a required field.
  22060. properties:
  22061. key:
  22062. description: |-
  22063. A key in the referenced Secret.
  22064. Some instances of this field may be defaulted, in others it may be required.
  22065. maxLength: 253
  22066. minLength: 1
  22067. pattern: ^[-._a-zA-Z0-9]+$
  22068. type: string
  22069. name:
  22070. description: The name of the Secret resource being referred to.
  22071. maxLength: 253
  22072. minLength: 1
  22073. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22074. type: string
  22075. namespace:
  22076. description: |-
  22077. The namespace of the Secret resource being referred to.
  22078. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22079. maxLength: 63
  22080. minLength: 1
  22081. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22082. type: string
  22083. type: object
  22084. usernameSecret:
  22085. description: |-
  22086. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22087. In some instances, `key` is a required field.
  22088. properties:
  22089. key:
  22090. description: |-
  22091. A key in the referenced Secret.
  22092. Some instances of this field may be defaulted, in others it may be required.
  22093. maxLength: 253
  22094. minLength: 1
  22095. pattern: ^[-._a-zA-Z0-9]+$
  22096. type: string
  22097. name:
  22098. description: The name of the Secret resource being referred to.
  22099. maxLength: 253
  22100. minLength: 1
  22101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22102. type: string
  22103. namespace:
  22104. description: |-
  22105. The namespace of the Secret resource being referred to.
  22106. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22107. maxLength: 63
  22108. minLength: 1
  22109. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22110. type: string
  22111. type: object
  22112. required:
  22113. - passwordSecret
  22114. - usernameSecret
  22115. type: object
  22116. type: object
  22117. body:
  22118. description: Body
  22119. type: string
  22120. caBundle:
  22121. description: |-
  22122. PEM encoded CA bundle used to validate webhook server certificate. Only used
  22123. if the Server URL is using HTTPS protocol. This parameter is ignored for
  22124. plain HTTP protocol connection. If not set the system root certificates
  22125. are used to validate the TLS connection.
  22126. format: byte
  22127. type: string
  22128. caProvider:
  22129. description: The provider for the CA bundle to use to validate webhook server certificate.
  22130. properties:
  22131. key:
  22132. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22133. maxLength: 253
  22134. minLength: 1
  22135. pattern: ^[-._a-zA-Z0-9]+$
  22136. type: string
  22137. name:
  22138. description: The name of the object located at the provider type.
  22139. maxLength: 253
  22140. minLength: 1
  22141. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22142. type: string
  22143. namespace:
  22144. description: The namespace the Provider type is in.
  22145. maxLength: 63
  22146. minLength: 1
  22147. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22148. type: string
  22149. type:
  22150. description: The type of provider to use such as "Secret", or "ConfigMap".
  22151. enum:
  22152. - Secret
  22153. - ConfigMap
  22154. type: string
  22155. required:
  22156. - name
  22157. - type
  22158. type: object
  22159. headers:
  22160. additionalProperties:
  22161. type: string
  22162. description: Headers
  22163. type: object
  22164. method:
  22165. description: Webhook Method
  22166. type: string
  22167. result:
  22168. description: Result formatting
  22169. properties:
  22170. jsonPath:
  22171. description: Json path of return value
  22172. type: string
  22173. type: object
  22174. secrets:
  22175. description: |-
  22176. Secrets to fill in templates
  22177. These secrets will be passed to the templating function as key value pairs under the given name
  22178. items:
  22179. description: WebhookSecret defines a secret that will be passed to the webhook request.
  22180. properties:
  22181. name:
  22182. description: Name of this secret in templates
  22183. type: string
  22184. secretRef:
  22185. description: Secret ref to fill in credentials
  22186. properties:
  22187. key:
  22188. description: |-
  22189. A key in the referenced Secret.
  22190. Some instances of this field may be defaulted, in others it may be required.
  22191. maxLength: 253
  22192. minLength: 1
  22193. pattern: ^[-._a-zA-Z0-9]+$
  22194. type: string
  22195. name:
  22196. description: The name of the Secret resource being referred to.
  22197. maxLength: 253
  22198. minLength: 1
  22199. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22200. type: string
  22201. namespace:
  22202. description: |-
  22203. The namespace of the Secret resource being referred to.
  22204. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22205. maxLength: 63
  22206. minLength: 1
  22207. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22208. type: string
  22209. type: object
  22210. required:
  22211. - name
  22212. - secretRef
  22213. type: object
  22214. type: array
  22215. timeout:
  22216. description: Timeout
  22217. type: string
  22218. url:
  22219. description: Webhook url to call
  22220. type: string
  22221. required:
  22222. - url
  22223. type: object
  22224. yandexcertificatemanager:
  22225. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  22226. properties:
  22227. apiEndpoint:
  22228. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  22229. type: string
  22230. auth:
  22231. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  22232. properties:
  22233. authorizedKeySecretRef:
  22234. description: The authorized key used for authentication
  22235. properties:
  22236. key:
  22237. description: |-
  22238. A key in the referenced Secret.
  22239. Some instances of this field may be defaulted, in others it may be required.
  22240. maxLength: 253
  22241. minLength: 1
  22242. pattern: ^[-._a-zA-Z0-9]+$
  22243. type: string
  22244. name:
  22245. description: The name of the Secret resource being referred to.
  22246. maxLength: 253
  22247. minLength: 1
  22248. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22249. type: string
  22250. namespace:
  22251. description: |-
  22252. The namespace of the Secret resource being referred to.
  22253. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22254. maxLength: 63
  22255. minLength: 1
  22256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22257. type: string
  22258. type: object
  22259. type: object
  22260. caProvider:
  22261. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  22262. properties:
  22263. certSecretRef:
  22264. description: |-
  22265. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22266. In some instances, `key` is a required field.
  22267. properties:
  22268. key:
  22269. description: |-
  22270. A key in the referenced Secret.
  22271. Some instances of this field may be defaulted, in others it may be required.
  22272. maxLength: 253
  22273. minLength: 1
  22274. pattern: ^[-._a-zA-Z0-9]+$
  22275. type: string
  22276. name:
  22277. description: The name of the Secret resource being referred to.
  22278. maxLength: 253
  22279. minLength: 1
  22280. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22281. type: string
  22282. namespace:
  22283. description: |-
  22284. The namespace of the Secret resource being referred to.
  22285. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22286. maxLength: 63
  22287. minLength: 1
  22288. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22289. type: string
  22290. type: object
  22291. type: object
  22292. fetching:
  22293. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  22294. maxProperties: 1
  22295. minProperties: 1
  22296. properties:
  22297. byID:
  22298. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  22299. type: object
  22300. byName:
  22301. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  22302. properties:
  22303. folderID:
  22304. description: The folder to fetch secrets from
  22305. type: string
  22306. required:
  22307. - folderID
  22308. type: object
  22309. type: object
  22310. required:
  22311. - auth
  22312. type: object
  22313. yandexlockbox:
  22314. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  22315. properties:
  22316. apiEndpoint:
  22317. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  22318. type: string
  22319. auth:
  22320. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  22321. properties:
  22322. authorizedKeySecretRef:
  22323. description: The authorized key used for authentication
  22324. properties:
  22325. key:
  22326. description: |-
  22327. A key in the referenced Secret.
  22328. Some instances of this field may be defaulted, in others it may be required.
  22329. maxLength: 253
  22330. minLength: 1
  22331. pattern: ^[-._a-zA-Z0-9]+$
  22332. type: string
  22333. name:
  22334. description: The name of the Secret resource being referred to.
  22335. maxLength: 253
  22336. minLength: 1
  22337. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22338. type: string
  22339. namespace:
  22340. description: |-
  22341. The namespace of the Secret resource being referred to.
  22342. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22343. maxLength: 63
  22344. minLength: 1
  22345. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22346. type: string
  22347. type: object
  22348. type: object
  22349. caProvider:
  22350. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  22351. properties:
  22352. certSecretRef:
  22353. description: |-
  22354. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22355. In some instances, `key` is a required field.
  22356. properties:
  22357. key:
  22358. description: |-
  22359. A key in the referenced Secret.
  22360. Some instances of this field may be defaulted, in others it may be required.
  22361. maxLength: 253
  22362. minLength: 1
  22363. pattern: ^[-._a-zA-Z0-9]+$
  22364. type: string
  22365. name:
  22366. description: The name of the Secret resource being referred to.
  22367. maxLength: 253
  22368. minLength: 1
  22369. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22370. type: string
  22371. namespace:
  22372. description: |-
  22373. The namespace of the Secret resource being referred to.
  22374. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22375. maxLength: 63
  22376. minLength: 1
  22377. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22378. type: string
  22379. type: object
  22380. type: object
  22381. fetching:
  22382. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  22383. maxProperties: 1
  22384. minProperties: 1
  22385. properties:
  22386. byID:
  22387. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  22388. type: object
  22389. byName:
  22390. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  22391. properties:
  22392. folderID:
  22393. description: The folder to fetch secrets from
  22394. type: string
  22395. required:
  22396. - folderID
  22397. type: object
  22398. type: object
  22399. required:
  22400. - auth
  22401. type: object
  22402. type: object
  22403. refreshInterval:
  22404. anyOf:
  22405. - type: integer
  22406. - type: string
  22407. description: |-
  22408. Used to configure store refresh interval. Accepts either an integer number
  22409. of seconds (legacy) or a Go duration string such as "1h" or "5m". Empty or
  22410. 0 will default to the controller config.
  22411. x-kubernetes-int-or-string: true
  22412. retrySettings:
  22413. description: Used to configure HTTP retries on failures.
  22414. properties:
  22415. maxRetries:
  22416. format: int32
  22417. type: integer
  22418. retryInterval:
  22419. type: string
  22420. type: object
  22421. required:
  22422. - provider
  22423. type: object
  22424. status:
  22425. description: SecretStoreStatus defines the observed state of the SecretStore.
  22426. properties:
  22427. capabilities:
  22428. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  22429. type: string
  22430. conditions:
  22431. items:
  22432. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  22433. properties:
  22434. lastTransitionTime:
  22435. format: date-time
  22436. type: string
  22437. message:
  22438. type: string
  22439. reason:
  22440. type: string
  22441. status:
  22442. type: string
  22443. type:
  22444. description: SecretStoreConditionType represents the condition of the SecretStore.
  22445. type: string
  22446. required:
  22447. - status
  22448. - type
  22449. type: object
  22450. type: array
  22451. type: object
  22452. type: object
  22453. served: true
  22454. storage: true
  22455. subresources:
  22456. status: {}
  22457. - additionalPrinterColumns:
  22458. - jsonPath: .metadata.creationTimestamp
  22459. name: AGE
  22460. type: date
  22461. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  22462. name: Status
  22463. type: string
  22464. - jsonPath: .status.capabilities
  22465. name: Capabilities
  22466. type: string
  22467. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  22468. name: Ready
  22469. type: string
  22470. deprecated: true
  22471. name: v1beta1
  22472. schema:
  22473. openAPIV3Schema:
  22474. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  22475. properties:
  22476. apiVersion:
  22477. description: |-
  22478. APIVersion defines the versioned schema of this representation of an object.
  22479. Servers should convert recognized schemas to the latest internal value, and
  22480. may reject unrecognized values.
  22481. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  22482. type: string
  22483. kind:
  22484. description: |-
  22485. Kind is a string value representing the REST resource this object represents.
  22486. Servers may infer this from the endpoint the client submits requests to.
  22487. Cannot be updated.
  22488. In CamelCase.
  22489. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  22490. type: string
  22491. metadata:
  22492. type: object
  22493. spec:
  22494. description: SecretStoreSpec defines the desired state of SecretStore.
  22495. properties:
  22496. conditions:
  22497. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  22498. items:
  22499. description: |-
  22500. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  22501. for a ClusterSecretStore instance.
  22502. properties:
  22503. namespaceRegexes:
  22504. description: Choose namespaces by using regex matching
  22505. items:
  22506. type: string
  22507. type: array
  22508. namespaceSelector:
  22509. description: Choose namespace using a labelSelector
  22510. properties:
  22511. matchExpressions:
  22512. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  22513. items:
  22514. description: |-
  22515. A label selector requirement is a selector that contains values, a key, and an operator that
  22516. relates the key and values.
  22517. properties:
  22518. key:
  22519. description: key is the label key that the selector applies to.
  22520. type: string
  22521. operator:
  22522. description: |-
  22523. operator represents a key's relationship to a set of values.
  22524. Valid operators are In, NotIn, Exists and DoesNotExist.
  22525. type: string
  22526. values:
  22527. description: |-
  22528. values is an array of string values. If the operator is In or NotIn,
  22529. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  22530. the values array must be empty. This array is replaced during a strategic
  22531. merge patch.
  22532. items:
  22533. type: string
  22534. type: array
  22535. x-kubernetes-list-type: atomic
  22536. required:
  22537. - key
  22538. - operator
  22539. type: object
  22540. type: array
  22541. x-kubernetes-list-type: atomic
  22542. matchLabels:
  22543. additionalProperties:
  22544. type: string
  22545. description: |-
  22546. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  22547. map is equivalent to an element of matchExpressions, whose key field is "key", the
  22548. operator is "In", and the values array contains only "value". The requirements are ANDed.
  22549. type: object
  22550. type: object
  22551. x-kubernetes-map-type: atomic
  22552. namespaces:
  22553. description: Choose namespaces by name
  22554. items:
  22555. maxLength: 63
  22556. minLength: 1
  22557. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22558. type: string
  22559. type: array
  22560. type: object
  22561. type: array
  22562. controller:
  22563. description: |-
  22564. Used to select the correct ESO controller (think: ingress.ingressClassName)
  22565. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  22566. type: string
  22567. provider:
  22568. description: Used to configure the provider. Only one provider may be set
  22569. maxProperties: 1
  22570. minProperties: 1
  22571. properties:
  22572. akeyless:
  22573. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  22574. properties:
  22575. akeylessGWApiURL:
  22576. description: Akeyless GW API Url from which the secrets to be fetched from.
  22577. type: string
  22578. authSecretRef:
  22579. description: Auth configures how the operator authenticates with Akeyless.
  22580. properties:
  22581. kubernetesAuth:
  22582. description: |-
  22583. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  22584. token stored in the named Secret resource.
  22585. properties:
  22586. accessID:
  22587. description: the Akeyless Kubernetes auth-method access-id
  22588. type: string
  22589. k8sConfName:
  22590. description: Kubernetes-auth configuration name in Akeyless-Gateway
  22591. type: string
  22592. secretRef:
  22593. description: |-
  22594. Optional secret field containing a Kubernetes ServiceAccount JWT used
  22595. for authenticating with Akeyless. If a name is specified without a key,
  22596. `token` is the default. If one is not specified, the one bound to
  22597. the controller will be used.
  22598. properties:
  22599. key:
  22600. description: |-
  22601. A key in the referenced Secret.
  22602. Some instances of this field may be defaulted, in others it may be required.
  22603. maxLength: 253
  22604. minLength: 1
  22605. pattern: ^[-._a-zA-Z0-9]+$
  22606. type: string
  22607. name:
  22608. description: The name of the Secret resource being referred to.
  22609. maxLength: 253
  22610. minLength: 1
  22611. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22612. type: string
  22613. namespace:
  22614. description: |-
  22615. The namespace of the Secret resource being referred to.
  22616. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22617. maxLength: 63
  22618. minLength: 1
  22619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22620. type: string
  22621. type: object
  22622. serviceAccountRef:
  22623. description: |-
  22624. Optional service account field containing the name of a kubernetes ServiceAccount.
  22625. If the service account is specified, the service account secret token JWT will be used
  22626. for authenticating with Akeyless. If the service account selector is not supplied,
  22627. the secretRef will be used instead.
  22628. properties:
  22629. audiences:
  22630. description: |-
  22631. Audience specifies the `aud` claim for the service account token
  22632. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  22633. then this audiences will be appended to the list
  22634. items:
  22635. type: string
  22636. type: array
  22637. name:
  22638. description: The name of the ServiceAccount resource being referred to.
  22639. maxLength: 253
  22640. minLength: 1
  22641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22642. type: string
  22643. namespace:
  22644. description: |-
  22645. Namespace of the resource being referred to.
  22646. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22647. maxLength: 63
  22648. minLength: 1
  22649. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22650. type: string
  22651. required:
  22652. - name
  22653. type: object
  22654. required:
  22655. - accessID
  22656. - k8sConfName
  22657. type: object
  22658. secretRef:
  22659. description: |-
  22660. Reference to a Secret that contains the details
  22661. to authenticate with Akeyless.
  22662. properties:
  22663. accessID:
  22664. description: The SecretAccessID is used for authentication
  22665. properties:
  22666. key:
  22667. description: |-
  22668. A key in the referenced Secret.
  22669. Some instances of this field may be defaulted, in others it may be required.
  22670. maxLength: 253
  22671. minLength: 1
  22672. pattern: ^[-._a-zA-Z0-9]+$
  22673. type: string
  22674. name:
  22675. description: The name of the Secret resource being referred to.
  22676. maxLength: 253
  22677. minLength: 1
  22678. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22679. type: string
  22680. namespace:
  22681. description: |-
  22682. The namespace of the Secret resource being referred to.
  22683. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22684. maxLength: 63
  22685. minLength: 1
  22686. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22687. type: string
  22688. type: object
  22689. accessType:
  22690. description: |-
  22691. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22692. In some instances, `key` is a required field.
  22693. properties:
  22694. key:
  22695. description: |-
  22696. A key in the referenced Secret.
  22697. Some instances of this field may be defaulted, in others it may be required.
  22698. maxLength: 253
  22699. minLength: 1
  22700. pattern: ^[-._a-zA-Z0-9]+$
  22701. type: string
  22702. name:
  22703. description: The name of the Secret resource being referred to.
  22704. maxLength: 253
  22705. minLength: 1
  22706. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22707. type: string
  22708. namespace:
  22709. description: |-
  22710. The namespace of the Secret resource being referred to.
  22711. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22712. maxLength: 63
  22713. minLength: 1
  22714. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22715. type: string
  22716. type: object
  22717. accessTypeParam:
  22718. description: |-
  22719. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22720. In some instances, `key` is a required field.
  22721. properties:
  22722. key:
  22723. description: |-
  22724. A key in the referenced Secret.
  22725. Some instances of this field may be defaulted, in others it may be required.
  22726. maxLength: 253
  22727. minLength: 1
  22728. pattern: ^[-._a-zA-Z0-9]+$
  22729. type: string
  22730. name:
  22731. description: The name of the Secret resource being referred to.
  22732. maxLength: 253
  22733. minLength: 1
  22734. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22735. type: string
  22736. namespace:
  22737. description: |-
  22738. The namespace of the Secret resource being referred to.
  22739. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22740. maxLength: 63
  22741. minLength: 1
  22742. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22743. type: string
  22744. type: object
  22745. type: object
  22746. type: object
  22747. caBundle:
  22748. description: |-
  22749. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  22750. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  22751. are used to validate the TLS connection.
  22752. format: byte
  22753. type: string
  22754. caProvider:
  22755. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  22756. properties:
  22757. key:
  22758. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22759. maxLength: 253
  22760. minLength: 1
  22761. pattern: ^[-._a-zA-Z0-9]+$
  22762. type: string
  22763. name:
  22764. description: The name of the object located at the provider type.
  22765. maxLength: 253
  22766. minLength: 1
  22767. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22768. type: string
  22769. namespace:
  22770. description: |-
  22771. The namespace the Provider type is in.
  22772. Can only be defined when used in a ClusterSecretStore.
  22773. maxLength: 63
  22774. minLength: 1
  22775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22776. type: string
  22777. type:
  22778. description: The type of provider to use such as "Secret", or "ConfigMap".
  22779. enum:
  22780. - Secret
  22781. - ConfigMap
  22782. type: string
  22783. required:
  22784. - name
  22785. - type
  22786. type: object
  22787. required:
  22788. - akeylessGWApiURL
  22789. - authSecretRef
  22790. type: object
  22791. alibaba:
  22792. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  22793. properties:
  22794. auth:
  22795. description: AlibabaAuth contains a secretRef for credentials.
  22796. properties:
  22797. rrsa:
  22798. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  22799. properties:
  22800. oidcProviderArn:
  22801. type: string
  22802. oidcTokenFilePath:
  22803. type: string
  22804. roleArn:
  22805. type: string
  22806. sessionName:
  22807. type: string
  22808. required:
  22809. - oidcProviderArn
  22810. - oidcTokenFilePath
  22811. - roleArn
  22812. - sessionName
  22813. type: object
  22814. secretRef:
  22815. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  22816. properties:
  22817. accessKeyIDSecretRef:
  22818. description: The AccessKeyID is used for authentication
  22819. properties:
  22820. key:
  22821. description: |-
  22822. A key in the referenced Secret.
  22823. Some instances of this field may be defaulted, in others it may be required.
  22824. maxLength: 253
  22825. minLength: 1
  22826. pattern: ^[-._a-zA-Z0-9]+$
  22827. type: string
  22828. name:
  22829. description: The name of the Secret resource being referred to.
  22830. maxLength: 253
  22831. minLength: 1
  22832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22833. type: string
  22834. namespace:
  22835. description: |-
  22836. The namespace of the Secret resource being referred to.
  22837. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22838. maxLength: 63
  22839. minLength: 1
  22840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22841. type: string
  22842. type: object
  22843. accessKeySecretSecretRef:
  22844. description: The AccessKeySecret is used for authentication
  22845. properties:
  22846. key:
  22847. description: |-
  22848. A key in the referenced Secret.
  22849. Some instances of this field may be defaulted, in others it may be required.
  22850. maxLength: 253
  22851. minLength: 1
  22852. pattern: ^[-._a-zA-Z0-9]+$
  22853. type: string
  22854. name:
  22855. description: The name of the Secret resource being referred to.
  22856. maxLength: 253
  22857. minLength: 1
  22858. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22859. type: string
  22860. namespace:
  22861. description: |-
  22862. The namespace of the Secret resource being referred to.
  22863. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22864. maxLength: 63
  22865. minLength: 1
  22866. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22867. type: string
  22868. type: object
  22869. required:
  22870. - accessKeyIDSecretRef
  22871. - accessKeySecretSecretRef
  22872. type: object
  22873. type: object
  22874. regionID:
  22875. description: Alibaba Region to be used for the provider
  22876. type: string
  22877. required:
  22878. - auth
  22879. - regionID
  22880. type: object
  22881. aws:
  22882. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  22883. properties:
  22884. additionalRoles:
  22885. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  22886. items:
  22887. type: string
  22888. type: array
  22889. auth:
  22890. description: |-
  22891. Auth defines the information necessary to authenticate against AWS
  22892. if not set aws sdk will infer credentials from your environment
  22893. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  22894. properties:
  22895. jwt:
  22896. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  22897. properties:
  22898. serviceAccountRef:
  22899. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  22900. properties:
  22901. audiences:
  22902. description: |-
  22903. Audience specifies the `aud` claim for the service account token
  22904. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  22905. then this audiences will be appended to the list
  22906. items:
  22907. type: string
  22908. type: array
  22909. name:
  22910. description: The name of the ServiceAccount resource being referred to.
  22911. maxLength: 253
  22912. minLength: 1
  22913. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22914. type: string
  22915. namespace:
  22916. description: |-
  22917. Namespace of the resource being referred to.
  22918. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22919. maxLength: 63
  22920. minLength: 1
  22921. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22922. type: string
  22923. required:
  22924. - name
  22925. type: object
  22926. type: object
  22927. secretRef:
  22928. description: |-
  22929. AWSAuthSecretRef holds secret references for AWS credentials
  22930. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  22931. properties:
  22932. accessKeyIDSecretRef:
  22933. description: The AccessKeyID is used for authentication
  22934. properties:
  22935. key:
  22936. description: |-
  22937. A key in the referenced Secret.
  22938. Some instances of this field may be defaulted, in others it may be required.
  22939. maxLength: 253
  22940. minLength: 1
  22941. pattern: ^[-._a-zA-Z0-9]+$
  22942. type: string
  22943. name:
  22944. description: The name of the Secret resource being referred to.
  22945. maxLength: 253
  22946. minLength: 1
  22947. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22948. type: string
  22949. namespace:
  22950. description: |-
  22951. The namespace of the Secret resource being referred to.
  22952. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22953. maxLength: 63
  22954. minLength: 1
  22955. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22956. type: string
  22957. type: object
  22958. secretAccessKeySecretRef:
  22959. description: The SecretAccessKey is used for authentication
  22960. properties:
  22961. key:
  22962. description: |-
  22963. A key in the referenced Secret.
  22964. Some instances of this field may be defaulted, in others it may be required.
  22965. maxLength: 253
  22966. minLength: 1
  22967. pattern: ^[-._a-zA-Z0-9]+$
  22968. type: string
  22969. name:
  22970. description: The name of the Secret resource being referred to.
  22971. maxLength: 253
  22972. minLength: 1
  22973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22974. type: string
  22975. namespace:
  22976. description: |-
  22977. The namespace of the Secret resource being referred to.
  22978. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22979. maxLength: 63
  22980. minLength: 1
  22981. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22982. type: string
  22983. type: object
  22984. sessionTokenSecretRef:
  22985. description: |-
  22986. The SessionToken used for authentication
  22987. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  22988. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  22989. properties:
  22990. key:
  22991. description: |-
  22992. A key in the referenced Secret.
  22993. Some instances of this field may be defaulted, in others it may be required.
  22994. maxLength: 253
  22995. minLength: 1
  22996. pattern: ^[-._a-zA-Z0-9]+$
  22997. type: string
  22998. name:
  22999. description: The name of the Secret resource being referred to.
  23000. maxLength: 253
  23001. minLength: 1
  23002. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23003. type: string
  23004. namespace:
  23005. description: |-
  23006. The namespace of the Secret resource being referred to.
  23007. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23008. maxLength: 63
  23009. minLength: 1
  23010. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23011. type: string
  23012. type: object
  23013. type: object
  23014. type: object
  23015. externalID:
  23016. description: AWS External ID set on assumed IAM roles
  23017. type: string
  23018. prefix:
  23019. description: Prefix adds a prefix to all retrieved values.
  23020. type: string
  23021. region:
  23022. description: AWS Region to be used for the provider
  23023. type: string
  23024. role:
  23025. description: Role is a Role ARN which the provider will assume
  23026. type: string
  23027. secretsManager:
  23028. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  23029. properties:
  23030. forceDeleteWithoutRecovery:
  23031. description: |-
  23032. Specifies whether to delete the secret without any recovery window. You
  23033. can't use both this parameter and RecoveryWindowInDays in the same call.
  23034. If you don't use either, then by default Secrets Manager uses a 30 day
  23035. recovery window.
  23036. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  23037. type: boolean
  23038. recoveryWindowInDays:
  23039. description: |-
  23040. The number of days from 7 to 30 that Secrets Manager waits before
  23041. permanently deleting the secret. You can't use both this parameter and
  23042. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  23043. then by default Secrets Manager uses a 30 day recovery window.
  23044. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  23045. format: int64
  23046. type: integer
  23047. type: object
  23048. service:
  23049. description: Service defines which service should be used to fetch the secrets
  23050. enum:
  23051. - SecretsManager
  23052. - ParameterStore
  23053. type: string
  23054. sessionTags:
  23055. description: AWS STS assume role session tags
  23056. items:
  23057. description: Tag defines a tag key and value for AWS resources.
  23058. properties:
  23059. key:
  23060. type: string
  23061. value:
  23062. type: string
  23063. required:
  23064. - key
  23065. - value
  23066. type: object
  23067. type: array
  23068. transitiveTagKeys:
  23069. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  23070. items:
  23071. type: string
  23072. type: array
  23073. required:
  23074. - region
  23075. - service
  23076. type: object
  23077. azurekv:
  23078. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  23079. properties:
  23080. authSecretRef:
  23081. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  23082. properties:
  23083. clientCertificate:
  23084. description: The Azure ClientCertificate of the service principle used for authentication.
  23085. properties:
  23086. key:
  23087. description: |-
  23088. A key in the referenced Secret.
  23089. Some instances of this field may be defaulted, in others it may be required.
  23090. maxLength: 253
  23091. minLength: 1
  23092. pattern: ^[-._a-zA-Z0-9]+$
  23093. type: string
  23094. name:
  23095. description: The name of the Secret resource being referred to.
  23096. maxLength: 253
  23097. minLength: 1
  23098. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23099. type: string
  23100. namespace:
  23101. description: |-
  23102. The namespace of the Secret resource being referred to.
  23103. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23104. maxLength: 63
  23105. minLength: 1
  23106. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23107. type: string
  23108. type: object
  23109. clientId:
  23110. description: The Azure clientId of the service principle or managed identity used for authentication.
  23111. properties:
  23112. key:
  23113. description: |-
  23114. A key in the referenced Secret.
  23115. Some instances of this field may be defaulted, in others it may be required.
  23116. maxLength: 253
  23117. minLength: 1
  23118. pattern: ^[-._a-zA-Z0-9]+$
  23119. type: string
  23120. name:
  23121. description: The name of the Secret resource being referred to.
  23122. maxLength: 253
  23123. minLength: 1
  23124. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23125. type: string
  23126. namespace:
  23127. description: |-
  23128. The namespace of the Secret resource being referred to.
  23129. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23130. maxLength: 63
  23131. minLength: 1
  23132. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23133. type: string
  23134. type: object
  23135. clientSecret:
  23136. description: The Azure ClientSecret of the service principle used for authentication.
  23137. properties:
  23138. key:
  23139. description: |-
  23140. A key in the referenced Secret.
  23141. Some instances of this field may be defaulted, in others it may be required.
  23142. maxLength: 253
  23143. minLength: 1
  23144. pattern: ^[-._a-zA-Z0-9]+$
  23145. type: string
  23146. name:
  23147. description: The name of the Secret resource being referred to.
  23148. maxLength: 253
  23149. minLength: 1
  23150. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23151. type: string
  23152. namespace:
  23153. description: |-
  23154. The namespace of the Secret resource being referred to.
  23155. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23156. maxLength: 63
  23157. minLength: 1
  23158. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23159. type: string
  23160. type: object
  23161. tenantId:
  23162. description: The Azure tenantId of the managed identity used for authentication.
  23163. properties:
  23164. key:
  23165. description: |-
  23166. A key in the referenced Secret.
  23167. Some instances of this field may be defaulted, in others it may be required.
  23168. maxLength: 253
  23169. minLength: 1
  23170. pattern: ^[-._a-zA-Z0-9]+$
  23171. type: string
  23172. name:
  23173. description: The name of the Secret resource being referred to.
  23174. maxLength: 253
  23175. minLength: 1
  23176. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23177. type: string
  23178. namespace:
  23179. description: |-
  23180. The namespace of the Secret resource being referred to.
  23181. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23182. maxLength: 63
  23183. minLength: 1
  23184. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23185. type: string
  23186. type: object
  23187. type: object
  23188. authType:
  23189. default: ServicePrincipal
  23190. description: |-
  23191. Auth type defines how to authenticate to the keyvault service.
  23192. Valid values are:
  23193. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  23194. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  23195. enum:
  23196. - ServicePrincipal
  23197. - ManagedIdentity
  23198. - WorkloadIdentity
  23199. type: string
  23200. environmentType:
  23201. default: PublicCloud
  23202. description: |-
  23203. EnvironmentType specifies the Azure cloud environment endpoints to use for
  23204. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  23205. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  23206. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  23207. enum:
  23208. - PublicCloud
  23209. - USGovernmentCloud
  23210. - ChinaCloud
  23211. - GermanCloud
  23212. type: string
  23213. identityId:
  23214. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  23215. type: string
  23216. serviceAccountRef:
  23217. description: |-
  23218. ServiceAccountRef specified the service account
  23219. that should be used when authenticating with WorkloadIdentity.
  23220. properties:
  23221. audiences:
  23222. description: |-
  23223. Audience specifies the `aud` claim for the service account token
  23224. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  23225. then this audiences will be appended to the list
  23226. items:
  23227. type: string
  23228. type: array
  23229. name:
  23230. description: The name of the ServiceAccount resource being referred to.
  23231. maxLength: 253
  23232. minLength: 1
  23233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23234. type: string
  23235. namespace:
  23236. description: |-
  23237. Namespace of the resource being referred to.
  23238. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23239. maxLength: 63
  23240. minLength: 1
  23241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23242. type: string
  23243. required:
  23244. - name
  23245. type: object
  23246. tenantId:
  23247. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  23248. type: string
  23249. vaultUrl:
  23250. description: Vault Url from which the secrets to be fetched from.
  23251. type: string
  23252. required:
  23253. - vaultUrl
  23254. type: object
  23255. beyondtrust:
  23256. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  23257. properties:
  23258. auth:
  23259. description: Auth configures how the operator authenticates with Beyondtrust.
  23260. properties:
  23261. apiKey:
  23262. description: APIKey If not provided then ClientID/ClientSecret become required.
  23263. properties:
  23264. secretRef:
  23265. description: SecretRef references a key in a secret that will be used as value.
  23266. properties:
  23267. key:
  23268. description: |-
  23269. A key in the referenced Secret.
  23270. Some instances of this field may be defaulted, in others it may be required.
  23271. maxLength: 253
  23272. minLength: 1
  23273. pattern: ^[-._a-zA-Z0-9]+$
  23274. type: string
  23275. name:
  23276. description: The name of the Secret resource being referred to.
  23277. maxLength: 253
  23278. minLength: 1
  23279. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23280. type: string
  23281. namespace:
  23282. description: |-
  23283. The namespace of the Secret resource being referred to.
  23284. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23285. maxLength: 63
  23286. minLength: 1
  23287. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23288. type: string
  23289. type: object
  23290. value:
  23291. description: Value can be specified directly to set a value without using a secret.
  23292. type: string
  23293. type: object
  23294. certificate:
  23295. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  23296. properties:
  23297. secretRef:
  23298. description: SecretRef references a key in a secret that will be used as value.
  23299. properties:
  23300. key:
  23301. description: |-
  23302. A key in the referenced Secret.
  23303. Some instances of this field may be defaulted, in others it may be required.
  23304. maxLength: 253
  23305. minLength: 1
  23306. pattern: ^[-._a-zA-Z0-9]+$
  23307. type: string
  23308. name:
  23309. description: The name of the Secret resource being referred to.
  23310. maxLength: 253
  23311. minLength: 1
  23312. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23313. type: string
  23314. namespace:
  23315. description: |-
  23316. The namespace of the Secret resource being referred to.
  23317. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23318. maxLength: 63
  23319. minLength: 1
  23320. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23321. type: string
  23322. type: object
  23323. value:
  23324. description: Value can be specified directly to set a value without using a secret.
  23325. type: string
  23326. type: object
  23327. certificateKey:
  23328. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  23329. properties:
  23330. secretRef:
  23331. description: SecretRef references a key in a secret that will be used as value.
  23332. properties:
  23333. key:
  23334. description: |-
  23335. A key in the referenced Secret.
  23336. Some instances of this field may be defaulted, in others it may be required.
  23337. maxLength: 253
  23338. minLength: 1
  23339. pattern: ^[-._a-zA-Z0-9]+$
  23340. type: string
  23341. name:
  23342. description: The name of the Secret resource being referred to.
  23343. maxLength: 253
  23344. minLength: 1
  23345. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23346. type: string
  23347. namespace:
  23348. description: |-
  23349. The namespace of the Secret resource being referred to.
  23350. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23351. maxLength: 63
  23352. minLength: 1
  23353. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23354. type: string
  23355. type: object
  23356. value:
  23357. description: Value can be specified directly to set a value without using a secret.
  23358. type: string
  23359. type: object
  23360. clientId:
  23361. description: ClientID is the API OAuth Client ID.
  23362. properties:
  23363. secretRef:
  23364. description: SecretRef references a key in a secret that will be used as value.
  23365. properties:
  23366. key:
  23367. description: |-
  23368. A key in the referenced Secret.
  23369. Some instances of this field may be defaulted, in others it may be required.
  23370. maxLength: 253
  23371. minLength: 1
  23372. pattern: ^[-._a-zA-Z0-9]+$
  23373. type: string
  23374. name:
  23375. description: The name of the Secret resource being referred to.
  23376. maxLength: 253
  23377. minLength: 1
  23378. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23379. type: string
  23380. namespace:
  23381. description: |-
  23382. The namespace of the Secret resource being referred to.
  23383. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23384. maxLength: 63
  23385. minLength: 1
  23386. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23387. type: string
  23388. type: object
  23389. value:
  23390. description: Value can be specified directly to set a value without using a secret.
  23391. type: string
  23392. type: object
  23393. clientSecret:
  23394. description: ClientSecret is the API OAuth Client Secret.
  23395. properties:
  23396. secretRef:
  23397. description: SecretRef references a key in a secret that will be used as value.
  23398. properties:
  23399. key:
  23400. description: |-
  23401. A key in the referenced Secret.
  23402. Some instances of this field may be defaulted, in others it may be required.
  23403. maxLength: 253
  23404. minLength: 1
  23405. pattern: ^[-._a-zA-Z0-9]+$
  23406. type: string
  23407. name:
  23408. description: The name of the Secret resource being referred to.
  23409. maxLength: 253
  23410. minLength: 1
  23411. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23412. type: string
  23413. namespace:
  23414. description: |-
  23415. The namespace of the Secret resource being referred to.
  23416. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23417. maxLength: 63
  23418. minLength: 1
  23419. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23420. type: string
  23421. type: object
  23422. value:
  23423. description: Value can be specified directly to set a value without using a secret.
  23424. type: string
  23425. type: object
  23426. type: object
  23427. server:
  23428. description: Auth configures how API server works.
  23429. properties:
  23430. apiUrl:
  23431. type: string
  23432. apiVersion:
  23433. type: string
  23434. clientTimeOutSeconds:
  23435. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  23436. type: integer
  23437. decrypt:
  23438. default: true
  23439. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  23440. type: boolean
  23441. retrievalType:
  23442. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  23443. type: string
  23444. separator:
  23445. description: A character that separates the folder names.
  23446. type: string
  23447. verifyCA:
  23448. type: boolean
  23449. required:
  23450. - apiUrl
  23451. - verifyCA
  23452. type: object
  23453. required:
  23454. - auth
  23455. - server
  23456. type: object
  23457. bitwardensecretsmanager:
  23458. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  23459. properties:
  23460. apiURL:
  23461. type: string
  23462. auth:
  23463. description: |-
  23464. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  23465. Make sure that the token being used has permissions on the given secret.
  23466. properties:
  23467. secretRef:
  23468. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  23469. properties:
  23470. credentials:
  23471. description: AccessToken used for the bitwarden instance.
  23472. properties:
  23473. key:
  23474. description: |-
  23475. A key in the referenced Secret.
  23476. Some instances of this field may be defaulted, in others it may be required.
  23477. maxLength: 253
  23478. minLength: 1
  23479. pattern: ^[-._a-zA-Z0-9]+$
  23480. type: string
  23481. name:
  23482. description: The name of the Secret resource being referred to.
  23483. maxLength: 253
  23484. minLength: 1
  23485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23486. type: string
  23487. namespace:
  23488. description: |-
  23489. The namespace of the Secret resource being referred to.
  23490. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23491. maxLength: 63
  23492. minLength: 1
  23493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23494. type: string
  23495. type: object
  23496. required:
  23497. - credentials
  23498. type: object
  23499. required:
  23500. - secretRef
  23501. type: object
  23502. bitwardenServerSDKURL:
  23503. type: string
  23504. caBundle:
  23505. description: |-
  23506. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  23507. can be performed.
  23508. type: string
  23509. caProvider:
  23510. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  23511. properties:
  23512. key:
  23513. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23514. maxLength: 253
  23515. minLength: 1
  23516. pattern: ^[-._a-zA-Z0-9]+$
  23517. type: string
  23518. name:
  23519. description: The name of the object located at the provider type.
  23520. maxLength: 253
  23521. minLength: 1
  23522. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23523. type: string
  23524. namespace:
  23525. description: |-
  23526. The namespace the Provider type is in.
  23527. Can only be defined when used in a ClusterSecretStore.
  23528. maxLength: 63
  23529. minLength: 1
  23530. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23531. type: string
  23532. type:
  23533. description: The type of provider to use such as "Secret", or "ConfigMap".
  23534. enum:
  23535. - Secret
  23536. - ConfigMap
  23537. type: string
  23538. required:
  23539. - name
  23540. - type
  23541. type: object
  23542. identityURL:
  23543. type: string
  23544. organizationID:
  23545. description: OrganizationID determines which organization this secret store manages.
  23546. type: string
  23547. projectID:
  23548. description: ProjectID determines which project this secret store manages.
  23549. type: string
  23550. required:
  23551. - auth
  23552. - organizationID
  23553. - projectID
  23554. type: object
  23555. chef:
  23556. description: Chef configures this store to sync secrets with chef server
  23557. properties:
  23558. auth:
  23559. description: Auth defines the information necessary to authenticate against chef Server
  23560. properties:
  23561. secretRef:
  23562. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  23563. properties:
  23564. privateKeySecretRef:
  23565. description: SecretKey is the Signing Key in PEM format, used for authentication.
  23566. properties:
  23567. key:
  23568. description: |-
  23569. A key in the referenced Secret.
  23570. Some instances of this field may be defaulted, in others it may be required.
  23571. maxLength: 253
  23572. minLength: 1
  23573. pattern: ^[-._a-zA-Z0-9]+$
  23574. type: string
  23575. name:
  23576. description: The name of the Secret resource being referred to.
  23577. maxLength: 253
  23578. minLength: 1
  23579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23580. type: string
  23581. namespace:
  23582. description: |-
  23583. The namespace of the Secret resource being referred to.
  23584. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23585. maxLength: 63
  23586. minLength: 1
  23587. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23588. type: string
  23589. type: object
  23590. required:
  23591. - privateKeySecretRef
  23592. type: object
  23593. required:
  23594. - secretRef
  23595. type: object
  23596. serverUrl:
  23597. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  23598. type: string
  23599. username:
  23600. description: UserName should be the user ID on the chef server
  23601. type: string
  23602. required:
  23603. - auth
  23604. - serverUrl
  23605. - username
  23606. type: object
  23607. cloudrusm:
  23608. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  23609. properties:
  23610. auth:
  23611. description: CSMAuth contains a secretRef for credentials.
  23612. properties:
  23613. secretRef:
  23614. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  23615. properties:
  23616. accessKeyIDSecretRef:
  23617. description: The AccessKeyID is used for authentication
  23618. properties:
  23619. key:
  23620. description: |-
  23621. A key in the referenced Secret.
  23622. Some instances of this field may be defaulted, in others it may be required.
  23623. maxLength: 253
  23624. minLength: 1
  23625. pattern: ^[-._a-zA-Z0-9]+$
  23626. type: string
  23627. name:
  23628. description: The name of the Secret resource being referred to.
  23629. maxLength: 253
  23630. minLength: 1
  23631. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23632. type: string
  23633. namespace:
  23634. description: |-
  23635. The namespace of the Secret resource being referred to.
  23636. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23637. maxLength: 63
  23638. minLength: 1
  23639. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23640. type: string
  23641. type: object
  23642. accessKeySecretSecretRef:
  23643. description: The AccessKeySecret is used for authentication
  23644. properties:
  23645. key:
  23646. description: |-
  23647. A key in the referenced Secret.
  23648. Some instances of this field may be defaulted, in others it may be required.
  23649. maxLength: 253
  23650. minLength: 1
  23651. pattern: ^[-._a-zA-Z0-9]+$
  23652. type: string
  23653. name:
  23654. description: The name of the Secret resource being referred to.
  23655. maxLength: 253
  23656. minLength: 1
  23657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23658. type: string
  23659. namespace:
  23660. description: |-
  23661. The namespace of the Secret resource being referred to.
  23662. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23663. maxLength: 63
  23664. minLength: 1
  23665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23666. type: string
  23667. type: object
  23668. required:
  23669. - accessKeyIDSecretRef
  23670. - accessKeySecretSecretRef
  23671. type: object
  23672. type: object
  23673. projectID:
  23674. description: ProjectID is the project, which the secrets are stored in.
  23675. type: string
  23676. required:
  23677. - auth
  23678. type: object
  23679. conjur:
  23680. description: Conjur configures this store to sync secrets using conjur provider
  23681. properties:
  23682. auth:
  23683. description: Defines authentication settings for connecting to Conjur.
  23684. properties:
  23685. apikey:
  23686. description: Authenticates with Conjur using an API key.
  23687. properties:
  23688. account:
  23689. description: Account is the Conjur organization account name.
  23690. type: string
  23691. apiKeyRef:
  23692. description: |-
  23693. A reference to a specific 'key' containing the Conjur API key
  23694. within a Secret resource. In some instances, `key` is a required field.
  23695. properties:
  23696. key:
  23697. description: |-
  23698. A key in the referenced Secret.
  23699. Some instances of this field may be defaulted, in others it may be required.
  23700. maxLength: 253
  23701. minLength: 1
  23702. pattern: ^[-._a-zA-Z0-9]+$
  23703. type: string
  23704. name:
  23705. description: The name of the Secret resource being referred to.
  23706. maxLength: 253
  23707. minLength: 1
  23708. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23709. type: string
  23710. namespace:
  23711. description: |-
  23712. The namespace of the Secret resource being referred to.
  23713. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23714. maxLength: 63
  23715. minLength: 1
  23716. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23717. type: string
  23718. type: object
  23719. userRef:
  23720. description: |-
  23721. A reference to a specific 'key' containing the Conjur username
  23722. within a Secret resource. In some instances, `key` is a required field.
  23723. properties:
  23724. key:
  23725. description: |-
  23726. A key in the referenced Secret.
  23727. Some instances of this field may be defaulted, in others it may be required.
  23728. maxLength: 253
  23729. minLength: 1
  23730. pattern: ^[-._a-zA-Z0-9]+$
  23731. type: string
  23732. name:
  23733. description: The name of the Secret resource being referred to.
  23734. maxLength: 253
  23735. minLength: 1
  23736. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23737. type: string
  23738. namespace:
  23739. description: |-
  23740. The namespace of the Secret resource being referred to.
  23741. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23742. maxLength: 63
  23743. minLength: 1
  23744. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23745. type: string
  23746. type: object
  23747. required:
  23748. - account
  23749. - apiKeyRef
  23750. - userRef
  23751. type: object
  23752. jwt:
  23753. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  23754. properties:
  23755. account:
  23756. description: Account is the Conjur organization account name.
  23757. type: string
  23758. hostId:
  23759. description: |-
  23760. Optional HostID for JWT authentication. This may be used depending
  23761. on how the Conjur JWT authenticator policy is configured.
  23762. type: string
  23763. secretRef:
  23764. description: |-
  23765. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  23766. authenticate with Conjur using the JWT authentication method.
  23767. properties:
  23768. key:
  23769. description: |-
  23770. A key in the referenced Secret.
  23771. Some instances of this field may be defaulted, in others it may be required.
  23772. maxLength: 253
  23773. minLength: 1
  23774. pattern: ^[-._a-zA-Z0-9]+$
  23775. type: string
  23776. name:
  23777. description: The name of the Secret resource being referred to.
  23778. maxLength: 253
  23779. minLength: 1
  23780. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23781. type: string
  23782. namespace:
  23783. description: |-
  23784. The namespace of the Secret resource being referred to.
  23785. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23786. maxLength: 63
  23787. minLength: 1
  23788. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23789. type: string
  23790. type: object
  23791. serviceAccountRef:
  23792. description: |-
  23793. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  23794. a token for with the `TokenRequest` API.
  23795. properties:
  23796. audiences:
  23797. description: |-
  23798. Audience specifies the `aud` claim for the service account token
  23799. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  23800. then this audiences will be appended to the list
  23801. items:
  23802. type: string
  23803. type: array
  23804. name:
  23805. description: The name of the ServiceAccount resource being referred to.
  23806. maxLength: 253
  23807. minLength: 1
  23808. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23809. type: string
  23810. namespace:
  23811. description: |-
  23812. Namespace of the resource being referred to.
  23813. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23814. maxLength: 63
  23815. minLength: 1
  23816. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23817. type: string
  23818. required:
  23819. - name
  23820. type: object
  23821. serviceID:
  23822. description: The conjur authn jwt webservice id
  23823. type: string
  23824. required:
  23825. - account
  23826. - serviceID
  23827. type: object
  23828. type: object
  23829. caBundle:
  23830. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  23831. type: string
  23832. caProvider:
  23833. description: |-
  23834. Used to provide custom certificate authority (CA) certificates
  23835. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  23836. that contains a PEM-encoded certificate.
  23837. properties:
  23838. key:
  23839. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23840. maxLength: 253
  23841. minLength: 1
  23842. pattern: ^[-._a-zA-Z0-9]+$
  23843. type: string
  23844. name:
  23845. description: The name of the object located at the provider type.
  23846. maxLength: 253
  23847. minLength: 1
  23848. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23849. type: string
  23850. namespace:
  23851. description: |-
  23852. The namespace the Provider type is in.
  23853. Can only be defined when used in a ClusterSecretStore.
  23854. maxLength: 63
  23855. minLength: 1
  23856. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23857. type: string
  23858. type:
  23859. description: The type of provider to use such as "Secret", or "ConfigMap".
  23860. enum:
  23861. - Secret
  23862. - ConfigMap
  23863. type: string
  23864. required:
  23865. - name
  23866. - type
  23867. type: object
  23868. url:
  23869. description: URL is the endpoint of the Conjur instance.
  23870. type: string
  23871. required:
  23872. - auth
  23873. - url
  23874. type: object
  23875. delinea:
  23876. description: |-
  23877. Delinea DevOps Secrets Vault
  23878. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  23879. properties:
  23880. clientId:
  23881. description: ClientID is the non-secret part of the credential.
  23882. properties:
  23883. secretRef:
  23884. description: SecretRef references a key in a secret that will be used as value.
  23885. properties:
  23886. key:
  23887. description: |-
  23888. A key in the referenced Secret.
  23889. Some instances of this field may be defaulted, in others it may be required.
  23890. maxLength: 253
  23891. minLength: 1
  23892. pattern: ^[-._a-zA-Z0-9]+$
  23893. type: string
  23894. name:
  23895. description: The name of the Secret resource being referred to.
  23896. maxLength: 253
  23897. minLength: 1
  23898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23899. type: string
  23900. namespace:
  23901. description: |-
  23902. The namespace of the Secret resource being referred to.
  23903. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23904. maxLength: 63
  23905. minLength: 1
  23906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23907. type: string
  23908. type: object
  23909. value:
  23910. description: Value can be specified directly to set a value without using a secret.
  23911. type: string
  23912. type: object
  23913. clientSecret:
  23914. description: ClientSecret is the secret part of the credential.
  23915. properties:
  23916. secretRef:
  23917. description: SecretRef references a key in a secret that will be used as value.
  23918. properties:
  23919. key:
  23920. description: |-
  23921. A key in the referenced Secret.
  23922. Some instances of this field may be defaulted, in others it may be required.
  23923. maxLength: 253
  23924. minLength: 1
  23925. pattern: ^[-._a-zA-Z0-9]+$
  23926. type: string
  23927. name:
  23928. description: The name of the Secret resource being referred to.
  23929. maxLength: 253
  23930. minLength: 1
  23931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23932. type: string
  23933. namespace:
  23934. description: |-
  23935. The namespace of the Secret resource being referred to.
  23936. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23937. maxLength: 63
  23938. minLength: 1
  23939. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23940. type: string
  23941. type: object
  23942. value:
  23943. description: Value can be specified directly to set a value without using a secret.
  23944. type: string
  23945. type: object
  23946. tenant:
  23947. description: Tenant is the chosen hostname / site name.
  23948. type: string
  23949. tld:
  23950. description: |-
  23951. TLD is based on the server location that was chosen during provisioning.
  23952. If unset, defaults to "com".
  23953. type: string
  23954. urlTemplate:
  23955. description: |-
  23956. URLTemplate
  23957. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  23958. type: string
  23959. required:
  23960. - clientId
  23961. - clientSecret
  23962. - tenant
  23963. type: object
  23964. device42:
  23965. description: Device42 configures this store to sync secrets using the Device42 provider
  23966. properties:
  23967. auth:
  23968. description: Auth configures how secret-manager authenticates with a Device42 instance.
  23969. properties:
  23970. secretRef:
  23971. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  23972. properties:
  23973. credentials:
  23974. description: Username / Password is used for authentication.
  23975. properties:
  23976. key:
  23977. description: |-
  23978. A key in the referenced Secret.
  23979. Some instances of this field may be defaulted, in others it may be required.
  23980. maxLength: 253
  23981. minLength: 1
  23982. pattern: ^[-._a-zA-Z0-9]+$
  23983. type: string
  23984. name:
  23985. description: The name of the Secret resource being referred to.
  23986. maxLength: 253
  23987. minLength: 1
  23988. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23989. type: string
  23990. namespace:
  23991. description: |-
  23992. The namespace of the Secret resource being referred to.
  23993. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23994. maxLength: 63
  23995. minLength: 1
  23996. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23997. type: string
  23998. type: object
  23999. type: object
  24000. required:
  24001. - secretRef
  24002. type: object
  24003. host:
  24004. description: URL configures the Device42 instance URL.
  24005. type: string
  24006. required:
  24007. - auth
  24008. - host
  24009. type: object
  24010. doppler:
  24011. description: Doppler configures this store to sync secrets using the Doppler provider
  24012. properties:
  24013. auth:
  24014. description: Auth configures how the Operator authenticates with the Doppler API
  24015. properties:
  24016. secretRef:
  24017. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  24018. properties:
  24019. dopplerToken:
  24020. description: |-
  24021. The DopplerToken is used for authentication.
  24022. See https://docs.doppler.com/reference/api#authentication for auth token types.
  24023. The Key attribute defaults to dopplerToken if not specified.
  24024. properties:
  24025. key:
  24026. description: |-
  24027. A key in the referenced Secret.
  24028. Some instances of this field may be defaulted, in others it may be required.
  24029. maxLength: 253
  24030. minLength: 1
  24031. pattern: ^[-._a-zA-Z0-9]+$
  24032. type: string
  24033. name:
  24034. description: The name of the Secret resource being referred to.
  24035. maxLength: 253
  24036. minLength: 1
  24037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24038. type: string
  24039. namespace:
  24040. description: |-
  24041. The namespace of the Secret resource being referred to.
  24042. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24043. maxLength: 63
  24044. minLength: 1
  24045. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24046. type: string
  24047. type: object
  24048. required:
  24049. - dopplerToken
  24050. type: object
  24051. required:
  24052. - secretRef
  24053. type: object
  24054. config:
  24055. description: Doppler config (required if not using a Service Token)
  24056. type: string
  24057. format:
  24058. description: Format enables the downloading of secrets as a file (string)
  24059. enum:
  24060. - json
  24061. - dotnet-json
  24062. - env
  24063. - yaml
  24064. - docker
  24065. type: string
  24066. nameTransformer:
  24067. description: Environment variable compatible name transforms that change secret names to a different format
  24068. enum:
  24069. - upper-camel
  24070. - camel
  24071. - lower-snake
  24072. - tf-var
  24073. - dotnet-env
  24074. - lower-kebab
  24075. type: string
  24076. project:
  24077. description: Doppler project (required if not using a Service Token)
  24078. type: string
  24079. required:
  24080. - auth
  24081. type: object
  24082. fake:
  24083. description: Fake configures a store with static key/value pairs
  24084. properties:
  24085. data:
  24086. items:
  24087. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  24088. properties:
  24089. key:
  24090. type: string
  24091. value:
  24092. type: string
  24093. version:
  24094. type: string
  24095. required:
  24096. - key
  24097. - value
  24098. type: object
  24099. type: array
  24100. required:
  24101. - data
  24102. type: object
  24103. fortanix:
  24104. description: Fortanix configures this store to sync secrets using the Fortanix provider
  24105. properties:
  24106. apiKey:
  24107. description: APIKey is the API token to access SDKMS Applications.
  24108. properties:
  24109. secretRef:
  24110. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  24111. properties:
  24112. key:
  24113. description: |-
  24114. A key in the referenced Secret.
  24115. Some instances of this field may be defaulted, in others it may be required.
  24116. maxLength: 253
  24117. minLength: 1
  24118. pattern: ^[-._a-zA-Z0-9]+$
  24119. type: string
  24120. name:
  24121. description: The name of the Secret resource being referred to.
  24122. maxLength: 253
  24123. minLength: 1
  24124. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24125. type: string
  24126. namespace:
  24127. description: |-
  24128. The namespace of the Secret resource being referred to.
  24129. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24130. maxLength: 63
  24131. minLength: 1
  24132. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24133. type: string
  24134. type: object
  24135. type: object
  24136. apiUrl:
  24137. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  24138. type: string
  24139. type: object
  24140. gcpsm:
  24141. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  24142. properties:
  24143. auth:
  24144. description: Auth defines the information necessary to authenticate against GCP
  24145. properties:
  24146. secretRef:
  24147. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  24148. properties:
  24149. secretAccessKeySecretRef:
  24150. description: The SecretAccessKey is used for authentication
  24151. properties:
  24152. key:
  24153. description: |-
  24154. A key in the referenced Secret.
  24155. Some instances of this field may be defaulted, in others it may be required.
  24156. maxLength: 253
  24157. minLength: 1
  24158. pattern: ^[-._a-zA-Z0-9]+$
  24159. type: string
  24160. name:
  24161. description: The name of the Secret resource being referred to.
  24162. maxLength: 253
  24163. minLength: 1
  24164. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24165. type: string
  24166. namespace:
  24167. description: |-
  24168. The namespace of the Secret resource being referred to.
  24169. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24170. maxLength: 63
  24171. minLength: 1
  24172. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24173. type: string
  24174. type: object
  24175. type: object
  24176. workloadIdentity:
  24177. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  24178. properties:
  24179. clusterLocation:
  24180. description: |-
  24181. ClusterLocation is the location of the cluster
  24182. If not specified, it fetches information from the metadata server
  24183. type: string
  24184. clusterName:
  24185. description: |-
  24186. ClusterName is the name of the cluster
  24187. If not specified, it fetches information from the metadata server
  24188. type: string
  24189. clusterProjectID:
  24190. description: |-
  24191. ClusterProjectID is the project ID of the cluster
  24192. If not specified, it fetches information from the metadata server
  24193. type: string
  24194. serviceAccountRef:
  24195. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  24196. properties:
  24197. audiences:
  24198. description: |-
  24199. Audience specifies the `aud` claim for the service account token
  24200. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  24201. then this audiences will be appended to the list
  24202. items:
  24203. type: string
  24204. type: array
  24205. name:
  24206. description: The name of the ServiceAccount resource being referred to.
  24207. maxLength: 253
  24208. minLength: 1
  24209. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24210. type: string
  24211. namespace:
  24212. description: |-
  24213. Namespace of the resource being referred to.
  24214. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24215. maxLength: 63
  24216. minLength: 1
  24217. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24218. type: string
  24219. required:
  24220. - name
  24221. type: object
  24222. required:
  24223. - serviceAccountRef
  24224. type: object
  24225. type: object
  24226. location:
  24227. description: Location optionally defines a location for a secret
  24228. type: string
  24229. projectID:
  24230. description: ProjectID project where secret is located
  24231. type: string
  24232. type: object
  24233. github:
  24234. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  24235. properties:
  24236. appID:
  24237. description: appID specifies the Github APP that will be used to authenticate the client
  24238. format: int64
  24239. type: integer
  24240. auth:
  24241. description: auth configures how secret-manager authenticates with a Github instance.
  24242. properties:
  24243. privateKey:
  24244. description: |-
  24245. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24246. In some instances, `key` is a required field.
  24247. properties:
  24248. key:
  24249. description: |-
  24250. A key in the referenced Secret.
  24251. Some instances of this field may be defaulted, in others it may be required.
  24252. maxLength: 253
  24253. minLength: 1
  24254. pattern: ^[-._a-zA-Z0-9]+$
  24255. type: string
  24256. name:
  24257. description: The name of the Secret resource being referred to.
  24258. maxLength: 253
  24259. minLength: 1
  24260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24261. type: string
  24262. namespace:
  24263. description: |-
  24264. The namespace of the Secret resource being referred to.
  24265. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24266. maxLength: 63
  24267. minLength: 1
  24268. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24269. type: string
  24270. type: object
  24271. required:
  24272. - privateKey
  24273. type: object
  24274. environment:
  24275. description: environment will be used to fetch secrets from a particular environment within a github repository
  24276. type: string
  24277. installationID:
  24278. description: installationID specifies the Github APP installation that will be used to authenticate the client
  24279. format: int64
  24280. type: integer
  24281. organization:
  24282. description: organization will be used to fetch secrets from the Github organization
  24283. type: string
  24284. repository:
  24285. description: repository will be used to fetch secrets from the Github repository within an organization
  24286. type: string
  24287. uploadURL:
  24288. description: Upload URL for enterprise instances. Default to URL.
  24289. type: string
  24290. url:
  24291. default: https://github.com/
  24292. description: URL configures the Github instance URL. Defaults to https://github.com/.
  24293. type: string
  24294. required:
  24295. - appID
  24296. - auth
  24297. - installationID
  24298. - organization
  24299. type: object
  24300. gitlab:
  24301. description: GitLab configures this store to sync secrets using GitLab Variables provider
  24302. properties:
  24303. auth:
  24304. description: Auth configures how secret-manager authenticates with a GitLab instance.
  24305. properties:
  24306. SecretRef:
  24307. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  24308. properties:
  24309. accessToken:
  24310. description: AccessToken is used for authentication.
  24311. properties:
  24312. key:
  24313. description: |-
  24314. A key in the referenced Secret.
  24315. Some instances of this field may be defaulted, in others it may be required.
  24316. maxLength: 253
  24317. minLength: 1
  24318. pattern: ^[-._a-zA-Z0-9]+$
  24319. type: string
  24320. name:
  24321. description: The name of the Secret resource being referred to.
  24322. maxLength: 253
  24323. minLength: 1
  24324. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24325. type: string
  24326. namespace:
  24327. description: |-
  24328. The namespace of the Secret resource being referred to.
  24329. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24330. maxLength: 63
  24331. minLength: 1
  24332. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24333. type: string
  24334. type: object
  24335. type: object
  24336. required:
  24337. - SecretRef
  24338. type: object
  24339. caBundle:
  24340. description: |-
  24341. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  24342. can be performed.
  24343. format: byte
  24344. type: string
  24345. caProvider:
  24346. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  24347. properties:
  24348. key:
  24349. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24350. maxLength: 253
  24351. minLength: 1
  24352. pattern: ^[-._a-zA-Z0-9]+$
  24353. type: string
  24354. name:
  24355. description: The name of the object located at the provider type.
  24356. maxLength: 253
  24357. minLength: 1
  24358. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24359. type: string
  24360. namespace:
  24361. description: |-
  24362. The namespace the Provider type is in.
  24363. Can only be defined when used in a ClusterSecretStore.
  24364. maxLength: 63
  24365. minLength: 1
  24366. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24367. type: string
  24368. type:
  24369. description: The type of provider to use such as "Secret", or "ConfigMap".
  24370. enum:
  24371. - Secret
  24372. - ConfigMap
  24373. type: string
  24374. required:
  24375. - name
  24376. - type
  24377. type: object
  24378. environment:
  24379. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  24380. type: string
  24381. groupIDs:
  24382. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  24383. items:
  24384. type: string
  24385. type: array
  24386. inheritFromGroups:
  24387. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  24388. type: boolean
  24389. projectID:
  24390. description: ProjectID specifies a project where secrets are located.
  24391. type: string
  24392. url:
  24393. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  24394. type: string
  24395. required:
  24396. - auth
  24397. type: object
  24398. ibm:
  24399. description: IBM configures this store to sync secrets using IBM Cloud provider
  24400. properties:
  24401. auth:
  24402. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  24403. maxProperties: 1
  24404. minProperties: 1
  24405. properties:
  24406. containerAuth:
  24407. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  24408. properties:
  24409. iamEndpoint:
  24410. type: string
  24411. profile:
  24412. description: the IBM Trusted Profile
  24413. type: string
  24414. tokenLocation:
  24415. description: Location the token is mounted on the pod
  24416. type: string
  24417. required:
  24418. - profile
  24419. type: object
  24420. secretRef:
  24421. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  24422. properties:
  24423. secretApiKeySecretRef:
  24424. description: The SecretAccessKey is used for authentication
  24425. properties:
  24426. key:
  24427. description: |-
  24428. A key in the referenced Secret.
  24429. Some instances of this field may be defaulted, in others it may be required.
  24430. maxLength: 253
  24431. minLength: 1
  24432. pattern: ^[-._a-zA-Z0-9]+$
  24433. type: string
  24434. name:
  24435. description: The name of the Secret resource being referred to.
  24436. maxLength: 253
  24437. minLength: 1
  24438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24439. type: string
  24440. namespace:
  24441. description: |-
  24442. The namespace of the Secret resource being referred to.
  24443. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24444. maxLength: 63
  24445. minLength: 1
  24446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24447. type: string
  24448. type: object
  24449. type: object
  24450. type: object
  24451. serviceUrl:
  24452. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  24453. type: string
  24454. required:
  24455. - auth
  24456. type: object
  24457. infisical:
  24458. description: Infisical configures this store to sync secrets using the Infisical provider
  24459. properties:
  24460. auth:
  24461. description: Auth configures how the Operator authenticates with the Infisical API
  24462. properties:
  24463. universalAuthCredentials:
  24464. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  24465. properties:
  24466. clientId:
  24467. description: |-
  24468. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24469. In some instances, `key` is a required field.
  24470. properties:
  24471. key:
  24472. description: |-
  24473. A key in the referenced Secret.
  24474. Some instances of this field may be defaulted, in others it may be required.
  24475. maxLength: 253
  24476. minLength: 1
  24477. pattern: ^[-._a-zA-Z0-9]+$
  24478. type: string
  24479. name:
  24480. description: The name of the Secret resource being referred to.
  24481. maxLength: 253
  24482. minLength: 1
  24483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24484. type: string
  24485. namespace:
  24486. description: |-
  24487. The namespace of the Secret resource being referred to.
  24488. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24489. maxLength: 63
  24490. minLength: 1
  24491. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24492. type: string
  24493. type: object
  24494. clientSecret:
  24495. description: |-
  24496. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24497. In some instances, `key` is a required field.
  24498. properties:
  24499. key:
  24500. description: |-
  24501. A key in the referenced Secret.
  24502. Some instances of this field may be defaulted, in others it may be required.
  24503. maxLength: 253
  24504. minLength: 1
  24505. pattern: ^[-._a-zA-Z0-9]+$
  24506. type: string
  24507. name:
  24508. description: The name of the Secret resource being referred to.
  24509. maxLength: 253
  24510. minLength: 1
  24511. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24512. type: string
  24513. namespace:
  24514. description: |-
  24515. The namespace of the Secret resource being referred to.
  24516. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24517. maxLength: 63
  24518. minLength: 1
  24519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24520. type: string
  24521. type: object
  24522. required:
  24523. - clientId
  24524. - clientSecret
  24525. type: object
  24526. type: object
  24527. hostAPI:
  24528. default: https://app.infisical.com/api
  24529. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  24530. type: string
  24531. secretsScope:
  24532. description: SecretsScope defines the scope of the secrets within the workspace
  24533. properties:
  24534. environmentSlug:
  24535. description: EnvironmentSlug is the required slug identifier for the environment.
  24536. type: string
  24537. expandSecretReferences:
  24538. default: true
  24539. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  24540. type: boolean
  24541. projectSlug:
  24542. description: ProjectSlug is the required slug identifier for the project.
  24543. type: string
  24544. recursive:
  24545. default: false
  24546. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  24547. type: boolean
  24548. secretsPath:
  24549. default: /
  24550. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  24551. type: string
  24552. required:
  24553. - environmentSlug
  24554. - projectSlug
  24555. type: object
  24556. required:
  24557. - auth
  24558. - secretsScope
  24559. type: object
  24560. keepersecurity:
  24561. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  24562. properties:
  24563. authRef:
  24564. description: |-
  24565. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24566. In some instances, `key` is a required field.
  24567. properties:
  24568. key:
  24569. description: |-
  24570. A key in the referenced Secret.
  24571. Some instances of this field may be defaulted, in others it may be required.
  24572. maxLength: 253
  24573. minLength: 1
  24574. pattern: ^[-._a-zA-Z0-9]+$
  24575. type: string
  24576. name:
  24577. description: The name of the Secret resource being referred to.
  24578. maxLength: 253
  24579. minLength: 1
  24580. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24581. type: string
  24582. namespace:
  24583. description: |-
  24584. The namespace of the Secret resource being referred to.
  24585. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24586. maxLength: 63
  24587. minLength: 1
  24588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24589. type: string
  24590. type: object
  24591. folderID:
  24592. type: string
  24593. required:
  24594. - authRef
  24595. - folderID
  24596. type: object
  24597. kubernetes:
  24598. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  24599. properties:
  24600. auth:
  24601. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  24602. maxProperties: 1
  24603. minProperties: 1
  24604. properties:
  24605. cert:
  24606. description: has both clientCert and clientKey as secretKeySelector
  24607. properties:
  24608. clientCert:
  24609. description: |-
  24610. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24611. In some instances, `key` is a required field.
  24612. properties:
  24613. key:
  24614. description: |-
  24615. A key in the referenced Secret.
  24616. Some instances of this field may be defaulted, in others it may be required.
  24617. maxLength: 253
  24618. minLength: 1
  24619. pattern: ^[-._a-zA-Z0-9]+$
  24620. type: string
  24621. name:
  24622. description: The name of the Secret resource being referred to.
  24623. maxLength: 253
  24624. minLength: 1
  24625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24626. type: string
  24627. namespace:
  24628. description: |-
  24629. The namespace of the Secret resource being referred to.
  24630. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24631. maxLength: 63
  24632. minLength: 1
  24633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24634. type: string
  24635. type: object
  24636. clientKey:
  24637. description: |-
  24638. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24639. In some instances, `key` is a required field.
  24640. properties:
  24641. key:
  24642. description: |-
  24643. A key in the referenced Secret.
  24644. Some instances of this field may be defaulted, in others it may be required.
  24645. maxLength: 253
  24646. minLength: 1
  24647. pattern: ^[-._a-zA-Z0-9]+$
  24648. type: string
  24649. name:
  24650. description: The name of the Secret resource being referred to.
  24651. maxLength: 253
  24652. minLength: 1
  24653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24654. type: string
  24655. namespace:
  24656. description: |-
  24657. The namespace of the Secret resource being referred to.
  24658. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24659. maxLength: 63
  24660. minLength: 1
  24661. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24662. type: string
  24663. type: object
  24664. type: object
  24665. serviceAccount:
  24666. description: points to a service account that should be used for authentication
  24667. properties:
  24668. audiences:
  24669. description: |-
  24670. Audience specifies the `aud` claim for the service account token
  24671. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  24672. then this audiences will be appended to the list
  24673. items:
  24674. type: string
  24675. type: array
  24676. name:
  24677. description: The name of the ServiceAccount resource being referred to.
  24678. maxLength: 253
  24679. minLength: 1
  24680. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24681. type: string
  24682. namespace:
  24683. description: |-
  24684. Namespace of the resource being referred to.
  24685. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24686. maxLength: 63
  24687. minLength: 1
  24688. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24689. type: string
  24690. required:
  24691. - name
  24692. type: object
  24693. token:
  24694. description: use static token to authenticate with
  24695. properties:
  24696. bearerToken:
  24697. description: |-
  24698. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24699. In some instances, `key` is a required field.
  24700. properties:
  24701. key:
  24702. description: |-
  24703. A key in the referenced Secret.
  24704. Some instances of this field may be defaulted, in others it may be required.
  24705. maxLength: 253
  24706. minLength: 1
  24707. pattern: ^[-._a-zA-Z0-9]+$
  24708. type: string
  24709. name:
  24710. description: The name of the Secret resource being referred to.
  24711. maxLength: 253
  24712. minLength: 1
  24713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24714. type: string
  24715. namespace:
  24716. description: |-
  24717. The namespace of the Secret resource being referred to.
  24718. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24719. maxLength: 63
  24720. minLength: 1
  24721. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24722. type: string
  24723. type: object
  24724. type: object
  24725. type: object
  24726. authRef:
  24727. description: A reference to a secret that contains the auth information.
  24728. properties:
  24729. key:
  24730. description: |-
  24731. A key in the referenced Secret.
  24732. Some instances of this field may be defaulted, in others it may be required.
  24733. maxLength: 253
  24734. minLength: 1
  24735. pattern: ^[-._a-zA-Z0-9]+$
  24736. type: string
  24737. name:
  24738. description: The name of the Secret resource being referred to.
  24739. maxLength: 253
  24740. minLength: 1
  24741. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24742. type: string
  24743. namespace:
  24744. description: |-
  24745. The namespace of the Secret resource being referred to.
  24746. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24747. maxLength: 63
  24748. minLength: 1
  24749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24750. type: string
  24751. type: object
  24752. remoteNamespace:
  24753. default: default
  24754. description: Remote namespace to fetch the secrets from
  24755. maxLength: 63
  24756. minLength: 1
  24757. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24758. type: string
  24759. server:
  24760. description: configures the Kubernetes server Address.
  24761. properties:
  24762. caBundle:
  24763. description: CABundle is a base64-encoded CA certificate
  24764. format: byte
  24765. type: string
  24766. caProvider:
  24767. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  24768. properties:
  24769. key:
  24770. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24771. maxLength: 253
  24772. minLength: 1
  24773. pattern: ^[-._a-zA-Z0-9]+$
  24774. type: string
  24775. name:
  24776. description: The name of the object located at the provider type.
  24777. maxLength: 253
  24778. minLength: 1
  24779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24780. type: string
  24781. namespace:
  24782. description: |-
  24783. The namespace the Provider type is in.
  24784. Can only be defined when used in a ClusterSecretStore.
  24785. maxLength: 63
  24786. minLength: 1
  24787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24788. type: string
  24789. type:
  24790. description: The type of provider to use such as "Secret", or "ConfigMap".
  24791. enum:
  24792. - Secret
  24793. - ConfigMap
  24794. type: string
  24795. required:
  24796. - name
  24797. - type
  24798. type: object
  24799. url:
  24800. default: kubernetes.default
  24801. description: configures the Kubernetes server Address.
  24802. type: string
  24803. type: object
  24804. type: object
  24805. onboardbase:
  24806. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  24807. properties:
  24808. apiHost:
  24809. default: https://public.onboardbase.com/api/v1/
  24810. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  24811. type: string
  24812. auth:
  24813. description: Auth configures how the Operator authenticates with the Onboardbase API
  24814. properties:
  24815. apiKeyRef:
  24816. description: |-
  24817. OnboardbaseAPIKey is the APIKey generated by an admin account.
  24818. It is used to recognize and authorize access to a project and environment within onboardbase
  24819. properties:
  24820. key:
  24821. description: |-
  24822. A key in the referenced Secret.
  24823. Some instances of this field may be defaulted, in others it may be required.
  24824. maxLength: 253
  24825. minLength: 1
  24826. pattern: ^[-._a-zA-Z0-9]+$
  24827. type: string
  24828. name:
  24829. description: The name of the Secret resource being referred to.
  24830. maxLength: 253
  24831. minLength: 1
  24832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24833. type: string
  24834. namespace:
  24835. description: |-
  24836. The namespace of the Secret resource being referred to.
  24837. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24838. maxLength: 63
  24839. minLength: 1
  24840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24841. type: string
  24842. type: object
  24843. passcodeRef:
  24844. description: OnboardbasePasscode is the passcode attached to the API Key
  24845. properties:
  24846. key:
  24847. description: |-
  24848. A key in the referenced Secret.
  24849. Some instances of this field may be defaulted, in others it may be required.
  24850. maxLength: 253
  24851. minLength: 1
  24852. pattern: ^[-._a-zA-Z0-9]+$
  24853. type: string
  24854. name:
  24855. description: The name of the Secret resource being referred to.
  24856. maxLength: 253
  24857. minLength: 1
  24858. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24859. type: string
  24860. namespace:
  24861. description: |-
  24862. The namespace of the Secret resource being referred to.
  24863. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24864. maxLength: 63
  24865. minLength: 1
  24866. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24867. type: string
  24868. type: object
  24869. required:
  24870. - apiKeyRef
  24871. - passcodeRef
  24872. type: object
  24873. environment:
  24874. default: development
  24875. description: Environment is the name of an environmnent within a project to pull the secrets from
  24876. type: string
  24877. project:
  24878. default: development
  24879. description: Project is an onboardbase project that the secrets should be pulled from
  24880. type: string
  24881. required:
  24882. - apiHost
  24883. - auth
  24884. - environment
  24885. - project
  24886. type: object
  24887. onepassword:
  24888. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  24889. properties:
  24890. auth:
  24891. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  24892. properties:
  24893. secretRef:
  24894. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  24895. properties:
  24896. connectTokenSecretRef:
  24897. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  24898. properties:
  24899. key:
  24900. description: |-
  24901. A key in the referenced Secret.
  24902. Some instances of this field may be defaulted, in others it may be required.
  24903. maxLength: 253
  24904. minLength: 1
  24905. pattern: ^[-._a-zA-Z0-9]+$
  24906. type: string
  24907. name:
  24908. description: The name of the Secret resource being referred to.
  24909. maxLength: 253
  24910. minLength: 1
  24911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24912. type: string
  24913. namespace:
  24914. description: |-
  24915. The namespace of the Secret resource being referred to.
  24916. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24917. maxLength: 63
  24918. minLength: 1
  24919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24920. type: string
  24921. type: object
  24922. required:
  24923. - connectTokenSecretRef
  24924. type: object
  24925. required:
  24926. - secretRef
  24927. type: object
  24928. connectHost:
  24929. description: ConnectHost defines the OnePassword Connect Server to connect to
  24930. type: string
  24931. vaults:
  24932. additionalProperties:
  24933. type: integer
  24934. description: Vaults defines which OnePassword vaults to search in which order
  24935. type: object
  24936. required:
  24937. - auth
  24938. - connectHost
  24939. - vaults
  24940. type: object
  24941. oracle:
  24942. description: Oracle configures this store to sync secrets using Oracle Vault provider
  24943. properties:
  24944. auth:
  24945. description: |-
  24946. Auth configures how secret-manager authenticates with the Oracle Vault.
  24947. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  24948. properties:
  24949. secretRef:
  24950. description: SecretRef to pass through sensitive information.
  24951. properties:
  24952. fingerprint:
  24953. description: Fingerprint is the fingerprint of the API private key.
  24954. properties:
  24955. key:
  24956. description: |-
  24957. A key in the referenced Secret.
  24958. Some instances of this field may be defaulted, in others it may be required.
  24959. maxLength: 253
  24960. minLength: 1
  24961. pattern: ^[-._a-zA-Z0-9]+$
  24962. type: string
  24963. name:
  24964. description: The name of the Secret resource being referred to.
  24965. maxLength: 253
  24966. minLength: 1
  24967. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24968. type: string
  24969. namespace:
  24970. description: |-
  24971. The namespace of the Secret resource being referred to.
  24972. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24973. maxLength: 63
  24974. minLength: 1
  24975. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24976. type: string
  24977. type: object
  24978. privatekey:
  24979. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  24980. properties:
  24981. key:
  24982. description: |-
  24983. A key in the referenced Secret.
  24984. Some instances of this field may be defaulted, in others it may be required.
  24985. maxLength: 253
  24986. minLength: 1
  24987. pattern: ^[-._a-zA-Z0-9]+$
  24988. type: string
  24989. name:
  24990. description: The name of the Secret resource being referred to.
  24991. maxLength: 253
  24992. minLength: 1
  24993. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24994. type: string
  24995. namespace:
  24996. description: |-
  24997. The namespace of the Secret resource being referred to.
  24998. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24999. maxLength: 63
  25000. minLength: 1
  25001. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25002. type: string
  25003. type: object
  25004. required:
  25005. - fingerprint
  25006. - privatekey
  25007. type: object
  25008. tenancy:
  25009. description: Tenancy is the tenancy OCID where user is located.
  25010. type: string
  25011. user:
  25012. description: User is an access OCID specific to the account.
  25013. type: string
  25014. required:
  25015. - secretRef
  25016. - tenancy
  25017. - user
  25018. type: object
  25019. compartment:
  25020. description: |-
  25021. Compartment is the vault compartment OCID.
  25022. Required for PushSecret
  25023. type: string
  25024. encryptionKey:
  25025. description: |-
  25026. EncryptionKey is the OCID of the encryption key within the vault.
  25027. Required for PushSecret
  25028. type: string
  25029. principalType:
  25030. description: |-
  25031. The type of principal to use for authentication. If left blank, the Auth struct will
  25032. determine the principal type. This optional field must be specified if using
  25033. workload identity.
  25034. enum:
  25035. - ""
  25036. - UserPrincipal
  25037. - InstancePrincipal
  25038. - Workload
  25039. type: string
  25040. region:
  25041. description: Region is the region where vault is located.
  25042. type: string
  25043. serviceAccountRef:
  25044. description: |-
  25045. ServiceAccountRef specified the service account
  25046. that should be used when authenticating with WorkloadIdentity.
  25047. properties:
  25048. audiences:
  25049. description: |-
  25050. Audience specifies the `aud` claim for the service account token
  25051. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25052. then this audiences will be appended to the list
  25053. items:
  25054. type: string
  25055. type: array
  25056. name:
  25057. description: The name of the ServiceAccount resource being referred to.
  25058. maxLength: 253
  25059. minLength: 1
  25060. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25061. type: string
  25062. namespace:
  25063. description: |-
  25064. Namespace of the resource being referred to.
  25065. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25066. maxLength: 63
  25067. minLength: 1
  25068. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25069. type: string
  25070. required:
  25071. - name
  25072. type: object
  25073. vault:
  25074. description: Vault is the vault's OCID of the specific vault where secret is located.
  25075. type: string
  25076. required:
  25077. - region
  25078. - vault
  25079. type: object
  25080. passbolt:
  25081. description: PassboltProvider defines configuration for the Passbolt provider.
  25082. properties:
  25083. auth:
  25084. description: Auth defines the information necessary to authenticate against Passbolt Server
  25085. properties:
  25086. passwordSecretRef:
  25087. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  25088. properties:
  25089. key:
  25090. description: |-
  25091. A key in the referenced Secret.
  25092. Some instances of this field may be defaulted, in others it may be required.
  25093. maxLength: 253
  25094. minLength: 1
  25095. pattern: ^[-._a-zA-Z0-9]+$
  25096. type: string
  25097. name:
  25098. description: The name of the Secret resource being referred to.
  25099. maxLength: 253
  25100. minLength: 1
  25101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25102. type: string
  25103. namespace:
  25104. description: |-
  25105. The namespace of the Secret resource being referred to.
  25106. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25107. maxLength: 63
  25108. minLength: 1
  25109. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25110. type: string
  25111. type: object
  25112. privateKeySecretRef:
  25113. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  25114. properties:
  25115. key:
  25116. description: |-
  25117. A key in the referenced Secret.
  25118. Some instances of this field may be defaulted, in others it may be required.
  25119. maxLength: 253
  25120. minLength: 1
  25121. pattern: ^[-._a-zA-Z0-9]+$
  25122. type: string
  25123. name:
  25124. description: The name of the Secret resource being referred to.
  25125. maxLength: 253
  25126. minLength: 1
  25127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25128. type: string
  25129. namespace:
  25130. description: |-
  25131. The namespace of the Secret resource being referred to.
  25132. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25133. maxLength: 63
  25134. minLength: 1
  25135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25136. type: string
  25137. type: object
  25138. required:
  25139. - passwordSecretRef
  25140. - privateKeySecretRef
  25141. type: object
  25142. host:
  25143. description: Host defines the Passbolt Server to connect to
  25144. type: string
  25145. required:
  25146. - auth
  25147. - host
  25148. type: object
  25149. passworddepot:
  25150. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  25151. properties:
  25152. auth:
  25153. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  25154. properties:
  25155. secretRef:
  25156. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  25157. properties:
  25158. credentials:
  25159. description: Username / Password is used for authentication.
  25160. properties:
  25161. key:
  25162. description: |-
  25163. A key in the referenced Secret.
  25164. Some instances of this field may be defaulted, in others it may be required.
  25165. maxLength: 253
  25166. minLength: 1
  25167. pattern: ^[-._a-zA-Z0-9]+$
  25168. type: string
  25169. name:
  25170. description: The name of the Secret resource being referred to.
  25171. maxLength: 253
  25172. minLength: 1
  25173. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25174. type: string
  25175. namespace:
  25176. description: |-
  25177. The namespace of the Secret resource being referred to.
  25178. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25179. maxLength: 63
  25180. minLength: 1
  25181. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25182. type: string
  25183. type: object
  25184. type: object
  25185. required:
  25186. - secretRef
  25187. type: object
  25188. database:
  25189. description: Database to use as source
  25190. type: string
  25191. host:
  25192. description: URL configures the Password Depot instance URL.
  25193. type: string
  25194. required:
  25195. - auth
  25196. - database
  25197. - host
  25198. type: object
  25199. previder:
  25200. description: Previder configures this store to sync secrets using the Previder provider
  25201. properties:
  25202. auth:
  25203. description: PreviderAuth contains a secretRef for credentials.
  25204. properties:
  25205. secretRef:
  25206. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  25207. properties:
  25208. accessToken:
  25209. description: The AccessToken is used for authentication
  25210. properties:
  25211. key:
  25212. description: |-
  25213. A key in the referenced Secret.
  25214. Some instances of this field may be defaulted, in others it may be required.
  25215. maxLength: 253
  25216. minLength: 1
  25217. pattern: ^[-._a-zA-Z0-9]+$
  25218. type: string
  25219. name:
  25220. description: The name of the Secret resource being referred to.
  25221. maxLength: 253
  25222. minLength: 1
  25223. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25224. type: string
  25225. namespace:
  25226. description: |-
  25227. The namespace of the Secret resource being referred to.
  25228. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25229. maxLength: 63
  25230. minLength: 1
  25231. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25232. type: string
  25233. type: object
  25234. required:
  25235. - accessToken
  25236. type: object
  25237. type: object
  25238. baseUri:
  25239. type: string
  25240. required:
  25241. - auth
  25242. type: object
  25243. pulumi:
  25244. description: Pulumi configures this store to sync secrets using the Pulumi provider
  25245. properties:
  25246. accessToken:
  25247. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  25248. properties:
  25249. secretRef:
  25250. description: SecretRef is a reference to a secret containing the Pulumi API token.
  25251. properties:
  25252. key:
  25253. description: |-
  25254. A key in the referenced Secret.
  25255. Some instances of this field may be defaulted, in others it may be required.
  25256. maxLength: 253
  25257. minLength: 1
  25258. pattern: ^[-._a-zA-Z0-9]+$
  25259. type: string
  25260. name:
  25261. description: The name of the Secret resource being referred to.
  25262. maxLength: 253
  25263. minLength: 1
  25264. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25265. type: string
  25266. namespace:
  25267. description: |-
  25268. The namespace of the Secret resource being referred to.
  25269. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25270. maxLength: 63
  25271. minLength: 1
  25272. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25273. type: string
  25274. type: object
  25275. type: object
  25276. apiUrl:
  25277. default: https://api.pulumi.com/api/esc
  25278. description: APIURL is the URL of the Pulumi API.
  25279. type: string
  25280. environment:
  25281. description: |-
  25282. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  25283. dynamically retrieved values from supported providers including all major clouds,
  25284. and other Pulumi ESC environments.
  25285. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  25286. type: string
  25287. organization:
  25288. description: |-
  25289. Organization are a space to collaborate on shared projects and stacks.
  25290. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  25291. type: string
  25292. project:
  25293. description: Project is the name of the Pulumi ESC project the environment belongs to.
  25294. type: string
  25295. required:
  25296. - accessToken
  25297. - environment
  25298. - organization
  25299. - project
  25300. type: object
  25301. scaleway:
  25302. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  25303. properties:
  25304. accessKey:
  25305. description: AccessKey is the non-secret part of the api key.
  25306. properties:
  25307. secretRef:
  25308. description: SecretRef references a key in a secret that will be used as value.
  25309. properties:
  25310. key:
  25311. description: |-
  25312. A key in the referenced Secret.
  25313. Some instances of this field may be defaulted, in others it may be required.
  25314. maxLength: 253
  25315. minLength: 1
  25316. pattern: ^[-._a-zA-Z0-9]+$
  25317. type: string
  25318. name:
  25319. description: The name of the Secret resource being referred to.
  25320. maxLength: 253
  25321. minLength: 1
  25322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25323. type: string
  25324. namespace:
  25325. description: |-
  25326. The namespace of the Secret resource being referred to.
  25327. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25328. maxLength: 63
  25329. minLength: 1
  25330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25331. type: string
  25332. type: object
  25333. value:
  25334. description: Value can be specified directly to set a value without using a secret.
  25335. type: string
  25336. type: object
  25337. apiUrl:
  25338. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  25339. type: string
  25340. projectId:
  25341. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  25342. type: string
  25343. region:
  25344. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  25345. type: string
  25346. secretKey:
  25347. description: SecretKey is the non-secret part of the api key.
  25348. properties:
  25349. secretRef:
  25350. description: SecretRef references a key in a secret that will be used as value.
  25351. properties:
  25352. key:
  25353. description: |-
  25354. A key in the referenced Secret.
  25355. Some instances of this field may be defaulted, in others it may be required.
  25356. maxLength: 253
  25357. minLength: 1
  25358. pattern: ^[-._a-zA-Z0-9]+$
  25359. type: string
  25360. name:
  25361. description: The name of the Secret resource being referred to.
  25362. maxLength: 253
  25363. minLength: 1
  25364. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25365. type: string
  25366. namespace:
  25367. description: |-
  25368. The namespace of the Secret resource being referred to.
  25369. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25370. maxLength: 63
  25371. minLength: 1
  25372. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25373. type: string
  25374. type: object
  25375. value:
  25376. description: Value can be specified directly to set a value without using a secret.
  25377. type: string
  25378. type: object
  25379. required:
  25380. - accessKey
  25381. - projectId
  25382. - region
  25383. - secretKey
  25384. type: object
  25385. secretserver:
  25386. description: |-
  25387. SecretServer configures this store to sync secrets using SecretServer provider
  25388. https://docs.delinea.com/online-help/secret-server/start.htm
  25389. properties:
  25390. password:
  25391. description: Password is the secret server account password.
  25392. properties:
  25393. secretRef:
  25394. description: SecretRef references a key in a secret that will be used as value.
  25395. properties:
  25396. key:
  25397. description: |-
  25398. A key in the referenced Secret.
  25399. Some instances of this field may be defaulted, in others it may be required.
  25400. maxLength: 253
  25401. minLength: 1
  25402. pattern: ^[-._a-zA-Z0-9]+$
  25403. type: string
  25404. name:
  25405. description: The name of the Secret resource being referred to.
  25406. maxLength: 253
  25407. minLength: 1
  25408. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25409. type: string
  25410. namespace:
  25411. description: |-
  25412. The namespace of the Secret resource being referred to.
  25413. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25414. maxLength: 63
  25415. minLength: 1
  25416. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25417. type: string
  25418. type: object
  25419. value:
  25420. description: Value can be specified directly to set a value without using a secret.
  25421. type: string
  25422. type: object
  25423. serverURL:
  25424. description: |-
  25425. ServerURL
  25426. URL to your secret server installation
  25427. type: string
  25428. username:
  25429. description: Username is the secret server account username.
  25430. properties:
  25431. secretRef:
  25432. description: SecretRef references a key in a secret that will be used as value.
  25433. properties:
  25434. key:
  25435. description: |-
  25436. A key in the referenced Secret.
  25437. Some instances of this field may be defaulted, in others it may be required.
  25438. maxLength: 253
  25439. minLength: 1
  25440. pattern: ^[-._a-zA-Z0-9]+$
  25441. type: string
  25442. name:
  25443. description: The name of the Secret resource being referred to.
  25444. maxLength: 253
  25445. minLength: 1
  25446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25447. type: string
  25448. namespace:
  25449. description: |-
  25450. The namespace of the Secret resource being referred to.
  25451. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25452. maxLength: 63
  25453. minLength: 1
  25454. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25455. type: string
  25456. type: object
  25457. value:
  25458. description: Value can be specified directly to set a value without using a secret.
  25459. type: string
  25460. type: object
  25461. required:
  25462. - password
  25463. - serverURL
  25464. - username
  25465. type: object
  25466. senhasegura:
  25467. description: Senhasegura configures this store to sync secrets using senhasegura provider
  25468. properties:
  25469. auth:
  25470. description: Auth defines parameters to authenticate in senhasegura
  25471. properties:
  25472. clientId:
  25473. type: string
  25474. clientSecretSecretRef:
  25475. description: |-
  25476. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25477. In some instances, `key` is a required field.
  25478. properties:
  25479. key:
  25480. description: |-
  25481. A key in the referenced Secret.
  25482. Some instances of this field may be defaulted, in others it may be required.
  25483. maxLength: 253
  25484. minLength: 1
  25485. pattern: ^[-._a-zA-Z0-9]+$
  25486. type: string
  25487. name:
  25488. description: The name of the Secret resource being referred to.
  25489. maxLength: 253
  25490. minLength: 1
  25491. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25492. type: string
  25493. namespace:
  25494. description: |-
  25495. The namespace of the Secret resource being referred to.
  25496. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25497. maxLength: 63
  25498. minLength: 1
  25499. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25500. type: string
  25501. type: object
  25502. required:
  25503. - clientId
  25504. - clientSecretSecretRef
  25505. type: object
  25506. ignoreSslCertificate:
  25507. default: false
  25508. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  25509. type: boolean
  25510. module:
  25511. description: Module defines which senhasegura module should be used to get secrets
  25512. type: string
  25513. url:
  25514. description: URL of senhasegura
  25515. type: string
  25516. required:
  25517. - auth
  25518. - module
  25519. - url
  25520. type: object
  25521. vault:
  25522. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  25523. properties:
  25524. auth:
  25525. description: Auth configures how secret-manager authenticates with the Vault server.
  25526. properties:
  25527. appRole:
  25528. description: |-
  25529. AppRole authenticates with Vault using the App Role auth mechanism,
  25530. with the role and secret stored in a Kubernetes Secret resource.
  25531. properties:
  25532. path:
  25533. default: approle
  25534. description: |-
  25535. Path where the App Role authentication backend is mounted
  25536. in Vault, e.g: "approle"
  25537. type: string
  25538. roleId:
  25539. description: |-
  25540. RoleID configured in the App Role authentication backend when setting
  25541. up the authentication backend in Vault.
  25542. type: string
  25543. roleRef:
  25544. description: |-
  25545. Reference to a key in a Secret that contains the App Role ID used
  25546. to authenticate with Vault.
  25547. The `key` field must be specified and denotes which entry within the Secret
  25548. resource is used as the app role id.
  25549. properties:
  25550. key:
  25551. description: |-
  25552. A key in the referenced Secret.
  25553. Some instances of this field may be defaulted, in others it may be required.
  25554. maxLength: 253
  25555. minLength: 1
  25556. pattern: ^[-._a-zA-Z0-9]+$
  25557. type: string
  25558. name:
  25559. description: The name of the Secret resource being referred to.
  25560. maxLength: 253
  25561. minLength: 1
  25562. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25563. type: string
  25564. namespace:
  25565. description: |-
  25566. The namespace of the Secret resource being referred to.
  25567. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25568. maxLength: 63
  25569. minLength: 1
  25570. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25571. type: string
  25572. type: object
  25573. secretRef:
  25574. description: |-
  25575. Reference to a key in a Secret that contains the App Role secret used
  25576. to authenticate with Vault.
  25577. The `key` field must be specified and denotes which entry within the Secret
  25578. resource is used as the app role secret.
  25579. properties:
  25580. key:
  25581. description: |-
  25582. A key in the referenced Secret.
  25583. Some instances of this field may be defaulted, in others it may be required.
  25584. maxLength: 253
  25585. minLength: 1
  25586. pattern: ^[-._a-zA-Z0-9]+$
  25587. type: string
  25588. name:
  25589. description: The name of the Secret resource being referred to.
  25590. maxLength: 253
  25591. minLength: 1
  25592. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25593. type: string
  25594. namespace:
  25595. description: |-
  25596. The namespace of the Secret resource being referred to.
  25597. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25598. maxLength: 63
  25599. minLength: 1
  25600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25601. type: string
  25602. type: object
  25603. required:
  25604. - path
  25605. - secretRef
  25606. type: object
  25607. cert:
  25608. description: |-
  25609. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  25610. Cert authentication method
  25611. properties:
  25612. clientCert:
  25613. description: |-
  25614. ClientCert is a certificate to authenticate using the Cert Vault
  25615. authentication method
  25616. properties:
  25617. key:
  25618. description: |-
  25619. A key in the referenced Secret.
  25620. Some instances of this field may be defaulted, in others it may be required.
  25621. maxLength: 253
  25622. minLength: 1
  25623. pattern: ^[-._a-zA-Z0-9]+$
  25624. type: string
  25625. name:
  25626. description: The name of the Secret resource being referred to.
  25627. maxLength: 253
  25628. minLength: 1
  25629. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25630. type: string
  25631. namespace:
  25632. description: |-
  25633. The namespace of the Secret resource being referred to.
  25634. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25635. maxLength: 63
  25636. minLength: 1
  25637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25638. type: string
  25639. type: object
  25640. secretRef:
  25641. description: |-
  25642. SecretRef to a key in a Secret resource containing client private key to
  25643. authenticate with Vault using the Cert authentication method
  25644. properties:
  25645. key:
  25646. description: |-
  25647. A key in the referenced Secret.
  25648. Some instances of this field may be defaulted, in others it may be required.
  25649. maxLength: 253
  25650. minLength: 1
  25651. pattern: ^[-._a-zA-Z0-9]+$
  25652. type: string
  25653. name:
  25654. description: The name of the Secret resource being referred to.
  25655. maxLength: 253
  25656. minLength: 1
  25657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25658. type: string
  25659. namespace:
  25660. description: |-
  25661. The namespace of the Secret resource being referred to.
  25662. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25663. maxLength: 63
  25664. minLength: 1
  25665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25666. type: string
  25667. type: object
  25668. type: object
  25669. iam:
  25670. description: |-
  25671. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  25672. AWS IAM authentication method
  25673. properties:
  25674. externalID:
  25675. description: AWS External ID set on assumed IAM roles
  25676. type: string
  25677. jwt:
  25678. description: Specify a service account with IRSA enabled
  25679. properties:
  25680. serviceAccountRef:
  25681. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  25682. properties:
  25683. audiences:
  25684. description: |-
  25685. Audience specifies the `aud` claim for the service account token
  25686. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25687. then this audiences will be appended to the list
  25688. items:
  25689. type: string
  25690. type: array
  25691. name:
  25692. description: The name of the ServiceAccount resource being referred to.
  25693. maxLength: 253
  25694. minLength: 1
  25695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25696. type: string
  25697. namespace:
  25698. description: |-
  25699. Namespace of the resource being referred to.
  25700. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25701. maxLength: 63
  25702. minLength: 1
  25703. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25704. type: string
  25705. required:
  25706. - name
  25707. type: object
  25708. type: object
  25709. path:
  25710. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  25711. type: string
  25712. region:
  25713. description: AWS region
  25714. type: string
  25715. role:
  25716. description: This is the AWS role to be assumed before talking to vault
  25717. type: string
  25718. secretRef:
  25719. description: Specify credentials in a Secret object
  25720. properties:
  25721. accessKeyIDSecretRef:
  25722. description: The AccessKeyID is used for authentication
  25723. properties:
  25724. key:
  25725. description: |-
  25726. A key in the referenced Secret.
  25727. Some instances of this field may be defaulted, in others it may be required.
  25728. maxLength: 253
  25729. minLength: 1
  25730. pattern: ^[-._a-zA-Z0-9]+$
  25731. type: string
  25732. name:
  25733. description: The name of the Secret resource being referred to.
  25734. maxLength: 253
  25735. minLength: 1
  25736. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25737. type: string
  25738. namespace:
  25739. description: |-
  25740. The namespace of the Secret resource being referred to.
  25741. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25742. maxLength: 63
  25743. minLength: 1
  25744. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25745. type: string
  25746. type: object
  25747. secretAccessKeySecretRef:
  25748. description: The SecretAccessKey is used for authentication
  25749. properties:
  25750. key:
  25751. description: |-
  25752. A key in the referenced Secret.
  25753. Some instances of this field may be defaulted, in others it may be required.
  25754. maxLength: 253
  25755. minLength: 1
  25756. pattern: ^[-._a-zA-Z0-9]+$
  25757. type: string
  25758. name:
  25759. description: The name of the Secret resource being referred to.
  25760. maxLength: 253
  25761. minLength: 1
  25762. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25763. type: string
  25764. namespace:
  25765. description: |-
  25766. The namespace of the Secret resource being referred to.
  25767. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25768. maxLength: 63
  25769. minLength: 1
  25770. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25771. type: string
  25772. type: object
  25773. sessionTokenSecretRef:
  25774. description: |-
  25775. The SessionToken used for authentication
  25776. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  25777. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  25778. properties:
  25779. key:
  25780. description: |-
  25781. A key in the referenced Secret.
  25782. Some instances of this field may be defaulted, in others it may be required.
  25783. maxLength: 253
  25784. minLength: 1
  25785. pattern: ^[-._a-zA-Z0-9]+$
  25786. type: string
  25787. name:
  25788. description: The name of the Secret resource being referred to.
  25789. maxLength: 253
  25790. minLength: 1
  25791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25792. type: string
  25793. namespace:
  25794. description: |-
  25795. The namespace of the Secret resource being referred to.
  25796. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25797. maxLength: 63
  25798. minLength: 1
  25799. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25800. type: string
  25801. type: object
  25802. type: object
  25803. vaultAwsIamServerID:
  25804. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  25805. type: string
  25806. vaultRole:
  25807. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  25808. type: string
  25809. required:
  25810. - vaultRole
  25811. type: object
  25812. jwt:
  25813. description: |-
  25814. Jwt authenticates with Vault by passing role and JWT token using the
  25815. JWT/OIDC authentication method
  25816. properties:
  25817. kubernetesServiceAccountToken:
  25818. description: |-
  25819. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  25820. a token for with the `TokenRequest` API.
  25821. properties:
  25822. audiences:
  25823. description: |-
  25824. Optional audiences field that will be used to request a temporary Kubernetes service
  25825. account token for the service account referenced by `serviceAccountRef`.
  25826. Defaults to a single audience `vault` it not specified.
  25827. Deprecated: use serviceAccountRef.Audiences instead
  25828. items:
  25829. type: string
  25830. type: array
  25831. expirationSeconds:
  25832. description: |-
  25833. Optional expiration time in seconds that will be used to request a temporary
  25834. Kubernetes service account token for the service account referenced by
  25835. `serviceAccountRef`.
  25836. Deprecated: this will be removed in the future.
  25837. Defaults to 10 minutes.
  25838. format: int64
  25839. type: integer
  25840. serviceAccountRef:
  25841. description: Service account field containing the name of a kubernetes ServiceAccount.
  25842. properties:
  25843. audiences:
  25844. description: |-
  25845. Audience specifies the `aud` claim for the service account token
  25846. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25847. then this audiences will be appended to the list
  25848. items:
  25849. type: string
  25850. type: array
  25851. name:
  25852. description: The name of the ServiceAccount resource being referred to.
  25853. maxLength: 253
  25854. minLength: 1
  25855. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25856. type: string
  25857. namespace:
  25858. description: |-
  25859. Namespace of the resource being referred to.
  25860. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25861. maxLength: 63
  25862. minLength: 1
  25863. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25864. type: string
  25865. required:
  25866. - name
  25867. type: object
  25868. required:
  25869. - serviceAccountRef
  25870. type: object
  25871. path:
  25872. default: jwt
  25873. description: |-
  25874. Path where the JWT authentication backend is mounted
  25875. in Vault, e.g: "jwt"
  25876. type: string
  25877. role:
  25878. description: |-
  25879. Role is a JWT role to authenticate using the JWT/OIDC Vault
  25880. authentication method
  25881. type: string
  25882. secretRef:
  25883. description: |-
  25884. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  25885. authenticate with Vault using the JWT/OIDC authentication method.
  25886. properties:
  25887. key:
  25888. description: |-
  25889. A key in the referenced Secret.
  25890. Some instances of this field may be defaulted, in others it may be required.
  25891. maxLength: 253
  25892. minLength: 1
  25893. pattern: ^[-._a-zA-Z0-9]+$
  25894. type: string
  25895. name:
  25896. description: The name of the Secret resource being referred to.
  25897. maxLength: 253
  25898. minLength: 1
  25899. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25900. type: string
  25901. namespace:
  25902. description: |-
  25903. The namespace of the Secret resource being referred to.
  25904. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25905. maxLength: 63
  25906. minLength: 1
  25907. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25908. type: string
  25909. type: object
  25910. required:
  25911. - path
  25912. type: object
  25913. kubernetes:
  25914. description: |-
  25915. Kubernetes authenticates with Vault by passing the ServiceAccount
  25916. token stored in the named Secret resource to the Vault server.
  25917. properties:
  25918. mountPath:
  25919. default: kubernetes
  25920. description: |-
  25921. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  25922. "kubernetes"
  25923. type: string
  25924. role:
  25925. description: |-
  25926. A required field containing the Vault Role to assume. A Role binds a
  25927. Kubernetes ServiceAccount with a set of Vault policies.
  25928. type: string
  25929. secretRef:
  25930. description: |-
  25931. Optional secret field containing a Kubernetes ServiceAccount JWT used
  25932. for authenticating with Vault. If a name is specified without a key,
  25933. `token` is the default. If one is not specified, the one bound to
  25934. the controller will be used.
  25935. properties:
  25936. key:
  25937. description: |-
  25938. A key in the referenced Secret.
  25939. Some instances of this field may be defaulted, in others it may be required.
  25940. maxLength: 253
  25941. minLength: 1
  25942. pattern: ^[-._a-zA-Z0-9]+$
  25943. type: string
  25944. name:
  25945. description: The name of the Secret resource being referred to.
  25946. maxLength: 253
  25947. minLength: 1
  25948. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25949. type: string
  25950. namespace:
  25951. description: |-
  25952. The namespace of the Secret resource being referred to.
  25953. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25954. maxLength: 63
  25955. minLength: 1
  25956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25957. type: string
  25958. type: object
  25959. serviceAccountRef:
  25960. description: |-
  25961. Optional service account field containing the name of a kubernetes ServiceAccount.
  25962. If the service account is specified, the service account secret token JWT will be used
  25963. for authenticating with Vault. If the service account selector is not supplied,
  25964. the secretRef will be used instead.
  25965. properties:
  25966. audiences:
  25967. description: |-
  25968. Audience specifies the `aud` claim for the service account token
  25969. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25970. then this audiences will be appended to the list
  25971. items:
  25972. type: string
  25973. type: array
  25974. name:
  25975. description: The name of the ServiceAccount resource being referred to.
  25976. maxLength: 253
  25977. minLength: 1
  25978. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25979. type: string
  25980. namespace:
  25981. description: |-
  25982. Namespace of the resource being referred to.
  25983. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25984. maxLength: 63
  25985. minLength: 1
  25986. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25987. type: string
  25988. required:
  25989. - name
  25990. type: object
  25991. required:
  25992. - mountPath
  25993. - role
  25994. type: object
  25995. ldap:
  25996. description: |-
  25997. Ldap authenticates with Vault by passing username/password pair using
  25998. the LDAP authentication method
  25999. properties:
  26000. path:
  26001. default: ldap
  26002. description: |-
  26003. Path where the LDAP authentication backend is mounted
  26004. in Vault, e.g: "ldap"
  26005. type: string
  26006. secretRef:
  26007. description: |-
  26008. SecretRef to a key in a Secret resource containing password for the LDAP
  26009. user used to authenticate with Vault using the LDAP authentication
  26010. method
  26011. properties:
  26012. key:
  26013. description: |-
  26014. A key in the referenced Secret.
  26015. Some instances of this field may be defaulted, in others it may be required.
  26016. maxLength: 253
  26017. minLength: 1
  26018. pattern: ^[-._a-zA-Z0-9]+$
  26019. type: string
  26020. name:
  26021. description: The name of the Secret resource being referred to.
  26022. maxLength: 253
  26023. minLength: 1
  26024. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26025. type: string
  26026. namespace:
  26027. description: |-
  26028. The namespace of the Secret resource being referred to.
  26029. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26030. maxLength: 63
  26031. minLength: 1
  26032. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26033. type: string
  26034. type: object
  26035. username:
  26036. description: |-
  26037. Username is an LDAP username used to authenticate using the LDAP Vault
  26038. authentication method
  26039. type: string
  26040. required:
  26041. - path
  26042. - username
  26043. type: object
  26044. namespace:
  26045. description: |-
  26046. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  26047. Namespaces is a set of features within Vault Enterprise that allows
  26048. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  26049. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  26050. This will default to Vault.Namespace field if set, or empty otherwise
  26051. type: string
  26052. tokenSecretRef:
  26053. description: TokenSecretRef authenticates with Vault by presenting a token.
  26054. properties:
  26055. key:
  26056. description: |-
  26057. A key in the referenced Secret.
  26058. Some instances of this field may be defaulted, in others it may be required.
  26059. maxLength: 253
  26060. minLength: 1
  26061. pattern: ^[-._a-zA-Z0-9]+$
  26062. type: string
  26063. name:
  26064. description: The name of the Secret resource being referred to.
  26065. maxLength: 253
  26066. minLength: 1
  26067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26068. type: string
  26069. namespace:
  26070. description: |-
  26071. The namespace of the Secret resource being referred to.
  26072. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26073. maxLength: 63
  26074. minLength: 1
  26075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26076. type: string
  26077. type: object
  26078. userPass:
  26079. description: UserPass authenticates with Vault by passing username/password pair
  26080. properties:
  26081. path:
  26082. default: userpass
  26083. description: |-
  26084. Path where the UserPassword authentication backend is mounted
  26085. in Vault, e.g: "userpass"
  26086. type: string
  26087. secretRef:
  26088. description: |-
  26089. SecretRef to a key in a Secret resource containing password for the
  26090. user used to authenticate with Vault using the UserPass authentication
  26091. method
  26092. properties:
  26093. key:
  26094. description: |-
  26095. A key in the referenced Secret.
  26096. Some instances of this field may be defaulted, in others it may be required.
  26097. maxLength: 253
  26098. minLength: 1
  26099. pattern: ^[-._a-zA-Z0-9]+$
  26100. type: string
  26101. name:
  26102. description: The name of the Secret resource being referred to.
  26103. maxLength: 253
  26104. minLength: 1
  26105. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26106. type: string
  26107. namespace:
  26108. description: |-
  26109. The namespace of the Secret resource being referred to.
  26110. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26111. maxLength: 63
  26112. minLength: 1
  26113. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26114. type: string
  26115. type: object
  26116. username:
  26117. description: |-
  26118. Username is a username used to authenticate using the UserPass Vault
  26119. authentication method
  26120. type: string
  26121. required:
  26122. - path
  26123. - username
  26124. type: object
  26125. type: object
  26126. caBundle:
  26127. description: |-
  26128. PEM encoded CA bundle used to validate Vault server certificate. Only used
  26129. if the Server URL is using HTTPS protocol. This parameter is ignored for
  26130. plain HTTP protocol connection. If not set the system root certificates
  26131. are used to validate the TLS connection.
  26132. format: byte
  26133. type: string
  26134. caProvider:
  26135. description: The provider for the CA bundle to use to validate Vault server certificate.
  26136. properties:
  26137. key:
  26138. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26139. maxLength: 253
  26140. minLength: 1
  26141. pattern: ^[-._a-zA-Z0-9]+$
  26142. type: string
  26143. name:
  26144. description: The name of the object located at the provider type.
  26145. maxLength: 253
  26146. minLength: 1
  26147. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26148. type: string
  26149. namespace:
  26150. description: |-
  26151. The namespace the Provider type is in.
  26152. Can only be defined when used in a ClusterSecretStore.
  26153. maxLength: 63
  26154. minLength: 1
  26155. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26156. type: string
  26157. type:
  26158. description: The type of provider to use such as "Secret", or "ConfigMap".
  26159. enum:
  26160. - Secret
  26161. - ConfigMap
  26162. type: string
  26163. required:
  26164. - name
  26165. - type
  26166. type: object
  26167. forwardInconsistent:
  26168. description: |-
  26169. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  26170. leader instead of simply retrying within a loop. This can increase performance if
  26171. the option is enabled serverside.
  26172. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  26173. type: boolean
  26174. headers:
  26175. additionalProperties:
  26176. type: string
  26177. description: Headers to be added in Vault request
  26178. type: object
  26179. namespace:
  26180. description: |-
  26181. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  26182. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  26183. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  26184. type: string
  26185. path:
  26186. description: |-
  26187. Path is the mount path of the Vault KV backend endpoint, e.g:
  26188. "secret". The v2 KV secret engine version specific "/data" path suffix
  26189. for fetching secrets from Vault is optional and will be appended
  26190. if not present in specified path.
  26191. type: string
  26192. readYourWrites:
  26193. description: |-
  26194. ReadYourWrites ensures isolated read-after-write semantics by
  26195. providing discovered cluster replication states in each request.
  26196. More information about eventual consistency in Vault can be found here
  26197. https://www.vaultproject.io/docs/enterprise/consistency
  26198. type: boolean
  26199. server:
  26200. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  26201. type: string
  26202. tls:
  26203. description: |-
  26204. The configuration used for client side related TLS communication, when the Vault server
  26205. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  26206. This parameter is ignored for plain HTTP protocol connection.
  26207. It's worth noting this configuration is different from the "TLS certificates auth method",
  26208. which is available under the `auth.cert` section.
  26209. properties:
  26210. certSecretRef:
  26211. description: |-
  26212. CertSecretRef is a certificate added to the transport layer
  26213. when communicating with the Vault server.
  26214. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  26215. properties:
  26216. key:
  26217. description: |-
  26218. A key in the referenced Secret.
  26219. Some instances of this field may be defaulted, in others it may be required.
  26220. maxLength: 253
  26221. minLength: 1
  26222. pattern: ^[-._a-zA-Z0-9]+$
  26223. type: string
  26224. name:
  26225. description: The name of the Secret resource being referred to.
  26226. maxLength: 253
  26227. minLength: 1
  26228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26229. type: string
  26230. namespace:
  26231. description: |-
  26232. The namespace of the Secret resource being referred to.
  26233. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26234. maxLength: 63
  26235. minLength: 1
  26236. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26237. type: string
  26238. type: object
  26239. keySecretRef:
  26240. description: |-
  26241. KeySecretRef to a key in a Secret resource containing client private key
  26242. added to the transport layer when communicating with the Vault server.
  26243. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  26244. properties:
  26245. key:
  26246. description: |-
  26247. A key in the referenced Secret.
  26248. Some instances of this field may be defaulted, in others it may be required.
  26249. maxLength: 253
  26250. minLength: 1
  26251. pattern: ^[-._a-zA-Z0-9]+$
  26252. type: string
  26253. name:
  26254. description: The name of the Secret resource being referred to.
  26255. maxLength: 253
  26256. minLength: 1
  26257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26258. type: string
  26259. namespace:
  26260. description: |-
  26261. The namespace of the Secret resource being referred to.
  26262. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26263. maxLength: 63
  26264. minLength: 1
  26265. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26266. type: string
  26267. type: object
  26268. type: object
  26269. version:
  26270. default: v2
  26271. description: |-
  26272. Version is the Vault KV secret engine version. This can be either "v1" or
  26273. "v2". Version defaults to "v2".
  26274. enum:
  26275. - v1
  26276. - v2
  26277. type: string
  26278. required:
  26279. - server
  26280. type: object
  26281. webhook:
  26282. description: Webhook configures this store to sync secrets using a generic templated webhook
  26283. properties:
  26284. auth:
  26285. description: Auth specifies a authorization protocol. Only one protocol may be set.
  26286. maxProperties: 1
  26287. minProperties: 1
  26288. properties:
  26289. ntlm:
  26290. description: NTLMProtocol configures the store to use NTLM for auth
  26291. properties:
  26292. passwordSecret:
  26293. description: |-
  26294. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26295. In some instances, `key` is a required field.
  26296. properties:
  26297. key:
  26298. description: |-
  26299. A key in the referenced Secret.
  26300. Some instances of this field may be defaulted, in others it may be required.
  26301. maxLength: 253
  26302. minLength: 1
  26303. pattern: ^[-._a-zA-Z0-9]+$
  26304. type: string
  26305. name:
  26306. description: The name of the Secret resource being referred to.
  26307. maxLength: 253
  26308. minLength: 1
  26309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26310. type: string
  26311. namespace:
  26312. description: |-
  26313. The namespace of the Secret resource being referred to.
  26314. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26315. maxLength: 63
  26316. minLength: 1
  26317. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26318. type: string
  26319. type: object
  26320. usernameSecret:
  26321. description: |-
  26322. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26323. In some instances, `key` is a required field.
  26324. properties:
  26325. key:
  26326. description: |-
  26327. A key in the referenced Secret.
  26328. Some instances of this field may be defaulted, in others it may be required.
  26329. maxLength: 253
  26330. minLength: 1
  26331. pattern: ^[-._a-zA-Z0-9]+$
  26332. type: string
  26333. name:
  26334. description: The name of the Secret resource being referred to.
  26335. maxLength: 253
  26336. minLength: 1
  26337. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26338. type: string
  26339. namespace:
  26340. description: |-
  26341. The namespace of the Secret resource being referred to.
  26342. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26343. maxLength: 63
  26344. minLength: 1
  26345. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26346. type: string
  26347. type: object
  26348. required:
  26349. - passwordSecret
  26350. - usernameSecret
  26351. type: object
  26352. type: object
  26353. body:
  26354. description: Body
  26355. type: string
  26356. caBundle:
  26357. description: |-
  26358. PEM encoded CA bundle used to validate webhook server certificate. Only used
  26359. if the Server URL is using HTTPS protocol. This parameter is ignored for
  26360. plain HTTP protocol connection. If not set the system root certificates
  26361. are used to validate the TLS connection.
  26362. format: byte
  26363. type: string
  26364. caProvider:
  26365. description: The provider for the CA bundle to use to validate webhook server certificate.
  26366. properties:
  26367. key:
  26368. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26369. maxLength: 253
  26370. minLength: 1
  26371. pattern: ^[-._a-zA-Z0-9]+$
  26372. type: string
  26373. name:
  26374. description: The name of the object located at the provider type.
  26375. maxLength: 253
  26376. minLength: 1
  26377. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26378. type: string
  26379. namespace:
  26380. description: The namespace the Provider type is in.
  26381. maxLength: 63
  26382. minLength: 1
  26383. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26384. type: string
  26385. type:
  26386. description: The type of provider to use such as "Secret", or "ConfigMap".
  26387. enum:
  26388. - Secret
  26389. - ConfigMap
  26390. type: string
  26391. required:
  26392. - name
  26393. - type
  26394. type: object
  26395. headers:
  26396. additionalProperties:
  26397. type: string
  26398. description: Headers
  26399. type: object
  26400. method:
  26401. description: Webhook Method
  26402. type: string
  26403. result:
  26404. description: Result formatting
  26405. properties:
  26406. jsonPath:
  26407. description: Json path of return value
  26408. type: string
  26409. type: object
  26410. secrets:
  26411. description: |-
  26412. Secrets to fill in templates
  26413. These secrets will be passed to the templating function as key value pairs under the given name
  26414. items:
  26415. description: WebhookSecret defines a secret to be used in webhook templates.
  26416. properties:
  26417. name:
  26418. description: Name of this secret in templates
  26419. type: string
  26420. secretRef:
  26421. description: Secret ref to fill in credentials
  26422. properties:
  26423. key:
  26424. description: |-
  26425. A key in the referenced Secret.
  26426. Some instances of this field may be defaulted, in others it may be required.
  26427. maxLength: 253
  26428. minLength: 1
  26429. pattern: ^[-._a-zA-Z0-9]+$
  26430. type: string
  26431. name:
  26432. description: The name of the Secret resource being referred to.
  26433. maxLength: 253
  26434. minLength: 1
  26435. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26436. type: string
  26437. namespace:
  26438. description: |-
  26439. The namespace of the Secret resource being referred to.
  26440. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26441. maxLength: 63
  26442. minLength: 1
  26443. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26444. type: string
  26445. type: object
  26446. required:
  26447. - name
  26448. - secretRef
  26449. type: object
  26450. type: array
  26451. timeout:
  26452. description: Timeout
  26453. type: string
  26454. url:
  26455. description: Webhook url to call
  26456. type: string
  26457. required:
  26458. - result
  26459. - url
  26460. type: object
  26461. yandexcertificatemanager:
  26462. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  26463. properties:
  26464. apiEndpoint:
  26465. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  26466. type: string
  26467. auth:
  26468. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  26469. properties:
  26470. authorizedKeySecretRef:
  26471. description: The authorized key used for authentication
  26472. properties:
  26473. key:
  26474. description: |-
  26475. A key in the referenced Secret.
  26476. Some instances of this field may be defaulted, in others it may be required.
  26477. maxLength: 253
  26478. minLength: 1
  26479. pattern: ^[-._a-zA-Z0-9]+$
  26480. type: string
  26481. name:
  26482. description: The name of the Secret resource being referred to.
  26483. maxLength: 253
  26484. minLength: 1
  26485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26486. type: string
  26487. namespace:
  26488. description: |-
  26489. The namespace of the Secret resource being referred to.
  26490. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26491. maxLength: 63
  26492. minLength: 1
  26493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26494. type: string
  26495. type: object
  26496. type: object
  26497. caProvider:
  26498. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  26499. properties:
  26500. certSecretRef:
  26501. description: |-
  26502. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26503. In some instances, `key` is a required field.
  26504. properties:
  26505. key:
  26506. description: |-
  26507. A key in the referenced Secret.
  26508. Some instances of this field may be defaulted, in others it may be required.
  26509. maxLength: 253
  26510. minLength: 1
  26511. pattern: ^[-._a-zA-Z0-9]+$
  26512. type: string
  26513. name:
  26514. description: The name of the Secret resource being referred to.
  26515. maxLength: 253
  26516. minLength: 1
  26517. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26518. type: string
  26519. namespace:
  26520. description: |-
  26521. The namespace of the Secret resource being referred to.
  26522. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26523. maxLength: 63
  26524. minLength: 1
  26525. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26526. type: string
  26527. type: object
  26528. type: object
  26529. required:
  26530. - auth
  26531. type: object
  26532. yandexlockbox:
  26533. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  26534. properties:
  26535. apiEndpoint:
  26536. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  26537. type: string
  26538. auth:
  26539. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  26540. properties:
  26541. authorizedKeySecretRef:
  26542. description: The authorized key used for authentication
  26543. properties:
  26544. key:
  26545. description: |-
  26546. A key in the referenced Secret.
  26547. Some instances of this field may be defaulted, in others it may be required.
  26548. maxLength: 253
  26549. minLength: 1
  26550. pattern: ^[-._a-zA-Z0-9]+$
  26551. type: string
  26552. name:
  26553. description: The name of the Secret resource being referred to.
  26554. maxLength: 253
  26555. minLength: 1
  26556. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26557. type: string
  26558. namespace:
  26559. description: |-
  26560. The namespace of the Secret resource being referred to.
  26561. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26562. maxLength: 63
  26563. minLength: 1
  26564. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26565. type: string
  26566. type: object
  26567. type: object
  26568. caProvider:
  26569. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  26570. properties:
  26571. certSecretRef:
  26572. description: |-
  26573. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26574. In some instances, `key` is a required field.
  26575. properties:
  26576. key:
  26577. description: |-
  26578. A key in the referenced Secret.
  26579. Some instances of this field may be defaulted, in others it may be required.
  26580. maxLength: 253
  26581. minLength: 1
  26582. pattern: ^[-._a-zA-Z0-9]+$
  26583. type: string
  26584. name:
  26585. description: The name of the Secret resource being referred to.
  26586. maxLength: 253
  26587. minLength: 1
  26588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26589. type: string
  26590. namespace:
  26591. description: |-
  26592. The namespace of the Secret resource being referred to.
  26593. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26594. maxLength: 63
  26595. minLength: 1
  26596. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26597. type: string
  26598. type: object
  26599. type: object
  26600. required:
  26601. - auth
  26602. type: object
  26603. type: object
  26604. refreshInterval:
  26605. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  26606. type: integer
  26607. retrySettings:
  26608. description: Used to configure HTTP retries on failures.
  26609. properties:
  26610. maxRetries:
  26611. description: MaxRetries is the maximum number of retry attempts.
  26612. format: int32
  26613. type: integer
  26614. retryInterval:
  26615. description: RetryInterval is the interval between retry attempts.
  26616. type: string
  26617. type: object
  26618. required:
  26619. - provider
  26620. type: object
  26621. status:
  26622. description: SecretStoreStatus defines the observed state of the SecretStore.
  26623. properties:
  26624. capabilities:
  26625. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  26626. type: string
  26627. conditions:
  26628. items:
  26629. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  26630. properties:
  26631. lastTransitionTime:
  26632. format: date-time
  26633. type: string
  26634. message:
  26635. type: string
  26636. reason:
  26637. type: string
  26638. status:
  26639. type: string
  26640. type:
  26641. description: SecretStoreConditionType represents the condition type of the SecretStore.
  26642. type: string
  26643. required:
  26644. - status
  26645. - type
  26646. type: object
  26647. type: array
  26648. type: object
  26649. type: object
  26650. served: false
  26651. storage: false
  26652. subresources:
  26653. status: {}
  26654. ---
  26655. apiVersion: apiextensions.k8s.io/v1
  26656. kind: CustomResourceDefinition
  26657. metadata:
  26658. annotations:
  26659. controller-gen.kubebuilder.io/version: v0.19.0
  26660. labels:
  26661. external-secrets.io/component: controller
  26662. name: acraccesstokens.generators.external-secrets.io
  26663. spec:
  26664. group: generators.external-secrets.io
  26665. names:
  26666. categories:
  26667. - external-secrets
  26668. - external-secrets-generators
  26669. kind: ACRAccessToken
  26670. listKind: ACRAccessTokenList
  26671. plural: acraccesstokens
  26672. singular: acraccesstoken
  26673. scope: Namespaced
  26674. versions:
  26675. - name: v1alpha1
  26676. schema:
  26677. openAPIV3Schema:
  26678. description: |-
  26679. ACRAccessToken returns an Azure Container Registry token
  26680. that can be used for pushing/pulling images.
  26681. Note: by default it will return an ACR Refresh Token with full access
  26682. (depending on the identity).
  26683. This can be scoped down to the repository level using .spec.scope.
  26684. In case scope is defined it will return an ACR Access Token.
  26685. See docs: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md
  26686. properties:
  26687. apiVersion:
  26688. description: |-
  26689. APIVersion defines the versioned schema of this representation of an object.
  26690. Servers should convert recognized schemas to the latest internal value, and
  26691. may reject unrecognized values.
  26692. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  26693. type: string
  26694. kind:
  26695. description: |-
  26696. Kind is a string value representing the REST resource this object represents.
  26697. Servers may infer this from the endpoint the client submits requests to.
  26698. Cannot be updated.
  26699. In CamelCase.
  26700. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  26701. type: string
  26702. metadata:
  26703. type: object
  26704. spec:
  26705. description: |-
  26706. ACRAccessTokenSpec defines how to generate the access token
  26707. e.g. how to authenticate and which registry to use.
  26708. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  26709. properties:
  26710. auth:
  26711. description: ACRAuth defines the authentication methods for Azure Container Registry.
  26712. properties:
  26713. managedIdentity:
  26714. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  26715. properties:
  26716. identityId:
  26717. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  26718. type: string
  26719. type: object
  26720. servicePrincipal:
  26721. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  26722. properties:
  26723. secretRef:
  26724. description: |-
  26725. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  26726. It uses static credentials stored in a Kind=Secret.
  26727. properties:
  26728. clientId:
  26729. description: The Azure clientId of the service principle used for authentication.
  26730. properties:
  26731. key:
  26732. description: |-
  26733. A key in the referenced Secret.
  26734. Some instances of this field may be defaulted, in others it may be required.
  26735. maxLength: 253
  26736. minLength: 1
  26737. pattern: ^[-._a-zA-Z0-9]+$
  26738. type: string
  26739. name:
  26740. description: The name of the Secret resource being referred to.
  26741. maxLength: 253
  26742. minLength: 1
  26743. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26744. type: string
  26745. namespace:
  26746. description: |-
  26747. The namespace of the Secret resource being referred to.
  26748. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26749. maxLength: 63
  26750. minLength: 1
  26751. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26752. type: string
  26753. type: object
  26754. clientSecret:
  26755. description: The Azure ClientSecret of the service principle used for authentication.
  26756. properties:
  26757. key:
  26758. description: |-
  26759. A key in the referenced Secret.
  26760. Some instances of this field may be defaulted, in others it may be required.
  26761. maxLength: 253
  26762. minLength: 1
  26763. pattern: ^[-._a-zA-Z0-9]+$
  26764. type: string
  26765. name:
  26766. description: The name of the Secret resource being referred to.
  26767. maxLength: 253
  26768. minLength: 1
  26769. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26770. type: string
  26771. namespace:
  26772. description: |-
  26773. The namespace of the Secret resource being referred to.
  26774. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26775. maxLength: 63
  26776. minLength: 1
  26777. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26778. type: string
  26779. type: object
  26780. type: object
  26781. required:
  26782. - secretRef
  26783. type: object
  26784. workloadIdentity:
  26785. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  26786. properties:
  26787. serviceAccountRef:
  26788. description: |-
  26789. ServiceAccountRef specified the service account
  26790. that should be used when authenticating with WorkloadIdentity.
  26791. properties:
  26792. audiences:
  26793. description: |-
  26794. Audience specifies the `aud` claim for the service account token
  26795. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  26796. then this audiences will be appended to the list
  26797. items:
  26798. type: string
  26799. type: array
  26800. name:
  26801. description: The name of the ServiceAccount resource being referred to.
  26802. maxLength: 253
  26803. minLength: 1
  26804. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26805. type: string
  26806. namespace:
  26807. description: |-
  26808. Namespace of the resource being referred to.
  26809. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26810. maxLength: 63
  26811. minLength: 1
  26812. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26813. type: string
  26814. required:
  26815. - name
  26816. type: object
  26817. type: object
  26818. type: object
  26819. environmentType:
  26820. default: PublicCloud
  26821. description: |-
  26822. EnvironmentType specifies the Azure cloud environment endpoints to use for
  26823. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  26824. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  26825. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  26826. enum:
  26827. - PublicCloud
  26828. - USGovernmentCloud
  26829. - ChinaCloud
  26830. - GermanCloud
  26831. - AzureStackCloud
  26832. type: string
  26833. registry:
  26834. description: |-
  26835. the domain name of the ACR registry
  26836. e.g. foobarexample.azurecr.io
  26837. type: string
  26838. scope:
  26839. description: |-
  26840. Define the scope for the access token, e.g. pull/push access for a repository.
  26841. if not provided it will return a refresh token that has full scope.
  26842. Note: you need to pin it down to the repository level, there is no wildcard available.
  26843. examples:
  26844. repository:my-repository:pull,push
  26845. repository:my-repository:pull
  26846. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  26847. type: string
  26848. tenantId:
  26849. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  26850. type: string
  26851. required:
  26852. - auth
  26853. - registry
  26854. type: object
  26855. type: object
  26856. served: true
  26857. storage: true
  26858. subresources:
  26859. status: {}
  26860. ---
  26861. apiVersion: apiextensions.k8s.io/v1
  26862. kind: CustomResourceDefinition
  26863. metadata:
  26864. annotations:
  26865. controller-gen.kubebuilder.io/version: v0.19.0
  26866. labels:
  26867. external-secrets.io/component: controller
  26868. name: beyondtrustworkloadcredentialsdynamicsecrets.generators.external-secrets.io
  26869. spec:
  26870. group: generators.external-secrets.io
  26871. names:
  26872. categories:
  26873. - external-secrets
  26874. - external-secrets-generators
  26875. kind: BeyondtrustWorkloadCredentialsDynamicSecret
  26876. listKind: BeyondtrustWorkloadCredentialsDynamicSecretList
  26877. plural: beyondtrustworkloadcredentialsdynamicsecrets
  26878. singular: beyondtrustworkloadcredentialsdynamicsecret
  26879. scope: Namespaced
  26880. versions:
  26881. - name: v1alpha1
  26882. schema:
  26883. openAPIV3Schema:
  26884. description: |-
  26885. BeyondtrustWorkloadCredentialsDynamicSecret represents a generator that requests dynamic credentials from BeyondTrust Workload Credentials.
  26886. This generator calls the BeyondTrust Workload Credentials API to generate fresh, temporary credentials
  26887. (such as AWS STS credentials) each time an ExternalSecret is refreshed.
  26888. Dynamic secret definitions must be created in BeyondTrust Workload Credentials before they can be referenced.
  26889. For complete documentation, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26890. properties:
  26891. apiVersion:
  26892. description: |-
  26893. APIVersion defines the versioned schema of this representation of an object.
  26894. Servers should convert recognized schemas to the latest internal value, and
  26895. may reject unrecognized values.
  26896. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  26897. type: string
  26898. kind:
  26899. description: |-
  26900. Kind is a string value representing the REST resource this object represents.
  26901. Servers may infer this from the endpoint the client submits requests to.
  26902. Cannot be updated.
  26903. In CamelCase.
  26904. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  26905. type: string
  26906. metadata:
  26907. type: object
  26908. spec:
  26909. description: |-
  26910. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  26911. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  26912. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26913. properties:
  26914. controller:
  26915. description: |-
  26916. Controller selects the controller that should handle this generator.
  26917. Leave empty to use the default controller.
  26918. type: string
  26919. provider:
  26920. description: |-
  26921. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  26922. server connection details, and the folder path to the dynamic secret definition.
  26923. The folderPath should point to a dynamic secret definition that has been created in
  26924. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  26925. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26926. properties:
  26927. auth:
  26928. description: |-
  26929. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  26930. Currently supports API key authentication via Kubernetes secret reference.
  26931. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  26932. properties:
  26933. apikey:
  26934. description: |-
  26935. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  26936. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  26937. properties:
  26938. token:
  26939. description: |-
  26940. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  26941. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  26942. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  26943. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  26944. properties:
  26945. key:
  26946. description: |-
  26947. A key in the referenced Secret.
  26948. Some instances of this field may be defaulted, in others it may be required.
  26949. maxLength: 253
  26950. minLength: 1
  26951. pattern: ^[-._a-zA-Z0-9]+$
  26952. type: string
  26953. name:
  26954. description: The name of the Secret resource being referred to.
  26955. maxLength: 253
  26956. minLength: 1
  26957. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26958. type: string
  26959. namespace:
  26960. description: |-
  26961. The namespace of the Secret resource being referred to.
  26962. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26963. maxLength: 63
  26964. minLength: 1
  26965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26966. type: string
  26967. type: object
  26968. required:
  26969. - token
  26970. type: object
  26971. required:
  26972. - apikey
  26973. type: object
  26974. caBundle:
  26975. description: |-
  26976. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  26977. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  26978. If not set, the system's trusted root certificates are used.
  26979. format: byte
  26980. type: string
  26981. caProvider:
  26982. description: |-
  26983. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  26984. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  26985. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  26986. properties:
  26987. key:
  26988. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26989. maxLength: 253
  26990. minLength: 1
  26991. pattern: ^[-._a-zA-Z0-9]+$
  26992. type: string
  26993. name:
  26994. description: The name of the object located at the provider type.
  26995. maxLength: 253
  26996. minLength: 1
  26997. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26998. type: string
  26999. namespace:
  27000. description: |-
  27001. The namespace the Provider type is in.
  27002. Can only be defined when used in a ClusterSecretStore.
  27003. maxLength: 63
  27004. minLength: 1
  27005. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27006. type: string
  27007. type:
  27008. description: The type of provider to use such as "Secret", or "ConfigMap".
  27009. enum:
  27010. - Secret
  27011. - ConfigMap
  27012. type: string
  27013. required:
  27014. - name
  27015. - type
  27016. type: object
  27017. folderPath:
  27018. description: |-
  27019. FolderPath specifies the default folder path for secret retrieval.
  27020. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  27021. Example: "production/database" or "dev/api-keys"
  27022. Leave empty to retrieve secrets from the root folder.
  27023. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  27024. type: string
  27025. server:
  27026. description: |-
  27027. Server configures the BeyondTrust Workload Credentials server connection details.
  27028. Includes the API URL and Site ID for your BeyondTrust instance.
  27029. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27030. properties:
  27031. apiUrl:
  27032. description: |-
  27033. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  27034. This should be the full URL to your BeyondTrust instance.
  27035. Example: https://api.beyondtrust.io/siie
  27036. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  27037. type: string
  27038. siteId:
  27039. description: |-
  27040. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  27041. This identifier is unique to your BeyondTrust Workload Credentials instance.
  27042. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  27043. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  27044. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27045. type: string
  27046. required:
  27047. - apiUrl
  27048. - siteId
  27049. type: object
  27050. required:
  27051. - auth
  27052. - server
  27053. type: object
  27054. retrySettings:
  27055. description: |-
  27056. RetrySettings configures exponential backoff for failed API requests.
  27057. If not specified, uses the default retry settings.
  27058. properties:
  27059. maxRetries:
  27060. format: int32
  27061. type: integer
  27062. retryInterval:
  27063. type: string
  27064. type: object
  27065. required:
  27066. - provider
  27067. type: object
  27068. type: object
  27069. served: true
  27070. storage: true
  27071. subresources:
  27072. status: {}
  27073. ---
  27074. apiVersion: apiextensions.k8s.io/v1
  27075. kind: CustomResourceDefinition
  27076. metadata:
  27077. annotations:
  27078. controller-gen.kubebuilder.io/version: v0.19.0
  27079. labels:
  27080. external-secrets.io/component: controller
  27081. name: cloudsmithaccesstokens.generators.external-secrets.io
  27082. spec:
  27083. group: generators.external-secrets.io
  27084. names:
  27085. categories:
  27086. - external-secrets
  27087. - external-secrets-generators
  27088. kind: CloudsmithAccessToken
  27089. listKind: CloudsmithAccessTokenList
  27090. plural: cloudsmithaccesstokens
  27091. singular: cloudsmithaccesstoken
  27092. scope: Namespaced
  27093. versions:
  27094. - name: v1alpha1
  27095. schema:
  27096. openAPIV3Schema:
  27097. description: CloudsmithAccessToken generates Cloudsmith access token using OIDC authentication
  27098. properties:
  27099. apiVersion:
  27100. description: |-
  27101. APIVersion defines the versioned schema of this representation of an object.
  27102. Servers should convert recognized schemas to the latest internal value, and
  27103. may reject unrecognized values.
  27104. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27105. type: string
  27106. kind:
  27107. description: |-
  27108. Kind is a string value representing the REST resource this object represents.
  27109. Servers may infer this from the endpoint the client submits requests to.
  27110. Cannot be updated.
  27111. In CamelCase.
  27112. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27113. type: string
  27114. metadata:
  27115. type: object
  27116. spec:
  27117. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  27118. properties:
  27119. apiUrl:
  27120. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  27121. type: string
  27122. orgSlug:
  27123. description: OrgSlug is the organization slug in Cloudsmith
  27124. type: string
  27125. serviceAccountRef:
  27126. description: Name of the service account you are federating with
  27127. properties:
  27128. audiences:
  27129. description: |-
  27130. Audience specifies the `aud` claim for the service account token
  27131. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27132. then this audiences will be appended to the list
  27133. items:
  27134. type: string
  27135. type: array
  27136. name:
  27137. description: The name of the ServiceAccount resource being referred to.
  27138. maxLength: 253
  27139. minLength: 1
  27140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27141. type: string
  27142. namespace:
  27143. description: |-
  27144. Namespace of the resource being referred to.
  27145. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27146. maxLength: 63
  27147. minLength: 1
  27148. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27149. type: string
  27150. required:
  27151. - name
  27152. type: object
  27153. serviceSlug:
  27154. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  27155. type: string
  27156. required:
  27157. - orgSlug
  27158. - serviceAccountRef
  27159. - serviceSlug
  27160. type: object
  27161. type: object
  27162. served: true
  27163. storage: true
  27164. subresources:
  27165. status: {}
  27166. ---
  27167. apiVersion: apiextensions.k8s.io/v1
  27168. kind: CustomResourceDefinition
  27169. metadata:
  27170. annotations:
  27171. controller-gen.kubebuilder.io/version: v0.19.0
  27172. labels:
  27173. external-secrets.io/component: controller
  27174. name: clustergenerators.generators.external-secrets.io
  27175. spec:
  27176. group: generators.external-secrets.io
  27177. names:
  27178. categories:
  27179. - external-secrets
  27180. - external-secrets-generators
  27181. kind: ClusterGenerator
  27182. listKind: ClusterGeneratorList
  27183. plural: clustergenerators
  27184. singular: clustergenerator
  27185. scope: Cluster
  27186. versions:
  27187. - name: v1alpha1
  27188. schema:
  27189. openAPIV3Schema:
  27190. description: ClusterGenerator represents a cluster-wide generator which can be referenced as part of `generatorRef` fields.
  27191. properties:
  27192. apiVersion:
  27193. description: |-
  27194. APIVersion defines the versioned schema of this representation of an object.
  27195. Servers should convert recognized schemas to the latest internal value, and
  27196. may reject unrecognized values.
  27197. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27198. type: string
  27199. kind:
  27200. description: |-
  27201. Kind is a string value representing the REST resource this object represents.
  27202. Servers may infer this from the endpoint the client submits requests to.
  27203. Cannot be updated.
  27204. In CamelCase.
  27205. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27206. type: string
  27207. metadata:
  27208. type: object
  27209. spec:
  27210. description: ClusterGeneratorSpec defines the desired state of a ClusterGenerator.
  27211. properties:
  27212. generator:
  27213. description: Generator the spec for this generator, must match the kind.
  27214. maxProperties: 1
  27215. minProperties: 1
  27216. properties:
  27217. acrAccessTokenSpec:
  27218. description: |-
  27219. ACRAccessTokenSpec defines how to generate the access token
  27220. e.g. how to authenticate and which registry to use.
  27221. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  27222. properties:
  27223. auth:
  27224. description: ACRAuth defines the authentication methods for Azure Container Registry.
  27225. properties:
  27226. managedIdentity:
  27227. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  27228. properties:
  27229. identityId:
  27230. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  27231. type: string
  27232. type: object
  27233. servicePrincipal:
  27234. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  27235. properties:
  27236. secretRef:
  27237. description: |-
  27238. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  27239. It uses static credentials stored in a Kind=Secret.
  27240. properties:
  27241. clientId:
  27242. description: The Azure clientId of the service principle used for authentication.
  27243. properties:
  27244. key:
  27245. description: |-
  27246. A key in the referenced Secret.
  27247. Some instances of this field may be defaulted, in others it may be required.
  27248. maxLength: 253
  27249. minLength: 1
  27250. pattern: ^[-._a-zA-Z0-9]+$
  27251. type: string
  27252. name:
  27253. description: The name of the Secret resource being referred to.
  27254. maxLength: 253
  27255. minLength: 1
  27256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27257. type: string
  27258. namespace:
  27259. description: |-
  27260. The namespace of the Secret resource being referred to.
  27261. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27262. maxLength: 63
  27263. minLength: 1
  27264. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27265. type: string
  27266. type: object
  27267. clientSecret:
  27268. description: The Azure ClientSecret of the service principle used for authentication.
  27269. properties:
  27270. key:
  27271. description: |-
  27272. A key in the referenced Secret.
  27273. Some instances of this field may be defaulted, in others it may be required.
  27274. maxLength: 253
  27275. minLength: 1
  27276. pattern: ^[-._a-zA-Z0-9]+$
  27277. type: string
  27278. name:
  27279. description: The name of the Secret resource being referred to.
  27280. maxLength: 253
  27281. minLength: 1
  27282. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27283. type: string
  27284. namespace:
  27285. description: |-
  27286. The namespace of the Secret resource being referred to.
  27287. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27288. maxLength: 63
  27289. minLength: 1
  27290. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27291. type: string
  27292. type: object
  27293. type: object
  27294. required:
  27295. - secretRef
  27296. type: object
  27297. workloadIdentity:
  27298. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  27299. properties:
  27300. serviceAccountRef:
  27301. description: |-
  27302. ServiceAccountRef specified the service account
  27303. that should be used when authenticating with WorkloadIdentity.
  27304. properties:
  27305. audiences:
  27306. description: |-
  27307. Audience specifies the `aud` claim for the service account token
  27308. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27309. then this audiences will be appended to the list
  27310. items:
  27311. type: string
  27312. type: array
  27313. name:
  27314. description: The name of the ServiceAccount resource being referred to.
  27315. maxLength: 253
  27316. minLength: 1
  27317. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27318. type: string
  27319. namespace:
  27320. description: |-
  27321. Namespace of the resource being referred to.
  27322. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27323. maxLength: 63
  27324. minLength: 1
  27325. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27326. type: string
  27327. required:
  27328. - name
  27329. type: object
  27330. type: object
  27331. type: object
  27332. environmentType:
  27333. default: PublicCloud
  27334. description: |-
  27335. EnvironmentType specifies the Azure cloud environment endpoints to use for
  27336. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  27337. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  27338. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  27339. enum:
  27340. - PublicCloud
  27341. - USGovernmentCloud
  27342. - ChinaCloud
  27343. - GermanCloud
  27344. - AzureStackCloud
  27345. type: string
  27346. registry:
  27347. description: |-
  27348. the domain name of the ACR registry
  27349. e.g. foobarexample.azurecr.io
  27350. type: string
  27351. scope:
  27352. description: |-
  27353. Define the scope for the access token, e.g. pull/push access for a repository.
  27354. if not provided it will return a refresh token that has full scope.
  27355. Note: you need to pin it down to the repository level, there is no wildcard available.
  27356. examples:
  27357. repository:my-repository:pull,push
  27358. repository:my-repository:pull
  27359. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  27360. type: string
  27361. tenantId:
  27362. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  27363. type: string
  27364. required:
  27365. - auth
  27366. - registry
  27367. type: object
  27368. beyondtrustWorkloadCredentialsDynamicSecretSpec:
  27369. description: |-
  27370. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  27371. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  27372. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27373. properties:
  27374. controller:
  27375. description: |-
  27376. Controller selects the controller that should handle this generator.
  27377. Leave empty to use the default controller.
  27378. type: string
  27379. provider:
  27380. description: |-
  27381. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  27382. server connection details, and the folder path to the dynamic secret definition.
  27383. The folderPath should point to a dynamic secret definition that has been created in
  27384. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  27385. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27386. properties:
  27387. auth:
  27388. description: |-
  27389. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  27390. Currently supports API key authentication via Kubernetes secret reference.
  27391. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27392. properties:
  27393. apikey:
  27394. description: |-
  27395. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  27396. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  27397. properties:
  27398. token:
  27399. description: |-
  27400. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  27401. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  27402. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  27403. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27404. properties:
  27405. key:
  27406. description: |-
  27407. A key in the referenced Secret.
  27408. Some instances of this field may be defaulted, in others it may be required.
  27409. maxLength: 253
  27410. minLength: 1
  27411. pattern: ^[-._a-zA-Z0-9]+$
  27412. type: string
  27413. name:
  27414. description: The name of the Secret resource being referred to.
  27415. maxLength: 253
  27416. minLength: 1
  27417. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27418. type: string
  27419. namespace:
  27420. description: |-
  27421. The namespace of the Secret resource being referred to.
  27422. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27423. maxLength: 63
  27424. minLength: 1
  27425. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27426. type: string
  27427. type: object
  27428. required:
  27429. - token
  27430. type: object
  27431. required:
  27432. - apikey
  27433. type: object
  27434. caBundle:
  27435. description: |-
  27436. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27437. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  27438. If not set, the system's trusted root certificates are used.
  27439. format: byte
  27440. type: string
  27441. caProvider:
  27442. description: |-
  27443. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  27444. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27445. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  27446. properties:
  27447. key:
  27448. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  27449. maxLength: 253
  27450. minLength: 1
  27451. pattern: ^[-._a-zA-Z0-9]+$
  27452. type: string
  27453. name:
  27454. description: The name of the object located at the provider type.
  27455. maxLength: 253
  27456. minLength: 1
  27457. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27458. type: string
  27459. namespace:
  27460. description: |-
  27461. The namespace the Provider type is in.
  27462. Can only be defined when used in a ClusterSecretStore.
  27463. maxLength: 63
  27464. minLength: 1
  27465. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27466. type: string
  27467. type:
  27468. description: The type of provider to use such as "Secret", or "ConfigMap".
  27469. enum:
  27470. - Secret
  27471. - ConfigMap
  27472. type: string
  27473. required:
  27474. - name
  27475. - type
  27476. type: object
  27477. folderPath:
  27478. description: |-
  27479. FolderPath specifies the default folder path for secret retrieval.
  27480. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  27481. Example: "production/database" or "dev/api-keys"
  27482. Leave empty to retrieve secrets from the root folder.
  27483. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  27484. type: string
  27485. server:
  27486. description: |-
  27487. Server configures the BeyondTrust Workload Credentials server connection details.
  27488. Includes the API URL and Site ID for your BeyondTrust instance.
  27489. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27490. properties:
  27491. apiUrl:
  27492. description: |-
  27493. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  27494. This should be the full URL to your BeyondTrust instance.
  27495. Example: https://api.beyondtrust.io/siie
  27496. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  27497. type: string
  27498. siteId:
  27499. description: |-
  27500. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  27501. This identifier is unique to your BeyondTrust Workload Credentials instance.
  27502. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  27503. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  27504. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27505. type: string
  27506. required:
  27507. - apiUrl
  27508. - siteId
  27509. type: object
  27510. required:
  27511. - auth
  27512. - server
  27513. type: object
  27514. retrySettings:
  27515. description: |-
  27516. RetrySettings configures exponential backoff for failed API requests.
  27517. If not specified, uses the default retry settings.
  27518. properties:
  27519. maxRetries:
  27520. format: int32
  27521. type: integer
  27522. retryInterval:
  27523. type: string
  27524. type: object
  27525. required:
  27526. - provider
  27527. type: object
  27528. cloudsmithAccessTokenSpec:
  27529. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  27530. properties:
  27531. apiUrl:
  27532. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  27533. type: string
  27534. orgSlug:
  27535. description: OrgSlug is the organization slug in Cloudsmith
  27536. type: string
  27537. serviceAccountRef:
  27538. description: Name of the service account you are federating with
  27539. properties:
  27540. audiences:
  27541. description: |-
  27542. Audience specifies the `aud` claim for the service account token
  27543. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27544. then this audiences will be appended to the list
  27545. items:
  27546. type: string
  27547. type: array
  27548. name:
  27549. description: The name of the ServiceAccount resource being referred to.
  27550. maxLength: 253
  27551. minLength: 1
  27552. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27553. type: string
  27554. namespace:
  27555. description: |-
  27556. Namespace of the resource being referred to.
  27557. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27558. maxLength: 63
  27559. minLength: 1
  27560. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27561. type: string
  27562. required:
  27563. - name
  27564. type: object
  27565. serviceSlug:
  27566. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  27567. type: string
  27568. required:
  27569. - orgSlug
  27570. - serviceAccountRef
  27571. - serviceSlug
  27572. type: object
  27573. ecrAuthorizationTokenSpec:
  27574. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  27575. properties:
  27576. auth:
  27577. description: Auth defines how to authenticate with AWS
  27578. properties:
  27579. jwt:
  27580. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  27581. properties:
  27582. serviceAccountRef:
  27583. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  27584. properties:
  27585. audiences:
  27586. description: |-
  27587. Audience specifies the `aud` claim for the service account token
  27588. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27589. then this audiences will be appended to the list
  27590. items:
  27591. type: string
  27592. type: array
  27593. name:
  27594. description: The name of the ServiceAccount resource being referred to.
  27595. maxLength: 253
  27596. minLength: 1
  27597. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27598. type: string
  27599. namespace:
  27600. description: |-
  27601. Namespace of the resource being referred to.
  27602. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27603. maxLength: 63
  27604. minLength: 1
  27605. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27606. type: string
  27607. required:
  27608. - name
  27609. type: object
  27610. type: object
  27611. secretRef:
  27612. description: |-
  27613. AWSAuthSecretRef holds secret references for AWS credentials
  27614. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  27615. properties:
  27616. accessKeyIDSecretRef:
  27617. description: The AccessKeyID is used for authentication
  27618. properties:
  27619. key:
  27620. description: |-
  27621. A key in the referenced Secret.
  27622. Some instances of this field may be defaulted, in others it may be required.
  27623. maxLength: 253
  27624. minLength: 1
  27625. pattern: ^[-._a-zA-Z0-9]+$
  27626. type: string
  27627. name:
  27628. description: The name of the Secret resource being referred to.
  27629. maxLength: 253
  27630. minLength: 1
  27631. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27632. type: string
  27633. namespace:
  27634. description: |-
  27635. The namespace of the Secret resource being referred to.
  27636. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27637. maxLength: 63
  27638. minLength: 1
  27639. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27640. type: string
  27641. type: object
  27642. secretAccessKeySecretRef:
  27643. description: The SecretAccessKey is used for authentication
  27644. properties:
  27645. key:
  27646. description: |-
  27647. A key in the referenced Secret.
  27648. Some instances of this field may be defaulted, in others it may be required.
  27649. maxLength: 253
  27650. minLength: 1
  27651. pattern: ^[-._a-zA-Z0-9]+$
  27652. type: string
  27653. name:
  27654. description: The name of the Secret resource being referred to.
  27655. maxLength: 253
  27656. minLength: 1
  27657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27658. type: string
  27659. namespace:
  27660. description: |-
  27661. The namespace of the Secret resource being referred to.
  27662. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27663. maxLength: 63
  27664. minLength: 1
  27665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27666. type: string
  27667. type: object
  27668. sessionTokenSecretRef:
  27669. description: |-
  27670. The SessionToken used for authentication
  27671. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  27672. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  27673. properties:
  27674. key:
  27675. description: |-
  27676. A key in the referenced Secret.
  27677. Some instances of this field may be defaulted, in others it may be required.
  27678. maxLength: 253
  27679. minLength: 1
  27680. pattern: ^[-._a-zA-Z0-9]+$
  27681. type: string
  27682. name:
  27683. description: The name of the Secret resource being referred to.
  27684. maxLength: 253
  27685. minLength: 1
  27686. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27687. type: string
  27688. namespace:
  27689. description: |-
  27690. The namespace of the Secret resource being referred to.
  27691. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27692. maxLength: 63
  27693. minLength: 1
  27694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27695. type: string
  27696. type: object
  27697. type: object
  27698. type: object
  27699. region:
  27700. description: Region specifies the region to operate in.
  27701. type: string
  27702. role:
  27703. description: |-
  27704. You can assume a role before making calls to the
  27705. desired AWS service.
  27706. type: string
  27707. scope:
  27708. description: |-
  27709. Scope specifies the ECR service scope.
  27710. Valid options are private and public.
  27711. type: string
  27712. required:
  27713. - region
  27714. type: object
  27715. fakeSpec:
  27716. description: FakeSpec contains the static data.
  27717. properties:
  27718. controller:
  27719. description: |-
  27720. Used to select the correct ESO controller (think: ingress.ingressClassName)
  27721. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  27722. type: string
  27723. data:
  27724. additionalProperties:
  27725. type: string
  27726. description: |-
  27727. Data defines the static data returned
  27728. by this generator.
  27729. type: object
  27730. type: object
  27731. gcrAccessTokenSpec:
  27732. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  27733. properties:
  27734. auth:
  27735. description: Auth defines the means for authenticating with GCP
  27736. properties:
  27737. secretRef:
  27738. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  27739. properties:
  27740. secretAccessKeySecretRef:
  27741. description: The SecretAccessKey is used for authentication
  27742. properties:
  27743. key:
  27744. description: |-
  27745. A key in the referenced Secret.
  27746. Some instances of this field may be defaulted, in others it may be required.
  27747. maxLength: 253
  27748. minLength: 1
  27749. pattern: ^[-._a-zA-Z0-9]+$
  27750. type: string
  27751. name:
  27752. description: The name of the Secret resource being referred to.
  27753. maxLength: 253
  27754. minLength: 1
  27755. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27756. type: string
  27757. namespace:
  27758. description: |-
  27759. The namespace of the Secret resource being referred to.
  27760. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27761. maxLength: 63
  27762. minLength: 1
  27763. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27764. type: string
  27765. type: object
  27766. type: object
  27767. workloadIdentity:
  27768. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  27769. properties:
  27770. clusterLocation:
  27771. type: string
  27772. clusterName:
  27773. type: string
  27774. clusterProjectID:
  27775. type: string
  27776. serviceAccountRef:
  27777. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  27778. properties:
  27779. audiences:
  27780. description: |-
  27781. Audience specifies the `aud` claim for the service account token
  27782. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27783. then this audiences will be appended to the list
  27784. items:
  27785. type: string
  27786. type: array
  27787. name:
  27788. description: The name of the ServiceAccount resource being referred to.
  27789. maxLength: 253
  27790. minLength: 1
  27791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27792. type: string
  27793. namespace:
  27794. description: |-
  27795. Namespace of the resource being referred to.
  27796. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27797. maxLength: 63
  27798. minLength: 1
  27799. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27800. type: string
  27801. required:
  27802. - name
  27803. type: object
  27804. required:
  27805. - clusterLocation
  27806. - clusterName
  27807. - serviceAccountRef
  27808. type: object
  27809. workloadIdentityFederation:
  27810. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  27811. properties:
  27812. audience:
  27813. description: |-
  27814. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  27815. If specified, Audience found in the external account credential config will be overridden with the configured value.
  27816. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  27817. type: string
  27818. awsSecurityCredentials:
  27819. description: |-
  27820. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  27821. when using the AWS metadata server is not an option.
  27822. properties:
  27823. awsCredentialsSecretRef:
  27824. description: |-
  27825. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  27826. Secret should be created with below names for keys
  27827. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  27828. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  27829. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  27830. properties:
  27831. name:
  27832. description: name of the secret.
  27833. maxLength: 253
  27834. minLength: 1
  27835. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27836. type: string
  27837. namespace:
  27838. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  27839. maxLength: 63
  27840. minLength: 1
  27841. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27842. type: string
  27843. required:
  27844. - name
  27845. type: object
  27846. region:
  27847. description: region is for configuring the AWS region to be used.
  27848. example: ap-south-1
  27849. maxLength: 50
  27850. minLength: 1
  27851. pattern: ^[a-z0-9-]+$
  27852. type: string
  27853. required:
  27854. - awsCredentialsSecretRef
  27855. - region
  27856. type: object
  27857. credConfig:
  27858. description: |-
  27859. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  27860. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  27861. serviceAccountRef must be used by providing operators service account details.
  27862. properties:
  27863. key:
  27864. description: key name holding the external account credential config.
  27865. maxLength: 253
  27866. minLength: 1
  27867. pattern: ^[-._a-zA-Z0-9]+$
  27868. type: string
  27869. name:
  27870. description: name of the configmap.
  27871. maxLength: 253
  27872. minLength: 1
  27873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27874. type: string
  27875. namespace:
  27876. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  27877. maxLength: 63
  27878. minLength: 1
  27879. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27880. type: string
  27881. required:
  27882. - key
  27883. - name
  27884. type: object
  27885. externalTokenEndpoint:
  27886. description: |-
  27887. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  27888. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  27889. URL is having the expected value.
  27890. type: string
  27891. gcpServiceAccountEmail:
  27892. description: |-
  27893. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  27894. after Workload Identity Federation. Use this to grant access through the service account's
  27895. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  27896. service_account_impersonation_url in the external account JSON from credConfig;
  27897. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  27898. on that ServiceAccount.
  27899. example: my-gsa@my-project.iam.gserviceaccount.com
  27900. minLength: 1
  27901. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  27902. type: string
  27903. serviceAccountRef:
  27904. description: |-
  27905. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  27906. when Kubernetes is configured as provider in workload identity pool.
  27907. properties:
  27908. audiences:
  27909. description: |-
  27910. Audience specifies the `aud` claim for the service account token
  27911. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27912. then this audiences will be appended to the list
  27913. items:
  27914. type: string
  27915. type: array
  27916. name:
  27917. description: The name of the ServiceAccount resource being referred to.
  27918. maxLength: 253
  27919. minLength: 1
  27920. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27921. type: string
  27922. namespace:
  27923. description: |-
  27924. Namespace of the resource being referred to.
  27925. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27926. maxLength: 63
  27927. minLength: 1
  27928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27929. type: string
  27930. required:
  27931. - name
  27932. type: object
  27933. type: object
  27934. type: object
  27935. projectID:
  27936. description: ProjectID defines which project to use to authenticate with
  27937. type: string
  27938. required:
  27939. - auth
  27940. - projectID
  27941. type: object
  27942. githubAccessTokenSpec:
  27943. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  27944. properties:
  27945. appID:
  27946. type: string
  27947. auth:
  27948. description: Auth configures how ESO authenticates with a Github instance.
  27949. properties:
  27950. privateKey:
  27951. description: GithubSecretRef references a secret containing GitHub credentials.
  27952. properties:
  27953. secretRef:
  27954. description: |-
  27955. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  27956. In some instances, `key` is a required field.
  27957. properties:
  27958. key:
  27959. description: |-
  27960. A key in the referenced Secret.
  27961. Some instances of this field may be defaulted, in others it may be required.
  27962. maxLength: 253
  27963. minLength: 1
  27964. pattern: ^[-._a-zA-Z0-9]+$
  27965. type: string
  27966. name:
  27967. description: The name of the Secret resource being referred to.
  27968. maxLength: 253
  27969. minLength: 1
  27970. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27971. type: string
  27972. namespace:
  27973. description: |-
  27974. The namespace of the Secret resource being referred to.
  27975. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27976. maxLength: 63
  27977. minLength: 1
  27978. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27979. type: string
  27980. type: object
  27981. required:
  27982. - secretRef
  27983. type: object
  27984. required:
  27985. - privateKey
  27986. type: object
  27987. installID:
  27988. type: string
  27989. permissions:
  27990. additionalProperties:
  27991. type: string
  27992. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  27993. type: object
  27994. repositories:
  27995. description: |-
  27996. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  27997. is installed to.
  27998. items:
  27999. type: string
  28000. type: array
  28001. url:
  28002. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  28003. type: string
  28004. required:
  28005. - appID
  28006. - auth
  28007. - installID
  28008. type: object
  28009. gitlabDeployTokenSpec:
  28010. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  28011. properties:
  28012. auth:
  28013. description: Auth configures how ESO authenticates with the GitLab API.
  28014. properties:
  28015. token:
  28016. description: |-
  28017. Token references a secret containing a GitLab access token (personal, group, or
  28018. project) with the api scope and at least the Maintainer role on the target.
  28019. properties:
  28020. secretRef:
  28021. description: |-
  28022. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28023. In some instances, `key` is a required field.
  28024. properties:
  28025. key:
  28026. description: |-
  28027. A key in the referenced Secret.
  28028. Some instances of this field may be defaulted, in others it may be required.
  28029. maxLength: 253
  28030. minLength: 1
  28031. pattern: ^[-._a-zA-Z0-9]+$
  28032. type: string
  28033. name:
  28034. description: The name of the Secret resource being referred to.
  28035. maxLength: 253
  28036. minLength: 1
  28037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28038. type: string
  28039. namespace:
  28040. description: |-
  28041. The namespace of the Secret resource being referred to.
  28042. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28043. maxLength: 63
  28044. minLength: 1
  28045. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28046. type: string
  28047. type: object
  28048. required:
  28049. - secretRef
  28050. type: object
  28051. required:
  28052. - token
  28053. type: object
  28054. expiresAt:
  28055. description: |-
  28056. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  28057. not expire on the GitLab side and is revoked only when the generator state is
  28058. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  28059. format: date-time
  28060. type: string
  28061. groupID:
  28062. description: |-
  28063. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  28064. create the deploy token in. The generator URL-escapes paths before calling the
  28065. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  28066. minLength: 1
  28067. type: string
  28068. name:
  28069. description: Name of the deploy token.
  28070. minLength: 1
  28071. type: string
  28072. projectID:
  28073. description: |-
  28074. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  28075. project to create the deploy token in. The generator URL-escapes paths before
  28076. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  28077. minLength: 1
  28078. type: string
  28079. scopes:
  28080. description: Scopes granted to the deploy token. At least one scope is required.
  28081. items:
  28082. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  28083. enum:
  28084. - read_repository
  28085. - read_registry
  28086. - write_registry
  28087. - read_package_registry
  28088. - write_package_registry
  28089. - read_virtual_registry
  28090. - write_virtual_registry
  28091. type: string
  28092. minItems: 1
  28093. type: array
  28094. url:
  28095. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  28096. type: string
  28097. username:
  28098. description: |-
  28099. Username is an optional username for the deploy token. GitLab defaults it to
  28100. gitlab+deploy-token-{n} when omitted.
  28101. type: string
  28102. required:
  28103. - auth
  28104. - name
  28105. - scopes
  28106. type: object
  28107. x-kubernetes-validations:
  28108. - message: exactly one of projectID or groupID must be set
  28109. rule: has(self.projectID) != has(self.groupID)
  28110. grafanaSpec:
  28111. description: GrafanaSpec controls the behavior of the grafana generator.
  28112. properties:
  28113. auth:
  28114. description: |-
  28115. Auth is the authentication configuration to authenticate
  28116. against the Grafana instance.
  28117. properties:
  28118. basic:
  28119. description: |-
  28120. Basic auth credentials used to authenticate against the Grafana instance.
  28121. Note: you need a token which has elevated permissions to create service accounts.
  28122. See here for the documentation on basic roles offered by Grafana:
  28123. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28124. properties:
  28125. password:
  28126. description: A basic auth password used to authenticate against the Grafana instance.
  28127. properties:
  28128. key:
  28129. description: The key where the token is found.
  28130. maxLength: 253
  28131. minLength: 1
  28132. pattern: ^[-._a-zA-Z0-9]+$
  28133. type: string
  28134. name:
  28135. description: The name of the Secret resource being referred to.
  28136. maxLength: 253
  28137. minLength: 1
  28138. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28139. type: string
  28140. type: object
  28141. username:
  28142. description: A basic auth username used to authenticate against the Grafana instance.
  28143. type: string
  28144. required:
  28145. - password
  28146. - username
  28147. type: object
  28148. token:
  28149. description: |-
  28150. A service account token used to authenticate against the Grafana instance.
  28151. Note: you need a token which has elevated permissions to create service accounts.
  28152. See here for the documentation on basic roles offered by Grafana:
  28153. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28154. properties:
  28155. key:
  28156. description: The key where the token is found.
  28157. maxLength: 253
  28158. minLength: 1
  28159. pattern: ^[-._a-zA-Z0-9]+$
  28160. type: string
  28161. name:
  28162. description: The name of the Secret resource being referred to.
  28163. maxLength: 253
  28164. minLength: 1
  28165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28166. type: string
  28167. type: object
  28168. type: object
  28169. serviceAccount:
  28170. description: |-
  28171. ServiceAccount is the configuration for the service account that
  28172. is supposed to be generated by the generator.
  28173. properties:
  28174. name:
  28175. description: Name is the name of the service account that will be created by ESO.
  28176. type: string
  28177. role:
  28178. description: |-
  28179. Role is the role of the service account.
  28180. See here for the documentation on basic roles offered by Grafana:
  28181. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28182. type: string
  28183. secondsToLive:
  28184. description: |-
  28185. SecondsToLive is the number of seconds before the generated service account token will expire.
  28186. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  28187. format: int64
  28188. minimum: 1
  28189. type: integer
  28190. required:
  28191. - name
  28192. - role
  28193. type: object
  28194. url:
  28195. description: URL is the URL of the Grafana instance.
  28196. type: string
  28197. required:
  28198. - auth
  28199. - serviceAccount
  28200. - url
  28201. type: object
  28202. mfaSpec:
  28203. description: MFASpec controls the behavior of the mfa generator.
  28204. properties:
  28205. algorithm:
  28206. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  28207. type: string
  28208. length:
  28209. description: Length defines the token length. Defaults to 6 characters.
  28210. type: integer
  28211. secret:
  28212. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  28213. properties:
  28214. key:
  28215. description: |-
  28216. A key in the referenced Secret.
  28217. Some instances of this field may be defaulted, in others it may be required.
  28218. maxLength: 253
  28219. minLength: 1
  28220. pattern: ^[-._a-zA-Z0-9]+$
  28221. type: string
  28222. name:
  28223. description: The name of the Secret resource being referred to.
  28224. maxLength: 253
  28225. minLength: 1
  28226. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28227. type: string
  28228. namespace:
  28229. description: |-
  28230. The namespace of the Secret resource being referred to.
  28231. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28232. maxLength: 63
  28233. minLength: 1
  28234. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28235. type: string
  28236. type: object
  28237. timePeriod:
  28238. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  28239. type: integer
  28240. when:
  28241. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  28242. format: date-time
  28243. type: string
  28244. required:
  28245. - secret
  28246. type: object
  28247. passwordSpec:
  28248. description: PasswordSpec controls the behavior of the password generator.
  28249. properties:
  28250. allowRepeat:
  28251. default: false
  28252. description: set AllowRepeat to true to allow repeating characters.
  28253. type: boolean
  28254. digits:
  28255. description: |-
  28256. Digits specifies the number of digits in the generated
  28257. password. If omitted it defaults to 25% of the length of the password
  28258. type: integer
  28259. encoding:
  28260. default: raw
  28261. description: |-
  28262. Encoding specifies the encoding of the generated password.
  28263. Valid values are:
  28264. - "raw" (default): no encoding
  28265. - "base64": standard base64 encoding
  28266. - "base64url": base64url encoding
  28267. - "base32": base32 encoding
  28268. - "hex": hexadecimal encoding
  28269. enum:
  28270. - base64
  28271. - base64url
  28272. - base32
  28273. - hex
  28274. - raw
  28275. type: string
  28276. length:
  28277. default: 24
  28278. description: |-
  28279. Length of the password to be generated.
  28280. Defaults to 24
  28281. type: integer
  28282. noUpper:
  28283. default: false
  28284. description: Set NoUpper to disable uppercase characters
  28285. type: boolean
  28286. secretKeys:
  28287. description: |-
  28288. SecretKeys defines the keys that will be populated with generated passwords.
  28289. Defaults to "password" when not set.
  28290. items:
  28291. type: string
  28292. minItems: 1
  28293. type: array
  28294. symbolCharacters:
  28295. description: |-
  28296. SymbolCharacters specifies the special characters that should be used
  28297. in the generated password.
  28298. type: string
  28299. symbols:
  28300. description: |-
  28301. Symbols specifies the number of symbol characters in the generated
  28302. password. If omitted it defaults to 25% of the length of the password
  28303. type: integer
  28304. required:
  28305. - allowRepeat
  28306. - length
  28307. - noUpper
  28308. type: object
  28309. quayAccessTokenSpec:
  28310. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  28311. properties:
  28312. robotAccount:
  28313. description: Name of the robot account you are federating with
  28314. type: string
  28315. serviceAccountRef:
  28316. description: Name of the service account you are federating with
  28317. properties:
  28318. audiences:
  28319. description: |-
  28320. Audience specifies the `aud` claim for the service account token
  28321. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28322. then this audiences will be appended to the list
  28323. items:
  28324. type: string
  28325. type: array
  28326. name:
  28327. description: The name of the ServiceAccount resource being referred to.
  28328. maxLength: 253
  28329. minLength: 1
  28330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28331. type: string
  28332. namespace:
  28333. description: |-
  28334. Namespace of the resource being referred to.
  28335. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28336. maxLength: 63
  28337. minLength: 1
  28338. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28339. type: string
  28340. required:
  28341. - name
  28342. type: object
  28343. url:
  28344. description: URL configures the Quay instance URL. Defaults to quay.io.
  28345. type: string
  28346. required:
  28347. - robotAccount
  28348. - serviceAccountRef
  28349. type: object
  28350. sshKeySpec:
  28351. description: SSHKeySpec controls the behavior of the ssh key generator.
  28352. properties:
  28353. comment:
  28354. description: Comment specifies an optional comment for the SSH key
  28355. type: string
  28356. keySize:
  28357. description: |-
  28358. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  28359. For RSA keys: 2048, 3072, 4096
  28360. For ECDSA keys: 256, 384, 521
  28361. Ignored for ed25519 keys
  28362. maximum: 8192
  28363. minimum: 256
  28364. type: integer
  28365. keyType:
  28366. default: rsa
  28367. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  28368. enum:
  28369. - rsa
  28370. - ecdsa
  28371. - ed25519
  28372. type: string
  28373. type: object
  28374. stsSessionTokenSpec:
  28375. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  28376. properties:
  28377. auth:
  28378. description: Auth defines how to authenticate with AWS
  28379. properties:
  28380. jwt:
  28381. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  28382. properties:
  28383. serviceAccountRef:
  28384. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28385. properties:
  28386. audiences:
  28387. description: |-
  28388. Audience specifies the `aud` claim for the service account token
  28389. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28390. then this audiences will be appended to the list
  28391. items:
  28392. type: string
  28393. type: array
  28394. name:
  28395. description: The name of the ServiceAccount resource being referred to.
  28396. maxLength: 253
  28397. minLength: 1
  28398. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28399. type: string
  28400. namespace:
  28401. description: |-
  28402. Namespace of the resource being referred to.
  28403. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28404. maxLength: 63
  28405. minLength: 1
  28406. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28407. type: string
  28408. required:
  28409. - name
  28410. type: object
  28411. type: object
  28412. secretRef:
  28413. description: |-
  28414. AWSAuthSecretRef holds secret references for AWS credentials
  28415. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  28416. properties:
  28417. accessKeyIDSecretRef:
  28418. description: The AccessKeyID is used for authentication
  28419. properties:
  28420. key:
  28421. description: |-
  28422. A key in the referenced Secret.
  28423. Some instances of this field may be defaulted, in others it may be required.
  28424. maxLength: 253
  28425. minLength: 1
  28426. pattern: ^[-._a-zA-Z0-9]+$
  28427. type: string
  28428. name:
  28429. description: The name of the Secret resource being referred to.
  28430. maxLength: 253
  28431. minLength: 1
  28432. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28433. type: string
  28434. namespace:
  28435. description: |-
  28436. The namespace of the Secret resource being referred to.
  28437. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28438. maxLength: 63
  28439. minLength: 1
  28440. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28441. type: string
  28442. type: object
  28443. secretAccessKeySecretRef:
  28444. description: The SecretAccessKey is used for authentication
  28445. properties:
  28446. key:
  28447. description: |-
  28448. A key in the referenced Secret.
  28449. Some instances of this field may be defaulted, in others it may be required.
  28450. maxLength: 253
  28451. minLength: 1
  28452. pattern: ^[-._a-zA-Z0-9]+$
  28453. type: string
  28454. name:
  28455. description: The name of the Secret resource being referred to.
  28456. maxLength: 253
  28457. minLength: 1
  28458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28459. type: string
  28460. namespace:
  28461. description: |-
  28462. The namespace of the Secret resource being referred to.
  28463. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28464. maxLength: 63
  28465. minLength: 1
  28466. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28467. type: string
  28468. type: object
  28469. sessionTokenSecretRef:
  28470. description: |-
  28471. The SessionToken used for authentication
  28472. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28473. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28474. properties:
  28475. key:
  28476. description: |-
  28477. A key in the referenced Secret.
  28478. Some instances of this field may be defaulted, in others it may be required.
  28479. maxLength: 253
  28480. minLength: 1
  28481. pattern: ^[-._a-zA-Z0-9]+$
  28482. type: string
  28483. name:
  28484. description: The name of the Secret resource being referred to.
  28485. maxLength: 253
  28486. minLength: 1
  28487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28488. type: string
  28489. namespace:
  28490. description: |-
  28491. The namespace of the Secret resource being referred to.
  28492. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28493. maxLength: 63
  28494. minLength: 1
  28495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28496. type: string
  28497. type: object
  28498. type: object
  28499. type: object
  28500. region:
  28501. description: Region specifies the region to operate in.
  28502. type: string
  28503. requestParameters:
  28504. description: RequestParameters contains parameters that can be passed to the STS service.
  28505. properties:
  28506. serialNumber:
  28507. description: |-
  28508. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  28509. the GetSessionToken call.
  28510. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  28511. (such as arn:aws:iam::123456789012:mfa/user)
  28512. type: string
  28513. sessionDuration:
  28514. format: int32
  28515. type: integer
  28516. tokenCode:
  28517. description: TokenCode is the value provided by the MFA device, if MFA is required.
  28518. type: string
  28519. type: object
  28520. role:
  28521. description: |-
  28522. You can assume a role before making calls to the
  28523. desired AWS service.
  28524. type: string
  28525. required:
  28526. - region
  28527. type: object
  28528. uuidSpec:
  28529. description: UUIDSpec controls the behavior of the uuid generator.
  28530. type: object
  28531. vaultDynamicSecretSpec:
  28532. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  28533. properties:
  28534. allowEmptyResponse:
  28535. default: false
  28536. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  28537. type: boolean
  28538. controller:
  28539. description: |-
  28540. Used to select the correct ESO controller (think: ingress.ingressClassName)
  28541. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  28542. type: string
  28543. getParameters:
  28544. additionalProperties:
  28545. items:
  28546. type: string
  28547. type: array
  28548. description: |-
  28549. GetParameters are query-string parameters passed to Vault on GET calls.
  28550. Each key may map to multiple values, matching HTTP query-string semantics.
  28551. Ignored for non-GET methods; use Parameters for write bodies.
  28552. type: object
  28553. method:
  28554. description: Vault API method to use (GET/POST/other)
  28555. type: string
  28556. parameters:
  28557. description: Parameters to pass to Vault write (for non-GET methods)
  28558. x-kubernetes-preserve-unknown-fields: true
  28559. path:
  28560. description: Vault path to obtain the dynamic secret from
  28561. type: string
  28562. provider:
  28563. description: Vault provider common spec
  28564. properties:
  28565. auth:
  28566. description: Auth configures how secret-manager authenticates with the Vault server.
  28567. properties:
  28568. appRole:
  28569. description: |-
  28570. AppRole authenticates with Vault using the App Role auth mechanism,
  28571. with the role and secret stored in a Kubernetes Secret resource.
  28572. properties:
  28573. path:
  28574. default: approle
  28575. description: |-
  28576. Path where the App Role authentication backend is mounted
  28577. in Vault, e.g: "approle"
  28578. type: string
  28579. roleId:
  28580. description: |-
  28581. RoleID configured in the App Role authentication backend when setting
  28582. up the authentication backend in Vault.
  28583. type: string
  28584. roleRef:
  28585. description: |-
  28586. Reference to a key in a Secret that contains the App Role ID used
  28587. to authenticate with Vault.
  28588. The `key` field must be specified and denotes which entry within the Secret
  28589. resource is used as the app role id.
  28590. properties:
  28591. key:
  28592. description: |-
  28593. A key in the referenced Secret.
  28594. Some instances of this field may be defaulted, in others it may be required.
  28595. maxLength: 253
  28596. minLength: 1
  28597. pattern: ^[-._a-zA-Z0-9]+$
  28598. type: string
  28599. name:
  28600. description: The name of the Secret resource being referred to.
  28601. maxLength: 253
  28602. minLength: 1
  28603. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28604. type: string
  28605. namespace:
  28606. description: |-
  28607. The namespace of the Secret resource being referred to.
  28608. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28609. maxLength: 63
  28610. minLength: 1
  28611. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28612. type: string
  28613. type: object
  28614. secretRef:
  28615. description: |-
  28616. Reference to a key in a Secret that contains the App Role secret used
  28617. to authenticate with Vault.
  28618. The `key` field must be specified and denotes which entry within the Secret
  28619. resource is used as the app role secret.
  28620. properties:
  28621. key:
  28622. description: |-
  28623. A key in the referenced Secret.
  28624. Some instances of this field may be defaulted, in others it may be required.
  28625. maxLength: 253
  28626. minLength: 1
  28627. pattern: ^[-._a-zA-Z0-9]+$
  28628. type: string
  28629. name:
  28630. description: The name of the Secret resource being referred to.
  28631. maxLength: 253
  28632. minLength: 1
  28633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28634. type: string
  28635. namespace:
  28636. description: |-
  28637. The namespace of the Secret resource being referred to.
  28638. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28639. maxLength: 63
  28640. minLength: 1
  28641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28642. type: string
  28643. type: object
  28644. required:
  28645. - path
  28646. - secretRef
  28647. type: object
  28648. cert:
  28649. description: |-
  28650. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  28651. Cert authentication method
  28652. properties:
  28653. clientCert:
  28654. description: |-
  28655. ClientCert is a certificate to authenticate using the Cert Vault
  28656. authentication method
  28657. properties:
  28658. key:
  28659. description: |-
  28660. A key in the referenced Secret.
  28661. Some instances of this field may be defaulted, in others it may be required.
  28662. maxLength: 253
  28663. minLength: 1
  28664. pattern: ^[-._a-zA-Z0-9]+$
  28665. type: string
  28666. name:
  28667. description: The name of the Secret resource being referred to.
  28668. maxLength: 253
  28669. minLength: 1
  28670. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28671. type: string
  28672. namespace:
  28673. description: |-
  28674. The namespace of the Secret resource being referred to.
  28675. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28676. maxLength: 63
  28677. minLength: 1
  28678. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28679. type: string
  28680. type: object
  28681. path:
  28682. default: cert
  28683. description: |-
  28684. Path where the Certificate authentication backend is mounted
  28685. in Vault, e.g: "cert"
  28686. type: string
  28687. secretRef:
  28688. description: |-
  28689. SecretRef to a key in a Secret resource containing client private key to
  28690. authenticate with Vault using the Cert authentication method
  28691. properties:
  28692. key:
  28693. description: |-
  28694. A key in the referenced Secret.
  28695. Some instances of this field may be defaulted, in others it may be required.
  28696. maxLength: 253
  28697. minLength: 1
  28698. pattern: ^[-._a-zA-Z0-9]+$
  28699. type: string
  28700. name:
  28701. description: The name of the Secret resource being referred to.
  28702. maxLength: 253
  28703. minLength: 1
  28704. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28705. type: string
  28706. namespace:
  28707. description: |-
  28708. The namespace of the Secret resource being referred to.
  28709. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28710. maxLength: 63
  28711. minLength: 1
  28712. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28713. type: string
  28714. type: object
  28715. vaultRole:
  28716. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  28717. type: string
  28718. type: object
  28719. gcp:
  28720. description: |-
  28721. Gcp authenticates with Vault using Google Cloud Platform authentication method
  28722. GCP authentication method
  28723. properties:
  28724. location:
  28725. description: Location optionally defines a location/region for the secret
  28726. type: string
  28727. path:
  28728. default: gcp
  28729. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  28730. type: string
  28731. projectID:
  28732. description: Project ID of the Google Cloud Platform project
  28733. type: string
  28734. role:
  28735. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  28736. type: string
  28737. secretRef:
  28738. description: Specify credentials in a Secret object
  28739. properties:
  28740. secretAccessKeySecretRef:
  28741. description: The SecretAccessKey is used for authentication
  28742. properties:
  28743. key:
  28744. description: |-
  28745. A key in the referenced Secret.
  28746. Some instances of this field may be defaulted, in others it may be required.
  28747. maxLength: 253
  28748. minLength: 1
  28749. pattern: ^[-._a-zA-Z0-9]+$
  28750. type: string
  28751. name:
  28752. description: The name of the Secret resource being referred to.
  28753. maxLength: 253
  28754. minLength: 1
  28755. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28756. type: string
  28757. namespace:
  28758. description: |-
  28759. The namespace of the Secret resource being referred to.
  28760. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28761. maxLength: 63
  28762. minLength: 1
  28763. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28764. type: string
  28765. type: object
  28766. type: object
  28767. serviceAccountRef:
  28768. description: ServiceAccountRef to a service account for impersonation
  28769. properties:
  28770. audiences:
  28771. description: |-
  28772. Audience specifies the `aud` claim for the service account token
  28773. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28774. then this audiences will be appended to the list
  28775. items:
  28776. type: string
  28777. type: array
  28778. name:
  28779. description: The name of the ServiceAccount resource being referred to.
  28780. maxLength: 253
  28781. minLength: 1
  28782. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28783. type: string
  28784. namespace:
  28785. description: |-
  28786. Namespace of the resource being referred to.
  28787. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28788. maxLength: 63
  28789. minLength: 1
  28790. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28791. type: string
  28792. required:
  28793. - name
  28794. type: object
  28795. workloadIdentity:
  28796. description: Specify a service account with Workload Identity
  28797. properties:
  28798. clusterLocation:
  28799. description: |-
  28800. ClusterLocation is the location of the cluster
  28801. If not specified, it fetches information from the metadata server
  28802. type: string
  28803. clusterName:
  28804. description: |-
  28805. ClusterName is the name of the cluster
  28806. If not specified, it fetches information from the metadata server
  28807. type: string
  28808. clusterProjectID:
  28809. description: |-
  28810. ClusterProjectID is the project ID of the cluster
  28811. If not specified, it fetches information from the metadata server
  28812. type: string
  28813. serviceAccountRef:
  28814. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28815. properties:
  28816. audiences:
  28817. description: |-
  28818. Audience specifies the `aud` claim for the service account token
  28819. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28820. then this audiences will be appended to the list
  28821. items:
  28822. type: string
  28823. type: array
  28824. name:
  28825. description: The name of the ServiceAccount resource being referred to.
  28826. maxLength: 253
  28827. minLength: 1
  28828. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28829. type: string
  28830. namespace:
  28831. description: |-
  28832. Namespace of the resource being referred to.
  28833. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28834. maxLength: 63
  28835. minLength: 1
  28836. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28837. type: string
  28838. required:
  28839. - name
  28840. type: object
  28841. required:
  28842. - serviceAccountRef
  28843. type: object
  28844. required:
  28845. - role
  28846. type: object
  28847. iam:
  28848. description: |-
  28849. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  28850. AWS IAM authentication method
  28851. properties:
  28852. externalID:
  28853. description: AWS External ID set on assumed IAM roles
  28854. type: string
  28855. jwt:
  28856. description: Specify a service account with IRSA enabled
  28857. properties:
  28858. serviceAccountRef:
  28859. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28860. properties:
  28861. audiences:
  28862. description: |-
  28863. Audience specifies the `aud` claim for the service account token
  28864. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28865. then this audiences will be appended to the list
  28866. items:
  28867. type: string
  28868. type: array
  28869. name:
  28870. description: The name of the ServiceAccount resource being referred to.
  28871. maxLength: 253
  28872. minLength: 1
  28873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28874. type: string
  28875. namespace:
  28876. description: |-
  28877. Namespace of the resource being referred to.
  28878. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28879. maxLength: 63
  28880. minLength: 1
  28881. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28882. type: string
  28883. required:
  28884. - name
  28885. type: object
  28886. type: object
  28887. path:
  28888. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  28889. type: string
  28890. region:
  28891. description: AWS region
  28892. type: string
  28893. role:
  28894. description: This is the AWS role to be assumed before talking to vault
  28895. type: string
  28896. secretRef:
  28897. description: Specify credentials in a Secret object
  28898. properties:
  28899. accessKeyIDSecretRef:
  28900. description: The AccessKeyID is used for authentication
  28901. properties:
  28902. key:
  28903. description: |-
  28904. A key in the referenced Secret.
  28905. Some instances of this field may be defaulted, in others it may be required.
  28906. maxLength: 253
  28907. minLength: 1
  28908. pattern: ^[-._a-zA-Z0-9]+$
  28909. type: string
  28910. name:
  28911. description: The name of the Secret resource being referred to.
  28912. maxLength: 253
  28913. minLength: 1
  28914. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28915. type: string
  28916. namespace:
  28917. description: |-
  28918. The namespace of the Secret resource being referred to.
  28919. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28920. maxLength: 63
  28921. minLength: 1
  28922. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28923. type: string
  28924. type: object
  28925. secretAccessKeySecretRef:
  28926. description: The SecretAccessKey is used for authentication
  28927. properties:
  28928. key:
  28929. description: |-
  28930. A key in the referenced Secret.
  28931. Some instances of this field may be defaulted, in others it may be required.
  28932. maxLength: 253
  28933. minLength: 1
  28934. pattern: ^[-._a-zA-Z0-9]+$
  28935. type: string
  28936. name:
  28937. description: The name of the Secret resource being referred to.
  28938. maxLength: 253
  28939. minLength: 1
  28940. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28941. type: string
  28942. namespace:
  28943. description: |-
  28944. The namespace of the Secret resource being referred to.
  28945. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28946. maxLength: 63
  28947. minLength: 1
  28948. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28949. type: string
  28950. type: object
  28951. sessionTokenSecretRef:
  28952. description: |-
  28953. The SessionToken used for authentication
  28954. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28955. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28956. properties:
  28957. key:
  28958. description: |-
  28959. A key in the referenced Secret.
  28960. Some instances of this field may be defaulted, in others it may be required.
  28961. maxLength: 253
  28962. minLength: 1
  28963. pattern: ^[-._a-zA-Z0-9]+$
  28964. type: string
  28965. name:
  28966. description: The name of the Secret resource being referred to.
  28967. maxLength: 253
  28968. minLength: 1
  28969. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28970. type: string
  28971. namespace:
  28972. description: |-
  28973. The namespace of the Secret resource being referred to.
  28974. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28975. maxLength: 63
  28976. minLength: 1
  28977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28978. type: string
  28979. type: object
  28980. type: object
  28981. vaultAwsIamServerID:
  28982. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  28983. type: string
  28984. vaultRole:
  28985. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  28986. type: string
  28987. required:
  28988. - vaultRole
  28989. type: object
  28990. jwt:
  28991. description: |-
  28992. Jwt authenticates with Vault by passing role and JWT token using the
  28993. JWT/OIDC authentication method
  28994. properties:
  28995. kubernetesServiceAccountToken:
  28996. description: |-
  28997. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  28998. a token for with the `TokenRequest` API.
  28999. properties:
  29000. audiences:
  29001. description: |-
  29002. Optional audiences field that will be used to request a temporary Kubernetes service
  29003. account token for the service account referenced by `serviceAccountRef`.
  29004. Defaults to a single audience `vault` it not specified.
  29005. Deprecated: use serviceAccountRef.Audiences instead
  29006. items:
  29007. type: string
  29008. type: array
  29009. expirationSeconds:
  29010. description: |-
  29011. Optional expiration time in seconds that will be used to request a temporary
  29012. Kubernetes service account token for the service account referenced by
  29013. `serviceAccountRef`.
  29014. Deprecated: this will be removed in the future.
  29015. Defaults to 10 minutes.
  29016. format: int64
  29017. type: integer
  29018. serviceAccountRef:
  29019. description: Service account field containing the name of a kubernetes ServiceAccount.
  29020. properties:
  29021. audiences:
  29022. description: |-
  29023. Audience specifies the `aud` claim for the service account token
  29024. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29025. then this audiences will be appended to the list
  29026. items:
  29027. type: string
  29028. type: array
  29029. name:
  29030. description: The name of the ServiceAccount resource being referred to.
  29031. maxLength: 253
  29032. minLength: 1
  29033. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29034. type: string
  29035. namespace:
  29036. description: |-
  29037. Namespace of the resource being referred to.
  29038. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29039. maxLength: 63
  29040. minLength: 1
  29041. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29042. type: string
  29043. required:
  29044. - name
  29045. type: object
  29046. required:
  29047. - serviceAccountRef
  29048. type: object
  29049. path:
  29050. default: jwt
  29051. description: |-
  29052. Path where the JWT authentication backend is mounted
  29053. in Vault, e.g: "jwt"
  29054. type: string
  29055. role:
  29056. description: |-
  29057. Role is a JWT role to authenticate using the JWT/OIDC Vault
  29058. authentication method
  29059. type: string
  29060. secretRef:
  29061. description: |-
  29062. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  29063. authenticate with Vault using the JWT/OIDC authentication method.
  29064. properties:
  29065. key:
  29066. description: |-
  29067. A key in the referenced Secret.
  29068. Some instances of this field may be defaulted, in others it may be required.
  29069. maxLength: 253
  29070. minLength: 1
  29071. pattern: ^[-._a-zA-Z0-9]+$
  29072. type: string
  29073. name:
  29074. description: The name of the Secret resource being referred to.
  29075. maxLength: 253
  29076. minLength: 1
  29077. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29078. type: string
  29079. namespace:
  29080. description: |-
  29081. The namespace of the Secret resource being referred to.
  29082. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29083. maxLength: 63
  29084. minLength: 1
  29085. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29086. type: string
  29087. type: object
  29088. required:
  29089. - path
  29090. type: object
  29091. kubernetes:
  29092. description: |-
  29093. Kubernetes authenticates with Vault by passing the ServiceAccount
  29094. token stored in the named Secret resource to the Vault server.
  29095. properties:
  29096. mountPath:
  29097. default: kubernetes
  29098. description: |-
  29099. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  29100. "kubernetes"
  29101. type: string
  29102. role:
  29103. description: |-
  29104. A required field containing the Vault Role to assume. A Role binds a
  29105. Kubernetes ServiceAccount with a set of Vault policies.
  29106. type: string
  29107. secretRef:
  29108. description: |-
  29109. Optional secret field containing a Kubernetes ServiceAccount JWT used
  29110. for authenticating with Vault. If a name is specified without a key,
  29111. `token` is the default. If one is not specified, the one bound to
  29112. the controller will be used.
  29113. properties:
  29114. key:
  29115. description: |-
  29116. A key in the referenced Secret.
  29117. Some instances of this field may be defaulted, in others it may be required.
  29118. maxLength: 253
  29119. minLength: 1
  29120. pattern: ^[-._a-zA-Z0-9]+$
  29121. type: string
  29122. name:
  29123. description: The name of the Secret resource being referred to.
  29124. maxLength: 253
  29125. minLength: 1
  29126. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29127. type: string
  29128. namespace:
  29129. description: |-
  29130. The namespace of the Secret resource being referred to.
  29131. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29132. maxLength: 63
  29133. minLength: 1
  29134. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29135. type: string
  29136. type: object
  29137. serviceAccountRef:
  29138. description: |-
  29139. Optional service account field containing the name of a kubernetes ServiceAccount.
  29140. If the service account is specified, the service account secret token JWT will be used
  29141. for authenticating with Vault. If the service account selector is not supplied,
  29142. the secretRef will be used instead.
  29143. properties:
  29144. audiences:
  29145. description: |-
  29146. Audience specifies the `aud` claim for the service account token
  29147. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29148. then this audiences will be appended to the list
  29149. items:
  29150. type: string
  29151. type: array
  29152. name:
  29153. description: The name of the ServiceAccount resource being referred to.
  29154. maxLength: 253
  29155. minLength: 1
  29156. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29157. type: string
  29158. namespace:
  29159. description: |-
  29160. Namespace of the resource being referred to.
  29161. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29162. maxLength: 63
  29163. minLength: 1
  29164. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29165. type: string
  29166. required:
  29167. - name
  29168. type: object
  29169. required:
  29170. - mountPath
  29171. - role
  29172. type: object
  29173. ldap:
  29174. description: |-
  29175. Ldap authenticates with Vault by passing username/password pair using
  29176. the LDAP authentication method
  29177. properties:
  29178. path:
  29179. default: ldap
  29180. description: |-
  29181. Path where the LDAP authentication backend is mounted
  29182. in Vault, e.g: "ldap"
  29183. type: string
  29184. secretRef:
  29185. description: |-
  29186. SecretRef to a key in a Secret resource containing password for the LDAP
  29187. user used to authenticate with Vault using the LDAP authentication
  29188. method
  29189. properties:
  29190. key:
  29191. description: |-
  29192. A key in the referenced Secret.
  29193. Some instances of this field may be defaulted, in others it may be required.
  29194. maxLength: 253
  29195. minLength: 1
  29196. pattern: ^[-._a-zA-Z0-9]+$
  29197. type: string
  29198. name:
  29199. description: The name of the Secret resource being referred to.
  29200. maxLength: 253
  29201. minLength: 1
  29202. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29203. type: string
  29204. namespace:
  29205. description: |-
  29206. The namespace of the Secret resource being referred to.
  29207. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29208. maxLength: 63
  29209. minLength: 1
  29210. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29211. type: string
  29212. type: object
  29213. username:
  29214. description: |-
  29215. Username is an LDAP username used to authenticate using the LDAP Vault
  29216. authentication method
  29217. type: string
  29218. required:
  29219. - path
  29220. - username
  29221. type: object
  29222. namespace:
  29223. description: |-
  29224. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  29225. Namespaces is a set of features within Vault Enterprise that allows
  29226. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  29227. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  29228. This will default to Vault.Namespace field if set, or empty otherwise
  29229. type: string
  29230. tokenSecretRef:
  29231. description: TokenSecretRef authenticates with Vault by presenting a token.
  29232. properties:
  29233. key:
  29234. description: |-
  29235. A key in the referenced Secret.
  29236. Some instances of this field may be defaulted, in others it may be required.
  29237. maxLength: 253
  29238. minLength: 1
  29239. pattern: ^[-._a-zA-Z0-9]+$
  29240. type: string
  29241. name:
  29242. description: The name of the Secret resource being referred to.
  29243. maxLength: 253
  29244. minLength: 1
  29245. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29246. type: string
  29247. namespace:
  29248. description: |-
  29249. The namespace of the Secret resource being referred to.
  29250. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29251. maxLength: 63
  29252. minLength: 1
  29253. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29254. type: string
  29255. type: object
  29256. userPass:
  29257. description: UserPass authenticates with Vault by passing username/password pair
  29258. properties:
  29259. path:
  29260. default: userpass
  29261. description: |-
  29262. Path where the UserPassword authentication backend is mounted
  29263. in Vault, e.g: "userpass"
  29264. type: string
  29265. secretRef:
  29266. description: |-
  29267. SecretRef to a key in a Secret resource containing password for the
  29268. user used to authenticate with Vault using the UserPass authentication
  29269. method
  29270. properties:
  29271. key:
  29272. description: |-
  29273. A key in the referenced Secret.
  29274. Some instances of this field may be defaulted, in others it may be required.
  29275. maxLength: 253
  29276. minLength: 1
  29277. pattern: ^[-._a-zA-Z0-9]+$
  29278. type: string
  29279. name:
  29280. description: The name of the Secret resource being referred to.
  29281. maxLength: 253
  29282. minLength: 1
  29283. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29284. type: string
  29285. namespace:
  29286. description: |-
  29287. The namespace of the Secret resource being referred to.
  29288. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29289. maxLength: 63
  29290. minLength: 1
  29291. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29292. type: string
  29293. type: object
  29294. username:
  29295. description: |-
  29296. Username is a username used to authenticate using the UserPass Vault
  29297. authentication method
  29298. type: string
  29299. required:
  29300. - path
  29301. - username
  29302. type: object
  29303. type: object
  29304. caBundle:
  29305. description: |-
  29306. PEM encoded CA bundle used to validate Vault server certificate. Only used
  29307. if the Server URL is using HTTPS protocol. This parameter is ignored for
  29308. plain HTTP protocol connection. If not set the system root certificates
  29309. are used to validate the TLS connection.
  29310. format: byte
  29311. type: string
  29312. caProvider:
  29313. description: The provider for the CA bundle to use to validate Vault server certificate.
  29314. properties:
  29315. key:
  29316. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  29317. maxLength: 253
  29318. minLength: 1
  29319. pattern: ^[-._a-zA-Z0-9]+$
  29320. type: string
  29321. name:
  29322. description: The name of the object located at the provider type.
  29323. maxLength: 253
  29324. minLength: 1
  29325. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29326. type: string
  29327. namespace:
  29328. description: |-
  29329. The namespace the Provider type is in.
  29330. Can only be defined when used in a ClusterSecretStore.
  29331. maxLength: 63
  29332. minLength: 1
  29333. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29334. type: string
  29335. type:
  29336. description: The type of provider to use such as "Secret", or "ConfigMap".
  29337. enum:
  29338. - Secret
  29339. - ConfigMap
  29340. type: string
  29341. required:
  29342. - name
  29343. - type
  29344. type: object
  29345. checkAndSet:
  29346. description: |-
  29347. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  29348. Only applies to Vault KV v2 stores. When enabled, write operations must include
  29349. the current version of the secret to prevent unintentional overwrites.
  29350. properties:
  29351. required:
  29352. description: |-
  29353. Required when true, all write operations must include a check-and-set parameter.
  29354. This helps prevent unintentional overwrites of secrets.
  29355. type: boolean
  29356. type: object
  29357. forwardInconsistent:
  29358. description: |-
  29359. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  29360. leader instead of simply retrying within a loop. This can increase performance if
  29361. the option is enabled serverside.
  29362. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  29363. type: boolean
  29364. headers:
  29365. additionalProperties:
  29366. type: string
  29367. description: Headers to be added in Vault request
  29368. type: object
  29369. namespace:
  29370. description: |-
  29371. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  29372. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  29373. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  29374. type: string
  29375. path:
  29376. description: |-
  29377. Path is the mount path of the Vault KV backend endpoint, e.g:
  29378. "secret". The v2 KV secret engine version specific "/data" path suffix
  29379. for fetching secrets from Vault is optional and will be appended
  29380. if not present in specified path.
  29381. type: string
  29382. readYourWrites:
  29383. description: |-
  29384. ReadYourWrites ensures isolated read-after-write semantics by
  29385. providing discovered cluster replication states in each request.
  29386. More information about eventual consistency in Vault can be found here
  29387. https://www.vaultproject.io/docs/enterprise/consistency
  29388. type: boolean
  29389. server:
  29390. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  29391. type: string
  29392. tls:
  29393. description: |-
  29394. The configuration used for client side related TLS communication, when the Vault server
  29395. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  29396. This parameter is ignored for plain HTTP protocol connection.
  29397. It's worth noting this configuration is different from the "TLS certificates auth method",
  29398. which is available under the `auth.cert` section.
  29399. properties:
  29400. certSecretRef:
  29401. description: |-
  29402. CertSecretRef is a certificate added to the transport layer
  29403. when communicating with the Vault server.
  29404. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  29405. properties:
  29406. key:
  29407. description: |-
  29408. A key in the referenced Secret.
  29409. Some instances of this field may be defaulted, in others it may be required.
  29410. maxLength: 253
  29411. minLength: 1
  29412. pattern: ^[-._a-zA-Z0-9]+$
  29413. type: string
  29414. name:
  29415. description: The name of the Secret resource being referred to.
  29416. maxLength: 253
  29417. minLength: 1
  29418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29419. type: string
  29420. namespace:
  29421. description: |-
  29422. The namespace of the Secret resource being referred to.
  29423. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29424. maxLength: 63
  29425. minLength: 1
  29426. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29427. type: string
  29428. type: object
  29429. keySecretRef:
  29430. description: |-
  29431. KeySecretRef to a key in a Secret resource containing client private key
  29432. added to the transport layer when communicating with the Vault server.
  29433. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  29434. properties:
  29435. key:
  29436. description: |-
  29437. A key in the referenced Secret.
  29438. Some instances of this field may be defaulted, in others it may be required.
  29439. maxLength: 253
  29440. minLength: 1
  29441. pattern: ^[-._a-zA-Z0-9]+$
  29442. type: string
  29443. name:
  29444. description: The name of the Secret resource being referred to.
  29445. maxLength: 253
  29446. minLength: 1
  29447. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29448. type: string
  29449. namespace:
  29450. description: |-
  29451. The namespace of the Secret resource being referred to.
  29452. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29453. maxLength: 63
  29454. minLength: 1
  29455. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29456. type: string
  29457. type: object
  29458. type: object
  29459. version:
  29460. default: v2
  29461. description: |-
  29462. Version is the Vault KV secret engine version. This can be either "v1" or
  29463. "v2". Version defaults to "v2".
  29464. enum:
  29465. - v1
  29466. - v2
  29467. type: string
  29468. required:
  29469. - server
  29470. type: object
  29471. resultType:
  29472. default: Data
  29473. description: |-
  29474. Result type defines which data is returned from the generator.
  29475. By default, it is the "data" section of the Vault API response.
  29476. When using e.g. /auth/token/create the "data" section is empty but
  29477. the "auth" section contains the generated token.
  29478. Please refer to the vault docs regarding the result data structure.
  29479. Additionally, accessing the raw response is possibly by using "Raw" result type.
  29480. enum:
  29481. - Data
  29482. - Auth
  29483. - Raw
  29484. type: string
  29485. retrySettings:
  29486. description: Used to configure http retries if failed
  29487. properties:
  29488. maxRetries:
  29489. format: int32
  29490. type: integer
  29491. retryInterval:
  29492. type: string
  29493. type: object
  29494. required:
  29495. - path
  29496. - provider
  29497. type: object
  29498. webhookSpec:
  29499. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  29500. properties:
  29501. auth:
  29502. description: Auth specifies a authorization protocol. Only one protocol may be set.
  29503. maxProperties: 1
  29504. minProperties: 1
  29505. properties:
  29506. ntlm:
  29507. description: NTLMProtocol configures the store to use NTLM for auth
  29508. properties:
  29509. passwordSecret:
  29510. description: |-
  29511. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  29512. In some instances, `key` is a required field.
  29513. properties:
  29514. key:
  29515. description: |-
  29516. A key in the referenced Secret.
  29517. Some instances of this field may be defaulted, in others it may be required.
  29518. maxLength: 253
  29519. minLength: 1
  29520. pattern: ^[-._a-zA-Z0-9]+$
  29521. type: string
  29522. name:
  29523. description: The name of the Secret resource being referred to.
  29524. maxLength: 253
  29525. minLength: 1
  29526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29527. type: string
  29528. namespace:
  29529. description: |-
  29530. The namespace of the Secret resource being referred to.
  29531. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29532. maxLength: 63
  29533. minLength: 1
  29534. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29535. type: string
  29536. type: object
  29537. usernameSecret:
  29538. description: |-
  29539. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  29540. In some instances, `key` is a required field.
  29541. properties:
  29542. key:
  29543. description: |-
  29544. A key in the referenced Secret.
  29545. Some instances of this field may be defaulted, in others it may be required.
  29546. maxLength: 253
  29547. minLength: 1
  29548. pattern: ^[-._a-zA-Z0-9]+$
  29549. type: string
  29550. name:
  29551. description: The name of the Secret resource being referred to.
  29552. maxLength: 253
  29553. minLength: 1
  29554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29555. type: string
  29556. namespace:
  29557. description: |-
  29558. The namespace of the Secret resource being referred to.
  29559. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29560. maxLength: 63
  29561. minLength: 1
  29562. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29563. type: string
  29564. type: object
  29565. required:
  29566. - passwordSecret
  29567. - usernameSecret
  29568. type: object
  29569. type: object
  29570. body:
  29571. description: Body
  29572. type: string
  29573. caBundle:
  29574. description: |-
  29575. PEM encoded CA bundle used to validate webhook server certificate. Only used
  29576. if the Server URL is using HTTPS protocol. This parameter is ignored for
  29577. plain HTTP protocol connection. If not set the system root certificates
  29578. are used to validate the TLS connection.
  29579. format: byte
  29580. type: string
  29581. caProvider:
  29582. description: The provider for the CA bundle to use to validate webhook server certificate.
  29583. properties:
  29584. key:
  29585. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  29586. maxLength: 253
  29587. minLength: 1
  29588. pattern: ^[-._a-zA-Z0-9]+$
  29589. type: string
  29590. name:
  29591. description: The name of the object located at the provider type.
  29592. maxLength: 253
  29593. minLength: 1
  29594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29595. type: string
  29596. namespace:
  29597. description: The namespace the Provider type is in.
  29598. maxLength: 63
  29599. minLength: 1
  29600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29601. type: string
  29602. type:
  29603. description: The type of provider to use such as "Secret", or "ConfigMap".
  29604. enum:
  29605. - Secret
  29606. - ConfigMap
  29607. type: string
  29608. required:
  29609. - name
  29610. - type
  29611. type: object
  29612. headers:
  29613. additionalProperties:
  29614. type: string
  29615. description: Headers
  29616. type: object
  29617. method:
  29618. description: Webhook Method
  29619. type: string
  29620. result:
  29621. description: Result formatting
  29622. properties:
  29623. jsonPath:
  29624. description: Json path of return value
  29625. type: string
  29626. type: object
  29627. secrets:
  29628. description: |-
  29629. Secrets to fill in templates
  29630. These secrets will be passed to the templating function as key value pairs under the given name
  29631. items:
  29632. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  29633. properties:
  29634. name:
  29635. description: Name of this secret in templates
  29636. type: string
  29637. secretRef:
  29638. description: Secret ref to fill in credentials
  29639. properties:
  29640. key:
  29641. description: The key where the token is found.
  29642. maxLength: 253
  29643. minLength: 1
  29644. pattern: ^[-._a-zA-Z0-9]+$
  29645. type: string
  29646. name:
  29647. description: The name of the Secret resource being referred to.
  29648. maxLength: 253
  29649. minLength: 1
  29650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29651. type: string
  29652. type: object
  29653. required:
  29654. - name
  29655. - secretRef
  29656. type: object
  29657. type: array
  29658. timeout:
  29659. description: Timeout
  29660. type: string
  29661. url:
  29662. description: Webhook url to call
  29663. type: string
  29664. required:
  29665. - result
  29666. - url
  29667. type: object
  29668. type: object
  29669. kind:
  29670. description: Kind the kind of this generator.
  29671. enum:
  29672. - ACRAccessToken
  29673. - BeyondtrustWorkloadCredentialsDynamicSecret
  29674. - CloudsmithAccessToken
  29675. - ECRAuthorizationToken
  29676. - Fake
  29677. - GCRAccessToken
  29678. - GithubAccessToken
  29679. - GitlabDeployToken
  29680. - QuayAccessToken
  29681. - Password
  29682. - SSHKey
  29683. - STSSessionToken
  29684. - UUID
  29685. - VaultDynamicSecret
  29686. - Webhook
  29687. - Grafana
  29688. - MFA
  29689. type: string
  29690. required:
  29691. - generator
  29692. - kind
  29693. type: object
  29694. type: object
  29695. served: true
  29696. storage: true
  29697. subresources:
  29698. status: {}
  29699. ---
  29700. apiVersion: apiextensions.k8s.io/v1
  29701. kind: CustomResourceDefinition
  29702. metadata:
  29703. annotations:
  29704. controller-gen.kubebuilder.io/version: v0.19.0
  29705. labels:
  29706. external-secrets.io/component: controller
  29707. name: ecrauthorizationtokens.generators.external-secrets.io
  29708. spec:
  29709. group: generators.external-secrets.io
  29710. names:
  29711. categories:
  29712. - external-secrets
  29713. - external-secrets-generators
  29714. kind: ECRAuthorizationToken
  29715. listKind: ECRAuthorizationTokenList
  29716. plural: ecrauthorizationtokens
  29717. singular: ecrauthorizationtoken
  29718. scope: Namespaced
  29719. versions:
  29720. - name: v1alpha1
  29721. schema:
  29722. openAPIV3Schema:
  29723. description: |-
  29724. ECRAuthorizationToken uses the GetAuthorizationToken API to retrieve an authorization token.
  29725. The authorization token is valid for 12 hours.
  29726. The authorizationToken returned is a base64 encoded string that can be decoded
  29727. and used in a docker login command to authenticate to a registry.
  29728. For more information, see Registry authentication (https://docs.aws.amazon.com/AmazonECR/latest/userguide/Registries.html#registry_auth) in the Amazon Elastic Container Registry User Guide.
  29729. properties:
  29730. apiVersion:
  29731. description: |-
  29732. APIVersion defines the versioned schema of this representation of an object.
  29733. Servers should convert recognized schemas to the latest internal value, and
  29734. may reject unrecognized values.
  29735. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29736. type: string
  29737. kind:
  29738. description: |-
  29739. Kind is a string value representing the REST resource this object represents.
  29740. Servers may infer this from the endpoint the client submits requests to.
  29741. Cannot be updated.
  29742. In CamelCase.
  29743. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29744. type: string
  29745. metadata:
  29746. type: object
  29747. spec:
  29748. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  29749. properties:
  29750. auth:
  29751. description: Auth defines how to authenticate with AWS
  29752. properties:
  29753. jwt:
  29754. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  29755. properties:
  29756. serviceAccountRef:
  29757. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29758. properties:
  29759. audiences:
  29760. description: |-
  29761. Audience specifies the `aud` claim for the service account token
  29762. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29763. then this audiences will be appended to the list
  29764. items:
  29765. type: string
  29766. type: array
  29767. name:
  29768. description: The name of the ServiceAccount resource being referred to.
  29769. maxLength: 253
  29770. minLength: 1
  29771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29772. type: string
  29773. namespace:
  29774. description: |-
  29775. Namespace of the resource being referred to.
  29776. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29777. maxLength: 63
  29778. minLength: 1
  29779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29780. type: string
  29781. required:
  29782. - name
  29783. type: object
  29784. type: object
  29785. secretRef:
  29786. description: |-
  29787. AWSAuthSecretRef holds secret references for AWS credentials
  29788. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  29789. properties:
  29790. accessKeyIDSecretRef:
  29791. description: The AccessKeyID is used for authentication
  29792. properties:
  29793. key:
  29794. description: |-
  29795. A key in the referenced Secret.
  29796. Some instances of this field may be defaulted, in others it may be required.
  29797. maxLength: 253
  29798. minLength: 1
  29799. pattern: ^[-._a-zA-Z0-9]+$
  29800. type: string
  29801. name:
  29802. description: The name of the Secret resource being referred to.
  29803. maxLength: 253
  29804. minLength: 1
  29805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29806. type: string
  29807. namespace:
  29808. description: |-
  29809. The namespace of the Secret resource being referred to.
  29810. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29811. maxLength: 63
  29812. minLength: 1
  29813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29814. type: string
  29815. type: object
  29816. secretAccessKeySecretRef:
  29817. description: The SecretAccessKey is used for authentication
  29818. properties:
  29819. key:
  29820. description: |-
  29821. A key in the referenced Secret.
  29822. Some instances of this field may be defaulted, in others it may be required.
  29823. maxLength: 253
  29824. minLength: 1
  29825. pattern: ^[-._a-zA-Z0-9]+$
  29826. type: string
  29827. name:
  29828. description: The name of the Secret resource being referred to.
  29829. maxLength: 253
  29830. minLength: 1
  29831. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29832. type: string
  29833. namespace:
  29834. description: |-
  29835. The namespace of the Secret resource being referred to.
  29836. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29837. maxLength: 63
  29838. minLength: 1
  29839. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29840. type: string
  29841. type: object
  29842. sessionTokenSecretRef:
  29843. description: |-
  29844. The SessionToken used for authentication
  29845. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  29846. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  29847. properties:
  29848. key:
  29849. description: |-
  29850. A key in the referenced Secret.
  29851. Some instances of this field may be defaulted, in others it may be required.
  29852. maxLength: 253
  29853. minLength: 1
  29854. pattern: ^[-._a-zA-Z0-9]+$
  29855. type: string
  29856. name:
  29857. description: The name of the Secret resource being referred to.
  29858. maxLength: 253
  29859. minLength: 1
  29860. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29861. type: string
  29862. namespace:
  29863. description: |-
  29864. The namespace of the Secret resource being referred to.
  29865. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29866. maxLength: 63
  29867. minLength: 1
  29868. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29869. type: string
  29870. type: object
  29871. type: object
  29872. type: object
  29873. region:
  29874. description: Region specifies the region to operate in.
  29875. type: string
  29876. role:
  29877. description: |-
  29878. You can assume a role before making calls to the
  29879. desired AWS service.
  29880. type: string
  29881. scope:
  29882. description: |-
  29883. Scope specifies the ECR service scope.
  29884. Valid options are private and public.
  29885. type: string
  29886. required:
  29887. - region
  29888. type: object
  29889. type: object
  29890. served: true
  29891. storage: true
  29892. subresources:
  29893. status: {}
  29894. ---
  29895. apiVersion: apiextensions.k8s.io/v1
  29896. kind: CustomResourceDefinition
  29897. metadata:
  29898. annotations:
  29899. controller-gen.kubebuilder.io/version: v0.19.0
  29900. labels:
  29901. external-secrets.io/component: controller
  29902. name: fakes.generators.external-secrets.io
  29903. spec:
  29904. group: generators.external-secrets.io
  29905. names:
  29906. categories:
  29907. - external-secrets
  29908. - external-secrets-generators
  29909. kind: Fake
  29910. listKind: FakeList
  29911. plural: fakes
  29912. singular: fake
  29913. scope: Namespaced
  29914. versions:
  29915. - name: v1alpha1
  29916. schema:
  29917. openAPIV3Schema:
  29918. description: |-
  29919. Fake generator is used for testing. It lets you define
  29920. a static set of credentials that is always returned.
  29921. properties:
  29922. apiVersion:
  29923. description: |-
  29924. APIVersion defines the versioned schema of this representation of an object.
  29925. Servers should convert recognized schemas to the latest internal value, and
  29926. may reject unrecognized values.
  29927. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29928. type: string
  29929. kind:
  29930. description: |-
  29931. Kind is a string value representing the REST resource this object represents.
  29932. Servers may infer this from the endpoint the client submits requests to.
  29933. Cannot be updated.
  29934. In CamelCase.
  29935. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29936. type: string
  29937. metadata:
  29938. type: object
  29939. spec:
  29940. description: FakeSpec contains the static data.
  29941. properties:
  29942. controller:
  29943. description: |-
  29944. Used to select the correct ESO controller (think: ingress.ingressClassName)
  29945. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  29946. type: string
  29947. data:
  29948. additionalProperties:
  29949. type: string
  29950. description: |-
  29951. Data defines the static data returned
  29952. by this generator.
  29953. type: object
  29954. type: object
  29955. type: object
  29956. served: true
  29957. storage: true
  29958. subresources:
  29959. status: {}
  29960. ---
  29961. apiVersion: apiextensions.k8s.io/v1
  29962. kind: CustomResourceDefinition
  29963. metadata:
  29964. annotations:
  29965. controller-gen.kubebuilder.io/version: v0.19.0
  29966. labels:
  29967. external-secrets.io/component: controller
  29968. name: gcraccesstokens.generators.external-secrets.io
  29969. spec:
  29970. group: generators.external-secrets.io
  29971. names:
  29972. categories:
  29973. - external-secrets
  29974. - external-secrets-generators
  29975. kind: GCRAccessToken
  29976. listKind: GCRAccessTokenList
  29977. plural: gcraccesstokens
  29978. singular: gcraccesstoken
  29979. scope: Namespaced
  29980. versions:
  29981. - name: v1alpha1
  29982. schema:
  29983. openAPIV3Schema:
  29984. description: |-
  29985. GCRAccessToken generates an GCP access token
  29986. that can be used to authenticate with GCR.
  29987. properties:
  29988. apiVersion:
  29989. description: |-
  29990. APIVersion defines the versioned schema of this representation of an object.
  29991. Servers should convert recognized schemas to the latest internal value, and
  29992. may reject unrecognized values.
  29993. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29994. type: string
  29995. kind:
  29996. description: |-
  29997. Kind is a string value representing the REST resource this object represents.
  29998. Servers may infer this from the endpoint the client submits requests to.
  29999. Cannot be updated.
  30000. In CamelCase.
  30001. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30002. type: string
  30003. metadata:
  30004. type: object
  30005. spec:
  30006. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  30007. properties:
  30008. auth:
  30009. description: Auth defines the means for authenticating with GCP
  30010. properties:
  30011. secretRef:
  30012. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  30013. properties:
  30014. secretAccessKeySecretRef:
  30015. description: The SecretAccessKey is used for authentication
  30016. properties:
  30017. key:
  30018. description: |-
  30019. A key in the referenced Secret.
  30020. Some instances of this field may be defaulted, in others it may be required.
  30021. maxLength: 253
  30022. minLength: 1
  30023. pattern: ^[-._a-zA-Z0-9]+$
  30024. type: string
  30025. name:
  30026. description: The name of the Secret resource being referred to.
  30027. maxLength: 253
  30028. minLength: 1
  30029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30030. type: string
  30031. namespace:
  30032. description: |-
  30033. The namespace of the Secret resource being referred to.
  30034. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30035. maxLength: 63
  30036. minLength: 1
  30037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30038. type: string
  30039. type: object
  30040. type: object
  30041. workloadIdentity:
  30042. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  30043. properties:
  30044. clusterLocation:
  30045. type: string
  30046. clusterName:
  30047. type: string
  30048. clusterProjectID:
  30049. type: string
  30050. serviceAccountRef:
  30051. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  30052. properties:
  30053. audiences:
  30054. description: |-
  30055. Audience specifies the `aud` claim for the service account token
  30056. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30057. then this audiences will be appended to the list
  30058. items:
  30059. type: string
  30060. type: array
  30061. name:
  30062. description: The name of the ServiceAccount resource being referred to.
  30063. maxLength: 253
  30064. minLength: 1
  30065. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30066. type: string
  30067. namespace:
  30068. description: |-
  30069. Namespace of the resource being referred to.
  30070. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30071. maxLength: 63
  30072. minLength: 1
  30073. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30074. type: string
  30075. required:
  30076. - name
  30077. type: object
  30078. required:
  30079. - clusterLocation
  30080. - clusterName
  30081. - serviceAccountRef
  30082. type: object
  30083. workloadIdentityFederation:
  30084. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  30085. properties:
  30086. audience:
  30087. description: |-
  30088. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  30089. If specified, Audience found in the external account credential config will be overridden with the configured value.
  30090. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  30091. type: string
  30092. awsSecurityCredentials:
  30093. description: |-
  30094. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  30095. when using the AWS metadata server is not an option.
  30096. properties:
  30097. awsCredentialsSecretRef:
  30098. description: |-
  30099. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  30100. Secret should be created with below names for keys
  30101. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  30102. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  30103. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  30104. properties:
  30105. name:
  30106. description: name of the secret.
  30107. maxLength: 253
  30108. minLength: 1
  30109. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30110. type: string
  30111. namespace:
  30112. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  30113. maxLength: 63
  30114. minLength: 1
  30115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30116. type: string
  30117. required:
  30118. - name
  30119. type: object
  30120. region:
  30121. description: region is for configuring the AWS region to be used.
  30122. example: ap-south-1
  30123. maxLength: 50
  30124. minLength: 1
  30125. pattern: ^[a-z0-9-]+$
  30126. type: string
  30127. required:
  30128. - awsCredentialsSecretRef
  30129. - region
  30130. type: object
  30131. credConfig:
  30132. description: |-
  30133. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  30134. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  30135. serviceAccountRef must be used by providing operators service account details.
  30136. properties:
  30137. key:
  30138. description: key name holding the external account credential config.
  30139. maxLength: 253
  30140. minLength: 1
  30141. pattern: ^[-._a-zA-Z0-9]+$
  30142. type: string
  30143. name:
  30144. description: name of the configmap.
  30145. maxLength: 253
  30146. minLength: 1
  30147. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30148. type: string
  30149. namespace:
  30150. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  30151. maxLength: 63
  30152. minLength: 1
  30153. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30154. type: string
  30155. required:
  30156. - key
  30157. - name
  30158. type: object
  30159. externalTokenEndpoint:
  30160. description: |-
  30161. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  30162. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  30163. URL is having the expected value.
  30164. type: string
  30165. gcpServiceAccountEmail:
  30166. description: |-
  30167. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  30168. after Workload Identity Federation. Use this to grant access through the service account's
  30169. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  30170. service_account_impersonation_url in the external account JSON from credConfig;
  30171. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  30172. on that ServiceAccount.
  30173. example: my-gsa@my-project.iam.gserviceaccount.com
  30174. minLength: 1
  30175. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  30176. type: string
  30177. serviceAccountRef:
  30178. description: |-
  30179. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  30180. when Kubernetes is configured as provider in workload identity pool.
  30181. properties:
  30182. audiences:
  30183. description: |-
  30184. Audience specifies the `aud` claim for the service account token
  30185. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30186. then this audiences will be appended to the list
  30187. items:
  30188. type: string
  30189. type: array
  30190. name:
  30191. description: The name of the ServiceAccount resource being referred to.
  30192. maxLength: 253
  30193. minLength: 1
  30194. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30195. type: string
  30196. namespace:
  30197. description: |-
  30198. Namespace of the resource being referred to.
  30199. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30200. maxLength: 63
  30201. minLength: 1
  30202. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30203. type: string
  30204. required:
  30205. - name
  30206. type: object
  30207. type: object
  30208. type: object
  30209. projectID:
  30210. description: ProjectID defines which project to use to authenticate with
  30211. type: string
  30212. required:
  30213. - auth
  30214. - projectID
  30215. type: object
  30216. type: object
  30217. served: true
  30218. storage: true
  30219. subresources:
  30220. status: {}
  30221. ---
  30222. apiVersion: apiextensions.k8s.io/v1
  30223. kind: CustomResourceDefinition
  30224. metadata:
  30225. annotations:
  30226. controller-gen.kubebuilder.io/version: v0.19.0
  30227. labels:
  30228. external-secrets.io/component: controller
  30229. name: generatorstates.generators.external-secrets.io
  30230. spec:
  30231. group: generators.external-secrets.io
  30232. names:
  30233. categories:
  30234. - external-secrets
  30235. - external-secrets-generators
  30236. kind: GeneratorState
  30237. listKind: GeneratorStateList
  30238. plural: generatorstates
  30239. shortNames:
  30240. - gs
  30241. singular: generatorstate
  30242. scope: Namespaced
  30243. versions:
  30244. - additionalPrinterColumns:
  30245. - jsonPath: .spec.garbageCollectionDeadline
  30246. name: GC Deadline
  30247. type: string
  30248. - jsonPath: .metadata.creationTimestamp
  30249. name: Age
  30250. type: date
  30251. name: v1alpha1
  30252. schema:
  30253. openAPIV3Schema:
  30254. description: GeneratorState represents the state created and managed by a generator resource.
  30255. properties:
  30256. apiVersion:
  30257. description: |-
  30258. APIVersion defines the versioned schema of this representation of an object.
  30259. Servers should convert recognized schemas to the latest internal value, and
  30260. may reject unrecognized values.
  30261. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30262. type: string
  30263. kind:
  30264. description: |-
  30265. Kind is a string value representing the REST resource this object represents.
  30266. Servers may infer this from the endpoint the client submits requests to.
  30267. Cannot be updated.
  30268. In CamelCase.
  30269. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30270. type: string
  30271. metadata:
  30272. type: object
  30273. spec:
  30274. description: GeneratorStateSpec defines the desired state of a generator state resource.
  30275. properties:
  30276. garbageCollectionDeadline:
  30277. description: |-
  30278. GarbageCollectionDeadline is the time after which the generator state
  30279. will be deleted.
  30280. It is set by the controller which creates the generator state and
  30281. can be set configured by the user.
  30282. If the garbage collection deadline is not set the generator state will not be deleted.
  30283. format: date-time
  30284. type: string
  30285. resource:
  30286. description: |-
  30287. Resource is the generator manifest that produced the state.
  30288. It is a snapshot of the generator manifest at the time the state was produced.
  30289. This manifest will be used to delete the resource. Any configuration that is referenced
  30290. in the manifest should be available at the time of garbage collection. If that is not the case deletion will
  30291. be blocked by a finalizer.
  30292. x-kubernetes-preserve-unknown-fields: true
  30293. state:
  30294. description: State is the state that was produced by the generator implementation.
  30295. x-kubernetes-preserve-unknown-fields: true
  30296. required:
  30297. - resource
  30298. - state
  30299. type: object
  30300. status:
  30301. description: GeneratorStateStatus defines the observed state of a generator state resource.
  30302. properties:
  30303. conditions:
  30304. items:
  30305. description: GeneratorStateStatusCondition represents the observed condition of a generator state.
  30306. properties:
  30307. lastTransitionTime:
  30308. format: date-time
  30309. type: string
  30310. message:
  30311. type: string
  30312. reason:
  30313. type: string
  30314. status:
  30315. type: string
  30316. type:
  30317. description: GeneratorStateConditionType represents the type of condition for a generator state.
  30318. type: string
  30319. required:
  30320. - status
  30321. - type
  30322. type: object
  30323. type: array
  30324. type: object
  30325. type: object
  30326. served: true
  30327. storage: true
  30328. subresources: {}
  30329. ---
  30330. apiVersion: apiextensions.k8s.io/v1
  30331. kind: CustomResourceDefinition
  30332. metadata:
  30333. annotations:
  30334. controller-gen.kubebuilder.io/version: v0.19.0
  30335. labels:
  30336. external-secrets.io/component: controller
  30337. name: githubaccesstokens.generators.external-secrets.io
  30338. spec:
  30339. group: generators.external-secrets.io
  30340. names:
  30341. categories:
  30342. - external-secrets
  30343. - external-secrets-generators
  30344. kind: GithubAccessToken
  30345. listKind: GithubAccessTokenList
  30346. plural: githubaccesstokens
  30347. singular: githubaccesstoken
  30348. scope: Namespaced
  30349. versions:
  30350. - name: v1alpha1
  30351. schema:
  30352. openAPIV3Schema:
  30353. description: GithubAccessToken generates ghs_ accessToken
  30354. properties:
  30355. apiVersion:
  30356. description: |-
  30357. APIVersion defines the versioned schema of this representation of an object.
  30358. Servers should convert recognized schemas to the latest internal value, and
  30359. may reject unrecognized values.
  30360. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30361. type: string
  30362. kind:
  30363. description: |-
  30364. Kind is a string value representing the REST resource this object represents.
  30365. Servers may infer this from the endpoint the client submits requests to.
  30366. Cannot be updated.
  30367. In CamelCase.
  30368. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30369. type: string
  30370. metadata:
  30371. type: object
  30372. spec:
  30373. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  30374. properties:
  30375. appID:
  30376. type: string
  30377. auth:
  30378. description: Auth configures how ESO authenticates with a Github instance.
  30379. properties:
  30380. privateKey:
  30381. description: GithubSecretRef references a secret containing GitHub credentials.
  30382. properties:
  30383. secretRef:
  30384. description: |-
  30385. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30386. In some instances, `key` is a required field.
  30387. properties:
  30388. key:
  30389. description: |-
  30390. A key in the referenced Secret.
  30391. Some instances of this field may be defaulted, in others it may be required.
  30392. maxLength: 253
  30393. minLength: 1
  30394. pattern: ^[-._a-zA-Z0-9]+$
  30395. type: string
  30396. name:
  30397. description: The name of the Secret resource being referred to.
  30398. maxLength: 253
  30399. minLength: 1
  30400. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30401. type: string
  30402. namespace:
  30403. description: |-
  30404. The namespace of the Secret resource being referred to.
  30405. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30406. maxLength: 63
  30407. minLength: 1
  30408. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30409. type: string
  30410. type: object
  30411. required:
  30412. - secretRef
  30413. type: object
  30414. required:
  30415. - privateKey
  30416. type: object
  30417. installID:
  30418. type: string
  30419. permissions:
  30420. additionalProperties:
  30421. type: string
  30422. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  30423. type: object
  30424. repositories:
  30425. description: |-
  30426. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  30427. is installed to.
  30428. items:
  30429. type: string
  30430. type: array
  30431. url:
  30432. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  30433. type: string
  30434. required:
  30435. - appID
  30436. - auth
  30437. - installID
  30438. type: object
  30439. type: object
  30440. served: true
  30441. storage: true
  30442. subresources:
  30443. status: {}
  30444. ---
  30445. apiVersion: apiextensions.k8s.io/v1
  30446. kind: CustomResourceDefinition
  30447. metadata:
  30448. annotations:
  30449. controller-gen.kubebuilder.io/version: v0.19.0
  30450. labels:
  30451. external-secrets.io/component: controller
  30452. name: gitlabdeploytokens.generators.external-secrets.io
  30453. spec:
  30454. group: generators.external-secrets.io
  30455. names:
  30456. categories:
  30457. - external-secrets
  30458. - external-secrets-generators
  30459. kind: GitlabDeployToken
  30460. listKind: GitlabDeployTokenList
  30461. plural: gitlabdeploytokens
  30462. singular: gitlabdeploytoken
  30463. scope: Namespaced
  30464. versions:
  30465. - name: v1alpha1
  30466. schema:
  30467. openAPIV3Schema:
  30468. description: GitlabDeployToken generates a GitLab deploy token.
  30469. properties:
  30470. apiVersion:
  30471. description: |-
  30472. APIVersion defines the versioned schema of this representation of an object.
  30473. Servers should convert recognized schemas to the latest internal value, and
  30474. may reject unrecognized values.
  30475. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30476. type: string
  30477. kind:
  30478. description: |-
  30479. Kind is a string value representing the REST resource this object represents.
  30480. Servers may infer this from the endpoint the client submits requests to.
  30481. Cannot be updated.
  30482. In CamelCase.
  30483. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30484. type: string
  30485. metadata:
  30486. type: object
  30487. spec:
  30488. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  30489. properties:
  30490. auth:
  30491. description: Auth configures how ESO authenticates with the GitLab API.
  30492. properties:
  30493. token:
  30494. description: |-
  30495. Token references a secret containing a GitLab access token (personal, group, or
  30496. project) with the api scope and at least the Maintainer role on the target.
  30497. properties:
  30498. secretRef:
  30499. description: |-
  30500. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30501. In some instances, `key` is a required field.
  30502. properties:
  30503. key:
  30504. description: |-
  30505. A key in the referenced Secret.
  30506. Some instances of this field may be defaulted, in others it may be required.
  30507. maxLength: 253
  30508. minLength: 1
  30509. pattern: ^[-._a-zA-Z0-9]+$
  30510. type: string
  30511. name:
  30512. description: The name of the Secret resource being referred to.
  30513. maxLength: 253
  30514. minLength: 1
  30515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30516. type: string
  30517. namespace:
  30518. description: |-
  30519. The namespace of the Secret resource being referred to.
  30520. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30521. maxLength: 63
  30522. minLength: 1
  30523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30524. type: string
  30525. type: object
  30526. required:
  30527. - secretRef
  30528. type: object
  30529. required:
  30530. - token
  30531. type: object
  30532. expiresAt:
  30533. description: |-
  30534. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  30535. not expire on the GitLab side and is revoked only when the generator state is
  30536. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  30537. format: date-time
  30538. type: string
  30539. groupID:
  30540. description: |-
  30541. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  30542. create the deploy token in. The generator URL-escapes paths before calling the
  30543. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  30544. minLength: 1
  30545. type: string
  30546. name:
  30547. description: Name of the deploy token.
  30548. minLength: 1
  30549. type: string
  30550. projectID:
  30551. description: |-
  30552. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  30553. project to create the deploy token in. The generator URL-escapes paths before
  30554. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  30555. minLength: 1
  30556. type: string
  30557. scopes:
  30558. description: Scopes granted to the deploy token. At least one scope is required.
  30559. items:
  30560. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  30561. enum:
  30562. - read_repository
  30563. - read_registry
  30564. - write_registry
  30565. - read_package_registry
  30566. - write_package_registry
  30567. - read_virtual_registry
  30568. - write_virtual_registry
  30569. type: string
  30570. minItems: 1
  30571. type: array
  30572. url:
  30573. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  30574. type: string
  30575. username:
  30576. description: |-
  30577. Username is an optional username for the deploy token. GitLab defaults it to
  30578. gitlab+deploy-token-{n} when omitted.
  30579. type: string
  30580. required:
  30581. - auth
  30582. - name
  30583. - scopes
  30584. type: object
  30585. x-kubernetes-validations:
  30586. - message: exactly one of projectID or groupID must be set
  30587. rule: has(self.projectID) != has(self.groupID)
  30588. type: object
  30589. served: true
  30590. storage: true
  30591. subresources:
  30592. status: {}
  30593. ---
  30594. apiVersion: apiextensions.k8s.io/v1
  30595. kind: CustomResourceDefinition
  30596. metadata:
  30597. annotations:
  30598. controller-gen.kubebuilder.io/version: v0.19.0
  30599. labels:
  30600. external-secrets.io/component: controller
  30601. name: grafanas.generators.external-secrets.io
  30602. spec:
  30603. group: generators.external-secrets.io
  30604. names:
  30605. categories:
  30606. - external-secrets
  30607. - external-secrets-generators
  30608. kind: Grafana
  30609. listKind: GrafanaList
  30610. plural: grafanas
  30611. singular: grafana
  30612. scope: Namespaced
  30613. versions:
  30614. - name: v1alpha1
  30615. schema:
  30616. openAPIV3Schema:
  30617. description: Grafana represents a generator for Grafana service account tokens.
  30618. properties:
  30619. apiVersion:
  30620. description: |-
  30621. APIVersion defines the versioned schema of this representation of an object.
  30622. Servers should convert recognized schemas to the latest internal value, and
  30623. may reject unrecognized values.
  30624. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30625. type: string
  30626. kind:
  30627. description: |-
  30628. Kind is a string value representing the REST resource this object represents.
  30629. Servers may infer this from the endpoint the client submits requests to.
  30630. Cannot be updated.
  30631. In CamelCase.
  30632. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30633. type: string
  30634. metadata:
  30635. type: object
  30636. spec:
  30637. description: GrafanaSpec controls the behavior of the grafana generator.
  30638. properties:
  30639. auth:
  30640. description: |-
  30641. Auth is the authentication configuration to authenticate
  30642. against the Grafana instance.
  30643. properties:
  30644. basic:
  30645. description: |-
  30646. Basic auth credentials used to authenticate against the Grafana instance.
  30647. Note: you need a token which has elevated permissions to create service accounts.
  30648. See here for the documentation on basic roles offered by Grafana:
  30649. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30650. properties:
  30651. password:
  30652. description: A basic auth password used to authenticate against the Grafana instance.
  30653. properties:
  30654. key:
  30655. description: The key where the token is found.
  30656. maxLength: 253
  30657. minLength: 1
  30658. pattern: ^[-._a-zA-Z0-9]+$
  30659. type: string
  30660. name:
  30661. description: The name of the Secret resource being referred to.
  30662. maxLength: 253
  30663. minLength: 1
  30664. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30665. type: string
  30666. type: object
  30667. username:
  30668. description: A basic auth username used to authenticate against the Grafana instance.
  30669. type: string
  30670. required:
  30671. - password
  30672. - username
  30673. type: object
  30674. token:
  30675. description: |-
  30676. A service account token used to authenticate against the Grafana instance.
  30677. Note: you need a token which has elevated permissions to create service accounts.
  30678. See here for the documentation on basic roles offered by Grafana:
  30679. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30680. properties:
  30681. key:
  30682. description: The key where the token is found.
  30683. maxLength: 253
  30684. minLength: 1
  30685. pattern: ^[-._a-zA-Z0-9]+$
  30686. type: string
  30687. name:
  30688. description: The name of the Secret resource being referred to.
  30689. maxLength: 253
  30690. minLength: 1
  30691. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30692. type: string
  30693. type: object
  30694. type: object
  30695. serviceAccount:
  30696. description: |-
  30697. ServiceAccount is the configuration for the service account that
  30698. is supposed to be generated by the generator.
  30699. properties:
  30700. name:
  30701. description: Name is the name of the service account that will be created by ESO.
  30702. type: string
  30703. role:
  30704. description: |-
  30705. Role is the role of the service account.
  30706. See here for the documentation on basic roles offered by Grafana:
  30707. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30708. type: string
  30709. secondsToLive:
  30710. description: |-
  30711. SecondsToLive is the number of seconds before the generated service account token will expire.
  30712. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  30713. format: int64
  30714. minimum: 1
  30715. type: integer
  30716. required:
  30717. - name
  30718. - role
  30719. type: object
  30720. url:
  30721. description: URL is the URL of the Grafana instance.
  30722. type: string
  30723. required:
  30724. - auth
  30725. - serviceAccount
  30726. - url
  30727. type: object
  30728. type: object
  30729. served: true
  30730. storage: true
  30731. subresources:
  30732. status: {}
  30733. ---
  30734. apiVersion: apiextensions.k8s.io/v1
  30735. kind: CustomResourceDefinition
  30736. metadata:
  30737. annotations:
  30738. controller-gen.kubebuilder.io/version: v0.19.0
  30739. labels:
  30740. external-secrets.io/component: controller
  30741. name: mfas.generators.external-secrets.io
  30742. spec:
  30743. group: generators.external-secrets.io
  30744. names:
  30745. categories:
  30746. - external-secrets
  30747. - external-secrets-generators
  30748. kind: MFA
  30749. listKind: MFAList
  30750. plural: mfas
  30751. singular: mfa
  30752. scope: Namespaced
  30753. versions:
  30754. - name: v1alpha1
  30755. schema:
  30756. openAPIV3Schema:
  30757. description: MFA generates a new TOTP token that is compliant with RFC 6238.
  30758. properties:
  30759. apiVersion:
  30760. description: |-
  30761. APIVersion defines the versioned schema of this representation of an object.
  30762. Servers should convert recognized schemas to the latest internal value, and
  30763. may reject unrecognized values.
  30764. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30765. type: string
  30766. kind:
  30767. description: |-
  30768. Kind is a string value representing the REST resource this object represents.
  30769. Servers may infer this from the endpoint the client submits requests to.
  30770. Cannot be updated.
  30771. In CamelCase.
  30772. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30773. type: string
  30774. metadata:
  30775. type: object
  30776. spec:
  30777. description: MFASpec controls the behavior of the mfa generator.
  30778. properties:
  30779. algorithm:
  30780. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  30781. type: string
  30782. length:
  30783. description: Length defines the token length. Defaults to 6 characters.
  30784. type: integer
  30785. secret:
  30786. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  30787. properties:
  30788. key:
  30789. description: |-
  30790. A key in the referenced Secret.
  30791. Some instances of this field may be defaulted, in others it may be required.
  30792. maxLength: 253
  30793. minLength: 1
  30794. pattern: ^[-._a-zA-Z0-9]+$
  30795. type: string
  30796. name:
  30797. description: The name of the Secret resource being referred to.
  30798. maxLength: 253
  30799. minLength: 1
  30800. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30801. type: string
  30802. namespace:
  30803. description: |-
  30804. The namespace of the Secret resource being referred to.
  30805. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30806. maxLength: 63
  30807. minLength: 1
  30808. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30809. type: string
  30810. type: object
  30811. timePeriod:
  30812. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  30813. type: integer
  30814. when:
  30815. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  30816. format: date-time
  30817. type: string
  30818. required:
  30819. - secret
  30820. type: object
  30821. type: object
  30822. served: true
  30823. storage: true
  30824. subresources:
  30825. status: {}
  30826. ---
  30827. apiVersion: apiextensions.k8s.io/v1
  30828. kind: CustomResourceDefinition
  30829. metadata:
  30830. annotations:
  30831. controller-gen.kubebuilder.io/version: v0.19.0
  30832. labels:
  30833. external-secrets.io/component: controller
  30834. name: passwords.generators.external-secrets.io
  30835. spec:
  30836. group: generators.external-secrets.io
  30837. names:
  30838. categories:
  30839. - external-secrets
  30840. - external-secrets-generators
  30841. kind: Password
  30842. listKind: PasswordList
  30843. plural: passwords
  30844. singular: password
  30845. scope: Namespaced
  30846. versions:
  30847. - name: v1alpha1
  30848. schema:
  30849. openAPIV3Schema:
  30850. description: |-
  30851. Password generates a random password based on the
  30852. configuration parameters in spec.
  30853. You can specify the length, characterset and other attributes.
  30854. properties:
  30855. apiVersion:
  30856. description: |-
  30857. APIVersion defines the versioned schema of this representation of an object.
  30858. Servers should convert recognized schemas to the latest internal value, and
  30859. may reject unrecognized values.
  30860. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30861. type: string
  30862. kind:
  30863. description: |-
  30864. Kind is a string value representing the REST resource this object represents.
  30865. Servers may infer this from the endpoint the client submits requests to.
  30866. Cannot be updated.
  30867. In CamelCase.
  30868. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30869. type: string
  30870. metadata:
  30871. type: object
  30872. spec:
  30873. description: PasswordSpec controls the behavior of the password generator.
  30874. properties:
  30875. allowRepeat:
  30876. default: false
  30877. description: set AllowRepeat to true to allow repeating characters.
  30878. type: boolean
  30879. digits:
  30880. description: |-
  30881. Digits specifies the number of digits in the generated
  30882. password. If omitted it defaults to 25% of the length of the password
  30883. type: integer
  30884. encoding:
  30885. default: raw
  30886. description: |-
  30887. Encoding specifies the encoding of the generated password.
  30888. Valid values are:
  30889. - "raw" (default): no encoding
  30890. - "base64": standard base64 encoding
  30891. - "base64url": base64url encoding
  30892. - "base32": base32 encoding
  30893. - "hex": hexadecimal encoding
  30894. enum:
  30895. - base64
  30896. - base64url
  30897. - base32
  30898. - hex
  30899. - raw
  30900. type: string
  30901. length:
  30902. default: 24
  30903. description: |-
  30904. Length of the password to be generated.
  30905. Defaults to 24
  30906. type: integer
  30907. noUpper:
  30908. default: false
  30909. description: Set NoUpper to disable uppercase characters
  30910. type: boolean
  30911. secretKeys:
  30912. description: |-
  30913. SecretKeys defines the keys that will be populated with generated passwords.
  30914. Defaults to "password" when not set.
  30915. items:
  30916. type: string
  30917. minItems: 1
  30918. type: array
  30919. symbolCharacters:
  30920. description: |-
  30921. SymbolCharacters specifies the special characters that should be used
  30922. in the generated password.
  30923. type: string
  30924. symbols:
  30925. description: |-
  30926. Symbols specifies the number of symbol characters in the generated
  30927. password. If omitted it defaults to 25% of the length of the password
  30928. type: integer
  30929. required:
  30930. - allowRepeat
  30931. - length
  30932. - noUpper
  30933. type: object
  30934. type: object
  30935. served: true
  30936. storage: true
  30937. subresources:
  30938. status: {}
  30939. ---
  30940. apiVersion: apiextensions.k8s.io/v1
  30941. kind: CustomResourceDefinition
  30942. metadata:
  30943. annotations:
  30944. controller-gen.kubebuilder.io/version: v0.19.0
  30945. labels:
  30946. external-secrets.io/component: controller
  30947. name: quayaccesstokens.generators.external-secrets.io
  30948. spec:
  30949. group: generators.external-secrets.io
  30950. names:
  30951. categories:
  30952. - external-secrets
  30953. - external-secrets-generators
  30954. kind: QuayAccessToken
  30955. listKind: QuayAccessTokenList
  30956. plural: quayaccesstokens
  30957. singular: quayaccesstoken
  30958. scope: Namespaced
  30959. versions:
  30960. - name: v1alpha1
  30961. schema:
  30962. openAPIV3Schema:
  30963. description: QuayAccessToken generates Quay oauth token for pulling/pushing images
  30964. properties:
  30965. apiVersion:
  30966. description: |-
  30967. APIVersion defines the versioned schema of this representation of an object.
  30968. Servers should convert recognized schemas to the latest internal value, and
  30969. may reject unrecognized values.
  30970. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30971. type: string
  30972. kind:
  30973. description: |-
  30974. Kind is a string value representing the REST resource this object represents.
  30975. Servers may infer this from the endpoint the client submits requests to.
  30976. Cannot be updated.
  30977. In CamelCase.
  30978. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30979. type: string
  30980. metadata:
  30981. type: object
  30982. spec:
  30983. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  30984. properties:
  30985. robotAccount:
  30986. description: Name of the robot account you are federating with
  30987. type: string
  30988. serviceAccountRef:
  30989. description: Name of the service account you are federating with
  30990. properties:
  30991. audiences:
  30992. description: |-
  30993. Audience specifies the `aud` claim for the service account token
  30994. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30995. then this audiences will be appended to the list
  30996. items:
  30997. type: string
  30998. type: array
  30999. name:
  31000. description: The name of the ServiceAccount resource being referred to.
  31001. maxLength: 253
  31002. minLength: 1
  31003. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31004. type: string
  31005. namespace:
  31006. description: |-
  31007. Namespace of the resource being referred to.
  31008. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31009. maxLength: 63
  31010. minLength: 1
  31011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31012. type: string
  31013. required:
  31014. - name
  31015. type: object
  31016. url:
  31017. description: URL configures the Quay instance URL. Defaults to quay.io.
  31018. type: string
  31019. required:
  31020. - robotAccount
  31021. - serviceAccountRef
  31022. type: object
  31023. type: object
  31024. served: true
  31025. storage: true
  31026. subresources:
  31027. status: {}
  31028. ---
  31029. apiVersion: apiextensions.k8s.io/v1
  31030. kind: CustomResourceDefinition
  31031. metadata:
  31032. annotations:
  31033. controller-gen.kubebuilder.io/version: v0.19.0
  31034. labels:
  31035. external-secrets.io/component: controller
  31036. name: sshkeys.generators.external-secrets.io
  31037. spec:
  31038. group: generators.external-secrets.io
  31039. names:
  31040. categories:
  31041. - external-secrets
  31042. - external-secrets-generators
  31043. kind: SSHKey
  31044. listKind: SSHKeyList
  31045. plural: sshkeys
  31046. singular: sshkey
  31047. scope: Namespaced
  31048. versions:
  31049. - name: v1alpha1
  31050. schema:
  31051. openAPIV3Schema:
  31052. description: SSHKey generates SSH key pairs.
  31053. properties:
  31054. apiVersion:
  31055. description: |-
  31056. APIVersion defines the versioned schema of this representation of an object.
  31057. Servers should convert recognized schemas to the latest internal value, and
  31058. may reject unrecognized values.
  31059. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31060. type: string
  31061. kind:
  31062. description: |-
  31063. Kind is a string value representing the REST resource this object represents.
  31064. Servers may infer this from the endpoint the client submits requests to.
  31065. Cannot be updated.
  31066. In CamelCase.
  31067. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31068. type: string
  31069. metadata:
  31070. type: object
  31071. spec:
  31072. description: SSHKeySpec controls the behavior of the ssh key generator.
  31073. properties:
  31074. comment:
  31075. description: Comment specifies an optional comment for the SSH key
  31076. type: string
  31077. keySize:
  31078. description: |-
  31079. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  31080. For RSA keys: 2048, 3072, 4096
  31081. For ECDSA keys: 256, 384, 521
  31082. Ignored for ed25519 keys
  31083. maximum: 8192
  31084. minimum: 256
  31085. type: integer
  31086. keyType:
  31087. default: rsa
  31088. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  31089. enum:
  31090. - rsa
  31091. - ecdsa
  31092. - ed25519
  31093. type: string
  31094. type: object
  31095. type: object
  31096. served: true
  31097. storage: true
  31098. subresources:
  31099. status: {}
  31100. ---
  31101. apiVersion: apiextensions.k8s.io/v1
  31102. kind: CustomResourceDefinition
  31103. metadata:
  31104. annotations:
  31105. controller-gen.kubebuilder.io/version: v0.19.0
  31106. labels:
  31107. external-secrets.io/component: controller
  31108. name: stssessiontokens.generators.external-secrets.io
  31109. spec:
  31110. group: generators.external-secrets.io
  31111. names:
  31112. categories:
  31113. - external-secrets
  31114. - external-secrets-generators
  31115. kind: STSSessionToken
  31116. listKind: STSSessionTokenList
  31117. plural: stssessiontokens
  31118. singular: stssessiontoken
  31119. scope: Namespaced
  31120. versions:
  31121. - name: v1alpha1
  31122. schema:
  31123. openAPIV3Schema:
  31124. description: |-
  31125. STSSessionToken uses the GetSessionToken API to retrieve an authorization token.
  31126. The authorization token is valid for 12 hours.
  31127. The authorizationToken returned is a base64 encoded string that can be decoded.
  31128. For more information, see GetSessionToken (https://docs.aws.amazon.com/STS/latest/APIReference/API_GetSessionToken.html).
  31129. properties:
  31130. apiVersion:
  31131. description: |-
  31132. APIVersion defines the versioned schema of this representation of an object.
  31133. Servers should convert recognized schemas to the latest internal value, and
  31134. may reject unrecognized values.
  31135. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31136. type: string
  31137. kind:
  31138. description: |-
  31139. Kind is a string value representing the REST resource this object represents.
  31140. Servers may infer this from the endpoint the client submits requests to.
  31141. Cannot be updated.
  31142. In CamelCase.
  31143. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31144. type: string
  31145. metadata:
  31146. type: object
  31147. spec:
  31148. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  31149. properties:
  31150. auth:
  31151. description: Auth defines how to authenticate with AWS
  31152. properties:
  31153. jwt:
  31154. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  31155. properties:
  31156. serviceAccountRef:
  31157. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31158. properties:
  31159. audiences:
  31160. description: |-
  31161. Audience specifies the `aud` claim for the service account token
  31162. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31163. then this audiences will be appended to the list
  31164. items:
  31165. type: string
  31166. type: array
  31167. name:
  31168. description: The name of the ServiceAccount resource being referred to.
  31169. maxLength: 253
  31170. minLength: 1
  31171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31172. type: string
  31173. namespace:
  31174. description: |-
  31175. Namespace of the resource being referred to.
  31176. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31177. maxLength: 63
  31178. minLength: 1
  31179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31180. type: string
  31181. required:
  31182. - name
  31183. type: object
  31184. type: object
  31185. secretRef:
  31186. description: |-
  31187. AWSAuthSecretRef holds secret references for AWS credentials
  31188. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  31189. properties:
  31190. accessKeyIDSecretRef:
  31191. description: The AccessKeyID is used for authentication
  31192. properties:
  31193. key:
  31194. description: |-
  31195. A key in the referenced Secret.
  31196. Some instances of this field may be defaulted, in others it may be required.
  31197. maxLength: 253
  31198. minLength: 1
  31199. pattern: ^[-._a-zA-Z0-9]+$
  31200. type: string
  31201. name:
  31202. description: The name of the Secret resource being referred to.
  31203. maxLength: 253
  31204. minLength: 1
  31205. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31206. type: string
  31207. namespace:
  31208. description: |-
  31209. The namespace of the Secret resource being referred to.
  31210. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31211. maxLength: 63
  31212. minLength: 1
  31213. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31214. type: string
  31215. type: object
  31216. secretAccessKeySecretRef:
  31217. description: The SecretAccessKey is used for authentication
  31218. properties:
  31219. key:
  31220. description: |-
  31221. A key in the referenced Secret.
  31222. Some instances of this field may be defaulted, in others it may be required.
  31223. maxLength: 253
  31224. minLength: 1
  31225. pattern: ^[-._a-zA-Z0-9]+$
  31226. type: string
  31227. name:
  31228. description: The name of the Secret resource being referred to.
  31229. maxLength: 253
  31230. minLength: 1
  31231. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31232. type: string
  31233. namespace:
  31234. description: |-
  31235. The namespace of the Secret resource being referred to.
  31236. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31237. maxLength: 63
  31238. minLength: 1
  31239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31240. type: string
  31241. type: object
  31242. sessionTokenSecretRef:
  31243. description: |-
  31244. The SessionToken used for authentication
  31245. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  31246. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  31247. properties:
  31248. key:
  31249. description: |-
  31250. A key in the referenced Secret.
  31251. Some instances of this field may be defaulted, in others it may be required.
  31252. maxLength: 253
  31253. minLength: 1
  31254. pattern: ^[-._a-zA-Z0-9]+$
  31255. type: string
  31256. name:
  31257. description: The name of the Secret resource being referred to.
  31258. maxLength: 253
  31259. minLength: 1
  31260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31261. type: string
  31262. namespace:
  31263. description: |-
  31264. The namespace of the Secret resource being referred to.
  31265. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31266. maxLength: 63
  31267. minLength: 1
  31268. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31269. type: string
  31270. type: object
  31271. type: object
  31272. type: object
  31273. region:
  31274. description: Region specifies the region to operate in.
  31275. type: string
  31276. requestParameters:
  31277. description: RequestParameters contains parameters that can be passed to the STS service.
  31278. properties:
  31279. serialNumber:
  31280. description: |-
  31281. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  31282. the GetSessionToken call.
  31283. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  31284. (such as arn:aws:iam::123456789012:mfa/user)
  31285. type: string
  31286. sessionDuration:
  31287. format: int32
  31288. type: integer
  31289. tokenCode:
  31290. description: TokenCode is the value provided by the MFA device, if MFA is required.
  31291. type: string
  31292. type: object
  31293. role:
  31294. description: |-
  31295. You can assume a role before making calls to the
  31296. desired AWS service.
  31297. type: string
  31298. required:
  31299. - region
  31300. type: object
  31301. type: object
  31302. served: true
  31303. storage: true
  31304. subresources:
  31305. status: {}
  31306. ---
  31307. apiVersion: apiextensions.k8s.io/v1
  31308. kind: CustomResourceDefinition
  31309. metadata:
  31310. annotations:
  31311. controller-gen.kubebuilder.io/version: v0.19.0
  31312. labels:
  31313. external-secrets.io/component: controller
  31314. name: uuids.generators.external-secrets.io
  31315. spec:
  31316. group: generators.external-secrets.io
  31317. names:
  31318. categories:
  31319. - external-secrets
  31320. - external-secrets-generators
  31321. kind: UUID
  31322. listKind: UUIDList
  31323. plural: uuids
  31324. singular: uuid
  31325. scope: Namespaced
  31326. versions:
  31327. - name: v1alpha1
  31328. schema:
  31329. openAPIV3Schema:
  31330. description: UUID generates a version 1 UUID (e56657e3-764f-11ef-a397-65231a88c216).
  31331. properties:
  31332. apiVersion:
  31333. description: |-
  31334. APIVersion defines the versioned schema of this representation of an object.
  31335. Servers should convert recognized schemas to the latest internal value, and
  31336. may reject unrecognized values.
  31337. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31338. type: string
  31339. kind:
  31340. description: |-
  31341. Kind is a string value representing the REST resource this object represents.
  31342. Servers may infer this from the endpoint the client submits requests to.
  31343. Cannot be updated.
  31344. In CamelCase.
  31345. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31346. type: string
  31347. metadata:
  31348. type: object
  31349. spec:
  31350. description: UUIDSpec controls the behavior of the uuid generator.
  31351. type: object
  31352. type: object
  31353. served: true
  31354. storage: true
  31355. subresources:
  31356. status: {}
  31357. ---
  31358. apiVersion: apiextensions.k8s.io/v1
  31359. kind: CustomResourceDefinition
  31360. metadata:
  31361. annotations:
  31362. controller-gen.kubebuilder.io/version: v0.19.0
  31363. labels:
  31364. external-secrets.io/component: controller
  31365. name: vaultdynamicsecrets.generators.external-secrets.io
  31366. spec:
  31367. group: generators.external-secrets.io
  31368. names:
  31369. categories:
  31370. - external-secrets
  31371. - external-secrets-generators
  31372. kind: VaultDynamicSecret
  31373. listKind: VaultDynamicSecretList
  31374. plural: vaultdynamicsecrets
  31375. singular: vaultdynamicsecret
  31376. scope: Namespaced
  31377. versions:
  31378. - name: v1alpha1
  31379. schema:
  31380. openAPIV3Schema:
  31381. description: VaultDynamicSecret represents a generator that can create dynamic secrets from HashiCorp Vault.
  31382. properties:
  31383. apiVersion:
  31384. description: |-
  31385. APIVersion defines the versioned schema of this representation of an object.
  31386. Servers should convert recognized schemas to the latest internal value, and
  31387. may reject unrecognized values.
  31388. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31389. type: string
  31390. kind:
  31391. description: |-
  31392. Kind is a string value representing the REST resource this object represents.
  31393. Servers may infer this from the endpoint the client submits requests to.
  31394. Cannot be updated.
  31395. In CamelCase.
  31396. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31397. type: string
  31398. metadata:
  31399. type: object
  31400. spec:
  31401. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  31402. properties:
  31403. allowEmptyResponse:
  31404. default: false
  31405. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  31406. type: boolean
  31407. controller:
  31408. description: |-
  31409. Used to select the correct ESO controller (think: ingress.ingressClassName)
  31410. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  31411. type: string
  31412. getParameters:
  31413. additionalProperties:
  31414. items:
  31415. type: string
  31416. type: array
  31417. description: |-
  31418. GetParameters are query-string parameters passed to Vault on GET calls.
  31419. Each key may map to multiple values, matching HTTP query-string semantics.
  31420. Ignored for non-GET methods; use Parameters for write bodies.
  31421. type: object
  31422. method:
  31423. description: Vault API method to use (GET/POST/other)
  31424. type: string
  31425. parameters:
  31426. description: Parameters to pass to Vault write (for non-GET methods)
  31427. x-kubernetes-preserve-unknown-fields: true
  31428. path:
  31429. description: Vault path to obtain the dynamic secret from
  31430. type: string
  31431. provider:
  31432. description: Vault provider common spec
  31433. properties:
  31434. auth:
  31435. description: Auth configures how secret-manager authenticates with the Vault server.
  31436. properties:
  31437. appRole:
  31438. description: |-
  31439. AppRole authenticates with Vault using the App Role auth mechanism,
  31440. with the role and secret stored in a Kubernetes Secret resource.
  31441. properties:
  31442. path:
  31443. default: approle
  31444. description: |-
  31445. Path where the App Role authentication backend is mounted
  31446. in Vault, e.g: "approle"
  31447. type: string
  31448. roleId:
  31449. description: |-
  31450. RoleID configured in the App Role authentication backend when setting
  31451. up the authentication backend in Vault.
  31452. type: string
  31453. roleRef:
  31454. description: |-
  31455. Reference to a key in a Secret that contains the App Role ID used
  31456. to authenticate with Vault.
  31457. The `key` field must be specified and denotes which entry within the Secret
  31458. resource is used as the app role id.
  31459. properties:
  31460. key:
  31461. description: |-
  31462. A key in the referenced Secret.
  31463. Some instances of this field may be defaulted, in others it may be required.
  31464. maxLength: 253
  31465. minLength: 1
  31466. pattern: ^[-._a-zA-Z0-9]+$
  31467. type: string
  31468. name:
  31469. description: The name of the Secret resource being referred to.
  31470. maxLength: 253
  31471. minLength: 1
  31472. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31473. type: string
  31474. namespace:
  31475. description: |-
  31476. The namespace of the Secret resource being referred to.
  31477. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31478. maxLength: 63
  31479. minLength: 1
  31480. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31481. type: string
  31482. type: object
  31483. secretRef:
  31484. description: |-
  31485. Reference to a key in a Secret that contains the App Role secret used
  31486. to authenticate with Vault.
  31487. The `key` field must be specified and denotes which entry within the Secret
  31488. resource is used as the app role secret.
  31489. properties:
  31490. key:
  31491. description: |-
  31492. A key in the referenced Secret.
  31493. Some instances of this field may be defaulted, in others it may be required.
  31494. maxLength: 253
  31495. minLength: 1
  31496. pattern: ^[-._a-zA-Z0-9]+$
  31497. type: string
  31498. name:
  31499. description: The name of the Secret resource being referred to.
  31500. maxLength: 253
  31501. minLength: 1
  31502. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31503. type: string
  31504. namespace:
  31505. description: |-
  31506. The namespace of the Secret resource being referred to.
  31507. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31508. maxLength: 63
  31509. minLength: 1
  31510. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31511. type: string
  31512. type: object
  31513. required:
  31514. - path
  31515. - secretRef
  31516. type: object
  31517. cert:
  31518. description: |-
  31519. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  31520. Cert authentication method
  31521. properties:
  31522. clientCert:
  31523. description: |-
  31524. ClientCert is a certificate to authenticate using the Cert Vault
  31525. authentication method
  31526. properties:
  31527. key:
  31528. description: |-
  31529. A key in the referenced Secret.
  31530. Some instances of this field may be defaulted, in others it may be required.
  31531. maxLength: 253
  31532. minLength: 1
  31533. pattern: ^[-._a-zA-Z0-9]+$
  31534. type: string
  31535. name:
  31536. description: The name of the Secret resource being referred to.
  31537. maxLength: 253
  31538. minLength: 1
  31539. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31540. type: string
  31541. namespace:
  31542. description: |-
  31543. The namespace of the Secret resource being referred to.
  31544. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31545. maxLength: 63
  31546. minLength: 1
  31547. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31548. type: string
  31549. type: object
  31550. path:
  31551. default: cert
  31552. description: |-
  31553. Path where the Certificate authentication backend is mounted
  31554. in Vault, e.g: "cert"
  31555. type: string
  31556. secretRef:
  31557. description: |-
  31558. SecretRef to a key in a Secret resource containing client private key to
  31559. authenticate with Vault using the Cert authentication method
  31560. properties:
  31561. key:
  31562. description: |-
  31563. A key in the referenced Secret.
  31564. Some instances of this field may be defaulted, in others it may be required.
  31565. maxLength: 253
  31566. minLength: 1
  31567. pattern: ^[-._a-zA-Z0-9]+$
  31568. type: string
  31569. name:
  31570. description: The name of the Secret resource being referred to.
  31571. maxLength: 253
  31572. minLength: 1
  31573. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31574. type: string
  31575. namespace:
  31576. description: |-
  31577. The namespace of the Secret resource being referred to.
  31578. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31579. maxLength: 63
  31580. minLength: 1
  31581. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31582. type: string
  31583. type: object
  31584. vaultRole:
  31585. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  31586. type: string
  31587. type: object
  31588. gcp:
  31589. description: |-
  31590. Gcp authenticates with Vault using Google Cloud Platform authentication method
  31591. GCP authentication method
  31592. properties:
  31593. location:
  31594. description: Location optionally defines a location/region for the secret
  31595. type: string
  31596. path:
  31597. default: gcp
  31598. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  31599. type: string
  31600. projectID:
  31601. description: Project ID of the Google Cloud Platform project
  31602. type: string
  31603. role:
  31604. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  31605. type: string
  31606. secretRef:
  31607. description: Specify credentials in a Secret object
  31608. properties:
  31609. secretAccessKeySecretRef:
  31610. description: The SecretAccessKey is used for authentication
  31611. properties:
  31612. key:
  31613. description: |-
  31614. A key in the referenced Secret.
  31615. Some instances of this field may be defaulted, in others it may be required.
  31616. maxLength: 253
  31617. minLength: 1
  31618. pattern: ^[-._a-zA-Z0-9]+$
  31619. type: string
  31620. name:
  31621. description: The name of the Secret resource being referred to.
  31622. maxLength: 253
  31623. minLength: 1
  31624. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31625. type: string
  31626. namespace:
  31627. description: |-
  31628. The namespace of the Secret resource being referred to.
  31629. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31630. maxLength: 63
  31631. minLength: 1
  31632. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31633. type: string
  31634. type: object
  31635. type: object
  31636. serviceAccountRef:
  31637. description: ServiceAccountRef to a service account for impersonation
  31638. properties:
  31639. audiences:
  31640. description: |-
  31641. Audience specifies the `aud` claim for the service account token
  31642. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31643. then this audiences will be appended to the list
  31644. items:
  31645. type: string
  31646. type: array
  31647. name:
  31648. description: The name of the ServiceAccount resource being referred to.
  31649. maxLength: 253
  31650. minLength: 1
  31651. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31652. type: string
  31653. namespace:
  31654. description: |-
  31655. Namespace of the resource being referred to.
  31656. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31657. maxLength: 63
  31658. minLength: 1
  31659. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31660. type: string
  31661. required:
  31662. - name
  31663. type: object
  31664. workloadIdentity:
  31665. description: Specify a service account with Workload Identity
  31666. properties:
  31667. clusterLocation:
  31668. description: |-
  31669. ClusterLocation is the location of the cluster
  31670. If not specified, it fetches information from the metadata server
  31671. type: string
  31672. clusterName:
  31673. description: |-
  31674. ClusterName is the name of the cluster
  31675. If not specified, it fetches information from the metadata server
  31676. type: string
  31677. clusterProjectID:
  31678. description: |-
  31679. ClusterProjectID is the project ID of the cluster
  31680. If not specified, it fetches information from the metadata server
  31681. type: string
  31682. serviceAccountRef:
  31683. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31684. properties:
  31685. audiences:
  31686. description: |-
  31687. Audience specifies the `aud` claim for the service account token
  31688. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31689. then this audiences will be appended to the list
  31690. items:
  31691. type: string
  31692. type: array
  31693. name:
  31694. description: The name of the ServiceAccount resource being referred to.
  31695. maxLength: 253
  31696. minLength: 1
  31697. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31698. type: string
  31699. namespace:
  31700. description: |-
  31701. Namespace of the resource being referred to.
  31702. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31703. maxLength: 63
  31704. minLength: 1
  31705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31706. type: string
  31707. required:
  31708. - name
  31709. type: object
  31710. required:
  31711. - serviceAccountRef
  31712. type: object
  31713. required:
  31714. - role
  31715. type: object
  31716. iam:
  31717. description: |-
  31718. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  31719. AWS IAM authentication method
  31720. properties:
  31721. externalID:
  31722. description: AWS External ID set on assumed IAM roles
  31723. type: string
  31724. jwt:
  31725. description: Specify a service account with IRSA enabled
  31726. properties:
  31727. serviceAccountRef:
  31728. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31729. properties:
  31730. audiences:
  31731. description: |-
  31732. Audience specifies the `aud` claim for the service account token
  31733. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31734. then this audiences will be appended to the list
  31735. items:
  31736. type: string
  31737. type: array
  31738. name:
  31739. description: The name of the ServiceAccount resource being referred to.
  31740. maxLength: 253
  31741. minLength: 1
  31742. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31743. type: string
  31744. namespace:
  31745. description: |-
  31746. Namespace of the resource being referred to.
  31747. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31748. maxLength: 63
  31749. minLength: 1
  31750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31751. type: string
  31752. required:
  31753. - name
  31754. type: object
  31755. type: object
  31756. path:
  31757. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  31758. type: string
  31759. region:
  31760. description: AWS region
  31761. type: string
  31762. role:
  31763. description: This is the AWS role to be assumed before talking to vault
  31764. type: string
  31765. secretRef:
  31766. description: Specify credentials in a Secret object
  31767. properties:
  31768. accessKeyIDSecretRef:
  31769. description: The AccessKeyID is used for authentication
  31770. properties:
  31771. key:
  31772. description: |-
  31773. A key in the referenced Secret.
  31774. Some instances of this field may be defaulted, in others it may be required.
  31775. maxLength: 253
  31776. minLength: 1
  31777. pattern: ^[-._a-zA-Z0-9]+$
  31778. type: string
  31779. name:
  31780. description: The name of the Secret resource being referred to.
  31781. maxLength: 253
  31782. minLength: 1
  31783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31784. type: string
  31785. namespace:
  31786. description: |-
  31787. The namespace of the Secret resource being referred to.
  31788. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31789. maxLength: 63
  31790. minLength: 1
  31791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31792. type: string
  31793. type: object
  31794. secretAccessKeySecretRef:
  31795. description: The SecretAccessKey is used for authentication
  31796. properties:
  31797. key:
  31798. description: |-
  31799. A key in the referenced Secret.
  31800. Some instances of this field may be defaulted, in others it may be required.
  31801. maxLength: 253
  31802. minLength: 1
  31803. pattern: ^[-._a-zA-Z0-9]+$
  31804. type: string
  31805. name:
  31806. description: The name of the Secret resource being referred to.
  31807. maxLength: 253
  31808. minLength: 1
  31809. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31810. type: string
  31811. namespace:
  31812. description: |-
  31813. The namespace of the Secret resource being referred to.
  31814. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31815. maxLength: 63
  31816. minLength: 1
  31817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31818. type: string
  31819. type: object
  31820. sessionTokenSecretRef:
  31821. description: |-
  31822. The SessionToken used for authentication
  31823. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  31824. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  31825. properties:
  31826. key:
  31827. description: |-
  31828. A key in the referenced Secret.
  31829. Some instances of this field may be defaulted, in others it may be required.
  31830. maxLength: 253
  31831. minLength: 1
  31832. pattern: ^[-._a-zA-Z0-9]+$
  31833. type: string
  31834. name:
  31835. description: The name of the Secret resource being referred to.
  31836. maxLength: 253
  31837. minLength: 1
  31838. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31839. type: string
  31840. namespace:
  31841. description: |-
  31842. The namespace of the Secret resource being referred to.
  31843. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31844. maxLength: 63
  31845. minLength: 1
  31846. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31847. type: string
  31848. type: object
  31849. type: object
  31850. vaultAwsIamServerID:
  31851. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  31852. type: string
  31853. vaultRole:
  31854. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  31855. type: string
  31856. required:
  31857. - vaultRole
  31858. type: object
  31859. jwt:
  31860. description: |-
  31861. Jwt authenticates with Vault by passing role and JWT token using the
  31862. JWT/OIDC authentication method
  31863. properties:
  31864. kubernetesServiceAccountToken:
  31865. description: |-
  31866. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  31867. a token for with the `TokenRequest` API.
  31868. properties:
  31869. audiences:
  31870. description: |-
  31871. Optional audiences field that will be used to request a temporary Kubernetes service
  31872. account token for the service account referenced by `serviceAccountRef`.
  31873. Defaults to a single audience `vault` it not specified.
  31874. Deprecated: use serviceAccountRef.Audiences instead
  31875. items:
  31876. type: string
  31877. type: array
  31878. expirationSeconds:
  31879. description: |-
  31880. Optional expiration time in seconds that will be used to request a temporary
  31881. Kubernetes service account token for the service account referenced by
  31882. `serviceAccountRef`.
  31883. Deprecated: this will be removed in the future.
  31884. Defaults to 10 minutes.
  31885. format: int64
  31886. type: integer
  31887. serviceAccountRef:
  31888. description: Service account field containing the name of a kubernetes ServiceAccount.
  31889. properties:
  31890. audiences:
  31891. description: |-
  31892. Audience specifies the `aud` claim for the service account token
  31893. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31894. then this audiences will be appended to the list
  31895. items:
  31896. type: string
  31897. type: array
  31898. name:
  31899. description: The name of the ServiceAccount resource being referred to.
  31900. maxLength: 253
  31901. minLength: 1
  31902. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31903. type: string
  31904. namespace:
  31905. description: |-
  31906. Namespace of the resource being referred to.
  31907. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31908. maxLength: 63
  31909. minLength: 1
  31910. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31911. type: string
  31912. required:
  31913. - name
  31914. type: object
  31915. required:
  31916. - serviceAccountRef
  31917. type: object
  31918. path:
  31919. default: jwt
  31920. description: |-
  31921. Path where the JWT authentication backend is mounted
  31922. in Vault, e.g: "jwt"
  31923. type: string
  31924. role:
  31925. description: |-
  31926. Role is a JWT role to authenticate using the JWT/OIDC Vault
  31927. authentication method
  31928. type: string
  31929. secretRef:
  31930. description: |-
  31931. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  31932. authenticate with Vault using the JWT/OIDC authentication method.
  31933. properties:
  31934. key:
  31935. description: |-
  31936. A key in the referenced Secret.
  31937. Some instances of this field may be defaulted, in others it may be required.
  31938. maxLength: 253
  31939. minLength: 1
  31940. pattern: ^[-._a-zA-Z0-9]+$
  31941. type: string
  31942. name:
  31943. description: The name of the Secret resource being referred to.
  31944. maxLength: 253
  31945. minLength: 1
  31946. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31947. type: string
  31948. namespace:
  31949. description: |-
  31950. The namespace of the Secret resource being referred to.
  31951. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31952. maxLength: 63
  31953. minLength: 1
  31954. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31955. type: string
  31956. type: object
  31957. required:
  31958. - path
  31959. type: object
  31960. kubernetes:
  31961. description: |-
  31962. Kubernetes authenticates with Vault by passing the ServiceAccount
  31963. token stored in the named Secret resource to the Vault server.
  31964. properties:
  31965. mountPath:
  31966. default: kubernetes
  31967. description: |-
  31968. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  31969. "kubernetes"
  31970. type: string
  31971. role:
  31972. description: |-
  31973. A required field containing the Vault Role to assume. A Role binds a
  31974. Kubernetes ServiceAccount with a set of Vault policies.
  31975. type: string
  31976. secretRef:
  31977. description: |-
  31978. Optional secret field containing a Kubernetes ServiceAccount JWT used
  31979. for authenticating with Vault. If a name is specified without a key,
  31980. `token` is the default. If one is not specified, the one bound to
  31981. the controller will be used.
  31982. properties:
  31983. key:
  31984. description: |-
  31985. A key in the referenced Secret.
  31986. Some instances of this field may be defaulted, in others it may be required.
  31987. maxLength: 253
  31988. minLength: 1
  31989. pattern: ^[-._a-zA-Z0-9]+$
  31990. type: string
  31991. name:
  31992. description: The name of the Secret resource being referred to.
  31993. maxLength: 253
  31994. minLength: 1
  31995. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31996. type: string
  31997. namespace:
  31998. description: |-
  31999. The namespace of the Secret resource being referred to.
  32000. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32001. maxLength: 63
  32002. minLength: 1
  32003. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32004. type: string
  32005. type: object
  32006. serviceAccountRef:
  32007. description: |-
  32008. Optional service account field containing the name of a kubernetes ServiceAccount.
  32009. If the service account is specified, the service account secret token JWT will be used
  32010. for authenticating with Vault. If the service account selector is not supplied,
  32011. the secretRef will be used instead.
  32012. properties:
  32013. audiences:
  32014. description: |-
  32015. Audience specifies the `aud` claim for the service account token
  32016. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  32017. then this audiences will be appended to the list
  32018. items:
  32019. type: string
  32020. type: array
  32021. name:
  32022. description: The name of the ServiceAccount resource being referred to.
  32023. maxLength: 253
  32024. minLength: 1
  32025. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32026. type: string
  32027. namespace:
  32028. description: |-
  32029. Namespace of the resource being referred to.
  32030. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32031. maxLength: 63
  32032. minLength: 1
  32033. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32034. type: string
  32035. required:
  32036. - name
  32037. type: object
  32038. required:
  32039. - mountPath
  32040. - role
  32041. type: object
  32042. ldap:
  32043. description: |-
  32044. Ldap authenticates with Vault by passing username/password pair using
  32045. the LDAP authentication method
  32046. properties:
  32047. path:
  32048. default: ldap
  32049. description: |-
  32050. Path where the LDAP authentication backend is mounted
  32051. in Vault, e.g: "ldap"
  32052. type: string
  32053. secretRef:
  32054. description: |-
  32055. SecretRef to a key in a Secret resource containing password for the LDAP
  32056. user used to authenticate with Vault using the LDAP authentication
  32057. method
  32058. properties:
  32059. key:
  32060. description: |-
  32061. A key in the referenced Secret.
  32062. Some instances of this field may be defaulted, in others it may be required.
  32063. maxLength: 253
  32064. minLength: 1
  32065. pattern: ^[-._a-zA-Z0-9]+$
  32066. type: string
  32067. name:
  32068. description: The name of the Secret resource being referred to.
  32069. maxLength: 253
  32070. minLength: 1
  32071. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32072. type: string
  32073. namespace:
  32074. description: |-
  32075. The namespace of the Secret resource being referred to.
  32076. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32077. maxLength: 63
  32078. minLength: 1
  32079. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32080. type: string
  32081. type: object
  32082. username:
  32083. description: |-
  32084. Username is an LDAP username used to authenticate using the LDAP Vault
  32085. authentication method
  32086. type: string
  32087. required:
  32088. - path
  32089. - username
  32090. type: object
  32091. namespace:
  32092. description: |-
  32093. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  32094. Namespaces is a set of features within Vault Enterprise that allows
  32095. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  32096. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  32097. This will default to Vault.Namespace field if set, or empty otherwise
  32098. type: string
  32099. tokenSecretRef:
  32100. description: TokenSecretRef authenticates with Vault by presenting a token.
  32101. properties:
  32102. key:
  32103. description: |-
  32104. A key in the referenced Secret.
  32105. Some instances of this field may be defaulted, in others it may be required.
  32106. maxLength: 253
  32107. minLength: 1
  32108. pattern: ^[-._a-zA-Z0-9]+$
  32109. type: string
  32110. name:
  32111. description: The name of the Secret resource being referred to.
  32112. maxLength: 253
  32113. minLength: 1
  32114. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32115. type: string
  32116. namespace:
  32117. description: |-
  32118. The namespace of the Secret resource being referred to.
  32119. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32120. maxLength: 63
  32121. minLength: 1
  32122. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32123. type: string
  32124. type: object
  32125. userPass:
  32126. description: UserPass authenticates with Vault by passing username/password pair
  32127. properties:
  32128. path:
  32129. default: userpass
  32130. description: |-
  32131. Path where the UserPassword authentication backend is mounted
  32132. in Vault, e.g: "userpass"
  32133. type: string
  32134. secretRef:
  32135. description: |-
  32136. SecretRef to a key in a Secret resource containing password for the
  32137. user used to authenticate with Vault using the UserPass authentication
  32138. method
  32139. properties:
  32140. key:
  32141. description: |-
  32142. A key in the referenced Secret.
  32143. Some instances of this field may be defaulted, in others it may be required.
  32144. maxLength: 253
  32145. minLength: 1
  32146. pattern: ^[-._a-zA-Z0-9]+$
  32147. type: string
  32148. name:
  32149. description: The name of the Secret resource being referred to.
  32150. maxLength: 253
  32151. minLength: 1
  32152. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32153. type: string
  32154. namespace:
  32155. description: |-
  32156. The namespace of the Secret resource being referred to.
  32157. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32158. maxLength: 63
  32159. minLength: 1
  32160. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32161. type: string
  32162. type: object
  32163. username:
  32164. description: |-
  32165. Username is a username used to authenticate using the UserPass Vault
  32166. authentication method
  32167. type: string
  32168. required:
  32169. - path
  32170. - username
  32171. type: object
  32172. type: object
  32173. caBundle:
  32174. description: |-
  32175. PEM encoded CA bundle used to validate Vault server certificate. Only used
  32176. if the Server URL is using HTTPS protocol. This parameter is ignored for
  32177. plain HTTP protocol connection. If not set the system root certificates
  32178. are used to validate the TLS connection.
  32179. format: byte
  32180. type: string
  32181. caProvider:
  32182. description: The provider for the CA bundle to use to validate Vault server certificate.
  32183. properties:
  32184. key:
  32185. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  32186. maxLength: 253
  32187. minLength: 1
  32188. pattern: ^[-._a-zA-Z0-9]+$
  32189. type: string
  32190. name:
  32191. description: The name of the object located at the provider type.
  32192. maxLength: 253
  32193. minLength: 1
  32194. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32195. type: string
  32196. namespace:
  32197. description: |-
  32198. The namespace the Provider type is in.
  32199. Can only be defined when used in a ClusterSecretStore.
  32200. maxLength: 63
  32201. minLength: 1
  32202. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32203. type: string
  32204. type:
  32205. description: The type of provider to use such as "Secret", or "ConfigMap".
  32206. enum:
  32207. - Secret
  32208. - ConfigMap
  32209. type: string
  32210. required:
  32211. - name
  32212. - type
  32213. type: object
  32214. checkAndSet:
  32215. description: |-
  32216. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  32217. Only applies to Vault KV v2 stores. When enabled, write operations must include
  32218. the current version of the secret to prevent unintentional overwrites.
  32219. properties:
  32220. required:
  32221. description: |-
  32222. Required when true, all write operations must include a check-and-set parameter.
  32223. This helps prevent unintentional overwrites of secrets.
  32224. type: boolean
  32225. type: object
  32226. forwardInconsistent:
  32227. description: |-
  32228. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  32229. leader instead of simply retrying within a loop. This can increase performance if
  32230. the option is enabled serverside.
  32231. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  32232. type: boolean
  32233. headers:
  32234. additionalProperties:
  32235. type: string
  32236. description: Headers to be added in Vault request
  32237. type: object
  32238. namespace:
  32239. description: |-
  32240. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  32241. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  32242. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  32243. type: string
  32244. path:
  32245. description: |-
  32246. Path is the mount path of the Vault KV backend endpoint, e.g:
  32247. "secret". The v2 KV secret engine version specific "/data" path suffix
  32248. for fetching secrets from Vault is optional and will be appended
  32249. if not present in specified path.
  32250. type: string
  32251. readYourWrites:
  32252. description: |-
  32253. ReadYourWrites ensures isolated read-after-write semantics by
  32254. providing discovered cluster replication states in each request.
  32255. More information about eventual consistency in Vault can be found here
  32256. https://www.vaultproject.io/docs/enterprise/consistency
  32257. type: boolean
  32258. server:
  32259. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  32260. type: string
  32261. tls:
  32262. description: |-
  32263. The configuration used for client side related TLS communication, when the Vault server
  32264. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  32265. This parameter is ignored for plain HTTP protocol connection.
  32266. It's worth noting this configuration is different from the "TLS certificates auth method",
  32267. which is available under the `auth.cert` section.
  32268. properties:
  32269. certSecretRef:
  32270. description: |-
  32271. CertSecretRef is a certificate added to the transport layer
  32272. when communicating with the Vault server.
  32273. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  32274. properties:
  32275. key:
  32276. description: |-
  32277. A key in the referenced Secret.
  32278. Some instances of this field may be defaulted, in others it may be required.
  32279. maxLength: 253
  32280. minLength: 1
  32281. pattern: ^[-._a-zA-Z0-9]+$
  32282. type: string
  32283. name:
  32284. description: The name of the Secret resource being referred to.
  32285. maxLength: 253
  32286. minLength: 1
  32287. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32288. type: string
  32289. namespace:
  32290. description: |-
  32291. The namespace of the Secret resource being referred to.
  32292. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32293. maxLength: 63
  32294. minLength: 1
  32295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32296. type: string
  32297. type: object
  32298. keySecretRef:
  32299. description: |-
  32300. KeySecretRef to a key in a Secret resource containing client private key
  32301. added to the transport layer when communicating with the Vault server.
  32302. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  32303. properties:
  32304. key:
  32305. description: |-
  32306. A key in the referenced Secret.
  32307. Some instances of this field may be defaulted, in others it may be required.
  32308. maxLength: 253
  32309. minLength: 1
  32310. pattern: ^[-._a-zA-Z0-9]+$
  32311. type: string
  32312. name:
  32313. description: The name of the Secret resource being referred to.
  32314. maxLength: 253
  32315. minLength: 1
  32316. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32317. type: string
  32318. namespace:
  32319. description: |-
  32320. The namespace of the Secret resource being referred to.
  32321. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32322. maxLength: 63
  32323. minLength: 1
  32324. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32325. type: string
  32326. type: object
  32327. type: object
  32328. version:
  32329. default: v2
  32330. description: |-
  32331. Version is the Vault KV secret engine version. This can be either "v1" or
  32332. "v2". Version defaults to "v2".
  32333. enum:
  32334. - v1
  32335. - v2
  32336. type: string
  32337. required:
  32338. - server
  32339. type: object
  32340. resultType:
  32341. default: Data
  32342. description: |-
  32343. Result type defines which data is returned from the generator.
  32344. By default, it is the "data" section of the Vault API response.
  32345. When using e.g. /auth/token/create the "data" section is empty but
  32346. the "auth" section contains the generated token.
  32347. Please refer to the vault docs regarding the result data structure.
  32348. Additionally, accessing the raw response is possibly by using "Raw" result type.
  32349. enum:
  32350. - Data
  32351. - Auth
  32352. - Raw
  32353. type: string
  32354. retrySettings:
  32355. description: Used to configure http retries if failed
  32356. properties:
  32357. maxRetries:
  32358. format: int32
  32359. type: integer
  32360. retryInterval:
  32361. type: string
  32362. type: object
  32363. required:
  32364. - path
  32365. - provider
  32366. type: object
  32367. type: object
  32368. served: true
  32369. storage: true
  32370. subresources:
  32371. status: {}
  32372. ---
  32373. apiVersion: apiextensions.k8s.io/v1
  32374. kind: CustomResourceDefinition
  32375. metadata:
  32376. annotations:
  32377. controller-gen.kubebuilder.io/version: v0.19.0
  32378. labels:
  32379. external-secrets.io/component: controller
  32380. name: webhooks.generators.external-secrets.io
  32381. spec:
  32382. group: generators.external-secrets.io
  32383. names:
  32384. categories:
  32385. - external-secrets
  32386. - external-secrets-generators
  32387. kind: Webhook
  32388. listKind: WebhookList
  32389. plural: webhooks
  32390. singular: webhook
  32391. scope: Namespaced
  32392. versions:
  32393. - name: v1alpha1
  32394. schema:
  32395. openAPIV3Schema:
  32396. description: |-
  32397. Webhook connects to a third party API server to handle the secrets generation
  32398. configuration parameters in spec.
  32399. You can specify the server, the token, and additional body parameters.
  32400. See documentation for the full API specification for requests and responses.
  32401. properties:
  32402. apiVersion:
  32403. description: |-
  32404. APIVersion defines the versioned schema of this representation of an object.
  32405. Servers should convert recognized schemas to the latest internal value, and
  32406. may reject unrecognized values.
  32407. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  32408. type: string
  32409. kind:
  32410. description: |-
  32411. Kind is a string value representing the REST resource this object represents.
  32412. Servers may infer this from the endpoint the client submits requests to.
  32413. Cannot be updated.
  32414. In CamelCase.
  32415. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  32416. type: string
  32417. metadata:
  32418. type: object
  32419. spec:
  32420. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  32421. properties:
  32422. auth:
  32423. description: Auth specifies a authorization protocol. Only one protocol may be set.
  32424. maxProperties: 1
  32425. minProperties: 1
  32426. properties:
  32427. ntlm:
  32428. description: NTLMProtocol configures the store to use NTLM for auth
  32429. properties:
  32430. passwordSecret:
  32431. description: |-
  32432. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  32433. In some instances, `key` is a required field.
  32434. properties:
  32435. key:
  32436. description: |-
  32437. A key in the referenced Secret.
  32438. Some instances of this field may be defaulted, in others it may be required.
  32439. maxLength: 253
  32440. minLength: 1
  32441. pattern: ^[-._a-zA-Z0-9]+$
  32442. type: string
  32443. name:
  32444. description: The name of the Secret resource being referred to.
  32445. maxLength: 253
  32446. minLength: 1
  32447. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32448. type: string
  32449. namespace:
  32450. description: |-
  32451. The namespace of the Secret resource being referred to.
  32452. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32453. maxLength: 63
  32454. minLength: 1
  32455. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32456. type: string
  32457. type: object
  32458. usernameSecret:
  32459. description: |-
  32460. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  32461. In some instances, `key` is a required field.
  32462. properties:
  32463. key:
  32464. description: |-
  32465. A key in the referenced Secret.
  32466. Some instances of this field may be defaulted, in others it may be required.
  32467. maxLength: 253
  32468. minLength: 1
  32469. pattern: ^[-._a-zA-Z0-9]+$
  32470. type: string
  32471. name:
  32472. description: The name of the Secret resource being referred to.
  32473. maxLength: 253
  32474. minLength: 1
  32475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32476. type: string
  32477. namespace:
  32478. description: |-
  32479. The namespace of the Secret resource being referred to.
  32480. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32481. maxLength: 63
  32482. minLength: 1
  32483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32484. type: string
  32485. type: object
  32486. required:
  32487. - passwordSecret
  32488. - usernameSecret
  32489. type: object
  32490. type: object
  32491. body:
  32492. description: Body
  32493. type: string
  32494. caBundle:
  32495. description: |-
  32496. PEM encoded CA bundle used to validate webhook server certificate. Only used
  32497. if the Server URL is using HTTPS protocol. This parameter is ignored for
  32498. plain HTTP protocol connection. If not set the system root certificates
  32499. are used to validate the TLS connection.
  32500. format: byte
  32501. type: string
  32502. caProvider:
  32503. description: The provider for the CA bundle to use to validate webhook server certificate.
  32504. properties:
  32505. key:
  32506. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  32507. maxLength: 253
  32508. minLength: 1
  32509. pattern: ^[-._a-zA-Z0-9]+$
  32510. type: string
  32511. name:
  32512. description: The name of the object located at the provider type.
  32513. maxLength: 253
  32514. minLength: 1
  32515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32516. type: string
  32517. namespace:
  32518. description: The namespace the Provider type is in.
  32519. maxLength: 63
  32520. minLength: 1
  32521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32522. type: string
  32523. type:
  32524. description: The type of provider to use such as "Secret", or "ConfigMap".
  32525. enum:
  32526. - Secret
  32527. - ConfigMap
  32528. type: string
  32529. required:
  32530. - name
  32531. - type
  32532. type: object
  32533. headers:
  32534. additionalProperties:
  32535. type: string
  32536. description: Headers
  32537. type: object
  32538. method:
  32539. description: Webhook Method
  32540. type: string
  32541. result:
  32542. description: Result formatting
  32543. properties:
  32544. jsonPath:
  32545. description: Json path of return value
  32546. type: string
  32547. type: object
  32548. secrets:
  32549. description: |-
  32550. Secrets to fill in templates
  32551. These secrets will be passed to the templating function as key value pairs under the given name
  32552. items:
  32553. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  32554. properties:
  32555. name:
  32556. description: Name of this secret in templates
  32557. type: string
  32558. secretRef:
  32559. description: Secret ref to fill in credentials
  32560. properties:
  32561. key:
  32562. description: The key where the token is found.
  32563. maxLength: 253
  32564. minLength: 1
  32565. pattern: ^[-._a-zA-Z0-9]+$
  32566. type: string
  32567. name:
  32568. description: The name of the Secret resource being referred to.
  32569. maxLength: 253
  32570. minLength: 1
  32571. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32572. type: string
  32573. type: object
  32574. required:
  32575. - name
  32576. - secretRef
  32577. type: object
  32578. type: array
  32579. timeout:
  32580. description: Timeout
  32581. type: string
  32582. url:
  32583. description: Webhook url to call
  32584. type: string
  32585. required:
  32586. - result
  32587. - url
  32588. type: object
  32589. type: object
  32590. served: true
  32591. storage: true
  32592. subresources:
  32593. status: {}