bundle.yaml 1.9 MB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117211821192120212121222123212421252126212721282129213021312132213321342135213621372138213921402141214221432144214521462147214821492150215121522153215421552156215721582159216021612162216321642165216621672168216921702171217221732174217521762177217821792180218121822183218421852186218721882189219021912192219321942195219621972198219922002201220222032204220522062207220822092210221122122213221422152216221722182219222022212222222322242225222622272228222922302231223222332234223522362237223822392240224122422243224422452246224722482249225022512252225322542255225622572258225922602261226222632264226522662267226822692270227122722273227422752276227722782279228022812282228322842285228622872288228922902291229222932294229522962297229822992300230123022303230423052306230723082309231023112312231323142315231623172318231923202321232223232324232523262327232823292330233123322333233423352336233723382339234023412342234323442345234623472348234923502351235223532354235523562357235823592360236123622363236423652366236723682369237023712372237323742375237623772378237923802381238223832384238523862387238823892390239123922393239423952396239723982399240024012402240324042405240624072408240924102411241224132414241524162417241824192420242124222423242424252426242724282429243024312432243324342435243624372438243924402441244224432444244524462447244824492450245124522453245424552456245724582459246024612462246324642465246624672468246924702471247224732474247524762477247824792480248124822483248424852486248724882489249024912492249324942495249624972498249925002501250225032504250525062507250825092510251125122513251425152516251725182519252025212522252325242525252625272528252925302531253225332534253525362537253825392540254125422543254425452546254725482549255025512552255325542555255625572558255925602561256225632564256525662567256825692570257125722573257425752576257725782579258025812582258325842585258625872588258925902591259225932594259525962597259825992600260126022603260426052606260726082609261026112612261326142615261626172618261926202621262226232624262526262627262826292630263126322633263426352636263726382639264026412642264326442645264626472648264926502651265226532654265526562657265826592660266126622663266426652666266726682669267026712672267326742675267626772678267926802681268226832684268526862687268826892690269126922693269426952696269726982699270027012702270327042705270627072708270927102711271227132714271527162717271827192720272127222723272427252726272727282729273027312732273327342735273627372738273927402741274227432744274527462747274827492750275127522753275427552756275727582759276027612762276327642765276627672768276927702771277227732774277527762777277827792780278127822783278427852786278727882789279027912792279327942795279627972798279928002801280228032804280528062807280828092810281128122813281428152816281728182819282028212822282328242825282628272828282928302831283228332834283528362837283828392840284128422843284428452846284728482849285028512852285328542855285628572858285928602861286228632864286528662867286828692870287128722873287428752876287728782879288028812882288328842885288628872888288928902891289228932894289528962897289828992900290129022903290429052906290729082909291029112912291329142915291629172918291929202921292229232924292529262927292829292930293129322933293429352936293729382939294029412942294329442945294629472948294929502951295229532954295529562957295829592960296129622963296429652966296729682969297029712972297329742975297629772978297929802981298229832984298529862987298829892990299129922993299429952996299729982999300030013002300330043005300630073008300930103011301230133014301530163017301830193020302130223023302430253026302730283029303030313032303330343035303630373038303930403041304230433044304530463047304830493050305130523053305430553056305730583059306030613062306330643065306630673068306930703071307230733074307530763077307830793080308130823083308430853086308730883089309030913092309330943095309630973098309931003101310231033104310531063107310831093110311131123113311431153116311731183119312031213122312331243125312631273128312931303131313231333134313531363137313831393140314131423143314431453146314731483149315031513152315331543155315631573158315931603161316231633164316531663167316831693170317131723173317431753176317731783179318031813182318331843185318631873188318931903191319231933194319531963197319831993200320132023203320432053206320732083209321032113212321332143215321632173218321932203221322232233224322532263227322832293230323132323233323432353236323732383239324032413242324332443245324632473248324932503251325232533254325532563257325832593260326132623263326432653266326732683269327032713272327332743275327632773278327932803281328232833284328532863287328832893290329132923293329432953296329732983299330033013302330333043305330633073308330933103311331233133314331533163317331833193320332133223323332433253326332733283329333033313332333333343335333633373338333933403341334233433344334533463347334833493350335133523353335433553356335733583359336033613362336333643365336633673368336933703371337233733374337533763377337833793380338133823383338433853386338733883389339033913392339333943395339633973398339934003401340234033404340534063407340834093410341134123413341434153416341734183419342034213422342334243425342634273428342934303431343234333434343534363437343834393440344134423443344434453446344734483449345034513452345334543455345634573458345934603461346234633464346534663467346834693470347134723473347434753476347734783479348034813482348334843485348634873488348934903491349234933494349534963497349834993500350135023503350435053506350735083509351035113512351335143515351635173518351935203521352235233524352535263527352835293530353135323533353435353536353735383539354035413542354335443545354635473548354935503551355235533554355535563557355835593560356135623563356435653566356735683569357035713572357335743575357635773578357935803581358235833584358535863587358835893590359135923593359435953596359735983599360036013602360336043605360636073608360936103611361236133614361536163617361836193620362136223623362436253626362736283629363036313632363336343635363636373638363936403641364236433644364536463647364836493650365136523653365436553656365736583659366036613662366336643665366636673668366936703671367236733674367536763677367836793680368136823683368436853686368736883689369036913692369336943695369636973698369937003701370237033704370537063707370837093710371137123713371437153716371737183719372037213722372337243725372637273728372937303731373237333734373537363737373837393740374137423743374437453746374737483749375037513752375337543755375637573758375937603761376237633764376537663767376837693770377137723773377437753776377737783779378037813782378337843785378637873788378937903791379237933794379537963797379837993800380138023803380438053806380738083809381038113812381338143815381638173818381938203821382238233824382538263827382838293830383138323833383438353836383738383839384038413842384338443845384638473848384938503851385238533854385538563857385838593860386138623863386438653866386738683869387038713872387338743875387638773878387938803881388238833884388538863887388838893890389138923893389438953896389738983899390039013902390339043905390639073908390939103911391239133914391539163917391839193920392139223923392439253926392739283929393039313932393339343935393639373938393939403941394239433944394539463947394839493950395139523953395439553956395739583959396039613962396339643965396639673968396939703971397239733974397539763977397839793980398139823983398439853986398739883989399039913992399339943995399639973998399940004001400240034004400540064007400840094010401140124013401440154016401740184019402040214022402340244025402640274028402940304031403240334034403540364037403840394040404140424043404440454046404740484049405040514052405340544055405640574058405940604061406240634064406540664067406840694070407140724073407440754076407740784079408040814082408340844085408640874088408940904091409240934094409540964097409840994100410141024103410441054106410741084109411041114112411341144115411641174118411941204121412241234124412541264127412841294130413141324133413441354136413741384139414041414142414341444145414641474148414941504151415241534154415541564157415841594160416141624163416441654166416741684169417041714172417341744175417641774178417941804181418241834184418541864187418841894190419141924193419441954196419741984199420042014202420342044205420642074208420942104211421242134214421542164217421842194220422142224223422442254226422742284229423042314232423342344235423642374238423942404241424242434244424542464247424842494250425142524253425442554256425742584259426042614262426342644265426642674268426942704271427242734274427542764277427842794280428142824283428442854286428742884289429042914292429342944295429642974298429943004301430243034304430543064307430843094310431143124313431443154316431743184319432043214322432343244325432643274328432943304331433243334334433543364337433843394340434143424343434443454346434743484349435043514352435343544355435643574358435943604361436243634364436543664367436843694370437143724373437443754376437743784379438043814382438343844385438643874388438943904391439243934394439543964397439843994400440144024403440444054406440744084409441044114412441344144415441644174418441944204421442244234424442544264427442844294430443144324433443444354436443744384439444044414442444344444445444644474448444944504451445244534454445544564457445844594460446144624463446444654466446744684469447044714472447344744475447644774478447944804481448244834484448544864487448844894490449144924493449444954496449744984499450045014502450345044505450645074508450945104511451245134514451545164517451845194520452145224523452445254526452745284529453045314532453345344535453645374538453945404541454245434544454545464547454845494550455145524553455445554556455745584559456045614562456345644565456645674568456945704571457245734574457545764577457845794580458145824583458445854586458745884589459045914592459345944595459645974598459946004601460246034604460546064607460846094610461146124613461446154616461746184619462046214622462346244625462646274628462946304631463246334634463546364637463846394640464146424643464446454646464746484649465046514652465346544655465646574658465946604661466246634664466546664667466846694670467146724673467446754676467746784679468046814682468346844685468646874688468946904691469246934694469546964697469846994700470147024703470447054706470747084709471047114712471347144715471647174718471947204721472247234724472547264727472847294730473147324733473447354736473747384739474047414742474347444745474647474748474947504751475247534754475547564757475847594760476147624763476447654766476747684769477047714772477347744775477647774778477947804781478247834784478547864787478847894790479147924793479447954796479747984799480048014802480348044805480648074808480948104811481248134814481548164817481848194820482148224823482448254826482748284829483048314832483348344835483648374838483948404841484248434844484548464847484848494850485148524853485448554856485748584859486048614862486348644865486648674868486948704871487248734874487548764877487848794880488148824883488448854886488748884889489048914892489348944895489648974898489949004901490249034904490549064907490849094910491149124913491449154916491749184919492049214922492349244925492649274928492949304931493249334934493549364937493849394940494149424943494449454946494749484949495049514952495349544955495649574958495949604961496249634964496549664967496849694970497149724973497449754976497749784979498049814982498349844985498649874988498949904991499249934994499549964997499849995000500150025003500450055006500750085009501050115012501350145015501650175018501950205021502250235024502550265027502850295030503150325033503450355036503750385039504050415042504350445045504650475048504950505051505250535054505550565057505850595060506150625063506450655066506750685069507050715072507350745075507650775078507950805081508250835084508550865087508850895090509150925093509450955096509750985099510051015102510351045105510651075108510951105111511251135114511551165117511851195120512151225123512451255126512751285129513051315132513351345135513651375138513951405141514251435144514551465147514851495150515151525153515451555156515751585159516051615162516351645165516651675168516951705171517251735174517551765177517851795180518151825183518451855186518751885189519051915192519351945195519651975198519952005201520252035204520552065207520852095210521152125213521452155216521752185219522052215222522352245225522652275228522952305231523252335234523552365237523852395240524152425243524452455246524752485249525052515252525352545255525652575258525952605261526252635264526552665267526852695270527152725273527452755276527752785279528052815282528352845285528652875288528952905291529252935294529552965297529852995300530153025303530453055306530753085309531053115312531353145315531653175318531953205321532253235324532553265327532853295330533153325333533453355336533753385339534053415342534353445345534653475348534953505351535253535354535553565357535853595360536153625363536453655366536753685369537053715372537353745375537653775378537953805381538253835384538553865387538853895390539153925393539453955396539753985399540054015402540354045405540654075408540954105411541254135414541554165417541854195420542154225423542454255426542754285429543054315432543354345435543654375438543954405441544254435444544554465447544854495450545154525453545454555456545754585459546054615462546354645465546654675468546954705471547254735474547554765477547854795480548154825483548454855486548754885489549054915492549354945495549654975498549955005501550255035504550555065507550855095510551155125513551455155516551755185519552055215522552355245525552655275528552955305531553255335534553555365537553855395540554155425543554455455546554755485549555055515552555355545555555655575558555955605561556255635564556555665567556855695570557155725573557455755576557755785579558055815582558355845585558655875588558955905591559255935594559555965597559855995600560156025603560456055606560756085609561056115612561356145615561656175618561956205621562256235624562556265627562856295630563156325633563456355636563756385639564056415642564356445645564656475648564956505651565256535654565556565657565856595660566156625663566456655666566756685669567056715672567356745675567656775678567956805681568256835684568556865687568856895690569156925693569456955696569756985699570057015702570357045705570657075708570957105711571257135714571557165717571857195720572157225723572457255726572757285729573057315732573357345735573657375738573957405741574257435744574557465747574857495750575157525753575457555756575757585759576057615762576357645765576657675768576957705771577257735774577557765777577857795780578157825783578457855786578757885789579057915792579357945795579657975798579958005801580258035804580558065807580858095810581158125813581458155816581758185819582058215822582358245825582658275828582958305831583258335834583558365837583858395840584158425843584458455846584758485849585058515852585358545855585658575858585958605861586258635864586558665867586858695870587158725873587458755876587758785879588058815882588358845885588658875888588958905891589258935894589558965897589858995900590159025903590459055906590759085909591059115912591359145915591659175918591959205921592259235924592559265927592859295930593159325933593459355936593759385939594059415942594359445945594659475948594959505951595259535954595559565957595859595960596159625963596459655966596759685969597059715972597359745975597659775978597959805981598259835984598559865987598859895990599159925993599459955996599759985999600060016002600360046005600660076008600960106011601260136014601560166017601860196020602160226023602460256026602760286029603060316032603360346035603660376038603960406041604260436044604560466047604860496050605160526053605460556056605760586059606060616062606360646065606660676068606960706071607260736074607560766077607860796080608160826083608460856086608760886089609060916092609360946095609660976098609961006101610261036104610561066107610861096110611161126113611461156116611761186119612061216122612361246125612661276128612961306131613261336134613561366137613861396140614161426143614461456146614761486149615061516152615361546155615661576158615961606161616261636164616561666167616861696170617161726173617461756176617761786179618061816182618361846185618661876188618961906191619261936194619561966197619861996200620162026203620462056206620762086209621062116212621362146215621662176218621962206221622262236224622562266227622862296230623162326233623462356236623762386239624062416242624362446245624662476248624962506251625262536254625562566257625862596260626162626263626462656266626762686269627062716272627362746275627662776278627962806281628262836284628562866287628862896290629162926293629462956296629762986299630063016302630363046305630663076308630963106311631263136314631563166317631863196320632163226323632463256326632763286329633063316332633363346335633663376338633963406341634263436344634563466347634863496350635163526353635463556356635763586359636063616362636363646365636663676368636963706371637263736374637563766377637863796380638163826383638463856386638763886389639063916392639363946395639663976398639964006401640264036404640564066407640864096410641164126413641464156416641764186419642064216422642364246425642664276428642964306431643264336434643564366437643864396440644164426443644464456446644764486449645064516452645364546455645664576458645964606461646264636464646564666467646864696470647164726473647464756476647764786479648064816482648364846485648664876488648964906491649264936494649564966497649864996500650165026503650465056506650765086509651065116512651365146515651665176518651965206521652265236524652565266527652865296530653165326533653465356536653765386539654065416542654365446545654665476548654965506551655265536554655565566557655865596560656165626563656465656566656765686569657065716572657365746575657665776578657965806581658265836584658565866587658865896590659165926593659465956596659765986599660066016602660366046605660666076608660966106611661266136614661566166617661866196620662166226623662466256626662766286629663066316632663366346635663666376638663966406641664266436644664566466647664866496650665166526653665466556656665766586659666066616662666366646665666666676668666966706671667266736674667566766677667866796680668166826683668466856686668766886689669066916692669366946695669666976698669967006701670267036704670567066707670867096710671167126713671467156716671767186719672067216722672367246725672667276728672967306731673267336734673567366737673867396740674167426743674467456746674767486749675067516752675367546755675667576758675967606761676267636764676567666767676867696770677167726773677467756776677767786779678067816782678367846785678667876788678967906791679267936794679567966797679867996800680168026803680468056806680768086809681068116812681368146815681668176818681968206821682268236824682568266827682868296830683168326833683468356836683768386839684068416842684368446845684668476848684968506851685268536854685568566857685868596860686168626863686468656866686768686869687068716872687368746875687668776878687968806881688268836884688568866887688868896890689168926893689468956896689768986899690069016902690369046905690669076908690969106911691269136914691569166917691869196920692169226923692469256926692769286929693069316932693369346935693669376938693969406941694269436944694569466947694869496950695169526953695469556956695769586959696069616962696369646965696669676968696969706971697269736974697569766977697869796980698169826983698469856986698769886989699069916992699369946995699669976998699970007001700270037004700570067007700870097010701170127013701470157016701770187019702070217022702370247025702670277028702970307031703270337034703570367037703870397040704170427043704470457046704770487049705070517052705370547055705670577058705970607061706270637064706570667067706870697070707170727073707470757076707770787079708070817082708370847085708670877088708970907091709270937094709570967097709870997100710171027103710471057106710771087109711071117112711371147115711671177118711971207121712271237124712571267127712871297130713171327133713471357136713771387139714071417142714371447145714671477148714971507151715271537154715571567157715871597160716171627163716471657166716771687169717071717172717371747175717671777178717971807181718271837184718571867187718871897190719171927193719471957196719771987199720072017202720372047205720672077208720972107211721272137214721572167217721872197220722172227223722472257226722772287229723072317232723372347235723672377238723972407241724272437244724572467247724872497250725172527253725472557256725772587259726072617262726372647265726672677268726972707271727272737274727572767277727872797280728172827283728472857286728772887289729072917292729372947295729672977298729973007301730273037304730573067307730873097310731173127313731473157316731773187319732073217322732373247325732673277328732973307331733273337334733573367337733873397340734173427343734473457346734773487349735073517352735373547355735673577358735973607361736273637364736573667367736873697370737173727373737473757376737773787379738073817382738373847385738673877388738973907391739273937394739573967397739873997400740174027403740474057406740774087409741074117412741374147415741674177418741974207421742274237424742574267427742874297430743174327433743474357436743774387439744074417442744374447445744674477448744974507451745274537454745574567457745874597460746174627463746474657466746774687469747074717472747374747475747674777478747974807481748274837484748574867487748874897490749174927493749474957496749774987499750075017502750375047505750675077508750975107511751275137514751575167517751875197520752175227523752475257526752775287529753075317532753375347535753675377538753975407541754275437544754575467547754875497550755175527553755475557556755775587559756075617562756375647565756675677568756975707571757275737574757575767577757875797580758175827583758475857586758775887589759075917592759375947595759675977598759976007601760276037604760576067607760876097610761176127613761476157616761776187619762076217622762376247625762676277628762976307631763276337634763576367637763876397640764176427643764476457646764776487649765076517652765376547655765676577658765976607661766276637664766576667667766876697670767176727673767476757676767776787679768076817682768376847685768676877688768976907691769276937694769576967697769876997700770177027703770477057706770777087709771077117712771377147715771677177718771977207721772277237724772577267727772877297730773177327733773477357736773777387739774077417742774377447745774677477748774977507751775277537754775577567757775877597760776177627763776477657766776777687769777077717772777377747775777677777778777977807781778277837784778577867787778877897790779177927793779477957796779777987799780078017802780378047805780678077808780978107811781278137814781578167817781878197820782178227823782478257826782778287829783078317832783378347835783678377838783978407841784278437844784578467847784878497850785178527853785478557856785778587859786078617862786378647865786678677868786978707871787278737874787578767877787878797880788178827883788478857886788778887889789078917892789378947895789678977898789979007901790279037904790579067907790879097910791179127913791479157916791779187919792079217922792379247925792679277928792979307931793279337934793579367937793879397940794179427943794479457946794779487949795079517952795379547955795679577958795979607961796279637964796579667967796879697970797179727973797479757976797779787979798079817982798379847985798679877988798979907991799279937994799579967997799879998000800180028003800480058006800780088009801080118012801380148015801680178018801980208021802280238024802580268027802880298030803180328033803480358036803780388039804080418042804380448045804680478048804980508051805280538054805580568057805880598060806180628063806480658066806780688069807080718072807380748075807680778078807980808081808280838084808580868087808880898090809180928093809480958096809780988099810081018102810381048105810681078108810981108111811281138114811581168117811881198120812181228123812481258126812781288129813081318132813381348135813681378138813981408141814281438144814581468147814881498150815181528153815481558156815781588159816081618162816381648165816681678168816981708171817281738174817581768177817881798180818181828183818481858186818781888189819081918192819381948195819681978198819982008201820282038204820582068207820882098210821182128213821482158216821782188219822082218222822382248225822682278228822982308231823282338234823582368237823882398240824182428243824482458246824782488249825082518252825382548255825682578258825982608261826282638264826582668267826882698270827182728273827482758276827782788279828082818282828382848285828682878288828982908291829282938294829582968297829882998300830183028303830483058306830783088309831083118312831383148315831683178318831983208321832283238324832583268327832883298330833183328333833483358336833783388339834083418342834383448345834683478348834983508351835283538354835583568357835883598360836183628363836483658366836783688369837083718372837383748375837683778378837983808381838283838384838583868387838883898390839183928393839483958396839783988399840084018402840384048405840684078408840984108411841284138414841584168417841884198420842184228423842484258426842784288429843084318432843384348435843684378438843984408441844284438444844584468447844884498450845184528453845484558456845784588459846084618462846384648465846684678468846984708471847284738474847584768477847884798480848184828483848484858486848784888489849084918492849384948495849684978498849985008501850285038504850585068507850885098510851185128513851485158516851785188519852085218522852385248525852685278528852985308531853285338534853585368537853885398540854185428543854485458546854785488549855085518552855385548555855685578558855985608561856285638564856585668567856885698570857185728573857485758576857785788579858085818582858385848585858685878588858985908591859285938594859585968597859885998600860186028603860486058606860786088609861086118612861386148615861686178618861986208621862286238624862586268627862886298630863186328633863486358636863786388639864086418642864386448645864686478648864986508651865286538654865586568657865886598660866186628663866486658666866786688669867086718672867386748675867686778678867986808681868286838684868586868687868886898690869186928693869486958696869786988699870087018702870387048705870687078708870987108711871287138714871587168717871887198720872187228723872487258726872787288729873087318732873387348735873687378738873987408741874287438744874587468747874887498750875187528753875487558756875787588759876087618762876387648765876687678768876987708771877287738774877587768777877887798780878187828783878487858786878787888789879087918792879387948795879687978798879988008801880288038804880588068807880888098810881188128813881488158816881788188819882088218822882388248825882688278828882988308831883288338834883588368837883888398840884188428843884488458846884788488849885088518852885388548855885688578858885988608861886288638864886588668867886888698870887188728873887488758876887788788879888088818882888388848885888688878888888988908891889288938894889588968897889888998900890189028903890489058906890789088909891089118912891389148915891689178918891989208921892289238924892589268927892889298930893189328933893489358936893789388939894089418942894389448945894689478948894989508951895289538954895589568957895889598960896189628963896489658966896789688969897089718972897389748975897689778978897989808981898289838984898589868987898889898990899189928993899489958996899789988999900090019002900390049005900690079008900990109011901290139014901590169017901890199020902190229023902490259026902790289029903090319032903390349035903690379038903990409041904290439044904590469047904890499050905190529053905490559056905790589059906090619062906390649065906690679068906990709071907290739074907590769077907890799080908190829083908490859086908790889089909090919092909390949095909690979098909991009101910291039104910591069107910891099110911191129113911491159116911791189119912091219122912391249125912691279128912991309131913291339134913591369137913891399140914191429143914491459146914791489149915091519152915391549155915691579158915991609161916291639164916591669167916891699170917191729173917491759176917791789179918091819182918391849185918691879188918991909191919291939194919591969197919891999200920192029203920492059206920792089209921092119212921392149215921692179218921992209221922292239224922592269227922892299230923192329233923492359236923792389239924092419242924392449245924692479248924992509251925292539254925592569257925892599260926192629263926492659266926792689269927092719272927392749275927692779278927992809281928292839284928592869287928892899290929192929293929492959296929792989299930093019302930393049305930693079308930993109311931293139314931593169317931893199320932193229323932493259326932793289329933093319332933393349335933693379338933993409341934293439344934593469347934893499350935193529353935493559356935793589359936093619362936393649365936693679368936993709371937293739374937593769377937893799380938193829383938493859386938793889389939093919392939393949395939693979398939994009401940294039404940594069407940894099410941194129413941494159416941794189419942094219422942394249425942694279428942994309431943294339434943594369437943894399440944194429443944494459446944794489449945094519452945394549455945694579458945994609461946294639464946594669467946894699470947194729473947494759476947794789479948094819482948394849485948694879488948994909491949294939494949594969497949894999500950195029503950495059506950795089509951095119512951395149515951695179518951995209521952295239524952595269527952895299530953195329533953495359536953795389539954095419542954395449545954695479548954995509551955295539554955595569557955895599560956195629563956495659566956795689569957095719572957395749575957695779578957995809581958295839584958595869587958895899590959195929593959495959596959795989599960096019602960396049605960696079608960996109611961296139614961596169617961896199620962196229623962496259626962796289629963096319632963396349635963696379638963996409641964296439644964596469647964896499650965196529653965496559656965796589659966096619662966396649665966696679668966996709671967296739674967596769677967896799680968196829683968496859686968796889689969096919692969396949695969696979698969997009701970297039704970597069707970897099710971197129713971497159716971797189719972097219722972397249725972697279728972997309731973297339734973597369737973897399740974197429743974497459746974797489749975097519752975397549755975697579758975997609761976297639764976597669767976897699770977197729773977497759776977797789779978097819782978397849785978697879788978997909791979297939794979597969797979897999800980198029803980498059806980798089809981098119812981398149815981698179818981998209821982298239824982598269827982898299830983198329833983498359836983798389839984098419842984398449845984698479848984998509851985298539854985598569857985898599860986198629863986498659866986798689869987098719872987398749875987698779878987998809881988298839884988598869887988898899890989198929893989498959896989798989899990099019902990399049905990699079908990999109911991299139914991599169917991899199920992199229923992499259926992799289929993099319932993399349935993699379938993999409941994299439944994599469947994899499950995199529953995499559956995799589959996099619962996399649965996699679968996999709971997299739974997599769977997899799980998199829983998499859986998799889989999099919992999399949995999699979998999910000100011000210003100041000510006100071000810009100101001110012100131001410015100161001710018100191002010021100221002310024100251002610027100281002910030100311003210033100341003510036100371003810039100401004110042100431004410045100461004710048100491005010051100521005310054100551005610057100581005910060100611006210063100641006510066100671006810069100701007110072100731007410075100761007710078100791008010081100821008310084100851008610087100881008910090100911009210093100941009510096100971009810099101001010110102101031010410105101061010710108101091011010111101121011310114101151011610117101181011910120101211012210123101241012510126101271012810129101301013110132101331013410135101361013710138101391014010141101421014310144101451014610147101481014910150101511015210153101541015510156101571015810159101601016110162101631016410165101661016710168101691017010171101721017310174101751017610177101781017910180101811018210183101841018510186101871018810189101901019110192101931019410195101961019710198101991020010201102021020310204102051020610207102081020910210102111021210213102141021510216102171021810219102201022110222102231022410225102261022710228102291023010231102321023310234102351023610237102381023910240102411024210243102441024510246102471024810249102501025110252102531025410255102561025710258102591026010261102621026310264102651026610267102681026910270102711027210273102741027510276102771027810279102801028110282102831028410285102861028710288102891029010291102921029310294102951029610297102981029910300103011030210303103041030510306103071030810309103101031110312103131031410315103161031710318103191032010321103221032310324103251032610327103281032910330103311033210333103341033510336103371033810339103401034110342103431034410345103461034710348103491035010351103521035310354103551035610357103581035910360103611036210363103641036510366103671036810369103701037110372103731037410375103761037710378103791038010381103821038310384103851038610387103881038910390103911039210393103941039510396103971039810399104001040110402104031040410405104061040710408104091041010411104121041310414104151041610417104181041910420104211042210423104241042510426104271042810429104301043110432104331043410435104361043710438104391044010441104421044310444104451044610447104481044910450104511045210453104541045510456104571045810459104601046110462104631046410465104661046710468104691047010471104721047310474104751047610477104781047910480104811048210483104841048510486104871048810489104901049110492104931049410495104961049710498104991050010501105021050310504105051050610507105081050910510105111051210513105141051510516105171051810519105201052110522105231052410525105261052710528105291053010531105321053310534105351053610537105381053910540105411054210543105441054510546105471054810549105501055110552105531055410555105561055710558105591056010561105621056310564105651056610567105681056910570105711057210573105741057510576105771057810579105801058110582105831058410585105861058710588105891059010591105921059310594105951059610597105981059910600106011060210603106041060510606106071060810609106101061110612106131061410615106161061710618106191062010621106221062310624106251062610627106281062910630106311063210633106341063510636106371063810639106401064110642106431064410645106461064710648106491065010651106521065310654106551065610657106581065910660106611066210663106641066510666106671066810669106701067110672106731067410675106761067710678106791068010681106821068310684106851068610687106881068910690106911069210693106941069510696106971069810699107001070110702107031070410705107061070710708107091071010711107121071310714107151071610717107181071910720107211072210723107241072510726107271072810729107301073110732107331073410735107361073710738107391074010741107421074310744107451074610747107481074910750107511075210753107541075510756107571075810759107601076110762107631076410765107661076710768107691077010771107721077310774107751077610777107781077910780107811078210783107841078510786107871078810789107901079110792107931079410795107961079710798107991080010801108021080310804108051080610807108081080910810108111081210813108141081510816108171081810819108201082110822108231082410825108261082710828108291083010831108321083310834108351083610837108381083910840108411084210843108441084510846108471084810849108501085110852108531085410855108561085710858108591086010861108621086310864108651086610867108681086910870108711087210873108741087510876108771087810879108801088110882108831088410885108861088710888108891089010891108921089310894108951089610897108981089910900109011090210903109041090510906109071090810909109101091110912109131091410915109161091710918109191092010921109221092310924109251092610927109281092910930109311093210933109341093510936109371093810939109401094110942109431094410945109461094710948109491095010951109521095310954109551095610957109581095910960109611096210963109641096510966109671096810969109701097110972109731097410975109761097710978109791098010981109821098310984109851098610987109881098910990109911099210993109941099510996109971099810999110001100111002110031100411005110061100711008110091101011011110121101311014110151101611017110181101911020110211102211023110241102511026110271102811029110301103111032110331103411035110361103711038110391104011041110421104311044110451104611047110481104911050110511105211053110541105511056110571105811059110601106111062110631106411065110661106711068110691107011071110721107311074110751107611077110781107911080110811108211083110841108511086110871108811089110901109111092110931109411095110961109711098110991110011101111021110311104111051110611107111081110911110111111111211113111141111511116111171111811119111201112111122111231112411125111261112711128111291113011131111321113311134111351113611137111381113911140111411114211143111441114511146111471114811149111501115111152111531115411155111561115711158111591116011161111621116311164111651116611167111681116911170111711117211173111741117511176111771117811179111801118111182111831118411185111861118711188111891119011191111921119311194111951119611197111981119911200112011120211203112041120511206112071120811209112101121111212112131121411215112161121711218112191122011221112221122311224112251122611227112281122911230112311123211233112341123511236112371123811239112401124111242112431124411245112461124711248112491125011251112521125311254112551125611257112581125911260112611126211263112641126511266112671126811269112701127111272112731127411275112761127711278112791128011281112821128311284112851128611287112881128911290112911129211293112941129511296112971129811299113001130111302113031130411305113061130711308113091131011311113121131311314113151131611317113181131911320113211132211323113241132511326113271132811329113301133111332113331133411335113361133711338113391134011341113421134311344113451134611347113481134911350113511135211353113541135511356113571135811359113601136111362113631136411365113661136711368113691137011371113721137311374113751137611377113781137911380113811138211383113841138511386113871138811389113901139111392113931139411395113961139711398113991140011401114021140311404114051140611407114081140911410114111141211413114141141511416114171141811419114201142111422114231142411425114261142711428114291143011431114321143311434114351143611437114381143911440114411144211443114441144511446114471144811449114501145111452114531145411455114561145711458114591146011461114621146311464114651146611467114681146911470114711147211473114741147511476114771147811479114801148111482114831148411485114861148711488114891149011491114921149311494114951149611497114981149911500115011150211503115041150511506115071150811509115101151111512115131151411515115161151711518115191152011521115221152311524115251152611527115281152911530115311153211533115341153511536115371153811539115401154111542115431154411545115461154711548115491155011551115521155311554115551155611557115581155911560115611156211563115641156511566115671156811569115701157111572115731157411575115761157711578115791158011581115821158311584115851158611587115881158911590115911159211593115941159511596115971159811599116001160111602116031160411605116061160711608116091161011611116121161311614116151161611617116181161911620116211162211623116241162511626116271162811629116301163111632116331163411635116361163711638116391164011641116421164311644116451164611647116481164911650116511165211653116541165511656116571165811659116601166111662116631166411665116661166711668116691167011671116721167311674116751167611677116781167911680116811168211683116841168511686116871168811689116901169111692116931169411695116961169711698116991170011701117021170311704117051170611707117081170911710117111171211713117141171511716117171171811719117201172111722117231172411725117261172711728117291173011731117321173311734117351173611737117381173911740117411174211743117441174511746117471174811749117501175111752117531175411755117561175711758117591176011761117621176311764117651176611767117681176911770117711177211773117741177511776117771177811779117801178111782117831178411785117861178711788117891179011791117921179311794117951179611797117981179911800118011180211803118041180511806118071180811809118101181111812118131181411815118161181711818118191182011821118221182311824118251182611827118281182911830118311183211833118341183511836118371183811839118401184111842118431184411845118461184711848118491185011851118521185311854118551185611857118581185911860118611186211863118641186511866118671186811869118701187111872118731187411875118761187711878118791188011881118821188311884118851188611887118881188911890118911189211893118941189511896118971189811899119001190111902119031190411905119061190711908119091191011911119121191311914119151191611917119181191911920119211192211923119241192511926119271192811929119301193111932119331193411935119361193711938119391194011941119421194311944119451194611947119481194911950119511195211953119541195511956119571195811959119601196111962119631196411965119661196711968119691197011971119721197311974119751197611977119781197911980119811198211983119841198511986119871198811989119901199111992119931199411995119961199711998119991200012001120021200312004120051200612007120081200912010120111201212013120141201512016120171201812019120201202112022120231202412025120261202712028120291203012031120321203312034120351203612037120381203912040120411204212043120441204512046120471204812049120501205112052120531205412055120561205712058120591206012061120621206312064120651206612067120681206912070120711207212073120741207512076120771207812079120801208112082120831208412085120861208712088120891209012091120921209312094120951209612097120981209912100121011210212103121041210512106121071210812109121101211112112121131211412115121161211712118121191212012121121221212312124121251212612127121281212912130121311213212133121341213512136121371213812139121401214112142121431214412145121461214712148121491215012151121521215312154121551215612157121581215912160121611216212163121641216512166121671216812169121701217112172121731217412175121761217712178121791218012181121821218312184121851218612187121881218912190121911219212193121941219512196121971219812199122001220112202122031220412205122061220712208122091221012211122121221312214122151221612217122181221912220122211222212223122241222512226122271222812229122301223112232122331223412235122361223712238122391224012241122421224312244122451224612247122481224912250122511225212253122541225512256122571225812259122601226112262122631226412265122661226712268122691227012271122721227312274122751227612277122781227912280122811228212283122841228512286122871228812289122901229112292122931229412295122961229712298122991230012301123021230312304123051230612307123081230912310123111231212313123141231512316123171231812319123201232112322123231232412325123261232712328123291233012331123321233312334123351233612337123381233912340123411234212343123441234512346123471234812349123501235112352123531235412355123561235712358123591236012361123621236312364123651236612367123681236912370123711237212373123741237512376123771237812379123801238112382123831238412385123861238712388123891239012391123921239312394123951239612397123981239912400124011240212403124041240512406124071240812409124101241112412124131241412415124161241712418124191242012421124221242312424124251242612427124281242912430124311243212433124341243512436124371243812439124401244112442124431244412445124461244712448124491245012451124521245312454124551245612457124581245912460124611246212463124641246512466124671246812469124701247112472124731247412475124761247712478124791248012481124821248312484124851248612487124881248912490124911249212493124941249512496124971249812499125001250112502125031250412505125061250712508125091251012511125121251312514125151251612517125181251912520125211252212523125241252512526125271252812529125301253112532125331253412535125361253712538125391254012541125421254312544125451254612547125481254912550125511255212553125541255512556125571255812559125601256112562125631256412565125661256712568125691257012571125721257312574125751257612577125781257912580125811258212583125841258512586125871258812589125901259112592125931259412595125961259712598125991260012601126021260312604126051260612607126081260912610126111261212613126141261512616126171261812619126201262112622126231262412625126261262712628126291263012631126321263312634126351263612637126381263912640126411264212643126441264512646126471264812649126501265112652126531265412655126561265712658126591266012661126621266312664126651266612667126681266912670126711267212673126741267512676126771267812679126801268112682126831268412685126861268712688126891269012691126921269312694126951269612697126981269912700127011270212703127041270512706127071270812709127101271112712127131271412715127161271712718127191272012721127221272312724127251272612727127281272912730127311273212733127341273512736127371273812739127401274112742127431274412745127461274712748127491275012751127521275312754127551275612757127581275912760127611276212763127641276512766127671276812769127701277112772127731277412775127761277712778127791278012781127821278312784127851278612787127881278912790127911279212793127941279512796127971279812799128001280112802128031280412805128061280712808128091281012811128121281312814128151281612817128181281912820128211282212823128241282512826128271282812829128301283112832128331283412835128361283712838128391284012841128421284312844128451284612847128481284912850128511285212853128541285512856128571285812859128601286112862128631286412865128661286712868128691287012871128721287312874128751287612877128781287912880128811288212883128841288512886128871288812889128901289112892128931289412895128961289712898128991290012901129021290312904129051290612907129081290912910129111291212913129141291512916129171291812919129201292112922129231292412925129261292712928129291293012931129321293312934129351293612937129381293912940129411294212943129441294512946129471294812949129501295112952129531295412955129561295712958129591296012961129621296312964129651296612967129681296912970129711297212973129741297512976129771297812979129801298112982129831298412985129861298712988129891299012991129921299312994129951299612997129981299913000130011300213003130041300513006130071300813009130101301113012130131301413015130161301713018130191302013021130221302313024130251302613027130281302913030130311303213033130341303513036130371303813039130401304113042130431304413045130461304713048130491305013051130521305313054130551305613057130581305913060130611306213063130641306513066130671306813069130701307113072130731307413075130761307713078130791308013081130821308313084130851308613087130881308913090130911309213093130941309513096130971309813099131001310113102131031310413105131061310713108131091311013111131121311313114131151311613117131181311913120131211312213123131241312513126131271312813129131301313113132131331313413135131361313713138131391314013141131421314313144131451314613147131481314913150131511315213153131541315513156131571315813159131601316113162131631316413165131661316713168131691317013171131721317313174131751317613177131781317913180131811318213183131841318513186131871318813189131901319113192131931319413195131961319713198131991320013201132021320313204132051320613207132081320913210132111321213213132141321513216132171321813219132201322113222132231322413225132261322713228132291323013231132321323313234132351323613237132381323913240132411324213243132441324513246132471324813249132501325113252132531325413255132561325713258132591326013261132621326313264132651326613267132681326913270132711327213273132741327513276132771327813279132801328113282132831328413285132861328713288132891329013291132921329313294132951329613297132981329913300133011330213303133041330513306133071330813309133101331113312133131331413315133161331713318133191332013321133221332313324133251332613327133281332913330133311333213333133341333513336133371333813339133401334113342133431334413345133461334713348133491335013351133521335313354133551335613357133581335913360133611336213363133641336513366133671336813369133701337113372133731337413375133761337713378133791338013381133821338313384133851338613387133881338913390133911339213393133941339513396133971339813399134001340113402134031340413405134061340713408134091341013411134121341313414134151341613417134181341913420134211342213423134241342513426134271342813429134301343113432134331343413435134361343713438134391344013441134421344313444134451344613447134481344913450134511345213453134541345513456134571345813459134601346113462134631346413465134661346713468134691347013471134721347313474134751347613477134781347913480134811348213483134841348513486134871348813489134901349113492134931349413495134961349713498134991350013501135021350313504135051350613507135081350913510135111351213513135141351513516135171351813519135201352113522135231352413525135261352713528135291353013531135321353313534135351353613537135381353913540135411354213543135441354513546135471354813549135501355113552135531355413555135561355713558135591356013561135621356313564135651356613567135681356913570135711357213573135741357513576135771357813579135801358113582135831358413585135861358713588135891359013591135921359313594135951359613597135981359913600136011360213603136041360513606136071360813609136101361113612136131361413615136161361713618136191362013621136221362313624136251362613627136281362913630136311363213633136341363513636136371363813639136401364113642136431364413645136461364713648136491365013651136521365313654136551365613657136581365913660136611366213663136641366513666136671366813669136701367113672136731367413675136761367713678136791368013681136821368313684136851368613687136881368913690136911369213693136941369513696136971369813699137001370113702137031370413705137061370713708137091371013711137121371313714137151371613717137181371913720137211372213723137241372513726137271372813729137301373113732137331373413735137361373713738137391374013741137421374313744137451374613747137481374913750137511375213753137541375513756137571375813759137601376113762137631376413765137661376713768137691377013771137721377313774137751377613777137781377913780137811378213783137841378513786137871378813789137901379113792137931379413795137961379713798137991380013801138021380313804138051380613807138081380913810138111381213813138141381513816138171381813819138201382113822138231382413825138261382713828138291383013831138321383313834138351383613837138381383913840138411384213843138441384513846138471384813849138501385113852138531385413855138561385713858138591386013861138621386313864138651386613867138681386913870138711387213873138741387513876138771387813879138801388113882138831388413885138861388713888138891389013891138921389313894138951389613897138981389913900139011390213903139041390513906139071390813909139101391113912139131391413915139161391713918139191392013921139221392313924139251392613927139281392913930139311393213933139341393513936139371393813939139401394113942139431394413945139461394713948139491395013951139521395313954139551395613957139581395913960139611396213963139641396513966139671396813969139701397113972139731397413975139761397713978139791398013981139821398313984139851398613987139881398913990139911399213993139941399513996139971399813999140001400114002140031400414005140061400714008140091401014011140121401314014140151401614017140181401914020140211402214023140241402514026140271402814029140301403114032140331403414035140361403714038140391404014041140421404314044140451404614047140481404914050140511405214053140541405514056140571405814059140601406114062140631406414065140661406714068140691407014071140721407314074140751407614077140781407914080140811408214083140841408514086140871408814089140901409114092140931409414095140961409714098140991410014101141021410314104141051410614107141081410914110141111411214113141141411514116141171411814119141201412114122141231412414125141261412714128141291413014131141321413314134141351413614137141381413914140141411414214143141441414514146141471414814149141501415114152141531415414155141561415714158141591416014161141621416314164141651416614167141681416914170141711417214173141741417514176141771417814179141801418114182141831418414185141861418714188141891419014191141921419314194141951419614197141981419914200142011420214203142041420514206142071420814209142101421114212142131421414215142161421714218142191422014221142221422314224142251422614227142281422914230142311423214233142341423514236142371423814239142401424114242142431424414245142461424714248142491425014251142521425314254142551425614257142581425914260142611426214263142641426514266142671426814269142701427114272142731427414275142761427714278142791428014281142821428314284142851428614287142881428914290142911429214293142941429514296142971429814299143001430114302143031430414305143061430714308143091431014311143121431314314143151431614317143181431914320143211432214323143241432514326143271432814329143301433114332143331433414335143361433714338143391434014341143421434314344143451434614347143481434914350143511435214353143541435514356143571435814359143601436114362143631436414365143661436714368143691437014371143721437314374143751437614377143781437914380143811438214383143841438514386143871438814389143901439114392143931439414395143961439714398143991440014401144021440314404144051440614407144081440914410144111441214413144141441514416144171441814419144201442114422144231442414425144261442714428144291443014431144321443314434144351443614437144381443914440144411444214443144441444514446144471444814449144501445114452144531445414455144561445714458144591446014461144621446314464144651446614467144681446914470144711447214473144741447514476144771447814479144801448114482144831448414485144861448714488144891449014491144921449314494144951449614497144981449914500145011450214503145041450514506145071450814509145101451114512145131451414515145161451714518145191452014521145221452314524145251452614527145281452914530145311453214533145341453514536145371453814539145401454114542145431454414545145461454714548145491455014551145521455314554145551455614557145581455914560145611456214563145641456514566145671456814569145701457114572145731457414575145761457714578145791458014581145821458314584145851458614587145881458914590145911459214593145941459514596145971459814599146001460114602146031460414605146061460714608146091461014611146121461314614146151461614617146181461914620146211462214623146241462514626146271462814629146301463114632146331463414635146361463714638146391464014641146421464314644146451464614647146481464914650146511465214653146541465514656146571465814659146601466114662146631466414665146661466714668146691467014671146721467314674146751467614677146781467914680146811468214683146841468514686146871468814689146901469114692146931469414695146961469714698146991470014701147021470314704147051470614707147081470914710147111471214713147141471514716147171471814719147201472114722147231472414725147261472714728147291473014731147321473314734147351473614737147381473914740147411474214743147441474514746147471474814749147501475114752147531475414755147561475714758147591476014761147621476314764147651476614767147681476914770147711477214773147741477514776147771477814779147801478114782147831478414785147861478714788147891479014791147921479314794147951479614797147981479914800148011480214803148041480514806148071480814809148101481114812148131481414815148161481714818148191482014821148221482314824148251482614827148281482914830148311483214833148341483514836148371483814839148401484114842148431484414845148461484714848148491485014851148521485314854148551485614857148581485914860148611486214863148641486514866148671486814869148701487114872148731487414875148761487714878148791488014881148821488314884148851488614887148881488914890148911489214893148941489514896148971489814899149001490114902149031490414905149061490714908149091491014911149121491314914149151491614917149181491914920149211492214923149241492514926149271492814929149301493114932149331493414935149361493714938149391494014941149421494314944149451494614947149481494914950149511495214953149541495514956149571495814959149601496114962149631496414965149661496714968149691497014971149721497314974149751497614977149781497914980149811498214983149841498514986149871498814989149901499114992149931499414995149961499714998149991500015001150021500315004150051500615007150081500915010150111501215013150141501515016150171501815019150201502115022150231502415025150261502715028150291503015031150321503315034150351503615037150381503915040150411504215043150441504515046150471504815049150501505115052150531505415055150561505715058150591506015061150621506315064150651506615067150681506915070150711507215073150741507515076150771507815079150801508115082150831508415085150861508715088150891509015091150921509315094150951509615097150981509915100151011510215103151041510515106151071510815109151101511115112151131511415115151161511715118151191512015121151221512315124151251512615127151281512915130151311513215133151341513515136151371513815139151401514115142151431514415145151461514715148151491515015151151521515315154151551515615157151581515915160151611516215163151641516515166151671516815169151701517115172151731517415175151761517715178151791518015181151821518315184151851518615187151881518915190151911519215193151941519515196151971519815199152001520115202152031520415205152061520715208152091521015211152121521315214152151521615217152181521915220152211522215223152241522515226152271522815229152301523115232152331523415235152361523715238152391524015241152421524315244152451524615247152481524915250152511525215253152541525515256152571525815259152601526115262152631526415265152661526715268152691527015271152721527315274152751527615277152781527915280152811528215283152841528515286152871528815289152901529115292152931529415295152961529715298152991530015301153021530315304153051530615307153081530915310153111531215313153141531515316153171531815319153201532115322153231532415325153261532715328153291533015331153321533315334153351533615337153381533915340153411534215343153441534515346153471534815349153501535115352153531535415355153561535715358153591536015361153621536315364153651536615367153681536915370153711537215373153741537515376153771537815379153801538115382153831538415385153861538715388153891539015391153921539315394153951539615397153981539915400154011540215403154041540515406154071540815409154101541115412154131541415415154161541715418154191542015421154221542315424154251542615427154281542915430154311543215433154341543515436154371543815439154401544115442154431544415445154461544715448154491545015451154521545315454154551545615457154581545915460154611546215463154641546515466154671546815469154701547115472154731547415475154761547715478154791548015481154821548315484154851548615487154881548915490154911549215493154941549515496154971549815499155001550115502155031550415505155061550715508155091551015511155121551315514155151551615517155181551915520155211552215523155241552515526155271552815529155301553115532155331553415535155361553715538155391554015541155421554315544155451554615547155481554915550155511555215553155541555515556155571555815559155601556115562155631556415565155661556715568155691557015571155721557315574155751557615577155781557915580155811558215583155841558515586155871558815589155901559115592155931559415595155961559715598155991560015601156021560315604156051560615607156081560915610156111561215613156141561515616156171561815619156201562115622156231562415625156261562715628156291563015631156321563315634156351563615637156381563915640156411564215643156441564515646156471564815649156501565115652156531565415655156561565715658156591566015661156621566315664156651566615667156681566915670156711567215673156741567515676156771567815679156801568115682156831568415685156861568715688156891569015691156921569315694156951569615697156981569915700157011570215703157041570515706157071570815709157101571115712157131571415715157161571715718157191572015721157221572315724157251572615727157281572915730157311573215733157341573515736157371573815739157401574115742157431574415745157461574715748157491575015751157521575315754157551575615757157581575915760157611576215763157641576515766157671576815769157701577115772157731577415775157761577715778157791578015781157821578315784157851578615787157881578915790157911579215793157941579515796157971579815799158001580115802158031580415805158061580715808158091581015811158121581315814158151581615817158181581915820158211582215823158241582515826158271582815829158301583115832158331583415835158361583715838158391584015841158421584315844158451584615847158481584915850158511585215853158541585515856158571585815859158601586115862158631586415865158661586715868158691587015871158721587315874158751587615877158781587915880158811588215883158841588515886158871588815889158901589115892158931589415895158961589715898158991590015901159021590315904159051590615907159081590915910159111591215913159141591515916159171591815919159201592115922159231592415925159261592715928159291593015931159321593315934159351593615937159381593915940159411594215943159441594515946159471594815949159501595115952159531595415955159561595715958159591596015961159621596315964159651596615967159681596915970159711597215973159741597515976159771597815979159801598115982159831598415985159861598715988159891599015991159921599315994159951599615997159981599916000160011600216003160041600516006160071600816009160101601116012160131601416015160161601716018160191602016021160221602316024160251602616027160281602916030160311603216033160341603516036160371603816039160401604116042160431604416045160461604716048160491605016051160521605316054160551605616057160581605916060160611606216063160641606516066160671606816069160701607116072160731607416075160761607716078160791608016081160821608316084160851608616087160881608916090160911609216093160941609516096160971609816099161001610116102161031610416105161061610716108161091611016111161121611316114161151611616117161181611916120161211612216123161241612516126161271612816129161301613116132161331613416135161361613716138161391614016141161421614316144161451614616147161481614916150161511615216153161541615516156161571615816159161601616116162161631616416165161661616716168161691617016171161721617316174161751617616177161781617916180161811618216183161841618516186161871618816189161901619116192161931619416195161961619716198161991620016201162021620316204162051620616207162081620916210162111621216213162141621516216162171621816219162201622116222162231622416225162261622716228162291623016231162321623316234162351623616237162381623916240162411624216243162441624516246162471624816249162501625116252162531625416255162561625716258162591626016261162621626316264162651626616267162681626916270162711627216273162741627516276162771627816279162801628116282162831628416285162861628716288162891629016291162921629316294162951629616297162981629916300163011630216303163041630516306163071630816309163101631116312163131631416315163161631716318163191632016321163221632316324163251632616327163281632916330163311633216333163341633516336163371633816339163401634116342163431634416345163461634716348163491635016351163521635316354163551635616357163581635916360163611636216363163641636516366163671636816369163701637116372163731637416375163761637716378163791638016381163821638316384163851638616387163881638916390163911639216393163941639516396163971639816399164001640116402164031640416405164061640716408164091641016411164121641316414164151641616417164181641916420164211642216423164241642516426164271642816429164301643116432164331643416435164361643716438164391644016441164421644316444164451644616447164481644916450164511645216453164541645516456164571645816459164601646116462164631646416465164661646716468164691647016471164721647316474164751647616477164781647916480164811648216483164841648516486164871648816489164901649116492164931649416495164961649716498164991650016501165021650316504165051650616507165081650916510165111651216513165141651516516165171651816519165201652116522165231652416525165261652716528165291653016531165321653316534165351653616537165381653916540165411654216543165441654516546165471654816549165501655116552165531655416555165561655716558165591656016561165621656316564165651656616567165681656916570165711657216573165741657516576165771657816579165801658116582165831658416585165861658716588165891659016591165921659316594165951659616597165981659916600166011660216603166041660516606166071660816609166101661116612166131661416615166161661716618166191662016621166221662316624166251662616627166281662916630166311663216633166341663516636166371663816639166401664116642166431664416645166461664716648166491665016651166521665316654166551665616657166581665916660166611666216663166641666516666166671666816669166701667116672166731667416675166761667716678166791668016681166821668316684166851668616687166881668916690166911669216693166941669516696166971669816699167001670116702167031670416705167061670716708167091671016711167121671316714167151671616717167181671916720167211672216723167241672516726167271672816729167301673116732167331673416735167361673716738167391674016741167421674316744167451674616747167481674916750167511675216753167541675516756167571675816759167601676116762167631676416765167661676716768167691677016771167721677316774167751677616777167781677916780167811678216783167841678516786167871678816789167901679116792167931679416795167961679716798167991680016801168021680316804168051680616807168081680916810168111681216813168141681516816168171681816819168201682116822168231682416825168261682716828168291683016831168321683316834168351683616837168381683916840168411684216843168441684516846168471684816849168501685116852168531685416855168561685716858168591686016861168621686316864168651686616867168681686916870168711687216873168741687516876168771687816879168801688116882168831688416885168861688716888168891689016891168921689316894168951689616897168981689916900169011690216903169041690516906169071690816909169101691116912169131691416915169161691716918169191692016921169221692316924169251692616927169281692916930169311693216933169341693516936169371693816939169401694116942169431694416945169461694716948169491695016951169521695316954169551695616957169581695916960169611696216963169641696516966169671696816969169701697116972169731697416975169761697716978169791698016981169821698316984169851698616987169881698916990169911699216993169941699516996169971699816999170001700117002170031700417005170061700717008170091701017011170121701317014170151701617017170181701917020170211702217023170241702517026170271702817029170301703117032170331703417035170361703717038170391704017041170421704317044170451704617047170481704917050170511705217053170541705517056170571705817059170601706117062170631706417065170661706717068170691707017071170721707317074170751707617077170781707917080170811708217083170841708517086170871708817089170901709117092170931709417095170961709717098170991710017101171021710317104171051710617107171081710917110171111711217113171141711517116171171711817119171201712117122171231712417125171261712717128171291713017131171321713317134171351713617137171381713917140171411714217143171441714517146171471714817149171501715117152171531715417155171561715717158171591716017161171621716317164171651716617167171681716917170171711717217173171741717517176171771717817179171801718117182171831718417185171861718717188171891719017191171921719317194171951719617197171981719917200172011720217203172041720517206172071720817209172101721117212172131721417215172161721717218172191722017221172221722317224172251722617227172281722917230172311723217233172341723517236172371723817239172401724117242172431724417245172461724717248172491725017251172521725317254172551725617257172581725917260172611726217263172641726517266172671726817269172701727117272172731727417275172761727717278172791728017281172821728317284172851728617287172881728917290172911729217293172941729517296172971729817299173001730117302173031730417305173061730717308173091731017311173121731317314173151731617317173181731917320173211732217323173241732517326173271732817329173301733117332173331733417335173361733717338173391734017341173421734317344173451734617347173481734917350173511735217353173541735517356173571735817359173601736117362173631736417365173661736717368173691737017371173721737317374173751737617377173781737917380173811738217383173841738517386173871738817389173901739117392173931739417395173961739717398173991740017401174021740317404174051740617407174081740917410174111741217413174141741517416174171741817419174201742117422174231742417425174261742717428174291743017431174321743317434174351743617437174381743917440174411744217443174441744517446174471744817449174501745117452174531745417455174561745717458174591746017461174621746317464174651746617467174681746917470174711747217473174741747517476174771747817479174801748117482174831748417485174861748717488174891749017491174921749317494174951749617497174981749917500175011750217503175041750517506175071750817509175101751117512175131751417515175161751717518175191752017521175221752317524175251752617527175281752917530175311753217533175341753517536175371753817539175401754117542175431754417545175461754717548175491755017551175521755317554175551755617557175581755917560175611756217563175641756517566175671756817569175701757117572175731757417575175761757717578175791758017581175821758317584175851758617587175881758917590175911759217593175941759517596175971759817599176001760117602176031760417605176061760717608176091761017611176121761317614176151761617617176181761917620176211762217623176241762517626176271762817629176301763117632176331763417635176361763717638176391764017641176421764317644176451764617647176481764917650176511765217653176541765517656176571765817659176601766117662176631766417665176661766717668176691767017671176721767317674176751767617677176781767917680176811768217683176841768517686176871768817689176901769117692176931769417695176961769717698176991770017701177021770317704177051770617707177081770917710177111771217713177141771517716177171771817719177201772117722177231772417725177261772717728177291773017731177321773317734177351773617737177381773917740177411774217743177441774517746177471774817749177501775117752177531775417755177561775717758177591776017761177621776317764177651776617767177681776917770177711777217773177741777517776177771777817779177801778117782177831778417785177861778717788177891779017791177921779317794177951779617797177981779917800178011780217803178041780517806178071780817809178101781117812178131781417815178161781717818178191782017821178221782317824178251782617827178281782917830178311783217833178341783517836178371783817839178401784117842178431784417845178461784717848178491785017851178521785317854178551785617857178581785917860178611786217863178641786517866178671786817869178701787117872178731787417875178761787717878178791788017881178821788317884178851788617887178881788917890178911789217893178941789517896178971789817899179001790117902179031790417905179061790717908179091791017911179121791317914179151791617917179181791917920179211792217923179241792517926179271792817929179301793117932179331793417935179361793717938179391794017941179421794317944179451794617947179481794917950179511795217953179541795517956179571795817959179601796117962179631796417965179661796717968179691797017971179721797317974179751797617977179781797917980179811798217983179841798517986179871798817989179901799117992179931799417995179961799717998179991800018001180021800318004180051800618007180081800918010180111801218013180141801518016180171801818019180201802118022180231802418025180261802718028180291803018031180321803318034180351803618037180381803918040180411804218043180441804518046180471804818049180501805118052180531805418055180561805718058180591806018061180621806318064180651806618067180681806918070180711807218073180741807518076180771807818079180801808118082180831808418085180861808718088180891809018091180921809318094180951809618097180981809918100181011810218103181041810518106181071810818109181101811118112181131811418115181161811718118181191812018121181221812318124181251812618127181281812918130181311813218133181341813518136181371813818139181401814118142181431814418145181461814718148181491815018151181521815318154181551815618157181581815918160181611816218163181641816518166181671816818169181701817118172181731817418175181761817718178181791818018181181821818318184181851818618187181881818918190181911819218193181941819518196181971819818199182001820118202182031820418205182061820718208182091821018211182121821318214182151821618217182181821918220182211822218223182241822518226182271822818229182301823118232182331823418235182361823718238182391824018241182421824318244182451824618247182481824918250182511825218253182541825518256182571825818259182601826118262182631826418265182661826718268182691827018271182721827318274182751827618277182781827918280182811828218283182841828518286182871828818289182901829118292182931829418295182961829718298182991830018301183021830318304183051830618307183081830918310183111831218313183141831518316183171831818319183201832118322183231832418325183261832718328183291833018331183321833318334183351833618337183381833918340183411834218343183441834518346183471834818349183501835118352183531835418355183561835718358183591836018361183621836318364183651836618367183681836918370183711837218373183741837518376183771837818379183801838118382183831838418385183861838718388183891839018391183921839318394183951839618397183981839918400184011840218403184041840518406184071840818409184101841118412184131841418415184161841718418184191842018421184221842318424184251842618427184281842918430184311843218433184341843518436184371843818439184401844118442184431844418445184461844718448184491845018451184521845318454184551845618457184581845918460184611846218463184641846518466184671846818469184701847118472184731847418475184761847718478184791848018481184821848318484184851848618487184881848918490184911849218493184941849518496184971849818499185001850118502185031850418505185061850718508185091851018511185121851318514185151851618517185181851918520185211852218523185241852518526185271852818529185301853118532185331853418535185361853718538185391854018541185421854318544185451854618547185481854918550185511855218553185541855518556185571855818559185601856118562185631856418565185661856718568185691857018571185721857318574185751857618577185781857918580185811858218583185841858518586185871858818589185901859118592185931859418595185961859718598185991860018601186021860318604186051860618607186081860918610186111861218613186141861518616186171861818619186201862118622186231862418625186261862718628186291863018631186321863318634186351863618637186381863918640186411864218643186441864518646186471864818649186501865118652186531865418655186561865718658186591866018661186621866318664186651866618667186681866918670186711867218673186741867518676186771867818679186801868118682186831868418685186861868718688186891869018691186921869318694186951869618697186981869918700187011870218703187041870518706187071870818709187101871118712187131871418715187161871718718187191872018721187221872318724187251872618727187281872918730187311873218733187341873518736187371873818739187401874118742187431874418745187461874718748187491875018751187521875318754187551875618757187581875918760187611876218763187641876518766187671876818769187701877118772187731877418775187761877718778187791878018781187821878318784187851878618787187881878918790187911879218793187941879518796187971879818799188001880118802188031880418805188061880718808188091881018811188121881318814188151881618817188181881918820188211882218823188241882518826188271882818829188301883118832188331883418835188361883718838188391884018841188421884318844188451884618847188481884918850188511885218853188541885518856188571885818859188601886118862188631886418865188661886718868188691887018871188721887318874188751887618877188781887918880188811888218883188841888518886188871888818889188901889118892188931889418895188961889718898188991890018901189021890318904189051890618907189081890918910189111891218913189141891518916189171891818919189201892118922189231892418925189261892718928189291893018931189321893318934189351893618937189381893918940189411894218943189441894518946189471894818949189501895118952189531895418955189561895718958189591896018961189621896318964189651896618967189681896918970189711897218973189741897518976189771897818979189801898118982189831898418985189861898718988189891899018991189921899318994189951899618997189981899919000190011900219003190041900519006190071900819009190101901119012190131901419015190161901719018190191902019021190221902319024190251902619027190281902919030190311903219033190341903519036190371903819039190401904119042190431904419045190461904719048190491905019051190521905319054190551905619057190581905919060190611906219063190641906519066190671906819069190701907119072190731907419075190761907719078190791908019081190821908319084190851908619087190881908919090190911909219093190941909519096190971909819099191001910119102191031910419105191061910719108191091911019111191121911319114191151911619117191181911919120191211912219123191241912519126191271912819129191301913119132191331913419135191361913719138191391914019141191421914319144191451914619147191481914919150191511915219153191541915519156191571915819159191601916119162191631916419165191661916719168191691917019171191721917319174191751917619177191781917919180191811918219183191841918519186191871918819189191901919119192191931919419195191961919719198191991920019201192021920319204192051920619207192081920919210192111921219213192141921519216192171921819219192201922119222192231922419225192261922719228192291923019231192321923319234192351923619237192381923919240192411924219243192441924519246192471924819249192501925119252192531925419255192561925719258192591926019261192621926319264192651926619267192681926919270192711927219273192741927519276192771927819279192801928119282192831928419285192861928719288192891929019291192921929319294192951929619297192981929919300193011930219303193041930519306193071930819309193101931119312193131931419315193161931719318193191932019321193221932319324193251932619327193281932919330193311933219333193341933519336193371933819339193401934119342193431934419345193461934719348193491935019351193521935319354193551935619357193581935919360193611936219363193641936519366193671936819369193701937119372193731937419375193761937719378193791938019381193821938319384193851938619387193881938919390193911939219393193941939519396193971939819399194001940119402194031940419405194061940719408194091941019411194121941319414194151941619417194181941919420194211942219423194241942519426194271942819429194301943119432194331943419435194361943719438194391944019441194421944319444194451944619447194481944919450194511945219453194541945519456194571945819459194601946119462194631946419465194661946719468194691947019471194721947319474194751947619477194781947919480194811948219483194841948519486194871948819489194901949119492194931949419495194961949719498194991950019501195021950319504195051950619507195081950919510195111951219513195141951519516195171951819519195201952119522195231952419525195261952719528195291953019531195321953319534195351953619537195381953919540195411954219543195441954519546195471954819549195501955119552195531955419555195561955719558195591956019561195621956319564195651956619567195681956919570195711957219573195741957519576195771957819579195801958119582195831958419585195861958719588195891959019591195921959319594195951959619597195981959919600196011960219603196041960519606196071960819609196101961119612196131961419615196161961719618196191962019621196221962319624196251962619627196281962919630196311963219633196341963519636196371963819639196401964119642196431964419645196461964719648196491965019651196521965319654196551965619657196581965919660196611966219663196641966519666196671966819669196701967119672196731967419675196761967719678196791968019681196821968319684196851968619687196881968919690196911969219693196941969519696196971969819699197001970119702197031970419705197061970719708197091971019711197121971319714197151971619717197181971919720197211972219723197241972519726197271972819729197301973119732197331973419735197361973719738197391974019741197421974319744197451974619747197481974919750197511975219753197541975519756197571975819759197601976119762197631976419765197661976719768197691977019771197721977319774197751977619777197781977919780197811978219783197841978519786197871978819789197901979119792197931979419795197961979719798197991980019801198021980319804198051980619807198081980919810198111981219813198141981519816198171981819819198201982119822198231982419825198261982719828198291983019831198321983319834198351983619837198381983919840198411984219843198441984519846198471984819849198501985119852198531985419855198561985719858198591986019861198621986319864198651986619867198681986919870198711987219873198741987519876198771987819879198801988119882198831988419885198861988719888198891989019891198921989319894198951989619897198981989919900199011990219903199041990519906199071990819909199101991119912199131991419915199161991719918199191992019921199221992319924199251992619927199281992919930199311993219933199341993519936199371993819939199401994119942199431994419945199461994719948199491995019951199521995319954199551995619957199581995919960199611996219963199641996519966199671996819969199701997119972199731997419975199761997719978199791998019981199821998319984199851998619987199881998919990199911999219993199941999519996199971999819999200002000120002200032000420005200062000720008200092001020011200122001320014200152001620017200182001920020200212002220023200242002520026200272002820029200302003120032200332003420035200362003720038200392004020041200422004320044200452004620047200482004920050200512005220053200542005520056200572005820059200602006120062200632006420065200662006720068200692007020071200722007320074200752007620077200782007920080200812008220083200842008520086200872008820089200902009120092200932009420095200962009720098200992010020101201022010320104201052010620107201082010920110201112011220113201142011520116201172011820119201202012120122201232012420125201262012720128201292013020131201322013320134201352013620137201382013920140201412014220143201442014520146201472014820149201502015120152201532015420155201562015720158201592016020161201622016320164201652016620167201682016920170201712017220173201742017520176201772017820179201802018120182201832018420185201862018720188201892019020191201922019320194201952019620197201982019920200202012020220203202042020520206202072020820209202102021120212202132021420215202162021720218202192022020221202222022320224202252022620227202282022920230202312023220233202342023520236202372023820239202402024120242202432024420245202462024720248202492025020251202522025320254202552025620257202582025920260202612026220263202642026520266202672026820269202702027120272202732027420275202762027720278202792028020281202822028320284202852028620287202882028920290202912029220293202942029520296202972029820299203002030120302203032030420305203062030720308203092031020311203122031320314203152031620317203182031920320203212032220323203242032520326203272032820329203302033120332203332033420335203362033720338203392034020341203422034320344203452034620347203482034920350203512035220353203542035520356203572035820359203602036120362203632036420365203662036720368203692037020371203722037320374203752037620377203782037920380203812038220383203842038520386203872038820389203902039120392203932039420395203962039720398203992040020401204022040320404204052040620407204082040920410204112041220413204142041520416204172041820419204202042120422204232042420425204262042720428204292043020431204322043320434204352043620437204382043920440204412044220443204442044520446204472044820449204502045120452204532045420455204562045720458204592046020461204622046320464204652046620467204682046920470204712047220473204742047520476204772047820479204802048120482204832048420485204862048720488204892049020491204922049320494204952049620497204982049920500205012050220503205042050520506205072050820509205102051120512205132051420515205162051720518205192052020521205222052320524205252052620527205282052920530205312053220533205342053520536205372053820539205402054120542205432054420545205462054720548205492055020551205522055320554205552055620557205582055920560205612056220563205642056520566205672056820569205702057120572205732057420575205762057720578205792058020581205822058320584205852058620587205882058920590205912059220593205942059520596205972059820599206002060120602206032060420605206062060720608206092061020611206122061320614206152061620617206182061920620206212062220623206242062520626206272062820629206302063120632206332063420635206362063720638206392064020641206422064320644206452064620647206482064920650206512065220653206542065520656206572065820659206602066120662206632066420665206662066720668206692067020671206722067320674206752067620677206782067920680206812068220683206842068520686206872068820689206902069120692206932069420695206962069720698206992070020701207022070320704207052070620707207082070920710207112071220713207142071520716207172071820719207202072120722207232072420725207262072720728207292073020731207322073320734207352073620737207382073920740207412074220743207442074520746207472074820749207502075120752207532075420755207562075720758207592076020761207622076320764207652076620767207682076920770207712077220773207742077520776207772077820779207802078120782207832078420785207862078720788207892079020791207922079320794207952079620797207982079920800208012080220803208042080520806208072080820809208102081120812208132081420815208162081720818208192082020821208222082320824208252082620827208282082920830208312083220833208342083520836208372083820839208402084120842208432084420845208462084720848208492085020851208522085320854208552085620857208582085920860208612086220863208642086520866208672086820869208702087120872208732087420875208762087720878208792088020881208822088320884208852088620887208882088920890208912089220893208942089520896208972089820899209002090120902209032090420905209062090720908209092091020911209122091320914209152091620917209182091920920209212092220923209242092520926209272092820929209302093120932209332093420935209362093720938209392094020941209422094320944209452094620947209482094920950209512095220953209542095520956209572095820959209602096120962209632096420965209662096720968209692097020971209722097320974209752097620977209782097920980209812098220983209842098520986209872098820989209902099120992209932099420995209962099720998209992100021001210022100321004210052100621007210082100921010210112101221013210142101521016210172101821019210202102121022210232102421025210262102721028210292103021031210322103321034210352103621037210382103921040210412104221043210442104521046210472104821049210502105121052210532105421055210562105721058210592106021061210622106321064210652106621067210682106921070210712107221073210742107521076210772107821079210802108121082210832108421085210862108721088210892109021091210922109321094210952109621097210982109921100211012110221103211042110521106211072110821109211102111121112211132111421115211162111721118211192112021121211222112321124211252112621127211282112921130211312113221133211342113521136211372113821139211402114121142211432114421145211462114721148211492115021151211522115321154211552115621157211582115921160211612116221163211642116521166211672116821169211702117121172211732117421175211762117721178211792118021181211822118321184211852118621187211882118921190211912119221193211942119521196211972119821199212002120121202212032120421205212062120721208212092121021211212122121321214212152121621217212182121921220212212122221223212242122521226212272122821229212302123121232212332123421235212362123721238212392124021241212422124321244212452124621247212482124921250212512125221253212542125521256212572125821259212602126121262212632126421265212662126721268212692127021271212722127321274212752127621277212782127921280212812128221283212842128521286212872128821289212902129121292212932129421295212962129721298212992130021301213022130321304213052130621307213082130921310213112131221313213142131521316213172131821319213202132121322213232132421325213262132721328213292133021331213322133321334213352133621337213382133921340213412134221343213442134521346213472134821349213502135121352213532135421355213562135721358213592136021361213622136321364213652136621367213682136921370213712137221373213742137521376213772137821379213802138121382213832138421385213862138721388213892139021391213922139321394213952139621397213982139921400214012140221403214042140521406214072140821409214102141121412214132141421415214162141721418214192142021421214222142321424214252142621427214282142921430214312143221433214342143521436214372143821439214402144121442214432144421445214462144721448214492145021451214522145321454214552145621457214582145921460214612146221463214642146521466214672146821469214702147121472214732147421475214762147721478214792148021481214822148321484214852148621487214882148921490214912149221493214942149521496214972149821499215002150121502215032150421505215062150721508215092151021511215122151321514215152151621517215182151921520215212152221523215242152521526215272152821529215302153121532215332153421535215362153721538215392154021541215422154321544215452154621547215482154921550215512155221553215542155521556215572155821559215602156121562215632156421565215662156721568215692157021571215722157321574215752157621577215782157921580215812158221583215842158521586215872158821589215902159121592215932159421595215962159721598215992160021601216022160321604216052160621607216082160921610216112161221613216142161521616216172161821619216202162121622216232162421625216262162721628216292163021631216322163321634216352163621637216382163921640216412164221643216442164521646216472164821649216502165121652216532165421655216562165721658216592166021661216622166321664216652166621667216682166921670216712167221673216742167521676216772167821679216802168121682216832168421685216862168721688216892169021691216922169321694216952169621697216982169921700217012170221703217042170521706217072170821709217102171121712217132171421715217162171721718217192172021721217222172321724217252172621727217282172921730217312173221733217342173521736217372173821739217402174121742217432174421745217462174721748217492175021751217522175321754217552175621757217582175921760217612176221763217642176521766217672176821769217702177121772217732177421775217762177721778217792178021781217822178321784217852178621787217882178921790217912179221793217942179521796217972179821799218002180121802218032180421805218062180721808218092181021811218122181321814218152181621817218182181921820218212182221823218242182521826218272182821829218302183121832218332183421835218362183721838218392184021841218422184321844218452184621847218482184921850218512185221853218542185521856218572185821859218602186121862218632186421865218662186721868218692187021871218722187321874218752187621877218782187921880218812188221883218842188521886218872188821889218902189121892218932189421895218962189721898218992190021901219022190321904219052190621907219082190921910219112191221913219142191521916219172191821919219202192121922219232192421925219262192721928219292193021931219322193321934219352193621937219382193921940219412194221943219442194521946219472194821949219502195121952219532195421955219562195721958219592196021961219622196321964219652196621967219682196921970219712197221973219742197521976219772197821979219802198121982219832198421985219862198721988219892199021991219922199321994219952199621997219982199922000220012200222003220042200522006220072200822009220102201122012220132201422015220162201722018220192202022021220222202322024220252202622027220282202922030220312203222033220342203522036220372203822039220402204122042220432204422045220462204722048220492205022051220522205322054220552205622057220582205922060220612206222063220642206522066220672206822069220702207122072220732207422075220762207722078220792208022081220822208322084220852208622087220882208922090220912209222093220942209522096220972209822099221002210122102221032210422105221062210722108221092211022111221122211322114221152211622117221182211922120221212212222123221242212522126221272212822129221302213122132221332213422135221362213722138221392214022141221422214322144221452214622147221482214922150221512215222153221542215522156221572215822159221602216122162221632216422165221662216722168221692217022171221722217322174221752217622177221782217922180221812218222183221842218522186221872218822189221902219122192221932219422195221962219722198221992220022201222022220322204222052220622207222082220922210222112221222213222142221522216222172221822219222202222122222222232222422225222262222722228222292223022231222322223322234222352223622237222382223922240222412224222243222442224522246222472224822249222502225122252222532225422255222562225722258222592226022261222622226322264222652226622267222682226922270222712227222273222742227522276222772227822279222802228122282222832228422285222862228722288222892229022291222922229322294222952229622297222982229922300223012230222303223042230522306223072230822309223102231122312223132231422315223162231722318223192232022321223222232322324223252232622327223282232922330223312233222333223342233522336223372233822339223402234122342223432234422345223462234722348223492235022351223522235322354223552235622357223582235922360223612236222363223642236522366223672236822369223702237122372223732237422375223762237722378223792238022381223822238322384223852238622387223882238922390223912239222393223942239522396223972239822399224002240122402224032240422405224062240722408224092241022411224122241322414224152241622417224182241922420224212242222423224242242522426224272242822429224302243122432224332243422435224362243722438224392244022441224422244322444224452244622447224482244922450224512245222453224542245522456224572245822459224602246122462224632246422465224662246722468224692247022471224722247322474224752247622477224782247922480224812248222483224842248522486224872248822489224902249122492224932249422495224962249722498224992250022501225022250322504225052250622507225082250922510225112251222513225142251522516225172251822519225202252122522225232252422525225262252722528225292253022531225322253322534225352253622537225382253922540225412254222543225442254522546225472254822549225502255122552225532255422555225562255722558225592256022561225622256322564225652256622567225682256922570225712257222573225742257522576225772257822579225802258122582225832258422585225862258722588225892259022591225922259322594225952259622597225982259922600226012260222603226042260522606226072260822609226102261122612226132261422615226162261722618226192262022621226222262322624226252262622627226282262922630226312263222633226342263522636226372263822639226402264122642226432264422645226462264722648226492265022651226522265322654226552265622657226582265922660226612266222663226642266522666226672266822669226702267122672226732267422675226762267722678226792268022681226822268322684226852268622687226882268922690226912269222693226942269522696226972269822699227002270122702227032270422705227062270722708227092271022711227122271322714227152271622717227182271922720227212272222723227242272522726227272272822729227302273122732227332273422735227362273722738227392274022741227422274322744227452274622747227482274922750227512275222753227542275522756227572275822759227602276122762227632276422765227662276722768227692277022771227722277322774227752277622777227782277922780227812278222783227842278522786227872278822789227902279122792227932279422795227962279722798227992280022801228022280322804228052280622807228082280922810228112281222813228142281522816228172281822819228202282122822228232282422825228262282722828228292283022831228322283322834228352283622837228382283922840228412284222843228442284522846228472284822849228502285122852228532285422855228562285722858228592286022861228622286322864228652286622867228682286922870228712287222873228742287522876228772287822879228802288122882228832288422885228862288722888228892289022891228922289322894228952289622897228982289922900229012290222903229042290522906229072290822909229102291122912229132291422915229162291722918229192292022921229222292322924229252292622927229282292922930229312293222933229342293522936229372293822939229402294122942229432294422945229462294722948229492295022951229522295322954229552295622957229582295922960229612296222963229642296522966229672296822969229702297122972229732297422975229762297722978229792298022981229822298322984229852298622987229882298922990229912299222993229942299522996229972299822999230002300123002230032300423005230062300723008230092301023011230122301323014230152301623017230182301923020230212302223023230242302523026230272302823029230302303123032230332303423035230362303723038230392304023041230422304323044230452304623047230482304923050230512305223053230542305523056230572305823059230602306123062230632306423065230662306723068230692307023071230722307323074230752307623077230782307923080230812308223083230842308523086230872308823089230902309123092230932309423095230962309723098230992310023101231022310323104231052310623107231082310923110231112311223113231142311523116231172311823119231202312123122231232312423125231262312723128231292313023131231322313323134231352313623137231382313923140231412314223143231442314523146231472314823149231502315123152231532315423155231562315723158231592316023161231622316323164231652316623167231682316923170231712317223173231742317523176231772317823179231802318123182231832318423185231862318723188231892319023191231922319323194231952319623197231982319923200232012320223203232042320523206232072320823209232102321123212232132321423215232162321723218232192322023221232222322323224232252322623227232282322923230232312323223233232342323523236232372323823239232402324123242232432324423245232462324723248232492325023251232522325323254232552325623257232582325923260232612326223263232642326523266232672326823269232702327123272232732327423275232762327723278232792328023281232822328323284232852328623287232882328923290232912329223293232942329523296232972329823299233002330123302233032330423305233062330723308233092331023311233122331323314233152331623317233182331923320233212332223323233242332523326233272332823329233302333123332233332333423335233362333723338233392334023341233422334323344233452334623347233482334923350233512335223353233542335523356233572335823359233602336123362233632336423365233662336723368233692337023371233722337323374233752337623377233782337923380233812338223383233842338523386233872338823389233902339123392233932339423395233962339723398233992340023401234022340323404234052340623407234082340923410234112341223413234142341523416234172341823419234202342123422234232342423425234262342723428234292343023431234322343323434234352343623437234382343923440234412344223443234442344523446234472344823449234502345123452234532345423455234562345723458234592346023461234622346323464234652346623467234682346923470234712347223473234742347523476234772347823479234802348123482234832348423485234862348723488234892349023491234922349323494234952349623497234982349923500235012350223503235042350523506235072350823509235102351123512235132351423515235162351723518235192352023521235222352323524235252352623527235282352923530235312353223533235342353523536235372353823539235402354123542235432354423545235462354723548235492355023551235522355323554235552355623557235582355923560235612356223563235642356523566235672356823569235702357123572235732357423575235762357723578235792358023581235822358323584235852358623587235882358923590235912359223593235942359523596235972359823599236002360123602236032360423605236062360723608236092361023611236122361323614236152361623617236182361923620236212362223623236242362523626236272362823629236302363123632236332363423635236362363723638236392364023641236422364323644236452364623647236482364923650236512365223653236542365523656236572365823659236602366123662236632366423665236662366723668236692367023671236722367323674236752367623677236782367923680236812368223683236842368523686236872368823689236902369123692236932369423695236962369723698236992370023701237022370323704237052370623707237082370923710237112371223713237142371523716237172371823719237202372123722237232372423725237262372723728237292373023731237322373323734237352373623737237382373923740237412374223743237442374523746237472374823749237502375123752237532375423755237562375723758237592376023761237622376323764237652376623767237682376923770237712377223773237742377523776237772377823779237802378123782237832378423785237862378723788237892379023791237922379323794237952379623797237982379923800238012380223803238042380523806238072380823809238102381123812238132381423815238162381723818238192382023821238222382323824238252382623827238282382923830238312383223833238342383523836238372383823839238402384123842238432384423845238462384723848238492385023851238522385323854238552385623857238582385923860238612386223863238642386523866238672386823869238702387123872238732387423875238762387723878238792388023881238822388323884238852388623887238882388923890238912389223893238942389523896238972389823899239002390123902239032390423905239062390723908239092391023911239122391323914239152391623917239182391923920239212392223923239242392523926239272392823929239302393123932239332393423935239362393723938239392394023941239422394323944239452394623947239482394923950239512395223953239542395523956239572395823959239602396123962239632396423965239662396723968239692397023971239722397323974239752397623977239782397923980239812398223983239842398523986239872398823989239902399123992239932399423995239962399723998239992400024001240022400324004240052400624007240082400924010240112401224013240142401524016240172401824019240202402124022240232402424025240262402724028240292403024031240322403324034240352403624037240382403924040240412404224043240442404524046240472404824049240502405124052240532405424055240562405724058240592406024061240622406324064240652406624067240682406924070240712407224073240742407524076240772407824079240802408124082240832408424085240862408724088240892409024091240922409324094240952409624097240982409924100241012410224103241042410524106241072410824109241102411124112241132411424115241162411724118241192412024121241222412324124241252412624127241282412924130241312413224133241342413524136241372413824139241402414124142241432414424145241462414724148241492415024151241522415324154241552415624157241582415924160241612416224163241642416524166241672416824169241702417124172241732417424175241762417724178241792418024181241822418324184241852418624187241882418924190241912419224193241942419524196241972419824199242002420124202242032420424205242062420724208242092421024211242122421324214242152421624217242182421924220242212422224223242242422524226242272422824229242302423124232242332423424235242362423724238242392424024241242422424324244242452424624247242482424924250242512425224253242542425524256242572425824259242602426124262242632426424265242662426724268242692427024271242722427324274242752427624277242782427924280242812428224283242842428524286242872428824289242902429124292242932429424295242962429724298242992430024301243022430324304243052430624307243082430924310243112431224313243142431524316243172431824319243202432124322243232432424325243262432724328243292433024331243322433324334243352433624337243382433924340243412434224343243442434524346243472434824349243502435124352243532435424355243562435724358243592436024361243622436324364243652436624367243682436924370243712437224373243742437524376243772437824379243802438124382243832438424385243862438724388243892439024391243922439324394243952439624397243982439924400244012440224403244042440524406244072440824409244102441124412244132441424415244162441724418244192442024421244222442324424244252442624427244282442924430244312443224433244342443524436244372443824439244402444124442244432444424445244462444724448244492445024451244522445324454244552445624457244582445924460244612446224463244642446524466244672446824469244702447124472244732447424475244762447724478244792448024481244822448324484244852448624487244882448924490244912449224493244942449524496244972449824499245002450124502245032450424505245062450724508245092451024511245122451324514245152451624517245182451924520245212452224523245242452524526245272452824529245302453124532245332453424535245362453724538245392454024541245422454324544245452454624547245482454924550245512455224553245542455524556245572455824559245602456124562245632456424565245662456724568245692457024571245722457324574245752457624577245782457924580245812458224583245842458524586245872458824589245902459124592245932459424595245962459724598245992460024601246022460324604246052460624607246082460924610246112461224613246142461524616246172461824619246202462124622246232462424625246262462724628246292463024631246322463324634246352463624637246382463924640246412464224643246442464524646246472464824649246502465124652246532465424655246562465724658246592466024661246622466324664246652466624667246682466924670246712467224673246742467524676246772467824679246802468124682246832468424685246862468724688246892469024691246922469324694246952469624697246982469924700247012470224703247042470524706247072470824709247102471124712247132471424715247162471724718247192472024721247222472324724247252472624727247282472924730247312473224733247342473524736247372473824739247402474124742247432474424745247462474724748247492475024751247522475324754247552475624757247582475924760247612476224763247642476524766247672476824769247702477124772247732477424775247762477724778247792478024781247822478324784247852478624787247882478924790247912479224793247942479524796247972479824799248002480124802248032480424805248062480724808248092481024811248122481324814248152481624817248182481924820248212482224823248242482524826248272482824829248302483124832248332483424835248362483724838248392484024841248422484324844248452484624847248482484924850248512485224853248542485524856248572485824859248602486124862248632486424865248662486724868248692487024871248722487324874248752487624877248782487924880248812488224883248842488524886248872488824889248902489124892248932489424895248962489724898248992490024901249022490324904249052490624907249082490924910249112491224913249142491524916249172491824919249202492124922249232492424925249262492724928249292493024931249322493324934249352493624937249382493924940249412494224943249442494524946249472494824949249502495124952249532495424955249562495724958249592496024961249622496324964249652496624967249682496924970249712497224973249742497524976249772497824979249802498124982249832498424985249862498724988249892499024991249922499324994249952499624997249982499925000250012500225003250042500525006250072500825009250102501125012250132501425015250162501725018250192502025021250222502325024250252502625027250282502925030250312503225033250342503525036250372503825039250402504125042250432504425045250462504725048250492505025051250522505325054250552505625057250582505925060250612506225063250642506525066250672506825069250702507125072250732507425075250762507725078250792508025081250822508325084250852508625087250882508925090250912509225093250942509525096250972509825099251002510125102251032510425105251062510725108251092511025111251122511325114251152511625117251182511925120251212512225123251242512525126251272512825129251302513125132251332513425135251362513725138251392514025141251422514325144251452514625147251482514925150251512515225153251542515525156251572515825159251602516125162251632516425165251662516725168251692517025171251722517325174251752517625177251782517925180251812518225183251842518525186251872518825189251902519125192251932519425195251962519725198251992520025201252022520325204252052520625207252082520925210252112521225213252142521525216252172521825219252202522125222252232522425225252262522725228252292523025231252322523325234252352523625237252382523925240252412524225243252442524525246252472524825249252502525125252252532525425255252562525725258252592526025261252622526325264252652526625267252682526925270252712527225273252742527525276252772527825279252802528125282252832528425285252862528725288252892529025291252922529325294252952529625297252982529925300253012530225303253042530525306253072530825309253102531125312253132531425315253162531725318253192532025321253222532325324253252532625327253282532925330253312533225333253342533525336253372533825339253402534125342253432534425345253462534725348253492535025351253522535325354253552535625357253582535925360253612536225363253642536525366253672536825369253702537125372253732537425375253762537725378253792538025381253822538325384253852538625387253882538925390253912539225393253942539525396253972539825399254002540125402254032540425405254062540725408254092541025411254122541325414254152541625417254182541925420254212542225423254242542525426254272542825429254302543125432254332543425435254362543725438254392544025441254422544325444254452544625447254482544925450254512545225453254542545525456254572545825459254602546125462254632546425465254662546725468254692547025471254722547325474254752547625477254782547925480254812548225483254842548525486254872548825489254902549125492254932549425495254962549725498254992550025501255022550325504255052550625507255082550925510255112551225513255142551525516255172551825519255202552125522255232552425525255262552725528255292553025531255322553325534255352553625537255382553925540255412554225543255442554525546255472554825549255502555125552255532555425555255562555725558255592556025561255622556325564255652556625567255682556925570255712557225573255742557525576255772557825579255802558125582255832558425585255862558725588255892559025591255922559325594255952559625597255982559925600256012560225603256042560525606256072560825609256102561125612256132561425615256162561725618256192562025621256222562325624256252562625627256282562925630256312563225633256342563525636256372563825639256402564125642256432564425645256462564725648256492565025651256522565325654256552565625657256582565925660256612566225663256642566525666256672566825669256702567125672256732567425675256762567725678256792568025681256822568325684256852568625687256882568925690256912569225693256942569525696256972569825699257002570125702257032570425705257062570725708257092571025711257122571325714257152571625717257182571925720257212572225723257242572525726257272572825729257302573125732257332573425735257362573725738257392574025741257422574325744257452574625747257482574925750257512575225753257542575525756257572575825759257602576125762257632576425765257662576725768257692577025771257722577325774257752577625777257782577925780257812578225783257842578525786257872578825789257902579125792257932579425795257962579725798257992580025801258022580325804258052580625807258082580925810258112581225813258142581525816258172581825819258202582125822258232582425825258262582725828258292583025831258322583325834258352583625837258382583925840258412584225843258442584525846258472584825849258502585125852258532585425855258562585725858258592586025861258622586325864258652586625867258682586925870258712587225873258742587525876258772587825879258802588125882258832588425885258862588725888258892589025891258922589325894258952589625897258982589925900259012590225903259042590525906259072590825909259102591125912259132591425915259162591725918259192592025921259222592325924259252592625927259282592925930259312593225933259342593525936259372593825939259402594125942259432594425945259462594725948259492595025951259522595325954259552595625957259582595925960259612596225963259642596525966259672596825969259702597125972259732597425975259762597725978259792598025981259822598325984259852598625987259882598925990259912599225993259942599525996259972599825999260002600126002260032600426005260062600726008260092601026011260122601326014260152601626017260182601926020260212602226023260242602526026260272602826029260302603126032260332603426035260362603726038260392604026041260422604326044260452604626047260482604926050260512605226053260542605526056260572605826059260602606126062260632606426065260662606726068260692607026071260722607326074260752607626077260782607926080260812608226083260842608526086260872608826089260902609126092260932609426095260962609726098260992610026101261022610326104261052610626107261082610926110261112611226113261142611526116261172611826119261202612126122261232612426125261262612726128261292613026131261322613326134261352613626137261382613926140261412614226143261442614526146261472614826149261502615126152261532615426155261562615726158261592616026161261622616326164261652616626167261682616926170261712617226173261742617526176261772617826179261802618126182261832618426185261862618726188261892619026191261922619326194261952619626197261982619926200262012620226203262042620526206262072620826209262102621126212262132621426215262162621726218262192622026221262222622326224262252622626227262282622926230262312623226233262342623526236262372623826239262402624126242262432624426245262462624726248262492625026251262522625326254262552625626257262582625926260262612626226263262642626526266262672626826269262702627126272262732627426275262762627726278262792628026281262822628326284262852628626287262882628926290262912629226293262942629526296262972629826299263002630126302263032630426305263062630726308263092631026311263122631326314263152631626317263182631926320263212632226323263242632526326263272632826329263302633126332263332633426335263362633726338263392634026341263422634326344263452634626347263482634926350263512635226353263542635526356263572635826359263602636126362263632636426365263662636726368263692637026371263722637326374263752637626377263782637926380263812638226383263842638526386263872638826389263902639126392263932639426395263962639726398263992640026401264022640326404264052640626407264082640926410264112641226413264142641526416264172641826419264202642126422264232642426425264262642726428264292643026431264322643326434264352643626437264382643926440264412644226443264442644526446264472644826449264502645126452264532645426455264562645726458264592646026461264622646326464264652646626467264682646926470264712647226473264742647526476264772647826479264802648126482264832648426485264862648726488264892649026491264922649326494264952649626497264982649926500265012650226503265042650526506265072650826509265102651126512265132651426515265162651726518265192652026521265222652326524265252652626527265282652926530265312653226533265342653526536265372653826539265402654126542265432654426545265462654726548265492655026551265522655326554265552655626557265582655926560265612656226563265642656526566265672656826569265702657126572265732657426575265762657726578265792658026581265822658326584265852658626587265882658926590265912659226593265942659526596265972659826599266002660126602266032660426605266062660726608266092661026611266122661326614266152661626617266182661926620266212662226623266242662526626266272662826629266302663126632266332663426635266362663726638266392664026641266422664326644266452664626647266482664926650266512665226653266542665526656266572665826659266602666126662266632666426665266662666726668266692667026671266722667326674266752667626677266782667926680266812668226683266842668526686266872668826689266902669126692266932669426695266962669726698266992670026701267022670326704267052670626707267082670926710267112671226713267142671526716267172671826719267202672126722267232672426725267262672726728267292673026731267322673326734267352673626737267382673926740267412674226743267442674526746267472674826749267502675126752267532675426755267562675726758267592676026761267622676326764267652676626767267682676926770267712677226773267742677526776267772677826779267802678126782267832678426785267862678726788267892679026791267922679326794267952679626797267982679926800268012680226803268042680526806268072680826809268102681126812268132681426815268162681726818268192682026821268222682326824268252682626827268282682926830268312683226833268342683526836268372683826839268402684126842268432684426845268462684726848268492685026851268522685326854268552685626857268582685926860268612686226863268642686526866268672686826869268702687126872268732687426875268762687726878268792688026881268822688326884268852688626887268882688926890268912689226893268942689526896268972689826899269002690126902269032690426905269062690726908269092691026911269122691326914269152691626917269182691926920269212692226923269242692526926269272692826929269302693126932269332693426935269362693726938269392694026941269422694326944269452694626947269482694926950269512695226953269542695526956269572695826959269602696126962269632696426965269662696726968269692697026971269722697326974269752697626977269782697926980269812698226983269842698526986269872698826989269902699126992269932699426995269962699726998269992700027001270022700327004270052700627007270082700927010270112701227013270142701527016270172701827019270202702127022270232702427025270262702727028270292703027031270322703327034270352703627037270382703927040270412704227043270442704527046270472704827049270502705127052270532705427055270562705727058270592706027061270622706327064270652706627067270682706927070270712707227073270742707527076270772707827079270802708127082270832708427085270862708727088270892709027091270922709327094270952709627097270982709927100271012710227103271042710527106271072710827109271102711127112271132711427115271162711727118271192712027121271222712327124271252712627127271282712927130271312713227133271342713527136271372713827139271402714127142271432714427145271462714727148271492715027151271522715327154271552715627157271582715927160271612716227163271642716527166271672716827169271702717127172271732717427175271762717727178271792718027181271822718327184271852718627187271882718927190271912719227193271942719527196271972719827199272002720127202272032720427205272062720727208272092721027211272122721327214272152721627217272182721927220272212722227223272242722527226272272722827229272302723127232272332723427235272362723727238272392724027241272422724327244272452724627247272482724927250272512725227253272542725527256272572725827259272602726127262272632726427265272662726727268272692727027271272722727327274272752727627277272782727927280272812728227283272842728527286272872728827289272902729127292272932729427295272962729727298272992730027301273022730327304273052730627307273082730927310273112731227313273142731527316273172731827319273202732127322273232732427325273262732727328273292733027331273322733327334273352733627337273382733927340273412734227343273442734527346273472734827349273502735127352273532735427355273562735727358273592736027361273622736327364273652736627367273682736927370273712737227373273742737527376273772737827379273802738127382273832738427385273862738727388273892739027391273922739327394273952739627397273982739927400274012740227403274042740527406274072740827409274102741127412274132741427415274162741727418274192742027421274222742327424274252742627427274282742927430274312743227433274342743527436274372743827439274402744127442274432744427445274462744727448274492745027451274522745327454274552745627457274582745927460274612746227463274642746527466274672746827469274702747127472274732747427475274762747727478274792748027481274822748327484274852748627487274882748927490274912749227493274942749527496274972749827499275002750127502275032750427505275062750727508275092751027511275122751327514275152751627517275182751927520275212752227523275242752527526275272752827529275302753127532275332753427535275362753727538275392754027541275422754327544275452754627547275482754927550275512755227553275542755527556275572755827559275602756127562275632756427565275662756727568275692757027571275722757327574275752757627577275782757927580275812758227583275842758527586275872758827589275902759127592275932759427595275962759727598275992760027601276022760327604276052760627607276082760927610276112761227613276142761527616276172761827619276202762127622276232762427625276262762727628276292763027631276322763327634276352763627637276382763927640276412764227643276442764527646276472764827649276502765127652276532765427655276562765727658276592766027661276622766327664276652766627667276682766927670276712767227673276742767527676276772767827679276802768127682276832768427685276862768727688276892769027691276922769327694276952769627697276982769927700277012770227703277042770527706277072770827709277102771127712277132771427715277162771727718277192772027721277222772327724277252772627727277282772927730277312773227733277342773527736277372773827739277402774127742277432774427745277462774727748277492775027751277522775327754277552775627757277582775927760277612776227763277642776527766277672776827769277702777127772277732777427775277762777727778277792778027781277822778327784277852778627787277882778927790277912779227793277942779527796277972779827799278002780127802278032780427805278062780727808278092781027811278122781327814278152781627817278182781927820278212782227823278242782527826278272782827829278302783127832278332783427835278362783727838278392784027841278422784327844278452784627847278482784927850278512785227853278542785527856278572785827859278602786127862278632786427865278662786727868278692787027871278722787327874278752787627877278782787927880278812788227883278842788527886278872788827889278902789127892278932789427895278962789727898278992790027901279022790327904279052790627907279082790927910279112791227913279142791527916279172791827919279202792127922279232792427925279262792727928279292793027931279322793327934279352793627937279382793927940279412794227943279442794527946279472794827949279502795127952279532795427955279562795727958279592796027961279622796327964279652796627967279682796927970279712797227973279742797527976279772797827979279802798127982279832798427985279862798727988279892799027991279922799327994279952799627997279982799928000280012800228003280042800528006280072800828009280102801128012280132801428015280162801728018280192802028021280222802328024280252802628027280282802928030280312803228033280342803528036280372803828039280402804128042280432804428045280462804728048280492805028051280522805328054280552805628057280582805928060280612806228063280642806528066280672806828069280702807128072280732807428075280762807728078280792808028081280822808328084280852808628087280882808928090280912809228093280942809528096280972809828099281002810128102281032810428105281062810728108281092811028111281122811328114281152811628117281182811928120281212812228123281242812528126281272812828129281302813128132281332813428135281362813728138281392814028141281422814328144281452814628147281482814928150281512815228153281542815528156281572815828159281602816128162281632816428165281662816728168281692817028171281722817328174281752817628177281782817928180281812818228183281842818528186281872818828189281902819128192281932819428195281962819728198281992820028201282022820328204282052820628207282082820928210282112821228213282142821528216282172821828219282202822128222282232822428225282262822728228282292823028231282322823328234282352823628237282382823928240282412824228243282442824528246282472824828249282502825128252282532825428255282562825728258282592826028261282622826328264282652826628267282682826928270282712827228273282742827528276282772827828279282802828128282282832828428285282862828728288282892829028291282922829328294282952829628297282982829928300283012830228303283042830528306283072830828309283102831128312283132831428315283162831728318283192832028321283222832328324283252832628327283282832928330283312833228333283342833528336283372833828339283402834128342283432834428345283462834728348283492835028351283522835328354283552835628357283582835928360283612836228363283642836528366283672836828369283702837128372283732837428375283762837728378283792838028381283822838328384283852838628387283882838928390283912839228393283942839528396283972839828399284002840128402284032840428405284062840728408284092841028411284122841328414284152841628417284182841928420284212842228423284242842528426284272842828429284302843128432284332843428435284362843728438284392844028441284422844328444284452844628447284482844928450284512845228453284542845528456284572845828459284602846128462284632846428465284662846728468284692847028471284722847328474284752847628477284782847928480284812848228483284842848528486284872848828489284902849128492284932849428495284962849728498284992850028501285022850328504285052850628507285082850928510285112851228513285142851528516285172851828519285202852128522285232852428525285262852728528285292853028531285322853328534285352853628537285382853928540285412854228543285442854528546285472854828549285502855128552285532855428555285562855728558285592856028561285622856328564285652856628567285682856928570285712857228573285742857528576285772857828579285802858128582285832858428585285862858728588285892859028591285922859328594285952859628597285982859928600286012860228603286042860528606286072860828609286102861128612286132861428615286162861728618286192862028621286222862328624286252862628627286282862928630286312863228633286342863528636286372863828639286402864128642286432864428645286462864728648286492865028651286522865328654286552865628657286582865928660286612866228663286642866528666286672866828669286702867128672286732867428675286762867728678286792868028681286822868328684286852868628687286882868928690286912869228693286942869528696286972869828699287002870128702287032870428705287062870728708287092871028711287122871328714287152871628717287182871928720287212872228723287242872528726287272872828729287302873128732287332873428735287362873728738287392874028741287422874328744287452874628747287482874928750287512875228753287542875528756287572875828759287602876128762287632876428765287662876728768287692877028771287722877328774287752877628777287782877928780287812878228783287842878528786287872878828789287902879128792287932879428795287962879728798287992880028801288022880328804288052880628807288082880928810288112881228813288142881528816288172881828819288202882128822288232882428825288262882728828288292883028831288322883328834288352883628837288382883928840288412884228843288442884528846288472884828849288502885128852288532885428855288562885728858288592886028861288622886328864288652886628867288682886928870288712887228873288742887528876288772887828879288802888128882288832888428885288862888728888288892889028891288922889328894288952889628897288982889928900289012890228903289042890528906289072890828909289102891128912289132891428915289162891728918289192892028921289222892328924289252892628927289282892928930289312893228933289342893528936289372893828939289402894128942289432894428945289462894728948289492895028951289522895328954289552895628957289582895928960289612896228963289642896528966289672896828969289702897128972289732897428975289762897728978289792898028981289822898328984289852898628987289882898928990289912899228993289942899528996289972899828999290002900129002290032900429005290062900729008290092901029011290122901329014290152901629017290182901929020290212902229023290242902529026290272902829029290302903129032290332903429035290362903729038290392904029041290422904329044290452904629047290482904929050290512905229053290542905529056290572905829059290602906129062290632906429065290662906729068290692907029071290722907329074290752907629077290782907929080290812908229083290842908529086290872908829089290902909129092290932909429095290962909729098290992910029101291022910329104291052910629107291082910929110291112911229113291142911529116291172911829119291202912129122291232912429125291262912729128291292913029131291322913329134291352913629137291382913929140291412914229143291442914529146291472914829149291502915129152291532915429155291562915729158291592916029161291622916329164291652916629167291682916929170291712917229173291742917529176291772917829179291802918129182291832918429185291862918729188291892919029191291922919329194291952919629197291982919929200292012920229203292042920529206292072920829209292102921129212292132921429215292162921729218292192922029221292222922329224292252922629227292282922929230292312923229233292342923529236292372923829239292402924129242292432924429245292462924729248292492925029251292522925329254292552925629257292582925929260292612926229263292642926529266292672926829269292702927129272292732927429275292762927729278292792928029281292822928329284292852928629287292882928929290292912929229293292942929529296292972929829299293002930129302293032930429305293062930729308293092931029311293122931329314293152931629317293182931929320293212932229323293242932529326293272932829329293302933129332293332933429335293362933729338293392934029341293422934329344293452934629347293482934929350293512935229353293542935529356293572935829359293602936129362293632936429365293662936729368293692937029371293722937329374293752937629377293782937929380293812938229383293842938529386293872938829389293902939129392293932939429395293962939729398293992940029401294022940329404294052940629407294082940929410294112941229413294142941529416294172941829419294202942129422294232942429425294262942729428294292943029431294322943329434294352943629437294382943929440294412944229443294442944529446294472944829449294502945129452294532945429455294562945729458294592946029461294622946329464294652946629467294682946929470294712947229473294742947529476294772947829479294802948129482294832948429485294862948729488294892949029491294922949329494294952949629497294982949929500295012950229503295042950529506295072950829509295102951129512295132951429515295162951729518295192952029521295222952329524295252952629527295282952929530295312953229533295342953529536295372953829539295402954129542295432954429545295462954729548295492955029551295522955329554295552955629557295582955929560295612956229563295642956529566295672956829569295702957129572295732957429575295762957729578295792958029581295822958329584295852958629587295882958929590295912959229593295942959529596295972959829599296002960129602296032960429605296062960729608296092961029611296122961329614296152961629617296182961929620296212962229623296242962529626296272962829629296302963129632296332963429635296362963729638296392964029641296422964329644296452964629647296482964929650296512965229653296542965529656296572965829659296602966129662296632966429665296662966729668296692967029671296722967329674296752967629677296782967929680296812968229683296842968529686296872968829689296902969129692296932969429695296962969729698296992970029701297022970329704297052970629707297082970929710297112971229713297142971529716297172971829719297202972129722297232972429725297262972729728297292973029731297322973329734297352973629737297382973929740297412974229743297442974529746297472974829749297502975129752297532975429755297562975729758297592976029761297622976329764297652976629767297682976929770297712977229773297742977529776297772977829779297802978129782297832978429785297862978729788297892979029791297922979329794297952979629797297982979929800298012980229803298042980529806298072980829809298102981129812298132981429815298162981729818298192982029821298222982329824298252982629827298282982929830298312983229833298342983529836298372983829839298402984129842298432984429845298462984729848298492985029851298522985329854298552985629857298582985929860298612986229863298642986529866298672986829869298702987129872298732987429875298762987729878298792988029881298822988329884298852988629887298882988929890298912989229893298942989529896298972989829899299002990129902299032990429905299062990729908299092991029911299122991329914299152991629917299182991929920299212992229923299242992529926299272992829929299302993129932299332993429935299362993729938299392994029941299422994329944299452994629947299482994929950299512995229953299542995529956299572995829959299602996129962299632996429965299662996729968299692997029971299722997329974299752997629977299782997929980299812998229983299842998529986299872998829989299902999129992299932999429995299962999729998299993000030001300023000330004300053000630007300083000930010300113001230013300143001530016300173001830019300203002130022300233002430025300263002730028300293003030031300323003330034300353003630037300383003930040300413004230043300443004530046300473004830049300503005130052300533005430055300563005730058300593006030061300623006330064300653006630067300683006930070300713007230073300743007530076300773007830079300803008130082300833008430085300863008730088300893009030091300923009330094300953009630097300983009930100301013010230103301043010530106301073010830109301103011130112301133011430115301163011730118301193012030121301223012330124301253012630127301283012930130301313013230133301343013530136301373013830139301403014130142301433014430145301463014730148301493015030151301523015330154301553015630157301583015930160301613016230163301643016530166301673016830169301703017130172301733017430175301763017730178301793018030181301823018330184301853018630187301883018930190301913019230193301943019530196301973019830199302003020130202302033020430205302063020730208302093021030211302123021330214302153021630217302183021930220302213022230223302243022530226302273022830229302303023130232302333023430235302363023730238302393024030241302423024330244302453024630247302483024930250302513025230253302543025530256302573025830259302603026130262302633026430265302663026730268302693027030271302723027330274302753027630277302783027930280302813028230283302843028530286302873028830289302903029130292302933029430295302963029730298302993030030301303023030330304303053030630307303083030930310303113031230313303143031530316303173031830319303203032130322303233032430325303263032730328303293033030331303323033330334303353033630337303383033930340303413034230343303443034530346303473034830349303503035130352303533035430355303563035730358303593036030361303623036330364303653036630367303683036930370303713037230373303743037530376303773037830379303803038130382303833038430385303863038730388303893039030391303923039330394303953039630397303983039930400304013040230403304043040530406304073040830409304103041130412304133041430415304163041730418304193042030421304223042330424304253042630427304283042930430304313043230433304343043530436304373043830439304403044130442304433044430445304463044730448304493045030451304523045330454304553045630457304583045930460304613046230463304643046530466304673046830469304703047130472304733047430475304763047730478304793048030481304823048330484304853048630487304883048930490304913049230493304943049530496304973049830499305003050130502305033050430505305063050730508305093051030511305123051330514305153051630517305183051930520305213052230523305243052530526305273052830529305303053130532305333053430535305363053730538305393054030541305423054330544305453054630547305483054930550305513055230553305543055530556305573055830559305603056130562305633056430565305663056730568305693057030571305723057330574305753057630577305783057930580305813058230583305843058530586305873058830589305903059130592305933059430595305963059730598305993060030601306023060330604306053060630607306083060930610306113061230613306143061530616306173061830619306203062130622306233062430625306263062730628306293063030631306323063330634306353063630637306383063930640306413064230643306443064530646306473064830649306503065130652306533065430655306563065730658306593066030661306623066330664306653066630667306683066930670306713067230673306743067530676306773067830679306803068130682306833068430685306863068730688306893069030691306923069330694306953069630697306983069930700307013070230703307043070530706307073070830709307103071130712307133071430715307163071730718307193072030721307223072330724307253072630727307283072930730307313073230733307343073530736307373073830739307403074130742307433074430745307463074730748307493075030751307523075330754307553075630757307583075930760307613076230763307643076530766307673076830769307703077130772307733077430775307763077730778307793078030781307823078330784307853078630787307883078930790307913079230793307943079530796307973079830799308003080130802308033080430805308063080730808308093081030811308123081330814308153081630817308183081930820308213082230823308243082530826308273082830829308303083130832308333083430835308363083730838308393084030841308423084330844308453084630847308483084930850308513085230853308543085530856308573085830859308603086130862308633086430865308663086730868308693087030871308723087330874308753087630877308783087930880308813088230883308843088530886308873088830889308903089130892308933089430895308963089730898308993090030901309023090330904309053090630907309083090930910309113091230913309143091530916309173091830919309203092130922309233092430925309263092730928309293093030931309323093330934309353093630937309383093930940309413094230943309443094530946309473094830949309503095130952309533095430955309563095730958309593096030961309623096330964309653096630967309683096930970309713097230973309743097530976309773097830979309803098130982309833098430985309863098730988309893099030991309923099330994309953099630997309983099931000310013100231003310043100531006310073100831009310103101131012310133101431015310163101731018310193102031021310223102331024310253102631027310283102931030310313103231033310343103531036310373103831039310403104131042310433104431045310463104731048310493105031051310523105331054310553105631057310583105931060310613106231063310643106531066310673106831069310703107131072310733107431075310763107731078310793108031081310823108331084310853108631087310883108931090310913109231093310943109531096310973109831099311003110131102311033110431105311063110731108311093111031111311123111331114311153111631117311183111931120311213112231123311243112531126311273112831129311303113131132311333113431135311363113731138311393114031141311423114331144311453114631147311483114931150311513115231153311543115531156311573115831159311603116131162311633116431165311663116731168311693117031171311723117331174311753117631177311783117931180311813118231183311843118531186311873118831189311903119131192311933119431195311963119731198311993120031201312023120331204312053120631207312083120931210312113121231213312143121531216312173121831219312203122131222312233122431225312263122731228312293123031231312323123331234312353123631237312383123931240312413124231243312443124531246312473124831249312503125131252312533125431255312563125731258312593126031261312623126331264312653126631267312683126931270312713127231273312743127531276312773127831279312803128131282312833128431285312863128731288312893129031291312923129331294312953129631297312983129931300313013130231303313043130531306313073130831309313103131131312313133131431315313163131731318313193132031321313223132331324313253132631327313283132931330313313133231333313343133531336313373133831339313403134131342313433134431345313463134731348313493135031351313523135331354313553135631357313583135931360313613136231363313643136531366313673136831369313703137131372313733137431375313763137731378313793138031381313823138331384313853138631387313883138931390313913139231393313943139531396313973139831399314003140131402314033140431405314063140731408314093141031411314123141331414314153141631417314183141931420314213142231423314243142531426314273142831429314303143131432314333143431435314363143731438314393144031441314423144331444314453144631447314483144931450314513145231453314543145531456314573145831459314603146131462314633146431465314663146731468314693147031471314723147331474314753147631477314783147931480314813148231483314843148531486314873148831489314903149131492314933149431495314963149731498314993150031501315023150331504315053150631507315083150931510315113151231513315143151531516315173151831519315203152131522315233152431525315263152731528315293153031531315323153331534315353153631537315383153931540315413154231543315443154531546315473154831549315503155131552315533155431555315563155731558315593156031561315623156331564315653156631567315683156931570315713157231573315743157531576315773157831579315803158131582315833158431585315863158731588315893159031591315923159331594315953159631597315983159931600316013160231603316043160531606316073160831609316103161131612316133161431615316163161731618316193162031621316223162331624316253162631627316283162931630316313163231633316343163531636316373163831639316403164131642316433164431645316463164731648316493165031651316523165331654316553165631657316583165931660316613166231663316643166531666316673166831669316703167131672316733167431675316763167731678316793168031681316823168331684316853168631687316883168931690316913169231693316943169531696316973169831699317003170131702317033170431705317063170731708317093171031711317123171331714317153171631717317183171931720317213172231723317243172531726317273172831729317303173131732317333173431735317363173731738317393174031741317423174331744317453174631747317483174931750317513175231753317543175531756317573175831759317603176131762317633176431765317663176731768317693177031771317723177331774317753177631777317783177931780317813178231783317843178531786317873178831789317903179131792317933179431795317963179731798317993180031801318023180331804318053180631807318083180931810318113181231813318143181531816318173181831819318203182131822318233182431825318263182731828318293183031831318323183331834318353183631837318383183931840318413184231843318443184531846318473184831849318503185131852318533185431855318563185731858318593186031861318623186331864318653186631867318683186931870318713187231873318743187531876318773187831879318803188131882318833188431885318863188731888318893189031891318923189331894318953189631897318983189931900319013190231903319043190531906319073190831909319103191131912319133191431915319163191731918319193192031921319223192331924319253192631927319283192931930319313193231933319343193531936319373193831939319403194131942319433194431945319463194731948319493195031951319523195331954319553195631957319583195931960319613196231963319643196531966319673196831969319703197131972319733197431975319763197731978319793198031981319823198331984319853198631987319883198931990319913199231993319943199531996319973199831999320003200132002320033200432005320063200732008320093201032011320123201332014320153201632017320183201932020320213202232023320243202532026320273202832029320303203132032320333203432035320363203732038320393204032041320423204332044320453204632047320483204932050320513205232053320543205532056320573205832059320603206132062320633206432065320663206732068320693207032071320723207332074320753207632077320783207932080320813208232083320843208532086320873208832089320903209132092320933209432095320963209732098320993210032101321023210332104321053210632107321083210932110321113211232113321143211532116321173211832119321203212132122321233212432125321263212732128321293213032131321323213332134321353213632137321383213932140321413214232143321443214532146321473214832149321503215132152321533215432155321563215732158321593216032161321623216332164321653216632167321683216932170321713217232173321743217532176321773217832179321803218132182321833218432185321863218732188321893219032191321923219332194321953219632197321983219932200322013220232203322043220532206322073220832209322103221132212322133221432215322163221732218322193222032221322223222332224322253222632227322283222932230322313223232233322343223532236322373223832239322403224132242322433224432245322463224732248322493225032251322523225332254322553225632257322583225932260322613226232263322643226532266322673226832269322703227132272322733227432275322763227732278322793228032281322823228332284322853228632287322883228932290322913229232293322943229532296322973229832299323003230132302323033230432305323063230732308323093231032311323123231332314323153231632317323183231932320323213232232323323243232532326323273232832329323303233132332323333233432335323363233732338323393234032341323423234332344323453234632347323483234932350323513235232353323543235532356323573235832359323603236132362323633236432365323663236732368323693237032371323723237332374323753237632377323783237932380323813238232383323843238532386323873238832389323903239132392323933239432395323963239732398323993240032401324023240332404324053240632407324083240932410324113241232413324143241532416324173241832419324203242132422324233242432425324263242732428324293243032431324323243332434324353243632437324383243932440324413244232443324443244532446324473244832449324503245132452324533245432455324563245732458324593246032461324623246332464324653246632467324683246932470324713247232473324743247532476324773247832479324803248132482324833248432485324863248732488324893249032491324923249332494324953249632497324983249932500325013250232503325043250532506325073250832509325103251132512325133251432515325163251732518325193252032521325223252332524325253252632527325283252932530325313253232533325343253532536325373253832539325403254132542325433254432545325463254732548325493255032551325523255332554325553255632557325583255932560325613256232563325643256532566325673256832569325703257132572325733257432575325763257732578325793258032581325823258332584325853258632587325883258932590325913259232593325943259532596325973259832599326003260132602326033260432605326063260732608326093261032611326123261332614326153261632617326183261932620326213262232623
  1. apiVersion: apiextensions.k8s.io/v1
  2. kind: CustomResourceDefinition
  3. metadata:
  4. annotations:
  5. controller-gen.kubebuilder.io/version: v0.19.0
  6. labels:
  7. external-secrets.io/component: controller
  8. name: clusterexternalsecrets.external-secrets.io
  9. spec:
  10. group: external-secrets.io
  11. names:
  12. categories:
  13. - external-secrets
  14. kind: ClusterExternalSecret
  15. listKind: ClusterExternalSecretList
  16. plural: clusterexternalsecrets
  17. shortNames:
  18. - ces
  19. singular: clusterexternalsecret
  20. scope: Cluster
  21. versions:
  22. - additionalPrinterColumns:
  23. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  24. name: Store
  25. type: string
  26. - jsonPath: .spec.refreshTime
  27. name: Refresh Interval
  28. type: string
  29. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  30. name: Ready
  31. type: string
  32. name: v1
  33. schema:
  34. openAPIV3Schema:
  35. description: ClusterExternalSecret is the Schema for the clusterexternalsecrets API.
  36. properties:
  37. apiVersion:
  38. description: |-
  39. APIVersion defines the versioned schema of this representation of an object.
  40. Servers should convert recognized schemas to the latest internal value, and
  41. may reject unrecognized values.
  42. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  43. type: string
  44. kind:
  45. description: |-
  46. Kind is a string value representing the REST resource this object represents.
  47. Servers may infer this from the endpoint the client submits requests to.
  48. Cannot be updated.
  49. In CamelCase.
  50. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  51. type: string
  52. metadata:
  53. type: object
  54. spec:
  55. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  56. properties:
  57. externalSecretMetadata:
  58. description: The metadata of the external secrets to be created
  59. properties:
  60. annotations:
  61. additionalProperties:
  62. type: string
  63. type: object
  64. labels:
  65. additionalProperties:
  66. type: string
  67. type: object
  68. type: object
  69. externalSecretName:
  70. description: |-
  71. The name of the external secrets to be created.
  72. Defaults to the name of the ClusterExternalSecret
  73. maxLength: 253
  74. minLength: 1
  75. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  76. type: string
  77. externalSecretSpec:
  78. description: The spec for the ExternalSecrets to be created
  79. properties:
  80. data:
  81. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  82. items:
  83. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  84. properties:
  85. remoteRef:
  86. description: |-
  87. RemoteRef points to the remote secret and defines
  88. which secret (version/property/..) to fetch.
  89. properties:
  90. conversionStrategy:
  91. default: Default
  92. description: Used to define a conversion Strategy
  93. enum:
  94. - Default
  95. - Unicode
  96. type: string
  97. decodingStrategy:
  98. default: None
  99. description: Used to define a decoding Strategy
  100. enum:
  101. - Auto
  102. - Base64
  103. - Base64URL
  104. - None
  105. type: string
  106. key:
  107. description: Key is the key used in the Provider, mandatory
  108. type: string
  109. metadataPolicy:
  110. default: None
  111. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  112. enum:
  113. - None
  114. - Fetch
  115. type: string
  116. nullBytePolicy:
  117. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  118. enum:
  119. - Ignore
  120. - Fail
  121. type: string
  122. property:
  123. description: Used to select a specific property of the Provider value (if a map), if supported
  124. type: string
  125. version:
  126. description: Used to select a specific version of the Provider value, if supported
  127. type: string
  128. required:
  129. - key
  130. type: object
  131. secretKey:
  132. description: The key in the Kubernetes Secret to store the value.
  133. maxLength: 253
  134. minLength: 1
  135. pattern: ^[-._a-zA-Z0-9]+$
  136. type: string
  137. sourceRef:
  138. description: |-
  139. SourceRef allows you to override the source
  140. from which the value will be pulled.
  141. maxProperties: 1
  142. minProperties: 1
  143. properties:
  144. generatorRef:
  145. description: |-
  146. GeneratorRef points to a generator custom resource.
  147. Deprecated: The generatorRef is not implemented in .data[].
  148. this will be removed with v1.
  149. properties:
  150. apiVersion:
  151. default: generators.external-secrets.io/v1alpha1
  152. description: Specify the apiVersion of the generator resource
  153. type: string
  154. kind:
  155. description: Specify the Kind of the generator resource
  156. enum:
  157. - ACRAccessToken
  158. - BeyondtrustWorkloadCredentialsDynamicSecret
  159. - ClusterGenerator
  160. - CloudsmithAccessToken
  161. - ECRAuthorizationToken
  162. - Fake
  163. - GCRAccessToken
  164. - GithubAccessToken
  165. - GitlabDeployToken
  166. - QuayAccessToken
  167. - Password
  168. - SSHKey
  169. - STSSessionToken
  170. - UUID
  171. - VaultDynamicSecret
  172. - Webhook
  173. - Grafana
  174. - MFA
  175. type: string
  176. name:
  177. description: Specify the name of the generator resource
  178. maxLength: 253
  179. minLength: 1
  180. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  181. type: string
  182. required:
  183. - kind
  184. - name
  185. type: object
  186. storeRef:
  187. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  188. properties:
  189. kind:
  190. description: |-
  191. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  192. Defaults to `SecretStore`
  193. enum:
  194. - SecretStore
  195. - ClusterSecretStore
  196. type: string
  197. name:
  198. description: Name of the SecretStore resource
  199. maxLength: 253
  200. minLength: 1
  201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  202. type: string
  203. type: object
  204. type: object
  205. required:
  206. - remoteRef
  207. - secretKey
  208. type: object
  209. type: array
  210. dataFrom:
  211. description: |-
  212. DataFrom is used to fetch all properties from a specific Provider data
  213. If multiple entries are specified, the Secret keys are merged in the specified order
  214. items:
  215. description: |-
  216. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  217. when using DataFrom to fetch multiple values from a Provider.
  218. properties:
  219. extract:
  220. description: |-
  221. Used to extract multiple key/value pairs from one secret
  222. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  223. properties:
  224. conversionStrategy:
  225. default: Default
  226. description: Used to define a conversion Strategy
  227. enum:
  228. - Default
  229. - Unicode
  230. type: string
  231. decodingStrategy:
  232. default: None
  233. description: Used to define a decoding Strategy
  234. enum:
  235. - Auto
  236. - Base64
  237. - Base64URL
  238. - None
  239. type: string
  240. key:
  241. description: Key is the key used in the Provider, mandatory
  242. type: string
  243. metadataPolicy:
  244. default: None
  245. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  246. enum:
  247. - None
  248. - Fetch
  249. type: string
  250. nullBytePolicy:
  251. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  252. enum:
  253. - Ignore
  254. - Fail
  255. type: string
  256. property:
  257. description: Used to select a specific property of the Provider value (if a map), if supported
  258. type: string
  259. version:
  260. description: Used to select a specific version of the Provider value, if supported
  261. type: string
  262. required:
  263. - key
  264. type: object
  265. find:
  266. description: |-
  267. Used to find secrets based on tags or regular expressions
  268. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  269. properties:
  270. conversionStrategy:
  271. default: Default
  272. description: Used to define a conversion Strategy
  273. enum:
  274. - Default
  275. - Unicode
  276. type: string
  277. decodingStrategy:
  278. default: None
  279. description: Used to define a decoding Strategy
  280. enum:
  281. - Auto
  282. - Base64
  283. - Base64URL
  284. - None
  285. type: string
  286. name:
  287. description: Finds secrets based on the name.
  288. properties:
  289. regexp:
  290. description: Finds secrets base
  291. type: string
  292. type: object
  293. nullBytePolicy:
  294. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  295. enum:
  296. - Ignore
  297. - Fail
  298. type: string
  299. path:
  300. description: A root path to start the find operations.
  301. type: string
  302. tags:
  303. additionalProperties:
  304. type: string
  305. description: Find secrets based on tags.
  306. type: object
  307. type: object
  308. rewrite:
  309. description: |-
  310. Used to rewrite secret Keys after getting them from the secret Provider
  311. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  312. items:
  313. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  314. maxProperties: 1
  315. minProperties: 1
  316. properties:
  317. merge:
  318. description: |-
  319. Used to merge key/values in one single Secret
  320. The resulting key will contain all values from the specified secrets
  321. properties:
  322. conflictPolicy:
  323. default: Error
  324. description: Used to define the policy to use in conflict resolution.
  325. enum:
  326. - Ignore
  327. - Error
  328. type: string
  329. into:
  330. default: ""
  331. description: |-
  332. Used to define the target key of the merge operation.
  333. Required if strategy is JSON. Ignored otherwise.
  334. type: string
  335. priority:
  336. description: Used to define key priority in conflict resolution.
  337. items:
  338. type: string
  339. type: array
  340. priorityPolicy:
  341. default: Strict
  342. description: Used to define the policy when a key in the priority list does not exist in the input.
  343. enum:
  344. - IgnoreNotFound
  345. - Strict
  346. type: string
  347. strategy:
  348. default: Extract
  349. description: Used to define the strategy to use in the merge operation.
  350. enum:
  351. - Extract
  352. - JSON
  353. type: string
  354. type: object
  355. regexp:
  356. description: |-
  357. Used to rewrite with regular expressions.
  358. The resulting key will be the output of a regexp.ReplaceAll operation.
  359. properties:
  360. source:
  361. description: Used to define the regular expression of a re.Compiler.
  362. type: string
  363. target:
  364. description: Used to define the target pattern of a ReplaceAll operation.
  365. type: string
  366. required:
  367. - source
  368. - target
  369. type: object
  370. transform:
  371. description: |-
  372. Used to apply string transformation on the secrets.
  373. The resulting key will be the output of the template applied by the operation.
  374. properties:
  375. template:
  376. description: |-
  377. Used to define the template to apply on the secret name.
  378. `.value ` will specify the secret name in the template.
  379. type: string
  380. required:
  381. - template
  382. type: object
  383. type: object
  384. type: array
  385. sourceRef:
  386. description: |-
  387. SourceRef points to a store or generator
  388. which contains secret values ready to use.
  389. Use this in combination with Extract or Find pull values out of
  390. a specific SecretStore.
  391. When sourceRef points to a generator Extract or Find is not supported.
  392. The generator returns a static map of values
  393. maxProperties: 1
  394. minProperties: 1
  395. properties:
  396. generatorRef:
  397. description: GeneratorRef points to a generator custom resource.
  398. properties:
  399. apiVersion:
  400. default: generators.external-secrets.io/v1alpha1
  401. description: Specify the apiVersion of the generator resource
  402. type: string
  403. kind:
  404. description: Specify the Kind of the generator resource
  405. enum:
  406. - ACRAccessToken
  407. - BeyondtrustWorkloadCredentialsDynamicSecret
  408. - ClusterGenerator
  409. - CloudsmithAccessToken
  410. - ECRAuthorizationToken
  411. - Fake
  412. - GCRAccessToken
  413. - GithubAccessToken
  414. - GitlabDeployToken
  415. - QuayAccessToken
  416. - Password
  417. - SSHKey
  418. - STSSessionToken
  419. - UUID
  420. - VaultDynamicSecret
  421. - Webhook
  422. - Grafana
  423. - MFA
  424. type: string
  425. name:
  426. description: Specify the name of the generator resource
  427. maxLength: 253
  428. minLength: 1
  429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  430. type: string
  431. required:
  432. - kind
  433. - name
  434. type: object
  435. storeRef:
  436. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  437. properties:
  438. kind:
  439. description: |-
  440. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  441. Defaults to `SecretStore`
  442. enum:
  443. - SecretStore
  444. - ClusterSecretStore
  445. type: string
  446. name:
  447. description: Name of the SecretStore resource
  448. maxLength: 253
  449. minLength: 1
  450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  451. type: string
  452. type: object
  453. type: object
  454. type: object
  455. type: array
  456. refreshInterval:
  457. default: 1h0m0s
  458. description: |-
  459. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  460. specified as Golang Duration strings.
  461. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  462. Example values: "1h0m0s", "2h30m0s", "10m0s"
  463. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  464. type: string
  465. refreshPolicy:
  466. description: |-
  467. RefreshPolicy determines how the ExternalSecret should be refreshed:
  468. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  469. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  470. No periodic updates occur if refreshInterval is 0.
  471. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  472. enum:
  473. - CreatedOnce
  474. - Periodic
  475. - OnChange
  476. type: string
  477. secretStoreRef:
  478. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  479. properties:
  480. kind:
  481. description: |-
  482. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  483. Defaults to `SecretStore`
  484. enum:
  485. - SecretStore
  486. - ClusterSecretStore
  487. type: string
  488. name:
  489. description: Name of the SecretStore resource
  490. maxLength: 253
  491. minLength: 1
  492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  493. type: string
  494. type: object
  495. syncWindows:
  496. description: |-
  497. SyncWindows optionally restricts when periodic refreshes may occur.
  498. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  499. properties:
  500. kind:
  501. description: |-
  502. Kind applies to every window in the list.
  503. "allow" -- syncs are permitted only while at least one window is active;
  504. all other times are blocked.
  505. "deny" -- syncs are blocked while any window is active;
  506. all other times are permitted.
  507. enum:
  508. - allow
  509. - deny
  510. type: string
  511. windows:
  512. description: Windows is the list of schedule+duration pairs.
  513. items:
  514. description: |-
  515. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  516. within a SyncWindows block.
  517. properties:
  518. duration:
  519. description: |-
  520. Duration specifies how long the window stays open after each Schedule
  521. firing. Example: "8h".
  522. type: string
  523. schedule:
  524. description: |-
  525. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  526. named shorthand such as @daily or @every 1h. It marks the start time of
  527. each window occurrence.
  528. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  529. minLength: 1
  530. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  531. type: string
  532. required:
  533. - duration
  534. - schedule
  535. type: object
  536. minItems: 1
  537. type: array
  538. required:
  539. - kind
  540. - windows
  541. type: object
  542. target:
  543. default:
  544. creationPolicy: Owner
  545. deletionPolicy: Retain
  546. description: |-
  547. ExternalSecretTarget defines the Kubernetes Secret to be created,
  548. there can be only one target per ExternalSecret.
  549. properties:
  550. creationPolicy:
  551. default: Owner
  552. description: |-
  553. CreationPolicy defines rules on how to create the resulting Secret.
  554. Defaults to "Owner"
  555. enum:
  556. - Owner
  557. - Orphan
  558. - Merge
  559. - None
  560. - CreateOrMerge
  561. type: string
  562. deletionPolicy:
  563. default: Retain
  564. description: |-
  565. DeletionPolicy defines rules on how to delete the resulting Secret.
  566. Defaults to "Retain"
  567. enum:
  568. - Delete
  569. - Merge
  570. - Retain
  571. type: string
  572. immutable:
  573. description: Immutable defines if the final secret will be immutable
  574. type: boolean
  575. manifest:
  576. description: |-
  577. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  578. When specified, ExternalSecret will create the resource type defined here
  579. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  580. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  581. properties:
  582. apiVersion:
  583. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  584. minLength: 1
  585. type: string
  586. kind:
  587. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  588. minLength: 1
  589. type: string
  590. required:
  591. - apiVersion
  592. - kind
  593. type: object
  594. name:
  595. description: |-
  596. The name of the Secret resource to be managed.
  597. Defaults to the .metadata.name of the ExternalSecret resource
  598. maxLength: 253
  599. minLength: 1
  600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  601. type: string
  602. template:
  603. description: Template defines a blueprint for the created Secret resource.
  604. properties:
  605. data:
  606. additionalProperties:
  607. type: string
  608. type: object
  609. engineVersion:
  610. default: v2
  611. description: |-
  612. EngineVersion specifies the template engine version
  613. that should be used to compile/execute the
  614. template specified in .data and .templateFrom[].
  615. enum:
  616. - v2
  617. type: string
  618. mergePolicy:
  619. default: Replace
  620. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  621. enum:
  622. - Replace
  623. - Merge
  624. type: string
  625. metadata:
  626. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  627. properties:
  628. annotations:
  629. additionalProperties:
  630. type: string
  631. type: object
  632. finalizers:
  633. items:
  634. type: string
  635. type: array
  636. labels:
  637. additionalProperties:
  638. type: string
  639. type: object
  640. type: object
  641. templateFrom:
  642. items:
  643. description: |-
  644. TemplateFrom specifies a source for templates.
  645. Each item in the list can either reference a ConfigMap or a Secret resource.
  646. properties:
  647. configMap:
  648. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  649. properties:
  650. items:
  651. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  652. items:
  653. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  654. properties:
  655. key:
  656. description: A key in the ConfigMap/Secret
  657. maxLength: 253
  658. minLength: 1
  659. pattern: ^[-._a-zA-Z0-9]+$
  660. type: string
  661. templateAs:
  662. default: Values
  663. description: TemplateScope specifies how the template keys should be interpreted.
  664. enum:
  665. - Values
  666. - KeysAndValues
  667. type: string
  668. required:
  669. - key
  670. type: object
  671. type: array
  672. name:
  673. description: The name of the ConfigMap/Secret resource
  674. maxLength: 253
  675. minLength: 1
  676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  677. type: string
  678. required:
  679. - items
  680. - name
  681. type: object
  682. literal:
  683. type: string
  684. secret:
  685. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  686. properties:
  687. items:
  688. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  689. items:
  690. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  691. properties:
  692. key:
  693. description: A key in the ConfigMap/Secret
  694. maxLength: 253
  695. minLength: 1
  696. pattern: ^[-._a-zA-Z0-9]+$
  697. type: string
  698. templateAs:
  699. default: Values
  700. description: TemplateScope specifies how the template keys should be interpreted.
  701. enum:
  702. - Values
  703. - KeysAndValues
  704. type: string
  705. required:
  706. - key
  707. type: object
  708. type: array
  709. name:
  710. description: The name of the ConfigMap/Secret resource
  711. maxLength: 253
  712. minLength: 1
  713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  714. type: string
  715. required:
  716. - items
  717. - name
  718. type: object
  719. target:
  720. default: Data
  721. description: |-
  722. Target specifies where to place the template result.
  723. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  724. any other value is rejected because it would allow writes to privileged Secret fields.
  725. For custom resources (when spec.target.manifest is set), this supports
  726. nested paths like "spec.database.config" or "data".
  727. type: string
  728. valuesDecodingStrategy:
  729. default: None
  730. description: Used to define a decoding Strategy for the rendered template values.
  731. enum:
  732. - Auto
  733. - Base64
  734. - Base64URL
  735. - None
  736. type: string
  737. type: object
  738. type: array
  739. type:
  740. type: string
  741. type: object
  742. type: object
  743. type: object
  744. namespaceSelector:
  745. description: |-
  746. The labels to select by to find the Namespaces to create the ExternalSecrets in.
  747. Deprecated: Use NamespaceSelectors instead.
  748. properties:
  749. matchExpressions:
  750. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  751. items:
  752. description: |-
  753. A label selector requirement is a selector that contains values, a key, and an operator that
  754. relates the key and values.
  755. properties:
  756. key:
  757. description: key is the label key that the selector applies to.
  758. type: string
  759. operator:
  760. description: |-
  761. operator represents a key's relationship to a set of values.
  762. Valid operators are In, NotIn, Exists and DoesNotExist.
  763. type: string
  764. values:
  765. description: |-
  766. values is an array of string values. If the operator is In or NotIn,
  767. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  768. the values array must be empty. This array is replaced during a strategic
  769. merge patch.
  770. items:
  771. type: string
  772. type: array
  773. x-kubernetes-list-type: atomic
  774. required:
  775. - key
  776. - operator
  777. type: object
  778. type: array
  779. x-kubernetes-list-type: atomic
  780. matchLabels:
  781. additionalProperties:
  782. type: string
  783. description: |-
  784. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  785. map is equivalent to an element of matchExpressions, whose key field is "key", the
  786. operator is "In", and the values array contains only "value". The requirements are ANDed.
  787. type: object
  788. type: object
  789. x-kubernetes-map-type: atomic
  790. namespaceSelectors:
  791. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  792. items:
  793. description: |-
  794. A label selector is a label query over a set of resources. The result of matchLabels and
  795. matchExpressions are ANDed. An empty label selector matches all objects. A null
  796. label selector matches no objects.
  797. properties:
  798. matchExpressions:
  799. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  800. items:
  801. description: |-
  802. A label selector requirement is a selector that contains values, a key, and an operator that
  803. relates the key and values.
  804. properties:
  805. key:
  806. description: key is the label key that the selector applies to.
  807. type: string
  808. operator:
  809. description: |-
  810. operator represents a key's relationship to a set of values.
  811. Valid operators are In, NotIn, Exists and DoesNotExist.
  812. type: string
  813. values:
  814. description: |-
  815. values is an array of string values. If the operator is In or NotIn,
  816. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  817. the values array must be empty. This array is replaced during a strategic
  818. merge patch.
  819. items:
  820. type: string
  821. type: array
  822. x-kubernetes-list-type: atomic
  823. required:
  824. - key
  825. - operator
  826. type: object
  827. type: array
  828. x-kubernetes-list-type: atomic
  829. matchLabels:
  830. additionalProperties:
  831. type: string
  832. description: |-
  833. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  834. map is equivalent to an element of matchExpressions, whose key field is "key", the
  835. operator is "In", and the values array contains only "value". The requirements are ANDed.
  836. type: object
  837. type: object
  838. x-kubernetes-map-type: atomic
  839. type: array
  840. namespaces:
  841. description: |-
  842. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  843. Deprecated: Use NamespaceSelectors instead.
  844. items:
  845. maxLength: 63
  846. minLength: 1
  847. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  848. type: string
  849. type: array
  850. refreshTime:
  851. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  852. type: string
  853. required:
  854. - externalSecretSpec
  855. type: object
  856. status:
  857. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  858. properties:
  859. conditions:
  860. items:
  861. description: ClusterExternalSecretStatusCondition defines the observed state of a ClusterExternalSecret resource.
  862. properties:
  863. message:
  864. type: string
  865. status:
  866. type: string
  867. type:
  868. description: ClusterExternalSecretConditionType defines a value type for ClusterExternalSecret conditions.
  869. type: string
  870. required:
  871. - status
  872. - type
  873. type: object
  874. type: array
  875. externalSecretName:
  876. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  877. type: string
  878. failedNamespaces:
  879. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  880. items:
  881. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  882. properties:
  883. namespace:
  884. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  885. type: string
  886. reason:
  887. description: Reason is why the ExternalSecret failed to apply to the namespace
  888. type: string
  889. required:
  890. - namespace
  891. type: object
  892. type: array
  893. provisionedNamespaces:
  894. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  895. items:
  896. type: string
  897. type: array
  898. type: object
  899. type: object
  900. served: true
  901. storage: true
  902. subresources:
  903. status: {}
  904. - additionalPrinterColumns:
  905. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  906. name: Store
  907. type: string
  908. - jsonPath: .spec.refreshTime
  909. name: Refresh Interval
  910. type: string
  911. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  912. name: Ready
  913. type: string
  914. deprecated: true
  915. name: v1beta1
  916. schema:
  917. openAPIV3Schema:
  918. description: ClusterExternalSecret is the schema for the clusterexternalsecrets API.
  919. properties:
  920. apiVersion:
  921. description: |-
  922. APIVersion defines the versioned schema of this representation of an object.
  923. Servers should convert recognized schemas to the latest internal value, and
  924. may reject unrecognized values.
  925. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  926. type: string
  927. kind:
  928. description: |-
  929. Kind is a string value representing the REST resource this object represents.
  930. Servers may infer this from the endpoint the client submits requests to.
  931. Cannot be updated.
  932. In CamelCase.
  933. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  934. type: string
  935. metadata:
  936. type: object
  937. spec:
  938. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  939. properties:
  940. externalSecretMetadata:
  941. description: The metadata of the external secrets to be created
  942. properties:
  943. annotations:
  944. additionalProperties:
  945. type: string
  946. type: object
  947. labels:
  948. additionalProperties:
  949. type: string
  950. type: object
  951. type: object
  952. externalSecretName:
  953. description: |-
  954. The name of the external secrets to be created.
  955. Defaults to the name of the ClusterExternalSecret
  956. maxLength: 253
  957. minLength: 1
  958. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  959. type: string
  960. externalSecretSpec:
  961. description: The spec for the ExternalSecrets to be created
  962. properties:
  963. data:
  964. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  965. items:
  966. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  967. properties:
  968. remoteRef:
  969. description: |-
  970. RemoteRef points to the remote secret and defines
  971. which secret (version/property/..) to fetch.
  972. properties:
  973. conversionStrategy:
  974. default: Default
  975. description: Used to define a conversion Strategy
  976. enum:
  977. - Default
  978. - Unicode
  979. type: string
  980. decodingStrategy:
  981. default: None
  982. description: Used to define a decoding Strategy
  983. enum:
  984. - Auto
  985. - Base64
  986. - Base64URL
  987. - None
  988. type: string
  989. key:
  990. description: Key is the key used in the Provider, mandatory
  991. type: string
  992. metadataPolicy:
  993. default: None
  994. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  995. enum:
  996. - None
  997. - Fetch
  998. type: string
  999. property:
  1000. description: Used to select a specific property of the Provider value (if a map), if supported
  1001. type: string
  1002. version:
  1003. description: Used to select a specific version of the Provider value, if supported
  1004. type: string
  1005. required:
  1006. - key
  1007. type: object
  1008. secretKey:
  1009. description: The key in the Kubernetes Secret to store the value.
  1010. maxLength: 253
  1011. minLength: 1
  1012. pattern: ^[-._a-zA-Z0-9]+$
  1013. type: string
  1014. sourceRef:
  1015. description: |-
  1016. SourceRef allows you to override the source
  1017. from which the value will be pulled.
  1018. maxProperties: 1
  1019. minProperties: 1
  1020. properties:
  1021. generatorRef:
  1022. description: |-
  1023. GeneratorRef points to a generator custom resource.
  1024. Deprecated: The generatorRef is not implemented in .data[].
  1025. this will be removed with v1.
  1026. properties:
  1027. apiVersion:
  1028. default: generators.external-secrets.io/v1alpha1
  1029. description: Specify the apiVersion of the generator resource
  1030. type: string
  1031. kind:
  1032. description: Specify the Kind of the generator resource
  1033. enum:
  1034. - ACRAccessToken
  1035. - ClusterGenerator
  1036. - ECRAuthorizationToken
  1037. - Fake
  1038. - GCRAccessToken
  1039. - GithubAccessToken
  1040. - QuayAccessToken
  1041. - Password
  1042. - SSHKey
  1043. - STSSessionToken
  1044. - UUID
  1045. - VaultDynamicSecret
  1046. - Webhook
  1047. - Grafana
  1048. type: string
  1049. name:
  1050. description: Specify the name of the generator resource
  1051. maxLength: 253
  1052. minLength: 1
  1053. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1054. type: string
  1055. required:
  1056. - kind
  1057. - name
  1058. type: object
  1059. storeRef:
  1060. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1061. properties:
  1062. kind:
  1063. description: |-
  1064. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1065. Defaults to `SecretStore`
  1066. enum:
  1067. - SecretStore
  1068. - ClusterSecretStore
  1069. type: string
  1070. name:
  1071. description: Name of the SecretStore resource
  1072. maxLength: 253
  1073. minLength: 1
  1074. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1075. type: string
  1076. type: object
  1077. type: object
  1078. required:
  1079. - remoteRef
  1080. - secretKey
  1081. type: object
  1082. type: array
  1083. dataFrom:
  1084. description: |-
  1085. DataFrom is used to fetch all properties from a specific Provider data
  1086. If multiple entries are specified, the Secret keys are merged in the specified order
  1087. items:
  1088. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  1089. properties:
  1090. extract:
  1091. description: |-
  1092. Used to extract multiple key/value pairs from one secret
  1093. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1094. properties:
  1095. conversionStrategy:
  1096. default: Default
  1097. description: Used to define a conversion Strategy
  1098. enum:
  1099. - Default
  1100. - Unicode
  1101. type: string
  1102. decodingStrategy:
  1103. default: None
  1104. description: Used to define a decoding Strategy
  1105. enum:
  1106. - Auto
  1107. - Base64
  1108. - Base64URL
  1109. - None
  1110. type: string
  1111. key:
  1112. description: Key is the key used in the Provider, mandatory
  1113. type: string
  1114. metadataPolicy:
  1115. default: None
  1116. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  1117. enum:
  1118. - None
  1119. - Fetch
  1120. type: string
  1121. property:
  1122. description: Used to select a specific property of the Provider value (if a map), if supported
  1123. type: string
  1124. version:
  1125. description: Used to select a specific version of the Provider value, if supported
  1126. type: string
  1127. required:
  1128. - key
  1129. type: object
  1130. find:
  1131. description: |-
  1132. Used to find secrets based on tags or regular expressions
  1133. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1134. properties:
  1135. conversionStrategy:
  1136. default: Default
  1137. description: Used to define a conversion Strategy
  1138. enum:
  1139. - Default
  1140. - Unicode
  1141. type: string
  1142. decodingStrategy:
  1143. default: None
  1144. description: Used to define a decoding Strategy
  1145. enum:
  1146. - Auto
  1147. - Base64
  1148. - Base64URL
  1149. - None
  1150. type: string
  1151. name:
  1152. description: Finds secrets based on the name.
  1153. properties:
  1154. regexp:
  1155. description: Finds secrets base
  1156. type: string
  1157. type: object
  1158. path:
  1159. description: A root path to start the find operations.
  1160. type: string
  1161. tags:
  1162. additionalProperties:
  1163. type: string
  1164. description: Find secrets based on tags.
  1165. type: object
  1166. type: object
  1167. rewrite:
  1168. description: |-
  1169. Used to rewrite secret Keys after getting them from the secret Provider
  1170. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  1171. items:
  1172. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  1173. maxProperties: 1
  1174. minProperties: 1
  1175. properties:
  1176. regexp:
  1177. description: |-
  1178. Used to rewrite with regular expressions.
  1179. The resulting key will be the output of a regexp.ReplaceAll operation.
  1180. properties:
  1181. source:
  1182. description: Used to define the regular expression of a re.Compiler.
  1183. type: string
  1184. target:
  1185. description: Used to define the target pattern of a ReplaceAll operation.
  1186. type: string
  1187. required:
  1188. - source
  1189. - target
  1190. type: object
  1191. transform:
  1192. description: |-
  1193. Used to apply string transformation on the secrets.
  1194. The resulting key will be the output of the template applied by the operation.
  1195. properties:
  1196. template:
  1197. description: |-
  1198. Used to define the template to apply on the secret name.
  1199. `.value ` will specify the secret name in the template.
  1200. type: string
  1201. required:
  1202. - template
  1203. type: object
  1204. type: object
  1205. type: array
  1206. sourceRef:
  1207. description: |-
  1208. SourceRef points to a store or generator
  1209. which contains secret values ready to use.
  1210. Use this in combination with Extract or Find pull values out of
  1211. a specific SecretStore.
  1212. When sourceRef points to a generator Extract or Find is not supported.
  1213. The generator returns a static map of values
  1214. maxProperties: 1
  1215. minProperties: 1
  1216. properties:
  1217. generatorRef:
  1218. description: GeneratorRef points to a generator custom resource.
  1219. properties:
  1220. apiVersion:
  1221. default: generators.external-secrets.io/v1alpha1
  1222. description: Specify the apiVersion of the generator resource
  1223. type: string
  1224. kind:
  1225. description: Specify the Kind of the generator resource
  1226. enum:
  1227. - ACRAccessToken
  1228. - ClusterGenerator
  1229. - ECRAuthorizationToken
  1230. - Fake
  1231. - GCRAccessToken
  1232. - GithubAccessToken
  1233. - QuayAccessToken
  1234. - Password
  1235. - SSHKey
  1236. - STSSessionToken
  1237. - UUID
  1238. - VaultDynamicSecret
  1239. - Webhook
  1240. - Grafana
  1241. type: string
  1242. name:
  1243. description: Specify the name of the generator resource
  1244. maxLength: 253
  1245. minLength: 1
  1246. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1247. type: string
  1248. required:
  1249. - kind
  1250. - name
  1251. type: object
  1252. storeRef:
  1253. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1254. properties:
  1255. kind:
  1256. description: |-
  1257. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1258. Defaults to `SecretStore`
  1259. enum:
  1260. - SecretStore
  1261. - ClusterSecretStore
  1262. type: string
  1263. name:
  1264. description: Name of the SecretStore resource
  1265. maxLength: 253
  1266. minLength: 1
  1267. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1268. type: string
  1269. type: object
  1270. type: object
  1271. type: object
  1272. type: array
  1273. refreshInterval:
  1274. default: 1h0m0s
  1275. description: |-
  1276. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  1277. specified as Golang Duration strings.
  1278. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  1279. Example values: "1h0m0s", "2h30m0s", "10m0s"
  1280. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  1281. type: string
  1282. refreshPolicy:
  1283. description: |-
  1284. RefreshPolicy determines how the ExternalSecret should be refreshed:
  1285. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  1286. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  1287. No periodic updates occur if refreshInterval is 0.
  1288. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  1289. enum:
  1290. - CreatedOnce
  1291. - Periodic
  1292. - OnChange
  1293. type: string
  1294. secretStoreRef:
  1295. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1296. properties:
  1297. kind:
  1298. description: |-
  1299. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1300. Defaults to `SecretStore`
  1301. enum:
  1302. - SecretStore
  1303. - ClusterSecretStore
  1304. type: string
  1305. name:
  1306. description: Name of the SecretStore resource
  1307. maxLength: 253
  1308. minLength: 1
  1309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1310. type: string
  1311. type: object
  1312. target:
  1313. default:
  1314. creationPolicy: Owner
  1315. deletionPolicy: Retain
  1316. description: |-
  1317. ExternalSecretTarget defines the Kubernetes Secret to be created
  1318. There can be only one target per ExternalSecret.
  1319. properties:
  1320. creationPolicy:
  1321. default: Owner
  1322. description: |-
  1323. CreationPolicy defines rules on how to create the resulting Secret.
  1324. Defaults to "Owner"
  1325. enum:
  1326. - Owner
  1327. - Orphan
  1328. - Merge
  1329. - None
  1330. type: string
  1331. deletionPolicy:
  1332. default: Retain
  1333. description: |-
  1334. DeletionPolicy defines rules on how to delete the resulting Secret.
  1335. Defaults to "Retain"
  1336. enum:
  1337. - Delete
  1338. - Merge
  1339. - Retain
  1340. type: string
  1341. immutable:
  1342. description: Immutable defines if the final secret will be immutable
  1343. type: boolean
  1344. name:
  1345. description: |-
  1346. The name of the Secret resource to be managed.
  1347. Defaults to the .metadata.name of the ExternalSecret resource
  1348. maxLength: 253
  1349. minLength: 1
  1350. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1351. type: string
  1352. template:
  1353. description: Template defines a blueprint for the created Secret resource.
  1354. properties:
  1355. data:
  1356. additionalProperties:
  1357. type: string
  1358. type: object
  1359. engineVersion:
  1360. default: v2
  1361. description: |-
  1362. EngineVersion specifies the template engine version
  1363. that should be used to compile/execute the
  1364. template specified in .data and .templateFrom[].
  1365. enum:
  1366. - v2
  1367. type: string
  1368. mergePolicy:
  1369. default: Replace
  1370. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  1371. enum:
  1372. - Replace
  1373. - Merge
  1374. type: string
  1375. metadata:
  1376. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  1377. properties:
  1378. annotations:
  1379. additionalProperties:
  1380. type: string
  1381. type: object
  1382. labels:
  1383. additionalProperties:
  1384. type: string
  1385. type: object
  1386. type: object
  1387. templateFrom:
  1388. items:
  1389. description: TemplateFrom defines a source for template data.
  1390. properties:
  1391. configMap:
  1392. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1393. properties:
  1394. items:
  1395. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1396. items:
  1397. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1398. properties:
  1399. key:
  1400. description: A key in the ConfigMap/Secret
  1401. maxLength: 253
  1402. minLength: 1
  1403. pattern: ^[-._a-zA-Z0-9]+$
  1404. type: string
  1405. templateAs:
  1406. default: Values
  1407. description: TemplateScope defines the scope of the template when processing template data.
  1408. enum:
  1409. - Values
  1410. - KeysAndValues
  1411. type: string
  1412. required:
  1413. - key
  1414. type: object
  1415. type: array
  1416. name:
  1417. description: The name of the ConfigMap/Secret resource
  1418. maxLength: 253
  1419. minLength: 1
  1420. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1421. type: string
  1422. required:
  1423. - items
  1424. - name
  1425. type: object
  1426. literal:
  1427. type: string
  1428. secret:
  1429. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1430. properties:
  1431. items:
  1432. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1433. items:
  1434. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1435. properties:
  1436. key:
  1437. description: A key in the ConfigMap/Secret
  1438. maxLength: 253
  1439. minLength: 1
  1440. pattern: ^[-._a-zA-Z0-9]+$
  1441. type: string
  1442. templateAs:
  1443. default: Values
  1444. description: TemplateScope defines the scope of the template when processing template data.
  1445. enum:
  1446. - Values
  1447. - KeysAndValues
  1448. type: string
  1449. required:
  1450. - key
  1451. type: object
  1452. type: array
  1453. name:
  1454. description: The name of the ConfigMap/Secret resource
  1455. maxLength: 253
  1456. minLength: 1
  1457. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1458. type: string
  1459. required:
  1460. - items
  1461. - name
  1462. type: object
  1463. target:
  1464. default: Data
  1465. description: TemplateTarget defines the target field where the template result will be stored.
  1466. enum:
  1467. - Data
  1468. - Annotations
  1469. - Labels
  1470. type: string
  1471. type: object
  1472. type: array
  1473. type:
  1474. type: string
  1475. type: object
  1476. type: object
  1477. type: object
  1478. namespaceSelector:
  1479. description: The labels to select by to find the Namespaces to create the ExternalSecrets in
  1480. properties:
  1481. matchExpressions:
  1482. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1483. items:
  1484. description: |-
  1485. A label selector requirement is a selector that contains values, a key, and an operator that
  1486. relates the key and values.
  1487. properties:
  1488. key:
  1489. description: key is the label key that the selector applies to.
  1490. type: string
  1491. operator:
  1492. description: |-
  1493. operator represents a key's relationship to a set of values.
  1494. Valid operators are In, NotIn, Exists and DoesNotExist.
  1495. type: string
  1496. values:
  1497. description: |-
  1498. values is an array of string values. If the operator is In or NotIn,
  1499. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1500. the values array must be empty. This array is replaced during a strategic
  1501. merge patch.
  1502. items:
  1503. type: string
  1504. type: array
  1505. x-kubernetes-list-type: atomic
  1506. required:
  1507. - key
  1508. - operator
  1509. type: object
  1510. type: array
  1511. x-kubernetes-list-type: atomic
  1512. matchLabels:
  1513. additionalProperties:
  1514. type: string
  1515. description: |-
  1516. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1517. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1518. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1519. type: object
  1520. type: object
  1521. x-kubernetes-map-type: atomic
  1522. namespaceSelectors:
  1523. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1524. items:
  1525. description: |-
  1526. A label selector is a label query over a set of resources. The result of matchLabels and
  1527. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1528. label selector matches no objects.
  1529. properties:
  1530. matchExpressions:
  1531. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1532. items:
  1533. description: |-
  1534. A label selector requirement is a selector that contains values, a key, and an operator that
  1535. relates the key and values.
  1536. properties:
  1537. key:
  1538. description: key is the label key that the selector applies to.
  1539. type: string
  1540. operator:
  1541. description: |-
  1542. operator represents a key's relationship to a set of values.
  1543. Valid operators are In, NotIn, Exists and DoesNotExist.
  1544. type: string
  1545. values:
  1546. description: |-
  1547. values is an array of string values. If the operator is In or NotIn,
  1548. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1549. the values array must be empty. This array is replaced during a strategic
  1550. merge patch.
  1551. items:
  1552. type: string
  1553. type: array
  1554. x-kubernetes-list-type: atomic
  1555. required:
  1556. - key
  1557. - operator
  1558. type: object
  1559. type: array
  1560. x-kubernetes-list-type: atomic
  1561. matchLabels:
  1562. additionalProperties:
  1563. type: string
  1564. description: |-
  1565. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1566. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1567. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1568. type: object
  1569. type: object
  1570. x-kubernetes-map-type: atomic
  1571. type: array
  1572. namespaces:
  1573. description: |-
  1574. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  1575. Deprecated: Use NamespaceSelectors instead.
  1576. items:
  1577. maxLength: 63
  1578. minLength: 1
  1579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1580. type: string
  1581. type: array
  1582. refreshTime:
  1583. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  1584. type: string
  1585. required:
  1586. - externalSecretSpec
  1587. type: object
  1588. status:
  1589. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  1590. properties:
  1591. conditions:
  1592. items:
  1593. description: ClusterExternalSecretStatusCondition indicates the status of the ClusterExternalSecret.
  1594. properties:
  1595. message:
  1596. type: string
  1597. status:
  1598. type: string
  1599. type:
  1600. description: ClusterExternalSecretConditionType indicates the condition of the ClusterExternalSecret.
  1601. type: string
  1602. required:
  1603. - status
  1604. - type
  1605. type: object
  1606. type: array
  1607. externalSecretName:
  1608. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  1609. type: string
  1610. failedNamespaces:
  1611. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  1612. items:
  1613. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  1614. properties:
  1615. namespace:
  1616. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  1617. type: string
  1618. reason:
  1619. description: Reason is why the ExternalSecret failed to apply to the namespace
  1620. type: string
  1621. required:
  1622. - namespace
  1623. type: object
  1624. type: array
  1625. provisionedNamespaces:
  1626. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  1627. items:
  1628. type: string
  1629. type: array
  1630. type: object
  1631. type: object
  1632. served: false
  1633. storage: false
  1634. subresources:
  1635. status: {}
  1636. ---
  1637. apiVersion: apiextensions.k8s.io/v1
  1638. kind: CustomResourceDefinition
  1639. metadata:
  1640. annotations:
  1641. controller-gen.kubebuilder.io/version: v0.19.0
  1642. labels:
  1643. external-secrets.io/component: controller
  1644. name: clusterpushsecrets.external-secrets.io
  1645. spec:
  1646. group: external-secrets.io
  1647. names:
  1648. categories:
  1649. - external-secrets
  1650. kind: ClusterPushSecret
  1651. listKind: ClusterPushSecretList
  1652. plural: clusterpushsecrets
  1653. singular: clusterpushsecret
  1654. scope: Cluster
  1655. versions:
  1656. - additionalPrinterColumns:
  1657. - jsonPath: .metadata.creationTimestamp
  1658. name: AGE
  1659. type: date
  1660. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  1661. name: Status
  1662. type: string
  1663. name: v1alpha1
  1664. schema:
  1665. openAPIV3Schema:
  1666. description: ClusterPushSecret is the Schema for the ClusterPushSecrets API that enables cluster-wide management of pushing Kubernetes secrets to external providers.
  1667. properties:
  1668. apiVersion:
  1669. description: |-
  1670. APIVersion defines the versioned schema of this representation of an object.
  1671. Servers should convert recognized schemas to the latest internal value, and
  1672. may reject unrecognized values.
  1673. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  1674. type: string
  1675. kind:
  1676. description: |-
  1677. Kind is a string value representing the REST resource this object represents.
  1678. Servers may infer this from the endpoint the client submits requests to.
  1679. Cannot be updated.
  1680. In CamelCase.
  1681. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  1682. type: string
  1683. metadata:
  1684. type: object
  1685. spec:
  1686. description: ClusterPushSecretSpec defines the configuration for a ClusterPushSecret resource.
  1687. properties:
  1688. namespaceSelectors:
  1689. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1690. items:
  1691. description: |-
  1692. A label selector is a label query over a set of resources. The result of matchLabels and
  1693. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1694. label selector matches no objects.
  1695. properties:
  1696. matchExpressions:
  1697. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1698. items:
  1699. description: |-
  1700. A label selector requirement is a selector that contains values, a key, and an operator that
  1701. relates the key and values.
  1702. properties:
  1703. key:
  1704. description: key is the label key that the selector applies to.
  1705. type: string
  1706. operator:
  1707. description: |-
  1708. operator represents a key's relationship to a set of values.
  1709. Valid operators are In, NotIn, Exists and DoesNotExist.
  1710. type: string
  1711. values:
  1712. description: |-
  1713. values is an array of string values. If the operator is In or NotIn,
  1714. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1715. the values array must be empty. This array is replaced during a strategic
  1716. merge patch.
  1717. items:
  1718. type: string
  1719. type: array
  1720. x-kubernetes-list-type: atomic
  1721. required:
  1722. - key
  1723. - operator
  1724. type: object
  1725. type: array
  1726. x-kubernetes-list-type: atomic
  1727. matchLabels:
  1728. additionalProperties:
  1729. type: string
  1730. description: |-
  1731. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1732. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1733. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1734. type: object
  1735. type: object
  1736. x-kubernetes-map-type: atomic
  1737. type: array
  1738. pushSecretMetadata:
  1739. description: The metadata of the external secrets to be created
  1740. properties:
  1741. annotations:
  1742. additionalProperties:
  1743. type: string
  1744. type: object
  1745. labels:
  1746. additionalProperties:
  1747. type: string
  1748. type: object
  1749. type: object
  1750. pushSecretName:
  1751. description: |-
  1752. The name of the push secrets to be created.
  1753. Defaults to the name of the ClusterPushSecret
  1754. maxLength: 253
  1755. minLength: 1
  1756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1757. type: string
  1758. pushSecretSpec:
  1759. description: PushSecretSpec defines what to do with the secrets.
  1760. properties:
  1761. data:
  1762. description: Secret Data that should be pushed to providers
  1763. items:
  1764. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  1765. properties:
  1766. conversionStrategy:
  1767. default: None
  1768. description: Used to define a conversion Strategy for the secret keys
  1769. enum:
  1770. - None
  1771. - ReverseUnicode
  1772. type: string
  1773. match:
  1774. description: Match a given Secret Key to be pushed to the provider.
  1775. properties:
  1776. remoteRef:
  1777. description: Remote Refs to push to providers.
  1778. properties:
  1779. property:
  1780. description: Name of the property in the resulting secret
  1781. type: string
  1782. remoteKey:
  1783. description: Name of the resulting provider secret.
  1784. type: string
  1785. required:
  1786. - remoteKey
  1787. type: object
  1788. secretKey:
  1789. description: Secret Key to be pushed
  1790. type: string
  1791. required:
  1792. - remoteRef
  1793. type: object
  1794. metadata:
  1795. description: |-
  1796. Metadata is metadata attached to the secret.
  1797. The structure of metadata is provider specific, please look it up in the provider documentation.
  1798. x-kubernetes-preserve-unknown-fields: true
  1799. required:
  1800. - match
  1801. type: object
  1802. type: array
  1803. dataTo:
  1804. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  1805. items:
  1806. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  1807. properties:
  1808. conversionStrategy:
  1809. default: None
  1810. description: Used to define a conversion Strategy for the secret keys
  1811. enum:
  1812. - None
  1813. - ReverseUnicode
  1814. type: string
  1815. match:
  1816. description: |-
  1817. Match pattern for selecting keys from the source Secret.
  1818. If not specified, all keys are selected.
  1819. properties:
  1820. regexp:
  1821. description: |-
  1822. Regexp matches keys by regular expression.
  1823. If not specified, all keys are matched.
  1824. type: string
  1825. type: object
  1826. metadata:
  1827. description: |-
  1828. Metadata is metadata attached to the secret.
  1829. The structure of metadata is provider specific, please look it up in the provider documentation.
  1830. x-kubernetes-preserve-unknown-fields: true
  1831. remoteKey:
  1832. description: |-
  1833. RemoteKey is the name of the single provider secret that will receive ALL
  1834. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  1835. When set, per-key expansion is skipped and a single push is performed.
  1836. The provider's store prefix (if any) is still prepended to this value.
  1837. When not set, each matched key is pushed as its own individual provider secret.
  1838. type: string
  1839. rewrite:
  1840. description: |-
  1841. Rewrite operations to transform keys before pushing to the provider.
  1842. Operations are applied sequentially.
  1843. items:
  1844. description: PushSecretRewrite defines how to transform secret keys before pushing.
  1845. properties:
  1846. regexp:
  1847. description: Used to rewrite with regular expressions.
  1848. properties:
  1849. source:
  1850. description: Used to define the regular expression of a re.Compiler.
  1851. type: string
  1852. target:
  1853. description: Used to define the target pattern of a ReplaceAll operation.
  1854. type: string
  1855. required:
  1856. - source
  1857. - target
  1858. type: object
  1859. transform:
  1860. description: Used to apply string transformation on the secrets.
  1861. properties:
  1862. template:
  1863. description: |-
  1864. Used to define the template to apply on the secret name.
  1865. `.value ` will specify the secret name in the template.
  1866. type: string
  1867. required:
  1868. - template
  1869. type: object
  1870. type: object
  1871. x-kubernetes-validations:
  1872. - message: exactly one of regexp or transform must be set
  1873. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  1874. type: array
  1875. storeRef:
  1876. description: StoreRef specifies which SecretStore to push to. Required.
  1877. properties:
  1878. kind:
  1879. default: SecretStore
  1880. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1881. enum:
  1882. - SecretStore
  1883. - ClusterSecretStore
  1884. type: string
  1885. labelSelector:
  1886. description: Optionally, sync to secret stores with label selector
  1887. properties:
  1888. matchExpressions:
  1889. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1890. items:
  1891. description: |-
  1892. A label selector requirement is a selector that contains values, a key, and an operator that
  1893. relates the key and values.
  1894. properties:
  1895. key:
  1896. description: key is the label key that the selector applies to.
  1897. type: string
  1898. operator:
  1899. description: |-
  1900. operator represents a key's relationship to a set of values.
  1901. Valid operators are In, NotIn, Exists and DoesNotExist.
  1902. type: string
  1903. values:
  1904. description: |-
  1905. values is an array of string values. If the operator is In or NotIn,
  1906. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1907. the values array must be empty. This array is replaced during a strategic
  1908. merge patch.
  1909. items:
  1910. type: string
  1911. type: array
  1912. x-kubernetes-list-type: atomic
  1913. required:
  1914. - key
  1915. - operator
  1916. type: object
  1917. type: array
  1918. x-kubernetes-list-type: atomic
  1919. matchLabels:
  1920. additionalProperties:
  1921. type: string
  1922. description: |-
  1923. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1924. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1925. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1926. type: object
  1927. type: object
  1928. x-kubernetes-map-type: atomic
  1929. name:
  1930. description: Optionally, sync to the SecretStore of the given name
  1931. maxLength: 253
  1932. minLength: 1
  1933. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1934. type: string
  1935. type: object
  1936. type: object
  1937. x-kubernetes-validations:
  1938. - message: storeRef must specify either name or labelSelector
  1939. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  1940. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  1941. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  1942. type: array
  1943. deletionPolicy:
  1944. default: None
  1945. description: Deletion Policy to handle Secrets in the provider.
  1946. enum:
  1947. - Delete
  1948. - None
  1949. type: string
  1950. refreshInterval:
  1951. default: 1h0m0s
  1952. description: The Interval to which External Secrets will try to push a secret definition
  1953. type: string
  1954. secretStoreRefs:
  1955. items:
  1956. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  1957. properties:
  1958. kind:
  1959. default: SecretStore
  1960. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1961. enum:
  1962. - SecretStore
  1963. - ClusterSecretStore
  1964. type: string
  1965. labelSelector:
  1966. description: Optionally, sync to secret stores with label selector
  1967. properties:
  1968. matchExpressions:
  1969. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1970. items:
  1971. description: |-
  1972. A label selector requirement is a selector that contains values, a key, and an operator that
  1973. relates the key and values.
  1974. properties:
  1975. key:
  1976. description: key is the label key that the selector applies to.
  1977. type: string
  1978. operator:
  1979. description: |-
  1980. operator represents a key's relationship to a set of values.
  1981. Valid operators are In, NotIn, Exists and DoesNotExist.
  1982. type: string
  1983. values:
  1984. description: |-
  1985. values is an array of string values. If the operator is In or NotIn,
  1986. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1987. the values array must be empty. This array is replaced during a strategic
  1988. merge patch.
  1989. items:
  1990. type: string
  1991. type: array
  1992. x-kubernetes-list-type: atomic
  1993. required:
  1994. - key
  1995. - operator
  1996. type: object
  1997. type: array
  1998. x-kubernetes-list-type: atomic
  1999. matchLabels:
  2000. additionalProperties:
  2001. type: string
  2002. description: |-
  2003. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2004. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2005. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2006. type: object
  2007. type: object
  2008. x-kubernetes-map-type: atomic
  2009. name:
  2010. description: Optionally, sync to the SecretStore of the given name
  2011. maxLength: 253
  2012. minLength: 1
  2013. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2014. type: string
  2015. type: object
  2016. type: array
  2017. selector:
  2018. description: The Secret Selector (k8s source) for the Push Secret
  2019. maxProperties: 1
  2020. minProperties: 1
  2021. properties:
  2022. generatorRef:
  2023. description: Point to a generator to create a Secret.
  2024. properties:
  2025. apiVersion:
  2026. default: generators.external-secrets.io/v1alpha1
  2027. description: Specify the apiVersion of the generator resource
  2028. type: string
  2029. kind:
  2030. description: Specify the Kind of the generator resource
  2031. enum:
  2032. - ACRAccessToken
  2033. - BeyondtrustWorkloadCredentialsDynamicSecret
  2034. - ClusterGenerator
  2035. - CloudsmithAccessToken
  2036. - ECRAuthorizationToken
  2037. - Fake
  2038. - GCRAccessToken
  2039. - GithubAccessToken
  2040. - GitlabDeployToken
  2041. - QuayAccessToken
  2042. - Password
  2043. - SSHKey
  2044. - STSSessionToken
  2045. - UUID
  2046. - VaultDynamicSecret
  2047. - Webhook
  2048. - Grafana
  2049. - MFA
  2050. type: string
  2051. name:
  2052. description: Specify the name of the generator resource
  2053. maxLength: 253
  2054. minLength: 1
  2055. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2056. type: string
  2057. required:
  2058. - kind
  2059. - name
  2060. type: object
  2061. secret:
  2062. description: Select a Secret to Push.
  2063. properties:
  2064. name:
  2065. description: |-
  2066. Name of the Secret.
  2067. The Secret must exist in the same namespace as the PushSecret manifest.
  2068. maxLength: 253
  2069. minLength: 1
  2070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2071. type: string
  2072. selector:
  2073. description: Selector chooses secrets using a labelSelector.
  2074. properties:
  2075. matchExpressions:
  2076. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2077. items:
  2078. description: |-
  2079. A label selector requirement is a selector that contains values, a key, and an operator that
  2080. relates the key and values.
  2081. properties:
  2082. key:
  2083. description: key is the label key that the selector applies to.
  2084. type: string
  2085. operator:
  2086. description: |-
  2087. operator represents a key's relationship to a set of values.
  2088. Valid operators are In, NotIn, Exists and DoesNotExist.
  2089. type: string
  2090. values:
  2091. description: |-
  2092. values is an array of string values. If the operator is In or NotIn,
  2093. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2094. the values array must be empty. This array is replaced during a strategic
  2095. merge patch.
  2096. items:
  2097. type: string
  2098. type: array
  2099. x-kubernetes-list-type: atomic
  2100. required:
  2101. - key
  2102. - operator
  2103. type: object
  2104. type: array
  2105. x-kubernetes-list-type: atomic
  2106. matchLabels:
  2107. additionalProperties:
  2108. type: string
  2109. description: |-
  2110. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2111. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2112. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2113. type: object
  2114. type: object
  2115. x-kubernetes-map-type: atomic
  2116. type: object
  2117. type: object
  2118. template:
  2119. description: Template defines a blueprint for the created Secret resource.
  2120. properties:
  2121. data:
  2122. additionalProperties:
  2123. type: string
  2124. type: object
  2125. engineVersion:
  2126. default: v2
  2127. description: |-
  2128. EngineVersion specifies the template engine version
  2129. that should be used to compile/execute the
  2130. template specified in .data and .templateFrom[].
  2131. enum:
  2132. - v2
  2133. type: string
  2134. mergePolicy:
  2135. default: Replace
  2136. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  2137. enum:
  2138. - Replace
  2139. - Merge
  2140. type: string
  2141. metadata:
  2142. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  2143. properties:
  2144. annotations:
  2145. additionalProperties:
  2146. type: string
  2147. type: object
  2148. finalizers:
  2149. items:
  2150. type: string
  2151. type: array
  2152. labels:
  2153. additionalProperties:
  2154. type: string
  2155. type: object
  2156. type: object
  2157. templateFrom:
  2158. items:
  2159. description: |-
  2160. TemplateFrom specifies a source for templates.
  2161. Each item in the list can either reference a ConfigMap or a Secret resource.
  2162. properties:
  2163. configMap:
  2164. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2165. properties:
  2166. items:
  2167. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2168. items:
  2169. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2170. properties:
  2171. key:
  2172. description: A key in the ConfigMap/Secret
  2173. maxLength: 253
  2174. minLength: 1
  2175. pattern: ^[-._a-zA-Z0-9]+$
  2176. type: string
  2177. templateAs:
  2178. default: Values
  2179. description: TemplateScope specifies how the template keys should be interpreted.
  2180. enum:
  2181. - Values
  2182. - KeysAndValues
  2183. type: string
  2184. required:
  2185. - key
  2186. type: object
  2187. type: array
  2188. name:
  2189. description: The name of the ConfigMap/Secret resource
  2190. maxLength: 253
  2191. minLength: 1
  2192. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2193. type: string
  2194. required:
  2195. - items
  2196. - name
  2197. type: object
  2198. literal:
  2199. type: string
  2200. secret:
  2201. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2202. properties:
  2203. items:
  2204. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2205. items:
  2206. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2207. properties:
  2208. key:
  2209. description: A key in the ConfigMap/Secret
  2210. maxLength: 253
  2211. minLength: 1
  2212. pattern: ^[-._a-zA-Z0-9]+$
  2213. type: string
  2214. templateAs:
  2215. default: Values
  2216. description: TemplateScope specifies how the template keys should be interpreted.
  2217. enum:
  2218. - Values
  2219. - KeysAndValues
  2220. type: string
  2221. required:
  2222. - key
  2223. type: object
  2224. type: array
  2225. name:
  2226. description: The name of the ConfigMap/Secret resource
  2227. maxLength: 253
  2228. minLength: 1
  2229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2230. type: string
  2231. required:
  2232. - items
  2233. - name
  2234. type: object
  2235. target:
  2236. default: Data
  2237. description: |-
  2238. Target specifies where to place the template result.
  2239. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  2240. any other value is rejected because it would allow writes to privileged Secret fields.
  2241. For custom resources (when spec.target.manifest is set), this supports
  2242. nested paths like "spec.database.config" or "data".
  2243. type: string
  2244. valuesDecodingStrategy:
  2245. default: None
  2246. description: Used to define a decoding Strategy for the rendered template values.
  2247. enum:
  2248. - Auto
  2249. - Base64
  2250. - Base64URL
  2251. - None
  2252. type: string
  2253. type: object
  2254. type: array
  2255. type:
  2256. type: string
  2257. type: object
  2258. updatePolicy:
  2259. default: Replace
  2260. description: UpdatePolicy to handle Secrets in the provider.
  2261. enum:
  2262. - Replace
  2263. - IfNotExists
  2264. type: string
  2265. required:
  2266. - secretStoreRefs
  2267. - selector
  2268. type: object
  2269. refreshTime:
  2270. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  2271. type: string
  2272. required:
  2273. - pushSecretSpec
  2274. type: object
  2275. status:
  2276. description: ClusterPushSecretStatus contains the status information for the ClusterPushSecret resource.
  2277. properties:
  2278. conditions:
  2279. items:
  2280. description: PushSecretStatusCondition indicates the status of the PushSecret.
  2281. properties:
  2282. lastTransitionTime:
  2283. format: date-time
  2284. type: string
  2285. message:
  2286. type: string
  2287. reason:
  2288. type: string
  2289. status:
  2290. type: string
  2291. type:
  2292. description: PushSecretConditionType indicates the condition of the PushSecret.
  2293. type: string
  2294. required:
  2295. - status
  2296. - type
  2297. type: object
  2298. type: array
  2299. failedNamespaces:
  2300. description: Failed namespaces are the namespaces that failed to apply an PushSecret
  2301. items:
  2302. description: ClusterPushSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  2303. properties:
  2304. namespace:
  2305. description: Namespace is the namespace that failed when trying to apply an PushSecret
  2306. type: string
  2307. reason:
  2308. description: Reason is why the PushSecret failed to apply to the namespace
  2309. type: string
  2310. required:
  2311. - namespace
  2312. type: object
  2313. type: array
  2314. provisionedNamespaces:
  2315. description: ProvisionedNamespaces are the namespaces where the ClusterPushSecret has secrets
  2316. items:
  2317. type: string
  2318. type: array
  2319. pushSecretName:
  2320. type: string
  2321. type: object
  2322. type: object
  2323. served: true
  2324. storage: true
  2325. subresources:
  2326. status: {}
  2327. ---
  2328. apiVersion: apiextensions.k8s.io/v1
  2329. kind: CustomResourceDefinition
  2330. metadata:
  2331. annotations:
  2332. controller-gen.kubebuilder.io/version: v0.19.0
  2333. labels:
  2334. external-secrets.io/component: controller
  2335. name: clustersecretstores.external-secrets.io
  2336. spec:
  2337. group: external-secrets.io
  2338. names:
  2339. categories:
  2340. - external-secrets
  2341. kind: ClusterSecretStore
  2342. listKind: ClusterSecretStoreList
  2343. plural: clustersecretstores
  2344. shortNames:
  2345. - css
  2346. singular: clustersecretstore
  2347. scope: Cluster
  2348. versions:
  2349. - additionalPrinterColumns:
  2350. - jsonPath: .metadata.creationTimestamp
  2351. name: AGE
  2352. type: date
  2353. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  2354. name: Status
  2355. type: string
  2356. - jsonPath: .status.capabilities
  2357. name: Capabilities
  2358. type: string
  2359. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  2360. name: Ready
  2361. type: string
  2362. name: v1
  2363. schema:
  2364. openAPIV3Schema:
  2365. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  2366. properties:
  2367. apiVersion:
  2368. description: |-
  2369. APIVersion defines the versioned schema of this representation of an object.
  2370. Servers should convert recognized schemas to the latest internal value, and
  2371. may reject unrecognized values.
  2372. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  2373. type: string
  2374. kind:
  2375. description: |-
  2376. Kind is a string value representing the REST resource this object represents.
  2377. Servers may infer this from the endpoint the client submits requests to.
  2378. Cannot be updated.
  2379. In CamelCase.
  2380. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  2381. type: string
  2382. metadata:
  2383. type: object
  2384. spec:
  2385. description: SecretStoreSpec defines the desired state of SecretStore.
  2386. properties:
  2387. conditions:
  2388. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  2389. items:
  2390. description: |-
  2391. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  2392. for a ClusterSecretStore instance.
  2393. properties:
  2394. namespaceRegexes:
  2395. description: Choose namespaces by using regex matching
  2396. items:
  2397. type: string
  2398. type: array
  2399. namespaceSelector:
  2400. description: Choose namespace using a labelSelector
  2401. properties:
  2402. matchExpressions:
  2403. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2404. items:
  2405. description: |-
  2406. A label selector requirement is a selector that contains values, a key, and an operator that
  2407. relates the key and values.
  2408. properties:
  2409. key:
  2410. description: key is the label key that the selector applies to.
  2411. type: string
  2412. operator:
  2413. description: |-
  2414. operator represents a key's relationship to a set of values.
  2415. Valid operators are In, NotIn, Exists and DoesNotExist.
  2416. type: string
  2417. values:
  2418. description: |-
  2419. values is an array of string values. If the operator is In or NotIn,
  2420. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2421. the values array must be empty. This array is replaced during a strategic
  2422. merge patch.
  2423. items:
  2424. type: string
  2425. type: array
  2426. x-kubernetes-list-type: atomic
  2427. required:
  2428. - key
  2429. - operator
  2430. type: object
  2431. type: array
  2432. x-kubernetes-list-type: atomic
  2433. matchLabels:
  2434. additionalProperties:
  2435. type: string
  2436. description: |-
  2437. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2438. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2439. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2440. type: object
  2441. type: object
  2442. x-kubernetes-map-type: atomic
  2443. namespaces:
  2444. description: Choose namespaces by name
  2445. items:
  2446. maxLength: 63
  2447. minLength: 1
  2448. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2449. type: string
  2450. type: array
  2451. type: object
  2452. type: array
  2453. controller:
  2454. description: |-
  2455. Used to select the correct ESO controller (think: ingress.ingressClassName)
  2456. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  2457. type: string
  2458. provider:
  2459. description: Used to configure the provider. Only one provider may be set
  2460. maxProperties: 1
  2461. minProperties: 1
  2462. properties:
  2463. akeyless:
  2464. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  2465. properties:
  2466. akeylessGWApiURL:
  2467. description: Akeyless GW API Url from which the secrets to be fetched from.
  2468. type: string
  2469. authSecretRef:
  2470. description: Auth configures how the operator authenticates with Akeyless.
  2471. properties:
  2472. kubernetesAuth:
  2473. description: |-
  2474. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  2475. token stored in the named Secret resource.
  2476. properties:
  2477. accessID:
  2478. description: the Akeyless Kubernetes auth-method access-id
  2479. type: string
  2480. k8sConfName:
  2481. description: Kubernetes-auth configuration name in Akeyless-Gateway
  2482. type: string
  2483. secretRef:
  2484. description: |-
  2485. Optional secret field containing a Kubernetes ServiceAccount JWT used
  2486. for authenticating with Akeyless. If a name is specified without a key,
  2487. `token` is the default. If one is not specified, the one bound to
  2488. the controller will be used.
  2489. properties:
  2490. key:
  2491. description: |-
  2492. A key in the referenced Secret.
  2493. Some instances of this field may be defaulted, in others it may be required.
  2494. maxLength: 253
  2495. minLength: 1
  2496. pattern: ^[-._a-zA-Z0-9]+$
  2497. type: string
  2498. name:
  2499. description: The name of the Secret resource being referred to.
  2500. maxLength: 253
  2501. minLength: 1
  2502. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2503. type: string
  2504. namespace:
  2505. description: |-
  2506. The namespace of the Secret resource being referred to.
  2507. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2508. maxLength: 63
  2509. minLength: 1
  2510. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2511. type: string
  2512. type: object
  2513. serviceAccountRef:
  2514. description: |-
  2515. Optional service account field containing the name of a kubernetes ServiceAccount.
  2516. If the service account is specified, the service account secret token JWT will be used
  2517. for authenticating with Akeyless. If the service account selector is not supplied,
  2518. the secretRef will be used instead.
  2519. properties:
  2520. audiences:
  2521. description: |-
  2522. Audience specifies the `aud` claim for the service account token
  2523. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2524. then this audiences will be appended to the list
  2525. items:
  2526. type: string
  2527. type: array
  2528. name:
  2529. description: The name of the ServiceAccount resource being referred to.
  2530. maxLength: 253
  2531. minLength: 1
  2532. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2533. type: string
  2534. namespace:
  2535. description: |-
  2536. Namespace of the resource being referred to.
  2537. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2538. maxLength: 63
  2539. minLength: 1
  2540. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2541. type: string
  2542. required:
  2543. - name
  2544. type: object
  2545. required:
  2546. - accessID
  2547. - k8sConfName
  2548. type: object
  2549. secretRef:
  2550. description: |-
  2551. Reference to a Secret that contains the details
  2552. to authenticate with Akeyless.
  2553. properties:
  2554. accessID:
  2555. description: The SecretAccessID is used for authentication
  2556. properties:
  2557. key:
  2558. description: |-
  2559. A key in the referenced Secret.
  2560. Some instances of this field may be defaulted, in others it may be required.
  2561. maxLength: 253
  2562. minLength: 1
  2563. pattern: ^[-._a-zA-Z0-9]+$
  2564. type: string
  2565. name:
  2566. description: The name of the Secret resource being referred to.
  2567. maxLength: 253
  2568. minLength: 1
  2569. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2570. type: string
  2571. namespace:
  2572. description: |-
  2573. The namespace of the Secret resource being referred to.
  2574. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2575. maxLength: 63
  2576. minLength: 1
  2577. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2578. type: string
  2579. type: object
  2580. accessType:
  2581. description: |-
  2582. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2583. In some instances, `key` is a required field.
  2584. properties:
  2585. key:
  2586. description: |-
  2587. A key in the referenced Secret.
  2588. Some instances of this field may be defaulted, in others it may be required.
  2589. maxLength: 253
  2590. minLength: 1
  2591. pattern: ^[-._a-zA-Z0-9]+$
  2592. type: string
  2593. name:
  2594. description: The name of the Secret resource being referred to.
  2595. maxLength: 253
  2596. minLength: 1
  2597. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2598. type: string
  2599. namespace:
  2600. description: |-
  2601. The namespace of the Secret resource being referred to.
  2602. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2603. maxLength: 63
  2604. minLength: 1
  2605. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2606. type: string
  2607. type: object
  2608. accessTypeParam:
  2609. description: |-
  2610. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2611. In some instances, `key` is a required field.
  2612. properties:
  2613. key:
  2614. description: |-
  2615. A key in the referenced Secret.
  2616. Some instances of this field may be defaulted, in others it may be required.
  2617. maxLength: 253
  2618. minLength: 1
  2619. pattern: ^[-._a-zA-Z0-9]+$
  2620. type: string
  2621. name:
  2622. description: The name of the Secret resource being referred to.
  2623. maxLength: 253
  2624. minLength: 1
  2625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2626. type: string
  2627. namespace:
  2628. description: |-
  2629. The namespace of the Secret resource being referred to.
  2630. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2631. maxLength: 63
  2632. minLength: 1
  2633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2634. type: string
  2635. type: object
  2636. type: object
  2637. serviceAccountRef:
  2638. description: |-
  2639. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  2640. authentication on AKS Workload Identity. The operator obtains a federated
  2641. identity token from this ServiceAccount via the TokenRequest API instead
  2642. of using the ESO controller pod identity. Ignored for other access types.
  2643. properties:
  2644. audiences:
  2645. description: |-
  2646. Audience specifies the `aud` claim for the service account token
  2647. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2648. then this audiences will be appended to the list
  2649. items:
  2650. type: string
  2651. type: array
  2652. name:
  2653. description: The name of the ServiceAccount resource being referred to.
  2654. maxLength: 253
  2655. minLength: 1
  2656. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2657. type: string
  2658. namespace:
  2659. description: |-
  2660. Namespace of the resource being referred to.
  2661. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2662. maxLength: 63
  2663. minLength: 1
  2664. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2665. type: string
  2666. required:
  2667. - name
  2668. type: object
  2669. type: object
  2670. caBundle:
  2671. description: |-
  2672. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  2673. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  2674. are used to validate the TLS connection.
  2675. format: byte
  2676. type: string
  2677. caProvider:
  2678. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  2679. properties:
  2680. key:
  2681. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  2682. maxLength: 253
  2683. minLength: 1
  2684. pattern: ^[-._a-zA-Z0-9]+$
  2685. type: string
  2686. name:
  2687. description: The name of the object located at the provider type.
  2688. maxLength: 253
  2689. minLength: 1
  2690. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2691. type: string
  2692. namespace:
  2693. description: |-
  2694. The namespace the Provider type is in.
  2695. Can only be defined when used in a ClusterSecretStore.
  2696. maxLength: 63
  2697. minLength: 1
  2698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2699. type: string
  2700. type:
  2701. description: The type of provider to use such as "Secret", or "ConfigMap".
  2702. enum:
  2703. - Secret
  2704. - ConfigMap
  2705. type: string
  2706. required:
  2707. - name
  2708. - type
  2709. type: object
  2710. ignoreCache:
  2711. description: |-
  2712. IgnoreCache bypasses the Gateway cache for secret reads when true.
  2713. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  2714. type: boolean
  2715. required:
  2716. - akeylessGWApiURL
  2717. - authSecretRef
  2718. type: object
  2719. aws:
  2720. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  2721. properties:
  2722. additionalRoles:
  2723. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  2724. items:
  2725. type: string
  2726. type: array
  2727. auth:
  2728. description: |-
  2729. Auth defines the information necessary to authenticate against AWS
  2730. if not set aws sdk will infer credentials from your environment
  2731. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  2732. properties:
  2733. jwt:
  2734. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  2735. properties:
  2736. serviceAccountRef:
  2737. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  2738. properties:
  2739. audiences:
  2740. description: |-
  2741. Audience specifies the `aud` claim for the service account token
  2742. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2743. then this audiences will be appended to the list
  2744. items:
  2745. type: string
  2746. type: array
  2747. name:
  2748. description: The name of the ServiceAccount resource being referred to.
  2749. maxLength: 253
  2750. minLength: 1
  2751. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2752. type: string
  2753. namespace:
  2754. description: |-
  2755. Namespace of the resource being referred to.
  2756. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2757. maxLength: 63
  2758. minLength: 1
  2759. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2760. type: string
  2761. required:
  2762. - name
  2763. type: object
  2764. type: object
  2765. secretRef:
  2766. description: |-
  2767. AWSAuthSecretRef holds secret references for AWS credentials
  2768. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  2769. properties:
  2770. accessKeyIDSecretRef:
  2771. description: The AccessKeyID is used for authentication
  2772. properties:
  2773. key:
  2774. description: |-
  2775. A key in the referenced Secret.
  2776. Some instances of this field may be defaulted, in others it may be required.
  2777. maxLength: 253
  2778. minLength: 1
  2779. pattern: ^[-._a-zA-Z0-9]+$
  2780. type: string
  2781. name:
  2782. description: The name of the Secret resource being referred to.
  2783. maxLength: 253
  2784. minLength: 1
  2785. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2786. type: string
  2787. namespace:
  2788. description: |-
  2789. The namespace of the Secret resource being referred to.
  2790. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2791. maxLength: 63
  2792. minLength: 1
  2793. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2794. type: string
  2795. type: object
  2796. secretAccessKeySecretRef:
  2797. description: The SecretAccessKey is used for authentication
  2798. properties:
  2799. key:
  2800. description: |-
  2801. A key in the referenced Secret.
  2802. Some instances of this field may be defaulted, in others it may be required.
  2803. maxLength: 253
  2804. minLength: 1
  2805. pattern: ^[-._a-zA-Z0-9]+$
  2806. type: string
  2807. name:
  2808. description: The name of the Secret resource being referred to.
  2809. maxLength: 253
  2810. minLength: 1
  2811. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2812. type: string
  2813. namespace:
  2814. description: |-
  2815. The namespace of the Secret resource being referred to.
  2816. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2817. maxLength: 63
  2818. minLength: 1
  2819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2820. type: string
  2821. type: object
  2822. sessionTokenSecretRef:
  2823. description: |-
  2824. The SessionToken used for authentication
  2825. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  2826. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  2827. properties:
  2828. key:
  2829. description: |-
  2830. A key in the referenced Secret.
  2831. Some instances of this field may be defaulted, in others it may be required.
  2832. maxLength: 253
  2833. minLength: 1
  2834. pattern: ^[-._a-zA-Z0-9]+$
  2835. type: string
  2836. name:
  2837. description: The name of the Secret resource being referred to.
  2838. maxLength: 253
  2839. minLength: 1
  2840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2841. type: string
  2842. namespace:
  2843. description: |-
  2844. The namespace of the Secret resource being referred to.
  2845. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2846. maxLength: 63
  2847. minLength: 1
  2848. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2849. type: string
  2850. type: object
  2851. type: object
  2852. type: object
  2853. customSessionTags:
  2854. additionalProperties:
  2855. type: string
  2856. description: |-
  2857. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  2858. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  2859. type: object
  2860. x-kubernetes-validations:
  2861. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  2862. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  2863. externalID:
  2864. description: AWS External ID set on assumed IAM roles
  2865. type: string
  2866. prefix:
  2867. description: Prefix adds a prefix to all retrieved values.
  2868. type: string
  2869. region:
  2870. description: AWS Region to be used for the provider
  2871. type: string
  2872. role:
  2873. description: Role is a Role ARN which the provider will assume
  2874. type: string
  2875. secretsManager:
  2876. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  2877. properties:
  2878. forceDeleteWithoutRecovery:
  2879. description: |-
  2880. Specifies whether to delete the secret without any recovery window. You
  2881. can't use both this parameter and RecoveryWindowInDays in the same call.
  2882. If you don't use either, then by default Secrets Manager uses a 30 day
  2883. recovery window.
  2884. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  2885. type: boolean
  2886. recoveryWindowInDays:
  2887. description: |-
  2888. The number of days from 7 to 30 that Secrets Manager waits before
  2889. permanently deleting the secret. You can't use both this parameter and
  2890. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  2891. then by default Secrets Manager uses a 30-day recovery window.
  2892. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  2893. format: int64
  2894. type: integer
  2895. type: object
  2896. service:
  2897. description: Service defines which service should be used to fetch the secrets
  2898. enum:
  2899. - SecretsManager
  2900. - ParameterStore
  2901. - CertificateManager
  2902. type: string
  2903. sessionTags:
  2904. description: AWS STS assume role session tags
  2905. items:
  2906. description: |-
  2907. Tag is a key-value pair that can be attached to an AWS resource.
  2908. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  2909. properties:
  2910. key:
  2911. type: string
  2912. value:
  2913. type: string
  2914. required:
  2915. - key
  2916. - value
  2917. type: object
  2918. type: array
  2919. sessionTagsPolicy:
  2920. default: None
  2921. description: |-
  2922. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  2923. None (default): no tags are added.
  2924. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  2925. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  2926. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  2927. enum:
  2928. - None
  2929. - Simple
  2930. - Custom
  2931. type: string
  2932. transitiveTagKeys:
  2933. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  2934. items:
  2935. type: string
  2936. type: array
  2937. required:
  2938. - region
  2939. - service
  2940. type: object
  2941. azurekv:
  2942. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  2943. properties:
  2944. authSecretRef:
  2945. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  2946. properties:
  2947. clientCertificate:
  2948. description: The Azure ClientCertificate of the service principle used for authentication.
  2949. properties:
  2950. key:
  2951. description: |-
  2952. A key in the referenced Secret.
  2953. Some instances of this field may be defaulted, in others it may be required.
  2954. maxLength: 253
  2955. minLength: 1
  2956. pattern: ^[-._a-zA-Z0-9]+$
  2957. type: string
  2958. name:
  2959. description: The name of the Secret resource being referred to.
  2960. maxLength: 253
  2961. minLength: 1
  2962. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2963. type: string
  2964. namespace:
  2965. description: |-
  2966. The namespace of the Secret resource being referred to.
  2967. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2968. maxLength: 63
  2969. minLength: 1
  2970. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2971. type: string
  2972. type: object
  2973. clientId:
  2974. description: The Azure clientId of the service principle or managed identity used for authentication.
  2975. properties:
  2976. key:
  2977. description: |-
  2978. A key in the referenced Secret.
  2979. Some instances of this field may be defaulted, in others it may be required.
  2980. maxLength: 253
  2981. minLength: 1
  2982. pattern: ^[-._a-zA-Z0-9]+$
  2983. type: string
  2984. name:
  2985. description: The name of the Secret resource being referred to.
  2986. maxLength: 253
  2987. minLength: 1
  2988. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2989. type: string
  2990. namespace:
  2991. description: |-
  2992. The namespace of the Secret resource being referred to.
  2993. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2994. maxLength: 63
  2995. minLength: 1
  2996. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2997. type: string
  2998. type: object
  2999. clientSecret:
  3000. description: The Azure ClientSecret of the service principle used for authentication.
  3001. properties:
  3002. key:
  3003. description: |-
  3004. A key in the referenced Secret.
  3005. Some instances of this field may be defaulted, in others it may be required.
  3006. maxLength: 253
  3007. minLength: 1
  3008. pattern: ^[-._a-zA-Z0-9]+$
  3009. type: string
  3010. name:
  3011. description: The name of the Secret resource being referred to.
  3012. maxLength: 253
  3013. minLength: 1
  3014. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3015. type: string
  3016. namespace:
  3017. description: |-
  3018. The namespace of the Secret resource being referred to.
  3019. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3020. maxLength: 63
  3021. minLength: 1
  3022. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3023. type: string
  3024. type: object
  3025. tenantId:
  3026. description: The Azure tenantId of the managed identity used for authentication.
  3027. properties:
  3028. key:
  3029. description: |-
  3030. A key in the referenced Secret.
  3031. Some instances of this field may be defaulted, in others it may be required.
  3032. maxLength: 253
  3033. minLength: 1
  3034. pattern: ^[-._a-zA-Z0-9]+$
  3035. type: string
  3036. name:
  3037. description: The name of the Secret resource being referred to.
  3038. maxLength: 253
  3039. minLength: 1
  3040. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3041. type: string
  3042. namespace:
  3043. description: |-
  3044. The namespace of the Secret resource being referred to.
  3045. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3046. maxLength: 63
  3047. minLength: 1
  3048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3049. type: string
  3050. type: object
  3051. type: object
  3052. authType:
  3053. default: ServicePrincipal
  3054. description: |-
  3055. Auth type defines how to authenticate to the keyvault service.
  3056. Valid values are:
  3057. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  3058. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  3059. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  3060. enum:
  3061. - ServicePrincipal
  3062. - ManagedIdentity
  3063. - WorkloadIdentity
  3064. type: string
  3065. customCloudConfig:
  3066. description: |-
  3067. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  3068. Required when EnvironmentType is AzureStackCloud.
  3069. Optional for other environment types - useful for Azure China when using Workload Identity
  3070. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  3071. standard China Cloud endpoint (login.chinacloudapi.cn).
  3072. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  3073. configuration is not supported with the legacy go-autorest SDK.
  3074. properties:
  3075. activeDirectoryEndpoint:
  3076. description: |-
  3077. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  3078. Required when using custom cloud configuration
  3079. type: string
  3080. keyVaultDNSSuffix:
  3081. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  3082. type: string
  3083. keyVaultEndpoint:
  3084. description: KeyVaultEndpoint is the Key Vault service endpoint
  3085. type: string
  3086. resourceManagerEndpoint:
  3087. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  3088. type: string
  3089. required:
  3090. - activeDirectoryEndpoint
  3091. type: object
  3092. environmentType:
  3093. default: PublicCloud
  3094. description: |-
  3095. EnvironmentType specifies the Azure cloud environment endpoints to use for
  3096. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  3097. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  3098. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  3099. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  3100. enum:
  3101. - PublicCloud
  3102. - USGovernmentCloud
  3103. - ChinaCloud
  3104. - GermanCloud
  3105. - AzureStackCloud
  3106. type: string
  3107. identityId:
  3108. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  3109. type: string
  3110. serviceAccountRef:
  3111. description: |-
  3112. ServiceAccountRef specified the service account
  3113. that should be used when authenticating with WorkloadIdentity.
  3114. properties:
  3115. audiences:
  3116. description: |-
  3117. Audience specifies the `aud` claim for the service account token
  3118. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  3119. then this audiences will be appended to the list
  3120. items:
  3121. type: string
  3122. type: array
  3123. name:
  3124. description: The name of the ServiceAccount resource being referred to.
  3125. maxLength: 253
  3126. minLength: 1
  3127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3128. type: string
  3129. namespace:
  3130. description: |-
  3131. Namespace of the resource being referred to.
  3132. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3133. maxLength: 63
  3134. minLength: 1
  3135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3136. type: string
  3137. required:
  3138. - name
  3139. type: object
  3140. tenantId:
  3141. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  3142. type: string
  3143. useAzureSDK:
  3144. default: false
  3145. description: |-
  3146. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  3147. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  3148. type: boolean
  3149. vaultUrl:
  3150. description: Vault Url from which the secrets to be fetched from.
  3151. type: string
  3152. required:
  3153. - vaultUrl
  3154. type: object
  3155. barbican:
  3156. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  3157. properties:
  3158. auth:
  3159. description: BarbicanAuth contains the authentication information for Barbican.
  3160. properties:
  3161. password:
  3162. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  3163. properties:
  3164. secretRef:
  3165. description: |-
  3166. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3167. In some instances, `key` is a required field.
  3168. properties:
  3169. key:
  3170. description: |-
  3171. A key in the referenced Secret.
  3172. Some instances of this field may be defaulted, in others it may be required.
  3173. maxLength: 253
  3174. minLength: 1
  3175. pattern: ^[-._a-zA-Z0-9]+$
  3176. type: string
  3177. name:
  3178. description: The name of the Secret resource being referred to.
  3179. maxLength: 253
  3180. minLength: 1
  3181. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3182. type: string
  3183. namespace:
  3184. description: |-
  3185. The namespace of the Secret resource being referred to.
  3186. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3187. maxLength: 63
  3188. minLength: 1
  3189. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3190. type: string
  3191. type: object
  3192. required:
  3193. - secretRef
  3194. type: object
  3195. username:
  3196. description: BarbicanProviderUsernameRef defines a reference to a secret containing username for the Barbican provider.
  3197. maxProperties: 1
  3198. minProperties: 1
  3199. properties:
  3200. secretRef:
  3201. description: |-
  3202. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3203. In some instances, `key` is a required field.
  3204. properties:
  3205. key:
  3206. description: |-
  3207. A key in the referenced Secret.
  3208. Some instances of this field may be defaulted, in others it may be required.
  3209. maxLength: 253
  3210. minLength: 1
  3211. pattern: ^[-._a-zA-Z0-9]+$
  3212. type: string
  3213. name:
  3214. description: The name of the Secret resource being referred to.
  3215. maxLength: 253
  3216. minLength: 1
  3217. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3218. type: string
  3219. namespace:
  3220. description: |-
  3221. The namespace of the Secret resource being referred to.
  3222. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3223. maxLength: 63
  3224. minLength: 1
  3225. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3226. type: string
  3227. type: object
  3228. value:
  3229. type: string
  3230. type: object
  3231. required:
  3232. - password
  3233. - username
  3234. type: object
  3235. authURL:
  3236. type: string
  3237. domainName:
  3238. type: string
  3239. region:
  3240. type: string
  3241. tenantName:
  3242. type: string
  3243. required:
  3244. - auth
  3245. type: object
  3246. beyondtrust:
  3247. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  3248. properties:
  3249. auth:
  3250. description: Auth configures how the operator authenticates with Beyondtrust.
  3251. properties:
  3252. apiKey:
  3253. description: APIKey If not provided then ClientID/ClientSecret become required.
  3254. properties:
  3255. secretRef:
  3256. description: SecretRef references a key in a secret that will be used as value.
  3257. properties:
  3258. key:
  3259. description: |-
  3260. A key in the referenced Secret.
  3261. Some instances of this field may be defaulted, in others it may be required.
  3262. maxLength: 253
  3263. minLength: 1
  3264. pattern: ^[-._a-zA-Z0-9]+$
  3265. type: string
  3266. name:
  3267. description: The name of the Secret resource being referred to.
  3268. maxLength: 253
  3269. minLength: 1
  3270. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3271. type: string
  3272. namespace:
  3273. description: |-
  3274. The namespace of the Secret resource being referred to.
  3275. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3276. maxLength: 63
  3277. minLength: 1
  3278. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3279. type: string
  3280. type: object
  3281. value:
  3282. description: Value can be specified directly to set a value without using a secret.
  3283. type: string
  3284. type: object
  3285. certificate:
  3286. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  3287. properties:
  3288. secretRef:
  3289. description: SecretRef references a key in a secret that will be used as value.
  3290. properties:
  3291. key:
  3292. description: |-
  3293. A key in the referenced Secret.
  3294. Some instances of this field may be defaulted, in others it may be required.
  3295. maxLength: 253
  3296. minLength: 1
  3297. pattern: ^[-._a-zA-Z0-9]+$
  3298. type: string
  3299. name:
  3300. description: The name of the Secret resource being referred to.
  3301. maxLength: 253
  3302. minLength: 1
  3303. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3304. type: string
  3305. namespace:
  3306. description: |-
  3307. The namespace of the Secret resource being referred to.
  3308. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3309. maxLength: 63
  3310. minLength: 1
  3311. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3312. type: string
  3313. type: object
  3314. value:
  3315. description: Value can be specified directly to set a value without using a secret.
  3316. type: string
  3317. type: object
  3318. certificateKey:
  3319. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  3320. properties:
  3321. secretRef:
  3322. description: SecretRef references a key in a secret that will be used as value.
  3323. properties:
  3324. key:
  3325. description: |-
  3326. A key in the referenced Secret.
  3327. Some instances of this field may be defaulted, in others it may be required.
  3328. maxLength: 253
  3329. minLength: 1
  3330. pattern: ^[-._a-zA-Z0-9]+$
  3331. type: string
  3332. name:
  3333. description: The name of the Secret resource being referred to.
  3334. maxLength: 253
  3335. minLength: 1
  3336. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3337. type: string
  3338. namespace:
  3339. description: |-
  3340. The namespace of the Secret resource being referred to.
  3341. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3342. maxLength: 63
  3343. minLength: 1
  3344. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3345. type: string
  3346. type: object
  3347. value:
  3348. description: Value can be specified directly to set a value without using a secret.
  3349. type: string
  3350. type: object
  3351. clientId:
  3352. description: ClientID is the API OAuth Client ID.
  3353. properties:
  3354. secretRef:
  3355. description: SecretRef references a key in a secret that will be used as value.
  3356. properties:
  3357. key:
  3358. description: |-
  3359. A key in the referenced Secret.
  3360. Some instances of this field may be defaulted, in others it may be required.
  3361. maxLength: 253
  3362. minLength: 1
  3363. pattern: ^[-._a-zA-Z0-9]+$
  3364. type: string
  3365. name:
  3366. description: The name of the Secret resource being referred to.
  3367. maxLength: 253
  3368. minLength: 1
  3369. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3370. type: string
  3371. namespace:
  3372. description: |-
  3373. The namespace of the Secret resource being referred to.
  3374. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3375. maxLength: 63
  3376. minLength: 1
  3377. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3378. type: string
  3379. type: object
  3380. value:
  3381. description: Value can be specified directly to set a value without using a secret.
  3382. type: string
  3383. type: object
  3384. clientSecret:
  3385. description: ClientSecret is the API OAuth Client Secret.
  3386. properties:
  3387. secretRef:
  3388. description: SecretRef references a key in a secret that will be used as value.
  3389. properties:
  3390. key:
  3391. description: |-
  3392. A key in the referenced Secret.
  3393. Some instances of this field may be defaulted, in others it may be required.
  3394. maxLength: 253
  3395. minLength: 1
  3396. pattern: ^[-._a-zA-Z0-9]+$
  3397. type: string
  3398. name:
  3399. description: The name of the Secret resource being referred to.
  3400. maxLength: 253
  3401. minLength: 1
  3402. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3403. type: string
  3404. namespace:
  3405. description: |-
  3406. The namespace of the Secret resource being referred to.
  3407. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3408. maxLength: 63
  3409. minLength: 1
  3410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3411. type: string
  3412. type: object
  3413. value:
  3414. description: Value can be specified directly to set a value without using a secret.
  3415. type: string
  3416. type: object
  3417. type: object
  3418. server:
  3419. description: Auth configures how API server works.
  3420. properties:
  3421. apiUrl:
  3422. type: string
  3423. apiVersion:
  3424. type: string
  3425. clientTimeOutSeconds:
  3426. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  3427. type: integer
  3428. decrypt:
  3429. default: true
  3430. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  3431. type: boolean
  3432. retrievalType:
  3433. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  3434. type: string
  3435. separator:
  3436. description: A character that separates the folder names.
  3437. type: string
  3438. verifyCA:
  3439. type: boolean
  3440. required:
  3441. - apiUrl
  3442. - verifyCA
  3443. type: object
  3444. required:
  3445. - auth
  3446. - server
  3447. type: object
  3448. beyondtrustworkloadcredentials:
  3449. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  3450. properties:
  3451. auth:
  3452. description: |-
  3453. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  3454. Currently supports API key authentication via Kubernetes secret reference.
  3455. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3456. properties:
  3457. apikey:
  3458. description: |-
  3459. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  3460. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  3461. properties:
  3462. token:
  3463. description: |-
  3464. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  3465. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  3466. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  3467. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3468. properties:
  3469. key:
  3470. description: |-
  3471. A key in the referenced Secret.
  3472. Some instances of this field may be defaulted, in others it may be required.
  3473. maxLength: 253
  3474. minLength: 1
  3475. pattern: ^[-._a-zA-Z0-9]+$
  3476. type: string
  3477. name:
  3478. description: The name of the Secret resource being referred to.
  3479. maxLength: 253
  3480. minLength: 1
  3481. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3482. type: string
  3483. namespace:
  3484. description: |-
  3485. The namespace of the Secret resource being referred to.
  3486. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3487. maxLength: 63
  3488. minLength: 1
  3489. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3490. type: string
  3491. type: object
  3492. required:
  3493. - token
  3494. type: object
  3495. required:
  3496. - apikey
  3497. type: object
  3498. caBundle:
  3499. description: |-
  3500. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3501. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  3502. If not set, the system's trusted root certificates are used.
  3503. format: byte
  3504. type: string
  3505. caProvider:
  3506. description: |-
  3507. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  3508. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3509. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  3510. properties:
  3511. key:
  3512. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3513. maxLength: 253
  3514. minLength: 1
  3515. pattern: ^[-._a-zA-Z0-9]+$
  3516. type: string
  3517. name:
  3518. description: The name of the object located at the provider type.
  3519. maxLength: 253
  3520. minLength: 1
  3521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3522. type: string
  3523. namespace:
  3524. description: |-
  3525. The namespace the Provider type is in.
  3526. Can only be defined when used in a ClusterSecretStore.
  3527. maxLength: 63
  3528. minLength: 1
  3529. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3530. type: string
  3531. type:
  3532. description: The type of provider to use such as "Secret", or "ConfigMap".
  3533. enum:
  3534. - Secret
  3535. - ConfigMap
  3536. type: string
  3537. required:
  3538. - name
  3539. - type
  3540. type: object
  3541. folderPath:
  3542. description: |-
  3543. FolderPath specifies the default folder path for secret retrieval.
  3544. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  3545. Example: "production/database" or "dev/api-keys"
  3546. Leave empty to retrieve secrets from the root folder.
  3547. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  3548. type: string
  3549. server:
  3550. description: |-
  3551. Server configures the BeyondTrust Workload Credentials server connection details.
  3552. Includes the API URL and Site ID for your BeyondTrust instance.
  3553. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3554. properties:
  3555. apiUrl:
  3556. description: |-
  3557. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  3558. This should be the full URL to your BeyondTrust instance.
  3559. Example: https://api.beyondtrust.io/siie
  3560. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  3561. type: string
  3562. siteId:
  3563. description: |-
  3564. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  3565. This identifier is unique to your BeyondTrust Workload Credentials instance.
  3566. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  3567. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  3568. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3569. type: string
  3570. required:
  3571. - apiUrl
  3572. - siteId
  3573. type: object
  3574. required:
  3575. - auth
  3576. - server
  3577. type: object
  3578. bitwardensecretsmanager:
  3579. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  3580. properties:
  3581. apiURL:
  3582. type: string
  3583. auth:
  3584. description: |-
  3585. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  3586. Make sure that the token being used has permissions on the given secret.
  3587. properties:
  3588. secretRef:
  3589. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  3590. properties:
  3591. credentials:
  3592. description: AccessToken used for the bitwarden instance.
  3593. properties:
  3594. key:
  3595. description: |-
  3596. A key in the referenced Secret.
  3597. Some instances of this field may be defaulted, in others it may be required.
  3598. maxLength: 253
  3599. minLength: 1
  3600. pattern: ^[-._a-zA-Z0-9]+$
  3601. type: string
  3602. name:
  3603. description: The name of the Secret resource being referred to.
  3604. maxLength: 253
  3605. minLength: 1
  3606. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3607. type: string
  3608. namespace:
  3609. description: |-
  3610. The namespace of the Secret resource being referred to.
  3611. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3612. maxLength: 63
  3613. minLength: 1
  3614. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3615. type: string
  3616. type: object
  3617. required:
  3618. - credentials
  3619. type: object
  3620. required:
  3621. - secretRef
  3622. type: object
  3623. bitwardenServerSDKURL:
  3624. type: string
  3625. caBundle:
  3626. description: |-
  3627. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  3628. can be performed.
  3629. type: string
  3630. caProvider:
  3631. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  3632. properties:
  3633. key:
  3634. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3635. maxLength: 253
  3636. minLength: 1
  3637. pattern: ^[-._a-zA-Z0-9]+$
  3638. type: string
  3639. name:
  3640. description: The name of the object located at the provider type.
  3641. maxLength: 253
  3642. minLength: 1
  3643. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3644. type: string
  3645. namespace:
  3646. description: |-
  3647. The namespace the Provider type is in.
  3648. Can only be defined when used in a ClusterSecretStore.
  3649. maxLength: 63
  3650. minLength: 1
  3651. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3652. type: string
  3653. type:
  3654. description: The type of provider to use such as "Secret", or "ConfigMap".
  3655. enum:
  3656. - Secret
  3657. - ConfigMap
  3658. type: string
  3659. required:
  3660. - name
  3661. - type
  3662. type: object
  3663. identityURL:
  3664. type: string
  3665. organizationID:
  3666. description: OrganizationID determines which organization this secret store manages.
  3667. type: string
  3668. projectID:
  3669. description: ProjectID determines which project this secret store manages.
  3670. type: string
  3671. required:
  3672. - auth
  3673. - organizationID
  3674. - projectID
  3675. type: object
  3676. chef:
  3677. description: Chef configures this store to sync secrets with chef server
  3678. properties:
  3679. auth:
  3680. description: Auth defines the information necessary to authenticate against chef Server
  3681. properties:
  3682. secretRef:
  3683. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  3684. properties:
  3685. privateKeySecretRef:
  3686. description: SecretKey is the Signing Key in PEM format, used for authentication.
  3687. properties:
  3688. key:
  3689. description: |-
  3690. A key in the referenced Secret.
  3691. Some instances of this field may be defaulted, in others it may be required.
  3692. maxLength: 253
  3693. minLength: 1
  3694. pattern: ^[-._a-zA-Z0-9]+$
  3695. type: string
  3696. name:
  3697. description: The name of the Secret resource being referred to.
  3698. maxLength: 253
  3699. minLength: 1
  3700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3701. type: string
  3702. namespace:
  3703. description: |-
  3704. The namespace of the Secret resource being referred to.
  3705. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3706. maxLength: 63
  3707. minLength: 1
  3708. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3709. type: string
  3710. type: object
  3711. required:
  3712. - privateKeySecretRef
  3713. type: object
  3714. required:
  3715. - secretRef
  3716. type: object
  3717. serverUrl:
  3718. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  3719. type: string
  3720. username:
  3721. description: UserName should be the user ID on the chef server
  3722. type: string
  3723. required:
  3724. - auth
  3725. - serverUrl
  3726. - username
  3727. type: object
  3728. cloudrusm:
  3729. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  3730. properties:
  3731. auth:
  3732. description: CSMAuth contains a secretRef for credentials.
  3733. properties:
  3734. secretRef:
  3735. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  3736. properties:
  3737. accessKeyIDSecretRef:
  3738. description: The AccessKeyID is used for authentication
  3739. properties:
  3740. key:
  3741. description: |-
  3742. A key in the referenced Secret.
  3743. Some instances of this field may be defaulted, in others it may be required.
  3744. maxLength: 253
  3745. minLength: 1
  3746. pattern: ^[-._a-zA-Z0-9]+$
  3747. type: string
  3748. name:
  3749. description: The name of the Secret resource being referred to.
  3750. maxLength: 253
  3751. minLength: 1
  3752. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3753. type: string
  3754. namespace:
  3755. description: |-
  3756. The namespace of the Secret resource being referred to.
  3757. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3758. maxLength: 63
  3759. minLength: 1
  3760. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3761. type: string
  3762. type: object
  3763. accessKeySecretSecretRef:
  3764. description: The AccessKeySecret is used for authentication
  3765. properties:
  3766. key:
  3767. description: |-
  3768. A key in the referenced Secret.
  3769. Some instances of this field may be defaulted, in others it may be required.
  3770. maxLength: 253
  3771. minLength: 1
  3772. pattern: ^[-._a-zA-Z0-9]+$
  3773. type: string
  3774. name:
  3775. description: The name of the Secret resource being referred to.
  3776. maxLength: 253
  3777. minLength: 1
  3778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3779. type: string
  3780. namespace:
  3781. description: |-
  3782. The namespace of the Secret resource being referred to.
  3783. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3784. maxLength: 63
  3785. minLength: 1
  3786. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3787. type: string
  3788. type: object
  3789. required:
  3790. - accessKeyIDSecretRef
  3791. - accessKeySecretSecretRef
  3792. type: object
  3793. type: object
  3794. projectID:
  3795. description: ProjectID is the project, which the secrets are stored in.
  3796. type: string
  3797. required:
  3798. - auth
  3799. type: object
  3800. conjur:
  3801. description: Conjur configures this store to sync secrets using conjur provider
  3802. properties:
  3803. auth:
  3804. description: Defines authentication settings for connecting to Conjur.
  3805. maxProperties: 1
  3806. minProperties: 1
  3807. properties:
  3808. apikey:
  3809. description: Authenticates with Conjur using an API key.
  3810. properties:
  3811. account:
  3812. description: Account is the Conjur organization account name.
  3813. type: string
  3814. apiKeyRef:
  3815. description: |-
  3816. A reference to a specific 'key' containing the Conjur API key
  3817. within a Secret resource. In some instances, `key` is a required field.
  3818. properties:
  3819. key:
  3820. description: |-
  3821. A key in the referenced Secret.
  3822. Some instances of this field may be defaulted, in others it may be required.
  3823. maxLength: 253
  3824. minLength: 1
  3825. pattern: ^[-._a-zA-Z0-9]+$
  3826. type: string
  3827. name:
  3828. description: The name of the Secret resource being referred to.
  3829. maxLength: 253
  3830. minLength: 1
  3831. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3832. type: string
  3833. namespace:
  3834. description: |-
  3835. The namespace of the Secret resource being referred to.
  3836. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3837. maxLength: 63
  3838. minLength: 1
  3839. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3840. type: string
  3841. type: object
  3842. userRef:
  3843. description: |-
  3844. A reference to a specific 'key' containing the Conjur username
  3845. within a Secret resource. In some instances, `key` is a required field.
  3846. properties:
  3847. key:
  3848. description: |-
  3849. A key in the referenced Secret.
  3850. Some instances of this field may be defaulted, in others it may be required.
  3851. maxLength: 253
  3852. minLength: 1
  3853. pattern: ^[-._a-zA-Z0-9]+$
  3854. type: string
  3855. name:
  3856. description: The name of the Secret resource being referred to.
  3857. maxLength: 253
  3858. minLength: 1
  3859. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3860. type: string
  3861. namespace:
  3862. description: |-
  3863. The namespace of the Secret resource being referred to.
  3864. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3865. maxLength: 63
  3866. minLength: 1
  3867. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3868. type: string
  3869. type: object
  3870. required:
  3871. - account
  3872. - apiKeyRef
  3873. - userRef
  3874. type: object
  3875. cert:
  3876. description: Cert enables certificate-based authentication using a client certificate and key.
  3877. properties:
  3878. account:
  3879. description: Account is the Conjur organization account name.
  3880. type: string
  3881. clientCertRef:
  3882. description: |-
  3883. ClientCertRef is a reference to a specific 'key' containing the client certificate
  3884. within a Secret resource. The certificate must be PEM-encoded.
  3885. properties:
  3886. key:
  3887. description: |-
  3888. A key in the referenced Secret.
  3889. Some instances of this field may be defaulted, in others it may be required.
  3890. maxLength: 253
  3891. minLength: 1
  3892. pattern: ^[-._a-zA-Z0-9]+$
  3893. type: string
  3894. name:
  3895. description: The name of the Secret resource being referred to.
  3896. maxLength: 253
  3897. minLength: 1
  3898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3899. type: string
  3900. namespace:
  3901. description: |-
  3902. The namespace of the Secret resource being referred to.
  3903. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3904. maxLength: 63
  3905. minLength: 1
  3906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3907. type: string
  3908. type: object
  3909. clientKeyRef:
  3910. description: |-
  3911. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  3912. within a Secret resource. The key must be PEM-encoded.
  3913. properties:
  3914. key:
  3915. description: |-
  3916. A key in the referenced Secret.
  3917. Some instances of this field may be defaulted, in others it may be required.
  3918. maxLength: 253
  3919. minLength: 1
  3920. pattern: ^[-._a-zA-Z0-9]+$
  3921. type: string
  3922. name:
  3923. description: The name of the Secret resource being referred to.
  3924. maxLength: 253
  3925. minLength: 1
  3926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3927. type: string
  3928. namespace:
  3929. description: |-
  3930. The namespace of the Secret resource being referred to.
  3931. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3932. maxLength: 63
  3933. minLength: 1
  3934. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3935. type: string
  3936. type: object
  3937. hostId:
  3938. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  3939. type: string
  3940. serviceID:
  3941. description: The conjur authn cert webservice id
  3942. type: string
  3943. required:
  3944. - account
  3945. - clientCertRef
  3946. - clientKeyRef
  3947. - serviceID
  3948. type: object
  3949. jwt:
  3950. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  3951. properties:
  3952. account:
  3953. description: Account is the Conjur organization account name.
  3954. type: string
  3955. hostId:
  3956. description: |-
  3957. Optional HostID for JWT authentication. This may be used depending
  3958. on how the Conjur JWT authenticator policy is configured.
  3959. type: string
  3960. secretRef:
  3961. description: |-
  3962. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  3963. authenticate with Conjur using the JWT authentication method.
  3964. properties:
  3965. key:
  3966. description: |-
  3967. A key in the referenced Secret.
  3968. Some instances of this field may be defaulted, in others it may be required.
  3969. maxLength: 253
  3970. minLength: 1
  3971. pattern: ^[-._a-zA-Z0-9]+$
  3972. type: string
  3973. name:
  3974. description: The name of the Secret resource being referred to.
  3975. maxLength: 253
  3976. minLength: 1
  3977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3978. type: string
  3979. namespace:
  3980. description: |-
  3981. The namespace of the Secret resource being referred to.
  3982. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3983. maxLength: 63
  3984. minLength: 1
  3985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3986. type: string
  3987. type: object
  3988. serviceAccountRef:
  3989. description: |-
  3990. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  3991. a token for with the `TokenRequest` API.
  3992. properties:
  3993. audiences:
  3994. description: |-
  3995. Audience specifies the `aud` claim for the service account token
  3996. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  3997. then this audiences will be appended to the list
  3998. items:
  3999. type: string
  4000. type: array
  4001. name:
  4002. description: The name of the ServiceAccount resource being referred to.
  4003. maxLength: 253
  4004. minLength: 1
  4005. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4006. type: string
  4007. namespace:
  4008. description: |-
  4009. Namespace of the resource being referred to.
  4010. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4011. maxLength: 63
  4012. minLength: 1
  4013. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4014. type: string
  4015. required:
  4016. - name
  4017. type: object
  4018. serviceID:
  4019. description: The conjur authn jwt webservice id
  4020. type: string
  4021. required:
  4022. - account
  4023. - serviceID
  4024. type: object
  4025. type: object
  4026. caBundle:
  4027. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  4028. type: string
  4029. caProvider:
  4030. description: |-
  4031. Used to provide custom certificate authority (CA) certificates
  4032. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  4033. that contains a PEM-encoded certificate.
  4034. properties:
  4035. key:
  4036. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4037. maxLength: 253
  4038. minLength: 1
  4039. pattern: ^[-._a-zA-Z0-9]+$
  4040. type: string
  4041. name:
  4042. description: The name of the object located at the provider type.
  4043. maxLength: 253
  4044. minLength: 1
  4045. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4046. type: string
  4047. namespace:
  4048. description: |-
  4049. The namespace the Provider type is in.
  4050. Can only be defined when used in a ClusterSecretStore.
  4051. maxLength: 63
  4052. minLength: 1
  4053. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4054. type: string
  4055. type:
  4056. description: The type of provider to use such as "Secret", or "ConfigMap".
  4057. enum:
  4058. - Secret
  4059. - ConfigMap
  4060. type: string
  4061. required:
  4062. - name
  4063. - type
  4064. type: object
  4065. url:
  4066. description: URL is the endpoint of the Conjur instance.
  4067. type: string
  4068. required:
  4069. - auth
  4070. - url
  4071. type: object
  4072. crd:
  4073. description: |-
  4074. CRD configures this store to sync secrets from arbitrary Kubernetes resources,
  4075. including both custom resources (CRDs) and core API resources. Resources are
  4076. selected by API group, version and kind, where group can be "" (empty string)
  4077. for core resources such as ConfigMap. Reading the core v1 Secret is
  4078. intentionally blocked — use the Kubernetes provider for that.
  4079. properties:
  4080. auth:
  4081. description: |-
  4082. Auth configures authentication to the Kubernetes API, same as the
  4083. Kubernetes provider. Required when Server.URL is set (unless using AuthRef).
  4084. maxProperties: 1
  4085. minProperties: 1
  4086. properties:
  4087. cert:
  4088. description: has both clientCert and clientKey as secretKeySelector
  4089. properties:
  4090. clientCert:
  4091. description: |-
  4092. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4093. In some instances, `key` is a required field.
  4094. properties:
  4095. key:
  4096. description: |-
  4097. A key in the referenced Secret.
  4098. Some instances of this field may be defaulted, in others it may be required.
  4099. maxLength: 253
  4100. minLength: 1
  4101. pattern: ^[-._a-zA-Z0-9]+$
  4102. type: string
  4103. name:
  4104. description: The name of the Secret resource being referred to.
  4105. maxLength: 253
  4106. minLength: 1
  4107. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4108. type: string
  4109. namespace:
  4110. description: |-
  4111. The namespace of the Secret resource being referred to.
  4112. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4113. maxLength: 63
  4114. minLength: 1
  4115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4116. type: string
  4117. type: object
  4118. clientKey:
  4119. description: |-
  4120. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4121. In some instances, `key` is a required field.
  4122. properties:
  4123. key:
  4124. description: |-
  4125. A key in the referenced Secret.
  4126. Some instances of this field may be defaulted, in others it may be required.
  4127. maxLength: 253
  4128. minLength: 1
  4129. pattern: ^[-._a-zA-Z0-9]+$
  4130. type: string
  4131. name:
  4132. description: The name of the Secret resource being referred to.
  4133. maxLength: 253
  4134. minLength: 1
  4135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4136. type: string
  4137. namespace:
  4138. description: |-
  4139. The namespace of the Secret resource being referred to.
  4140. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4141. maxLength: 63
  4142. minLength: 1
  4143. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4144. type: string
  4145. type: object
  4146. required:
  4147. - clientCert
  4148. - clientKey
  4149. type: object
  4150. serviceAccount:
  4151. description: points to a service account that should be used for authentication
  4152. properties:
  4153. audiences:
  4154. description: |-
  4155. Audience specifies the `aud` claim for the service account token
  4156. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4157. then this audiences will be appended to the list
  4158. items:
  4159. type: string
  4160. type: array
  4161. name:
  4162. description: The name of the ServiceAccount resource being referred to.
  4163. maxLength: 253
  4164. minLength: 1
  4165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4166. type: string
  4167. namespace:
  4168. description: |-
  4169. Namespace of the resource being referred to.
  4170. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4171. maxLength: 63
  4172. minLength: 1
  4173. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4174. type: string
  4175. required:
  4176. - name
  4177. type: object
  4178. token:
  4179. description: use static token to authenticate with
  4180. properties:
  4181. bearerToken:
  4182. description: |-
  4183. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4184. In some instances, `key` is a required field.
  4185. properties:
  4186. key:
  4187. description: |-
  4188. A key in the referenced Secret.
  4189. Some instances of this field may be defaulted, in others it may be required.
  4190. maxLength: 253
  4191. minLength: 1
  4192. pattern: ^[-._a-zA-Z0-9]+$
  4193. type: string
  4194. name:
  4195. description: The name of the Secret resource being referred to.
  4196. maxLength: 253
  4197. minLength: 1
  4198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4199. type: string
  4200. namespace:
  4201. description: |-
  4202. The namespace of the Secret resource being referred to.
  4203. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4204. maxLength: 63
  4205. minLength: 1
  4206. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4207. type: string
  4208. type: object
  4209. required:
  4210. - bearerToken
  4211. type: object
  4212. type: object
  4213. authRef:
  4214. description: |-
  4215. AuthRef references a Secret containing a kubeconfig. Same semantics as the
  4216. Kubernetes provider.
  4217. properties:
  4218. key:
  4219. description: |-
  4220. A key in the referenced Secret.
  4221. Some instances of this field may be defaulted, in others it may be required.
  4222. maxLength: 253
  4223. minLength: 1
  4224. pattern: ^[-._a-zA-Z0-9]+$
  4225. type: string
  4226. name:
  4227. description: The name of the Secret resource being referred to.
  4228. maxLength: 253
  4229. minLength: 1
  4230. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4231. type: string
  4232. namespace:
  4233. description: |-
  4234. The namespace of the Secret resource being referred to.
  4235. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4236. maxLength: 63
  4237. minLength: 1
  4238. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4239. type: string
  4240. type: object
  4241. resource:
  4242. description: Resource identifies the CRD by its API group, version and kind.
  4243. properties:
  4244. group:
  4245. description: |-
  4246. Group is the API group of the resource. Use "" (empty string) for core
  4247. Kubernetes resources such as ConfigMap; use e.g. "config.example.io"
  4248. for a CRD. The field is required to be present in the manifest — write
  4249. `group: ""` explicitly for core resources so typos fail at admission
  4250. time rather than later at discovery.
  4251. type: string
  4252. kind:
  4253. description: Kind is the Kubernetes resource kind (e.g. "MyCustomResource").
  4254. minLength: 1
  4255. type: string
  4256. version:
  4257. description: Version is the API version of the resource (e.g. "v1alpha1").
  4258. minLength: 1
  4259. type: string
  4260. required:
  4261. - group
  4262. - kind
  4263. - version
  4264. type: object
  4265. server:
  4266. description: |-
  4267. Server configures the Kubernetes API address and TLS trust, same as the
  4268. Kubernetes provider. When omitted, the URL defaults to the in-cluster API.
  4269. properties:
  4270. caBundle:
  4271. description: CABundle is a base64-encoded CA certificate
  4272. format: byte
  4273. type: string
  4274. caProvider:
  4275. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  4276. properties:
  4277. key:
  4278. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4279. maxLength: 253
  4280. minLength: 1
  4281. pattern: ^[-._a-zA-Z0-9]+$
  4282. type: string
  4283. name:
  4284. description: The name of the object located at the provider type.
  4285. maxLength: 253
  4286. minLength: 1
  4287. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4288. type: string
  4289. namespace:
  4290. description: |-
  4291. The namespace the Provider type is in.
  4292. Can only be defined when used in a ClusterSecretStore.
  4293. maxLength: 63
  4294. minLength: 1
  4295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4296. type: string
  4297. type:
  4298. description: The type of provider to use such as "Secret", or "ConfigMap".
  4299. enum:
  4300. - Secret
  4301. - ConfigMap
  4302. type: string
  4303. required:
  4304. - name
  4305. - type
  4306. type: object
  4307. url:
  4308. default: kubernetes.default
  4309. description: configures the Kubernetes server Address.
  4310. type: string
  4311. type: object
  4312. whitelist:
  4313. description: |-
  4314. Whitelist optionally restricts which object names and requested properties
  4315. are allowed to be read.
  4316. properties:
  4317. rules:
  4318. description: |-
  4319. Rules is a list of allow rules. If rules are set, at least one rule must
  4320. match for a request to be allowed.
  4321. items:
  4322. description: CRDProviderWhitelistRule defines a single allow rule for CRD reads.
  4323. properties:
  4324. name:
  4325. description: |-
  4326. Name is an optional regular expression matched against the bare object name.
  4327. For both SecretStore and ClusterSecretStore this is always the object name
  4328. without any namespace prefix (e.g. "my-db-spec", not "prod/my-db-spec").
  4329. type: string
  4330. namespace:
  4331. description: |-
  4332. Namespace is an optional regular expression matched against the namespace of
  4333. the object. Applies only when a ClusterSecretStore is used; it is ignored
  4334. for SecretStore (where the namespace is fixed to the store namespace).
  4335. type: string
  4336. properties:
  4337. description: |-
  4338. Properties is an optional list of regular expressions matched against
  4339. requested property keys (for example: "spec.secretValue").
  4340. items:
  4341. type: string
  4342. type: array
  4343. type: object
  4344. type: array
  4345. type: object
  4346. required:
  4347. - resource
  4348. type: object
  4349. x-kubernetes-validations:
  4350. - message: one of auth or authRef is required
  4351. rule: has(self.auth) || has(self.authRef)
  4352. - message: at most one of the fields in [auth authRef] may be set
  4353. rule: '[has(self.auth),has(self.authRef)].filter(x,x==true).size() <= 1'
  4354. delinea:
  4355. description: |-
  4356. Delinea DevOps Secrets Vault
  4357. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  4358. properties:
  4359. clientId:
  4360. description: ClientID is the non-secret part of the credential.
  4361. properties:
  4362. secretRef:
  4363. description: SecretRef references a key in a secret that will be used as value.
  4364. properties:
  4365. key:
  4366. description: |-
  4367. A key in the referenced Secret.
  4368. Some instances of this field may be defaulted, in others it may be required.
  4369. maxLength: 253
  4370. minLength: 1
  4371. pattern: ^[-._a-zA-Z0-9]+$
  4372. type: string
  4373. name:
  4374. description: The name of the Secret resource being referred to.
  4375. maxLength: 253
  4376. minLength: 1
  4377. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4378. type: string
  4379. namespace:
  4380. description: |-
  4381. The namespace of the Secret resource being referred to.
  4382. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4383. maxLength: 63
  4384. minLength: 1
  4385. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4386. type: string
  4387. type: object
  4388. value:
  4389. description: Value can be specified directly to set a value without using a secret.
  4390. type: string
  4391. type: object
  4392. clientSecret:
  4393. description: ClientSecret is the secret part of the credential.
  4394. properties:
  4395. secretRef:
  4396. description: SecretRef references a key in a secret that will be used as value.
  4397. properties:
  4398. key:
  4399. description: |-
  4400. A key in the referenced Secret.
  4401. Some instances of this field may be defaulted, in others it may be required.
  4402. maxLength: 253
  4403. minLength: 1
  4404. pattern: ^[-._a-zA-Z0-9]+$
  4405. type: string
  4406. name:
  4407. description: The name of the Secret resource being referred to.
  4408. maxLength: 253
  4409. minLength: 1
  4410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4411. type: string
  4412. namespace:
  4413. description: |-
  4414. The namespace of the Secret resource being referred to.
  4415. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4416. maxLength: 63
  4417. minLength: 1
  4418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4419. type: string
  4420. type: object
  4421. value:
  4422. description: Value can be specified directly to set a value without using a secret.
  4423. type: string
  4424. type: object
  4425. tenant:
  4426. description: Tenant is the chosen hostname / site name.
  4427. type: string
  4428. tld:
  4429. description: |-
  4430. TLD is based on the server location that was chosen during provisioning.
  4431. If unset, defaults to "com".
  4432. type: string
  4433. urlTemplate:
  4434. description: |-
  4435. URLTemplate
  4436. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  4437. type: string
  4438. required:
  4439. - clientId
  4440. - clientSecret
  4441. - tenant
  4442. type: object
  4443. doppler:
  4444. description: Doppler configures this store to sync secrets using the Doppler provider
  4445. properties:
  4446. auth:
  4447. description: Auth configures how the Operator authenticates with the Doppler API
  4448. properties:
  4449. oidcConfig:
  4450. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  4451. properties:
  4452. expirationSeconds:
  4453. default: 600
  4454. description: |-
  4455. ExpirationSeconds sets the ServiceAccount token validity duration.
  4456. Defaults to 10 minutes.
  4457. format: int64
  4458. type: integer
  4459. identity:
  4460. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  4461. type: string
  4462. serviceAccountRef:
  4463. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  4464. properties:
  4465. audiences:
  4466. description: |-
  4467. Audience specifies the `aud` claim for the service account token
  4468. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4469. then this audiences will be appended to the list
  4470. items:
  4471. type: string
  4472. type: array
  4473. name:
  4474. description: The name of the ServiceAccount resource being referred to.
  4475. maxLength: 253
  4476. minLength: 1
  4477. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4478. type: string
  4479. namespace:
  4480. description: |-
  4481. Namespace of the resource being referred to.
  4482. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4483. maxLength: 63
  4484. minLength: 1
  4485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4486. type: string
  4487. required:
  4488. - name
  4489. type: object
  4490. required:
  4491. - identity
  4492. - serviceAccountRef
  4493. type: object
  4494. secretRef:
  4495. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  4496. properties:
  4497. dopplerToken:
  4498. description: |-
  4499. The DopplerToken is used for authentication.
  4500. See https://docs.doppler.com/reference/api#authentication for auth token types.
  4501. The Key attribute defaults to dopplerToken if not specified.
  4502. properties:
  4503. key:
  4504. description: |-
  4505. A key in the referenced Secret.
  4506. Some instances of this field may be defaulted, in others it may be required.
  4507. maxLength: 253
  4508. minLength: 1
  4509. pattern: ^[-._a-zA-Z0-9]+$
  4510. type: string
  4511. name:
  4512. description: The name of the Secret resource being referred to.
  4513. maxLength: 253
  4514. minLength: 1
  4515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4516. type: string
  4517. namespace:
  4518. description: |-
  4519. The namespace of the Secret resource being referred to.
  4520. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4521. maxLength: 63
  4522. minLength: 1
  4523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4524. type: string
  4525. type: object
  4526. required:
  4527. - dopplerToken
  4528. type: object
  4529. type: object
  4530. x-kubernetes-validations:
  4531. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  4532. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  4533. config:
  4534. description: Doppler config (required if not using a Service Token)
  4535. type: string
  4536. format:
  4537. description: Format enables the downloading of secrets as a file (string)
  4538. enum:
  4539. - json
  4540. - dotnet-json
  4541. - env
  4542. - yaml
  4543. - docker
  4544. type: string
  4545. nameTransformer:
  4546. description: Environment variable compatible name transforms that change secret names to a different format
  4547. enum:
  4548. - upper-camel
  4549. - camel
  4550. - lower-snake
  4551. - tf-var
  4552. - dotnet-env
  4553. - lower-kebab
  4554. type: string
  4555. project:
  4556. description: Doppler project (required if not using a Service Token)
  4557. type: string
  4558. required:
  4559. - auth
  4560. type: object
  4561. dvls:
  4562. description: DVLS configures this store to sync secrets using Devolutions Server provider
  4563. properties:
  4564. auth:
  4565. description: Auth defines the authentication method to use.
  4566. properties:
  4567. secretRef:
  4568. description: SecretRef contains the Application ID and Application Secret for authentication.
  4569. properties:
  4570. appId:
  4571. description: AppID is the reference to the secret containing the Application ID.
  4572. properties:
  4573. key:
  4574. description: |-
  4575. A key in the referenced Secret.
  4576. Some instances of this field may be defaulted, in others it may be required.
  4577. maxLength: 253
  4578. minLength: 1
  4579. pattern: ^[-._a-zA-Z0-9]+$
  4580. type: string
  4581. name:
  4582. description: The name of the Secret resource being referred to.
  4583. maxLength: 253
  4584. minLength: 1
  4585. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4586. type: string
  4587. namespace:
  4588. description: |-
  4589. The namespace of the Secret resource being referred to.
  4590. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4591. maxLength: 63
  4592. minLength: 1
  4593. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4594. type: string
  4595. type: object
  4596. appSecret:
  4597. description: AppSecret is the reference to the secret containing the Application Secret.
  4598. properties:
  4599. key:
  4600. description: |-
  4601. A key in the referenced Secret.
  4602. Some instances of this field may be defaulted, in others it may be required.
  4603. maxLength: 253
  4604. minLength: 1
  4605. pattern: ^[-._a-zA-Z0-9]+$
  4606. type: string
  4607. name:
  4608. description: The name of the Secret resource being referred to.
  4609. maxLength: 253
  4610. minLength: 1
  4611. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4612. type: string
  4613. namespace:
  4614. description: |-
  4615. The namespace of the Secret resource being referred to.
  4616. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4617. maxLength: 63
  4618. minLength: 1
  4619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4620. type: string
  4621. type: object
  4622. required:
  4623. - appId
  4624. - appSecret
  4625. type: object
  4626. required:
  4627. - secretRef
  4628. type: object
  4629. insecure:
  4630. description: |-
  4631. Insecure allows connecting to DVLS over plain HTTP.
  4632. This is NOT RECOMMENDED for production use.
  4633. Set to true only if you understand the security implications.
  4634. type: boolean
  4635. serverUrl:
  4636. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  4637. type: string
  4638. vault:
  4639. description: |-
  4640. Vault is the name or UUID of the vault to fetch secrets from.
  4641. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  4642. type: string
  4643. required:
  4644. - auth
  4645. - serverUrl
  4646. type: object
  4647. fake:
  4648. description: Fake configures a store with static key/value pairs
  4649. properties:
  4650. data:
  4651. items:
  4652. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  4653. properties:
  4654. key:
  4655. type: string
  4656. value:
  4657. type: string
  4658. version:
  4659. type: string
  4660. required:
  4661. - key
  4662. - value
  4663. type: object
  4664. type: array
  4665. validationResult:
  4666. description: ValidationResult is defined type for the number of validation results.
  4667. type: integer
  4668. required:
  4669. - data
  4670. type: object
  4671. fortanix:
  4672. description: Fortanix configures this store to sync secrets using the Fortanix provider
  4673. properties:
  4674. apiKey:
  4675. description: APIKey is the API token to access SDKMS Applications.
  4676. properties:
  4677. secretRef:
  4678. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  4679. properties:
  4680. key:
  4681. description: |-
  4682. A key in the referenced Secret.
  4683. Some instances of this field may be defaulted, in others it may be required.
  4684. maxLength: 253
  4685. minLength: 1
  4686. pattern: ^[-._a-zA-Z0-9]+$
  4687. type: string
  4688. name:
  4689. description: The name of the Secret resource being referred to.
  4690. maxLength: 253
  4691. minLength: 1
  4692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4693. type: string
  4694. namespace:
  4695. description: |-
  4696. The namespace of the Secret resource being referred to.
  4697. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4698. maxLength: 63
  4699. minLength: 1
  4700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4701. type: string
  4702. type: object
  4703. type: object
  4704. apiUrl:
  4705. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  4706. type: string
  4707. type: object
  4708. gcpsm:
  4709. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  4710. properties:
  4711. auth:
  4712. description: Auth defines the information necessary to authenticate against GCP
  4713. properties:
  4714. secretRef:
  4715. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  4716. properties:
  4717. secretAccessKeySecretRef:
  4718. description: The SecretAccessKey is used for authentication
  4719. properties:
  4720. key:
  4721. description: |-
  4722. A key in the referenced Secret.
  4723. Some instances of this field may be defaulted, in others it may be required.
  4724. maxLength: 253
  4725. minLength: 1
  4726. pattern: ^[-._a-zA-Z0-9]+$
  4727. type: string
  4728. name:
  4729. description: The name of the Secret resource being referred to.
  4730. maxLength: 253
  4731. minLength: 1
  4732. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4733. type: string
  4734. namespace:
  4735. description: |-
  4736. The namespace of the Secret resource being referred to.
  4737. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4738. maxLength: 63
  4739. minLength: 1
  4740. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4741. type: string
  4742. type: object
  4743. type: object
  4744. workloadIdentity:
  4745. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  4746. properties:
  4747. clusterLocation:
  4748. description: |-
  4749. ClusterLocation is the location of the cluster
  4750. If not specified, it fetches information from the metadata server
  4751. type: string
  4752. clusterName:
  4753. description: |-
  4754. ClusterName is the name of the cluster
  4755. If not specified, it fetches information from the metadata server
  4756. type: string
  4757. clusterProjectID:
  4758. description: |-
  4759. ClusterProjectID is the project ID of the cluster
  4760. If not specified, it fetches information from the metadata server
  4761. type: string
  4762. serviceAccountRef:
  4763. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  4764. properties:
  4765. audiences:
  4766. description: |-
  4767. Audience specifies the `aud` claim for the service account token
  4768. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4769. then this audiences will be appended to the list
  4770. items:
  4771. type: string
  4772. type: array
  4773. name:
  4774. description: The name of the ServiceAccount resource being referred to.
  4775. maxLength: 253
  4776. minLength: 1
  4777. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4778. type: string
  4779. namespace:
  4780. description: |-
  4781. Namespace of the resource being referred to.
  4782. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4783. maxLength: 63
  4784. minLength: 1
  4785. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4786. type: string
  4787. required:
  4788. - name
  4789. type: object
  4790. required:
  4791. - serviceAccountRef
  4792. type: object
  4793. workloadIdentityFederation:
  4794. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  4795. properties:
  4796. audience:
  4797. description: |-
  4798. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  4799. If specified, Audience found in the external account credential config will be overridden with the configured value.
  4800. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  4801. type: string
  4802. awsSecurityCredentials:
  4803. description: |-
  4804. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  4805. when using the AWS metadata server is not an option.
  4806. properties:
  4807. awsCredentialsSecretRef:
  4808. description: |-
  4809. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  4810. Secret should be created with below names for keys
  4811. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  4812. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  4813. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  4814. properties:
  4815. name:
  4816. description: name of the secret.
  4817. maxLength: 253
  4818. minLength: 1
  4819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4820. type: string
  4821. namespace:
  4822. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  4823. maxLength: 63
  4824. minLength: 1
  4825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4826. type: string
  4827. required:
  4828. - name
  4829. type: object
  4830. region:
  4831. description: region is for configuring the AWS region to be used.
  4832. example: ap-south-1
  4833. maxLength: 50
  4834. minLength: 1
  4835. pattern: ^[a-z0-9-]+$
  4836. type: string
  4837. required:
  4838. - awsCredentialsSecretRef
  4839. - region
  4840. type: object
  4841. credConfig:
  4842. description: |-
  4843. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  4844. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  4845. serviceAccountRef must be used by providing operators service account details.
  4846. properties:
  4847. key:
  4848. description: key name holding the external account credential config.
  4849. maxLength: 253
  4850. minLength: 1
  4851. pattern: ^[-._a-zA-Z0-9]+$
  4852. type: string
  4853. name:
  4854. description: name of the configmap.
  4855. maxLength: 253
  4856. minLength: 1
  4857. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4858. type: string
  4859. namespace:
  4860. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  4861. maxLength: 63
  4862. minLength: 1
  4863. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4864. type: string
  4865. required:
  4866. - key
  4867. - name
  4868. type: object
  4869. externalTokenEndpoint:
  4870. description: |-
  4871. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  4872. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  4873. URL is having the expected value.
  4874. type: string
  4875. gcpServiceAccountEmail:
  4876. description: |-
  4877. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  4878. after Workload Identity Federation. Use this to grant access through the service account's
  4879. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  4880. service_account_impersonation_url in the external account JSON from credConfig;
  4881. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  4882. on that ServiceAccount.
  4883. example: my-gsa@my-project.iam.gserviceaccount.com
  4884. minLength: 1
  4885. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  4886. type: string
  4887. serviceAccountRef:
  4888. description: |-
  4889. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  4890. when Kubernetes is configured as provider in workload identity pool.
  4891. properties:
  4892. audiences:
  4893. description: |-
  4894. Audience specifies the `aud` claim for the service account token
  4895. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4896. then this audiences will be appended to the list
  4897. items:
  4898. type: string
  4899. type: array
  4900. name:
  4901. description: The name of the ServiceAccount resource being referred to.
  4902. maxLength: 253
  4903. minLength: 1
  4904. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4905. type: string
  4906. namespace:
  4907. description: |-
  4908. Namespace of the resource being referred to.
  4909. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4910. maxLength: 63
  4911. minLength: 1
  4912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4913. type: string
  4914. required:
  4915. - name
  4916. type: object
  4917. type: object
  4918. type: object
  4919. location:
  4920. description: Location optionally defines a location for a secret
  4921. type: string
  4922. projectID:
  4923. description: ProjectID project where secret is located
  4924. type: string
  4925. secretVersionSelectionPolicy:
  4926. default: LatestOrFail
  4927. description: |-
  4928. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  4929. when "latest" is disabled or destroyed.
  4930. Possible values are:
  4931. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  4932. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  4933. type: string
  4934. type: object
  4935. github:
  4936. description: |-
  4937. Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  4938. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  4939. properties:
  4940. appID:
  4941. description: appID specifies the Github APP that will be used to authenticate the client
  4942. format: int64
  4943. type: integer
  4944. auth:
  4945. description: auth configures how secret-manager authenticates with a Github instance.
  4946. properties:
  4947. privateKey:
  4948. description: |-
  4949. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4950. In some instances, `key` is a required field.
  4951. properties:
  4952. key:
  4953. description: |-
  4954. A key in the referenced Secret.
  4955. Some instances of this field may be defaulted, in others it may be required.
  4956. maxLength: 253
  4957. minLength: 1
  4958. pattern: ^[-._a-zA-Z0-9]+$
  4959. type: string
  4960. name:
  4961. description: The name of the Secret resource being referred to.
  4962. maxLength: 253
  4963. minLength: 1
  4964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4965. type: string
  4966. namespace:
  4967. description: |-
  4968. The namespace of the Secret resource being referred to.
  4969. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4970. maxLength: 63
  4971. minLength: 1
  4972. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4973. type: string
  4974. type: object
  4975. required:
  4976. - privateKey
  4977. type: object
  4978. environment:
  4979. description: environment will be used to fetch secrets from a particular environment within a github repository
  4980. type: string
  4981. installationID:
  4982. description: installationID specifies the Github APP installation that will be used to authenticate the client
  4983. format: int64
  4984. type: integer
  4985. orgSecretVisibility:
  4986. description: |-
  4987. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  4988. Valid values are "all" or "private".
  4989. When unset, new secrets are created with visibility "all" and existing secrets preserve
  4990. whatever visibility they already have in GitHub.
  4991. enum:
  4992. - all
  4993. - private
  4994. type: string
  4995. organization:
  4996. description: organization will be used to fetch secrets from the Github organization
  4997. type: string
  4998. repository:
  4999. description: repository will be used to fetch secrets from the Github repository within an organization
  5000. type: string
  5001. uploadURL:
  5002. description: Upload URL for enterprise instances. Default to URL.
  5003. type: string
  5004. url:
  5005. default: https://github.com/
  5006. description: URL configures the Github instance URL. Defaults to https://github.com/.
  5007. type: string
  5008. required:
  5009. - appID
  5010. - auth
  5011. - installationID
  5012. - organization
  5013. type: object
  5014. gitlab:
  5015. description: GitLab configures this store to sync secrets using GitLab Variables provider
  5016. properties:
  5017. auth:
  5018. description: Auth configures how secret-manager authenticates with a GitLab instance.
  5019. properties:
  5020. SecretRef:
  5021. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  5022. properties:
  5023. accessToken:
  5024. description: AccessToken is used for authentication.
  5025. properties:
  5026. key:
  5027. description: |-
  5028. A key in the referenced Secret.
  5029. Some instances of this field may be defaulted, in others it may be required.
  5030. maxLength: 253
  5031. minLength: 1
  5032. pattern: ^[-._a-zA-Z0-9]+$
  5033. type: string
  5034. name:
  5035. description: The name of the Secret resource being referred to.
  5036. maxLength: 253
  5037. minLength: 1
  5038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5039. type: string
  5040. namespace:
  5041. description: |-
  5042. The namespace of the Secret resource being referred to.
  5043. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5044. maxLength: 63
  5045. minLength: 1
  5046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5047. type: string
  5048. type: object
  5049. type: object
  5050. required:
  5051. - SecretRef
  5052. type: object
  5053. caBundle:
  5054. description: |-
  5055. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  5056. can be performed.
  5057. format: byte
  5058. type: string
  5059. caProvider:
  5060. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  5061. properties:
  5062. key:
  5063. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5064. maxLength: 253
  5065. minLength: 1
  5066. pattern: ^[-._a-zA-Z0-9]+$
  5067. type: string
  5068. name:
  5069. description: The name of the object located at the provider type.
  5070. maxLength: 253
  5071. minLength: 1
  5072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5073. type: string
  5074. namespace:
  5075. description: |-
  5076. The namespace the Provider type is in.
  5077. Can only be defined when used in a ClusterSecretStore.
  5078. maxLength: 63
  5079. minLength: 1
  5080. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5081. type: string
  5082. type:
  5083. description: The type of provider to use such as "Secret", or "ConfigMap".
  5084. enum:
  5085. - Secret
  5086. - ConfigMap
  5087. type: string
  5088. required:
  5089. - name
  5090. - type
  5091. type: object
  5092. environment:
  5093. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  5094. type: string
  5095. groupIDs:
  5096. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  5097. items:
  5098. type: string
  5099. type: array
  5100. inheritFromGroups:
  5101. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  5102. type: boolean
  5103. projectID:
  5104. description: ProjectID specifies a project where secrets are located.
  5105. type: string
  5106. url:
  5107. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  5108. type: string
  5109. required:
  5110. - auth
  5111. type: object
  5112. ibm:
  5113. description: IBM configures this store to sync secrets using IBM Cloud provider
  5114. properties:
  5115. auth:
  5116. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  5117. maxProperties: 1
  5118. minProperties: 1
  5119. properties:
  5120. containerAuth:
  5121. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  5122. properties:
  5123. iamEndpoint:
  5124. type: string
  5125. profile:
  5126. description: the IBM Trusted Profile
  5127. type: string
  5128. tokenLocation:
  5129. description: Location the token is mounted on the pod
  5130. type: string
  5131. required:
  5132. - profile
  5133. type: object
  5134. secretRef:
  5135. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  5136. properties:
  5137. iamEndpoint:
  5138. description: The IAM endpoint used to obain a token
  5139. type: string
  5140. secretApiKeySecretRef:
  5141. description: The SecretAccessKey is used for authentication
  5142. properties:
  5143. key:
  5144. description: |-
  5145. A key in the referenced Secret.
  5146. Some instances of this field may be defaulted, in others it may be required.
  5147. maxLength: 253
  5148. minLength: 1
  5149. pattern: ^[-._a-zA-Z0-9]+$
  5150. type: string
  5151. name:
  5152. description: The name of the Secret resource being referred to.
  5153. maxLength: 253
  5154. minLength: 1
  5155. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5156. type: string
  5157. namespace:
  5158. description: |-
  5159. The namespace of the Secret resource being referred to.
  5160. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5161. maxLength: 63
  5162. minLength: 1
  5163. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5164. type: string
  5165. type: object
  5166. type: object
  5167. type: object
  5168. serviceUrl:
  5169. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  5170. type: string
  5171. required:
  5172. - auth
  5173. type: object
  5174. infisical:
  5175. description: Infisical configures this store to sync secrets using the Infisical provider
  5176. properties:
  5177. auth:
  5178. description: Auth configures how the Operator authenticates with the Infisical API
  5179. properties:
  5180. awsAuthCredentials:
  5181. description: AwsAuthCredentials represents the credentials for AWS authentication.
  5182. properties:
  5183. identityId:
  5184. description: |-
  5185. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5186. In some instances, `key` is a required field.
  5187. properties:
  5188. key:
  5189. description: |-
  5190. A key in the referenced Secret.
  5191. Some instances of this field may be defaulted, in others it may be required.
  5192. maxLength: 253
  5193. minLength: 1
  5194. pattern: ^[-._a-zA-Z0-9]+$
  5195. type: string
  5196. name:
  5197. description: The name of the Secret resource being referred to.
  5198. maxLength: 253
  5199. minLength: 1
  5200. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5201. type: string
  5202. namespace:
  5203. description: |-
  5204. The namespace of the Secret resource being referred to.
  5205. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5206. maxLength: 63
  5207. minLength: 1
  5208. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5209. type: string
  5210. type: object
  5211. required:
  5212. - identityId
  5213. type: object
  5214. azureAuthCredentials:
  5215. description: AzureAuthCredentials represents the credentials for Azure authentication.
  5216. properties:
  5217. identityId:
  5218. description: |-
  5219. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5220. In some instances, `key` is a required field.
  5221. properties:
  5222. key:
  5223. description: |-
  5224. A key in the referenced Secret.
  5225. Some instances of this field may be defaulted, in others it may be required.
  5226. maxLength: 253
  5227. minLength: 1
  5228. pattern: ^[-._a-zA-Z0-9]+$
  5229. type: string
  5230. name:
  5231. description: The name of the Secret resource being referred to.
  5232. maxLength: 253
  5233. minLength: 1
  5234. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5235. type: string
  5236. namespace:
  5237. description: |-
  5238. The namespace of the Secret resource being referred to.
  5239. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5240. maxLength: 63
  5241. minLength: 1
  5242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5243. type: string
  5244. type: object
  5245. resource:
  5246. description: |-
  5247. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5248. In some instances, `key` is a required field.
  5249. properties:
  5250. key:
  5251. description: |-
  5252. A key in the referenced Secret.
  5253. Some instances of this field may be defaulted, in others it may be required.
  5254. maxLength: 253
  5255. minLength: 1
  5256. pattern: ^[-._a-zA-Z0-9]+$
  5257. type: string
  5258. name:
  5259. description: The name of the Secret resource being referred to.
  5260. maxLength: 253
  5261. minLength: 1
  5262. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5263. type: string
  5264. namespace:
  5265. description: |-
  5266. The namespace of the Secret resource being referred to.
  5267. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5268. maxLength: 63
  5269. minLength: 1
  5270. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5271. type: string
  5272. type: object
  5273. required:
  5274. - identityId
  5275. type: object
  5276. gcpIamAuthCredentials:
  5277. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  5278. properties:
  5279. identityId:
  5280. description: |-
  5281. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5282. In some instances, `key` is a required field.
  5283. properties:
  5284. key:
  5285. description: |-
  5286. A key in the referenced Secret.
  5287. Some instances of this field may be defaulted, in others it may be required.
  5288. maxLength: 253
  5289. minLength: 1
  5290. pattern: ^[-._a-zA-Z0-9]+$
  5291. type: string
  5292. name:
  5293. description: The name of the Secret resource being referred to.
  5294. maxLength: 253
  5295. minLength: 1
  5296. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5297. type: string
  5298. namespace:
  5299. description: |-
  5300. The namespace of the Secret resource being referred to.
  5301. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5302. maxLength: 63
  5303. minLength: 1
  5304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5305. type: string
  5306. type: object
  5307. serviceAccountKeyFilePath:
  5308. description: |-
  5309. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5310. In some instances, `key` is a required field.
  5311. properties:
  5312. key:
  5313. description: |-
  5314. A key in the referenced Secret.
  5315. Some instances of this field may be defaulted, in others it may be required.
  5316. maxLength: 253
  5317. minLength: 1
  5318. pattern: ^[-._a-zA-Z0-9]+$
  5319. type: string
  5320. name:
  5321. description: The name of the Secret resource being referred to.
  5322. maxLength: 253
  5323. minLength: 1
  5324. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5325. type: string
  5326. namespace:
  5327. description: |-
  5328. The namespace of the Secret resource being referred to.
  5329. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5330. maxLength: 63
  5331. minLength: 1
  5332. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5333. type: string
  5334. type: object
  5335. required:
  5336. - identityId
  5337. - serviceAccountKeyFilePath
  5338. type: object
  5339. gcpIdTokenAuthCredentials:
  5340. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  5341. properties:
  5342. identityId:
  5343. description: |-
  5344. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5345. In some instances, `key` is a required field.
  5346. properties:
  5347. key:
  5348. description: |-
  5349. A key in the referenced Secret.
  5350. Some instances of this field may be defaulted, in others it may be required.
  5351. maxLength: 253
  5352. minLength: 1
  5353. pattern: ^[-._a-zA-Z0-9]+$
  5354. type: string
  5355. name:
  5356. description: The name of the Secret resource being referred to.
  5357. maxLength: 253
  5358. minLength: 1
  5359. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5360. type: string
  5361. namespace:
  5362. description: |-
  5363. The namespace of the Secret resource being referred to.
  5364. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5365. maxLength: 63
  5366. minLength: 1
  5367. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5368. type: string
  5369. type: object
  5370. required:
  5371. - identityId
  5372. type: object
  5373. jwtAuthCredentials:
  5374. description: JwtAuthCredentials represents the credentials for JWT authentication.
  5375. properties:
  5376. identityId:
  5377. description: |-
  5378. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5379. In some instances, `key` is a required field.
  5380. properties:
  5381. key:
  5382. description: |-
  5383. A key in the referenced Secret.
  5384. Some instances of this field may be defaulted, in others it may be required.
  5385. maxLength: 253
  5386. minLength: 1
  5387. pattern: ^[-._a-zA-Z0-9]+$
  5388. type: string
  5389. name:
  5390. description: The name of the Secret resource being referred to.
  5391. maxLength: 253
  5392. minLength: 1
  5393. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5394. type: string
  5395. namespace:
  5396. description: |-
  5397. The namespace of the Secret resource being referred to.
  5398. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5399. maxLength: 63
  5400. minLength: 1
  5401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5402. type: string
  5403. type: object
  5404. jwt:
  5405. description: |-
  5406. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5407. In some instances, `key` is a required field.
  5408. properties:
  5409. key:
  5410. description: |-
  5411. A key in the referenced Secret.
  5412. Some instances of this field may be defaulted, in others it may be required.
  5413. maxLength: 253
  5414. minLength: 1
  5415. pattern: ^[-._a-zA-Z0-9]+$
  5416. type: string
  5417. name:
  5418. description: The name of the Secret resource being referred to.
  5419. maxLength: 253
  5420. minLength: 1
  5421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5422. type: string
  5423. namespace:
  5424. description: |-
  5425. The namespace of the Secret resource being referred to.
  5426. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5427. maxLength: 63
  5428. minLength: 1
  5429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5430. type: string
  5431. type: object
  5432. required:
  5433. - identityId
  5434. - jwt
  5435. type: object
  5436. kubernetesAuthCredentials:
  5437. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  5438. properties:
  5439. identityId:
  5440. description: |-
  5441. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5442. In some instances, `key` is a required field.
  5443. properties:
  5444. key:
  5445. description: |-
  5446. A key in the referenced Secret.
  5447. Some instances of this field may be defaulted, in others it may be required.
  5448. maxLength: 253
  5449. minLength: 1
  5450. pattern: ^[-._a-zA-Z0-9]+$
  5451. type: string
  5452. name:
  5453. description: The name of the Secret resource being referred to.
  5454. maxLength: 253
  5455. minLength: 1
  5456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5457. type: string
  5458. namespace:
  5459. description: |-
  5460. The namespace of the Secret resource being referred to.
  5461. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5462. maxLength: 63
  5463. minLength: 1
  5464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5465. type: string
  5466. type: object
  5467. serviceAccountTokenPath:
  5468. description: |-
  5469. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5470. In some instances, `key` is a required field.
  5471. properties:
  5472. key:
  5473. description: |-
  5474. A key in the referenced Secret.
  5475. Some instances of this field may be defaulted, in others it may be required.
  5476. maxLength: 253
  5477. minLength: 1
  5478. pattern: ^[-._a-zA-Z0-9]+$
  5479. type: string
  5480. name:
  5481. description: The name of the Secret resource being referred to.
  5482. maxLength: 253
  5483. minLength: 1
  5484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5485. type: string
  5486. namespace:
  5487. description: |-
  5488. The namespace of the Secret resource being referred to.
  5489. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5490. maxLength: 63
  5491. minLength: 1
  5492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5493. type: string
  5494. type: object
  5495. required:
  5496. - identityId
  5497. type: object
  5498. ldapAuthCredentials:
  5499. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  5500. properties:
  5501. identityId:
  5502. description: |-
  5503. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5504. In some instances, `key` is a required field.
  5505. properties:
  5506. key:
  5507. description: |-
  5508. A key in the referenced Secret.
  5509. Some instances of this field may be defaulted, in others it may be required.
  5510. maxLength: 253
  5511. minLength: 1
  5512. pattern: ^[-._a-zA-Z0-9]+$
  5513. type: string
  5514. name:
  5515. description: The name of the Secret resource being referred to.
  5516. maxLength: 253
  5517. minLength: 1
  5518. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5519. type: string
  5520. namespace:
  5521. description: |-
  5522. The namespace of the Secret resource being referred to.
  5523. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5524. maxLength: 63
  5525. minLength: 1
  5526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5527. type: string
  5528. type: object
  5529. ldapPassword:
  5530. description: |-
  5531. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5532. In some instances, `key` is a required field.
  5533. properties:
  5534. key:
  5535. description: |-
  5536. A key in the referenced Secret.
  5537. Some instances of this field may be defaulted, in others it may be required.
  5538. maxLength: 253
  5539. minLength: 1
  5540. pattern: ^[-._a-zA-Z0-9]+$
  5541. type: string
  5542. name:
  5543. description: The name of the Secret resource being referred to.
  5544. maxLength: 253
  5545. minLength: 1
  5546. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5547. type: string
  5548. namespace:
  5549. description: |-
  5550. The namespace of the Secret resource being referred to.
  5551. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5552. maxLength: 63
  5553. minLength: 1
  5554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5555. type: string
  5556. type: object
  5557. ldapUsername:
  5558. description: |-
  5559. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5560. In some instances, `key` is a required field.
  5561. properties:
  5562. key:
  5563. description: |-
  5564. A key in the referenced Secret.
  5565. Some instances of this field may be defaulted, in others it may be required.
  5566. maxLength: 253
  5567. minLength: 1
  5568. pattern: ^[-._a-zA-Z0-9]+$
  5569. type: string
  5570. name:
  5571. description: The name of the Secret resource being referred to.
  5572. maxLength: 253
  5573. minLength: 1
  5574. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5575. type: string
  5576. namespace:
  5577. description: |-
  5578. The namespace of the Secret resource being referred to.
  5579. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5580. maxLength: 63
  5581. minLength: 1
  5582. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5583. type: string
  5584. type: object
  5585. required:
  5586. - identityId
  5587. - ldapPassword
  5588. - ldapUsername
  5589. type: object
  5590. ociAuthCredentials:
  5591. description: OciAuthCredentials represents the credentials for OCI authentication.
  5592. properties:
  5593. fingerprint:
  5594. description: |-
  5595. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5596. In some instances, `key` is a required field.
  5597. properties:
  5598. key:
  5599. description: |-
  5600. A key in the referenced Secret.
  5601. Some instances of this field may be defaulted, in others it may be required.
  5602. maxLength: 253
  5603. minLength: 1
  5604. pattern: ^[-._a-zA-Z0-9]+$
  5605. type: string
  5606. name:
  5607. description: The name of the Secret resource being referred to.
  5608. maxLength: 253
  5609. minLength: 1
  5610. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5611. type: string
  5612. namespace:
  5613. description: |-
  5614. The namespace of the Secret resource being referred to.
  5615. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5616. maxLength: 63
  5617. minLength: 1
  5618. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5619. type: string
  5620. type: object
  5621. identityId:
  5622. description: |-
  5623. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5624. In some instances, `key` is a required field.
  5625. properties:
  5626. key:
  5627. description: |-
  5628. A key in the referenced Secret.
  5629. Some instances of this field may be defaulted, in others it may be required.
  5630. maxLength: 253
  5631. minLength: 1
  5632. pattern: ^[-._a-zA-Z0-9]+$
  5633. type: string
  5634. name:
  5635. description: The name of the Secret resource being referred to.
  5636. maxLength: 253
  5637. minLength: 1
  5638. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5639. type: string
  5640. namespace:
  5641. description: |-
  5642. The namespace of the Secret resource being referred to.
  5643. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5644. maxLength: 63
  5645. minLength: 1
  5646. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5647. type: string
  5648. type: object
  5649. privateKey:
  5650. description: |-
  5651. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5652. In some instances, `key` is a required field.
  5653. properties:
  5654. key:
  5655. description: |-
  5656. A key in the referenced Secret.
  5657. Some instances of this field may be defaulted, in others it may be required.
  5658. maxLength: 253
  5659. minLength: 1
  5660. pattern: ^[-._a-zA-Z0-9]+$
  5661. type: string
  5662. name:
  5663. description: The name of the Secret resource being referred to.
  5664. maxLength: 253
  5665. minLength: 1
  5666. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5667. type: string
  5668. namespace:
  5669. description: |-
  5670. The namespace of the Secret resource being referred to.
  5671. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5672. maxLength: 63
  5673. minLength: 1
  5674. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5675. type: string
  5676. type: object
  5677. privateKeyPassphrase:
  5678. description: |-
  5679. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5680. In some instances, `key` is a required field.
  5681. properties:
  5682. key:
  5683. description: |-
  5684. A key in the referenced Secret.
  5685. Some instances of this field may be defaulted, in others it may be required.
  5686. maxLength: 253
  5687. minLength: 1
  5688. pattern: ^[-._a-zA-Z0-9]+$
  5689. type: string
  5690. name:
  5691. description: The name of the Secret resource being referred to.
  5692. maxLength: 253
  5693. minLength: 1
  5694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5695. type: string
  5696. namespace:
  5697. description: |-
  5698. The namespace of the Secret resource being referred to.
  5699. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5700. maxLength: 63
  5701. minLength: 1
  5702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5703. type: string
  5704. type: object
  5705. region:
  5706. description: |-
  5707. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5708. In some instances, `key` is a required field.
  5709. properties:
  5710. key:
  5711. description: |-
  5712. A key in the referenced Secret.
  5713. Some instances of this field may be defaulted, in others it may be required.
  5714. maxLength: 253
  5715. minLength: 1
  5716. pattern: ^[-._a-zA-Z0-9]+$
  5717. type: string
  5718. name:
  5719. description: The name of the Secret resource being referred to.
  5720. maxLength: 253
  5721. minLength: 1
  5722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5723. type: string
  5724. namespace:
  5725. description: |-
  5726. The namespace of the Secret resource being referred to.
  5727. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5728. maxLength: 63
  5729. minLength: 1
  5730. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5731. type: string
  5732. type: object
  5733. tenancyId:
  5734. description: |-
  5735. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5736. In some instances, `key` is a required field.
  5737. properties:
  5738. key:
  5739. description: |-
  5740. A key in the referenced Secret.
  5741. Some instances of this field may be defaulted, in others it may be required.
  5742. maxLength: 253
  5743. minLength: 1
  5744. pattern: ^[-._a-zA-Z0-9]+$
  5745. type: string
  5746. name:
  5747. description: The name of the Secret resource being referred to.
  5748. maxLength: 253
  5749. minLength: 1
  5750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5751. type: string
  5752. namespace:
  5753. description: |-
  5754. The namespace of the Secret resource being referred to.
  5755. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5756. maxLength: 63
  5757. minLength: 1
  5758. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5759. type: string
  5760. type: object
  5761. userId:
  5762. description: |-
  5763. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5764. In some instances, `key` is a required field.
  5765. properties:
  5766. key:
  5767. description: |-
  5768. A key in the referenced Secret.
  5769. Some instances of this field may be defaulted, in others it may be required.
  5770. maxLength: 253
  5771. minLength: 1
  5772. pattern: ^[-._a-zA-Z0-9]+$
  5773. type: string
  5774. name:
  5775. description: The name of the Secret resource being referred to.
  5776. maxLength: 253
  5777. minLength: 1
  5778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5779. type: string
  5780. namespace:
  5781. description: |-
  5782. The namespace of the Secret resource being referred to.
  5783. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5784. maxLength: 63
  5785. minLength: 1
  5786. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5787. type: string
  5788. type: object
  5789. required:
  5790. - fingerprint
  5791. - identityId
  5792. - privateKey
  5793. - region
  5794. - tenancyId
  5795. - userId
  5796. type: object
  5797. tokenAuthCredentials:
  5798. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  5799. properties:
  5800. accessToken:
  5801. description: |-
  5802. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5803. In some instances, `key` is a required field.
  5804. properties:
  5805. key:
  5806. description: |-
  5807. A key in the referenced Secret.
  5808. Some instances of this field may be defaulted, in others it may be required.
  5809. maxLength: 253
  5810. minLength: 1
  5811. pattern: ^[-._a-zA-Z0-9]+$
  5812. type: string
  5813. name:
  5814. description: The name of the Secret resource being referred to.
  5815. maxLength: 253
  5816. minLength: 1
  5817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5818. type: string
  5819. namespace:
  5820. description: |-
  5821. The namespace of the Secret resource being referred to.
  5822. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5823. maxLength: 63
  5824. minLength: 1
  5825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5826. type: string
  5827. type: object
  5828. required:
  5829. - accessToken
  5830. type: object
  5831. universalAuthCredentials:
  5832. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  5833. properties:
  5834. clientId:
  5835. description: |-
  5836. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5837. In some instances, `key` is a required field.
  5838. properties:
  5839. key:
  5840. description: |-
  5841. A key in the referenced Secret.
  5842. Some instances of this field may be defaulted, in others it may be required.
  5843. maxLength: 253
  5844. minLength: 1
  5845. pattern: ^[-._a-zA-Z0-9]+$
  5846. type: string
  5847. name:
  5848. description: The name of the Secret resource being referred to.
  5849. maxLength: 253
  5850. minLength: 1
  5851. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5852. type: string
  5853. namespace:
  5854. description: |-
  5855. The namespace of the Secret resource being referred to.
  5856. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5857. maxLength: 63
  5858. minLength: 1
  5859. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5860. type: string
  5861. type: object
  5862. clientSecret:
  5863. description: |-
  5864. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5865. In some instances, `key` is a required field.
  5866. properties:
  5867. key:
  5868. description: |-
  5869. A key in the referenced Secret.
  5870. Some instances of this field may be defaulted, in others it may be required.
  5871. maxLength: 253
  5872. minLength: 1
  5873. pattern: ^[-._a-zA-Z0-9]+$
  5874. type: string
  5875. name:
  5876. description: The name of the Secret resource being referred to.
  5877. maxLength: 253
  5878. minLength: 1
  5879. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5880. type: string
  5881. namespace:
  5882. description: |-
  5883. The namespace of the Secret resource being referred to.
  5884. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5885. maxLength: 63
  5886. minLength: 1
  5887. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5888. type: string
  5889. type: object
  5890. required:
  5891. - clientId
  5892. - clientSecret
  5893. type: object
  5894. type: object
  5895. caBundle:
  5896. description: |-
  5897. CABundle is a PEM-encoded CA certificate bundle used to validate
  5898. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  5899. format: byte
  5900. type: string
  5901. caProvider:
  5902. description: |-
  5903. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  5904. The certificate is used to validate the Infisical server's TLS certificate.
  5905. Mutually exclusive with CABundle.
  5906. properties:
  5907. key:
  5908. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5909. maxLength: 253
  5910. minLength: 1
  5911. pattern: ^[-._a-zA-Z0-9]+$
  5912. type: string
  5913. name:
  5914. description: The name of the object located at the provider type.
  5915. maxLength: 253
  5916. minLength: 1
  5917. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5918. type: string
  5919. namespace:
  5920. description: |-
  5921. The namespace the Provider type is in.
  5922. Can only be defined when used in a ClusterSecretStore.
  5923. maxLength: 63
  5924. minLength: 1
  5925. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5926. type: string
  5927. type:
  5928. description: The type of provider to use such as "Secret", or "ConfigMap".
  5929. enum:
  5930. - Secret
  5931. - ConfigMap
  5932. type: string
  5933. required:
  5934. - name
  5935. - type
  5936. type: object
  5937. hostAPI:
  5938. default: https://app.infisical.com/api
  5939. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  5940. type: string
  5941. secretsScope:
  5942. description: SecretsScope defines the scope of the secrets within the workspace
  5943. properties:
  5944. environmentSlug:
  5945. description: EnvironmentSlug is the required slug identifier for the environment.
  5946. type: string
  5947. expandSecretReferences:
  5948. default: true
  5949. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  5950. type: boolean
  5951. organizationSlug:
  5952. description: |-
  5953. OrganizationSlug is the optional slug that identifies the organization that will be used
  5954. during authentication. Useful for sub-organization setups
  5955. type: string
  5956. projectSlug:
  5957. description: ProjectSlug is the required slug identifier for the project.
  5958. type: string
  5959. recursive:
  5960. default: false
  5961. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  5962. type: boolean
  5963. secretsPath:
  5964. default: /
  5965. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  5966. type: string
  5967. required:
  5968. - environmentSlug
  5969. - projectSlug
  5970. type: object
  5971. required:
  5972. - auth
  5973. - secretsScope
  5974. type: object
  5975. keepersecurity:
  5976. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  5977. properties:
  5978. authRef:
  5979. description: |-
  5980. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5981. In some instances, `key` is a required field.
  5982. properties:
  5983. key:
  5984. description: |-
  5985. A key in the referenced Secret.
  5986. Some instances of this field may be defaulted, in others it may be required.
  5987. maxLength: 253
  5988. minLength: 1
  5989. pattern: ^[-._a-zA-Z0-9]+$
  5990. type: string
  5991. name:
  5992. description: The name of the Secret resource being referred to.
  5993. maxLength: 253
  5994. minLength: 1
  5995. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5996. type: string
  5997. namespace:
  5998. description: |-
  5999. The namespace of the Secret resource being referred to.
  6000. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6001. maxLength: 63
  6002. minLength: 1
  6003. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6004. type: string
  6005. type: object
  6006. folderID:
  6007. type: string
  6008. getByTitleFallback:
  6009. type: boolean
  6010. required:
  6011. - authRef
  6012. - folderID
  6013. type: object
  6014. kubernetes:
  6015. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  6016. properties:
  6017. auth:
  6018. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  6019. maxProperties: 1
  6020. minProperties: 1
  6021. properties:
  6022. cert:
  6023. description: has both clientCert and clientKey as secretKeySelector
  6024. properties:
  6025. clientCert:
  6026. description: |-
  6027. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6028. In some instances, `key` is a required field.
  6029. properties:
  6030. key:
  6031. description: |-
  6032. A key in the referenced Secret.
  6033. Some instances of this field may be defaulted, in others it may be required.
  6034. maxLength: 253
  6035. minLength: 1
  6036. pattern: ^[-._a-zA-Z0-9]+$
  6037. type: string
  6038. name:
  6039. description: The name of the Secret resource being referred to.
  6040. maxLength: 253
  6041. minLength: 1
  6042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6043. type: string
  6044. namespace:
  6045. description: |-
  6046. The namespace of the Secret resource being referred to.
  6047. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6048. maxLength: 63
  6049. minLength: 1
  6050. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6051. type: string
  6052. type: object
  6053. clientKey:
  6054. description: |-
  6055. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6056. In some instances, `key` is a required field.
  6057. properties:
  6058. key:
  6059. description: |-
  6060. A key in the referenced Secret.
  6061. Some instances of this field may be defaulted, in others it may be required.
  6062. maxLength: 253
  6063. minLength: 1
  6064. pattern: ^[-._a-zA-Z0-9]+$
  6065. type: string
  6066. name:
  6067. description: The name of the Secret resource being referred to.
  6068. maxLength: 253
  6069. minLength: 1
  6070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6071. type: string
  6072. namespace:
  6073. description: |-
  6074. The namespace of the Secret resource being referred to.
  6075. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6076. maxLength: 63
  6077. minLength: 1
  6078. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6079. type: string
  6080. type: object
  6081. required:
  6082. - clientCert
  6083. - clientKey
  6084. type: object
  6085. serviceAccount:
  6086. description: points to a service account that should be used for authentication
  6087. properties:
  6088. audiences:
  6089. description: |-
  6090. Audience specifies the `aud` claim for the service account token
  6091. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  6092. then this audiences will be appended to the list
  6093. items:
  6094. type: string
  6095. type: array
  6096. name:
  6097. description: The name of the ServiceAccount resource being referred to.
  6098. maxLength: 253
  6099. minLength: 1
  6100. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6101. type: string
  6102. namespace:
  6103. description: |-
  6104. Namespace of the resource being referred to.
  6105. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6106. maxLength: 63
  6107. minLength: 1
  6108. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6109. type: string
  6110. required:
  6111. - name
  6112. type: object
  6113. token:
  6114. description: use static token to authenticate with
  6115. properties:
  6116. bearerToken:
  6117. description: |-
  6118. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6119. In some instances, `key` is a required field.
  6120. properties:
  6121. key:
  6122. description: |-
  6123. A key in the referenced Secret.
  6124. Some instances of this field may be defaulted, in others it may be required.
  6125. maxLength: 253
  6126. minLength: 1
  6127. pattern: ^[-._a-zA-Z0-9]+$
  6128. type: string
  6129. name:
  6130. description: The name of the Secret resource being referred to.
  6131. maxLength: 253
  6132. minLength: 1
  6133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6134. type: string
  6135. namespace:
  6136. description: |-
  6137. The namespace of the Secret resource being referred to.
  6138. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6139. maxLength: 63
  6140. minLength: 1
  6141. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6142. type: string
  6143. type: object
  6144. required:
  6145. - bearerToken
  6146. type: object
  6147. type: object
  6148. authRef:
  6149. description: A reference to a secret that contains the auth information.
  6150. properties:
  6151. key:
  6152. description: |-
  6153. A key in the referenced Secret.
  6154. Some instances of this field may be defaulted, in others it may be required.
  6155. maxLength: 253
  6156. minLength: 1
  6157. pattern: ^[-._a-zA-Z0-9]+$
  6158. type: string
  6159. name:
  6160. description: The name of the Secret resource being referred to.
  6161. maxLength: 253
  6162. minLength: 1
  6163. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6164. type: string
  6165. namespace:
  6166. description: |-
  6167. The namespace of the Secret resource being referred to.
  6168. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6169. maxLength: 63
  6170. minLength: 1
  6171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6172. type: string
  6173. type: object
  6174. remoteNamespace:
  6175. default: default
  6176. description: Remote namespace to fetch the secrets from
  6177. maxLength: 63
  6178. minLength: 1
  6179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6180. type: string
  6181. server:
  6182. description: configures the Kubernetes server Address.
  6183. properties:
  6184. caBundle:
  6185. description: CABundle is a base64-encoded CA certificate
  6186. format: byte
  6187. type: string
  6188. caProvider:
  6189. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  6190. properties:
  6191. key:
  6192. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6193. maxLength: 253
  6194. minLength: 1
  6195. pattern: ^[-._a-zA-Z0-9]+$
  6196. type: string
  6197. name:
  6198. description: The name of the object located at the provider type.
  6199. maxLength: 253
  6200. minLength: 1
  6201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6202. type: string
  6203. namespace:
  6204. description: |-
  6205. The namespace the Provider type is in.
  6206. Can only be defined when used in a ClusterSecretStore.
  6207. maxLength: 63
  6208. minLength: 1
  6209. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6210. type: string
  6211. type:
  6212. description: The type of provider to use such as "Secret", or "ConfigMap".
  6213. enum:
  6214. - Secret
  6215. - ConfigMap
  6216. type: string
  6217. required:
  6218. - name
  6219. - type
  6220. type: object
  6221. url:
  6222. default: kubernetes.default
  6223. description: configures the Kubernetes server Address.
  6224. type: string
  6225. type: object
  6226. type: object
  6227. nebiusmysterybox:
  6228. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  6229. properties:
  6230. apiDomain:
  6231. description: NebiusMysterybox API endpoint
  6232. type: string
  6233. auth:
  6234. description: Auth defines parameters to authenticate in MysteryBox
  6235. properties:
  6236. serviceAccountCredsSecretRef:
  6237. description: |-
  6238. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  6239. document with service account credentials used to get an IAM token.
  6240. Expected JSON structure:
  6241. {
  6242. "subject-credentials": {
  6243. "alg": "RS256",
  6244. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  6245. "kid": "<public-key-id>",
  6246. "iss": "<issuer-service-account-id>",
  6247. "sub": "<subject-service-account-id>"
  6248. }
  6249. }
  6250. properties:
  6251. key:
  6252. description: |-
  6253. A key in the referenced Secret.
  6254. Some instances of this field may be defaulted, in others it may be required.
  6255. maxLength: 253
  6256. minLength: 1
  6257. pattern: ^[-._a-zA-Z0-9]+$
  6258. type: string
  6259. name:
  6260. description: The name of the Secret resource being referred to.
  6261. maxLength: 253
  6262. minLength: 1
  6263. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6264. type: string
  6265. namespace:
  6266. description: |-
  6267. The namespace of the Secret resource being referred to.
  6268. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6269. maxLength: 63
  6270. minLength: 1
  6271. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6272. type: string
  6273. type: object
  6274. tokenSecretRef:
  6275. description: Token authenticates with Nebius Mysterybox by presenting a token.
  6276. properties:
  6277. key:
  6278. description: |-
  6279. A key in the referenced Secret.
  6280. Some instances of this field may be defaulted, in others it may be required.
  6281. maxLength: 253
  6282. minLength: 1
  6283. pattern: ^[-._a-zA-Z0-9]+$
  6284. type: string
  6285. name:
  6286. description: The name of the Secret resource being referred to.
  6287. maxLength: 253
  6288. minLength: 1
  6289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6290. type: string
  6291. namespace:
  6292. description: |-
  6293. The namespace of the Secret resource being referred to.
  6294. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6295. maxLength: 63
  6296. minLength: 1
  6297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6298. type: string
  6299. type: object
  6300. type: object
  6301. x-kubernetes-validations:
  6302. - message: either serviceAccountCredsSecretRef or tokenSecretRef must be set
  6303. rule: has(self.serviceAccountCredsSecretRef) || has(self.tokenSecretRef)
  6304. caProvider:
  6305. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  6306. properties:
  6307. certSecretRef:
  6308. description: |-
  6309. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6310. In some instances, `key` is a required field.
  6311. properties:
  6312. key:
  6313. description: |-
  6314. A key in the referenced Secret.
  6315. Some instances of this field may be defaulted, in others it may be required.
  6316. maxLength: 253
  6317. minLength: 1
  6318. pattern: ^[-._a-zA-Z0-9]+$
  6319. type: string
  6320. name:
  6321. description: The name of the Secret resource being referred to.
  6322. maxLength: 253
  6323. minLength: 1
  6324. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6325. type: string
  6326. namespace:
  6327. description: |-
  6328. The namespace of the Secret resource being referred to.
  6329. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6330. maxLength: 63
  6331. minLength: 1
  6332. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6333. type: string
  6334. type: object
  6335. type: object
  6336. required:
  6337. - apiDomain
  6338. - auth
  6339. type: object
  6340. ngrok:
  6341. description: Ngrok configures this store to sync secrets using the ngrok provider.
  6342. properties:
  6343. apiUrl:
  6344. default: https://api.ngrok.com
  6345. description: APIURL is the URL of the ngrok API.
  6346. type: string
  6347. auth:
  6348. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  6349. maxProperties: 1
  6350. minProperties: 1
  6351. properties:
  6352. apiKey:
  6353. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  6354. properties:
  6355. secretRef:
  6356. description: SecretRef is a reference to a secret containing the ngrok API key.
  6357. properties:
  6358. key:
  6359. description: |-
  6360. A key in the referenced Secret.
  6361. Some instances of this field may be defaulted, in others it may be required.
  6362. maxLength: 253
  6363. minLength: 1
  6364. pattern: ^[-._a-zA-Z0-9]+$
  6365. type: string
  6366. name:
  6367. description: The name of the Secret resource being referred to.
  6368. maxLength: 253
  6369. minLength: 1
  6370. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6371. type: string
  6372. namespace:
  6373. description: |-
  6374. The namespace of the Secret resource being referred to.
  6375. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6376. maxLength: 63
  6377. minLength: 1
  6378. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6379. type: string
  6380. type: object
  6381. type: object
  6382. type: object
  6383. vault:
  6384. description: Vault configures the ngrok vault to sync secrets with.
  6385. properties:
  6386. name:
  6387. description: Name is the name of the ngrok vault to sync secrets with.
  6388. type: string
  6389. required:
  6390. - name
  6391. type: object
  6392. required:
  6393. - auth
  6394. - vault
  6395. type: object
  6396. onboardbase:
  6397. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  6398. properties:
  6399. apiHost:
  6400. default: https://public.onboardbase.com/api/v1/
  6401. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  6402. type: string
  6403. auth:
  6404. description: Auth configures how the Operator authenticates with the Onboardbase API
  6405. properties:
  6406. apiKeyRef:
  6407. description: |-
  6408. OnboardbaseAPIKey is the APIKey generated by an admin account.
  6409. It is used to recognize and authorize access to a project and environment within onboardbase
  6410. properties:
  6411. key:
  6412. description: |-
  6413. A key in the referenced Secret.
  6414. Some instances of this field may be defaulted, in others it may be required.
  6415. maxLength: 253
  6416. minLength: 1
  6417. pattern: ^[-._a-zA-Z0-9]+$
  6418. type: string
  6419. name:
  6420. description: The name of the Secret resource being referred to.
  6421. maxLength: 253
  6422. minLength: 1
  6423. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6424. type: string
  6425. namespace:
  6426. description: |-
  6427. The namespace of the Secret resource being referred to.
  6428. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6429. maxLength: 63
  6430. minLength: 1
  6431. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6432. type: string
  6433. type: object
  6434. passcodeRef:
  6435. description: OnboardbasePasscode is the passcode attached to the API Key
  6436. properties:
  6437. key:
  6438. description: |-
  6439. A key in the referenced Secret.
  6440. Some instances of this field may be defaulted, in others it may be required.
  6441. maxLength: 253
  6442. minLength: 1
  6443. pattern: ^[-._a-zA-Z0-9]+$
  6444. type: string
  6445. name:
  6446. description: The name of the Secret resource being referred to.
  6447. maxLength: 253
  6448. minLength: 1
  6449. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6450. type: string
  6451. namespace:
  6452. description: |-
  6453. The namespace of the Secret resource being referred to.
  6454. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6455. maxLength: 63
  6456. minLength: 1
  6457. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6458. type: string
  6459. type: object
  6460. required:
  6461. - apiKeyRef
  6462. - passcodeRef
  6463. type: object
  6464. environment:
  6465. default: development
  6466. description: Environment is the name of an environmnent within a project to pull the secrets from
  6467. type: string
  6468. project:
  6469. default: development
  6470. description: Project is an onboardbase project that the secrets should be pulled from
  6471. type: string
  6472. required:
  6473. - apiHost
  6474. - auth
  6475. - environment
  6476. - project
  6477. type: object
  6478. onepassword:
  6479. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  6480. properties:
  6481. auth:
  6482. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  6483. properties:
  6484. secretRef:
  6485. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  6486. properties:
  6487. connectTokenSecretRef:
  6488. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  6489. properties:
  6490. key:
  6491. description: |-
  6492. A key in the referenced Secret.
  6493. Some instances of this field may be defaulted, in others it may be required.
  6494. maxLength: 253
  6495. minLength: 1
  6496. pattern: ^[-._a-zA-Z0-9]+$
  6497. type: string
  6498. name:
  6499. description: The name of the Secret resource being referred to.
  6500. maxLength: 253
  6501. minLength: 1
  6502. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6503. type: string
  6504. namespace:
  6505. description: |-
  6506. The namespace of the Secret resource being referred to.
  6507. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6508. maxLength: 63
  6509. minLength: 1
  6510. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6511. type: string
  6512. type: object
  6513. required:
  6514. - connectTokenSecretRef
  6515. type: object
  6516. required:
  6517. - secretRef
  6518. type: object
  6519. connectHost:
  6520. description: ConnectHost defines the OnePassword Connect Server to connect to
  6521. type: string
  6522. vaults:
  6523. additionalProperties:
  6524. type: integer
  6525. description: Vaults defines which OnePassword vaults to search in which order
  6526. type: object
  6527. required:
  6528. - auth
  6529. - connectHost
  6530. - vaults
  6531. type: object
  6532. onepasswordSDK:
  6533. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  6534. properties:
  6535. auth:
  6536. description: Auth defines the information necessary to authenticate against OnePassword API.
  6537. properties:
  6538. serviceAccountSecretRef:
  6539. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  6540. properties:
  6541. key:
  6542. description: |-
  6543. A key in the referenced Secret.
  6544. Some instances of this field may be defaulted, in others it may be required.
  6545. maxLength: 253
  6546. minLength: 1
  6547. pattern: ^[-._a-zA-Z0-9]+$
  6548. type: string
  6549. name:
  6550. description: The name of the Secret resource being referred to.
  6551. maxLength: 253
  6552. minLength: 1
  6553. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6554. type: string
  6555. namespace:
  6556. description: |-
  6557. The namespace of the Secret resource being referred to.
  6558. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6559. maxLength: 63
  6560. minLength: 1
  6561. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6562. type: string
  6563. type: object
  6564. required:
  6565. - serviceAccountSecretRef
  6566. type: object
  6567. cache:
  6568. description: |-
  6569. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  6570. When enabled, secrets are cached with the specified TTL.
  6571. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  6572. If omitted, caching is disabled (default).
  6573. cache: {} is a valid option to set.
  6574. properties:
  6575. maxSize:
  6576. default: 100
  6577. description: |-
  6578. MaxSize is the maximum number of secrets to cache.
  6579. When the cache is full, least-recently-used entries are evicted.
  6580. minimum: 1
  6581. type: integer
  6582. ttl:
  6583. default: 5m
  6584. description: |-
  6585. TTL is the time-to-live for cached secrets.
  6586. Format: duration string (e.g., "5m", "1h", "30s")
  6587. type: string
  6588. type: object
  6589. integrationInfo:
  6590. description: |-
  6591. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  6592. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  6593. properties:
  6594. name:
  6595. default: 1Password SDK
  6596. description: Name defaults to "1Password SDK".
  6597. type: string
  6598. version:
  6599. default: v1.0.0
  6600. description: Version defaults to "v1.0.0".
  6601. type: string
  6602. type: object
  6603. vault:
  6604. description: Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  6605. type: string
  6606. required:
  6607. - auth
  6608. - vault
  6609. type: object
  6610. openBao:
  6611. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  6612. properties:
  6613. auth:
  6614. description: Auth configures how secret-manager authenticates with the OpenBao server.
  6615. properties:
  6616. appRole:
  6617. description: |-
  6618. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  6619. with the role and secret stored in a Kubernetes Secret resource.
  6620. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  6621. properties:
  6622. path:
  6623. default: approle
  6624. description: |-
  6625. Path where the App Role authentication backend is mounted
  6626. in OpenBao, e.g: "approle"
  6627. type: string
  6628. roleId:
  6629. description: |-
  6630. RoleID configured in the App Role authentication backend when setting
  6631. up the authentication backend in OpenBao.
  6632. minLength: 1
  6633. type: string
  6634. roleRef:
  6635. description: |-
  6636. Reference to a key in a Secret that contains the App Role ID used
  6637. to authenticate with OpenBao.
  6638. The `key` field must be specified and denotes which entry within the Secret
  6639. resource is used as the app role id.
  6640. properties:
  6641. key:
  6642. description: |-
  6643. A key in the referenced Secret.
  6644. Some instances of this field may be defaulted, in others it may be required.
  6645. maxLength: 253
  6646. minLength: 1
  6647. pattern: ^[-._a-zA-Z0-9]+$
  6648. type: string
  6649. name:
  6650. description: The name of the Secret resource being referred to.
  6651. maxLength: 253
  6652. minLength: 1
  6653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6654. type: string
  6655. namespace:
  6656. description: |-
  6657. The namespace of the Secret resource being referred to.
  6658. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6659. maxLength: 63
  6660. minLength: 1
  6661. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6662. type: string
  6663. type: object
  6664. secretRef:
  6665. description: |-
  6666. Reference to a key in a Secret that contains the App Role secret used
  6667. to authenticate with OpenBao.
  6668. The `key` field must be specified and denotes which entry within the Secret
  6669. resource is used as the app role secret.
  6670. properties:
  6671. key:
  6672. description: |-
  6673. A key in the referenced Secret.
  6674. Some instances of this field may be defaulted, in others it may be required.
  6675. maxLength: 253
  6676. minLength: 1
  6677. pattern: ^[-._a-zA-Z0-9]+$
  6678. type: string
  6679. name:
  6680. description: The name of the Secret resource being referred to.
  6681. maxLength: 253
  6682. minLength: 1
  6683. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6684. type: string
  6685. namespace:
  6686. description: |-
  6687. The namespace of the Secret resource being referred to.
  6688. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6689. maxLength: 63
  6690. minLength: 1
  6691. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6692. type: string
  6693. type: object
  6694. required:
  6695. - path
  6696. - secretRef
  6697. type: object
  6698. x-kubernetes-validations:
  6699. - message: exactly one of the fields in [roleId roleRef] must be set
  6700. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  6701. namespace:
  6702. description: |-
  6703. Name of the [OpenBao Namespace] to authenticate to. This can be different
  6704. than the namespace your secret is in. Namespaces is a set of features
  6705. within OpenBao that allows OpenBao environments to support secure
  6706. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  6707. if set, or empty otherwise
  6708. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6709. type: string
  6710. tokenSecretRef:
  6711. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  6712. properties:
  6713. key:
  6714. description: |-
  6715. A key in the referenced Secret.
  6716. Some instances of this field may be defaulted, in others it may be required.
  6717. maxLength: 253
  6718. minLength: 1
  6719. pattern: ^[-._a-zA-Z0-9]+$
  6720. type: string
  6721. name:
  6722. description: The name of the Secret resource being referred to.
  6723. maxLength: 253
  6724. minLength: 1
  6725. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6726. type: string
  6727. namespace:
  6728. description: |-
  6729. The namespace of the Secret resource being referred to.
  6730. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6731. maxLength: 63
  6732. minLength: 1
  6733. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6734. type: string
  6735. type: object
  6736. userPass:
  6737. description: UserPass authenticates with OpenBao by passing a username/password pair
  6738. properties:
  6739. path:
  6740. default: userpass
  6741. description: |-
  6742. Path where the UserPassword authentication backend is mounted
  6743. in OpenBao, e.g: "userpass"
  6744. type: string
  6745. secretRef:
  6746. description: |-
  6747. SecretRef to a key in a Secret resource containing password for the user
  6748. used to authenticate with OpenBao using the [UserPass authentication
  6749. method]
  6750. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6751. properties:
  6752. key:
  6753. description: |-
  6754. A key in the referenced Secret.
  6755. Some instances of this field may be defaulted, in others it may be required.
  6756. maxLength: 253
  6757. minLength: 1
  6758. pattern: ^[-._a-zA-Z0-9]+$
  6759. type: string
  6760. name:
  6761. description: The name of the Secret resource being referred to.
  6762. maxLength: 253
  6763. minLength: 1
  6764. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6765. type: string
  6766. namespace:
  6767. description: |-
  6768. The namespace of the Secret resource being referred to.
  6769. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6770. maxLength: 63
  6771. minLength: 1
  6772. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6773. type: string
  6774. type: object
  6775. username:
  6776. description: |-
  6777. Username is a username used to authenticate using the [UserPass
  6778. authentication method]
  6779. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6780. type: string
  6781. required:
  6782. - path
  6783. - username
  6784. type: object
  6785. type: object
  6786. x-kubernetes-validations:
  6787. - message: exactly one of the fields in [appRole tokenSecretRef userPass] must be set
  6788. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass)].filter(x,x==true).size() == 1'
  6789. caBundle:
  6790. description: |-
  6791. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  6792. this and `caProvider` are not set the system root certificates are used
  6793. to validate the TLS connection.
  6794. format: byte
  6795. type: string
  6796. caProvider:
  6797. description: |-
  6798. The provider for the CA bundle to use to validate OpenBao server
  6799. certificate. If this and `caBundle` are not set the system root
  6800. certificates are used to validate the TLS connection.
  6801. properties:
  6802. key:
  6803. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6804. maxLength: 253
  6805. minLength: 1
  6806. pattern: ^[-._a-zA-Z0-9]+$
  6807. type: string
  6808. name:
  6809. description: The name of the object located at the provider type.
  6810. maxLength: 253
  6811. minLength: 1
  6812. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6813. type: string
  6814. namespace:
  6815. description: |-
  6816. The namespace the Provider type is in.
  6817. Can only be defined when used in a ClusterSecretStore.
  6818. maxLength: 63
  6819. minLength: 1
  6820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6821. type: string
  6822. type:
  6823. description: The type of provider to use such as "Secret", or "ConfigMap".
  6824. enum:
  6825. - Secret
  6826. - ConfigMap
  6827. type: string
  6828. required:
  6829. - name
  6830. - type
  6831. type: object
  6832. namespace:
  6833. description: |-
  6834. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  6835. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  6836. e.g: "ns1".
  6837. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6838. type: string
  6839. path:
  6840. description: |-
  6841. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  6842. "secret". The v2 KV secret engine version specific "/data" path suffix
  6843. for fetching secrets from OpenBao is optional and will be appended
  6844. if not present in specified path.
  6845. type: string
  6846. server:
  6847. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  6848. type: string
  6849. version:
  6850. default: v2
  6851. description: |-
  6852. Version is the OpenBao KV secret engine version. This can be either "v1" or
  6853. "v2". Version defaults to "v2".
  6854. enum:
  6855. - v1
  6856. - v2
  6857. type: string
  6858. required:
  6859. - server
  6860. type: object
  6861. x-kubernetes-validations:
  6862. - message: at most one of the fields in [caBundle caProvider] may be set
  6863. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  6864. oracle:
  6865. description: Oracle configures this store to sync secrets using Oracle Vault provider
  6866. properties:
  6867. auth:
  6868. description: |-
  6869. Auth configures how secret-manager authenticates with the Oracle Vault.
  6870. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  6871. properties:
  6872. secretRef:
  6873. description: SecretRef to pass through sensitive information.
  6874. properties:
  6875. fingerprint:
  6876. description: Fingerprint is the fingerprint of the API private key.
  6877. properties:
  6878. key:
  6879. description: |-
  6880. A key in the referenced Secret.
  6881. Some instances of this field may be defaulted, in others it may be required.
  6882. maxLength: 253
  6883. minLength: 1
  6884. pattern: ^[-._a-zA-Z0-9]+$
  6885. type: string
  6886. name:
  6887. description: The name of the Secret resource being referred to.
  6888. maxLength: 253
  6889. minLength: 1
  6890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6891. type: string
  6892. namespace:
  6893. description: |-
  6894. The namespace of the Secret resource being referred to.
  6895. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6896. maxLength: 63
  6897. minLength: 1
  6898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6899. type: string
  6900. type: object
  6901. privatekey:
  6902. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  6903. properties:
  6904. key:
  6905. description: |-
  6906. A key in the referenced Secret.
  6907. Some instances of this field may be defaulted, in others it may be required.
  6908. maxLength: 253
  6909. minLength: 1
  6910. pattern: ^[-._a-zA-Z0-9]+$
  6911. type: string
  6912. name:
  6913. description: The name of the Secret resource being referred to.
  6914. maxLength: 253
  6915. minLength: 1
  6916. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6917. type: string
  6918. namespace:
  6919. description: |-
  6920. The namespace of the Secret resource being referred to.
  6921. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6922. maxLength: 63
  6923. minLength: 1
  6924. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6925. type: string
  6926. type: object
  6927. required:
  6928. - fingerprint
  6929. - privatekey
  6930. type: object
  6931. tenancy:
  6932. description: Tenancy is the tenancy OCID where user is located.
  6933. type: string
  6934. user:
  6935. description: User is an access OCID specific to the account.
  6936. type: string
  6937. required:
  6938. - secretRef
  6939. - tenancy
  6940. - user
  6941. type: object
  6942. compartment:
  6943. description: |-
  6944. Compartment is the vault compartment OCID.
  6945. Required for PushSecret
  6946. type: string
  6947. encryptionKey:
  6948. description: |-
  6949. EncryptionKey is the OCID of the encryption key within the vault.
  6950. Required for PushSecret
  6951. type: string
  6952. principalType:
  6953. description: |-
  6954. The type of principal to use for authentication. If left blank, the Auth struct will
  6955. determine the principal type. This optional field must be specified if using
  6956. workload identity.
  6957. enum:
  6958. - ""
  6959. - UserPrincipal
  6960. - InstancePrincipal
  6961. - Workload
  6962. type: string
  6963. region:
  6964. description: Region is the region where vault is located.
  6965. type: string
  6966. serviceAccountRef:
  6967. description: |-
  6968. ServiceAccountRef specified the service account
  6969. that should be used when authenticating with WorkloadIdentity.
  6970. properties:
  6971. audiences:
  6972. description: |-
  6973. Audience specifies the `aud` claim for the service account token
  6974. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  6975. then this audiences will be appended to the list
  6976. items:
  6977. type: string
  6978. type: array
  6979. name:
  6980. description: The name of the ServiceAccount resource being referred to.
  6981. maxLength: 253
  6982. minLength: 1
  6983. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6984. type: string
  6985. namespace:
  6986. description: |-
  6987. Namespace of the resource being referred to.
  6988. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6989. maxLength: 63
  6990. minLength: 1
  6991. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6992. type: string
  6993. required:
  6994. - name
  6995. type: object
  6996. vault:
  6997. description: Vault is the vault's OCID of the specific vault where secret is located.
  6998. type: string
  6999. required:
  7000. - region
  7001. - vault
  7002. type: object
  7003. ovh:
  7004. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  7005. properties:
  7006. auth:
  7007. description: Authentication method (mtls or token).
  7008. properties:
  7009. mtls:
  7010. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  7011. properties:
  7012. caBundle:
  7013. format: byte
  7014. type: string
  7015. caProvider:
  7016. description: |-
  7017. CAProvider provides a custom certificate authority for accessing the provider's store.
  7018. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  7019. properties:
  7020. key:
  7021. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7022. maxLength: 253
  7023. minLength: 1
  7024. pattern: ^[-._a-zA-Z0-9]+$
  7025. type: string
  7026. name:
  7027. description: The name of the object located at the provider type.
  7028. maxLength: 253
  7029. minLength: 1
  7030. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7031. type: string
  7032. namespace:
  7033. description: |-
  7034. The namespace the Provider type is in.
  7035. Can only be defined when used in a ClusterSecretStore.
  7036. maxLength: 63
  7037. minLength: 1
  7038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7039. type: string
  7040. type:
  7041. description: The type of provider to use such as "Secret", or "ConfigMap".
  7042. enum:
  7043. - Secret
  7044. - ConfigMap
  7045. type: string
  7046. required:
  7047. - name
  7048. - type
  7049. type: object
  7050. certSecretRef:
  7051. description: |-
  7052. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7053. In some instances, `key` is a required field.
  7054. properties:
  7055. key:
  7056. description: |-
  7057. A key in the referenced Secret.
  7058. Some instances of this field may be defaulted, in others it may be required.
  7059. maxLength: 253
  7060. minLength: 1
  7061. pattern: ^[-._a-zA-Z0-9]+$
  7062. type: string
  7063. name:
  7064. description: The name of the Secret resource being referred to.
  7065. maxLength: 253
  7066. minLength: 1
  7067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7068. type: string
  7069. namespace:
  7070. description: |-
  7071. The namespace of the Secret resource being referred to.
  7072. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7073. maxLength: 63
  7074. minLength: 1
  7075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7076. type: string
  7077. type: object
  7078. keySecretRef:
  7079. description: |-
  7080. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7081. In some instances, `key` is a required field.
  7082. properties:
  7083. key:
  7084. description: |-
  7085. A key in the referenced Secret.
  7086. Some instances of this field may be defaulted, in others it may be required.
  7087. maxLength: 253
  7088. minLength: 1
  7089. pattern: ^[-._a-zA-Z0-9]+$
  7090. type: string
  7091. name:
  7092. description: The name of the Secret resource being referred to.
  7093. maxLength: 253
  7094. minLength: 1
  7095. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7096. type: string
  7097. namespace:
  7098. description: |-
  7099. The namespace of the Secret resource being referred to.
  7100. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7101. maxLength: 63
  7102. minLength: 1
  7103. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7104. type: string
  7105. type: object
  7106. required:
  7107. - certSecretRef
  7108. - keySecretRef
  7109. type: object
  7110. token:
  7111. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  7112. properties:
  7113. tokenSecretRef:
  7114. description: |-
  7115. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7116. In some instances, `key` is a required field.
  7117. properties:
  7118. key:
  7119. description: |-
  7120. A key in the referenced Secret.
  7121. Some instances of this field may be defaulted, in others it may be required.
  7122. maxLength: 253
  7123. minLength: 1
  7124. pattern: ^[-._a-zA-Z0-9]+$
  7125. type: string
  7126. name:
  7127. description: The name of the Secret resource being referred to.
  7128. maxLength: 253
  7129. minLength: 1
  7130. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7131. type: string
  7132. namespace:
  7133. description: |-
  7134. The namespace of the Secret resource being referred to.
  7135. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7136. maxLength: 63
  7137. minLength: 1
  7138. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7139. type: string
  7140. type: object
  7141. required:
  7142. - tokenSecretRef
  7143. type: object
  7144. type: object
  7145. casRequired:
  7146. description: 'Enables or disables check-and-set (CAS) (default: false).'
  7147. type: boolean
  7148. okmsTimeout:
  7149. default: 30
  7150. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  7151. format: int32
  7152. minimum: 1
  7153. type: integer
  7154. okmsid:
  7155. description: specifies the OKMS ID.
  7156. type: string
  7157. server:
  7158. description: specifies the OKMS server endpoint.
  7159. type: string
  7160. required:
  7161. - auth
  7162. - okmsid
  7163. - server
  7164. type: object
  7165. passbolt:
  7166. description: |-
  7167. PassboltProvider provides access to Passbolt secrets manager.
  7168. See: https://www.passbolt.com.
  7169. properties:
  7170. auth:
  7171. description: Auth defines the information necessary to authenticate against Passbolt Server
  7172. properties:
  7173. passwordSecretRef:
  7174. description: |-
  7175. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7176. In some instances, `key` is a required field.
  7177. properties:
  7178. key:
  7179. description: |-
  7180. A key in the referenced Secret.
  7181. Some instances of this field may be defaulted, in others it may be required.
  7182. maxLength: 253
  7183. minLength: 1
  7184. pattern: ^[-._a-zA-Z0-9]+$
  7185. type: string
  7186. name:
  7187. description: The name of the Secret resource being referred to.
  7188. maxLength: 253
  7189. minLength: 1
  7190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7191. type: string
  7192. namespace:
  7193. description: |-
  7194. The namespace of the Secret resource being referred to.
  7195. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7196. maxLength: 63
  7197. minLength: 1
  7198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7199. type: string
  7200. type: object
  7201. privateKeySecretRef:
  7202. description: |-
  7203. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7204. In some instances, `key` is a required field.
  7205. properties:
  7206. key:
  7207. description: |-
  7208. A key in the referenced Secret.
  7209. Some instances of this field may be defaulted, in others it may be required.
  7210. maxLength: 253
  7211. minLength: 1
  7212. pattern: ^[-._a-zA-Z0-9]+$
  7213. type: string
  7214. name:
  7215. description: The name of the Secret resource being referred to.
  7216. maxLength: 253
  7217. minLength: 1
  7218. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7219. type: string
  7220. namespace:
  7221. description: |-
  7222. The namespace of the Secret resource being referred to.
  7223. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7224. maxLength: 63
  7225. minLength: 1
  7226. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7227. type: string
  7228. type: object
  7229. required:
  7230. - passwordSecretRef
  7231. - privateKeySecretRef
  7232. type: object
  7233. caBundle:
  7234. description: |-
  7235. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  7236. if the Host URL is using HTTPS protocol. If not set the system root certificates
  7237. are used to validate the TLS connection.
  7238. format: byte
  7239. type: string
  7240. caProvider:
  7241. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  7242. properties:
  7243. key:
  7244. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7245. maxLength: 253
  7246. minLength: 1
  7247. pattern: ^[-._a-zA-Z0-9]+$
  7248. type: string
  7249. name:
  7250. description: The name of the object located at the provider type.
  7251. maxLength: 253
  7252. minLength: 1
  7253. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7254. type: string
  7255. namespace:
  7256. description: |-
  7257. The namespace the Provider type is in.
  7258. Can only be defined when used in a ClusterSecretStore.
  7259. maxLength: 63
  7260. minLength: 1
  7261. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7262. type: string
  7263. type:
  7264. description: The type of provider to use such as "Secret", or "ConfigMap".
  7265. enum:
  7266. - Secret
  7267. - ConfigMap
  7268. type: string
  7269. required:
  7270. - name
  7271. - type
  7272. type: object
  7273. host:
  7274. description: Host defines the Passbolt Server to connect to
  7275. type: string
  7276. required:
  7277. - auth
  7278. - host
  7279. type: object
  7280. passworddepot:
  7281. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  7282. properties:
  7283. auth:
  7284. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  7285. properties:
  7286. secretRef:
  7287. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  7288. properties:
  7289. credentials:
  7290. description: Username / Password is used for authentication.
  7291. properties:
  7292. key:
  7293. description: |-
  7294. A key in the referenced Secret.
  7295. Some instances of this field may be defaulted, in others it may be required.
  7296. maxLength: 253
  7297. minLength: 1
  7298. pattern: ^[-._a-zA-Z0-9]+$
  7299. type: string
  7300. name:
  7301. description: The name of the Secret resource being referred to.
  7302. maxLength: 253
  7303. minLength: 1
  7304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7305. type: string
  7306. namespace:
  7307. description: |-
  7308. The namespace of the Secret resource being referred to.
  7309. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7310. maxLength: 63
  7311. minLength: 1
  7312. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7313. type: string
  7314. type: object
  7315. type: object
  7316. required:
  7317. - secretRef
  7318. type: object
  7319. database:
  7320. description: Database to use as source
  7321. type: string
  7322. host:
  7323. description: URL configures the Password Depot instance URL.
  7324. type: string
  7325. required:
  7326. - auth
  7327. - database
  7328. - host
  7329. type: object
  7330. previder:
  7331. description: Previder configures this store to sync secrets using the Previder provider
  7332. properties:
  7333. auth:
  7334. description: PreviderAuth contains a secretRef for credentials.
  7335. properties:
  7336. secretRef:
  7337. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  7338. properties:
  7339. accessToken:
  7340. description: The AccessToken is used for authentication
  7341. properties:
  7342. key:
  7343. description: |-
  7344. A key in the referenced Secret.
  7345. Some instances of this field may be defaulted, in others it may be required.
  7346. maxLength: 253
  7347. minLength: 1
  7348. pattern: ^[-._a-zA-Z0-9]+$
  7349. type: string
  7350. name:
  7351. description: The name of the Secret resource being referred to.
  7352. maxLength: 253
  7353. minLength: 1
  7354. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7355. type: string
  7356. namespace:
  7357. description: |-
  7358. The namespace of the Secret resource being referred to.
  7359. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7360. maxLength: 63
  7361. minLength: 1
  7362. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7363. type: string
  7364. type: object
  7365. required:
  7366. - accessToken
  7367. type: object
  7368. type: object
  7369. baseUri:
  7370. type: string
  7371. required:
  7372. - auth
  7373. type: object
  7374. pulumi:
  7375. description: Pulumi configures this store to sync secrets using the Pulumi provider
  7376. properties:
  7377. accessToken:
  7378. description: |-
  7379. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  7380. Deprecated: Use auth.accessToken instead.
  7381. properties:
  7382. secretRef:
  7383. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7384. properties:
  7385. key:
  7386. description: |-
  7387. A key in the referenced Secret.
  7388. Some instances of this field may be defaulted, in others it may be required.
  7389. maxLength: 253
  7390. minLength: 1
  7391. pattern: ^[-._a-zA-Z0-9]+$
  7392. type: string
  7393. name:
  7394. description: The name of the Secret resource being referred to.
  7395. maxLength: 253
  7396. minLength: 1
  7397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7398. type: string
  7399. namespace:
  7400. description: |-
  7401. The namespace of the Secret resource being referred to.
  7402. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7403. maxLength: 63
  7404. minLength: 1
  7405. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7406. type: string
  7407. type: object
  7408. type: object
  7409. apiUrl:
  7410. default: https://api.pulumi.com/api/esc
  7411. description: APIURL is the URL of the Pulumi API.
  7412. type: string
  7413. auth:
  7414. description: |-
  7415. Auth configures how the Operator authenticates with the Pulumi API.
  7416. Either auth or the deprecated accessToken field must be specified.
  7417. properties:
  7418. accessToken:
  7419. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  7420. properties:
  7421. secretRef:
  7422. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7423. properties:
  7424. key:
  7425. description: |-
  7426. A key in the referenced Secret.
  7427. Some instances of this field may be defaulted, in others it may be required.
  7428. maxLength: 253
  7429. minLength: 1
  7430. pattern: ^[-._a-zA-Z0-9]+$
  7431. type: string
  7432. name:
  7433. description: The name of the Secret resource being referred to.
  7434. maxLength: 253
  7435. minLength: 1
  7436. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7437. type: string
  7438. namespace:
  7439. description: |-
  7440. The namespace of the Secret resource being referred to.
  7441. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7442. maxLength: 63
  7443. minLength: 1
  7444. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7445. type: string
  7446. type: object
  7447. type: object
  7448. oidcConfig:
  7449. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  7450. properties:
  7451. expirationSeconds:
  7452. default: 600
  7453. description: |-
  7454. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  7455. Defaults to 10 minutes.
  7456. format: int64
  7457. minimum: 600
  7458. type: integer
  7459. organization:
  7460. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  7461. type: string
  7462. serviceAccountRef:
  7463. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  7464. properties:
  7465. audiences:
  7466. description: |-
  7467. Audience specifies the `aud` claim for the service account token
  7468. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  7469. then this audiences will be appended to the list
  7470. items:
  7471. type: string
  7472. type: array
  7473. name:
  7474. description: The name of the ServiceAccount resource being referred to.
  7475. maxLength: 253
  7476. minLength: 1
  7477. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7478. type: string
  7479. namespace:
  7480. description: |-
  7481. Namespace of the resource being referred to.
  7482. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7483. maxLength: 63
  7484. minLength: 1
  7485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7486. type: string
  7487. required:
  7488. - name
  7489. type: object
  7490. required:
  7491. - organization
  7492. - serviceAccountRef
  7493. type: object
  7494. type: object
  7495. x-kubernetes-validations:
  7496. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  7497. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  7498. environment:
  7499. description: |-
  7500. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  7501. dynamically retrieved values from supported providers including all major clouds,
  7502. and other Pulumi ESC environments.
  7503. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  7504. type: string
  7505. organization:
  7506. description: |-
  7507. Organization are a space to collaborate on shared projects and stacks.
  7508. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  7509. type: string
  7510. project:
  7511. description: Project is the name of the Pulumi ESC project the environment belongs to.
  7512. type: string
  7513. required:
  7514. - environment
  7515. - organization
  7516. - project
  7517. type: object
  7518. x-kubernetes-validations:
  7519. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  7520. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  7521. scaleway:
  7522. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  7523. properties:
  7524. accessKey:
  7525. description: AccessKey is the non-secret part of the api key.
  7526. properties:
  7527. secretRef:
  7528. description: SecretRef references a key in a secret that will be used as value.
  7529. properties:
  7530. key:
  7531. description: |-
  7532. A key in the referenced Secret.
  7533. Some instances of this field may be defaulted, in others it may be required.
  7534. maxLength: 253
  7535. minLength: 1
  7536. pattern: ^[-._a-zA-Z0-9]+$
  7537. type: string
  7538. name:
  7539. description: The name of the Secret resource being referred to.
  7540. maxLength: 253
  7541. minLength: 1
  7542. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7543. type: string
  7544. namespace:
  7545. description: |-
  7546. The namespace of the Secret resource being referred to.
  7547. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7548. maxLength: 63
  7549. minLength: 1
  7550. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7551. type: string
  7552. type: object
  7553. value:
  7554. description: Value can be specified directly to set a value without using a secret.
  7555. type: string
  7556. type: object
  7557. apiUrl:
  7558. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  7559. type: string
  7560. projectId:
  7561. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  7562. type: string
  7563. region:
  7564. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  7565. type: string
  7566. secretKey:
  7567. description: SecretKey is the non-secret part of the api key.
  7568. properties:
  7569. secretRef:
  7570. description: SecretRef references a key in a secret that will be used as value.
  7571. properties:
  7572. key:
  7573. description: |-
  7574. A key in the referenced Secret.
  7575. Some instances of this field may be defaulted, in others it may be required.
  7576. maxLength: 253
  7577. minLength: 1
  7578. pattern: ^[-._a-zA-Z0-9]+$
  7579. type: string
  7580. name:
  7581. description: The name of the Secret resource being referred to.
  7582. maxLength: 253
  7583. minLength: 1
  7584. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7585. type: string
  7586. namespace:
  7587. description: |-
  7588. The namespace of the Secret resource being referred to.
  7589. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7590. maxLength: 63
  7591. minLength: 1
  7592. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7593. type: string
  7594. type: object
  7595. value:
  7596. description: Value can be specified directly to set a value without using a secret.
  7597. type: string
  7598. type: object
  7599. required:
  7600. - accessKey
  7601. - projectId
  7602. - region
  7603. - secretKey
  7604. type: object
  7605. secretserver:
  7606. description: |-
  7607. SecretServer configures this store to sync secrets using SecretServer provider
  7608. https://docs.delinea.com/online-help/secret-server/start.htm
  7609. properties:
  7610. caBundle:
  7611. description: |-
  7612. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  7613. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  7614. are used to validate the TLS connection.
  7615. format: byte
  7616. type: string
  7617. caProvider:
  7618. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  7619. properties:
  7620. key:
  7621. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7622. maxLength: 253
  7623. minLength: 1
  7624. pattern: ^[-._a-zA-Z0-9]+$
  7625. type: string
  7626. name:
  7627. description: The name of the object located at the provider type.
  7628. maxLength: 253
  7629. minLength: 1
  7630. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7631. type: string
  7632. namespace:
  7633. description: |-
  7634. The namespace the Provider type is in.
  7635. Can only be defined when used in a ClusterSecretStore.
  7636. maxLength: 63
  7637. minLength: 1
  7638. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7639. type: string
  7640. type:
  7641. description: The type of provider to use such as "Secret", or "ConfigMap".
  7642. enum:
  7643. - Secret
  7644. - ConfigMap
  7645. type: string
  7646. required:
  7647. - name
  7648. - type
  7649. type: object
  7650. domain:
  7651. description: Domain is the secret server domain.
  7652. type: string
  7653. password:
  7654. description: |-
  7655. Password is the secret server account password.
  7656. Required unless Token is set.
  7657. properties:
  7658. secretRef:
  7659. description: SecretRef references a key in a secret that will be used as value.
  7660. properties:
  7661. key:
  7662. description: |-
  7663. A key in the referenced Secret.
  7664. Some instances of this field may be defaulted, in others it may be required.
  7665. maxLength: 253
  7666. minLength: 1
  7667. pattern: ^[-._a-zA-Z0-9]+$
  7668. type: string
  7669. name:
  7670. description: The name of the Secret resource being referred to.
  7671. maxLength: 253
  7672. minLength: 1
  7673. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7674. type: string
  7675. namespace:
  7676. description: |-
  7677. The namespace of the Secret resource being referred to.
  7678. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7679. maxLength: 63
  7680. minLength: 1
  7681. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7682. type: string
  7683. type: object
  7684. value:
  7685. description: Value can be specified directly to set a value without using a secret.
  7686. minLength: 1
  7687. type: string
  7688. type: object
  7689. x-kubernetes-validations:
  7690. - message: exactly one of value or secretRef must be set
  7691. rule: has(self.value) != has(self.secretRef)
  7692. serverURL:
  7693. description: |-
  7694. ServerURL
  7695. URL to your secret server installation
  7696. type: string
  7697. token:
  7698. description: |-
  7699. Token is an access token used to authenticate to the secret server,
  7700. as an alternative to Username and Password. When set, Username and
  7701. Password are not required and are ignored.
  7702. properties:
  7703. secretRef:
  7704. description: SecretRef references a key in a secret that will be used as value.
  7705. properties:
  7706. key:
  7707. description: |-
  7708. A key in the referenced Secret.
  7709. Some instances of this field may be defaulted, in others it may be required.
  7710. maxLength: 253
  7711. minLength: 1
  7712. pattern: ^[-._a-zA-Z0-9]+$
  7713. type: string
  7714. name:
  7715. description: The name of the Secret resource being referred to.
  7716. maxLength: 253
  7717. minLength: 1
  7718. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7719. type: string
  7720. namespace:
  7721. description: |-
  7722. The namespace of the Secret resource being referred to.
  7723. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7724. maxLength: 63
  7725. minLength: 1
  7726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7727. type: string
  7728. type: object
  7729. value:
  7730. description: Value can be specified directly to set a value without using a secret.
  7731. minLength: 1
  7732. type: string
  7733. type: object
  7734. x-kubernetes-validations:
  7735. - message: exactly one of value or secretRef must be set
  7736. rule: has(self.value) != has(self.secretRef)
  7737. username:
  7738. description: |-
  7739. Username is the secret server account username.
  7740. Required unless Token is set.
  7741. properties:
  7742. secretRef:
  7743. description: SecretRef references a key in a secret that will be used as value.
  7744. properties:
  7745. key:
  7746. description: |-
  7747. A key in the referenced Secret.
  7748. Some instances of this field may be defaulted, in others it may be required.
  7749. maxLength: 253
  7750. minLength: 1
  7751. pattern: ^[-._a-zA-Z0-9]+$
  7752. type: string
  7753. name:
  7754. description: The name of the Secret resource being referred to.
  7755. maxLength: 253
  7756. minLength: 1
  7757. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7758. type: string
  7759. namespace:
  7760. description: |-
  7761. The namespace of the Secret resource being referred to.
  7762. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7763. maxLength: 63
  7764. minLength: 1
  7765. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7766. type: string
  7767. type: object
  7768. value:
  7769. description: Value can be specified directly to set a value without using a secret.
  7770. minLength: 1
  7771. type: string
  7772. type: object
  7773. x-kubernetes-validations:
  7774. - message: exactly one of value or secretRef must be set
  7775. rule: has(self.value) != has(self.secretRef)
  7776. required:
  7777. - serverURL
  7778. type: object
  7779. x-kubernetes-validations:
  7780. - message: either token, or both username and password, must be set
  7781. rule: has(self.token) || (has(self.username) && has(self.password))
  7782. senhasegura:
  7783. description: Senhasegura configures this store to sync secrets using senhasegura provider
  7784. properties:
  7785. auth:
  7786. description: Auth defines parameters to authenticate in senhasegura
  7787. properties:
  7788. clientId:
  7789. type: string
  7790. clientSecretSecretRef:
  7791. description: |-
  7792. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7793. In some instances, `key` is a required field.
  7794. properties:
  7795. key:
  7796. description: |-
  7797. A key in the referenced Secret.
  7798. Some instances of this field may be defaulted, in others it may be required.
  7799. maxLength: 253
  7800. minLength: 1
  7801. pattern: ^[-._a-zA-Z0-9]+$
  7802. type: string
  7803. name:
  7804. description: The name of the Secret resource being referred to.
  7805. maxLength: 253
  7806. minLength: 1
  7807. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7808. type: string
  7809. namespace:
  7810. description: |-
  7811. The namespace of the Secret resource being referred to.
  7812. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7813. maxLength: 63
  7814. minLength: 1
  7815. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7816. type: string
  7817. type: object
  7818. required:
  7819. - clientId
  7820. - clientSecretSecretRef
  7821. type: object
  7822. ignoreSslCertificate:
  7823. default: false
  7824. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  7825. type: boolean
  7826. module:
  7827. description: Module defines which senhasegura module should be used to get secrets
  7828. type: string
  7829. url:
  7830. description: URL of senhasegura
  7831. type: string
  7832. required:
  7833. - auth
  7834. - module
  7835. - url
  7836. type: object
  7837. vault:
  7838. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  7839. properties:
  7840. auth:
  7841. description: Auth configures how secret-manager authenticates with the Vault server.
  7842. properties:
  7843. appRole:
  7844. description: |-
  7845. AppRole authenticates with Vault using the App Role auth mechanism,
  7846. with the role and secret stored in a Kubernetes Secret resource.
  7847. properties:
  7848. path:
  7849. default: approle
  7850. description: |-
  7851. Path where the App Role authentication backend is mounted
  7852. in Vault, e.g: "approle"
  7853. type: string
  7854. roleId:
  7855. description: |-
  7856. RoleID configured in the App Role authentication backend when setting
  7857. up the authentication backend in Vault.
  7858. type: string
  7859. roleRef:
  7860. description: |-
  7861. Reference to a key in a Secret that contains the App Role ID used
  7862. to authenticate with Vault.
  7863. The `key` field must be specified and denotes which entry within the Secret
  7864. resource is used as the app role id.
  7865. properties:
  7866. key:
  7867. description: |-
  7868. A key in the referenced Secret.
  7869. Some instances of this field may be defaulted, in others it may be required.
  7870. maxLength: 253
  7871. minLength: 1
  7872. pattern: ^[-._a-zA-Z0-9]+$
  7873. type: string
  7874. name:
  7875. description: The name of the Secret resource being referred to.
  7876. maxLength: 253
  7877. minLength: 1
  7878. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7879. type: string
  7880. namespace:
  7881. description: |-
  7882. The namespace of the Secret resource being referred to.
  7883. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7884. maxLength: 63
  7885. minLength: 1
  7886. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7887. type: string
  7888. type: object
  7889. secretRef:
  7890. description: |-
  7891. Reference to a key in a Secret that contains the App Role secret used
  7892. to authenticate with Vault.
  7893. The `key` field must be specified and denotes which entry within the Secret
  7894. resource is used as the app role secret.
  7895. properties:
  7896. key:
  7897. description: |-
  7898. A key in the referenced Secret.
  7899. Some instances of this field may be defaulted, in others it may be required.
  7900. maxLength: 253
  7901. minLength: 1
  7902. pattern: ^[-._a-zA-Z0-9]+$
  7903. type: string
  7904. name:
  7905. description: The name of the Secret resource being referred to.
  7906. maxLength: 253
  7907. minLength: 1
  7908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7909. type: string
  7910. namespace:
  7911. description: |-
  7912. The namespace of the Secret resource being referred to.
  7913. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7914. maxLength: 63
  7915. minLength: 1
  7916. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7917. type: string
  7918. type: object
  7919. required:
  7920. - path
  7921. - secretRef
  7922. type: object
  7923. cert:
  7924. description: |-
  7925. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  7926. Cert authentication method
  7927. properties:
  7928. clientCert:
  7929. description: |-
  7930. ClientCert is a certificate to authenticate using the Cert Vault
  7931. authentication method
  7932. properties:
  7933. key:
  7934. description: |-
  7935. A key in the referenced Secret.
  7936. Some instances of this field may be defaulted, in others it may be required.
  7937. maxLength: 253
  7938. minLength: 1
  7939. pattern: ^[-._a-zA-Z0-9]+$
  7940. type: string
  7941. name:
  7942. description: The name of the Secret resource being referred to.
  7943. maxLength: 253
  7944. minLength: 1
  7945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7946. type: string
  7947. namespace:
  7948. description: |-
  7949. The namespace of the Secret resource being referred to.
  7950. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7951. maxLength: 63
  7952. minLength: 1
  7953. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7954. type: string
  7955. type: object
  7956. path:
  7957. default: cert
  7958. description: |-
  7959. Path where the Certificate authentication backend is mounted
  7960. in Vault, e.g: "cert"
  7961. type: string
  7962. secretRef:
  7963. description: |-
  7964. SecretRef to a key in a Secret resource containing client private key to
  7965. authenticate with Vault using the Cert authentication method
  7966. properties:
  7967. key:
  7968. description: |-
  7969. A key in the referenced Secret.
  7970. Some instances of this field may be defaulted, in others it may be required.
  7971. maxLength: 253
  7972. minLength: 1
  7973. pattern: ^[-._a-zA-Z0-9]+$
  7974. type: string
  7975. name:
  7976. description: The name of the Secret resource being referred to.
  7977. maxLength: 253
  7978. minLength: 1
  7979. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7980. type: string
  7981. namespace:
  7982. description: |-
  7983. The namespace of the Secret resource being referred to.
  7984. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7985. maxLength: 63
  7986. minLength: 1
  7987. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7988. type: string
  7989. type: object
  7990. vaultRole:
  7991. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  7992. type: string
  7993. type: object
  7994. gcp:
  7995. description: |-
  7996. Gcp authenticates with Vault using Google Cloud Platform authentication method
  7997. GCP authentication method
  7998. properties:
  7999. location:
  8000. description: Location optionally defines a location/region for the secret
  8001. type: string
  8002. path:
  8003. default: gcp
  8004. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  8005. type: string
  8006. projectID:
  8007. description: Project ID of the Google Cloud Platform project
  8008. type: string
  8009. role:
  8010. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  8011. type: string
  8012. secretRef:
  8013. description: Specify credentials in a Secret object
  8014. properties:
  8015. secretAccessKeySecretRef:
  8016. description: The SecretAccessKey is used for authentication
  8017. properties:
  8018. key:
  8019. description: |-
  8020. A key in the referenced Secret.
  8021. Some instances of this field may be defaulted, in others it may be required.
  8022. maxLength: 253
  8023. minLength: 1
  8024. pattern: ^[-._a-zA-Z0-9]+$
  8025. type: string
  8026. name:
  8027. description: The name of the Secret resource being referred to.
  8028. maxLength: 253
  8029. minLength: 1
  8030. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8031. type: string
  8032. namespace:
  8033. description: |-
  8034. The namespace of the Secret resource being referred to.
  8035. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8036. maxLength: 63
  8037. minLength: 1
  8038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8039. type: string
  8040. type: object
  8041. type: object
  8042. serviceAccountRef:
  8043. description: ServiceAccountRef to a service account for impersonation
  8044. properties:
  8045. audiences:
  8046. description: |-
  8047. Audience specifies the `aud` claim for the service account token
  8048. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8049. then this audiences will be appended to the list
  8050. items:
  8051. type: string
  8052. type: array
  8053. name:
  8054. description: The name of the ServiceAccount resource being referred to.
  8055. maxLength: 253
  8056. minLength: 1
  8057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8058. type: string
  8059. namespace:
  8060. description: |-
  8061. Namespace of the resource being referred to.
  8062. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8063. maxLength: 63
  8064. minLength: 1
  8065. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8066. type: string
  8067. required:
  8068. - name
  8069. type: object
  8070. workloadIdentity:
  8071. description: Specify a service account with Workload Identity
  8072. properties:
  8073. clusterLocation:
  8074. description: |-
  8075. ClusterLocation is the location of the cluster
  8076. If not specified, it fetches information from the metadata server
  8077. type: string
  8078. clusterName:
  8079. description: |-
  8080. ClusterName is the name of the cluster
  8081. If not specified, it fetches information from the metadata server
  8082. type: string
  8083. clusterProjectID:
  8084. description: |-
  8085. ClusterProjectID is the project ID of the cluster
  8086. If not specified, it fetches information from the metadata server
  8087. type: string
  8088. serviceAccountRef:
  8089. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  8090. properties:
  8091. audiences:
  8092. description: |-
  8093. Audience specifies the `aud` claim for the service account token
  8094. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8095. then this audiences will be appended to the list
  8096. items:
  8097. type: string
  8098. type: array
  8099. name:
  8100. description: The name of the ServiceAccount resource being referred to.
  8101. maxLength: 253
  8102. minLength: 1
  8103. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8104. type: string
  8105. namespace:
  8106. description: |-
  8107. Namespace of the resource being referred to.
  8108. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8109. maxLength: 63
  8110. minLength: 1
  8111. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8112. type: string
  8113. required:
  8114. - name
  8115. type: object
  8116. required:
  8117. - serviceAccountRef
  8118. type: object
  8119. required:
  8120. - role
  8121. type: object
  8122. iam:
  8123. description: |-
  8124. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  8125. AWS IAM authentication method
  8126. properties:
  8127. externalID:
  8128. description: AWS External ID set on assumed IAM roles
  8129. type: string
  8130. jwt:
  8131. description: Specify a service account with IRSA enabled
  8132. properties:
  8133. serviceAccountRef:
  8134. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  8135. properties:
  8136. audiences:
  8137. description: |-
  8138. Audience specifies the `aud` claim for the service account token
  8139. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8140. then this audiences will be appended to the list
  8141. items:
  8142. type: string
  8143. type: array
  8144. name:
  8145. description: The name of the ServiceAccount resource being referred to.
  8146. maxLength: 253
  8147. minLength: 1
  8148. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8149. type: string
  8150. namespace:
  8151. description: |-
  8152. Namespace of the resource being referred to.
  8153. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8154. maxLength: 63
  8155. minLength: 1
  8156. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8157. type: string
  8158. required:
  8159. - name
  8160. type: object
  8161. type: object
  8162. path:
  8163. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  8164. type: string
  8165. region:
  8166. description: AWS region
  8167. type: string
  8168. role:
  8169. description: This is the AWS role to be assumed before talking to vault
  8170. type: string
  8171. secretRef:
  8172. description: Specify credentials in a Secret object
  8173. properties:
  8174. accessKeyIDSecretRef:
  8175. description: The AccessKeyID is used for authentication
  8176. properties:
  8177. key:
  8178. description: |-
  8179. A key in the referenced Secret.
  8180. Some instances of this field may be defaulted, in others it may be required.
  8181. maxLength: 253
  8182. minLength: 1
  8183. pattern: ^[-._a-zA-Z0-9]+$
  8184. type: string
  8185. name:
  8186. description: The name of the Secret resource being referred to.
  8187. maxLength: 253
  8188. minLength: 1
  8189. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8190. type: string
  8191. namespace:
  8192. description: |-
  8193. The namespace of the Secret resource being referred to.
  8194. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8195. maxLength: 63
  8196. minLength: 1
  8197. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8198. type: string
  8199. type: object
  8200. secretAccessKeySecretRef:
  8201. description: The SecretAccessKey is used for authentication
  8202. properties:
  8203. key:
  8204. description: |-
  8205. A key in the referenced Secret.
  8206. Some instances of this field may be defaulted, in others it may be required.
  8207. maxLength: 253
  8208. minLength: 1
  8209. pattern: ^[-._a-zA-Z0-9]+$
  8210. type: string
  8211. name:
  8212. description: The name of the Secret resource being referred to.
  8213. maxLength: 253
  8214. minLength: 1
  8215. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8216. type: string
  8217. namespace:
  8218. description: |-
  8219. The namespace of the Secret resource being referred to.
  8220. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8221. maxLength: 63
  8222. minLength: 1
  8223. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8224. type: string
  8225. type: object
  8226. sessionTokenSecretRef:
  8227. description: |-
  8228. The SessionToken used for authentication
  8229. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  8230. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  8231. properties:
  8232. key:
  8233. description: |-
  8234. A key in the referenced Secret.
  8235. Some instances of this field may be defaulted, in others it may be required.
  8236. maxLength: 253
  8237. minLength: 1
  8238. pattern: ^[-._a-zA-Z0-9]+$
  8239. type: string
  8240. name:
  8241. description: The name of the Secret resource being referred to.
  8242. maxLength: 253
  8243. minLength: 1
  8244. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8245. type: string
  8246. namespace:
  8247. description: |-
  8248. The namespace of the Secret resource being referred to.
  8249. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8250. maxLength: 63
  8251. minLength: 1
  8252. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8253. type: string
  8254. type: object
  8255. type: object
  8256. vaultAwsIamServerID:
  8257. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  8258. type: string
  8259. vaultRole:
  8260. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  8261. type: string
  8262. required:
  8263. - vaultRole
  8264. type: object
  8265. jwt:
  8266. description: |-
  8267. Jwt authenticates with Vault by passing role and JWT token using the
  8268. JWT/OIDC authentication method
  8269. properties:
  8270. kubernetesServiceAccountToken:
  8271. description: |-
  8272. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  8273. a token for with the `TokenRequest` API.
  8274. properties:
  8275. audiences:
  8276. description: |-
  8277. Optional audiences field that will be used to request a temporary Kubernetes service
  8278. account token for the service account referenced by `serviceAccountRef`.
  8279. Defaults to a single audience `vault` it not specified.
  8280. Deprecated: use serviceAccountRef.Audiences instead
  8281. items:
  8282. type: string
  8283. type: array
  8284. expirationSeconds:
  8285. description: |-
  8286. Optional expiration time in seconds that will be used to request a temporary
  8287. Kubernetes service account token for the service account referenced by
  8288. `serviceAccountRef`.
  8289. Deprecated: this will be removed in the future.
  8290. Defaults to 10 minutes.
  8291. format: int64
  8292. type: integer
  8293. serviceAccountRef:
  8294. description: Service account field containing the name of a kubernetes ServiceAccount.
  8295. properties:
  8296. audiences:
  8297. description: |-
  8298. Audience specifies the `aud` claim for the service account token
  8299. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8300. then this audiences will be appended to the list
  8301. items:
  8302. type: string
  8303. type: array
  8304. name:
  8305. description: The name of the ServiceAccount resource being referred to.
  8306. maxLength: 253
  8307. minLength: 1
  8308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8309. type: string
  8310. namespace:
  8311. description: |-
  8312. Namespace of the resource being referred to.
  8313. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8314. maxLength: 63
  8315. minLength: 1
  8316. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8317. type: string
  8318. required:
  8319. - name
  8320. type: object
  8321. required:
  8322. - serviceAccountRef
  8323. type: object
  8324. path:
  8325. default: jwt
  8326. description: |-
  8327. Path where the JWT authentication backend is mounted
  8328. in Vault, e.g: "jwt"
  8329. type: string
  8330. role:
  8331. description: |-
  8332. Role is a JWT role to authenticate using the JWT/OIDC Vault
  8333. authentication method
  8334. type: string
  8335. secretRef:
  8336. description: |-
  8337. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  8338. authenticate with Vault using the JWT/OIDC authentication method.
  8339. properties:
  8340. key:
  8341. description: |-
  8342. A key in the referenced Secret.
  8343. Some instances of this field may be defaulted, in others it may be required.
  8344. maxLength: 253
  8345. minLength: 1
  8346. pattern: ^[-._a-zA-Z0-9]+$
  8347. type: string
  8348. name:
  8349. description: The name of the Secret resource being referred to.
  8350. maxLength: 253
  8351. minLength: 1
  8352. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8353. type: string
  8354. namespace:
  8355. description: |-
  8356. The namespace of the Secret resource being referred to.
  8357. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8358. maxLength: 63
  8359. minLength: 1
  8360. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8361. type: string
  8362. type: object
  8363. required:
  8364. - path
  8365. type: object
  8366. kubernetes:
  8367. description: |-
  8368. Kubernetes authenticates with Vault by passing the ServiceAccount
  8369. token stored in the named Secret resource to the Vault server.
  8370. properties:
  8371. mountPath:
  8372. default: kubernetes
  8373. description: |-
  8374. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  8375. "kubernetes"
  8376. type: string
  8377. role:
  8378. description: |-
  8379. A required field containing the Vault Role to assume. A Role binds a
  8380. Kubernetes ServiceAccount with a set of Vault policies.
  8381. type: string
  8382. secretRef:
  8383. description: |-
  8384. Optional secret field containing a Kubernetes ServiceAccount JWT used
  8385. for authenticating with Vault. If a name is specified without a key,
  8386. `token` is the default. If one is not specified, the one bound to
  8387. the controller will be used.
  8388. properties:
  8389. key:
  8390. description: |-
  8391. A key in the referenced Secret.
  8392. Some instances of this field may be defaulted, in others it may be required.
  8393. maxLength: 253
  8394. minLength: 1
  8395. pattern: ^[-._a-zA-Z0-9]+$
  8396. type: string
  8397. name:
  8398. description: The name of the Secret resource being referred to.
  8399. maxLength: 253
  8400. minLength: 1
  8401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8402. type: string
  8403. namespace:
  8404. description: |-
  8405. The namespace of the Secret resource being referred to.
  8406. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8407. maxLength: 63
  8408. minLength: 1
  8409. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8410. type: string
  8411. type: object
  8412. serviceAccountRef:
  8413. description: |-
  8414. Optional service account field containing the name of a kubernetes ServiceAccount.
  8415. If the service account is specified, the service account secret token JWT will be used
  8416. for authenticating with Vault. If the service account selector is not supplied,
  8417. the secretRef will be used instead.
  8418. properties:
  8419. audiences:
  8420. description: |-
  8421. Audience specifies the `aud` claim for the service account token
  8422. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8423. then this audiences will be appended to the list
  8424. items:
  8425. type: string
  8426. type: array
  8427. name:
  8428. description: The name of the ServiceAccount resource being referred to.
  8429. maxLength: 253
  8430. minLength: 1
  8431. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8432. type: string
  8433. namespace:
  8434. description: |-
  8435. Namespace of the resource being referred to.
  8436. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8437. maxLength: 63
  8438. minLength: 1
  8439. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8440. type: string
  8441. required:
  8442. - name
  8443. type: object
  8444. required:
  8445. - mountPath
  8446. - role
  8447. type: object
  8448. ldap:
  8449. description: |-
  8450. Ldap authenticates with Vault by passing username/password pair using
  8451. the LDAP authentication method
  8452. properties:
  8453. path:
  8454. default: ldap
  8455. description: |-
  8456. Path where the LDAP authentication backend is mounted
  8457. in Vault, e.g: "ldap"
  8458. type: string
  8459. secretRef:
  8460. description: |-
  8461. SecretRef to a key in a Secret resource containing password for the LDAP
  8462. user used to authenticate with Vault using the LDAP authentication
  8463. method
  8464. properties:
  8465. key:
  8466. description: |-
  8467. A key in the referenced Secret.
  8468. Some instances of this field may be defaulted, in others it may be required.
  8469. maxLength: 253
  8470. minLength: 1
  8471. pattern: ^[-._a-zA-Z0-9]+$
  8472. type: string
  8473. name:
  8474. description: The name of the Secret resource being referred to.
  8475. maxLength: 253
  8476. minLength: 1
  8477. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8478. type: string
  8479. namespace:
  8480. description: |-
  8481. The namespace of the Secret resource being referred to.
  8482. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8483. maxLength: 63
  8484. minLength: 1
  8485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8486. type: string
  8487. type: object
  8488. username:
  8489. description: |-
  8490. Username is an LDAP username used to authenticate using the LDAP Vault
  8491. authentication method
  8492. type: string
  8493. required:
  8494. - path
  8495. - username
  8496. type: object
  8497. namespace:
  8498. description: |-
  8499. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  8500. Namespaces is a set of features within Vault Enterprise that allows
  8501. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8502. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8503. This will default to Vault.Namespace field if set, or empty otherwise
  8504. type: string
  8505. tokenSecretRef:
  8506. description: TokenSecretRef authenticates with Vault by presenting a token.
  8507. properties:
  8508. key:
  8509. description: |-
  8510. A key in the referenced Secret.
  8511. Some instances of this field may be defaulted, in others it may be required.
  8512. maxLength: 253
  8513. minLength: 1
  8514. pattern: ^[-._a-zA-Z0-9]+$
  8515. type: string
  8516. name:
  8517. description: The name of the Secret resource being referred to.
  8518. maxLength: 253
  8519. minLength: 1
  8520. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8521. type: string
  8522. namespace:
  8523. description: |-
  8524. The namespace of the Secret resource being referred to.
  8525. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8526. maxLength: 63
  8527. minLength: 1
  8528. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8529. type: string
  8530. type: object
  8531. userPass:
  8532. description: UserPass authenticates with Vault by passing username/password pair
  8533. properties:
  8534. path:
  8535. default: userpass
  8536. description: |-
  8537. Path where the UserPassword authentication backend is mounted
  8538. in Vault, e.g: "userpass"
  8539. type: string
  8540. secretRef:
  8541. description: |-
  8542. SecretRef to a key in a Secret resource containing password for the
  8543. user used to authenticate with Vault using the UserPass authentication
  8544. method
  8545. properties:
  8546. key:
  8547. description: |-
  8548. A key in the referenced Secret.
  8549. Some instances of this field may be defaulted, in others it may be required.
  8550. maxLength: 253
  8551. minLength: 1
  8552. pattern: ^[-._a-zA-Z0-9]+$
  8553. type: string
  8554. name:
  8555. description: The name of the Secret resource being referred to.
  8556. maxLength: 253
  8557. minLength: 1
  8558. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8559. type: string
  8560. namespace:
  8561. description: |-
  8562. The namespace of the Secret resource being referred to.
  8563. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8564. maxLength: 63
  8565. minLength: 1
  8566. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8567. type: string
  8568. type: object
  8569. username:
  8570. description: |-
  8571. Username is a username used to authenticate using the UserPass Vault
  8572. authentication method
  8573. type: string
  8574. required:
  8575. - path
  8576. - username
  8577. type: object
  8578. type: object
  8579. caBundle:
  8580. description: |-
  8581. PEM encoded CA bundle used to validate Vault server certificate. Only used
  8582. if the Server URL is using HTTPS protocol. This parameter is ignored for
  8583. plain HTTP protocol connection. If not set the system root certificates
  8584. are used to validate the TLS connection.
  8585. format: byte
  8586. type: string
  8587. caProvider:
  8588. description: The provider for the CA bundle to use to validate Vault server certificate.
  8589. properties:
  8590. key:
  8591. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8592. maxLength: 253
  8593. minLength: 1
  8594. pattern: ^[-._a-zA-Z0-9]+$
  8595. type: string
  8596. name:
  8597. description: The name of the object located at the provider type.
  8598. maxLength: 253
  8599. minLength: 1
  8600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8601. type: string
  8602. namespace:
  8603. description: |-
  8604. The namespace the Provider type is in.
  8605. Can only be defined when used in a ClusterSecretStore.
  8606. maxLength: 63
  8607. minLength: 1
  8608. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8609. type: string
  8610. type:
  8611. description: The type of provider to use such as "Secret", or "ConfigMap".
  8612. enum:
  8613. - Secret
  8614. - ConfigMap
  8615. type: string
  8616. required:
  8617. - name
  8618. - type
  8619. type: object
  8620. checkAndSet:
  8621. description: |-
  8622. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  8623. Only applies to Vault KV v2 stores. When enabled, write operations must include
  8624. the current version of the secret to prevent unintentional overwrites.
  8625. properties:
  8626. required:
  8627. description: |-
  8628. Required when true, all write operations must include a check-and-set parameter.
  8629. This helps prevent unintentional overwrites of secrets.
  8630. type: boolean
  8631. type: object
  8632. forwardInconsistent:
  8633. description: |-
  8634. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  8635. leader instead of simply retrying within a loop. This can increase performance if
  8636. the option is enabled serverside.
  8637. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  8638. type: boolean
  8639. headers:
  8640. additionalProperties:
  8641. type: string
  8642. description: Headers to be added in Vault request
  8643. type: object
  8644. namespace:
  8645. description: |-
  8646. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  8647. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8648. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8649. type: string
  8650. path:
  8651. description: |-
  8652. Path is the mount path of the Vault KV backend endpoint, e.g:
  8653. "secret". The v2 KV secret engine version specific "/data" path suffix
  8654. for fetching secrets from Vault is optional and will be appended
  8655. if not present in specified path.
  8656. type: string
  8657. readYourWrites:
  8658. description: |-
  8659. ReadYourWrites ensures isolated read-after-write semantics by
  8660. providing discovered cluster replication states in each request.
  8661. More information about eventual consistency in Vault can be found here
  8662. https://www.vaultproject.io/docs/enterprise/consistency
  8663. type: boolean
  8664. server:
  8665. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  8666. type: string
  8667. tls:
  8668. description: |-
  8669. The configuration used for client side related TLS communication, when the Vault server
  8670. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  8671. This parameter is ignored for plain HTTP protocol connection.
  8672. It's worth noting this configuration is different from the "TLS certificates auth method",
  8673. which is available under the `auth.cert` section.
  8674. properties:
  8675. certSecretRef:
  8676. description: |-
  8677. CertSecretRef is a certificate added to the transport layer
  8678. when communicating with the Vault server.
  8679. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  8680. properties:
  8681. key:
  8682. description: |-
  8683. A key in the referenced Secret.
  8684. Some instances of this field may be defaulted, in others it may be required.
  8685. maxLength: 253
  8686. minLength: 1
  8687. pattern: ^[-._a-zA-Z0-9]+$
  8688. type: string
  8689. name:
  8690. description: The name of the Secret resource being referred to.
  8691. maxLength: 253
  8692. minLength: 1
  8693. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8694. type: string
  8695. namespace:
  8696. description: |-
  8697. The namespace of the Secret resource being referred to.
  8698. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8699. maxLength: 63
  8700. minLength: 1
  8701. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8702. type: string
  8703. type: object
  8704. keySecretRef:
  8705. description: |-
  8706. KeySecretRef to a key in a Secret resource containing client private key
  8707. added to the transport layer when communicating with the Vault server.
  8708. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  8709. properties:
  8710. key:
  8711. description: |-
  8712. A key in the referenced Secret.
  8713. Some instances of this field may be defaulted, in others it may be required.
  8714. maxLength: 253
  8715. minLength: 1
  8716. pattern: ^[-._a-zA-Z0-9]+$
  8717. type: string
  8718. name:
  8719. description: The name of the Secret resource being referred to.
  8720. maxLength: 253
  8721. minLength: 1
  8722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8723. type: string
  8724. namespace:
  8725. description: |-
  8726. The namespace of the Secret resource being referred to.
  8727. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8728. maxLength: 63
  8729. minLength: 1
  8730. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8731. type: string
  8732. type: object
  8733. type: object
  8734. version:
  8735. default: v2
  8736. description: |-
  8737. Version is the Vault KV secret engine version. This can be either "v1" or
  8738. "v2". Version defaults to "v2".
  8739. enum:
  8740. - v1
  8741. - v2
  8742. type: string
  8743. required:
  8744. - server
  8745. type: object
  8746. volcengine:
  8747. description: Volcengine configures this store to sync secrets using the Volcengine provider
  8748. properties:
  8749. auth:
  8750. description: |-
  8751. Auth defines the authentication method to use.
  8752. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  8753. properties:
  8754. secretRef:
  8755. description: |-
  8756. SecretRef defines the static credentials to use for authentication.
  8757. If not set, IRSA is used.
  8758. properties:
  8759. accessKeyID:
  8760. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  8761. properties:
  8762. key:
  8763. description: |-
  8764. A key in the referenced Secret.
  8765. Some instances of this field may be defaulted, in others it may be required.
  8766. maxLength: 253
  8767. minLength: 1
  8768. pattern: ^[-._a-zA-Z0-9]+$
  8769. type: string
  8770. name:
  8771. description: The name of the Secret resource being referred to.
  8772. maxLength: 253
  8773. minLength: 1
  8774. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8775. type: string
  8776. namespace:
  8777. description: |-
  8778. The namespace of the Secret resource being referred to.
  8779. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8780. maxLength: 63
  8781. minLength: 1
  8782. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8783. type: string
  8784. type: object
  8785. secretAccessKey:
  8786. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  8787. properties:
  8788. key:
  8789. description: |-
  8790. A key in the referenced Secret.
  8791. Some instances of this field may be defaulted, in others it may be required.
  8792. maxLength: 253
  8793. minLength: 1
  8794. pattern: ^[-._a-zA-Z0-9]+$
  8795. type: string
  8796. name:
  8797. description: The name of the Secret resource being referred to.
  8798. maxLength: 253
  8799. minLength: 1
  8800. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8801. type: string
  8802. namespace:
  8803. description: |-
  8804. The namespace of the Secret resource being referred to.
  8805. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8806. maxLength: 63
  8807. minLength: 1
  8808. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8809. type: string
  8810. type: object
  8811. token:
  8812. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  8813. properties:
  8814. key:
  8815. description: |-
  8816. A key in the referenced Secret.
  8817. Some instances of this field may be defaulted, in others it may be required.
  8818. maxLength: 253
  8819. minLength: 1
  8820. pattern: ^[-._a-zA-Z0-9]+$
  8821. type: string
  8822. name:
  8823. description: The name of the Secret resource being referred to.
  8824. maxLength: 253
  8825. minLength: 1
  8826. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8827. type: string
  8828. namespace:
  8829. description: |-
  8830. The namespace of the Secret resource being referred to.
  8831. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8832. maxLength: 63
  8833. minLength: 1
  8834. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8835. type: string
  8836. type: object
  8837. required:
  8838. - accessKeyID
  8839. - secretAccessKey
  8840. type: object
  8841. type: object
  8842. region:
  8843. description: Region specifies the Volcengine region to connect to.
  8844. type: string
  8845. required:
  8846. - region
  8847. type: object
  8848. webhook:
  8849. description: Webhook configures this store to sync secrets using a generic templated webhook
  8850. properties:
  8851. auth:
  8852. description: Auth specifies a authorization protocol. Only one protocol may be set.
  8853. maxProperties: 1
  8854. minProperties: 1
  8855. properties:
  8856. ntlm:
  8857. description: NTLMProtocol configures the store to use NTLM for auth
  8858. properties:
  8859. passwordSecret:
  8860. description: |-
  8861. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8862. In some instances, `key` is a required field.
  8863. properties:
  8864. key:
  8865. description: |-
  8866. A key in the referenced Secret.
  8867. Some instances of this field may be defaulted, in others it may be required.
  8868. maxLength: 253
  8869. minLength: 1
  8870. pattern: ^[-._a-zA-Z0-9]+$
  8871. type: string
  8872. name:
  8873. description: The name of the Secret resource being referred to.
  8874. maxLength: 253
  8875. minLength: 1
  8876. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8877. type: string
  8878. namespace:
  8879. description: |-
  8880. The namespace of the Secret resource being referred to.
  8881. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8882. maxLength: 63
  8883. minLength: 1
  8884. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8885. type: string
  8886. type: object
  8887. usernameSecret:
  8888. description: |-
  8889. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8890. In some instances, `key` is a required field.
  8891. properties:
  8892. key:
  8893. description: |-
  8894. A key in the referenced Secret.
  8895. Some instances of this field may be defaulted, in others it may be required.
  8896. maxLength: 253
  8897. minLength: 1
  8898. pattern: ^[-._a-zA-Z0-9]+$
  8899. type: string
  8900. name:
  8901. description: The name of the Secret resource being referred to.
  8902. maxLength: 253
  8903. minLength: 1
  8904. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8905. type: string
  8906. namespace:
  8907. description: |-
  8908. The namespace of the Secret resource being referred to.
  8909. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8910. maxLength: 63
  8911. minLength: 1
  8912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8913. type: string
  8914. type: object
  8915. required:
  8916. - passwordSecret
  8917. - usernameSecret
  8918. type: object
  8919. type: object
  8920. body:
  8921. description: Body
  8922. type: string
  8923. caBundle:
  8924. description: |-
  8925. PEM encoded CA bundle used to validate webhook server certificate. Only used
  8926. if the Server URL is using HTTPS protocol. This parameter is ignored for
  8927. plain HTTP protocol connection. If not set the system root certificates
  8928. are used to validate the TLS connection.
  8929. format: byte
  8930. type: string
  8931. caProvider:
  8932. description: The provider for the CA bundle to use to validate webhook server certificate.
  8933. properties:
  8934. key:
  8935. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8936. maxLength: 253
  8937. minLength: 1
  8938. pattern: ^[-._a-zA-Z0-9]+$
  8939. type: string
  8940. name:
  8941. description: The name of the object located at the provider type.
  8942. maxLength: 253
  8943. minLength: 1
  8944. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8945. type: string
  8946. namespace:
  8947. description: The namespace the Provider type is in.
  8948. maxLength: 63
  8949. minLength: 1
  8950. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8951. type: string
  8952. type:
  8953. description: The type of provider to use such as "Secret", or "ConfigMap".
  8954. enum:
  8955. - Secret
  8956. - ConfigMap
  8957. type: string
  8958. required:
  8959. - name
  8960. - type
  8961. type: object
  8962. headers:
  8963. additionalProperties:
  8964. type: string
  8965. description: Headers
  8966. type: object
  8967. method:
  8968. description: Webhook Method
  8969. type: string
  8970. result:
  8971. description: Result formatting
  8972. properties:
  8973. jsonPath:
  8974. description: Json path of return value
  8975. type: string
  8976. type: object
  8977. secrets:
  8978. description: |-
  8979. Secrets to fill in templates
  8980. These secrets will be passed to the templating function as key value pairs under the given name
  8981. items:
  8982. description: WebhookSecret defines a secret that will be passed to the webhook request.
  8983. properties:
  8984. name:
  8985. description: Name of this secret in templates
  8986. type: string
  8987. secretRef:
  8988. description: Secret ref to fill in credentials
  8989. properties:
  8990. key:
  8991. description: |-
  8992. A key in the referenced Secret.
  8993. Some instances of this field may be defaulted, in others it may be required.
  8994. maxLength: 253
  8995. minLength: 1
  8996. pattern: ^[-._a-zA-Z0-9]+$
  8997. type: string
  8998. name:
  8999. description: The name of the Secret resource being referred to.
  9000. maxLength: 253
  9001. minLength: 1
  9002. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9003. type: string
  9004. namespace:
  9005. description: |-
  9006. The namespace of the Secret resource being referred to.
  9007. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9008. maxLength: 63
  9009. minLength: 1
  9010. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9011. type: string
  9012. type: object
  9013. required:
  9014. - name
  9015. - secretRef
  9016. type: object
  9017. type: array
  9018. timeout:
  9019. description: Timeout
  9020. type: string
  9021. url:
  9022. description: Webhook url to call
  9023. type: string
  9024. required:
  9025. - url
  9026. type: object
  9027. yandexcertificatemanager:
  9028. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  9029. properties:
  9030. apiEndpoint:
  9031. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9032. type: string
  9033. auth:
  9034. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  9035. properties:
  9036. authorizedKeySecretRef:
  9037. description: The authorized key used for authentication
  9038. properties:
  9039. key:
  9040. description: |-
  9041. A key in the referenced Secret.
  9042. Some instances of this field may be defaulted, in others it may be required.
  9043. maxLength: 253
  9044. minLength: 1
  9045. pattern: ^[-._a-zA-Z0-9]+$
  9046. type: string
  9047. name:
  9048. description: The name of the Secret resource being referred to.
  9049. maxLength: 253
  9050. minLength: 1
  9051. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9052. type: string
  9053. namespace:
  9054. description: |-
  9055. The namespace of the Secret resource being referred to.
  9056. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9057. maxLength: 63
  9058. minLength: 1
  9059. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9060. type: string
  9061. type: object
  9062. type: object
  9063. caProvider:
  9064. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9065. properties:
  9066. certSecretRef:
  9067. description: |-
  9068. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9069. In some instances, `key` is a required field.
  9070. properties:
  9071. key:
  9072. description: |-
  9073. A key in the referenced Secret.
  9074. Some instances of this field may be defaulted, in others it may be required.
  9075. maxLength: 253
  9076. minLength: 1
  9077. pattern: ^[-._a-zA-Z0-9]+$
  9078. type: string
  9079. name:
  9080. description: The name of the Secret resource being referred to.
  9081. maxLength: 253
  9082. minLength: 1
  9083. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9084. type: string
  9085. namespace:
  9086. description: |-
  9087. The namespace of the Secret resource being referred to.
  9088. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9089. maxLength: 63
  9090. minLength: 1
  9091. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9092. type: string
  9093. type: object
  9094. type: object
  9095. fetching:
  9096. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  9097. maxProperties: 1
  9098. minProperties: 1
  9099. properties:
  9100. byID:
  9101. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  9102. type: object
  9103. byName:
  9104. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  9105. properties:
  9106. folderID:
  9107. description: The folder to fetch secrets from
  9108. type: string
  9109. required:
  9110. - folderID
  9111. type: object
  9112. type: object
  9113. required:
  9114. - auth
  9115. type: object
  9116. yandexlockbox:
  9117. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  9118. properties:
  9119. apiEndpoint:
  9120. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9121. type: string
  9122. auth:
  9123. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  9124. properties:
  9125. authorizedKeySecretRef:
  9126. description: The authorized key used for authentication
  9127. properties:
  9128. key:
  9129. description: |-
  9130. A key in the referenced Secret.
  9131. Some instances of this field may be defaulted, in others it may be required.
  9132. maxLength: 253
  9133. minLength: 1
  9134. pattern: ^[-._a-zA-Z0-9]+$
  9135. type: string
  9136. name:
  9137. description: The name of the Secret resource being referred to.
  9138. maxLength: 253
  9139. minLength: 1
  9140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9141. type: string
  9142. namespace:
  9143. description: |-
  9144. The namespace of the Secret resource being referred to.
  9145. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9146. maxLength: 63
  9147. minLength: 1
  9148. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9149. type: string
  9150. type: object
  9151. type: object
  9152. caProvider:
  9153. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9154. properties:
  9155. certSecretRef:
  9156. description: |-
  9157. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9158. In some instances, `key` is a required field.
  9159. properties:
  9160. key:
  9161. description: |-
  9162. A key in the referenced Secret.
  9163. Some instances of this field may be defaulted, in others it may be required.
  9164. maxLength: 253
  9165. minLength: 1
  9166. pattern: ^[-._a-zA-Z0-9]+$
  9167. type: string
  9168. name:
  9169. description: The name of the Secret resource being referred to.
  9170. maxLength: 253
  9171. minLength: 1
  9172. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9173. type: string
  9174. namespace:
  9175. description: |-
  9176. The namespace of the Secret resource being referred to.
  9177. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9178. maxLength: 63
  9179. minLength: 1
  9180. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9181. type: string
  9182. type: object
  9183. type: object
  9184. fetching:
  9185. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  9186. maxProperties: 1
  9187. minProperties: 1
  9188. properties:
  9189. byID:
  9190. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  9191. type: object
  9192. byName:
  9193. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  9194. properties:
  9195. folderID:
  9196. description: The folder to fetch secrets from
  9197. type: string
  9198. required:
  9199. - folderID
  9200. type: object
  9201. type: object
  9202. required:
  9203. - auth
  9204. type: object
  9205. type: object
  9206. refreshInterval:
  9207. anyOf:
  9208. - type: integer
  9209. - type: string
  9210. description: |-
  9211. Used to configure store refresh interval. Accepts either an integer number
  9212. of seconds (legacy) or a Go duration string such as "1h" or "5m". Empty or
  9213. 0 will default to the controller config.
  9214. x-kubernetes-int-or-string: true
  9215. retrySettings:
  9216. description: Used to configure HTTP retries on failures.
  9217. properties:
  9218. maxRetries:
  9219. format: int32
  9220. type: integer
  9221. retryInterval:
  9222. type: string
  9223. type: object
  9224. required:
  9225. - provider
  9226. type: object
  9227. status:
  9228. description: SecretStoreStatus defines the observed state of the SecretStore.
  9229. properties:
  9230. capabilities:
  9231. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  9232. type: string
  9233. conditions:
  9234. items:
  9235. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  9236. properties:
  9237. lastTransitionTime:
  9238. format: date-time
  9239. type: string
  9240. message:
  9241. type: string
  9242. reason:
  9243. type: string
  9244. status:
  9245. type: string
  9246. type:
  9247. description: SecretStoreConditionType represents the condition of the SecretStore.
  9248. type: string
  9249. required:
  9250. - status
  9251. - type
  9252. type: object
  9253. type: array
  9254. type: object
  9255. type: object
  9256. served: true
  9257. storage: true
  9258. subresources:
  9259. status: {}
  9260. - additionalPrinterColumns:
  9261. - jsonPath: .metadata.creationTimestamp
  9262. name: AGE
  9263. type: date
  9264. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  9265. name: Status
  9266. type: string
  9267. - jsonPath: .status.capabilities
  9268. name: Capabilities
  9269. type: string
  9270. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  9271. name: Ready
  9272. type: string
  9273. deprecated: true
  9274. name: v1beta1
  9275. schema:
  9276. openAPIV3Schema:
  9277. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  9278. properties:
  9279. apiVersion:
  9280. description: |-
  9281. APIVersion defines the versioned schema of this representation of an object.
  9282. Servers should convert recognized schemas to the latest internal value, and
  9283. may reject unrecognized values.
  9284. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  9285. type: string
  9286. kind:
  9287. description: |-
  9288. Kind is a string value representing the REST resource this object represents.
  9289. Servers may infer this from the endpoint the client submits requests to.
  9290. Cannot be updated.
  9291. In CamelCase.
  9292. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  9293. type: string
  9294. metadata:
  9295. type: object
  9296. spec:
  9297. description: SecretStoreSpec defines the desired state of SecretStore.
  9298. properties:
  9299. conditions:
  9300. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  9301. items:
  9302. description: |-
  9303. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  9304. for a ClusterSecretStore instance.
  9305. properties:
  9306. namespaceRegexes:
  9307. description: Choose namespaces by using regex matching
  9308. items:
  9309. type: string
  9310. type: array
  9311. namespaceSelector:
  9312. description: Choose namespace using a labelSelector
  9313. properties:
  9314. matchExpressions:
  9315. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  9316. items:
  9317. description: |-
  9318. A label selector requirement is a selector that contains values, a key, and an operator that
  9319. relates the key and values.
  9320. properties:
  9321. key:
  9322. description: key is the label key that the selector applies to.
  9323. type: string
  9324. operator:
  9325. description: |-
  9326. operator represents a key's relationship to a set of values.
  9327. Valid operators are In, NotIn, Exists and DoesNotExist.
  9328. type: string
  9329. values:
  9330. description: |-
  9331. values is an array of string values. If the operator is In or NotIn,
  9332. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  9333. the values array must be empty. This array is replaced during a strategic
  9334. merge patch.
  9335. items:
  9336. type: string
  9337. type: array
  9338. x-kubernetes-list-type: atomic
  9339. required:
  9340. - key
  9341. - operator
  9342. type: object
  9343. type: array
  9344. x-kubernetes-list-type: atomic
  9345. matchLabels:
  9346. additionalProperties:
  9347. type: string
  9348. description: |-
  9349. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  9350. map is equivalent to an element of matchExpressions, whose key field is "key", the
  9351. operator is "In", and the values array contains only "value". The requirements are ANDed.
  9352. type: object
  9353. type: object
  9354. x-kubernetes-map-type: atomic
  9355. namespaces:
  9356. description: Choose namespaces by name
  9357. items:
  9358. maxLength: 63
  9359. minLength: 1
  9360. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9361. type: string
  9362. type: array
  9363. type: object
  9364. type: array
  9365. controller:
  9366. description: |-
  9367. Used to select the correct ESO controller (think: ingress.ingressClassName)
  9368. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  9369. type: string
  9370. provider:
  9371. description: Used to configure the provider. Only one provider may be set
  9372. maxProperties: 1
  9373. minProperties: 1
  9374. properties:
  9375. akeyless:
  9376. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  9377. properties:
  9378. akeylessGWApiURL:
  9379. description: Akeyless GW API Url from which the secrets to be fetched from.
  9380. type: string
  9381. authSecretRef:
  9382. description: Auth configures how the operator authenticates with Akeyless.
  9383. properties:
  9384. kubernetesAuth:
  9385. description: |-
  9386. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  9387. token stored in the named Secret resource.
  9388. properties:
  9389. accessID:
  9390. description: the Akeyless Kubernetes auth-method access-id
  9391. type: string
  9392. k8sConfName:
  9393. description: Kubernetes-auth configuration name in Akeyless-Gateway
  9394. type: string
  9395. secretRef:
  9396. description: |-
  9397. Optional secret field containing a Kubernetes ServiceAccount JWT used
  9398. for authenticating with Akeyless. If a name is specified without a key,
  9399. `token` is the default. If one is not specified, the one bound to
  9400. the controller will be used.
  9401. properties:
  9402. key:
  9403. description: |-
  9404. A key in the referenced Secret.
  9405. Some instances of this field may be defaulted, in others it may be required.
  9406. maxLength: 253
  9407. minLength: 1
  9408. pattern: ^[-._a-zA-Z0-9]+$
  9409. type: string
  9410. name:
  9411. description: The name of the Secret resource being referred to.
  9412. maxLength: 253
  9413. minLength: 1
  9414. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9415. type: string
  9416. namespace:
  9417. description: |-
  9418. The namespace of the Secret resource being referred to.
  9419. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9420. maxLength: 63
  9421. minLength: 1
  9422. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9423. type: string
  9424. type: object
  9425. serviceAccountRef:
  9426. description: |-
  9427. Optional service account field containing the name of a kubernetes ServiceAccount.
  9428. If the service account is specified, the service account secret token JWT will be used
  9429. for authenticating with Akeyless. If the service account selector is not supplied,
  9430. the secretRef will be used instead.
  9431. properties:
  9432. audiences:
  9433. description: |-
  9434. Audience specifies the `aud` claim for the service account token
  9435. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  9436. then this audiences will be appended to the list
  9437. items:
  9438. type: string
  9439. type: array
  9440. name:
  9441. description: The name of the ServiceAccount resource being referred to.
  9442. maxLength: 253
  9443. minLength: 1
  9444. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9445. type: string
  9446. namespace:
  9447. description: |-
  9448. Namespace of the resource being referred to.
  9449. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9450. maxLength: 63
  9451. minLength: 1
  9452. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9453. type: string
  9454. required:
  9455. - name
  9456. type: object
  9457. required:
  9458. - accessID
  9459. - k8sConfName
  9460. type: object
  9461. secretRef:
  9462. description: |-
  9463. Reference to a Secret that contains the details
  9464. to authenticate with Akeyless.
  9465. properties:
  9466. accessID:
  9467. description: The SecretAccessID is used for authentication
  9468. properties:
  9469. key:
  9470. description: |-
  9471. A key in the referenced Secret.
  9472. Some instances of this field may be defaulted, in others it may be required.
  9473. maxLength: 253
  9474. minLength: 1
  9475. pattern: ^[-._a-zA-Z0-9]+$
  9476. type: string
  9477. name:
  9478. description: The name of the Secret resource being referred to.
  9479. maxLength: 253
  9480. minLength: 1
  9481. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9482. type: string
  9483. namespace:
  9484. description: |-
  9485. The namespace of the Secret resource being referred to.
  9486. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9487. maxLength: 63
  9488. minLength: 1
  9489. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9490. type: string
  9491. type: object
  9492. accessType:
  9493. description: |-
  9494. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9495. In some instances, `key` is a required field.
  9496. properties:
  9497. key:
  9498. description: |-
  9499. A key in the referenced Secret.
  9500. Some instances of this field may be defaulted, in others it may be required.
  9501. maxLength: 253
  9502. minLength: 1
  9503. pattern: ^[-._a-zA-Z0-9]+$
  9504. type: string
  9505. name:
  9506. description: The name of the Secret resource being referred to.
  9507. maxLength: 253
  9508. minLength: 1
  9509. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9510. type: string
  9511. namespace:
  9512. description: |-
  9513. The namespace of the Secret resource being referred to.
  9514. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9515. maxLength: 63
  9516. minLength: 1
  9517. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9518. type: string
  9519. type: object
  9520. accessTypeParam:
  9521. description: |-
  9522. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9523. In some instances, `key` is a required field.
  9524. properties:
  9525. key:
  9526. description: |-
  9527. A key in the referenced Secret.
  9528. Some instances of this field may be defaulted, in others it may be required.
  9529. maxLength: 253
  9530. minLength: 1
  9531. pattern: ^[-._a-zA-Z0-9]+$
  9532. type: string
  9533. name:
  9534. description: The name of the Secret resource being referred to.
  9535. maxLength: 253
  9536. minLength: 1
  9537. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9538. type: string
  9539. namespace:
  9540. description: |-
  9541. The namespace of the Secret resource being referred to.
  9542. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9543. maxLength: 63
  9544. minLength: 1
  9545. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9546. type: string
  9547. type: object
  9548. type: object
  9549. type: object
  9550. caBundle:
  9551. description: |-
  9552. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  9553. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  9554. are used to validate the TLS connection.
  9555. format: byte
  9556. type: string
  9557. caProvider:
  9558. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  9559. properties:
  9560. key:
  9561. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9562. maxLength: 253
  9563. minLength: 1
  9564. pattern: ^[-._a-zA-Z0-9]+$
  9565. type: string
  9566. name:
  9567. description: The name of the object located at the provider type.
  9568. maxLength: 253
  9569. minLength: 1
  9570. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9571. type: string
  9572. namespace:
  9573. description: |-
  9574. The namespace the Provider type is in.
  9575. Can only be defined when used in a ClusterSecretStore.
  9576. maxLength: 63
  9577. minLength: 1
  9578. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9579. type: string
  9580. type:
  9581. description: The type of provider to use such as "Secret", or "ConfigMap".
  9582. enum:
  9583. - Secret
  9584. - ConfigMap
  9585. type: string
  9586. required:
  9587. - name
  9588. - type
  9589. type: object
  9590. required:
  9591. - akeylessGWApiURL
  9592. - authSecretRef
  9593. type: object
  9594. alibaba:
  9595. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  9596. properties:
  9597. auth:
  9598. description: AlibabaAuth contains a secretRef for credentials.
  9599. properties:
  9600. rrsa:
  9601. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  9602. properties:
  9603. oidcProviderArn:
  9604. type: string
  9605. oidcTokenFilePath:
  9606. type: string
  9607. roleArn:
  9608. type: string
  9609. sessionName:
  9610. type: string
  9611. required:
  9612. - oidcProviderArn
  9613. - oidcTokenFilePath
  9614. - roleArn
  9615. - sessionName
  9616. type: object
  9617. secretRef:
  9618. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  9619. properties:
  9620. accessKeyIDSecretRef:
  9621. description: The AccessKeyID is used for authentication
  9622. properties:
  9623. key:
  9624. description: |-
  9625. A key in the referenced Secret.
  9626. Some instances of this field may be defaulted, in others it may be required.
  9627. maxLength: 253
  9628. minLength: 1
  9629. pattern: ^[-._a-zA-Z0-9]+$
  9630. type: string
  9631. name:
  9632. description: The name of the Secret resource being referred to.
  9633. maxLength: 253
  9634. minLength: 1
  9635. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9636. type: string
  9637. namespace:
  9638. description: |-
  9639. The namespace of the Secret resource being referred to.
  9640. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9641. maxLength: 63
  9642. minLength: 1
  9643. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9644. type: string
  9645. type: object
  9646. accessKeySecretSecretRef:
  9647. description: The AccessKeySecret is used for authentication
  9648. properties:
  9649. key:
  9650. description: |-
  9651. A key in the referenced Secret.
  9652. Some instances of this field may be defaulted, in others it may be required.
  9653. maxLength: 253
  9654. minLength: 1
  9655. pattern: ^[-._a-zA-Z0-9]+$
  9656. type: string
  9657. name:
  9658. description: The name of the Secret resource being referred to.
  9659. maxLength: 253
  9660. minLength: 1
  9661. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9662. type: string
  9663. namespace:
  9664. description: |-
  9665. The namespace of the Secret resource being referred to.
  9666. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9667. maxLength: 63
  9668. minLength: 1
  9669. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9670. type: string
  9671. type: object
  9672. required:
  9673. - accessKeyIDSecretRef
  9674. - accessKeySecretSecretRef
  9675. type: object
  9676. type: object
  9677. regionID:
  9678. description: Alibaba Region to be used for the provider
  9679. type: string
  9680. required:
  9681. - auth
  9682. - regionID
  9683. type: object
  9684. aws:
  9685. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  9686. properties:
  9687. additionalRoles:
  9688. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  9689. items:
  9690. type: string
  9691. type: array
  9692. auth:
  9693. description: |-
  9694. Auth defines the information necessary to authenticate against AWS
  9695. if not set aws sdk will infer credentials from your environment
  9696. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  9697. properties:
  9698. jwt:
  9699. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  9700. properties:
  9701. serviceAccountRef:
  9702. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  9703. properties:
  9704. audiences:
  9705. description: |-
  9706. Audience specifies the `aud` claim for the service account token
  9707. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  9708. then this audiences will be appended to the list
  9709. items:
  9710. type: string
  9711. type: array
  9712. name:
  9713. description: The name of the ServiceAccount resource being referred to.
  9714. maxLength: 253
  9715. minLength: 1
  9716. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9717. type: string
  9718. namespace:
  9719. description: |-
  9720. Namespace of the resource being referred to.
  9721. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9722. maxLength: 63
  9723. minLength: 1
  9724. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9725. type: string
  9726. required:
  9727. - name
  9728. type: object
  9729. type: object
  9730. secretRef:
  9731. description: |-
  9732. AWSAuthSecretRef holds secret references for AWS credentials
  9733. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  9734. properties:
  9735. accessKeyIDSecretRef:
  9736. description: The AccessKeyID is used for authentication
  9737. properties:
  9738. key:
  9739. description: |-
  9740. A key in the referenced Secret.
  9741. Some instances of this field may be defaulted, in others it may be required.
  9742. maxLength: 253
  9743. minLength: 1
  9744. pattern: ^[-._a-zA-Z0-9]+$
  9745. type: string
  9746. name:
  9747. description: The name of the Secret resource being referred to.
  9748. maxLength: 253
  9749. minLength: 1
  9750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9751. type: string
  9752. namespace:
  9753. description: |-
  9754. The namespace of the Secret resource being referred to.
  9755. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9756. maxLength: 63
  9757. minLength: 1
  9758. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9759. type: string
  9760. type: object
  9761. secretAccessKeySecretRef:
  9762. description: The SecretAccessKey is used for authentication
  9763. properties:
  9764. key:
  9765. description: |-
  9766. A key in the referenced Secret.
  9767. Some instances of this field may be defaulted, in others it may be required.
  9768. maxLength: 253
  9769. minLength: 1
  9770. pattern: ^[-._a-zA-Z0-9]+$
  9771. type: string
  9772. name:
  9773. description: The name of the Secret resource being referred to.
  9774. maxLength: 253
  9775. minLength: 1
  9776. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9777. type: string
  9778. namespace:
  9779. description: |-
  9780. The namespace of the Secret resource being referred to.
  9781. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9782. maxLength: 63
  9783. minLength: 1
  9784. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9785. type: string
  9786. type: object
  9787. sessionTokenSecretRef:
  9788. description: |-
  9789. The SessionToken used for authentication
  9790. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  9791. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  9792. properties:
  9793. key:
  9794. description: |-
  9795. A key in the referenced Secret.
  9796. Some instances of this field may be defaulted, in others it may be required.
  9797. maxLength: 253
  9798. minLength: 1
  9799. pattern: ^[-._a-zA-Z0-9]+$
  9800. type: string
  9801. name:
  9802. description: The name of the Secret resource being referred to.
  9803. maxLength: 253
  9804. minLength: 1
  9805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9806. type: string
  9807. namespace:
  9808. description: |-
  9809. The namespace of the Secret resource being referred to.
  9810. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9811. maxLength: 63
  9812. minLength: 1
  9813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9814. type: string
  9815. type: object
  9816. type: object
  9817. type: object
  9818. externalID:
  9819. description: AWS External ID set on assumed IAM roles
  9820. type: string
  9821. prefix:
  9822. description: Prefix adds a prefix to all retrieved values.
  9823. type: string
  9824. region:
  9825. description: AWS Region to be used for the provider
  9826. type: string
  9827. role:
  9828. description: Role is a Role ARN which the provider will assume
  9829. type: string
  9830. secretsManager:
  9831. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  9832. properties:
  9833. forceDeleteWithoutRecovery:
  9834. description: |-
  9835. Specifies whether to delete the secret without any recovery window. You
  9836. can't use both this parameter and RecoveryWindowInDays in the same call.
  9837. If you don't use either, then by default Secrets Manager uses a 30 day
  9838. recovery window.
  9839. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  9840. type: boolean
  9841. recoveryWindowInDays:
  9842. description: |-
  9843. The number of days from 7 to 30 that Secrets Manager waits before
  9844. permanently deleting the secret. You can't use both this parameter and
  9845. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  9846. then by default Secrets Manager uses a 30 day recovery window.
  9847. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  9848. format: int64
  9849. type: integer
  9850. type: object
  9851. service:
  9852. description: Service defines which service should be used to fetch the secrets
  9853. enum:
  9854. - SecretsManager
  9855. - ParameterStore
  9856. type: string
  9857. sessionTags:
  9858. description: AWS STS assume role session tags
  9859. items:
  9860. description: Tag defines a tag key and value for AWS resources.
  9861. properties:
  9862. key:
  9863. type: string
  9864. value:
  9865. type: string
  9866. required:
  9867. - key
  9868. - value
  9869. type: object
  9870. type: array
  9871. transitiveTagKeys:
  9872. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  9873. items:
  9874. type: string
  9875. type: array
  9876. required:
  9877. - region
  9878. - service
  9879. type: object
  9880. azurekv:
  9881. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  9882. properties:
  9883. authSecretRef:
  9884. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  9885. properties:
  9886. clientCertificate:
  9887. description: The Azure ClientCertificate of the service principle used for authentication.
  9888. properties:
  9889. key:
  9890. description: |-
  9891. A key in the referenced Secret.
  9892. Some instances of this field may be defaulted, in others it may be required.
  9893. maxLength: 253
  9894. minLength: 1
  9895. pattern: ^[-._a-zA-Z0-9]+$
  9896. type: string
  9897. name:
  9898. description: The name of the Secret resource being referred to.
  9899. maxLength: 253
  9900. minLength: 1
  9901. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9902. type: string
  9903. namespace:
  9904. description: |-
  9905. The namespace of the Secret resource being referred to.
  9906. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9907. maxLength: 63
  9908. minLength: 1
  9909. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9910. type: string
  9911. type: object
  9912. clientId:
  9913. description: The Azure clientId of the service principle or managed identity used for authentication.
  9914. properties:
  9915. key:
  9916. description: |-
  9917. A key in the referenced Secret.
  9918. Some instances of this field may be defaulted, in others it may be required.
  9919. maxLength: 253
  9920. minLength: 1
  9921. pattern: ^[-._a-zA-Z0-9]+$
  9922. type: string
  9923. name:
  9924. description: The name of the Secret resource being referred to.
  9925. maxLength: 253
  9926. minLength: 1
  9927. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9928. type: string
  9929. namespace:
  9930. description: |-
  9931. The namespace of the Secret resource being referred to.
  9932. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9933. maxLength: 63
  9934. minLength: 1
  9935. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9936. type: string
  9937. type: object
  9938. clientSecret:
  9939. description: The Azure ClientSecret of the service principle used for authentication.
  9940. properties:
  9941. key:
  9942. description: |-
  9943. A key in the referenced Secret.
  9944. Some instances of this field may be defaulted, in others it may be required.
  9945. maxLength: 253
  9946. minLength: 1
  9947. pattern: ^[-._a-zA-Z0-9]+$
  9948. type: string
  9949. name:
  9950. description: The name of the Secret resource being referred to.
  9951. maxLength: 253
  9952. minLength: 1
  9953. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9954. type: string
  9955. namespace:
  9956. description: |-
  9957. The namespace of the Secret resource being referred to.
  9958. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9959. maxLength: 63
  9960. minLength: 1
  9961. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9962. type: string
  9963. type: object
  9964. tenantId:
  9965. description: The Azure tenantId of the managed identity used for authentication.
  9966. properties:
  9967. key:
  9968. description: |-
  9969. A key in the referenced Secret.
  9970. Some instances of this field may be defaulted, in others it may be required.
  9971. maxLength: 253
  9972. minLength: 1
  9973. pattern: ^[-._a-zA-Z0-9]+$
  9974. type: string
  9975. name:
  9976. description: The name of the Secret resource being referred to.
  9977. maxLength: 253
  9978. minLength: 1
  9979. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9980. type: string
  9981. namespace:
  9982. description: |-
  9983. The namespace of the Secret resource being referred to.
  9984. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9985. maxLength: 63
  9986. minLength: 1
  9987. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9988. type: string
  9989. type: object
  9990. type: object
  9991. authType:
  9992. default: ServicePrincipal
  9993. description: |-
  9994. Auth type defines how to authenticate to the keyvault service.
  9995. Valid values are:
  9996. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  9997. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  9998. enum:
  9999. - ServicePrincipal
  10000. - ManagedIdentity
  10001. - WorkloadIdentity
  10002. type: string
  10003. environmentType:
  10004. default: PublicCloud
  10005. description: |-
  10006. EnvironmentType specifies the Azure cloud environment endpoints to use for
  10007. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  10008. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  10009. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  10010. enum:
  10011. - PublicCloud
  10012. - USGovernmentCloud
  10013. - ChinaCloud
  10014. - GermanCloud
  10015. type: string
  10016. identityId:
  10017. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  10018. type: string
  10019. serviceAccountRef:
  10020. description: |-
  10021. ServiceAccountRef specified the service account
  10022. that should be used when authenticating with WorkloadIdentity.
  10023. properties:
  10024. audiences:
  10025. description: |-
  10026. Audience specifies the `aud` claim for the service account token
  10027. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  10028. then this audiences will be appended to the list
  10029. items:
  10030. type: string
  10031. type: array
  10032. name:
  10033. description: The name of the ServiceAccount resource being referred to.
  10034. maxLength: 253
  10035. minLength: 1
  10036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10037. type: string
  10038. namespace:
  10039. description: |-
  10040. Namespace of the resource being referred to.
  10041. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10042. maxLength: 63
  10043. minLength: 1
  10044. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10045. type: string
  10046. required:
  10047. - name
  10048. type: object
  10049. tenantId:
  10050. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  10051. type: string
  10052. vaultUrl:
  10053. description: Vault Url from which the secrets to be fetched from.
  10054. type: string
  10055. required:
  10056. - vaultUrl
  10057. type: object
  10058. beyondtrust:
  10059. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  10060. properties:
  10061. auth:
  10062. description: Auth configures how the operator authenticates with Beyondtrust.
  10063. properties:
  10064. apiKey:
  10065. description: APIKey If not provided then ClientID/ClientSecret become required.
  10066. properties:
  10067. secretRef:
  10068. description: SecretRef references a key in a secret that will be used as value.
  10069. properties:
  10070. key:
  10071. description: |-
  10072. A key in the referenced Secret.
  10073. Some instances of this field may be defaulted, in others it may be required.
  10074. maxLength: 253
  10075. minLength: 1
  10076. pattern: ^[-._a-zA-Z0-9]+$
  10077. type: string
  10078. name:
  10079. description: The name of the Secret resource being referred to.
  10080. maxLength: 253
  10081. minLength: 1
  10082. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10083. type: string
  10084. namespace:
  10085. description: |-
  10086. The namespace of the Secret resource being referred to.
  10087. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10088. maxLength: 63
  10089. minLength: 1
  10090. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10091. type: string
  10092. type: object
  10093. value:
  10094. description: Value can be specified directly to set a value without using a secret.
  10095. type: string
  10096. type: object
  10097. certificate:
  10098. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  10099. properties:
  10100. secretRef:
  10101. description: SecretRef references a key in a secret that will be used as value.
  10102. properties:
  10103. key:
  10104. description: |-
  10105. A key in the referenced Secret.
  10106. Some instances of this field may be defaulted, in others it may be required.
  10107. maxLength: 253
  10108. minLength: 1
  10109. pattern: ^[-._a-zA-Z0-9]+$
  10110. type: string
  10111. name:
  10112. description: The name of the Secret resource being referred to.
  10113. maxLength: 253
  10114. minLength: 1
  10115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10116. type: string
  10117. namespace:
  10118. description: |-
  10119. The namespace of the Secret resource being referred to.
  10120. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10121. maxLength: 63
  10122. minLength: 1
  10123. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10124. type: string
  10125. type: object
  10126. value:
  10127. description: Value can be specified directly to set a value without using a secret.
  10128. type: string
  10129. type: object
  10130. certificateKey:
  10131. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  10132. properties:
  10133. secretRef:
  10134. description: SecretRef references a key in a secret that will be used as value.
  10135. properties:
  10136. key:
  10137. description: |-
  10138. A key in the referenced Secret.
  10139. Some instances of this field may be defaulted, in others it may be required.
  10140. maxLength: 253
  10141. minLength: 1
  10142. pattern: ^[-._a-zA-Z0-9]+$
  10143. type: string
  10144. name:
  10145. description: The name of the Secret resource being referred to.
  10146. maxLength: 253
  10147. minLength: 1
  10148. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10149. type: string
  10150. namespace:
  10151. description: |-
  10152. The namespace of the Secret resource being referred to.
  10153. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10154. maxLength: 63
  10155. minLength: 1
  10156. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10157. type: string
  10158. type: object
  10159. value:
  10160. description: Value can be specified directly to set a value without using a secret.
  10161. type: string
  10162. type: object
  10163. clientId:
  10164. description: ClientID is the API OAuth Client ID.
  10165. properties:
  10166. secretRef:
  10167. description: SecretRef references a key in a secret that will be used as value.
  10168. properties:
  10169. key:
  10170. description: |-
  10171. A key in the referenced Secret.
  10172. Some instances of this field may be defaulted, in others it may be required.
  10173. maxLength: 253
  10174. minLength: 1
  10175. pattern: ^[-._a-zA-Z0-9]+$
  10176. type: string
  10177. name:
  10178. description: The name of the Secret resource being referred to.
  10179. maxLength: 253
  10180. minLength: 1
  10181. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10182. type: string
  10183. namespace:
  10184. description: |-
  10185. The namespace of the Secret resource being referred to.
  10186. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10187. maxLength: 63
  10188. minLength: 1
  10189. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10190. type: string
  10191. type: object
  10192. value:
  10193. description: Value can be specified directly to set a value without using a secret.
  10194. type: string
  10195. type: object
  10196. clientSecret:
  10197. description: ClientSecret is the API OAuth Client Secret.
  10198. properties:
  10199. secretRef:
  10200. description: SecretRef references a key in a secret that will be used as value.
  10201. properties:
  10202. key:
  10203. description: |-
  10204. A key in the referenced Secret.
  10205. Some instances of this field may be defaulted, in others it may be required.
  10206. maxLength: 253
  10207. minLength: 1
  10208. pattern: ^[-._a-zA-Z0-9]+$
  10209. type: string
  10210. name:
  10211. description: The name of the Secret resource being referred to.
  10212. maxLength: 253
  10213. minLength: 1
  10214. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10215. type: string
  10216. namespace:
  10217. description: |-
  10218. The namespace of the Secret resource being referred to.
  10219. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10220. maxLength: 63
  10221. minLength: 1
  10222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10223. type: string
  10224. type: object
  10225. value:
  10226. description: Value can be specified directly to set a value without using a secret.
  10227. type: string
  10228. type: object
  10229. type: object
  10230. server:
  10231. description: Auth configures how API server works.
  10232. properties:
  10233. apiUrl:
  10234. type: string
  10235. apiVersion:
  10236. type: string
  10237. clientTimeOutSeconds:
  10238. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  10239. type: integer
  10240. decrypt:
  10241. default: true
  10242. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  10243. type: boolean
  10244. retrievalType:
  10245. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  10246. type: string
  10247. separator:
  10248. description: A character that separates the folder names.
  10249. type: string
  10250. verifyCA:
  10251. type: boolean
  10252. required:
  10253. - apiUrl
  10254. - verifyCA
  10255. type: object
  10256. required:
  10257. - auth
  10258. - server
  10259. type: object
  10260. bitwardensecretsmanager:
  10261. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  10262. properties:
  10263. apiURL:
  10264. type: string
  10265. auth:
  10266. description: |-
  10267. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  10268. Make sure that the token being used has permissions on the given secret.
  10269. properties:
  10270. secretRef:
  10271. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  10272. properties:
  10273. credentials:
  10274. description: AccessToken used for the bitwarden instance.
  10275. properties:
  10276. key:
  10277. description: |-
  10278. A key in the referenced Secret.
  10279. Some instances of this field may be defaulted, in others it may be required.
  10280. maxLength: 253
  10281. minLength: 1
  10282. pattern: ^[-._a-zA-Z0-9]+$
  10283. type: string
  10284. name:
  10285. description: The name of the Secret resource being referred to.
  10286. maxLength: 253
  10287. minLength: 1
  10288. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10289. type: string
  10290. namespace:
  10291. description: |-
  10292. The namespace of the Secret resource being referred to.
  10293. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10294. maxLength: 63
  10295. minLength: 1
  10296. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10297. type: string
  10298. type: object
  10299. required:
  10300. - credentials
  10301. type: object
  10302. required:
  10303. - secretRef
  10304. type: object
  10305. bitwardenServerSDKURL:
  10306. type: string
  10307. caBundle:
  10308. description: |-
  10309. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  10310. can be performed.
  10311. type: string
  10312. caProvider:
  10313. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  10314. properties:
  10315. key:
  10316. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10317. maxLength: 253
  10318. minLength: 1
  10319. pattern: ^[-._a-zA-Z0-9]+$
  10320. type: string
  10321. name:
  10322. description: The name of the object located at the provider type.
  10323. maxLength: 253
  10324. minLength: 1
  10325. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10326. type: string
  10327. namespace:
  10328. description: |-
  10329. The namespace the Provider type is in.
  10330. Can only be defined when used in a ClusterSecretStore.
  10331. maxLength: 63
  10332. minLength: 1
  10333. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10334. type: string
  10335. type:
  10336. description: The type of provider to use such as "Secret", or "ConfigMap".
  10337. enum:
  10338. - Secret
  10339. - ConfigMap
  10340. type: string
  10341. required:
  10342. - name
  10343. - type
  10344. type: object
  10345. identityURL:
  10346. type: string
  10347. organizationID:
  10348. description: OrganizationID determines which organization this secret store manages.
  10349. type: string
  10350. projectID:
  10351. description: ProjectID determines which project this secret store manages.
  10352. type: string
  10353. required:
  10354. - auth
  10355. - organizationID
  10356. - projectID
  10357. type: object
  10358. chef:
  10359. description: Chef configures this store to sync secrets with chef server
  10360. properties:
  10361. auth:
  10362. description: Auth defines the information necessary to authenticate against chef Server
  10363. properties:
  10364. secretRef:
  10365. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  10366. properties:
  10367. privateKeySecretRef:
  10368. description: SecretKey is the Signing Key in PEM format, used for authentication.
  10369. properties:
  10370. key:
  10371. description: |-
  10372. A key in the referenced Secret.
  10373. Some instances of this field may be defaulted, in others it may be required.
  10374. maxLength: 253
  10375. minLength: 1
  10376. pattern: ^[-._a-zA-Z0-9]+$
  10377. type: string
  10378. name:
  10379. description: The name of the Secret resource being referred to.
  10380. maxLength: 253
  10381. minLength: 1
  10382. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10383. type: string
  10384. namespace:
  10385. description: |-
  10386. The namespace of the Secret resource being referred to.
  10387. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10388. maxLength: 63
  10389. minLength: 1
  10390. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10391. type: string
  10392. type: object
  10393. required:
  10394. - privateKeySecretRef
  10395. type: object
  10396. required:
  10397. - secretRef
  10398. type: object
  10399. serverUrl:
  10400. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  10401. type: string
  10402. username:
  10403. description: UserName should be the user ID on the chef server
  10404. type: string
  10405. required:
  10406. - auth
  10407. - serverUrl
  10408. - username
  10409. type: object
  10410. cloudrusm:
  10411. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  10412. properties:
  10413. auth:
  10414. description: CSMAuth contains a secretRef for credentials.
  10415. properties:
  10416. secretRef:
  10417. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  10418. properties:
  10419. accessKeyIDSecretRef:
  10420. description: The AccessKeyID is used for authentication
  10421. properties:
  10422. key:
  10423. description: |-
  10424. A key in the referenced Secret.
  10425. Some instances of this field may be defaulted, in others it may be required.
  10426. maxLength: 253
  10427. minLength: 1
  10428. pattern: ^[-._a-zA-Z0-9]+$
  10429. type: string
  10430. name:
  10431. description: The name of the Secret resource being referred to.
  10432. maxLength: 253
  10433. minLength: 1
  10434. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10435. type: string
  10436. namespace:
  10437. description: |-
  10438. The namespace of the Secret resource being referred to.
  10439. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10440. maxLength: 63
  10441. minLength: 1
  10442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10443. type: string
  10444. type: object
  10445. accessKeySecretSecretRef:
  10446. description: The AccessKeySecret is used for authentication
  10447. properties:
  10448. key:
  10449. description: |-
  10450. A key in the referenced Secret.
  10451. Some instances of this field may be defaulted, in others it may be required.
  10452. maxLength: 253
  10453. minLength: 1
  10454. pattern: ^[-._a-zA-Z0-9]+$
  10455. type: string
  10456. name:
  10457. description: The name of the Secret resource being referred to.
  10458. maxLength: 253
  10459. minLength: 1
  10460. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10461. type: string
  10462. namespace:
  10463. description: |-
  10464. The namespace of the Secret resource being referred to.
  10465. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10466. maxLength: 63
  10467. minLength: 1
  10468. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10469. type: string
  10470. type: object
  10471. required:
  10472. - accessKeyIDSecretRef
  10473. - accessKeySecretSecretRef
  10474. type: object
  10475. type: object
  10476. projectID:
  10477. description: ProjectID is the project, which the secrets are stored in.
  10478. type: string
  10479. required:
  10480. - auth
  10481. type: object
  10482. conjur:
  10483. description: Conjur configures this store to sync secrets using conjur provider
  10484. properties:
  10485. auth:
  10486. description: Defines authentication settings for connecting to Conjur.
  10487. properties:
  10488. apikey:
  10489. description: Authenticates with Conjur using an API key.
  10490. properties:
  10491. account:
  10492. description: Account is the Conjur organization account name.
  10493. type: string
  10494. apiKeyRef:
  10495. description: |-
  10496. A reference to a specific 'key' containing the Conjur API key
  10497. within a Secret resource. In some instances, `key` is a required field.
  10498. properties:
  10499. key:
  10500. description: |-
  10501. A key in the referenced Secret.
  10502. Some instances of this field may be defaulted, in others it may be required.
  10503. maxLength: 253
  10504. minLength: 1
  10505. pattern: ^[-._a-zA-Z0-9]+$
  10506. type: string
  10507. name:
  10508. description: The name of the Secret resource being referred to.
  10509. maxLength: 253
  10510. minLength: 1
  10511. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10512. type: string
  10513. namespace:
  10514. description: |-
  10515. The namespace of the Secret resource being referred to.
  10516. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10517. maxLength: 63
  10518. minLength: 1
  10519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10520. type: string
  10521. type: object
  10522. userRef:
  10523. description: |-
  10524. A reference to a specific 'key' containing the Conjur username
  10525. within a Secret resource. In some instances, `key` is a required field.
  10526. properties:
  10527. key:
  10528. description: |-
  10529. A key in the referenced Secret.
  10530. Some instances of this field may be defaulted, in others it may be required.
  10531. maxLength: 253
  10532. minLength: 1
  10533. pattern: ^[-._a-zA-Z0-9]+$
  10534. type: string
  10535. name:
  10536. description: The name of the Secret resource being referred to.
  10537. maxLength: 253
  10538. minLength: 1
  10539. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10540. type: string
  10541. namespace:
  10542. description: |-
  10543. The namespace of the Secret resource being referred to.
  10544. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10545. maxLength: 63
  10546. minLength: 1
  10547. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10548. type: string
  10549. type: object
  10550. required:
  10551. - account
  10552. - apiKeyRef
  10553. - userRef
  10554. type: object
  10555. jwt:
  10556. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  10557. properties:
  10558. account:
  10559. description: Account is the Conjur organization account name.
  10560. type: string
  10561. hostId:
  10562. description: |-
  10563. Optional HostID for JWT authentication. This may be used depending
  10564. on how the Conjur JWT authenticator policy is configured.
  10565. type: string
  10566. secretRef:
  10567. description: |-
  10568. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  10569. authenticate with Conjur using the JWT authentication method.
  10570. properties:
  10571. key:
  10572. description: |-
  10573. A key in the referenced Secret.
  10574. Some instances of this field may be defaulted, in others it may be required.
  10575. maxLength: 253
  10576. minLength: 1
  10577. pattern: ^[-._a-zA-Z0-9]+$
  10578. type: string
  10579. name:
  10580. description: The name of the Secret resource being referred to.
  10581. maxLength: 253
  10582. minLength: 1
  10583. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10584. type: string
  10585. namespace:
  10586. description: |-
  10587. The namespace of the Secret resource being referred to.
  10588. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10589. maxLength: 63
  10590. minLength: 1
  10591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10592. type: string
  10593. type: object
  10594. serviceAccountRef:
  10595. description: |-
  10596. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  10597. a token for with the `TokenRequest` API.
  10598. properties:
  10599. audiences:
  10600. description: |-
  10601. Audience specifies the `aud` claim for the service account token
  10602. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  10603. then this audiences will be appended to the list
  10604. items:
  10605. type: string
  10606. type: array
  10607. name:
  10608. description: The name of the ServiceAccount resource being referred to.
  10609. maxLength: 253
  10610. minLength: 1
  10611. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10612. type: string
  10613. namespace:
  10614. description: |-
  10615. Namespace of the resource being referred to.
  10616. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10617. maxLength: 63
  10618. minLength: 1
  10619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10620. type: string
  10621. required:
  10622. - name
  10623. type: object
  10624. serviceID:
  10625. description: The conjur authn jwt webservice id
  10626. type: string
  10627. required:
  10628. - account
  10629. - serviceID
  10630. type: object
  10631. type: object
  10632. caBundle:
  10633. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  10634. type: string
  10635. caProvider:
  10636. description: |-
  10637. Used to provide custom certificate authority (CA) certificates
  10638. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  10639. that contains a PEM-encoded certificate.
  10640. properties:
  10641. key:
  10642. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10643. maxLength: 253
  10644. minLength: 1
  10645. pattern: ^[-._a-zA-Z0-9]+$
  10646. type: string
  10647. name:
  10648. description: The name of the object located at the provider type.
  10649. maxLength: 253
  10650. minLength: 1
  10651. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10652. type: string
  10653. namespace:
  10654. description: |-
  10655. The namespace the Provider type is in.
  10656. Can only be defined when used in a ClusterSecretStore.
  10657. maxLength: 63
  10658. minLength: 1
  10659. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10660. type: string
  10661. type:
  10662. description: The type of provider to use such as "Secret", or "ConfigMap".
  10663. enum:
  10664. - Secret
  10665. - ConfigMap
  10666. type: string
  10667. required:
  10668. - name
  10669. - type
  10670. type: object
  10671. url:
  10672. description: URL is the endpoint of the Conjur instance.
  10673. type: string
  10674. required:
  10675. - auth
  10676. - url
  10677. type: object
  10678. delinea:
  10679. description: |-
  10680. Delinea DevOps Secrets Vault
  10681. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  10682. properties:
  10683. clientId:
  10684. description: ClientID is the non-secret part of the credential.
  10685. properties:
  10686. secretRef:
  10687. description: SecretRef references a key in a secret that will be used as value.
  10688. properties:
  10689. key:
  10690. description: |-
  10691. A key in the referenced Secret.
  10692. Some instances of this field may be defaulted, in others it may be required.
  10693. maxLength: 253
  10694. minLength: 1
  10695. pattern: ^[-._a-zA-Z0-9]+$
  10696. type: string
  10697. name:
  10698. description: The name of the Secret resource being referred to.
  10699. maxLength: 253
  10700. minLength: 1
  10701. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10702. type: string
  10703. namespace:
  10704. description: |-
  10705. The namespace of the Secret resource being referred to.
  10706. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10707. maxLength: 63
  10708. minLength: 1
  10709. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10710. type: string
  10711. type: object
  10712. value:
  10713. description: Value can be specified directly to set a value without using a secret.
  10714. type: string
  10715. type: object
  10716. clientSecret:
  10717. description: ClientSecret is the secret part of the credential.
  10718. properties:
  10719. secretRef:
  10720. description: SecretRef references a key in a secret that will be used as value.
  10721. properties:
  10722. key:
  10723. description: |-
  10724. A key in the referenced Secret.
  10725. Some instances of this field may be defaulted, in others it may be required.
  10726. maxLength: 253
  10727. minLength: 1
  10728. pattern: ^[-._a-zA-Z0-9]+$
  10729. type: string
  10730. name:
  10731. description: The name of the Secret resource being referred to.
  10732. maxLength: 253
  10733. minLength: 1
  10734. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10735. type: string
  10736. namespace:
  10737. description: |-
  10738. The namespace of the Secret resource being referred to.
  10739. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10740. maxLength: 63
  10741. minLength: 1
  10742. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10743. type: string
  10744. type: object
  10745. value:
  10746. description: Value can be specified directly to set a value without using a secret.
  10747. type: string
  10748. type: object
  10749. tenant:
  10750. description: Tenant is the chosen hostname / site name.
  10751. type: string
  10752. tld:
  10753. description: |-
  10754. TLD is based on the server location that was chosen during provisioning.
  10755. If unset, defaults to "com".
  10756. type: string
  10757. urlTemplate:
  10758. description: |-
  10759. URLTemplate
  10760. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  10761. type: string
  10762. required:
  10763. - clientId
  10764. - clientSecret
  10765. - tenant
  10766. type: object
  10767. device42:
  10768. description: Device42 configures this store to sync secrets using the Device42 provider
  10769. properties:
  10770. auth:
  10771. description: Auth configures how secret-manager authenticates with a Device42 instance.
  10772. properties:
  10773. secretRef:
  10774. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  10775. properties:
  10776. credentials:
  10777. description: Username / Password is used for authentication.
  10778. properties:
  10779. key:
  10780. description: |-
  10781. A key in the referenced Secret.
  10782. Some instances of this field may be defaulted, in others it may be required.
  10783. maxLength: 253
  10784. minLength: 1
  10785. pattern: ^[-._a-zA-Z0-9]+$
  10786. type: string
  10787. name:
  10788. description: The name of the Secret resource being referred to.
  10789. maxLength: 253
  10790. minLength: 1
  10791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10792. type: string
  10793. namespace:
  10794. description: |-
  10795. The namespace of the Secret resource being referred to.
  10796. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10797. maxLength: 63
  10798. minLength: 1
  10799. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10800. type: string
  10801. type: object
  10802. type: object
  10803. required:
  10804. - secretRef
  10805. type: object
  10806. host:
  10807. description: URL configures the Device42 instance URL.
  10808. type: string
  10809. required:
  10810. - auth
  10811. - host
  10812. type: object
  10813. doppler:
  10814. description: Doppler configures this store to sync secrets using the Doppler provider
  10815. properties:
  10816. auth:
  10817. description: Auth configures how the Operator authenticates with the Doppler API
  10818. properties:
  10819. secretRef:
  10820. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  10821. properties:
  10822. dopplerToken:
  10823. description: |-
  10824. The DopplerToken is used for authentication.
  10825. See https://docs.doppler.com/reference/api#authentication for auth token types.
  10826. The Key attribute defaults to dopplerToken if not specified.
  10827. properties:
  10828. key:
  10829. description: |-
  10830. A key in the referenced Secret.
  10831. Some instances of this field may be defaulted, in others it may be required.
  10832. maxLength: 253
  10833. minLength: 1
  10834. pattern: ^[-._a-zA-Z0-9]+$
  10835. type: string
  10836. name:
  10837. description: The name of the Secret resource being referred to.
  10838. maxLength: 253
  10839. minLength: 1
  10840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10841. type: string
  10842. namespace:
  10843. description: |-
  10844. The namespace of the Secret resource being referred to.
  10845. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10846. maxLength: 63
  10847. minLength: 1
  10848. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10849. type: string
  10850. type: object
  10851. required:
  10852. - dopplerToken
  10853. type: object
  10854. required:
  10855. - secretRef
  10856. type: object
  10857. config:
  10858. description: Doppler config (required if not using a Service Token)
  10859. type: string
  10860. format:
  10861. description: Format enables the downloading of secrets as a file (string)
  10862. enum:
  10863. - json
  10864. - dotnet-json
  10865. - env
  10866. - yaml
  10867. - docker
  10868. type: string
  10869. nameTransformer:
  10870. description: Environment variable compatible name transforms that change secret names to a different format
  10871. enum:
  10872. - upper-camel
  10873. - camel
  10874. - lower-snake
  10875. - tf-var
  10876. - dotnet-env
  10877. - lower-kebab
  10878. type: string
  10879. project:
  10880. description: Doppler project (required if not using a Service Token)
  10881. type: string
  10882. required:
  10883. - auth
  10884. type: object
  10885. fake:
  10886. description: Fake configures a store with static key/value pairs
  10887. properties:
  10888. data:
  10889. items:
  10890. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  10891. properties:
  10892. key:
  10893. type: string
  10894. value:
  10895. type: string
  10896. version:
  10897. type: string
  10898. required:
  10899. - key
  10900. - value
  10901. type: object
  10902. type: array
  10903. required:
  10904. - data
  10905. type: object
  10906. fortanix:
  10907. description: Fortanix configures this store to sync secrets using the Fortanix provider
  10908. properties:
  10909. apiKey:
  10910. description: APIKey is the API token to access SDKMS Applications.
  10911. properties:
  10912. secretRef:
  10913. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  10914. properties:
  10915. key:
  10916. description: |-
  10917. A key in the referenced Secret.
  10918. Some instances of this field may be defaulted, in others it may be required.
  10919. maxLength: 253
  10920. minLength: 1
  10921. pattern: ^[-._a-zA-Z0-9]+$
  10922. type: string
  10923. name:
  10924. description: The name of the Secret resource being referred to.
  10925. maxLength: 253
  10926. minLength: 1
  10927. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10928. type: string
  10929. namespace:
  10930. description: |-
  10931. The namespace of the Secret resource being referred to.
  10932. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10933. maxLength: 63
  10934. minLength: 1
  10935. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10936. type: string
  10937. type: object
  10938. type: object
  10939. apiUrl:
  10940. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  10941. type: string
  10942. type: object
  10943. gcpsm:
  10944. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  10945. properties:
  10946. auth:
  10947. description: Auth defines the information necessary to authenticate against GCP
  10948. properties:
  10949. secretRef:
  10950. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  10951. properties:
  10952. secretAccessKeySecretRef:
  10953. description: The SecretAccessKey is used for authentication
  10954. properties:
  10955. key:
  10956. description: |-
  10957. A key in the referenced Secret.
  10958. Some instances of this field may be defaulted, in others it may be required.
  10959. maxLength: 253
  10960. minLength: 1
  10961. pattern: ^[-._a-zA-Z0-9]+$
  10962. type: string
  10963. name:
  10964. description: The name of the Secret resource being referred to.
  10965. maxLength: 253
  10966. minLength: 1
  10967. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10968. type: string
  10969. namespace:
  10970. description: |-
  10971. The namespace of the Secret resource being referred to.
  10972. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10973. maxLength: 63
  10974. minLength: 1
  10975. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10976. type: string
  10977. type: object
  10978. type: object
  10979. workloadIdentity:
  10980. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  10981. properties:
  10982. clusterLocation:
  10983. description: |-
  10984. ClusterLocation is the location of the cluster
  10985. If not specified, it fetches information from the metadata server
  10986. type: string
  10987. clusterName:
  10988. description: |-
  10989. ClusterName is the name of the cluster
  10990. If not specified, it fetches information from the metadata server
  10991. type: string
  10992. clusterProjectID:
  10993. description: |-
  10994. ClusterProjectID is the project ID of the cluster
  10995. If not specified, it fetches information from the metadata server
  10996. type: string
  10997. serviceAccountRef:
  10998. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  10999. properties:
  11000. audiences:
  11001. description: |-
  11002. Audience specifies the `aud` claim for the service account token
  11003. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11004. then this audiences will be appended to the list
  11005. items:
  11006. type: string
  11007. type: array
  11008. name:
  11009. description: The name of the ServiceAccount resource being referred to.
  11010. maxLength: 253
  11011. minLength: 1
  11012. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11013. type: string
  11014. namespace:
  11015. description: |-
  11016. Namespace of the resource being referred to.
  11017. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11018. maxLength: 63
  11019. minLength: 1
  11020. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11021. type: string
  11022. required:
  11023. - name
  11024. type: object
  11025. required:
  11026. - serviceAccountRef
  11027. type: object
  11028. type: object
  11029. location:
  11030. description: Location optionally defines a location for a secret
  11031. type: string
  11032. projectID:
  11033. description: ProjectID project where secret is located
  11034. type: string
  11035. type: object
  11036. github:
  11037. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  11038. properties:
  11039. appID:
  11040. description: appID specifies the Github APP that will be used to authenticate the client
  11041. format: int64
  11042. type: integer
  11043. auth:
  11044. description: auth configures how secret-manager authenticates with a Github instance.
  11045. properties:
  11046. privateKey:
  11047. description: |-
  11048. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11049. In some instances, `key` is a required field.
  11050. properties:
  11051. key:
  11052. description: |-
  11053. A key in the referenced Secret.
  11054. Some instances of this field may be defaulted, in others it may be required.
  11055. maxLength: 253
  11056. minLength: 1
  11057. pattern: ^[-._a-zA-Z0-9]+$
  11058. type: string
  11059. name:
  11060. description: The name of the Secret resource being referred to.
  11061. maxLength: 253
  11062. minLength: 1
  11063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11064. type: string
  11065. namespace:
  11066. description: |-
  11067. The namespace of the Secret resource being referred to.
  11068. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11069. maxLength: 63
  11070. minLength: 1
  11071. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11072. type: string
  11073. type: object
  11074. required:
  11075. - privateKey
  11076. type: object
  11077. environment:
  11078. description: environment will be used to fetch secrets from a particular environment within a github repository
  11079. type: string
  11080. installationID:
  11081. description: installationID specifies the Github APP installation that will be used to authenticate the client
  11082. format: int64
  11083. type: integer
  11084. organization:
  11085. description: organization will be used to fetch secrets from the Github organization
  11086. type: string
  11087. repository:
  11088. description: repository will be used to fetch secrets from the Github repository within an organization
  11089. type: string
  11090. uploadURL:
  11091. description: Upload URL for enterprise instances. Default to URL.
  11092. type: string
  11093. url:
  11094. default: https://github.com/
  11095. description: URL configures the Github instance URL. Defaults to https://github.com/.
  11096. type: string
  11097. required:
  11098. - appID
  11099. - auth
  11100. - installationID
  11101. - organization
  11102. type: object
  11103. gitlab:
  11104. description: GitLab configures this store to sync secrets using GitLab Variables provider
  11105. properties:
  11106. auth:
  11107. description: Auth configures how secret-manager authenticates with a GitLab instance.
  11108. properties:
  11109. SecretRef:
  11110. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  11111. properties:
  11112. accessToken:
  11113. description: AccessToken is used for authentication.
  11114. properties:
  11115. key:
  11116. description: |-
  11117. A key in the referenced Secret.
  11118. Some instances of this field may be defaulted, in others it may be required.
  11119. maxLength: 253
  11120. minLength: 1
  11121. pattern: ^[-._a-zA-Z0-9]+$
  11122. type: string
  11123. name:
  11124. description: The name of the Secret resource being referred to.
  11125. maxLength: 253
  11126. minLength: 1
  11127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11128. type: string
  11129. namespace:
  11130. description: |-
  11131. The namespace of the Secret resource being referred to.
  11132. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11133. maxLength: 63
  11134. minLength: 1
  11135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11136. type: string
  11137. type: object
  11138. type: object
  11139. required:
  11140. - SecretRef
  11141. type: object
  11142. caBundle:
  11143. description: |-
  11144. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  11145. can be performed.
  11146. format: byte
  11147. type: string
  11148. caProvider:
  11149. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  11150. properties:
  11151. key:
  11152. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11153. maxLength: 253
  11154. minLength: 1
  11155. pattern: ^[-._a-zA-Z0-9]+$
  11156. type: string
  11157. name:
  11158. description: The name of the object located at the provider type.
  11159. maxLength: 253
  11160. minLength: 1
  11161. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11162. type: string
  11163. namespace:
  11164. description: |-
  11165. The namespace the Provider type is in.
  11166. Can only be defined when used in a ClusterSecretStore.
  11167. maxLength: 63
  11168. minLength: 1
  11169. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11170. type: string
  11171. type:
  11172. description: The type of provider to use such as "Secret", or "ConfigMap".
  11173. enum:
  11174. - Secret
  11175. - ConfigMap
  11176. type: string
  11177. required:
  11178. - name
  11179. - type
  11180. type: object
  11181. environment:
  11182. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  11183. type: string
  11184. groupIDs:
  11185. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  11186. items:
  11187. type: string
  11188. type: array
  11189. inheritFromGroups:
  11190. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  11191. type: boolean
  11192. projectID:
  11193. description: ProjectID specifies a project where secrets are located.
  11194. type: string
  11195. url:
  11196. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  11197. type: string
  11198. required:
  11199. - auth
  11200. type: object
  11201. ibm:
  11202. description: IBM configures this store to sync secrets using IBM Cloud provider
  11203. properties:
  11204. auth:
  11205. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  11206. maxProperties: 1
  11207. minProperties: 1
  11208. properties:
  11209. containerAuth:
  11210. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  11211. properties:
  11212. iamEndpoint:
  11213. type: string
  11214. profile:
  11215. description: the IBM Trusted Profile
  11216. type: string
  11217. tokenLocation:
  11218. description: Location the token is mounted on the pod
  11219. type: string
  11220. required:
  11221. - profile
  11222. type: object
  11223. secretRef:
  11224. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  11225. properties:
  11226. secretApiKeySecretRef:
  11227. description: The SecretAccessKey is used for authentication
  11228. properties:
  11229. key:
  11230. description: |-
  11231. A key in the referenced Secret.
  11232. Some instances of this field may be defaulted, in others it may be required.
  11233. maxLength: 253
  11234. minLength: 1
  11235. pattern: ^[-._a-zA-Z0-9]+$
  11236. type: string
  11237. name:
  11238. description: The name of the Secret resource being referred to.
  11239. maxLength: 253
  11240. minLength: 1
  11241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11242. type: string
  11243. namespace:
  11244. description: |-
  11245. The namespace of the Secret resource being referred to.
  11246. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11247. maxLength: 63
  11248. minLength: 1
  11249. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11250. type: string
  11251. type: object
  11252. type: object
  11253. type: object
  11254. serviceUrl:
  11255. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  11256. type: string
  11257. required:
  11258. - auth
  11259. type: object
  11260. infisical:
  11261. description: Infisical configures this store to sync secrets using the Infisical provider
  11262. properties:
  11263. auth:
  11264. description: Auth configures how the Operator authenticates with the Infisical API
  11265. properties:
  11266. universalAuthCredentials:
  11267. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  11268. properties:
  11269. clientId:
  11270. description: |-
  11271. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11272. In some instances, `key` is a required field.
  11273. properties:
  11274. key:
  11275. description: |-
  11276. A key in the referenced Secret.
  11277. Some instances of this field may be defaulted, in others it may be required.
  11278. maxLength: 253
  11279. minLength: 1
  11280. pattern: ^[-._a-zA-Z0-9]+$
  11281. type: string
  11282. name:
  11283. description: The name of the Secret resource being referred to.
  11284. maxLength: 253
  11285. minLength: 1
  11286. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11287. type: string
  11288. namespace:
  11289. description: |-
  11290. The namespace of the Secret resource being referred to.
  11291. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11292. maxLength: 63
  11293. minLength: 1
  11294. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11295. type: string
  11296. type: object
  11297. clientSecret:
  11298. description: |-
  11299. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11300. In some instances, `key` is a required field.
  11301. properties:
  11302. key:
  11303. description: |-
  11304. A key in the referenced Secret.
  11305. Some instances of this field may be defaulted, in others it may be required.
  11306. maxLength: 253
  11307. minLength: 1
  11308. pattern: ^[-._a-zA-Z0-9]+$
  11309. type: string
  11310. name:
  11311. description: The name of the Secret resource being referred to.
  11312. maxLength: 253
  11313. minLength: 1
  11314. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11315. type: string
  11316. namespace:
  11317. description: |-
  11318. The namespace of the Secret resource being referred to.
  11319. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11320. maxLength: 63
  11321. minLength: 1
  11322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11323. type: string
  11324. type: object
  11325. required:
  11326. - clientId
  11327. - clientSecret
  11328. type: object
  11329. type: object
  11330. hostAPI:
  11331. default: https://app.infisical.com/api
  11332. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  11333. type: string
  11334. secretsScope:
  11335. description: SecretsScope defines the scope of the secrets within the workspace
  11336. properties:
  11337. environmentSlug:
  11338. description: EnvironmentSlug is the required slug identifier for the environment.
  11339. type: string
  11340. expandSecretReferences:
  11341. default: true
  11342. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  11343. type: boolean
  11344. projectSlug:
  11345. description: ProjectSlug is the required slug identifier for the project.
  11346. type: string
  11347. recursive:
  11348. default: false
  11349. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  11350. type: boolean
  11351. secretsPath:
  11352. default: /
  11353. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  11354. type: string
  11355. required:
  11356. - environmentSlug
  11357. - projectSlug
  11358. type: object
  11359. required:
  11360. - auth
  11361. - secretsScope
  11362. type: object
  11363. keepersecurity:
  11364. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  11365. properties:
  11366. authRef:
  11367. description: |-
  11368. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11369. In some instances, `key` is a required field.
  11370. properties:
  11371. key:
  11372. description: |-
  11373. A key in the referenced Secret.
  11374. Some instances of this field may be defaulted, in others it may be required.
  11375. maxLength: 253
  11376. minLength: 1
  11377. pattern: ^[-._a-zA-Z0-9]+$
  11378. type: string
  11379. name:
  11380. description: The name of the Secret resource being referred to.
  11381. maxLength: 253
  11382. minLength: 1
  11383. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11384. type: string
  11385. namespace:
  11386. description: |-
  11387. The namespace of the Secret resource being referred to.
  11388. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11389. maxLength: 63
  11390. minLength: 1
  11391. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11392. type: string
  11393. type: object
  11394. folderID:
  11395. type: string
  11396. required:
  11397. - authRef
  11398. - folderID
  11399. type: object
  11400. kubernetes:
  11401. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  11402. properties:
  11403. auth:
  11404. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  11405. maxProperties: 1
  11406. minProperties: 1
  11407. properties:
  11408. cert:
  11409. description: has both clientCert and clientKey as secretKeySelector
  11410. properties:
  11411. clientCert:
  11412. description: |-
  11413. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11414. In some instances, `key` is a required field.
  11415. properties:
  11416. key:
  11417. description: |-
  11418. A key in the referenced Secret.
  11419. Some instances of this field may be defaulted, in others it may be required.
  11420. maxLength: 253
  11421. minLength: 1
  11422. pattern: ^[-._a-zA-Z0-9]+$
  11423. type: string
  11424. name:
  11425. description: The name of the Secret resource being referred to.
  11426. maxLength: 253
  11427. minLength: 1
  11428. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11429. type: string
  11430. namespace:
  11431. description: |-
  11432. The namespace of the Secret resource being referred to.
  11433. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11434. maxLength: 63
  11435. minLength: 1
  11436. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11437. type: string
  11438. type: object
  11439. clientKey:
  11440. description: |-
  11441. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11442. In some instances, `key` is a required field.
  11443. properties:
  11444. key:
  11445. description: |-
  11446. A key in the referenced Secret.
  11447. Some instances of this field may be defaulted, in others it may be required.
  11448. maxLength: 253
  11449. minLength: 1
  11450. pattern: ^[-._a-zA-Z0-9]+$
  11451. type: string
  11452. name:
  11453. description: The name of the Secret resource being referred to.
  11454. maxLength: 253
  11455. minLength: 1
  11456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11457. type: string
  11458. namespace:
  11459. description: |-
  11460. The namespace of the Secret resource being referred to.
  11461. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11462. maxLength: 63
  11463. minLength: 1
  11464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11465. type: string
  11466. type: object
  11467. type: object
  11468. serviceAccount:
  11469. description: points to a service account that should be used for authentication
  11470. properties:
  11471. audiences:
  11472. description: |-
  11473. Audience specifies the `aud` claim for the service account token
  11474. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11475. then this audiences will be appended to the list
  11476. items:
  11477. type: string
  11478. type: array
  11479. name:
  11480. description: The name of the ServiceAccount resource being referred to.
  11481. maxLength: 253
  11482. minLength: 1
  11483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11484. type: string
  11485. namespace:
  11486. description: |-
  11487. Namespace of the resource being referred to.
  11488. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11489. maxLength: 63
  11490. minLength: 1
  11491. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11492. type: string
  11493. required:
  11494. - name
  11495. type: object
  11496. token:
  11497. description: use static token to authenticate with
  11498. properties:
  11499. bearerToken:
  11500. description: |-
  11501. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11502. In some instances, `key` is a required field.
  11503. properties:
  11504. key:
  11505. description: |-
  11506. A key in the referenced Secret.
  11507. Some instances of this field may be defaulted, in others it may be required.
  11508. maxLength: 253
  11509. minLength: 1
  11510. pattern: ^[-._a-zA-Z0-9]+$
  11511. type: string
  11512. name:
  11513. description: The name of the Secret resource being referred to.
  11514. maxLength: 253
  11515. minLength: 1
  11516. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11517. type: string
  11518. namespace:
  11519. description: |-
  11520. The namespace of the Secret resource being referred to.
  11521. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11522. maxLength: 63
  11523. minLength: 1
  11524. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11525. type: string
  11526. type: object
  11527. type: object
  11528. type: object
  11529. authRef:
  11530. description: A reference to a secret that contains the auth information.
  11531. properties:
  11532. key:
  11533. description: |-
  11534. A key in the referenced Secret.
  11535. Some instances of this field may be defaulted, in others it may be required.
  11536. maxLength: 253
  11537. minLength: 1
  11538. pattern: ^[-._a-zA-Z0-9]+$
  11539. type: string
  11540. name:
  11541. description: The name of the Secret resource being referred to.
  11542. maxLength: 253
  11543. minLength: 1
  11544. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11545. type: string
  11546. namespace:
  11547. description: |-
  11548. The namespace of the Secret resource being referred to.
  11549. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11550. maxLength: 63
  11551. minLength: 1
  11552. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11553. type: string
  11554. type: object
  11555. remoteNamespace:
  11556. default: default
  11557. description: Remote namespace to fetch the secrets from
  11558. maxLength: 63
  11559. minLength: 1
  11560. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11561. type: string
  11562. server:
  11563. description: configures the Kubernetes server Address.
  11564. properties:
  11565. caBundle:
  11566. description: CABundle is a base64-encoded CA certificate
  11567. format: byte
  11568. type: string
  11569. caProvider:
  11570. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  11571. properties:
  11572. key:
  11573. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11574. maxLength: 253
  11575. minLength: 1
  11576. pattern: ^[-._a-zA-Z0-9]+$
  11577. type: string
  11578. name:
  11579. description: The name of the object located at the provider type.
  11580. maxLength: 253
  11581. minLength: 1
  11582. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11583. type: string
  11584. namespace:
  11585. description: |-
  11586. The namespace the Provider type is in.
  11587. Can only be defined when used in a ClusterSecretStore.
  11588. maxLength: 63
  11589. minLength: 1
  11590. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11591. type: string
  11592. type:
  11593. description: The type of provider to use such as "Secret", or "ConfigMap".
  11594. enum:
  11595. - Secret
  11596. - ConfigMap
  11597. type: string
  11598. required:
  11599. - name
  11600. - type
  11601. type: object
  11602. url:
  11603. default: kubernetes.default
  11604. description: configures the Kubernetes server Address.
  11605. type: string
  11606. type: object
  11607. type: object
  11608. onboardbase:
  11609. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  11610. properties:
  11611. apiHost:
  11612. default: https://public.onboardbase.com/api/v1/
  11613. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  11614. type: string
  11615. auth:
  11616. description: Auth configures how the Operator authenticates with the Onboardbase API
  11617. properties:
  11618. apiKeyRef:
  11619. description: |-
  11620. OnboardbaseAPIKey is the APIKey generated by an admin account.
  11621. It is used to recognize and authorize access to a project and environment within onboardbase
  11622. properties:
  11623. key:
  11624. description: |-
  11625. A key in the referenced Secret.
  11626. Some instances of this field may be defaulted, in others it may be required.
  11627. maxLength: 253
  11628. minLength: 1
  11629. pattern: ^[-._a-zA-Z0-9]+$
  11630. type: string
  11631. name:
  11632. description: The name of the Secret resource being referred to.
  11633. maxLength: 253
  11634. minLength: 1
  11635. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11636. type: string
  11637. namespace:
  11638. description: |-
  11639. The namespace of the Secret resource being referred to.
  11640. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11641. maxLength: 63
  11642. minLength: 1
  11643. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11644. type: string
  11645. type: object
  11646. passcodeRef:
  11647. description: OnboardbasePasscode is the passcode attached to the API Key
  11648. properties:
  11649. key:
  11650. description: |-
  11651. A key in the referenced Secret.
  11652. Some instances of this field may be defaulted, in others it may be required.
  11653. maxLength: 253
  11654. minLength: 1
  11655. pattern: ^[-._a-zA-Z0-9]+$
  11656. type: string
  11657. name:
  11658. description: The name of the Secret resource being referred to.
  11659. maxLength: 253
  11660. minLength: 1
  11661. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11662. type: string
  11663. namespace:
  11664. description: |-
  11665. The namespace of the Secret resource being referred to.
  11666. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11667. maxLength: 63
  11668. minLength: 1
  11669. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11670. type: string
  11671. type: object
  11672. required:
  11673. - apiKeyRef
  11674. - passcodeRef
  11675. type: object
  11676. environment:
  11677. default: development
  11678. description: Environment is the name of an environmnent within a project to pull the secrets from
  11679. type: string
  11680. project:
  11681. default: development
  11682. description: Project is an onboardbase project that the secrets should be pulled from
  11683. type: string
  11684. required:
  11685. - apiHost
  11686. - auth
  11687. - environment
  11688. - project
  11689. type: object
  11690. onepassword:
  11691. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  11692. properties:
  11693. auth:
  11694. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  11695. properties:
  11696. secretRef:
  11697. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  11698. properties:
  11699. connectTokenSecretRef:
  11700. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  11701. properties:
  11702. key:
  11703. description: |-
  11704. A key in the referenced Secret.
  11705. Some instances of this field may be defaulted, in others it may be required.
  11706. maxLength: 253
  11707. minLength: 1
  11708. pattern: ^[-._a-zA-Z0-9]+$
  11709. type: string
  11710. name:
  11711. description: The name of the Secret resource being referred to.
  11712. maxLength: 253
  11713. minLength: 1
  11714. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11715. type: string
  11716. namespace:
  11717. description: |-
  11718. The namespace of the Secret resource being referred to.
  11719. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11720. maxLength: 63
  11721. minLength: 1
  11722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11723. type: string
  11724. type: object
  11725. required:
  11726. - connectTokenSecretRef
  11727. type: object
  11728. required:
  11729. - secretRef
  11730. type: object
  11731. connectHost:
  11732. description: ConnectHost defines the OnePassword Connect Server to connect to
  11733. type: string
  11734. vaults:
  11735. additionalProperties:
  11736. type: integer
  11737. description: Vaults defines which OnePassword vaults to search in which order
  11738. type: object
  11739. required:
  11740. - auth
  11741. - connectHost
  11742. - vaults
  11743. type: object
  11744. oracle:
  11745. description: Oracle configures this store to sync secrets using Oracle Vault provider
  11746. properties:
  11747. auth:
  11748. description: |-
  11749. Auth configures how secret-manager authenticates with the Oracle Vault.
  11750. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  11751. properties:
  11752. secretRef:
  11753. description: SecretRef to pass through sensitive information.
  11754. properties:
  11755. fingerprint:
  11756. description: Fingerprint is the fingerprint of the API private key.
  11757. properties:
  11758. key:
  11759. description: |-
  11760. A key in the referenced Secret.
  11761. Some instances of this field may be defaulted, in others it may be required.
  11762. maxLength: 253
  11763. minLength: 1
  11764. pattern: ^[-._a-zA-Z0-9]+$
  11765. type: string
  11766. name:
  11767. description: The name of the Secret resource being referred to.
  11768. maxLength: 253
  11769. minLength: 1
  11770. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11771. type: string
  11772. namespace:
  11773. description: |-
  11774. The namespace of the Secret resource being referred to.
  11775. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11776. maxLength: 63
  11777. minLength: 1
  11778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11779. type: string
  11780. type: object
  11781. privatekey:
  11782. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  11783. properties:
  11784. key:
  11785. description: |-
  11786. A key in the referenced Secret.
  11787. Some instances of this field may be defaulted, in others it may be required.
  11788. maxLength: 253
  11789. minLength: 1
  11790. pattern: ^[-._a-zA-Z0-9]+$
  11791. type: string
  11792. name:
  11793. description: The name of the Secret resource being referred to.
  11794. maxLength: 253
  11795. minLength: 1
  11796. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11797. type: string
  11798. namespace:
  11799. description: |-
  11800. The namespace of the Secret resource being referred to.
  11801. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11802. maxLength: 63
  11803. minLength: 1
  11804. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11805. type: string
  11806. type: object
  11807. required:
  11808. - fingerprint
  11809. - privatekey
  11810. type: object
  11811. tenancy:
  11812. description: Tenancy is the tenancy OCID where user is located.
  11813. type: string
  11814. user:
  11815. description: User is an access OCID specific to the account.
  11816. type: string
  11817. required:
  11818. - secretRef
  11819. - tenancy
  11820. - user
  11821. type: object
  11822. compartment:
  11823. description: |-
  11824. Compartment is the vault compartment OCID.
  11825. Required for PushSecret
  11826. type: string
  11827. encryptionKey:
  11828. description: |-
  11829. EncryptionKey is the OCID of the encryption key within the vault.
  11830. Required for PushSecret
  11831. type: string
  11832. principalType:
  11833. description: |-
  11834. The type of principal to use for authentication. If left blank, the Auth struct will
  11835. determine the principal type. This optional field must be specified if using
  11836. workload identity.
  11837. enum:
  11838. - ""
  11839. - UserPrincipal
  11840. - InstancePrincipal
  11841. - Workload
  11842. type: string
  11843. region:
  11844. description: Region is the region where vault is located.
  11845. type: string
  11846. serviceAccountRef:
  11847. description: |-
  11848. ServiceAccountRef specified the service account
  11849. that should be used when authenticating with WorkloadIdentity.
  11850. properties:
  11851. audiences:
  11852. description: |-
  11853. Audience specifies the `aud` claim for the service account token
  11854. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11855. then this audiences will be appended to the list
  11856. items:
  11857. type: string
  11858. type: array
  11859. name:
  11860. description: The name of the ServiceAccount resource being referred to.
  11861. maxLength: 253
  11862. minLength: 1
  11863. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11864. type: string
  11865. namespace:
  11866. description: |-
  11867. Namespace of the resource being referred to.
  11868. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11869. maxLength: 63
  11870. minLength: 1
  11871. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11872. type: string
  11873. required:
  11874. - name
  11875. type: object
  11876. vault:
  11877. description: Vault is the vault's OCID of the specific vault where secret is located.
  11878. type: string
  11879. required:
  11880. - region
  11881. - vault
  11882. type: object
  11883. passbolt:
  11884. description: PassboltProvider defines configuration for the Passbolt provider.
  11885. properties:
  11886. auth:
  11887. description: Auth defines the information necessary to authenticate against Passbolt Server
  11888. properties:
  11889. passwordSecretRef:
  11890. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  11891. properties:
  11892. key:
  11893. description: |-
  11894. A key in the referenced Secret.
  11895. Some instances of this field may be defaulted, in others it may be required.
  11896. maxLength: 253
  11897. minLength: 1
  11898. pattern: ^[-._a-zA-Z0-9]+$
  11899. type: string
  11900. name:
  11901. description: The name of the Secret resource being referred to.
  11902. maxLength: 253
  11903. minLength: 1
  11904. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11905. type: string
  11906. namespace:
  11907. description: |-
  11908. The namespace of the Secret resource being referred to.
  11909. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11910. maxLength: 63
  11911. minLength: 1
  11912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11913. type: string
  11914. type: object
  11915. privateKeySecretRef:
  11916. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  11917. properties:
  11918. key:
  11919. description: |-
  11920. A key in the referenced Secret.
  11921. Some instances of this field may be defaulted, in others it may be required.
  11922. maxLength: 253
  11923. minLength: 1
  11924. pattern: ^[-._a-zA-Z0-9]+$
  11925. type: string
  11926. name:
  11927. description: The name of the Secret resource being referred to.
  11928. maxLength: 253
  11929. minLength: 1
  11930. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11931. type: string
  11932. namespace:
  11933. description: |-
  11934. The namespace of the Secret resource being referred to.
  11935. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11936. maxLength: 63
  11937. minLength: 1
  11938. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11939. type: string
  11940. type: object
  11941. required:
  11942. - passwordSecretRef
  11943. - privateKeySecretRef
  11944. type: object
  11945. host:
  11946. description: Host defines the Passbolt Server to connect to
  11947. type: string
  11948. required:
  11949. - auth
  11950. - host
  11951. type: object
  11952. passworddepot:
  11953. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  11954. properties:
  11955. auth:
  11956. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  11957. properties:
  11958. secretRef:
  11959. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  11960. properties:
  11961. credentials:
  11962. description: Username / Password is used for authentication.
  11963. properties:
  11964. key:
  11965. description: |-
  11966. A key in the referenced Secret.
  11967. Some instances of this field may be defaulted, in others it may be required.
  11968. maxLength: 253
  11969. minLength: 1
  11970. pattern: ^[-._a-zA-Z0-9]+$
  11971. type: string
  11972. name:
  11973. description: The name of the Secret resource being referred to.
  11974. maxLength: 253
  11975. minLength: 1
  11976. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11977. type: string
  11978. namespace:
  11979. description: |-
  11980. The namespace of the Secret resource being referred to.
  11981. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11982. maxLength: 63
  11983. minLength: 1
  11984. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11985. type: string
  11986. type: object
  11987. type: object
  11988. required:
  11989. - secretRef
  11990. type: object
  11991. database:
  11992. description: Database to use as source
  11993. type: string
  11994. host:
  11995. description: URL configures the Password Depot instance URL.
  11996. type: string
  11997. required:
  11998. - auth
  11999. - database
  12000. - host
  12001. type: object
  12002. previder:
  12003. description: Previder configures this store to sync secrets using the Previder provider
  12004. properties:
  12005. auth:
  12006. description: PreviderAuth contains a secretRef for credentials.
  12007. properties:
  12008. secretRef:
  12009. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  12010. properties:
  12011. accessToken:
  12012. description: The AccessToken is used for authentication
  12013. properties:
  12014. key:
  12015. description: |-
  12016. A key in the referenced Secret.
  12017. Some instances of this field may be defaulted, in others it may be required.
  12018. maxLength: 253
  12019. minLength: 1
  12020. pattern: ^[-._a-zA-Z0-9]+$
  12021. type: string
  12022. name:
  12023. description: The name of the Secret resource being referred to.
  12024. maxLength: 253
  12025. minLength: 1
  12026. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12027. type: string
  12028. namespace:
  12029. description: |-
  12030. The namespace of the Secret resource being referred to.
  12031. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12032. maxLength: 63
  12033. minLength: 1
  12034. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12035. type: string
  12036. type: object
  12037. required:
  12038. - accessToken
  12039. type: object
  12040. type: object
  12041. baseUri:
  12042. type: string
  12043. required:
  12044. - auth
  12045. type: object
  12046. pulumi:
  12047. description: Pulumi configures this store to sync secrets using the Pulumi provider
  12048. properties:
  12049. accessToken:
  12050. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  12051. properties:
  12052. secretRef:
  12053. description: SecretRef is a reference to a secret containing the Pulumi API token.
  12054. properties:
  12055. key:
  12056. description: |-
  12057. A key in the referenced Secret.
  12058. Some instances of this field may be defaulted, in others it may be required.
  12059. maxLength: 253
  12060. minLength: 1
  12061. pattern: ^[-._a-zA-Z0-9]+$
  12062. type: string
  12063. name:
  12064. description: The name of the Secret resource being referred to.
  12065. maxLength: 253
  12066. minLength: 1
  12067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12068. type: string
  12069. namespace:
  12070. description: |-
  12071. The namespace of the Secret resource being referred to.
  12072. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12073. maxLength: 63
  12074. minLength: 1
  12075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12076. type: string
  12077. type: object
  12078. type: object
  12079. apiUrl:
  12080. default: https://api.pulumi.com/api/esc
  12081. description: APIURL is the URL of the Pulumi API.
  12082. type: string
  12083. environment:
  12084. description: |-
  12085. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  12086. dynamically retrieved values from supported providers including all major clouds,
  12087. and other Pulumi ESC environments.
  12088. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  12089. type: string
  12090. organization:
  12091. description: |-
  12092. Organization are a space to collaborate on shared projects and stacks.
  12093. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  12094. type: string
  12095. project:
  12096. description: Project is the name of the Pulumi ESC project the environment belongs to.
  12097. type: string
  12098. required:
  12099. - accessToken
  12100. - environment
  12101. - organization
  12102. - project
  12103. type: object
  12104. scaleway:
  12105. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  12106. properties:
  12107. accessKey:
  12108. description: AccessKey is the non-secret part of the api key.
  12109. properties:
  12110. secretRef:
  12111. description: SecretRef references a key in a secret that will be used as value.
  12112. properties:
  12113. key:
  12114. description: |-
  12115. A key in the referenced Secret.
  12116. Some instances of this field may be defaulted, in others it may be required.
  12117. maxLength: 253
  12118. minLength: 1
  12119. pattern: ^[-._a-zA-Z0-9]+$
  12120. type: string
  12121. name:
  12122. description: The name of the Secret resource being referred to.
  12123. maxLength: 253
  12124. minLength: 1
  12125. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12126. type: string
  12127. namespace:
  12128. description: |-
  12129. The namespace of the Secret resource being referred to.
  12130. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12131. maxLength: 63
  12132. minLength: 1
  12133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12134. type: string
  12135. type: object
  12136. value:
  12137. description: Value can be specified directly to set a value without using a secret.
  12138. type: string
  12139. type: object
  12140. apiUrl:
  12141. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  12142. type: string
  12143. projectId:
  12144. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  12145. type: string
  12146. region:
  12147. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  12148. type: string
  12149. secretKey:
  12150. description: SecretKey is the non-secret part of the api key.
  12151. properties:
  12152. secretRef:
  12153. description: SecretRef references a key in a secret that will be used as value.
  12154. properties:
  12155. key:
  12156. description: |-
  12157. A key in the referenced Secret.
  12158. Some instances of this field may be defaulted, in others it may be required.
  12159. maxLength: 253
  12160. minLength: 1
  12161. pattern: ^[-._a-zA-Z0-9]+$
  12162. type: string
  12163. name:
  12164. description: The name of the Secret resource being referred to.
  12165. maxLength: 253
  12166. minLength: 1
  12167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12168. type: string
  12169. namespace:
  12170. description: |-
  12171. The namespace of the Secret resource being referred to.
  12172. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12173. maxLength: 63
  12174. minLength: 1
  12175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12176. type: string
  12177. type: object
  12178. value:
  12179. description: Value can be specified directly to set a value without using a secret.
  12180. type: string
  12181. type: object
  12182. required:
  12183. - accessKey
  12184. - projectId
  12185. - region
  12186. - secretKey
  12187. type: object
  12188. secretserver:
  12189. description: |-
  12190. SecretServer configures this store to sync secrets using SecretServer provider
  12191. https://docs.delinea.com/online-help/secret-server/start.htm
  12192. properties:
  12193. password:
  12194. description: Password is the secret server account password.
  12195. properties:
  12196. secretRef:
  12197. description: SecretRef references a key in a secret that will be used as value.
  12198. properties:
  12199. key:
  12200. description: |-
  12201. A key in the referenced Secret.
  12202. Some instances of this field may be defaulted, in others it may be required.
  12203. maxLength: 253
  12204. minLength: 1
  12205. pattern: ^[-._a-zA-Z0-9]+$
  12206. type: string
  12207. name:
  12208. description: The name of the Secret resource being referred to.
  12209. maxLength: 253
  12210. minLength: 1
  12211. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12212. type: string
  12213. namespace:
  12214. description: |-
  12215. The namespace of the Secret resource being referred to.
  12216. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12217. maxLength: 63
  12218. minLength: 1
  12219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12220. type: string
  12221. type: object
  12222. value:
  12223. description: Value can be specified directly to set a value without using a secret.
  12224. type: string
  12225. type: object
  12226. serverURL:
  12227. description: |-
  12228. ServerURL
  12229. URL to your secret server installation
  12230. type: string
  12231. username:
  12232. description: Username is the secret server account username.
  12233. properties:
  12234. secretRef:
  12235. description: SecretRef references a key in a secret that will be used as value.
  12236. properties:
  12237. key:
  12238. description: |-
  12239. A key in the referenced Secret.
  12240. Some instances of this field may be defaulted, in others it may be required.
  12241. maxLength: 253
  12242. minLength: 1
  12243. pattern: ^[-._a-zA-Z0-9]+$
  12244. type: string
  12245. name:
  12246. description: The name of the Secret resource being referred to.
  12247. maxLength: 253
  12248. minLength: 1
  12249. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12250. type: string
  12251. namespace:
  12252. description: |-
  12253. The namespace of the Secret resource being referred to.
  12254. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12255. maxLength: 63
  12256. minLength: 1
  12257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12258. type: string
  12259. type: object
  12260. value:
  12261. description: Value can be specified directly to set a value without using a secret.
  12262. type: string
  12263. type: object
  12264. required:
  12265. - password
  12266. - serverURL
  12267. - username
  12268. type: object
  12269. senhasegura:
  12270. description: Senhasegura configures this store to sync secrets using senhasegura provider
  12271. properties:
  12272. auth:
  12273. description: Auth defines parameters to authenticate in senhasegura
  12274. properties:
  12275. clientId:
  12276. type: string
  12277. clientSecretSecretRef:
  12278. description: |-
  12279. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  12280. In some instances, `key` is a required field.
  12281. properties:
  12282. key:
  12283. description: |-
  12284. A key in the referenced Secret.
  12285. Some instances of this field may be defaulted, in others it may be required.
  12286. maxLength: 253
  12287. minLength: 1
  12288. pattern: ^[-._a-zA-Z0-9]+$
  12289. type: string
  12290. name:
  12291. description: The name of the Secret resource being referred to.
  12292. maxLength: 253
  12293. minLength: 1
  12294. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12295. type: string
  12296. namespace:
  12297. description: |-
  12298. The namespace of the Secret resource being referred to.
  12299. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12300. maxLength: 63
  12301. minLength: 1
  12302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12303. type: string
  12304. type: object
  12305. required:
  12306. - clientId
  12307. - clientSecretSecretRef
  12308. type: object
  12309. ignoreSslCertificate:
  12310. default: false
  12311. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  12312. type: boolean
  12313. module:
  12314. description: Module defines which senhasegura module should be used to get secrets
  12315. type: string
  12316. url:
  12317. description: URL of senhasegura
  12318. type: string
  12319. required:
  12320. - auth
  12321. - module
  12322. - url
  12323. type: object
  12324. vault:
  12325. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  12326. properties:
  12327. auth:
  12328. description: Auth configures how secret-manager authenticates with the Vault server.
  12329. properties:
  12330. appRole:
  12331. description: |-
  12332. AppRole authenticates with Vault using the App Role auth mechanism,
  12333. with the role and secret stored in a Kubernetes Secret resource.
  12334. properties:
  12335. path:
  12336. default: approle
  12337. description: |-
  12338. Path where the App Role authentication backend is mounted
  12339. in Vault, e.g: "approle"
  12340. type: string
  12341. roleId:
  12342. description: |-
  12343. RoleID configured in the App Role authentication backend when setting
  12344. up the authentication backend in Vault.
  12345. type: string
  12346. roleRef:
  12347. description: |-
  12348. Reference to a key in a Secret that contains the App Role ID used
  12349. to authenticate with Vault.
  12350. The `key` field must be specified and denotes which entry within the Secret
  12351. resource is used as the app role id.
  12352. properties:
  12353. key:
  12354. description: |-
  12355. A key in the referenced Secret.
  12356. Some instances of this field may be defaulted, in others it may be required.
  12357. maxLength: 253
  12358. minLength: 1
  12359. pattern: ^[-._a-zA-Z0-9]+$
  12360. type: string
  12361. name:
  12362. description: The name of the Secret resource being referred to.
  12363. maxLength: 253
  12364. minLength: 1
  12365. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12366. type: string
  12367. namespace:
  12368. description: |-
  12369. The namespace of the Secret resource being referred to.
  12370. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12371. maxLength: 63
  12372. minLength: 1
  12373. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12374. type: string
  12375. type: object
  12376. secretRef:
  12377. description: |-
  12378. Reference to a key in a Secret that contains the App Role secret used
  12379. to authenticate with Vault.
  12380. The `key` field must be specified and denotes which entry within the Secret
  12381. resource is used as the app role secret.
  12382. properties:
  12383. key:
  12384. description: |-
  12385. A key in the referenced Secret.
  12386. Some instances of this field may be defaulted, in others it may be required.
  12387. maxLength: 253
  12388. minLength: 1
  12389. pattern: ^[-._a-zA-Z0-9]+$
  12390. type: string
  12391. name:
  12392. description: The name of the Secret resource being referred to.
  12393. maxLength: 253
  12394. minLength: 1
  12395. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12396. type: string
  12397. namespace:
  12398. description: |-
  12399. The namespace of the Secret resource being referred to.
  12400. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12401. maxLength: 63
  12402. minLength: 1
  12403. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12404. type: string
  12405. type: object
  12406. required:
  12407. - path
  12408. - secretRef
  12409. type: object
  12410. cert:
  12411. description: |-
  12412. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  12413. Cert authentication method
  12414. properties:
  12415. clientCert:
  12416. description: |-
  12417. ClientCert is a certificate to authenticate using the Cert Vault
  12418. authentication method
  12419. properties:
  12420. key:
  12421. description: |-
  12422. A key in the referenced Secret.
  12423. Some instances of this field may be defaulted, in others it may be required.
  12424. maxLength: 253
  12425. minLength: 1
  12426. pattern: ^[-._a-zA-Z0-9]+$
  12427. type: string
  12428. name:
  12429. description: The name of the Secret resource being referred to.
  12430. maxLength: 253
  12431. minLength: 1
  12432. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12433. type: string
  12434. namespace:
  12435. description: |-
  12436. The namespace of the Secret resource being referred to.
  12437. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12438. maxLength: 63
  12439. minLength: 1
  12440. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12441. type: string
  12442. type: object
  12443. secretRef:
  12444. description: |-
  12445. SecretRef to a key in a Secret resource containing client private key to
  12446. authenticate with Vault using the Cert authentication method
  12447. properties:
  12448. key:
  12449. description: |-
  12450. A key in the referenced Secret.
  12451. Some instances of this field may be defaulted, in others it may be required.
  12452. maxLength: 253
  12453. minLength: 1
  12454. pattern: ^[-._a-zA-Z0-9]+$
  12455. type: string
  12456. name:
  12457. description: The name of the Secret resource being referred to.
  12458. maxLength: 253
  12459. minLength: 1
  12460. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12461. type: string
  12462. namespace:
  12463. description: |-
  12464. The namespace of the Secret resource being referred to.
  12465. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12466. maxLength: 63
  12467. minLength: 1
  12468. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12469. type: string
  12470. type: object
  12471. type: object
  12472. iam:
  12473. description: |-
  12474. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  12475. AWS IAM authentication method
  12476. properties:
  12477. externalID:
  12478. description: AWS External ID set on assumed IAM roles
  12479. type: string
  12480. jwt:
  12481. description: Specify a service account with IRSA enabled
  12482. properties:
  12483. serviceAccountRef:
  12484. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  12485. properties:
  12486. audiences:
  12487. description: |-
  12488. Audience specifies the `aud` claim for the service account token
  12489. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12490. then this audiences will be appended to the list
  12491. items:
  12492. type: string
  12493. type: array
  12494. name:
  12495. description: The name of the ServiceAccount resource being referred to.
  12496. maxLength: 253
  12497. minLength: 1
  12498. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12499. type: string
  12500. namespace:
  12501. description: |-
  12502. Namespace of the resource being referred to.
  12503. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12504. maxLength: 63
  12505. minLength: 1
  12506. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12507. type: string
  12508. required:
  12509. - name
  12510. type: object
  12511. type: object
  12512. path:
  12513. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  12514. type: string
  12515. region:
  12516. description: AWS region
  12517. type: string
  12518. role:
  12519. description: This is the AWS role to be assumed before talking to vault
  12520. type: string
  12521. secretRef:
  12522. description: Specify credentials in a Secret object
  12523. properties:
  12524. accessKeyIDSecretRef:
  12525. description: The AccessKeyID is used for authentication
  12526. properties:
  12527. key:
  12528. description: |-
  12529. A key in the referenced Secret.
  12530. Some instances of this field may be defaulted, in others it may be required.
  12531. maxLength: 253
  12532. minLength: 1
  12533. pattern: ^[-._a-zA-Z0-9]+$
  12534. type: string
  12535. name:
  12536. description: The name of the Secret resource being referred to.
  12537. maxLength: 253
  12538. minLength: 1
  12539. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12540. type: string
  12541. namespace:
  12542. description: |-
  12543. The namespace of the Secret resource being referred to.
  12544. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12545. maxLength: 63
  12546. minLength: 1
  12547. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12548. type: string
  12549. type: object
  12550. secretAccessKeySecretRef:
  12551. description: The SecretAccessKey is used for authentication
  12552. properties:
  12553. key:
  12554. description: |-
  12555. A key in the referenced Secret.
  12556. Some instances of this field may be defaulted, in others it may be required.
  12557. maxLength: 253
  12558. minLength: 1
  12559. pattern: ^[-._a-zA-Z0-9]+$
  12560. type: string
  12561. name:
  12562. description: The name of the Secret resource being referred to.
  12563. maxLength: 253
  12564. minLength: 1
  12565. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12566. type: string
  12567. namespace:
  12568. description: |-
  12569. The namespace of the Secret resource being referred to.
  12570. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12571. maxLength: 63
  12572. minLength: 1
  12573. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12574. type: string
  12575. type: object
  12576. sessionTokenSecretRef:
  12577. description: |-
  12578. The SessionToken used for authentication
  12579. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  12580. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  12581. properties:
  12582. key:
  12583. description: |-
  12584. A key in the referenced Secret.
  12585. Some instances of this field may be defaulted, in others it may be required.
  12586. maxLength: 253
  12587. minLength: 1
  12588. pattern: ^[-._a-zA-Z0-9]+$
  12589. type: string
  12590. name:
  12591. description: The name of the Secret resource being referred to.
  12592. maxLength: 253
  12593. minLength: 1
  12594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12595. type: string
  12596. namespace:
  12597. description: |-
  12598. The namespace of the Secret resource being referred to.
  12599. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12600. maxLength: 63
  12601. minLength: 1
  12602. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12603. type: string
  12604. type: object
  12605. type: object
  12606. vaultAwsIamServerID:
  12607. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  12608. type: string
  12609. vaultRole:
  12610. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  12611. type: string
  12612. required:
  12613. - vaultRole
  12614. type: object
  12615. jwt:
  12616. description: |-
  12617. Jwt authenticates with Vault by passing role and JWT token using the
  12618. JWT/OIDC authentication method
  12619. properties:
  12620. kubernetesServiceAccountToken:
  12621. description: |-
  12622. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  12623. a token for with the `TokenRequest` API.
  12624. properties:
  12625. audiences:
  12626. description: |-
  12627. Optional audiences field that will be used to request a temporary Kubernetes service
  12628. account token for the service account referenced by `serviceAccountRef`.
  12629. Defaults to a single audience `vault` it not specified.
  12630. Deprecated: use serviceAccountRef.Audiences instead
  12631. items:
  12632. type: string
  12633. type: array
  12634. expirationSeconds:
  12635. description: |-
  12636. Optional expiration time in seconds that will be used to request a temporary
  12637. Kubernetes service account token for the service account referenced by
  12638. `serviceAccountRef`.
  12639. Deprecated: this will be removed in the future.
  12640. Defaults to 10 minutes.
  12641. format: int64
  12642. type: integer
  12643. serviceAccountRef:
  12644. description: Service account field containing the name of a kubernetes ServiceAccount.
  12645. properties:
  12646. audiences:
  12647. description: |-
  12648. Audience specifies the `aud` claim for the service account token
  12649. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12650. then this audiences will be appended to the list
  12651. items:
  12652. type: string
  12653. type: array
  12654. name:
  12655. description: The name of the ServiceAccount resource being referred to.
  12656. maxLength: 253
  12657. minLength: 1
  12658. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12659. type: string
  12660. namespace:
  12661. description: |-
  12662. Namespace of the resource being referred to.
  12663. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12664. maxLength: 63
  12665. minLength: 1
  12666. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12667. type: string
  12668. required:
  12669. - name
  12670. type: object
  12671. required:
  12672. - serviceAccountRef
  12673. type: object
  12674. path:
  12675. default: jwt
  12676. description: |-
  12677. Path where the JWT authentication backend is mounted
  12678. in Vault, e.g: "jwt"
  12679. type: string
  12680. role:
  12681. description: |-
  12682. Role is a JWT role to authenticate using the JWT/OIDC Vault
  12683. authentication method
  12684. type: string
  12685. secretRef:
  12686. description: |-
  12687. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  12688. authenticate with Vault using the JWT/OIDC authentication method.
  12689. properties:
  12690. key:
  12691. description: |-
  12692. A key in the referenced Secret.
  12693. Some instances of this field may be defaulted, in others it may be required.
  12694. maxLength: 253
  12695. minLength: 1
  12696. pattern: ^[-._a-zA-Z0-9]+$
  12697. type: string
  12698. name:
  12699. description: The name of the Secret resource being referred to.
  12700. maxLength: 253
  12701. minLength: 1
  12702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12703. type: string
  12704. namespace:
  12705. description: |-
  12706. The namespace of the Secret resource being referred to.
  12707. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12708. maxLength: 63
  12709. minLength: 1
  12710. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12711. type: string
  12712. type: object
  12713. required:
  12714. - path
  12715. type: object
  12716. kubernetes:
  12717. description: |-
  12718. Kubernetes authenticates with Vault by passing the ServiceAccount
  12719. token stored in the named Secret resource to the Vault server.
  12720. properties:
  12721. mountPath:
  12722. default: kubernetes
  12723. description: |-
  12724. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  12725. "kubernetes"
  12726. type: string
  12727. role:
  12728. description: |-
  12729. A required field containing the Vault Role to assume. A Role binds a
  12730. Kubernetes ServiceAccount with a set of Vault policies.
  12731. type: string
  12732. secretRef:
  12733. description: |-
  12734. Optional secret field containing a Kubernetes ServiceAccount JWT used
  12735. for authenticating with Vault. If a name is specified without a key,
  12736. `token` is the default. If one is not specified, the one bound to
  12737. the controller will be used.
  12738. properties:
  12739. key:
  12740. description: |-
  12741. A key in the referenced Secret.
  12742. Some instances of this field may be defaulted, in others it may be required.
  12743. maxLength: 253
  12744. minLength: 1
  12745. pattern: ^[-._a-zA-Z0-9]+$
  12746. type: string
  12747. name:
  12748. description: The name of the Secret resource being referred to.
  12749. maxLength: 253
  12750. minLength: 1
  12751. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12752. type: string
  12753. namespace:
  12754. description: |-
  12755. The namespace of the Secret resource being referred to.
  12756. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12757. maxLength: 63
  12758. minLength: 1
  12759. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12760. type: string
  12761. type: object
  12762. serviceAccountRef:
  12763. description: |-
  12764. Optional service account field containing the name of a kubernetes ServiceAccount.
  12765. If the service account is specified, the service account secret token JWT will be used
  12766. for authenticating with Vault. If the service account selector is not supplied,
  12767. the secretRef will be used instead.
  12768. properties:
  12769. audiences:
  12770. description: |-
  12771. Audience specifies the `aud` claim for the service account token
  12772. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12773. then this audiences will be appended to the list
  12774. items:
  12775. type: string
  12776. type: array
  12777. name:
  12778. description: The name of the ServiceAccount resource being referred to.
  12779. maxLength: 253
  12780. minLength: 1
  12781. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12782. type: string
  12783. namespace:
  12784. description: |-
  12785. Namespace of the resource being referred to.
  12786. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12787. maxLength: 63
  12788. minLength: 1
  12789. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12790. type: string
  12791. required:
  12792. - name
  12793. type: object
  12794. required:
  12795. - mountPath
  12796. - role
  12797. type: object
  12798. ldap:
  12799. description: |-
  12800. Ldap authenticates with Vault by passing username/password pair using
  12801. the LDAP authentication method
  12802. properties:
  12803. path:
  12804. default: ldap
  12805. description: |-
  12806. Path where the LDAP authentication backend is mounted
  12807. in Vault, e.g: "ldap"
  12808. type: string
  12809. secretRef:
  12810. description: |-
  12811. SecretRef to a key in a Secret resource containing password for the LDAP
  12812. user used to authenticate with Vault using the LDAP authentication
  12813. method
  12814. properties:
  12815. key:
  12816. description: |-
  12817. A key in the referenced Secret.
  12818. Some instances of this field may be defaulted, in others it may be required.
  12819. maxLength: 253
  12820. minLength: 1
  12821. pattern: ^[-._a-zA-Z0-9]+$
  12822. type: string
  12823. name:
  12824. description: The name of the Secret resource being referred to.
  12825. maxLength: 253
  12826. minLength: 1
  12827. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12828. type: string
  12829. namespace:
  12830. description: |-
  12831. The namespace of the Secret resource being referred to.
  12832. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12833. maxLength: 63
  12834. minLength: 1
  12835. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12836. type: string
  12837. type: object
  12838. username:
  12839. description: |-
  12840. Username is an LDAP username used to authenticate using the LDAP Vault
  12841. authentication method
  12842. type: string
  12843. required:
  12844. - path
  12845. - username
  12846. type: object
  12847. namespace:
  12848. description: |-
  12849. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  12850. Namespaces is a set of features within Vault Enterprise that allows
  12851. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  12852. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  12853. This will default to Vault.Namespace field if set, or empty otherwise
  12854. type: string
  12855. tokenSecretRef:
  12856. description: TokenSecretRef authenticates with Vault by presenting a token.
  12857. properties:
  12858. key:
  12859. description: |-
  12860. A key in the referenced Secret.
  12861. Some instances of this field may be defaulted, in others it may be required.
  12862. maxLength: 253
  12863. minLength: 1
  12864. pattern: ^[-._a-zA-Z0-9]+$
  12865. type: string
  12866. name:
  12867. description: The name of the Secret resource being referred to.
  12868. maxLength: 253
  12869. minLength: 1
  12870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12871. type: string
  12872. namespace:
  12873. description: |-
  12874. The namespace of the Secret resource being referred to.
  12875. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12876. maxLength: 63
  12877. minLength: 1
  12878. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12879. type: string
  12880. type: object
  12881. userPass:
  12882. description: UserPass authenticates with Vault by passing username/password pair
  12883. properties:
  12884. path:
  12885. default: userpass
  12886. description: |-
  12887. Path where the UserPassword authentication backend is mounted
  12888. in Vault, e.g: "userpass"
  12889. type: string
  12890. secretRef:
  12891. description: |-
  12892. SecretRef to a key in a Secret resource containing password for the
  12893. user used to authenticate with Vault using the UserPass authentication
  12894. method
  12895. properties:
  12896. key:
  12897. description: |-
  12898. A key in the referenced Secret.
  12899. Some instances of this field may be defaulted, in others it may be required.
  12900. maxLength: 253
  12901. minLength: 1
  12902. pattern: ^[-._a-zA-Z0-9]+$
  12903. type: string
  12904. name:
  12905. description: The name of the Secret resource being referred to.
  12906. maxLength: 253
  12907. minLength: 1
  12908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12909. type: string
  12910. namespace:
  12911. description: |-
  12912. The namespace of the Secret resource being referred to.
  12913. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12914. maxLength: 63
  12915. minLength: 1
  12916. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12917. type: string
  12918. type: object
  12919. username:
  12920. description: |-
  12921. Username is a username used to authenticate using the UserPass Vault
  12922. authentication method
  12923. type: string
  12924. required:
  12925. - path
  12926. - username
  12927. type: object
  12928. type: object
  12929. caBundle:
  12930. description: |-
  12931. PEM encoded CA bundle used to validate Vault server certificate. Only used
  12932. if the Server URL is using HTTPS protocol. This parameter is ignored for
  12933. plain HTTP protocol connection. If not set the system root certificates
  12934. are used to validate the TLS connection.
  12935. format: byte
  12936. type: string
  12937. caProvider:
  12938. description: The provider for the CA bundle to use to validate Vault server certificate.
  12939. properties:
  12940. key:
  12941. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  12942. maxLength: 253
  12943. minLength: 1
  12944. pattern: ^[-._a-zA-Z0-9]+$
  12945. type: string
  12946. name:
  12947. description: The name of the object located at the provider type.
  12948. maxLength: 253
  12949. minLength: 1
  12950. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12951. type: string
  12952. namespace:
  12953. description: |-
  12954. The namespace the Provider type is in.
  12955. Can only be defined when used in a ClusterSecretStore.
  12956. maxLength: 63
  12957. minLength: 1
  12958. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12959. type: string
  12960. type:
  12961. description: The type of provider to use such as "Secret", or "ConfigMap".
  12962. enum:
  12963. - Secret
  12964. - ConfigMap
  12965. type: string
  12966. required:
  12967. - name
  12968. - type
  12969. type: object
  12970. forwardInconsistent:
  12971. description: |-
  12972. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  12973. leader instead of simply retrying within a loop. This can increase performance if
  12974. the option is enabled serverside.
  12975. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  12976. type: boolean
  12977. headers:
  12978. additionalProperties:
  12979. type: string
  12980. description: Headers to be added in Vault request
  12981. type: object
  12982. namespace:
  12983. description: |-
  12984. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  12985. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  12986. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  12987. type: string
  12988. path:
  12989. description: |-
  12990. Path is the mount path of the Vault KV backend endpoint, e.g:
  12991. "secret". The v2 KV secret engine version specific "/data" path suffix
  12992. for fetching secrets from Vault is optional and will be appended
  12993. if not present in specified path.
  12994. type: string
  12995. readYourWrites:
  12996. description: |-
  12997. ReadYourWrites ensures isolated read-after-write semantics by
  12998. providing discovered cluster replication states in each request.
  12999. More information about eventual consistency in Vault can be found here
  13000. https://www.vaultproject.io/docs/enterprise/consistency
  13001. type: boolean
  13002. server:
  13003. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  13004. type: string
  13005. tls:
  13006. description: |-
  13007. The configuration used for client side related TLS communication, when the Vault server
  13008. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  13009. This parameter is ignored for plain HTTP protocol connection.
  13010. It's worth noting this configuration is different from the "TLS certificates auth method",
  13011. which is available under the `auth.cert` section.
  13012. properties:
  13013. certSecretRef:
  13014. description: |-
  13015. CertSecretRef is a certificate added to the transport layer
  13016. when communicating with the Vault server.
  13017. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  13018. properties:
  13019. key:
  13020. description: |-
  13021. A key in the referenced Secret.
  13022. Some instances of this field may be defaulted, in others it may be required.
  13023. maxLength: 253
  13024. minLength: 1
  13025. pattern: ^[-._a-zA-Z0-9]+$
  13026. type: string
  13027. name:
  13028. description: The name of the Secret resource being referred to.
  13029. maxLength: 253
  13030. minLength: 1
  13031. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13032. type: string
  13033. namespace:
  13034. description: |-
  13035. The namespace of the Secret resource being referred to.
  13036. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13037. maxLength: 63
  13038. minLength: 1
  13039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13040. type: string
  13041. type: object
  13042. keySecretRef:
  13043. description: |-
  13044. KeySecretRef to a key in a Secret resource containing client private key
  13045. added to the transport layer when communicating with the Vault server.
  13046. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  13047. properties:
  13048. key:
  13049. description: |-
  13050. A key in the referenced Secret.
  13051. Some instances of this field may be defaulted, in others it may be required.
  13052. maxLength: 253
  13053. minLength: 1
  13054. pattern: ^[-._a-zA-Z0-9]+$
  13055. type: string
  13056. name:
  13057. description: The name of the Secret resource being referred to.
  13058. maxLength: 253
  13059. minLength: 1
  13060. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13061. type: string
  13062. namespace:
  13063. description: |-
  13064. The namespace of the Secret resource being referred to.
  13065. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13066. maxLength: 63
  13067. minLength: 1
  13068. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13069. type: string
  13070. type: object
  13071. type: object
  13072. version:
  13073. default: v2
  13074. description: |-
  13075. Version is the Vault KV secret engine version. This can be either "v1" or
  13076. "v2". Version defaults to "v2".
  13077. enum:
  13078. - v1
  13079. - v2
  13080. type: string
  13081. required:
  13082. - server
  13083. type: object
  13084. webhook:
  13085. description: Webhook configures this store to sync secrets using a generic templated webhook
  13086. properties:
  13087. auth:
  13088. description: Auth specifies a authorization protocol. Only one protocol may be set.
  13089. maxProperties: 1
  13090. minProperties: 1
  13091. properties:
  13092. ntlm:
  13093. description: NTLMProtocol configures the store to use NTLM for auth
  13094. properties:
  13095. passwordSecret:
  13096. description: |-
  13097. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13098. In some instances, `key` is a required field.
  13099. properties:
  13100. key:
  13101. description: |-
  13102. A key in the referenced Secret.
  13103. Some instances of this field may be defaulted, in others it may be required.
  13104. maxLength: 253
  13105. minLength: 1
  13106. pattern: ^[-._a-zA-Z0-9]+$
  13107. type: string
  13108. name:
  13109. description: The name of the Secret resource being referred to.
  13110. maxLength: 253
  13111. minLength: 1
  13112. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13113. type: string
  13114. namespace:
  13115. description: |-
  13116. The namespace of the Secret resource being referred to.
  13117. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13118. maxLength: 63
  13119. minLength: 1
  13120. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13121. type: string
  13122. type: object
  13123. usernameSecret:
  13124. description: |-
  13125. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13126. In some instances, `key` is a required field.
  13127. properties:
  13128. key:
  13129. description: |-
  13130. A key in the referenced Secret.
  13131. Some instances of this field may be defaulted, in others it may be required.
  13132. maxLength: 253
  13133. minLength: 1
  13134. pattern: ^[-._a-zA-Z0-9]+$
  13135. type: string
  13136. name:
  13137. description: The name of the Secret resource being referred to.
  13138. maxLength: 253
  13139. minLength: 1
  13140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13141. type: string
  13142. namespace:
  13143. description: |-
  13144. The namespace of the Secret resource being referred to.
  13145. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13146. maxLength: 63
  13147. minLength: 1
  13148. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13149. type: string
  13150. type: object
  13151. required:
  13152. - passwordSecret
  13153. - usernameSecret
  13154. type: object
  13155. type: object
  13156. body:
  13157. description: Body
  13158. type: string
  13159. caBundle:
  13160. description: |-
  13161. PEM encoded CA bundle used to validate webhook server certificate. Only used
  13162. if the Server URL is using HTTPS protocol. This parameter is ignored for
  13163. plain HTTP protocol connection. If not set the system root certificates
  13164. are used to validate the TLS connection.
  13165. format: byte
  13166. type: string
  13167. caProvider:
  13168. description: The provider for the CA bundle to use to validate webhook server certificate.
  13169. properties:
  13170. key:
  13171. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  13172. maxLength: 253
  13173. minLength: 1
  13174. pattern: ^[-._a-zA-Z0-9]+$
  13175. type: string
  13176. name:
  13177. description: The name of the object located at the provider type.
  13178. maxLength: 253
  13179. minLength: 1
  13180. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13181. type: string
  13182. namespace:
  13183. description: The namespace the Provider type is in.
  13184. maxLength: 63
  13185. minLength: 1
  13186. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13187. type: string
  13188. type:
  13189. description: The type of provider to use such as "Secret", or "ConfigMap".
  13190. enum:
  13191. - Secret
  13192. - ConfigMap
  13193. type: string
  13194. required:
  13195. - name
  13196. - type
  13197. type: object
  13198. headers:
  13199. additionalProperties:
  13200. type: string
  13201. description: Headers
  13202. type: object
  13203. method:
  13204. description: Webhook Method
  13205. type: string
  13206. result:
  13207. description: Result formatting
  13208. properties:
  13209. jsonPath:
  13210. description: Json path of return value
  13211. type: string
  13212. type: object
  13213. secrets:
  13214. description: |-
  13215. Secrets to fill in templates
  13216. These secrets will be passed to the templating function as key value pairs under the given name
  13217. items:
  13218. description: WebhookSecret defines a secret to be used in webhook templates.
  13219. properties:
  13220. name:
  13221. description: Name of this secret in templates
  13222. type: string
  13223. secretRef:
  13224. description: Secret ref to fill in credentials
  13225. properties:
  13226. key:
  13227. description: |-
  13228. A key in the referenced Secret.
  13229. Some instances of this field may be defaulted, in others it may be required.
  13230. maxLength: 253
  13231. minLength: 1
  13232. pattern: ^[-._a-zA-Z0-9]+$
  13233. type: string
  13234. name:
  13235. description: The name of the Secret resource being referred to.
  13236. maxLength: 253
  13237. minLength: 1
  13238. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13239. type: string
  13240. namespace:
  13241. description: |-
  13242. The namespace of the Secret resource being referred to.
  13243. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13244. maxLength: 63
  13245. minLength: 1
  13246. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13247. type: string
  13248. type: object
  13249. required:
  13250. - name
  13251. - secretRef
  13252. type: object
  13253. type: array
  13254. timeout:
  13255. description: Timeout
  13256. type: string
  13257. url:
  13258. description: Webhook url to call
  13259. type: string
  13260. required:
  13261. - result
  13262. - url
  13263. type: object
  13264. yandexcertificatemanager:
  13265. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  13266. properties:
  13267. apiEndpoint:
  13268. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13269. type: string
  13270. auth:
  13271. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  13272. properties:
  13273. authorizedKeySecretRef:
  13274. description: The authorized key used for authentication
  13275. properties:
  13276. key:
  13277. description: |-
  13278. A key in the referenced Secret.
  13279. Some instances of this field may be defaulted, in others it may be required.
  13280. maxLength: 253
  13281. minLength: 1
  13282. pattern: ^[-._a-zA-Z0-9]+$
  13283. type: string
  13284. name:
  13285. description: The name of the Secret resource being referred to.
  13286. maxLength: 253
  13287. minLength: 1
  13288. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13289. type: string
  13290. namespace:
  13291. description: |-
  13292. The namespace of the Secret resource being referred to.
  13293. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13294. maxLength: 63
  13295. minLength: 1
  13296. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13297. type: string
  13298. type: object
  13299. type: object
  13300. caProvider:
  13301. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13302. properties:
  13303. certSecretRef:
  13304. description: |-
  13305. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13306. In some instances, `key` is a required field.
  13307. properties:
  13308. key:
  13309. description: |-
  13310. A key in the referenced Secret.
  13311. Some instances of this field may be defaulted, in others it may be required.
  13312. maxLength: 253
  13313. minLength: 1
  13314. pattern: ^[-._a-zA-Z0-9]+$
  13315. type: string
  13316. name:
  13317. description: The name of the Secret resource being referred to.
  13318. maxLength: 253
  13319. minLength: 1
  13320. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13321. type: string
  13322. namespace:
  13323. description: |-
  13324. The namespace of the Secret resource being referred to.
  13325. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13326. maxLength: 63
  13327. minLength: 1
  13328. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13329. type: string
  13330. type: object
  13331. type: object
  13332. required:
  13333. - auth
  13334. type: object
  13335. yandexlockbox:
  13336. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  13337. properties:
  13338. apiEndpoint:
  13339. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13340. type: string
  13341. auth:
  13342. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  13343. properties:
  13344. authorizedKeySecretRef:
  13345. description: The authorized key used for authentication
  13346. properties:
  13347. key:
  13348. description: |-
  13349. A key in the referenced Secret.
  13350. Some instances of this field may be defaulted, in others it may be required.
  13351. maxLength: 253
  13352. minLength: 1
  13353. pattern: ^[-._a-zA-Z0-9]+$
  13354. type: string
  13355. name:
  13356. description: The name of the Secret resource being referred to.
  13357. maxLength: 253
  13358. minLength: 1
  13359. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13360. type: string
  13361. namespace:
  13362. description: |-
  13363. The namespace of the Secret resource being referred to.
  13364. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13365. maxLength: 63
  13366. minLength: 1
  13367. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13368. type: string
  13369. type: object
  13370. type: object
  13371. caProvider:
  13372. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13373. properties:
  13374. certSecretRef:
  13375. description: |-
  13376. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13377. In some instances, `key` is a required field.
  13378. properties:
  13379. key:
  13380. description: |-
  13381. A key in the referenced Secret.
  13382. Some instances of this field may be defaulted, in others it may be required.
  13383. maxLength: 253
  13384. minLength: 1
  13385. pattern: ^[-._a-zA-Z0-9]+$
  13386. type: string
  13387. name:
  13388. description: The name of the Secret resource being referred to.
  13389. maxLength: 253
  13390. minLength: 1
  13391. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13392. type: string
  13393. namespace:
  13394. description: |-
  13395. The namespace of the Secret resource being referred to.
  13396. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13397. maxLength: 63
  13398. minLength: 1
  13399. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13400. type: string
  13401. type: object
  13402. type: object
  13403. required:
  13404. - auth
  13405. type: object
  13406. type: object
  13407. refreshInterval:
  13408. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  13409. type: integer
  13410. retrySettings:
  13411. description: Used to configure HTTP retries on failures.
  13412. properties:
  13413. maxRetries:
  13414. description: MaxRetries is the maximum number of retry attempts.
  13415. format: int32
  13416. type: integer
  13417. retryInterval:
  13418. description: RetryInterval is the interval between retry attempts.
  13419. type: string
  13420. type: object
  13421. required:
  13422. - provider
  13423. type: object
  13424. status:
  13425. description: SecretStoreStatus defines the observed state of the SecretStore.
  13426. properties:
  13427. capabilities:
  13428. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  13429. type: string
  13430. conditions:
  13431. items:
  13432. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  13433. properties:
  13434. lastTransitionTime:
  13435. format: date-time
  13436. type: string
  13437. message:
  13438. type: string
  13439. reason:
  13440. type: string
  13441. status:
  13442. type: string
  13443. type:
  13444. description: SecretStoreConditionType represents the condition type of the SecretStore.
  13445. type: string
  13446. required:
  13447. - status
  13448. - type
  13449. type: object
  13450. type: array
  13451. type: object
  13452. type: object
  13453. served: false
  13454. storage: false
  13455. subresources:
  13456. status: {}
  13457. ---
  13458. apiVersion: apiextensions.k8s.io/v1
  13459. kind: CustomResourceDefinition
  13460. metadata:
  13461. annotations:
  13462. controller-gen.kubebuilder.io/version: v0.19.0
  13463. labels:
  13464. external-secrets.io/component: controller
  13465. name: externalsecrets.external-secrets.io
  13466. spec:
  13467. group: external-secrets.io
  13468. names:
  13469. categories:
  13470. - external-secrets
  13471. kind: ExternalSecret
  13472. listKind: ExternalSecretList
  13473. plural: externalsecrets
  13474. shortNames:
  13475. - es
  13476. singular: externalsecret
  13477. scope: Namespaced
  13478. versions:
  13479. - additionalPrinterColumns:
  13480. - jsonPath: .spec.secretStoreRef.kind
  13481. name: StoreType
  13482. type: string
  13483. - jsonPath: .spec.secretStoreRef.name
  13484. name: Store
  13485. type: string
  13486. - jsonPath: .spec.refreshInterval
  13487. name: Refresh Interval
  13488. type: string
  13489. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  13490. name: Status
  13491. type: string
  13492. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  13493. name: Ready
  13494. type: string
  13495. - jsonPath: .status.refreshTime
  13496. name: Last Sync
  13497. type: date
  13498. name: v1
  13499. schema:
  13500. openAPIV3Schema:
  13501. description: |-
  13502. ExternalSecret is the Schema for the external-secrets API.
  13503. It defines how to fetch data from external APIs and make it available as Kubernetes Secrets.
  13504. properties:
  13505. apiVersion:
  13506. description: |-
  13507. APIVersion defines the versioned schema of this representation of an object.
  13508. Servers should convert recognized schemas to the latest internal value, and
  13509. may reject unrecognized values.
  13510. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  13511. type: string
  13512. kind:
  13513. description: |-
  13514. Kind is a string value representing the REST resource this object represents.
  13515. Servers may infer this from the endpoint the client submits requests to.
  13516. Cannot be updated.
  13517. In CamelCase.
  13518. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  13519. type: string
  13520. metadata:
  13521. type: object
  13522. spec:
  13523. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  13524. properties:
  13525. data:
  13526. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  13527. items:
  13528. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  13529. properties:
  13530. remoteRef:
  13531. description: |-
  13532. RemoteRef points to the remote secret and defines
  13533. which secret (version/property/..) to fetch.
  13534. properties:
  13535. conversionStrategy:
  13536. default: Default
  13537. description: Used to define a conversion Strategy
  13538. enum:
  13539. - Default
  13540. - Unicode
  13541. type: string
  13542. decodingStrategy:
  13543. default: None
  13544. description: Used to define a decoding Strategy
  13545. enum:
  13546. - Auto
  13547. - Base64
  13548. - Base64URL
  13549. - None
  13550. type: string
  13551. key:
  13552. description: Key is the key used in the Provider, mandatory
  13553. type: string
  13554. metadataPolicy:
  13555. default: None
  13556. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13557. enum:
  13558. - None
  13559. - Fetch
  13560. type: string
  13561. nullBytePolicy:
  13562. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13563. enum:
  13564. - Ignore
  13565. - Fail
  13566. type: string
  13567. property:
  13568. description: Used to select a specific property of the Provider value (if a map), if supported
  13569. type: string
  13570. version:
  13571. description: Used to select a specific version of the Provider value, if supported
  13572. type: string
  13573. required:
  13574. - key
  13575. type: object
  13576. secretKey:
  13577. description: The key in the Kubernetes Secret to store the value.
  13578. maxLength: 253
  13579. minLength: 1
  13580. pattern: ^[-._a-zA-Z0-9]+$
  13581. type: string
  13582. sourceRef:
  13583. description: |-
  13584. SourceRef allows you to override the source
  13585. from which the value will be pulled.
  13586. maxProperties: 1
  13587. minProperties: 1
  13588. properties:
  13589. generatorRef:
  13590. description: |-
  13591. GeneratorRef points to a generator custom resource.
  13592. Deprecated: The generatorRef is not implemented in .data[].
  13593. this will be removed with v1.
  13594. properties:
  13595. apiVersion:
  13596. default: generators.external-secrets.io/v1alpha1
  13597. description: Specify the apiVersion of the generator resource
  13598. type: string
  13599. kind:
  13600. description: Specify the Kind of the generator resource
  13601. enum:
  13602. - ACRAccessToken
  13603. - BeyondtrustWorkloadCredentialsDynamicSecret
  13604. - ClusterGenerator
  13605. - CloudsmithAccessToken
  13606. - ECRAuthorizationToken
  13607. - Fake
  13608. - GCRAccessToken
  13609. - GithubAccessToken
  13610. - GitlabDeployToken
  13611. - QuayAccessToken
  13612. - Password
  13613. - SSHKey
  13614. - STSSessionToken
  13615. - UUID
  13616. - VaultDynamicSecret
  13617. - Webhook
  13618. - Grafana
  13619. - MFA
  13620. type: string
  13621. name:
  13622. description: Specify the name of the generator resource
  13623. maxLength: 253
  13624. minLength: 1
  13625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13626. type: string
  13627. required:
  13628. - kind
  13629. - name
  13630. type: object
  13631. storeRef:
  13632. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13633. properties:
  13634. kind:
  13635. description: |-
  13636. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13637. Defaults to `SecretStore`
  13638. enum:
  13639. - SecretStore
  13640. - ClusterSecretStore
  13641. type: string
  13642. name:
  13643. description: Name of the SecretStore resource
  13644. maxLength: 253
  13645. minLength: 1
  13646. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13647. type: string
  13648. type: object
  13649. type: object
  13650. required:
  13651. - remoteRef
  13652. - secretKey
  13653. type: object
  13654. type: array
  13655. dataFrom:
  13656. description: |-
  13657. DataFrom is used to fetch all properties from a specific Provider data
  13658. If multiple entries are specified, the Secret keys are merged in the specified order
  13659. items:
  13660. description: |-
  13661. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  13662. when using DataFrom to fetch multiple values from a Provider.
  13663. properties:
  13664. extract:
  13665. description: |-
  13666. Used to extract multiple key/value pairs from one secret
  13667. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13668. properties:
  13669. conversionStrategy:
  13670. default: Default
  13671. description: Used to define a conversion Strategy
  13672. enum:
  13673. - Default
  13674. - Unicode
  13675. type: string
  13676. decodingStrategy:
  13677. default: None
  13678. description: Used to define a decoding Strategy
  13679. enum:
  13680. - Auto
  13681. - Base64
  13682. - Base64URL
  13683. - None
  13684. type: string
  13685. key:
  13686. description: Key is the key used in the Provider, mandatory
  13687. type: string
  13688. metadataPolicy:
  13689. default: None
  13690. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13691. enum:
  13692. - None
  13693. - Fetch
  13694. type: string
  13695. nullBytePolicy:
  13696. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13697. enum:
  13698. - Ignore
  13699. - Fail
  13700. type: string
  13701. property:
  13702. description: Used to select a specific property of the Provider value (if a map), if supported
  13703. type: string
  13704. version:
  13705. description: Used to select a specific version of the Provider value, if supported
  13706. type: string
  13707. required:
  13708. - key
  13709. type: object
  13710. find:
  13711. description: |-
  13712. Used to find secrets based on tags or regular expressions
  13713. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13714. properties:
  13715. conversionStrategy:
  13716. default: Default
  13717. description: Used to define a conversion Strategy
  13718. enum:
  13719. - Default
  13720. - Unicode
  13721. type: string
  13722. decodingStrategy:
  13723. default: None
  13724. description: Used to define a decoding Strategy
  13725. enum:
  13726. - Auto
  13727. - Base64
  13728. - Base64URL
  13729. - None
  13730. type: string
  13731. name:
  13732. description: Finds secrets based on the name.
  13733. properties:
  13734. regexp:
  13735. description: Finds secrets base
  13736. type: string
  13737. type: object
  13738. nullBytePolicy:
  13739. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  13740. enum:
  13741. - Ignore
  13742. - Fail
  13743. type: string
  13744. path:
  13745. description: A root path to start the find operations.
  13746. type: string
  13747. tags:
  13748. additionalProperties:
  13749. type: string
  13750. description: Find secrets based on tags.
  13751. type: object
  13752. type: object
  13753. rewrite:
  13754. description: |-
  13755. Used to rewrite secret Keys after getting them from the secret Provider
  13756. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  13757. items:
  13758. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  13759. maxProperties: 1
  13760. minProperties: 1
  13761. properties:
  13762. merge:
  13763. description: |-
  13764. Used to merge key/values in one single Secret
  13765. The resulting key will contain all values from the specified secrets
  13766. properties:
  13767. conflictPolicy:
  13768. default: Error
  13769. description: Used to define the policy to use in conflict resolution.
  13770. enum:
  13771. - Ignore
  13772. - Error
  13773. type: string
  13774. into:
  13775. default: ""
  13776. description: |-
  13777. Used to define the target key of the merge operation.
  13778. Required if strategy is JSON. Ignored otherwise.
  13779. type: string
  13780. priority:
  13781. description: Used to define key priority in conflict resolution.
  13782. items:
  13783. type: string
  13784. type: array
  13785. priorityPolicy:
  13786. default: Strict
  13787. description: Used to define the policy when a key in the priority list does not exist in the input.
  13788. enum:
  13789. - IgnoreNotFound
  13790. - Strict
  13791. type: string
  13792. strategy:
  13793. default: Extract
  13794. description: Used to define the strategy to use in the merge operation.
  13795. enum:
  13796. - Extract
  13797. - JSON
  13798. type: string
  13799. type: object
  13800. regexp:
  13801. description: |-
  13802. Used to rewrite with regular expressions.
  13803. The resulting key will be the output of a regexp.ReplaceAll operation.
  13804. properties:
  13805. source:
  13806. description: Used to define the regular expression of a re.Compiler.
  13807. type: string
  13808. target:
  13809. description: Used to define the target pattern of a ReplaceAll operation.
  13810. type: string
  13811. required:
  13812. - source
  13813. - target
  13814. type: object
  13815. transform:
  13816. description: |-
  13817. Used to apply string transformation on the secrets.
  13818. The resulting key will be the output of the template applied by the operation.
  13819. properties:
  13820. template:
  13821. description: |-
  13822. Used to define the template to apply on the secret name.
  13823. `.value ` will specify the secret name in the template.
  13824. type: string
  13825. required:
  13826. - template
  13827. type: object
  13828. type: object
  13829. type: array
  13830. sourceRef:
  13831. description: |-
  13832. SourceRef points to a store or generator
  13833. which contains secret values ready to use.
  13834. Use this in combination with Extract or Find pull values out of
  13835. a specific SecretStore.
  13836. When sourceRef points to a generator Extract or Find is not supported.
  13837. The generator returns a static map of values
  13838. maxProperties: 1
  13839. minProperties: 1
  13840. properties:
  13841. generatorRef:
  13842. description: GeneratorRef points to a generator custom resource.
  13843. properties:
  13844. apiVersion:
  13845. default: generators.external-secrets.io/v1alpha1
  13846. description: Specify the apiVersion of the generator resource
  13847. type: string
  13848. kind:
  13849. description: Specify the Kind of the generator resource
  13850. enum:
  13851. - ACRAccessToken
  13852. - BeyondtrustWorkloadCredentialsDynamicSecret
  13853. - ClusterGenerator
  13854. - CloudsmithAccessToken
  13855. - ECRAuthorizationToken
  13856. - Fake
  13857. - GCRAccessToken
  13858. - GithubAccessToken
  13859. - GitlabDeployToken
  13860. - QuayAccessToken
  13861. - Password
  13862. - SSHKey
  13863. - STSSessionToken
  13864. - UUID
  13865. - VaultDynamicSecret
  13866. - Webhook
  13867. - Grafana
  13868. - MFA
  13869. type: string
  13870. name:
  13871. description: Specify the name of the generator resource
  13872. maxLength: 253
  13873. minLength: 1
  13874. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13875. type: string
  13876. required:
  13877. - kind
  13878. - name
  13879. type: object
  13880. storeRef:
  13881. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13882. properties:
  13883. kind:
  13884. description: |-
  13885. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13886. Defaults to `SecretStore`
  13887. enum:
  13888. - SecretStore
  13889. - ClusterSecretStore
  13890. type: string
  13891. name:
  13892. description: Name of the SecretStore resource
  13893. maxLength: 253
  13894. minLength: 1
  13895. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13896. type: string
  13897. type: object
  13898. type: object
  13899. type: object
  13900. type: array
  13901. refreshInterval:
  13902. default: 1h0m0s
  13903. description: |-
  13904. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  13905. specified as Golang Duration strings.
  13906. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  13907. Example values: "1h0m0s", "2h30m0s", "10m0s"
  13908. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  13909. type: string
  13910. refreshPolicy:
  13911. description: |-
  13912. RefreshPolicy determines how the ExternalSecret should be refreshed:
  13913. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  13914. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  13915. No periodic updates occur if refreshInterval is 0.
  13916. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  13917. enum:
  13918. - CreatedOnce
  13919. - Periodic
  13920. - OnChange
  13921. type: string
  13922. secretStoreRef:
  13923. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13924. properties:
  13925. kind:
  13926. description: |-
  13927. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13928. Defaults to `SecretStore`
  13929. enum:
  13930. - SecretStore
  13931. - ClusterSecretStore
  13932. type: string
  13933. name:
  13934. description: Name of the SecretStore resource
  13935. maxLength: 253
  13936. minLength: 1
  13937. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13938. type: string
  13939. type: object
  13940. syncWindows:
  13941. description: |-
  13942. SyncWindows optionally restricts when periodic refreshes may occur.
  13943. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  13944. properties:
  13945. kind:
  13946. description: |-
  13947. Kind applies to every window in the list.
  13948. "allow" -- syncs are permitted only while at least one window is active;
  13949. all other times are blocked.
  13950. "deny" -- syncs are blocked while any window is active;
  13951. all other times are permitted.
  13952. enum:
  13953. - allow
  13954. - deny
  13955. type: string
  13956. windows:
  13957. description: Windows is the list of schedule+duration pairs.
  13958. items:
  13959. description: |-
  13960. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  13961. within a SyncWindows block.
  13962. properties:
  13963. duration:
  13964. description: |-
  13965. Duration specifies how long the window stays open after each Schedule
  13966. firing. Example: "8h".
  13967. type: string
  13968. schedule:
  13969. description: |-
  13970. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  13971. named shorthand such as @daily or @every 1h. It marks the start time of
  13972. each window occurrence.
  13973. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  13974. minLength: 1
  13975. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  13976. type: string
  13977. required:
  13978. - duration
  13979. - schedule
  13980. type: object
  13981. minItems: 1
  13982. type: array
  13983. required:
  13984. - kind
  13985. - windows
  13986. type: object
  13987. target:
  13988. default:
  13989. creationPolicy: Owner
  13990. deletionPolicy: Retain
  13991. description: |-
  13992. ExternalSecretTarget defines the Kubernetes Secret to be created,
  13993. there can be only one target per ExternalSecret.
  13994. properties:
  13995. creationPolicy:
  13996. default: Owner
  13997. description: |-
  13998. CreationPolicy defines rules on how to create the resulting Secret.
  13999. Defaults to "Owner"
  14000. enum:
  14001. - Owner
  14002. - Orphan
  14003. - Merge
  14004. - None
  14005. - CreateOrMerge
  14006. type: string
  14007. deletionPolicy:
  14008. default: Retain
  14009. description: |-
  14010. DeletionPolicy defines rules on how to delete the resulting Secret.
  14011. Defaults to "Retain"
  14012. enum:
  14013. - Delete
  14014. - Merge
  14015. - Retain
  14016. type: string
  14017. immutable:
  14018. description: Immutable defines if the final secret will be immutable
  14019. type: boolean
  14020. manifest:
  14021. description: |-
  14022. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  14023. When specified, ExternalSecret will create the resource type defined here
  14024. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  14025. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  14026. properties:
  14027. apiVersion:
  14028. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  14029. minLength: 1
  14030. type: string
  14031. kind:
  14032. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  14033. minLength: 1
  14034. type: string
  14035. required:
  14036. - apiVersion
  14037. - kind
  14038. type: object
  14039. name:
  14040. description: |-
  14041. The name of the Secret resource to be managed.
  14042. Defaults to the .metadata.name of the ExternalSecret resource
  14043. maxLength: 253
  14044. minLength: 1
  14045. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14046. type: string
  14047. template:
  14048. description: Template defines a blueprint for the created Secret resource.
  14049. properties:
  14050. data:
  14051. additionalProperties:
  14052. type: string
  14053. type: object
  14054. engineVersion:
  14055. default: v2
  14056. description: |-
  14057. EngineVersion specifies the template engine version
  14058. that should be used to compile/execute the
  14059. template specified in .data and .templateFrom[].
  14060. enum:
  14061. - v2
  14062. type: string
  14063. mergePolicy:
  14064. default: Replace
  14065. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  14066. enum:
  14067. - Replace
  14068. - Merge
  14069. type: string
  14070. metadata:
  14071. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14072. properties:
  14073. annotations:
  14074. additionalProperties:
  14075. type: string
  14076. type: object
  14077. finalizers:
  14078. items:
  14079. type: string
  14080. type: array
  14081. labels:
  14082. additionalProperties:
  14083. type: string
  14084. type: object
  14085. type: object
  14086. templateFrom:
  14087. items:
  14088. description: |-
  14089. TemplateFrom specifies a source for templates.
  14090. Each item in the list can either reference a ConfigMap or a Secret resource.
  14091. properties:
  14092. configMap:
  14093. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14094. properties:
  14095. items:
  14096. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14097. items:
  14098. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14099. properties:
  14100. key:
  14101. description: A key in the ConfigMap/Secret
  14102. maxLength: 253
  14103. minLength: 1
  14104. pattern: ^[-._a-zA-Z0-9]+$
  14105. type: string
  14106. templateAs:
  14107. default: Values
  14108. description: TemplateScope specifies how the template keys should be interpreted.
  14109. enum:
  14110. - Values
  14111. - KeysAndValues
  14112. type: string
  14113. required:
  14114. - key
  14115. type: object
  14116. type: array
  14117. name:
  14118. description: The name of the ConfigMap/Secret resource
  14119. maxLength: 253
  14120. minLength: 1
  14121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14122. type: string
  14123. required:
  14124. - items
  14125. - name
  14126. type: object
  14127. literal:
  14128. type: string
  14129. secret:
  14130. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14131. properties:
  14132. items:
  14133. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14134. items:
  14135. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14136. properties:
  14137. key:
  14138. description: A key in the ConfigMap/Secret
  14139. maxLength: 253
  14140. minLength: 1
  14141. pattern: ^[-._a-zA-Z0-9]+$
  14142. type: string
  14143. templateAs:
  14144. default: Values
  14145. description: TemplateScope specifies how the template keys should be interpreted.
  14146. enum:
  14147. - Values
  14148. - KeysAndValues
  14149. type: string
  14150. required:
  14151. - key
  14152. type: object
  14153. type: array
  14154. name:
  14155. description: The name of the ConfigMap/Secret resource
  14156. maxLength: 253
  14157. minLength: 1
  14158. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14159. type: string
  14160. required:
  14161. - items
  14162. - name
  14163. type: object
  14164. target:
  14165. default: Data
  14166. description: |-
  14167. Target specifies where to place the template result.
  14168. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  14169. any other value is rejected because it would allow writes to privileged Secret fields.
  14170. For custom resources (when spec.target.manifest is set), this supports
  14171. nested paths like "spec.database.config" or "data".
  14172. type: string
  14173. valuesDecodingStrategy:
  14174. default: None
  14175. description: Used to define a decoding Strategy for the rendered template values.
  14176. enum:
  14177. - Auto
  14178. - Base64
  14179. - Base64URL
  14180. - None
  14181. type: string
  14182. type: object
  14183. type: array
  14184. type:
  14185. type: string
  14186. type: object
  14187. type: object
  14188. type: object
  14189. status:
  14190. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  14191. properties:
  14192. binding:
  14193. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  14194. properties:
  14195. name:
  14196. default: ""
  14197. description: |-
  14198. Name of the referent.
  14199. This field is effectively required, but due to backwards compatibility is
  14200. allowed to be empty. Instances of this type with an empty value here are
  14201. almost certainly wrong.
  14202. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  14203. type: string
  14204. type: object
  14205. x-kubernetes-map-type: atomic
  14206. conditions:
  14207. items:
  14208. description: ExternalSecretStatusCondition defines a status condition of an ExternalSecret resource.
  14209. properties:
  14210. lastTransitionTime:
  14211. format: date-time
  14212. type: string
  14213. message:
  14214. type: string
  14215. reason:
  14216. type: string
  14217. status:
  14218. type: string
  14219. type:
  14220. description: ExternalSecretConditionType defines a value type for ExternalSecret conditions.
  14221. enum:
  14222. - Ready
  14223. - Deleted
  14224. type: string
  14225. required:
  14226. - status
  14227. - type
  14228. type: object
  14229. type: array
  14230. refreshTime:
  14231. description: |-
  14232. refreshTime is the time and date the external secret was fetched and
  14233. the target secret updated
  14234. format: date-time
  14235. nullable: true
  14236. type: string
  14237. syncedResourceVersion:
  14238. description: SyncedResourceVersion keeps track of the last synced version
  14239. type: string
  14240. type: object
  14241. type: object
  14242. selectableFields:
  14243. - jsonPath: .spec.secretStoreRef.name
  14244. - jsonPath: .spec.secretStoreRef.kind
  14245. - jsonPath: .spec.target.name
  14246. - jsonPath: .spec.refreshInterval
  14247. served: true
  14248. storage: true
  14249. subresources:
  14250. status: {}
  14251. - additionalPrinterColumns:
  14252. - jsonPath: .spec.secretStoreRef.kind
  14253. name: StoreType
  14254. type: string
  14255. - jsonPath: .spec.secretStoreRef.name
  14256. name: Store
  14257. type: string
  14258. - jsonPath: .spec.refreshInterval
  14259. name: Refresh Interval
  14260. type: string
  14261. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  14262. name: Status
  14263. type: string
  14264. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  14265. name: Ready
  14266. type: string
  14267. - jsonPath: .status.refreshTime
  14268. name: Last Sync
  14269. type: date
  14270. deprecated: true
  14271. name: v1beta1
  14272. schema:
  14273. openAPIV3Schema:
  14274. description: ExternalSecret is the schema for the external-secrets API.
  14275. properties:
  14276. apiVersion:
  14277. description: |-
  14278. APIVersion defines the versioned schema of this representation of an object.
  14279. Servers should convert recognized schemas to the latest internal value, and
  14280. may reject unrecognized values.
  14281. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  14282. type: string
  14283. kind:
  14284. description: |-
  14285. Kind is a string value representing the REST resource this object represents.
  14286. Servers may infer this from the endpoint the client submits requests to.
  14287. Cannot be updated.
  14288. In CamelCase.
  14289. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  14290. type: string
  14291. metadata:
  14292. type: object
  14293. spec:
  14294. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  14295. properties:
  14296. data:
  14297. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  14298. items:
  14299. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  14300. properties:
  14301. remoteRef:
  14302. description: |-
  14303. RemoteRef points to the remote secret and defines
  14304. which secret (version/property/..) to fetch.
  14305. properties:
  14306. conversionStrategy:
  14307. default: Default
  14308. description: Used to define a conversion Strategy
  14309. enum:
  14310. - Default
  14311. - Unicode
  14312. type: string
  14313. decodingStrategy:
  14314. default: None
  14315. description: Used to define a decoding Strategy
  14316. enum:
  14317. - Auto
  14318. - Base64
  14319. - Base64URL
  14320. - None
  14321. type: string
  14322. key:
  14323. description: Key is the key used in the Provider, mandatory
  14324. type: string
  14325. metadataPolicy:
  14326. default: None
  14327. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14328. enum:
  14329. - None
  14330. - Fetch
  14331. type: string
  14332. property:
  14333. description: Used to select a specific property of the Provider value (if a map), if supported
  14334. type: string
  14335. version:
  14336. description: Used to select a specific version of the Provider value, if supported
  14337. type: string
  14338. required:
  14339. - key
  14340. type: object
  14341. secretKey:
  14342. description: The key in the Kubernetes Secret to store the value.
  14343. maxLength: 253
  14344. minLength: 1
  14345. pattern: ^[-._a-zA-Z0-9]+$
  14346. type: string
  14347. sourceRef:
  14348. description: |-
  14349. SourceRef allows you to override the source
  14350. from which the value will be pulled.
  14351. maxProperties: 1
  14352. minProperties: 1
  14353. properties:
  14354. generatorRef:
  14355. description: |-
  14356. GeneratorRef points to a generator custom resource.
  14357. Deprecated: The generatorRef is not implemented in .data[].
  14358. this will be removed with v1.
  14359. properties:
  14360. apiVersion:
  14361. default: generators.external-secrets.io/v1alpha1
  14362. description: Specify the apiVersion of the generator resource
  14363. type: string
  14364. kind:
  14365. description: Specify the Kind of the generator resource
  14366. enum:
  14367. - ACRAccessToken
  14368. - ClusterGenerator
  14369. - ECRAuthorizationToken
  14370. - Fake
  14371. - GCRAccessToken
  14372. - GithubAccessToken
  14373. - QuayAccessToken
  14374. - Password
  14375. - SSHKey
  14376. - STSSessionToken
  14377. - UUID
  14378. - VaultDynamicSecret
  14379. - Webhook
  14380. - Grafana
  14381. type: string
  14382. name:
  14383. description: Specify the name of the generator resource
  14384. maxLength: 253
  14385. minLength: 1
  14386. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14387. type: string
  14388. required:
  14389. - kind
  14390. - name
  14391. type: object
  14392. storeRef:
  14393. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14394. properties:
  14395. kind:
  14396. description: |-
  14397. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14398. Defaults to `SecretStore`
  14399. enum:
  14400. - SecretStore
  14401. - ClusterSecretStore
  14402. type: string
  14403. name:
  14404. description: Name of the SecretStore resource
  14405. maxLength: 253
  14406. minLength: 1
  14407. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14408. type: string
  14409. type: object
  14410. type: object
  14411. required:
  14412. - remoteRef
  14413. - secretKey
  14414. type: object
  14415. type: array
  14416. dataFrom:
  14417. description: |-
  14418. DataFrom is used to fetch all properties from a specific Provider data
  14419. If multiple entries are specified, the Secret keys are merged in the specified order
  14420. items:
  14421. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  14422. properties:
  14423. extract:
  14424. description: |-
  14425. Used to extract multiple key/value pairs from one secret
  14426. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14427. properties:
  14428. conversionStrategy:
  14429. default: Default
  14430. description: Used to define a conversion Strategy
  14431. enum:
  14432. - Default
  14433. - Unicode
  14434. type: string
  14435. decodingStrategy:
  14436. default: None
  14437. description: Used to define a decoding Strategy
  14438. enum:
  14439. - Auto
  14440. - Base64
  14441. - Base64URL
  14442. - None
  14443. type: string
  14444. key:
  14445. description: Key is the key used in the Provider, mandatory
  14446. type: string
  14447. metadataPolicy:
  14448. default: None
  14449. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14450. enum:
  14451. - None
  14452. - Fetch
  14453. type: string
  14454. property:
  14455. description: Used to select a specific property of the Provider value (if a map), if supported
  14456. type: string
  14457. version:
  14458. description: Used to select a specific version of the Provider value, if supported
  14459. type: string
  14460. required:
  14461. - key
  14462. type: object
  14463. find:
  14464. description: |-
  14465. Used to find secrets based on tags or regular expressions
  14466. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14467. properties:
  14468. conversionStrategy:
  14469. default: Default
  14470. description: Used to define a conversion Strategy
  14471. enum:
  14472. - Default
  14473. - Unicode
  14474. type: string
  14475. decodingStrategy:
  14476. default: None
  14477. description: Used to define a decoding Strategy
  14478. enum:
  14479. - Auto
  14480. - Base64
  14481. - Base64URL
  14482. - None
  14483. type: string
  14484. name:
  14485. description: Finds secrets based on the name.
  14486. properties:
  14487. regexp:
  14488. description: Finds secrets base
  14489. type: string
  14490. type: object
  14491. path:
  14492. description: A root path to start the find operations.
  14493. type: string
  14494. tags:
  14495. additionalProperties:
  14496. type: string
  14497. description: Find secrets based on tags.
  14498. type: object
  14499. type: object
  14500. rewrite:
  14501. description: |-
  14502. Used to rewrite secret Keys after getting them from the secret Provider
  14503. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  14504. items:
  14505. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  14506. maxProperties: 1
  14507. minProperties: 1
  14508. properties:
  14509. regexp:
  14510. description: |-
  14511. Used to rewrite with regular expressions.
  14512. The resulting key will be the output of a regexp.ReplaceAll operation.
  14513. properties:
  14514. source:
  14515. description: Used to define the regular expression of a re.Compiler.
  14516. type: string
  14517. target:
  14518. description: Used to define the target pattern of a ReplaceAll operation.
  14519. type: string
  14520. required:
  14521. - source
  14522. - target
  14523. type: object
  14524. transform:
  14525. description: |-
  14526. Used to apply string transformation on the secrets.
  14527. The resulting key will be the output of the template applied by the operation.
  14528. properties:
  14529. template:
  14530. description: |-
  14531. Used to define the template to apply on the secret name.
  14532. `.value ` will specify the secret name in the template.
  14533. type: string
  14534. required:
  14535. - template
  14536. type: object
  14537. type: object
  14538. type: array
  14539. sourceRef:
  14540. description: |-
  14541. SourceRef points to a store or generator
  14542. which contains secret values ready to use.
  14543. Use this in combination with Extract or Find pull values out of
  14544. a specific SecretStore.
  14545. When sourceRef points to a generator Extract or Find is not supported.
  14546. The generator returns a static map of values
  14547. maxProperties: 1
  14548. minProperties: 1
  14549. properties:
  14550. generatorRef:
  14551. description: GeneratorRef points to a generator custom resource.
  14552. properties:
  14553. apiVersion:
  14554. default: generators.external-secrets.io/v1alpha1
  14555. description: Specify the apiVersion of the generator resource
  14556. type: string
  14557. kind:
  14558. description: Specify the Kind of the generator resource
  14559. enum:
  14560. - ACRAccessToken
  14561. - ClusterGenerator
  14562. - ECRAuthorizationToken
  14563. - Fake
  14564. - GCRAccessToken
  14565. - GithubAccessToken
  14566. - QuayAccessToken
  14567. - Password
  14568. - SSHKey
  14569. - STSSessionToken
  14570. - UUID
  14571. - VaultDynamicSecret
  14572. - Webhook
  14573. - Grafana
  14574. type: string
  14575. name:
  14576. description: Specify the name of the generator resource
  14577. maxLength: 253
  14578. minLength: 1
  14579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14580. type: string
  14581. required:
  14582. - kind
  14583. - name
  14584. type: object
  14585. storeRef:
  14586. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14587. properties:
  14588. kind:
  14589. description: |-
  14590. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14591. Defaults to `SecretStore`
  14592. enum:
  14593. - SecretStore
  14594. - ClusterSecretStore
  14595. type: string
  14596. name:
  14597. description: Name of the SecretStore resource
  14598. maxLength: 253
  14599. minLength: 1
  14600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14601. type: string
  14602. type: object
  14603. type: object
  14604. type: object
  14605. type: array
  14606. refreshInterval:
  14607. default: 1h0m0s
  14608. description: |-
  14609. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  14610. specified as Golang Duration strings.
  14611. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  14612. Example values: "1h0m0s", "2h30m0s", "10m0s"
  14613. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  14614. type: string
  14615. refreshPolicy:
  14616. description: |-
  14617. RefreshPolicy determines how the ExternalSecret should be refreshed:
  14618. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  14619. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  14620. No periodic updates occur if refreshInterval is 0.
  14621. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  14622. enum:
  14623. - CreatedOnce
  14624. - Periodic
  14625. - OnChange
  14626. type: string
  14627. secretStoreRef:
  14628. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14629. properties:
  14630. kind:
  14631. description: |-
  14632. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14633. Defaults to `SecretStore`
  14634. enum:
  14635. - SecretStore
  14636. - ClusterSecretStore
  14637. type: string
  14638. name:
  14639. description: Name of the SecretStore resource
  14640. maxLength: 253
  14641. minLength: 1
  14642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14643. type: string
  14644. type: object
  14645. target:
  14646. default:
  14647. creationPolicy: Owner
  14648. deletionPolicy: Retain
  14649. description: |-
  14650. ExternalSecretTarget defines the Kubernetes Secret to be created
  14651. There can be only one target per ExternalSecret.
  14652. properties:
  14653. creationPolicy:
  14654. default: Owner
  14655. description: |-
  14656. CreationPolicy defines rules on how to create the resulting Secret.
  14657. Defaults to "Owner"
  14658. enum:
  14659. - Owner
  14660. - Orphan
  14661. - Merge
  14662. - None
  14663. type: string
  14664. deletionPolicy:
  14665. default: Retain
  14666. description: |-
  14667. DeletionPolicy defines rules on how to delete the resulting Secret.
  14668. Defaults to "Retain"
  14669. enum:
  14670. - Delete
  14671. - Merge
  14672. - Retain
  14673. type: string
  14674. immutable:
  14675. description: Immutable defines if the final secret will be immutable
  14676. type: boolean
  14677. name:
  14678. description: |-
  14679. The name of the Secret resource to be managed.
  14680. Defaults to the .metadata.name of the ExternalSecret resource
  14681. maxLength: 253
  14682. minLength: 1
  14683. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14684. type: string
  14685. template:
  14686. description: Template defines a blueprint for the created Secret resource.
  14687. properties:
  14688. data:
  14689. additionalProperties:
  14690. type: string
  14691. type: object
  14692. engineVersion:
  14693. default: v2
  14694. description: |-
  14695. EngineVersion specifies the template engine version
  14696. that should be used to compile/execute the
  14697. template specified in .data and .templateFrom[].
  14698. enum:
  14699. - v2
  14700. type: string
  14701. mergePolicy:
  14702. default: Replace
  14703. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  14704. enum:
  14705. - Replace
  14706. - Merge
  14707. type: string
  14708. metadata:
  14709. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14710. properties:
  14711. annotations:
  14712. additionalProperties:
  14713. type: string
  14714. type: object
  14715. labels:
  14716. additionalProperties:
  14717. type: string
  14718. type: object
  14719. type: object
  14720. templateFrom:
  14721. items:
  14722. description: TemplateFrom defines a source for template data.
  14723. properties:
  14724. configMap:
  14725. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14726. properties:
  14727. items:
  14728. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14729. items:
  14730. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14731. properties:
  14732. key:
  14733. description: A key in the ConfigMap/Secret
  14734. maxLength: 253
  14735. minLength: 1
  14736. pattern: ^[-._a-zA-Z0-9]+$
  14737. type: string
  14738. templateAs:
  14739. default: Values
  14740. description: TemplateScope defines the scope of the template when processing template data.
  14741. enum:
  14742. - Values
  14743. - KeysAndValues
  14744. type: string
  14745. required:
  14746. - key
  14747. type: object
  14748. type: array
  14749. name:
  14750. description: The name of the ConfigMap/Secret resource
  14751. maxLength: 253
  14752. minLength: 1
  14753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14754. type: string
  14755. required:
  14756. - items
  14757. - name
  14758. type: object
  14759. literal:
  14760. type: string
  14761. secret:
  14762. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14763. properties:
  14764. items:
  14765. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14766. items:
  14767. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14768. properties:
  14769. key:
  14770. description: A key in the ConfigMap/Secret
  14771. maxLength: 253
  14772. minLength: 1
  14773. pattern: ^[-._a-zA-Z0-9]+$
  14774. type: string
  14775. templateAs:
  14776. default: Values
  14777. description: TemplateScope defines the scope of the template when processing template data.
  14778. enum:
  14779. - Values
  14780. - KeysAndValues
  14781. type: string
  14782. required:
  14783. - key
  14784. type: object
  14785. type: array
  14786. name:
  14787. description: The name of the ConfigMap/Secret resource
  14788. maxLength: 253
  14789. minLength: 1
  14790. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14791. type: string
  14792. required:
  14793. - items
  14794. - name
  14795. type: object
  14796. target:
  14797. default: Data
  14798. description: TemplateTarget defines the target field where the template result will be stored.
  14799. enum:
  14800. - Data
  14801. - Annotations
  14802. - Labels
  14803. type: string
  14804. type: object
  14805. type: array
  14806. type:
  14807. type: string
  14808. type: object
  14809. type: object
  14810. type: object
  14811. status:
  14812. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  14813. properties:
  14814. binding:
  14815. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  14816. properties:
  14817. name:
  14818. default: ""
  14819. description: |-
  14820. Name of the referent.
  14821. This field is effectively required, but due to backwards compatibility is
  14822. allowed to be empty. Instances of this type with an empty value here are
  14823. almost certainly wrong.
  14824. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  14825. type: string
  14826. type: object
  14827. x-kubernetes-map-type: atomic
  14828. conditions:
  14829. items:
  14830. description: ExternalSecretStatusCondition contains condition information for an ExternalSecret.
  14831. properties:
  14832. lastTransitionTime:
  14833. format: date-time
  14834. type: string
  14835. message:
  14836. type: string
  14837. reason:
  14838. type: string
  14839. status:
  14840. type: string
  14841. type:
  14842. description: ExternalSecretConditionType defines the condition type for an ExternalSecret.
  14843. type: string
  14844. required:
  14845. - status
  14846. - type
  14847. type: object
  14848. type: array
  14849. refreshTime:
  14850. description: |-
  14851. refreshTime is the time and date the external secret was fetched and
  14852. the target secret updated
  14853. format: date-time
  14854. nullable: true
  14855. type: string
  14856. syncedResourceVersion:
  14857. description: SyncedResourceVersion keeps track of the last synced version
  14858. type: string
  14859. type: object
  14860. type: object
  14861. served: false
  14862. storage: false
  14863. subresources:
  14864. status: {}
  14865. ---
  14866. apiVersion: apiextensions.k8s.io/v1
  14867. kind: CustomResourceDefinition
  14868. metadata:
  14869. annotations:
  14870. controller-gen.kubebuilder.io/version: v0.19.0
  14871. labels:
  14872. external-secrets.io/component: controller
  14873. name: pushsecrets.external-secrets.io
  14874. spec:
  14875. group: external-secrets.io
  14876. names:
  14877. categories:
  14878. - external-secrets
  14879. kind: PushSecret
  14880. listKind: PushSecretList
  14881. plural: pushsecrets
  14882. shortNames:
  14883. - ps
  14884. singular: pushsecret
  14885. scope: Namespaced
  14886. versions:
  14887. - additionalPrinterColumns:
  14888. - jsonPath: .metadata.creationTimestamp
  14889. name: AGE
  14890. type: date
  14891. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  14892. name: Status
  14893. type: string
  14894. - jsonPath: .status.refreshTime
  14895. name: Last Sync
  14896. type: date
  14897. name: v1alpha1
  14898. schema:
  14899. openAPIV3Schema:
  14900. description: PushSecret is the Schema for the PushSecrets API that enables pushing Kubernetes secrets to external secret providers.
  14901. properties:
  14902. apiVersion:
  14903. description: |-
  14904. APIVersion defines the versioned schema of this representation of an object.
  14905. Servers should convert recognized schemas to the latest internal value, and
  14906. may reject unrecognized values.
  14907. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  14908. type: string
  14909. kind:
  14910. description: |-
  14911. Kind is a string value representing the REST resource this object represents.
  14912. Servers may infer this from the endpoint the client submits requests to.
  14913. Cannot be updated.
  14914. In CamelCase.
  14915. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  14916. type: string
  14917. metadata:
  14918. type: object
  14919. spec:
  14920. description: PushSecretSpec configures the behavior of the PushSecret.
  14921. properties:
  14922. data:
  14923. description: Secret Data that should be pushed to providers
  14924. items:
  14925. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  14926. properties:
  14927. conversionStrategy:
  14928. default: None
  14929. description: Used to define a conversion Strategy for the secret keys
  14930. enum:
  14931. - None
  14932. - ReverseUnicode
  14933. type: string
  14934. match:
  14935. description: Match a given Secret Key to be pushed to the provider.
  14936. properties:
  14937. remoteRef:
  14938. description: Remote Refs to push to providers.
  14939. properties:
  14940. property:
  14941. description: Name of the property in the resulting secret
  14942. type: string
  14943. remoteKey:
  14944. description: Name of the resulting provider secret.
  14945. type: string
  14946. required:
  14947. - remoteKey
  14948. type: object
  14949. secretKey:
  14950. description: Secret Key to be pushed
  14951. type: string
  14952. required:
  14953. - remoteRef
  14954. type: object
  14955. metadata:
  14956. description: |-
  14957. Metadata is metadata attached to the secret.
  14958. The structure of metadata is provider specific, please look it up in the provider documentation.
  14959. x-kubernetes-preserve-unknown-fields: true
  14960. required:
  14961. - match
  14962. type: object
  14963. type: array
  14964. dataTo:
  14965. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  14966. items:
  14967. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  14968. properties:
  14969. conversionStrategy:
  14970. default: None
  14971. description: Used to define a conversion Strategy for the secret keys
  14972. enum:
  14973. - None
  14974. - ReverseUnicode
  14975. type: string
  14976. match:
  14977. description: |-
  14978. Match pattern for selecting keys from the source Secret.
  14979. If not specified, all keys are selected.
  14980. properties:
  14981. regexp:
  14982. description: |-
  14983. Regexp matches keys by regular expression.
  14984. If not specified, all keys are matched.
  14985. type: string
  14986. type: object
  14987. metadata:
  14988. description: |-
  14989. Metadata is metadata attached to the secret.
  14990. The structure of metadata is provider specific, please look it up in the provider documentation.
  14991. x-kubernetes-preserve-unknown-fields: true
  14992. remoteKey:
  14993. description: |-
  14994. RemoteKey is the name of the single provider secret that will receive ALL
  14995. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  14996. When set, per-key expansion is skipped and a single push is performed.
  14997. The provider's store prefix (if any) is still prepended to this value.
  14998. When not set, each matched key is pushed as its own individual provider secret.
  14999. type: string
  15000. rewrite:
  15001. description: |-
  15002. Rewrite operations to transform keys before pushing to the provider.
  15003. Operations are applied sequentially.
  15004. items:
  15005. description: PushSecretRewrite defines how to transform secret keys before pushing.
  15006. properties:
  15007. regexp:
  15008. description: Used to rewrite with regular expressions.
  15009. properties:
  15010. source:
  15011. description: Used to define the regular expression of a re.Compiler.
  15012. type: string
  15013. target:
  15014. description: Used to define the target pattern of a ReplaceAll operation.
  15015. type: string
  15016. required:
  15017. - source
  15018. - target
  15019. type: object
  15020. transform:
  15021. description: Used to apply string transformation on the secrets.
  15022. properties:
  15023. template:
  15024. description: |-
  15025. Used to define the template to apply on the secret name.
  15026. `.value ` will specify the secret name in the template.
  15027. type: string
  15028. required:
  15029. - template
  15030. type: object
  15031. type: object
  15032. x-kubernetes-validations:
  15033. - message: exactly one of regexp or transform must be set
  15034. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  15035. type: array
  15036. storeRef:
  15037. description: StoreRef specifies which SecretStore to push to. Required.
  15038. properties:
  15039. kind:
  15040. default: SecretStore
  15041. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  15042. enum:
  15043. - SecretStore
  15044. - ClusterSecretStore
  15045. type: string
  15046. labelSelector:
  15047. description: Optionally, sync to secret stores with label selector
  15048. properties:
  15049. matchExpressions:
  15050. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15051. items:
  15052. description: |-
  15053. A label selector requirement is a selector that contains values, a key, and an operator that
  15054. relates the key and values.
  15055. properties:
  15056. key:
  15057. description: key is the label key that the selector applies to.
  15058. type: string
  15059. operator:
  15060. description: |-
  15061. operator represents a key's relationship to a set of values.
  15062. Valid operators are In, NotIn, Exists and DoesNotExist.
  15063. type: string
  15064. values:
  15065. description: |-
  15066. values is an array of string values. If the operator is In or NotIn,
  15067. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15068. the values array must be empty. This array is replaced during a strategic
  15069. merge patch.
  15070. items:
  15071. type: string
  15072. type: array
  15073. x-kubernetes-list-type: atomic
  15074. required:
  15075. - key
  15076. - operator
  15077. type: object
  15078. type: array
  15079. x-kubernetes-list-type: atomic
  15080. matchLabels:
  15081. additionalProperties:
  15082. type: string
  15083. description: |-
  15084. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15085. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15086. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15087. type: object
  15088. type: object
  15089. x-kubernetes-map-type: atomic
  15090. name:
  15091. description: Optionally, sync to the SecretStore of the given name
  15092. maxLength: 253
  15093. minLength: 1
  15094. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15095. type: string
  15096. type: object
  15097. type: object
  15098. x-kubernetes-validations:
  15099. - message: storeRef must specify either name or labelSelector
  15100. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  15101. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  15102. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  15103. type: array
  15104. deletionPolicy:
  15105. default: None
  15106. description: Deletion Policy to handle Secrets in the provider.
  15107. enum:
  15108. - Delete
  15109. - None
  15110. type: string
  15111. refreshInterval:
  15112. default: 1h0m0s
  15113. description: The Interval to which External Secrets will try to push a secret definition
  15114. type: string
  15115. secretStoreRefs:
  15116. items:
  15117. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  15118. properties:
  15119. kind:
  15120. default: SecretStore
  15121. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  15122. enum:
  15123. - SecretStore
  15124. - ClusterSecretStore
  15125. type: string
  15126. labelSelector:
  15127. description: Optionally, sync to secret stores with label selector
  15128. properties:
  15129. matchExpressions:
  15130. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15131. items:
  15132. description: |-
  15133. A label selector requirement is a selector that contains values, a key, and an operator that
  15134. relates the key and values.
  15135. properties:
  15136. key:
  15137. description: key is the label key that the selector applies to.
  15138. type: string
  15139. operator:
  15140. description: |-
  15141. operator represents a key's relationship to a set of values.
  15142. Valid operators are In, NotIn, Exists and DoesNotExist.
  15143. type: string
  15144. values:
  15145. description: |-
  15146. values is an array of string values. If the operator is In or NotIn,
  15147. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15148. the values array must be empty. This array is replaced during a strategic
  15149. merge patch.
  15150. items:
  15151. type: string
  15152. type: array
  15153. x-kubernetes-list-type: atomic
  15154. required:
  15155. - key
  15156. - operator
  15157. type: object
  15158. type: array
  15159. x-kubernetes-list-type: atomic
  15160. matchLabels:
  15161. additionalProperties:
  15162. type: string
  15163. description: |-
  15164. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15165. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15166. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15167. type: object
  15168. type: object
  15169. x-kubernetes-map-type: atomic
  15170. name:
  15171. description: Optionally, sync to the SecretStore of the given name
  15172. maxLength: 253
  15173. minLength: 1
  15174. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15175. type: string
  15176. type: object
  15177. type: array
  15178. selector:
  15179. description: The Secret Selector (k8s source) for the Push Secret
  15180. maxProperties: 1
  15181. minProperties: 1
  15182. properties:
  15183. generatorRef:
  15184. description: Point to a generator to create a Secret.
  15185. properties:
  15186. apiVersion:
  15187. default: generators.external-secrets.io/v1alpha1
  15188. description: Specify the apiVersion of the generator resource
  15189. type: string
  15190. kind:
  15191. description: Specify the Kind of the generator resource
  15192. enum:
  15193. - ACRAccessToken
  15194. - BeyondtrustWorkloadCredentialsDynamicSecret
  15195. - ClusterGenerator
  15196. - CloudsmithAccessToken
  15197. - ECRAuthorizationToken
  15198. - Fake
  15199. - GCRAccessToken
  15200. - GithubAccessToken
  15201. - GitlabDeployToken
  15202. - QuayAccessToken
  15203. - Password
  15204. - SSHKey
  15205. - STSSessionToken
  15206. - UUID
  15207. - VaultDynamicSecret
  15208. - Webhook
  15209. - Grafana
  15210. - MFA
  15211. type: string
  15212. name:
  15213. description: Specify the name of the generator resource
  15214. maxLength: 253
  15215. minLength: 1
  15216. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15217. type: string
  15218. required:
  15219. - kind
  15220. - name
  15221. type: object
  15222. secret:
  15223. description: Select a Secret to Push.
  15224. properties:
  15225. name:
  15226. description: |-
  15227. Name of the Secret.
  15228. The Secret must exist in the same namespace as the PushSecret manifest.
  15229. maxLength: 253
  15230. minLength: 1
  15231. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15232. type: string
  15233. selector:
  15234. description: Selector chooses secrets using a labelSelector.
  15235. properties:
  15236. matchExpressions:
  15237. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15238. items:
  15239. description: |-
  15240. A label selector requirement is a selector that contains values, a key, and an operator that
  15241. relates the key and values.
  15242. properties:
  15243. key:
  15244. description: key is the label key that the selector applies to.
  15245. type: string
  15246. operator:
  15247. description: |-
  15248. operator represents a key's relationship to a set of values.
  15249. Valid operators are In, NotIn, Exists and DoesNotExist.
  15250. type: string
  15251. values:
  15252. description: |-
  15253. values is an array of string values. If the operator is In or NotIn,
  15254. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15255. the values array must be empty. This array is replaced during a strategic
  15256. merge patch.
  15257. items:
  15258. type: string
  15259. type: array
  15260. x-kubernetes-list-type: atomic
  15261. required:
  15262. - key
  15263. - operator
  15264. type: object
  15265. type: array
  15266. x-kubernetes-list-type: atomic
  15267. matchLabels:
  15268. additionalProperties:
  15269. type: string
  15270. description: |-
  15271. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15272. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15273. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15274. type: object
  15275. type: object
  15276. x-kubernetes-map-type: atomic
  15277. type: object
  15278. type: object
  15279. template:
  15280. description: Template defines a blueprint for the created Secret resource.
  15281. properties:
  15282. data:
  15283. additionalProperties:
  15284. type: string
  15285. type: object
  15286. engineVersion:
  15287. default: v2
  15288. description: |-
  15289. EngineVersion specifies the template engine version
  15290. that should be used to compile/execute the
  15291. template specified in .data and .templateFrom[].
  15292. enum:
  15293. - v2
  15294. type: string
  15295. mergePolicy:
  15296. default: Replace
  15297. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  15298. enum:
  15299. - Replace
  15300. - Merge
  15301. type: string
  15302. metadata:
  15303. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  15304. properties:
  15305. annotations:
  15306. additionalProperties:
  15307. type: string
  15308. type: object
  15309. finalizers:
  15310. items:
  15311. type: string
  15312. type: array
  15313. labels:
  15314. additionalProperties:
  15315. type: string
  15316. type: object
  15317. type: object
  15318. templateFrom:
  15319. items:
  15320. description: |-
  15321. TemplateFrom specifies a source for templates.
  15322. Each item in the list can either reference a ConfigMap or a Secret resource.
  15323. properties:
  15324. configMap:
  15325. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15326. properties:
  15327. items:
  15328. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15329. items:
  15330. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15331. properties:
  15332. key:
  15333. description: A key in the ConfigMap/Secret
  15334. maxLength: 253
  15335. minLength: 1
  15336. pattern: ^[-._a-zA-Z0-9]+$
  15337. type: string
  15338. templateAs:
  15339. default: Values
  15340. description: TemplateScope specifies how the template keys should be interpreted.
  15341. enum:
  15342. - Values
  15343. - KeysAndValues
  15344. type: string
  15345. required:
  15346. - key
  15347. type: object
  15348. type: array
  15349. name:
  15350. description: The name of the ConfigMap/Secret resource
  15351. maxLength: 253
  15352. minLength: 1
  15353. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15354. type: string
  15355. required:
  15356. - items
  15357. - name
  15358. type: object
  15359. literal:
  15360. type: string
  15361. secret:
  15362. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15363. properties:
  15364. items:
  15365. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15366. items:
  15367. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15368. properties:
  15369. key:
  15370. description: A key in the ConfigMap/Secret
  15371. maxLength: 253
  15372. minLength: 1
  15373. pattern: ^[-._a-zA-Z0-9]+$
  15374. type: string
  15375. templateAs:
  15376. default: Values
  15377. description: TemplateScope specifies how the template keys should be interpreted.
  15378. enum:
  15379. - Values
  15380. - KeysAndValues
  15381. type: string
  15382. required:
  15383. - key
  15384. type: object
  15385. type: array
  15386. name:
  15387. description: The name of the ConfigMap/Secret resource
  15388. maxLength: 253
  15389. minLength: 1
  15390. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15391. type: string
  15392. required:
  15393. - items
  15394. - name
  15395. type: object
  15396. target:
  15397. default: Data
  15398. description: |-
  15399. Target specifies where to place the template result.
  15400. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  15401. any other value is rejected because it would allow writes to privileged Secret fields.
  15402. For custom resources (when spec.target.manifest is set), this supports
  15403. nested paths like "spec.database.config" or "data".
  15404. type: string
  15405. valuesDecodingStrategy:
  15406. default: None
  15407. description: Used to define a decoding Strategy for the rendered template values.
  15408. enum:
  15409. - Auto
  15410. - Base64
  15411. - Base64URL
  15412. - None
  15413. type: string
  15414. type: object
  15415. type: array
  15416. type:
  15417. type: string
  15418. type: object
  15419. updatePolicy:
  15420. default: Replace
  15421. description: UpdatePolicy to handle Secrets in the provider.
  15422. enum:
  15423. - Replace
  15424. - IfNotExists
  15425. type: string
  15426. required:
  15427. - secretStoreRefs
  15428. - selector
  15429. type: object
  15430. status:
  15431. description: PushSecretStatus indicates the history of the status of PushSecret.
  15432. properties:
  15433. conditions:
  15434. items:
  15435. description: PushSecretStatusCondition indicates the status of the PushSecret.
  15436. properties:
  15437. lastTransitionTime:
  15438. format: date-time
  15439. type: string
  15440. message:
  15441. type: string
  15442. reason:
  15443. type: string
  15444. status:
  15445. type: string
  15446. type:
  15447. description: PushSecretConditionType indicates the condition of the PushSecret.
  15448. type: string
  15449. required:
  15450. - status
  15451. - type
  15452. type: object
  15453. type: array
  15454. refreshTime:
  15455. description: |-
  15456. refreshTime is the time and date the external secret was fetched and
  15457. the target secret updated
  15458. format: date-time
  15459. nullable: true
  15460. type: string
  15461. syncedPushSecrets:
  15462. additionalProperties:
  15463. additionalProperties:
  15464. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  15465. properties:
  15466. conversionStrategy:
  15467. default: None
  15468. description: Used to define a conversion Strategy for the secret keys
  15469. enum:
  15470. - None
  15471. - ReverseUnicode
  15472. type: string
  15473. match:
  15474. description: Match a given Secret Key to be pushed to the provider.
  15475. properties:
  15476. remoteRef:
  15477. description: Remote Refs to push to providers.
  15478. properties:
  15479. property:
  15480. description: Name of the property in the resulting secret
  15481. type: string
  15482. remoteKey:
  15483. description: Name of the resulting provider secret.
  15484. type: string
  15485. required:
  15486. - remoteKey
  15487. type: object
  15488. secretKey:
  15489. description: Secret Key to be pushed
  15490. type: string
  15491. required:
  15492. - remoteRef
  15493. type: object
  15494. metadata:
  15495. description: |-
  15496. Metadata is metadata attached to the secret.
  15497. The structure of metadata is provider specific, please look it up in the provider documentation.
  15498. x-kubernetes-preserve-unknown-fields: true
  15499. required:
  15500. - match
  15501. type: object
  15502. type: object
  15503. description: |-
  15504. Synced PushSecrets, including secrets that already exist in provider.
  15505. Matches secret stores to PushSecretData that was stored to that secret store.
  15506. type: object
  15507. syncedResourceVersion:
  15508. description: SyncedResourceVersion keeps track of the last synced version.
  15509. type: string
  15510. type: object
  15511. type: object
  15512. served: true
  15513. storage: true
  15514. subresources:
  15515. status: {}
  15516. ---
  15517. apiVersion: apiextensions.k8s.io/v1
  15518. kind: CustomResourceDefinition
  15519. metadata:
  15520. annotations:
  15521. controller-gen.kubebuilder.io/version: v0.19.0
  15522. labels:
  15523. external-secrets.io/component: controller
  15524. name: secretstores.external-secrets.io
  15525. spec:
  15526. group: external-secrets.io
  15527. names:
  15528. categories:
  15529. - external-secrets
  15530. kind: SecretStore
  15531. listKind: SecretStoreList
  15532. plural: secretstores
  15533. shortNames:
  15534. - ss
  15535. singular: secretstore
  15536. scope: Namespaced
  15537. versions:
  15538. - additionalPrinterColumns:
  15539. - jsonPath: .metadata.creationTimestamp
  15540. name: AGE
  15541. type: date
  15542. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  15543. name: Status
  15544. type: string
  15545. - jsonPath: .status.capabilities
  15546. name: Capabilities
  15547. type: string
  15548. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  15549. name: Ready
  15550. type: string
  15551. name: v1
  15552. schema:
  15553. openAPIV3Schema:
  15554. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  15555. properties:
  15556. apiVersion:
  15557. description: |-
  15558. APIVersion defines the versioned schema of this representation of an object.
  15559. Servers should convert recognized schemas to the latest internal value, and
  15560. may reject unrecognized values.
  15561. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15562. type: string
  15563. kind:
  15564. description: |-
  15565. Kind is a string value representing the REST resource this object represents.
  15566. Servers may infer this from the endpoint the client submits requests to.
  15567. Cannot be updated.
  15568. In CamelCase.
  15569. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15570. type: string
  15571. metadata:
  15572. type: object
  15573. spec:
  15574. description: SecretStoreSpec defines the desired state of SecretStore.
  15575. properties:
  15576. conditions:
  15577. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  15578. items:
  15579. description: |-
  15580. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  15581. for a ClusterSecretStore instance.
  15582. properties:
  15583. namespaceRegexes:
  15584. description: Choose namespaces by using regex matching
  15585. items:
  15586. type: string
  15587. type: array
  15588. namespaceSelector:
  15589. description: Choose namespace using a labelSelector
  15590. properties:
  15591. matchExpressions:
  15592. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15593. items:
  15594. description: |-
  15595. A label selector requirement is a selector that contains values, a key, and an operator that
  15596. relates the key and values.
  15597. properties:
  15598. key:
  15599. description: key is the label key that the selector applies to.
  15600. type: string
  15601. operator:
  15602. description: |-
  15603. operator represents a key's relationship to a set of values.
  15604. Valid operators are In, NotIn, Exists and DoesNotExist.
  15605. type: string
  15606. values:
  15607. description: |-
  15608. values is an array of string values. If the operator is In or NotIn,
  15609. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15610. the values array must be empty. This array is replaced during a strategic
  15611. merge patch.
  15612. items:
  15613. type: string
  15614. type: array
  15615. x-kubernetes-list-type: atomic
  15616. required:
  15617. - key
  15618. - operator
  15619. type: object
  15620. type: array
  15621. x-kubernetes-list-type: atomic
  15622. matchLabels:
  15623. additionalProperties:
  15624. type: string
  15625. description: |-
  15626. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15627. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15628. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15629. type: object
  15630. type: object
  15631. x-kubernetes-map-type: atomic
  15632. namespaces:
  15633. description: Choose namespaces by name
  15634. items:
  15635. maxLength: 63
  15636. minLength: 1
  15637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15638. type: string
  15639. type: array
  15640. type: object
  15641. type: array
  15642. controller:
  15643. description: |-
  15644. Used to select the correct ESO controller (think: ingress.ingressClassName)
  15645. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  15646. type: string
  15647. provider:
  15648. description: Used to configure the provider. Only one provider may be set
  15649. maxProperties: 1
  15650. minProperties: 1
  15651. properties:
  15652. akeyless:
  15653. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  15654. properties:
  15655. akeylessGWApiURL:
  15656. description: Akeyless GW API Url from which the secrets to be fetched from.
  15657. type: string
  15658. authSecretRef:
  15659. description: Auth configures how the operator authenticates with Akeyless.
  15660. properties:
  15661. kubernetesAuth:
  15662. description: |-
  15663. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  15664. token stored in the named Secret resource.
  15665. properties:
  15666. accessID:
  15667. description: the Akeyless Kubernetes auth-method access-id
  15668. type: string
  15669. k8sConfName:
  15670. description: Kubernetes-auth configuration name in Akeyless-Gateway
  15671. type: string
  15672. secretRef:
  15673. description: |-
  15674. Optional secret field containing a Kubernetes ServiceAccount JWT used
  15675. for authenticating with Akeyless. If a name is specified without a key,
  15676. `token` is the default. If one is not specified, the one bound to
  15677. the controller will be used.
  15678. properties:
  15679. key:
  15680. description: |-
  15681. A key in the referenced Secret.
  15682. Some instances of this field may be defaulted, in others it may be required.
  15683. maxLength: 253
  15684. minLength: 1
  15685. pattern: ^[-._a-zA-Z0-9]+$
  15686. type: string
  15687. name:
  15688. description: The name of the Secret resource being referred to.
  15689. maxLength: 253
  15690. minLength: 1
  15691. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15692. type: string
  15693. namespace:
  15694. description: |-
  15695. The namespace of the Secret resource being referred to.
  15696. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15697. maxLength: 63
  15698. minLength: 1
  15699. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15700. type: string
  15701. type: object
  15702. serviceAccountRef:
  15703. description: |-
  15704. Optional service account field containing the name of a kubernetes ServiceAccount.
  15705. If the service account is specified, the service account secret token JWT will be used
  15706. for authenticating with Akeyless. If the service account selector is not supplied,
  15707. the secretRef will be used instead.
  15708. properties:
  15709. audiences:
  15710. description: |-
  15711. Audience specifies the `aud` claim for the service account token
  15712. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15713. then this audiences will be appended to the list
  15714. items:
  15715. type: string
  15716. type: array
  15717. name:
  15718. description: The name of the ServiceAccount resource being referred to.
  15719. maxLength: 253
  15720. minLength: 1
  15721. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15722. type: string
  15723. namespace:
  15724. description: |-
  15725. Namespace of the resource being referred to.
  15726. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15727. maxLength: 63
  15728. minLength: 1
  15729. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15730. type: string
  15731. required:
  15732. - name
  15733. type: object
  15734. required:
  15735. - accessID
  15736. - k8sConfName
  15737. type: object
  15738. secretRef:
  15739. description: |-
  15740. Reference to a Secret that contains the details
  15741. to authenticate with Akeyless.
  15742. properties:
  15743. accessID:
  15744. description: The SecretAccessID is used for authentication
  15745. properties:
  15746. key:
  15747. description: |-
  15748. A key in the referenced Secret.
  15749. Some instances of this field may be defaulted, in others it may be required.
  15750. maxLength: 253
  15751. minLength: 1
  15752. pattern: ^[-._a-zA-Z0-9]+$
  15753. type: string
  15754. name:
  15755. description: The name of the Secret resource being referred to.
  15756. maxLength: 253
  15757. minLength: 1
  15758. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15759. type: string
  15760. namespace:
  15761. description: |-
  15762. The namespace of the Secret resource being referred to.
  15763. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15764. maxLength: 63
  15765. minLength: 1
  15766. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15767. type: string
  15768. type: object
  15769. accessType:
  15770. description: |-
  15771. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15772. In some instances, `key` is a required field.
  15773. properties:
  15774. key:
  15775. description: |-
  15776. A key in the referenced Secret.
  15777. Some instances of this field may be defaulted, in others it may be required.
  15778. maxLength: 253
  15779. minLength: 1
  15780. pattern: ^[-._a-zA-Z0-9]+$
  15781. type: string
  15782. name:
  15783. description: The name of the Secret resource being referred to.
  15784. maxLength: 253
  15785. minLength: 1
  15786. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15787. type: string
  15788. namespace:
  15789. description: |-
  15790. The namespace of the Secret resource being referred to.
  15791. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15792. maxLength: 63
  15793. minLength: 1
  15794. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15795. type: string
  15796. type: object
  15797. accessTypeParam:
  15798. description: |-
  15799. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15800. In some instances, `key` is a required field.
  15801. properties:
  15802. key:
  15803. description: |-
  15804. A key in the referenced Secret.
  15805. Some instances of this field may be defaulted, in others it may be required.
  15806. maxLength: 253
  15807. minLength: 1
  15808. pattern: ^[-._a-zA-Z0-9]+$
  15809. type: string
  15810. name:
  15811. description: The name of the Secret resource being referred to.
  15812. maxLength: 253
  15813. minLength: 1
  15814. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15815. type: string
  15816. namespace:
  15817. description: |-
  15818. The namespace of the Secret resource being referred to.
  15819. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15820. maxLength: 63
  15821. minLength: 1
  15822. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15823. type: string
  15824. type: object
  15825. type: object
  15826. serviceAccountRef:
  15827. description: |-
  15828. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  15829. authentication on AKS Workload Identity. The operator obtains a federated
  15830. identity token from this ServiceAccount via the TokenRequest API instead
  15831. of using the ESO controller pod identity. Ignored for other access types.
  15832. properties:
  15833. audiences:
  15834. description: |-
  15835. Audience specifies the `aud` claim for the service account token
  15836. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15837. then this audiences will be appended to the list
  15838. items:
  15839. type: string
  15840. type: array
  15841. name:
  15842. description: The name of the ServiceAccount resource being referred to.
  15843. maxLength: 253
  15844. minLength: 1
  15845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15846. type: string
  15847. namespace:
  15848. description: |-
  15849. Namespace of the resource being referred to.
  15850. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15851. maxLength: 63
  15852. minLength: 1
  15853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15854. type: string
  15855. required:
  15856. - name
  15857. type: object
  15858. type: object
  15859. caBundle:
  15860. description: |-
  15861. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  15862. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  15863. are used to validate the TLS connection.
  15864. format: byte
  15865. type: string
  15866. caProvider:
  15867. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  15868. properties:
  15869. key:
  15870. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  15871. maxLength: 253
  15872. minLength: 1
  15873. pattern: ^[-._a-zA-Z0-9]+$
  15874. type: string
  15875. name:
  15876. description: The name of the object located at the provider type.
  15877. maxLength: 253
  15878. minLength: 1
  15879. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15880. type: string
  15881. namespace:
  15882. description: |-
  15883. The namespace the Provider type is in.
  15884. Can only be defined when used in a ClusterSecretStore.
  15885. maxLength: 63
  15886. minLength: 1
  15887. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15888. type: string
  15889. type:
  15890. description: The type of provider to use such as "Secret", or "ConfigMap".
  15891. enum:
  15892. - Secret
  15893. - ConfigMap
  15894. type: string
  15895. required:
  15896. - name
  15897. - type
  15898. type: object
  15899. ignoreCache:
  15900. description: |-
  15901. IgnoreCache bypasses the Gateway cache for secret reads when true.
  15902. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  15903. type: boolean
  15904. required:
  15905. - akeylessGWApiURL
  15906. - authSecretRef
  15907. type: object
  15908. aws:
  15909. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  15910. properties:
  15911. additionalRoles:
  15912. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  15913. items:
  15914. type: string
  15915. type: array
  15916. auth:
  15917. description: |-
  15918. Auth defines the information necessary to authenticate against AWS
  15919. if not set aws sdk will infer credentials from your environment
  15920. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  15921. properties:
  15922. jwt:
  15923. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  15924. properties:
  15925. serviceAccountRef:
  15926. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  15927. properties:
  15928. audiences:
  15929. description: |-
  15930. Audience specifies the `aud` claim for the service account token
  15931. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15932. then this audiences will be appended to the list
  15933. items:
  15934. type: string
  15935. type: array
  15936. name:
  15937. description: The name of the ServiceAccount resource being referred to.
  15938. maxLength: 253
  15939. minLength: 1
  15940. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15941. type: string
  15942. namespace:
  15943. description: |-
  15944. Namespace of the resource being referred to.
  15945. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15946. maxLength: 63
  15947. minLength: 1
  15948. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15949. type: string
  15950. required:
  15951. - name
  15952. type: object
  15953. type: object
  15954. secretRef:
  15955. description: |-
  15956. AWSAuthSecretRef holds secret references for AWS credentials
  15957. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  15958. properties:
  15959. accessKeyIDSecretRef:
  15960. description: The AccessKeyID is used for authentication
  15961. properties:
  15962. key:
  15963. description: |-
  15964. A key in the referenced Secret.
  15965. Some instances of this field may be defaulted, in others it may be required.
  15966. maxLength: 253
  15967. minLength: 1
  15968. pattern: ^[-._a-zA-Z0-9]+$
  15969. type: string
  15970. name:
  15971. description: The name of the Secret resource being referred to.
  15972. maxLength: 253
  15973. minLength: 1
  15974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15975. type: string
  15976. namespace:
  15977. description: |-
  15978. The namespace of the Secret resource being referred to.
  15979. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15980. maxLength: 63
  15981. minLength: 1
  15982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15983. type: string
  15984. type: object
  15985. secretAccessKeySecretRef:
  15986. description: The SecretAccessKey is used for authentication
  15987. properties:
  15988. key:
  15989. description: |-
  15990. A key in the referenced Secret.
  15991. Some instances of this field may be defaulted, in others it may be required.
  15992. maxLength: 253
  15993. minLength: 1
  15994. pattern: ^[-._a-zA-Z0-9]+$
  15995. type: string
  15996. name:
  15997. description: The name of the Secret resource being referred to.
  15998. maxLength: 253
  15999. minLength: 1
  16000. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16001. type: string
  16002. namespace:
  16003. description: |-
  16004. The namespace of the Secret resource being referred to.
  16005. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16006. maxLength: 63
  16007. minLength: 1
  16008. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16009. type: string
  16010. type: object
  16011. sessionTokenSecretRef:
  16012. description: |-
  16013. The SessionToken used for authentication
  16014. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  16015. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  16016. properties:
  16017. key:
  16018. description: |-
  16019. A key in the referenced Secret.
  16020. Some instances of this field may be defaulted, in others it may be required.
  16021. maxLength: 253
  16022. minLength: 1
  16023. pattern: ^[-._a-zA-Z0-9]+$
  16024. type: string
  16025. name:
  16026. description: The name of the Secret resource being referred to.
  16027. maxLength: 253
  16028. minLength: 1
  16029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16030. type: string
  16031. namespace:
  16032. description: |-
  16033. The namespace of the Secret resource being referred to.
  16034. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16035. maxLength: 63
  16036. minLength: 1
  16037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16038. type: string
  16039. type: object
  16040. type: object
  16041. type: object
  16042. customSessionTags:
  16043. additionalProperties:
  16044. type: string
  16045. description: |-
  16046. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  16047. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  16048. type: object
  16049. x-kubernetes-validations:
  16050. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  16051. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  16052. externalID:
  16053. description: AWS External ID set on assumed IAM roles
  16054. type: string
  16055. prefix:
  16056. description: Prefix adds a prefix to all retrieved values.
  16057. type: string
  16058. region:
  16059. description: AWS Region to be used for the provider
  16060. type: string
  16061. role:
  16062. description: Role is a Role ARN which the provider will assume
  16063. type: string
  16064. secretsManager:
  16065. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  16066. properties:
  16067. forceDeleteWithoutRecovery:
  16068. description: |-
  16069. Specifies whether to delete the secret without any recovery window. You
  16070. can't use both this parameter and RecoveryWindowInDays in the same call.
  16071. If you don't use either, then by default Secrets Manager uses a 30 day
  16072. recovery window.
  16073. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  16074. type: boolean
  16075. recoveryWindowInDays:
  16076. description: |-
  16077. The number of days from 7 to 30 that Secrets Manager waits before
  16078. permanently deleting the secret. You can't use both this parameter and
  16079. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  16080. then by default Secrets Manager uses a 30-day recovery window.
  16081. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  16082. format: int64
  16083. type: integer
  16084. type: object
  16085. service:
  16086. description: Service defines which service should be used to fetch the secrets
  16087. enum:
  16088. - SecretsManager
  16089. - ParameterStore
  16090. - CertificateManager
  16091. type: string
  16092. sessionTags:
  16093. description: AWS STS assume role session tags
  16094. items:
  16095. description: |-
  16096. Tag is a key-value pair that can be attached to an AWS resource.
  16097. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  16098. properties:
  16099. key:
  16100. type: string
  16101. value:
  16102. type: string
  16103. required:
  16104. - key
  16105. - value
  16106. type: object
  16107. type: array
  16108. sessionTagsPolicy:
  16109. default: None
  16110. description: |-
  16111. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  16112. None (default): no tags are added.
  16113. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  16114. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  16115. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  16116. enum:
  16117. - None
  16118. - Simple
  16119. - Custom
  16120. type: string
  16121. transitiveTagKeys:
  16122. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  16123. items:
  16124. type: string
  16125. type: array
  16126. required:
  16127. - region
  16128. - service
  16129. type: object
  16130. azurekv:
  16131. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  16132. properties:
  16133. authSecretRef:
  16134. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16135. properties:
  16136. clientCertificate:
  16137. description: The Azure ClientCertificate of the service principle used for authentication.
  16138. properties:
  16139. key:
  16140. description: |-
  16141. A key in the referenced Secret.
  16142. Some instances of this field may be defaulted, in others it may be required.
  16143. maxLength: 253
  16144. minLength: 1
  16145. pattern: ^[-._a-zA-Z0-9]+$
  16146. type: string
  16147. name:
  16148. description: The name of the Secret resource being referred to.
  16149. maxLength: 253
  16150. minLength: 1
  16151. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16152. type: string
  16153. namespace:
  16154. description: |-
  16155. The namespace of the Secret resource being referred to.
  16156. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16157. maxLength: 63
  16158. minLength: 1
  16159. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16160. type: string
  16161. type: object
  16162. clientId:
  16163. description: The Azure clientId of the service principle or managed identity used for authentication.
  16164. properties:
  16165. key:
  16166. description: |-
  16167. A key in the referenced Secret.
  16168. Some instances of this field may be defaulted, in others it may be required.
  16169. maxLength: 253
  16170. minLength: 1
  16171. pattern: ^[-._a-zA-Z0-9]+$
  16172. type: string
  16173. name:
  16174. description: The name of the Secret resource being referred to.
  16175. maxLength: 253
  16176. minLength: 1
  16177. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16178. type: string
  16179. namespace:
  16180. description: |-
  16181. The namespace of the Secret resource being referred to.
  16182. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16183. maxLength: 63
  16184. minLength: 1
  16185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16186. type: string
  16187. type: object
  16188. clientSecret:
  16189. description: The Azure ClientSecret of the service principle used for authentication.
  16190. properties:
  16191. key:
  16192. description: |-
  16193. A key in the referenced Secret.
  16194. Some instances of this field may be defaulted, in others it may be required.
  16195. maxLength: 253
  16196. minLength: 1
  16197. pattern: ^[-._a-zA-Z0-9]+$
  16198. type: string
  16199. name:
  16200. description: The name of the Secret resource being referred to.
  16201. maxLength: 253
  16202. minLength: 1
  16203. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16204. type: string
  16205. namespace:
  16206. description: |-
  16207. The namespace of the Secret resource being referred to.
  16208. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16209. maxLength: 63
  16210. minLength: 1
  16211. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16212. type: string
  16213. type: object
  16214. tenantId:
  16215. description: The Azure tenantId of the managed identity used for authentication.
  16216. properties:
  16217. key:
  16218. description: |-
  16219. A key in the referenced Secret.
  16220. Some instances of this field may be defaulted, in others it may be required.
  16221. maxLength: 253
  16222. minLength: 1
  16223. pattern: ^[-._a-zA-Z0-9]+$
  16224. type: string
  16225. name:
  16226. description: The name of the Secret resource being referred to.
  16227. maxLength: 253
  16228. minLength: 1
  16229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16230. type: string
  16231. namespace:
  16232. description: |-
  16233. The namespace of the Secret resource being referred to.
  16234. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16235. maxLength: 63
  16236. minLength: 1
  16237. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16238. type: string
  16239. type: object
  16240. type: object
  16241. authType:
  16242. default: ServicePrincipal
  16243. description: |-
  16244. Auth type defines how to authenticate to the keyvault service.
  16245. Valid values are:
  16246. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  16247. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  16248. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  16249. enum:
  16250. - ServicePrincipal
  16251. - ManagedIdentity
  16252. - WorkloadIdentity
  16253. type: string
  16254. customCloudConfig:
  16255. description: |-
  16256. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  16257. Required when EnvironmentType is AzureStackCloud.
  16258. Optional for other environment types - useful for Azure China when using Workload Identity
  16259. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  16260. standard China Cloud endpoint (login.chinacloudapi.cn).
  16261. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  16262. configuration is not supported with the legacy go-autorest SDK.
  16263. properties:
  16264. activeDirectoryEndpoint:
  16265. description: |-
  16266. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  16267. Required when using custom cloud configuration
  16268. type: string
  16269. keyVaultDNSSuffix:
  16270. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  16271. type: string
  16272. keyVaultEndpoint:
  16273. description: KeyVaultEndpoint is the Key Vault service endpoint
  16274. type: string
  16275. resourceManagerEndpoint:
  16276. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  16277. type: string
  16278. required:
  16279. - activeDirectoryEndpoint
  16280. type: object
  16281. environmentType:
  16282. default: PublicCloud
  16283. description: |-
  16284. EnvironmentType specifies the Azure cloud environment endpoints to use for
  16285. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  16286. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  16287. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  16288. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  16289. enum:
  16290. - PublicCloud
  16291. - USGovernmentCloud
  16292. - ChinaCloud
  16293. - GermanCloud
  16294. - AzureStackCloud
  16295. type: string
  16296. identityId:
  16297. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  16298. type: string
  16299. serviceAccountRef:
  16300. description: |-
  16301. ServiceAccountRef specified the service account
  16302. that should be used when authenticating with WorkloadIdentity.
  16303. properties:
  16304. audiences:
  16305. description: |-
  16306. Audience specifies the `aud` claim for the service account token
  16307. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  16308. then this audiences will be appended to the list
  16309. items:
  16310. type: string
  16311. type: array
  16312. name:
  16313. description: The name of the ServiceAccount resource being referred to.
  16314. maxLength: 253
  16315. minLength: 1
  16316. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16317. type: string
  16318. namespace:
  16319. description: |-
  16320. Namespace of the resource being referred to.
  16321. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16322. maxLength: 63
  16323. minLength: 1
  16324. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16325. type: string
  16326. required:
  16327. - name
  16328. type: object
  16329. tenantId:
  16330. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16331. type: string
  16332. useAzureSDK:
  16333. default: false
  16334. description: |-
  16335. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  16336. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  16337. type: boolean
  16338. vaultUrl:
  16339. description: Vault Url from which the secrets to be fetched from.
  16340. type: string
  16341. required:
  16342. - vaultUrl
  16343. type: object
  16344. barbican:
  16345. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  16346. properties:
  16347. auth:
  16348. description: BarbicanAuth contains the authentication information for Barbican.
  16349. properties:
  16350. password:
  16351. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  16352. properties:
  16353. secretRef:
  16354. description: |-
  16355. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16356. In some instances, `key` is a required field.
  16357. properties:
  16358. key:
  16359. description: |-
  16360. A key in the referenced Secret.
  16361. Some instances of this field may be defaulted, in others it may be required.
  16362. maxLength: 253
  16363. minLength: 1
  16364. pattern: ^[-._a-zA-Z0-9]+$
  16365. type: string
  16366. name:
  16367. description: The name of the Secret resource being referred to.
  16368. maxLength: 253
  16369. minLength: 1
  16370. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16371. type: string
  16372. namespace:
  16373. description: |-
  16374. The namespace of the Secret resource being referred to.
  16375. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16376. maxLength: 63
  16377. minLength: 1
  16378. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16379. type: string
  16380. type: object
  16381. required:
  16382. - secretRef
  16383. type: object
  16384. username:
  16385. description: BarbicanProviderUsernameRef defines a reference to a secret containing username for the Barbican provider.
  16386. maxProperties: 1
  16387. minProperties: 1
  16388. properties:
  16389. secretRef:
  16390. description: |-
  16391. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16392. In some instances, `key` is a required field.
  16393. properties:
  16394. key:
  16395. description: |-
  16396. A key in the referenced Secret.
  16397. Some instances of this field may be defaulted, in others it may be required.
  16398. maxLength: 253
  16399. minLength: 1
  16400. pattern: ^[-._a-zA-Z0-9]+$
  16401. type: string
  16402. name:
  16403. description: The name of the Secret resource being referred to.
  16404. maxLength: 253
  16405. minLength: 1
  16406. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16407. type: string
  16408. namespace:
  16409. description: |-
  16410. The namespace of the Secret resource being referred to.
  16411. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16412. maxLength: 63
  16413. minLength: 1
  16414. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16415. type: string
  16416. type: object
  16417. value:
  16418. type: string
  16419. type: object
  16420. required:
  16421. - password
  16422. - username
  16423. type: object
  16424. authURL:
  16425. type: string
  16426. domainName:
  16427. type: string
  16428. region:
  16429. type: string
  16430. tenantName:
  16431. type: string
  16432. required:
  16433. - auth
  16434. type: object
  16435. beyondtrust:
  16436. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  16437. properties:
  16438. auth:
  16439. description: Auth configures how the operator authenticates with Beyondtrust.
  16440. properties:
  16441. apiKey:
  16442. description: APIKey If not provided then ClientID/ClientSecret become required.
  16443. properties:
  16444. secretRef:
  16445. description: SecretRef references a key in a secret that will be used as value.
  16446. properties:
  16447. key:
  16448. description: |-
  16449. A key in the referenced Secret.
  16450. Some instances of this field may be defaulted, in others it may be required.
  16451. maxLength: 253
  16452. minLength: 1
  16453. pattern: ^[-._a-zA-Z0-9]+$
  16454. type: string
  16455. name:
  16456. description: The name of the Secret resource being referred to.
  16457. maxLength: 253
  16458. minLength: 1
  16459. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16460. type: string
  16461. namespace:
  16462. description: |-
  16463. The namespace of the Secret resource being referred to.
  16464. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16465. maxLength: 63
  16466. minLength: 1
  16467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16468. type: string
  16469. type: object
  16470. value:
  16471. description: Value can be specified directly to set a value without using a secret.
  16472. type: string
  16473. type: object
  16474. certificate:
  16475. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  16476. properties:
  16477. secretRef:
  16478. description: SecretRef references a key in a secret that will be used as value.
  16479. properties:
  16480. key:
  16481. description: |-
  16482. A key in the referenced Secret.
  16483. Some instances of this field may be defaulted, in others it may be required.
  16484. maxLength: 253
  16485. minLength: 1
  16486. pattern: ^[-._a-zA-Z0-9]+$
  16487. type: string
  16488. name:
  16489. description: The name of the Secret resource being referred to.
  16490. maxLength: 253
  16491. minLength: 1
  16492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16493. type: string
  16494. namespace:
  16495. description: |-
  16496. The namespace of the Secret resource being referred to.
  16497. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16498. maxLength: 63
  16499. minLength: 1
  16500. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16501. type: string
  16502. type: object
  16503. value:
  16504. description: Value can be specified directly to set a value without using a secret.
  16505. type: string
  16506. type: object
  16507. certificateKey:
  16508. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  16509. properties:
  16510. secretRef:
  16511. description: SecretRef references a key in a secret that will be used as value.
  16512. properties:
  16513. key:
  16514. description: |-
  16515. A key in the referenced Secret.
  16516. Some instances of this field may be defaulted, in others it may be required.
  16517. maxLength: 253
  16518. minLength: 1
  16519. pattern: ^[-._a-zA-Z0-9]+$
  16520. type: string
  16521. name:
  16522. description: The name of the Secret resource being referred to.
  16523. maxLength: 253
  16524. minLength: 1
  16525. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16526. type: string
  16527. namespace:
  16528. description: |-
  16529. The namespace of the Secret resource being referred to.
  16530. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16531. maxLength: 63
  16532. minLength: 1
  16533. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16534. type: string
  16535. type: object
  16536. value:
  16537. description: Value can be specified directly to set a value without using a secret.
  16538. type: string
  16539. type: object
  16540. clientId:
  16541. description: ClientID is the API OAuth Client ID.
  16542. properties:
  16543. secretRef:
  16544. description: SecretRef references a key in a secret that will be used as value.
  16545. properties:
  16546. key:
  16547. description: |-
  16548. A key in the referenced Secret.
  16549. Some instances of this field may be defaulted, in others it may be required.
  16550. maxLength: 253
  16551. minLength: 1
  16552. pattern: ^[-._a-zA-Z0-9]+$
  16553. type: string
  16554. name:
  16555. description: The name of the Secret resource being referred to.
  16556. maxLength: 253
  16557. minLength: 1
  16558. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16559. type: string
  16560. namespace:
  16561. description: |-
  16562. The namespace of the Secret resource being referred to.
  16563. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16564. maxLength: 63
  16565. minLength: 1
  16566. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16567. type: string
  16568. type: object
  16569. value:
  16570. description: Value can be specified directly to set a value without using a secret.
  16571. type: string
  16572. type: object
  16573. clientSecret:
  16574. description: ClientSecret is the API OAuth Client Secret.
  16575. properties:
  16576. secretRef:
  16577. description: SecretRef references a key in a secret that will be used as value.
  16578. properties:
  16579. key:
  16580. description: |-
  16581. A key in the referenced Secret.
  16582. Some instances of this field may be defaulted, in others it may be required.
  16583. maxLength: 253
  16584. minLength: 1
  16585. pattern: ^[-._a-zA-Z0-9]+$
  16586. type: string
  16587. name:
  16588. description: The name of the Secret resource being referred to.
  16589. maxLength: 253
  16590. minLength: 1
  16591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16592. type: string
  16593. namespace:
  16594. description: |-
  16595. The namespace of the Secret resource being referred to.
  16596. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16597. maxLength: 63
  16598. minLength: 1
  16599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16600. type: string
  16601. type: object
  16602. value:
  16603. description: Value can be specified directly to set a value without using a secret.
  16604. type: string
  16605. type: object
  16606. type: object
  16607. server:
  16608. description: Auth configures how API server works.
  16609. properties:
  16610. apiUrl:
  16611. type: string
  16612. apiVersion:
  16613. type: string
  16614. clientTimeOutSeconds:
  16615. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  16616. type: integer
  16617. decrypt:
  16618. default: true
  16619. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  16620. type: boolean
  16621. retrievalType:
  16622. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  16623. type: string
  16624. separator:
  16625. description: A character that separates the folder names.
  16626. type: string
  16627. verifyCA:
  16628. type: boolean
  16629. required:
  16630. - apiUrl
  16631. - verifyCA
  16632. type: object
  16633. required:
  16634. - auth
  16635. - server
  16636. type: object
  16637. beyondtrustworkloadcredentials:
  16638. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  16639. properties:
  16640. auth:
  16641. description: |-
  16642. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  16643. Currently supports API key authentication via Kubernetes secret reference.
  16644. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16645. properties:
  16646. apikey:
  16647. description: |-
  16648. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  16649. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  16650. properties:
  16651. token:
  16652. description: |-
  16653. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  16654. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  16655. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  16656. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16657. properties:
  16658. key:
  16659. description: |-
  16660. A key in the referenced Secret.
  16661. Some instances of this field may be defaulted, in others it may be required.
  16662. maxLength: 253
  16663. minLength: 1
  16664. pattern: ^[-._a-zA-Z0-9]+$
  16665. type: string
  16666. name:
  16667. description: The name of the Secret resource being referred to.
  16668. maxLength: 253
  16669. minLength: 1
  16670. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16671. type: string
  16672. namespace:
  16673. description: |-
  16674. The namespace of the Secret resource being referred to.
  16675. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16676. maxLength: 63
  16677. minLength: 1
  16678. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16679. type: string
  16680. type: object
  16681. required:
  16682. - token
  16683. type: object
  16684. required:
  16685. - apikey
  16686. type: object
  16687. caBundle:
  16688. description: |-
  16689. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  16690. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  16691. If not set, the system's trusted root certificates are used.
  16692. format: byte
  16693. type: string
  16694. caProvider:
  16695. description: |-
  16696. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  16697. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  16698. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  16699. properties:
  16700. key:
  16701. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16702. maxLength: 253
  16703. minLength: 1
  16704. pattern: ^[-._a-zA-Z0-9]+$
  16705. type: string
  16706. name:
  16707. description: The name of the object located at the provider type.
  16708. maxLength: 253
  16709. minLength: 1
  16710. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16711. type: string
  16712. namespace:
  16713. description: |-
  16714. The namespace the Provider type is in.
  16715. Can only be defined when used in a ClusterSecretStore.
  16716. maxLength: 63
  16717. minLength: 1
  16718. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16719. type: string
  16720. type:
  16721. description: The type of provider to use such as "Secret", or "ConfigMap".
  16722. enum:
  16723. - Secret
  16724. - ConfigMap
  16725. type: string
  16726. required:
  16727. - name
  16728. - type
  16729. type: object
  16730. folderPath:
  16731. description: |-
  16732. FolderPath specifies the default folder path for secret retrieval.
  16733. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  16734. Example: "production/database" or "dev/api-keys"
  16735. Leave empty to retrieve secrets from the root folder.
  16736. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  16737. type: string
  16738. server:
  16739. description: |-
  16740. Server configures the BeyondTrust Workload Credentials server connection details.
  16741. Includes the API URL and Site ID for your BeyondTrust instance.
  16742. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  16743. properties:
  16744. apiUrl:
  16745. description: |-
  16746. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  16747. This should be the full URL to your BeyondTrust instance.
  16748. Example: https://api.beyondtrust.io/siie
  16749. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  16750. type: string
  16751. siteId:
  16752. description: |-
  16753. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  16754. This identifier is unique to your BeyondTrust Workload Credentials instance.
  16755. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  16756. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  16757. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  16758. type: string
  16759. required:
  16760. - apiUrl
  16761. - siteId
  16762. type: object
  16763. required:
  16764. - auth
  16765. - server
  16766. type: object
  16767. bitwardensecretsmanager:
  16768. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  16769. properties:
  16770. apiURL:
  16771. type: string
  16772. auth:
  16773. description: |-
  16774. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  16775. Make sure that the token being used has permissions on the given secret.
  16776. properties:
  16777. secretRef:
  16778. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  16779. properties:
  16780. credentials:
  16781. description: AccessToken used for the bitwarden instance.
  16782. properties:
  16783. key:
  16784. description: |-
  16785. A key in the referenced Secret.
  16786. Some instances of this field may be defaulted, in others it may be required.
  16787. maxLength: 253
  16788. minLength: 1
  16789. pattern: ^[-._a-zA-Z0-9]+$
  16790. type: string
  16791. name:
  16792. description: The name of the Secret resource being referred to.
  16793. maxLength: 253
  16794. minLength: 1
  16795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16796. type: string
  16797. namespace:
  16798. description: |-
  16799. The namespace of the Secret resource being referred to.
  16800. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16801. maxLength: 63
  16802. minLength: 1
  16803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16804. type: string
  16805. type: object
  16806. required:
  16807. - credentials
  16808. type: object
  16809. required:
  16810. - secretRef
  16811. type: object
  16812. bitwardenServerSDKURL:
  16813. type: string
  16814. caBundle:
  16815. description: |-
  16816. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  16817. can be performed.
  16818. type: string
  16819. caProvider:
  16820. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  16821. properties:
  16822. key:
  16823. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16824. maxLength: 253
  16825. minLength: 1
  16826. pattern: ^[-._a-zA-Z0-9]+$
  16827. type: string
  16828. name:
  16829. description: The name of the object located at the provider type.
  16830. maxLength: 253
  16831. minLength: 1
  16832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16833. type: string
  16834. namespace:
  16835. description: |-
  16836. The namespace the Provider type is in.
  16837. Can only be defined when used in a ClusterSecretStore.
  16838. maxLength: 63
  16839. minLength: 1
  16840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16841. type: string
  16842. type:
  16843. description: The type of provider to use such as "Secret", or "ConfigMap".
  16844. enum:
  16845. - Secret
  16846. - ConfigMap
  16847. type: string
  16848. required:
  16849. - name
  16850. - type
  16851. type: object
  16852. identityURL:
  16853. type: string
  16854. organizationID:
  16855. description: OrganizationID determines which organization this secret store manages.
  16856. type: string
  16857. projectID:
  16858. description: ProjectID determines which project this secret store manages.
  16859. type: string
  16860. required:
  16861. - auth
  16862. - organizationID
  16863. - projectID
  16864. type: object
  16865. chef:
  16866. description: Chef configures this store to sync secrets with chef server
  16867. properties:
  16868. auth:
  16869. description: Auth defines the information necessary to authenticate against chef Server
  16870. properties:
  16871. secretRef:
  16872. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  16873. properties:
  16874. privateKeySecretRef:
  16875. description: SecretKey is the Signing Key in PEM format, used for authentication.
  16876. properties:
  16877. key:
  16878. description: |-
  16879. A key in the referenced Secret.
  16880. Some instances of this field may be defaulted, in others it may be required.
  16881. maxLength: 253
  16882. minLength: 1
  16883. pattern: ^[-._a-zA-Z0-9]+$
  16884. type: string
  16885. name:
  16886. description: The name of the Secret resource being referred to.
  16887. maxLength: 253
  16888. minLength: 1
  16889. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16890. type: string
  16891. namespace:
  16892. description: |-
  16893. The namespace of the Secret resource being referred to.
  16894. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16895. maxLength: 63
  16896. minLength: 1
  16897. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16898. type: string
  16899. type: object
  16900. required:
  16901. - privateKeySecretRef
  16902. type: object
  16903. required:
  16904. - secretRef
  16905. type: object
  16906. serverUrl:
  16907. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  16908. type: string
  16909. username:
  16910. description: UserName should be the user ID on the chef server
  16911. type: string
  16912. required:
  16913. - auth
  16914. - serverUrl
  16915. - username
  16916. type: object
  16917. cloudrusm:
  16918. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  16919. properties:
  16920. auth:
  16921. description: CSMAuth contains a secretRef for credentials.
  16922. properties:
  16923. secretRef:
  16924. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  16925. properties:
  16926. accessKeyIDSecretRef:
  16927. description: The AccessKeyID is used for authentication
  16928. properties:
  16929. key:
  16930. description: |-
  16931. A key in the referenced Secret.
  16932. Some instances of this field may be defaulted, in others it may be required.
  16933. maxLength: 253
  16934. minLength: 1
  16935. pattern: ^[-._a-zA-Z0-9]+$
  16936. type: string
  16937. name:
  16938. description: The name of the Secret resource being referred to.
  16939. maxLength: 253
  16940. minLength: 1
  16941. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16942. type: string
  16943. namespace:
  16944. description: |-
  16945. The namespace of the Secret resource being referred to.
  16946. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16947. maxLength: 63
  16948. minLength: 1
  16949. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16950. type: string
  16951. type: object
  16952. accessKeySecretSecretRef:
  16953. description: The AccessKeySecret is used for authentication
  16954. properties:
  16955. key:
  16956. description: |-
  16957. A key in the referenced Secret.
  16958. Some instances of this field may be defaulted, in others it may be required.
  16959. maxLength: 253
  16960. minLength: 1
  16961. pattern: ^[-._a-zA-Z0-9]+$
  16962. type: string
  16963. name:
  16964. description: The name of the Secret resource being referred to.
  16965. maxLength: 253
  16966. minLength: 1
  16967. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16968. type: string
  16969. namespace:
  16970. description: |-
  16971. The namespace of the Secret resource being referred to.
  16972. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16973. maxLength: 63
  16974. minLength: 1
  16975. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16976. type: string
  16977. type: object
  16978. required:
  16979. - accessKeyIDSecretRef
  16980. - accessKeySecretSecretRef
  16981. type: object
  16982. type: object
  16983. projectID:
  16984. description: ProjectID is the project, which the secrets are stored in.
  16985. type: string
  16986. required:
  16987. - auth
  16988. type: object
  16989. conjur:
  16990. description: Conjur configures this store to sync secrets using conjur provider
  16991. properties:
  16992. auth:
  16993. description: Defines authentication settings for connecting to Conjur.
  16994. maxProperties: 1
  16995. minProperties: 1
  16996. properties:
  16997. apikey:
  16998. description: Authenticates with Conjur using an API key.
  16999. properties:
  17000. account:
  17001. description: Account is the Conjur organization account name.
  17002. type: string
  17003. apiKeyRef:
  17004. description: |-
  17005. A reference to a specific 'key' containing the Conjur API key
  17006. within a Secret resource. In some instances, `key` is a required field.
  17007. properties:
  17008. key:
  17009. description: |-
  17010. A key in the referenced Secret.
  17011. Some instances of this field may be defaulted, in others it may be required.
  17012. maxLength: 253
  17013. minLength: 1
  17014. pattern: ^[-._a-zA-Z0-9]+$
  17015. type: string
  17016. name:
  17017. description: The name of the Secret resource being referred to.
  17018. maxLength: 253
  17019. minLength: 1
  17020. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17021. type: string
  17022. namespace:
  17023. description: |-
  17024. The namespace of the Secret resource being referred to.
  17025. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17026. maxLength: 63
  17027. minLength: 1
  17028. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17029. type: string
  17030. type: object
  17031. userRef:
  17032. description: |-
  17033. A reference to a specific 'key' containing the Conjur username
  17034. within a Secret resource. In some instances, `key` is a required field.
  17035. properties:
  17036. key:
  17037. description: |-
  17038. A key in the referenced Secret.
  17039. Some instances of this field may be defaulted, in others it may be required.
  17040. maxLength: 253
  17041. minLength: 1
  17042. pattern: ^[-._a-zA-Z0-9]+$
  17043. type: string
  17044. name:
  17045. description: The name of the Secret resource being referred to.
  17046. maxLength: 253
  17047. minLength: 1
  17048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17049. type: string
  17050. namespace:
  17051. description: |-
  17052. The namespace of the Secret resource being referred to.
  17053. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17054. maxLength: 63
  17055. minLength: 1
  17056. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17057. type: string
  17058. type: object
  17059. required:
  17060. - account
  17061. - apiKeyRef
  17062. - userRef
  17063. type: object
  17064. cert:
  17065. description: Cert enables certificate-based authentication using a client certificate and key.
  17066. properties:
  17067. account:
  17068. description: Account is the Conjur organization account name.
  17069. type: string
  17070. clientCertRef:
  17071. description: |-
  17072. ClientCertRef is a reference to a specific 'key' containing the client certificate
  17073. within a Secret resource. The certificate must be PEM-encoded.
  17074. properties:
  17075. key:
  17076. description: |-
  17077. A key in the referenced Secret.
  17078. Some instances of this field may be defaulted, in others it may be required.
  17079. maxLength: 253
  17080. minLength: 1
  17081. pattern: ^[-._a-zA-Z0-9]+$
  17082. type: string
  17083. name:
  17084. description: The name of the Secret resource being referred to.
  17085. maxLength: 253
  17086. minLength: 1
  17087. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17088. type: string
  17089. namespace:
  17090. description: |-
  17091. The namespace of the Secret resource being referred to.
  17092. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17093. maxLength: 63
  17094. minLength: 1
  17095. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17096. type: string
  17097. type: object
  17098. clientKeyRef:
  17099. description: |-
  17100. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  17101. within a Secret resource. The key must be PEM-encoded.
  17102. properties:
  17103. key:
  17104. description: |-
  17105. A key in the referenced Secret.
  17106. Some instances of this field may be defaulted, in others it may be required.
  17107. maxLength: 253
  17108. minLength: 1
  17109. pattern: ^[-._a-zA-Z0-9]+$
  17110. type: string
  17111. name:
  17112. description: The name of the Secret resource being referred to.
  17113. maxLength: 253
  17114. minLength: 1
  17115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17116. type: string
  17117. namespace:
  17118. description: |-
  17119. The namespace of the Secret resource being referred to.
  17120. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17121. maxLength: 63
  17122. minLength: 1
  17123. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17124. type: string
  17125. type: object
  17126. hostId:
  17127. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  17128. type: string
  17129. serviceID:
  17130. description: The conjur authn cert webservice id
  17131. type: string
  17132. required:
  17133. - account
  17134. - clientCertRef
  17135. - clientKeyRef
  17136. - serviceID
  17137. type: object
  17138. jwt:
  17139. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  17140. properties:
  17141. account:
  17142. description: Account is the Conjur organization account name.
  17143. type: string
  17144. hostId:
  17145. description: |-
  17146. Optional HostID for JWT authentication. This may be used depending
  17147. on how the Conjur JWT authenticator policy is configured.
  17148. type: string
  17149. secretRef:
  17150. description: |-
  17151. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  17152. authenticate with Conjur using the JWT authentication method.
  17153. properties:
  17154. key:
  17155. description: |-
  17156. A key in the referenced Secret.
  17157. Some instances of this field may be defaulted, in others it may be required.
  17158. maxLength: 253
  17159. minLength: 1
  17160. pattern: ^[-._a-zA-Z0-9]+$
  17161. type: string
  17162. name:
  17163. description: The name of the Secret resource being referred to.
  17164. maxLength: 253
  17165. minLength: 1
  17166. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17167. type: string
  17168. namespace:
  17169. description: |-
  17170. The namespace of the Secret resource being referred to.
  17171. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17172. maxLength: 63
  17173. minLength: 1
  17174. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17175. type: string
  17176. type: object
  17177. serviceAccountRef:
  17178. description: |-
  17179. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  17180. a token for with the `TokenRequest` API.
  17181. properties:
  17182. audiences:
  17183. description: |-
  17184. Audience specifies the `aud` claim for the service account token
  17185. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17186. then this audiences will be appended to the list
  17187. items:
  17188. type: string
  17189. type: array
  17190. name:
  17191. description: The name of the ServiceAccount resource being referred to.
  17192. maxLength: 253
  17193. minLength: 1
  17194. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17195. type: string
  17196. namespace:
  17197. description: |-
  17198. Namespace of the resource being referred to.
  17199. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17200. maxLength: 63
  17201. minLength: 1
  17202. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17203. type: string
  17204. required:
  17205. - name
  17206. type: object
  17207. serviceID:
  17208. description: The conjur authn jwt webservice id
  17209. type: string
  17210. required:
  17211. - account
  17212. - serviceID
  17213. type: object
  17214. type: object
  17215. caBundle:
  17216. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  17217. type: string
  17218. caProvider:
  17219. description: |-
  17220. Used to provide custom certificate authority (CA) certificates
  17221. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  17222. that contains a PEM-encoded certificate.
  17223. properties:
  17224. key:
  17225. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17226. maxLength: 253
  17227. minLength: 1
  17228. pattern: ^[-._a-zA-Z0-9]+$
  17229. type: string
  17230. name:
  17231. description: The name of the object located at the provider type.
  17232. maxLength: 253
  17233. minLength: 1
  17234. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17235. type: string
  17236. namespace:
  17237. description: |-
  17238. The namespace the Provider type is in.
  17239. Can only be defined when used in a ClusterSecretStore.
  17240. maxLength: 63
  17241. minLength: 1
  17242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17243. type: string
  17244. type:
  17245. description: The type of provider to use such as "Secret", or "ConfigMap".
  17246. enum:
  17247. - Secret
  17248. - ConfigMap
  17249. type: string
  17250. required:
  17251. - name
  17252. - type
  17253. type: object
  17254. url:
  17255. description: URL is the endpoint of the Conjur instance.
  17256. type: string
  17257. required:
  17258. - auth
  17259. - url
  17260. type: object
  17261. crd:
  17262. description: |-
  17263. CRD configures this store to sync secrets from arbitrary Kubernetes resources,
  17264. including both custom resources (CRDs) and core API resources. Resources are
  17265. selected by API group, version and kind, where group can be "" (empty string)
  17266. for core resources such as ConfigMap. Reading the core v1 Secret is
  17267. intentionally blocked — use the Kubernetes provider for that.
  17268. properties:
  17269. auth:
  17270. description: |-
  17271. Auth configures authentication to the Kubernetes API, same as the
  17272. Kubernetes provider. Required when Server.URL is set (unless using AuthRef).
  17273. maxProperties: 1
  17274. minProperties: 1
  17275. properties:
  17276. cert:
  17277. description: has both clientCert and clientKey as secretKeySelector
  17278. properties:
  17279. clientCert:
  17280. description: |-
  17281. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17282. In some instances, `key` is a required field.
  17283. properties:
  17284. key:
  17285. description: |-
  17286. A key in the referenced Secret.
  17287. Some instances of this field may be defaulted, in others it may be required.
  17288. maxLength: 253
  17289. minLength: 1
  17290. pattern: ^[-._a-zA-Z0-9]+$
  17291. type: string
  17292. name:
  17293. description: The name of the Secret resource being referred to.
  17294. maxLength: 253
  17295. minLength: 1
  17296. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17297. type: string
  17298. namespace:
  17299. description: |-
  17300. The namespace of the Secret resource being referred to.
  17301. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17302. maxLength: 63
  17303. minLength: 1
  17304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17305. type: string
  17306. type: object
  17307. clientKey:
  17308. description: |-
  17309. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17310. In some instances, `key` is a required field.
  17311. properties:
  17312. key:
  17313. description: |-
  17314. A key in the referenced Secret.
  17315. Some instances of this field may be defaulted, in others it may be required.
  17316. maxLength: 253
  17317. minLength: 1
  17318. pattern: ^[-._a-zA-Z0-9]+$
  17319. type: string
  17320. name:
  17321. description: The name of the Secret resource being referred to.
  17322. maxLength: 253
  17323. minLength: 1
  17324. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17325. type: string
  17326. namespace:
  17327. description: |-
  17328. The namespace of the Secret resource being referred to.
  17329. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17330. maxLength: 63
  17331. minLength: 1
  17332. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17333. type: string
  17334. type: object
  17335. required:
  17336. - clientCert
  17337. - clientKey
  17338. type: object
  17339. serviceAccount:
  17340. description: points to a service account that should be used for authentication
  17341. properties:
  17342. audiences:
  17343. description: |-
  17344. Audience specifies the `aud` claim for the service account token
  17345. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17346. then this audiences will be appended to the list
  17347. items:
  17348. type: string
  17349. type: array
  17350. name:
  17351. description: The name of the ServiceAccount resource being referred to.
  17352. maxLength: 253
  17353. minLength: 1
  17354. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17355. type: string
  17356. namespace:
  17357. description: |-
  17358. Namespace of the resource being referred to.
  17359. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17360. maxLength: 63
  17361. minLength: 1
  17362. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17363. type: string
  17364. required:
  17365. - name
  17366. type: object
  17367. token:
  17368. description: use static token to authenticate with
  17369. properties:
  17370. bearerToken:
  17371. description: |-
  17372. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17373. In some instances, `key` is a required field.
  17374. properties:
  17375. key:
  17376. description: |-
  17377. A key in the referenced Secret.
  17378. Some instances of this field may be defaulted, in others it may be required.
  17379. maxLength: 253
  17380. minLength: 1
  17381. pattern: ^[-._a-zA-Z0-9]+$
  17382. type: string
  17383. name:
  17384. description: The name of the Secret resource being referred to.
  17385. maxLength: 253
  17386. minLength: 1
  17387. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17388. type: string
  17389. namespace:
  17390. description: |-
  17391. The namespace of the Secret resource being referred to.
  17392. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17393. maxLength: 63
  17394. minLength: 1
  17395. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17396. type: string
  17397. type: object
  17398. required:
  17399. - bearerToken
  17400. type: object
  17401. type: object
  17402. authRef:
  17403. description: |-
  17404. AuthRef references a Secret containing a kubeconfig. Same semantics as the
  17405. Kubernetes provider.
  17406. properties:
  17407. key:
  17408. description: |-
  17409. A key in the referenced Secret.
  17410. Some instances of this field may be defaulted, in others it may be required.
  17411. maxLength: 253
  17412. minLength: 1
  17413. pattern: ^[-._a-zA-Z0-9]+$
  17414. type: string
  17415. name:
  17416. description: The name of the Secret resource being referred to.
  17417. maxLength: 253
  17418. minLength: 1
  17419. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17420. type: string
  17421. namespace:
  17422. description: |-
  17423. The namespace of the Secret resource being referred to.
  17424. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17425. maxLength: 63
  17426. minLength: 1
  17427. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17428. type: string
  17429. type: object
  17430. resource:
  17431. description: Resource identifies the CRD by its API group, version and kind.
  17432. properties:
  17433. group:
  17434. description: |-
  17435. Group is the API group of the resource. Use "" (empty string) for core
  17436. Kubernetes resources such as ConfigMap; use e.g. "config.example.io"
  17437. for a CRD. The field is required to be present in the manifest — write
  17438. `group: ""` explicitly for core resources so typos fail at admission
  17439. time rather than later at discovery.
  17440. type: string
  17441. kind:
  17442. description: Kind is the Kubernetes resource kind (e.g. "MyCustomResource").
  17443. minLength: 1
  17444. type: string
  17445. version:
  17446. description: Version is the API version of the resource (e.g. "v1alpha1").
  17447. minLength: 1
  17448. type: string
  17449. required:
  17450. - group
  17451. - kind
  17452. - version
  17453. type: object
  17454. server:
  17455. description: |-
  17456. Server configures the Kubernetes API address and TLS trust, same as the
  17457. Kubernetes provider. When omitted, the URL defaults to the in-cluster API.
  17458. properties:
  17459. caBundle:
  17460. description: CABundle is a base64-encoded CA certificate
  17461. format: byte
  17462. type: string
  17463. caProvider:
  17464. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  17465. properties:
  17466. key:
  17467. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17468. maxLength: 253
  17469. minLength: 1
  17470. pattern: ^[-._a-zA-Z0-9]+$
  17471. type: string
  17472. name:
  17473. description: The name of the object located at the provider type.
  17474. maxLength: 253
  17475. minLength: 1
  17476. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17477. type: string
  17478. namespace:
  17479. description: |-
  17480. The namespace the Provider type is in.
  17481. Can only be defined when used in a ClusterSecretStore.
  17482. maxLength: 63
  17483. minLength: 1
  17484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17485. type: string
  17486. type:
  17487. description: The type of provider to use such as "Secret", or "ConfigMap".
  17488. enum:
  17489. - Secret
  17490. - ConfigMap
  17491. type: string
  17492. required:
  17493. - name
  17494. - type
  17495. type: object
  17496. url:
  17497. default: kubernetes.default
  17498. description: configures the Kubernetes server Address.
  17499. type: string
  17500. type: object
  17501. whitelist:
  17502. description: |-
  17503. Whitelist optionally restricts which object names and requested properties
  17504. are allowed to be read.
  17505. properties:
  17506. rules:
  17507. description: |-
  17508. Rules is a list of allow rules. If rules are set, at least one rule must
  17509. match for a request to be allowed.
  17510. items:
  17511. description: CRDProviderWhitelistRule defines a single allow rule for CRD reads.
  17512. properties:
  17513. name:
  17514. description: |-
  17515. Name is an optional regular expression matched against the bare object name.
  17516. For both SecretStore and ClusterSecretStore this is always the object name
  17517. without any namespace prefix (e.g. "my-db-spec", not "prod/my-db-spec").
  17518. type: string
  17519. namespace:
  17520. description: |-
  17521. Namespace is an optional regular expression matched against the namespace of
  17522. the object. Applies only when a ClusterSecretStore is used; it is ignored
  17523. for SecretStore (where the namespace is fixed to the store namespace).
  17524. type: string
  17525. properties:
  17526. description: |-
  17527. Properties is an optional list of regular expressions matched against
  17528. requested property keys (for example: "spec.secretValue").
  17529. items:
  17530. type: string
  17531. type: array
  17532. type: object
  17533. type: array
  17534. type: object
  17535. required:
  17536. - resource
  17537. type: object
  17538. x-kubernetes-validations:
  17539. - message: one of auth or authRef is required
  17540. rule: has(self.auth) || has(self.authRef)
  17541. - message: at most one of the fields in [auth authRef] may be set
  17542. rule: '[has(self.auth),has(self.authRef)].filter(x,x==true).size() <= 1'
  17543. delinea:
  17544. description: |-
  17545. Delinea DevOps Secrets Vault
  17546. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  17547. properties:
  17548. clientId:
  17549. description: ClientID is the non-secret part of the credential.
  17550. properties:
  17551. secretRef:
  17552. description: SecretRef references a key in a secret that will be used as value.
  17553. properties:
  17554. key:
  17555. description: |-
  17556. A key in the referenced Secret.
  17557. Some instances of this field may be defaulted, in others it may be required.
  17558. maxLength: 253
  17559. minLength: 1
  17560. pattern: ^[-._a-zA-Z0-9]+$
  17561. type: string
  17562. name:
  17563. description: The name of the Secret resource being referred to.
  17564. maxLength: 253
  17565. minLength: 1
  17566. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17567. type: string
  17568. namespace:
  17569. description: |-
  17570. The namespace of the Secret resource being referred to.
  17571. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17572. maxLength: 63
  17573. minLength: 1
  17574. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17575. type: string
  17576. type: object
  17577. value:
  17578. description: Value can be specified directly to set a value without using a secret.
  17579. type: string
  17580. type: object
  17581. clientSecret:
  17582. description: ClientSecret is the secret part of the credential.
  17583. properties:
  17584. secretRef:
  17585. description: SecretRef references a key in a secret that will be used as value.
  17586. properties:
  17587. key:
  17588. description: |-
  17589. A key in the referenced Secret.
  17590. Some instances of this field may be defaulted, in others it may be required.
  17591. maxLength: 253
  17592. minLength: 1
  17593. pattern: ^[-._a-zA-Z0-9]+$
  17594. type: string
  17595. name:
  17596. description: The name of the Secret resource being referred to.
  17597. maxLength: 253
  17598. minLength: 1
  17599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17600. type: string
  17601. namespace:
  17602. description: |-
  17603. The namespace of the Secret resource being referred to.
  17604. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17605. maxLength: 63
  17606. minLength: 1
  17607. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17608. type: string
  17609. type: object
  17610. value:
  17611. description: Value can be specified directly to set a value without using a secret.
  17612. type: string
  17613. type: object
  17614. tenant:
  17615. description: Tenant is the chosen hostname / site name.
  17616. type: string
  17617. tld:
  17618. description: |-
  17619. TLD is based on the server location that was chosen during provisioning.
  17620. If unset, defaults to "com".
  17621. type: string
  17622. urlTemplate:
  17623. description: |-
  17624. URLTemplate
  17625. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  17626. type: string
  17627. required:
  17628. - clientId
  17629. - clientSecret
  17630. - tenant
  17631. type: object
  17632. doppler:
  17633. description: Doppler configures this store to sync secrets using the Doppler provider
  17634. properties:
  17635. auth:
  17636. description: Auth configures how the Operator authenticates with the Doppler API
  17637. properties:
  17638. oidcConfig:
  17639. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  17640. properties:
  17641. expirationSeconds:
  17642. default: 600
  17643. description: |-
  17644. ExpirationSeconds sets the ServiceAccount token validity duration.
  17645. Defaults to 10 minutes.
  17646. format: int64
  17647. type: integer
  17648. identity:
  17649. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  17650. type: string
  17651. serviceAccountRef:
  17652. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  17653. properties:
  17654. audiences:
  17655. description: |-
  17656. Audience specifies the `aud` claim for the service account token
  17657. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17658. then this audiences will be appended to the list
  17659. items:
  17660. type: string
  17661. type: array
  17662. name:
  17663. description: The name of the ServiceAccount resource being referred to.
  17664. maxLength: 253
  17665. minLength: 1
  17666. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17667. type: string
  17668. namespace:
  17669. description: |-
  17670. Namespace of the resource being referred to.
  17671. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17672. maxLength: 63
  17673. minLength: 1
  17674. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17675. type: string
  17676. required:
  17677. - name
  17678. type: object
  17679. required:
  17680. - identity
  17681. - serviceAccountRef
  17682. type: object
  17683. secretRef:
  17684. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  17685. properties:
  17686. dopplerToken:
  17687. description: |-
  17688. The DopplerToken is used for authentication.
  17689. See https://docs.doppler.com/reference/api#authentication for auth token types.
  17690. The Key attribute defaults to dopplerToken if not specified.
  17691. properties:
  17692. key:
  17693. description: |-
  17694. A key in the referenced Secret.
  17695. Some instances of this field may be defaulted, in others it may be required.
  17696. maxLength: 253
  17697. minLength: 1
  17698. pattern: ^[-._a-zA-Z0-9]+$
  17699. type: string
  17700. name:
  17701. description: The name of the Secret resource being referred to.
  17702. maxLength: 253
  17703. minLength: 1
  17704. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17705. type: string
  17706. namespace:
  17707. description: |-
  17708. The namespace of the Secret resource being referred to.
  17709. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17710. maxLength: 63
  17711. minLength: 1
  17712. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17713. type: string
  17714. type: object
  17715. required:
  17716. - dopplerToken
  17717. type: object
  17718. type: object
  17719. x-kubernetes-validations:
  17720. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  17721. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  17722. config:
  17723. description: Doppler config (required if not using a Service Token)
  17724. type: string
  17725. format:
  17726. description: Format enables the downloading of secrets as a file (string)
  17727. enum:
  17728. - json
  17729. - dotnet-json
  17730. - env
  17731. - yaml
  17732. - docker
  17733. type: string
  17734. nameTransformer:
  17735. description: Environment variable compatible name transforms that change secret names to a different format
  17736. enum:
  17737. - upper-camel
  17738. - camel
  17739. - lower-snake
  17740. - tf-var
  17741. - dotnet-env
  17742. - lower-kebab
  17743. type: string
  17744. project:
  17745. description: Doppler project (required if not using a Service Token)
  17746. type: string
  17747. required:
  17748. - auth
  17749. type: object
  17750. dvls:
  17751. description: DVLS configures this store to sync secrets using Devolutions Server provider
  17752. properties:
  17753. auth:
  17754. description: Auth defines the authentication method to use.
  17755. properties:
  17756. secretRef:
  17757. description: SecretRef contains the Application ID and Application Secret for authentication.
  17758. properties:
  17759. appId:
  17760. description: AppID is the reference to the secret containing the Application ID.
  17761. properties:
  17762. key:
  17763. description: |-
  17764. A key in the referenced Secret.
  17765. Some instances of this field may be defaulted, in others it may be required.
  17766. maxLength: 253
  17767. minLength: 1
  17768. pattern: ^[-._a-zA-Z0-9]+$
  17769. type: string
  17770. name:
  17771. description: The name of the Secret resource being referred to.
  17772. maxLength: 253
  17773. minLength: 1
  17774. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17775. type: string
  17776. namespace:
  17777. description: |-
  17778. The namespace of the Secret resource being referred to.
  17779. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17780. maxLength: 63
  17781. minLength: 1
  17782. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17783. type: string
  17784. type: object
  17785. appSecret:
  17786. description: AppSecret is the reference to the secret containing the Application Secret.
  17787. properties:
  17788. key:
  17789. description: |-
  17790. A key in the referenced Secret.
  17791. Some instances of this field may be defaulted, in others it may be required.
  17792. maxLength: 253
  17793. minLength: 1
  17794. pattern: ^[-._a-zA-Z0-9]+$
  17795. type: string
  17796. name:
  17797. description: The name of the Secret resource being referred to.
  17798. maxLength: 253
  17799. minLength: 1
  17800. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17801. type: string
  17802. namespace:
  17803. description: |-
  17804. The namespace of the Secret resource being referred to.
  17805. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17806. maxLength: 63
  17807. minLength: 1
  17808. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17809. type: string
  17810. type: object
  17811. required:
  17812. - appId
  17813. - appSecret
  17814. type: object
  17815. required:
  17816. - secretRef
  17817. type: object
  17818. insecure:
  17819. description: |-
  17820. Insecure allows connecting to DVLS over plain HTTP.
  17821. This is NOT RECOMMENDED for production use.
  17822. Set to true only if you understand the security implications.
  17823. type: boolean
  17824. serverUrl:
  17825. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  17826. type: string
  17827. vault:
  17828. description: |-
  17829. Vault is the name or UUID of the vault to fetch secrets from.
  17830. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  17831. type: string
  17832. required:
  17833. - auth
  17834. - serverUrl
  17835. type: object
  17836. fake:
  17837. description: Fake configures a store with static key/value pairs
  17838. properties:
  17839. data:
  17840. items:
  17841. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  17842. properties:
  17843. key:
  17844. type: string
  17845. value:
  17846. type: string
  17847. version:
  17848. type: string
  17849. required:
  17850. - key
  17851. - value
  17852. type: object
  17853. type: array
  17854. validationResult:
  17855. description: ValidationResult is defined type for the number of validation results.
  17856. type: integer
  17857. required:
  17858. - data
  17859. type: object
  17860. fortanix:
  17861. description: Fortanix configures this store to sync secrets using the Fortanix provider
  17862. properties:
  17863. apiKey:
  17864. description: APIKey is the API token to access SDKMS Applications.
  17865. properties:
  17866. secretRef:
  17867. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  17868. properties:
  17869. key:
  17870. description: |-
  17871. A key in the referenced Secret.
  17872. Some instances of this field may be defaulted, in others it may be required.
  17873. maxLength: 253
  17874. minLength: 1
  17875. pattern: ^[-._a-zA-Z0-9]+$
  17876. type: string
  17877. name:
  17878. description: The name of the Secret resource being referred to.
  17879. maxLength: 253
  17880. minLength: 1
  17881. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17882. type: string
  17883. namespace:
  17884. description: |-
  17885. The namespace of the Secret resource being referred to.
  17886. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17887. maxLength: 63
  17888. minLength: 1
  17889. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17890. type: string
  17891. type: object
  17892. type: object
  17893. apiUrl:
  17894. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  17895. type: string
  17896. type: object
  17897. gcpsm:
  17898. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  17899. properties:
  17900. auth:
  17901. description: Auth defines the information necessary to authenticate against GCP
  17902. properties:
  17903. secretRef:
  17904. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  17905. properties:
  17906. secretAccessKeySecretRef:
  17907. description: The SecretAccessKey is used for authentication
  17908. properties:
  17909. key:
  17910. description: |-
  17911. A key in the referenced Secret.
  17912. Some instances of this field may be defaulted, in others it may be required.
  17913. maxLength: 253
  17914. minLength: 1
  17915. pattern: ^[-._a-zA-Z0-9]+$
  17916. type: string
  17917. name:
  17918. description: The name of the Secret resource being referred to.
  17919. maxLength: 253
  17920. minLength: 1
  17921. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17922. type: string
  17923. namespace:
  17924. description: |-
  17925. The namespace of the Secret resource being referred to.
  17926. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17927. maxLength: 63
  17928. minLength: 1
  17929. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17930. type: string
  17931. type: object
  17932. type: object
  17933. workloadIdentity:
  17934. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  17935. properties:
  17936. clusterLocation:
  17937. description: |-
  17938. ClusterLocation is the location of the cluster
  17939. If not specified, it fetches information from the metadata server
  17940. type: string
  17941. clusterName:
  17942. description: |-
  17943. ClusterName is the name of the cluster
  17944. If not specified, it fetches information from the metadata server
  17945. type: string
  17946. clusterProjectID:
  17947. description: |-
  17948. ClusterProjectID is the project ID of the cluster
  17949. If not specified, it fetches information from the metadata server
  17950. type: string
  17951. serviceAccountRef:
  17952. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  17953. properties:
  17954. audiences:
  17955. description: |-
  17956. Audience specifies the `aud` claim for the service account token
  17957. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17958. then this audiences will be appended to the list
  17959. items:
  17960. type: string
  17961. type: array
  17962. name:
  17963. description: The name of the ServiceAccount resource being referred to.
  17964. maxLength: 253
  17965. minLength: 1
  17966. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17967. type: string
  17968. namespace:
  17969. description: |-
  17970. Namespace of the resource being referred to.
  17971. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17972. maxLength: 63
  17973. minLength: 1
  17974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17975. type: string
  17976. required:
  17977. - name
  17978. type: object
  17979. required:
  17980. - serviceAccountRef
  17981. type: object
  17982. workloadIdentityFederation:
  17983. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  17984. properties:
  17985. audience:
  17986. description: |-
  17987. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  17988. If specified, Audience found in the external account credential config will be overridden with the configured value.
  17989. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  17990. type: string
  17991. awsSecurityCredentials:
  17992. description: |-
  17993. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  17994. when using the AWS metadata server is not an option.
  17995. properties:
  17996. awsCredentialsSecretRef:
  17997. description: |-
  17998. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  17999. Secret should be created with below names for keys
  18000. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  18001. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  18002. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  18003. properties:
  18004. name:
  18005. description: name of the secret.
  18006. maxLength: 253
  18007. minLength: 1
  18008. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18009. type: string
  18010. namespace:
  18011. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  18012. maxLength: 63
  18013. minLength: 1
  18014. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18015. type: string
  18016. required:
  18017. - name
  18018. type: object
  18019. region:
  18020. description: region is for configuring the AWS region to be used.
  18021. example: ap-south-1
  18022. maxLength: 50
  18023. minLength: 1
  18024. pattern: ^[a-z0-9-]+$
  18025. type: string
  18026. required:
  18027. - awsCredentialsSecretRef
  18028. - region
  18029. type: object
  18030. credConfig:
  18031. description: |-
  18032. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  18033. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  18034. serviceAccountRef must be used by providing operators service account details.
  18035. properties:
  18036. key:
  18037. description: key name holding the external account credential config.
  18038. maxLength: 253
  18039. minLength: 1
  18040. pattern: ^[-._a-zA-Z0-9]+$
  18041. type: string
  18042. name:
  18043. description: name of the configmap.
  18044. maxLength: 253
  18045. minLength: 1
  18046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18047. type: string
  18048. namespace:
  18049. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  18050. maxLength: 63
  18051. minLength: 1
  18052. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18053. type: string
  18054. required:
  18055. - key
  18056. - name
  18057. type: object
  18058. externalTokenEndpoint:
  18059. description: |-
  18060. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  18061. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  18062. URL is having the expected value.
  18063. type: string
  18064. gcpServiceAccountEmail:
  18065. description: |-
  18066. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  18067. after Workload Identity Federation. Use this to grant access through the service account's
  18068. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  18069. service_account_impersonation_url in the external account JSON from credConfig;
  18070. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  18071. on that ServiceAccount.
  18072. example: my-gsa@my-project.iam.gserviceaccount.com
  18073. minLength: 1
  18074. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  18075. type: string
  18076. serviceAccountRef:
  18077. description: |-
  18078. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  18079. when Kubernetes is configured as provider in workload identity pool.
  18080. properties:
  18081. audiences:
  18082. description: |-
  18083. Audience specifies the `aud` claim for the service account token
  18084. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  18085. then this audiences will be appended to the list
  18086. items:
  18087. type: string
  18088. type: array
  18089. name:
  18090. description: The name of the ServiceAccount resource being referred to.
  18091. maxLength: 253
  18092. minLength: 1
  18093. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18094. type: string
  18095. namespace:
  18096. description: |-
  18097. Namespace of the resource being referred to.
  18098. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18099. maxLength: 63
  18100. minLength: 1
  18101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18102. type: string
  18103. required:
  18104. - name
  18105. type: object
  18106. type: object
  18107. type: object
  18108. location:
  18109. description: Location optionally defines a location for a secret
  18110. type: string
  18111. projectID:
  18112. description: ProjectID project where secret is located
  18113. type: string
  18114. secretVersionSelectionPolicy:
  18115. default: LatestOrFail
  18116. description: |-
  18117. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  18118. when "latest" is disabled or destroyed.
  18119. Possible values are:
  18120. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  18121. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  18122. type: string
  18123. type: object
  18124. github:
  18125. description: |-
  18126. Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  18127. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  18128. properties:
  18129. appID:
  18130. description: appID specifies the Github APP that will be used to authenticate the client
  18131. format: int64
  18132. type: integer
  18133. auth:
  18134. description: auth configures how secret-manager authenticates with a Github instance.
  18135. properties:
  18136. privateKey:
  18137. description: |-
  18138. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18139. In some instances, `key` is a required field.
  18140. properties:
  18141. key:
  18142. description: |-
  18143. A key in the referenced Secret.
  18144. Some instances of this field may be defaulted, in others it may be required.
  18145. maxLength: 253
  18146. minLength: 1
  18147. pattern: ^[-._a-zA-Z0-9]+$
  18148. type: string
  18149. name:
  18150. description: The name of the Secret resource being referred to.
  18151. maxLength: 253
  18152. minLength: 1
  18153. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18154. type: string
  18155. namespace:
  18156. description: |-
  18157. The namespace of the Secret resource being referred to.
  18158. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18159. maxLength: 63
  18160. minLength: 1
  18161. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18162. type: string
  18163. type: object
  18164. required:
  18165. - privateKey
  18166. type: object
  18167. environment:
  18168. description: environment will be used to fetch secrets from a particular environment within a github repository
  18169. type: string
  18170. installationID:
  18171. description: installationID specifies the Github APP installation that will be used to authenticate the client
  18172. format: int64
  18173. type: integer
  18174. orgSecretVisibility:
  18175. description: |-
  18176. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  18177. Valid values are "all" or "private".
  18178. When unset, new secrets are created with visibility "all" and existing secrets preserve
  18179. whatever visibility they already have in GitHub.
  18180. enum:
  18181. - all
  18182. - private
  18183. type: string
  18184. organization:
  18185. description: organization will be used to fetch secrets from the Github organization
  18186. type: string
  18187. repository:
  18188. description: repository will be used to fetch secrets from the Github repository within an organization
  18189. type: string
  18190. uploadURL:
  18191. description: Upload URL for enterprise instances. Default to URL.
  18192. type: string
  18193. url:
  18194. default: https://github.com/
  18195. description: URL configures the Github instance URL. Defaults to https://github.com/.
  18196. type: string
  18197. required:
  18198. - appID
  18199. - auth
  18200. - installationID
  18201. - organization
  18202. type: object
  18203. gitlab:
  18204. description: GitLab configures this store to sync secrets using GitLab Variables provider
  18205. properties:
  18206. auth:
  18207. description: Auth configures how secret-manager authenticates with a GitLab instance.
  18208. properties:
  18209. SecretRef:
  18210. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  18211. properties:
  18212. accessToken:
  18213. description: AccessToken is used for authentication.
  18214. properties:
  18215. key:
  18216. description: |-
  18217. A key in the referenced Secret.
  18218. Some instances of this field may be defaulted, in others it may be required.
  18219. maxLength: 253
  18220. minLength: 1
  18221. pattern: ^[-._a-zA-Z0-9]+$
  18222. type: string
  18223. name:
  18224. description: The name of the Secret resource being referred to.
  18225. maxLength: 253
  18226. minLength: 1
  18227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18228. type: string
  18229. namespace:
  18230. description: |-
  18231. The namespace of the Secret resource being referred to.
  18232. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18233. maxLength: 63
  18234. minLength: 1
  18235. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18236. type: string
  18237. type: object
  18238. type: object
  18239. required:
  18240. - SecretRef
  18241. type: object
  18242. caBundle:
  18243. description: |-
  18244. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  18245. can be performed.
  18246. format: byte
  18247. type: string
  18248. caProvider:
  18249. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  18250. properties:
  18251. key:
  18252. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  18253. maxLength: 253
  18254. minLength: 1
  18255. pattern: ^[-._a-zA-Z0-9]+$
  18256. type: string
  18257. name:
  18258. description: The name of the object located at the provider type.
  18259. maxLength: 253
  18260. minLength: 1
  18261. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18262. type: string
  18263. namespace:
  18264. description: |-
  18265. The namespace the Provider type is in.
  18266. Can only be defined when used in a ClusterSecretStore.
  18267. maxLength: 63
  18268. minLength: 1
  18269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18270. type: string
  18271. type:
  18272. description: The type of provider to use such as "Secret", or "ConfigMap".
  18273. enum:
  18274. - Secret
  18275. - ConfigMap
  18276. type: string
  18277. required:
  18278. - name
  18279. - type
  18280. type: object
  18281. environment:
  18282. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  18283. type: string
  18284. groupIDs:
  18285. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  18286. items:
  18287. type: string
  18288. type: array
  18289. inheritFromGroups:
  18290. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  18291. type: boolean
  18292. projectID:
  18293. description: ProjectID specifies a project where secrets are located.
  18294. type: string
  18295. url:
  18296. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  18297. type: string
  18298. required:
  18299. - auth
  18300. type: object
  18301. ibm:
  18302. description: IBM configures this store to sync secrets using IBM Cloud provider
  18303. properties:
  18304. auth:
  18305. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  18306. maxProperties: 1
  18307. minProperties: 1
  18308. properties:
  18309. containerAuth:
  18310. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  18311. properties:
  18312. iamEndpoint:
  18313. type: string
  18314. profile:
  18315. description: the IBM Trusted Profile
  18316. type: string
  18317. tokenLocation:
  18318. description: Location the token is mounted on the pod
  18319. type: string
  18320. required:
  18321. - profile
  18322. type: object
  18323. secretRef:
  18324. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  18325. properties:
  18326. iamEndpoint:
  18327. description: The IAM endpoint used to obain a token
  18328. type: string
  18329. secretApiKeySecretRef:
  18330. description: The SecretAccessKey is used for authentication
  18331. properties:
  18332. key:
  18333. description: |-
  18334. A key in the referenced Secret.
  18335. Some instances of this field may be defaulted, in others it may be required.
  18336. maxLength: 253
  18337. minLength: 1
  18338. pattern: ^[-._a-zA-Z0-9]+$
  18339. type: string
  18340. name:
  18341. description: The name of the Secret resource being referred to.
  18342. maxLength: 253
  18343. minLength: 1
  18344. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18345. type: string
  18346. namespace:
  18347. description: |-
  18348. The namespace of the Secret resource being referred to.
  18349. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18350. maxLength: 63
  18351. minLength: 1
  18352. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18353. type: string
  18354. type: object
  18355. type: object
  18356. type: object
  18357. serviceUrl:
  18358. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  18359. type: string
  18360. required:
  18361. - auth
  18362. type: object
  18363. infisical:
  18364. description: Infisical configures this store to sync secrets using the Infisical provider
  18365. properties:
  18366. auth:
  18367. description: Auth configures how the Operator authenticates with the Infisical API
  18368. properties:
  18369. awsAuthCredentials:
  18370. description: AwsAuthCredentials represents the credentials for AWS authentication.
  18371. properties:
  18372. identityId:
  18373. description: |-
  18374. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18375. In some instances, `key` is a required field.
  18376. properties:
  18377. key:
  18378. description: |-
  18379. A key in the referenced Secret.
  18380. Some instances of this field may be defaulted, in others it may be required.
  18381. maxLength: 253
  18382. minLength: 1
  18383. pattern: ^[-._a-zA-Z0-9]+$
  18384. type: string
  18385. name:
  18386. description: The name of the Secret resource being referred to.
  18387. maxLength: 253
  18388. minLength: 1
  18389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18390. type: string
  18391. namespace:
  18392. description: |-
  18393. The namespace of the Secret resource being referred to.
  18394. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18395. maxLength: 63
  18396. minLength: 1
  18397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18398. type: string
  18399. type: object
  18400. required:
  18401. - identityId
  18402. type: object
  18403. azureAuthCredentials:
  18404. description: AzureAuthCredentials represents the credentials for Azure authentication.
  18405. properties:
  18406. identityId:
  18407. description: |-
  18408. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18409. In some instances, `key` is a required field.
  18410. properties:
  18411. key:
  18412. description: |-
  18413. A key in the referenced Secret.
  18414. Some instances of this field may be defaulted, in others it may be required.
  18415. maxLength: 253
  18416. minLength: 1
  18417. pattern: ^[-._a-zA-Z0-9]+$
  18418. type: string
  18419. name:
  18420. description: The name of the Secret resource being referred to.
  18421. maxLength: 253
  18422. minLength: 1
  18423. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18424. type: string
  18425. namespace:
  18426. description: |-
  18427. The namespace of the Secret resource being referred to.
  18428. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18429. maxLength: 63
  18430. minLength: 1
  18431. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18432. type: string
  18433. type: object
  18434. resource:
  18435. description: |-
  18436. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18437. In some instances, `key` is a required field.
  18438. properties:
  18439. key:
  18440. description: |-
  18441. A key in the referenced Secret.
  18442. Some instances of this field may be defaulted, in others it may be required.
  18443. maxLength: 253
  18444. minLength: 1
  18445. pattern: ^[-._a-zA-Z0-9]+$
  18446. type: string
  18447. name:
  18448. description: The name of the Secret resource being referred to.
  18449. maxLength: 253
  18450. minLength: 1
  18451. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18452. type: string
  18453. namespace:
  18454. description: |-
  18455. The namespace of the Secret resource being referred to.
  18456. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18457. maxLength: 63
  18458. minLength: 1
  18459. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18460. type: string
  18461. type: object
  18462. required:
  18463. - identityId
  18464. type: object
  18465. gcpIamAuthCredentials:
  18466. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  18467. properties:
  18468. identityId:
  18469. description: |-
  18470. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18471. In some instances, `key` is a required field.
  18472. properties:
  18473. key:
  18474. description: |-
  18475. A key in the referenced Secret.
  18476. Some instances of this field may be defaulted, in others it may be required.
  18477. maxLength: 253
  18478. minLength: 1
  18479. pattern: ^[-._a-zA-Z0-9]+$
  18480. type: string
  18481. name:
  18482. description: The name of the Secret resource being referred to.
  18483. maxLength: 253
  18484. minLength: 1
  18485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18486. type: string
  18487. namespace:
  18488. description: |-
  18489. The namespace of the Secret resource being referred to.
  18490. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18491. maxLength: 63
  18492. minLength: 1
  18493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18494. type: string
  18495. type: object
  18496. serviceAccountKeyFilePath:
  18497. description: |-
  18498. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18499. In some instances, `key` is a required field.
  18500. properties:
  18501. key:
  18502. description: |-
  18503. A key in the referenced Secret.
  18504. Some instances of this field may be defaulted, in others it may be required.
  18505. maxLength: 253
  18506. minLength: 1
  18507. pattern: ^[-._a-zA-Z0-9]+$
  18508. type: string
  18509. name:
  18510. description: The name of the Secret resource being referred to.
  18511. maxLength: 253
  18512. minLength: 1
  18513. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18514. type: string
  18515. namespace:
  18516. description: |-
  18517. The namespace of the Secret resource being referred to.
  18518. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18519. maxLength: 63
  18520. minLength: 1
  18521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18522. type: string
  18523. type: object
  18524. required:
  18525. - identityId
  18526. - serviceAccountKeyFilePath
  18527. type: object
  18528. gcpIdTokenAuthCredentials:
  18529. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  18530. properties:
  18531. identityId:
  18532. description: |-
  18533. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18534. In some instances, `key` is a required field.
  18535. properties:
  18536. key:
  18537. description: |-
  18538. A key in the referenced Secret.
  18539. Some instances of this field may be defaulted, in others it may be required.
  18540. maxLength: 253
  18541. minLength: 1
  18542. pattern: ^[-._a-zA-Z0-9]+$
  18543. type: string
  18544. name:
  18545. description: The name of the Secret resource being referred to.
  18546. maxLength: 253
  18547. minLength: 1
  18548. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18549. type: string
  18550. namespace:
  18551. description: |-
  18552. The namespace of the Secret resource being referred to.
  18553. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18554. maxLength: 63
  18555. minLength: 1
  18556. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18557. type: string
  18558. type: object
  18559. required:
  18560. - identityId
  18561. type: object
  18562. jwtAuthCredentials:
  18563. description: JwtAuthCredentials represents the credentials for JWT authentication.
  18564. properties:
  18565. identityId:
  18566. description: |-
  18567. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18568. In some instances, `key` is a required field.
  18569. properties:
  18570. key:
  18571. description: |-
  18572. A key in the referenced Secret.
  18573. Some instances of this field may be defaulted, in others it may be required.
  18574. maxLength: 253
  18575. minLength: 1
  18576. pattern: ^[-._a-zA-Z0-9]+$
  18577. type: string
  18578. name:
  18579. description: The name of the Secret resource being referred to.
  18580. maxLength: 253
  18581. minLength: 1
  18582. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18583. type: string
  18584. namespace:
  18585. description: |-
  18586. The namespace of the Secret resource being referred to.
  18587. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18588. maxLength: 63
  18589. minLength: 1
  18590. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18591. type: string
  18592. type: object
  18593. jwt:
  18594. description: |-
  18595. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18596. In some instances, `key` is a required field.
  18597. properties:
  18598. key:
  18599. description: |-
  18600. A key in the referenced Secret.
  18601. Some instances of this field may be defaulted, in others it may be required.
  18602. maxLength: 253
  18603. minLength: 1
  18604. pattern: ^[-._a-zA-Z0-9]+$
  18605. type: string
  18606. name:
  18607. description: The name of the Secret resource being referred to.
  18608. maxLength: 253
  18609. minLength: 1
  18610. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18611. type: string
  18612. namespace:
  18613. description: |-
  18614. The namespace of the Secret resource being referred to.
  18615. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18616. maxLength: 63
  18617. minLength: 1
  18618. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18619. type: string
  18620. type: object
  18621. required:
  18622. - identityId
  18623. - jwt
  18624. type: object
  18625. kubernetesAuthCredentials:
  18626. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  18627. properties:
  18628. identityId:
  18629. description: |-
  18630. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18631. In some instances, `key` is a required field.
  18632. properties:
  18633. key:
  18634. description: |-
  18635. A key in the referenced Secret.
  18636. Some instances of this field may be defaulted, in others it may be required.
  18637. maxLength: 253
  18638. minLength: 1
  18639. pattern: ^[-._a-zA-Z0-9]+$
  18640. type: string
  18641. name:
  18642. description: The name of the Secret resource being referred to.
  18643. maxLength: 253
  18644. minLength: 1
  18645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18646. type: string
  18647. namespace:
  18648. description: |-
  18649. The namespace of the Secret resource being referred to.
  18650. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18651. maxLength: 63
  18652. minLength: 1
  18653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18654. type: string
  18655. type: object
  18656. serviceAccountTokenPath:
  18657. description: |-
  18658. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18659. In some instances, `key` is a required field.
  18660. properties:
  18661. key:
  18662. description: |-
  18663. A key in the referenced Secret.
  18664. Some instances of this field may be defaulted, in others it may be required.
  18665. maxLength: 253
  18666. minLength: 1
  18667. pattern: ^[-._a-zA-Z0-9]+$
  18668. type: string
  18669. name:
  18670. description: The name of the Secret resource being referred to.
  18671. maxLength: 253
  18672. minLength: 1
  18673. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18674. type: string
  18675. namespace:
  18676. description: |-
  18677. The namespace of the Secret resource being referred to.
  18678. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18679. maxLength: 63
  18680. minLength: 1
  18681. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18682. type: string
  18683. type: object
  18684. required:
  18685. - identityId
  18686. type: object
  18687. ldapAuthCredentials:
  18688. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  18689. properties:
  18690. identityId:
  18691. description: |-
  18692. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18693. In some instances, `key` is a required field.
  18694. properties:
  18695. key:
  18696. description: |-
  18697. A key in the referenced Secret.
  18698. Some instances of this field may be defaulted, in others it may be required.
  18699. maxLength: 253
  18700. minLength: 1
  18701. pattern: ^[-._a-zA-Z0-9]+$
  18702. type: string
  18703. name:
  18704. description: The name of the Secret resource being referred to.
  18705. maxLength: 253
  18706. minLength: 1
  18707. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18708. type: string
  18709. namespace:
  18710. description: |-
  18711. The namespace of the Secret resource being referred to.
  18712. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18713. maxLength: 63
  18714. minLength: 1
  18715. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18716. type: string
  18717. type: object
  18718. ldapPassword:
  18719. description: |-
  18720. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18721. In some instances, `key` is a required field.
  18722. properties:
  18723. key:
  18724. description: |-
  18725. A key in the referenced Secret.
  18726. Some instances of this field may be defaulted, in others it may be required.
  18727. maxLength: 253
  18728. minLength: 1
  18729. pattern: ^[-._a-zA-Z0-9]+$
  18730. type: string
  18731. name:
  18732. description: The name of the Secret resource being referred to.
  18733. maxLength: 253
  18734. minLength: 1
  18735. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18736. type: string
  18737. namespace:
  18738. description: |-
  18739. The namespace of the Secret resource being referred to.
  18740. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18741. maxLength: 63
  18742. minLength: 1
  18743. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18744. type: string
  18745. type: object
  18746. ldapUsername:
  18747. description: |-
  18748. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18749. In some instances, `key` is a required field.
  18750. properties:
  18751. key:
  18752. description: |-
  18753. A key in the referenced Secret.
  18754. Some instances of this field may be defaulted, in others it may be required.
  18755. maxLength: 253
  18756. minLength: 1
  18757. pattern: ^[-._a-zA-Z0-9]+$
  18758. type: string
  18759. name:
  18760. description: The name of the Secret resource being referred to.
  18761. maxLength: 253
  18762. minLength: 1
  18763. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18764. type: string
  18765. namespace:
  18766. description: |-
  18767. The namespace of the Secret resource being referred to.
  18768. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18769. maxLength: 63
  18770. minLength: 1
  18771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18772. type: string
  18773. type: object
  18774. required:
  18775. - identityId
  18776. - ldapPassword
  18777. - ldapUsername
  18778. type: object
  18779. ociAuthCredentials:
  18780. description: OciAuthCredentials represents the credentials for OCI authentication.
  18781. properties:
  18782. fingerprint:
  18783. description: |-
  18784. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18785. In some instances, `key` is a required field.
  18786. properties:
  18787. key:
  18788. description: |-
  18789. A key in the referenced Secret.
  18790. Some instances of this field may be defaulted, in others it may be required.
  18791. maxLength: 253
  18792. minLength: 1
  18793. pattern: ^[-._a-zA-Z0-9]+$
  18794. type: string
  18795. name:
  18796. description: The name of the Secret resource being referred to.
  18797. maxLength: 253
  18798. minLength: 1
  18799. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18800. type: string
  18801. namespace:
  18802. description: |-
  18803. The namespace of the Secret resource being referred to.
  18804. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18805. maxLength: 63
  18806. minLength: 1
  18807. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18808. type: string
  18809. type: object
  18810. identityId:
  18811. description: |-
  18812. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18813. In some instances, `key` is a required field.
  18814. properties:
  18815. key:
  18816. description: |-
  18817. A key in the referenced Secret.
  18818. Some instances of this field may be defaulted, in others it may be required.
  18819. maxLength: 253
  18820. minLength: 1
  18821. pattern: ^[-._a-zA-Z0-9]+$
  18822. type: string
  18823. name:
  18824. description: The name of the Secret resource being referred to.
  18825. maxLength: 253
  18826. minLength: 1
  18827. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18828. type: string
  18829. namespace:
  18830. description: |-
  18831. The namespace of the Secret resource being referred to.
  18832. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18833. maxLength: 63
  18834. minLength: 1
  18835. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18836. type: string
  18837. type: object
  18838. privateKey:
  18839. description: |-
  18840. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18841. In some instances, `key` is a required field.
  18842. properties:
  18843. key:
  18844. description: |-
  18845. A key in the referenced Secret.
  18846. Some instances of this field may be defaulted, in others it may be required.
  18847. maxLength: 253
  18848. minLength: 1
  18849. pattern: ^[-._a-zA-Z0-9]+$
  18850. type: string
  18851. name:
  18852. description: The name of the Secret resource being referred to.
  18853. maxLength: 253
  18854. minLength: 1
  18855. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18856. type: string
  18857. namespace:
  18858. description: |-
  18859. The namespace of the Secret resource being referred to.
  18860. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18861. maxLength: 63
  18862. minLength: 1
  18863. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18864. type: string
  18865. type: object
  18866. privateKeyPassphrase:
  18867. description: |-
  18868. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18869. In some instances, `key` is a required field.
  18870. properties:
  18871. key:
  18872. description: |-
  18873. A key in the referenced Secret.
  18874. Some instances of this field may be defaulted, in others it may be required.
  18875. maxLength: 253
  18876. minLength: 1
  18877. pattern: ^[-._a-zA-Z0-9]+$
  18878. type: string
  18879. name:
  18880. description: The name of the Secret resource being referred to.
  18881. maxLength: 253
  18882. minLength: 1
  18883. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18884. type: string
  18885. namespace:
  18886. description: |-
  18887. The namespace of the Secret resource being referred to.
  18888. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18889. maxLength: 63
  18890. minLength: 1
  18891. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18892. type: string
  18893. type: object
  18894. region:
  18895. description: |-
  18896. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18897. In some instances, `key` is a required field.
  18898. properties:
  18899. key:
  18900. description: |-
  18901. A key in the referenced Secret.
  18902. Some instances of this field may be defaulted, in others it may be required.
  18903. maxLength: 253
  18904. minLength: 1
  18905. pattern: ^[-._a-zA-Z0-9]+$
  18906. type: string
  18907. name:
  18908. description: The name of the Secret resource being referred to.
  18909. maxLength: 253
  18910. minLength: 1
  18911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18912. type: string
  18913. namespace:
  18914. description: |-
  18915. The namespace of the Secret resource being referred to.
  18916. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18917. maxLength: 63
  18918. minLength: 1
  18919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18920. type: string
  18921. type: object
  18922. tenancyId:
  18923. description: |-
  18924. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18925. In some instances, `key` is a required field.
  18926. properties:
  18927. key:
  18928. description: |-
  18929. A key in the referenced Secret.
  18930. Some instances of this field may be defaulted, in others it may be required.
  18931. maxLength: 253
  18932. minLength: 1
  18933. pattern: ^[-._a-zA-Z0-9]+$
  18934. type: string
  18935. name:
  18936. description: The name of the Secret resource being referred to.
  18937. maxLength: 253
  18938. minLength: 1
  18939. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18940. type: string
  18941. namespace:
  18942. description: |-
  18943. The namespace of the Secret resource being referred to.
  18944. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18945. maxLength: 63
  18946. minLength: 1
  18947. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18948. type: string
  18949. type: object
  18950. userId:
  18951. description: |-
  18952. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18953. In some instances, `key` is a required field.
  18954. properties:
  18955. key:
  18956. description: |-
  18957. A key in the referenced Secret.
  18958. Some instances of this field may be defaulted, in others it may be required.
  18959. maxLength: 253
  18960. minLength: 1
  18961. pattern: ^[-._a-zA-Z0-9]+$
  18962. type: string
  18963. name:
  18964. description: The name of the Secret resource being referred to.
  18965. maxLength: 253
  18966. minLength: 1
  18967. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18968. type: string
  18969. namespace:
  18970. description: |-
  18971. The namespace of the Secret resource being referred to.
  18972. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18973. maxLength: 63
  18974. minLength: 1
  18975. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18976. type: string
  18977. type: object
  18978. required:
  18979. - fingerprint
  18980. - identityId
  18981. - privateKey
  18982. - region
  18983. - tenancyId
  18984. - userId
  18985. type: object
  18986. tokenAuthCredentials:
  18987. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  18988. properties:
  18989. accessToken:
  18990. description: |-
  18991. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18992. In some instances, `key` is a required field.
  18993. properties:
  18994. key:
  18995. description: |-
  18996. A key in the referenced Secret.
  18997. Some instances of this field may be defaulted, in others it may be required.
  18998. maxLength: 253
  18999. minLength: 1
  19000. pattern: ^[-._a-zA-Z0-9]+$
  19001. type: string
  19002. name:
  19003. description: The name of the Secret resource being referred to.
  19004. maxLength: 253
  19005. minLength: 1
  19006. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19007. type: string
  19008. namespace:
  19009. description: |-
  19010. The namespace of the Secret resource being referred to.
  19011. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19012. maxLength: 63
  19013. minLength: 1
  19014. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19015. type: string
  19016. type: object
  19017. required:
  19018. - accessToken
  19019. type: object
  19020. universalAuthCredentials:
  19021. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  19022. properties:
  19023. clientId:
  19024. description: |-
  19025. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19026. In some instances, `key` is a required field.
  19027. properties:
  19028. key:
  19029. description: |-
  19030. A key in the referenced Secret.
  19031. Some instances of this field may be defaulted, in others it may be required.
  19032. maxLength: 253
  19033. minLength: 1
  19034. pattern: ^[-._a-zA-Z0-9]+$
  19035. type: string
  19036. name:
  19037. description: The name of the Secret resource being referred to.
  19038. maxLength: 253
  19039. minLength: 1
  19040. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19041. type: string
  19042. namespace:
  19043. description: |-
  19044. The namespace of the Secret resource being referred to.
  19045. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19046. maxLength: 63
  19047. minLength: 1
  19048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19049. type: string
  19050. type: object
  19051. clientSecret:
  19052. description: |-
  19053. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19054. In some instances, `key` is a required field.
  19055. properties:
  19056. key:
  19057. description: |-
  19058. A key in the referenced Secret.
  19059. Some instances of this field may be defaulted, in others it may be required.
  19060. maxLength: 253
  19061. minLength: 1
  19062. pattern: ^[-._a-zA-Z0-9]+$
  19063. type: string
  19064. name:
  19065. description: The name of the Secret resource being referred to.
  19066. maxLength: 253
  19067. minLength: 1
  19068. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19069. type: string
  19070. namespace:
  19071. description: |-
  19072. The namespace of the Secret resource being referred to.
  19073. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19074. maxLength: 63
  19075. minLength: 1
  19076. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19077. type: string
  19078. type: object
  19079. required:
  19080. - clientId
  19081. - clientSecret
  19082. type: object
  19083. type: object
  19084. caBundle:
  19085. description: |-
  19086. CABundle is a PEM-encoded CA certificate bundle used to validate
  19087. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  19088. format: byte
  19089. type: string
  19090. caProvider:
  19091. description: |-
  19092. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  19093. The certificate is used to validate the Infisical server's TLS certificate.
  19094. Mutually exclusive with CABundle.
  19095. properties:
  19096. key:
  19097. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19098. maxLength: 253
  19099. minLength: 1
  19100. pattern: ^[-._a-zA-Z0-9]+$
  19101. type: string
  19102. name:
  19103. description: The name of the object located at the provider type.
  19104. maxLength: 253
  19105. minLength: 1
  19106. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19107. type: string
  19108. namespace:
  19109. description: |-
  19110. The namespace the Provider type is in.
  19111. Can only be defined when used in a ClusterSecretStore.
  19112. maxLength: 63
  19113. minLength: 1
  19114. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19115. type: string
  19116. type:
  19117. description: The type of provider to use such as "Secret", or "ConfigMap".
  19118. enum:
  19119. - Secret
  19120. - ConfigMap
  19121. type: string
  19122. required:
  19123. - name
  19124. - type
  19125. type: object
  19126. hostAPI:
  19127. default: https://app.infisical.com/api
  19128. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  19129. type: string
  19130. secretsScope:
  19131. description: SecretsScope defines the scope of the secrets within the workspace
  19132. properties:
  19133. environmentSlug:
  19134. description: EnvironmentSlug is the required slug identifier for the environment.
  19135. type: string
  19136. expandSecretReferences:
  19137. default: true
  19138. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  19139. type: boolean
  19140. organizationSlug:
  19141. description: |-
  19142. OrganizationSlug is the optional slug that identifies the organization that will be used
  19143. during authentication. Useful for sub-organization setups
  19144. type: string
  19145. projectSlug:
  19146. description: ProjectSlug is the required slug identifier for the project.
  19147. type: string
  19148. recursive:
  19149. default: false
  19150. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  19151. type: boolean
  19152. secretsPath:
  19153. default: /
  19154. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  19155. type: string
  19156. required:
  19157. - environmentSlug
  19158. - projectSlug
  19159. type: object
  19160. required:
  19161. - auth
  19162. - secretsScope
  19163. type: object
  19164. keepersecurity:
  19165. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  19166. properties:
  19167. authRef:
  19168. description: |-
  19169. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19170. In some instances, `key` is a required field.
  19171. properties:
  19172. key:
  19173. description: |-
  19174. A key in the referenced Secret.
  19175. Some instances of this field may be defaulted, in others it may be required.
  19176. maxLength: 253
  19177. minLength: 1
  19178. pattern: ^[-._a-zA-Z0-9]+$
  19179. type: string
  19180. name:
  19181. description: The name of the Secret resource being referred to.
  19182. maxLength: 253
  19183. minLength: 1
  19184. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19185. type: string
  19186. namespace:
  19187. description: |-
  19188. The namespace of the Secret resource being referred to.
  19189. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19190. maxLength: 63
  19191. minLength: 1
  19192. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19193. type: string
  19194. type: object
  19195. folderID:
  19196. type: string
  19197. getByTitleFallback:
  19198. type: boolean
  19199. required:
  19200. - authRef
  19201. - folderID
  19202. type: object
  19203. kubernetes:
  19204. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  19205. properties:
  19206. auth:
  19207. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  19208. maxProperties: 1
  19209. minProperties: 1
  19210. properties:
  19211. cert:
  19212. description: has both clientCert and clientKey as secretKeySelector
  19213. properties:
  19214. clientCert:
  19215. description: |-
  19216. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19217. In some instances, `key` is a required field.
  19218. properties:
  19219. key:
  19220. description: |-
  19221. A key in the referenced Secret.
  19222. Some instances of this field may be defaulted, in others it may be required.
  19223. maxLength: 253
  19224. minLength: 1
  19225. pattern: ^[-._a-zA-Z0-9]+$
  19226. type: string
  19227. name:
  19228. description: The name of the Secret resource being referred to.
  19229. maxLength: 253
  19230. minLength: 1
  19231. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19232. type: string
  19233. namespace:
  19234. description: |-
  19235. The namespace of the Secret resource being referred to.
  19236. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19237. maxLength: 63
  19238. minLength: 1
  19239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19240. type: string
  19241. type: object
  19242. clientKey:
  19243. description: |-
  19244. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19245. In some instances, `key` is a required field.
  19246. properties:
  19247. key:
  19248. description: |-
  19249. A key in the referenced Secret.
  19250. Some instances of this field may be defaulted, in others it may be required.
  19251. maxLength: 253
  19252. minLength: 1
  19253. pattern: ^[-._a-zA-Z0-9]+$
  19254. type: string
  19255. name:
  19256. description: The name of the Secret resource being referred to.
  19257. maxLength: 253
  19258. minLength: 1
  19259. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19260. type: string
  19261. namespace:
  19262. description: |-
  19263. The namespace of the Secret resource being referred to.
  19264. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19265. maxLength: 63
  19266. minLength: 1
  19267. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19268. type: string
  19269. type: object
  19270. required:
  19271. - clientCert
  19272. - clientKey
  19273. type: object
  19274. serviceAccount:
  19275. description: points to a service account that should be used for authentication
  19276. properties:
  19277. audiences:
  19278. description: |-
  19279. Audience specifies the `aud` claim for the service account token
  19280. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  19281. then this audiences will be appended to the list
  19282. items:
  19283. type: string
  19284. type: array
  19285. name:
  19286. description: The name of the ServiceAccount resource being referred to.
  19287. maxLength: 253
  19288. minLength: 1
  19289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19290. type: string
  19291. namespace:
  19292. description: |-
  19293. Namespace of the resource being referred to.
  19294. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19295. maxLength: 63
  19296. minLength: 1
  19297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19298. type: string
  19299. required:
  19300. - name
  19301. type: object
  19302. token:
  19303. description: use static token to authenticate with
  19304. properties:
  19305. bearerToken:
  19306. description: |-
  19307. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19308. In some instances, `key` is a required field.
  19309. properties:
  19310. key:
  19311. description: |-
  19312. A key in the referenced Secret.
  19313. Some instances of this field may be defaulted, in others it may be required.
  19314. maxLength: 253
  19315. minLength: 1
  19316. pattern: ^[-._a-zA-Z0-9]+$
  19317. type: string
  19318. name:
  19319. description: The name of the Secret resource being referred to.
  19320. maxLength: 253
  19321. minLength: 1
  19322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19323. type: string
  19324. namespace:
  19325. description: |-
  19326. The namespace of the Secret resource being referred to.
  19327. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19328. maxLength: 63
  19329. minLength: 1
  19330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19331. type: string
  19332. type: object
  19333. required:
  19334. - bearerToken
  19335. type: object
  19336. type: object
  19337. authRef:
  19338. description: A reference to a secret that contains the auth information.
  19339. properties:
  19340. key:
  19341. description: |-
  19342. A key in the referenced Secret.
  19343. Some instances of this field may be defaulted, in others it may be required.
  19344. maxLength: 253
  19345. minLength: 1
  19346. pattern: ^[-._a-zA-Z0-9]+$
  19347. type: string
  19348. name:
  19349. description: The name of the Secret resource being referred to.
  19350. maxLength: 253
  19351. minLength: 1
  19352. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19353. type: string
  19354. namespace:
  19355. description: |-
  19356. The namespace of the Secret resource being referred to.
  19357. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19358. maxLength: 63
  19359. minLength: 1
  19360. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19361. type: string
  19362. type: object
  19363. remoteNamespace:
  19364. default: default
  19365. description: Remote namespace to fetch the secrets from
  19366. maxLength: 63
  19367. minLength: 1
  19368. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19369. type: string
  19370. server:
  19371. description: configures the Kubernetes server Address.
  19372. properties:
  19373. caBundle:
  19374. description: CABundle is a base64-encoded CA certificate
  19375. format: byte
  19376. type: string
  19377. caProvider:
  19378. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  19379. properties:
  19380. key:
  19381. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19382. maxLength: 253
  19383. minLength: 1
  19384. pattern: ^[-._a-zA-Z0-9]+$
  19385. type: string
  19386. name:
  19387. description: The name of the object located at the provider type.
  19388. maxLength: 253
  19389. minLength: 1
  19390. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19391. type: string
  19392. namespace:
  19393. description: |-
  19394. The namespace the Provider type is in.
  19395. Can only be defined when used in a ClusterSecretStore.
  19396. maxLength: 63
  19397. minLength: 1
  19398. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19399. type: string
  19400. type:
  19401. description: The type of provider to use such as "Secret", or "ConfigMap".
  19402. enum:
  19403. - Secret
  19404. - ConfigMap
  19405. type: string
  19406. required:
  19407. - name
  19408. - type
  19409. type: object
  19410. url:
  19411. default: kubernetes.default
  19412. description: configures the Kubernetes server Address.
  19413. type: string
  19414. type: object
  19415. type: object
  19416. nebiusmysterybox:
  19417. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  19418. properties:
  19419. apiDomain:
  19420. description: NebiusMysterybox API endpoint
  19421. type: string
  19422. auth:
  19423. description: Auth defines parameters to authenticate in MysteryBox
  19424. properties:
  19425. serviceAccountCredsSecretRef:
  19426. description: |-
  19427. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  19428. document with service account credentials used to get an IAM token.
  19429. Expected JSON structure:
  19430. {
  19431. "subject-credentials": {
  19432. "alg": "RS256",
  19433. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  19434. "kid": "<public-key-id>",
  19435. "iss": "<issuer-service-account-id>",
  19436. "sub": "<subject-service-account-id>"
  19437. }
  19438. }
  19439. properties:
  19440. key:
  19441. description: |-
  19442. A key in the referenced Secret.
  19443. Some instances of this field may be defaulted, in others it may be required.
  19444. maxLength: 253
  19445. minLength: 1
  19446. pattern: ^[-._a-zA-Z0-9]+$
  19447. type: string
  19448. name:
  19449. description: The name of the Secret resource being referred to.
  19450. maxLength: 253
  19451. minLength: 1
  19452. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19453. type: string
  19454. namespace:
  19455. description: |-
  19456. The namespace of the Secret resource being referred to.
  19457. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19458. maxLength: 63
  19459. minLength: 1
  19460. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19461. type: string
  19462. type: object
  19463. tokenSecretRef:
  19464. description: Token authenticates with Nebius Mysterybox by presenting a token.
  19465. properties:
  19466. key:
  19467. description: |-
  19468. A key in the referenced Secret.
  19469. Some instances of this field may be defaulted, in others it may be required.
  19470. maxLength: 253
  19471. minLength: 1
  19472. pattern: ^[-._a-zA-Z0-9]+$
  19473. type: string
  19474. name:
  19475. description: The name of the Secret resource being referred to.
  19476. maxLength: 253
  19477. minLength: 1
  19478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19479. type: string
  19480. namespace:
  19481. description: |-
  19482. The namespace of the Secret resource being referred to.
  19483. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19484. maxLength: 63
  19485. minLength: 1
  19486. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19487. type: string
  19488. type: object
  19489. type: object
  19490. x-kubernetes-validations:
  19491. - message: either serviceAccountCredsSecretRef or tokenSecretRef must be set
  19492. rule: has(self.serviceAccountCredsSecretRef) || has(self.tokenSecretRef)
  19493. caProvider:
  19494. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  19495. properties:
  19496. certSecretRef:
  19497. description: |-
  19498. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19499. In some instances, `key` is a required field.
  19500. properties:
  19501. key:
  19502. description: |-
  19503. A key in the referenced Secret.
  19504. Some instances of this field may be defaulted, in others it may be required.
  19505. maxLength: 253
  19506. minLength: 1
  19507. pattern: ^[-._a-zA-Z0-9]+$
  19508. type: string
  19509. name:
  19510. description: The name of the Secret resource being referred to.
  19511. maxLength: 253
  19512. minLength: 1
  19513. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19514. type: string
  19515. namespace:
  19516. description: |-
  19517. The namespace of the Secret resource being referred to.
  19518. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19519. maxLength: 63
  19520. minLength: 1
  19521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19522. type: string
  19523. type: object
  19524. type: object
  19525. required:
  19526. - apiDomain
  19527. - auth
  19528. type: object
  19529. ngrok:
  19530. description: Ngrok configures this store to sync secrets using the ngrok provider.
  19531. properties:
  19532. apiUrl:
  19533. default: https://api.ngrok.com
  19534. description: APIURL is the URL of the ngrok API.
  19535. type: string
  19536. auth:
  19537. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  19538. maxProperties: 1
  19539. minProperties: 1
  19540. properties:
  19541. apiKey:
  19542. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  19543. properties:
  19544. secretRef:
  19545. description: SecretRef is a reference to a secret containing the ngrok API key.
  19546. properties:
  19547. key:
  19548. description: |-
  19549. A key in the referenced Secret.
  19550. Some instances of this field may be defaulted, in others it may be required.
  19551. maxLength: 253
  19552. minLength: 1
  19553. pattern: ^[-._a-zA-Z0-9]+$
  19554. type: string
  19555. name:
  19556. description: The name of the Secret resource being referred to.
  19557. maxLength: 253
  19558. minLength: 1
  19559. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19560. type: string
  19561. namespace:
  19562. description: |-
  19563. The namespace of the Secret resource being referred to.
  19564. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19565. maxLength: 63
  19566. minLength: 1
  19567. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19568. type: string
  19569. type: object
  19570. type: object
  19571. type: object
  19572. vault:
  19573. description: Vault configures the ngrok vault to sync secrets with.
  19574. properties:
  19575. name:
  19576. description: Name is the name of the ngrok vault to sync secrets with.
  19577. type: string
  19578. required:
  19579. - name
  19580. type: object
  19581. required:
  19582. - auth
  19583. - vault
  19584. type: object
  19585. onboardbase:
  19586. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  19587. properties:
  19588. apiHost:
  19589. default: https://public.onboardbase.com/api/v1/
  19590. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  19591. type: string
  19592. auth:
  19593. description: Auth configures how the Operator authenticates with the Onboardbase API
  19594. properties:
  19595. apiKeyRef:
  19596. description: |-
  19597. OnboardbaseAPIKey is the APIKey generated by an admin account.
  19598. It is used to recognize and authorize access to a project and environment within onboardbase
  19599. properties:
  19600. key:
  19601. description: |-
  19602. A key in the referenced Secret.
  19603. Some instances of this field may be defaulted, in others it may be required.
  19604. maxLength: 253
  19605. minLength: 1
  19606. pattern: ^[-._a-zA-Z0-9]+$
  19607. type: string
  19608. name:
  19609. description: The name of the Secret resource being referred to.
  19610. maxLength: 253
  19611. minLength: 1
  19612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19613. type: string
  19614. namespace:
  19615. description: |-
  19616. The namespace of the Secret resource being referred to.
  19617. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19618. maxLength: 63
  19619. minLength: 1
  19620. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19621. type: string
  19622. type: object
  19623. passcodeRef:
  19624. description: OnboardbasePasscode is the passcode attached to the API Key
  19625. properties:
  19626. key:
  19627. description: |-
  19628. A key in the referenced Secret.
  19629. Some instances of this field may be defaulted, in others it may be required.
  19630. maxLength: 253
  19631. minLength: 1
  19632. pattern: ^[-._a-zA-Z0-9]+$
  19633. type: string
  19634. name:
  19635. description: The name of the Secret resource being referred to.
  19636. maxLength: 253
  19637. minLength: 1
  19638. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19639. type: string
  19640. namespace:
  19641. description: |-
  19642. The namespace of the Secret resource being referred to.
  19643. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19644. maxLength: 63
  19645. minLength: 1
  19646. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19647. type: string
  19648. type: object
  19649. required:
  19650. - apiKeyRef
  19651. - passcodeRef
  19652. type: object
  19653. environment:
  19654. default: development
  19655. description: Environment is the name of an environmnent within a project to pull the secrets from
  19656. type: string
  19657. project:
  19658. default: development
  19659. description: Project is an onboardbase project that the secrets should be pulled from
  19660. type: string
  19661. required:
  19662. - apiHost
  19663. - auth
  19664. - environment
  19665. - project
  19666. type: object
  19667. onepassword:
  19668. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  19669. properties:
  19670. auth:
  19671. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  19672. properties:
  19673. secretRef:
  19674. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  19675. properties:
  19676. connectTokenSecretRef:
  19677. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  19678. properties:
  19679. key:
  19680. description: |-
  19681. A key in the referenced Secret.
  19682. Some instances of this field may be defaulted, in others it may be required.
  19683. maxLength: 253
  19684. minLength: 1
  19685. pattern: ^[-._a-zA-Z0-9]+$
  19686. type: string
  19687. name:
  19688. description: The name of the Secret resource being referred to.
  19689. maxLength: 253
  19690. minLength: 1
  19691. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19692. type: string
  19693. namespace:
  19694. description: |-
  19695. The namespace of the Secret resource being referred to.
  19696. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19697. maxLength: 63
  19698. minLength: 1
  19699. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19700. type: string
  19701. type: object
  19702. required:
  19703. - connectTokenSecretRef
  19704. type: object
  19705. required:
  19706. - secretRef
  19707. type: object
  19708. connectHost:
  19709. description: ConnectHost defines the OnePassword Connect Server to connect to
  19710. type: string
  19711. vaults:
  19712. additionalProperties:
  19713. type: integer
  19714. description: Vaults defines which OnePassword vaults to search in which order
  19715. type: object
  19716. required:
  19717. - auth
  19718. - connectHost
  19719. - vaults
  19720. type: object
  19721. onepasswordSDK:
  19722. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  19723. properties:
  19724. auth:
  19725. description: Auth defines the information necessary to authenticate against OnePassword API.
  19726. properties:
  19727. serviceAccountSecretRef:
  19728. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  19729. properties:
  19730. key:
  19731. description: |-
  19732. A key in the referenced Secret.
  19733. Some instances of this field may be defaulted, in others it may be required.
  19734. maxLength: 253
  19735. minLength: 1
  19736. pattern: ^[-._a-zA-Z0-9]+$
  19737. type: string
  19738. name:
  19739. description: The name of the Secret resource being referred to.
  19740. maxLength: 253
  19741. minLength: 1
  19742. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19743. type: string
  19744. namespace:
  19745. description: |-
  19746. The namespace of the Secret resource being referred to.
  19747. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19748. maxLength: 63
  19749. minLength: 1
  19750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19751. type: string
  19752. type: object
  19753. required:
  19754. - serviceAccountSecretRef
  19755. type: object
  19756. cache:
  19757. description: |-
  19758. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  19759. When enabled, secrets are cached with the specified TTL.
  19760. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  19761. If omitted, caching is disabled (default).
  19762. cache: {} is a valid option to set.
  19763. properties:
  19764. maxSize:
  19765. default: 100
  19766. description: |-
  19767. MaxSize is the maximum number of secrets to cache.
  19768. When the cache is full, least-recently-used entries are evicted.
  19769. minimum: 1
  19770. type: integer
  19771. ttl:
  19772. default: 5m
  19773. description: |-
  19774. TTL is the time-to-live for cached secrets.
  19775. Format: duration string (e.g., "5m", "1h", "30s")
  19776. type: string
  19777. type: object
  19778. integrationInfo:
  19779. description: |-
  19780. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  19781. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  19782. properties:
  19783. name:
  19784. default: 1Password SDK
  19785. description: Name defaults to "1Password SDK".
  19786. type: string
  19787. version:
  19788. default: v1.0.0
  19789. description: Version defaults to "v1.0.0".
  19790. type: string
  19791. type: object
  19792. vault:
  19793. description: Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  19794. type: string
  19795. required:
  19796. - auth
  19797. - vault
  19798. type: object
  19799. openBao:
  19800. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  19801. properties:
  19802. auth:
  19803. description: Auth configures how secret-manager authenticates with the OpenBao server.
  19804. properties:
  19805. appRole:
  19806. description: |-
  19807. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  19808. with the role and secret stored in a Kubernetes Secret resource.
  19809. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  19810. properties:
  19811. path:
  19812. default: approle
  19813. description: |-
  19814. Path where the App Role authentication backend is mounted
  19815. in OpenBao, e.g: "approle"
  19816. type: string
  19817. roleId:
  19818. description: |-
  19819. RoleID configured in the App Role authentication backend when setting
  19820. up the authentication backend in OpenBao.
  19821. minLength: 1
  19822. type: string
  19823. roleRef:
  19824. description: |-
  19825. Reference to a key in a Secret that contains the App Role ID used
  19826. to authenticate with OpenBao.
  19827. The `key` field must be specified and denotes which entry within the Secret
  19828. resource is used as the app role id.
  19829. properties:
  19830. key:
  19831. description: |-
  19832. A key in the referenced Secret.
  19833. Some instances of this field may be defaulted, in others it may be required.
  19834. maxLength: 253
  19835. minLength: 1
  19836. pattern: ^[-._a-zA-Z0-9]+$
  19837. type: string
  19838. name:
  19839. description: The name of the Secret resource being referred to.
  19840. maxLength: 253
  19841. minLength: 1
  19842. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19843. type: string
  19844. namespace:
  19845. description: |-
  19846. The namespace of the Secret resource being referred to.
  19847. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19848. maxLength: 63
  19849. minLength: 1
  19850. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19851. type: string
  19852. type: object
  19853. secretRef:
  19854. description: |-
  19855. Reference to a key in a Secret that contains the App Role secret used
  19856. to authenticate with OpenBao.
  19857. The `key` field must be specified and denotes which entry within the Secret
  19858. resource is used as the app role secret.
  19859. properties:
  19860. key:
  19861. description: |-
  19862. A key in the referenced Secret.
  19863. Some instances of this field may be defaulted, in others it may be required.
  19864. maxLength: 253
  19865. minLength: 1
  19866. pattern: ^[-._a-zA-Z0-9]+$
  19867. type: string
  19868. name:
  19869. description: The name of the Secret resource being referred to.
  19870. maxLength: 253
  19871. minLength: 1
  19872. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19873. type: string
  19874. namespace:
  19875. description: |-
  19876. The namespace of the Secret resource being referred to.
  19877. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19878. maxLength: 63
  19879. minLength: 1
  19880. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19881. type: string
  19882. type: object
  19883. required:
  19884. - path
  19885. - secretRef
  19886. type: object
  19887. x-kubernetes-validations:
  19888. - message: exactly one of the fields in [roleId roleRef] must be set
  19889. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  19890. namespace:
  19891. description: |-
  19892. Name of the [OpenBao Namespace] to authenticate to. This can be different
  19893. than the namespace your secret is in. Namespaces is a set of features
  19894. within OpenBao that allows OpenBao environments to support secure
  19895. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  19896. if set, or empty otherwise
  19897. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  19898. type: string
  19899. tokenSecretRef:
  19900. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  19901. properties:
  19902. key:
  19903. description: |-
  19904. A key in the referenced Secret.
  19905. Some instances of this field may be defaulted, in others it may be required.
  19906. maxLength: 253
  19907. minLength: 1
  19908. pattern: ^[-._a-zA-Z0-9]+$
  19909. type: string
  19910. name:
  19911. description: The name of the Secret resource being referred to.
  19912. maxLength: 253
  19913. minLength: 1
  19914. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19915. type: string
  19916. namespace:
  19917. description: |-
  19918. The namespace of the Secret resource being referred to.
  19919. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19920. maxLength: 63
  19921. minLength: 1
  19922. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19923. type: string
  19924. type: object
  19925. userPass:
  19926. description: UserPass authenticates with OpenBao by passing a username/password pair
  19927. properties:
  19928. path:
  19929. default: userpass
  19930. description: |-
  19931. Path where the UserPassword authentication backend is mounted
  19932. in OpenBao, e.g: "userpass"
  19933. type: string
  19934. secretRef:
  19935. description: |-
  19936. SecretRef to a key in a Secret resource containing password for the user
  19937. used to authenticate with OpenBao using the [UserPass authentication
  19938. method]
  19939. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  19940. properties:
  19941. key:
  19942. description: |-
  19943. A key in the referenced Secret.
  19944. Some instances of this field may be defaulted, in others it may be required.
  19945. maxLength: 253
  19946. minLength: 1
  19947. pattern: ^[-._a-zA-Z0-9]+$
  19948. type: string
  19949. name:
  19950. description: The name of the Secret resource being referred to.
  19951. maxLength: 253
  19952. minLength: 1
  19953. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19954. type: string
  19955. namespace:
  19956. description: |-
  19957. The namespace of the Secret resource being referred to.
  19958. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19959. maxLength: 63
  19960. minLength: 1
  19961. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19962. type: string
  19963. type: object
  19964. username:
  19965. description: |-
  19966. Username is a username used to authenticate using the [UserPass
  19967. authentication method]
  19968. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  19969. type: string
  19970. required:
  19971. - path
  19972. - username
  19973. type: object
  19974. type: object
  19975. x-kubernetes-validations:
  19976. - message: exactly one of the fields in [appRole tokenSecretRef userPass] must be set
  19977. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass)].filter(x,x==true).size() == 1'
  19978. caBundle:
  19979. description: |-
  19980. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  19981. this and `caProvider` are not set the system root certificates are used
  19982. to validate the TLS connection.
  19983. format: byte
  19984. type: string
  19985. caProvider:
  19986. description: |-
  19987. The provider for the CA bundle to use to validate OpenBao server
  19988. certificate. If this and `caBundle` are not set the system root
  19989. certificates are used to validate the TLS connection.
  19990. properties:
  19991. key:
  19992. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19993. maxLength: 253
  19994. minLength: 1
  19995. pattern: ^[-._a-zA-Z0-9]+$
  19996. type: string
  19997. name:
  19998. description: The name of the object located at the provider type.
  19999. maxLength: 253
  20000. minLength: 1
  20001. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20002. type: string
  20003. namespace:
  20004. description: |-
  20005. The namespace the Provider type is in.
  20006. Can only be defined when used in a ClusterSecretStore.
  20007. maxLength: 63
  20008. minLength: 1
  20009. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20010. type: string
  20011. type:
  20012. description: The type of provider to use such as "Secret", or "ConfigMap".
  20013. enum:
  20014. - Secret
  20015. - ConfigMap
  20016. type: string
  20017. required:
  20018. - name
  20019. - type
  20020. type: object
  20021. namespace:
  20022. description: |-
  20023. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  20024. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  20025. e.g: "ns1".
  20026. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  20027. type: string
  20028. path:
  20029. description: |-
  20030. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  20031. "secret". The v2 KV secret engine version specific "/data" path suffix
  20032. for fetching secrets from OpenBao is optional and will be appended
  20033. if not present in specified path.
  20034. type: string
  20035. server:
  20036. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  20037. type: string
  20038. version:
  20039. default: v2
  20040. description: |-
  20041. Version is the OpenBao KV secret engine version. This can be either "v1" or
  20042. "v2". Version defaults to "v2".
  20043. enum:
  20044. - v1
  20045. - v2
  20046. type: string
  20047. required:
  20048. - server
  20049. type: object
  20050. x-kubernetes-validations:
  20051. - message: at most one of the fields in [caBundle caProvider] may be set
  20052. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  20053. oracle:
  20054. description: Oracle configures this store to sync secrets using Oracle Vault provider
  20055. properties:
  20056. auth:
  20057. description: |-
  20058. Auth configures how secret-manager authenticates with the Oracle Vault.
  20059. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  20060. properties:
  20061. secretRef:
  20062. description: SecretRef to pass through sensitive information.
  20063. properties:
  20064. fingerprint:
  20065. description: Fingerprint is the fingerprint of the API private key.
  20066. properties:
  20067. key:
  20068. description: |-
  20069. A key in the referenced Secret.
  20070. Some instances of this field may be defaulted, in others it may be required.
  20071. maxLength: 253
  20072. minLength: 1
  20073. pattern: ^[-._a-zA-Z0-9]+$
  20074. type: string
  20075. name:
  20076. description: The name of the Secret resource being referred to.
  20077. maxLength: 253
  20078. minLength: 1
  20079. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20080. type: string
  20081. namespace:
  20082. description: |-
  20083. The namespace of the Secret resource being referred to.
  20084. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20085. maxLength: 63
  20086. minLength: 1
  20087. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20088. type: string
  20089. type: object
  20090. privatekey:
  20091. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  20092. properties:
  20093. key:
  20094. description: |-
  20095. A key in the referenced Secret.
  20096. Some instances of this field may be defaulted, in others it may be required.
  20097. maxLength: 253
  20098. minLength: 1
  20099. pattern: ^[-._a-zA-Z0-9]+$
  20100. type: string
  20101. name:
  20102. description: The name of the Secret resource being referred to.
  20103. maxLength: 253
  20104. minLength: 1
  20105. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20106. type: string
  20107. namespace:
  20108. description: |-
  20109. The namespace of the Secret resource being referred to.
  20110. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20111. maxLength: 63
  20112. minLength: 1
  20113. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20114. type: string
  20115. type: object
  20116. required:
  20117. - fingerprint
  20118. - privatekey
  20119. type: object
  20120. tenancy:
  20121. description: Tenancy is the tenancy OCID where user is located.
  20122. type: string
  20123. user:
  20124. description: User is an access OCID specific to the account.
  20125. type: string
  20126. required:
  20127. - secretRef
  20128. - tenancy
  20129. - user
  20130. type: object
  20131. compartment:
  20132. description: |-
  20133. Compartment is the vault compartment OCID.
  20134. Required for PushSecret
  20135. type: string
  20136. encryptionKey:
  20137. description: |-
  20138. EncryptionKey is the OCID of the encryption key within the vault.
  20139. Required for PushSecret
  20140. type: string
  20141. principalType:
  20142. description: |-
  20143. The type of principal to use for authentication. If left blank, the Auth struct will
  20144. determine the principal type. This optional field must be specified if using
  20145. workload identity.
  20146. enum:
  20147. - ""
  20148. - UserPrincipal
  20149. - InstancePrincipal
  20150. - Workload
  20151. type: string
  20152. region:
  20153. description: Region is the region where vault is located.
  20154. type: string
  20155. serviceAccountRef:
  20156. description: |-
  20157. ServiceAccountRef specified the service account
  20158. that should be used when authenticating with WorkloadIdentity.
  20159. properties:
  20160. audiences:
  20161. description: |-
  20162. Audience specifies the `aud` claim for the service account token
  20163. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20164. then this audiences will be appended to the list
  20165. items:
  20166. type: string
  20167. type: array
  20168. name:
  20169. description: The name of the ServiceAccount resource being referred to.
  20170. maxLength: 253
  20171. minLength: 1
  20172. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20173. type: string
  20174. namespace:
  20175. description: |-
  20176. Namespace of the resource being referred to.
  20177. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20178. maxLength: 63
  20179. minLength: 1
  20180. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20181. type: string
  20182. required:
  20183. - name
  20184. type: object
  20185. vault:
  20186. description: Vault is the vault's OCID of the specific vault where secret is located.
  20187. type: string
  20188. required:
  20189. - region
  20190. - vault
  20191. type: object
  20192. ovh:
  20193. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  20194. properties:
  20195. auth:
  20196. description: Authentication method (mtls or token).
  20197. properties:
  20198. mtls:
  20199. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  20200. properties:
  20201. caBundle:
  20202. format: byte
  20203. type: string
  20204. caProvider:
  20205. description: |-
  20206. CAProvider provides a custom certificate authority for accessing the provider's store.
  20207. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  20208. properties:
  20209. key:
  20210. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20211. maxLength: 253
  20212. minLength: 1
  20213. pattern: ^[-._a-zA-Z0-9]+$
  20214. type: string
  20215. name:
  20216. description: The name of the object located at the provider type.
  20217. maxLength: 253
  20218. minLength: 1
  20219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20220. type: string
  20221. namespace:
  20222. description: |-
  20223. The namespace the Provider type is in.
  20224. Can only be defined when used in a ClusterSecretStore.
  20225. maxLength: 63
  20226. minLength: 1
  20227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20228. type: string
  20229. type:
  20230. description: The type of provider to use such as "Secret", or "ConfigMap".
  20231. enum:
  20232. - Secret
  20233. - ConfigMap
  20234. type: string
  20235. required:
  20236. - name
  20237. - type
  20238. type: object
  20239. certSecretRef:
  20240. description: |-
  20241. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20242. In some instances, `key` is a required field.
  20243. properties:
  20244. key:
  20245. description: |-
  20246. A key in the referenced Secret.
  20247. Some instances of this field may be defaulted, in others it may be required.
  20248. maxLength: 253
  20249. minLength: 1
  20250. pattern: ^[-._a-zA-Z0-9]+$
  20251. type: string
  20252. name:
  20253. description: The name of the Secret resource being referred to.
  20254. maxLength: 253
  20255. minLength: 1
  20256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20257. type: string
  20258. namespace:
  20259. description: |-
  20260. The namespace of the Secret resource being referred to.
  20261. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20262. maxLength: 63
  20263. minLength: 1
  20264. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20265. type: string
  20266. type: object
  20267. keySecretRef:
  20268. description: |-
  20269. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20270. In some instances, `key` is a required field.
  20271. properties:
  20272. key:
  20273. description: |-
  20274. A key in the referenced Secret.
  20275. Some instances of this field may be defaulted, in others it may be required.
  20276. maxLength: 253
  20277. minLength: 1
  20278. pattern: ^[-._a-zA-Z0-9]+$
  20279. type: string
  20280. name:
  20281. description: The name of the Secret resource being referred to.
  20282. maxLength: 253
  20283. minLength: 1
  20284. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20285. type: string
  20286. namespace:
  20287. description: |-
  20288. The namespace of the Secret resource being referred to.
  20289. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20290. maxLength: 63
  20291. minLength: 1
  20292. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20293. type: string
  20294. type: object
  20295. required:
  20296. - certSecretRef
  20297. - keySecretRef
  20298. type: object
  20299. token:
  20300. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  20301. properties:
  20302. tokenSecretRef:
  20303. description: |-
  20304. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20305. In some instances, `key` is a required field.
  20306. properties:
  20307. key:
  20308. description: |-
  20309. A key in the referenced Secret.
  20310. Some instances of this field may be defaulted, in others it may be required.
  20311. maxLength: 253
  20312. minLength: 1
  20313. pattern: ^[-._a-zA-Z0-9]+$
  20314. type: string
  20315. name:
  20316. description: The name of the Secret resource being referred to.
  20317. maxLength: 253
  20318. minLength: 1
  20319. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20320. type: string
  20321. namespace:
  20322. description: |-
  20323. The namespace of the Secret resource being referred to.
  20324. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20325. maxLength: 63
  20326. minLength: 1
  20327. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20328. type: string
  20329. type: object
  20330. required:
  20331. - tokenSecretRef
  20332. type: object
  20333. type: object
  20334. casRequired:
  20335. description: 'Enables or disables check-and-set (CAS) (default: false).'
  20336. type: boolean
  20337. okmsTimeout:
  20338. default: 30
  20339. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  20340. format: int32
  20341. minimum: 1
  20342. type: integer
  20343. okmsid:
  20344. description: specifies the OKMS ID.
  20345. type: string
  20346. server:
  20347. description: specifies the OKMS server endpoint.
  20348. type: string
  20349. required:
  20350. - auth
  20351. - okmsid
  20352. - server
  20353. type: object
  20354. passbolt:
  20355. description: |-
  20356. PassboltProvider provides access to Passbolt secrets manager.
  20357. See: https://www.passbolt.com.
  20358. properties:
  20359. auth:
  20360. description: Auth defines the information necessary to authenticate against Passbolt Server
  20361. properties:
  20362. passwordSecretRef:
  20363. description: |-
  20364. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20365. In some instances, `key` is a required field.
  20366. properties:
  20367. key:
  20368. description: |-
  20369. A key in the referenced Secret.
  20370. Some instances of this field may be defaulted, in others it may be required.
  20371. maxLength: 253
  20372. minLength: 1
  20373. pattern: ^[-._a-zA-Z0-9]+$
  20374. type: string
  20375. name:
  20376. description: The name of the Secret resource being referred to.
  20377. maxLength: 253
  20378. minLength: 1
  20379. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20380. type: string
  20381. namespace:
  20382. description: |-
  20383. The namespace of the Secret resource being referred to.
  20384. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20385. maxLength: 63
  20386. minLength: 1
  20387. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20388. type: string
  20389. type: object
  20390. privateKeySecretRef:
  20391. description: |-
  20392. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20393. In some instances, `key` is a required field.
  20394. properties:
  20395. key:
  20396. description: |-
  20397. A key in the referenced Secret.
  20398. Some instances of this field may be defaulted, in others it may be required.
  20399. maxLength: 253
  20400. minLength: 1
  20401. pattern: ^[-._a-zA-Z0-9]+$
  20402. type: string
  20403. name:
  20404. description: The name of the Secret resource being referred to.
  20405. maxLength: 253
  20406. minLength: 1
  20407. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20408. type: string
  20409. namespace:
  20410. description: |-
  20411. The namespace of the Secret resource being referred to.
  20412. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20413. maxLength: 63
  20414. minLength: 1
  20415. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20416. type: string
  20417. type: object
  20418. required:
  20419. - passwordSecretRef
  20420. - privateKeySecretRef
  20421. type: object
  20422. caBundle:
  20423. description: |-
  20424. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  20425. if the Host URL is using HTTPS protocol. If not set the system root certificates
  20426. are used to validate the TLS connection.
  20427. format: byte
  20428. type: string
  20429. caProvider:
  20430. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  20431. properties:
  20432. key:
  20433. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20434. maxLength: 253
  20435. minLength: 1
  20436. pattern: ^[-._a-zA-Z0-9]+$
  20437. type: string
  20438. name:
  20439. description: The name of the object located at the provider type.
  20440. maxLength: 253
  20441. minLength: 1
  20442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20443. type: string
  20444. namespace:
  20445. description: |-
  20446. The namespace the Provider type is in.
  20447. Can only be defined when used in a ClusterSecretStore.
  20448. maxLength: 63
  20449. minLength: 1
  20450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20451. type: string
  20452. type:
  20453. description: The type of provider to use such as "Secret", or "ConfigMap".
  20454. enum:
  20455. - Secret
  20456. - ConfigMap
  20457. type: string
  20458. required:
  20459. - name
  20460. - type
  20461. type: object
  20462. host:
  20463. description: Host defines the Passbolt Server to connect to
  20464. type: string
  20465. required:
  20466. - auth
  20467. - host
  20468. type: object
  20469. passworddepot:
  20470. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  20471. properties:
  20472. auth:
  20473. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  20474. properties:
  20475. secretRef:
  20476. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  20477. properties:
  20478. credentials:
  20479. description: Username / Password is used for authentication.
  20480. properties:
  20481. key:
  20482. description: |-
  20483. A key in the referenced Secret.
  20484. Some instances of this field may be defaulted, in others it may be required.
  20485. maxLength: 253
  20486. minLength: 1
  20487. pattern: ^[-._a-zA-Z0-9]+$
  20488. type: string
  20489. name:
  20490. description: The name of the Secret resource being referred to.
  20491. maxLength: 253
  20492. minLength: 1
  20493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20494. type: string
  20495. namespace:
  20496. description: |-
  20497. The namespace of the Secret resource being referred to.
  20498. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20499. maxLength: 63
  20500. minLength: 1
  20501. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20502. type: string
  20503. type: object
  20504. type: object
  20505. required:
  20506. - secretRef
  20507. type: object
  20508. database:
  20509. description: Database to use as source
  20510. type: string
  20511. host:
  20512. description: URL configures the Password Depot instance URL.
  20513. type: string
  20514. required:
  20515. - auth
  20516. - database
  20517. - host
  20518. type: object
  20519. previder:
  20520. description: Previder configures this store to sync secrets using the Previder provider
  20521. properties:
  20522. auth:
  20523. description: PreviderAuth contains a secretRef for credentials.
  20524. properties:
  20525. secretRef:
  20526. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  20527. properties:
  20528. accessToken:
  20529. description: The AccessToken is used for authentication
  20530. properties:
  20531. key:
  20532. description: |-
  20533. A key in the referenced Secret.
  20534. Some instances of this field may be defaulted, in others it may be required.
  20535. maxLength: 253
  20536. minLength: 1
  20537. pattern: ^[-._a-zA-Z0-9]+$
  20538. type: string
  20539. name:
  20540. description: The name of the Secret resource being referred to.
  20541. maxLength: 253
  20542. minLength: 1
  20543. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20544. type: string
  20545. namespace:
  20546. description: |-
  20547. The namespace of the Secret resource being referred to.
  20548. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20549. maxLength: 63
  20550. minLength: 1
  20551. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20552. type: string
  20553. type: object
  20554. required:
  20555. - accessToken
  20556. type: object
  20557. type: object
  20558. baseUri:
  20559. type: string
  20560. required:
  20561. - auth
  20562. type: object
  20563. pulumi:
  20564. description: Pulumi configures this store to sync secrets using the Pulumi provider
  20565. properties:
  20566. accessToken:
  20567. description: |-
  20568. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  20569. Deprecated: Use auth.accessToken instead.
  20570. properties:
  20571. secretRef:
  20572. description: SecretRef is a reference to a secret containing the Pulumi API token.
  20573. properties:
  20574. key:
  20575. description: |-
  20576. A key in the referenced Secret.
  20577. Some instances of this field may be defaulted, in others it may be required.
  20578. maxLength: 253
  20579. minLength: 1
  20580. pattern: ^[-._a-zA-Z0-9]+$
  20581. type: string
  20582. name:
  20583. description: The name of the Secret resource being referred to.
  20584. maxLength: 253
  20585. minLength: 1
  20586. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20587. type: string
  20588. namespace:
  20589. description: |-
  20590. The namespace of the Secret resource being referred to.
  20591. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20592. maxLength: 63
  20593. minLength: 1
  20594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20595. type: string
  20596. type: object
  20597. type: object
  20598. apiUrl:
  20599. default: https://api.pulumi.com/api/esc
  20600. description: APIURL is the URL of the Pulumi API.
  20601. type: string
  20602. auth:
  20603. description: |-
  20604. Auth configures how the Operator authenticates with the Pulumi API.
  20605. Either auth or the deprecated accessToken field must be specified.
  20606. properties:
  20607. accessToken:
  20608. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  20609. properties:
  20610. secretRef:
  20611. description: SecretRef is a reference to a secret containing the Pulumi API token.
  20612. properties:
  20613. key:
  20614. description: |-
  20615. A key in the referenced Secret.
  20616. Some instances of this field may be defaulted, in others it may be required.
  20617. maxLength: 253
  20618. minLength: 1
  20619. pattern: ^[-._a-zA-Z0-9]+$
  20620. type: string
  20621. name:
  20622. description: The name of the Secret resource being referred to.
  20623. maxLength: 253
  20624. minLength: 1
  20625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20626. type: string
  20627. namespace:
  20628. description: |-
  20629. The namespace of the Secret resource being referred to.
  20630. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20631. maxLength: 63
  20632. minLength: 1
  20633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20634. type: string
  20635. type: object
  20636. type: object
  20637. oidcConfig:
  20638. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  20639. properties:
  20640. expirationSeconds:
  20641. default: 600
  20642. description: |-
  20643. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  20644. Defaults to 10 minutes.
  20645. format: int64
  20646. minimum: 600
  20647. type: integer
  20648. organization:
  20649. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  20650. type: string
  20651. serviceAccountRef:
  20652. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  20653. properties:
  20654. audiences:
  20655. description: |-
  20656. Audience specifies the `aud` claim for the service account token
  20657. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20658. then this audiences will be appended to the list
  20659. items:
  20660. type: string
  20661. type: array
  20662. name:
  20663. description: The name of the ServiceAccount resource being referred to.
  20664. maxLength: 253
  20665. minLength: 1
  20666. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20667. type: string
  20668. namespace:
  20669. description: |-
  20670. Namespace of the resource being referred to.
  20671. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20672. maxLength: 63
  20673. minLength: 1
  20674. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20675. type: string
  20676. required:
  20677. - name
  20678. type: object
  20679. required:
  20680. - organization
  20681. - serviceAccountRef
  20682. type: object
  20683. type: object
  20684. x-kubernetes-validations:
  20685. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  20686. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  20687. environment:
  20688. description: |-
  20689. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  20690. dynamically retrieved values from supported providers including all major clouds,
  20691. and other Pulumi ESC environments.
  20692. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  20693. type: string
  20694. organization:
  20695. description: |-
  20696. Organization are a space to collaborate on shared projects and stacks.
  20697. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  20698. type: string
  20699. project:
  20700. description: Project is the name of the Pulumi ESC project the environment belongs to.
  20701. type: string
  20702. required:
  20703. - environment
  20704. - organization
  20705. - project
  20706. type: object
  20707. x-kubernetes-validations:
  20708. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  20709. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  20710. scaleway:
  20711. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  20712. properties:
  20713. accessKey:
  20714. description: AccessKey is the non-secret part of the api key.
  20715. properties:
  20716. secretRef:
  20717. description: SecretRef references a key in a secret that will be used as value.
  20718. properties:
  20719. key:
  20720. description: |-
  20721. A key in the referenced Secret.
  20722. Some instances of this field may be defaulted, in others it may be required.
  20723. maxLength: 253
  20724. minLength: 1
  20725. pattern: ^[-._a-zA-Z0-9]+$
  20726. type: string
  20727. name:
  20728. description: The name of the Secret resource being referred to.
  20729. maxLength: 253
  20730. minLength: 1
  20731. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20732. type: string
  20733. namespace:
  20734. description: |-
  20735. The namespace of the Secret resource being referred to.
  20736. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20737. maxLength: 63
  20738. minLength: 1
  20739. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20740. type: string
  20741. type: object
  20742. value:
  20743. description: Value can be specified directly to set a value without using a secret.
  20744. type: string
  20745. type: object
  20746. apiUrl:
  20747. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  20748. type: string
  20749. projectId:
  20750. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  20751. type: string
  20752. region:
  20753. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  20754. type: string
  20755. secretKey:
  20756. description: SecretKey is the non-secret part of the api key.
  20757. properties:
  20758. secretRef:
  20759. description: SecretRef references a key in a secret that will be used as value.
  20760. properties:
  20761. key:
  20762. description: |-
  20763. A key in the referenced Secret.
  20764. Some instances of this field may be defaulted, in others it may be required.
  20765. maxLength: 253
  20766. minLength: 1
  20767. pattern: ^[-._a-zA-Z0-9]+$
  20768. type: string
  20769. name:
  20770. description: The name of the Secret resource being referred to.
  20771. maxLength: 253
  20772. minLength: 1
  20773. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20774. type: string
  20775. namespace:
  20776. description: |-
  20777. The namespace of the Secret resource being referred to.
  20778. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20779. maxLength: 63
  20780. minLength: 1
  20781. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20782. type: string
  20783. type: object
  20784. value:
  20785. description: Value can be specified directly to set a value without using a secret.
  20786. type: string
  20787. type: object
  20788. required:
  20789. - accessKey
  20790. - projectId
  20791. - region
  20792. - secretKey
  20793. type: object
  20794. secretserver:
  20795. description: |-
  20796. SecretServer configures this store to sync secrets using SecretServer provider
  20797. https://docs.delinea.com/online-help/secret-server/start.htm
  20798. properties:
  20799. caBundle:
  20800. description: |-
  20801. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  20802. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  20803. are used to validate the TLS connection.
  20804. format: byte
  20805. type: string
  20806. caProvider:
  20807. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  20808. properties:
  20809. key:
  20810. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20811. maxLength: 253
  20812. minLength: 1
  20813. pattern: ^[-._a-zA-Z0-9]+$
  20814. type: string
  20815. name:
  20816. description: The name of the object located at the provider type.
  20817. maxLength: 253
  20818. minLength: 1
  20819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20820. type: string
  20821. namespace:
  20822. description: |-
  20823. The namespace the Provider type is in.
  20824. Can only be defined when used in a ClusterSecretStore.
  20825. maxLength: 63
  20826. minLength: 1
  20827. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20828. type: string
  20829. type:
  20830. description: The type of provider to use such as "Secret", or "ConfigMap".
  20831. enum:
  20832. - Secret
  20833. - ConfigMap
  20834. type: string
  20835. required:
  20836. - name
  20837. - type
  20838. type: object
  20839. domain:
  20840. description: Domain is the secret server domain.
  20841. type: string
  20842. password:
  20843. description: |-
  20844. Password is the secret server account password.
  20845. Required unless Token is set.
  20846. properties:
  20847. secretRef:
  20848. description: SecretRef references a key in a secret that will be used as value.
  20849. properties:
  20850. key:
  20851. description: |-
  20852. A key in the referenced Secret.
  20853. Some instances of this field may be defaulted, in others it may be required.
  20854. maxLength: 253
  20855. minLength: 1
  20856. pattern: ^[-._a-zA-Z0-9]+$
  20857. type: string
  20858. name:
  20859. description: The name of the Secret resource being referred to.
  20860. maxLength: 253
  20861. minLength: 1
  20862. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20863. type: string
  20864. namespace:
  20865. description: |-
  20866. The namespace of the Secret resource being referred to.
  20867. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20868. maxLength: 63
  20869. minLength: 1
  20870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20871. type: string
  20872. type: object
  20873. value:
  20874. description: Value can be specified directly to set a value without using a secret.
  20875. minLength: 1
  20876. type: string
  20877. type: object
  20878. x-kubernetes-validations:
  20879. - message: exactly one of value or secretRef must be set
  20880. rule: has(self.value) != has(self.secretRef)
  20881. serverURL:
  20882. description: |-
  20883. ServerURL
  20884. URL to your secret server installation
  20885. type: string
  20886. token:
  20887. description: |-
  20888. Token is an access token used to authenticate to the secret server,
  20889. as an alternative to Username and Password. When set, Username and
  20890. Password are not required and are ignored.
  20891. properties:
  20892. secretRef:
  20893. description: SecretRef references a key in a secret that will be used as value.
  20894. properties:
  20895. key:
  20896. description: |-
  20897. A key in the referenced Secret.
  20898. Some instances of this field may be defaulted, in others it may be required.
  20899. maxLength: 253
  20900. minLength: 1
  20901. pattern: ^[-._a-zA-Z0-9]+$
  20902. type: string
  20903. name:
  20904. description: The name of the Secret resource being referred to.
  20905. maxLength: 253
  20906. minLength: 1
  20907. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20908. type: string
  20909. namespace:
  20910. description: |-
  20911. The namespace of the Secret resource being referred to.
  20912. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20913. maxLength: 63
  20914. minLength: 1
  20915. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20916. type: string
  20917. type: object
  20918. value:
  20919. description: Value can be specified directly to set a value without using a secret.
  20920. minLength: 1
  20921. type: string
  20922. type: object
  20923. x-kubernetes-validations:
  20924. - message: exactly one of value or secretRef must be set
  20925. rule: has(self.value) != has(self.secretRef)
  20926. username:
  20927. description: |-
  20928. Username is the secret server account username.
  20929. Required unless Token is set.
  20930. properties:
  20931. secretRef:
  20932. description: SecretRef references a key in a secret that will be used as value.
  20933. properties:
  20934. key:
  20935. description: |-
  20936. A key in the referenced Secret.
  20937. Some instances of this field may be defaulted, in others it may be required.
  20938. maxLength: 253
  20939. minLength: 1
  20940. pattern: ^[-._a-zA-Z0-9]+$
  20941. type: string
  20942. name:
  20943. description: The name of the Secret resource being referred to.
  20944. maxLength: 253
  20945. minLength: 1
  20946. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20947. type: string
  20948. namespace:
  20949. description: |-
  20950. The namespace of the Secret resource being referred to.
  20951. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20952. maxLength: 63
  20953. minLength: 1
  20954. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20955. type: string
  20956. type: object
  20957. value:
  20958. description: Value can be specified directly to set a value without using a secret.
  20959. minLength: 1
  20960. type: string
  20961. type: object
  20962. x-kubernetes-validations:
  20963. - message: exactly one of value or secretRef must be set
  20964. rule: has(self.value) != has(self.secretRef)
  20965. required:
  20966. - serverURL
  20967. type: object
  20968. x-kubernetes-validations:
  20969. - message: either token, or both username and password, must be set
  20970. rule: has(self.token) || (has(self.username) && has(self.password))
  20971. senhasegura:
  20972. description: Senhasegura configures this store to sync secrets using senhasegura provider
  20973. properties:
  20974. auth:
  20975. description: Auth defines parameters to authenticate in senhasegura
  20976. properties:
  20977. clientId:
  20978. type: string
  20979. clientSecretSecretRef:
  20980. description: |-
  20981. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20982. In some instances, `key` is a required field.
  20983. properties:
  20984. key:
  20985. description: |-
  20986. A key in the referenced Secret.
  20987. Some instances of this field may be defaulted, in others it may be required.
  20988. maxLength: 253
  20989. minLength: 1
  20990. pattern: ^[-._a-zA-Z0-9]+$
  20991. type: string
  20992. name:
  20993. description: The name of the Secret resource being referred to.
  20994. maxLength: 253
  20995. minLength: 1
  20996. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20997. type: string
  20998. namespace:
  20999. description: |-
  21000. The namespace of the Secret resource being referred to.
  21001. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21002. maxLength: 63
  21003. minLength: 1
  21004. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21005. type: string
  21006. type: object
  21007. required:
  21008. - clientId
  21009. - clientSecretSecretRef
  21010. type: object
  21011. ignoreSslCertificate:
  21012. default: false
  21013. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  21014. type: boolean
  21015. module:
  21016. description: Module defines which senhasegura module should be used to get secrets
  21017. type: string
  21018. url:
  21019. description: URL of senhasegura
  21020. type: string
  21021. required:
  21022. - auth
  21023. - module
  21024. - url
  21025. type: object
  21026. vault:
  21027. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  21028. properties:
  21029. auth:
  21030. description: Auth configures how secret-manager authenticates with the Vault server.
  21031. properties:
  21032. appRole:
  21033. description: |-
  21034. AppRole authenticates with Vault using the App Role auth mechanism,
  21035. with the role and secret stored in a Kubernetes Secret resource.
  21036. properties:
  21037. path:
  21038. default: approle
  21039. description: |-
  21040. Path where the App Role authentication backend is mounted
  21041. in Vault, e.g: "approle"
  21042. type: string
  21043. roleId:
  21044. description: |-
  21045. RoleID configured in the App Role authentication backend when setting
  21046. up the authentication backend in Vault.
  21047. type: string
  21048. roleRef:
  21049. description: |-
  21050. Reference to a key in a Secret that contains the App Role ID used
  21051. to authenticate with Vault.
  21052. The `key` field must be specified and denotes which entry within the Secret
  21053. resource is used as the app role id.
  21054. properties:
  21055. key:
  21056. description: |-
  21057. A key in the referenced Secret.
  21058. Some instances of this field may be defaulted, in others it may be required.
  21059. maxLength: 253
  21060. minLength: 1
  21061. pattern: ^[-._a-zA-Z0-9]+$
  21062. type: string
  21063. name:
  21064. description: The name of the Secret resource being referred to.
  21065. maxLength: 253
  21066. minLength: 1
  21067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21068. type: string
  21069. namespace:
  21070. description: |-
  21071. The namespace of the Secret resource being referred to.
  21072. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21073. maxLength: 63
  21074. minLength: 1
  21075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21076. type: string
  21077. type: object
  21078. secretRef:
  21079. description: |-
  21080. Reference to a key in a Secret that contains the App Role secret used
  21081. to authenticate with Vault.
  21082. The `key` field must be specified and denotes which entry within the Secret
  21083. resource is used as the app role secret.
  21084. properties:
  21085. key:
  21086. description: |-
  21087. A key in the referenced Secret.
  21088. Some instances of this field may be defaulted, in others it may be required.
  21089. maxLength: 253
  21090. minLength: 1
  21091. pattern: ^[-._a-zA-Z0-9]+$
  21092. type: string
  21093. name:
  21094. description: The name of the Secret resource being referred to.
  21095. maxLength: 253
  21096. minLength: 1
  21097. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21098. type: string
  21099. namespace:
  21100. description: |-
  21101. The namespace of the Secret resource being referred to.
  21102. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21103. maxLength: 63
  21104. minLength: 1
  21105. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21106. type: string
  21107. type: object
  21108. required:
  21109. - path
  21110. - secretRef
  21111. type: object
  21112. cert:
  21113. description: |-
  21114. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  21115. Cert authentication method
  21116. properties:
  21117. clientCert:
  21118. description: |-
  21119. ClientCert is a certificate to authenticate using the Cert Vault
  21120. authentication method
  21121. properties:
  21122. key:
  21123. description: |-
  21124. A key in the referenced Secret.
  21125. Some instances of this field may be defaulted, in others it may be required.
  21126. maxLength: 253
  21127. minLength: 1
  21128. pattern: ^[-._a-zA-Z0-9]+$
  21129. type: string
  21130. name:
  21131. description: The name of the Secret resource being referred to.
  21132. maxLength: 253
  21133. minLength: 1
  21134. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21135. type: string
  21136. namespace:
  21137. description: |-
  21138. The namespace of the Secret resource being referred to.
  21139. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21140. maxLength: 63
  21141. minLength: 1
  21142. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21143. type: string
  21144. type: object
  21145. path:
  21146. default: cert
  21147. description: |-
  21148. Path where the Certificate authentication backend is mounted
  21149. in Vault, e.g: "cert"
  21150. type: string
  21151. secretRef:
  21152. description: |-
  21153. SecretRef to a key in a Secret resource containing client private key to
  21154. authenticate with Vault using the Cert authentication method
  21155. properties:
  21156. key:
  21157. description: |-
  21158. A key in the referenced Secret.
  21159. Some instances of this field may be defaulted, in others it may be required.
  21160. maxLength: 253
  21161. minLength: 1
  21162. pattern: ^[-._a-zA-Z0-9]+$
  21163. type: string
  21164. name:
  21165. description: The name of the Secret resource being referred to.
  21166. maxLength: 253
  21167. minLength: 1
  21168. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21169. type: string
  21170. namespace:
  21171. description: |-
  21172. The namespace of the Secret resource being referred to.
  21173. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21174. maxLength: 63
  21175. minLength: 1
  21176. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21177. type: string
  21178. type: object
  21179. vaultRole:
  21180. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  21181. type: string
  21182. type: object
  21183. gcp:
  21184. description: |-
  21185. Gcp authenticates with Vault using Google Cloud Platform authentication method
  21186. GCP authentication method
  21187. properties:
  21188. location:
  21189. description: Location optionally defines a location/region for the secret
  21190. type: string
  21191. path:
  21192. default: gcp
  21193. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  21194. type: string
  21195. projectID:
  21196. description: Project ID of the Google Cloud Platform project
  21197. type: string
  21198. role:
  21199. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  21200. type: string
  21201. secretRef:
  21202. description: Specify credentials in a Secret object
  21203. properties:
  21204. secretAccessKeySecretRef:
  21205. description: The SecretAccessKey is used for authentication
  21206. properties:
  21207. key:
  21208. description: |-
  21209. A key in the referenced Secret.
  21210. Some instances of this field may be defaulted, in others it may be required.
  21211. maxLength: 253
  21212. minLength: 1
  21213. pattern: ^[-._a-zA-Z0-9]+$
  21214. type: string
  21215. name:
  21216. description: The name of the Secret resource being referred to.
  21217. maxLength: 253
  21218. minLength: 1
  21219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21220. type: string
  21221. namespace:
  21222. description: |-
  21223. The namespace of the Secret resource being referred to.
  21224. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21225. maxLength: 63
  21226. minLength: 1
  21227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21228. type: string
  21229. type: object
  21230. type: object
  21231. serviceAccountRef:
  21232. description: ServiceAccountRef to a service account for impersonation
  21233. properties:
  21234. audiences:
  21235. description: |-
  21236. Audience specifies the `aud` claim for the service account token
  21237. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21238. then this audiences will be appended to the list
  21239. items:
  21240. type: string
  21241. type: array
  21242. name:
  21243. description: The name of the ServiceAccount resource being referred to.
  21244. maxLength: 253
  21245. minLength: 1
  21246. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21247. type: string
  21248. namespace:
  21249. description: |-
  21250. Namespace of the resource being referred to.
  21251. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21252. maxLength: 63
  21253. minLength: 1
  21254. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21255. type: string
  21256. required:
  21257. - name
  21258. type: object
  21259. workloadIdentity:
  21260. description: Specify a service account with Workload Identity
  21261. properties:
  21262. clusterLocation:
  21263. description: |-
  21264. ClusterLocation is the location of the cluster
  21265. If not specified, it fetches information from the metadata server
  21266. type: string
  21267. clusterName:
  21268. description: |-
  21269. ClusterName is the name of the cluster
  21270. If not specified, it fetches information from the metadata server
  21271. type: string
  21272. clusterProjectID:
  21273. description: |-
  21274. ClusterProjectID is the project ID of the cluster
  21275. If not specified, it fetches information from the metadata server
  21276. type: string
  21277. serviceAccountRef:
  21278. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  21279. properties:
  21280. audiences:
  21281. description: |-
  21282. Audience specifies the `aud` claim for the service account token
  21283. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21284. then this audiences will be appended to the list
  21285. items:
  21286. type: string
  21287. type: array
  21288. name:
  21289. description: The name of the ServiceAccount resource being referred to.
  21290. maxLength: 253
  21291. minLength: 1
  21292. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21293. type: string
  21294. namespace:
  21295. description: |-
  21296. Namespace of the resource being referred to.
  21297. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21298. maxLength: 63
  21299. minLength: 1
  21300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21301. type: string
  21302. required:
  21303. - name
  21304. type: object
  21305. required:
  21306. - serviceAccountRef
  21307. type: object
  21308. required:
  21309. - role
  21310. type: object
  21311. iam:
  21312. description: |-
  21313. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  21314. AWS IAM authentication method
  21315. properties:
  21316. externalID:
  21317. description: AWS External ID set on assumed IAM roles
  21318. type: string
  21319. jwt:
  21320. description: Specify a service account with IRSA enabled
  21321. properties:
  21322. serviceAccountRef:
  21323. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  21324. properties:
  21325. audiences:
  21326. description: |-
  21327. Audience specifies the `aud` claim for the service account token
  21328. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21329. then this audiences will be appended to the list
  21330. items:
  21331. type: string
  21332. type: array
  21333. name:
  21334. description: The name of the ServiceAccount resource being referred to.
  21335. maxLength: 253
  21336. minLength: 1
  21337. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21338. type: string
  21339. namespace:
  21340. description: |-
  21341. Namespace of the resource being referred to.
  21342. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21343. maxLength: 63
  21344. minLength: 1
  21345. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21346. type: string
  21347. required:
  21348. - name
  21349. type: object
  21350. type: object
  21351. path:
  21352. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  21353. type: string
  21354. region:
  21355. description: AWS region
  21356. type: string
  21357. role:
  21358. description: This is the AWS role to be assumed before talking to vault
  21359. type: string
  21360. secretRef:
  21361. description: Specify credentials in a Secret object
  21362. properties:
  21363. accessKeyIDSecretRef:
  21364. description: The AccessKeyID is used for authentication
  21365. properties:
  21366. key:
  21367. description: |-
  21368. A key in the referenced Secret.
  21369. Some instances of this field may be defaulted, in others it may be required.
  21370. maxLength: 253
  21371. minLength: 1
  21372. pattern: ^[-._a-zA-Z0-9]+$
  21373. type: string
  21374. name:
  21375. description: The name of the Secret resource being referred to.
  21376. maxLength: 253
  21377. minLength: 1
  21378. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21379. type: string
  21380. namespace:
  21381. description: |-
  21382. The namespace of the Secret resource being referred to.
  21383. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21384. maxLength: 63
  21385. minLength: 1
  21386. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21387. type: string
  21388. type: object
  21389. secretAccessKeySecretRef:
  21390. description: The SecretAccessKey is used for authentication
  21391. properties:
  21392. key:
  21393. description: |-
  21394. A key in the referenced Secret.
  21395. Some instances of this field may be defaulted, in others it may be required.
  21396. maxLength: 253
  21397. minLength: 1
  21398. pattern: ^[-._a-zA-Z0-9]+$
  21399. type: string
  21400. name:
  21401. description: The name of the Secret resource being referred to.
  21402. maxLength: 253
  21403. minLength: 1
  21404. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21405. type: string
  21406. namespace:
  21407. description: |-
  21408. The namespace of the Secret resource being referred to.
  21409. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21410. maxLength: 63
  21411. minLength: 1
  21412. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21413. type: string
  21414. type: object
  21415. sessionTokenSecretRef:
  21416. description: |-
  21417. The SessionToken used for authentication
  21418. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  21419. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  21420. properties:
  21421. key:
  21422. description: |-
  21423. A key in the referenced Secret.
  21424. Some instances of this field may be defaulted, in others it may be required.
  21425. maxLength: 253
  21426. minLength: 1
  21427. pattern: ^[-._a-zA-Z0-9]+$
  21428. type: string
  21429. name:
  21430. description: The name of the Secret resource being referred to.
  21431. maxLength: 253
  21432. minLength: 1
  21433. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21434. type: string
  21435. namespace:
  21436. description: |-
  21437. The namespace of the Secret resource being referred to.
  21438. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21439. maxLength: 63
  21440. minLength: 1
  21441. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21442. type: string
  21443. type: object
  21444. type: object
  21445. vaultAwsIamServerID:
  21446. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  21447. type: string
  21448. vaultRole:
  21449. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  21450. type: string
  21451. required:
  21452. - vaultRole
  21453. type: object
  21454. jwt:
  21455. description: |-
  21456. Jwt authenticates with Vault by passing role and JWT token using the
  21457. JWT/OIDC authentication method
  21458. properties:
  21459. kubernetesServiceAccountToken:
  21460. description: |-
  21461. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  21462. a token for with the `TokenRequest` API.
  21463. properties:
  21464. audiences:
  21465. description: |-
  21466. Optional audiences field that will be used to request a temporary Kubernetes service
  21467. account token for the service account referenced by `serviceAccountRef`.
  21468. Defaults to a single audience `vault` it not specified.
  21469. Deprecated: use serviceAccountRef.Audiences instead
  21470. items:
  21471. type: string
  21472. type: array
  21473. expirationSeconds:
  21474. description: |-
  21475. Optional expiration time in seconds that will be used to request a temporary
  21476. Kubernetes service account token for the service account referenced by
  21477. `serviceAccountRef`.
  21478. Deprecated: this will be removed in the future.
  21479. Defaults to 10 minutes.
  21480. format: int64
  21481. type: integer
  21482. serviceAccountRef:
  21483. description: Service account field containing the name of a kubernetes ServiceAccount.
  21484. properties:
  21485. audiences:
  21486. description: |-
  21487. Audience specifies the `aud` claim for the service account token
  21488. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21489. then this audiences will be appended to the list
  21490. items:
  21491. type: string
  21492. type: array
  21493. name:
  21494. description: The name of the ServiceAccount resource being referred to.
  21495. maxLength: 253
  21496. minLength: 1
  21497. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21498. type: string
  21499. namespace:
  21500. description: |-
  21501. Namespace of the resource being referred to.
  21502. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21503. maxLength: 63
  21504. minLength: 1
  21505. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21506. type: string
  21507. required:
  21508. - name
  21509. type: object
  21510. required:
  21511. - serviceAccountRef
  21512. type: object
  21513. path:
  21514. default: jwt
  21515. description: |-
  21516. Path where the JWT authentication backend is mounted
  21517. in Vault, e.g: "jwt"
  21518. type: string
  21519. role:
  21520. description: |-
  21521. Role is a JWT role to authenticate using the JWT/OIDC Vault
  21522. authentication method
  21523. type: string
  21524. secretRef:
  21525. description: |-
  21526. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  21527. authenticate with Vault using the JWT/OIDC authentication method.
  21528. properties:
  21529. key:
  21530. description: |-
  21531. A key in the referenced Secret.
  21532. Some instances of this field may be defaulted, in others it may be required.
  21533. maxLength: 253
  21534. minLength: 1
  21535. pattern: ^[-._a-zA-Z0-9]+$
  21536. type: string
  21537. name:
  21538. description: The name of the Secret resource being referred to.
  21539. maxLength: 253
  21540. minLength: 1
  21541. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21542. type: string
  21543. namespace:
  21544. description: |-
  21545. The namespace of the Secret resource being referred to.
  21546. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21547. maxLength: 63
  21548. minLength: 1
  21549. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21550. type: string
  21551. type: object
  21552. required:
  21553. - path
  21554. type: object
  21555. kubernetes:
  21556. description: |-
  21557. Kubernetes authenticates with Vault by passing the ServiceAccount
  21558. token stored in the named Secret resource to the Vault server.
  21559. properties:
  21560. mountPath:
  21561. default: kubernetes
  21562. description: |-
  21563. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  21564. "kubernetes"
  21565. type: string
  21566. role:
  21567. description: |-
  21568. A required field containing the Vault Role to assume. A Role binds a
  21569. Kubernetes ServiceAccount with a set of Vault policies.
  21570. type: string
  21571. secretRef:
  21572. description: |-
  21573. Optional secret field containing a Kubernetes ServiceAccount JWT used
  21574. for authenticating with Vault. If a name is specified without a key,
  21575. `token` is the default. If one is not specified, the one bound to
  21576. the controller will be used.
  21577. properties:
  21578. key:
  21579. description: |-
  21580. A key in the referenced Secret.
  21581. Some instances of this field may be defaulted, in others it may be required.
  21582. maxLength: 253
  21583. minLength: 1
  21584. pattern: ^[-._a-zA-Z0-9]+$
  21585. type: string
  21586. name:
  21587. description: The name of the Secret resource being referred to.
  21588. maxLength: 253
  21589. minLength: 1
  21590. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21591. type: string
  21592. namespace:
  21593. description: |-
  21594. The namespace of the Secret resource being referred to.
  21595. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21596. maxLength: 63
  21597. minLength: 1
  21598. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21599. type: string
  21600. type: object
  21601. serviceAccountRef:
  21602. description: |-
  21603. Optional service account field containing the name of a kubernetes ServiceAccount.
  21604. If the service account is specified, the service account secret token JWT will be used
  21605. for authenticating with Vault. If the service account selector is not supplied,
  21606. the secretRef will be used instead.
  21607. properties:
  21608. audiences:
  21609. description: |-
  21610. Audience specifies the `aud` claim for the service account token
  21611. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21612. then this audiences will be appended to the list
  21613. items:
  21614. type: string
  21615. type: array
  21616. name:
  21617. description: The name of the ServiceAccount resource being referred to.
  21618. maxLength: 253
  21619. minLength: 1
  21620. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21621. type: string
  21622. namespace:
  21623. description: |-
  21624. Namespace of the resource being referred to.
  21625. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21626. maxLength: 63
  21627. minLength: 1
  21628. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21629. type: string
  21630. required:
  21631. - name
  21632. type: object
  21633. required:
  21634. - mountPath
  21635. - role
  21636. type: object
  21637. ldap:
  21638. description: |-
  21639. Ldap authenticates with Vault by passing username/password pair using
  21640. the LDAP authentication method
  21641. properties:
  21642. path:
  21643. default: ldap
  21644. description: |-
  21645. Path where the LDAP authentication backend is mounted
  21646. in Vault, e.g: "ldap"
  21647. type: string
  21648. secretRef:
  21649. description: |-
  21650. SecretRef to a key in a Secret resource containing password for the LDAP
  21651. user used to authenticate with Vault using the LDAP authentication
  21652. method
  21653. properties:
  21654. key:
  21655. description: |-
  21656. A key in the referenced Secret.
  21657. Some instances of this field may be defaulted, in others it may be required.
  21658. maxLength: 253
  21659. minLength: 1
  21660. pattern: ^[-._a-zA-Z0-9]+$
  21661. type: string
  21662. name:
  21663. description: The name of the Secret resource being referred to.
  21664. maxLength: 253
  21665. minLength: 1
  21666. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21667. type: string
  21668. namespace:
  21669. description: |-
  21670. The namespace of the Secret resource being referred to.
  21671. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21672. maxLength: 63
  21673. minLength: 1
  21674. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21675. type: string
  21676. type: object
  21677. username:
  21678. description: |-
  21679. Username is an LDAP username used to authenticate using the LDAP Vault
  21680. authentication method
  21681. type: string
  21682. required:
  21683. - path
  21684. - username
  21685. type: object
  21686. namespace:
  21687. description: |-
  21688. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  21689. Namespaces is a set of features within Vault Enterprise that allows
  21690. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  21691. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  21692. This will default to Vault.Namespace field if set, or empty otherwise
  21693. type: string
  21694. tokenSecretRef:
  21695. description: TokenSecretRef authenticates with Vault by presenting a token.
  21696. properties:
  21697. key:
  21698. description: |-
  21699. A key in the referenced Secret.
  21700. Some instances of this field may be defaulted, in others it may be required.
  21701. maxLength: 253
  21702. minLength: 1
  21703. pattern: ^[-._a-zA-Z0-9]+$
  21704. type: string
  21705. name:
  21706. description: The name of the Secret resource being referred to.
  21707. maxLength: 253
  21708. minLength: 1
  21709. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21710. type: string
  21711. namespace:
  21712. description: |-
  21713. The namespace of the Secret resource being referred to.
  21714. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21715. maxLength: 63
  21716. minLength: 1
  21717. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21718. type: string
  21719. type: object
  21720. userPass:
  21721. description: UserPass authenticates with Vault by passing username/password pair
  21722. properties:
  21723. path:
  21724. default: userpass
  21725. description: |-
  21726. Path where the UserPassword authentication backend is mounted
  21727. in Vault, e.g: "userpass"
  21728. type: string
  21729. secretRef:
  21730. description: |-
  21731. SecretRef to a key in a Secret resource containing password for the
  21732. user used to authenticate with Vault using the UserPass authentication
  21733. method
  21734. properties:
  21735. key:
  21736. description: |-
  21737. A key in the referenced Secret.
  21738. Some instances of this field may be defaulted, in others it may be required.
  21739. maxLength: 253
  21740. minLength: 1
  21741. pattern: ^[-._a-zA-Z0-9]+$
  21742. type: string
  21743. name:
  21744. description: The name of the Secret resource being referred to.
  21745. maxLength: 253
  21746. minLength: 1
  21747. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21748. type: string
  21749. namespace:
  21750. description: |-
  21751. The namespace of the Secret resource being referred to.
  21752. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21753. maxLength: 63
  21754. minLength: 1
  21755. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21756. type: string
  21757. type: object
  21758. username:
  21759. description: |-
  21760. Username is a username used to authenticate using the UserPass Vault
  21761. authentication method
  21762. type: string
  21763. required:
  21764. - path
  21765. - username
  21766. type: object
  21767. type: object
  21768. caBundle:
  21769. description: |-
  21770. PEM encoded CA bundle used to validate Vault server certificate. Only used
  21771. if the Server URL is using HTTPS protocol. This parameter is ignored for
  21772. plain HTTP protocol connection. If not set the system root certificates
  21773. are used to validate the TLS connection.
  21774. format: byte
  21775. type: string
  21776. caProvider:
  21777. description: The provider for the CA bundle to use to validate Vault server certificate.
  21778. properties:
  21779. key:
  21780. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  21781. maxLength: 253
  21782. minLength: 1
  21783. pattern: ^[-._a-zA-Z0-9]+$
  21784. type: string
  21785. name:
  21786. description: The name of the object located at the provider type.
  21787. maxLength: 253
  21788. minLength: 1
  21789. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21790. type: string
  21791. namespace:
  21792. description: |-
  21793. The namespace the Provider type is in.
  21794. Can only be defined when used in a ClusterSecretStore.
  21795. maxLength: 63
  21796. minLength: 1
  21797. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21798. type: string
  21799. type:
  21800. description: The type of provider to use such as "Secret", or "ConfigMap".
  21801. enum:
  21802. - Secret
  21803. - ConfigMap
  21804. type: string
  21805. required:
  21806. - name
  21807. - type
  21808. type: object
  21809. checkAndSet:
  21810. description: |-
  21811. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  21812. Only applies to Vault KV v2 stores. When enabled, write operations must include
  21813. the current version of the secret to prevent unintentional overwrites.
  21814. properties:
  21815. required:
  21816. description: |-
  21817. Required when true, all write operations must include a check-and-set parameter.
  21818. This helps prevent unintentional overwrites of secrets.
  21819. type: boolean
  21820. type: object
  21821. forwardInconsistent:
  21822. description: |-
  21823. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  21824. leader instead of simply retrying within a loop. This can increase performance if
  21825. the option is enabled serverside.
  21826. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  21827. type: boolean
  21828. headers:
  21829. additionalProperties:
  21830. type: string
  21831. description: Headers to be added in Vault request
  21832. type: object
  21833. namespace:
  21834. description: |-
  21835. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  21836. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  21837. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  21838. type: string
  21839. path:
  21840. description: |-
  21841. Path is the mount path of the Vault KV backend endpoint, e.g:
  21842. "secret". The v2 KV secret engine version specific "/data" path suffix
  21843. for fetching secrets from Vault is optional and will be appended
  21844. if not present in specified path.
  21845. type: string
  21846. readYourWrites:
  21847. description: |-
  21848. ReadYourWrites ensures isolated read-after-write semantics by
  21849. providing discovered cluster replication states in each request.
  21850. More information about eventual consistency in Vault can be found here
  21851. https://www.vaultproject.io/docs/enterprise/consistency
  21852. type: boolean
  21853. server:
  21854. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  21855. type: string
  21856. tls:
  21857. description: |-
  21858. The configuration used for client side related TLS communication, when the Vault server
  21859. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  21860. This parameter is ignored for plain HTTP protocol connection.
  21861. It's worth noting this configuration is different from the "TLS certificates auth method",
  21862. which is available under the `auth.cert` section.
  21863. properties:
  21864. certSecretRef:
  21865. description: |-
  21866. CertSecretRef is a certificate added to the transport layer
  21867. when communicating with the Vault server.
  21868. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  21869. properties:
  21870. key:
  21871. description: |-
  21872. A key in the referenced Secret.
  21873. Some instances of this field may be defaulted, in others it may be required.
  21874. maxLength: 253
  21875. minLength: 1
  21876. pattern: ^[-._a-zA-Z0-9]+$
  21877. type: string
  21878. name:
  21879. description: The name of the Secret resource being referred to.
  21880. maxLength: 253
  21881. minLength: 1
  21882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21883. type: string
  21884. namespace:
  21885. description: |-
  21886. The namespace of the Secret resource being referred to.
  21887. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21888. maxLength: 63
  21889. minLength: 1
  21890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21891. type: string
  21892. type: object
  21893. keySecretRef:
  21894. description: |-
  21895. KeySecretRef to a key in a Secret resource containing client private key
  21896. added to the transport layer when communicating with the Vault server.
  21897. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  21898. properties:
  21899. key:
  21900. description: |-
  21901. A key in the referenced Secret.
  21902. Some instances of this field may be defaulted, in others it may be required.
  21903. maxLength: 253
  21904. minLength: 1
  21905. pattern: ^[-._a-zA-Z0-9]+$
  21906. type: string
  21907. name:
  21908. description: The name of the Secret resource being referred to.
  21909. maxLength: 253
  21910. minLength: 1
  21911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21912. type: string
  21913. namespace:
  21914. description: |-
  21915. The namespace of the Secret resource being referred to.
  21916. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21917. maxLength: 63
  21918. minLength: 1
  21919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21920. type: string
  21921. type: object
  21922. type: object
  21923. version:
  21924. default: v2
  21925. description: |-
  21926. Version is the Vault KV secret engine version. This can be either "v1" or
  21927. "v2". Version defaults to "v2".
  21928. enum:
  21929. - v1
  21930. - v2
  21931. type: string
  21932. required:
  21933. - server
  21934. type: object
  21935. volcengine:
  21936. description: Volcengine configures this store to sync secrets using the Volcengine provider
  21937. properties:
  21938. auth:
  21939. description: |-
  21940. Auth defines the authentication method to use.
  21941. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  21942. properties:
  21943. secretRef:
  21944. description: |-
  21945. SecretRef defines the static credentials to use for authentication.
  21946. If not set, IRSA is used.
  21947. properties:
  21948. accessKeyID:
  21949. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  21950. properties:
  21951. key:
  21952. description: |-
  21953. A key in the referenced Secret.
  21954. Some instances of this field may be defaulted, in others it may be required.
  21955. maxLength: 253
  21956. minLength: 1
  21957. pattern: ^[-._a-zA-Z0-9]+$
  21958. type: string
  21959. name:
  21960. description: The name of the Secret resource being referred to.
  21961. maxLength: 253
  21962. minLength: 1
  21963. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21964. type: string
  21965. namespace:
  21966. description: |-
  21967. The namespace of the Secret resource being referred to.
  21968. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21969. maxLength: 63
  21970. minLength: 1
  21971. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21972. type: string
  21973. type: object
  21974. secretAccessKey:
  21975. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  21976. properties:
  21977. key:
  21978. description: |-
  21979. A key in the referenced Secret.
  21980. Some instances of this field may be defaulted, in others it may be required.
  21981. maxLength: 253
  21982. minLength: 1
  21983. pattern: ^[-._a-zA-Z0-9]+$
  21984. type: string
  21985. name:
  21986. description: The name of the Secret resource being referred to.
  21987. maxLength: 253
  21988. minLength: 1
  21989. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21990. type: string
  21991. namespace:
  21992. description: |-
  21993. The namespace of the Secret resource being referred to.
  21994. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21995. maxLength: 63
  21996. minLength: 1
  21997. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21998. type: string
  21999. type: object
  22000. token:
  22001. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  22002. properties:
  22003. key:
  22004. description: |-
  22005. A key in the referenced Secret.
  22006. Some instances of this field may be defaulted, in others it may be required.
  22007. maxLength: 253
  22008. minLength: 1
  22009. pattern: ^[-._a-zA-Z0-9]+$
  22010. type: string
  22011. name:
  22012. description: The name of the Secret resource being referred to.
  22013. maxLength: 253
  22014. minLength: 1
  22015. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22016. type: string
  22017. namespace:
  22018. description: |-
  22019. The namespace of the Secret resource being referred to.
  22020. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22021. maxLength: 63
  22022. minLength: 1
  22023. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22024. type: string
  22025. type: object
  22026. required:
  22027. - accessKeyID
  22028. - secretAccessKey
  22029. type: object
  22030. type: object
  22031. region:
  22032. description: Region specifies the Volcengine region to connect to.
  22033. type: string
  22034. required:
  22035. - region
  22036. type: object
  22037. webhook:
  22038. description: Webhook configures this store to sync secrets using a generic templated webhook
  22039. properties:
  22040. auth:
  22041. description: Auth specifies a authorization protocol. Only one protocol may be set.
  22042. maxProperties: 1
  22043. minProperties: 1
  22044. properties:
  22045. ntlm:
  22046. description: NTLMProtocol configures the store to use NTLM for auth
  22047. properties:
  22048. passwordSecret:
  22049. description: |-
  22050. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22051. In some instances, `key` is a required field.
  22052. properties:
  22053. key:
  22054. description: |-
  22055. A key in the referenced Secret.
  22056. Some instances of this field may be defaulted, in others it may be required.
  22057. maxLength: 253
  22058. minLength: 1
  22059. pattern: ^[-._a-zA-Z0-9]+$
  22060. type: string
  22061. name:
  22062. description: The name of the Secret resource being referred to.
  22063. maxLength: 253
  22064. minLength: 1
  22065. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22066. type: string
  22067. namespace:
  22068. description: |-
  22069. The namespace of the Secret resource being referred to.
  22070. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22071. maxLength: 63
  22072. minLength: 1
  22073. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22074. type: string
  22075. type: object
  22076. usernameSecret:
  22077. description: |-
  22078. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22079. In some instances, `key` is a required field.
  22080. properties:
  22081. key:
  22082. description: |-
  22083. A key in the referenced Secret.
  22084. Some instances of this field may be defaulted, in others it may be required.
  22085. maxLength: 253
  22086. minLength: 1
  22087. pattern: ^[-._a-zA-Z0-9]+$
  22088. type: string
  22089. name:
  22090. description: The name of the Secret resource being referred to.
  22091. maxLength: 253
  22092. minLength: 1
  22093. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22094. type: string
  22095. namespace:
  22096. description: |-
  22097. The namespace of the Secret resource being referred to.
  22098. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22099. maxLength: 63
  22100. minLength: 1
  22101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22102. type: string
  22103. type: object
  22104. required:
  22105. - passwordSecret
  22106. - usernameSecret
  22107. type: object
  22108. type: object
  22109. body:
  22110. description: Body
  22111. type: string
  22112. caBundle:
  22113. description: |-
  22114. PEM encoded CA bundle used to validate webhook server certificate. Only used
  22115. if the Server URL is using HTTPS protocol. This parameter is ignored for
  22116. plain HTTP protocol connection. If not set the system root certificates
  22117. are used to validate the TLS connection.
  22118. format: byte
  22119. type: string
  22120. caProvider:
  22121. description: The provider for the CA bundle to use to validate webhook server certificate.
  22122. properties:
  22123. key:
  22124. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22125. maxLength: 253
  22126. minLength: 1
  22127. pattern: ^[-._a-zA-Z0-9]+$
  22128. type: string
  22129. name:
  22130. description: The name of the object located at the provider type.
  22131. maxLength: 253
  22132. minLength: 1
  22133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22134. type: string
  22135. namespace:
  22136. description: The namespace the Provider type is in.
  22137. maxLength: 63
  22138. minLength: 1
  22139. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22140. type: string
  22141. type:
  22142. description: The type of provider to use such as "Secret", or "ConfigMap".
  22143. enum:
  22144. - Secret
  22145. - ConfigMap
  22146. type: string
  22147. required:
  22148. - name
  22149. - type
  22150. type: object
  22151. headers:
  22152. additionalProperties:
  22153. type: string
  22154. description: Headers
  22155. type: object
  22156. method:
  22157. description: Webhook Method
  22158. type: string
  22159. result:
  22160. description: Result formatting
  22161. properties:
  22162. jsonPath:
  22163. description: Json path of return value
  22164. type: string
  22165. type: object
  22166. secrets:
  22167. description: |-
  22168. Secrets to fill in templates
  22169. These secrets will be passed to the templating function as key value pairs under the given name
  22170. items:
  22171. description: WebhookSecret defines a secret that will be passed to the webhook request.
  22172. properties:
  22173. name:
  22174. description: Name of this secret in templates
  22175. type: string
  22176. secretRef:
  22177. description: Secret ref to fill in credentials
  22178. properties:
  22179. key:
  22180. description: |-
  22181. A key in the referenced Secret.
  22182. Some instances of this field may be defaulted, in others it may be required.
  22183. maxLength: 253
  22184. minLength: 1
  22185. pattern: ^[-._a-zA-Z0-9]+$
  22186. type: string
  22187. name:
  22188. description: The name of the Secret resource being referred to.
  22189. maxLength: 253
  22190. minLength: 1
  22191. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22192. type: string
  22193. namespace:
  22194. description: |-
  22195. The namespace of the Secret resource being referred to.
  22196. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22197. maxLength: 63
  22198. minLength: 1
  22199. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22200. type: string
  22201. type: object
  22202. required:
  22203. - name
  22204. - secretRef
  22205. type: object
  22206. type: array
  22207. timeout:
  22208. description: Timeout
  22209. type: string
  22210. url:
  22211. description: Webhook url to call
  22212. type: string
  22213. required:
  22214. - url
  22215. type: object
  22216. yandexcertificatemanager:
  22217. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  22218. properties:
  22219. apiEndpoint:
  22220. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  22221. type: string
  22222. auth:
  22223. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  22224. properties:
  22225. authorizedKeySecretRef:
  22226. description: The authorized key used for authentication
  22227. properties:
  22228. key:
  22229. description: |-
  22230. A key in the referenced Secret.
  22231. Some instances of this field may be defaulted, in others it may be required.
  22232. maxLength: 253
  22233. minLength: 1
  22234. pattern: ^[-._a-zA-Z0-9]+$
  22235. type: string
  22236. name:
  22237. description: The name of the Secret resource being referred to.
  22238. maxLength: 253
  22239. minLength: 1
  22240. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22241. type: string
  22242. namespace:
  22243. description: |-
  22244. The namespace of the Secret resource being referred to.
  22245. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22246. maxLength: 63
  22247. minLength: 1
  22248. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22249. type: string
  22250. type: object
  22251. type: object
  22252. caProvider:
  22253. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  22254. properties:
  22255. certSecretRef:
  22256. description: |-
  22257. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22258. In some instances, `key` is a required field.
  22259. properties:
  22260. key:
  22261. description: |-
  22262. A key in the referenced Secret.
  22263. Some instances of this field may be defaulted, in others it may be required.
  22264. maxLength: 253
  22265. minLength: 1
  22266. pattern: ^[-._a-zA-Z0-9]+$
  22267. type: string
  22268. name:
  22269. description: The name of the Secret resource being referred to.
  22270. maxLength: 253
  22271. minLength: 1
  22272. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22273. type: string
  22274. namespace:
  22275. description: |-
  22276. The namespace of the Secret resource being referred to.
  22277. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22278. maxLength: 63
  22279. minLength: 1
  22280. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22281. type: string
  22282. type: object
  22283. type: object
  22284. fetching:
  22285. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  22286. maxProperties: 1
  22287. minProperties: 1
  22288. properties:
  22289. byID:
  22290. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  22291. type: object
  22292. byName:
  22293. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  22294. properties:
  22295. folderID:
  22296. description: The folder to fetch secrets from
  22297. type: string
  22298. required:
  22299. - folderID
  22300. type: object
  22301. type: object
  22302. required:
  22303. - auth
  22304. type: object
  22305. yandexlockbox:
  22306. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  22307. properties:
  22308. apiEndpoint:
  22309. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  22310. type: string
  22311. auth:
  22312. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  22313. properties:
  22314. authorizedKeySecretRef:
  22315. description: The authorized key used for authentication
  22316. properties:
  22317. key:
  22318. description: |-
  22319. A key in the referenced Secret.
  22320. Some instances of this field may be defaulted, in others it may be required.
  22321. maxLength: 253
  22322. minLength: 1
  22323. pattern: ^[-._a-zA-Z0-9]+$
  22324. type: string
  22325. name:
  22326. description: The name of the Secret resource being referred to.
  22327. maxLength: 253
  22328. minLength: 1
  22329. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22330. type: string
  22331. namespace:
  22332. description: |-
  22333. The namespace of the Secret resource being referred to.
  22334. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22335. maxLength: 63
  22336. minLength: 1
  22337. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22338. type: string
  22339. type: object
  22340. type: object
  22341. caProvider:
  22342. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  22343. properties:
  22344. certSecretRef:
  22345. description: |-
  22346. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22347. In some instances, `key` is a required field.
  22348. properties:
  22349. key:
  22350. description: |-
  22351. A key in the referenced Secret.
  22352. Some instances of this field may be defaulted, in others it may be required.
  22353. maxLength: 253
  22354. minLength: 1
  22355. pattern: ^[-._a-zA-Z0-9]+$
  22356. type: string
  22357. name:
  22358. description: The name of the Secret resource being referred to.
  22359. maxLength: 253
  22360. minLength: 1
  22361. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22362. type: string
  22363. namespace:
  22364. description: |-
  22365. The namespace of the Secret resource being referred to.
  22366. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22367. maxLength: 63
  22368. minLength: 1
  22369. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22370. type: string
  22371. type: object
  22372. type: object
  22373. fetching:
  22374. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  22375. maxProperties: 1
  22376. minProperties: 1
  22377. properties:
  22378. byID:
  22379. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  22380. type: object
  22381. byName:
  22382. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  22383. properties:
  22384. folderID:
  22385. description: The folder to fetch secrets from
  22386. type: string
  22387. required:
  22388. - folderID
  22389. type: object
  22390. type: object
  22391. required:
  22392. - auth
  22393. type: object
  22394. type: object
  22395. refreshInterval:
  22396. anyOf:
  22397. - type: integer
  22398. - type: string
  22399. description: |-
  22400. Used to configure store refresh interval. Accepts either an integer number
  22401. of seconds (legacy) or a Go duration string such as "1h" or "5m". Empty or
  22402. 0 will default to the controller config.
  22403. x-kubernetes-int-or-string: true
  22404. retrySettings:
  22405. description: Used to configure HTTP retries on failures.
  22406. properties:
  22407. maxRetries:
  22408. format: int32
  22409. type: integer
  22410. retryInterval:
  22411. type: string
  22412. type: object
  22413. required:
  22414. - provider
  22415. type: object
  22416. status:
  22417. description: SecretStoreStatus defines the observed state of the SecretStore.
  22418. properties:
  22419. capabilities:
  22420. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  22421. type: string
  22422. conditions:
  22423. items:
  22424. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  22425. properties:
  22426. lastTransitionTime:
  22427. format: date-time
  22428. type: string
  22429. message:
  22430. type: string
  22431. reason:
  22432. type: string
  22433. status:
  22434. type: string
  22435. type:
  22436. description: SecretStoreConditionType represents the condition of the SecretStore.
  22437. type: string
  22438. required:
  22439. - status
  22440. - type
  22441. type: object
  22442. type: array
  22443. type: object
  22444. type: object
  22445. served: true
  22446. storage: true
  22447. subresources:
  22448. status: {}
  22449. - additionalPrinterColumns:
  22450. - jsonPath: .metadata.creationTimestamp
  22451. name: AGE
  22452. type: date
  22453. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  22454. name: Status
  22455. type: string
  22456. - jsonPath: .status.capabilities
  22457. name: Capabilities
  22458. type: string
  22459. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  22460. name: Ready
  22461. type: string
  22462. deprecated: true
  22463. name: v1beta1
  22464. schema:
  22465. openAPIV3Schema:
  22466. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  22467. properties:
  22468. apiVersion:
  22469. description: |-
  22470. APIVersion defines the versioned schema of this representation of an object.
  22471. Servers should convert recognized schemas to the latest internal value, and
  22472. may reject unrecognized values.
  22473. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  22474. type: string
  22475. kind:
  22476. description: |-
  22477. Kind is a string value representing the REST resource this object represents.
  22478. Servers may infer this from the endpoint the client submits requests to.
  22479. Cannot be updated.
  22480. In CamelCase.
  22481. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  22482. type: string
  22483. metadata:
  22484. type: object
  22485. spec:
  22486. description: SecretStoreSpec defines the desired state of SecretStore.
  22487. properties:
  22488. conditions:
  22489. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  22490. items:
  22491. description: |-
  22492. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  22493. for a ClusterSecretStore instance.
  22494. properties:
  22495. namespaceRegexes:
  22496. description: Choose namespaces by using regex matching
  22497. items:
  22498. type: string
  22499. type: array
  22500. namespaceSelector:
  22501. description: Choose namespace using a labelSelector
  22502. properties:
  22503. matchExpressions:
  22504. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  22505. items:
  22506. description: |-
  22507. A label selector requirement is a selector that contains values, a key, and an operator that
  22508. relates the key and values.
  22509. properties:
  22510. key:
  22511. description: key is the label key that the selector applies to.
  22512. type: string
  22513. operator:
  22514. description: |-
  22515. operator represents a key's relationship to a set of values.
  22516. Valid operators are In, NotIn, Exists and DoesNotExist.
  22517. type: string
  22518. values:
  22519. description: |-
  22520. values is an array of string values. If the operator is In or NotIn,
  22521. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  22522. the values array must be empty. This array is replaced during a strategic
  22523. merge patch.
  22524. items:
  22525. type: string
  22526. type: array
  22527. x-kubernetes-list-type: atomic
  22528. required:
  22529. - key
  22530. - operator
  22531. type: object
  22532. type: array
  22533. x-kubernetes-list-type: atomic
  22534. matchLabels:
  22535. additionalProperties:
  22536. type: string
  22537. description: |-
  22538. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  22539. map is equivalent to an element of matchExpressions, whose key field is "key", the
  22540. operator is "In", and the values array contains only "value". The requirements are ANDed.
  22541. type: object
  22542. type: object
  22543. x-kubernetes-map-type: atomic
  22544. namespaces:
  22545. description: Choose namespaces by name
  22546. items:
  22547. maxLength: 63
  22548. minLength: 1
  22549. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22550. type: string
  22551. type: array
  22552. type: object
  22553. type: array
  22554. controller:
  22555. description: |-
  22556. Used to select the correct ESO controller (think: ingress.ingressClassName)
  22557. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  22558. type: string
  22559. provider:
  22560. description: Used to configure the provider. Only one provider may be set
  22561. maxProperties: 1
  22562. minProperties: 1
  22563. properties:
  22564. akeyless:
  22565. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  22566. properties:
  22567. akeylessGWApiURL:
  22568. description: Akeyless GW API Url from which the secrets to be fetched from.
  22569. type: string
  22570. authSecretRef:
  22571. description: Auth configures how the operator authenticates with Akeyless.
  22572. properties:
  22573. kubernetesAuth:
  22574. description: |-
  22575. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  22576. token stored in the named Secret resource.
  22577. properties:
  22578. accessID:
  22579. description: the Akeyless Kubernetes auth-method access-id
  22580. type: string
  22581. k8sConfName:
  22582. description: Kubernetes-auth configuration name in Akeyless-Gateway
  22583. type: string
  22584. secretRef:
  22585. description: |-
  22586. Optional secret field containing a Kubernetes ServiceAccount JWT used
  22587. for authenticating with Akeyless. If a name is specified without a key,
  22588. `token` is the default. If one is not specified, the one bound to
  22589. the controller will be used.
  22590. properties:
  22591. key:
  22592. description: |-
  22593. A key in the referenced Secret.
  22594. Some instances of this field may be defaulted, in others it may be required.
  22595. maxLength: 253
  22596. minLength: 1
  22597. pattern: ^[-._a-zA-Z0-9]+$
  22598. type: string
  22599. name:
  22600. description: The name of the Secret resource being referred to.
  22601. maxLength: 253
  22602. minLength: 1
  22603. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22604. type: string
  22605. namespace:
  22606. description: |-
  22607. The namespace of the Secret resource being referred to.
  22608. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22609. maxLength: 63
  22610. minLength: 1
  22611. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22612. type: string
  22613. type: object
  22614. serviceAccountRef:
  22615. description: |-
  22616. Optional service account field containing the name of a kubernetes ServiceAccount.
  22617. If the service account is specified, the service account secret token JWT will be used
  22618. for authenticating with Akeyless. If the service account selector is not supplied,
  22619. the secretRef will be used instead.
  22620. properties:
  22621. audiences:
  22622. description: |-
  22623. Audience specifies the `aud` claim for the service account token
  22624. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  22625. then this audiences will be appended to the list
  22626. items:
  22627. type: string
  22628. type: array
  22629. name:
  22630. description: The name of the ServiceAccount resource being referred to.
  22631. maxLength: 253
  22632. minLength: 1
  22633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22634. type: string
  22635. namespace:
  22636. description: |-
  22637. Namespace of the resource being referred to.
  22638. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22639. maxLength: 63
  22640. minLength: 1
  22641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22642. type: string
  22643. required:
  22644. - name
  22645. type: object
  22646. required:
  22647. - accessID
  22648. - k8sConfName
  22649. type: object
  22650. secretRef:
  22651. description: |-
  22652. Reference to a Secret that contains the details
  22653. to authenticate with Akeyless.
  22654. properties:
  22655. accessID:
  22656. description: The SecretAccessID is used for authentication
  22657. properties:
  22658. key:
  22659. description: |-
  22660. A key in the referenced Secret.
  22661. Some instances of this field may be defaulted, in others it may be required.
  22662. maxLength: 253
  22663. minLength: 1
  22664. pattern: ^[-._a-zA-Z0-9]+$
  22665. type: string
  22666. name:
  22667. description: The name of the Secret resource being referred to.
  22668. maxLength: 253
  22669. minLength: 1
  22670. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22671. type: string
  22672. namespace:
  22673. description: |-
  22674. The namespace of the Secret resource being referred to.
  22675. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22676. maxLength: 63
  22677. minLength: 1
  22678. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22679. type: string
  22680. type: object
  22681. accessType:
  22682. description: |-
  22683. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22684. In some instances, `key` is a required field.
  22685. properties:
  22686. key:
  22687. description: |-
  22688. A key in the referenced Secret.
  22689. Some instances of this field may be defaulted, in others it may be required.
  22690. maxLength: 253
  22691. minLength: 1
  22692. pattern: ^[-._a-zA-Z0-9]+$
  22693. type: string
  22694. name:
  22695. description: The name of the Secret resource being referred to.
  22696. maxLength: 253
  22697. minLength: 1
  22698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22699. type: string
  22700. namespace:
  22701. description: |-
  22702. The namespace of the Secret resource being referred to.
  22703. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22704. maxLength: 63
  22705. minLength: 1
  22706. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22707. type: string
  22708. type: object
  22709. accessTypeParam:
  22710. description: |-
  22711. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22712. In some instances, `key` is a required field.
  22713. properties:
  22714. key:
  22715. description: |-
  22716. A key in the referenced Secret.
  22717. Some instances of this field may be defaulted, in others it may be required.
  22718. maxLength: 253
  22719. minLength: 1
  22720. pattern: ^[-._a-zA-Z0-9]+$
  22721. type: string
  22722. name:
  22723. description: The name of the Secret resource being referred to.
  22724. maxLength: 253
  22725. minLength: 1
  22726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22727. type: string
  22728. namespace:
  22729. description: |-
  22730. The namespace of the Secret resource being referred to.
  22731. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22732. maxLength: 63
  22733. minLength: 1
  22734. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22735. type: string
  22736. type: object
  22737. type: object
  22738. type: object
  22739. caBundle:
  22740. description: |-
  22741. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  22742. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  22743. are used to validate the TLS connection.
  22744. format: byte
  22745. type: string
  22746. caProvider:
  22747. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  22748. properties:
  22749. key:
  22750. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22751. maxLength: 253
  22752. minLength: 1
  22753. pattern: ^[-._a-zA-Z0-9]+$
  22754. type: string
  22755. name:
  22756. description: The name of the object located at the provider type.
  22757. maxLength: 253
  22758. minLength: 1
  22759. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22760. type: string
  22761. namespace:
  22762. description: |-
  22763. The namespace the Provider type is in.
  22764. Can only be defined when used in a ClusterSecretStore.
  22765. maxLength: 63
  22766. minLength: 1
  22767. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22768. type: string
  22769. type:
  22770. description: The type of provider to use such as "Secret", or "ConfigMap".
  22771. enum:
  22772. - Secret
  22773. - ConfigMap
  22774. type: string
  22775. required:
  22776. - name
  22777. - type
  22778. type: object
  22779. required:
  22780. - akeylessGWApiURL
  22781. - authSecretRef
  22782. type: object
  22783. alibaba:
  22784. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  22785. properties:
  22786. auth:
  22787. description: AlibabaAuth contains a secretRef for credentials.
  22788. properties:
  22789. rrsa:
  22790. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  22791. properties:
  22792. oidcProviderArn:
  22793. type: string
  22794. oidcTokenFilePath:
  22795. type: string
  22796. roleArn:
  22797. type: string
  22798. sessionName:
  22799. type: string
  22800. required:
  22801. - oidcProviderArn
  22802. - oidcTokenFilePath
  22803. - roleArn
  22804. - sessionName
  22805. type: object
  22806. secretRef:
  22807. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  22808. properties:
  22809. accessKeyIDSecretRef:
  22810. description: The AccessKeyID is used for authentication
  22811. properties:
  22812. key:
  22813. description: |-
  22814. A key in the referenced Secret.
  22815. Some instances of this field may be defaulted, in others it may be required.
  22816. maxLength: 253
  22817. minLength: 1
  22818. pattern: ^[-._a-zA-Z0-9]+$
  22819. type: string
  22820. name:
  22821. description: The name of the Secret resource being referred to.
  22822. maxLength: 253
  22823. minLength: 1
  22824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22825. type: string
  22826. namespace:
  22827. description: |-
  22828. The namespace of the Secret resource being referred to.
  22829. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22830. maxLength: 63
  22831. minLength: 1
  22832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22833. type: string
  22834. type: object
  22835. accessKeySecretSecretRef:
  22836. description: The AccessKeySecret is used for authentication
  22837. properties:
  22838. key:
  22839. description: |-
  22840. A key in the referenced Secret.
  22841. Some instances of this field may be defaulted, in others it may be required.
  22842. maxLength: 253
  22843. minLength: 1
  22844. pattern: ^[-._a-zA-Z0-9]+$
  22845. type: string
  22846. name:
  22847. description: The name of the Secret resource being referred to.
  22848. maxLength: 253
  22849. minLength: 1
  22850. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22851. type: string
  22852. namespace:
  22853. description: |-
  22854. The namespace of the Secret resource being referred to.
  22855. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22856. maxLength: 63
  22857. minLength: 1
  22858. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22859. type: string
  22860. type: object
  22861. required:
  22862. - accessKeyIDSecretRef
  22863. - accessKeySecretSecretRef
  22864. type: object
  22865. type: object
  22866. regionID:
  22867. description: Alibaba Region to be used for the provider
  22868. type: string
  22869. required:
  22870. - auth
  22871. - regionID
  22872. type: object
  22873. aws:
  22874. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  22875. properties:
  22876. additionalRoles:
  22877. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  22878. items:
  22879. type: string
  22880. type: array
  22881. auth:
  22882. description: |-
  22883. Auth defines the information necessary to authenticate against AWS
  22884. if not set aws sdk will infer credentials from your environment
  22885. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  22886. properties:
  22887. jwt:
  22888. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  22889. properties:
  22890. serviceAccountRef:
  22891. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  22892. properties:
  22893. audiences:
  22894. description: |-
  22895. Audience specifies the `aud` claim for the service account token
  22896. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  22897. then this audiences will be appended to the list
  22898. items:
  22899. type: string
  22900. type: array
  22901. name:
  22902. description: The name of the ServiceAccount resource being referred to.
  22903. maxLength: 253
  22904. minLength: 1
  22905. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22906. type: string
  22907. namespace:
  22908. description: |-
  22909. Namespace of the resource being referred to.
  22910. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22911. maxLength: 63
  22912. minLength: 1
  22913. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22914. type: string
  22915. required:
  22916. - name
  22917. type: object
  22918. type: object
  22919. secretRef:
  22920. description: |-
  22921. AWSAuthSecretRef holds secret references for AWS credentials
  22922. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  22923. properties:
  22924. accessKeyIDSecretRef:
  22925. description: The AccessKeyID is used for authentication
  22926. properties:
  22927. key:
  22928. description: |-
  22929. A key in the referenced Secret.
  22930. Some instances of this field may be defaulted, in others it may be required.
  22931. maxLength: 253
  22932. minLength: 1
  22933. pattern: ^[-._a-zA-Z0-9]+$
  22934. type: string
  22935. name:
  22936. description: The name of the Secret resource being referred to.
  22937. maxLength: 253
  22938. minLength: 1
  22939. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22940. type: string
  22941. namespace:
  22942. description: |-
  22943. The namespace of the Secret resource being referred to.
  22944. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22945. maxLength: 63
  22946. minLength: 1
  22947. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22948. type: string
  22949. type: object
  22950. secretAccessKeySecretRef:
  22951. description: The SecretAccessKey is used for authentication
  22952. properties:
  22953. key:
  22954. description: |-
  22955. A key in the referenced Secret.
  22956. Some instances of this field may be defaulted, in others it may be required.
  22957. maxLength: 253
  22958. minLength: 1
  22959. pattern: ^[-._a-zA-Z0-9]+$
  22960. type: string
  22961. name:
  22962. description: The name of the Secret resource being referred to.
  22963. maxLength: 253
  22964. minLength: 1
  22965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22966. type: string
  22967. namespace:
  22968. description: |-
  22969. The namespace of the Secret resource being referred to.
  22970. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22971. maxLength: 63
  22972. minLength: 1
  22973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22974. type: string
  22975. type: object
  22976. sessionTokenSecretRef:
  22977. description: |-
  22978. The SessionToken used for authentication
  22979. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  22980. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  22981. properties:
  22982. key:
  22983. description: |-
  22984. A key in the referenced Secret.
  22985. Some instances of this field may be defaulted, in others it may be required.
  22986. maxLength: 253
  22987. minLength: 1
  22988. pattern: ^[-._a-zA-Z0-9]+$
  22989. type: string
  22990. name:
  22991. description: The name of the Secret resource being referred to.
  22992. maxLength: 253
  22993. minLength: 1
  22994. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22995. type: string
  22996. namespace:
  22997. description: |-
  22998. The namespace of the Secret resource being referred to.
  22999. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23000. maxLength: 63
  23001. minLength: 1
  23002. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23003. type: string
  23004. type: object
  23005. type: object
  23006. type: object
  23007. externalID:
  23008. description: AWS External ID set on assumed IAM roles
  23009. type: string
  23010. prefix:
  23011. description: Prefix adds a prefix to all retrieved values.
  23012. type: string
  23013. region:
  23014. description: AWS Region to be used for the provider
  23015. type: string
  23016. role:
  23017. description: Role is a Role ARN which the provider will assume
  23018. type: string
  23019. secretsManager:
  23020. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  23021. properties:
  23022. forceDeleteWithoutRecovery:
  23023. description: |-
  23024. Specifies whether to delete the secret without any recovery window. You
  23025. can't use both this parameter and RecoveryWindowInDays in the same call.
  23026. If you don't use either, then by default Secrets Manager uses a 30 day
  23027. recovery window.
  23028. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  23029. type: boolean
  23030. recoveryWindowInDays:
  23031. description: |-
  23032. The number of days from 7 to 30 that Secrets Manager waits before
  23033. permanently deleting the secret. You can't use both this parameter and
  23034. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  23035. then by default Secrets Manager uses a 30 day recovery window.
  23036. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  23037. format: int64
  23038. type: integer
  23039. type: object
  23040. service:
  23041. description: Service defines which service should be used to fetch the secrets
  23042. enum:
  23043. - SecretsManager
  23044. - ParameterStore
  23045. type: string
  23046. sessionTags:
  23047. description: AWS STS assume role session tags
  23048. items:
  23049. description: Tag defines a tag key and value for AWS resources.
  23050. properties:
  23051. key:
  23052. type: string
  23053. value:
  23054. type: string
  23055. required:
  23056. - key
  23057. - value
  23058. type: object
  23059. type: array
  23060. transitiveTagKeys:
  23061. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  23062. items:
  23063. type: string
  23064. type: array
  23065. required:
  23066. - region
  23067. - service
  23068. type: object
  23069. azurekv:
  23070. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  23071. properties:
  23072. authSecretRef:
  23073. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  23074. properties:
  23075. clientCertificate:
  23076. description: The Azure ClientCertificate of the service principle used for authentication.
  23077. properties:
  23078. key:
  23079. description: |-
  23080. A key in the referenced Secret.
  23081. Some instances of this field may be defaulted, in others it may be required.
  23082. maxLength: 253
  23083. minLength: 1
  23084. pattern: ^[-._a-zA-Z0-9]+$
  23085. type: string
  23086. name:
  23087. description: The name of the Secret resource being referred to.
  23088. maxLength: 253
  23089. minLength: 1
  23090. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23091. type: string
  23092. namespace:
  23093. description: |-
  23094. The namespace of the Secret resource being referred to.
  23095. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23096. maxLength: 63
  23097. minLength: 1
  23098. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23099. type: string
  23100. type: object
  23101. clientId:
  23102. description: The Azure clientId of the service principle or managed identity used for authentication.
  23103. properties:
  23104. key:
  23105. description: |-
  23106. A key in the referenced Secret.
  23107. Some instances of this field may be defaulted, in others it may be required.
  23108. maxLength: 253
  23109. minLength: 1
  23110. pattern: ^[-._a-zA-Z0-9]+$
  23111. type: string
  23112. name:
  23113. description: The name of the Secret resource being referred to.
  23114. maxLength: 253
  23115. minLength: 1
  23116. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23117. type: string
  23118. namespace:
  23119. description: |-
  23120. The namespace of the Secret resource being referred to.
  23121. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23122. maxLength: 63
  23123. minLength: 1
  23124. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23125. type: string
  23126. type: object
  23127. clientSecret:
  23128. description: The Azure ClientSecret of the service principle used for authentication.
  23129. properties:
  23130. key:
  23131. description: |-
  23132. A key in the referenced Secret.
  23133. Some instances of this field may be defaulted, in others it may be required.
  23134. maxLength: 253
  23135. minLength: 1
  23136. pattern: ^[-._a-zA-Z0-9]+$
  23137. type: string
  23138. name:
  23139. description: The name of the Secret resource being referred to.
  23140. maxLength: 253
  23141. minLength: 1
  23142. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23143. type: string
  23144. namespace:
  23145. description: |-
  23146. The namespace of the Secret resource being referred to.
  23147. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23148. maxLength: 63
  23149. minLength: 1
  23150. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23151. type: string
  23152. type: object
  23153. tenantId:
  23154. description: The Azure tenantId of the managed identity used for authentication.
  23155. properties:
  23156. key:
  23157. description: |-
  23158. A key in the referenced Secret.
  23159. Some instances of this field may be defaulted, in others it may be required.
  23160. maxLength: 253
  23161. minLength: 1
  23162. pattern: ^[-._a-zA-Z0-9]+$
  23163. type: string
  23164. name:
  23165. description: The name of the Secret resource being referred to.
  23166. maxLength: 253
  23167. minLength: 1
  23168. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23169. type: string
  23170. namespace:
  23171. description: |-
  23172. The namespace of the Secret resource being referred to.
  23173. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23174. maxLength: 63
  23175. minLength: 1
  23176. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23177. type: string
  23178. type: object
  23179. type: object
  23180. authType:
  23181. default: ServicePrincipal
  23182. description: |-
  23183. Auth type defines how to authenticate to the keyvault service.
  23184. Valid values are:
  23185. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  23186. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  23187. enum:
  23188. - ServicePrincipal
  23189. - ManagedIdentity
  23190. - WorkloadIdentity
  23191. type: string
  23192. environmentType:
  23193. default: PublicCloud
  23194. description: |-
  23195. EnvironmentType specifies the Azure cloud environment endpoints to use for
  23196. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  23197. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  23198. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  23199. enum:
  23200. - PublicCloud
  23201. - USGovernmentCloud
  23202. - ChinaCloud
  23203. - GermanCloud
  23204. type: string
  23205. identityId:
  23206. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  23207. type: string
  23208. serviceAccountRef:
  23209. description: |-
  23210. ServiceAccountRef specified the service account
  23211. that should be used when authenticating with WorkloadIdentity.
  23212. properties:
  23213. audiences:
  23214. description: |-
  23215. Audience specifies the `aud` claim for the service account token
  23216. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  23217. then this audiences will be appended to the list
  23218. items:
  23219. type: string
  23220. type: array
  23221. name:
  23222. description: The name of the ServiceAccount resource being referred to.
  23223. maxLength: 253
  23224. minLength: 1
  23225. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23226. type: string
  23227. namespace:
  23228. description: |-
  23229. Namespace of the resource being referred to.
  23230. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23231. maxLength: 63
  23232. minLength: 1
  23233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23234. type: string
  23235. required:
  23236. - name
  23237. type: object
  23238. tenantId:
  23239. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  23240. type: string
  23241. vaultUrl:
  23242. description: Vault Url from which the secrets to be fetched from.
  23243. type: string
  23244. required:
  23245. - vaultUrl
  23246. type: object
  23247. beyondtrust:
  23248. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  23249. properties:
  23250. auth:
  23251. description: Auth configures how the operator authenticates with Beyondtrust.
  23252. properties:
  23253. apiKey:
  23254. description: APIKey If not provided then ClientID/ClientSecret become required.
  23255. properties:
  23256. secretRef:
  23257. description: SecretRef references a key in a secret that will be used as value.
  23258. properties:
  23259. key:
  23260. description: |-
  23261. A key in the referenced Secret.
  23262. Some instances of this field may be defaulted, in others it may be required.
  23263. maxLength: 253
  23264. minLength: 1
  23265. pattern: ^[-._a-zA-Z0-9]+$
  23266. type: string
  23267. name:
  23268. description: The name of the Secret resource being referred to.
  23269. maxLength: 253
  23270. minLength: 1
  23271. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23272. type: string
  23273. namespace:
  23274. description: |-
  23275. The namespace of the Secret resource being referred to.
  23276. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23277. maxLength: 63
  23278. minLength: 1
  23279. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23280. type: string
  23281. type: object
  23282. value:
  23283. description: Value can be specified directly to set a value without using a secret.
  23284. type: string
  23285. type: object
  23286. certificate:
  23287. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  23288. properties:
  23289. secretRef:
  23290. description: SecretRef references a key in a secret that will be used as value.
  23291. properties:
  23292. key:
  23293. description: |-
  23294. A key in the referenced Secret.
  23295. Some instances of this field may be defaulted, in others it may be required.
  23296. maxLength: 253
  23297. minLength: 1
  23298. pattern: ^[-._a-zA-Z0-9]+$
  23299. type: string
  23300. name:
  23301. description: The name of the Secret resource being referred to.
  23302. maxLength: 253
  23303. minLength: 1
  23304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23305. type: string
  23306. namespace:
  23307. description: |-
  23308. The namespace of the Secret resource being referred to.
  23309. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23310. maxLength: 63
  23311. minLength: 1
  23312. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23313. type: string
  23314. type: object
  23315. value:
  23316. description: Value can be specified directly to set a value without using a secret.
  23317. type: string
  23318. type: object
  23319. certificateKey:
  23320. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  23321. properties:
  23322. secretRef:
  23323. description: SecretRef references a key in a secret that will be used as value.
  23324. properties:
  23325. key:
  23326. description: |-
  23327. A key in the referenced Secret.
  23328. Some instances of this field may be defaulted, in others it may be required.
  23329. maxLength: 253
  23330. minLength: 1
  23331. pattern: ^[-._a-zA-Z0-9]+$
  23332. type: string
  23333. name:
  23334. description: The name of the Secret resource being referred to.
  23335. maxLength: 253
  23336. minLength: 1
  23337. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23338. type: string
  23339. namespace:
  23340. description: |-
  23341. The namespace of the Secret resource being referred to.
  23342. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23343. maxLength: 63
  23344. minLength: 1
  23345. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23346. type: string
  23347. type: object
  23348. value:
  23349. description: Value can be specified directly to set a value without using a secret.
  23350. type: string
  23351. type: object
  23352. clientId:
  23353. description: ClientID is the API OAuth Client ID.
  23354. properties:
  23355. secretRef:
  23356. description: SecretRef references a key in a secret that will be used as value.
  23357. properties:
  23358. key:
  23359. description: |-
  23360. A key in the referenced Secret.
  23361. Some instances of this field may be defaulted, in others it may be required.
  23362. maxLength: 253
  23363. minLength: 1
  23364. pattern: ^[-._a-zA-Z0-9]+$
  23365. type: string
  23366. name:
  23367. description: The name of the Secret resource being referred to.
  23368. maxLength: 253
  23369. minLength: 1
  23370. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23371. type: string
  23372. namespace:
  23373. description: |-
  23374. The namespace of the Secret resource being referred to.
  23375. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23376. maxLength: 63
  23377. minLength: 1
  23378. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23379. type: string
  23380. type: object
  23381. value:
  23382. description: Value can be specified directly to set a value without using a secret.
  23383. type: string
  23384. type: object
  23385. clientSecret:
  23386. description: ClientSecret is the API OAuth Client Secret.
  23387. properties:
  23388. secretRef:
  23389. description: SecretRef references a key in a secret that will be used as value.
  23390. properties:
  23391. key:
  23392. description: |-
  23393. A key in the referenced Secret.
  23394. Some instances of this field may be defaulted, in others it may be required.
  23395. maxLength: 253
  23396. minLength: 1
  23397. pattern: ^[-._a-zA-Z0-9]+$
  23398. type: string
  23399. name:
  23400. description: The name of the Secret resource being referred to.
  23401. maxLength: 253
  23402. minLength: 1
  23403. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23404. type: string
  23405. namespace:
  23406. description: |-
  23407. The namespace of the Secret resource being referred to.
  23408. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23409. maxLength: 63
  23410. minLength: 1
  23411. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23412. type: string
  23413. type: object
  23414. value:
  23415. description: Value can be specified directly to set a value without using a secret.
  23416. type: string
  23417. type: object
  23418. type: object
  23419. server:
  23420. description: Auth configures how API server works.
  23421. properties:
  23422. apiUrl:
  23423. type: string
  23424. apiVersion:
  23425. type: string
  23426. clientTimeOutSeconds:
  23427. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  23428. type: integer
  23429. decrypt:
  23430. default: true
  23431. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  23432. type: boolean
  23433. retrievalType:
  23434. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  23435. type: string
  23436. separator:
  23437. description: A character that separates the folder names.
  23438. type: string
  23439. verifyCA:
  23440. type: boolean
  23441. required:
  23442. - apiUrl
  23443. - verifyCA
  23444. type: object
  23445. required:
  23446. - auth
  23447. - server
  23448. type: object
  23449. bitwardensecretsmanager:
  23450. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  23451. properties:
  23452. apiURL:
  23453. type: string
  23454. auth:
  23455. description: |-
  23456. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  23457. Make sure that the token being used has permissions on the given secret.
  23458. properties:
  23459. secretRef:
  23460. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  23461. properties:
  23462. credentials:
  23463. description: AccessToken used for the bitwarden instance.
  23464. properties:
  23465. key:
  23466. description: |-
  23467. A key in the referenced Secret.
  23468. Some instances of this field may be defaulted, in others it may be required.
  23469. maxLength: 253
  23470. minLength: 1
  23471. pattern: ^[-._a-zA-Z0-9]+$
  23472. type: string
  23473. name:
  23474. description: The name of the Secret resource being referred to.
  23475. maxLength: 253
  23476. minLength: 1
  23477. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23478. type: string
  23479. namespace:
  23480. description: |-
  23481. The namespace of the Secret resource being referred to.
  23482. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23483. maxLength: 63
  23484. minLength: 1
  23485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23486. type: string
  23487. type: object
  23488. required:
  23489. - credentials
  23490. type: object
  23491. required:
  23492. - secretRef
  23493. type: object
  23494. bitwardenServerSDKURL:
  23495. type: string
  23496. caBundle:
  23497. description: |-
  23498. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  23499. can be performed.
  23500. type: string
  23501. caProvider:
  23502. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  23503. properties:
  23504. key:
  23505. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23506. maxLength: 253
  23507. minLength: 1
  23508. pattern: ^[-._a-zA-Z0-9]+$
  23509. type: string
  23510. name:
  23511. description: The name of the object located at the provider type.
  23512. maxLength: 253
  23513. minLength: 1
  23514. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23515. type: string
  23516. namespace:
  23517. description: |-
  23518. The namespace the Provider type is in.
  23519. Can only be defined when used in a ClusterSecretStore.
  23520. maxLength: 63
  23521. minLength: 1
  23522. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23523. type: string
  23524. type:
  23525. description: The type of provider to use such as "Secret", or "ConfigMap".
  23526. enum:
  23527. - Secret
  23528. - ConfigMap
  23529. type: string
  23530. required:
  23531. - name
  23532. - type
  23533. type: object
  23534. identityURL:
  23535. type: string
  23536. organizationID:
  23537. description: OrganizationID determines which organization this secret store manages.
  23538. type: string
  23539. projectID:
  23540. description: ProjectID determines which project this secret store manages.
  23541. type: string
  23542. required:
  23543. - auth
  23544. - organizationID
  23545. - projectID
  23546. type: object
  23547. chef:
  23548. description: Chef configures this store to sync secrets with chef server
  23549. properties:
  23550. auth:
  23551. description: Auth defines the information necessary to authenticate against chef Server
  23552. properties:
  23553. secretRef:
  23554. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  23555. properties:
  23556. privateKeySecretRef:
  23557. description: SecretKey is the Signing Key in PEM format, used for authentication.
  23558. properties:
  23559. key:
  23560. description: |-
  23561. A key in the referenced Secret.
  23562. Some instances of this field may be defaulted, in others it may be required.
  23563. maxLength: 253
  23564. minLength: 1
  23565. pattern: ^[-._a-zA-Z0-9]+$
  23566. type: string
  23567. name:
  23568. description: The name of the Secret resource being referred to.
  23569. maxLength: 253
  23570. minLength: 1
  23571. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23572. type: string
  23573. namespace:
  23574. description: |-
  23575. The namespace of the Secret resource being referred to.
  23576. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23577. maxLength: 63
  23578. minLength: 1
  23579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23580. type: string
  23581. type: object
  23582. required:
  23583. - privateKeySecretRef
  23584. type: object
  23585. required:
  23586. - secretRef
  23587. type: object
  23588. serverUrl:
  23589. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  23590. type: string
  23591. username:
  23592. description: UserName should be the user ID on the chef server
  23593. type: string
  23594. required:
  23595. - auth
  23596. - serverUrl
  23597. - username
  23598. type: object
  23599. cloudrusm:
  23600. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  23601. properties:
  23602. auth:
  23603. description: CSMAuth contains a secretRef for credentials.
  23604. properties:
  23605. secretRef:
  23606. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  23607. properties:
  23608. accessKeyIDSecretRef:
  23609. description: The AccessKeyID is used for authentication
  23610. properties:
  23611. key:
  23612. description: |-
  23613. A key in the referenced Secret.
  23614. Some instances of this field may be defaulted, in others it may be required.
  23615. maxLength: 253
  23616. minLength: 1
  23617. pattern: ^[-._a-zA-Z0-9]+$
  23618. type: string
  23619. name:
  23620. description: The name of the Secret resource being referred to.
  23621. maxLength: 253
  23622. minLength: 1
  23623. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23624. type: string
  23625. namespace:
  23626. description: |-
  23627. The namespace of the Secret resource being referred to.
  23628. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23629. maxLength: 63
  23630. minLength: 1
  23631. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23632. type: string
  23633. type: object
  23634. accessKeySecretSecretRef:
  23635. description: The AccessKeySecret is used for authentication
  23636. properties:
  23637. key:
  23638. description: |-
  23639. A key in the referenced Secret.
  23640. Some instances of this field may be defaulted, in others it may be required.
  23641. maxLength: 253
  23642. minLength: 1
  23643. pattern: ^[-._a-zA-Z0-9]+$
  23644. type: string
  23645. name:
  23646. description: The name of the Secret resource being referred to.
  23647. maxLength: 253
  23648. minLength: 1
  23649. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23650. type: string
  23651. namespace:
  23652. description: |-
  23653. The namespace of the Secret resource being referred to.
  23654. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23655. maxLength: 63
  23656. minLength: 1
  23657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23658. type: string
  23659. type: object
  23660. required:
  23661. - accessKeyIDSecretRef
  23662. - accessKeySecretSecretRef
  23663. type: object
  23664. type: object
  23665. projectID:
  23666. description: ProjectID is the project, which the secrets are stored in.
  23667. type: string
  23668. required:
  23669. - auth
  23670. type: object
  23671. conjur:
  23672. description: Conjur configures this store to sync secrets using conjur provider
  23673. properties:
  23674. auth:
  23675. description: Defines authentication settings for connecting to Conjur.
  23676. properties:
  23677. apikey:
  23678. description: Authenticates with Conjur using an API key.
  23679. properties:
  23680. account:
  23681. description: Account is the Conjur organization account name.
  23682. type: string
  23683. apiKeyRef:
  23684. description: |-
  23685. A reference to a specific 'key' containing the Conjur API key
  23686. within a Secret resource. In some instances, `key` is a required field.
  23687. properties:
  23688. key:
  23689. description: |-
  23690. A key in the referenced Secret.
  23691. Some instances of this field may be defaulted, in others it may be required.
  23692. maxLength: 253
  23693. minLength: 1
  23694. pattern: ^[-._a-zA-Z0-9]+$
  23695. type: string
  23696. name:
  23697. description: The name of the Secret resource being referred to.
  23698. maxLength: 253
  23699. minLength: 1
  23700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23701. type: string
  23702. namespace:
  23703. description: |-
  23704. The namespace of the Secret resource being referred to.
  23705. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23706. maxLength: 63
  23707. minLength: 1
  23708. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23709. type: string
  23710. type: object
  23711. userRef:
  23712. description: |-
  23713. A reference to a specific 'key' containing the Conjur username
  23714. within a Secret resource. In some instances, `key` is a required field.
  23715. properties:
  23716. key:
  23717. description: |-
  23718. A key in the referenced Secret.
  23719. Some instances of this field may be defaulted, in others it may be required.
  23720. maxLength: 253
  23721. minLength: 1
  23722. pattern: ^[-._a-zA-Z0-9]+$
  23723. type: string
  23724. name:
  23725. description: The name of the Secret resource being referred to.
  23726. maxLength: 253
  23727. minLength: 1
  23728. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23729. type: string
  23730. namespace:
  23731. description: |-
  23732. The namespace of the Secret resource being referred to.
  23733. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23734. maxLength: 63
  23735. minLength: 1
  23736. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23737. type: string
  23738. type: object
  23739. required:
  23740. - account
  23741. - apiKeyRef
  23742. - userRef
  23743. type: object
  23744. jwt:
  23745. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  23746. properties:
  23747. account:
  23748. description: Account is the Conjur organization account name.
  23749. type: string
  23750. hostId:
  23751. description: |-
  23752. Optional HostID for JWT authentication. This may be used depending
  23753. on how the Conjur JWT authenticator policy is configured.
  23754. type: string
  23755. secretRef:
  23756. description: |-
  23757. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  23758. authenticate with Conjur using the JWT authentication method.
  23759. properties:
  23760. key:
  23761. description: |-
  23762. A key in the referenced Secret.
  23763. Some instances of this field may be defaulted, in others it may be required.
  23764. maxLength: 253
  23765. minLength: 1
  23766. pattern: ^[-._a-zA-Z0-9]+$
  23767. type: string
  23768. name:
  23769. description: The name of the Secret resource being referred to.
  23770. maxLength: 253
  23771. minLength: 1
  23772. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23773. type: string
  23774. namespace:
  23775. description: |-
  23776. The namespace of the Secret resource being referred to.
  23777. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23778. maxLength: 63
  23779. minLength: 1
  23780. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23781. type: string
  23782. type: object
  23783. serviceAccountRef:
  23784. description: |-
  23785. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  23786. a token for with the `TokenRequest` API.
  23787. properties:
  23788. audiences:
  23789. description: |-
  23790. Audience specifies the `aud` claim for the service account token
  23791. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  23792. then this audiences will be appended to the list
  23793. items:
  23794. type: string
  23795. type: array
  23796. name:
  23797. description: The name of the ServiceAccount resource being referred to.
  23798. maxLength: 253
  23799. minLength: 1
  23800. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23801. type: string
  23802. namespace:
  23803. description: |-
  23804. Namespace of the resource being referred to.
  23805. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23806. maxLength: 63
  23807. minLength: 1
  23808. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23809. type: string
  23810. required:
  23811. - name
  23812. type: object
  23813. serviceID:
  23814. description: The conjur authn jwt webservice id
  23815. type: string
  23816. required:
  23817. - account
  23818. - serviceID
  23819. type: object
  23820. type: object
  23821. caBundle:
  23822. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  23823. type: string
  23824. caProvider:
  23825. description: |-
  23826. Used to provide custom certificate authority (CA) certificates
  23827. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  23828. that contains a PEM-encoded certificate.
  23829. properties:
  23830. key:
  23831. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23832. maxLength: 253
  23833. minLength: 1
  23834. pattern: ^[-._a-zA-Z0-9]+$
  23835. type: string
  23836. name:
  23837. description: The name of the object located at the provider type.
  23838. maxLength: 253
  23839. minLength: 1
  23840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23841. type: string
  23842. namespace:
  23843. description: |-
  23844. The namespace the Provider type is in.
  23845. Can only be defined when used in a ClusterSecretStore.
  23846. maxLength: 63
  23847. minLength: 1
  23848. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23849. type: string
  23850. type:
  23851. description: The type of provider to use such as "Secret", or "ConfigMap".
  23852. enum:
  23853. - Secret
  23854. - ConfigMap
  23855. type: string
  23856. required:
  23857. - name
  23858. - type
  23859. type: object
  23860. url:
  23861. description: URL is the endpoint of the Conjur instance.
  23862. type: string
  23863. required:
  23864. - auth
  23865. - url
  23866. type: object
  23867. delinea:
  23868. description: |-
  23869. Delinea DevOps Secrets Vault
  23870. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  23871. properties:
  23872. clientId:
  23873. description: ClientID is the non-secret part of the credential.
  23874. properties:
  23875. secretRef:
  23876. description: SecretRef references a key in a secret that will be used as value.
  23877. properties:
  23878. key:
  23879. description: |-
  23880. A key in the referenced Secret.
  23881. Some instances of this field may be defaulted, in others it may be required.
  23882. maxLength: 253
  23883. minLength: 1
  23884. pattern: ^[-._a-zA-Z0-9]+$
  23885. type: string
  23886. name:
  23887. description: The name of the Secret resource being referred to.
  23888. maxLength: 253
  23889. minLength: 1
  23890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23891. type: string
  23892. namespace:
  23893. description: |-
  23894. The namespace of the Secret resource being referred to.
  23895. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23896. maxLength: 63
  23897. minLength: 1
  23898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23899. type: string
  23900. type: object
  23901. value:
  23902. description: Value can be specified directly to set a value without using a secret.
  23903. type: string
  23904. type: object
  23905. clientSecret:
  23906. description: ClientSecret is the secret part of the credential.
  23907. properties:
  23908. secretRef:
  23909. description: SecretRef references a key in a secret that will be used as value.
  23910. properties:
  23911. key:
  23912. description: |-
  23913. A key in the referenced Secret.
  23914. Some instances of this field may be defaulted, in others it may be required.
  23915. maxLength: 253
  23916. minLength: 1
  23917. pattern: ^[-._a-zA-Z0-9]+$
  23918. type: string
  23919. name:
  23920. description: The name of the Secret resource being referred to.
  23921. maxLength: 253
  23922. minLength: 1
  23923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23924. type: string
  23925. namespace:
  23926. description: |-
  23927. The namespace of the Secret resource being referred to.
  23928. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23929. maxLength: 63
  23930. minLength: 1
  23931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23932. type: string
  23933. type: object
  23934. value:
  23935. description: Value can be specified directly to set a value without using a secret.
  23936. type: string
  23937. type: object
  23938. tenant:
  23939. description: Tenant is the chosen hostname / site name.
  23940. type: string
  23941. tld:
  23942. description: |-
  23943. TLD is based on the server location that was chosen during provisioning.
  23944. If unset, defaults to "com".
  23945. type: string
  23946. urlTemplate:
  23947. description: |-
  23948. URLTemplate
  23949. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  23950. type: string
  23951. required:
  23952. - clientId
  23953. - clientSecret
  23954. - tenant
  23955. type: object
  23956. device42:
  23957. description: Device42 configures this store to sync secrets using the Device42 provider
  23958. properties:
  23959. auth:
  23960. description: Auth configures how secret-manager authenticates with a Device42 instance.
  23961. properties:
  23962. secretRef:
  23963. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  23964. properties:
  23965. credentials:
  23966. description: Username / Password is used for authentication.
  23967. properties:
  23968. key:
  23969. description: |-
  23970. A key in the referenced Secret.
  23971. Some instances of this field may be defaulted, in others it may be required.
  23972. maxLength: 253
  23973. minLength: 1
  23974. pattern: ^[-._a-zA-Z0-9]+$
  23975. type: string
  23976. name:
  23977. description: The name of the Secret resource being referred to.
  23978. maxLength: 253
  23979. minLength: 1
  23980. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23981. type: string
  23982. namespace:
  23983. description: |-
  23984. The namespace of the Secret resource being referred to.
  23985. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23986. maxLength: 63
  23987. minLength: 1
  23988. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23989. type: string
  23990. type: object
  23991. type: object
  23992. required:
  23993. - secretRef
  23994. type: object
  23995. host:
  23996. description: URL configures the Device42 instance URL.
  23997. type: string
  23998. required:
  23999. - auth
  24000. - host
  24001. type: object
  24002. doppler:
  24003. description: Doppler configures this store to sync secrets using the Doppler provider
  24004. properties:
  24005. auth:
  24006. description: Auth configures how the Operator authenticates with the Doppler API
  24007. properties:
  24008. secretRef:
  24009. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  24010. properties:
  24011. dopplerToken:
  24012. description: |-
  24013. The DopplerToken is used for authentication.
  24014. See https://docs.doppler.com/reference/api#authentication for auth token types.
  24015. The Key attribute defaults to dopplerToken if not specified.
  24016. properties:
  24017. key:
  24018. description: |-
  24019. A key in the referenced Secret.
  24020. Some instances of this field may be defaulted, in others it may be required.
  24021. maxLength: 253
  24022. minLength: 1
  24023. pattern: ^[-._a-zA-Z0-9]+$
  24024. type: string
  24025. name:
  24026. description: The name of the Secret resource being referred to.
  24027. maxLength: 253
  24028. minLength: 1
  24029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24030. type: string
  24031. namespace:
  24032. description: |-
  24033. The namespace of the Secret resource being referred to.
  24034. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24035. maxLength: 63
  24036. minLength: 1
  24037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24038. type: string
  24039. type: object
  24040. required:
  24041. - dopplerToken
  24042. type: object
  24043. required:
  24044. - secretRef
  24045. type: object
  24046. config:
  24047. description: Doppler config (required if not using a Service Token)
  24048. type: string
  24049. format:
  24050. description: Format enables the downloading of secrets as a file (string)
  24051. enum:
  24052. - json
  24053. - dotnet-json
  24054. - env
  24055. - yaml
  24056. - docker
  24057. type: string
  24058. nameTransformer:
  24059. description: Environment variable compatible name transforms that change secret names to a different format
  24060. enum:
  24061. - upper-camel
  24062. - camel
  24063. - lower-snake
  24064. - tf-var
  24065. - dotnet-env
  24066. - lower-kebab
  24067. type: string
  24068. project:
  24069. description: Doppler project (required if not using a Service Token)
  24070. type: string
  24071. required:
  24072. - auth
  24073. type: object
  24074. fake:
  24075. description: Fake configures a store with static key/value pairs
  24076. properties:
  24077. data:
  24078. items:
  24079. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  24080. properties:
  24081. key:
  24082. type: string
  24083. value:
  24084. type: string
  24085. version:
  24086. type: string
  24087. required:
  24088. - key
  24089. - value
  24090. type: object
  24091. type: array
  24092. required:
  24093. - data
  24094. type: object
  24095. fortanix:
  24096. description: Fortanix configures this store to sync secrets using the Fortanix provider
  24097. properties:
  24098. apiKey:
  24099. description: APIKey is the API token to access SDKMS Applications.
  24100. properties:
  24101. secretRef:
  24102. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  24103. properties:
  24104. key:
  24105. description: |-
  24106. A key in the referenced Secret.
  24107. Some instances of this field may be defaulted, in others it may be required.
  24108. maxLength: 253
  24109. minLength: 1
  24110. pattern: ^[-._a-zA-Z0-9]+$
  24111. type: string
  24112. name:
  24113. description: The name of the Secret resource being referred to.
  24114. maxLength: 253
  24115. minLength: 1
  24116. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24117. type: string
  24118. namespace:
  24119. description: |-
  24120. The namespace of the Secret resource being referred to.
  24121. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24122. maxLength: 63
  24123. minLength: 1
  24124. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24125. type: string
  24126. type: object
  24127. type: object
  24128. apiUrl:
  24129. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  24130. type: string
  24131. type: object
  24132. gcpsm:
  24133. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  24134. properties:
  24135. auth:
  24136. description: Auth defines the information necessary to authenticate against GCP
  24137. properties:
  24138. secretRef:
  24139. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  24140. properties:
  24141. secretAccessKeySecretRef:
  24142. description: The SecretAccessKey is used for authentication
  24143. properties:
  24144. key:
  24145. description: |-
  24146. A key in the referenced Secret.
  24147. Some instances of this field may be defaulted, in others it may be required.
  24148. maxLength: 253
  24149. minLength: 1
  24150. pattern: ^[-._a-zA-Z0-9]+$
  24151. type: string
  24152. name:
  24153. description: The name of the Secret resource being referred to.
  24154. maxLength: 253
  24155. minLength: 1
  24156. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24157. type: string
  24158. namespace:
  24159. description: |-
  24160. The namespace of the Secret resource being referred to.
  24161. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24162. maxLength: 63
  24163. minLength: 1
  24164. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24165. type: string
  24166. type: object
  24167. type: object
  24168. workloadIdentity:
  24169. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  24170. properties:
  24171. clusterLocation:
  24172. description: |-
  24173. ClusterLocation is the location of the cluster
  24174. If not specified, it fetches information from the metadata server
  24175. type: string
  24176. clusterName:
  24177. description: |-
  24178. ClusterName is the name of the cluster
  24179. If not specified, it fetches information from the metadata server
  24180. type: string
  24181. clusterProjectID:
  24182. description: |-
  24183. ClusterProjectID is the project ID of the cluster
  24184. If not specified, it fetches information from the metadata server
  24185. type: string
  24186. serviceAccountRef:
  24187. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  24188. properties:
  24189. audiences:
  24190. description: |-
  24191. Audience specifies the `aud` claim for the service account token
  24192. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  24193. then this audiences will be appended to the list
  24194. items:
  24195. type: string
  24196. type: array
  24197. name:
  24198. description: The name of the ServiceAccount resource being referred to.
  24199. maxLength: 253
  24200. minLength: 1
  24201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24202. type: string
  24203. namespace:
  24204. description: |-
  24205. Namespace of the resource being referred to.
  24206. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24207. maxLength: 63
  24208. minLength: 1
  24209. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24210. type: string
  24211. required:
  24212. - name
  24213. type: object
  24214. required:
  24215. - serviceAccountRef
  24216. type: object
  24217. type: object
  24218. location:
  24219. description: Location optionally defines a location for a secret
  24220. type: string
  24221. projectID:
  24222. description: ProjectID project where secret is located
  24223. type: string
  24224. type: object
  24225. github:
  24226. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  24227. properties:
  24228. appID:
  24229. description: appID specifies the Github APP that will be used to authenticate the client
  24230. format: int64
  24231. type: integer
  24232. auth:
  24233. description: auth configures how secret-manager authenticates with a Github instance.
  24234. properties:
  24235. privateKey:
  24236. description: |-
  24237. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24238. In some instances, `key` is a required field.
  24239. properties:
  24240. key:
  24241. description: |-
  24242. A key in the referenced Secret.
  24243. Some instances of this field may be defaulted, in others it may be required.
  24244. maxLength: 253
  24245. minLength: 1
  24246. pattern: ^[-._a-zA-Z0-9]+$
  24247. type: string
  24248. name:
  24249. description: The name of the Secret resource being referred to.
  24250. maxLength: 253
  24251. minLength: 1
  24252. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24253. type: string
  24254. namespace:
  24255. description: |-
  24256. The namespace of the Secret resource being referred to.
  24257. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24258. maxLength: 63
  24259. minLength: 1
  24260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24261. type: string
  24262. type: object
  24263. required:
  24264. - privateKey
  24265. type: object
  24266. environment:
  24267. description: environment will be used to fetch secrets from a particular environment within a github repository
  24268. type: string
  24269. installationID:
  24270. description: installationID specifies the Github APP installation that will be used to authenticate the client
  24271. format: int64
  24272. type: integer
  24273. organization:
  24274. description: organization will be used to fetch secrets from the Github organization
  24275. type: string
  24276. repository:
  24277. description: repository will be used to fetch secrets from the Github repository within an organization
  24278. type: string
  24279. uploadURL:
  24280. description: Upload URL for enterprise instances. Default to URL.
  24281. type: string
  24282. url:
  24283. default: https://github.com/
  24284. description: URL configures the Github instance URL. Defaults to https://github.com/.
  24285. type: string
  24286. required:
  24287. - appID
  24288. - auth
  24289. - installationID
  24290. - organization
  24291. type: object
  24292. gitlab:
  24293. description: GitLab configures this store to sync secrets using GitLab Variables provider
  24294. properties:
  24295. auth:
  24296. description: Auth configures how secret-manager authenticates with a GitLab instance.
  24297. properties:
  24298. SecretRef:
  24299. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  24300. properties:
  24301. accessToken:
  24302. description: AccessToken is used for authentication.
  24303. properties:
  24304. key:
  24305. description: |-
  24306. A key in the referenced Secret.
  24307. Some instances of this field may be defaulted, in others it may be required.
  24308. maxLength: 253
  24309. minLength: 1
  24310. pattern: ^[-._a-zA-Z0-9]+$
  24311. type: string
  24312. name:
  24313. description: The name of the Secret resource being referred to.
  24314. maxLength: 253
  24315. minLength: 1
  24316. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24317. type: string
  24318. namespace:
  24319. description: |-
  24320. The namespace of the Secret resource being referred to.
  24321. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24322. maxLength: 63
  24323. minLength: 1
  24324. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24325. type: string
  24326. type: object
  24327. type: object
  24328. required:
  24329. - SecretRef
  24330. type: object
  24331. caBundle:
  24332. description: |-
  24333. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  24334. can be performed.
  24335. format: byte
  24336. type: string
  24337. caProvider:
  24338. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  24339. properties:
  24340. key:
  24341. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24342. maxLength: 253
  24343. minLength: 1
  24344. pattern: ^[-._a-zA-Z0-9]+$
  24345. type: string
  24346. name:
  24347. description: The name of the object located at the provider type.
  24348. maxLength: 253
  24349. minLength: 1
  24350. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24351. type: string
  24352. namespace:
  24353. description: |-
  24354. The namespace the Provider type is in.
  24355. Can only be defined when used in a ClusterSecretStore.
  24356. maxLength: 63
  24357. minLength: 1
  24358. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24359. type: string
  24360. type:
  24361. description: The type of provider to use such as "Secret", or "ConfigMap".
  24362. enum:
  24363. - Secret
  24364. - ConfigMap
  24365. type: string
  24366. required:
  24367. - name
  24368. - type
  24369. type: object
  24370. environment:
  24371. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  24372. type: string
  24373. groupIDs:
  24374. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  24375. items:
  24376. type: string
  24377. type: array
  24378. inheritFromGroups:
  24379. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  24380. type: boolean
  24381. projectID:
  24382. description: ProjectID specifies a project where secrets are located.
  24383. type: string
  24384. url:
  24385. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  24386. type: string
  24387. required:
  24388. - auth
  24389. type: object
  24390. ibm:
  24391. description: IBM configures this store to sync secrets using IBM Cloud provider
  24392. properties:
  24393. auth:
  24394. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  24395. maxProperties: 1
  24396. minProperties: 1
  24397. properties:
  24398. containerAuth:
  24399. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  24400. properties:
  24401. iamEndpoint:
  24402. type: string
  24403. profile:
  24404. description: the IBM Trusted Profile
  24405. type: string
  24406. tokenLocation:
  24407. description: Location the token is mounted on the pod
  24408. type: string
  24409. required:
  24410. - profile
  24411. type: object
  24412. secretRef:
  24413. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  24414. properties:
  24415. secretApiKeySecretRef:
  24416. description: The SecretAccessKey is used for authentication
  24417. properties:
  24418. key:
  24419. description: |-
  24420. A key in the referenced Secret.
  24421. Some instances of this field may be defaulted, in others it may be required.
  24422. maxLength: 253
  24423. minLength: 1
  24424. pattern: ^[-._a-zA-Z0-9]+$
  24425. type: string
  24426. name:
  24427. description: The name of the Secret resource being referred to.
  24428. maxLength: 253
  24429. minLength: 1
  24430. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24431. type: string
  24432. namespace:
  24433. description: |-
  24434. The namespace of the Secret resource being referred to.
  24435. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24436. maxLength: 63
  24437. minLength: 1
  24438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24439. type: string
  24440. type: object
  24441. type: object
  24442. type: object
  24443. serviceUrl:
  24444. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  24445. type: string
  24446. required:
  24447. - auth
  24448. type: object
  24449. infisical:
  24450. description: Infisical configures this store to sync secrets using the Infisical provider
  24451. properties:
  24452. auth:
  24453. description: Auth configures how the Operator authenticates with the Infisical API
  24454. properties:
  24455. universalAuthCredentials:
  24456. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  24457. properties:
  24458. clientId:
  24459. description: |-
  24460. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24461. In some instances, `key` is a required field.
  24462. properties:
  24463. key:
  24464. description: |-
  24465. A key in the referenced Secret.
  24466. Some instances of this field may be defaulted, in others it may be required.
  24467. maxLength: 253
  24468. minLength: 1
  24469. pattern: ^[-._a-zA-Z0-9]+$
  24470. type: string
  24471. name:
  24472. description: The name of the Secret resource being referred to.
  24473. maxLength: 253
  24474. minLength: 1
  24475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24476. type: string
  24477. namespace:
  24478. description: |-
  24479. The namespace of the Secret resource being referred to.
  24480. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24481. maxLength: 63
  24482. minLength: 1
  24483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24484. type: string
  24485. type: object
  24486. clientSecret:
  24487. description: |-
  24488. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24489. In some instances, `key` is a required field.
  24490. properties:
  24491. key:
  24492. description: |-
  24493. A key in the referenced Secret.
  24494. Some instances of this field may be defaulted, in others it may be required.
  24495. maxLength: 253
  24496. minLength: 1
  24497. pattern: ^[-._a-zA-Z0-9]+$
  24498. type: string
  24499. name:
  24500. description: The name of the Secret resource being referred to.
  24501. maxLength: 253
  24502. minLength: 1
  24503. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24504. type: string
  24505. namespace:
  24506. description: |-
  24507. The namespace of the Secret resource being referred to.
  24508. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24509. maxLength: 63
  24510. minLength: 1
  24511. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24512. type: string
  24513. type: object
  24514. required:
  24515. - clientId
  24516. - clientSecret
  24517. type: object
  24518. type: object
  24519. hostAPI:
  24520. default: https://app.infisical.com/api
  24521. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  24522. type: string
  24523. secretsScope:
  24524. description: SecretsScope defines the scope of the secrets within the workspace
  24525. properties:
  24526. environmentSlug:
  24527. description: EnvironmentSlug is the required slug identifier for the environment.
  24528. type: string
  24529. expandSecretReferences:
  24530. default: true
  24531. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  24532. type: boolean
  24533. projectSlug:
  24534. description: ProjectSlug is the required slug identifier for the project.
  24535. type: string
  24536. recursive:
  24537. default: false
  24538. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  24539. type: boolean
  24540. secretsPath:
  24541. default: /
  24542. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  24543. type: string
  24544. required:
  24545. - environmentSlug
  24546. - projectSlug
  24547. type: object
  24548. required:
  24549. - auth
  24550. - secretsScope
  24551. type: object
  24552. keepersecurity:
  24553. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  24554. properties:
  24555. authRef:
  24556. description: |-
  24557. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24558. In some instances, `key` is a required field.
  24559. properties:
  24560. key:
  24561. description: |-
  24562. A key in the referenced Secret.
  24563. Some instances of this field may be defaulted, in others it may be required.
  24564. maxLength: 253
  24565. minLength: 1
  24566. pattern: ^[-._a-zA-Z0-9]+$
  24567. type: string
  24568. name:
  24569. description: The name of the Secret resource being referred to.
  24570. maxLength: 253
  24571. minLength: 1
  24572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24573. type: string
  24574. namespace:
  24575. description: |-
  24576. The namespace of the Secret resource being referred to.
  24577. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24578. maxLength: 63
  24579. minLength: 1
  24580. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24581. type: string
  24582. type: object
  24583. folderID:
  24584. type: string
  24585. required:
  24586. - authRef
  24587. - folderID
  24588. type: object
  24589. kubernetes:
  24590. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  24591. properties:
  24592. auth:
  24593. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  24594. maxProperties: 1
  24595. minProperties: 1
  24596. properties:
  24597. cert:
  24598. description: has both clientCert and clientKey as secretKeySelector
  24599. properties:
  24600. clientCert:
  24601. description: |-
  24602. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24603. In some instances, `key` is a required field.
  24604. properties:
  24605. key:
  24606. description: |-
  24607. A key in the referenced Secret.
  24608. Some instances of this field may be defaulted, in others it may be required.
  24609. maxLength: 253
  24610. minLength: 1
  24611. pattern: ^[-._a-zA-Z0-9]+$
  24612. type: string
  24613. name:
  24614. description: The name of the Secret resource being referred to.
  24615. maxLength: 253
  24616. minLength: 1
  24617. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24618. type: string
  24619. namespace:
  24620. description: |-
  24621. The namespace of the Secret resource being referred to.
  24622. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24623. maxLength: 63
  24624. minLength: 1
  24625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24626. type: string
  24627. type: object
  24628. clientKey:
  24629. description: |-
  24630. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24631. In some instances, `key` is a required field.
  24632. properties:
  24633. key:
  24634. description: |-
  24635. A key in the referenced Secret.
  24636. Some instances of this field may be defaulted, in others it may be required.
  24637. maxLength: 253
  24638. minLength: 1
  24639. pattern: ^[-._a-zA-Z0-9]+$
  24640. type: string
  24641. name:
  24642. description: The name of the Secret resource being referred to.
  24643. maxLength: 253
  24644. minLength: 1
  24645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24646. type: string
  24647. namespace:
  24648. description: |-
  24649. The namespace of the Secret resource being referred to.
  24650. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24651. maxLength: 63
  24652. minLength: 1
  24653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24654. type: string
  24655. type: object
  24656. type: object
  24657. serviceAccount:
  24658. description: points to a service account that should be used for authentication
  24659. properties:
  24660. audiences:
  24661. description: |-
  24662. Audience specifies the `aud` claim for the service account token
  24663. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  24664. then this audiences will be appended to the list
  24665. items:
  24666. type: string
  24667. type: array
  24668. name:
  24669. description: The name of the ServiceAccount resource being referred to.
  24670. maxLength: 253
  24671. minLength: 1
  24672. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24673. type: string
  24674. namespace:
  24675. description: |-
  24676. Namespace of the resource being referred to.
  24677. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24678. maxLength: 63
  24679. minLength: 1
  24680. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24681. type: string
  24682. required:
  24683. - name
  24684. type: object
  24685. token:
  24686. description: use static token to authenticate with
  24687. properties:
  24688. bearerToken:
  24689. description: |-
  24690. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24691. In some instances, `key` is a required field.
  24692. properties:
  24693. key:
  24694. description: |-
  24695. A key in the referenced Secret.
  24696. Some instances of this field may be defaulted, in others it may be required.
  24697. maxLength: 253
  24698. minLength: 1
  24699. pattern: ^[-._a-zA-Z0-9]+$
  24700. type: string
  24701. name:
  24702. description: The name of the Secret resource being referred to.
  24703. maxLength: 253
  24704. minLength: 1
  24705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24706. type: string
  24707. namespace:
  24708. description: |-
  24709. The namespace of the Secret resource being referred to.
  24710. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24711. maxLength: 63
  24712. minLength: 1
  24713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24714. type: string
  24715. type: object
  24716. type: object
  24717. type: object
  24718. authRef:
  24719. description: A reference to a secret that contains the auth information.
  24720. properties:
  24721. key:
  24722. description: |-
  24723. A key in the referenced Secret.
  24724. Some instances of this field may be defaulted, in others it may be required.
  24725. maxLength: 253
  24726. minLength: 1
  24727. pattern: ^[-._a-zA-Z0-9]+$
  24728. type: string
  24729. name:
  24730. description: The name of the Secret resource being referred to.
  24731. maxLength: 253
  24732. minLength: 1
  24733. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24734. type: string
  24735. namespace:
  24736. description: |-
  24737. The namespace of the Secret resource being referred to.
  24738. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24739. maxLength: 63
  24740. minLength: 1
  24741. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24742. type: string
  24743. type: object
  24744. remoteNamespace:
  24745. default: default
  24746. description: Remote namespace to fetch the secrets from
  24747. maxLength: 63
  24748. minLength: 1
  24749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24750. type: string
  24751. server:
  24752. description: configures the Kubernetes server Address.
  24753. properties:
  24754. caBundle:
  24755. description: CABundle is a base64-encoded CA certificate
  24756. format: byte
  24757. type: string
  24758. caProvider:
  24759. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  24760. properties:
  24761. key:
  24762. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24763. maxLength: 253
  24764. minLength: 1
  24765. pattern: ^[-._a-zA-Z0-9]+$
  24766. type: string
  24767. name:
  24768. description: The name of the object located at the provider type.
  24769. maxLength: 253
  24770. minLength: 1
  24771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24772. type: string
  24773. namespace:
  24774. description: |-
  24775. The namespace the Provider type is in.
  24776. Can only be defined when used in a ClusterSecretStore.
  24777. maxLength: 63
  24778. minLength: 1
  24779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24780. type: string
  24781. type:
  24782. description: The type of provider to use such as "Secret", or "ConfigMap".
  24783. enum:
  24784. - Secret
  24785. - ConfigMap
  24786. type: string
  24787. required:
  24788. - name
  24789. - type
  24790. type: object
  24791. url:
  24792. default: kubernetes.default
  24793. description: configures the Kubernetes server Address.
  24794. type: string
  24795. type: object
  24796. type: object
  24797. onboardbase:
  24798. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  24799. properties:
  24800. apiHost:
  24801. default: https://public.onboardbase.com/api/v1/
  24802. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  24803. type: string
  24804. auth:
  24805. description: Auth configures how the Operator authenticates with the Onboardbase API
  24806. properties:
  24807. apiKeyRef:
  24808. description: |-
  24809. OnboardbaseAPIKey is the APIKey generated by an admin account.
  24810. It is used to recognize and authorize access to a project and environment within onboardbase
  24811. properties:
  24812. key:
  24813. description: |-
  24814. A key in the referenced Secret.
  24815. Some instances of this field may be defaulted, in others it may be required.
  24816. maxLength: 253
  24817. minLength: 1
  24818. pattern: ^[-._a-zA-Z0-9]+$
  24819. type: string
  24820. name:
  24821. description: The name of the Secret resource being referred to.
  24822. maxLength: 253
  24823. minLength: 1
  24824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24825. type: string
  24826. namespace:
  24827. description: |-
  24828. The namespace of the Secret resource being referred to.
  24829. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24830. maxLength: 63
  24831. minLength: 1
  24832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24833. type: string
  24834. type: object
  24835. passcodeRef:
  24836. description: OnboardbasePasscode is the passcode attached to the API Key
  24837. properties:
  24838. key:
  24839. description: |-
  24840. A key in the referenced Secret.
  24841. Some instances of this field may be defaulted, in others it may be required.
  24842. maxLength: 253
  24843. minLength: 1
  24844. pattern: ^[-._a-zA-Z0-9]+$
  24845. type: string
  24846. name:
  24847. description: The name of the Secret resource being referred to.
  24848. maxLength: 253
  24849. minLength: 1
  24850. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24851. type: string
  24852. namespace:
  24853. description: |-
  24854. The namespace of the Secret resource being referred to.
  24855. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24856. maxLength: 63
  24857. minLength: 1
  24858. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24859. type: string
  24860. type: object
  24861. required:
  24862. - apiKeyRef
  24863. - passcodeRef
  24864. type: object
  24865. environment:
  24866. default: development
  24867. description: Environment is the name of an environmnent within a project to pull the secrets from
  24868. type: string
  24869. project:
  24870. default: development
  24871. description: Project is an onboardbase project that the secrets should be pulled from
  24872. type: string
  24873. required:
  24874. - apiHost
  24875. - auth
  24876. - environment
  24877. - project
  24878. type: object
  24879. onepassword:
  24880. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  24881. properties:
  24882. auth:
  24883. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  24884. properties:
  24885. secretRef:
  24886. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  24887. properties:
  24888. connectTokenSecretRef:
  24889. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  24890. properties:
  24891. key:
  24892. description: |-
  24893. A key in the referenced Secret.
  24894. Some instances of this field may be defaulted, in others it may be required.
  24895. maxLength: 253
  24896. minLength: 1
  24897. pattern: ^[-._a-zA-Z0-9]+$
  24898. type: string
  24899. name:
  24900. description: The name of the Secret resource being referred to.
  24901. maxLength: 253
  24902. minLength: 1
  24903. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24904. type: string
  24905. namespace:
  24906. description: |-
  24907. The namespace of the Secret resource being referred to.
  24908. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24909. maxLength: 63
  24910. minLength: 1
  24911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24912. type: string
  24913. type: object
  24914. required:
  24915. - connectTokenSecretRef
  24916. type: object
  24917. required:
  24918. - secretRef
  24919. type: object
  24920. connectHost:
  24921. description: ConnectHost defines the OnePassword Connect Server to connect to
  24922. type: string
  24923. vaults:
  24924. additionalProperties:
  24925. type: integer
  24926. description: Vaults defines which OnePassword vaults to search in which order
  24927. type: object
  24928. required:
  24929. - auth
  24930. - connectHost
  24931. - vaults
  24932. type: object
  24933. oracle:
  24934. description: Oracle configures this store to sync secrets using Oracle Vault provider
  24935. properties:
  24936. auth:
  24937. description: |-
  24938. Auth configures how secret-manager authenticates with the Oracle Vault.
  24939. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  24940. properties:
  24941. secretRef:
  24942. description: SecretRef to pass through sensitive information.
  24943. properties:
  24944. fingerprint:
  24945. description: Fingerprint is the fingerprint of the API private key.
  24946. properties:
  24947. key:
  24948. description: |-
  24949. A key in the referenced Secret.
  24950. Some instances of this field may be defaulted, in others it may be required.
  24951. maxLength: 253
  24952. minLength: 1
  24953. pattern: ^[-._a-zA-Z0-9]+$
  24954. type: string
  24955. name:
  24956. description: The name of the Secret resource being referred to.
  24957. maxLength: 253
  24958. minLength: 1
  24959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24960. type: string
  24961. namespace:
  24962. description: |-
  24963. The namespace of the Secret resource being referred to.
  24964. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24965. maxLength: 63
  24966. minLength: 1
  24967. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24968. type: string
  24969. type: object
  24970. privatekey:
  24971. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  24972. properties:
  24973. key:
  24974. description: |-
  24975. A key in the referenced Secret.
  24976. Some instances of this field may be defaulted, in others it may be required.
  24977. maxLength: 253
  24978. minLength: 1
  24979. pattern: ^[-._a-zA-Z0-9]+$
  24980. type: string
  24981. name:
  24982. description: The name of the Secret resource being referred to.
  24983. maxLength: 253
  24984. minLength: 1
  24985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24986. type: string
  24987. namespace:
  24988. description: |-
  24989. The namespace of the Secret resource being referred to.
  24990. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24991. maxLength: 63
  24992. minLength: 1
  24993. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24994. type: string
  24995. type: object
  24996. required:
  24997. - fingerprint
  24998. - privatekey
  24999. type: object
  25000. tenancy:
  25001. description: Tenancy is the tenancy OCID where user is located.
  25002. type: string
  25003. user:
  25004. description: User is an access OCID specific to the account.
  25005. type: string
  25006. required:
  25007. - secretRef
  25008. - tenancy
  25009. - user
  25010. type: object
  25011. compartment:
  25012. description: |-
  25013. Compartment is the vault compartment OCID.
  25014. Required for PushSecret
  25015. type: string
  25016. encryptionKey:
  25017. description: |-
  25018. EncryptionKey is the OCID of the encryption key within the vault.
  25019. Required for PushSecret
  25020. type: string
  25021. principalType:
  25022. description: |-
  25023. The type of principal to use for authentication. If left blank, the Auth struct will
  25024. determine the principal type. This optional field must be specified if using
  25025. workload identity.
  25026. enum:
  25027. - ""
  25028. - UserPrincipal
  25029. - InstancePrincipal
  25030. - Workload
  25031. type: string
  25032. region:
  25033. description: Region is the region where vault is located.
  25034. type: string
  25035. serviceAccountRef:
  25036. description: |-
  25037. ServiceAccountRef specified the service account
  25038. that should be used when authenticating with WorkloadIdentity.
  25039. properties:
  25040. audiences:
  25041. description: |-
  25042. Audience specifies the `aud` claim for the service account token
  25043. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25044. then this audiences will be appended to the list
  25045. items:
  25046. type: string
  25047. type: array
  25048. name:
  25049. description: The name of the ServiceAccount resource being referred to.
  25050. maxLength: 253
  25051. minLength: 1
  25052. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25053. type: string
  25054. namespace:
  25055. description: |-
  25056. Namespace of the resource being referred to.
  25057. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25058. maxLength: 63
  25059. minLength: 1
  25060. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25061. type: string
  25062. required:
  25063. - name
  25064. type: object
  25065. vault:
  25066. description: Vault is the vault's OCID of the specific vault where secret is located.
  25067. type: string
  25068. required:
  25069. - region
  25070. - vault
  25071. type: object
  25072. passbolt:
  25073. description: PassboltProvider defines configuration for the Passbolt provider.
  25074. properties:
  25075. auth:
  25076. description: Auth defines the information necessary to authenticate against Passbolt Server
  25077. properties:
  25078. passwordSecretRef:
  25079. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  25080. properties:
  25081. key:
  25082. description: |-
  25083. A key in the referenced Secret.
  25084. Some instances of this field may be defaulted, in others it may be required.
  25085. maxLength: 253
  25086. minLength: 1
  25087. pattern: ^[-._a-zA-Z0-9]+$
  25088. type: string
  25089. name:
  25090. description: The name of the Secret resource being referred to.
  25091. maxLength: 253
  25092. minLength: 1
  25093. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25094. type: string
  25095. namespace:
  25096. description: |-
  25097. The namespace of the Secret resource being referred to.
  25098. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25099. maxLength: 63
  25100. minLength: 1
  25101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25102. type: string
  25103. type: object
  25104. privateKeySecretRef:
  25105. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  25106. properties:
  25107. key:
  25108. description: |-
  25109. A key in the referenced Secret.
  25110. Some instances of this field may be defaulted, in others it may be required.
  25111. maxLength: 253
  25112. minLength: 1
  25113. pattern: ^[-._a-zA-Z0-9]+$
  25114. type: string
  25115. name:
  25116. description: The name of the Secret resource being referred to.
  25117. maxLength: 253
  25118. minLength: 1
  25119. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25120. type: string
  25121. namespace:
  25122. description: |-
  25123. The namespace of the Secret resource being referred to.
  25124. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25125. maxLength: 63
  25126. minLength: 1
  25127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25128. type: string
  25129. type: object
  25130. required:
  25131. - passwordSecretRef
  25132. - privateKeySecretRef
  25133. type: object
  25134. host:
  25135. description: Host defines the Passbolt Server to connect to
  25136. type: string
  25137. required:
  25138. - auth
  25139. - host
  25140. type: object
  25141. passworddepot:
  25142. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  25143. properties:
  25144. auth:
  25145. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  25146. properties:
  25147. secretRef:
  25148. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  25149. properties:
  25150. credentials:
  25151. description: Username / Password is used for authentication.
  25152. properties:
  25153. key:
  25154. description: |-
  25155. A key in the referenced Secret.
  25156. Some instances of this field may be defaulted, in others it may be required.
  25157. maxLength: 253
  25158. minLength: 1
  25159. pattern: ^[-._a-zA-Z0-9]+$
  25160. type: string
  25161. name:
  25162. description: The name of the Secret resource being referred to.
  25163. maxLength: 253
  25164. minLength: 1
  25165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25166. type: string
  25167. namespace:
  25168. description: |-
  25169. The namespace of the Secret resource being referred to.
  25170. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25171. maxLength: 63
  25172. minLength: 1
  25173. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25174. type: string
  25175. type: object
  25176. type: object
  25177. required:
  25178. - secretRef
  25179. type: object
  25180. database:
  25181. description: Database to use as source
  25182. type: string
  25183. host:
  25184. description: URL configures the Password Depot instance URL.
  25185. type: string
  25186. required:
  25187. - auth
  25188. - database
  25189. - host
  25190. type: object
  25191. previder:
  25192. description: Previder configures this store to sync secrets using the Previder provider
  25193. properties:
  25194. auth:
  25195. description: PreviderAuth contains a secretRef for credentials.
  25196. properties:
  25197. secretRef:
  25198. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  25199. properties:
  25200. accessToken:
  25201. description: The AccessToken is used for authentication
  25202. properties:
  25203. key:
  25204. description: |-
  25205. A key in the referenced Secret.
  25206. Some instances of this field may be defaulted, in others it may be required.
  25207. maxLength: 253
  25208. minLength: 1
  25209. pattern: ^[-._a-zA-Z0-9]+$
  25210. type: string
  25211. name:
  25212. description: The name of the Secret resource being referred to.
  25213. maxLength: 253
  25214. minLength: 1
  25215. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25216. type: string
  25217. namespace:
  25218. description: |-
  25219. The namespace of the Secret resource being referred to.
  25220. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25221. maxLength: 63
  25222. minLength: 1
  25223. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25224. type: string
  25225. type: object
  25226. required:
  25227. - accessToken
  25228. type: object
  25229. type: object
  25230. baseUri:
  25231. type: string
  25232. required:
  25233. - auth
  25234. type: object
  25235. pulumi:
  25236. description: Pulumi configures this store to sync secrets using the Pulumi provider
  25237. properties:
  25238. accessToken:
  25239. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  25240. properties:
  25241. secretRef:
  25242. description: SecretRef is a reference to a secret containing the Pulumi API token.
  25243. properties:
  25244. key:
  25245. description: |-
  25246. A key in the referenced Secret.
  25247. Some instances of this field may be defaulted, in others it may be required.
  25248. maxLength: 253
  25249. minLength: 1
  25250. pattern: ^[-._a-zA-Z0-9]+$
  25251. type: string
  25252. name:
  25253. description: The name of the Secret resource being referred to.
  25254. maxLength: 253
  25255. minLength: 1
  25256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25257. type: string
  25258. namespace:
  25259. description: |-
  25260. The namespace of the Secret resource being referred to.
  25261. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25262. maxLength: 63
  25263. minLength: 1
  25264. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25265. type: string
  25266. type: object
  25267. type: object
  25268. apiUrl:
  25269. default: https://api.pulumi.com/api/esc
  25270. description: APIURL is the URL of the Pulumi API.
  25271. type: string
  25272. environment:
  25273. description: |-
  25274. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  25275. dynamically retrieved values from supported providers including all major clouds,
  25276. and other Pulumi ESC environments.
  25277. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  25278. type: string
  25279. organization:
  25280. description: |-
  25281. Organization are a space to collaborate on shared projects and stacks.
  25282. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  25283. type: string
  25284. project:
  25285. description: Project is the name of the Pulumi ESC project the environment belongs to.
  25286. type: string
  25287. required:
  25288. - accessToken
  25289. - environment
  25290. - organization
  25291. - project
  25292. type: object
  25293. scaleway:
  25294. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  25295. properties:
  25296. accessKey:
  25297. description: AccessKey is the non-secret part of the api key.
  25298. properties:
  25299. secretRef:
  25300. description: SecretRef references a key in a secret that will be used as value.
  25301. properties:
  25302. key:
  25303. description: |-
  25304. A key in the referenced Secret.
  25305. Some instances of this field may be defaulted, in others it may be required.
  25306. maxLength: 253
  25307. minLength: 1
  25308. pattern: ^[-._a-zA-Z0-9]+$
  25309. type: string
  25310. name:
  25311. description: The name of the Secret resource being referred to.
  25312. maxLength: 253
  25313. minLength: 1
  25314. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25315. type: string
  25316. namespace:
  25317. description: |-
  25318. The namespace of the Secret resource being referred to.
  25319. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25320. maxLength: 63
  25321. minLength: 1
  25322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25323. type: string
  25324. type: object
  25325. value:
  25326. description: Value can be specified directly to set a value without using a secret.
  25327. type: string
  25328. type: object
  25329. apiUrl:
  25330. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  25331. type: string
  25332. projectId:
  25333. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  25334. type: string
  25335. region:
  25336. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  25337. type: string
  25338. secretKey:
  25339. description: SecretKey is the non-secret part of the api key.
  25340. properties:
  25341. secretRef:
  25342. description: SecretRef references a key in a secret that will be used as value.
  25343. properties:
  25344. key:
  25345. description: |-
  25346. A key in the referenced Secret.
  25347. Some instances of this field may be defaulted, in others it may be required.
  25348. maxLength: 253
  25349. minLength: 1
  25350. pattern: ^[-._a-zA-Z0-9]+$
  25351. type: string
  25352. name:
  25353. description: The name of the Secret resource being referred to.
  25354. maxLength: 253
  25355. minLength: 1
  25356. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25357. type: string
  25358. namespace:
  25359. description: |-
  25360. The namespace of the Secret resource being referred to.
  25361. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25362. maxLength: 63
  25363. minLength: 1
  25364. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25365. type: string
  25366. type: object
  25367. value:
  25368. description: Value can be specified directly to set a value without using a secret.
  25369. type: string
  25370. type: object
  25371. required:
  25372. - accessKey
  25373. - projectId
  25374. - region
  25375. - secretKey
  25376. type: object
  25377. secretserver:
  25378. description: |-
  25379. SecretServer configures this store to sync secrets using SecretServer provider
  25380. https://docs.delinea.com/online-help/secret-server/start.htm
  25381. properties:
  25382. password:
  25383. description: Password is the secret server account password.
  25384. properties:
  25385. secretRef:
  25386. description: SecretRef references a key in a secret that will be used as value.
  25387. properties:
  25388. key:
  25389. description: |-
  25390. A key in the referenced Secret.
  25391. Some instances of this field may be defaulted, in others it may be required.
  25392. maxLength: 253
  25393. minLength: 1
  25394. pattern: ^[-._a-zA-Z0-9]+$
  25395. type: string
  25396. name:
  25397. description: The name of the Secret resource being referred to.
  25398. maxLength: 253
  25399. minLength: 1
  25400. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25401. type: string
  25402. namespace:
  25403. description: |-
  25404. The namespace of the Secret resource being referred to.
  25405. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25406. maxLength: 63
  25407. minLength: 1
  25408. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25409. type: string
  25410. type: object
  25411. value:
  25412. description: Value can be specified directly to set a value without using a secret.
  25413. type: string
  25414. type: object
  25415. serverURL:
  25416. description: |-
  25417. ServerURL
  25418. URL to your secret server installation
  25419. type: string
  25420. username:
  25421. description: Username is the secret server account username.
  25422. properties:
  25423. secretRef:
  25424. description: SecretRef references a key in a secret that will be used as value.
  25425. properties:
  25426. key:
  25427. description: |-
  25428. A key in the referenced Secret.
  25429. Some instances of this field may be defaulted, in others it may be required.
  25430. maxLength: 253
  25431. minLength: 1
  25432. pattern: ^[-._a-zA-Z0-9]+$
  25433. type: string
  25434. name:
  25435. description: The name of the Secret resource being referred to.
  25436. maxLength: 253
  25437. minLength: 1
  25438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25439. type: string
  25440. namespace:
  25441. description: |-
  25442. The namespace of the Secret resource being referred to.
  25443. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25444. maxLength: 63
  25445. minLength: 1
  25446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25447. type: string
  25448. type: object
  25449. value:
  25450. description: Value can be specified directly to set a value without using a secret.
  25451. type: string
  25452. type: object
  25453. required:
  25454. - password
  25455. - serverURL
  25456. - username
  25457. type: object
  25458. senhasegura:
  25459. description: Senhasegura configures this store to sync secrets using senhasegura provider
  25460. properties:
  25461. auth:
  25462. description: Auth defines parameters to authenticate in senhasegura
  25463. properties:
  25464. clientId:
  25465. type: string
  25466. clientSecretSecretRef:
  25467. description: |-
  25468. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25469. In some instances, `key` is a required field.
  25470. properties:
  25471. key:
  25472. description: |-
  25473. A key in the referenced Secret.
  25474. Some instances of this field may be defaulted, in others it may be required.
  25475. maxLength: 253
  25476. minLength: 1
  25477. pattern: ^[-._a-zA-Z0-9]+$
  25478. type: string
  25479. name:
  25480. description: The name of the Secret resource being referred to.
  25481. maxLength: 253
  25482. minLength: 1
  25483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25484. type: string
  25485. namespace:
  25486. description: |-
  25487. The namespace of the Secret resource being referred to.
  25488. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25489. maxLength: 63
  25490. minLength: 1
  25491. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25492. type: string
  25493. type: object
  25494. required:
  25495. - clientId
  25496. - clientSecretSecretRef
  25497. type: object
  25498. ignoreSslCertificate:
  25499. default: false
  25500. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  25501. type: boolean
  25502. module:
  25503. description: Module defines which senhasegura module should be used to get secrets
  25504. type: string
  25505. url:
  25506. description: URL of senhasegura
  25507. type: string
  25508. required:
  25509. - auth
  25510. - module
  25511. - url
  25512. type: object
  25513. vault:
  25514. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  25515. properties:
  25516. auth:
  25517. description: Auth configures how secret-manager authenticates with the Vault server.
  25518. properties:
  25519. appRole:
  25520. description: |-
  25521. AppRole authenticates with Vault using the App Role auth mechanism,
  25522. with the role and secret stored in a Kubernetes Secret resource.
  25523. properties:
  25524. path:
  25525. default: approle
  25526. description: |-
  25527. Path where the App Role authentication backend is mounted
  25528. in Vault, e.g: "approle"
  25529. type: string
  25530. roleId:
  25531. description: |-
  25532. RoleID configured in the App Role authentication backend when setting
  25533. up the authentication backend in Vault.
  25534. type: string
  25535. roleRef:
  25536. description: |-
  25537. Reference to a key in a Secret that contains the App Role ID used
  25538. to authenticate with Vault.
  25539. The `key` field must be specified and denotes which entry within the Secret
  25540. resource is used as the app role id.
  25541. properties:
  25542. key:
  25543. description: |-
  25544. A key in the referenced Secret.
  25545. Some instances of this field may be defaulted, in others it may be required.
  25546. maxLength: 253
  25547. minLength: 1
  25548. pattern: ^[-._a-zA-Z0-9]+$
  25549. type: string
  25550. name:
  25551. description: The name of the Secret resource being referred to.
  25552. maxLength: 253
  25553. minLength: 1
  25554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25555. type: string
  25556. namespace:
  25557. description: |-
  25558. The namespace of the Secret resource being referred to.
  25559. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25560. maxLength: 63
  25561. minLength: 1
  25562. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25563. type: string
  25564. type: object
  25565. secretRef:
  25566. description: |-
  25567. Reference to a key in a Secret that contains the App Role secret used
  25568. to authenticate with Vault.
  25569. The `key` field must be specified and denotes which entry within the Secret
  25570. resource is used as the app role secret.
  25571. properties:
  25572. key:
  25573. description: |-
  25574. A key in the referenced Secret.
  25575. Some instances of this field may be defaulted, in others it may be required.
  25576. maxLength: 253
  25577. minLength: 1
  25578. pattern: ^[-._a-zA-Z0-9]+$
  25579. type: string
  25580. name:
  25581. description: The name of the Secret resource being referred to.
  25582. maxLength: 253
  25583. minLength: 1
  25584. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25585. type: string
  25586. namespace:
  25587. description: |-
  25588. The namespace of the Secret resource being referred to.
  25589. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25590. maxLength: 63
  25591. minLength: 1
  25592. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25593. type: string
  25594. type: object
  25595. required:
  25596. - path
  25597. - secretRef
  25598. type: object
  25599. cert:
  25600. description: |-
  25601. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  25602. Cert authentication method
  25603. properties:
  25604. clientCert:
  25605. description: |-
  25606. ClientCert is a certificate to authenticate using the Cert Vault
  25607. authentication method
  25608. properties:
  25609. key:
  25610. description: |-
  25611. A key in the referenced Secret.
  25612. Some instances of this field may be defaulted, in others it may be required.
  25613. maxLength: 253
  25614. minLength: 1
  25615. pattern: ^[-._a-zA-Z0-9]+$
  25616. type: string
  25617. name:
  25618. description: The name of the Secret resource being referred to.
  25619. maxLength: 253
  25620. minLength: 1
  25621. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25622. type: string
  25623. namespace:
  25624. description: |-
  25625. The namespace of the Secret resource being referred to.
  25626. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25627. maxLength: 63
  25628. minLength: 1
  25629. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25630. type: string
  25631. type: object
  25632. secretRef:
  25633. description: |-
  25634. SecretRef to a key in a Secret resource containing client private key to
  25635. authenticate with Vault using the Cert authentication method
  25636. properties:
  25637. key:
  25638. description: |-
  25639. A key in the referenced Secret.
  25640. Some instances of this field may be defaulted, in others it may be required.
  25641. maxLength: 253
  25642. minLength: 1
  25643. pattern: ^[-._a-zA-Z0-9]+$
  25644. type: string
  25645. name:
  25646. description: The name of the Secret resource being referred to.
  25647. maxLength: 253
  25648. minLength: 1
  25649. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25650. type: string
  25651. namespace:
  25652. description: |-
  25653. The namespace of the Secret resource being referred to.
  25654. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25655. maxLength: 63
  25656. minLength: 1
  25657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25658. type: string
  25659. type: object
  25660. type: object
  25661. iam:
  25662. description: |-
  25663. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  25664. AWS IAM authentication method
  25665. properties:
  25666. externalID:
  25667. description: AWS External ID set on assumed IAM roles
  25668. type: string
  25669. jwt:
  25670. description: Specify a service account with IRSA enabled
  25671. properties:
  25672. serviceAccountRef:
  25673. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  25674. properties:
  25675. audiences:
  25676. description: |-
  25677. Audience specifies the `aud` claim for the service account token
  25678. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25679. then this audiences will be appended to the list
  25680. items:
  25681. type: string
  25682. type: array
  25683. name:
  25684. description: The name of the ServiceAccount resource being referred to.
  25685. maxLength: 253
  25686. minLength: 1
  25687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25688. type: string
  25689. namespace:
  25690. description: |-
  25691. Namespace of the resource being referred to.
  25692. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25693. maxLength: 63
  25694. minLength: 1
  25695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25696. type: string
  25697. required:
  25698. - name
  25699. type: object
  25700. type: object
  25701. path:
  25702. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  25703. type: string
  25704. region:
  25705. description: AWS region
  25706. type: string
  25707. role:
  25708. description: This is the AWS role to be assumed before talking to vault
  25709. type: string
  25710. secretRef:
  25711. description: Specify credentials in a Secret object
  25712. properties:
  25713. accessKeyIDSecretRef:
  25714. description: The AccessKeyID is used for authentication
  25715. properties:
  25716. key:
  25717. description: |-
  25718. A key in the referenced Secret.
  25719. Some instances of this field may be defaulted, in others it may be required.
  25720. maxLength: 253
  25721. minLength: 1
  25722. pattern: ^[-._a-zA-Z0-9]+$
  25723. type: string
  25724. name:
  25725. description: The name of the Secret resource being referred to.
  25726. maxLength: 253
  25727. minLength: 1
  25728. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25729. type: string
  25730. namespace:
  25731. description: |-
  25732. The namespace of the Secret resource being referred to.
  25733. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25734. maxLength: 63
  25735. minLength: 1
  25736. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25737. type: string
  25738. type: object
  25739. secretAccessKeySecretRef:
  25740. description: The SecretAccessKey is used for authentication
  25741. properties:
  25742. key:
  25743. description: |-
  25744. A key in the referenced Secret.
  25745. Some instances of this field may be defaulted, in others it may be required.
  25746. maxLength: 253
  25747. minLength: 1
  25748. pattern: ^[-._a-zA-Z0-9]+$
  25749. type: string
  25750. name:
  25751. description: The name of the Secret resource being referred to.
  25752. maxLength: 253
  25753. minLength: 1
  25754. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25755. type: string
  25756. namespace:
  25757. description: |-
  25758. The namespace of the Secret resource being referred to.
  25759. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25760. maxLength: 63
  25761. minLength: 1
  25762. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25763. type: string
  25764. type: object
  25765. sessionTokenSecretRef:
  25766. description: |-
  25767. The SessionToken used for authentication
  25768. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  25769. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  25770. properties:
  25771. key:
  25772. description: |-
  25773. A key in the referenced Secret.
  25774. Some instances of this field may be defaulted, in others it may be required.
  25775. maxLength: 253
  25776. minLength: 1
  25777. pattern: ^[-._a-zA-Z0-9]+$
  25778. type: string
  25779. name:
  25780. description: The name of the Secret resource being referred to.
  25781. maxLength: 253
  25782. minLength: 1
  25783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25784. type: string
  25785. namespace:
  25786. description: |-
  25787. The namespace of the Secret resource being referred to.
  25788. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25789. maxLength: 63
  25790. minLength: 1
  25791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25792. type: string
  25793. type: object
  25794. type: object
  25795. vaultAwsIamServerID:
  25796. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  25797. type: string
  25798. vaultRole:
  25799. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  25800. type: string
  25801. required:
  25802. - vaultRole
  25803. type: object
  25804. jwt:
  25805. description: |-
  25806. Jwt authenticates with Vault by passing role and JWT token using the
  25807. JWT/OIDC authentication method
  25808. properties:
  25809. kubernetesServiceAccountToken:
  25810. description: |-
  25811. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  25812. a token for with the `TokenRequest` API.
  25813. properties:
  25814. audiences:
  25815. description: |-
  25816. Optional audiences field that will be used to request a temporary Kubernetes service
  25817. account token for the service account referenced by `serviceAccountRef`.
  25818. Defaults to a single audience `vault` it not specified.
  25819. Deprecated: use serviceAccountRef.Audiences instead
  25820. items:
  25821. type: string
  25822. type: array
  25823. expirationSeconds:
  25824. description: |-
  25825. Optional expiration time in seconds that will be used to request a temporary
  25826. Kubernetes service account token for the service account referenced by
  25827. `serviceAccountRef`.
  25828. Deprecated: this will be removed in the future.
  25829. Defaults to 10 minutes.
  25830. format: int64
  25831. type: integer
  25832. serviceAccountRef:
  25833. description: Service account field containing the name of a kubernetes ServiceAccount.
  25834. properties:
  25835. audiences:
  25836. description: |-
  25837. Audience specifies the `aud` claim for the service account token
  25838. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25839. then this audiences will be appended to the list
  25840. items:
  25841. type: string
  25842. type: array
  25843. name:
  25844. description: The name of the ServiceAccount resource being referred to.
  25845. maxLength: 253
  25846. minLength: 1
  25847. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25848. type: string
  25849. namespace:
  25850. description: |-
  25851. Namespace of the resource being referred to.
  25852. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25853. maxLength: 63
  25854. minLength: 1
  25855. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25856. type: string
  25857. required:
  25858. - name
  25859. type: object
  25860. required:
  25861. - serviceAccountRef
  25862. type: object
  25863. path:
  25864. default: jwt
  25865. description: |-
  25866. Path where the JWT authentication backend is mounted
  25867. in Vault, e.g: "jwt"
  25868. type: string
  25869. role:
  25870. description: |-
  25871. Role is a JWT role to authenticate using the JWT/OIDC Vault
  25872. authentication method
  25873. type: string
  25874. secretRef:
  25875. description: |-
  25876. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  25877. authenticate with Vault using the JWT/OIDC authentication method.
  25878. properties:
  25879. key:
  25880. description: |-
  25881. A key in the referenced Secret.
  25882. Some instances of this field may be defaulted, in others it may be required.
  25883. maxLength: 253
  25884. minLength: 1
  25885. pattern: ^[-._a-zA-Z0-9]+$
  25886. type: string
  25887. name:
  25888. description: The name of the Secret resource being referred to.
  25889. maxLength: 253
  25890. minLength: 1
  25891. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25892. type: string
  25893. namespace:
  25894. description: |-
  25895. The namespace of the Secret resource being referred to.
  25896. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25897. maxLength: 63
  25898. minLength: 1
  25899. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25900. type: string
  25901. type: object
  25902. required:
  25903. - path
  25904. type: object
  25905. kubernetes:
  25906. description: |-
  25907. Kubernetes authenticates with Vault by passing the ServiceAccount
  25908. token stored in the named Secret resource to the Vault server.
  25909. properties:
  25910. mountPath:
  25911. default: kubernetes
  25912. description: |-
  25913. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  25914. "kubernetes"
  25915. type: string
  25916. role:
  25917. description: |-
  25918. A required field containing the Vault Role to assume. A Role binds a
  25919. Kubernetes ServiceAccount with a set of Vault policies.
  25920. type: string
  25921. secretRef:
  25922. description: |-
  25923. Optional secret field containing a Kubernetes ServiceAccount JWT used
  25924. for authenticating with Vault. If a name is specified without a key,
  25925. `token` is the default. If one is not specified, the one bound to
  25926. the controller will be used.
  25927. properties:
  25928. key:
  25929. description: |-
  25930. A key in the referenced Secret.
  25931. Some instances of this field may be defaulted, in others it may be required.
  25932. maxLength: 253
  25933. minLength: 1
  25934. pattern: ^[-._a-zA-Z0-9]+$
  25935. type: string
  25936. name:
  25937. description: The name of the Secret resource being referred to.
  25938. maxLength: 253
  25939. minLength: 1
  25940. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25941. type: string
  25942. namespace:
  25943. description: |-
  25944. The namespace of the Secret resource being referred to.
  25945. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25946. maxLength: 63
  25947. minLength: 1
  25948. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25949. type: string
  25950. type: object
  25951. serviceAccountRef:
  25952. description: |-
  25953. Optional service account field containing the name of a kubernetes ServiceAccount.
  25954. If the service account is specified, the service account secret token JWT will be used
  25955. for authenticating with Vault. If the service account selector is not supplied,
  25956. the secretRef will be used instead.
  25957. properties:
  25958. audiences:
  25959. description: |-
  25960. Audience specifies the `aud` claim for the service account token
  25961. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25962. then this audiences will be appended to the list
  25963. items:
  25964. type: string
  25965. type: array
  25966. name:
  25967. description: The name of the ServiceAccount resource being referred to.
  25968. maxLength: 253
  25969. minLength: 1
  25970. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25971. type: string
  25972. namespace:
  25973. description: |-
  25974. Namespace of the resource being referred to.
  25975. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25976. maxLength: 63
  25977. minLength: 1
  25978. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25979. type: string
  25980. required:
  25981. - name
  25982. type: object
  25983. required:
  25984. - mountPath
  25985. - role
  25986. type: object
  25987. ldap:
  25988. description: |-
  25989. Ldap authenticates with Vault by passing username/password pair using
  25990. the LDAP authentication method
  25991. properties:
  25992. path:
  25993. default: ldap
  25994. description: |-
  25995. Path where the LDAP authentication backend is mounted
  25996. in Vault, e.g: "ldap"
  25997. type: string
  25998. secretRef:
  25999. description: |-
  26000. SecretRef to a key in a Secret resource containing password for the LDAP
  26001. user used to authenticate with Vault using the LDAP authentication
  26002. method
  26003. properties:
  26004. key:
  26005. description: |-
  26006. A key in the referenced Secret.
  26007. Some instances of this field may be defaulted, in others it may be required.
  26008. maxLength: 253
  26009. minLength: 1
  26010. pattern: ^[-._a-zA-Z0-9]+$
  26011. type: string
  26012. name:
  26013. description: The name of the Secret resource being referred to.
  26014. maxLength: 253
  26015. minLength: 1
  26016. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26017. type: string
  26018. namespace:
  26019. description: |-
  26020. The namespace of the Secret resource being referred to.
  26021. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26022. maxLength: 63
  26023. minLength: 1
  26024. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26025. type: string
  26026. type: object
  26027. username:
  26028. description: |-
  26029. Username is an LDAP username used to authenticate using the LDAP Vault
  26030. authentication method
  26031. type: string
  26032. required:
  26033. - path
  26034. - username
  26035. type: object
  26036. namespace:
  26037. description: |-
  26038. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  26039. Namespaces is a set of features within Vault Enterprise that allows
  26040. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  26041. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  26042. This will default to Vault.Namespace field if set, or empty otherwise
  26043. type: string
  26044. tokenSecretRef:
  26045. description: TokenSecretRef authenticates with Vault by presenting a token.
  26046. properties:
  26047. key:
  26048. description: |-
  26049. A key in the referenced Secret.
  26050. Some instances of this field may be defaulted, in others it may be required.
  26051. maxLength: 253
  26052. minLength: 1
  26053. pattern: ^[-._a-zA-Z0-9]+$
  26054. type: string
  26055. name:
  26056. description: The name of the Secret resource being referred to.
  26057. maxLength: 253
  26058. minLength: 1
  26059. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26060. type: string
  26061. namespace:
  26062. description: |-
  26063. The namespace of the Secret resource being referred to.
  26064. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26065. maxLength: 63
  26066. minLength: 1
  26067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26068. type: string
  26069. type: object
  26070. userPass:
  26071. description: UserPass authenticates with Vault by passing username/password pair
  26072. properties:
  26073. path:
  26074. default: userpass
  26075. description: |-
  26076. Path where the UserPassword authentication backend is mounted
  26077. in Vault, e.g: "userpass"
  26078. type: string
  26079. secretRef:
  26080. description: |-
  26081. SecretRef to a key in a Secret resource containing password for the
  26082. user used to authenticate with Vault using the UserPass authentication
  26083. method
  26084. properties:
  26085. key:
  26086. description: |-
  26087. A key in the referenced Secret.
  26088. Some instances of this field may be defaulted, in others it may be required.
  26089. maxLength: 253
  26090. minLength: 1
  26091. pattern: ^[-._a-zA-Z0-9]+$
  26092. type: string
  26093. name:
  26094. description: The name of the Secret resource being referred to.
  26095. maxLength: 253
  26096. minLength: 1
  26097. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26098. type: string
  26099. namespace:
  26100. description: |-
  26101. The namespace of the Secret resource being referred to.
  26102. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26103. maxLength: 63
  26104. minLength: 1
  26105. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26106. type: string
  26107. type: object
  26108. username:
  26109. description: |-
  26110. Username is a username used to authenticate using the UserPass Vault
  26111. authentication method
  26112. type: string
  26113. required:
  26114. - path
  26115. - username
  26116. type: object
  26117. type: object
  26118. caBundle:
  26119. description: |-
  26120. PEM encoded CA bundle used to validate Vault server certificate. Only used
  26121. if the Server URL is using HTTPS protocol. This parameter is ignored for
  26122. plain HTTP protocol connection. If not set the system root certificates
  26123. are used to validate the TLS connection.
  26124. format: byte
  26125. type: string
  26126. caProvider:
  26127. description: The provider for the CA bundle to use to validate Vault server certificate.
  26128. properties:
  26129. key:
  26130. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26131. maxLength: 253
  26132. minLength: 1
  26133. pattern: ^[-._a-zA-Z0-9]+$
  26134. type: string
  26135. name:
  26136. description: The name of the object located at the provider type.
  26137. maxLength: 253
  26138. minLength: 1
  26139. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26140. type: string
  26141. namespace:
  26142. description: |-
  26143. The namespace the Provider type is in.
  26144. Can only be defined when used in a ClusterSecretStore.
  26145. maxLength: 63
  26146. minLength: 1
  26147. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26148. type: string
  26149. type:
  26150. description: The type of provider to use such as "Secret", or "ConfigMap".
  26151. enum:
  26152. - Secret
  26153. - ConfigMap
  26154. type: string
  26155. required:
  26156. - name
  26157. - type
  26158. type: object
  26159. forwardInconsistent:
  26160. description: |-
  26161. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  26162. leader instead of simply retrying within a loop. This can increase performance if
  26163. the option is enabled serverside.
  26164. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  26165. type: boolean
  26166. headers:
  26167. additionalProperties:
  26168. type: string
  26169. description: Headers to be added in Vault request
  26170. type: object
  26171. namespace:
  26172. description: |-
  26173. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  26174. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  26175. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  26176. type: string
  26177. path:
  26178. description: |-
  26179. Path is the mount path of the Vault KV backend endpoint, e.g:
  26180. "secret". The v2 KV secret engine version specific "/data" path suffix
  26181. for fetching secrets from Vault is optional and will be appended
  26182. if not present in specified path.
  26183. type: string
  26184. readYourWrites:
  26185. description: |-
  26186. ReadYourWrites ensures isolated read-after-write semantics by
  26187. providing discovered cluster replication states in each request.
  26188. More information about eventual consistency in Vault can be found here
  26189. https://www.vaultproject.io/docs/enterprise/consistency
  26190. type: boolean
  26191. server:
  26192. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  26193. type: string
  26194. tls:
  26195. description: |-
  26196. The configuration used for client side related TLS communication, when the Vault server
  26197. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  26198. This parameter is ignored for plain HTTP protocol connection.
  26199. It's worth noting this configuration is different from the "TLS certificates auth method",
  26200. which is available under the `auth.cert` section.
  26201. properties:
  26202. certSecretRef:
  26203. description: |-
  26204. CertSecretRef is a certificate added to the transport layer
  26205. when communicating with the Vault server.
  26206. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  26207. properties:
  26208. key:
  26209. description: |-
  26210. A key in the referenced Secret.
  26211. Some instances of this field may be defaulted, in others it may be required.
  26212. maxLength: 253
  26213. minLength: 1
  26214. pattern: ^[-._a-zA-Z0-9]+$
  26215. type: string
  26216. name:
  26217. description: The name of the Secret resource being referred to.
  26218. maxLength: 253
  26219. minLength: 1
  26220. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26221. type: string
  26222. namespace:
  26223. description: |-
  26224. The namespace of the Secret resource being referred to.
  26225. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26226. maxLength: 63
  26227. minLength: 1
  26228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26229. type: string
  26230. type: object
  26231. keySecretRef:
  26232. description: |-
  26233. KeySecretRef to a key in a Secret resource containing client private key
  26234. added to the transport layer when communicating with the Vault server.
  26235. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  26236. properties:
  26237. key:
  26238. description: |-
  26239. A key in the referenced Secret.
  26240. Some instances of this field may be defaulted, in others it may be required.
  26241. maxLength: 253
  26242. minLength: 1
  26243. pattern: ^[-._a-zA-Z0-9]+$
  26244. type: string
  26245. name:
  26246. description: The name of the Secret resource being referred to.
  26247. maxLength: 253
  26248. minLength: 1
  26249. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26250. type: string
  26251. namespace:
  26252. description: |-
  26253. The namespace of the Secret resource being referred to.
  26254. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26255. maxLength: 63
  26256. minLength: 1
  26257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26258. type: string
  26259. type: object
  26260. type: object
  26261. version:
  26262. default: v2
  26263. description: |-
  26264. Version is the Vault KV secret engine version. This can be either "v1" or
  26265. "v2". Version defaults to "v2".
  26266. enum:
  26267. - v1
  26268. - v2
  26269. type: string
  26270. required:
  26271. - server
  26272. type: object
  26273. webhook:
  26274. description: Webhook configures this store to sync secrets using a generic templated webhook
  26275. properties:
  26276. auth:
  26277. description: Auth specifies a authorization protocol. Only one protocol may be set.
  26278. maxProperties: 1
  26279. minProperties: 1
  26280. properties:
  26281. ntlm:
  26282. description: NTLMProtocol configures the store to use NTLM for auth
  26283. properties:
  26284. passwordSecret:
  26285. description: |-
  26286. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26287. In some instances, `key` is a required field.
  26288. properties:
  26289. key:
  26290. description: |-
  26291. A key in the referenced Secret.
  26292. Some instances of this field may be defaulted, in others it may be required.
  26293. maxLength: 253
  26294. minLength: 1
  26295. pattern: ^[-._a-zA-Z0-9]+$
  26296. type: string
  26297. name:
  26298. description: The name of the Secret resource being referred to.
  26299. maxLength: 253
  26300. minLength: 1
  26301. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26302. type: string
  26303. namespace:
  26304. description: |-
  26305. The namespace of the Secret resource being referred to.
  26306. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26307. maxLength: 63
  26308. minLength: 1
  26309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26310. type: string
  26311. type: object
  26312. usernameSecret:
  26313. description: |-
  26314. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26315. In some instances, `key` is a required field.
  26316. properties:
  26317. key:
  26318. description: |-
  26319. A key in the referenced Secret.
  26320. Some instances of this field may be defaulted, in others it may be required.
  26321. maxLength: 253
  26322. minLength: 1
  26323. pattern: ^[-._a-zA-Z0-9]+$
  26324. type: string
  26325. name:
  26326. description: The name of the Secret resource being referred to.
  26327. maxLength: 253
  26328. minLength: 1
  26329. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26330. type: string
  26331. namespace:
  26332. description: |-
  26333. The namespace of the Secret resource being referred to.
  26334. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26335. maxLength: 63
  26336. minLength: 1
  26337. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26338. type: string
  26339. type: object
  26340. required:
  26341. - passwordSecret
  26342. - usernameSecret
  26343. type: object
  26344. type: object
  26345. body:
  26346. description: Body
  26347. type: string
  26348. caBundle:
  26349. description: |-
  26350. PEM encoded CA bundle used to validate webhook server certificate. Only used
  26351. if the Server URL is using HTTPS protocol. This parameter is ignored for
  26352. plain HTTP protocol connection. If not set the system root certificates
  26353. are used to validate the TLS connection.
  26354. format: byte
  26355. type: string
  26356. caProvider:
  26357. description: The provider for the CA bundle to use to validate webhook server certificate.
  26358. properties:
  26359. key:
  26360. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26361. maxLength: 253
  26362. minLength: 1
  26363. pattern: ^[-._a-zA-Z0-9]+$
  26364. type: string
  26365. name:
  26366. description: The name of the object located at the provider type.
  26367. maxLength: 253
  26368. minLength: 1
  26369. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26370. type: string
  26371. namespace:
  26372. description: The namespace the Provider type is in.
  26373. maxLength: 63
  26374. minLength: 1
  26375. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26376. type: string
  26377. type:
  26378. description: The type of provider to use such as "Secret", or "ConfigMap".
  26379. enum:
  26380. - Secret
  26381. - ConfigMap
  26382. type: string
  26383. required:
  26384. - name
  26385. - type
  26386. type: object
  26387. headers:
  26388. additionalProperties:
  26389. type: string
  26390. description: Headers
  26391. type: object
  26392. method:
  26393. description: Webhook Method
  26394. type: string
  26395. result:
  26396. description: Result formatting
  26397. properties:
  26398. jsonPath:
  26399. description: Json path of return value
  26400. type: string
  26401. type: object
  26402. secrets:
  26403. description: |-
  26404. Secrets to fill in templates
  26405. These secrets will be passed to the templating function as key value pairs under the given name
  26406. items:
  26407. description: WebhookSecret defines a secret to be used in webhook templates.
  26408. properties:
  26409. name:
  26410. description: Name of this secret in templates
  26411. type: string
  26412. secretRef:
  26413. description: Secret ref to fill in credentials
  26414. properties:
  26415. key:
  26416. description: |-
  26417. A key in the referenced Secret.
  26418. Some instances of this field may be defaulted, in others it may be required.
  26419. maxLength: 253
  26420. minLength: 1
  26421. pattern: ^[-._a-zA-Z0-9]+$
  26422. type: string
  26423. name:
  26424. description: The name of the Secret resource being referred to.
  26425. maxLength: 253
  26426. minLength: 1
  26427. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26428. type: string
  26429. namespace:
  26430. description: |-
  26431. The namespace of the Secret resource being referred to.
  26432. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26433. maxLength: 63
  26434. minLength: 1
  26435. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26436. type: string
  26437. type: object
  26438. required:
  26439. - name
  26440. - secretRef
  26441. type: object
  26442. type: array
  26443. timeout:
  26444. description: Timeout
  26445. type: string
  26446. url:
  26447. description: Webhook url to call
  26448. type: string
  26449. required:
  26450. - result
  26451. - url
  26452. type: object
  26453. yandexcertificatemanager:
  26454. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  26455. properties:
  26456. apiEndpoint:
  26457. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  26458. type: string
  26459. auth:
  26460. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  26461. properties:
  26462. authorizedKeySecretRef:
  26463. description: The authorized key used for authentication
  26464. properties:
  26465. key:
  26466. description: |-
  26467. A key in the referenced Secret.
  26468. Some instances of this field may be defaulted, in others it may be required.
  26469. maxLength: 253
  26470. minLength: 1
  26471. pattern: ^[-._a-zA-Z0-9]+$
  26472. type: string
  26473. name:
  26474. description: The name of the Secret resource being referred to.
  26475. maxLength: 253
  26476. minLength: 1
  26477. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26478. type: string
  26479. namespace:
  26480. description: |-
  26481. The namespace of the Secret resource being referred to.
  26482. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26483. maxLength: 63
  26484. minLength: 1
  26485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26486. type: string
  26487. type: object
  26488. type: object
  26489. caProvider:
  26490. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  26491. properties:
  26492. certSecretRef:
  26493. description: |-
  26494. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26495. In some instances, `key` is a required field.
  26496. properties:
  26497. key:
  26498. description: |-
  26499. A key in the referenced Secret.
  26500. Some instances of this field may be defaulted, in others it may be required.
  26501. maxLength: 253
  26502. minLength: 1
  26503. pattern: ^[-._a-zA-Z0-9]+$
  26504. type: string
  26505. name:
  26506. description: The name of the Secret resource being referred to.
  26507. maxLength: 253
  26508. minLength: 1
  26509. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26510. type: string
  26511. namespace:
  26512. description: |-
  26513. The namespace of the Secret resource being referred to.
  26514. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26515. maxLength: 63
  26516. minLength: 1
  26517. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26518. type: string
  26519. type: object
  26520. type: object
  26521. required:
  26522. - auth
  26523. type: object
  26524. yandexlockbox:
  26525. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  26526. properties:
  26527. apiEndpoint:
  26528. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  26529. type: string
  26530. auth:
  26531. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  26532. properties:
  26533. authorizedKeySecretRef:
  26534. description: The authorized key used for authentication
  26535. properties:
  26536. key:
  26537. description: |-
  26538. A key in the referenced Secret.
  26539. Some instances of this field may be defaulted, in others it may be required.
  26540. maxLength: 253
  26541. minLength: 1
  26542. pattern: ^[-._a-zA-Z0-9]+$
  26543. type: string
  26544. name:
  26545. description: The name of the Secret resource being referred to.
  26546. maxLength: 253
  26547. minLength: 1
  26548. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26549. type: string
  26550. namespace:
  26551. description: |-
  26552. The namespace of the Secret resource being referred to.
  26553. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26554. maxLength: 63
  26555. minLength: 1
  26556. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26557. type: string
  26558. type: object
  26559. type: object
  26560. caProvider:
  26561. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  26562. properties:
  26563. certSecretRef:
  26564. description: |-
  26565. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26566. In some instances, `key` is a required field.
  26567. properties:
  26568. key:
  26569. description: |-
  26570. A key in the referenced Secret.
  26571. Some instances of this field may be defaulted, in others it may be required.
  26572. maxLength: 253
  26573. minLength: 1
  26574. pattern: ^[-._a-zA-Z0-9]+$
  26575. type: string
  26576. name:
  26577. description: The name of the Secret resource being referred to.
  26578. maxLength: 253
  26579. minLength: 1
  26580. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26581. type: string
  26582. namespace:
  26583. description: |-
  26584. The namespace of the Secret resource being referred to.
  26585. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26586. maxLength: 63
  26587. minLength: 1
  26588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26589. type: string
  26590. type: object
  26591. type: object
  26592. required:
  26593. - auth
  26594. type: object
  26595. type: object
  26596. refreshInterval:
  26597. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  26598. type: integer
  26599. retrySettings:
  26600. description: Used to configure HTTP retries on failures.
  26601. properties:
  26602. maxRetries:
  26603. description: MaxRetries is the maximum number of retry attempts.
  26604. format: int32
  26605. type: integer
  26606. retryInterval:
  26607. description: RetryInterval is the interval between retry attempts.
  26608. type: string
  26609. type: object
  26610. required:
  26611. - provider
  26612. type: object
  26613. status:
  26614. description: SecretStoreStatus defines the observed state of the SecretStore.
  26615. properties:
  26616. capabilities:
  26617. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  26618. type: string
  26619. conditions:
  26620. items:
  26621. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  26622. properties:
  26623. lastTransitionTime:
  26624. format: date-time
  26625. type: string
  26626. message:
  26627. type: string
  26628. reason:
  26629. type: string
  26630. status:
  26631. type: string
  26632. type:
  26633. description: SecretStoreConditionType represents the condition type of the SecretStore.
  26634. type: string
  26635. required:
  26636. - status
  26637. - type
  26638. type: object
  26639. type: array
  26640. type: object
  26641. type: object
  26642. served: false
  26643. storage: false
  26644. subresources:
  26645. status: {}
  26646. ---
  26647. apiVersion: apiextensions.k8s.io/v1
  26648. kind: CustomResourceDefinition
  26649. metadata:
  26650. annotations:
  26651. controller-gen.kubebuilder.io/version: v0.19.0
  26652. labels:
  26653. external-secrets.io/component: controller
  26654. name: acraccesstokens.generators.external-secrets.io
  26655. spec:
  26656. group: generators.external-secrets.io
  26657. names:
  26658. categories:
  26659. - external-secrets
  26660. - external-secrets-generators
  26661. kind: ACRAccessToken
  26662. listKind: ACRAccessTokenList
  26663. plural: acraccesstokens
  26664. singular: acraccesstoken
  26665. scope: Namespaced
  26666. versions:
  26667. - name: v1alpha1
  26668. schema:
  26669. openAPIV3Schema:
  26670. description: |-
  26671. ACRAccessToken returns an Azure Container Registry token
  26672. that can be used for pushing/pulling images.
  26673. Note: by default it will return an ACR Refresh Token with full access
  26674. (depending on the identity).
  26675. This can be scoped down to the repository level using .spec.scope.
  26676. In case scope is defined it will return an ACR Access Token.
  26677. See docs: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md
  26678. properties:
  26679. apiVersion:
  26680. description: |-
  26681. APIVersion defines the versioned schema of this representation of an object.
  26682. Servers should convert recognized schemas to the latest internal value, and
  26683. may reject unrecognized values.
  26684. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  26685. type: string
  26686. kind:
  26687. description: |-
  26688. Kind is a string value representing the REST resource this object represents.
  26689. Servers may infer this from the endpoint the client submits requests to.
  26690. Cannot be updated.
  26691. In CamelCase.
  26692. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  26693. type: string
  26694. metadata:
  26695. type: object
  26696. spec:
  26697. description: |-
  26698. ACRAccessTokenSpec defines how to generate the access token
  26699. e.g. how to authenticate and which registry to use.
  26700. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  26701. properties:
  26702. auth:
  26703. description: ACRAuth defines the authentication methods for Azure Container Registry.
  26704. properties:
  26705. managedIdentity:
  26706. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  26707. properties:
  26708. identityId:
  26709. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  26710. type: string
  26711. type: object
  26712. servicePrincipal:
  26713. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  26714. properties:
  26715. secretRef:
  26716. description: |-
  26717. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  26718. It uses static credentials stored in a Kind=Secret.
  26719. properties:
  26720. clientId:
  26721. description: The Azure clientId of the service principle used for authentication.
  26722. properties:
  26723. key:
  26724. description: |-
  26725. A key in the referenced Secret.
  26726. Some instances of this field may be defaulted, in others it may be required.
  26727. maxLength: 253
  26728. minLength: 1
  26729. pattern: ^[-._a-zA-Z0-9]+$
  26730. type: string
  26731. name:
  26732. description: The name of the Secret resource being referred to.
  26733. maxLength: 253
  26734. minLength: 1
  26735. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26736. type: string
  26737. namespace:
  26738. description: |-
  26739. The namespace of the Secret resource being referred to.
  26740. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26741. maxLength: 63
  26742. minLength: 1
  26743. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26744. type: string
  26745. type: object
  26746. clientSecret:
  26747. description: The Azure ClientSecret of the service principle used for authentication.
  26748. properties:
  26749. key:
  26750. description: |-
  26751. A key in the referenced Secret.
  26752. Some instances of this field may be defaulted, in others it may be required.
  26753. maxLength: 253
  26754. minLength: 1
  26755. pattern: ^[-._a-zA-Z0-9]+$
  26756. type: string
  26757. name:
  26758. description: The name of the Secret resource being referred to.
  26759. maxLength: 253
  26760. minLength: 1
  26761. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26762. type: string
  26763. namespace:
  26764. description: |-
  26765. The namespace of the Secret resource being referred to.
  26766. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26767. maxLength: 63
  26768. minLength: 1
  26769. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26770. type: string
  26771. type: object
  26772. type: object
  26773. required:
  26774. - secretRef
  26775. type: object
  26776. workloadIdentity:
  26777. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  26778. properties:
  26779. serviceAccountRef:
  26780. description: |-
  26781. ServiceAccountRef specified the service account
  26782. that should be used when authenticating with WorkloadIdentity.
  26783. properties:
  26784. audiences:
  26785. description: |-
  26786. Audience specifies the `aud` claim for the service account token
  26787. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  26788. then this audiences will be appended to the list
  26789. items:
  26790. type: string
  26791. type: array
  26792. name:
  26793. description: The name of the ServiceAccount resource being referred to.
  26794. maxLength: 253
  26795. minLength: 1
  26796. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26797. type: string
  26798. namespace:
  26799. description: |-
  26800. Namespace of the resource being referred to.
  26801. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26802. maxLength: 63
  26803. minLength: 1
  26804. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26805. type: string
  26806. required:
  26807. - name
  26808. type: object
  26809. type: object
  26810. type: object
  26811. environmentType:
  26812. default: PublicCloud
  26813. description: |-
  26814. EnvironmentType specifies the Azure cloud environment endpoints to use for
  26815. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  26816. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  26817. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  26818. enum:
  26819. - PublicCloud
  26820. - USGovernmentCloud
  26821. - ChinaCloud
  26822. - GermanCloud
  26823. - AzureStackCloud
  26824. type: string
  26825. registry:
  26826. description: |-
  26827. the domain name of the ACR registry
  26828. e.g. foobarexample.azurecr.io
  26829. type: string
  26830. scope:
  26831. description: |-
  26832. Define the scope for the access token, e.g. pull/push access for a repository.
  26833. if not provided it will return a refresh token that has full scope.
  26834. Note: you need to pin it down to the repository level, there is no wildcard available.
  26835. examples:
  26836. repository:my-repository:pull,push
  26837. repository:my-repository:pull
  26838. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  26839. type: string
  26840. tenantId:
  26841. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  26842. type: string
  26843. required:
  26844. - auth
  26845. - registry
  26846. type: object
  26847. type: object
  26848. served: true
  26849. storage: true
  26850. subresources:
  26851. status: {}
  26852. ---
  26853. apiVersion: apiextensions.k8s.io/v1
  26854. kind: CustomResourceDefinition
  26855. metadata:
  26856. annotations:
  26857. controller-gen.kubebuilder.io/version: v0.19.0
  26858. labels:
  26859. external-secrets.io/component: controller
  26860. name: beyondtrustworkloadcredentialsdynamicsecrets.generators.external-secrets.io
  26861. spec:
  26862. group: generators.external-secrets.io
  26863. names:
  26864. categories:
  26865. - external-secrets
  26866. - external-secrets-generators
  26867. kind: BeyondtrustWorkloadCredentialsDynamicSecret
  26868. listKind: BeyondtrustWorkloadCredentialsDynamicSecretList
  26869. plural: beyondtrustworkloadcredentialsdynamicsecrets
  26870. singular: beyondtrustworkloadcredentialsdynamicsecret
  26871. scope: Namespaced
  26872. versions:
  26873. - name: v1alpha1
  26874. schema:
  26875. openAPIV3Schema:
  26876. description: |-
  26877. BeyondtrustWorkloadCredentialsDynamicSecret represents a generator that requests dynamic credentials from BeyondTrust Workload Credentials.
  26878. This generator calls the BeyondTrust Workload Credentials API to generate fresh, temporary credentials
  26879. (such as AWS STS credentials) each time an ExternalSecret is refreshed.
  26880. Dynamic secret definitions must be created in BeyondTrust Workload Credentials before they can be referenced.
  26881. For complete documentation, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26882. properties:
  26883. apiVersion:
  26884. description: |-
  26885. APIVersion defines the versioned schema of this representation of an object.
  26886. Servers should convert recognized schemas to the latest internal value, and
  26887. may reject unrecognized values.
  26888. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  26889. type: string
  26890. kind:
  26891. description: |-
  26892. Kind is a string value representing the REST resource this object represents.
  26893. Servers may infer this from the endpoint the client submits requests to.
  26894. Cannot be updated.
  26895. In CamelCase.
  26896. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  26897. type: string
  26898. metadata:
  26899. type: object
  26900. spec:
  26901. description: |-
  26902. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  26903. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  26904. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26905. properties:
  26906. controller:
  26907. description: |-
  26908. Controller selects the controller that should handle this generator.
  26909. Leave empty to use the default controller.
  26910. type: string
  26911. provider:
  26912. description: |-
  26913. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  26914. server connection details, and the folder path to the dynamic secret definition.
  26915. The folderPath should point to a dynamic secret definition that has been created in
  26916. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  26917. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26918. properties:
  26919. auth:
  26920. description: |-
  26921. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  26922. Currently supports API key authentication via Kubernetes secret reference.
  26923. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  26924. properties:
  26925. apikey:
  26926. description: |-
  26927. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  26928. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  26929. properties:
  26930. token:
  26931. description: |-
  26932. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  26933. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  26934. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  26935. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  26936. properties:
  26937. key:
  26938. description: |-
  26939. A key in the referenced Secret.
  26940. Some instances of this field may be defaulted, in others it may be required.
  26941. maxLength: 253
  26942. minLength: 1
  26943. pattern: ^[-._a-zA-Z0-9]+$
  26944. type: string
  26945. name:
  26946. description: The name of the Secret resource being referred to.
  26947. maxLength: 253
  26948. minLength: 1
  26949. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26950. type: string
  26951. namespace:
  26952. description: |-
  26953. The namespace of the Secret resource being referred to.
  26954. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26955. maxLength: 63
  26956. minLength: 1
  26957. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26958. type: string
  26959. type: object
  26960. required:
  26961. - token
  26962. type: object
  26963. required:
  26964. - apikey
  26965. type: object
  26966. caBundle:
  26967. description: |-
  26968. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  26969. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  26970. If not set, the system's trusted root certificates are used.
  26971. format: byte
  26972. type: string
  26973. caProvider:
  26974. description: |-
  26975. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  26976. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  26977. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  26978. properties:
  26979. key:
  26980. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26981. maxLength: 253
  26982. minLength: 1
  26983. pattern: ^[-._a-zA-Z0-9]+$
  26984. type: string
  26985. name:
  26986. description: The name of the object located at the provider type.
  26987. maxLength: 253
  26988. minLength: 1
  26989. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26990. type: string
  26991. namespace:
  26992. description: |-
  26993. The namespace the Provider type is in.
  26994. Can only be defined when used in a ClusterSecretStore.
  26995. maxLength: 63
  26996. minLength: 1
  26997. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26998. type: string
  26999. type:
  27000. description: The type of provider to use such as "Secret", or "ConfigMap".
  27001. enum:
  27002. - Secret
  27003. - ConfigMap
  27004. type: string
  27005. required:
  27006. - name
  27007. - type
  27008. type: object
  27009. folderPath:
  27010. description: |-
  27011. FolderPath specifies the default folder path for secret retrieval.
  27012. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  27013. Example: "production/database" or "dev/api-keys"
  27014. Leave empty to retrieve secrets from the root folder.
  27015. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  27016. type: string
  27017. server:
  27018. description: |-
  27019. Server configures the BeyondTrust Workload Credentials server connection details.
  27020. Includes the API URL and Site ID for your BeyondTrust instance.
  27021. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27022. properties:
  27023. apiUrl:
  27024. description: |-
  27025. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  27026. This should be the full URL to your BeyondTrust instance.
  27027. Example: https://api.beyondtrust.io/siie
  27028. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  27029. type: string
  27030. siteId:
  27031. description: |-
  27032. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  27033. This identifier is unique to your BeyondTrust Workload Credentials instance.
  27034. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  27035. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  27036. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27037. type: string
  27038. required:
  27039. - apiUrl
  27040. - siteId
  27041. type: object
  27042. required:
  27043. - auth
  27044. - server
  27045. type: object
  27046. retrySettings:
  27047. description: |-
  27048. RetrySettings configures exponential backoff for failed API requests.
  27049. If not specified, uses the default retry settings.
  27050. properties:
  27051. maxRetries:
  27052. format: int32
  27053. type: integer
  27054. retryInterval:
  27055. type: string
  27056. type: object
  27057. required:
  27058. - provider
  27059. type: object
  27060. type: object
  27061. served: true
  27062. storage: true
  27063. subresources:
  27064. status: {}
  27065. ---
  27066. apiVersion: apiextensions.k8s.io/v1
  27067. kind: CustomResourceDefinition
  27068. metadata:
  27069. annotations:
  27070. controller-gen.kubebuilder.io/version: v0.19.0
  27071. labels:
  27072. external-secrets.io/component: controller
  27073. name: cloudsmithaccesstokens.generators.external-secrets.io
  27074. spec:
  27075. group: generators.external-secrets.io
  27076. names:
  27077. categories:
  27078. - external-secrets
  27079. - external-secrets-generators
  27080. kind: CloudsmithAccessToken
  27081. listKind: CloudsmithAccessTokenList
  27082. plural: cloudsmithaccesstokens
  27083. singular: cloudsmithaccesstoken
  27084. scope: Namespaced
  27085. versions:
  27086. - name: v1alpha1
  27087. schema:
  27088. openAPIV3Schema:
  27089. description: CloudsmithAccessToken generates Cloudsmith access token using OIDC authentication
  27090. properties:
  27091. apiVersion:
  27092. description: |-
  27093. APIVersion defines the versioned schema of this representation of an object.
  27094. Servers should convert recognized schemas to the latest internal value, and
  27095. may reject unrecognized values.
  27096. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27097. type: string
  27098. kind:
  27099. description: |-
  27100. Kind is a string value representing the REST resource this object represents.
  27101. Servers may infer this from the endpoint the client submits requests to.
  27102. Cannot be updated.
  27103. In CamelCase.
  27104. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27105. type: string
  27106. metadata:
  27107. type: object
  27108. spec:
  27109. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  27110. properties:
  27111. apiUrl:
  27112. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  27113. type: string
  27114. orgSlug:
  27115. description: OrgSlug is the organization slug in Cloudsmith
  27116. type: string
  27117. serviceAccountRef:
  27118. description: Name of the service account you are federating with
  27119. properties:
  27120. audiences:
  27121. description: |-
  27122. Audience specifies the `aud` claim for the service account token
  27123. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27124. then this audiences will be appended to the list
  27125. items:
  27126. type: string
  27127. type: array
  27128. name:
  27129. description: The name of the ServiceAccount resource being referred to.
  27130. maxLength: 253
  27131. minLength: 1
  27132. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27133. type: string
  27134. namespace:
  27135. description: |-
  27136. Namespace of the resource being referred to.
  27137. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27138. maxLength: 63
  27139. minLength: 1
  27140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27141. type: string
  27142. required:
  27143. - name
  27144. type: object
  27145. serviceSlug:
  27146. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  27147. type: string
  27148. required:
  27149. - orgSlug
  27150. - serviceAccountRef
  27151. - serviceSlug
  27152. type: object
  27153. type: object
  27154. served: true
  27155. storage: true
  27156. subresources:
  27157. status: {}
  27158. ---
  27159. apiVersion: apiextensions.k8s.io/v1
  27160. kind: CustomResourceDefinition
  27161. metadata:
  27162. annotations:
  27163. controller-gen.kubebuilder.io/version: v0.19.0
  27164. labels:
  27165. external-secrets.io/component: controller
  27166. name: clustergenerators.generators.external-secrets.io
  27167. spec:
  27168. group: generators.external-secrets.io
  27169. names:
  27170. categories:
  27171. - external-secrets
  27172. - external-secrets-generators
  27173. kind: ClusterGenerator
  27174. listKind: ClusterGeneratorList
  27175. plural: clustergenerators
  27176. singular: clustergenerator
  27177. scope: Cluster
  27178. versions:
  27179. - name: v1alpha1
  27180. schema:
  27181. openAPIV3Schema:
  27182. description: ClusterGenerator represents a cluster-wide generator which can be referenced as part of `generatorRef` fields.
  27183. properties:
  27184. apiVersion:
  27185. description: |-
  27186. APIVersion defines the versioned schema of this representation of an object.
  27187. Servers should convert recognized schemas to the latest internal value, and
  27188. may reject unrecognized values.
  27189. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27190. type: string
  27191. kind:
  27192. description: |-
  27193. Kind is a string value representing the REST resource this object represents.
  27194. Servers may infer this from the endpoint the client submits requests to.
  27195. Cannot be updated.
  27196. In CamelCase.
  27197. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27198. type: string
  27199. metadata:
  27200. type: object
  27201. spec:
  27202. description: ClusterGeneratorSpec defines the desired state of a ClusterGenerator.
  27203. properties:
  27204. generator:
  27205. description: Generator the spec for this generator, must match the kind.
  27206. maxProperties: 1
  27207. minProperties: 1
  27208. properties:
  27209. acrAccessTokenSpec:
  27210. description: |-
  27211. ACRAccessTokenSpec defines how to generate the access token
  27212. e.g. how to authenticate and which registry to use.
  27213. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  27214. properties:
  27215. auth:
  27216. description: ACRAuth defines the authentication methods for Azure Container Registry.
  27217. properties:
  27218. managedIdentity:
  27219. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  27220. properties:
  27221. identityId:
  27222. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  27223. type: string
  27224. type: object
  27225. servicePrincipal:
  27226. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  27227. properties:
  27228. secretRef:
  27229. description: |-
  27230. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  27231. It uses static credentials stored in a Kind=Secret.
  27232. properties:
  27233. clientId:
  27234. description: The Azure clientId of the service principle used for authentication.
  27235. properties:
  27236. key:
  27237. description: |-
  27238. A key in the referenced Secret.
  27239. Some instances of this field may be defaulted, in others it may be required.
  27240. maxLength: 253
  27241. minLength: 1
  27242. pattern: ^[-._a-zA-Z0-9]+$
  27243. type: string
  27244. name:
  27245. description: The name of the Secret resource being referred to.
  27246. maxLength: 253
  27247. minLength: 1
  27248. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27249. type: string
  27250. namespace:
  27251. description: |-
  27252. The namespace of the Secret resource being referred to.
  27253. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27254. maxLength: 63
  27255. minLength: 1
  27256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27257. type: string
  27258. type: object
  27259. clientSecret:
  27260. description: The Azure ClientSecret of the service principle used for authentication.
  27261. properties:
  27262. key:
  27263. description: |-
  27264. A key in the referenced Secret.
  27265. Some instances of this field may be defaulted, in others it may be required.
  27266. maxLength: 253
  27267. minLength: 1
  27268. pattern: ^[-._a-zA-Z0-9]+$
  27269. type: string
  27270. name:
  27271. description: The name of the Secret resource being referred to.
  27272. maxLength: 253
  27273. minLength: 1
  27274. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27275. type: string
  27276. namespace:
  27277. description: |-
  27278. The namespace of the Secret resource being referred to.
  27279. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27280. maxLength: 63
  27281. minLength: 1
  27282. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27283. type: string
  27284. type: object
  27285. type: object
  27286. required:
  27287. - secretRef
  27288. type: object
  27289. workloadIdentity:
  27290. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  27291. properties:
  27292. serviceAccountRef:
  27293. description: |-
  27294. ServiceAccountRef specified the service account
  27295. that should be used when authenticating with WorkloadIdentity.
  27296. properties:
  27297. audiences:
  27298. description: |-
  27299. Audience specifies the `aud` claim for the service account token
  27300. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27301. then this audiences will be appended to the list
  27302. items:
  27303. type: string
  27304. type: array
  27305. name:
  27306. description: The name of the ServiceAccount resource being referred to.
  27307. maxLength: 253
  27308. minLength: 1
  27309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27310. type: string
  27311. namespace:
  27312. description: |-
  27313. Namespace of the resource being referred to.
  27314. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27315. maxLength: 63
  27316. minLength: 1
  27317. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27318. type: string
  27319. required:
  27320. - name
  27321. type: object
  27322. type: object
  27323. type: object
  27324. environmentType:
  27325. default: PublicCloud
  27326. description: |-
  27327. EnvironmentType specifies the Azure cloud environment endpoints to use for
  27328. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  27329. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  27330. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  27331. enum:
  27332. - PublicCloud
  27333. - USGovernmentCloud
  27334. - ChinaCloud
  27335. - GermanCloud
  27336. - AzureStackCloud
  27337. type: string
  27338. registry:
  27339. description: |-
  27340. the domain name of the ACR registry
  27341. e.g. foobarexample.azurecr.io
  27342. type: string
  27343. scope:
  27344. description: |-
  27345. Define the scope for the access token, e.g. pull/push access for a repository.
  27346. if not provided it will return a refresh token that has full scope.
  27347. Note: you need to pin it down to the repository level, there is no wildcard available.
  27348. examples:
  27349. repository:my-repository:pull,push
  27350. repository:my-repository:pull
  27351. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  27352. type: string
  27353. tenantId:
  27354. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  27355. type: string
  27356. required:
  27357. - auth
  27358. - registry
  27359. type: object
  27360. beyondtrustWorkloadCredentialsDynamicSecretSpec:
  27361. description: |-
  27362. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  27363. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  27364. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27365. properties:
  27366. controller:
  27367. description: |-
  27368. Controller selects the controller that should handle this generator.
  27369. Leave empty to use the default controller.
  27370. type: string
  27371. provider:
  27372. description: |-
  27373. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  27374. server connection details, and the folder path to the dynamic secret definition.
  27375. The folderPath should point to a dynamic secret definition that has been created in
  27376. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  27377. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27378. properties:
  27379. auth:
  27380. description: |-
  27381. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  27382. Currently supports API key authentication via Kubernetes secret reference.
  27383. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27384. properties:
  27385. apikey:
  27386. description: |-
  27387. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  27388. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  27389. properties:
  27390. token:
  27391. description: |-
  27392. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  27393. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  27394. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  27395. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27396. properties:
  27397. key:
  27398. description: |-
  27399. A key in the referenced Secret.
  27400. Some instances of this field may be defaulted, in others it may be required.
  27401. maxLength: 253
  27402. minLength: 1
  27403. pattern: ^[-._a-zA-Z0-9]+$
  27404. type: string
  27405. name:
  27406. description: The name of the Secret resource being referred to.
  27407. maxLength: 253
  27408. minLength: 1
  27409. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27410. type: string
  27411. namespace:
  27412. description: |-
  27413. The namespace of the Secret resource being referred to.
  27414. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27415. maxLength: 63
  27416. minLength: 1
  27417. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27418. type: string
  27419. type: object
  27420. required:
  27421. - token
  27422. type: object
  27423. required:
  27424. - apikey
  27425. type: object
  27426. caBundle:
  27427. description: |-
  27428. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27429. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  27430. If not set, the system's trusted root certificates are used.
  27431. format: byte
  27432. type: string
  27433. caProvider:
  27434. description: |-
  27435. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  27436. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27437. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  27438. properties:
  27439. key:
  27440. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  27441. maxLength: 253
  27442. minLength: 1
  27443. pattern: ^[-._a-zA-Z0-9]+$
  27444. type: string
  27445. name:
  27446. description: The name of the object located at the provider type.
  27447. maxLength: 253
  27448. minLength: 1
  27449. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27450. type: string
  27451. namespace:
  27452. description: |-
  27453. The namespace the Provider type is in.
  27454. Can only be defined when used in a ClusterSecretStore.
  27455. maxLength: 63
  27456. minLength: 1
  27457. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27458. type: string
  27459. type:
  27460. description: The type of provider to use such as "Secret", or "ConfigMap".
  27461. enum:
  27462. - Secret
  27463. - ConfigMap
  27464. type: string
  27465. required:
  27466. - name
  27467. - type
  27468. type: object
  27469. folderPath:
  27470. description: |-
  27471. FolderPath specifies the default folder path for secret retrieval.
  27472. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  27473. Example: "production/database" or "dev/api-keys"
  27474. Leave empty to retrieve secrets from the root folder.
  27475. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  27476. type: string
  27477. server:
  27478. description: |-
  27479. Server configures the BeyondTrust Workload Credentials server connection details.
  27480. Includes the API URL and Site ID for your BeyondTrust instance.
  27481. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27482. properties:
  27483. apiUrl:
  27484. description: |-
  27485. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  27486. This should be the full URL to your BeyondTrust instance.
  27487. Example: https://api.beyondtrust.io/siie
  27488. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  27489. type: string
  27490. siteId:
  27491. description: |-
  27492. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  27493. This identifier is unique to your BeyondTrust Workload Credentials instance.
  27494. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  27495. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  27496. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27497. type: string
  27498. required:
  27499. - apiUrl
  27500. - siteId
  27501. type: object
  27502. required:
  27503. - auth
  27504. - server
  27505. type: object
  27506. retrySettings:
  27507. description: |-
  27508. RetrySettings configures exponential backoff for failed API requests.
  27509. If not specified, uses the default retry settings.
  27510. properties:
  27511. maxRetries:
  27512. format: int32
  27513. type: integer
  27514. retryInterval:
  27515. type: string
  27516. type: object
  27517. required:
  27518. - provider
  27519. type: object
  27520. cloudsmithAccessTokenSpec:
  27521. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  27522. properties:
  27523. apiUrl:
  27524. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  27525. type: string
  27526. orgSlug:
  27527. description: OrgSlug is the organization slug in Cloudsmith
  27528. type: string
  27529. serviceAccountRef:
  27530. description: Name of the service account you are federating with
  27531. properties:
  27532. audiences:
  27533. description: |-
  27534. Audience specifies the `aud` claim for the service account token
  27535. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27536. then this audiences will be appended to the list
  27537. items:
  27538. type: string
  27539. type: array
  27540. name:
  27541. description: The name of the ServiceAccount resource being referred to.
  27542. maxLength: 253
  27543. minLength: 1
  27544. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27545. type: string
  27546. namespace:
  27547. description: |-
  27548. Namespace of the resource being referred to.
  27549. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27550. maxLength: 63
  27551. minLength: 1
  27552. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27553. type: string
  27554. required:
  27555. - name
  27556. type: object
  27557. serviceSlug:
  27558. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  27559. type: string
  27560. required:
  27561. - orgSlug
  27562. - serviceAccountRef
  27563. - serviceSlug
  27564. type: object
  27565. ecrAuthorizationTokenSpec:
  27566. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  27567. properties:
  27568. auth:
  27569. description: Auth defines how to authenticate with AWS
  27570. properties:
  27571. jwt:
  27572. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  27573. properties:
  27574. serviceAccountRef:
  27575. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  27576. properties:
  27577. audiences:
  27578. description: |-
  27579. Audience specifies the `aud` claim for the service account token
  27580. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27581. then this audiences will be appended to the list
  27582. items:
  27583. type: string
  27584. type: array
  27585. name:
  27586. description: The name of the ServiceAccount resource being referred to.
  27587. maxLength: 253
  27588. minLength: 1
  27589. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27590. type: string
  27591. namespace:
  27592. description: |-
  27593. Namespace of the resource being referred to.
  27594. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27595. maxLength: 63
  27596. minLength: 1
  27597. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27598. type: string
  27599. required:
  27600. - name
  27601. type: object
  27602. type: object
  27603. secretRef:
  27604. description: |-
  27605. AWSAuthSecretRef holds secret references for AWS credentials
  27606. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  27607. properties:
  27608. accessKeyIDSecretRef:
  27609. description: The AccessKeyID is used for authentication
  27610. properties:
  27611. key:
  27612. description: |-
  27613. A key in the referenced Secret.
  27614. Some instances of this field may be defaulted, in others it may be required.
  27615. maxLength: 253
  27616. minLength: 1
  27617. pattern: ^[-._a-zA-Z0-9]+$
  27618. type: string
  27619. name:
  27620. description: The name of the Secret resource being referred to.
  27621. maxLength: 253
  27622. minLength: 1
  27623. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27624. type: string
  27625. namespace:
  27626. description: |-
  27627. The namespace of the Secret resource being referred to.
  27628. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27629. maxLength: 63
  27630. minLength: 1
  27631. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27632. type: string
  27633. type: object
  27634. secretAccessKeySecretRef:
  27635. description: The SecretAccessKey is used for authentication
  27636. properties:
  27637. key:
  27638. description: |-
  27639. A key in the referenced Secret.
  27640. Some instances of this field may be defaulted, in others it may be required.
  27641. maxLength: 253
  27642. minLength: 1
  27643. pattern: ^[-._a-zA-Z0-9]+$
  27644. type: string
  27645. name:
  27646. description: The name of the Secret resource being referred to.
  27647. maxLength: 253
  27648. minLength: 1
  27649. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27650. type: string
  27651. namespace:
  27652. description: |-
  27653. The namespace of the Secret resource being referred to.
  27654. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27655. maxLength: 63
  27656. minLength: 1
  27657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27658. type: string
  27659. type: object
  27660. sessionTokenSecretRef:
  27661. description: |-
  27662. The SessionToken used for authentication
  27663. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  27664. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  27665. properties:
  27666. key:
  27667. description: |-
  27668. A key in the referenced Secret.
  27669. Some instances of this field may be defaulted, in others it may be required.
  27670. maxLength: 253
  27671. minLength: 1
  27672. pattern: ^[-._a-zA-Z0-9]+$
  27673. type: string
  27674. name:
  27675. description: The name of the Secret resource being referred to.
  27676. maxLength: 253
  27677. minLength: 1
  27678. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27679. type: string
  27680. namespace:
  27681. description: |-
  27682. The namespace of the Secret resource being referred to.
  27683. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27684. maxLength: 63
  27685. minLength: 1
  27686. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27687. type: string
  27688. type: object
  27689. type: object
  27690. type: object
  27691. region:
  27692. description: Region specifies the region to operate in.
  27693. type: string
  27694. role:
  27695. description: |-
  27696. You can assume a role before making calls to the
  27697. desired AWS service.
  27698. type: string
  27699. scope:
  27700. description: |-
  27701. Scope specifies the ECR service scope.
  27702. Valid options are private and public.
  27703. type: string
  27704. required:
  27705. - region
  27706. type: object
  27707. fakeSpec:
  27708. description: FakeSpec contains the static data.
  27709. properties:
  27710. controller:
  27711. description: |-
  27712. Used to select the correct ESO controller (think: ingress.ingressClassName)
  27713. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  27714. type: string
  27715. data:
  27716. additionalProperties:
  27717. type: string
  27718. description: |-
  27719. Data defines the static data returned
  27720. by this generator.
  27721. type: object
  27722. type: object
  27723. gcrAccessTokenSpec:
  27724. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  27725. properties:
  27726. auth:
  27727. description: Auth defines the means for authenticating with GCP
  27728. properties:
  27729. secretRef:
  27730. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  27731. properties:
  27732. secretAccessKeySecretRef:
  27733. description: The SecretAccessKey is used for authentication
  27734. properties:
  27735. key:
  27736. description: |-
  27737. A key in the referenced Secret.
  27738. Some instances of this field may be defaulted, in others it may be required.
  27739. maxLength: 253
  27740. minLength: 1
  27741. pattern: ^[-._a-zA-Z0-9]+$
  27742. type: string
  27743. name:
  27744. description: The name of the Secret resource being referred to.
  27745. maxLength: 253
  27746. minLength: 1
  27747. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27748. type: string
  27749. namespace:
  27750. description: |-
  27751. The namespace of the Secret resource being referred to.
  27752. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27753. maxLength: 63
  27754. minLength: 1
  27755. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27756. type: string
  27757. type: object
  27758. type: object
  27759. workloadIdentity:
  27760. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  27761. properties:
  27762. clusterLocation:
  27763. type: string
  27764. clusterName:
  27765. type: string
  27766. clusterProjectID:
  27767. type: string
  27768. serviceAccountRef:
  27769. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  27770. properties:
  27771. audiences:
  27772. description: |-
  27773. Audience specifies the `aud` claim for the service account token
  27774. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27775. then this audiences will be appended to the list
  27776. items:
  27777. type: string
  27778. type: array
  27779. name:
  27780. description: The name of the ServiceAccount resource being referred to.
  27781. maxLength: 253
  27782. minLength: 1
  27783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27784. type: string
  27785. namespace:
  27786. description: |-
  27787. Namespace of the resource being referred to.
  27788. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27789. maxLength: 63
  27790. minLength: 1
  27791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27792. type: string
  27793. required:
  27794. - name
  27795. type: object
  27796. required:
  27797. - clusterLocation
  27798. - clusterName
  27799. - serviceAccountRef
  27800. type: object
  27801. workloadIdentityFederation:
  27802. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  27803. properties:
  27804. audience:
  27805. description: |-
  27806. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  27807. If specified, Audience found in the external account credential config will be overridden with the configured value.
  27808. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  27809. type: string
  27810. awsSecurityCredentials:
  27811. description: |-
  27812. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  27813. when using the AWS metadata server is not an option.
  27814. properties:
  27815. awsCredentialsSecretRef:
  27816. description: |-
  27817. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  27818. Secret should be created with below names for keys
  27819. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  27820. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  27821. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  27822. properties:
  27823. name:
  27824. description: name of the secret.
  27825. maxLength: 253
  27826. minLength: 1
  27827. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27828. type: string
  27829. namespace:
  27830. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  27831. maxLength: 63
  27832. minLength: 1
  27833. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27834. type: string
  27835. required:
  27836. - name
  27837. type: object
  27838. region:
  27839. description: region is for configuring the AWS region to be used.
  27840. example: ap-south-1
  27841. maxLength: 50
  27842. minLength: 1
  27843. pattern: ^[a-z0-9-]+$
  27844. type: string
  27845. required:
  27846. - awsCredentialsSecretRef
  27847. - region
  27848. type: object
  27849. credConfig:
  27850. description: |-
  27851. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  27852. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  27853. serviceAccountRef must be used by providing operators service account details.
  27854. properties:
  27855. key:
  27856. description: key name holding the external account credential config.
  27857. maxLength: 253
  27858. minLength: 1
  27859. pattern: ^[-._a-zA-Z0-9]+$
  27860. type: string
  27861. name:
  27862. description: name of the configmap.
  27863. maxLength: 253
  27864. minLength: 1
  27865. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27866. type: string
  27867. namespace:
  27868. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  27869. maxLength: 63
  27870. minLength: 1
  27871. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27872. type: string
  27873. required:
  27874. - key
  27875. - name
  27876. type: object
  27877. externalTokenEndpoint:
  27878. description: |-
  27879. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  27880. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  27881. URL is having the expected value.
  27882. type: string
  27883. gcpServiceAccountEmail:
  27884. description: |-
  27885. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  27886. after Workload Identity Federation. Use this to grant access through the service account's
  27887. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  27888. service_account_impersonation_url in the external account JSON from credConfig;
  27889. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  27890. on that ServiceAccount.
  27891. example: my-gsa@my-project.iam.gserviceaccount.com
  27892. minLength: 1
  27893. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  27894. type: string
  27895. serviceAccountRef:
  27896. description: |-
  27897. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  27898. when Kubernetes is configured as provider in workload identity pool.
  27899. properties:
  27900. audiences:
  27901. description: |-
  27902. Audience specifies the `aud` claim for the service account token
  27903. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27904. then this audiences will be appended to the list
  27905. items:
  27906. type: string
  27907. type: array
  27908. name:
  27909. description: The name of the ServiceAccount resource being referred to.
  27910. maxLength: 253
  27911. minLength: 1
  27912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27913. type: string
  27914. namespace:
  27915. description: |-
  27916. Namespace of the resource being referred to.
  27917. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27918. maxLength: 63
  27919. minLength: 1
  27920. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27921. type: string
  27922. required:
  27923. - name
  27924. type: object
  27925. type: object
  27926. type: object
  27927. projectID:
  27928. description: ProjectID defines which project to use to authenticate with
  27929. type: string
  27930. required:
  27931. - auth
  27932. - projectID
  27933. type: object
  27934. githubAccessTokenSpec:
  27935. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  27936. properties:
  27937. appID:
  27938. type: string
  27939. auth:
  27940. description: Auth configures how ESO authenticates with a Github instance.
  27941. properties:
  27942. privateKey:
  27943. description: GithubSecretRef references a secret containing GitHub credentials.
  27944. properties:
  27945. secretRef:
  27946. description: |-
  27947. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  27948. In some instances, `key` is a required field.
  27949. properties:
  27950. key:
  27951. description: |-
  27952. A key in the referenced Secret.
  27953. Some instances of this field may be defaulted, in others it may be required.
  27954. maxLength: 253
  27955. minLength: 1
  27956. pattern: ^[-._a-zA-Z0-9]+$
  27957. type: string
  27958. name:
  27959. description: The name of the Secret resource being referred to.
  27960. maxLength: 253
  27961. minLength: 1
  27962. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27963. type: string
  27964. namespace:
  27965. description: |-
  27966. The namespace of the Secret resource being referred to.
  27967. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27968. maxLength: 63
  27969. minLength: 1
  27970. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27971. type: string
  27972. type: object
  27973. required:
  27974. - secretRef
  27975. type: object
  27976. required:
  27977. - privateKey
  27978. type: object
  27979. installID:
  27980. type: string
  27981. permissions:
  27982. additionalProperties:
  27983. type: string
  27984. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  27985. type: object
  27986. repositories:
  27987. description: |-
  27988. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  27989. is installed to.
  27990. items:
  27991. type: string
  27992. type: array
  27993. url:
  27994. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  27995. type: string
  27996. required:
  27997. - appID
  27998. - auth
  27999. - installID
  28000. type: object
  28001. gitlabDeployTokenSpec:
  28002. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  28003. properties:
  28004. auth:
  28005. description: Auth configures how ESO authenticates with the GitLab API.
  28006. properties:
  28007. token:
  28008. description: |-
  28009. Token references a secret containing a GitLab access token (personal, group, or
  28010. project) with the api scope and at least the Maintainer role on the target.
  28011. properties:
  28012. secretRef:
  28013. description: |-
  28014. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28015. In some instances, `key` is a required field.
  28016. properties:
  28017. key:
  28018. description: |-
  28019. A key in the referenced Secret.
  28020. Some instances of this field may be defaulted, in others it may be required.
  28021. maxLength: 253
  28022. minLength: 1
  28023. pattern: ^[-._a-zA-Z0-9]+$
  28024. type: string
  28025. name:
  28026. description: The name of the Secret resource being referred to.
  28027. maxLength: 253
  28028. minLength: 1
  28029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28030. type: string
  28031. namespace:
  28032. description: |-
  28033. The namespace of the Secret resource being referred to.
  28034. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28035. maxLength: 63
  28036. minLength: 1
  28037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28038. type: string
  28039. type: object
  28040. required:
  28041. - secretRef
  28042. type: object
  28043. required:
  28044. - token
  28045. type: object
  28046. expiresAt:
  28047. description: |-
  28048. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  28049. not expire on the GitLab side and is revoked only when the generator state is
  28050. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  28051. format: date-time
  28052. type: string
  28053. groupID:
  28054. description: |-
  28055. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  28056. create the deploy token in. The generator URL-escapes paths before calling the
  28057. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  28058. minLength: 1
  28059. type: string
  28060. name:
  28061. description: Name of the deploy token.
  28062. minLength: 1
  28063. type: string
  28064. projectID:
  28065. description: |-
  28066. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  28067. project to create the deploy token in. The generator URL-escapes paths before
  28068. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  28069. minLength: 1
  28070. type: string
  28071. scopes:
  28072. description: Scopes granted to the deploy token. At least one scope is required.
  28073. items:
  28074. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  28075. enum:
  28076. - read_repository
  28077. - read_registry
  28078. - write_registry
  28079. - read_package_registry
  28080. - write_package_registry
  28081. - read_virtual_registry
  28082. - write_virtual_registry
  28083. type: string
  28084. minItems: 1
  28085. type: array
  28086. url:
  28087. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  28088. type: string
  28089. username:
  28090. description: |-
  28091. Username is an optional username for the deploy token. GitLab defaults it to
  28092. gitlab+deploy-token-{n} when omitted.
  28093. type: string
  28094. required:
  28095. - auth
  28096. - name
  28097. - scopes
  28098. type: object
  28099. x-kubernetes-validations:
  28100. - message: exactly one of projectID or groupID must be set
  28101. rule: has(self.projectID) != has(self.groupID)
  28102. grafanaSpec:
  28103. description: GrafanaSpec controls the behavior of the grafana generator.
  28104. properties:
  28105. auth:
  28106. description: |-
  28107. Auth is the authentication configuration to authenticate
  28108. against the Grafana instance.
  28109. properties:
  28110. basic:
  28111. description: |-
  28112. Basic auth credentials used to authenticate against the Grafana instance.
  28113. Note: you need a token which has elevated permissions to create service accounts.
  28114. See here for the documentation on basic roles offered by Grafana:
  28115. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28116. properties:
  28117. password:
  28118. description: A basic auth password used to authenticate against the Grafana instance.
  28119. properties:
  28120. key:
  28121. description: The key where the token is found.
  28122. maxLength: 253
  28123. minLength: 1
  28124. pattern: ^[-._a-zA-Z0-9]+$
  28125. type: string
  28126. name:
  28127. description: The name of the Secret resource being referred to.
  28128. maxLength: 253
  28129. minLength: 1
  28130. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28131. type: string
  28132. type: object
  28133. username:
  28134. description: A basic auth username used to authenticate against the Grafana instance.
  28135. type: string
  28136. required:
  28137. - password
  28138. - username
  28139. type: object
  28140. token:
  28141. description: |-
  28142. A service account token used to authenticate against the Grafana instance.
  28143. Note: you need a token which has elevated permissions to create service accounts.
  28144. See here for the documentation on basic roles offered by Grafana:
  28145. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28146. properties:
  28147. key:
  28148. description: The key where the token is found.
  28149. maxLength: 253
  28150. minLength: 1
  28151. pattern: ^[-._a-zA-Z0-9]+$
  28152. type: string
  28153. name:
  28154. description: The name of the Secret resource being referred to.
  28155. maxLength: 253
  28156. minLength: 1
  28157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28158. type: string
  28159. type: object
  28160. type: object
  28161. serviceAccount:
  28162. description: |-
  28163. ServiceAccount is the configuration for the service account that
  28164. is supposed to be generated by the generator.
  28165. properties:
  28166. name:
  28167. description: Name is the name of the service account that will be created by ESO.
  28168. type: string
  28169. role:
  28170. description: |-
  28171. Role is the role of the service account.
  28172. See here for the documentation on basic roles offered by Grafana:
  28173. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28174. type: string
  28175. secondsToLive:
  28176. description: |-
  28177. SecondsToLive is the number of seconds before the generated service account token will expire.
  28178. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  28179. format: int64
  28180. minimum: 1
  28181. type: integer
  28182. required:
  28183. - name
  28184. - role
  28185. type: object
  28186. url:
  28187. description: URL is the URL of the Grafana instance.
  28188. type: string
  28189. required:
  28190. - auth
  28191. - serviceAccount
  28192. - url
  28193. type: object
  28194. mfaSpec:
  28195. description: MFASpec controls the behavior of the mfa generator.
  28196. properties:
  28197. algorithm:
  28198. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  28199. type: string
  28200. length:
  28201. description: Length defines the token length. Defaults to 6 characters.
  28202. type: integer
  28203. secret:
  28204. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  28205. properties:
  28206. key:
  28207. description: |-
  28208. A key in the referenced Secret.
  28209. Some instances of this field may be defaulted, in others it may be required.
  28210. maxLength: 253
  28211. minLength: 1
  28212. pattern: ^[-._a-zA-Z0-9]+$
  28213. type: string
  28214. name:
  28215. description: The name of the Secret resource being referred to.
  28216. maxLength: 253
  28217. minLength: 1
  28218. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28219. type: string
  28220. namespace:
  28221. description: |-
  28222. The namespace of the Secret resource being referred to.
  28223. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28224. maxLength: 63
  28225. minLength: 1
  28226. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28227. type: string
  28228. type: object
  28229. timePeriod:
  28230. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  28231. type: integer
  28232. when:
  28233. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  28234. format: date-time
  28235. type: string
  28236. required:
  28237. - secret
  28238. type: object
  28239. passwordSpec:
  28240. description: PasswordSpec controls the behavior of the password generator.
  28241. properties:
  28242. allowRepeat:
  28243. default: false
  28244. description: set AllowRepeat to true to allow repeating characters.
  28245. type: boolean
  28246. digits:
  28247. description: |-
  28248. Digits specifies the number of digits in the generated
  28249. password. If omitted it defaults to 25% of the length of the password
  28250. type: integer
  28251. encoding:
  28252. default: raw
  28253. description: |-
  28254. Encoding specifies the encoding of the generated password.
  28255. Valid values are:
  28256. - "raw" (default): no encoding
  28257. - "base64": standard base64 encoding
  28258. - "base64url": base64url encoding
  28259. - "base32": base32 encoding
  28260. - "hex": hexadecimal encoding
  28261. enum:
  28262. - base64
  28263. - base64url
  28264. - base32
  28265. - hex
  28266. - raw
  28267. type: string
  28268. length:
  28269. default: 24
  28270. description: |-
  28271. Length of the password to be generated.
  28272. Defaults to 24
  28273. type: integer
  28274. noUpper:
  28275. default: false
  28276. description: Set NoUpper to disable uppercase characters
  28277. type: boolean
  28278. secretKeys:
  28279. description: |-
  28280. SecretKeys defines the keys that will be populated with generated passwords.
  28281. Defaults to "password" when not set.
  28282. items:
  28283. type: string
  28284. minItems: 1
  28285. type: array
  28286. symbolCharacters:
  28287. description: |-
  28288. SymbolCharacters specifies the special characters that should be used
  28289. in the generated password.
  28290. type: string
  28291. symbols:
  28292. description: |-
  28293. Symbols specifies the number of symbol characters in the generated
  28294. password. If omitted it defaults to 25% of the length of the password
  28295. type: integer
  28296. required:
  28297. - allowRepeat
  28298. - length
  28299. - noUpper
  28300. type: object
  28301. quayAccessTokenSpec:
  28302. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  28303. properties:
  28304. robotAccount:
  28305. description: Name of the robot account you are federating with
  28306. type: string
  28307. serviceAccountRef:
  28308. description: Name of the service account you are federating with
  28309. properties:
  28310. audiences:
  28311. description: |-
  28312. Audience specifies the `aud` claim for the service account token
  28313. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28314. then this audiences will be appended to the list
  28315. items:
  28316. type: string
  28317. type: array
  28318. name:
  28319. description: The name of the ServiceAccount resource being referred to.
  28320. maxLength: 253
  28321. minLength: 1
  28322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28323. type: string
  28324. namespace:
  28325. description: |-
  28326. Namespace of the resource being referred to.
  28327. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28328. maxLength: 63
  28329. minLength: 1
  28330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28331. type: string
  28332. required:
  28333. - name
  28334. type: object
  28335. url:
  28336. description: URL configures the Quay instance URL. Defaults to quay.io.
  28337. type: string
  28338. required:
  28339. - robotAccount
  28340. - serviceAccountRef
  28341. type: object
  28342. sshKeySpec:
  28343. description: SSHKeySpec controls the behavior of the ssh key generator.
  28344. properties:
  28345. comment:
  28346. description: Comment specifies an optional comment for the SSH key
  28347. type: string
  28348. keySize:
  28349. description: |-
  28350. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  28351. For RSA keys: 2048, 3072, 4096
  28352. For ECDSA keys: 256, 384, 521
  28353. Ignored for ed25519 keys
  28354. maximum: 8192
  28355. minimum: 256
  28356. type: integer
  28357. keyType:
  28358. default: rsa
  28359. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  28360. enum:
  28361. - rsa
  28362. - ecdsa
  28363. - ed25519
  28364. type: string
  28365. type: object
  28366. stsSessionTokenSpec:
  28367. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  28368. properties:
  28369. auth:
  28370. description: Auth defines how to authenticate with AWS
  28371. properties:
  28372. jwt:
  28373. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  28374. properties:
  28375. serviceAccountRef:
  28376. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28377. properties:
  28378. audiences:
  28379. description: |-
  28380. Audience specifies the `aud` claim for the service account token
  28381. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28382. then this audiences will be appended to the list
  28383. items:
  28384. type: string
  28385. type: array
  28386. name:
  28387. description: The name of the ServiceAccount resource being referred to.
  28388. maxLength: 253
  28389. minLength: 1
  28390. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28391. type: string
  28392. namespace:
  28393. description: |-
  28394. Namespace of the resource being referred to.
  28395. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28396. maxLength: 63
  28397. minLength: 1
  28398. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28399. type: string
  28400. required:
  28401. - name
  28402. type: object
  28403. type: object
  28404. secretRef:
  28405. description: |-
  28406. AWSAuthSecretRef holds secret references for AWS credentials
  28407. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  28408. properties:
  28409. accessKeyIDSecretRef:
  28410. description: The AccessKeyID is used for authentication
  28411. properties:
  28412. key:
  28413. description: |-
  28414. A key in the referenced Secret.
  28415. Some instances of this field may be defaulted, in others it may be required.
  28416. maxLength: 253
  28417. minLength: 1
  28418. pattern: ^[-._a-zA-Z0-9]+$
  28419. type: string
  28420. name:
  28421. description: The name of the Secret resource being referred to.
  28422. maxLength: 253
  28423. minLength: 1
  28424. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28425. type: string
  28426. namespace:
  28427. description: |-
  28428. The namespace of the Secret resource being referred to.
  28429. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28430. maxLength: 63
  28431. minLength: 1
  28432. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28433. type: string
  28434. type: object
  28435. secretAccessKeySecretRef:
  28436. description: The SecretAccessKey is used for authentication
  28437. properties:
  28438. key:
  28439. description: |-
  28440. A key in the referenced Secret.
  28441. Some instances of this field may be defaulted, in others it may be required.
  28442. maxLength: 253
  28443. minLength: 1
  28444. pattern: ^[-._a-zA-Z0-9]+$
  28445. type: string
  28446. name:
  28447. description: The name of the Secret resource being referred to.
  28448. maxLength: 253
  28449. minLength: 1
  28450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28451. type: string
  28452. namespace:
  28453. description: |-
  28454. The namespace of the Secret resource being referred to.
  28455. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28456. maxLength: 63
  28457. minLength: 1
  28458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28459. type: string
  28460. type: object
  28461. sessionTokenSecretRef:
  28462. description: |-
  28463. The SessionToken used for authentication
  28464. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28465. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28466. properties:
  28467. key:
  28468. description: |-
  28469. A key in the referenced Secret.
  28470. Some instances of this field may be defaulted, in others it may be required.
  28471. maxLength: 253
  28472. minLength: 1
  28473. pattern: ^[-._a-zA-Z0-9]+$
  28474. type: string
  28475. name:
  28476. description: The name of the Secret resource being referred to.
  28477. maxLength: 253
  28478. minLength: 1
  28479. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28480. type: string
  28481. namespace:
  28482. description: |-
  28483. The namespace of the Secret resource being referred to.
  28484. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28485. maxLength: 63
  28486. minLength: 1
  28487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28488. type: string
  28489. type: object
  28490. type: object
  28491. type: object
  28492. region:
  28493. description: Region specifies the region to operate in.
  28494. type: string
  28495. requestParameters:
  28496. description: RequestParameters contains parameters that can be passed to the STS service.
  28497. properties:
  28498. serialNumber:
  28499. description: |-
  28500. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  28501. the GetSessionToken call.
  28502. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  28503. (such as arn:aws:iam::123456789012:mfa/user)
  28504. type: string
  28505. sessionDuration:
  28506. format: int32
  28507. type: integer
  28508. tokenCode:
  28509. description: TokenCode is the value provided by the MFA device, if MFA is required.
  28510. type: string
  28511. type: object
  28512. role:
  28513. description: |-
  28514. You can assume a role before making calls to the
  28515. desired AWS service.
  28516. type: string
  28517. required:
  28518. - region
  28519. type: object
  28520. uuidSpec:
  28521. description: UUIDSpec controls the behavior of the uuid generator.
  28522. type: object
  28523. vaultDynamicSecretSpec:
  28524. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  28525. properties:
  28526. allowEmptyResponse:
  28527. default: false
  28528. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  28529. type: boolean
  28530. controller:
  28531. description: |-
  28532. Used to select the correct ESO controller (think: ingress.ingressClassName)
  28533. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  28534. type: string
  28535. getParameters:
  28536. additionalProperties:
  28537. items:
  28538. type: string
  28539. type: array
  28540. description: |-
  28541. GetParameters are query-string parameters passed to Vault on GET calls.
  28542. Each key may map to multiple values, matching HTTP query-string semantics.
  28543. Ignored for non-GET methods; use Parameters for write bodies.
  28544. type: object
  28545. method:
  28546. description: Vault API method to use (GET/POST/other)
  28547. type: string
  28548. parameters:
  28549. description: Parameters to pass to Vault write (for non-GET methods)
  28550. x-kubernetes-preserve-unknown-fields: true
  28551. path:
  28552. description: Vault path to obtain the dynamic secret from
  28553. type: string
  28554. provider:
  28555. description: Vault provider common spec
  28556. properties:
  28557. auth:
  28558. description: Auth configures how secret-manager authenticates with the Vault server.
  28559. properties:
  28560. appRole:
  28561. description: |-
  28562. AppRole authenticates with Vault using the App Role auth mechanism,
  28563. with the role and secret stored in a Kubernetes Secret resource.
  28564. properties:
  28565. path:
  28566. default: approle
  28567. description: |-
  28568. Path where the App Role authentication backend is mounted
  28569. in Vault, e.g: "approle"
  28570. type: string
  28571. roleId:
  28572. description: |-
  28573. RoleID configured in the App Role authentication backend when setting
  28574. up the authentication backend in Vault.
  28575. type: string
  28576. roleRef:
  28577. description: |-
  28578. Reference to a key in a Secret that contains the App Role ID used
  28579. to authenticate with Vault.
  28580. The `key` field must be specified and denotes which entry within the Secret
  28581. resource is used as the app role id.
  28582. properties:
  28583. key:
  28584. description: |-
  28585. A key in the referenced Secret.
  28586. Some instances of this field may be defaulted, in others it may be required.
  28587. maxLength: 253
  28588. minLength: 1
  28589. pattern: ^[-._a-zA-Z0-9]+$
  28590. type: string
  28591. name:
  28592. description: The name of the Secret resource being referred to.
  28593. maxLength: 253
  28594. minLength: 1
  28595. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28596. type: string
  28597. namespace:
  28598. description: |-
  28599. The namespace of the Secret resource being referred to.
  28600. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28601. maxLength: 63
  28602. minLength: 1
  28603. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28604. type: string
  28605. type: object
  28606. secretRef:
  28607. description: |-
  28608. Reference to a key in a Secret that contains the App Role secret used
  28609. to authenticate with Vault.
  28610. The `key` field must be specified and denotes which entry within the Secret
  28611. resource is used as the app role secret.
  28612. properties:
  28613. key:
  28614. description: |-
  28615. A key in the referenced Secret.
  28616. Some instances of this field may be defaulted, in others it may be required.
  28617. maxLength: 253
  28618. minLength: 1
  28619. pattern: ^[-._a-zA-Z0-9]+$
  28620. type: string
  28621. name:
  28622. description: The name of the Secret resource being referred to.
  28623. maxLength: 253
  28624. minLength: 1
  28625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28626. type: string
  28627. namespace:
  28628. description: |-
  28629. The namespace of the Secret resource being referred to.
  28630. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28631. maxLength: 63
  28632. minLength: 1
  28633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28634. type: string
  28635. type: object
  28636. required:
  28637. - path
  28638. - secretRef
  28639. type: object
  28640. cert:
  28641. description: |-
  28642. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  28643. Cert authentication method
  28644. properties:
  28645. clientCert:
  28646. description: |-
  28647. ClientCert is a certificate to authenticate using the Cert Vault
  28648. authentication method
  28649. properties:
  28650. key:
  28651. description: |-
  28652. A key in the referenced Secret.
  28653. Some instances of this field may be defaulted, in others it may be required.
  28654. maxLength: 253
  28655. minLength: 1
  28656. pattern: ^[-._a-zA-Z0-9]+$
  28657. type: string
  28658. name:
  28659. description: The name of the Secret resource being referred to.
  28660. maxLength: 253
  28661. minLength: 1
  28662. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28663. type: string
  28664. namespace:
  28665. description: |-
  28666. The namespace of the Secret resource being referred to.
  28667. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28668. maxLength: 63
  28669. minLength: 1
  28670. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28671. type: string
  28672. type: object
  28673. path:
  28674. default: cert
  28675. description: |-
  28676. Path where the Certificate authentication backend is mounted
  28677. in Vault, e.g: "cert"
  28678. type: string
  28679. secretRef:
  28680. description: |-
  28681. SecretRef to a key in a Secret resource containing client private key to
  28682. authenticate with Vault using the Cert authentication method
  28683. properties:
  28684. key:
  28685. description: |-
  28686. A key in the referenced Secret.
  28687. Some instances of this field may be defaulted, in others it may be required.
  28688. maxLength: 253
  28689. minLength: 1
  28690. pattern: ^[-._a-zA-Z0-9]+$
  28691. type: string
  28692. name:
  28693. description: The name of the Secret resource being referred to.
  28694. maxLength: 253
  28695. minLength: 1
  28696. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28697. type: string
  28698. namespace:
  28699. description: |-
  28700. The namespace of the Secret resource being referred to.
  28701. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28702. maxLength: 63
  28703. minLength: 1
  28704. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28705. type: string
  28706. type: object
  28707. vaultRole:
  28708. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  28709. type: string
  28710. type: object
  28711. gcp:
  28712. description: |-
  28713. Gcp authenticates with Vault using Google Cloud Platform authentication method
  28714. GCP authentication method
  28715. properties:
  28716. location:
  28717. description: Location optionally defines a location/region for the secret
  28718. type: string
  28719. path:
  28720. default: gcp
  28721. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  28722. type: string
  28723. projectID:
  28724. description: Project ID of the Google Cloud Platform project
  28725. type: string
  28726. role:
  28727. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  28728. type: string
  28729. secretRef:
  28730. description: Specify credentials in a Secret object
  28731. properties:
  28732. secretAccessKeySecretRef:
  28733. description: The SecretAccessKey is used for authentication
  28734. properties:
  28735. key:
  28736. description: |-
  28737. A key in the referenced Secret.
  28738. Some instances of this field may be defaulted, in others it may be required.
  28739. maxLength: 253
  28740. minLength: 1
  28741. pattern: ^[-._a-zA-Z0-9]+$
  28742. type: string
  28743. name:
  28744. description: The name of the Secret resource being referred to.
  28745. maxLength: 253
  28746. minLength: 1
  28747. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28748. type: string
  28749. namespace:
  28750. description: |-
  28751. The namespace of the Secret resource being referred to.
  28752. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28753. maxLength: 63
  28754. minLength: 1
  28755. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28756. type: string
  28757. type: object
  28758. type: object
  28759. serviceAccountRef:
  28760. description: ServiceAccountRef to a service account for impersonation
  28761. properties:
  28762. audiences:
  28763. description: |-
  28764. Audience specifies the `aud` claim for the service account token
  28765. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28766. then this audiences will be appended to the list
  28767. items:
  28768. type: string
  28769. type: array
  28770. name:
  28771. description: The name of the ServiceAccount resource being referred to.
  28772. maxLength: 253
  28773. minLength: 1
  28774. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28775. type: string
  28776. namespace:
  28777. description: |-
  28778. Namespace of the resource being referred to.
  28779. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28780. maxLength: 63
  28781. minLength: 1
  28782. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28783. type: string
  28784. required:
  28785. - name
  28786. type: object
  28787. workloadIdentity:
  28788. description: Specify a service account with Workload Identity
  28789. properties:
  28790. clusterLocation:
  28791. description: |-
  28792. ClusterLocation is the location of the cluster
  28793. If not specified, it fetches information from the metadata server
  28794. type: string
  28795. clusterName:
  28796. description: |-
  28797. ClusterName is the name of the cluster
  28798. If not specified, it fetches information from the metadata server
  28799. type: string
  28800. clusterProjectID:
  28801. description: |-
  28802. ClusterProjectID is the project ID of the cluster
  28803. If not specified, it fetches information from the metadata server
  28804. type: string
  28805. serviceAccountRef:
  28806. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28807. properties:
  28808. audiences:
  28809. description: |-
  28810. Audience specifies the `aud` claim for the service account token
  28811. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28812. then this audiences will be appended to the list
  28813. items:
  28814. type: string
  28815. type: array
  28816. name:
  28817. description: The name of the ServiceAccount resource being referred to.
  28818. maxLength: 253
  28819. minLength: 1
  28820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28821. type: string
  28822. namespace:
  28823. description: |-
  28824. Namespace of the resource being referred to.
  28825. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28826. maxLength: 63
  28827. minLength: 1
  28828. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28829. type: string
  28830. required:
  28831. - name
  28832. type: object
  28833. required:
  28834. - serviceAccountRef
  28835. type: object
  28836. required:
  28837. - role
  28838. type: object
  28839. iam:
  28840. description: |-
  28841. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  28842. AWS IAM authentication method
  28843. properties:
  28844. externalID:
  28845. description: AWS External ID set on assumed IAM roles
  28846. type: string
  28847. jwt:
  28848. description: Specify a service account with IRSA enabled
  28849. properties:
  28850. serviceAccountRef:
  28851. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28852. properties:
  28853. audiences:
  28854. description: |-
  28855. Audience specifies the `aud` claim for the service account token
  28856. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28857. then this audiences will be appended to the list
  28858. items:
  28859. type: string
  28860. type: array
  28861. name:
  28862. description: The name of the ServiceAccount resource being referred to.
  28863. maxLength: 253
  28864. minLength: 1
  28865. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28866. type: string
  28867. namespace:
  28868. description: |-
  28869. Namespace of the resource being referred to.
  28870. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28871. maxLength: 63
  28872. minLength: 1
  28873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28874. type: string
  28875. required:
  28876. - name
  28877. type: object
  28878. type: object
  28879. path:
  28880. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  28881. type: string
  28882. region:
  28883. description: AWS region
  28884. type: string
  28885. role:
  28886. description: This is the AWS role to be assumed before talking to vault
  28887. type: string
  28888. secretRef:
  28889. description: Specify credentials in a Secret object
  28890. properties:
  28891. accessKeyIDSecretRef:
  28892. description: The AccessKeyID is used for authentication
  28893. properties:
  28894. key:
  28895. description: |-
  28896. A key in the referenced Secret.
  28897. Some instances of this field may be defaulted, in others it may be required.
  28898. maxLength: 253
  28899. minLength: 1
  28900. pattern: ^[-._a-zA-Z0-9]+$
  28901. type: string
  28902. name:
  28903. description: The name of the Secret resource being referred to.
  28904. maxLength: 253
  28905. minLength: 1
  28906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28907. type: string
  28908. namespace:
  28909. description: |-
  28910. The namespace of the Secret resource being referred to.
  28911. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28912. maxLength: 63
  28913. minLength: 1
  28914. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28915. type: string
  28916. type: object
  28917. secretAccessKeySecretRef:
  28918. description: The SecretAccessKey is used for authentication
  28919. properties:
  28920. key:
  28921. description: |-
  28922. A key in the referenced Secret.
  28923. Some instances of this field may be defaulted, in others it may be required.
  28924. maxLength: 253
  28925. minLength: 1
  28926. pattern: ^[-._a-zA-Z0-9]+$
  28927. type: string
  28928. name:
  28929. description: The name of the Secret resource being referred to.
  28930. maxLength: 253
  28931. minLength: 1
  28932. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28933. type: string
  28934. namespace:
  28935. description: |-
  28936. The namespace of the Secret resource being referred to.
  28937. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28938. maxLength: 63
  28939. minLength: 1
  28940. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28941. type: string
  28942. type: object
  28943. sessionTokenSecretRef:
  28944. description: |-
  28945. The SessionToken used for authentication
  28946. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28947. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28948. properties:
  28949. key:
  28950. description: |-
  28951. A key in the referenced Secret.
  28952. Some instances of this field may be defaulted, in others it may be required.
  28953. maxLength: 253
  28954. minLength: 1
  28955. pattern: ^[-._a-zA-Z0-9]+$
  28956. type: string
  28957. name:
  28958. description: The name of the Secret resource being referred to.
  28959. maxLength: 253
  28960. minLength: 1
  28961. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28962. type: string
  28963. namespace:
  28964. description: |-
  28965. The namespace of the Secret resource being referred to.
  28966. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28967. maxLength: 63
  28968. minLength: 1
  28969. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28970. type: string
  28971. type: object
  28972. type: object
  28973. vaultAwsIamServerID:
  28974. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  28975. type: string
  28976. vaultRole:
  28977. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  28978. type: string
  28979. required:
  28980. - vaultRole
  28981. type: object
  28982. jwt:
  28983. description: |-
  28984. Jwt authenticates with Vault by passing role and JWT token using the
  28985. JWT/OIDC authentication method
  28986. properties:
  28987. kubernetesServiceAccountToken:
  28988. description: |-
  28989. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  28990. a token for with the `TokenRequest` API.
  28991. properties:
  28992. audiences:
  28993. description: |-
  28994. Optional audiences field that will be used to request a temporary Kubernetes service
  28995. account token for the service account referenced by `serviceAccountRef`.
  28996. Defaults to a single audience `vault` it not specified.
  28997. Deprecated: use serviceAccountRef.Audiences instead
  28998. items:
  28999. type: string
  29000. type: array
  29001. expirationSeconds:
  29002. description: |-
  29003. Optional expiration time in seconds that will be used to request a temporary
  29004. Kubernetes service account token for the service account referenced by
  29005. `serviceAccountRef`.
  29006. Deprecated: this will be removed in the future.
  29007. Defaults to 10 minutes.
  29008. format: int64
  29009. type: integer
  29010. serviceAccountRef:
  29011. description: Service account field containing the name of a kubernetes ServiceAccount.
  29012. properties:
  29013. audiences:
  29014. description: |-
  29015. Audience specifies the `aud` claim for the service account token
  29016. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29017. then this audiences will be appended to the list
  29018. items:
  29019. type: string
  29020. type: array
  29021. name:
  29022. description: The name of the ServiceAccount resource being referred to.
  29023. maxLength: 253
  29024. minLength: 1
  29025. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29026. type: string
  29027. namespace:
  29028. description: |-
  29029. Namespace of the resource being referred to.
  29030. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29031. maxLength: 63
  29032. minLength: 1
  29033. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29034. type: string
  29035. required:
  29036. - name
  29037. type: object
  29038. required:
  29039. - serviceAccountRef
  29040. type: object
  29041. path:
  29042. default: jwt
  29043. description: |-
  29044. Path where the JWT authentication backend is mounted
  29045. in Vault, e.g: "jwt"
  29046. type: string
  29047. role:
  29048. description: |-
  29049. Role is a JWT role to authenticate using the JWT/OIDC Vault
  29050. authentication method
  29051. type: string
  29052. secretRef:
  29053. description: |-
  29054. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  29055. authenticate with Vault using the JWT/OIDC authentication method.
  29056. properties:
  29057. key:
  29058. description: |-
  29059. A key in the referenced Secret.
  29060. Some instances of this field may be defaulted, in others it may be required.
  29061. maxLength: 253
  29062. minLength: 1
  29063. pattern: ^[-._a-zA-Z0-9]+$
  29064. type: string
  29065. name:
  29066. description: The name of the Secret resource being referred to.
  29067. maxLength: 253
  29068. minLength: 1
  29069. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29070. type: string
  29071. namespace:
  29072. description: |-
  29073. The namespace of the Secret resource being referred to.
  29074. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29075. maxLength: 63
  29076. minLength: 1
  29077. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29078. type: string
  29079. type: object
  29080. required:
  29081. - path
  29082. type: object
  29083. kubernetes:
  29084. description: |-
  29085. Kubernetes authenticates with Vault by passing the ServiceAccount
  29086. token stored in the named Secret resource to the Vault server.
  29087. properties:
  29088. mountPath:
  29089. default: kubernetes
  29090. description: |-
  29091. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  29092. "kubernetes"
  29093. type: string
  29094. role:
  29095. description: |-
  29096. A required field containing the Vault Role to assume. A Role binds a
  29097. Kubernetes ServiceAccount with a set of Vault policies.
  29098. type: string
  29099. secretRef:
  29100. description: |-
  29101. Optional secret field containing a Kubernetes ServiceAccount JWT used
  29102. for authenticating with Vault. If a name is specified without a key,
  29103. `token` is the default. If one is not specified, the one bound to
  29104. the controller will be used.
  29105. properties:
  29106. key:
  29107. description: |-
  29108. A key in the referenced Secret.
  29109. Some instances of this field may be defaulted, in others it may be required.
  29110. maxLength: 253
  29111. minLength: 1
  29112. pattern: ^[-._a-zA-Z0-9]+$
  29113. type: string
  29114. name:
  29115. description: The name of the Secret resource being referred to.
  29116. maxLength: 253
  29117. minLength: 1
  29118. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29119. type: string
  29120. namespace:
  29121. description: |-
  29122. The namespace of the Secret resource being referred to.
  29123. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29124. maxLength: 63
  29125. minLength: 1
  29126. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29127. type: string
  29128. type: object
  29129. serviceAccountRef:
  29130. description: |-
  29131. Optional service account field containing the name of a kubernetes ServiceAccount.
  29132. If the service account is specified, the service account secret token JWT will be used
  29133. for authenticating with Vault. If the service account selector is not supplied,
  29134. the secretRef will be used instead.
  29135. properties:
  29136. audiences:
  29137. description: |-
  29138. Audience specifies the `aud` claim for the service account token
  29139. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29140. then this audiences will be appended to the list
  29141. items:
  29142. type: string
  29143. type: array
  29144. name:
  29145. description: The name of the ServiceAccount resource being referred to.
  29146. maxLength: 253
  29147. minLength: 1
  29148. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29149. type: string
  29150. namespace:
  29151. description: |-
  29152. Namespace of the resource being referred to.
  29153. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29154. maxLength: 63
  29155. minLength: 1
  29156. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29157. type: string
  29158. required:
  29159. - name
  29160. type: object
  29161. required:
  29162. - mountPath
  29163. - role
  29164. type: object
  29165. ldap:
  29166. description: |-
  29167. Ldap authenticates with Vault by passing username/password pair using
  29168. the LDAP authentication method
  29169. properties:
  29170. path:
  29171. default: ldap
  29172. description: |-
  29173. Path where the LDAP authentication backend is mounted
  29174. in Vault, e.g: "ldap"
  29175. type: string
  29176. secretRef:
  29177. description: |-
  29178. SecretRef to a key in a Secret resource containing password for the LDAP
  29179. user used to authenticate with Vault using the LDAP authentication
  29180. method
  29181. properties:
  29182. key:
  29183. description: |-
  29184. A key in the referenced Secret.
  29185. Some instances of this field may be defaulted, in others it may be required.
  29186. maxLength: 253
  29187. minLength: 1
  29188. pattern: ^[-._a-zA-Z0-9]+$
  29189. type: string
  29190. name:
  29191. description: The name of the Secret resource being referred to.
  29192. maxLength: 253
  29193. minLength: 1
  29194. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29195. type: string
  29196. namespace:
  29197. description: |-
  29198. The namespace of the Secret resource being referred to.
  29199. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29200. maxLength: 63
  29201. minLength: 1
  29202. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29203. type: string
  29204. type: object
  29205. username:
  29206. description: |-
  29207. Username is an LDAP username used to authenticate using the LDAP Vault
  29208. authentication method
  29209. type: string
  29210. required:
  29211. - path
  29212. - username
  29213. type: object
  29214. namespace:
  29215. description: |-
  29216. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  29217. Namespaces is a set of features within Vault Enterprise that allows
  29218. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  29219. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  29220. This will default to Vault.Namespace field if set, or empty otherwise
  29221. type: string
  29222. tokenSecretRef:
  29223. description: TokenSecretRef authenticates with Vault by presenting a token.
  29224. properties:
  29225. key:
  29226. description: |-
  29227. A key in the referenced Secret.
  29228. Some instances of this field may be defaulted, in others it may be required.
  29229. maxLength: 253
  29230. minLength: 1
  29231. pattern: ^[-._a-zA-Z0-9]+$
  29232. type: string
  29233. name:
  29234. description: The name of the Secret resource being referred to.
  29235. maxLength: 253
  29236. minLength: 1
  29237. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29238. type: string
  29239. namespace:
  29240. description: |-
  29241. The namespace of the Secret resource being referred to.
  29242. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29243. maxLength: 63
  29244. minLength: 1
  29245. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29246. type: string
  29247. type: object
  29248. userPass:
  29249. description: UserPass authenticates with Vault by passing username/password pair
  29250. properties:
  29251. path:
  29252. default: userpass
  29253. description: |-
  29254. Path where the UserPassword authentication backend is mounted
  29255. in Vault, e.g: "userpass"
  29256. type: string
  29257. secretRef:
  29258. description: |-
  29259. SecretRef to a key in a Secret resource containing password for the
  29260. user used to authenticate with Vault using the UserPass authentication
  29261. method
  29262. properties:
  29263. key:
  29264. description: |-
  29265. A key in the referenced Secret.
  29266. Some instances of this field may be defaulted, in others it may be required.
  29267. maxLength: 253
  29268. minLength: 1
  29269. pattern: ^[-._a-zA-Z0-9]+$
  29270. type: string
  29271. name:
  29272. description: The name of the Secret resource being referred to.
  29273. maxLength: 253
  29274. minLength: 1
  29275. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29276. type: string
  29277. namespace:
  29278. description: |-
  29279. The namespace of the Secret resource being referred to.
  29280. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29281. maxLength: 63
  29282. minLength: 1
  29283. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29284. type: string
  29285. type: object
  29286. username:
  29287. description: |-
  29288. Username is a username used to authenticate using the UserPass Vault
  29289. authentication method
  29290. type: string
  29291. required:
  29292. - path
  29293. - username
  29294. type: object
  29295. type: object
  29296. caBundle:
  29297. description: |-
  29298. PEM encoded CA bundle used to validate Vault server certificate. Only used
  29299. if the Server URL is using HTTPS protocol. This parameter is ignored for
  29300. plain HTTP protocol connection. If not set the system root certificates
  29301. are used to validate the TLS connection.
  29302. format: byte
  29303. type: string
  29304. caProvider:
  29305. description: The provider for the CA bundle to use to validate Vault server certificate.
  29306. properties:
  29307. key:
  29308. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  29309. maxLength: 253
  29310. minLength: 1
  29311. pattern: ^[-._a-zA-Z0-9]+$
  29312. type: string
  29313. name:
  29314. description: The name of the object located at the provider type.
  29315. maxLength: 253
  29316. minLength: 1
  29317. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29318. type: string
  29319. namespace:
  29320. description: |-
  29321. The namespace the Provider type is in.
  29322. Can only be defined when used in a ClusterSecretStore.
  29323. maxLength: 63
  29324. minLength: 1
  29325. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29326. type: string
  29327. type:
  29328. description: The type of provider to use such as "Secret", or "ConfigMap".
  29329. enum:
  29330. - Secret
  29331. - ConfigMap
  29332. type: string
  29333. required:
  29334. - name
  29335. - type
  29336. type: object
  29337. checkAndSet:
  29338. description: |-
  29339. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  29340. Only applies to Vault KV v2 stores. When enabled, write operations must include
  29341. the current version of the secret to prevent unintentional overwrites.
  29342. properties:
  29343. required:
  29344. description: |-
  29345. Required when true, all write operations must include a check-and-set parameter.
  29346. This helps prevent unintentional overwrites of secrets.
  29347. type: boolean
  29348. type: object
  29349. forwardInconsistent:
  29350. description: |-
  29351. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  29352. leader instead of simply retrying within a loop. This can increase performance if
  29353. the option is enabled serverside.
  29354. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  29355. type: boolean
  29356. headers:
  29357. additionalProperties:
  29358. type: string
  29359. description: Headers to be added in Vault request
  29360. type: object
  29361. namespace:
  29362. description: |-
  29363. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  29364. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  29365. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  29366. type: string
  29367. path:
  29368. description: |-
  29369. Path is the mount path of the Vault KV backend endpoint, e.g:
  29370. "secret". The v2 KV secret engine version specific "/data" path suffix
  29371. for fetching secrets from Vault is optional and will be appended
  29372. if not present in specified path.
  29373. type: string
  29374. readYourWrites:
  29375. description: |-
  29376. ReadYourWrites ensures isolated read-after-write semantics by
  29377. providing discovered cluster replication states in each request.
  29378. More information about eventual consistency in Vault can be found here
  29379. https://www.vaultproject.io/docs/enterprise/consistency
  29380. type: boolean
  29381. server:
  29382. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  29383. type: string
  29384. tls:
  29385. description: |-
  29386. The configuration used for client side related TLS communication, when the Vault server
  29387. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  29388. This parameter is ignored for plain HTTP protocol connection.
  29389. It's worth noting this configuration is different from the "TLS certificates auth method",
  29390. which is available under the `auth.cert` section.
  29391. properties:
  29392. certSecretRef:
  29393. description: |-
  29394. CertSecretRef is a certificate added to the transport layer
  29395. when communicating with the Vault server.
  29396. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  29397. properties:
  29398. key:
  29399. description: |-
  29400. A key in the referenced Secret.
  29401. Some instances of this field may be defaulted, in others it may be required.
  29402. maxLength: 253
  29403. minLength: 1
  29404. pattern: ^[-._a-zA-Z0-9]+$
  29405. type: string
  29406. name:
  29407. description: The name of the Secret resource being referred to.
  29408. maxLength: 253
  29409. minLength: 1
  29410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29411. type: string
  29412. namespace:
  29413. description: |-
  29414. The namespace of the Secret resource being referred to.
  29415. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29416. maxLength: 63
  29417. minLength: 1
  29418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29419. type: string
  29420. type: object
  29421. keySecretRef:
  29422. description: |-
  29423. KeySecretRef to a key in a Secret resource containing client private key
  29424. added to the transport layer when communicating with the Vault server.
  29425. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  29426. properties:
  29427. key:
  29428. description: |-
  29429. A key in the referenced Secret.
  29430. Some instances of this field may be defaulted, in others it may be required.
  29431. maxLength: 253
  29432. minLength: 1
  29433. pattern: ^[-._a-zA-Z0-9]+$
  29434. type: string
  29435. name:
  29436. description: The name of the Secret resource being referred to.
  29437. maxLength: 253
  29438. minLength: 1
  29439. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29440. type: string
  29441. namespace:
  29442. description: |-
  29443. The namespace of the Secret resource being referred to.
  29444. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29445. maxLength: 63
  29446. minLength: 1
  29447. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29448. type: string
  29449. type: object
  29450. type: object
  29451. version:
  29452. default: v2
  29453. description: |-
  29454. Version is the Vault KV secret engine version. This can be either "v1" or
  29455. "v2". Version defaults to "v2".
  29456. enum:
  29457. - v1
  29458. - v2
  29459. type: string
  29460. required:
  29461. - server
  29462. type: object
  29463. resultType:
  29464. default: Data
  29465. description: |-
  29466. Result type defines which data is returned from the generator.
  29467. By default, it is the "data" section of the Vault API response.
  29468. When using e.g. /auth/token/create the "data" section is empty but
  29469. the "auth" section contains the generated token.
  29470. Please refer to the vault docs regarding the result data structure.
  29471. Additionally, accessing the raw response is possibly by using "Raw" result type.
  29472. enum:
  29473. - Data
  29474. - Auth
  29475. - Raw
  29476. type: string
  29477. retrySettings:
  29478. description: Used to configure http retries if failed
  29479. properties:
  29480. maxRetries:
  29481. format: int32
  29482. type: integer
  29483. retryInterval:
  29484. type: string
  29485. type: object
  29486. required:
  29487. - path
  29488. - provider
  29489. type: object
  29490. webhookSpec:
  29491. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  29492. properties:
  29493. auth:
  29494. description: Auth specifies a authorization protocol. Only one protocol may be set.
  29495. maxProperties: 1
  29496. minProperties: 1
  29497. properties:
  29498. ntlm:
  29499. description: NTLMProtocol configures the store to use NTLM for auth
  29500. properties:
  29501. passwordSecret:
  29502. description: |-
  29503. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  29504. In some instances, `key` is a required field.
  29505. properties:
  29506. key:
  29507. description: |-
  29508. A key in the referenced Secret.
  29509. Some instances of this field may be defaulted, in others it may be required.
  29510. maxLength: 253
  29511. minLength: 1
  29512. pattern: ^[-._a-zA-Z0-9]+$
  29513. type: string
  29514. name:
  29515. description: The name of the Secret resource being referred to.
  29516. maxLength: 253
  29517. minLength: 1
  29518. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29519. type: string
  29520. namespace:
  29521. description: |-
  29522. The namespace of the Secret resource being referred to.
  29523. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29524. maxLength: 63
  29525. minLength: 1
  29526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29527. type: string
  29528. type: object
  29529. usernameSecret:
  29530. description: |-
  29531. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  29532. In some instances, `key` is a required field.
  29533. properties:
  29534. key:
  29535. description: |-
  29536. A key in the referenced Secret.
  29537. Some instances of this field may be defaulted, in others it may be required.
  29538. maxLength: 253
  29539. minLength: 1
  29540. pattern: ^[-._a-zA-Z0-9]+$
  29541. type: string
  29542. name:
  29543. description: The name of the Secret resource being referred to.
  29544. maxLength: 253
  29545. minLength: 1
  29546. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29547. type: string
  29548. namespace:
  29549. description: |-
  29550. The namespace of the Secret resource being referred to.
  29551. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29552. maxLength: 63
  29553. minLength: 1
  29554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29555. type: string
  29556. type: object
  29557. required:
  29558. - passwordSecret
  29559. - usernameSecret
  29560. type: object
  29561. type: object
  29562. body:
  29563. description: Body
  29564. type: string
  29565. caBundle:
  29566. description: |-
  29567. PEM encoded CA bundle used to validate webhook server certificate. Only used
  29568. if the Server URL is using HTTPS protocol. This parameter is ignored for
  29569. plain HTTP protocol connection. If not set the system root certificates
  29570. are used to validate the TLS connection.
  29571. format: byte
  29572. type: string
  29573. caProvider:
  29574. description: The provider for the CA bundle to use to validate webhook server certificate.
  29575. properties:
  29576. key:
  29577. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  29578. maxLength: 253
  29579. minLength: 1
  29580. pattern: ^[-._a-zA-Z0-9]+$
  29581. type: string
  29582. name:
  29583. description: The name of the object located at the provider type.
  29584. maxLength: 253
  29585. minLength: 1
  29586. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29587. type: string
  29588. namespace:
  29589. description: The namespace the Provider type is in.
  29590. maxLength: 63
  29591. minLength: 1
  29592. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29593. type: string
  29594. type:
  29595. description: The type of provider to use such as "Secret", or "ConfigMap".
  29596. enum:
  29597. - Secret
  29598. - ConfigMap
  29599. type: string
  29600. required:
  29601. - name
  29602. - type
  29603. type: object
  29604. headers:
  29605. additionalProperties:
  29606. type: string
  29607. description: Headers
  29608. type: object
  29609. method:
  29610. description: Webhook Method
  29611. type: string
  29612. result:
  29613. description: Result formatting
  29614. properties:
  29615. jsonPath:
  29616. description: Json path of return value
  29617. type: string
  29618. type: object
  29619. secrets:
  29620. description: |-
  29621. Secrets to fill in templates
  29622. These secrets will be passed to the templating function as key value pairs under the given name
  29623. items:
  29624. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  29625. properties:
  29626. name:
  29627. description: Name of this secret in templates
  29628. type: string
  29629. secretRef:
  29630. description: Secret ref to fill in credentials
  29631. properties:
  29632. key:
  29633. description: The key where the token is found.
  29634. maxLength: 253
  29635. minLength: 1
  29636. pattern: ^[-._a-zA-Z0-9]+$
  29637. type: string
  29638. name:
  29639. description: The name of the Secret resource being referred to.
  29640. maxLength: 253
  29641. minLength: 1
  29642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29643. type: string
  29644. type: object
  29645. required:
  29646. - name
  29647. - secretRef
  29648. type: object
  29649. type: array
  29650. timeout:
  29651. description: Timeout
  29652. type: string
  29653. url:
  29654. description: Webhook url to call
  29655. type: string
  29656. required:
  29657. - result
  29658. - url
  29659. type: object
  29660. type: object
  29661. kind:
  29662. description: Kind the kind of this generator.
  29663. enum:
  29664. - ACRAccessToken
  29665. - BeyondtrustWorkloadCredentialsDynamicSecret
  29666. - CloudsmithAccessToken
  29667. - ECRAuthorizationToken
  29668. - Fake
  29669. - GCRAccessToken
  29670. - GithubAccessToken
  29671. - GitlabDeployToken
  29672. - QuayAccessToken
  29673. - Password
  29674. - SSHKey
  29675. - STSSessionToken
  29676. - UUID
  29677. - VaultDynamicSecret
  29678. - Webhook
  29679. - Grafana
  29680. - MFA
  29681. type: string
  29682. required:
  29683. - generator
  29684. - kind
  29685. type: object
  29686. type: object
  29687. served: true
  29688. storage: true
  29689. subresources:
  29690. status: {}
  29691. ---
  29692. apiVersion: apiextensions.k8s.io/v1
  29693. kind: CustomResourceDefinition
  29694. metadata:
  29695. annotations:
  29696. controller-gen.kubebuilder.io/version: v0.19.0
  29697. labels:
  29698. external-secrets.io/component: controller
  29699. name: ecrauthorizationtokens.generators.external-secrets.io
  29700. spec:
  29701. group: generators.external-secrets.io
  29702. names:
  29703. categories:
  29704. - external-secrets
  29705. - external-secrets-generators
  29706. kind: ECRAuthorizationToken
  29707. listKind: ECRAuthorizationTokenList
  29708. plural: ecrauthorizationtokens
  29709. singular: ecrauthorizationtoken
  29710. scope: Namespaced
  29711. versions:
  29712. - name: v1alpha1
  29713. schema:
  29714. openAPIV3Schema:
  29715. description: |-
  29716. ECRAuthorizationToken uses the GetAuthorizationToken API to retrieve an authorization token.
  29717. The authorization token is valid for 12 hours.
  29718. The authorizationToken returned is a base64 encoded string that can be decoded
  29719. and used in a docker login command to authenticate to a registry.
  29720. For more information, see Registry authentication (https://docs.aws.amazon.com/AmazonECR/latest/userguide/Registries.html#registry_auth) in the Amazon Elastic Container Registry User Guide.
  29721. properties:
  29722. apiVersion:
  29723. description: |-
  29724. APIVersion defines the versioned schema of this representation of an object.
  29725. Servers should convert recognized schemas to the latest internal value, and
  29726. may reject unrecognized values.
  29727. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29728. type: string
  29729. kind:
  29730. description: |-
  29731. Kind is a string value representing the REST resource this object represents.
  29732. Servers may infer this from the endpoint the client submits requests to.
  29733. Cannot be updated.
  29734. In CamelCase.
  29735. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29736. type: string
  29737. metadata:
  29738. type: object
  29739. spec:
  29740. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  29741. properties:
  29742. auth:
  29743. description: Auth defines how to authenticate with AWS
  29744. properties:
  29745. jwt:
  29746. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  29747. properties:
  29748. serviceAccountRef:
  29749. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29750. properties:
  29751. audiences:
  29752. description: |-
  29753. Audience specifies the `aud` claim for the service account token
  29754. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29755. then this audiences will be appended to the list
  29756. items:
  29757. type: string
  29758. type: array
  29759. name:
  29760. description: The name of the ServiceAccount resource being referred to.
  29761. maxLength: 253
  29762. minLength: 1
  29763. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29764. type: string
  29765. namespace:
  29766. description: |-
  29767. Namespace of the resource being referred to.
  29768. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29769. maxLength: 63
  29770. minLength: 1
  29771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29772. type: string
  29773. required:
  29774. - name
  29775. type: object
  29776. type: object
  29777. secretRef:
  29778. description: |-
  29779. AWSAuthSecretRef holds secret references for AWS credentials
  29780. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  29781. properties:
  29782. accessKeyIDSecretRef:
  29783. description: The AccessKeyID is used for authentication
  29784. properties:
  29785. key:
  29786. description: |-
  29787. A key in the referenced Secret.
  29788. Some instances of this field may be defaulted, in others it may be required.
  29789. maxLength: 253
  29790. minLength: 1
  29791. pattern: ^[-._a-zA-Z0-9]+$
  29792. type: string
  29793. name:
  29794. description: The name of the Secret resource being referred to.
  29795. maxLength: 253
  29796. minLength: 1
  29797. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29798. type: string
  29799. namespace:
  29800. description: |-
  29801. The namespace of the Secret resource being referred to.
  29802. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29803. maxLength: 63
  29804. minLength: 1
  29805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29806. type: string
  29807. type: object
  29808. secretAccessKeySecretRef:
  29809. description: The SecretAccessKey is used for authentication
  29810. properties:
  29811. key:
  29812. description: |-
  29813. A key in the referenced Secret.
  29814. Some instances of this field may be defaulted, in others it may be required.
  29815. maxLength: 253
  29816. minLength: 1
  29817. pattern: ^[-._a-zA-Z0-9]+$
  29818. type: string
  29819. name:
  29820. description: The name of the Secret resource being referred to.
  29821. maxLength: 253
  29822. minLength: 1
  29823. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29824. type: string
  29825. namespace:
  29826. description: |-
  29827. The namespace of the Secret resource being referred to.
  29828. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29829. maxLength: 63
  29830. minLength: 1
  29831. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29832. type: string
  29833. type: object
  29834. sessionTokenSecretRef:
  29835. description: |-
  29836. The SessionToken used for authentication
  29837. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  29838. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  29839. properties:
  29840. key:
  29841. description: |-
  29842. A key in the referenced Secret.
  29843. Some instances of this field may be defaulted, in others it may be required.
  29844. maxLength: 253
  29845. minLength: 1
  29846. pattern: ^[-._a-zA-Z0-9]+$
  29847. type: string
  29848. name:
  29849. description: The name of the Secret resource being referred to.
  29850. maxLength: 253
  29851. minLength: 1
  29852. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29853. type: string
  29854. namespace:
  29855. description: |-
  29856. The namespace of the Secret resource being referred to.
  29857. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29858. maxLength: 63
  29859. minLength: 1
  29860. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29861. type: string
  29862. type: object
  29863. type: object
  29864. type: object
  29865. region:
  29866. description: Region specifies the region to operate in.
  29867. type: string
  29868. role:
  29869. description: |-
  29870. You can assume a role before making calls to the
  29871. desired AWS service.
  29872. type: string
  29873. scope:
  29874. description: |-
  29875. Scope specifies the ECR service scope.
  29876. Valid options are private and public.
  29877. type: string
  29878. required:
  29879. - region
  29880. type: object
  29881. type: object
  29882. served: true
  29883. storage: true
  29884. subresources:
  29885. status: {}
  29886. ---
  29887. apiVersion: apiextensions.k8s.io/v1
  29888. kind: CustomResourceDefinition
  29889. metadata:
  29890. annotations:
  29891. controller-gen.kubebuilder.io/version: v0.19.0
  29892. labels:
  29893. external-secrets.io/component: controller
  29894. name: fakes.generators.external-secrets.io
  29895. spec:
  29896. group: generators.external-secrets.io
  29897. names:
  29898. categories:
  29899. - external-secrets
  29900. - external-secrets-generators
  29901. kind: Fake
  29902. listKind: FakeList
  29903. plural: fakes
  29904. singular: fake
  29905. scope: Namespaced
  29906. versions:
  29907. - name: v1alpha1
  29908. schema:
  29909. openAPIV3Schema:
  29910. description: |-
  29911. Fake generator is used for testing. It lets you define
  29912. a static set of credentials that is always returned.
  29913. properties:
  29914. apiVersion:
  29915. description: |-
  29916. APIVersion defines the versioned schema of this representation of an object.
  29917. Servers should convert recognized schemas to the latest internal value, and
  29918. may reject unrecognized values.
  29919. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29920. type: string
  29921. kind:
  29922. description: |-
  29923. Kind is a string value representing the REST resource this object represents.
  29924. Servers may infer this from the endpoint the client submits requests to.
  29925. Cannot be updated.
  29926. In CamelCase.
  29927. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29928. type: string
  29929. metadata:
  29930. type: object
  29931. spec:
  29932. description: FakeSpec contains the static data.
  29933. properties:
  29934. controller:
  29935. description: |-
  29936. Used to select the correct ESO controller (think: ingress.ingressClassName)
  29937. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  29938. type: string
  29939. data:
  29940. additionalProperties:
  29941. type: string
  29942. description: |-
  29943. Data defines the static data returned
  29944. by this generator.
  29945. type: object
  29946. type: object
  29947. type: object
  29948. served: true
  29949. storage: true
  29950. subresources:
  29951. status: {}
  29952. ---
  29953. apiVersion: apiextensions.k8s.io/v1
  29954. kind: CustomResourceDefinition
  29955. metadata:
  29956. annotations:
  29957. controller-gen.kubebuilder.io/version: v0.19.0
  29958. labels:
  29959. external-secrets.io/component: controller
  29960. name: gcraccesstokens.generators.external-secrets.io
  29961. spec:
  29962. group: generators.external-secrets.io
  29963. names:
  29964. categories:
  29965. - external-secrets
  29966. - external-secrets-generators
  29967. kind: GCRAccessToken
  29968. listKind: GCRAccessTokenList
  29969. plural: gcraccesstokens
  29970. singular: gcraccesstoken
  29971. scope: Namespaced
  29972. versions:
  29973. - name: v1alpha1
  29974. schema:
  29975. openAPIV3Schema:
  29976. description: |-
  29977. GCRAccessToken generates an GCP access token
  29978. that can be used to authenticate with GCR.
  29979. properties:
  29980. apiVersion:
  29981. description: |-
  29982. APIVersion defines the versioned schema of this representation of an object.
  29983. Servers should convert recognized schemas to the latest internal value, and
  29984. may reject unrecognized values.
  29985. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29986. type: string
  29987. kind:
  29988. description: |-
  29989. Kind is a string value representing the REST resource this object represents.
  29990. Servers may infer this from the endpoint the client submits requests to.
  29991. Cannot be updated.
  29992. In CamelCase.
  29993. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29994. type: string
  29995. metadata:
  29996. type: object
  29997. spec:
  29998. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  29999. properties:
  30000. auth:
  30001. description: Auth defines the means for authenticating with GCP
  30002. properties:
  30003. secretRef:
  30004. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  30005. properties:
  30006. secretAccessKeySecretRef:
  30007. description: The SecretAccessKey is used for authentication
  30008. properties:
  30009. key:
  30010. description: |-
  30011. A key in the referenced Secret.
  30012. Some instances of this field may be defaulted, in others it may be required.
  30013. maxLength: 253
  30014. minLength: 1
  30015. pattern: ^[-._a-zA-Z0-9]+$
  30016. type: string
  30017. name:
  30018. description: The name of the Secret resource being referred to.
  30019. maxLength: 253
  30020. minLength: 1
  30021. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30022. type: string
  30023. namespace:
  30024. description: |-
  30025. The namespace of the Secret resource being referred to.
  30026. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30027. maxLength: 63
  30028. minLength: 1
  30029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30030. type: string
  30031. type: object
  30032. type: object
  30033. workloadIdentity:
  30034. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  30035. properties:
  30036. clusterLocation:
  30037. type: string
  30038. clusterName:
  30039. type: string
  30040. clusterProjectID:
  30041. type: string
  30042. serviceAccountRef:
  30043. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  30044. properties:
  30045. audiences:
  30046. description: |-
  30047. Audience specifies the `aud` claim for the service account token
  30048. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30049. then this audiences will be appended to the list
  30050. items:
  30051. type: string
  30052. type: array
  30053. name:
  30054. description: The name of the ServiceAccount resource being referred to.
  30055. maxLength: 253
  30056. minLength: 1
  30057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30058. type: string
  30059. namespace:
  30060. description: |-
  30061. Namespace of the resource being referred to.
  30062. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30063. maxLength: 63
  30064. minLength: 1
  30065. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30066. type: string
  30067. required:
  30068. - name
  30069. type: object
  30070. required:
  30071. - clusterLocation
  30072. - clusterName
  30073. - serviceAccountRef
  30074. type: object
  30075. workloadIdentityFederation:
  30076. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  30077. properties:
  30078. audience:
  30079. description: |-
  30080. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  30081. If specified, Audience found in the external account credential config will be overridden with the configured value.
  30082. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  30083. type: string
  30084. awsSecurityCredentials:
  30085. description: |-
  30086. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  30087. when using the AWS metadata server is not an option.
  30088. properties:
  30089. awsCredentialsSecretRef:
  30090. description: |-
  30091. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  30092. Secret should be created with below names for keys
  30093. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  30094. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  30095. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  30096. properties:
  30097. name:
  30098. description: name of the secret.
  30099. maxLength: 253
  30100. minLength: 1
  30101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30102. type: string
  30103. namespace:
  30104. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  30105. maxLength: 63
  30106. minLength: 1
  30107. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30108. type: string
  30109. required:
  30110. - name
  30111. type: object
  30112. region:
  30113. description: region is for configuring the AWS region to be used.
  30114. example: ap-south-1
  30115. maxLength: 50
  30116. minLength: 1
  30117. pattern: ^[a-z0-9-]+$
  30118. type: string
  30119. required:
  30120. - awsCredentialsSecretRef
  30121. - region
  30122. type: object
  30123. credConfig:
  30124. description: |-
  30125. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  30126. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  30127. serviceAccountRef must be used by providing operators service account details.
  30128. properties:
  30129. key:
  30130. description: key name holding the external account credential config.
  30131. maxLength: 253
  30132. minLength: 1
  30133. pattern: ^[-._a-zA-Z0-9]+$
  30134. type: string
  30135. name:
  30136. description: name of the configmap.
  30137. maxLength: 253
  30138. minLength: 1
  30139. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30140. type: string
  30141. namespace:
  30142. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  30143. maxLength: 63
  30144. minLength: 1
  30145. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30146. type: string
  30147. required:
  30148. - key
  30149. - name
  30150. type: object
  30151. externalTokenEndpoint:
  30152. description: |-
  30153. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  30154. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  30155. URL is having the expected value.
  30156. type: string
  30157. gcpServiceAccountEmail:
  30158. description: |-
  30159. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  30160. after Workload Identity Federation. Use this to grant access through the service account's
  30161. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  30162. service_account_impersonation_url in the external account JSON from credConfig;
  30163. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  30164. on that ServiceAccount.
  30165. example: my-gsa@my-project.iam.gserviceaccount.com
  30166. minLength: 1
  30167. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  30168. type: string
  30169. serviceAccountRef:
  30170. description: |-
  30171. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  30172. when Kubernetes is configured as provider in workload identity pool.
  30173. properties:
  30174. audiences:
  30175. description: |-
  30176. Audience specifies the `aud` claim for the service account token
  30177. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30178. then this audiences will be appended to the list
  30179. items:
  30180. type: string
  30181. type: array
  30182. name:
  30183. description: The name of the ServiceAccount resource being referred to.
  30184. maxLength: 253
  30185. minLength: 1
  30186. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30187. type: string
  30188. namespace:
  30189. description: |-
  30190. Namespace of the resource being referred to.
  30191. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30192. maxLength: 63
  30193. minLength: 1
  30194. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30195. type: string
  30196. required:
  30197. - name
  30198. type: object
  30199. type: object
  30200. type: object
  30201. projectID:
  30202. description: ProjectID defines which project to use to authenticate with
  30203. type: string
  30204. required:
  30205. - auth
  30206. - projectID
  30207. type: object
  30208. type: object
  30209. served: true
  30210. storage: true
  30211. subresources:
  30212. status: {}
  30213. ---
  30214. apiVersion: apiextensions.k8s.io/v1
  30215. kind: CustomResourceDefinition
  30216. metadata:
  30217. annotations:
  30218. controller-gen.kubebuilder.io/version: v0.19.0
  30219. labels:
  30220. external-secrets.io/component: controller
  30221. name: generatorstates.generators.external-secrets.io
  30222. spec:
  30223. group: generators.external-secrets.io
  30224. names:
  30225. categories:
  30226. - external-secrets
  30227. - external-secrets-generators
  30228. kind: GeneratorState
  30229. listKind: GeneratorStateList
  30230. plural: generatorstates
  30231. shortNames:
  30232. - gs
  30233. singular: generatorstate
  30234. scope: Namespaced
  30235. versions:
  30236. - additionalPrinterColumns:
  30237. - jsonPath: .spec.garbageCollectionDeadline
  30238. name: GC Deadline
  30239. type: string
  30240. - jsonPath: .metadata.creationTimestamp
  30241. name: Age
  30242. type: date
  30243. name: v1alpha1
  30244. schema:
  30245. openAPIV3Schema:
  30246. description: GeneratorState represents the state created and managed by a generator resource.
  30247. properties:
  30248. apiVersion:
  30249. description: |-
  30250. APIVersion defines the versioned schema of this representation of an object.
  30251. Servers should convert recognized schemas to the latest internal value, and
  30252. may reject unrecognized values.
  30253. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30254. type: string
  30255. kind:
  30256. description: |-
  30257. Kind is a string value representing the REST resource this object represents.
  30258. Servers may infer this from the endpoint the client submits requests to.
  30259. Cannot be updated.
  30260. In CamelCase.
  30261. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30262. type: string
  30263. metadata:
  30264. type: object
  30265. spec:
  30266. description: GeneratorStateSpec defines the desired state of a generator state resource.
  30267. properties:
  30268. garbageCollectionDeadline:
  30269. description: |-
  30270. GarbageCollectionDeadline is the time after which the generator state
  30271. will be deleted.
  30272. It is set by the controller which creates the generator state and
  30273. can be set configured by the user.
  30274. If the garbage collection deadline is not set the generator state will not be deleted.
  30275. format: date-time
  30276. type: string
  30277. resource:
  30278. description: |-
  30279. Resource is the generator manifest that produced the state.
  30280. It is a snapshot of the generator manifest at the time the state was produced.
  30281. This manifest will be used to delete the resource. Any configuration that is referenced
  30282. in the manifest should be available at the time of garbage collection. If that is not the case deletion will
  30283. be blocked by a finalizer.
  30284. x-kubernetes-preserve-unknown-fields: true
  30285. state:
  30286. description: State is the state that was produced by the generator implementation.
  30287. x-kubernetes-preserve-unknown-fields: true
  30288. required:
  30289. - resource
  30290. - state
  30291. type: object
  30292. status:
  30293. description: GeneratorStateStatus defines the observed state of a generator state resource.
  30294. properties:
  30295. conditions:
  30296. items:
  30297. description: GeneratorStateStatusCondition represents the observed condition of a generator state.
  30298. properties:
  30299. lastTransitionTime:
  30300. format: date-time
  30301. type: string
  30302. message:
  30303. type: string
  30304. reason:
  30305. type: string
  30306. status:
  30307. type: string
  30308. type:
  30309. description: GeneratorStateConditionType represents the type of condition for a generator state.
  30310. type: string
  30311. required:
  30312. - status
  30313. - type
  30314. type: object
  30315. type: array
  30316. type: object
  30317. type: object
  30318. served: true
  30319. storage: true
  30320. subresources: {}
  30321. ---
  30322. apiVersion: apiextensions.k8s.io/v1
  30323. kind: CustomResourceDefinition
  30324. metadata:
  30325. annotations:
  30326. controller-gen.kubebuilder.io/version: v0.19.0
  30327. labels:
  30328. external-secrets.io/component: controller
  30329. name: githubaccesstokens.generators.external-secrets.io
  30330. spec:
  30331. group: generators.external-secrets.io
  30332. names:
  30333. categories:
  30334. - external-secrets
  30335. - external-secrets-generators
  30336. kind: GithubAccessToken
  30337. listKind: GithubAccessTokenList
  30338. plural: githubaccesstokens
  30339. singular: githubaccesstoken
  30340. scope: Namespaced
  30341. versions:
  30342. - name: v1alpha1
  30343. schema:
  30344. openAPIV3Schema:
  30345. description: GithubAccessToken generates ghs_ accessToken
  30346. properties:
  30347. apiVersion:
  30348. description: |-
  30349. APIVersion defines the versioned schema of this representation of an object.
  30350. Servers should convert recognized schemas to the latest internal value, and
  30351. may reject unrecognized values.
  30352. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30353. type: string
  30354. kind:
  30355. description: |-
  30356. Kind is a string value representing the REST resource this object represents.
  30357. Servers may infer this from the endpoint the client submits requests to.
  30358. Cannot be updated.
  30359. In CamelCase.
  30360. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30361. type: string
  30362. metadata:
  30363. type: object
  30364. spec:
  30365. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  30366. properties:
  30367. appID:
  30368. type: string
  30369. auth:
  30370. description: Auth configures how ESO authenticates with a Github instance.
  30371. properties:
  30372. privateKey:
  30373. description: GithubSecretRef references a secret containing GitHub credentials.
  30374. properties:
  30375. secretRef:
  30376. description: |-
  30377. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30378. In some instances, `key` is a required field.
  30379. properties:
  30380. key:
  30381. description: |-
  30382. A key in the referenced Secret.
  30383. Some instances of this field may be defaulted, in others it may be required.
  30384. maxLength: 253
  30385. minLength: 1
  30386. pattern: ^[-._a-zA-Z0-9]+$
  30387. type: string
  30388. name:
  30389. description: The name of the Secret resource being referred to.
  30390. maxLength: 253
  30391. minLength: 1
  30392. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30393. type: string
  30394. namespace:
  30395. description: |-
  30396. The namespace of the Secret resource being referred to.
  30397. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30398. maxLength: 63
  30399. minLength: 1
  30400. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30401. type: string
  30402. type: object
  30403. required:
  30404. - secretRef
  30405. type: object
  30406. required:
  30407. - privateKey
  30408. type: object
  30409. installID:
  30410. type: string
  30411. permissions:
  30412. additionalProperties:
  30413. type: string
  30414. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  30415. type: object
  30416. repositories:
  30417. description: |-
  30418. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  30419. is installed to.
  30420. items:
  30421. type: string
  30422. type: array
  30423. url:
  30424. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  30425. type: string
  30426. required:
  30427. - appID
  30428. - auth
  30429. - installID
  30430. type: object
  30431. type: object
  30432. served: true
  30433. storage: true
  30434. subresources:
  30435. status: {}
  30436. ---
  30437. apiVersion: apiextensions.k8s.io/v1
  30438. kind: CustomResourceDefinition
  30439. metadata:
  30440. annotations:
  30441. controller-gen.kubebuilder.io/version: v0.19.0
  30442. labels:
  30443. external-secrets.io/component: controller
  30444. name: gitlabdeploytokens.generators.external-secrets.io
  30445. spec:
  30446. group: generators.external-secrets.io
  30447. names:
  30448. categories:
  30449. - external-secrets
  30450. - external-secrets-generators
  30451. kind: GitlabDeployToken
  30452. listKind: GitlabDeployTokenList
  30453. plural: gitlabdeploytokens
  30454. singular: gitlabdeploytoken
  30455. scope: Namespaced
  30456. versions:
  30457. - name: v1alpha1
  30458. schema:
  30459. openAPIV3Schema:
  30460. description: GitlabDeployToken generates a GitLab deploy token.
  30461. properties:
  30462. apiVersion:
  30463. description: |-
  30464. APIVersion defines the versioned schema of this representation of an object.
  30465. Servers should convert recognized schemas to the latest internal value, and
  30466. may reject unrecognized values.
  30467. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30468. type: string
  30469. kind:
  30470. description: |-
  30471. Kind is a string value representing the REST resource this object represents.
  30472. Servers may infer this from the endpoint the client submits requests to.
  30473. Cannot be updated.
  30474. In CamelCase.
  30475. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30476. type: string
  30477. metadata:
  30478. type: object
  30479. spec:
  30480. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  30481. properties:
  30482. auth:
  30483. description: Auth configures how ESO authenticates with the GitLab API.
  30484. properties:
  30485. token:
  30486. description: |-
  30487. Token references a secret containing a GitLab access token (personal, group, or
  30488. project) with the api scope and at least the Maintainer role on the target.
  30489. properties:
  30490. secretRef:
  30491. description: |-
  30492. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30493. In some instances, `key` is a required field.
  30494. properties:
  30495. key:
  30496. description: |-
  30497. A key in the referenced Secret.
  30498. Some instances of this field may be defaulted, in others it may be required.
  30499. maxLength: 253
  30500. minLength: 1
  30501. pattern: ^[-._a-zA-Z0-9]+$
  30502. type: string
  30503. name:
  30504. description: The name of the Secret resource being referred to.
  30505. maxLength: 253
  30506. minLength: 1
  30507. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30508. type: string
  30509. namespace:
  30510. description: |-
  30511. The namespace of the Secret resource being referred to.
  30512. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30513. maxLength: 63
  30514. minLength: 1
  30515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30516. type: string
  30517. type: object
  30518. required:
  30519. - secretRef
  30520. type: object
  30521. required:
  30522. - token
  30523. type: object
  30524. expiresAt:
  30525. description: |-
  30526. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  30527. not expire on the GitLab side and is revoked only when the generator state is
  30528. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  30529. format: date-time
  30530. type: string
  30531. groupID:
  30532. description: |-
  30533. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  30534. create the deploy token in. The generator URL-escapes paths before calling the
  30535. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  30536. minLength: 1
  30537. type: string
  30538. name:
  30539. description: Name of the deploy token.
  30540. minLength: 1
  30541. type: string
  30542. projectID:
  30543. description: |-
  30544. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  30545. project to create the deploy token in. The generator URL-escapes paths before
  30546. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  30547. minLength: 1
  30548. type: string
  30549. scopes:
  30550. description: Scopes granted to the deploy token. At least one scope is required.
  30551. items:
  30552. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  30553. enum:
  30554. - read_repository
  30555. - read_registry
  30556. - write_registry
  30557. - read_package_registry
  30558. - write_package_registry
  30559. - read_virtual_registry
  30560. - write_virtual_registry
  30561. type: string
  30562. minItems: 1
  30563. type: array
  30564. url:
  30565. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  30566. type: string
  30567. username:
  30568. description: |-
  30569. Username is an optional username for the deploy token. GitLab defaults it to
  30570. gitlab+deploy-token-{n} when omitted.
  30571. type: string
  30572. required:
  30573. - auth
  30574. - name
  30575. - scopes
  30576. type: object
  30577. x-kubernetes-validations:
  30578. - message: exactly one of projectID or groupID must be set
  30579. rule: has(self.projectID) != has(self.groupID)
  30580. type: object
  30581. served: true
  30582. storage: true
  30583. subresources:
  30584. status: {}
  30585. ---
  30586. apiVersion: apiextensions.k8s.io/v1
  30587. kind: CustomResourceDefinition
  30588. metadata:
  30589. annotations:
  30590. controller-gen.kubebuilder.io/version: v0.19.0
  30591. labels:
  30592. external-secrets.io/component: controller
  30593. name: grafanas.generators.external-secrets.io
  30594. spec:
  30595. group: generators.external-secrets.io
  30596. names:
  30597. categories:
  30598. - external-secrets
  30599. - external-secrets-generators
  30600. kind: Grafana
  30601. listKind: GrafanaList
  30602. plural: grafanas
  30603. singular: grafana
  30604. scope: Namespaced
  30605. versions:
  30606. - name: v1alpha1
  30607. schema:
  30608. openAPIV3Schema:
  30609. description: Grafana represents a generator for Grafana service account tokens.
  30610. properties:
  30611. apiVersion:
  30612. description: |-
  30613. APIVersion defines the versioned schema of this representation of an object.
  30614. Servers should convert recognized schemas to the latest internal value, and
  30615. may reject unrecognized values.
  30616. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30617. type: string
  30618. kind:
  30619. description: |-
  30620. Kind is a string value representing the REST resource this object represents.
  30621. Servers may infer this from the endpoint the client submits requests to.
  30622. Cannot be updated.
  30623. In CamelCase.
  30624. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30625. type: string
  30626. metadata:
  30627. type: object
  30628. spec:
  30629. description: GrafanaSpec controls the behavior of the grafana generator.
  30630. properties:
  30631. auth:
  30632. description: |-
  30633. Auth is the authentication configuration to authenticate
  30634. against the Grafana instance.
  30635. properties:
  30636. basic:
  30637. description: |-
  30638. Basic auth credentials used to authenticate against the Grafana instance.
  30639. Note: you need a token which has elevated permissions to create service accounts.
  30640. See here for the documentation on basic roles offered by Grafana:
  30641. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30642. properties:
  30643. password:
  30644. description: A basic auth password used to authenticate against the Grafana instance.
  30645. properties:
  30646. key:
  30647. description: The key where the token is found.
  30648. maxLength: 253
  30649. minLength: 1
  30650. pattern: ^[-._a-zA-Z0-9]+$
  30651. type: string
  30652. name:
  30653. description: The name of the Secret resource being referred to.
  30654. maxLength: 253
  30655. minLength: 1
  30656. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30657. type: string
  30658. type: object
  30659. username:
  30660. description: A basic auth username used to authenticate against the Grafana instance.
  30661. type: string
  30662. required:
  30663. - password
  30664. - username
  30665. type: object
  30666. token:
  30667. description: |-
  30668. A service account token used to authenticate against the Grafana instance.
  30669. Note: you need a token which has elevated permissions to create service accounts.
  30670. See here for the documentation on basic roles offered by Grafana:
  30671. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30672. properties:
  30673. key:
  30674. description: The key where the token is found.
  30675. maxLength: 253
  30676. minLength: 1
  30677. pattern: ^[-._a-zA-Z0-9]+$
  30678. type: string
  30679. name:
  30680. description: The name of the Secret resource being referred to.
  30681. maxLength: 253
  30682. minLength: 1
  30683. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30684. type: string
  30685. type: object
  30686. type: object
  30687. serviceAccount:
  30688. description: |-
  30689. ServiceAccount is the configuration for the service account that
  30690. is supposed to be generated by the generator.
  30691. properties:
  30692. name:
  30693. description: Name is the name of the service account that will be created by ESO.
  30694. type: string
  30695. role:
  30696. description: |-
  30697. Role is the role of the service account.
  30698. See here for the documentation on basic roles offered by Grafana:
  30699. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30700. type: string
  30701. secondsToLive:
  30702. description: |-
  30703. SecondsToLive is the number of seconds before the generated service account token will expire.
  30704. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  30705. format: int64
  30706. minimum: 1
  30707. type: integer
  30708. required:
  30709. - name
  30710. - role
  30711. type: object
  30712. url:
  30713. description: URL is the URL of the Grafana instance.
  30714. type: string
  30715. required:
  30716. - auth
  30717. - serviceAccount
  30718. - url
  30719. type: object
  30720. type: object
  30721. served: true
  30722. storage: true
  30723. subresources:
  30724. status: {}
  30725. ---
  30726. apiVersion: apiextensions.k8s.io/v1
  30727. kind: CustomResourceDefinition
  30728. metadata:
  30729. annotations:
  30730. controller-gen.kubebuilder.io/version: v0.19.0
  30731. labels:
  30732. external-secrets.io/component: controller
  30733. name: mfas.generators.external-secrets.io
  30734. spec:
  30735. group: generators.external-secrets.io
  30736. names:
  30737. categories:
  30738. - external-secrets
  30739. - external-secrets-generators
  30740. kind: MFA
  30741. listKind: MFAList
  30742. plural: mfas
  30743. singular: mfa
  30744. scope: Namespaced
  30745. versions:
  30746. - name: v1alpha1
  30747. schema:
  30748. openAPIV3Schema:
  30749. description: MFA generates a new TOTP token that is compliant with RFC 6238.
  30750. properties:
  30751. apiVersion:
  30752. description: |-
  30753. APIVersion defines the versioned schema of this representation of an object.
  30754. Servers should convert recognized schemas to the latest internal value, and
  30755. may reject unrecognized values.
  30756. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30757. type: string
  30758. kind:
  30759. description: |-
  30760. Kind is a string value representing the REST resource this object represents.
  30761. Servers may infer this from the endpoint the client submits requests to.
  30762. Cannot be updated.
  30763. In CamelCase.
  30764. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30765. type: string
  30766. metadata:
  30767. type: object
  30768. spec:
  30769. description: MFASpec controls the behavior of the mfa generator.
  30770. properties:
  30771. algorithm:
  30772. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  30773. type: string
  30774. length:
  30775. description: Length defines the token length. Defaults to 6 characters.
  30776. type: integer
  30777. secret:
  30778. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  30779. properties:
  30780. key:
  30781. description: |-
  30782. A key in the referenced Secret.
  30783. Some instances of this field may be defaulted, in others it may be required.
  30784. maxLength: 253
  30785. minLength: 1
  30786. pattern: ^[-._a-zA-Z0-9]+$
  30787. type: string
  30788. name:
  30789. description: The name of the Secret resource being referred to.
  30790. maxLength: 253
  30791. minLength: 1
  30792. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30793. type: string
  30794. namespace:
  30795. description: |-
  30796. The namespace of the Secret resource being referred to.
  30797. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30798. maxLength: 63
  30799. minLength: 1
  30800. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30801. type: string
  30802. type: object
  30803. timePeriod:
  30804. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  30805. type: integer
  30806. when:
  30807. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  30808. format: date-time
  30809. type: string
  30810. required:
  30811. - secret
  30812. type: object
  30813. type: object
  30814. served: true
  30815. storage: true
  30816. subresources:
  30817. status: {}
  30818. ---
  30819. apiVersion: apiextensions.k8s.io/v1
  30820. kind: CustomResourceDefinition
  30821. metadata:
  30822. annotations:
  30823. controller-gen.kubebuilder.io/version: v0.19.0
  30824. labels:
  30825. external-secrets.io/component: controller
  30826. name: passwords.generators.external-secrets.io
  30827. spec:
  30828. group: generators.external-secrets.io
  30829. names:
  30830. categories:
  30831. - external-secrets
  30832. - external-secrets-generators
  30833. kind: Password
  30834. listKind: PasswordList
  30835. plural: passwords
  30836. singular: password
  30837. scope: Namespaced
  30838. versions:
  30839. - name: v1alpha1
  30840. schema:
  30841. openAPIV3Schema:
  30842. description: |-
  30843. Password generates a random password based on the
  30844. configuration parameters in spec.
  30845. You can specify the length, characterset and other attributes.
  30846. properties:
  30847. apiVersion:
  30848. description: |-
  30849. APIVersion defines the versioned schema of this representation of an object.
  30850. Servers should convert recognized schemas to the latest internal value, and
  30851. may reject unrecognized values.
  30852. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30853. type: string
  30854. kind:
  30855. description: |-
  30856. Kind is a string value representing the REST resource this object represents.
  30857. Servers may infer this from the endpoint the client submits requests to.
  30858. Cannot be updated.
  30859. In CamelCase.
  30860. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30861. type: string
  30862. metadata:
  30863. type: object
  30864. spec:
  30865. description: PasswordSpec controls the behavior of the password generator.
  30866. properties:
  30867. allowRepeat:
  30868. default: false
  30869. description: set AllowRepeat to true to allow repeating characters.
  30870. type: boolean
  30871. digits:
  30872. description: |-
  30873. Digits specifies the number of digits in the generated
  30874. password. If omitted it defaults to 25% of the length of the password
  30875. type: integer
  30876. encoding:
  30877. default: raw
  30878. description: |-
  30879. Encoding specifies the encoding of the generated password.
  30880. Valid values are:
  30881. - "raw" (default): no encoding
  30882. - "base64": standard base64 encoding
  30883. - "base64url": base64url encoding
  30884. - "base32": base32 encoding
  30885. - "hex": hexadecimal encoding
  30886. enum:
  30887. - base64
  30888. - base64url
  30889. - base32
  30890. - hex
  30891. - raw
  30892. type: string
  30893. length:
  30894. default: 24
  30895. description: |-
  30896. Length of the password to be generated.
  30897. Defaults to 24
  30898. type: integer
  30899. noUpper:
  30900. default: false
  30901. description: Set NoUpper to disable uppercase characters
  30902. type: boolean
  30903. secretKeys:
  30904. description: |-
  30905. SecretKeys defines the keys that will be populated with generated passwords.
  30906. Defaults to "password" when not set.
  30907. items:
  30908. type: string
  30909. minItems: 1
  30910. type: array
  30911. symbolCharacters:
  30912. description: |-
  30913. SymbolCharacters specifies the special characters that should be used
  30914. in the generated password.
  30915. type: string
  30916. symbols:
  30917. description: |-
  30918. Symbols specifies the number of symbol characters in the generated
  30919. password. If omitted it defaults to 25% of the length of the password
  30920. type: integer
  30921. required:
  30922. - allowRepeat
  30923. - length
  30924. - noUpper
  30925. type: object
  30926. type: object
  30927. served: true
  30928. storage: true
  30929. subresources:
  30930. status: {}
  30931. ---
  30932. apiVersion: apiextensions.k8s.io/v1
  30933. kind: CustomResourceDefinition
  30934. metadata:
  30935. annotations:
  30936. controller-gen.kubebuilder.io/version: v0.19.0
  30937. labels:
  30938. external-secrets.io/component: controller
  30939. name: quayaccesstokens.generators.external-secrets.io
  30940. spec:
  30941. group: generators.external-secrets.io
  30942. names:
  30943. categories:
  30944. - external-secrets
  30945. - external-secrets-generators
  30946. kind: QuayAccessToken
  30947. listKind: QuayAccessTokenList
  30948. plural: quayaccesstokens
  30949. singular: quayaccesstoken
  30950. scope: Namespaced
  30951. versions:
  30952. - name: v1alpha1
  30953. schema:
  30954. openAPIV3Schema:
  30955. description: QuayAccessToken generates Quay oauth token for pulling/pushing images
  30956. properties:
  30957. apiVersion:
  30958. description: |-
  30959. APIVersion defines the versioned schema of this representation of an object.
  30960. Servers should convert recognized schemas to the latest internal value, and
  30961. may reject unrecognized values.
  30962. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30963. type: string
  30964. kind:
  30965. description: |-
  30966. Kind is a string value representing the REST resource this object represents.
  30967. Servers may infer this from the endpoint the client submits requests to.
  30968. Cannot be updated.
  30969. In CamelCase.
  30970. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30971. type: string
  30972. metadata:
  30973. type: object
  30974. spec:
  30975. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  30976. properties:
  30977. robotAccount:
  30978. description: Name of the robot account you are federating with
  30979. type: string
  30980. serviceAccountRef:
  30981. description: Name of the service account you are federating with
  30982. properties:
  30983. audiences:
  30984. description: |-
  30985. Audience specifies the `aud` claim for the service account token
  30986. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30987. then this audiences will be appended to the list
  30988. items:
  30989. type: string
  30990. type: array
  30991. name:
  30992. description: The name of the ServiceAccount resource being referred to.
  30993. maxLength: 253
  30994. minLength: 1
  30995. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30996. type: string
  30997. namespace:
  30998. description: |-
  30999. Namespace of the resource being referred to.
  31000. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31001. maxLength: 63
  31002. minLength: 1
  31003. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31004. type: string
  31005. required:
  31006. - name
  31007. type: object
  31008. url:
  31009. description: URL configures the Quay instance URL. Defaults to quay.io.
  31010. type: string
  31011. required:
  31012. - robotAccount
  31013. - serviceAccountRef
  31014. type: object
  31015. type: object
  31016. served: true
  31017. storage: true
  31018. subresources:
  31019. status: {}
  31020. ---
  31021. apiVersion: apiextensions.k8s.io/v1
  31022. kind: CustomResourceDefinition
  31023. metadata:
  31024. annotations:
  31025. controller-gen.kubebuilder.io/version: v0.19.0
  31026. labels:
  31027. external-secrets.io/component: controller
  31028. name: sshkeys.generators.external-secrets.io
  31029. spec:
  31030. group: generators.external-secrets.io
  31031. names:
  31032. categories:
  31033. - external-secrets
  31034. - external-secrets-generators
  31035. kind: SSHKey
  31036. listKind: SSHKeyList
  31037. plural: sshkeys
  31038. singular: sshkey
  31039. scope: Namespaced
  31040. versions:
  31041. - name: v1alpha1
  31042. schema:
  31043. openAPIV3Schema:
  31044. description: SSHKey generates SSH key pairs.
  31045. properties:
  31046. apiVersion:
  31047. description: |-
  31048. APIVersion defines the versioned schema of this representation of an object.
  31049. Servers should convert recognized schemas to the latest internal value, and
  31050. may reject unrecognized values.
  31051. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31052. type: string
  31053. kind:
  31054. description: |-
  31055. Kind is a string value representing the REST resource this object represents.
  31056. Servers may infer this from the endpoint the client submits requests to.
  31057. Cannot be updated.
  31058. In CamelCase.
  31059. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31060. type: string
  31061. metadata:
  31062. type: object
  31063. spec:
  31064. description: SSHKeySpec controls the behavior of the ssh key generator.
  31065. properties:
  31066. comment:
  31067. description: Comment specifies an optional comment for the SSH key
  31068. type: string
  31069. keySize:
  31070. description: |-
  31071. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  31072. For RSA keys: 2048, 3072, 4096
  31073. For ECDSA keys: 256, 384, 521
  31074. Ignored for ed25519 keys
  31075. maximum: 8192
  31076. minimum: 256
  31077. type: integer
  31078. keyType:
  31079. default: rsa
  31080. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  31081. enum:
  31082. - rsa
  31083. - ecdsa
  31084. - ed25519
  31085. type: string
  31086. type: object
  31087. type: object
  31088. served: true
  31089. storage: true
  31090. subresources:
  31091. status: {}
  31092. ---
  31093. apiVersion: apiextensions.k8s.io/v1
  31094. kind: CustomResourceDefinition
  31095. metadata:
  31096. annotations:
  31097. controller-gen.kubebuilder.io/version: v0.19.0
  31098. labels:
  31099. external-secrets.io/component: controller
  31100. name: stssessiontokens.generators.external-secrets.io
  31101. spec:
  31102. group: generators.external-secrets.io
  31103. names:
  31104. categories:
  31105. - external-secrets
  31106. - external-secrets-generators
  31107. kind: STSSessionToken
  31108. listKind: STSSessionTokenList
  31109. plural: stssessiontokens
  31110. singular: stssessiontoken
  31111. scope: Namespaced
  31112. versions:
  31113. - name: v1alpha1
  31114. schema:
  31115. openAPIV3Schema:
  31116. description: |-
  31117. STSSessionToken uses the GetSessionToken API to retrieve an authorization token.
  31118. The authorization token is valid for 12 hours.
  31119. The authorizationToken returned is a base64 encoded string that can be decoded.
  31120. For more information, see GetSessionToken (https://docs.aws.amazon.com/STS/latest/APIReference/API_GetSessionToken.html).
  31121. properties:
  31122. apiVersion:
  31123. description: |-
  31124. APIVersion defines the versioned schema of this representation of an object.
  31125. Servers should convert recognized schemas to the latest internal value, and
  31126. may reject unrecognized values.
  31127. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31128. type: string
  31129. kind:
  31130. description: |-
  31131. Kind is a string value representing the REST resource this object represents.
  31132. Servers may infer this from the endpoint the client submits requests to.
  31133. Cannot be updated.
  31134. In CamelCase.
  31135. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31136. type: string
  31137. metadata:
  31138. type: object
  31139. spec:
  31140. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  31141. properties:
  31142. auth:
  31143. description: Auth defines how to authenticate with AWS
  31144. properties:
  31145. jwt:
  31146. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  31147. properties:
  31148. serviceAccountRef:
  31149. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31150. properties:
  31151. audiences:
  31152. description: |-
  31153. Audience specifies the `aud` claim for the service account token
  31154. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31155. then this audiences will be appended to the list
  31156. items:
  31157. type: string
  31158. type: array
  31159. name:
  31160. description: The name of the ServiceAccount resource being referred to.
  31161. maxLength: 253
  31162. minLength: 1
  31163. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31164. type: string
  31165. namespace:
  31166. description: |-
  31167. Namespace of the resource being referred to.
  31168. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31169. maxLength: 63
  31170. minLength: 1
  31171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31172. type: string
  31173. required:
  31174. - name
  31175. type: object
  31176. type: object
  31177. secretRef:
  31178. description: |-
  31179. AWSAuthSecretRef holds secret references for AWS credentials
  31180. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  31181. properties:
  31182. accessKeyIDSecretRef:
  31183. description: The AccessKeyID is used for authentication
  31184. properties:
  31185. key:
  31186. description: |-
  31187. A key in the referenced Secret.
  31188. Some instances of this field may be defaulted, in others it may be required.
  31189. maxLength: 253
  31190. minLength: 1
  31191. pattern: ^[-._a-zA-Z0-9]+$
  31192. type: string
  31193. name:
  31194. description: The name of the Secret resource being referred to.
  31195. maxLength: 253
  31196. minLength: 1
  31197. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31198. type: string
  31199. namespace:
  31200. description: |-
  31201. The namespace of the Secret resource being referred to.
  31202. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31203. maxLength: 63
  31204. minLength: 1
  31205. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31206. type: string
  31207. type: object
  31208. secretAccessKeySecretRef:
  31209. description: The SecretAccessKey is used for authentication
  31210. properties:
  31211. key:
  31212. description: |-
  31213. A key in the referenced Secret.
  31214. Some instances of this field may be defaulted, in others it may be required.
  31215. maxLength: 253
  31216. minLength: 1
  31217. pattern: ^[-._a-zA-Z0-9]+$
  31218. type: string
  31219. name:
  31220. description: The name of the Secret resource being referred to.
  31221. maxLength: 253
  31222. minLength: 1
  31223. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31224. type: string
  31225. namespace:
  31226. description: |-
  31227. The namespace of the Secret resource being referred to.
  31228. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31229. maxLength: 63
  31230. minLength: 1
  31231. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31232. type: string
  31233. type: object
  31234. sessionTokenSecretRef:
  31235. description: |-
  31236. The SessionToken used for authentication
  31237. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  31238. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  31239. properties:
  31240. key:
  31241. description: |-
  31242. A key in the referenced Secret.
  31243. Some instances of this field may be defaulted, in others it may be required.
  31244. maxLength: 253
  31245. minLength: 1
  31246. pattern: ^[-._a-zA-Z0-9]+$
  31247. type: string
  31248. name:
  31249. description: The name of the Secret resource being referred to.
  31250. maxLength: 253
  31251. minLength: 1
  31252. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31253. type: string
  31254. namespace:
  31255. description: |-
  31256. The namespace of the Secret resource being referred to.
  31257. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31258. maxLength: 63
  31259. minLength: 1
  31260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31261. type: string
  31262. type: object
  31263. type: object
  31264. type: object
  31265. region:
  31266. description: Region specifies the region to operate in.
  31267. type: string
  31268. requestParameters:
  31269. description: RequestParameters contains parameters that can be passed to the STS service.
  31270. properties:
  31271. serialNumber:
  31272. description: |-
  31273. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  31274. the GetSessionToken call.
  31275. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  31276. (such as arn:aws:iam::123456789012:mfa/user)
  31277. type: string
  31278. sessionDuration:
  31279. format: int32
  31280. type: integer
  31281. tokenCode:
  31282. description: TokenCode is the value provided by the MFA device, if MFA is required.
  31283. type: string
  31284. type: object
  31285. role:
  31286. description: |-
  31287. You can assume a role before making calls to the
  31288. desired AWS service.
  31289. type: string
  31290. required:
  31291. - region
  31292. type: object
  31293. type: object
  31294. served: true
  31295. storage: true
  31296. subresources:
  31297. status: {}
  31298. ---
  31299. apiVersion: apiextensions.k8s.io/v1
  31300. kind: CustomResourceDefinition
  31301. metadata:
  31302. annotations:
  31303. controller-gen.kubebuilder.io/version: v0.19.0
  31304. labels:
  31305. external-secrets.io/component: controller
  31306. name: uuids.generators.external-secrets.io
  31307. spec:
  31308. group: generators.external-secrets.io
  31309. names:
  31310. categories:
  31311. - external-secrets
  31312. - external-secrets-generators
  31313. kind: UUID
  31314. listKind: UUIDList
  31315. plural: uuids
  31316. singular: uuid
  31317. scope: Namespaced
  31318. versions:
  31319. - name: v1alpha1
  31320. schema:
  31321. openAPIV3Schema:
  31322. description: UUID generates a version 1 UUID (e56657e3-764f-11ef-a397-65231a88c216).
  31323. properties:
  31324. apiVersion:
  31325. description: |-
  31326. APIVersion defines the versioned schema of this representation of an object.
  31327. Servers should convert recognized schemas to the latest internal value, and
  31328. may reject unrecognized values.
  31329. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31330. type: string
  31331. kind:
  31332. description: |-
  31333. Kind is a string value representing the REST resource this object represents.
  31334. Servers may infer this from the endpoint the client submits requests to.
  31335. Cannot be updated.
  31336. In CamelCase.
  31337. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31338. type: string
  31339. metadata:
  31340. type: object
  31341. spec:
  31342. description: UUIDSpec controls the behavior of the uuid generator.
  31343. type: object
  31344. type: object
  31345. served: true
  31346. storage: true
  31347. subresources:
  31348. status: {}
  31349. ---
  31350. apiVersion: apiextensions.k8s.io/v1
  31351. kind: CustomResourceDefinition
  31352. metadata:
  31353. annotations:
  31354. controller-gen.kubebuilder.io/version: v0.19.0
  31355. labels:
  31356. external-secrets.io/component: controller
  31357. name: vaultdynamicsecrets.generators.external-secrets.io
  31358. spec:
  31359. group: generators.external-secrets.io
  31360. names:
  31361. categories:
  31362. - external-secrets
  31363. - external-secrets-generators
  31364. kind: VaultDynamicSecret
  31365. listKind: VaultDynamicSecretList
  31366. plural: vaultdynamicsecrets
  31367. singular: vaultdynamicsecret
  31368. scope: Namespaced
  31369. versions:
  31370. - name: v1alpha1
  31371. schema:
  31372. openAPIV3Schema:
  31373. description: VaultDynamicSecret represents a generator that can create dynamic secrets from HashiCorp Vault.
  31374. properties:
  31375. apiVersion:
  31376. description: |-
  31377. APIVersion defines the versioned schema of this representation of an object.
  31378. Servers should convert recognized schemas to the latest internal value, and
  31379. may reject unrecognized values.
  31380. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31381. type: string
  31382. kind:
  31383. description: |-
  31384. Kind is a string value representing the REST resource this object represents.
  31385. Servers may infer this from the endpoint the client submits requests to.
  31386. Cannot be updated.
  31387. In CamelCase.
  31388. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31389. type: string
  31390. metadata:
  31391. type: object
  31392. spec:
  31393. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  31394. properties:
  31395. allowEmptyResponse:
  31396. default: false
  31397. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  31398. type: boolean
  31399. controller:
  31400. description: |-
  31401. Used to select the correct ESO controller (think: ingress.ingressClassName)
  31402. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  31403. type: string
  31404. getParameters:
  31405. additionalProperties:
  31406. items:
  31407. type: string
  31408. type: array
  31409. description: |-
  31410. GetParameters are query-string parameters passed to Vault on GET calls.
  31411. Each key may map to multiple values, matching HTTP query-string semantics.
  31412. Ignored for non-GET methods; use Parameters for write bodies.
  31413. type: object
  31414. method:
  31415. description: Vault API method to use (GET/POST/other)
  31416. type: string
  31417. parameters:
  31418. description: Parameters to pass to Vault write (for non-GET methods)
  31419. x-kubernetes-preserve-unknown-fields: true
  31420. path:
  31421. description: Vault path to obtain the dynamic secret from
  31422. type: string
  31423. provider:
  31424. description: Vault provider common spec
  31425. properties:
  31426. auth:
  31427. description: Auth configures how secret-manager authenticates with the Vault server.
  31428. properties:
  31429. appRole:
  31430. description: |-
  31431. AppRole authenticates with Vault using the App Role auth mechanism,
  31432. with the role and secret stored in a Kubernetes Secret resource.
  31433. properties:
  31434. path:
  31435. default: approle
  31436. description: |-
  31437. Path where the App Role authentication backend is mounted
  31438. in Vault, e.g: "approle"
  31439. type: string
  31440. roleId:
  31441. description: |-
  31442. RoleID configured in the App Role authentication backend when setting
  31443. up the authentication backend in Vault.
  31444. type: string
  31445. roleRef:
  31446. description: |-
  31447. Reference to a key in a Secret that contains the App Role ID used
  31448. to authenticate with Vault.
  31449. The `key` field must be specified and denotes which entry within the Secret
  31450. resource is used as the app role id.
  31451. properties:
  31452. key:
  31453. description: |-
  31454. A key in the referenced Secret.
  31455. Some instances of this field may be defaulted, in others it may be required.
  31456. maxLength: 253
  31457. minLength: 1
  31458. pattern: ^[-._a-zA-Z0-9]+$
  31459. type: string
  31460. name:
  31461. description: The name of the Secret resource being referred to.
  31462. maxLength: 253
  31463. minLength: 1
  31464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31465. type: string
  31466. namespace:
  31467. description: |-
  31468. The namespace of the Secret resource being referred to.
  31469. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31470. maxLength: 63
  31471. minLength: 1
  31472. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31473. type: string
  31474. type: object
  31475. secretRef:
  31476. description: |-
  31477. Reference to a key in a Secret that contains the App Role secret used
  31478. to authenticate with Vault.
  31479. The `key` field must be specified and denotes which entry within the Secret
  31480. resource is used as the app role secret.
  31481. properties:
  31482. key:
  31483. description: |-
  31484. A key in the referenced Secret.
  31485. Some instances of this field may be defaulted, in others it may be required.
  31486. maxLength: 253
  31487. minLength: 1
  31488. pattern: ^[-._a-zA-Z0-9]+$
  31489. type: string
  31490. name:
  31491. description: The name of the Secret resource being referred to.
  31492. maxLength: 253
  31493. minLength: 1
  31494. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31495. type: string
  31496. namespace:
  31497. description: |-
  31498. The namespace of the Secret resource being referred to.
  31499. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31500. maxLength: 63
  31501. minLength: 1
  31502. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31503. type: string
  31504. type: object
  31505. required:
  31506. - path
  31507. - secretRef
  31508. type: object
  31509. cert:
  31510. description: |-
  31511. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  31512. Cert authentication method
  31513. properties:
  31514. clientCert:
  31515. description: |-
  31516. ClientCert is a certificate to authenticate using the Cert Vault
  31517. authentication method
  31518. properties:
  31519. key:
  31520. description: |-
  31521. A key in the referenced Secret.
  31522. Some instances of this field may be defaulted, in others it may be required.
  31523. maxLength: 253
  31524. minLength: 1
  31525. pattern: ^[-._a-zA-Z0-9]+$
  31526. type: string
  31527. name:
  31528. description: The name of the Secret resource being referred to.
  31529. maxLength: 253
  31530. minLength: 1
  31531. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31532. type: string
  31533. namespace:
  31534. description: |-
  31535. The namespace of the Secret resource being referred to.
  31536. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31537. maxLength: 63
  31538. minLength: 1
  31539. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31540. type: string
  31541. type: object
  31542. path:
  31543. default: cert
  31544. description: |-
  31545. Path where the Certificate authentication backend is mounted
  31546. in Vault, e.g: "cert"
  31547. type: string
  31548. secretRef:
  31549. description: |-
  31550. SecretRef to a key in a Secret resource containing client private key to
  31551. authenticate with Vault using the Cert authentication method
  31552. properties:
  31553. key:
  31554. description: |-
  31555. A key in the referenced Secret.
  31556. Some instances of this field may be defaulted, in others it may be required.
  31557. maxLength: 253
  31558. minLength: 1
  31559. pattern: ^[-._a-zA-Z0-9]+$
  31560. type: string
  31561. name:
  31562. description: The name of the Secret resource being referred to.
  31563. maxLength: 253
  31564. minLength: 1
  31565. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31566. type: string
  31567. namespace:
  31568. description: |-
  31569. The namespace of the Secret resource being referred to.
  31570. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31571. maxLength: 63
  31572. minLength: 1
  31573. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31574. type: string
  31575. type: object
  31576. vaultRole:
  31577. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  31578. type: string
  31579. type: object
  31580. gcp:
  31581. description: |-
  31582. Gcp authenticates with Vault using Google Cloud Platform authentication method
  31583. GCP authentication method
  31584. properties:
  31585. location:
  31586. description: Location optionally defines a location/region for the secret
  31587. type: string
  31588. path:
  31589. default: gcp
  31590. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  31591. type: string
  31592. projectID:
  31593. description: Project ID of the Google Cloud Platform project
  31594. type: string
  31595. role:
  31596. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  31597. type: string
  31598. secretRef:
  31599. description: Specify credentials in a Secret object
  31600. properties:
  31601. secretAccessKeySecretRef:
  31602. description: The SecretAccessKey is used for authentication
  31603. properties:
  31604. key:
  31605. description: |-
  31606. A key in the referenced Secret.
  31607. Some instances of this field may be defaulted, in others it may be required.
  31608. maxLength: 253
  31609. minLength: 1
  31610. pattern: ^[-._a-zA-Z0-9]+$
  31611. type: string
  31612. name:
  31613. description: The name of the Secret resource being referred to.
  31614. maxLength: 253
  31615. minLength: 1
  31616. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31617. type: string
  31618. namespace:
  31619. description: |-
  31620. The namespace of the Secret resource being referred to.
  31621. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31622. maxLength: 63
  31623. minLength: 1
  31624. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31625. type: string
  31626. type: object
  31627. type: object
  31628. serviceAccountRef:
  31629. description: ServiceAccountRef to a service account for impersonation
  31630. properties:
  31631. audiences:
  31632. description: |-
  31633. Audience specifies the `aud` claim for the service account token
  31634. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31635. then this audiences will be appended to the list
  31636. items:
  31637. type: string
  31638. type: array
  31639. name:
  31640. description: The name of the ServiceAccount resource being referred to.
  31641. maxLength: 253
  31642. minLength: 1
  31643. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31644. type: string
  31645. namespace:
  31646. description: |-
  31647. Namespace of the resource being referred to.
  31648. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31649. maxLength: 63
  31650. minLength: 1
  31651. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31652. type: string
  31653. required:
  31654. - name
  31655. type: object
  31656. workloadIdentity:
  31657. description: Specify a service account with Workload Identity
  31658. properties:
  31659. clusterLocation:
  31660. description: |-
  31661. ClusterLocation is the location of the cluster
  31662. If not specified, it fetches information from the metadata server
  31663. type: string
  31664. clusterName:
  31665. description: |-
  31666. ClusterName is the name of the cluster
  31667. If not specified, it fetches information from the metadata server
  31668. type: string
  31669. clusterProjectID:
  31670. description: |-
  31671. ClusterProjectID is the project ID of the cluster
  31672. If not specified, it fetches information from the metadata server
  31673. type: string
  31674. serviceAccountRef:
  31675. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31676. properties:
  31677. audiences:
  31678. description: |-
  31679. Audience specifies the `aud` claim for the service account token
  31680. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31681. then this audiences will be appended to the list
  31682. items:
  31683. type: string
  31684. type: array
  31685. name:
  31686. description: The name of the ServiceAccount resource being referred to.
  31687. maxLength: 253
  31688. minLength: 1
  31689. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31690. type: string
  31691. namespace:
  31692. description: |-
  31693. Namespace of the resource being referred to.
  31694. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31695. maxLength: 63
  31696. minLength: 1
  31697. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31698. type: string
  31699. required:
  31700. - name
  31701. type: object
  31702. required:
  31703. - serviceAccountRef
  31704. type: object
  31705. required:
  31706. - role
  31707. type: object
  31708. iam:
  31709. description: |-
  31710. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  31711. AWS IAM authentication method
  31712. properties:
  31713. externalID:
  31714. description: AWS External ID set on assumed IAM roles
  31715. type: string
  31716. jwt:
  31717. description: Specify a service account with IRSA enabled
  31718. properties:
  31719. serviceAccountRef:
  31720. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31721. properties:
  31722. audiences:
  31723. description: |-
  31724. Audience specifies the `aud` claim for the service account token
  31725. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31726. then this audiences will be appended to the list
  31727. items:
  31728. type: string
  31729. type: array
  31730. name:
  31731. description: The name of the ServiceAccount resource being referred to.
  31732. maxLength: 253
  31733. minLength: 1
  31734. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31735. type: string
  31736. namespace:
  31737. description: |-
  31738. Namespace of the resource being referred to.
  31739. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31740. maxLength: 63
  31741. minLength: 1
  31742. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31743. type: string
  31744. required:
  31745. - name
  31746. type: object
  31747. type: object
  31748. path:
  31749. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  31750. type: string
  31751. region:
  31752. description: AWS region
  31753. type: string
  31754. role:
  31755. description: This is the AWS role to be assumed before talking to vault
  31756. type: string
  31757. secretRef:
  31758. description: Specify credentials in a Secret object
  31759. properties:
  31760. accessKeyIDSecretRef:
  31761. description: The AccessKeyID is used for authentication
  31762. properties:
  31763. key:
  31764. description: |-
  31765. A key in the referenced Secret.
  31766. Some instances of this field may be defaulted, in others it may be required.
  31767. maxLength: 253
  31768. minLength: 1
  31769. pattern: ^[-._a-zA-Z0-9]+$
  31770. type: string
  31771. name:
  31772. description: The name of the Secret resource being referred to.
  31773. maxLength: 253
  31774. minLength: 1
  31775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31776. type: string
  31777. namespace:
  31778. description: |-
  31779. The namespace of the Secret resource being referred to.
  31780. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31781. maxLength: 63
  31782. minLength: 1
  31783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31784. type: string
  31785. type: object
  31786. secretAccessKeySecretRef:
  31787. description: The SecretAccessKey is used for authentication
  31788. properties:
  31789. key:
  31790. description: |-
  31791. A key in the referenced Secret.
  31792. Some instances of this field may be defaulted, in others it may be required.
  31793. maxLength: 253
  31794. minLength: 1
  31795. pattern: ^[-._a-zA-Z0-9]+$
  31796. type: string
  31797. name:
  31798. description: The name of the Secret resource being referred to.
  31799. maxLength: 253
  31800. minLength: 1
  31801. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31802. type: string
  31803. namespace:
  31804. description: |-
  31805. The namespace of the Secret resource being referred to.
  31806. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31807. maxLength: 63
  31808. minLength: 1
  31809. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31810. type: string
  31811. type: object
  31812. sessionTokenSecretRef:
  31813. description: |-
  31814. The SessionToken used for authentication
  31815. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  31816. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  31817. properties:
  31818. key:
  31819. description: |-
  31820. A key in the referenced Secret.
  31821. Some instances of this field may be defaulted, in others it may be required.
  31822. maxLength: 253
  31823. minLength: 1
  31824. pattern: ^[-._a-zA-Z0-9]+$
  31825. type: string
  31826. name:
  31827. description: The name of the Secret resource being referred to.
  31828. maxLength: 253
  31829. minLength: 1
  31830. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31831. type: string
  31832. namespace:
  31833. description: |-
  31834. The namespace of the Secret resource being referred to.
  31835. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31836. maxLength: 63
  31837. minLength: 1
  31838. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31839. type: string
  31840. type: object
  31841. type: object
  31842. vaultAwsIamServerID:
  31843. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  31844. type: string
  31845. vaultRole:
  31846. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  31847. type: string
  31848. required:
  31849. - vaultRole
  31850. type: object
  31851. jwt:
  31852. description: |-
  31853. Jwt authenticates with Vault by passing role and JWT token using the
  31854. JWT/OIDC authentication method
  31855. properties:
  31856. kubernetesServiceAccountToken:
  31857. description: |-
  31858. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  31859. a token for with the `TokenRequest` API.
  31860. properties:
  31861. audiences:
  31862. description: |-
  31863. Optional audiences field that will be used to request a temporary Kubernetes service
  31864. account token for the service account referenced by `serviceAccountRef`.
  31865. Defaults to a single audience `vault` it not specified.
  31866. Deprecated: use serviceAccountRef.Audiences instead
  31867. items:
  31868. type: string
  31869. type: array
  31870. expirationSeconds:
  31871. description: |-
  31872. Optional expiration time in seconds that will be used to request a temporary
  31873. Kubernetes service account token for the service account referenced by
  31874. `serviceAccountRef`.
  31875. Deprecated: this will be removed in the future.
  31876. Defaults to 10 minutes.
  31877. format: int64
  31878. type: integer
  31879. serviceAccountRef:
  31880. description: Service account field containing the name of a kubernetes ServiceAccount.
  31881. properties:
  31882. audiences:
  31883. description: |-
  31884. Audience specifies the `aud` claim for the service account token
  31885. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31886. then this audiences will be appended to the list
  31887. items:
  31888. type: string
  31889. type: array
  31890. name:
  31891. description: The name of the ServiceAccount resource being referred to.
  31892. maxLength: 253
  31893. minLength: 1
  31894. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31895. type: string
  31896. namespace:
  31897. description: |-
  31898. Namespace of the resource being referred to.
  31899. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31900. maxLength: 63
  31901. minLength: 1
  31902. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31903. type: string
  31904. required:
  31905. - name
  31906. type: object
  31907. required:
  31908. - serviceAccountRef
  31909. type: object
  31910. path:
  31911. default: jwt
  31912. description: |-
  31913. Path where the JWT authentication backend is mounted
  31914. in Vault, e.g: "jwt"
  31915. type: string
  31916. role:
  31917. description: |-
  31918. Role is a JWT role to authenticate using the JWT/OIDC Vault
  31919. authentication method
  31920. type: string
  31921. secretRef:
  31922. description: |-
  31923. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  31924. authenticate with Vault using the JWT/OIDC authentication method.
  31925. properties:
  31926. key:
  31927. description: |-
  31928. A key in the referenced Secret.
  31929. Some instances of this field may be defaulted, in others it may be required.
  31930. maxLength: 253
  31931. minLength: 1
  31932. pattern: ^[-._a-zA-Z0-9]+$
  31933. type: string
  31934. name:
  31935. description: The name of the Secret resource being referred to.
  31936. maxLength: 253
  31937. minLength: 1
  31938. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31939. type: string
  31940. namespace:
  31941. description: |-
  31942. The namespace of the Secret resource being referred to.
  31943. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31944. maxLength: 63
  31945. minLength: 1
  31946. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31947. type: string
  31948. type: object
  31949. required:
  31950. - path
  31951. type: object
  31952. kubernetes:
  31953. description: |-
  31954. Kubernetes authenticates with Vault by passing the ServiceAccount
  31955. token stored in the named Secret resource to the Vault server.
  31956. properties:
  31957. mountPath:
  31958. default: kubernetes
  31959. description: |-
  31960. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  31961. "kubernetes"
  31962. type: string
  31963. role:
  31964. description: |-
  31965. A required field containing the Vault Role to assume. A Role binds a
  31966. Kubernetes ServiceAccount with a set of Vault policies.
  31967. type: string
  31968. secretRef:
  31969. description: |-
  31970. Optional secret field containing a Kubernetes ServiceAccount JWT used
  31971. for authenticating with Vault. If a name is specified without a key,
  31972. `token` is the default. If one is not specified, the one bound to
  31973. the controller will be used.
  31974. properties:
  31975. key:
  31976. description: |-
  31977. A key in the referenced Secret.
  31978. Some instances of this field may be defaulted, in others it may be required.
  31979. maxLength: 253
  31980. minLength: 1
  31981. pattern: ^[-._a-zA-Z0-9]+$
  31982. type: string
  31983. name:
  31984. description: The name of the Secret resource being referred to.
  31985. maxLength: 253
  31986. minLength: 1
  31987. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31988. type: string
  31989. namespace:
  31990. description: |-
  31991. The namespace of the Secret resource being referred to.
  31992. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31993. maxLength: 63
  31994. minLength: 1
  31995. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31996. type: string
  31997. type: object
  31998. serviceAccountRef:
  31999. description: |-
  32000. Optional service account field containing the name of a kubernetes ServiceAccount.
  32001. If the service account is specified, the service account secret token JWT will be used
  32002. for authenticating with Vault. If the service account selector is not supplied,
  32003. the secretRef will be used instead.
  32004. properties:
  32005. audiences:
  32006. description: |-
  32007. Audience specifies the `aud` claim for the service account token
  32008. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  32009. then this audiences will be appended to the list
  32010. items:
  32011. type: string
  32012. type: array
  32013. name:
  32014. description: The name of the ServiceAccount resource being referred to.
  32015. maxLength: 253
  32016. minLength: 1
  32017. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32018. type: string
  32019. namespace:
  32020. description: |-
  32021. Namespace of the resource being referred to.
  32022. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32023. maxLength: 63
  32024. minLength: 1
  32025. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32026. type: string
  32027. required:
  32028. - name
  32029. type: object
  32030. required:
  32031. - mountPath
  32032. - role
  32033. type: object
  32034. ldap:
  32035. description: |-
  32036. Ldap authenticates with Vault by passing username/password pair using
  32037. the LDAP authentication method
  32038. properties:
  32039. path:
  32040. default: ldap
  32041. description: |-
  32042. Path where the LDAP authentication backend is mounted
  32043. in Vault, e.g: "ldap"
  32044. type: string
  32045. secretRef:
  32046. description: |-
  32047. SecretRef to a key in a Secret resource containing password for the LDAP
  32048. user used to authenticate with Vault using the LDAP authentication
  32049. method
  32050. properties:
  32051. key:
  32052. description: |-
  32053. A key in the referenced Secret.
  32054. Some instances of this field may be defaulted, in others it may be required.
  32055. maxLength: 253
  32056. minLength: 1
  32057. pattern: ^[-._a-zA-Z0-9]+$
  32058. type: string
  32059. name:
  32060. description: The name of the Secret resource being referred to.
  32061. maxLength: 253
  32062. minLength: 1
  32063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32064. type: string
  32065. namespace:
  32066. description: |-
  32067. The namespace of the Secret resource being referred to.
  32068. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32069. maxLength: 63
  32070. minLength: 1
  32071. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32072. type: string
  32073. type: object
  32074. username:
  32075. description: |-
  32076. Username is an LDAP username used to authenticate using the LDAP Vault
  32077. authentication method
  32078. type: string
  32079. required:
  32080. - path
  32081. - username
  32082. type: object
  32083. namespace:
  32084. description: |-
  32085. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  32086. Namespaces is a set of features within Vault Enterprise that allows
  32087. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  32088. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  32089. This will default to Vault.Namespace field if set, or empty otherwise
  32090. type: string
  32091. tokenSecretRef:
  32092. description: TokenSecretRef authenticates with Vault by presenting a token.
  32093. properties:
  32094. key:
  32095. description: |-
  32096. A key in the referenced Secret.
  32097. Some instances of this field may be defaulted, in others it may be required.
  32098. maxLength: 253
  32099. minLength: 1
  32100. pattern: ^[-._a-zA-Z0-9]+$
  32101. type: string
  32102. name:
  32103. description: The name of the Secret resource being referred to.
  32104. maxLength: 253
  32105. minLength: 1
  32106. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32107. type: string
  32108. namespace:
  32109. description: |-
  32110. The namespace of the Secret resource being referred to.
  32111. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32112. maxLength: 63
  32113. minLength: 1
  32114. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32115. type: string
  32116. type: object
  32117. userPass:
  32118. description: UserPass authenticates with Vault by passing username/password pair
  32119. properties:
  32120. path:
  32121. default: userpass
  32122. description: |-
  32123. Path where the UserPassword authentication backend is mounted
  32124. in Vault, e.g: "userpass"
  32125. type: string
  32126. secretRef:
  32127. description: |-
  32128. SecretRef to a key in a Secret resource containing password for the
  32129. user used to authenticate with Vault using the UserPass authentication
  32130. method
  32131. properties:
  32132. key:
  32133. description: |-
  32134. A key in the referenced Secret.
  32135. Some instances of this field may be defaulted, in others it may be required.
  32136. maxLength: 253
  32137. minLength: 1
  32138. pattern: ^[-._a-zA-Z0-9]+$
  32139. type: string
  32140. name:
  32141. description: The name of the Secret resource being referred to.
  32142. maxLength: 253
  32143. minLength: 1
  32144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32145. type: string
  32146. namespace:
  32147. description: |-
  32148. The namespace of the Secret resource being referred to.
  32149. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32150. maxLength: 63
  32151. minLength: 1
  32152. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32153. type: string
  32154. type: object
  32155. username:
  32156. description: |-
  32157. Username is a username used to authenticate using the UserPass Vault
  32158. authentication method
  32159. type: string
  32160. required:
  32161. - path
  32162. - username
  32163. type: object
  32164. type: object
  32165. caBundle:
  32166. description: |-
  32167. PEM encoded CA bundle used to validate Vault server certificate. Only used
  32168. if the Server URL is using HTTPS protocol. This parameter is ignored for
  32169. plain HTTP protocol connection. If not set the system root certificates
  32170. are used to validate the TLS connection.
  32171. format: byte
  32172. type: string
  32173. caProvider:
  32174. description: The provider for the CA bundle to use to validate Vault server certificate.
  32175. properties:
  32176. key:
  32177. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  32178. maxLength: 253
  32179. minLength: 1
  32180. pattern: ^[-._a-zA-Z0-9]+$
  32181. type: string
  32182. name:
  32183. description: The name of the object located at the provider type.
  32184. maxLength: 253
  32185. minLength: 1
  32186. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32187. type: string
  32188. namespace:
  32189. description: |-
  32190. The namespace the Provider type is in.
  32191. Can only be defined when used in a ClusterSecretStore.
  32192. maxLength: 63
  32193. minLength: 1
  32194. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32195. type: string
  32196. type:
  32197. description: The type of provider to use such as "Secret", or "ConfigMap".
  32198. enum:
  32199. - Secret
  32200. - ConfigMap
  32201. type: string
  32202. required:
  32203. - name
  32204. - type
  32205. type: object
  32206. checkAndSet:
  32207. description: |-
  32208. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  32209. Only applies to Vault KV v2 stores. When enabled, write operations must include
  32210. the current version of the secret to prevent unintentional overwrites.
  32211. properties:
  32212. required:
  32213. description: |-
  32214. Required when true, all write operations must include a check-and-set parameter.
  32215. This helps prevent unintentional overwrites of secrets.
  32216. type: boolean
  32217. type: object
  32218. forwardInconsistent:
  32219. description: |-
  32220. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  32221. leader instead of simply retrying within a loop. This can increase performance if
  32222. the option is enabled serverside.
  32223. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  32224. type: boolean
  32225. headers:
  32226. additionalProperties:
  32227. type: string
  32228. description: Headers to be added in Vault request
  32229. type: object
  32230. namespace:
  32231. description: |-
  32232. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  32233. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  32234. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  32235. type: string
  32236. path:
  32237. description: |-
  32238. Path is the mount path of the Vault KV backend endpoint, e.g:
  32239. "secret". The v2 KV secret engine version specific "/data" path suffix
  32240. for fetching secrets from Vault is optional and will be appended
  32241. if not present in specified path.
  32242. type: string
  32243. readYourWrites:
  32244. description: |-
  32245. ReadYourWrites ensures isolated read-after-write semantics by
  32246. providing discovered cluster replication states in each request.
  32247. More information about eventual consistency in Vault can be found here
  32248. https://www.vaultproject.io/docs/enterprise/consistency
  32249. type: boolean
  32250. server:
  32251. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  32252. type: string
  32253. tls:
  32254. description: |-
  32255. The configuration used for client side related TLS communication, when the Vault server
  32256. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  32257. This parameter is ignored for plain HTTP protocol connection.
  32258. It's worth noting this configuration is different from the "TLS certificates auth method",
  32259. which is available under the `auth.cert` section.
  32260. properties:
  32261. certSecretRef:
  32262. description: |-
  32263. CertSecretRef is a certificate added to the transport layer
  32264. when communicating with the Vault server.
  32265. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  32266. properties:
  32267. key:
  32268. description: |-
  32269. A key in the referenced Secret.
  32270. Some instances of this field may be defaulted, in others it may be required.
  32271. maxLength: 253
  32272. minLength: 1
  32273. pattern: ^[-._a-zA-Z0-9]+$
  32274. type: string
  32275. name:
  32276. description: The name of the Secret resource being referred to.
  32277. maxLength: 253
  32278. minLength: 1
  32279. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32280. type: string
  32281. namespace:
  32282. description: |-
  32283. The namespace of the Secret resource being referred to.
  32284. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32285. maxLength: 63
  32286. minLength: 1
  32287. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32288. type: string
  32289. type: object
  32290. keySecretRef:
  32291. description: |-
  32292. KeySecretRef to a key in a Secret resource containing client private key
  32293. added to the transport layer when communicating with the Vault server.
  32294. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  32295. properties:
  32296. key:
  32297. description: |-
  32298. A key in the referenced Secret.
  32299. Some instances of this field may be defaulted, in others it may be required.
  32300. maxLength: 253
  32301. minLength: 1
  32302. pattern: ^[-._a-zA-Z0-9]+$
  32303. type: string
  32304. name:
  32305. description: The name of the Secret resource being referred to.
  32306. maxLength: 253
  32307. minLength: 1
  32308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32309. type: string
  32310. namespace:
  32311. description: |-
  32312. The namespace of the Secret resource being referred to.
  32313. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32314. maxLength: 63
  32315. minLength: 1
  32316. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32317. type: string
  32318. type: object
  32319. type: object
  32320. version:
  32321. default: v2
  32322. description: |-
  32323. Version is the Vault KV secret engine version. This can be either "v1" or
  32324. "v2". Version defaults to "v2".
  32325. enum:
  32326. - v1
  32327. - v2
  32328. type: string
  32329. required:
  32330. - server
  32331. type: object
  32332. resultType:
  32333. default: Data
  32334. description: |-
  32335. Result type defines which data is returned from the generator.
  32336. By default, it is the "data" section of the Vault API response.
  32337. When using e.g. /auth/token/create the "data" section is empty but
  32338. the "auth" section contains the generated token.
  32339. Please refer to the vault docs regarding the result data structure.
  32340. Additionally, accessing the raw response is possibly by using "Raw" result type.
  32341. enum:
  32342. - Data
  32343. - Auth
  32344. - Raw
  32345. type: string
  32346. retrySettings:
  32347. description: Used to configure http retries if failed
  32348. properties:
  32349. maxRetries:
  32350. format: int32
  32351. type: integer
  32352. retryInterval:
  32353. type: string
  32354. type: object
  32355. required:
  32356. - path
  32357. - provider
  32358. type: object
  32359. type: object
  32360. served: true
  32361. storage: true
  32362. subresources:
  32363. status: {}
  32364. ---
  32365. apiVersion: apiextensions.k8s.io/v1
  32366. kind: CustomResourceDefinition
  32367. metadata:
  32368. annotations:
  32369. controller-gen.kubebuilder.io/version: v0.19.0
  32370. labels:
  32371. external-secrets.io/component: controller
  32372. name: webhooks.generators.external-secrets.io
  32373. spec:
  32374. group: generators.external-secrets.io
  32375. names:
  32376. categories:
  32377. - external-secrets
  32378. - external-secrets-generators
  32379. kind: Webhook
  32380. listKind: WebhookList
  32381. plural: webhooks
  32382. singular: webhook
  32383. scope: Namespaced
  32384. versions:
  32385. - name: v1alpha1
  32386. schema:
  32387. openAPIV3Schema:
  32388. description: |-
  32389. Webhook connects to a third party API server to handle the secrets generation
  32390. configuration parameters in spec.
  32391. You can specify the server, the token, and additional body parameters.
  32392. See documentation for the full API specification for requests and responses.
  32393. properties:
  32394. apiVersion:
  32395. description: |-
  32396. APIVersion defines the versioned schema of this representation of an object.
  32397. Servers should convert recognized schemas to the latest internal value, and
  32398. may reject unrecognized values.
  32399. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  32400. type: string
  32401. kind:
  32402. description: |-
  32403. Kind is a string value representing the REST resource this object represents.
  32404. Servers may infer this from the endpoint the client submits requests to.
  32405. Cannot be updated.
  32406. In CamelCase.
  32407. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  32408. type: string
  32409. metadata:
  32410. type: object
  32411. spec:
  32412. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  32413. properties:
  32414. auth:
  32415. description: Auth specifies a authorization protocol. Only one protocol may be set.
  32416. maxProperties: 1
  32417. minProperties: 1
  32418. properties:
  32419. ntlm:
  32420. description: NTLMProtocol configures the store to use NTLM for auth
  32421. properties:
  32422. passwordSecret:
  32423. description: |-
  32424. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  32425. In some instances, `key` is a required field.
  32426. properties:
  32427. key:
  32428. description: |-
  32429. A key in the referenced Secret.
  32430. Some instances of this field may be defaulted, in others it may be required.
  32431. maxLength: 253
  32432. minLength: 1
  32433. pattern: ^[-._a-zA-Z0-9]+$
  32434. type: string
  32435. name:
  32436. description: The name of the Secret resource being referred to.
  32437. maxLength: 253
  32438. minLength: 1
  32439. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32440. type: string
  32441. namespace:
  32442. description: |-
  32443. The namespace of the Secret resource being referred to.
  32444. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32445. maxLength: 63
  32446. minLength: 1
  32447. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32448. type: string
  32449. type: object
  32450. usernameSecret:
  32451. description: |-
  32452. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  32453. In some instances, `key` is a required field.
  32454. properties:
  32455. key:
  32456. description: |-
  32457. A key in the referenced Secret.
  32458. Some instances of this field may be defaulted, in others it may be required.
  32459. maxLength: 253
  32460. minLength: 1
  32461. pattern: ^[-._a-zA-Z0-9]+$
  32462. type: string
  32463. name:
  32464. description: The name of the Secret resource being referred to.
  32465. maxLength: 253
  32466. minLength: 1
  32467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32468. type: string
  32469. namespace:
  32470. description: |-
  32471. The namespace of the Secret resource being referred to.
  32472. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32473. maxLength: 63
  32474. minLength: 1
  32475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32476. type: string
  32477. type: object
  32478. required:
  32479. - passwordSecret
  32480. - usernameSecret
  32481. type: object
  32482. type: object
  32483. body:
  32484. description: Body
  32485. type: string
  32486. caBundle:
  32487. description: |-
  32488. PEM encoded CA bundle used to validate webhook server certificate. Only used
  32489. if the Server URL is using HTTPS protocol. This parameter is ignored for
  32490. plain HTTP protocol connection. If not set the system root certificates
  32491. are used to validate the TLS connection.
  32492. format: byte
  32493. type: string
  32494. caProvider:
  32495. description: The provider for the CA bundle to use to validate webhook server certificate.
  32496. properties:
  32497. key:
  32498. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  32499. maxLength: 253
  32500. minLength: 1
  32501. pattern: ^[-._a-zA-Z0-9]+$
  32502. type: string
  32503. name:
  32504. description: The name of the object located at the provider type.
  32505. maxLength: 253
  32506. minLength: 1
  32507. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32508. type: string
  32509. namespace:
  32510. description: The namespace the Provider type is in.
  32511. maxLength: 63
  32512. minLength: 1
  32513. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32514. type: string
  32515. type:
  32516. description: The type of provider to use such as "Secret", or "ConfigMap".
  32517. enum:
  32518. - Secret
  32519. - ConfigMap
  32520. type: string
  32521. required:
  32522. - name
  32523. - type
  32524. type: object
  32525. headers:
  32526. additionalProperties:
  32527. type: string
  32528. description: Headers
  32529. type: object
  32530. method:
  32531. description: Webhook Method
  32532. type: string
  32533. result:
  32534. description: Result formatting
  32535. properties:
  32536. jsonPath:
  32537. description: Json path of return value
  32538. type: string
  32539. type: object
  32540. secrets:
  32541. description: |-
  32542. Secrets to fill in templates
  32543. These secrets will be passed to the templating function as key value pairs under the given name
  32544. items:
  32545. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  32546. properties:
  32547. name:
  32548. description: Name of this secret in templates
  32549. type: string
  32550. secretRef:
  32551. description: Secret ref to fill in credentials
  32552. properties:
  32553. key:
  32554. description: The key where the token is found.
  32555. maxLength: 253
  32556. minLength: 1
  32557. pattern: ^[-._a-zA-Z0-9]+$
  32558. type: string
  32559. name:
  32560. description: The name of the Secret resource being referred to.
  32561. maxLength: 253
  32562. minLength: 1
  32563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32564. type: string
  32565. type: object
  32566. required:
  32567. - name
  32568. - secretRef
  32569. type: object
  32570. type: array
  32571. timeout:
  32572. description: Timeout
  32573. type: string
  32574. url:
  32575. description: Webhook url to call
  32576. type: string
  32577. required:
  32578. - result
  32579. - url
  32580. type: object
  32581. type: object
  32582. served: true
  32583. storage: true
  32584. subresources:
  32585. status: {}