bundle.yaml 1.9 MB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488248924902491249224932494249524962497249824992500250125022503250425052506250725082509251025112512251325142515251625172518251925202521252225232524252525262527252825292530253125322533253425352536253725382539254025412542254325442545254625472548254925502551255225532554255525562557255825592560256125622563256425652566256725682569257025712572257325742575257625772578257925802581258225832584258525862587258825892590259125922593259425952596259725982599260026012602260326042605260626072608260926102611261226132614261526162617261826192620262126222623262426252626262726282629263026312632263326342635263626372638263926402641264226432644264526462647264826492650265126522653265426552656265726582659266026612662266326642665266626672668266926702671267226732674267526762677267826792680268126822683268426852686268726882689269026912692269326942695269626972698269927002701270227032704270527062707270827092710271127122713271427152716271727182719272027212722272327242725272627272728272927302731273227332734273527362737273827392740274127422743274427452746274727482749275027512752275327542755275627572758275927602761276227632764276527662767276827692770277127722773277427752776277727782779278027812782278327842785278627872788278927902791279227932794279527962797279827992800280128022803280428052806280728082809281028112812281328142815281628172818281928202821282228232824282528262827282828292830283128322833283428352836283728382839284028412842284328442845284628472848284928502851285228532854285528562857285828592860286128622863286428652866286728682869287028712872287328742875287628772878287928802881288228832884288528862887288828892890289128922893289428952896289728982899290029012902290329042905290629072908290929102911291229132914291529162917291829192920292129222923292429252926292729282929293029312932293329342935293629372938293929402941294229432944294529462947294829492950295129522953295429552956295729582959296029612962296329642965296629672968296929702971297229732974297529762977297829792980298129822983298429852986298729882989299029912992299329942995299629972998299930003001300230033004300530063007300830093010301130123013301430153016301730183019302030213022302330243025302630273028302930303031303230333034303530363037303830393040304130423043304430453046304730483049305030513052305330543055305630573058305930603061306230633064306530663067306830693070307130723073307430753076307730783079308030813082308330843085308630873088308930903091309230933094309530963097309830993100310131023103310431053106310731083109311031113112311331143115311631173118311931203121312231233124312531263127312831293130313131323133313431353136313731383139314031413142314331443145314631473148314931503151315231533154315531563157315831593160316131623163316431653166316731683169317031713172317331743175317631773178317931803181318231833184318531863187318831893190319131923193319431953196319731983199320032013202320332043205320632073208320932103211321232133214321532163217321832193220322132223223322432253226322732283229323032313232323332343235323632373238323932403241324232433244324532463247324832493250325132523253325432553256325732583259326032613262326332643265326632673268326932703271327232733274327532763277327832793280328132823283328432853286328732883289329032913292329332943295329632973298329933003301330233033304330533063307330833093310331133123313331433153316331733183319332033213322332333243325332633273328332933303331333233333334333533363337333833393340334133423343334433453346334733483349335033513352335333543355335633573358335933603361336233633364336533663367336833693370337133723373337433753376337733783379338033813382338333843385338633873388338933903391339233933394339533963397339833993400340134023403340434053406340734083409341034113412341334143415341634173418341934203421342234233424342534263427342834293430343134323433343434353436343734383439344034413442344334443445344634473448344934503451345234533454345534563457345834593460346134623463346434653466346734683469347034713472347334743475347634773478347934803481348234833484348534863487348834893490349134923493349434953496349734983499350035013502350335043505350635073508350935103511351235133514351535163517351835193520352135223523352435253526352735283529353035313532353335343535353635373538353935403541354235433544354535463547354835493550355135523553355435553556355735583559356035613562356335643565356635673568356935703571357235733574357535763577357835793580358135823583358435853586358735883589359035913592359335943595359635973598359936003601360236033604360536063607360836093610361136123613361436153616361736183619362036213622362336243625362636273628362936303631363236333634363536363637363836393640364136423643364436453646364736483649365036513652365336543655365636573658365936603661366236633664366536663667366836693670367136723673367436753676367736783679368036813682368336843685368636873688368936903691369236933694369536963697369836993700370137023703370437053706370737083709371037113712371337143715371637173718371937203721372237233724372537263727372837293730373137323733373437353736373737383739374037413742374337443745374637473748374937503751375237533754375537563757375837593760376137623763376437653766376737683769377037713772377337743775377637773778377937803781378237833784378537863787378837893790379137923793379437953796379737983799380038013802380338043805380638073808380938103811381238133814381538163817381838193820382138223823382438253826382738283829383038313832383338343835383638373838383938403841384238433844384538463847384838493850385138523853385438553856385738583859386038613862386338643865386638673868386938703871387238733874387538763877387838793880388138823883388438853886388738883889389038913892389338943895389638973898389939003901390239033904390539063907390839093910391139123913391439153916391739183919392039213922392339243925392639273928392939303931393239333934393539363937393839393940394139423943394439453946394739483949395039513952395339543955395639573958395939603961396239633964396539663967396839693970397139723973397439753976397739783979398039813982398339843985398639873988398939903991399239933994399539963997399839994000400140024003400440054006400740084009401040114012401340144015401640174018401940204021402240234024402540264027402840294030403140324033403440354036403740384039404040414042404340444045404640474048404940504051405240534054405540564057405840594060406140624063406440654066406740684069407040714072407340744075407640774078407940804081408240834084408540864087408840894090409140924093409440954096409740984099410041014102410341044105410641074108410941104111411241134114411541164117411841194120412141224123412441254126412741284129413041314132413341344135413641374138413941404141414241434144414541464147414841494150415141524153415441554156415741584159416041614162416341644165416641674168416941704171417241734174417541764177417841794180418141824183418441854186418741884189419041914192419341944195419641974198419942004201420242034204420542064207420842094210421142124213421442154216421742184219422042214222422342244225422642274228422942304231423242334234423542364237423842394240424142424243424442454246424742484249425042514252425342544255425642574258425942604261426242634264426542664267426842694270427142724273427442754276427742784279428042814282428342844285428642874288428942904291429242934294429542964297429842994300430143024303430443054306430743084309431043114312431343144315431643174318431943204321432243234324432543264327432843294330433143324333433443354336433743384339434043414342434343444345434643474348434943504351435243534354435543564357435843594360436143624363436443654366436743684369437043714372437343744375437643774378437943804381438243834384438543864387438843894390439143924393439443954396439743984399440044014402440344044405440644074408440944104411441244134414441544164417441844194420442144224423442444254426442744284429443044314432443344344435443644374438443944404441444244434444444544464447444844494450445144524453445444554456445744584459446044614462446344644465446644674468446944704471447244734474447544764477447844794480448144824483448444854486448744884489449044914492449344944495449644974498449945004501450245034504450545064507450845094510451145124513451445154516451745184519452045214522452345244525452645274528452945304531453245334534453545364537453845394540454145424543454445454546454745484549455045514552455345544555455645574558455945604561456245634564456545664567456845694570457145724573457445754576457745784579458045814582458345844585458645874588458945904591459245934594459545964597459845994600460146024603460446054606460746084609461046114612461346144615461646174618461946204621462246234624462546264627462846294630463146324633463446354636463746384639464046414642464346444645464646474648464946504651465246534654465546564657465846594660466146624663466446654666466746684669467046714672467346744675467646774678467946804681468246834684468546864687468846894690469146924693469446954696469746984699470047014702470347044705470647074708470947104711471247134714471547164717471847194720472147224723472447254726472747284729473047314732473347344735473647374738473947404741474247434744474547464747474847494750475147524753475447554756475747584759476047614762476347644765476647674768476947704771477247734774477547764777477847794780478147824783478447854786478747884789479047914792479347944795479647974798479948004801480248034804480548064807480848094810481148124813481448154816481748184819482048214822482348244825482648274828482948304831483248334834483548364837483848394840484148424843484448454846484748484849485048514852485348544855485648574858485948604861486248634864486548664867486848694870487148724873487448754876487748784879488048814882488348844885488648874888488948904891489248934894489548964897489848994900490149024903490449054906490749084909491049114912491349144915491649174918491949204921492249234924492549264927492849294930493149324933493449354936493749384939494049414942494349444945494649474948494949504951495249534954495549564957495849594960496149624963496449654966496749684969497049714972497349744975497649774978497949804981498249834984498549864987498849894990499149924993499449954996499749984999500050015002500350045005500650075008500950105011501250135014501550165017501850195020502150225023502450255026502750285029503050315032503350345035503650375038503950405041504250435044504550465047504850495050505150525053505450555056505750585059506050615062506350645065506650675068506950705071507250735074507550765077507850795080508150825083508450855086508750885089509050915092509350945095509650975098509951005101510251035104510551065107510851095110511151125113511451155116511751185119512051215122512351245125512651275128512951305131513251335134513551365137513851395140514151425143514451455146514751485149515051515152515351545155515651575158515951605161516251635164516551665167516851695170517151725173517451755176517751785179518051815182518351845185518651875188518951905191519251935194519551965197519851995200520152025203520452055206520752085209521052115212521352145215521652175218521952205221522252235224522552265227522852295230523152325233523452355236523752385239524052415242524352445245524652475248524952505251525252535254525552565257525852595260526152625263526452655266526752685269527052715272527352745275527652775278527952805281528252835284528552865287528852895290529152925293529452955296529752985299530053015302530353045305530653075308530953105311531253135314531553165317531853195320532153225323532453255326532753285329533053315332533353345335533653375338533953405341534253435344534553465347534853495350535153525353535453555356535753585359536053615362536353645365536653675368536953705371537253735374537553765377537853795380538153825383538453855386538753885389539053915392539353945395539653975398539954005401540254035404540554065407540854095410541154125413541454155416541754185419542054215422542354245425542654275428542954305431543254335434543554365437543854395440544154425443544454455446544754485449545054515452545354545455545654575458545954605461546254635464546554665467546854695470547154725473547454755476547754785479548054815482548354845485548654875488548954905491549254935494549554965497549854995500550155025503550455055506550755085509551055115512551355145515551655175518551955205521552255235524552555265527552855295530553155325533553455355536553755385539554055415542554355445545554655475548554955505551555255535554555555565557555855595560556155625563556455655566556755685569557055715572557355745575557655775578557955805581558255835584558555865587558855895590559155925593559455955596559755985599560056015602560356045605560656075608560956105611561256135614561556165617561856195620562156225623562456255626562756285629563056315632563356345635563656375638563956405641564256435644564556465647564856495650565156525653565456555656565756585659566056615662566356645665566656675668566956705671567256735674567556765677567856795680568156825683568456855686568756885689569056915692569356945695569656975698569957005701570257035704570557065707570857095710571157125713571457155716571757185719572057215722572357245725572657275728572957305731573257335734573557365737573857395740574157425743574457455746574757485749575057515752575357545755575657575758575957605761576257635764576557665767576857695770577157725773577457755776577757785779578057815782578357845785578657875788578957905791579257935794579557965797579857995800580158025803580458055806580758085809581058115812581358145815581658175818581958205821582258235824582558265827582858295830583158325833583458355836583758385839584058415842584358445845584658475848584958505851585258535854585558565857585858595860586158625863586458655866586758685869587058715872587358745875587658775878587958805881588258835884588558865887588858895890589158925893589458955896589758985899590059015902590359045905590659075908590959105911591259135914591559165917591859195920592159225923592459255926592759285929593059315932593359345935593659375938593959405941594259435944594559465947594859495950595159525953595459555956595759585959596059615962596359645965596659675968596959705971597259735974597559765977597859795980598159825983598459855986598759885989599059915992599359945995599659975998599960006001600260036004600560066007600860096010601160126013601460156016601760186019602060216022602360246025602660276028602960306031603260336034603560366037603860396040604160426043604460456046604760486049605060516052605360546055605660576058605960606061606260636064606560666067606860696070607160726073607460756076607760786079608060816082608360846085608660876088608960906091609260936094609560966097609860996100610161026103610461056106610761086109611061116112611361146115611661176118611961206121612261236124612561266127612861296130613161326133613461356136613761386139614061416142614361446145614661476148614961506151615261536154615561566157615861596160616161626163616461656166616761686169617061716172617361746175617661776178617961806181618261836184618561866187618861896190619161926193619461956196619761986199620062016202620362046205620662076208620962106211621262136214621562166217621862196220622162226223622462256226622762286229623062316232623362346235623662376238623962406241624262436244624562466247624862496250625162526253625462556256625762586259626062616262626362646265626662676268626962706271627262736274627562766277627862796280628162826283628462856286628762886289629062916292629362946295629662976298629963006301630263036304630563066307630863096310631163126313631463156316631763186319632063216322632363246325632663276328632963306331633263336334633563366337633863396340634163426343634463456346634763486349635063516352635363546355635663576358635963606361636263636364636563666367636863696370637163726373637463756376637763786379638063816382638363846385638663876388638963906391639263936394639563966397639863996400640164026403640464056406640764086409641064116412641364146415641664176418641964206421642264236424642564266427642864296430643164326433643464356436643764386439644064416442644364446445644664476448644964506451645264536454645564566457645864596460646164626463646464656466646764686469647064716472647364746475647664776478647964806481648264836484648564866487648864896490649164926493649464956496649764986499650065016502650365046505650665076508650965106511651265136514651565166517651865196520652165226523652465256526652765286529653065316532653365346535653665376538653965406541654265436544654565466547654865496550655165526553655465556556655765586559656065616562656365646565656665676568656965706571657265736574657565766577657865796580658165826583658465856586658765886589659065916592659365946595659665976598659966006601660266036604660566066607660866096610661166126613661466156616661766186619662066216622662366246625662666276628662966306631663266336634663566366637663866396640664166426643664466456646664766486649665066516652665366546655665666576658665966606661666266636664666566666667666866696670667166726673667466756676667766786679668066816682668366846685668666876688668966906691669266936694669566966697669866996700670167026703670467056706670767086709671067116712671367146715671667176718671967206721672267236724672567266727672867296730673167326733673467356736673767386739674067416742674367446745674667476748674967506751675267536754675567566757675867596760676167626763676467656766676767686769677067716772677367746775677667776778677967806781678267836784678567866787678867896790679167926793679467956796679767986799680068016802680368046805680668076808680968106811681268136814681568166817681868196820682168226823682468256826682768286829683068316832683368346835683668376838683968406841684268436844684568466847684868496850685168526853685468556856685768586859686068616862686368646865686668676868686968706871687268736874687568766877687868796880688168826883688468856886688768886889689068916892689368946895689668976898689969006901690269036904690569066907690869096910691169126913691469156916691769186919692069216922692369246925692669276928692969306931693269336934693569366937693869396940694169426943694469456946694769486949695069516952695369546955695669576958695969606961696269636964696569666967696869696970697169726973697469756976697769786979698069816982698369846985698669876988698969906991699269936994699569966997699869997000700170027003700470057006700770087009701070117012701370147015701670177018701970207021702270237024702570267027702870297030703170327033703470357036703770387039704070417042704370447045704670477048704970507051705270537054705570567057705870597060706170627063706470657066706770687069707070717072707370747075707670777078707970807081708270837084708570867087708870897090709170927093709470957096709770987099710071017102710371047105710671077108710971107111711271137114711571167117711871197120712171227123712471257126712771287129713071317132713371347135713671377138713971407141714271437144714571467147714871497150715171527153715471557156715771587159716071617162716371647165716671677168716971707171717271737174717571767177717871797180718171827183718471857186718771887189719071917192719371947195719671977198719972007201720272037204720572067207720872097210721172127213721472157216721772187219722072217222722372247225722672277228722972307231723272337234723572367237723872397240724172427243724472457246724772487249725072517252725372547255725672577258725972607261726272637264726572667267726872697270727172727273727472757276727772787279728072817282728372847285728672877288728972907291729272937294729572967297729872997300730173027303730473057306730773087309731073117312731373147315731673177318731973207321732273237324732573267327732873297330733173327333733473357336733773387339734073417342734373447345734673477348734973507351735273537354735573567357735873597360736173627363736473657366736773687369737073717372737373747375737673777378737973807381738273837384738573867387738873897390739173927393739473957396739773987399740074017402740374047405740674077408740974107411741274137414741574167417741874197420742174227423742474257426742774287429743074317432743374347435743674377438743974407441744274437444744574467447744874497450745174527453745474557456745774587459746074617462746374647465746674677468746974707471747274737474747574767477747874797480748174827483748474857486748774887489749074917492749374947495749674977498749975007501750275037504750575067507750875097510751175127513751475157516751775187519752075217522752375247525752675277528752975307531753275337534753575367537753875397540754175427543754475457546754775487549755075517552755375547555755675577558755975607561756275637564756575667567756875697570757175727573757475757576757775787579758075817582758375847585758675877588758975907591759275937594759575967597759875997600760176027603760476057606760776087609761076117612761376147615761676177618761976207621762276237624762576267627762876297630763176327633763476357636763776387639764076417642764376447645764676477648764976507651765276537654765576567657765876597660766176627663766476657666766776687669767076717672767376747675767676777678767976807681768276837684768576867687768876897690769176927693769476957696769776987699770077017702770377047705770677077708770977107711771277137714771577167717771877197720772177227723772477257726772777287729773077317732773377347735773677377738773977407741774277437744774577467747774877497750775177527753775477557756775777587759776077617762776377647765776677677768776977707771777277737774777577767777777877797780778177827783778477857786778777887789779077917792779377947795779677977798779978007801780278037804780578067807780878097810781178127813781478157816781778187819782078217822782378247825782678277828782978307831783278337834783578367837783878397840784178427843784478457846784778487849785078517852785378547855785678577858785978607861786278637864786578667867786878697870787178727873787478757876787778787879788078817882788378847885788678877888788978907891789278937894789578967897789878997900790179027903790479057906790779087909791079117912791379147915791679177918791979207921792279237924792579267927792879297930793179327933793479357936793779387939794079417942794379447945794679477948794979507951795279537954795579567957795879597960796179627963796479657966796779687969797079717972797379747975797679777978797979807981798279837984798579867987798879897990799179927993799479957996799779987999800080018002800380048005800680078008800980108011801280138014801580168017801880198020802180228023802480258026802780288029803080318032803380348035803680378038803980408041804280438044804580468047804880498050805180528053805480558056805780588059806080618062806380648065806680678068806980708071807280738074807580768077807880798080808180828083808480858086808780888089809080918092809380948095809680978098809981008101810281038104810581068107810881098110811181128113811481158116811781188119812081218122812381248125812681278128812981308131813281338134813581368137813881398140814181428143814481458146814781488149815081518152815381548155815681578158815981608161816281638164816581668167816881698170817181728173817481758176817781788179818081818182818381848185818681878188818981908191819281938194819581968197819881998200820182028203820482058206820782088209821082118212821382148215821682178218821982208221822282238224822582268227822882298230823182328233823482358236823782388239824082418242824382448245824682478248824982508251825282538254825582568257825882598260826182628263826482658266826782688269827082718272827382748275827682778278827982808281828282838284828582868287828882898290829182928293829482958296829782988299830083018302830383048305830683078308830983108311831283138314831583168317831883198320832183228323832483258326832783288329833083318332833383348335833683378338833983408341834283438344834583468347834883498350835183528353835483558356835783588359836083618362836383648365836683678368836983708371837283738374837583768377837883798380838183828383838483858386838783888389839083918392839383948395839683978398839984008401840284038404840584068407840884098410841184128413841484158416841784188419842084218422842384248425842684278428842984308431843284338434843584368437843884398440844184428443844484458446844784488449845084518452845384548455845684578458845984608461846284638464846584668467846884698470847184728473847484758476847784788479848084818482848384848485848684878488848984908491849284938494849584968497849884998500850185028503850485058506850785088509851085118512851385148515851685178518851985208521852285238524852585268527852885298530853185328533853485358536853785388539854085418542854385448545854685478548854985508551855285538554855585568557855885598560856185628563856485658566856785688569857085718572857385748575857685778578857985808581858285838584858585868587858885898590859185928593859485958596859785988599860086018602860386048605860686078608860986108611861286138614861586168617861886198620862186228623862486258626862786288629863086318632863386348635863686378638863986408641864286438644864586468647864886498650865186528653865486558656865786588659866086618662866386648665866686678668866986708671867286738674867586768677867886798680868186828683868486858686868786888689869086918692869386948695869686978698869987008701870287038704870587068707870887098710871187128713871487158716871787188719872087218722872387248725872687278728872987308731873287338734873587368737873887398740874187428743874487458746874787488749875087518752875387548755875687578758875987608761876287638764876587668767876887698770877187728773877487758776877787788779878087818782878387848785878687878788878987908791879287938794879587968797879887998800880188028803880488058806880788088809881088118812881388148815881688178818881988208821882288238824882588268827882888298830883188328833883488358836883788388839884088418842884388448845884688478848884988508851885288538854885588568857885888598860886188628863886488658866886788688869887088718872887388748875887688778878887988808881888288838884888588868887888888898890889188928893889488958896889788988899890089018902890389048905890689078908890989108911891289138914891589168917891889198920892189228923892489258926892789288929893089318932893389348935893689378938893989408941894289438944894589468947894889498950895189528953895489558956895789588959896089618962896389648965896689678968896989708971897289738974897589768977897889798980898189828983898489858986898789888989899089918992899389948995899689978998899990009001900290039004900590069007900890099010901190129013901490159016901790189019902090219022902390249025902690279028902990309031903290339034903590369037903890399040904190429043904490459046904790489049905090519052905390549055905690579058905990609061906290639064906590669067906890699070907190729073907490759076907790789079908090819082908390849085908690879088908990909091909290939094909590969097909890999100910191029103910491059106910791089109911091119112911391149115911691179118911991209121912291239124912591269127912891299130913191329133913491359136913791389139914091419142914391449145914691479148914991509151915291539154915591569157915891599160916191629163916491659166916791689169917091719172917391749175917691779178917991809181918291839184918591869187918891899190919191929193919491959196919791989199920092019202920392049205920692079208920992109211921292139214921592169217921892199220922192229223922492259226922792289229923092319232923392349235923692379238923992409241924292439244924592469247924892499250925192529253925492559256925792589259926092619262926392649265926692679268926992709271927292739274927592769277927892799280928192829283928492859286928792889289929092919292929392949295929692979298929993009301930293039304930593069307930893099310931193129313931493159316931793189319932093219322932393249325932693279328932993309331933293339334933593369337933893399340934193429343934493459346934793489349935093519352935393549355935693579358935993609361936293639364936593669367936893699370937193729373937493759376937793789379938093819382938393849385938693879388938993909391939293939394939593969397939893999400940194029403940494059406940794089409941094119412941394149415941694179418941994209421942294239424942594269427942894299430943194329433943494359436943794389439944094419442944394449445944694479448944994509451945294539454945594569457945894599460946194629463946494659466946794689469947094719472947394749475947694779478947994809481948294839484948594869487948894899490949194929493949494959496949794989499950095019502950395049505950695079508950995109511951295139514951595169517951895199520952195229523952495259526952795289529953095319532953395349535953695379538953995409541954295439544954595469547954895499550955195529553955495559556955795589559956095619562956395649565956695679568956995709571957295739574957595769577957895799580958195829583958495859586958795889589959095919592959395949595959695979598959996009601960296039604960596069607960896099610961196129613961496159616961796189619962096219622962396249625962696279628962996309631963296339634963596369637963896399640964196429643964496459646964796489649965096519652965396549655965696579658965996609661966296639664966596669667966896699670967196729673967496759676967796789679968096819682968396849685968696879688968996909691969296939694969596969697969896999700970197029703970497059706970797089709971097119712971397149715971697179718971997209721972297239724972597269727972897299730973197329733973497359736973797389739974097419742974397449745974697479748974997509751975297539754975597569757975897599760976197629763976497659766976797689769977097719772977397749775977697779778977997809781978297839784978597869787978897899790979197929793979497959796979797989799980098019802980398049805980698079808980998109811981298139814981598169817981898199820982198229823982498259826982798289829983098319832983398349835983698379838983998409841984298439844984598469847984898499850985198529853985498559856985798589859986098619862986398649865986698679868986998709871987298739874987598769877987898799880988198829883988498859886988798889889989098919892989398949895989698979898989999009901990299039904990599069907990899099910991199129913991499159916991799189919992099219922992399249925992699279928992999309931993299339934993599369937993899399940994199429943994499459946994799489949995099519952995399549955995699579958995999609961996299639964996599669967996899699970997199729973997499759976997799789979998099819982998399849985998699879988998999909991999299939994999599969997999899991000010001100021000310004100051000610007100081000910010100111001210013100141001510016100171001810019100201002110022100231002410025100261002710028100291003010031100321003310034100351003610037100381003910040100411004210043100441004510046100471004810049100501005110052100531005410055100561005710058100591006010061100621006310064100651006610067100681006910070100711007210073100741007510076100771007810079100801008110082100831008410085100861008710088100891009010091100921009310094100951009610097100981009910100101011010210103101041010510106101071010810109101101011110112101131011410115101161011710118101191012010121101221012310124101251012610127101281012910130101311013210133101341013510136101371013810139101401014110142101431014410145101461014710148101491015010151101521015310154101551015610157101581015910160101611016210163101641016510166101671016810169101701017110172101731017410175101761017710178101791018010181101821018310184101851018610187101881018910190101911019210193101941019510196101971019810199102001020110202102031020410205102061020710208102091021010211102121021310214102151021610217102181021910220102211022210223102241022510226102271022810229102301023110232102331023410235102361023710238102391024010241102421024310244102451024610247102481024910250102511025210253102541025510256102571025810259102601026110262102631026410265102661026710268102691027010271102721027310274102751027610277102781027910280102811028210283102841028510286102871028810289102901029110292102931029410295102961029710298102991030010301103021030310304103051030610307103081030910310103111031210313103141031510316103171031810319103201032110322103231032410325103261032710328103291033010331103321033310334103351033610337103381033910340103411034210343103441034510346103471034810349103501035110352103531035410355103561035710358103591036010361103621036310364103651036610367103681036910370103711037210373103741037510376103771037810379103801038110382103831038410385103861038710388103891039010391103921039310394103951039610397103981039910400104011040210403104041040510406104071040810409104101041110412104131041410415104161041710418104191042010421104221042310424104251042610427104281042910430104311043210433104341043510436104371043810439104401044110442104431044410445104461044710448104491045010451104521045310454104551045610457104581045910460104611046210463104641046510466104671046810469104701047110472104731047410475104761047710478104791048010481104821048310484104851048610487104881048910490104911049210493104941049510496104971049810499105001050110502105031050410505105061050710508105091051010511105121051310514105151051610517105181051910520105211052210523105241052510526105271052810529105301053110532105331053410535105361053710538105391054010541105421054310544105451054610547105481054910550105511055210553105541055510556105571055810559105601056110562105631056410565105661056710568105691057010571105721057310574105751057610577105781057910580105811058210583105841058510586105871058810589105901059110592105931059410595105961059710598105991060010601106021060310604106051060610607106081060910610106111061210613106141061510616106171061810619106201062110622106231062410625106261062710628106291063010631106321063310634106351063610637106381063910640106411064210643106441064510646106471064810649106501065110652106531065410655106561065710658106591066010661106621066310664106651066610667106681066910670106711067210673106741067510676106771067810679106801068110682106831068410685106861068710688106891069010691106921069310694106951069610697106981069910700107011070210703107041070510706107071070810709107101071110712107131071410715107161071710718107191072010721107221072310724107251072610727107281072910730107311073210733107341073510736107371073810739107401074110742107431074410745107461074710748107491075010751107521075310754107551075610757107581075910760107611076210763107641076510766107671076810769107701077110772107731077410775107761077710778107791078010781107821078310784107851078610787107881078910790107911079210793107941079510796107971079810799108001080110802108031080410805108061080710808108091081010811108121081310814108151081610817108181081910820108211082210823108241082510826108271082810829108301083110832108331083410835108361083710838108391084010841108421084310844108451084610847108481084910850108511085210853108541085510856108571085810859108601086110862108631086410865108661086710868108691087010871108721087310874108751087610877108781087910880108811088210883108841088510886108871088810889108901089110892108931089410895108961089710898108991090010901109021090310904109051090610907109081090910910109111091210913109141091510916109171091810919109201092110922109231092410925109261092710928109291093010931109321093310934109351093610937109381093910940109411094210943109441094510946109471094810949109501095110952109531095410955109561095710958109591096010961109621096310964109651096610967109681096910970109711097210973109741097510976109771097810979109801098110982109831098410985109861098710988109891099010991109921099310994109951099610997109981099911000110011100211003110041100511006110071100811009110101101111012110131101411015110161101711018110191102011021110221102311024110251102611027110281102911030110311103211033110341103511036110371103811039110401104111042110431104411045110461104711048110491105011051110521105311054110551105611057110581105911060110611106211063110641106511066110671106811069110701107111072110731107411075110761107711078110791108011081110821108311084110851108611087110881108911090110911109211093110941109511096110971109811099111001110111102111031110411105111061110711108111091111011111111121111311114111151111611117111181111911120111211112211123111241112511126111271112811129111301113111132111331113411135111361113711138111391114011141111421114311144111451114611147111481114911150111511115211153111541115511156111571115811159111601116111162111631116411165111661116711168111691117011171111721117311174111751117611177111781117911180111811118211183111841118511186111871118811189111901119111192111931119411195111961119711198111991120011201112021120311204112051120611207112081120911210112111121211213112141121511216112171121811219112201122111222112231122411225112261122711228112291123011231112321123311234112351123611237112381123911240112411124211243112441124511246112471124811249112501125111252112531125411255112561125711258112591126011261112621126311264112651126611267112681126911270112711127211273112741127511276112771127811279112801128111282112831128411285112861128711288112891129011291112921129311294112951129611297112981129911300113011130211303113041130511306113071130811309113101131111312113131131411315113161131711318113191132011321113221132311324113251132611327113281132911330113311133211333113341133511336113371133811339113401134111342113431134411345113461134711348113491135011351113521135311354113551135611357113581135911360113611136211363113641136511366113671136811369113701137111372113731137411375113761137711378113791138011381113821138311384113851138611387113881138911390113911139211393113941139511396113971139811399114001140111402114031140411405114061140711408114091141011411114121141311414114151141611417114181141911420114211142211423114241142511426114271142811429114301143111432114331143411435114361143711438114391144011441114421144311444114451144611447114481144911450114511145211453114541145511456114571145811459114601146111462114631146411465114661146711468114691147011471114721147311474114751147611477114781147911480114811148211483114841148511486114871148811489114901149111492114931149411495114961149711498114991150011501115021150311504115051150611507115081150911510115111151211513115141151511516115171151811519115201152111522115231152411525115261152711528115291153011531115321153311534115351153611537115381153911540115411154211543115441154511546115471154811549115501155111552115531155411555115561155711558115591156011561115621156311564115651156611567115681156911570115711157211573115741157511576115771157811579115801158111582115831158411585115861158711588115891159011591115921159311594115951159611597115981159911600116011160211603116041160511606116071160811609116101161111612116131161411615116161161711618116191162011621116221162311624116251162611627116281162911630116311163211633116341163511636116371163811639116401164111642116431164411645116461164711648116491165011651116521165311654116551165611657116581165911660116611166211663116641166511666116671166811669116701167111672116731167411675116761167711678116791168011681116821168311684116851168611687116881168911690116911169211693116941169511696116971169811699117001170111702117031170411705117061170711708117091171011711117121171311714117151171611717117181171911720117211172211723117241172511726117271172811729117301173111732117331173411735117361173711738117391174011741117421174311744117451174611747117481174911750117511175211753117541175511756117571175811759117601176111762117631176411765117661176711768117691177011771117721177311774117751177611777117781177911780117811178211783117841178511786117871178811789117901179111792117931179411795117961179711798117991180011801118021180311804118051180611807118081180911810118111181211813118141181511816118171181811819118201182111822118231182411825118261182711828118291183011831118321183311834118351183611837118381183911840118411184211843118441184511846118471184811849118501185111852118531185411855118561185711858118591186011861118621186311864118651186611867118681186911870118711187211873118741187511876118771187811879118801188111882118831188411885118861188711888118891189011891118921189311894118951189611897118981189911900119011190211903119041190511906119071190811909119101191111912119131191411915119161191711918119191192011921119221192311924119251192611927119281192911930119311193211933119341193511936119371193811939119401194111942119431194411945119461194711948119491195011951119521195311954119551195611957119581195911960119611196211963119641196511966119671196811969119701197111972119731197411975119761197711978119791198011981119821198311984119851198611987119881198911990119911199211993119941199511996119971199811999120001200112002120031200412005120061200712008120091201012011120121201312014120151201612017120181201912020120211202212023120241202512026120271202812029120301203112032120331203412035120361203712038120391204012041120421204312044120451204612047120481204912050120511205212053120541205512056120571205812059120601206112062120631206412065120661206712068120691207012071120721207312074120751207612077120781207912080120811208212083120841208512086120871208812089120901209112092120931209412095120961209712098120991210012101121021210312104121051210612107121081210912110121111211212113121141211512116121171211812119121201212112122121231212412125121261212712128121291213012131121321213312134121351213612137121381213912140121411214212143121441214512146121471214812149121501215112152121531215412155121561215712158121591216012161121621216312164121651216612167121681216912170121711217212173121741217512176121771217812179121801218112182121831218412185121861218712188121891219012191121921219312194121951219612197121981219912200122011220212203122041220512206122071220812209122101221112212122131221412215122161221712218122191222012221122221222312224122251222612227122281222912230122311223212233122341223512236122371223812239122401224112242122431224412245122461224712248122491225012251122521225312254122551225612257122581225912260122611226212263122641226512266122671226812269122701227112272122731227412275122761227712278122791228012281122821228312284122851228612287122881228912290122911229212293122941229512296122971229812299123001230112302123031230412305123061230712308123091231012311123121231312314123151231612317123181231912320123211232212323123241232512326123271232812329123301233112332123331233412335123361233712338123391234012341123421234312344123451234612347123481234912350123511235212353123541235512356123571235812359123601236112362123631236412365123661236712368123691237012371123721237312374123751237612377123781237912380123811238212383123841238512386123871238812389123901239112392123931239412395123961239712398123991240012401124021240312404124051240612407124081240912410124111241212413124141241512416124171241812419124201242112422124231242412425124261242712428124291243012431124321243312434124351243612437124381243912440124411244212443124441244512446124471244812449124501245112452124531245412455124561245712458124591246012461124621246312464124651246612467124681246912470124711247212473124741247512476124771247812479124801248112482124831248412485124861248712488124891249012491124921249312494124951249612497124981249912500125011250212503125041250512506125071250812509125101251112512125131251412515125161251712518125191252012521125221252312524125251252612527125281252912530125311253212533125341253512536125371253812539125401254112542125431254412545125461254712548125491255012551125521255312554125551255612557125581255912560125611256212563125641256512566125671256812569125701257112572125731257412575125761257712578125791258012581125821258312584125851258612587125881258912590125911259212593125941259512596125971259812599126001260112602126031260412605126061260712608126091261012611126121261312614126151261612617126181261912620126211262212623126241262512626126271262812629126301263112632126331263412635126361263712638126391264012641126421264312644126451264612647126481264912650126511265212653126541265512656126571265812659126601266112662126631266412665126661266712668126691267012671126721267312674126751267612677126781267912680126811268212683126841268512686126871268812689126901269112692126931269412695126961269712698126991270012701127021270312704127051270612707127081270912710127111271212713127141271512716127171271812719127201272112722127231272412725127261272712728127291273012731127321273312734127351273612737127381273912740127411274212743127441274512746127471274812749127501275112752127531275412755127561275712758127591276012761127621276312764127651276612767127681276912770127711277212773127741277512776127771277812779127801278112782127831278412785127861278712788127891279012791127921279312794127951279612797127981279912800128011280212803128041280512806128071280812809128101281112812128131281412815128161281712818128191282012821128221282312824128251282612827128281282912830128311283212833128341283512836128371283812839128401284112842128431284412845128461284712848128491285012851128521285312854128551285612857128581285912860128611286212863128641286512866128671286812869128701287112872128731287412875128761287712878128791288012881128821288312884128851288612887128881288912890128911289212893128941289512896128971289812899129001290112902129031290412905129061290712908129091291012911129121291312914129151291612917129181291912920129211292212923129241292512926129271292812929129301293112932129331293412935129361293712938129391294012941129421294312944129451294612947129481294912950129511295212953129541295512956129571295812959129601296112962129631296412965129661296712968129691297012971129721297312974129751297612977129781297912980129811298212983129841298512986129871298812989129901299112992129931299412995129961299712998129991300013001130021300313004130051300613007130081300913010130111301213013130141301513016130171301813019130201302113022130231302413025130261302713028130291303013031130321303313034130351303613037130381303913040130411304213043130441304513046130471304813049130501305113052130531305413055130561305713058130591306013061130621306313064130651306613067130681306913070130711307213073130741307513076130771307813079130801308113082130831308413085130861308713088130891309013091130921309313094130951309613097130981309913100131011310213103131041310513106131071310813109131101311113112131131311413115131161311713118131191312013121131221312313124131251312613127131281312913130131311313213133131341313513136131371313813139131401314113142131431314413145131461314713148131491315013151131521315313154131551315613157131581315913160131611316213163131641316513166131671316813169131701317113172131731317413175131761317713178131791318013181131821318313184131851318613187131881318913190131911319213193131941319513196131971319813199132001320113202132031320413205132061320713208132091321013211132121321313214132151321613217132181321913220132211322213223132241322513226132271322813229132301323113232132331323413235132361323713238132391324013241132421324313244132451324613247132481324913250132511325213253132541325513256132571325813259132601326113262132631326413265132661326713268132691327013271132721327313274132751327613277132781327913280132811328213283132841328513286132871328813289132901329113292132931329413295132961329713298132991330013301133021330313304133051330613307133081330913310133111331213313133141331513316133171331813319133201332113322133231332413325133261332713328133291333013331133321333313334133351333613337133381333913340133411334213343133441334513346133471334813349133501335113352133531335413355133561335713358133591336013361133621336313364133651336613367133681336913370133711337213373133741337513376133771337813379133801338113382133831338413385133861338713388133891339013391133921339313394133951339613397133981339913400134011340213403134041340513406134071340813409134101341113412134131341413415134161341713418134191342013421134221342313424134251342613427134281342913430134311343213433134341343513436134371343813439134401344113442134431344413445134461344713448134491345013451134521345313454134551345613457134581345913460134611346213463134641346513466134671346813469134701347113472134731347413475134761347713478134791348013481134821348313484134851348613487134881348913490134911349213493134941349513496134971349813499135001350113502135031350413505135061350713508135091351013511135121351313514135151351613517135181351913520135211352213523135241352513526135271352813529135301353113532135331353413535135361353713538135391354013541135421354313544135451354613547135481354913550135511355213553135541355513556135571355813559135601356113562135631356413565135661356713568135691357013571135721357313574135751357613577135781357913580135811358213583135841358513586135871358813589135901359113592135931359413595135961359713598135991360013601136021360313604136051360613607136081360913610136111361213613136141361513616136171361813619136201362113622136231362413625136261362713628136291363013631136321363313634136351363613637136381363913640136411364213643136441364513646136471364813649136501365113652136531365413655136561365713658136591366013661136621366313664136651366613667136681366913670136711367213673136741367513676136771367813679136801368113682136831368413685136861368713688136891369013691136921369313694136951369613697136981369913700137011370213703137041370513706137071370813709137101371113712137131371413715137161371713718137191372013721137221372313724137251372613727137281372913730137311373213733137341373513736137371373813739137401374113742137431374413745137461374713748137491375013751137521375313754137551375613757137581375913760137611376213763137641376513766137671376813769137701377113772137731377413775137761377713778137791378013781137821378313784137851378613787137881378913790137911379213793137941379513796137971379813799138001380113802138031380413805138061380713808138091381013811138121381313814138151381613817138181381913820138211382213823138241382513826138271382813829138301383113832138331383413835138361383713838138391384013841138421384313844138451384613847138481384913850138511385213853138541385513856138571385813859138601386113862138631386413865138661386713868138691387013871138721387313874138751387613877138781387913880138811388213883138841388513886138871388813889138901389113892138931389413895138961389713898138991390013901139021390313904139051390613907139081390913910139111391213913139141391513916139171391813919139201392113922139231392413925139261392713928139291393013931139321393313934139351393613937139381393913940139411394213943139441394513946139471394813949139501395113952139531395413955139561395713958139591396013961139621396313964139651396613967139681396913970139711397213973139741397513976139771397813979139801398113982139831398413985139861398713988139891399013991139921399313994139951399613997139981399914000140011400214003140041400514006140071400814009140101401114012140131401414015140161401714018140191402014021140221402314024140251402614027140281402914030140311403214033140341403514036140371403814039140401404114042140431404414045140461404714048140491405014051140521405314054140551405614057140581405914060140611406214063140641406514066140671406814069140701407114072140731407414075140761407714078140791408014081140821408314084140851408614087140881408914090140911409214093140941409514096140971409814099141001410114102141031410414105141061410714108141091411014111141121411314114141151411614117141181411914120141211412214123141241412514126141271412814129141301413114132141331413414135141361413714138141391414014141141421414314144141451414614147141481414914150141511415214153141541415514156141571415814159141601416114162141631416414165141661416714168141691417014171141721417314174141751417614177141781417914180141811418214183141841418514186141871418814189141901419114192141931419414195141961419714198141991420014201142021420314204142051420614207142081420914210142111421214213142141421514216142171421814219142201422114222142231422414225142261422714228142291423014231142321423314234142351423614237142381423914240142411424214243142441424514246142471424814249142501425114252142531425414255142561425714258142591426014261142621426314264142651426614267142681426914270142711427214273142741427514276142771427814279142801428114282142831428414285142861428714288142891429014291142921429314294142951429614297142981429914300143011430214303143041430514306143071430814309143101431114312143131431414315143161431714318143191432014321143221432314324143251432614327143281432914330143311433214333143341433514336143371433814339143401434114342143431434414345143461434714348143491435014351143521435314354143551435614357143581435914360143611436214363143641436514366143671436814369143701437114372143731437414375143761437714378143791438014381143821438314384143851438614387143881438914390143911439214393143941439514396143971439814399144001440114402144031440414405144061440714408144091441014411144121441314414144151441614417144181441914420144211442214423144241442514426144271442814429144301443114432144331443414435144361443714438144391444014441144421444314444144451444614447144481444914450144511445214453144541445514456144571445814459144601446114462144631446414465144661446714468144691447014471144721447314474144751447614477144781447914480144811448214483144841448514486144871448814489144901449114492144931449414495144961449714498144991450014501145021450314504145051450614507145081450914510145111451214513145141451514516145171451814519145201452114522145231452414525145261452714528145291453014531145321453314534145351453614537145381453914540145411454214543145441454514546145471454814549145501455114552145531455414555145561455714558145591456014561145621456314564145651456614567145681456914570145711457214573145741457514576145771457814579145801458114582145831458414585145861458714588145891459014591145921459314594145951459614597145981459914600146011460214603146041460514606146071460814609146101461114612146131461414615146161461714618146191462014621146221462314624146251462614627146281462914630146311463214633146341463514636146371463814639146401464114642146431464414645146461464714648146491465014651146521465314654146551465614657146581465914660146611466214663146641466514666146671466814669146701467114672146731467414675146761467714678146791468014681146821468314684146851468614687146881468914690146911469214693146941469514696146971469814699147001470114702147031470414705147061470714708147091471014711147121471314714147151471614717147181471914720147211472214723147241472514726147271472814729147301473114732147331473414735147361473714738147391474014741147421474314744147451474614747147481474914750147511475214753147541475514756147571475814759147601476114762147631476414765147661476714768147691477014771147721477314774147751477614777147781477914780147811478214783147841478514786147871478814789147901479114792147931479414795147961479714798147991480014801148021480314804148051480614807148081480914810148111481214813148141481514816148171481814819148201482114822148231482414825148261482714828148291483014831148321483314834148351483614837148381483914840148411484214843148441484514846148471484814849148501485114852148531485414855148561485714858148591486014861148621486314864148651486614867148681486914870148711487214873148741487514876148771487814879148801488114882148831488414885148861488714888148891489014891148921489314894148951489614897148981489914900149011490214903149041490514906149071490814909149101491114912149131491414915149161491714918149191492014921149221492314924149251492614927149281492914930149311493214933149341493514936149371493814939149401494114942149431494414945149461494714948149491495014951149521495314954149551495614957149581495914960149611496214963149641496514966149671496814969149701497114972149731497414975149761497714978149791498014981149821498314984149851498614987149881498914990149911499214993149941499514996149971499814999150001500115002150031500415005150061500715008150091501015011150121501315014150151501615017150181501915020150211502215023150241502515026150271502815029150301503115032150331503415035150361503715038150391504015041150421504315044150451504615047150481504915050150511505215053150541505515056150571505815059150601506115062150631506415065150661506715068150691507015071150721507315074150751507615077150781507915080150811508215083150841508515086150871508815089150901509115092150931509415095150961509715098150991510015101151021510315104151051510615107151081510915110151111511215113151141511515116151171511815119151201512115122151231512415125151261512715128151291513015131151321513315134151351513615137151381513915140151411514215143151441514515146151471514815149151501515115152151531515415155151561515715158151591516015161151621516315164151651516615167151681516915170151711517215173151741517515176151771517815179151801518115182151831518415185151861518715188151891519015191151921519315194151951519615197151981519915200152011520215203152041520515206152071520815209152101521115212152131521415215152161521715218152191522015221152221522315224152251522615227152281522915230152311523215233152341523515236152371523815239152401524115242152431524415245152461524715248152491525015251152521525315254152551525615257152581525915260152611526215263152641526515266152671526815269152701527115272152731527415275152761527715278152791528015281152821528315284152851528615287152881528915290152911529215293152941529515296152971529815299153001530115302153031530415305153061530715308153091531015311153121531315314153151531615317153181531915320153211532215323153241532515326153271532815329153301533115332153331533415335153361533715338153391534015341153421534315344153451534615347153481534915350153511535215353153541535515356153571535815359153601536115362153631536415365153661536715368153691537015371153721537315374153751537615377153781537915380153811538215383153841538515386153871538815389153901539115392153931539415395153961539715398153991540015401154021540315404154051540615407154081540915410154111541215413154141541515416154171541815419154201542115422154231542415425154261542715428154291543015431154321543315434154351543615437154381543915440154411544215443154441544515446154471544815449154501545115452154531545415455154561545715458154591546015461154621546315464154651546615467154681546915470154711547215473154741547515476154771547815479154801548115482154831548415485154861548715488154891549015491154921549315494154951549615497154981549915500155011550215503155041550515506155071550815509155101551115512155131551415515155161551715518155191552015521155221552315524155251552615527155281552915530155311553215533155341553515536155371553815539155401554115542155431554415545155461554715548155491555015551155521555315554155551555615557155581555915560155611556215563155641556515566155671556815569155701557115572155731557415575155761557715578155791558015581155821558315584155851558615587155881558915590155911559215593155941559515596155971559815599156001560115602156031560415605156061560715608156091561015611156121561315614156151561615617156181561915620156211562215623156241562515626156271562815629156301563115632156331563415635156361563715638156391564015641156421564315644156451564615647156481564915650156511565215653156541565515656156571565815659156601566115662156631566415665156661566715668156691567015671156721567315674156751567615677156781567915680156811568215683156841568515686156871568815689156901569115692156931569415695156961569715698156991570015701157021570315704157051570615707157081570915710157111571215713157141571515716157171571815719157201572115722157231572415725157261572715728157291573015731157321573315734157351573615737157381573915740157411574215743157441574515746157471574815749157501575115752157531575415755157561575715758157591576015761157621576315764157651576615767157681576915770157711577215773157741577515776157771577815779157801578115782157831578415785157861578715788157891579015791157921579315794157951579615797157981579915800158011580215803158041580515806158071580815809158101581115812158131581415815158161581715818158191582015821158221582315824158251582615827158281582915830158311583215833158341583515836158371583815839158401584115842158431584415845158461584715848158491585015851158521585315854158551585615857158581585915860158611586215863158641586515866158671586815869158701587115872158731587415875158761587715878158791588015881158821588315884158851588615887158881588915890158911589215893158941589515896158971589815899159001590115902159031590415905159061590715908159091591015911159121591315914159151591615917159181591915920159211592215923159241592515926159271592815929159301593115932159331593415935159361593715938159391594015941159421594315944159451594615947159481594915950159511595215953159541595515956159571595815959159601596115962159631596415965159661596715968159691597015971159721597315974159751597615977159781597915980159811598215983159841598515986159871598815989159901599115992159931599415995159961599715998159991600016001160021600316004160051600616007160081600916010160111601216013160141601516016160171601816019160201602116022160231602416025160261602716028160291603016031160321603316034160351603616037160381603916040160411604216043160441604516046160471604816049160501605116052160531605416055160561605716058160591606016061160621606316064160651606616067160681606916070160711607216073160741607516076160771607816079160801608116082160831608416085160861608716088160891609016091160921609316094160951609616097160981609916100161011610216103161041610516106161071610816109161101611116112161131611416115161161611716118161191612016121161221612316124161251612616127161281612916130161311613216133161341613516136161371613816139161401614116142161431614416145161461614716148161491615016151161521615316154161551615616157161581615916160161611616216163161641616516166161671616816169161701617116172161731617416175161761617716178161791618016181161821618316184161851618616187161881618916190161911619216193161941619516196161971619816199162001620116202162031620416205162061620716208162091621016211162121621316214162151621616217162181621916220162211622216223162241622516226162271622816229162301623116232162331623416235162361623716238162391624016241162421624316244162451624616247162481624916250162511625216253162541625516256162571625816259162601626116262162631626416265162661626716268162691627016271162721627316274162751627616277162781627916280162811628216283162841628516286162871628816289162901629116292162931629416295162961629716298162991630016301163021630316304163051630616307163081630916310163111631216313163141631516316163171631816319163201632116322163231632416325163261632716328163291633016331163321633316334163351633616337163381633916340163411634216343163441634516346163471634816349163501635116352163531635416355163561635716358163591636016361163621636316364163651636616367163681636916370163711637216373163741637516376163771637816379163801638116382163831638416385163861638716388163891639016391163921639316394163951639616397163981639916400164011640216403164041640516406164071640816409164101641116412164131641416415164161641716418164191642016421164221642316424164251642616427164281642916430164311643216433164341643516436164371643816439164401644116442164431644416445164461644716448164491645016451164521645316454164551645616457164581645916460164611646216463164641646516466164671646816469164701647116472164731647416475164761647716478164791648016481164821648316484164851648616487164881648916490164911649216493164941649516496164971649816499165001650116502165031650416505165061650716508165091651016511165121651316514165151651616517165181651916520165211652216523165241652516526165271652816529165301653116532165331653416535165361653716538165391654016541165421654316544165451654616547165481654916550165511655216553165541655516556165571655816559165601656116562165631656416565165661656716568165691657016571165721657316574165751657616577165781657916580165811658216583165841658516586165871658816589165901659116592165931659416595165961659716598165991660016601166021660316604166051660616607166081660916610166111661216613166141661516616166171661816619166201662116622166231662416625166261662716628166291663016631166321663316634166351663616637166381663916640166411664216643166441664516646166471664816649166501665116652166531665416655166561665716658166591666016661166621666316664166651666616667166681666916670166711667216673166741667516676166771667816679166801668116682166831668416685166861668716688166891669016691166921669316694166951669616697166981669916700167011670216703167041670516706167071670816709167101671116712167131671416715167161671716718167191672016721167221672316724167251672616727167281672916730167311673216733167341673516736167371673816739167401674116742167431674416745167461674716748167491675016751167521675316754167551675616757167581675916760167611676216763167641676516766167671676816769167701677116772167731677416775167761677716778167791678016781167821678316784167851678616787167881678916790167911679216793167941679516796167971679816799168001680116802168031680416805168061680716808168091681016811168121681316814168151681616817168181681916820168211682216823168241682516826168271682816829168301683116832168331683416835168361683716838168391684016841168421684316844168451684616847168481684916850168511685216853168541685516856168571685816859168601686116862168631686416865168661686716868168691687016871168721687316874168751687616877168781687916880168811688216883168841688516886168871688816889168901689116892168931689416895168961689716898168991690016901169021690316904169051690616907169081690916910169111691216913169141691516916169171691816919169201692116922169231692416925169261692716928169291693016931169321693316934169351693616937169381693916940169411694216943169441694516946169471694816949169501695116952169531695416955169561695716958169591696016961169621696316964169651696616967169681696916970169711697216973169741697516976169771697816979169801698116982169831698416985169861698716988169891699016991169921699316994169951699616997169981699917000170011700217003170041700517006170071700817009170101701117012170131701417015170161701717018170191702017021170221702317024170251702617027170281702917030170311703217033170341703517036170371703817039170401704117042170431704417045170461704717048170491705017051170521705317054170551705617057170581705917060170611706217063170641706517066170671706817069170701707117072170731707417075170761707717078170791708017081170821708317084170851708617087170881708917090170911709217093170941709517096170971709817099171001710117102171031710417105171061710717108171091711017111171121711317114171151711617117171181711917120171211712217123171241712517126171271712817129171301713117132171331713417135171361713717138171391714017141171421714317144171451714617147171481714917150171511715217153171541715517156171571715817159171601716117162171631716417165171661716717168171691717017171171721717317174171751717617177171781717917180171811718217183171841718517186171871718817189171901719117192171931719417195171961719717198171991720017201172021720317204172051720617207172081720917210172111721217213172141721517216172171721817219172201722117222172231722417225172261722717228172291723017231172321723317234172351723617237172381723917240172411724217243172441724517246172471724817249172501725117252172531725417255172561725717258172591726017261172621726317264172651726617267172681726917270172711727217273172741727517276172771727817279172801728117282172831728417285172861728717288172891729017291172921729317294172951729617297172981729917300173011730217303173041730517306173071730817309173101731117312173131731417315173161731717318173191732017321173221732317324173251732617327173281732917330173311733217333173341733517336173371733817339173401734117342173431734417345173461734717348173491735017351173521735317354173551735617357173581735917360173611736217363173641736517366173671736817369173701737117372173731737417375173761737717378173791738017381173821738317384173851738617387173881738917390173911739217393173941739517396173971739817399174001740117402174031740417405174061740717408174091741017411174121741317414174151741617417174181741917420174211742217423174241742517426174271742817429174301743117432174331743417435174361743717438174391744017441174421744317444174451744617447174481744917450174511745217453174541745517456174571745817459174601746117462174631746417465174661746717468174691747017471174721747317474174751747617477174781747917480174811748217483174841748517486174871748817489174901749117492174931749417495174961749717498174991750017501175021750317504175051750617507175081750917510175111751217513175141751517516175171751817519175201752117522175231752417525175261752717528175291753017531175321753317534175351753617537175381753917540175411754217543175441754517546175471754817549175501755117552175531755417555175561755717558175591756017561175621756317564175651756617567175681756917570175711757217573175741757517576175771757817579175801758117582175831758417585175861758717588175891759017591175921759317594175951759617597175981759917600176011760217603176041760517606176071760817609176101761117612176131761417615176161761717618176191762017621176221762317624176251762617627176281762917630176311763217633176341763517636176371763817639176401764117642176431764417645176461764717648176491765017651176521765317654176551765617657176581765917660176611766217663176641766517666176671766817669176701767117672176731767417675176761767717678176791768017681176821768317684176851768617687176881768917690176911769217693176941769517696176971769817699177001770117702177031770417705177061770717708177091771017711177121771317714177151771617717177181771917720177211772217723177241772517726177271772817729177301773117732177331773417735177361773717738177391774017741177421774317744177451774617747177481774917750177511775217753177541775517756177571775817759177601776117762177631776417765177661776717768177691777017771177721777317774177751777617777177781777917780177811778217783177841778517786177871778817789177901779117792177931779417795177961779717798177991780017801178021780317804178051780617807178081780917810178111781217813178141781517816178171781817819178201782117822178231782417825178261782717828178291783017831178321783317834178351783617837178381783917840178411784217843178441784517846178471784817849178501785117852178531785417855178561785717858178591786017861178621786317864178651786617867178681786917870178711787217873178741787517876178771787817879178801788117882178831788417885178861788717888178891789017891178921789317894178951789617897178981789917900179011790217903179041790517906179071790817909179101791117912179131791417915179161791717918179191792017921179221792317924179251792617927179281792917930179311793217933179341793517936179371793817939179401794117942179431794417945179461794717948179491795017951179521795317954179551795617957179581795917960179611796217963179641796517966179671796817969179701797117972179731797417975179761797717978179791798017981179821798317984179851798617987179881798917990179911799217993179941799517996179971799817999180001800118002180031800418005180061800718008180091801018011180121801318014180151801618017180181801918020180211802218023180241802518026180271802818029180301803118032180331803418035180361803718038180391804018041180421804318044180451804618047180481804918050180511805218053180541805518056180571805818059180601806118062180631806418065180661806718068180691807018071180721807318074180751807618077180781807918080180811808218083180841808518086180871808818089180901809118092180931809418095180961809718098180991810018101181021810318104181051810618107181081810918110181111811218113181141811518116181171811818119181201812118122181231812418125181261812718128181291813018131181321813318134181351813618137181381813918140181411814218143181441814518146181471814818149181501815118152181531815418155181561815718158181591816018161181621816318164181651816618167181681816918170181711817218173181741817518176181771817818179181801818118182181831818418185181861818718188181891819018191181921819318194181951819618197181981819918200182011820218203182041820518206182071820818209182101821118212182131821418215182161821718218182191822018221182221822318224182251822618227182281822918230182311823218233182341823518236182371823818239182401824118242182431824418245182461824718248182491825018251182521825318254182551825618257182581825918260182611826218263182641826518266182671826818269182701827118272182731827418275182761827718278182791828018281182821828318284182851828618287182881828918290182911829218293182941829518296182971829818299183001830118302183031830418305183061830718308183091831018311183121831318314183151831618317183181831918320183211832218323183241832518326183271832818329183301833118332183331833418335183361833718338183391834018341183421834318344183451834618347183481834918350183511835218353183541835518356183571835818359183601836118362183631836418365183661836718368183691837018371183721837318374183751837618377183781837918380183811838218383183841838518386183871838818389183901839118392183931839418395183961839718398183991840018401184021840318404184051840618407184081840918410184111841218413184141841518416184171841818419184201842118422184231842418425184261842718428184291843018431184321843318434184351843618437184381843918440184411844218443184441844518446184471844818449184501845118452184531845418455184561845718458184591846018461184621846318464184651846618467184681846918470184711847218473184741847518476184771847818479184801848118482184831848418485184861848718488184891849018491184921849318494184951849618497184981849918500185011850218503185041850518506185071850818509185101851118512185131851418515185161851718518185191852018521185221852318524185251852618527185281852918530185311853218533185341853518536185371853818539185401854118542185431854418545185461854718548185491855018551185521855318554185551855618557185581855918560185611856218563185641856518566185671856818569185701857118572185731857418575185761857718578185791858018581185821858318584185851858618587185881858918590185911859218593185941859518596185971859818599186001860118602186031860418605186061860718608186091861018611186121861318614186151861618617186181861918620186211862218623186241862518626186271862818629186301863118632186331863418635186361863718638186391864018641186421864318644186451864618647186481864918650186511865218653186541865518656186571865818659186601866118662186631866418665186661866718668186691867018671186721867318674186751867618677186781867918680186811868218683186841868518686186871868818689186901869118692186931869418695186961869718698186991870018701187021870318704187051870618707187081870918710187111871218713187141871518716187171871818719187201872118722187231872418725187261872718728187291873018731187321873318734187351873618737187381873918740187411874218743187441874518746187471874818749187501875118752187531875418755187561875718758187591876018761187621876318764187651876618767187681876918770187711877218773187741877518776187771877818779187801878118782187831878418785187861878718788187891879018791187921879318794187951879618797187981879918800188011880218803188041880518806188071880818809188101881118812188131881418815188161881718818188191882018821188221882318824188251882618827188281882918830188311883218833188341883518836188371883818839188401884118842188431884418845188461884718848188491885018851188521885318854188551885618857188581885918860188611886218863188641886518866188671886818869188701887118872188731887418875188761887718878188791888018881188821888318884188851888618887188881888918890188911889218893188941889518896188971889818899189001890118902189031890418905189061890718908189091891018911189121891318914189151891618917189181891918920189211892218923189241892518926189271892818929189301893118932189331893418935189361893718938189391894018941189421894318944189451894618947189481894918950189511895218953189541895518956189571895818959189601896118962189631896418965189661896718968189691897018971189721897318974189751897618977189781897918980189811898218983189841898518986189871898818989189901899118992189931899418995189961899718998189991900019001190021900319004190051900619007190081900919010190111901219013190141901519016190171901819019190201902119022190231902419025190261902719028190291903019031190321903319034190351903619037190381903919040190411904219043190441904519046190471904819049190501905119052190531905419055190561905719058190591906019061190621906319064190651906619067190681906919070190711907219073190741907519076190771907819079190801908119082190831908419085190861908719088190891909019091190921909319094190951909619097190981909919100191011910219103191041910519106191071910819109191101911119112191131911419115191161911719118191191912019121191221912319124191251912619127191281912919130191311913219133191341913519136191371913819139191401914119142191431914419145191461914719148191491915019151191521915319154191551915619157191581915919160191611916219163191641916519166191671916819169191701917119172191731917419175191761917719178191791918019181191821918319184191851918619187191881918919190191911919219193191941919519196191971919819199192001920119202192031920419205192061920719208192091921019211192121921319214192151921619217192181921919220192211922219223192241922519226192271922819229192301923119232192331923419235192361923719238192391924019241192421924319244192451924619247192481924919250192511925219253192541925519256192571925819259192601926119262192631926419265192661926719268192691927019271192721927319274192751927619277192781927919280192811928219283192841928519286192871928819289192901929119292192931929419295192961929719298192991930019301193021930319304193051930619307193081930919310193111931219313193141931519316193171931819319193201932119322193231932419325193261932719328193291933019331193321933319334193351933619337193381933919340193411934219343193441934519346193471934819349193501935119352193531935419355193561935719358193591936019361193621936319364193651936619367193681936919370193711937219373193741937519376193771937819379193801938119382193831938419385193861938719388193891939019391193921939319394193951939619397193981939919400194011940219403194041940519406194071940819409194101941119412194131941419415194161941719418194191942019421194221942319424194251942619427194281942919430194311943219433194341943519436194371943819439194401944119442194431944419445194461944719448194491945019451194521945319454194551945619457194581945919460194611946219463194641946519466194671946819469194701947119472194731947419475194761947719478194791948019481194821948319484194851948619487194881948919490194911949219493194941949519496194971949819499195001950119502195031950419505195061950719508195091951019511195121951319514195151951619517195181951919520195211952219523195241952519526195271952819529195301953119532195331953419535195361953719538195391954019541195421954319544195451954619547195481954919550195511955219553195541955519556195571955819559195601956119562195631956419565195661956719568195691957019571195721957319574195751957619577195781957919580195811958219583195841958519586195871958819589195901959119592195931959419595195961959719598195991960019601196021960319604196051960619607196081960919610196111961219613196141961519616196171961819619196201962119622196231962419625196261962719628196291963019631196321963319634196351963619637196381963919640196411964219643196441964519646196471964819649196501965119652196531965419655196561965719658196591966019661196621966319664196651966619667196681966919670196711967219673196741967519676196771967819679196801968119682196831968419685196861968719688196891969019691196921969319694196951969619697196981969919700197011970219703197041970519706197071970819709197101971119712197131971419715197161971719718197191972019721197221972319724197251972619727197281972919730197311973219733197341973519736197371973819739197401974119742197431974419745197461974719748197491975019751197521975319754197551975619757197581975919760197611976219763197641976519766197671976819769197701977119772197731977419775197761977719778197791978019781197821978319784197851978619787197881978919790197911979219793197941979519796197971979819799198001980119802198031980419805198061980719808198091981019811198121981319814198151981619817198181981919820198211982219823198241982519826198271982819829198301983119832198331983419835198361983719838198391984019841198421984319844198451984619847198481984919850198511985219853198541985519856198571985819859198601986119862198631986419865198661986719868198691987019871198721987319874198751987619877198781987919880198811988219883198841988519886198871988819889198901989119892198931989419895198961989719898198991990019901199021990319904199051990619907199081990919910199111991219913199141991519916199171991819919199201992119922199231992419925199261992719928199291993019931199321993319934199351993619937199381993919940199411994219943199441994519946199471994819949199501995119952199531995419955199561995719958199591996019961199621996319964199651996619967199681996919970199711997219973199741997519976199771997819979199801998119982199831998419985199861998719988199891999019991199921999319994199951999619997199981999920000200012000220003200042000520006200072000820009200102001120012200132001420015200162001720018200192002020021200222002320024200252002620027200282002920030200312003220033200342003520036200372003820039200402004120042200432004420045200462004720048200492005020051200522005320054200552005620057200582005920060200612006220063200642006520066200672006820069200702007120072200732007420075200762007720078200792008020081200822008320084200852008620087200882008920090200912009220093200942009520096200972009820099201002010120102201032010420105201062010720108201092011020111201122011320114201152011620117201182011920120201212012220123201242012520126201272012820129201302013120132201332013420135201362013720138201392014020141201422014320144201452014620147201482014920150201512015220153201542015520156201572015820159201602016120162201632016420165201662016720168201692017020171201722017320174201752017620177201782017920180201812018220183201842018520186201872018820189201902019120192201932019420195201962019720198201992020020201202022020320204202052020620207202082020920210202112021220213202142021520216202172021820219202202022120222202232022420225202262022720228202292023020231202322023320234202352023620237202382023920240202412024220243202442024520246202472024820249202502025120252202532025420255202562025720258202592026020261202622026320264202652026620267202682026920270202712027220273202742027520276202772027820279202802028120282202832028420285202862028720288202892029020291202922029320294202952029620297202982029920300203012030220303203042030520306203072030820309203102031120312203132031420315203162031720318203192032020321203222032320324203252032620327203282032920330203312033220333203342033520336203372033820339203402034120342203432034420345203462034720348203492035020351203522035320354203552035620357203582035920360203612036220363203642036520366203672036820369203702037120372203732037420375203762037720378203792038020381203822038320384203852038620387203882038920390203912039220393203942039520396203972039820399204002040120402204032040420405204062040720408204092041020411204122041320414204152041620417204182041920420204212042220423204242042520426204272042820429204302043120432204332043420435204362043720438204392044020441204422044320444204452044620447204482044920450204512045220453204542045520456204572045820459204602046120462204632046420465204662046720468204692047020471204722047320474204752047620477204782047920480204812048220483204842048520486204872048820489204902049120492204932049420495204962049720498204992050020501205022050320504205052050620507205082050920510205112051220513205142051520516205172051820519205202052120522205232052420525205262052720528205292053020531205322053320534205352053620537205382053920540205412054220543205442054520546205472054820549205502055120552205532055420555205562055720558205592056020561205622056320564205652056620567205682056920570205712057220573205742057520576205772057820579205802058120582205832058420585205862058720588205892059020591205922059320594205952059620597205982059920600206012060220603206042060520606206072060820609206102061120612206132061420615206162061720618206192062020621206222062320624206252062620627206282062920630206312063220633206342063520636206372063820639206402064120642206432064420645206462064720648206492065020651206522065320654206552065620657206582065920660206612066220663206642066520666206672066820669206702067120672206732067420675206762067720678206792068020681206822068320684206852068620687206882068920690206912069220693206942069520696206972069820699207002070120702207032070420705207062070720708207092071020711207122071320714207152071620717207182071920720207212072220723207242072520726207272072820729207302073120732207332073420735207362073720738207392074020741207422074320744207452074620747207482074920750207512075220753207542075520756207572075820759207602076120762207632076420765207662076720768207692077020771207722077320774207752077620777207782077920780207812078220783207842078520786207872078820789207902079120792207932079420795207962079720798207992080020801208022080320804208052080620807208082080920810208112081220813208142081520816208172081820819208202082120822208232082420825208262082720828208292083020831208322083320834208352083620837208382083920840208412084220843208442084520846208472084820849208502085120852208532085420855208562085720858208592086020861208622086320864208652086620867208682086920870208712087220873208742087520876208772087820879208802088120882208832088420885208862088720888208892089020891208922089320894208952089620897208982089920900209012090220903209042090520906209072090820909209102091120912209132091420915209162091720918209192092020921209222092320924209252092620927209282092920930209312093220933209342093520936209372093820939209402094120942209432094420945209462094720948209492095020951209522095320954209552095620957209582095920960209612096220963209642096520966209672096820969209702097120972209732097420975209762097720978209792098020981209822098320984209852098620987209882098920990209912099220993209942099520996209972099820999210002100121002210032100421005210062100721008210092101021011210122101321014210152101621017210182101921020210212102221023210242102521026210272102821029210302103121032210332103421035210362103721038210392104021041210422104321044210452104621047210482104921050210512105221053210542105521056210572105821059210602106121062210632106421065210662106721068210692107021071210722107321074210752107621077210782107921080210812108221083210842108521086210872108821089210902109121092210932109421095210962109721098210992110021101211022110321104211052110621107211082110921110211112111221113211142111521116211172111821119211202112121122211232112421125211262112721128211292113021131211322113321134211352113621137211382113921140211412114221143211442114521146211472114821149211502115121152211532115421155211562115721158211592116021161211622116321164211652116621167211682116921170211712117221173211742117521176211772117821179211802118121182211832118421185211862118721188211892119021191211922119321194211952119621197211982119921200212012120221203212042120521206212072120821209212102121121212212132121421215212162121721218212192122021221212222122321224212252122621227212282122921230212312123221233212342123521236212372123821239212402124121242212432124421245212462124721248212492125021251212522125321254212552125621257212582125921260212612126221263212642126521266212672126821269212702127121272212732127421275212762127721278212792128021281212822128321284212852128621287212882128921290212912129221293212942129521296212972129821299213002130121302213032130421305213062130721308213092131021311213122131321314213152131621317213182131921320213212132221323213242132521326213272132821329213302133121332213332133421335213362133721338213392134021341213422134321344213452134621347213482134921350213512135221353213542135521356213572135821359213602136121362213632136421365213662136721368213692137021371213722137321374213752137621377213782137921380213812138221383213842138521386213872138821389213902139121392213932139421395213962139721398213992140021401214022140321404214052140621407214082140921410214112141221413214142141521416214172141821419214202142121422214232142421425214262142721428214292143021431214322143321434214352143621437214382143921440214412144221443214442144521446214472144821449214502145121452214532145421455214562145721458214592146021461214622146321464214652146621467214682146921470214712147221473214742147521476214772147821479214802148121482214832148421485214862148721488214892149021491214922149321494214952149621497214982149921500215012150221503215042150521506215072150821509215102151121512215132151421515215162151721518215192152021521215222152321524215252152621527215282152921530215312153221533215342153521536215372153821539215402154121542215432154421545215462154721548215492155021551215522155321554215552155621557215582155921560215612156221563215642156521566215672156821569215702157121572215732157421575215762157721578215792158021581215822158321584215852158621587215882158921590215912159221593215942159521596215972159821599216002160121602216032160421605216062160721608216092161021611216122161321614216152161621617216182161921620216212162221623216242162521626216272162821629216302163121632216332163421635216362163721638216392164021641216422164321644216452164621647216482164921650216512165221653216542165521656216572165821659216602166121662216632166421665216662166721668216692167021671216722167321674216752167621677216782167921680216812168221683216842168521686216872168821689216902169121692216932169421695216962169721698216992170021701217022170321704217052170621707217082170921710217112171221713217142171521716217172171821719217202172121722217232172421725217262172721728217292173021731217322173321734217352173621737217382173921740217412174221743217442174521746217472174821749217502175121752217532175421755217562175721758217592176021761217622176321764217652176621767217682176921770217712177221773217742177521776217772177821779217802178121782217832178421785217862178721788217892179021791217922179321794217952179621797217982179921800218012180221803218042180521806218072180821809218102181121812218132181421815218162181721818218192182021821218222182321824218252182621827218282182921830218312183221833218342183521836218372183821839218402184121842218432184421845218462184721848218492185021851218522185321854218552185621857218582185921860218612186221863218642186521866218672186821869218702187121872218732187421875218762187721878218792188021881218822188321884218852188621887218882188921890218912189221893218942189521896218972189821899219002190121902219032190421905219062190721908219092191021911219122191321914219152191621917219182191921920219212192221923219242192521926219272192821929219302193121932219332193421935219362193721938219392194021941219422194321944219452194621947219482194921950219512195221953219542195521956219572195821959219602196121962219632196421965219662196721968219692197021971219722197321974219752197621977219782197921980219812198221983219842198521986219872198821989219902199121992219932199421995219962199721998219992200022001220022200322004220052200622007220082200922010220112201222013220142201522016220172201822019220202202122022220232202422025220262202722028220292203022031220322203322034220352203622037220382203922040220412204222043220442204522046220472204822049220502205122052220532205422055220562205722058220592206022061220622206322064220652206622067220682206922070220712207222073220742207522076220772207822079220802208122082220832208422085220862208722088220892209022091220922209322094220952209622097220982209922100221012210222103221042210522106221072210822109221102211122112221132211422115221162211722118221192212022121221222212322124221252212622127221282212922130221312213222133221342213522136221372213822139221402214122142221432214422145221462214722148221492215022151221522215322154221552215622157221582215922160221612216222163221642216522166221672216822169221702217122172221732217422175221762217722178221792218022181221822218322184221852218622187221882218922190221912219222193221942219522196221972219822199222002220122202222032220422205222062220722208222092221022211222122221322214222152221622217222182221922220222212222222223222242222522226222272222822229222302223122232222332223422235222362223722238222392224022241222422224322244222452224622247222482224922250222512225222253222542225522256222572225822259222602226122262222632226422265222662226722268222692227022271222722227322274222752227622277222782227922280222812228222283222842228522286222872228822289222902229122292222932229422295222962229722298222992230022301223022230322304223052230622307223082230922310223112231222313223142231522316223172231822319223202232122322223232232422325223262232722328223292233022331223322233322334223352233622337223382233922340223412234222343223442234522346223472234822349223502235122352223532235422355223562235722358223592236022361223622236322364223652236622367223682236922370223712237222373223742237522376223772237822379223802238122382223832238422385223862238722388223892239022391223922239322394223952239622397223982239922400224012240222403224042240522406224072240822409224102241122412224132241422415224162241722418224192242022421224222242322424224252242622427224282242922430224312243222433224342243522436224372243822439224402244122442224432244422445224462244722448224492245022451224522245322454224552245622457224582245922460224612246222463224642246522466224672246822469224702247122472224732247422475224762247722478224792248022481224822248322484224852248622487224882248922490224912249222493224942249522496224972249822499225002250122502225032250422505225062250722508225092251022511225122251322514225152251622517225182251922520225212252222523225242252522526225272252822529225302253122532225332253422535225362253722538225392254022541225422254322544225452254622547225482254922550225512255222553225542255522556225572255822559225602256122562225632256422565225662256722568225692257022571225722257322574225752257622577225782257922580225812258222583225842258522586225872258822589225902259122592225932259422595225962259722598225992260022601226022260322604226052260622607226082260922610226112261222613226142261522616226172261822619226202262122622226232262422625226262262722628226292263022631226322263322634226352263622637226382263922640226412264222643226442264522646226472264822649226502265122652226532265422655226562265722658226592266022661226622266322664226652266622667226682266922670226712267222673226742267522676226772267822679226802268122682226832268422685226862268722688226892269022691226922269322694226952269622697226982269922700227012270222703227042270522706227072270822709227102271122712227132271422715227162271722718227192272022721227222272322724227252272622727227282272922730227312273222733227342273522736227372273822739227402274122742227432274422745227462274722748227492275022751227522275322754227552275622757227582275922760227612276222763227642276522766227672276822769227702277122772227732277422775227762277722778227792278022781227822278322784227852278622787227882278922790227912279222793227942279522796227972279822799228002280122802228032280422805228062280722808228092281022811228122281322814228152281622817228182281922820228212282222823228242282522826228272282822829228302283122832228332283422835228362283722838228392284022841228422284322844228452284622847228482284922850228512285222853228542285522856228572285822859228602286122862228632286422865228662286722868228692287022871228722287322874228752287622877228782287922880228812288222883228842288522886228872288822889228902289122892228932289422895228962289722898228992290022901229022290322904229052290622907229082290922910229112291222913229142291522916229172291822919229202292122922229232292422925229262292722928229292293022931229322293322934229352293622937229382293922940229412294222943229442294522946229472294822949229502295122952229532295422955229562295722958229592296022961229622296322964229652296622967229682296922970229712297222973229742297522976229772297822979229802298122982229832298422985229862298722988229892299022991229922299322994229952299622997229982299923000230012300223003230042300523006230072300823009230102301123012230132301423015230162301723018230192302023021230222302323024230252302623027230282302923030230312303223033230342303523036230372303823039230402304123042230432304423045230462304723048230492305023051230522305323054230552305623057230582305923060230612306223063230642306523066230672306823069230702307123072230732307423075230762307723078230792308023081230822308323084230852308623087230882308923090230912309223093230942309523096230972309823099231002310123102231032310423105231062310723108231092311023111231122311323114231152311623117231182311923120231212312223123231242312523126231272312823129231302313123132231332313423135231362313723138231392314023141231422314323144231452314623147231482314923150231512315223153231542315523156231572315823159231602316123162231632316423165231662316723168231692317023171231722317323174231752317623177231782317923180231812318223183231842318523186231872318823189231902319123192231932319423195231962319723198231992320023201232022320323204232052320623207232082320923210232112321223213232142321523216232172321823219232202322123222232232322423225232262322723228232292323023231232322323323234232352323623237232382323923240232412324223243232442324523246232472324823249232502325123252232532325423255232562325723258232592326023261232622326323264232652326623267232682326923270232712327223273232742327523276232772327823279232802328123282232832328423285232862328723288232892329023291232922329323294232952329623297232982329923300233012330223303233042330523306233072330823309233102331123312233132331423315233162331723318233192332023321233222332323324233252332623327233282332923330233312333223333233342333523336233372333823339233402334123342233432334423345233462334723348233492335023351233522335323354233552335623357233582335923360233612336223363233642336523366233672336823369233702337123372233732337423375233762337723378233792338023381233822338323384233852338623387233882338923390233912339223393233942339523396233972339823399234002340123402234032340423405234062340723408234092341023411234122341323414234152341623417234182341923420234212342223423234242342523426234272342823429234302343123432234332343423435234362343723438234392344023441234422344323444234452344623447234482344923450234512345223453234542345523456234572345823459234602346123462234632346423465234662346723468234692347023471234722347323474234752347623477234782347923480234812348223483234842348523486234872348823489234902349123492234932349423495234962349723498234992350023501235022350323504235052350623507235082350923510235112351223513235142351523516235172351823519235202352123522235232352423525235262352723528235292353023531235322353323534235352353623537235382353923540235412354223543235442354523546235472354823549235502355123552235532355423555235562355723558235592356023561235622356323564235652356623567235682356923570235712357223573235742357523576235772357823579235802358123582235832358423585235862358723588235892359023591235922359323594235952359623597235982359923600236012360223603236042360523606236072360823609236102361123612236132361423615236162361723618236192362023621236222362323624236252362623627236282362923630236312363223633236342363523636236372363823639236402364123642236432364423645236462364723648236492365023651236522365323654236552365623657236582365923660236612366223663236642366523666236672366823669236702367123672236732367423675236762367723678236792368023681236822368323684236852368623687236882368923690236912369223693236942369523696236972369823699237002370123702237032370423705237062370723708237092371023711237122371323714237152371623717237182371923720237212372223723237242372523726237272372823729237302373123732237332373423735237362373723738237392374023741237422374323744237452374623747237482374923750237512375223753237542375523756237572375823759237602376123762237632376423765237662376723768237692377023771237722377323774237752377623777237782377923780237812378223783237842378523786237872378823789237902379123792237932379423795237962379723798237992380023801238022380323804238052380623807238082380923810238112381223813238142381523816238172381823819238202382123822238232382423825238262382723828238292383023831238322383323834238352383623837238382383923840238412384223843238442384523846238472384823849238502385123852238532385423855238562385723858238592386023861238622386323864238652386623867238682386923870238712387223873238742387523876238772387823879238802388123882238832388423885238862388723888238892389023891238922389323894238952389623897238982389923900239012390223903239042390523906239072390823909239102391123912239132391423915239162391723918239192392023921239222392323924239252392623927239282392923930239312393223933239342393523936239372393823939239402394123942239432394423945239462394723948239492395023951239522395323954239552395623957239582395923960239612396223963239642396523966239672396823969239702397123972239732397423975239762397723978239792398023981239822398323984239852398623987239882398923990239912399223993239942399523996239972399823999240002400124002240032400424005240062400724008240092401024011240122401324014240152401624017240182401924020240212402224023240242402524026240272402824029240302403124032240332403424035240362403724038240392404024041240422404324044240452404624047240482404924050240512405224053240542405524056240572405824059240602406124062240632406424065240662406724068240692407024071240722407324074240752407624077240782407924080240812408224083240842408524086240872408824089240902409124092240932409424095240962409724098240992410024101241022410324104241052410624107241082410924110241112411224113241142411524116241172411824119241202412124122241232412424125241262412724128241292413024131241322413324134241352413624137241382413924140241412414224143241442414524146241472414824149241502415124152241532415424155241562415724158241592416024161241622416324164241652416624167241682416924170241712417224173241742417524176241772417824179241802418124182241832418424185241862418724188241892419024191241922419324194241952419624197241982419924200242012420224203242042420524206242072420824209242102421124212242132421424215242162421724218242192422024221242222422324224242252422624227242282422924230242312423224233242342423524236242372423824239242402424124242242432424424245242462424724248242492425024251242522425324254242552425624257242582425924260242612426224263242642426524266242672426824269242702427124272242732427424275242762427724278242792428024281242822428324284242852428624287242882428924290242912429224293242942429524296242972429824299243002430124302243032430424305243062430724308243092431024311243122431324314243152431624317243182431924320243212432224323243242432524326243272432824329243302433124332243332433424335243362433724338243392434024341243422434324344243452434624347243482434924350243512435224353243542435524356243572435824359243602436124362243632436424365243662436724368243692437024371243722437324374243752437624377243782437924380243812438224383243842438524386243872438824389243902439124392243932439424395243962439724398243992440024401244022440324404244052440624407244082440924410244112441224413244142441524416244172441824419244202442124422244232442424425244262442724428244292443024431244322443324434244352443624437244382443924440244412444224443244442444524446244472444824449244502445124452244532445424455244562445724458244592446024461244622446324464244652446624467244682446924470244712447224473244742447524476244772447824479244802448124482244832448424485244862448724488244892449024491244922449324494244952449624497244982449924500245012450224503245042450524506245072450824509245102451124512245132451424515245162451724518245192452024521245222452324524245252452624527245282452924530245312453224533245342453524536245372453824539245402454124542245432454424545245462454724548245492455024551245522455324554245552455624557245582455924560245612456224563245642456524566245672456824569245702457124572245732457424575245762457724578245792458024581245822458324584245852458624587245882458924590245912459224593245942459524596245972459824599246002460124602246032460424605246062460724608246092461024611246122461324614246152461624617246182461924620246212462224623246242462524626246272462824629246302463124632246332463424635246362463724638246392464024641246422464324644246452464624647246482464924650246512465224653246542465524656246572465824659246602466124662246632466424665246662466724668246692467024671246722467324674246752467624677246782467924680246812468224683246842468524686246872468824689246902469124692246932469424695246962469724698246992470024701247022470324704247052470624707247082470924710247112471224713247142471524716247172471824719247202472124722247232472424725247262472724728247292473024731247322473324734247352473624737247382473924740247412474224743247442474524746247472474824749247502475124752247532475424755247562475724758247592476024761247622476324764247652476624767247682476924770247712477224773247742477524776247772477824779247802478124782247832478424785247862478724788247892479024791247922479324794247952479624797247982479924800248012480224803248042480524806248072480824809248102481124812248132481424815248162481724818248192482024821248222482324824248252482624827248282482924830248312483224833248342483524836248372483824839248402484124842248432484424845248462484724848248492485024851248522485324854248552485624857248582485924860248612486224863248642486524866248672486824869248702487124872248732487424875248762487724878248792488024881248822488324884248852488624887248882488924890248912489224893248942489524896248972489824899249002490124902249032490424905249062490724908249092491024911249122491324914249152491624917249182491924920249212492224923249242492524926249272492824929249302493124932249332493424935249362493724938249392494024941249422494324944249452494624947249482494924950249512495224953249542495524956249572495824959249602496124962249632496424965249662496724968249692497024971249722497324974249752497624977249782497924980249812498224983249842498524986249872498824989249902499124992249932499424995249962499724998249992500025001250022500325004250052500625007250082500925010250112501225013250142501525016250172501825019250202502125022250232502425025250262502725028250292503025031250322503325034250352503625037250382503925040250412504225043250442504525046250472504825049250502505125052250532505425055250562505725058250592506025061250622506325064250652506625067250682506925070250712507225073250742507525076250772507825079250802508125082250832508425085250862508725088250892509025091250922509325094250952509625097250982509925100251012510225103251042510525106251072510825109251102511125112251132511425115251162511725118251192512025121251222512325124251252512625127251282512925130251312513225133251342513525136251372513825139251402514125142251432514425145251462514725148251492515025151251522515325154251552515625157251582515925160251612516225163251642516525166251672516825169251702517125172251732517425175251762517725178251792518025181251822518325184251852518625187251882518925190251912519225193251942519525196251972519825199252002520125202252032520425205252062520725208252092521025211252122521325214252152521625217252182521925220252212522225223252242522525226252272522825229252302523125232252332523425235252362523725238252392524025241252422524325244252452524625247252482524925250252512525225253252542525525256252572525825259252602526125262252632526425265252662526725268252692527025271252722527325274252752527625277252782527925280252812528225283252842528525286252872528825289252902529125292252932529425295252962529725298252992530025301253022530325304253052530625307253082530925310253112531225313253142531525316253172531825319253202532125322253232532425325253262532725328253292533025331253322533325334253352533625337253382533925340253412534225343253442534525346253472534825349253502535125352253532535425355253562535725358253592536025361253622536325364253652536625367253682536925370253712537225373253742537525376253772537825379253802538125382253832538425385253862538725388253892539025391253922539325394253952539625397253982539925400254012540225403254042540525406254072540825409254102541125412254132541425415254162541725418254192542025421254222542325424254252542625427254282542925430254312543225433254342543525436254372543825439254402544125442254432544425445254462544725448254492545025451254522545325454254552545625457254582545925460254612546225463254642546525466254672546825469254702547125472254732547425475254762547725478254792548025481254822548325484254852548625487254882548925490254912549225493254942549525496254972549825499255002550125502255032550425505255062550725508255092551025511255122551325514255152551625517255182551925520255212552225523255242552525526255272552825529255302553125532255332553425535255362553725538255392554025541255422554325544255452554625547255482554925550255512555225553255542555525556255572555825559255602556125562255632556425565255662556725568255692557025571255722557325574255752557625577255782557925580255812558225583255842558525586255872558825589255902559125592255932559425595255962559725598255992560025601256022560325604256052560625607256082560925610256112561225613256142561525616256172561825619256202562125622256232562425625256262562725628256292563025631256322563325634256352563625637256382563925640256412564225643256442564525646256472564825649256502565125652256532565425655256562565725658256592566025661256622566325664256652566625667256682566925670256712567225673256742567525676256772567825679256802568125682256832568425685256862568725688256892569025691256922569325694256952569625697256982569925700257012570225703257042570525706257072570825709257102571125712257132571425715257162571725718257192572025721257222572325724257252572625727257282572925730257312573225733257342573525736257372573825739257402574125742257432574425745257462574725748257492575025751257522575325754257552575625757257582575925760257612576225763257642576525766257672576825769257702577125772257732577425775257762577725778257792578025781257822578325784257852578625787257882578925790257912579225793257942579525796257972579825799258002580125802258032580425805258062580725808258092581025811258122581325814258152581625817258182581925820258212582225823258242582525826258272582825829258302583125832258332583425835258362583725838258392584025841258422584325844258452584625847258482584925850258512585225853258542585525856258572585825859258602586125862258632586425865258662586725868258692587025871258722587325874258752587625877258782587925880258812588225883258842588525886258872588825889258902589125892258932589425895258962589725898258992590025901259022590325904259052590625907259082590925910259112591225913259142591525916259172591825919259202592125922259232592425925259262592725928259292593025931259322593325934259352593625937259382593925940259412594225943259442594525946259472594825949259502595125952259532595425955259562595725958259592596025961259622596325964259652596625967259682596925970259712597225973259742597525976259772597825979259802598125982259832598425985259862598725988259892599025991259922599325994259952599625997259982599926000260012600226003260042600526006260072600826009260102601126012260132601426015260162601726018260192602026021260222602326024260252602626027260282602926030260312603226033260342603526036260372603826039260402604126042260432604426045260462604726048260492605026051260522605326054260552605626057260582605926060260612606226063260642606526066260672606826069260702607126072260732607426075260762607726078260792608026081260822608326084260852608626087260882608926090260912609226093260942609526096260972609826099261002610126102261032610426105261062610726108261092611026111261122611326114261152611626117261182611926120261212612226123261242612526126261272612826129261302613126132261332613426135261362613726138261392614026141261422614326144261452614626147261482614926150261512615226153261542615526156261572615826159261602616126162261632616426165261662616726168261692617026171261722617326174261752617626177261782617926180261812618226183261842618526186261872618826189261902619126192261932619426195261962619726198261992620026201262022620326204262052620626207262082620926210262112621226213262142621526216262172621826219262202622126222262232622426225262262622726228262292623026231262322623326234262352623626237262382623926240262412624226243262442624526246262472624826249262502625126252262532625426255262562625726258262592626026261262622626326264262652626626267262682626926270262712627226273262742627526276262772627826279262802628126282262832628426285262862628726288262892629026291262922629326294262952629626297262982629926300263012630226303263042630526306263072630826309263102631126312263132631426315263162631726318263192632026321263222632326324263252632626327263282632926330263312633226333263342633526336263372633826339263402634126342263432634426345263462634726348263492635026351263522635326354263552635626357263582635926360263612636226363263642636526366263672636826369263702637126372263732637426375263762637726378263792638026381263822638326384263852638626387263882638926390263912639226393263942639526396263972639826399264002640126402264032640426405264062640726408264092641026411264122641326414264152641626417264182641926420264212642226423264242642526426264272642826429264302643126432264332643426435264362643726438264392644026441264422644326444264452644626447264482644926450264512645226453264542645526456264572645826459264602646126462264632646426465264662646726468264692647026471264722647326474264752647626477264782647926480264812648226483264842648526486264872648826489264902649126492264932649426495264962649726498264992650026501265022650326504265052650626507265082650926510265112651226513265142651526516265172651826519265202652126522265232652426525265262652726528265292653026531265322653326534265352653626537265382653926540265412654226543265442654526546265472654826549265502655126552265532655426555265562655726558265592656026561265622656326564265652656626567265682656926570265712657226573265742657526576265772657826579265802658126582265832658426585265862658726588265892659026591265922659326594265952659626597265982659926600266012660226603266042660526606266072660826609266102661126612266132661426615266162661726618266192662026621266222662326624266252662626627266282662926630266312663226633266342663526636266372663826639266402664126642266432664426645266462664726648266492665026651266522665326654266552665626657266582665926660266612666226663266642666526666266672666826669266702667126672266732667426675266762667726678266792668026681266822668326684266852668626687266882668926690266912669226693266942669526696266972669826699267002670126702267032670426705267062670726708267092671026711267122671326714267152671626717267182671926720267212672226723267242672526726267272672826729267302673126732267332673426735267362673726738267392674026741267422674326744267452674626747267482674926750267512675226753267542675526756267572675826759267602676126762267632676426765267662676726768267692677026771267722677326774267752677626777267782677926780267812678226783267842678526786267872678826789267902679126792267932679426795267962679726798267992680026801268022680326804268052680626807268082680926810268112681226813268142681526816268172681826819268202682126822268232682426825268262682726828268292683026831268322683326834268352683626837268382683926840268412684226843268442684526846268472684826849268502685126852268532685426855268562685726858268592686026861268622686326864268652686626867268682686926870268712687226873268742687526876268772687826879268802688126882268832688426885268862688726888268892689026891268922689326894268952689626897268982689926900269012690226903269042690526906269072690826909269102691126912269132691426915269162691726918269192692026921269222692326924269252692626927269282692926930269312693226933269342693526936269372693826939269402694126942269432694426945269462694726948269492695026951269522695326954269552695626957269582695926960269612696226963269642696526966269672696826969269702697126972269732697426975269762697726978269792698026981269822698326984269852698626987269882698926990269912699226993269942699526996269972699826999270002700127002270032700427005270062700727008270092701027011270122701327014270152701627017270182701927020270212702227023270242702527026270272702827029270302703127032270332703427035270362703727038270392704027041270422704327044270452704627047270482704927050270512705227053270542705527056270572705827059270602706127062270632706427065270662706727068270692707027071270722707327074270752707627077270782707927080270812708227083270842708527086270872708827089270902709127092270932709427095270962709727098270992710027101271022710327104271052710627107271082710927110271112711227113271142711527116271172711827119271202712127122271232712427125271262712727128271292713027131271322713327134271352713627137271382713927140271412714227143271442714527146271472714827149271502715127152271532715427155271562715727158271592716027161271622716327164271652716627167271682716927170271712717227173271742717527176271772717827179271802718127182271832718427185271862718727188271892719027191271922719327194271952719627197271982719927200272012720227203272042720527206272072720827209272102721127212272132721427215272162721727218272192722027221272222722327224272252722627227272282722927230272312723227233272342723527236272372723827239272402724127242272432724427245272462724727248272492725027251272522725327254272552725627257272582725927260272612726227263272642726527266272672726827269272702727127272272732727427275272762727727278272792728027281272822728327284272852728627287272882728927290272912729227293272942729527296272972729827299273002730127302273032730427305273062730727308273092731027311273122731327314273152731627317273182731927320273212732227323273242732527326273272732827329273302733127332273332733427335273362733727338273392734027341273422734327344273452734627347273482734927350273512735227353273542735527356273572735827359273602736127362273632736427365273662736727368273692737027371273722737327374273752737627377273782737927380273812738227383273842738527386273872738827389273902739127392273932739427395273962739727398273992740027401274022740327404274052740627407274082740927410274112741227413274142741527416274172741827419274202742127422274232742427425274262742727428274292743027431274322743327434274352743627437274382743927440274412744227443274442744527446274472744827449274502745127452274532745427455274562745727458274592746027461274622746327464274652746627467274682746927470274712747227473274742747527476274772747827479274802748127482274832748427485274862748727488274892749027491274922749327494274952749627497274982749927500275012750227503275042750527506275072750827509275102751127512275132751427515275162751727518275192752027521275222752327524275252752627527275282752927530275312753227533275342753527536275372753827539275402754127542275432754427545275462754727548275492755027551275522755327554275552755627557275582755927560275612756227563275642756527566275672756827569275702757127572275732757427575275762757727578275792758027581275822758327584275852758627587275882758927590275912759227593275942759527596275972759827599276002760127602276032760427605276062760727608276092761027611276122761327614276152761627617276182761927620276212762227623276242762527626276272762827629276302763127632276332763427635276362763727638276392764027641276422764327644276452764627647276482764927650276512765227653276542765527656276572765827659276602766127662276632766427665276662766727668276692767027671276722767327674276752767627677276782767927680276812768227683276842768527686276872768827689276902769127692276932769427695276962769727698276992770027701277022770327704277052770627707277082770927710277112771227713277142771527716277172771827719277202772127722277232772427725277262772727728277292773027731277322773327734277352773627737277382773927740277412774227743277442774527746277472774827749277502775127752277532775427755277562775727758277592776027761277622776327764277652776627767277682776927770277712777227773277742777527776277772777827779277802778127782277832778427785277862778727788277892779027791277922779327794277952779627797277982779927800278012780227803278042780527806278072780827809278102781127812278132781427815278162781727818278192782027821278222782327824278252782627827278282782927830278312783227833278342783527836278372783827839278402784127842278432784427845278462784727848278492785027851278522785327854278552785627857278582785927860278612786227863278642786527866278672786827869278702787127872278732787427875278762787727878278792788027881278822788327884278852788627887278882788927890278912789227893278942789527896278972789827899279002790127902279032790427905279062790727908279092791027911279122791327914279152791627917279182791927920279212792227923279242792527926279272792827929279302793127932279332793427935279362793727938279392794027941279422794327944279452794627947279482794927950279512795227953279542795527956279572795827959279602796127962279632796427965279662796727968279692797027971279722797327974279752797627977279782797927980279812798227983279842798527986279872798827989279902799127992279932799427995279962799727998279992800028001280022800328004280052800628007280082800928010280112801228013280142801528016280172801828019280202802128022280232802428025280262802728028280292803028031280322803328034280352803628037280382803928040280412804228043280442804528046280472804828049280502805128052280532805428055280562805728058280592806028061280622806328064280652806628067280682806928070280712807228073280742807528076280772807828079280802808128082280832808428085280862808728088280892809028091280922809328094280952809628097280982809928100281012810228103281042810528106281072810828109281102811128112281132811428115281162811728118281192812028121281222812328124281252812628127281282812928130281312813228133281342813528136281372813828139281402814128142281432814428145281462814728148281492815028151281522815328154281552815628157281582815928160281612816228163281642816528166281672816828169281702817128172281732817428175281762817728178281792818028181281822818328184281852818628187281882818928190281912819228193281942819528196281972819828199282002820128202282032820428205282062820728208282092821028211282122821328214282152821628217282182821928220282212822228223282242822528226282272822828229282302823128232282332823428235282362823728238282392824028241282422824328244282452824628247282482824928250282512825228253282542825528256282572825828259282602826128262282632826428265282662826728268282692827028271282722827328274282752827628277282782827928280282812828228283282842828528286282872828828289282902829128292282932829428295282962829728298282992830028301283022830328304283052830628307283082830928310283112831228313283142831528316283172831828319283202832128322283232832428325283262832728328283292833028331283322833328334283352833628337283382833928340283412834228343283442834528346283472834828349283502835128352283532835428355283562835728358283592836028361283622836328364283652836628367283682836928370283712837228373283742837528376283772837828379283802838128382283832838428385283862838728388283892839028391283922839328394283952839628397283982839928400284012840228403284042840528406284072840828409284102841128412284132841428415284162841728418284192842028421284222842328424284252842628427284282842928430284312843228433284342843528436284372843828439284402844128442284432844428445284462844728448284492845028451284522845328454284552845628457284582845928460284612846228463284642846528466284672846828469284702847128472284732847428475284762847728478284792848028481284822848328484284852848628487284882848928490284912849228493284942849528496284972849828499285002850128502285032850428505285062850728508285092851028511285122851328514285152851628517285182851928520285212852228523285242852528526285272852828529285302853128532285332853428535285362853728538285392854028541285422854328544285452854628547285482854928550285512855228553285542855528556285572855828559285602856128562285632856428565285662856728568285692857028571285722857328574285752857628577285782857928580285812858228583285842858528586285872858828589285902859128592285932859428595285962859728598285992860028601286022860328604286052860628607286082860928610286112861228613286142861528616286172861828619286202862128622286232862428625286262862728628286292863028631286322863328634286352863628637286382863928640286412864228643286442864528646286472864828649286502865128652286532865428655286562865728658286592866028661286622866328664286652866628667286682866928670286712867228673286742867528676286772867828679286802868128682286832868428685286862868728688286892869028691286922869328694286952869628697286982869928700287012870228703287042870528706287072870828709287102871128712287132871428715287162871728718287192872028721287222872328724287252872628727287282872928730287312873228733287342873528736287372873828739287402874128742287432874428745287462874728748287492875028751287522875328754287552875628757287582875928760287612876228763287642876528766287672876828769287702877128772287732877428775287762877728778287792878028781287822878328784287852878628787287882878928790287912879228793287942879528796287972879828799288002880128802288032880428805288062880728808288092881028811288122881328814288152881628817288182881928820288212882228823288242882528826288272882828829288302883128832288332883428835288362883728838288392884028841288422884328844288452884628847288482884928850288512885228853288542885528856288572885828859288602886128862288632886428865288662886728868288692887028871288722887328874288752887628877288782887928880288812888228883288842888528886288872888828889288902889128892288932889428895288962889728898288992890028901289022890328904289052890628907289082890928910289112891228913289142891528916289172891828919289202892128922289232892428925289262892728928289292893028931289322893328934289352893628937289382893928940289412894228943289442894528946289472894828949289502895128952289532895428955289562895728958289592896028961289622896328964289652896628967289682896928970289712897228973289742897528976289772897828979289802898128982289832898428985289862898728988289892899028991289922899328994289952899628997289982899929000290012900229003290042900529006290072900829009290102901129012290132901429015290162901729018290192902029021290222902329024290252902629027290282902929030290312903229033290342903529036290372903829039290402904129042290432904429045290462904729048290492905029051290522905329054290552905629057290582905929060290612906229063290642906529066290672906829069290702907129072290732907429075290762907729078290792908029081290822908329084290852908629087290882908929090290912909229093290942909529096290972909829099291002910129102291032910429105291062910729108291092911029111291122911329114291152911629117291182911929120291212912229123291242912529126291272912829129291302913129132291332913429135291362913729138291392914029141291422914329144291452914629147291482914929150291512915229153291542915529156291572915829159291602916129162291632916429165291662916729168291692917029171291722917329174291752917629177291782917929180291812918229183291842918529186291872918829189291902919129192291932919429195291962919729198291992920029201292022920329204292052920629207292082920929210292112921229213292142921529216292172921829219292202922129222292232922429225292262922729228292292923029231292322923329234292352923629237292382923929240292412924229243292442924529246292472924829249292502925129252292532925429255292562925729258292592926029261292622926329264292652926629267292682926929270292712927229273292742927529276292772927829279292802928129282292832928429285292862928729288292892929029291292922929329294292952929629297292982929929300293012930229303293042930529306293072930829309293102931129312293132931429315293162931729318293192932029321293222932329324293252932629327293282932929330293312933229333293342933529336293372933829339293402934129342293432934429345293462934729348293492935029351293522935329354293552935629357293582935929360293612936229363293642936529366293672936829369293702937129372293732937429375293762937729378293792938029381293822938329384293852938629387293882938929390293912939229393293942939529396293972939829399294002940129402294032940429405294062940729408294092941029411294122941329414294152941629417294182941929420294212942229423294242942529426294272942829429294302943129432294332943429435294362943729438294392944029441294422944329444294452944629447294482944929450294512945229453294542945529456294572945829459294602946129462294632946429465294662946729468294692947029471294722947329474294752947629477294782947929480294812948229483294842948529486294872948829489294902949129492294932949429495294962949729498294992950029501295022950329504295052950629507295082950929510295112951229513295142951529516295172951829519295202952129522295232952429525295262952729528295292953029531295322953329534295352953629537295382953929540295412954229543295442954529546295472954829549295502955129552295532955429555295562955729558295592956029561295622956329564295652956629567295682956929570295712957229573295742957529576295772957829579295802958129582295832958429585295862958729588295892959029591295922959329594295952959629597295982959929600296012960229603296042960529606296072960829609296102961129612296132961429615296162961729618296192962029621296222962329624296252962629627296282962929630296312963229633296342963529636296372963829639296402964129642296432964429645296462964729648296492965029651296522965329654296552965629657296582965929660296612966229663296642966529666296672966829669296702967129672296732967429675296762967729678296792968029681296822968329684296852968629687296882968929690296912969229693296942969529696296972969829699297002970129702297032970429705297062970729708297092971029711297122971329714297152971629717297182971929720297212972229723297242972529726297272972829729297302973129732297332973429735297362973729738297392974029741297422974329744297452974629747297482974929750297512975229753297542975529756297572975829759297602976129762297632976429765297662976729768297692977029771297722977329774297752977629777297782977929780297812978229783297842978529786297872978829789297902979129792297932979429795297962979729798297992980029801298022980329804298052980629807298082980929810298112981229813298142981529816298172981829819298202982129822298232982429825298262982729828298292983029831298322983329834298352983629837298382983929840298412984229843298442984529846298472984829849298502985129852298532985429855298562985729858298592986029861298622986329864298652986629867298682986929870298712987229873298742987529876298772987829879298802988129882298832988429885298862988729888298892989029891298922989329894298952989629897298982989929900299012990229903299042990529906299072990829909299102991129912299132991429915299162991729918299192992029921299222992329924299252992629927299282992929930299312993229933299342993529936299372993829939299402994129942299432994429945299462994729948299492995029951299522995329954299552995629957299582995929960299612996229963299642996529966299672996829969299702997129972299732997429975299762997729978299792998029981299822998329984299852998629987299882998929990299912999229993299942999529996299972999829999300003000130002300033000430005300063000730008300093001030011300123001330014300153001630017300183001930020300213002230023300243002530026300273002830029300303003130032300333003430035300363003730038300393004030041300423004330044300453004630047300483004930050300513005230053300543005530056300573005830059300603006130062300633006430065300663006730068300693007030071300723007330074300753007630077300783007930080300813008230083300843008530086300873008830089300903009130092300933009430095300963009730098300993010030101301023010330104301053010630107301083010930110301113011230113301143011530116301173011830119301203012130122301233012430125301263012730128301293013030131301323013330134301353013630137301383013930140301413014230143301443014530146301473014830149301503015130152301533015430155301563015730158301593016030161301623016330164301653016630167301683016930170301713017230173301743017530176301773017830179301803018130182301833018430185301863018730188301893019030191301923019330194301953019630197301983019930200302013020230203302043020530206302073020830209302103021130212302133021430215302163021730218302193022030221302223022330224302253022630227302283022930230302313023230233302343023530236302373023830239302403024130242302433024430245302463024730248302493025030251302523025330254302553025630257302583025930260302613026230263302643026530266302673026830269302703027130272302733027430275302763027730278302793028030281302823028330284302853028630287302883028930290302913029230293302943029530296302973029830299303003030130302303033030430305303063030730308303093031030311303123031330314303153031630317303183031930320303213032230323303243032530326303273032830329303303033130332303333033430335303363033730338303393034030341303423034330344303453034630347303483034930350303513035230353303543035530356303573035830359303603036130362303633036430365303663036730368303693037030371303723037330374303753037630377303783037930380303813038230383303843038530386303873038830389303903039130392303933039430395303963039730398303993040030401304023040330404304053040630407304083040930410304113041230413304143041530416304173041830419304203042130422304233042430425304263042730428304293043030431304323043330434304353043630437304383043930440304413044230443304443044530446304473044830449304503045130452304533045430455304563045730458304593046030461304623046330464304653046630467304683046930470304713047230473304743047530476304773047830479304803048130482304833048430485304863048730488304893049030491304923049330494304953049630497304983049930500305013050230503305043050530506305073050830509305103051130512305133051430515305163051730518305193052030521305223052330524305253052630527305283052930530305313053230533305343053530536305373053830539305403054130542305433054430545305463054730548305493055030551305523055330554305553055630557305583055930560305613056230563305643056530566305673056830569305703057130572305733057430575305763057730578305793058030581305823058330584305853058630587305883058930590305913059230593305943059530596305973059830599306003060130602306033060430605306063060730608306093061030611306123061330614306153061630617306183061930620306213062230623306243062530626306273062830629306303063130632306333063430635306363063730638306393064030641306423064330644306453064630647306483064930650306513065230653306543065530656306573065830659306603066130662306633066430665306663066730668306693067030671306723067330674306753067630677306783067930680306813068230683306843068530686306873068830689306903069130692306933069430695306963069730698306993070030701307023070330704307053070630707307083070930710307113071230713307143071530716307173071830719307203072130722307233072430725307263072730728307293073030731307323073330734307353073630737307383073930740307413074230743307443074530746307473074830749307503075130752307533075430755307563075730758307593076030761307623076330764307653076630767307683076930770307713077230773307743077530776307773077830779307803078130782307833078430785307863078730788307893079030791307923079330794307953079630797307983079930800308013080230803308043080530806308073080830809308103081130812308133081430815308163081730818308193082030821308223082330824308253082630827308283082930830308313083230833308343083530836308373083830839308403084130842308433084430845308463084730848308493085030851308523085330854308553085630857308583085930860308613086230863308643086530866308673086830869308703087130872308733087430875308763087730878308793088030881308823088330884308853088630887308883088930890308913089230893308943089530896308973089830899309003090130902309033090430905309063090730908309093091030911309123091330914309153091630917309183091930920309213092230923309243092530926309273092830929309303093130932309333093430935309363093730938309393094030941309423094330944309453094630947309483094930950309513095230953309543095530956309573095830959309603096130962309633096430965309663096730968309693097030971309723097330974309753097630977309783097930980309813098230983309843098530986309873098830989309903099130992309933099430995309963099730998309993100031001310023100331004310053100631007310083100931010310113101231013310143101531016310173101831019310203102131022310233102431025310263102731028310293103031031310323103331034310353103631037310383103931040310413104231043310443104531046310473104831049310503105131052310533105431055310563105731058310593106031061310623106331064310653106631067310683106931070310713107231073310743107531076310773107831079310803108131082310833108431085310863108731088310893109031091310923109331094310953109631097310983109931100311013110231103311043110531106311073110831109311103111131112311133111431115311163111731118311193112031121311223112331124311253112631127311283112931130311313113231133311343113531136311373113831139311403114131142311433114431145311463114731148311493115031151311523115331154311553115631157311583115931160311613116231163311643116531166311673116831169311703117131172311733117431175311763117731178311793118031181311823118331184311853118631187311883118931190311913119231193311943119531196311973119831199312003120131202312033120431205312063120731208312093121031211312123121331214312153121631217312183121931220312213122231223312243122531226312273122831229312303123131232312333123431235312363123731238312393124031241312423124331244312453124631247312483124931250312513125231253312543125531256312573125831259312603126131262312633126431265312663126731268312693127031271312723127331274312753127631277312783127931280312813128231283312843128531286312873128831289312903129131292312933129431295312963129731298312993130031301313023130331304313053130631307313083130931310313113131231313313143131531316313173131831319313203132131322313233132431325313263132731328313293133031331313323133331334313353133631337313383133931340313413134231343313443134531346313473134831349313503135131352313533135431355313563135731358313593136031361313623136331364313653136631367313683136931370313713137231373313743137531376313773137831379313803138131382313833138431385313863138731388313893139031391313923139331394313953139631397313983139931400314013140231403314043140531406314073140831409314103141131412314133141431415314163141731418314193142031421314223142331424314253142631427314283142931430314313143231433314343143531436314373143831439314403144131442314433144431445314463144731448314493145031451314523145331454314553145631457314583145931460314613146231463314643146531466314673146831469314703147131472314733147431475314763147731478314793148031481314823148331484314853148631487314883148931490314913149231493314943149531496314973149831499315003150131502315033150431505315063150731508315093151031511315123151331514315153151631517315183151931520315213152231523315243152531526315273152831529315303153131532315333153431535315363153731538315393154031541315423154331544315453154631547315483154931550315513155231553315543155531556315573155831559315603156131562315633156431565315663156731568315693157031571315723157331574315753157631577315783157931580315813158231583315843158531586315873158831589315903159131592315933159431595315963159731598315993160031601316023160331604316053160631607316083160931610316113161231613316143161531616316173161831619316203162131622316233162431625316263162731628316293163031631316323163331634316353163631637316383163931640316413164231643316443164531646316473164831649316503165131652316533165431655316563165731658316593166031661316623166331664316653166631667316683166931670316713167231673316743167531676316773167831679316803168131682316833168431685316863168731688316893169031691316923169331694316953169631697316983169931700317013170231703317043170531706317073170831709317103171131712317133171431715317163171731718317193172031721317223172331724317253172631727317283172931730317313173231733317343173531736317373173831739317403174131742317433174431745317463174731748317493175031751317523175331754317553175631757317583175931760317613176231763317643176531766317673176831769317703177131772317733177431775317763177731778317793178031781317823178331784317853178631787317883178931790317913179231793317943179531796317973179831799318003180131802318033180431805318063180731808318093181031811318123181331814318153181631817318183181931820318213182231823318243182531826318273182831829318303183131832318333183431835318363183731838318393184031841318423184331844318453184631847318483184931850318513185231853318543185531856318573185831859318603186131862318633186431865318663186731868318693187031871318723187331874318753187631877318783187931880318813188231883318843188531886318873188831889318903189131892318933189431895318963189731898318993190031901319023190331904319053190631907319083190931910319113191231913319143191531916319173191831919319203192131922319233192431925319263192731928319293193031931319323193331934319353193631937319383193931940319413194231943319443194531946319473194831949319503195131952319533195431955319563195731958319593196031961319623196331964319653196631967319683196931970319713197231973319743197531976319773197831979319803198131982319833198431985319863198731988319893199031991319923199331994319953199631997319983199932000320013200232003320043200532006320073200832009320103201132012320133201432015320163201732018320193202032021320223202332024320253202632027320283202932030320313203232033320343203532036320373203832039320403204132042320433204432045320463204732048320493205032051320523205332054320553205632057320583205932060320613206232063320643206532066320673206832069320703207132072320733207432075320763207732078320793208032081320823208332084320853208632087320883208932090320913209232093320943209532096320973209832099321003210132102321033210432105321063210732108321093211032111321123211332114321153211632117321183211932120321213212232123321243212532126321273212832129321303213132132321333213432135321363213732138321393214032141321423214332144321453214632147321483214932150321513215232153321543215532156321573215832159321603216132162321633216432165321663216732168321693217032171321723217332174321753217632177321783217932180321813218232183321843218532186321873218832189321903219132192321933219432195321963219732198321993220032201322023220332204322053220632207322083220932210322113221232213322143221532216322173221832219322203222132222322233222432225322263222732228322293223032231322323223332234322353223632237322383223932240322413224232243322443224532246322473224832249322503225132252322533225432255322563225732258322593226032261322623226332264322653226632267322683226932270322713227232273322743227532276322773227832279322803228132282322833228432285322863228732288322893229032291322923229332294322953229632297322983229932300323013230232303323043230532306323073230832309323103231132312323133231432315323163231732318323193232032321323223232332324323253232632327323283232932330323313233232333323343233532336323373233832339323403234132342323433234432345323463234732348323493235032351323523235332354323553235632357323583235932360323613236232363323643236532366323673236832369323703237132372323733237432375323763237732378323793238032381323823238332384323853238632387323883238932390323913239232393323943239532396323973239832399324003240132402324033240432405324063240732408324093241032411324123241332414324153241632417324183241932420324213242232423324243242532426324273242832429324303243132432324333243432435324363243732438324393244032441324423244332444324453244632447324483244932450324513245232453324543245532456324573245832459324603246132462324633246432465324663246732468324693247032471324723247332474324753247632477324783247932480324813248232483324843248532486324873248832489324903249132492324933249432495324963249732498324993250032501325023250332504325053250632507325083250932510325113251232513325143251532516325173251832519325203252132522325233252432525325263252732528325293253032531325323253332534325353253632537325383253932540325413254232543325443254532546325473254832549325503255132552325533255432555325563255732558325593256032561325623256332564325653256632567325683256932570325713257232573325743257532576325773257832579325803258132582325833258432585325863258732588325893259032591325923259332594325953259632597325983259932600326013260232603326043260532606326073260832609326103261132612326133261432615326163261732618326193262032621326223262332624326253262632627326283262932630326313263232633326343263532636326373263832639326403264132642326433264432645326463264732648326493265032651326523265332654326553265632657326583265932660326613266232663326643266532666326673266832669326703267132672326733267432675326763267732678326793268032681326823268332684326853268632687326883268932690326913269232693326943269532696326973269832699327003270132702327033270432705327063270732708327093271032711327123271332714327153271632717327183271932720327213272232723327243272532726327273272832729327303273132732327333273432735327363273732738327393274032741327423274332744327453274632747327483274932750327513275232753327543275532756327573275832759327603276132762327633276432765327663276732768327693277032771327723277332774327753277632777327783277932780327813278232783327843278532786327873278832789327903279132792327933279432795327963279732798327993280032801328023280332804328053280632807328083280932810328113281232813328143281532816328173281832819328203282132822328233282432825328263282732828328293283032831328323283332834328353283632837328383283932840328413284232843328443284532846328473284832849328503285132852328533285432855328563285732858328593286032861328623286332864328653286632867328683286932870328713287232873328743287532876328773287832879328803288132882328833288432885328863288732888328893289032891328923289332894328953289632897328983289932900329013290232903329043290532906329073290832909329103291132912329133291432915329163291732918329193292032921329223292332924329253292632927329283292932930329313293232933329343293532936329373293832939329403294132942329433294432945
  1. apiVersion: apiextensions.k8s.io/v1
  2. kind: CustomResourceDefinition
  3. metadata:
  4. annotations:
  5. controller-gen.kubebuilder.io/version: v0.19.0
  6. labels:
  7. external-secrets.io/component: controller
  8. name: clusterexternalsecrets.external-secrets.io
  9. spec:
  10. group: external-secrets.io
  11. names:
  12. categories:
  13. - external-secrets
  14. kind: ClusterExternalSecret
  15. listKind: ClusterExternalSecretList
  16. plural: clusterexternalsecrets
  17. shortNames:
  18. - ces
  19. singular: clusterexternalsecret
  20. scope: Cluster
  21. versions:
  22. - additionalPrinterColumns:
  23. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  24. name: Store
  25. type: string
  26. - jsonPath: .spec.refreshTime
  27. name: Refresh Interval
  28. type: string
  29. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  30. name: Ready
  31. type: string
  32. name: v1
  33. schema:
  34. openAPIV3Schema:
  35. description: ClusterExternalSecret is the Schema for the clusterexternalsecrets API.
  36. properties:
  37. apiVersion:
  38. description: |-
  39. APIVersion defines the versioned schema of this representation of an object.
  40. Servers should convert recognized schemas to the latest internal value, and
  41. may reject unrecognized values.
  42. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  43. type: string
  44. kind:
  45. description: |-
  46. Kind is a string value representing the REST resource this object represents.
  47. Servers may infer this from the endpoint the client submits requests to.
  48. Cannot be updated.
  49. In CamelCase.
  50. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  51. type: string
  52. metadata:
  53. type: object
  54. spec:
  55. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  56. properties:
  57. externalSecretMetadata:
  58. description: The metadata of the external secrets to be created
  59. properties:
  60. annotations:
  61. additionalProperties:
  62. type: string
  63. type: object
  64. labels:
  65. additionalProperties:
  66. type: string
  67. type: object
  68. type: object
  69. externalSecretName:
  70. description: |-
  71. The name of the external secrets to be created.
  72. Defaults to the name of the ClusterExternalSecret
  73. maxLength: 253
  74. minLength: 1
  75. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  76. type: string
  77. externalSecretSpec:
  78. description: The spec for the ExternalSecrets to be created
  79. properties:
  80. data:
  81. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  82. items:
  83. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  84. properties:
  85. remoteRef:
  86. description: |-
  87. RemoteRef points to the remote secret and defines
  88. which secret (version/property/..) to fetch.
  89. properties:
  90. conversionStrategy:
  91. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  92. enum:
  93. - Default
  94. - Unicode
  95. type: string
  96. decodingStrategy:
  97. description: Used to define a decoding Strategy. Defaults to None when omitted.
  98. enum:
  99. - Auto
  100. - Base64
  101. - Base64URL
  102. - None
  103. type: string
  104. key:
  105. description: Key is the key used in the Provider, mandatory
  106. type: string
  107. metadataPolicy:
  108. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  109. enum:
  110. - None
  111. - Fetch
  112. type: string
  113. nullBytePolicy:
  114. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  115. enum:
  116. - Ignore
  117. - Fail
  118. type: string
  119. property:
  120. description: Used to select a specific property of the Provider value (if a map), if supported
  121. type: string
  122. version:
  123. description: Used to select a specific version of the Provider value, if supported
  124. type: string
  125. required:
  126. - key
  127. type: object
  128. secretKey:
  129. description: The key in the Kubernetes Secret to store the value.
  130. maxLength: 253
  131. minLength: 1
  132. pattern: ^[-._a-zA-Z0-9]+$
  133. type: string
  134. sourceRef:
  135. description: |-
  136. SourceRef allows you to override the source
  137. from which the value will be pulled.
  138. maxProperties: 1
  139. minProperties: 1
  140. properties:
  141. generatorRef:
  142. description: |-
  143. GeneratorRef points to a generator custom resource.
  144. Deprecated: The generatorRef is not implemented in .data[].
  145. this will be removed with v1.
  146. properties:
  147. apiVersion:
  148. default: generators.external-secrets.io/v1alpha1
  149. description: Specify the apiVersion of the generator resource
  150. type: string
  151. kind:
  152. description: Specify the Kind of the generator resource
  153. enum:
  154. - ACRAccessToken
  155. - BeyondtrustWorkloadCredentialsDynamicSecret
  156. - ClusterGenerator
  157. - CloudsmithAccessToken
  158. - ECRAuthorizationToken
  159. - Fake
  160. - GCRAccessToken
  161. - GithubAccessToken
  162. - GitlabDeployToken
  163. - QuayAccessToken
  164. - Password
  165. - SSHKey
  166. - STSSessionToken
  167. - UUID
  168. - VaultDynamicSecret
  169. - Webhook
  170. - Grafana
  171. - MFA
  172. type: string
  173. name:
  174. description: Specify the name of the generator resource
  175. maxLength: 253
  176. minLength: 1
  177. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  178. type: string
  179. required:
  180. - kind
  181. - name
  182. type: object
  183. storeRef:
  184. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  185. properties:
  186. kind:
  187. description: |-
  188. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  189. Defaults to `SecretStore`
  190. enum:
  191. - SecretStore
  192. - ClusterSecretStore
  193. type: string
  194. name:
  195. description: Name of the SecretStore resource
  196. maxLength: 253
  197. minLength: 1
  198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  199. type: string
  200. type: object
  201. type: object
  202. required:
  203. - remoteRef
  204. - secretKey
  205. type: object
  206. type: array
  207. dataFrom:
  208. description: |-
  209. DataFrom is used to fetch all properties from a specific Provider data
  210. If multiple entries are specified, the Secret keys are merged in the specified order
  211. items:
  212. description: |-
  213. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  214. when using DataFrom to fetch multiple values from a Provider.
  215. properties:
  216. extract:
  217. description: |-
  218. Used to extract multiple key/value pairs from one secret
  219. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  220. properties:
  221. conversionStrategy:
  222. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  223. enum:
  224. - Default
  225. - Unicode
  226. type: string
  227. decodingStrategy:
  228. description: Used to define a decoding Strategy. Defaults to None when omitted.
  229. enum:
  230. - Auto
  231. - Base64
  232. - Base64URL
  233. - None
  234. type: string
  235. key:
  236. description: Key is the key used in the Provider, mandatory
  237. type: string
  238. metadataPolicy:
  239. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  240. enum:
  241. - None
  242. - Fetch
  243. type: string
  244. nullBytePolicy:
  245. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  246. enum:
  247. - Ignore
  248. - Fail
  249. type: string
  250. property:
  251. description: Used to select a specific property of the Provider value (if a map), if supported
  252. type: string
  253. version:
  254. description: Used to select a specific version of the Provider value, if supported
  255. type: string
  256. required:
  257. - key
  258. type: object
  259. find:
  260. description: |-
  261. Used to find secrets based on tags or regular expressions
  262. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  263. properties:
  264. conversionStrategy:
  265. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  266. enum:
  267. - Default
  268. - Unicode
  269. type: string
  270. decodingStrategy:
  271. description: Used to define a decoding Strategy. Defaults to None when omitted.
  272. enum:
  273. - Auto
  274. - Base64
  275. - Base64URL
  276. - None
  277. type: string
  278. name:
  279. description: Finds secrets based on the name.
  280. properties:
  281. regexp:
  282. description: Finds secrets base
  283. type: string
  284. type: object
  285. nullBytePolicy:
  286. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  287. enum:
  288. - Ignore
  289. - Fail
  290. type: string
  291. path:
  292. description: A root path to start the find operations.
  293. type: string
  294. tags:
  295. additionalProperties:
  296. type: string
  297. description: Find secrets based on tags.
  298. type: object
  299. type: object
  300. rewrite:
  301. description: |-
  302. Used to rewrite secret Keys after getting them from the secret Provider
  303. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  304. items:
  305. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  306. maxProperties: 1
  307. minProperties: 1
  308. properties:
  309. merge:
  310. description: |-
  311. Used to merge key/values in one single Secret
  312. The resulting key will contain all values from the specified secrets
  313. properties:
  314. conflictPolicy:
  315. default: Error
  316. description: Used to define the policy to use in conflict resolution.
  317. enum:
  318. - Ignore
  319. - Error
  320. type: string
  321. into:
  322. default: ""
  323. description: |-
  324. Used to define the target key of the merge operation.
  325. Required if strategy is JSON. Ignored otherwise.
  326. type: string
  327. priority:
  328. description: Used to define key priority in conflict resolution.
  329. items:
  330. type: string
  331. type: array
  332. priorityPolicy:
  333. default: Strict
  334. description: Used to define the policy when a key in the priority list does not exist in the input.
  335. enum:
  336. - IgnoreNotFound
  337. - Strict
  338. type: string
  339. strategy:
  340. default: Extract
  341. description: Used to define the strategy to use in the merge operation.
  342. enum:
  343. - Extract
  344. - JSON
  345. type: string
  346. type: object
  347. regexp:
  348. description: |-
  349. Used to rewrite with regular expressions.
  350. The resulting key will be the output of a regexp.ReplaceAll operation.
  351. properties:
  352. source:
  353. description: Used to define the regular expression of a re.Compiler.
  354. type: string
  355. target:
  356. description: Used to define the target pattern of a ReplaceAll operation.
  357. type: string
  358. required:
  359. - source
  360. - target
  361. type: object
  362. transform:
  363. description: |-
  364. Used to apply string transformation on the secrets.
  365. The resulting key will be the output of the template applied by the operation.
  366. properties:
  367. template:
  368. description: |-
  369. Used to define the template to apply on the secret name.
  370. `.value ` will specify the secret name in the template.
  371. type: string
  372. required:
  373. - template
  374. type: object
  375. type: object
  376. type: array
  377. sourceRef:
  378. description: |-
  379. SourceRef points to a store or generator
  380. which contains secret values ready to use.
  381. Use this in combination with Extract or Find pull values out of
  382. a specific SecretStore.
  383. When sourceRef points to a generator Extract or Find is not supported.
  384. The generator returns a static map of values
  385. maxProperties: 1
  386. minProperties: 1
  387. properties:
  388. generatorRef:
  389. description: GeneratorRef points to a generator custom resource.
  390. properties:
  391. apiVersion:
  392. default: generators.external-secrets.io/v1alpha1
  393. description: Specify the apiVersion of the generator resource
  394. type: string
  395. kind:
  396. description: Specify the Kind of the generator resource
  397. enum:
  398. - ACRAccessToken
  399. - BeyondtrustWorkloadCredentialsDynamicSecret
  400. - ClusterGenerator
  401. - CloudsmithAccessToken
  402. - ECRAuthorizationToken
  403. - Fake
  404. - GCRAccessToken
  405. - GithubAccessToken
  406. - GitlabDeployToken
  407. - QuayAccessToken
  408. - Password
  409. - SSHKey
  410. - STSSessionToken
  411. - UUID
  412. - VaultDynamicSecret
  413. - Webhook
  414. - Grafana
  415. - MFA
  416. type: string
  417. name:
  418. description: Specify the name of the generator resource
  419. maxLength: 253
  420. minLength: 1
  421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  422. type: string
  423. required:
  424. - kind
  425. - name
  426. type: object
  427. storeRef:
  428. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  429. properties:
  430. kind:
  431. description: |-
  432. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  433. Defaults to `SecretStore`
  434. enum:
  435. - SecretStore
  436. - ClusterSecretStore
  437. type: string
  438. name:
  439. description: Name of the SecretStore resource
  440. maxLength: 253
  441. minLength: 1
  442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  443. type: string
  444. type: object
  445. type: object
  446. type: object
  447. type: array
  448. refreshInterval:
  449. default: 1h0m0s
  450. description: |-
  451. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  452. specified as Golang Duration strings.
  453. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  454. Example values: "1h0m0s", "2h30m0s", "10m0s"
  455. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  456. type: string
  457. refreshPolicy:
  458. description: |-
  459. RefreshPolicy determines how the ExternalSecret should be refreshed:
  460. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  461. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  462. No periodic updates occur if refreshInterval is 0.
  463. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  464. enum:
  465. - CreatedOnce
  466. - Periodic
  467. - OnChange
  468. type: string
  469. secretStoreRef:
  470. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  471. properties:
  472. kind:
  473. description: |-
  474. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  475. Defaults to `SecretStore`
  476. enum:
  477. - SecretStore
  478. - ClusterSecretStore
  479. type: string
  480. name:
  481. description: Name of the SecretStore resource
  482. maxLength: 253
  483. minLength: 1
  484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  485. type: string
  486. type: object
  487. syncWindows:
  488. description: |-
  489. SyncWindows optionally restricts when periodic refreshes may occur.
  490. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  491. properties:
  492. kind:
  493. description: |-
  494. Kind applies to every window in the list.
  495. "allow" -- syncs are permitted only while at least one window is active;
  496. all other times are blocked.
  497. "deny" -- syncs are blocked while any window is active;
  498. all other times are permitted.
  499. enum:
  500. - allow
  501. - deny
  502. type: string
  503. windows:
  504. description: Windows is the list of schedule+duration pairs.
  505. items:
  506. description: |-
  507. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  508. within a SyncWindows block.
  509. properties:
  510. duration:
  511. description: |-
  512. Duration specifies how long the window stays open after each Schedule
  513. firing. Example: "8h".
  514. type: string
  515. schedule:
  516. description: |-
  517. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  518. named shorthand such as @daily or @every 1h. It marks the start time of
  519. each window occurrence.
  520. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  521. minLength: 1
  522. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  523. type: string
  524. required:
  525. - duration
  526. - schedule
  527. type: object
  528. minItems: 1
  529. type: array
  530. required:
  531. - kind
  532. - windows
  533. type: object
  534. target:
  535. default:
  536. creationPolicy: Owner
  537. deletionPolicy: Retain
  538. description: |-
  539. ExternalSecretTarget defines the Kubernetes Secret to be created,
  540. there can be only one target per ExternalSecret.
  541. properties:
  542. creationPolicy:
  543. default: Owner
  544. description: |-
  545. CreationPolicy defines rules on how to create the resulting Secret.
  546. Defaults to "Owner"
  547. enum:
  548. - Owner
  549. - Orphan
  550. - Merge
  551. - None
  552. - CreateOrMerge
  553. type: string
  554. deletionPolicy:
  555. default: Retain
  556. description: |-
  557. DeletionPolicy defines rules on how to delete the resulting Secret.
  558. Defaults to "Retain"
  559. enum:
  560. - Delete
  561. - Merge
  562. - Retain
  563. type: string
  564. immutable:
  565. description: Immutable defines if the final secret will be immutable
  566. type: boolean
  567. manifest:
  568. description: |-
  569. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  570. When specified, ExternalSecret will create the resource type defined here
  571. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  572. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  573. properties:
  574. apiVersion:
  575. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  576. minLength: 1
  577. type: string
  578. kind:
  579. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  580. minLength: 1
  581. type: string
  582. required:
  583. - apiVersion
  584. - kind
  585. type: object
  586. name:
  587. description: |-
  588. The name of the Secret resource to be managed.
  589. Defaults to the .metadata.name of the ExternalSecret resource
  590. maxLength: 253
  591. minLength: 1
  592. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  593. type: string
  594. template:
  595. description: Template defines a blueprint for the created Secret resource.
  596. properties:
  597. data:
  598. additionalProperties:
  599. type: string
  600. type: object
  601. engineVersion:
  602. default: v2
  603. description: |-
  604. EngineVersion specifies the template engine version
  605. that should be used to compile/execute the
  606. template specified in .data and .templateFrom[].
  607. enum:
  608. - v2
  609. type: string
  610. mergePolicy:
  611. default: Replace
  612. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  613. enum:
  614. - Replace
  615. - Merge
  616. type: string
  617. metadata:
  618. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  619. properties:
  620. annotations:
  621. additionalProperties:
  622. type: string
  623. type: object
  624. finalizers:
  625. items:
  626. type: string
  627. type: array
  628. labels:
  629. additionalProperties:
  630. type: string
  631. type: object
  632. type: object
  633. templateFrom:
  634. items:
  635. description: |-
  636. TemplateFrom specifies a source for templates.
  637. Each item in the list can either reference a ConfigMap or a Secret resource.
  638. properties:
  639. configMap:
  640. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  641. properties:
  642. items:
  643. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  644. items:
  645. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  646. properties:
  647. key:
  648. description: A key in the ConfigMap/Secret
  649. maxLength: 253
  650. minLength: 1
  651. pattern: ^[-._a-zA-Z0-9]+$
  652. type: string
  653. templateAs:
  654. default: Values
  655. description: TemplateScope specifies how the template keys should be interpreted.
  656. enum:
  657. - Values
  658. - KeysAndValues
  659. type: string
  660. required:
  661. - key
  662. type: object
  663. type: array
  664. name:
  665. description: The name of the ConfigMap/Secret resource
  666. maxLength: 253
  667. minLength: 1
  668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  669. type: string
  670. required:
  671. - items
  672. - name
  673. type: object
  674. literal:
  675. type: string
  676. secret:
  677. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  678. properties:
  679. items:
  680. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  681. items:
  682. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  683. properties:
  684. key:
  685. description: A key in the ConfigMap/Secret
  686. maxLength: 253
  687. minLength: 1
  688. pattern: ^[-._a-zA-Z0-9]+$
  689. type: string
  690. templateAs:
  691. default: Values
  692. description: TemplateScope specifies how the template keys should be interpreted.
  693. enum:
  694. - Values
  695. - KeysAndValues
  696. type: string
  697. required:
  698. - key
  699. type: object
  700. type: array
  701. name:
  702. description: The name of the ConfigMap/Secret resource
  703. maxLength: 253
  704. minLength: 1
  705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  706. type: string
  707. required:
  708. - items
  709. - name
  710. type: object
  711. target:
  712. default: Data
  713. description: |-
  714. Target specifies where to place the template result.
  715. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  716. any other value is rejected because it would allow writes to privileged Secret fields.
  717. For custom resources (when spec.target.manifest is set), this supports
  718. nested paths like "spec.database.config" or "data".
  719. type: string
  720. valuesDecodingStrategy:
  721. description: |-
  722. Used to define a decoding Strategy for the rendered template values.
  723. Defaults to None when omitted.
  724. enum:
  725. - Auto
  726. - Base64
  727. - Base64URL
  728. - None
  729. type: string
  730. type: object
  731. type: array
  732. type:
  733. type: string
  734. type: object
  735. type: object
  736. type: object
  737. namespaceSelector:
  738. description: |-
  739. The labels to select by to find the Namespaces to create the ExternalSecrets in.
  740. Deprecated: Use NamespaceSelectors instead.
  741. properties:
  742. matchExpressions:
  743. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  744. items:
  745. description: |-
  746. A label selector requirement is a selector that contains values, a key, and an operator that
  747. relates the key and values.
  748. properties:
  749. key:
  750. description: key is the label key that the selector applies to.
  751. type: string
  752. operator:
  753. description: |-
  754. operator represents a key's relationship to a set of values.
  755. Valid operators are In, NotIn, Exists and DoesNotExist.
  756. type: string
  757. values:
  758. description: |-
  759. values is an array of string values. If the operator is In or NotIn,
  760. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  761. the values array must be empty. This array is replaced during a strategic
  762. merge patch.
  763. items:
  764. type: string
  765. type: array
  766. x-kubernetes-list-type: atomic
  767. required:
  768. - key
  769. - operator
  770. type: object
  771. type: array
  772. x-kubernetes-list-type: atomic
  773. matchLabels:
  774. additionalProperties:
  775. type: string
  776. description: |-
  777. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  778. map is equivalent to an element of matchExpressions, whose key field is "key", the
  779. operator is "In", and the values array contains only "value". The requirements are ANDed.
  780. type: object
  781. type: object
  782. x-kubernetes-map-type: atomic
  783. namespaceSelectors:
  784. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  785. items:
  786. description: |-
  787. A label selector is a label query over a set of resources. The result of matchLabels and
  788. matchExpressions are ANDed. An empty label selector matches all objects. A null
  789. label selector matches no objects.
  790. properties:
  791. matchExpressions:
  792. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  793. items:
  794. description: |-
  795. A label selector requirement is a selector that contains values, a key, and an operator that
  796. relates the key and values.
  797. properties:
  798. key:
  799. description: key is the label key that the selector applies to.
  800. type: string
  801. operator:
  802. description: |-
  803. operator represents a key's relationship to a set of values.
  804. Valid operators are In, NotIn, Exists and DoesNotExist.
  805. type: string
  806. values:
  807. description: |-
  808. values is an array of string values. If the operator is In or NotIn,
  809. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  810. the values array must be empty. This array is replaced during a strategic
  811. merge patch.
  812. items:
  813. type: string
  814. type: array
  815. x-kubernetes-list-type: atomic
  816. required:
  817. - key
  818. - operator
  819. type: object
  820. type: array
  821. x-kubernetes-list-type: atomic
  822. matchLabels:
  823. additionalProperties:
  824. type: string
  825. description: |-
  826. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  827. map is equivalent to an element of matchExpressions, whose key field is "key", the
  828. operator is "In", and the values array contains only "value". The requirements are ANDed.
  829. type: object
  830. type: object
  831. x-kubernetes-map-type: atomic
  832. type: array
  833. namespaces:
  834. description: |-
  835. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  836. Deprecated: Use NamespaceSelectors instead.
  837. items:
  838. maxLength: 63
  839. minLength: 1
  840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  841. type: string
  842. type: array
  843. refreshTime:
  844. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  845. type: string
  846. required:
  847. - externalSecretSpec
  848. type: object
  849. status:
  850. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  851. properties:
  852. conditions:
  853. items:
  854. description: ClusterExternalSecretStatusCondition defines the observed state of a ClusterExternalSecret resource.
  855. properties:
  856. message:
  857. type: string
  858. status:
  859. type: string
  860. type:
  861. description: ClusterExternalSecretConditionType defines a value type for ClusterExternalSecret conditions.
  862. type: string
  863. required:
  864. - status
  865. - type
  866. type: object
  867. type: array
  868. externalSecretName:
  869. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  870. type: string
  871. failedNamespaces:
  872. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  873. items:
  874. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  875. properties:
  876. namespace:
  877. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  878. type: string
  879. reason:
  880. description: Reason is why the ExternalSecret failed to apply to the namespace
  881. type: string
  882. required:
  883. - namespace
  884. type: object
  885. type: array
  886. provisionedNamespaces:
  887. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  888. items:
  889. type: string
  890. type: array
  891. type: object
  892. type: object
  893. served: true
  894. storage: true
  895. subresources:
  896. status: {}
  897. - additionalPrinterColumns:
  898. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  899. name: Store
  900. type: string
  901. - jsonPath: .spec.refreshTime
  902. name: Refresh Interval
  903. type: string
  904. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  905. name: Ready
  906. type: string
  907. deprecated: true
  908. name: v1beta1
  909. schema:
  910. openAPIV3Schema:
  911. description: ClusterExternalSecret is the schema for the clusterexternalsecrets API.
  912. properties:
  913. apiVersion:
  914. description: |-
  915. APIVersion defines the versioned schema of this representation of an object.
  916. Servers should convert recognized schemas to the latest internal value, and
  917. may reject unrecognized values.
  918. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  919. type: string
  920. kind:
  921. description: |-
  922. Kind is a string value representing the REST resource this object represents.
  923. Servers may infer this from the endpoint the client submits requests to.
  924. Cannot be updated.
  925. In CamelCase.
  926. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  927. type: string
  928. metadata:
  929. type: object
  930. spec:
  931. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  932. properties:
  933. externalSecretMetadata:
  934. description: The metadata of the external secrets to be created
  935. properties:
  936. annotations:
  937. additionalProperties:
  938. type: string
  939. type: object
  940. labels:
  941. additionalProperties:
  942. type: string
  943. type: object
  944. type: object
  945. externalSecretName:
  946. description: |-
  947. The name of the external secrets to be created.
  948. Defaults to the name of the ClusterExternalSecret
  949. maxLength: 253
  950. minLength: 1
  951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  952. type: string
  953. externalSecretSpec:
  954. description: The spec for the ExternalSecrets to be created
  955. properties:
  956. data:
  957. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  958. items:
  959. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  960. properties:
  961. remoteRef:
  962. description: |-
  963. RemoteRef points to the remote secret and defines
  964. which secret (version/property/..) to fetch.
  965. properties:
  966. conversionStrategy:
  967. default: Default
  968. description: Used to define a conversion Strategy
  969. enum:
  970. - Default
  971. - Unicode
  972. type: string
  973. decodingStrategy:
  974. default: None
  975. description: Used to define a decoding Strategy
  976. enum:
  977. - Auto
  978. - Base64
  979. - Base64URL
  980. - None
  981. type: string
  982. key:
  983. description: Key is the key used in the Provider, mandatory
  984. type: string
  985. metadataPolicy:
  986. default: None
  987. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  988. enum:
  989. - None
  990. - Fetch
  991. type: string
  992. property:
  993. description: Used to select a specific property of the Provider value (if a map), if supported
  994. type: string
  995. version:
  996. description: Used to select a specific version of the Provider value, if supported
  997. type: string
  998. required:
  999. - key
  1000. type: object
  1001. secretKey:
  1002. description: The key in the Kubernetes Secret to store the value.
  1003. maxLength: 253
  1004. minLength: 1
  1005. pattern: ^[-._a-zA-Z0-9]+$
  1006. type: string
  1007. sourceRef:
  1008. description: |-
  1009. SourceRef allows you to override the source
  1010. from which the value will be pulled.
  1011. maxProperties: 1
  1012. minProperties: 1
  1013. properties:
  1014. generatorRef:
  1015. description: |-
  1016. GeneratorRef points to a generator custom resource.
  1017. Deprecated: The generatorRef is not implemented in .data[].
  1018. this will be removed with v1.
  1019. properties:
  1020. apiVersion:
  1021. default: generators.external-secrets.io/v1alpha1
  1022. description: Specify the apiVersion of the generator resource
  1023. type: string
  1024. kind:
  1025. description: Specify the Kind of the generator resource
  1026. enum:
  1027. - ACRAccessToken
  1028. - ClusterGenerator
  1029. - ECRAuthorizationToken
  1030. - Fake
  1031. - GCRAccessToken
  1032. - GithubAccessToken
  1033. - QuayAccessToken
  1034. - Password
  1035. - SSHKey
  1036. - STSSessionToken
  1037. - UUID
  1038. - VaultDynamicSecret
  1039. - Webhook
  1040. - Grafana
  1041. type: string
  1042. name:
  1043. description: Specify the name of the generator resource
  1044. maxLength: 253
  1045. minLength: 1
  1046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1047. type: string
  1048. required:
  1049. - kind
  1050. - name
  1051. type: object
  1052. storeRef:
  1053. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1054. properties:
  1055. kind:
  1056. description: |-
  1057. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1058. Defaults to `SecretStore`
  1059. enum:
  1060. - SecretStore
  1061. - ClusterSecretStore
  1062. type: string
  1063. name:
  1064. description: Name of the SecretStore resource
  1065. maxLength: 253
  1066. minLength: 1
  1067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1068. type: string
  1069. type: object
  1070. type: object
  1071. required:
  1072. - remoteRef
  1073. - secretKey
  1074. type: object
  1075. type: array
  1076. dataFrom:
  1077. description: |-
  1078. DataFrom is used to fetch all properties from a specific Provider data
  1079. If multiple entries are specified, the Secret keys are merged in the specified order
  1080. items:
  1081. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  1082. properties:
  1083. extract:
  1084. description: |-
  1085. Used to extract multiple key/value pairs from one secret
  1086. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1087. properties:
  1088. conversionStrategy:
  1089. default: Default
  1090. description: Used to define a conversion Strategy
  1091. enum:
  1092. - Default
  1093. - Unicode
  1094. type: string
  1095. decodingStrategy:
  1096. default: None
  1097. description: Used to define a decoding Strategy
  1098. enum:
  1099. - Auto
  1100. - Base64
  1101. - Base64URL
  1102. - None
  1103. type: string
  1104. key:
  1105. description: Key is the key used in the Provider, mandatory
  1106. type: string
  1107. metadataPolicy:
  1108. default: None
  1109. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  1110. enum:
  1111. - None
  1112. - Fetch
  1113. type: string
  1114. property:
  1115. description: Used to select a specific property of the Provider value (if a map), if supported
  1116. type: string
  1117. version:
  1118. description: Used to select a specific version of the Provider value, if supported
  1119. type: string
  1120. required:
  1121. - key
  1122. type: object
  1123. find:
  1124. description: |-
  1125. Used to find secrets based on tags or regular expressions
  1126. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1127. properties:
  1128. conversionStrategy:
  1129. default: Default
  1130. description: Used to define a conversion Strategy
  1131. enum:
  1132. - Default
  1133. - Unicode
  1134. type: string
  1135. decodingStrategy:
  1136. default: None
  1137. description: Used to define a decoding Strategy
  1138. enum:
  1139. - Auto
  1140. - Base64
  1141. - Base64URL
  1142. - None
  1143. type: string
  1144. name:
  1145. description: Finds secrets based on the name.
  1146. properties:
  1147. regexp:
  1148. description: Finds secrets base
  1149. type: string
  1150. type: object
  1151. path:
  1152. description: A root path to start the find operations.
  1153. type: string
  1154. tags:
  1155. additionalProperties:
  1156. type: string
  1157. description: Find secrets based on tags.
  1158. type: object
  1159. type: object
  1160. rewrite:
  1161. description: |-
  1162. Used to rewrite secret Keys after getting them from the secret Provider
  1163. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  1164. items:
  1165. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  1166. maxProperties: 1
  1167. minProperties: 1
  1168. properties:
  1169. regexp:
  1170. description: |-
  1171. Used to rewrite with regular expressions.
  1172. The resulting key will be the output of a regexp.ReplaceAll operation.
  1173. properties:
  1174. source:
  1175. description: Used to define the regular expression of a re.Compiler.
  1176. type: string
  1177. target:
  1178. description: Used to define the target pattern of a ReplaceAll operation.
  1179. type: string
  1180. required:
  1181. - source
  1182. - target
  1183. type: object
  1184. transform:
  1185. description: |-
  1186. Used to apply string transformation on the secrets.
  1187. The resulting key will be the output of the template applied by the operation.
  1188. properties:
  1189. template:
  1190. description: |-
  1191. Used to define the template to apply on the secret name.
  1192. `.value ` will specify the secret name in the template.
  1193. type: string
  1194. required:
  1195. - template
  1196. type: object
  1197. type: object
  1198. type: array
  1199. sourceRef:
  1200. description: |-
  1201. SourceRef points to a store or generator
  1202. which contains secret values ready to use.
  1203. Use this in combination with Extract or Find pull values out of
  1204. a specific SecretStore.
  1205. When sourceRef points to a generator Extract or Find is not supported.
  1206. The generator returns a static map of values
  1207. maxProperties: 1
  1208. minProperties: 1
  1209. properties:
  1210. generatorRef:
  1211. description: GeneratorRef points to a generator custom resource.
  1212. properties:
  1213. apiVersion:
  1214. default: generators.external-secrets.io/v1alpha1
  1215. description: Specify the apiVersion of the generator resource
  1216. type: string
  1217. kind:
  1218. description: Specify the Kind of the generator resource
  1219. enum:
  1220. - ACRAccessToken
  1221. - ClusterGenerator
  1222. - ECRAuthorizationToken
  1223. - Fake
  1224. - GCRAccessToken
  1225. - GithubAccessToken
  1226. - QuayAccessToken
  1227. - Password
  1228. - SSHKey
  1229. - STSSessionToken
  1230. - UUID
  1231. - VaultDynamicSecret
  1232. - Webhook
  1233. - Grafana
  1234. type: string
  1235. name:
  1236. description: Specify the name of the generator resource
  1237. maxLength: 253
  1238. minLength: 1
  1239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1240. type: string
  1241. required:
  1242. - kind
  1243. - name
  1244. type: object
  1245. storeRef:
  1246. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1247. properties:
  1248. kind:
  1249. description: |-
  1250. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1251. Defaults to `SecretStore`
  1252. enum:
  1253. - SecretStore
  1254. - ClusterSecretStore
  1255. type: string
  1256. name:
  1257. description: Name of the SecretStore resource
  1258. maxLength: 253
  1259. minLength: 1
  1260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1261. type: string
  1262. type: object
  1263. type: object
  1264. type: object
  1265. type: array
  1266. refreshInterval:
  1267. default: 1h0m0s
  1268. description: |-
  1269. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  1270. specified as Golang Duration strings.
  1271. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  1272. Example values: "1h0m0s", "2h30m0s", "10m0s"
  1273. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  1274. type: string
  1275. refreshPolicy:
  1276. description: |-
  1277. RefreshPolicy determines how the ExternalSecret should be refreshed:
  1278. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  1279. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  1280. No periodic updates occur if refreshInterval is 0.
  1281. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  1282. enum:
  1283. - CreatedOnce
  1284. - Periodic
  1285. - OnChange
  1286. type: string
  1287. secretStoreRef:
  1288. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1289. properties:
  1290. kind:
  1291. description: |-
  1292. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1293. Defaults to `SecretStore`
  1294. enum:
  1295. - SecretStore
  1296. - ClusterSecretStore
  1297. type: string
  1298. name:
  1299. description: Name of the SecretStore resource
  1300. maxLength: 253
  1301. minLength: 1
  1302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1303. type: string
  1304. type: object
  1305. target:
  1306. default:
  1307. creationPolicy: Owner
  1308. deletionPolicy: Retain
  1309. description: |-
  1310. ExternalSecretTarget defines the Kubernetes Secret to be created
  1311. There can be only one target per ExternalSecret.
  1312. properties:
  1313. creationPolicy:
  1314. default: Owner
  1315. description: |-
  1316. CreationPolicy defines rules on how to create the resulting Secret.
  1317. Defaults to "Owner"
  1318. enum:
  1319. - Owner
  1320. - Orphan
  1321. - Merge
  1322. - None
  1323. type: string
  1324. deletionPolicy:
  1325. default: Retain
  1326. description: |-
  1327. DeletionPolicy defines rules on how to delete the resulting Secret.
  1328. Defaults to "Retain"
  1329. enum:
  1330. - Delete
  1331. - Merge
  1332. - Retain
  1333. type: string
  1334. immutable:
  1335. description: Immutable defines if the final secret will be immutable
  1336. type: boolean
  1337. name:
  1338. description: |-
  1339. The name of the Secret resource to be managed.
  1340. Defaults to the .metadata.name of the ExternalSecret resource
  1341. maxLength: 253
  1342. minLength: 1
  1343. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1344. type: string
  1345. template:
  1346. description: Template defines a blueprint for the created Secret resource.
  1347. properties:
  1348. data:
  1349. additionalProperties:
  1350. type: string
  1351. type: object
  1352. engineVersion:
  1353. default: v2
  1354. description: |-
  1355. EngineVersion specifies the template engine version
  1356. that should be used to compile/execute the
  1357. template specified in .data and .templateFrom[].
  1358. enum:
  1359. - v2
  1360. type: string
  1361. mergePolicy:
  1362. default: Replace
  1363. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  1364. enum:
  1365. - Replace
  1366. - Merge
  1367. type: string
  1368. metadata:
  1369. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  1370. properties:
  1371. annotations:
  1372. additionalProperties:
  1373. type: string
  1374. type: object
  1375. labels:
  1376. additionalProperties:
  1377. type: string
  1378. type: object
  1379. type: object
  1380. templateFrom:
  1381. items:
  1382. description: TemplateFrom defines a source for template data.
  1383. properties:
  1384. configMap:
  1385. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1386. properties:
  1387. items:
  1388. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1389. items:
  1390. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1391. properties:
  1392. key:
  1393. description: A key in the ConfigMap/Secret
  1394. maxLength: 253
  1395. minLength: 1
  1396. pattern: ^[-._a-zA-Z0-9]+$
  1397. type: string
  1398. templateAs:
  1399. default: Values
  1400. description: TemplateScope defines the scope of the template when processing template data.
  1401. enum:
  1402. - Values
  1403. - KeysAndValues
  1404. type: string
  1405. required:
  1406. - key
  1407. type: object
  1408. type: array
  1409. name:
  1410. description: The name of the ConfigMap/Secret resource
  1411. maxLength: 253
  1412. minLength: 1
  1413. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1414. type: string
  1415. required:
  1416. - items
  1417. - name
  1418. type: object
  1419. literal:
  1420. type: string
  1421. secret:
  1422. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1423. properties:
  1424. items:
  1425. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1426. items:
  1427. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1428. properties:
  1429. key:
  1430. description: A key in the ConfigMap/Secret
  1431. maxLength: 253
  1432. minLength: 1
  1433. pattern: ^[-._a-zA-Z0-9]+$
  1434. type: string
  1435. templateAs:
  1436. default: Values
  1437. description: TemplateScope defines the scope of the template when processing template data.
  1438. enum:
  1439. - Values
  1440. - KeysAndValues
  1441. type: string
  1442. required:
  1443. - key
  1444. type: object
  1445. type: array
  1446. name:
  1447. description: The name of the ConfigMap/Secret resource
  1448. maxLength: 253
  1449. minLength: 1
  1450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1451. type: string
  1452. required:
  1453. - items
  1454. - name
  1455. type: object
  1456. target:
  1457. default: Data
  1458. description: TemplateTarget defines the target field where the template result will be stored.
  1459. enum:
  1460. - Data
  1461. - Annotations
  1462. - Labels
  1463. type: string
  1464. type: object
  1465. type: array
  1466. type:
  1467. type: string
  1468. type: object
  1469. type: object
  1470. type: object
  1471. namespaceSelector:
  1472. description: The labels to select by to find the Namespaces to create the ExternalSecrets in
  1473. properties:
  1474. matchExpressions:
  1475. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1476. items:
  1477. description: |-
  1478. A label selector requirement is a selector that contains values, a key, and an operator that
  1479. relates the key and values.
  1480. properties:
  1481. key:
  1482. description: key is the label key that the selector applies to.
  1483. type: string
  1484. operator:
  1485. description: |-
  1486. operator represents a key's relationship to a set of values.
  1487. Valid operators are In, NotIn, Exists and DoesNotExist.
  1488. type: string
  1489. values:
  1490. description: |-
  1491. values is an array of string values. If the operator is In or NotIn,
  1492. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1493. the values array must be empty. This array is replaced during a strategic
  1494. merge patch.
  1495. items:
  1496. type: string
  1497. type: array
  1498. x-kubernetes-list-type: atomic
  1499. required:
  1500. - key
  1501. - operator
  1502. type: object
  1503. type: array
  1504. x-kubernetes-list-type: atomic
  1505. matchLabels:
  1506. additionalProperties:
  1507. type: string
  1508. description: |-
  1509. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1510. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1511. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1512. type: object
  1513. type: object
  1514. x-kubernetes-map-type: atomic
  1515. namespaceSelectors:
  1516. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1517. items:
  1518. description: |-
  1519. A label selector is a label query over a set of resources. The result of matchLabels and
  1520. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1521. label selector matches no objects.
  1522. properties:
  1523. matchExpressions:
  1524. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1525. items:
  1526. description: |-
  1527. A label selector requirement is a selector that contains values, a key, and an operator that
  1528. relates the key and values.
  1529. properties:
  1530. key:
  1531. description: key is the label key that the selector applies to.
  1532. type: string
  1533. operator:
  1534. description: |-
  1535. operator represents a key's relationship to a set of values.
  1536. Valid operators are In, NotIn, Exists and DoesNotExist.
  1537. type: string
  1538. values:
  1539. description: |-
  1540. values is an array of string values. If the operator is In or NotIn,
  1541. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1542. the values array must be empty. This array is replaced during a strategic
  1543. merge patch.
  1544. items:
  1545. type: string
  1546. type: array
  1547. x-kubernetes-list-type: atomic
  1548. required:
  1549. - key
  1550. - operator
  1551. type: object
  1552. type: array
  1553. x-kubernetes-list-type: atomic
  1554. matchLabels:
  1555. additionalProperties:
  1556. type: string
  1557. description: |-
  1558. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1559. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1560. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1561. type: object
  1562. type: object
  1563. x-kubernetes-map-type: atomic
  1564. type: array
  1565. namespaces:
  1566. description: |-
  1567. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  1568. Deprecated: Use NamespaceSelectors instead.
  1569. items:
  1570. maxLength: 63
  1571. minLength: 1
  1572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1573. type: string
  1574. type: array
  1575. refreshTime:
  1576. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  1577. type: string
  1578. required:
  1579. - externalSecretSpec
  1580. type: object
  1581. status:
  1582. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  1583. properties:
  1584. conditions:
  1585. items:
  1586. description: ClusterExternalSecretStatusCondition indicates the status of the ClusterExternalSecret.
  1587. properties:
  1588. message:
  1589. type: string
  1590. status:
  1591. type: string
  1592. type:
  1593. description: ClusterExternalSecretConditionType indicates the condition of the ClusterExternalSecret.
  1594. type: string
  1595. required:
  1596. - status
  1597. - type
  1598. type: object
  1599. type: array
  1600. externalSecretName:
  1601. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  1602. type: string
  1603. failedNamespaces:
  1604. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  1605. items:
  1606. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  1607. properties:
  1608. namespace:
  1609. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  1610. type: string
  1611. reason:
  1612. description: Reason is why the ExternalSecret failed to apply to the namespace
  1613. type: string
  1614. required:
  1615. - namespace
  1616. type: object
  1617. type: array
  1618. provisionedNamespaces:
  1619. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  1620. items:
  1621. type: string
  1622. type: array
  1623. type: object
  1624. type: object
  1625. served: false
  1626. storage: false
  1627. subresources:
  1628. status: {}
  1629. ---
  1630. apiVersion: apiextensions.k8s.io/v1
  1631. kind: CustomResourceDefinition
  1632. metadata:
  1633. annotations:
  1634. controller-gen.kubebuilder.io/version: v0.19.0
  1635. labels:
  1636. external-secrets.io/component: controller
  1637. name: clusterpushsecrets.external-secrets.io
  1638. spec:
  1639. group: external-secrets.io
  1640. names:
  1641. categories:
  1642. - external-secrets
  1643. kind: ClusterPushSecret
  1644. listKind: ClusterPushSecretList
  1645. plural: clusterpushsecrets
  1646. singular: clusterpushsecret
  1647. scope: Cluster
  1648. versions:
  1649. - additionalPrinterColumns:
  1650. - jsonPath: .metadata.creationTimestamp
  1651. name: AGE
  1652. type: date
  1653. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  1654. name: Status
  1655. type: string
  1656. name: v1alpha1
  1657. schema:
  1658. openAPIV3Schema:
  1659. description: ClusterPushSecret is the Schema for the ClusterPushSecrets API that enables cluster-wide management of pushing Kubernetes secrets to external providers.
  1660. properties:
  1661. apiVersion:
  1662. description: |-
  1663. APIVersion defines the versioned schema of this representation of an object.
  1664. Servers should convert recognized schemas to the latest internal value, and
  1665. may reject unrecognized values.
  1666. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  1667. type: string
  1668. kind:
  1669. description: |-
  1670. Kind is a string value representing the REST resource this object represents.
  1671. Servers may infer this from the endpoint the client submits requests to.
  1672. Cannot be updated.
  1673. In CamelCase.
  1674. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  1675. type: string
  1676. metadata:
  1677. type: object
  1678. spec:
  1679. description: ClusterPushSecretSpec defines the configuration for a ClusterPushSecret resource.
  1680. properties:
  1681. namespaceSelectors:
  1682. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1683. items:
  1684. description: |-
  1685. A label selector is a label query over a set of resources. The result of matchLabels and
  1686. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1687. label selector matches no objects.
  1688. properties:
  1689. matchExpressions:
  1690. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1691. items:
  1692. description: |-
  1693. A label selector requirement is a selector that contains values, a key, and an operator that
  1694. relates the key and values.
  1695. properties:
  1696. key:
  1697. description: key is the label key that the selector applies to.
  1698. type: string
  1699. operator:
  1700. description: |-
  1701. operator represents a key's relationship to a set of values.
  1702. Valid operators are In, NotIn, Exists and DoesNotExist.
  1703. type: string
  1704. values:
  1705. description: |-
  1706. values is an array of string values. If the operator is In or NotIn,
  1707. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1708. the values array must be empty. This array is replaced during a strategic
  1709. merge patch.
  1710. items:
  1711. type: string
  1712. type: array
  1713. x-kubernetes-list-type: atomic
  1714. required:
  1715. - key
  1716. - operator
  1717. type: object
  1718. type: array
  1719. x-kubernetes-list-type: atomic
  1720. matchLabels:
  1721. additionalProperties:
  1722. type: string
  1723. description: |-
  1724. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1725. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1726. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1727. type: object
  1728. type: object
  1729. x-kubernetes-map-type: atomic
  1730. type: array
  1731. pushSecretMetadata:
  1732. description: The metadata of the external secrets to be created
  1733. properties:
  1734. annotations:
  1735. additionalProperties:
  1736. type: string
  1737. type: object
  1738. labels:
  1739. additionalProperties:
  1740. type: string
  1741. type: object
  1742. type: object
  1743. pushSecretName:
  1744. description: |-
  1745. The name of the push secrets to be created.
  1746. Defaults to the name of the ClusterPushSecret
  1747. maxLength: 253
  1748. minLength: 1
  1749. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1750. type: string
  1751. pushSecretSpec:
  1752. description: PushSecretSpec defines what to do with the secrets.
  1753. properties:
  1754. data:
  1755. description: Secret Data that should be pushed to providers
  1756. items:
  1757. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  1758. properties:
  1759. conversionStrategy:
  1760. default: None
  1761. description: Used to define a conversion Strategy for the secret keys
  1762. enum:
  1763. - None
  1764. - ReverseUnicode
  1765. type: string
  1766. match:
  1767. description: Match a given Secret Key to be pushed to the provider.
  1768. properties:
  1769. remoteRef:
  1770. description: Remote Refs to push to providers.
  1771. properties:
  1772. property:
  1773. description: Name of the property in the resulting secret
  1774. type: string
  1775. remoteKey:
  1776. description: Name of the resulting provider secret.
  1777. type: string
  1778. required:
  1779. - remoteKey
  1780. type: object
  1781. secretKey:
  1782. description: Secret Key to be pushed
  1783. type: string
  1784. required:
  1785. - remoteRef
  1786. type: object
  1787. metadata:
  1788. description: |-
  1789. Metadata is metadata attached to the secret.
  1790. The structure of metadata is provider specific, please look it up in the provider documentation.
  1791. x-kubernetes-preserve-unknown-fields: true
  1792. required:
  1793. - match
  1794. type: object
  1795. type: array
  1796. dataTo:
  1797. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  1798. items:
  1799. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  1800. properties:
  1801. conversionStrategy:
  1802. default: None
  1803. description: Used to define a conversion Strategy for the secret keys
  1804. enum:
  1805. - None
  1806. - ReverseUnicode
  1807. type: string
  1808. match:
  1809. description: |-
  1810. Match pattern for selecting keys from the source Secret.
  1811. If not specified, all keys are selected.
  1812. properties:
  1813. regexp:
  1814. description: |-
  1815. Regexp matches keys by regular expression.
  1816. If not specified, all keys are matched.
  1817. type: string
  1818. type: object
  1819. metadata:
  1820. description: |-
  1821. Metadata is metadata attached to the secret.
  1822. The structure of metadata is provider specific, please look it up in the provider documentation.
  1823. x-kubernetes-preserve-unknown-fields: true
  1824. remoteKey:
  1825. description: |-
  1826. RemoteKey is the name of the single provider secret that will receive ALL
  1827. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  1828. When set, per-key expansion is skipped and a single push is performed.
  1829. The provider's store prefix (if any) is still prepended to this value.
  1830. When not set, each matched key is pushed as its own individual provider secret.
  1831. type: string
  1832. rewrite:
  1833. description: |-
  1834. Rewrite operations to transform keys before pushing to the provider.
  1835. Operations are applied sequentially.
  1836. items:
  1837. description: PushSecretRewrite defines how to transform secret keys before pushing.
  1838. properties:
  1839. regexp:
  1840. description: Used to rewrite with regular expressions.
  1841. properties:
  1842. source:
  1843. description: Used to define the regular expression of a re.Compiler.
  1844. type: string
  1845. target:
  1846. description: Used to define the target pattern of a ReplaceAll operation.
  1847. type: string
  1848. required:
  1849. - source
  1850. - target
  1851. type: object
  1852. transform:
  1853. description: Used to apply string transformation on the secrets.
  1854. properties:
  1855. template:
  1856. description: |-
  1857. Used to define the template to apply on the secret name.
  1858. `.value ` will specify the secret name in the template.
  1859. type: string
  1860. required:
  1861. - template
  1862. type: object
  1863. type: object
  1864. x-kubernetes-validations:
  1865. - message: exactly one of regexp or transform must be set
  1866. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  1867. type: array
  1868. storeRef:
  1869. description: StoreRef specifies which SecretStore to push to. Required.
  1870. properties:
  1871. kind:
  1872. default: SecretStore
  1873. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1874. enum:
  1875. - SecretStore
  1876. - ClusterSecretStore
  1877. type: string
  1878. labelSelector:
  1879. description: Optionally, sync to secret stores with label selector
  1880. properties:
  1881. matchExpressions:
  1882. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1883. items:
  1884. description: |-
  1885. A label selector requirement is a selector that contains values, a key, and an operator that
  1886. relates the key and values.
  1887. properties:
  1888. key:
  1889. description: key is the label key that the selector applies to.
  1890. type: string
  1891. operator:
  1892. description: |-
  1893. operator represents a key's relationship to a set of values.
  1894. Valid operators are In, NotIn, Exists and DoesNotExist.
  1895. type: string
  1896. values:
  1897. description: |-
  1898. values is an array of string values. If the operator is In or NotIn,
  1899. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1900. the values array must be empty. This array is replaced during a strategic
  1901. merge patch.
  1902. items:
  1903. type: string
  1904. type: array
  1905. x-kubernetes-list-type: atomic
  1906. required:
  1907. - key
  1908. - operator
  1909. type: object
  1910. type: array
  1911. x-kubernetes-list-type: atomic
  1912. matchLabels:
  1913. additionalProperties:
  1914. type: string
  1915. description: |-
  1916. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1917. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1918. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1919. type: object
  1920. type: object
  1921. x-kubernetes-map-type: atomic
  1922. name:
  1923. description: Optionally, sync to the SecretStore of the given name
  1924. maxLength: 253
  1925. minLength: 1
  1926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1927. type: string
  1928. type: object
  1929. type: object
  1930. x-kubernetes-validations:
  1931. - message: storeRef must specify either name or labelSelector
  1932. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  1933. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  1934. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  1935. type: array
  1936. deletionPolicy:
  1937. default: None
  1938. description: Deletion Policy to handle Secrets in the provider.
  1939. enum:
  1940. - Delete
  1941. - None
  1942. type: string
  1943. refreshInterval:
  1944. default: 1h0m0s
  1945. description: The Interval to which External Secrets will try to push a secret definition
  1946. type: string
  1947. secretStoreRefs:
  1948. items:
  1949. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  1950. properties:
  1951. kind:
  1952. default: SecretStore
  1953. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1954. enum:
  1955. - SecretStore
  1956. - ClusterSecretStore
  1957. type: string
  1958. labelSelector:
  1959. description: Optionally, sync to secret stores with label selector
  1960. properties:
  1961. matchExpressions:
  1962. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1963. items:
  1964. description: |-
  1965. A label selector requirement is a selector that contains values, a key, and an operator that
  1966. relates the key and values.
  1967. properties:
  1968. key:
  1969. description: key is the label key that the selector applies to.
  1970. type: string
  1971. operator:
  1972. description: |-
  1973. operator represents a key's relationship to a set of values.
  1974. Valid operators are In, NotIn, Exists and DoesNotExist.
  1975. type: string
  1976. values:
  1977. description: |-
  1978. values is an array of string values. If the operator is In or NotIn,
  1979. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1980. the values array must be empty. This array is replaced during a strategic
  1981. merge patch.
  1982. items:
  1983. type: string
  1984. type: array
  1985. x-kubernetes-list-type: atomic
  1986. required:
  1987. - key
  1988. - operator
  1989. type: object
  1990. type: array
  1991. x-kubernetes-list-type: atomic
  1992. matchLabels:
  1993. additionalProperties:
  1994. type: string
  1995. description: |-
  1996. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1997. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1998. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1999. type: object
  2000. type: object
  2001. x-kubernetes-map-type: atomic
  2002. name:
  2003. description: Optionally, sync to the SecretStore of the given name
  2004. maxLength: 253
  2005. minLength: 1
  2006. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2007. type: string
  2008. type: object
  2009. type: array
  2010. selector:
  2011. description: The Secret Selector (k8s source) for the Push Secret
  2012. maxProperties: 1
  2013. minProperties: 1
  2014. properties:
  2015. generatorRef:
  2016. description: Point to a generator to create a Secret.
  2017. properties:
  2018. apiVersion:
  2019. default: generators.external-secrets.io/v1alpha1
  2020. description: Specify the apiVersion of the generator resource
  2021. type: string
  2022. kind:
  2023. description: Specify the Kind of the generator resource
  2024. enum:
  2025. - ACRAccessToken
  2026. - BeyondtrustWorkloadCredentialsDynamicSecret
  2027. - ClusterGenerator
  2028. - CloudsmithAccessToken
  2029. - ECRAuthorizationToken
  2030. - Fake
  2031. - GCRAccessToken
  2032. - GithubAccessToken
  2033. - GitlabDeployToken
  2034. - QuayAccessToken
  2035. - Password
  2036. - SSHKey
  2037. - STSSessionToken
  2038. - UUID
  2039. - VaultDynamicSecret
  2040. - Webhook
  2041. - Grafana
  2042. - MFA
  2043. type: string
  2044. name:
  2045. description: Specify the name of the generator resource
  2046. maxLength: 253
  2047. minLength: 1
  2048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2049. type: string
  2050. required:
  2051. - kind
  2052. - name
  2053. type: object
  2054. secret:
  2055. description: Select a Secret to Push.
  2056. properties:
  2057. name:
  2058. description: |-
  2059. Name of the Secret.
  2060. The Secret must exist in the same namespace as the PushSecret manifest.
  2061. maxLength: 253
  2062. minLength: 1
  2063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2064. type: string
  2065. selector:
  2066. description: Selector chooses secrets using a labelSelector.
  2067. properties:
  2068. matchExpressions:
  2069. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2070. items:
  2071. description: |-
  2072. A label selector requirement is a selector that contains values, a key, and an operator that
  2073. relates the key and values.
  2074. properties:
  2075. key:
  2076. description: key is the label key that the selector applies to.
  2077. type: string
  2078. operator:
  2079. description: |-
  2080. operator represents a key's relationship to a set of values.
  2081. Valid operators are In, NotIn, Exists and DoesNotExist.
  2082. type: string
  2083. values:
  2084. description: |-
  2085. values is an array of string values. If the operator is In or NotIn,
  2086. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2087. the values array must be empty. This array is replaced during a strategic
  2088. merge patch.
  2089. items:
  2090. type: string
  2091. type: array
  2092. x-kubernetes-list-type: atomic
  2093. required:
  2094. - key
  2095. - operator
  2096. type: object
  2097. type: array
  2098. x-kubernetes-list-type: atomic
  2099. matchLabels:
  2100. additionalProperties:
  2101. type: string
  2102. description: |-
  2103. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2104. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2105. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2106. type: object
  2107. type: object
  2108. x-kubernetes-map-type: atomic
  2109. type: object
  2110. type: object
  2111. template:
  2112. description: Template defines a blueprint for the created Secret resource.
  2113. properties:
  2114. data:
  2115. additionalProperties:
  2116. type: string
  2117. type: object
  2118. engineVersion:
  2119. default: v2
  2120. description: |-
  2121. EngineVersion specifies the template engine version
  2122. that should be used to compile/execute the
  2123. template specified in .data and .templateFrom[].
  2124. enum:
  2125. - v2
  2126. type: string
  2127. mergePolicy:
  2128. default: Replace
  2129. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  2130. enum:
  2131. - Replace
  2132. - Merge
  2133. type: string
  2134. metadata:
  2135. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  2136. properties:
  2137. annotations:
  2138. additionalProperties:
  2139. type: string
  2140. type: object
  2141. finalizers:
  2142. items:
  2143. type: string
  2144. type: array
  2145. labels:
  2146. additionalProperties:
  2147. type: string
  2148. type: object
  2149. type: object
  2150. templateFrom:
  2151. items:
  2152. description: |-
  2153. TemplateFrom specifies a source for templates.
  2154. Each item in the list can either reference a ConfigMap or a Secret resource.
  2155. properties:
  2156. configMap:
  2157. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2158. properties:
  2159. items:
  2160. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2161. items:
  2162. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2163. properties:
  2164. key:
  2165. description: A key in the ConfigMap/Secret
  2166. maxLength: 253
  2167. minLength: 1
  2168. pattern: ^[-._a-zA-Z0-9]+$
  2169. type: string
  2170. templateAs:
  2171. default: Values
  2172. description: TemplateScope specifies how the template keys should be interpreted.
  2173. enum:
  2174. - Values
  2175. - KeysAndValues
  2176. type: string
  2177. required:
  2178. - key
  2179. type: object
  2180. type: array
  2181. name:
  2182. description: The name of the ConfigMap/Secret resource
  2183. maxLength: 253
  2184. minLength: 1
  2185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2186. type: string
  2187. required:
  2188. - items
  2189. - name
  2190. type: object
  2191. literal:
  2192. type: string
  2193. secret:
  2194. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2195. properties:
  2196. items:
  2197. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2198. items:
  2199. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2200. properties:
  2201. key:
  2202. description: A key in the ConfigMap/Secret
  2203. maxLength: 253
  2204. minLength: 1
  2205. pattern: ^[-._a-zA-Z0-9]+$
  2206. type: string
  2207. templateAs:
  2208. default: Values
  2209. description: TemplateScope specifies how the template keys should be interpreted.
  2210. enum:
  2211. - Values
  2212. - KeysAndValues
  2213. type: string
  2214. required:
  2215. - key
  2216. type: object
  2217. type: array
  2218. name:
  2219. description: The name of the ConfigMap/Secret resource
  2220. maxLength: 253
  2221. minLength: 1
  2222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2223. type: string
  2224. required:
  2225. - items
  2226. - name
  2227. type: object
  2228. target:
  2229. default: Data
  2230. description: |-
  2231. Target specifies where to place the template result.
  2232. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  2233. any other value is rejected because it would allow writes to privileged Secret fields.
  2234. For custom resources (when spec.target.manifest is set), this supports
  2235. nested paths like "spec.database.config" or "data".
  2236. type: string
  2237. valuesDecodingStrategy:
  2238. description: |-
  2239. Used to define a decoding Strategy for the rendered template values.
  2240. Defaults to None when omitted.
  2241. enum:
  2242. - Auto
  2243. - Base64
  2244. - Base64URL
  2245. - None
  2246. type: string
  2247. type: object
  2248. type: array
  2249. type:
  2250. type: string
  2251. type: object
  2252. updatePolicy:
  2253. default: Replace
  2254. description: UpdatePolicy to handle Secrets in the provider.
  2255. enum:
  2256. - Replace
  2257. - IfNotExists
  2258. type: string
  2259. required:
  2260. - secretStoreRefs
  2261. - selector
  2262. type: object
  2263. refreshTime:
  2264. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  2265. type: string
  2266. required:
  2267. - pushSecretSpec
  2268. type: object
  2269. status:
  2270. description: ClusterPushSecretStatus contains the status information for the ClusterPushSecret resource.
  2271. properties:
  2272. conditions:
  2273. items:
  2274. description: PushSecretStatusCondition indicates the status of the PushSecret.
  2275. properties:
  2276. lastTransitionTime:
  2277. format: date-time
  2278. type: string
  2279. message:
  2280. type: string
  2281. reason:
  2282. type: string
  2283. status:
  2284. type: string
  2285. type:
  2286. description: PushSecretConditionType indicates the condition of the PushSecret.
  2287. type: string
  2288. required:
  2289. - status
  2290. - type
  2291. type: object
  2292. type: array
  2293. failedNamespaces:
  2294. description: Failed namespaces are the namespaces that failed to apply an PushSecret
  2295. items:
  2296. description: ClusterPushSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  2297. properties:
  2298. namespace:
  2299. description: Namespace is the namespace that failed when trying to apply an PushSecret
  2300. type: string
  2301. reason:
  2302. description: Reason is why the PushSecret failed to apply to the namespace
  2303. type: string
  2304. required:
  2305. - namespace
  2306. type: object
  2307. type: array
  2308. provisionedNamespaces:
  2309. description: ProvisionedNamespaces are the namespaces where the ClusterPushSecret has secrets
  2310. items:
  2311. type: string
  2312. type: array
  2313. pushSecretName:
  2314. type: string
  2315. type: object
  2316. type: object
  2317. served: true
  2318. storage: true
  2319. subresources:
  2320. status: {}
  2321. ---
  2322. apiVersion: apiextensions.k8s.io/v1
  2323. kind: CustomResourceDefinition
  2324. metadata:
  2325. annotations:
  2326. controller-gen.kubebuilder.io/version: v0.19.0
  2327. labels:
  2328. external-secrets.io/component: controller
  2329. name: clustersecretstores.external-secrets.io
  2330. spec:
  2331. group: external-secrets.io
  2332. names:
  2333. categories:
  2334. - external-secrets
  2335. kind: ClusterSecretStore
  2336. listKind: ClusterSecretStoreList
  2337. plural: clustersecretstores
  2338. shortNames:
  2339. - css
  2340. singular: clustersecretstore
  2341. scope: Cluster
  2342. versions:
  2343. - additionalPrinterColumns:
  2344. - jsonPath: .metadata.creationTimestamp
  2345. name: AGE
  2346. type: date
  2347. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  2348. name: Status
  2349. type: string
  2350. - jsonPath: .status.capabilities
  2351. name: Capabilities
  2352. type: string
  2353. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  2354. name: Ready
  2355. type: string
  2356. name: v1
  2357. schema:
  2358. openAPIV3Schema:
  2359. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  2360. properties:
  2361. apiVersion:
  2362. description: |-
  2363. APIVersion defines the versioned schema of this representation of an object.
  2364. Servers should convert recognized schemas to the latest internal value, and
  2365. may reject unrecognized values.
  2366. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  2367. type: string
  2368. kind:
  2369. description: |-
  2370. Kind is a string value representing the REST resource this object represents.
  2371. Servers may infer this from the endpoint the client submits requests to.
  2372. Cannot be updated.
  2373. In CamelCase.
  2374. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  2375. type: string
  2376. metadata:
  2377. type: object
  2378. spec:
  2379. description: SecretStoreSpec defines the desired state of SecretStore.
  2380. properties:
  2381. conditions:
  2382. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  2383. items:
  2384. description: |-
  2385. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  2386. for a ClusterSecretStore instance.
  2387. properties:
  2388. namespaceRegexes:
  2389. description: Choose namespaces by using regex matching
  2390. items:
  2391. type: string
  2392. type: array
  2393. namespaceSelector:
  2394. description: Choose namespace using a labelSelector
  2395. properties:
  2396. matchExpressions:
  2397. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2398. items:
  2399. description: |-
  2400. A label selector requirement is a selector that contains values, a key, and an operator that
  2401. relates the key and values.
  2402. properties:
  2403. key:
  2404. description: key is the label key that the selector applies to.
  2405. type: string
  2406. operator:
  2407. description: |-
  2408. operator represents a key's relationship to a set of values.
  2409. Valid operators are In, NotIn, Exists and DoesNotExist.
  2410. type: string
  2411. values:
  2412. description: |-
  2413. values is an array of string values. If the operator is In or NotIn,
  2414. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2415. the values array must be empty. This array is replaced during a strategic
  2416. merge patch.
  2417. items:
  2418. type: string
  2419. type: array
  2420. x-kubernetes-list-type: atomic
  2421. required:
  2422. - key
  2423. - operator
  2424. type: object
  2425. type: array
  2426. x-kubernetes-list-type: atomic
  2427. matchLabels:
  2428. additionalProperties:
  2429. type: string
  2430. description: |-
  2431. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2432. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2433. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2434. type: object
  2435. type: object
  2436. x-kubernetes-map-type: atomic
  2437. namespaces:
  2438. description: Choose namespaces by name
  2439. items:
  2440. maxLength: 63
  2441. minLength: 1
  2442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2443. type: string
  2444. type: array
  2445. type: object
  2446. type: array
  2447. controller:
  2448. description: |-
  2449. Used to select the correct ESO controller (think: ingress.ingressClassName)
  2450. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  2451. type: string
  2452. provider:
  2453. description: Used to configure the provider. Only one provider may be set
  2454. maxProperties: 1
  2455. minProperties: 1
  2456. properties:
  2457. akeyless:
  2458. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  2459. properties:
  2460. akeylessGWApiURL:
  2461. description: Akeyless GW API Url from which the secrets to be fetched from.
  2462. type: string
  2463. authSecretRef:
  2464. description: Auth configures how the operator authenticates with Akeyless.
  2465. properties:
  2466. kubernetesAuth:
  2467. description: |-
  2468. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  2469. token stored in the named Secret resource.
  2470. properties:
  2471. accessID:
  2472. description: the Akeyless Kubernetes auth-method access-id
  2473. type: string
  2474. k8sConfName:
  2475. description: Kubernetes-auth configuration name in Akeyless-Gateway
  2476. type: string
  2477. secretRef:
  2478. description: |-
  2479. Optional secret field containing a Kubernetes ServiceAccount JWT used
  2480. for authenticating with Akeyless. If a name is specified without a key,
  2481. `token` is the default. If one is not specified, the one bound to
  2482. the controller will be used.
  2483. properties:
  2484. key:
  2485. description: |-
  2486. A key in the referenced Secret.
  2487. Some instances of this field may be defaulted, in others it may be required.
  2488. maxLength: 253
  2489. minLength: 1
  2490. pattern: ^[-._a-zA-Z0-9]+$
  2491. type: string
  2492. name:
  2493. description: The name of the Secret resource being referred to.
  2494. maxLength: 253
  2495. minLength: 1
  2496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2497. type: string
  2498. namespace:
  2499. description: |-
  2500. The namespace of the Secret resource being referred to.
  2501. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2502. maxLength: 63
  2503. minLength: 1
  2504. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2505. type: string
  2506. type: object
  2507. serviceAccountRef:
  2508. description: |-
  2509. Optional service account field containing the name of a kubernetes ServiceAccount.
  2510. If the service account is specified, the service account secret token JWT will be used
  2511. for authenticating with Akeyless. If the service account selector is not supplied,
  2512. the secretRef will be used instead.
  2513. properties:
  2514. audiences:
  2515. description: |-
  2516. Audience specifies the `aud` claim for the service account token
  2517. Some providers automatically extend the audience field based on well-known annotations for workload
  2518. identity (e.g. IRSA or GCP Workload Identity)
  2519. items:
  2520. type: string
  2521. type: array
  2522. name:
  2523. description: The name of the ServiceAccount resource being referred to.
  2524. maxLength: 253
  2525. minLength: 1
  2526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2527. type: string
  2528. namespace:
  2529. description: |-
  2530. Namespace of the resource being referred to.
  2531. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2532. maxLength: 63
  2533. minLength: 1
  2534. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2535. type: string
  2536. required:
  2537. - name
  2538. type: object
  2539. required:
  2540. - accessID
  2541. - k8sConfName
  2542. type: object
  2543. secretRef:
  2544. description: |-
  2545. Reference to a Secret that contains the details
  2546. to authenticate with Akeyless.
  2547. properties:
  2548. accessID:
  2549. description: The SecretAccessID is used for authentication
  2550. properties:
  2551. key:
  2552. description: |-
  2553. A key in the referenced Secret.
  2554. Some instances of this field may be defaulted, in others it may be required.
  2555. maxLength: 253
  2556. minLength: 1
  2557. pattern: ^[-._a-zA-Z0-9]+$
  2558. type: string
  2559. name:
  2560. description: The name of the Secret resource being referred to.
  2561. maxLength: 253
  2562. minLength: 1
  2563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2564. type: string
  2565. namespace:
  2566. description: |-
  2567. The namespace of the Secret resource being referred to.
  2568. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2569. maxLength: 63
  2570. minLength: 1
  2571. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2572. type: string
  2573. type: object
  2574. accessType:
  2575. description: |-
  2576. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2577. In some instances, `key` is a required field.
  2578. properties:
  2579. key:
  2580. description: |-
  2581. A key in the referenced Secret.
  2582. Some instances of this field may be defaulted, in others it may be required.
  2583. maxLength: 253
  2584. minLength: 1
  2585. pattern: ^[-._a-zA-Z0-9]+$
  2586. type: string
  2587. name:
  2588. description: The name of the Secret resource being referred to.
  2589. maxLength: 253
  2590. minLength: 1
  2591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2592. type: string
  2593. namespace:
  2594. description: |-
  2595. The namespace of the Secret resource being referred to.
  2596. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2597. maxLength: 63
  2598. minLength: 1
  2599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2600. type: string
  2601. type: object
  2602. accessTypeParam:
  2603. description: |-
  2604. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2605. In some instances, `key` is a required field.
  2606. properties:
  2607. key:
  2608. description: |-
  2609. A key in the referenced Secret.
  2610. Some instances of this field may be defaulted, in others it may be required.
  2611. maxLength: 253
  2612. minLength: 1
  2613. pattern: ^[-._a-zA-Z0-9]+$
  2614. type: string
  2615. name:
  2616. description: The name of the Secret resource being referred to.
  2617. maxLength: 253
  2618. minLength: 1
  2619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2620. type: string
  2621. namespace:
  2622. description: |-
  2623. The namespace of the Secret resource being referred to.
  2624. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2625. maxLength: 63
  2626. minLength: 1
  2627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2628. type: string
  2629. type: object
  2630. type: object
  2631. serviceAccountRef:
  2632. description: |-
  2633. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  2634. authentication on AKS Workload Identity. The operator obtains a federated
  2635. identity token from this ServiceAccount via the TokenRequest API instead
  2636. of using the ESO controller pod identity. Ignored for other access types.
  2637. properties:
  2638. audiences:
  2639. description: |-
  2640. Audience specifies the `aud` claim for the service account token
  2641. Some providers automatically extend the audience field based on well-known annotations for workload
  2642. identity (e.g. IRSA or GCP Workload Identity)
  2643. items:
  2644. type: string
  2645. type: array
  2646. name:
  2647. description: The name of the ServiceAccount resource being referred to.
  2648. maxLength: 253
  2649. minLength: 1
  2650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2651. type: string
  2652. namespace:
  2653. description: |-
  2654. Namespace of the resource being referred to.
  2655. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2656. maxLength: 63
  2657. minLength: 1
  2658. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2659. type: string
  2660. required:
  2661. - name
  2662. type: object
  2663. type: object
  2664. caBundle:
  2665. description: |-
  2666. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  2667. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  2668. are used to validate the TLS connection.
  2669. format: byte
  2670. type: string
  2671. caProvider:
  2672. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  2673. properties:
  2674. key:
  2675. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  2676. maxLength: 253
  2677. minLength: 1
  2678. pattern: ^[-._a-zA-Z0-9]+$
  2679. type: string
  2680. name:
  2681. description: The name of the object located at the provider type.
  2682. maxLength: 253
  2683. minLength: 1
  2684. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2685. type: string
  2686. namespace:
  2687. description: |-
  2688. The namespace the Provider type is in.
  2689. Can only be defined when used in a ClusterSecretStore.
  2690. maxLength: 63
  2691. minLength: 1
  2692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2693. type: string
  2694. type:
  2695. description: The type of provider to use such as "Secret", or "ConfigMap".
  2696. enum:
  2697. - Secret
  2698. - ConfigMap
  2699. type: string
  2700. required:
  2701. - name
  2702. - type
  2703. type: object
  2704. ignoreCache:
  2705. description: |-
  2706. IgnoreCache bypasses the Gateway cache for secret reads when true.
  2707. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  2708. type: boolean
  2709. required:
  2710. - akeylessGWApiURL
  2711. - authSecretRef
  2712. type: object
  2713. aws:
  2714. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  2715. properties:
  2716. additionalRoles:
  2717. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  2718. items:
  2719. type: string
  2720. type: array
  2721. auth:
  2722. description: |-
  2723. Auth defines the information necessary to authenticate against AWS
  2724. if not set aws sdk will infer credentials from your environment
  2725. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  2726. properties:
  2727. jwt:
  2728. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  2729. properties:
  2730. serviceAccountRef:
  2731. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  2732. properties:
  2733. audiences:
  2734. description: |-
  2735. Audience specifies the `aud` claim for the service account token
  2736. Some providers automatically extend the audience field based on well-known annotations for workload
  2737. identity (e.g. IRSA or GCP Workload Identity)
  2738. items:
  2739. type: string
  2740. type: array
  2741. name:
  2742. description: The name of the ServiceAccount resource being referred to.
  2743. maxLength: 253
  2744. minLength: 1
  2745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2746. type: string
  2747. namespace:
  2748. description: |-
  2749. Namespace of the resource being referred to.
  2750. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2751. maxLength: 63
  2752. minLength: 1
  2753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2754. type: string
  2755. required:
  2756. - name
  2757. type: object
  2758. type: object
  2759. secretRef:
  2760. description: |-
  2761. AWSAuthSecretRef holds secret references for AWS credentials
  2762. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  2763. properties:
  2764. accessKeyIDSecretRef:
  2765. description: The AccessKeyID is used for authentication
  2766. properties:
  2767. key:
  2768. description: |-
  2769. A key in the referenced Secret.
  2770. Some instances of this field may be defaulted, in others it may be required.
  2771. maxLength: 253
  2772. minLength: 1
  2773. pattern: ^[-._a-zA-Z0-9]+$
  2774. type: string
  2775. name:
  2776. description: The name of the Secret resource being referred to.
  2777. maxLength: 253
  2778. minLength: 1
  2779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2780. type: string
  2781. namespace:
  2782. description: |-
  2783. The namespace of the Secret resource being referred to.
  2784. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2785. maxLength: 63
  2786. minLength: 1
  2787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2788. type: string
  2789. type: object
  2790. secretAccessKeySecretRef:
  2791. description: The SecretAccessKey is used for authentication
  2792. properties:
  2793. key:
  2794. description: |-
  2795. A key in the referenced Secret.
  2796. Some instances of this field may be defaulted, in others it may be required.
  2797. maxLength: 253
  2798. minLength: 1
  2799. pattern: ^[-._a-zA-Z0-9]+$
  2800. type: string
  2801. name:
  2802. description: The name of the Secret resource being referred to.
  2803. maxLength: 253
  2804. minLength: 1
  2805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2806. type: string
  2807. namespace:
  2808. description: |-
  2809. The namespace of the Secret resource being referred to.
  2810. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2811. maxLength: 63
  2812. minLength: 1
  2813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2814. type: string
  2815. type: object
  2816. sessionTokenSecretRef:
  2817. description: |-
  2818. The SessionToken used for authentication
  2819. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  2820. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  2821. properties:
  2822. key:
  2823. description: |-
  2824. A key in the referenced Secret.
  2825. Some instances of this field may be defaulted, in others it may be required.
  2826. maxLength: 253
  2827. minLength: 1
  2828. pattern: ^[-._a-zA-Z0-9]+$
  2829. type: string
  2830. name:
  2831. description: The name of the Secret resource being referred to.
  2832. maxLength: 253
  2833. minLength: 1
  2834. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2835. type: string
  2836. namespace:
  2837. description: |-
  2838. The namespace of the Secret resource being referred to.
  2839. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2840. maxLength: 63
  2841. minLength: 1
  2842. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2843. type: string
  2844. type: object
  2845. type: object
  2846. type: object
  2847. customSessionTags:
  2848. additionalProperties:
  2849. type: string
  2850. description: |-
  2851. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  2852. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  2853. type: object
  2854. x-kubernetes-validations:
  2855. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  2856. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  2857. externalID:
  2858. description: AWS External ID set on assumed IAM roles
  2859. type: string
  2860. prefix:
  2861. description: Prefix adds a prefix to all retrieved values.
  2862. type: string
  2863. region:
  2864. description: AWS Region to be used for the provider
  2865. type: string
  2866. role:
  2867. description: Role is a Role ARN which the provider will assume
  2868. type: string
  2869. secretsManager:
  2870. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  2871. properties:
  2872. forceDeleteWithoutRecovery:
  2873. description: |-
  2874. Specifies whether to delete the secret without any recovery window. You
  2875. can't use both this parameter and RecoveryWindowInDays in the same call.
  2876. If you don't use either, then by default Secrets Manager uses a 30 day
  2877. recovery window.
  2878. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  2879. type: boolean
  2880. recoveryWindowInDays:
  2881. description: |-
  2882. The number of days from 7 to 30 that Secrets Manager waits before
  2883. permanently deleting the secret. You can't use both this parameter and
  2884. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  2885. then by default Secrets Manager uses a 30-day recovery window.
  2886. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  2887. format: int64
  2888. type: integer
  2889. type: object
  2890. service:
  2891. description: Service defines which service should be used to fetch the secrets
  2892. enum:
  2893. - SecretsManager
  2894. - ParameterStore
  2895. - CertificateManager
  2896. type: string
  2897. sessionTags:
  2898. description: AWS STS assume role session tags
  2899. items:
  2900. description: |-
  2901. Tag is a key-value pair that can be attached to an AWS resource.
  2902. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  2903. properties:
  2904. key:
  2905. type: string
  2906. value:
  2907. type: string
  2908. required:
  2909. - key
  2910. - value
  2911. type: object
  2912. type: array
  2913. sessionTagsPolicy:
  2914. default: None
  2915. description: |-
  2916. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  2917. None (default): no tags are added.
  2918. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  2919. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  2920. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  2921. enum:
  2922. - None
  2923. - Simple
  2924. - Custom
  2925. type: string
  2926. transitiveTagKeys:
  2927. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  2928. items:
  2929. type: string
  2930. type: array
  2931. required:
  2932. - region
  2933. - service
  2934. type: object
  2935. azurekv:
  2936. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  2937. properties:
  2938. authSecretRef:
  2939. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  2940. properties:
  2941. clientCertificate:
  2942. description: The Azure ClientCertificate of the service principle used for authentication.
  2943. properties:
  2944. key:
  2945. description: |-
  2946. A key in the referenced Secret.
  2947. Some instances of this field may be defaulted, in others it may be required.
  2948. maxLength: 253
  2949. minLength: 1
  2950. pattern: ^[-._a-zA-Z0-9]+$
  2951. type: string
  2952. name:
  2953. description: The name of the Secret resource being referred to.
  2954. maxLength: 253
  2955. minLength: 1
  2956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2957. type: string
  2958. namespace:
  2959. description: |-
  2960. The namespace of the Secret resource being referred to.
  2961. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2962. maxLength: 63
  2963. minLength: 1
  2964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2965. type: string
  2966. type: object
  2967. clientId:
  2968. description: The Azure clientId of the service principle or managed identity used for authentication.
  2969. properties:
  2970. key:
  2971. description: |-
  2972. A key in the referenced Secret.
  2973. Some instances of this field may be defaulted, in others it may be required.
  2974. maxLength: 253
  2975. minLength: 1
  2976. pattern: ^[-._a-zA-Z0-9]+$
  2977. type: string
  2978. name:
  2979. description: The name of the Secret resource being referred to.
  2980. maxLength: 253
  2981. minLength: 1
  2982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2983. type: string
  2984. namespace:
  2985. description: |-
  2986. The namespace of the Secret resource being referred to.
  2987. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2988. maxLength: 63
  2989. minLength: 1
  2990. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2991. type: string
  2992. type: object
  2993. clientSecret:
  2994. description: The Azure ClientSecret of the service principle used for authentication.
  2995. properties:
  2996. key:
  2997. description: |-
  2998. A key in the referenced Secret.
  2999. Some instances of this field may be defaulted, in others it may be required.
  3000. maxLength: 253
  3001. minLength: 1
  3002. pattern: ^[-._a-zA-Z0-9]+$
  3003. type: string
  3004. name:
  3005. description: The name of the Secret resource being referred to.
  3006. maxLength: 253
  3007. minLength: 1
  3008. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3009. type: string
  3010. namespace:
  3011. description: |-
  3012. The namespace of the Secret resource being referred to.
  3013. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3014. maxLength: 63
  3015. minLength: 1
  3016. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3017. type: string
  3018. type: object
  3019. tenantId:
  3020. description: The Azure tenantId of the managed identity used for authentication.
  3021. properties:
  3022. key:
  3023. description: |-
  3024. A key in the referenced Secret.
  3025. Some instances of this field may be defaulted, in others it may be required.
  3026. maxLength: 253
  3027. minLength: 1
  3028. pattern: ^[-._a-zA-Z0-9]+$
  3029. type: string
  3030. name:
  3031. description: The name of the Secret resource being referred to.
  3032. maxLength: 253
  3033. minLength: 1
  3034. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3035. type: string
  3036. namespace:
  3037. description: |-
  3038. The namespace of the Secret resource being referred to.
  3039. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3040. maxLength: 63
  3041. minLength: 1
  3042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3043. type: string
  3044. type: object
  3045. type: object
  3046. authType:
  3047. default: ServicePrincipal
  3048. description: |-
  3049. Auth type defines how to authenticate to the keyvault service.
  3050. Valid values are:
  3051. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  3052. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  3053. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  3054. enum:
  3055. - ServicePrincipal
  3056. - ManagedIdentity
  3057. - WorkloadIdentity
  3058. type: string
  3059. customCloudConfig:
  3060. description: |-
  3061. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  3062. Required when EnvironmentType is AzureStackCloud.
  3063. Optional for other environment types - useful for Azure China when using Workload Identity
  3064. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  3065. standard China Cloud endpoint (login.chinacloudapi.cn).
  3066. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  3067. configuration is not supported with the legacy go-autorest SDK.
  3068. properties:
  3069. activeDirectoryEndpoint:
  3070. description: |-
  3071. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  3072. Required when using custom cloud configuration
  3073. type: string
  3074. keyVaultDNSSuffix:
  3075. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  3076. type: string
  3077. keyVaultEndpoint:
  3078. description: KeyVaultEndpoint is the Key Vault service endpoint
  3079. type: string
  3080. resourceManagerEndpoint:
  3081. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  3082. type: string
  3083. required:
  3084. - activeDirectoryEndpoint
  3085. type: object
  3086. environmentType:
  3087. default: PublicCloud
  3088. description: |-
  3089. EnvironmentType specifies the Azure cloud environment endpoints to use for
  3090. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  3091. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  3092. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  3093. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  3094. enum:
  3095. - PublicCloud
  3096. - USGovernmentCloud
  3097. - ChinaCloud
  3098. - GermanCloud
  3099. - AzureStackCloud
  3100. type: string
  3101. identityId:
  3102. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  3103. type: string
  3104. serviceAccountRef:
  3105. description: |-
  3106. ServiceAccountRef specified the service account
  3107. that should be used when authenticating with WorkloadIdentity.
  3108. properties:
  3109. audiences:
  3110. description: |-
  3111. Audience specifies the `aud` claim for the service account token
  3112. Some providers automatically extend the audience field based on well-known annotations for workload
  3113. identity (e.g. IRSA or GCP Workload Identity)
  3114. items:
  3115. type: string
  3116. type: array
  3117. name:
  3118. description: The name of the ServiceAccount resource being referred to.
  3119. maxLength: 253
  3120. minLength: 1
  3121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3122. type: string
  3123. namespace:
  3124. description: |-
  3125. Namespace of the resource being referred to.
  3126. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3127. maxLength: 63
  3128. minLength: 1
  3129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3130. type: string
  3131. required:
  3132. - name
  3133. type: object
  3134. tenantId:
  3135. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  3136. type: string
  3137. useAzureSDK:
  3138. default: false
  3139. description: |-
  3140. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  3141. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  3142. type: boolean
  3143. vaultUrl:
  3144. description: Vault Url from which the secrets to be fetched from.
  3145. type: string
  3146. required:
  3147. - vaultUrl
  3148. type: object
  3149. barbican:
  3150. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  3151. properties:
  3152. auth:
  3153. description: BarbicanAuth contains the authentication information for Barbican.
  3154. properties:
  3155. password:
  3156. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  3157. properties:
  3158. secretRef:
  3159. description: |-
  3160. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3161. In some instances, `key` is a required field.
  3162. properties:
  3163. key:
  3164. description: |-
  3165. A key in the referenced Secret.
  3166. Some instances of this field may be defaulted, in others it may be required.
  3167. maxLength: 253
  3168. minLength: 1
  3169. pattern: ^[-._a-zA-Z0-9]+$
  3170. type: string
  3171. name:
  3172. description: The name of the Secret resource being referred to.
  3173. maxLength: 253
  3174. minLength: 1
  3175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3176. type: string
  3177. namespace:
  3178. description: |-
  3179. The namespace of the Secret resource being referred to.
  3180. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3181. maxLength: 63
  3182. minLength: 1
  3183. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3184. type: string
  3185. type: object
  3186. required:
  3187. - secretRef
  3188. type: object
  3189. username:
  3190. description: BarbicanProviderUsernameRef defines a reference to a secret containing username for the Barbican provider.
  3191. maxProperties: 1
  3192. minProperties: 1
  3193. properties:
  3194. secretRef:
  3195. description: |-
  3196. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3197. In some instances, `key` is a required field.
  3198. properties:
  3199. key:
  3200. description: |-
  3201. A key in the referenced Secret.
  3202. Some instances of this field may be defaulted, in others it may be required.
  3203. maxLength: 253
  3204. minLength: 1
  3205. pattern: ^[-._a-zA-Z0-9]+$
  3206. type: string
  3207. name:
  3208. description: The name of the Secret resource being referred to.
  3209. maxLength: 253
  3210. minLength: 1
  3211. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3212. type: string
  3213. namespace:
  3214. description: |-
  3215. The namespace of the Secret resource being referred to.
  3216. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3217. maxLength: 63
  3218. minLength: 1
  3219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3220. type: string
  3221. type: object
  3222. value:
  3223. type: string
  3224. type: object
  3225. required:
  3226. - password
  3227. - username
  3228. type: object
  3229. authURL:
  3230. type: string
  3231. domainName:
  3232. type: string
  3233. region:
  3234. type: string
  3235. tenantName:
  3236. type: string
  3237. required:
  3238. - auth
  3239. type: object
  3240. beyondtrust:
  3241. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  3242. properties:
  3243. auth:
  3244. description: Auth configures how the operator authenticates with Beyondtrust.
  3245. properties:
  3246. apiKey:
  3247. description: APIKey If not provided then ClientID/ClientSecret become required.
  3248. properties:
  3249. secretRef:
  3250. description: SecretRef references a key in a secret that will be used as value.
  3251. properties:
  3252. key:
  3253. description: |-
  3254. A key in the referenced Secret.
  3255. Some instances of this field may be defaulted, in others it may be required.
  3256. maxLength: 253
  3257. minLength: 1
  3258. pattern: ^[-._a-zA-Z0-9]+$
  3259. type: string
  3260. name:
  3261. description: The name of the Secret resource being referred to.
  3262. maxLength: 253
  3263. minLength: 1
  3264. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3265. type: string
  3266. namespace:
  3267. description: |-
  3268. The namespace of the Secret resource being referred to.
  3269. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3270. maxLength: 63
  3271. minLength: 1
  3272. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3273. type: string
  3274. type: object
  3275. value:
  3276. description: Value can be specified directly to set a value without using a secret.
  3277. type: string
  3278. type: object
  3279. certificate:
  3280. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  3281. properties:
  3282. secretRef:
  3283. description: SecretRef references a key in a secret that will be used as value.
  3284. properties:
  3285. key:
  3286. description: |-
  3287. A key in the referenced Secret.
  3288. Some instances of this field may be defaulted, in others it may be required.
  3289. maxLength: 253
  3290. minLength: 1
  3291. pattern: ^[-._a-zA-Z0-9]+$
  3292. type: string
  3293. name:
  3294. description: The name of the Secret resource being referred to.
  3295. maxLength: 253
  3296. minLength: 1
  3297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3298. type: string
  3299. namespace:
  3300. description: |-
  3301. The namespace of the Secret resource being referred to.
  3302. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3303. maxLength: 63
  3304. minLength: 1
  3305. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3306. type: string
  3307. type: object
  3308. value:
  3309. description: Value can be specified directly to set a value without using a secret.
  3310. type: string
  3311. type: object
  3312. certificateKey:
  3313. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  3314. properties:
  3315. secretRef:
  3316. description: SecretRef references a key in a secret that will be used as value.
  3317. properties:
  3318. key:
  3319. description: |-
  3320. A key in the referenced Secret.
  3321. Some instances of this field may be defaulted, in others it may be required.
  3322. maxLength: 253
  3323. minLength: 1
  3324. pattern: ^[-._a-zA-Z0-9]+$
  3325. type: string
  3326. name:
  3327. description: The name of the Secret resource being referred to.
  3328. maxLength: 253
  3329. minLength: 1
  3330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3331. type: string
  3332. namespace:
  3333. description: |-
  3334. The namespace of the Secret resource being referred to.
  3335. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3336. maxLength: 63
  3337. minLength: 1
  3338. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3339. type: string
  3340. type: object
  3341. value:
  3342. description: Value can be specified directly to set a value without using a secret.
  3343. type: string
  3344. type: object
  3345. clientId:
  3346. description: ClientID is the API OAuth Client ID.
  3347. properties:
  3348. secretRef:
  3349. description: SecretRef references a key in a secret that will be used as value.
  3350. properties:
  3351. key:
  3352. description: |-
  3353. A key in the referenced Secret.
  3354. Some instances of this field may be defaulted, in others it may be required.
  3355. maxLength: 253
  3356. minLength: 1
  3357. pattern: ^[-._a-zA-Z0-9]+$
  3358. type: string
  3359. name:
  3360. description: The name of the Secret resource being referred to.
  3361. maxLength: 253
  3362. minLength: 1
  3363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3364. type: string
  3365. namespace:
  3366. description: |-
  3367. The namespace of the Secret resource being referred to.
  3368. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3369. maxLength: 63
  3370. minLength: 1
  3371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3372. type: string
  3373. type: object
  3374. value:
  3375. description: Value can be specified directly to set a value without using a secret.
  3376. type: string
  3377. type: object
  3378. clientSecret:
  3379. description: ClientSecret is the API OAuth Client Secret.
  3380. properties:
  3381. secretRef:
  3382. description: SecretRef references a key in a secret that will be used as value.
  3383. properties:
  3384. key:
  3385. description: |-
  3386. A key in the referenced Secret.
  3387. Some instances of this field may be defaulted, in others it may be required.
  3388. maxLength: 253
  3389. minLength: 1
  3390. pattern: ^[-._a-zA-Z0-9]+$
  3391. type: string
  3392. name:
  3393. description: The name of the Secret resource being referred to.
  3394. maxLength: 253
  3395. minLength: 1
  3396. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3397. type: string
  3398. namespace:
  3399. description: |-
  3400. The namespace of the Secret resource being referred to.
  3401. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3402. maxLength: 63
  3403. minLength: 1
  3404. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3405. type: string
  3406. type: object
  3407. value:
  3408. description: Value can be specified directly to set a value without using a secret.
  3409. type: string
  3410. type: object
  3411. type: object
  3412. server:
  3413. description: Auth configures how API server works.
  3414. properties:
  3415. apiUrl:
  3416. type: string
  3417. apiVersion:
  3418. type: string
  3419. clientTimeOutSeconds:
  3420. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  3421. type: integer
  3422. decrypt:
  3423. default: true
  3424. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  3425. type: boolean
  3426. retrievalType:
  3427. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  3428. type: string
  3429. separator:
  3430. description: A character that separates the folder names.
  3431. type: string
  3432. verifyCA:
  3433. type: boolean
  3434. required:
  3435. - apiUrl
  3436. - verifyCA
  3437. type: object
  3438. required:
  3439. - auth
  3440. - server
  3441. type: object
  3442. beyondtrustworkloadcredentials:
  3443. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  3444. properties:
  3445. auth:
  3446. description: |-
  3447. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  3448. Currently supports API key authentication via Kubernetes secret reference.
  3449. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3450. properties:
  3451. apikey:
  3452. description: |-
  3453. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  3454. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  3455. properties:
  3456. token:
  3457. description: |-
  3458. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  3459. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  3460. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  3461. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3462. properties:
  3463. key:
  3464. description: |-
  3465. A key in the referenced Secret.
  3466. Some instances of this field may be defaulted, in others it may be required.
  3467. maxLength: 253
  3468. minLength: 1
  3469. pattern: ^[-._a-zA-Z0-9]+$
  3470. type: string
  3471. name:
  3472. description: The name of the Secret resource being referred to.
  3473. maxLength: 253
  3474. minLength: 1
  3475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3476. type: string
  3477. namespace:
  3478. description: |-
  3479. The namespace of the Secret resource being referred to.
  3480. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3481. maxLength: 63
  3482. minLength: 1
  3483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3484. type: string
  3485. type: object
  3486. required:
  3487. - token
  3488. type: object
  3489. required:
  3490. - apikey
  3491. type: object
  3492. caBundle:
  3493. description: |-
  3494. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3495. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  3496. If not set, the system's trusted root certificates are used.
  3497. format: byte
  3498. type: string
  3499. caProvider:
  3500. description: |-
  3501. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  3502. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3503. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  3504. properties:
  3505. key:
  3506. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3507. maxLength: 253
  3508. minLength: 1
  3509. pattern: ^[-._a-zA-Z0-9]+$
  3510. type: string
  3511. name:
  3512. description: The name of the object located at the provider type.
  3513. maxLength: 253
  3514. minLength: 1
  3515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3516. type: string
  3517. namespace:
  3518. description: |-
  3519. The namespace the Provider type is in.
  3520. Can only be defined when used in a ClusterSecretStore.
  3521. maxLength: 63
  3522. minLength: 1
  3523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3524. type: string
  3525. type:
  3526. description: The type of provider to use such as "Secret", or "ConfigMap".
  3527. enum:
  3528. - Secret
  3529. - ConfigMap
  3530. type: string
  3531. required:
  3532. - name
  3533. - type
  3534. type: object
  3535. folderPath:
  3536. description: |-
  3537. FolderPath specifies the default folder path for secret retrieval.
  3538. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  3539. Example: "production/database" or "dev/api-keys"
  3540. Leave empty to retrieve secrets from the root folder.
  3541. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  3542. type: string
  3543. server:
  3544. description: |-
  3545. Server configures the BeyondTrust Workload Credentials server connection details.
  3546. Includes the API URL and Site ID for your BeyondTrust instance.
  3547. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3548. properties:
  3549. apiUrl:
  3550. description: |-
  3551. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  3552. This should be the full URL to your BeyondTrust instance.
  3553. Example: https://api.beyondtrust.io/siie
  3554. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  3555. type: string
  3556. siteId:
  3557. description: |-
  3558. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  3559. This identifier is unique to your BeyondTrust Workload Credentials instance.
  3560. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  3561. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  3562. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3563. type: string
  3564. required:
  3565. - apiUrl
  3566. - siteId
  3567. type: object
  3568. required:
  3569. - auth
  3570. - server
  3571. type: object
  3572. bitwardensecretsmanager:
  3573. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  3574. properties:
  3575. apiURL:
  3576. type: string
  3577. auth:
  3578. description: |-
  3579. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  3580. Make sure that the token being used has permissions on the given secret.
  3581. properties:
  3582. secretRef:
  3583. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  3584. properties:
  3585. credentials:
  3586. description: AccessToken used for the bitwarden instance.
  3587. properties:
  3588. key:
  3589. description: |-
  3590. A key in the referenced Secret.
  3591. Some instances of this field may be defaulted, in others it may be required.
  3592. maxLength: 253
  3593. minLength: 1
  3594. pattern: ^[-._a-zA-Z0-9]+$
  3595. type: string
  3596. name:
  3597. description: The name of the Secret resource being referred to.
  3598. maxLength: 253
  3599. minLength: 1
  3600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3601. type: string
  3602. namespace:
  3603. description: |-
  3604. The namespace of the Secret resource being referred to.
  3605. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3606. maxLength: 63
  3607. minLength: 1
  3608. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3609. type: string
  3610. type: object
  3611. required:
  3612. - credentials
  3613. type: object
  3614. required:
  3615. - secretRef
  3616. type: object
  3617. bitwardenServerSDKURL:
  3618. type: string
  3619. caBundle:
  3620. description: |-
  3621. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  3622. can be performed.
  3623. type: string
  3624. caProvider:
  3625. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  3626. properties:
  3627. key:
  3628. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3629. maxLength: 253
  3630. minLength: 1
  3631. pattern: ^[-._a-zA-Z0-9]+$
  3632. type: string
  3633. name:
  3634. description: The name of the object located at the provider type.
  3635. maxLength: 253
  3636. minLength: 1
  3637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3638. type: string
  3639. namespace:
  3640. description: |-
  3641. The namespace the Provider type is in.
  3642. Can only be defined when used in a ClusterSecretStore.
  3643. maxLength: 63
  3644. minLength: 1
  3645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3646. type: string
  3647. type:
  3648. description: The type of provider to use such as "Secret", or "ConfigMap".
  3649. enum:
  3650. - Secret
  3651. - ConfigMap
  3652. type: string
  3653. required:
  3654. - name
  3655. - type
  3656. type: object
  3657. identityURL:
  3658. type: string
  3659. organizationID:
  3660. description: OrganizationID determines which organization this secret store manages.
  3661. type: string
  3662. projectID:
  3663. description: ProjectID determines which project this secret store manages.
  3664. type: string
  3665. required:
  3666. - auth
  3667. - organizationID
  3668. - projectID
  3669. type: object
  3670. chef:
  3671. description: Chef configures this store to sync secrets with chef server
  3672. properties:
  3673. auth:
  3674. description: Auth defines the information necessary to authenticate against chef Server
  3675. properties:
  3676. secretRef:
  3677. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  3678. properties:
  3679. privateKeySecretRef:
  3680. description: SecretKey is the Signing Key in PEM format, used for authentication.
  3681. properties:
  3682. key:
  3683. description: |-
  3684. A key in the referenced Secret.
  3685. Some instances of this field may be defaulted, in others it may be required.
  3686. maxLength: 253
  3687. minLength: 1
  3688. pattern: ^[-._a-zA-Z0-9]+$
  3689. type: string
  3690. name:
  3691. description: The name of the Secret resource being referred to.
  3692. maxLength: 253
  3693. minLength: 1
  3694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3695. type: string
  3696. namespace:
  3697. description: |-
  3698. The namespace of the Secret resource being referred to.
  3699. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3700. maxLength: 63
  3701. minLength: 1
  3702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3703. type: string
  3704. type: object
  3705. required:
  3706. - privateKeySecretRef
  3707. type: object
  3708. required:
  3709. - secretRef
  3710. type: object
  3711. serverUrl:
  3712. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  3713. type: string
  3714. username:
  3715. description: UserName should be the user ID on the chef server
  3716. type: string
  3717. required:
  3718. - auth
  3719. - serverUrl
  3720. - username
  3721. type: object
  3722. cloudrusm:
  3723. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  3724. properties:
  3725. auth:
  3726. description: CSMAuth contains a secretRef for credentials.
  3727. properties:
  3728. secretRef:
  3729. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  3730. properties:
  3731. accessKeyIDSecretRef:
  3732. description: The AccessKeyID is used for authentication
  3733. properties:
  3734. key:
  3735. description: |-
  3736. A key in the referenced Secret.
  3737. Some instances of this field may be defaulted, in others it may be required.
  3738. maxLength: 253
  3739. minLength: 1
  3740. pattern: ^[-._a-zA-Z0-9]+$
  3741. type: string
  3742. name:
  3743. description: The name of the Secret resource being referred to.
  3744. maxLength: 253
  3745. minLength: 1
  3746. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3747. type: string
  3748. namespace:
  3749. description: |-
  3750. The namespace of the Secret resource being referred to.
  3751. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3752. maxLength: 63
  3753. minLength: 1
  3754. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3755. type: string
  3756. type: object
  3757. accessKeySecretSecretRef:
  3758. description: The AccessKeySecret is used for authentication
  3759. properties:
  3760. key:
  3761. description: |-
  3762. A key in the referenced Secret.
  3763. Some instances of this field may be defaulted, in others it may be required.
  3764. maxLength: 253
  3765. minLength: 1
  3766. pattern: ^[-._a-zA-Z0-9]+$
  3767. type: string
  3768. name:
  3769. description: The name of the Secret resource being referred to.
  3770. maxLength: 253
  3771. minLength: 1
  3772. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3773. type: string
  3774. namespace:
  3775. description: |-
  3776. The namespace of the Secret resource being referred to.
  3777. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3778. maxLength: 63
  3779. minLength: 1
  3780. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3781. type: string
  3782. type: object
  3783. required:
  3784. - accessKeyIDSecretRef
  3785. - accessKeySecretSecretRef
  3786. type: object
  3787. type: object
  3788. projectID:
  3789. description: ProjectID is the project, which the secrets are stored in.
  3790. type: string
  3791. required:
  3792. - auth
  3793. type: object
  3794. conjur:
  3795. description: Conjur configures this store to sync secrets using conjur provider
  3796. properties:
  3797. auth:
  3798. description: Defines authentication settings for connecting to Conjur.
  3799. maxProperties: 1
  3800. minProperties: 1
  3801. properties:
  3802. apikey:
  3803. description: Authenticates with Conjur using an API key.
  3804. properties:
  3805. account:
  3806. description: Account is the Conjur organization account name.
  3807. type: string
  3808. apiKeyRef:
  3809. description: |-
  3810. A reference to a specific 'key' containing the Conjur API key
  3811. within a Secret resource. In some instances, `key` is a required field.
  3812. properties:
  3813. key:
  3814. description: |-
  3815. A key in the referenced Secret.
  3816. Some instances of this field may be defaulted, in others it may be required.
  3817. maxLength: 253
  3818. minLength: 1
  3819. pattern: ^[-._a-zA-Z0-9]+$
  3820. type: string
  3821. name:
  3822. description: The name of the Secret resource being referred to.
  3823. maxLength: 253
  3824. minLength: 1
  3825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3826. type: string
  3827. namespace:
  3828. description: |-
  3829. The namespace of the Secret resource being referred to.
  3830. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3831. maxLength: 63
  3832. minLength: 1
  3833. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3834. type: string
  3835. type: object
  3836. userRef:
  3837. description: |-
  3838. A reference to a specific 'key' containing the Conjur username
  3839. within a Secret resource. In some instances, `key` is a required field.
  3840. properties:
  3841. key:
  3842. description: |-
  3843. A key in the referenced Secret.
  3844. Some instances of this field may be defaulted, in others it may be required.
  3845. maxLength: 253
  3846. minLength: 1
  3847. pattern: ^[-._a-zA-Z0-9]+$
  3848. type: string
  3849. name:
  3850. description: The name of the Secret resource being referred to.
  3851. maxLength: 253
  3852. minLength: 1
  3853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3854. type: string
  3855. namespace:
  3856. description: |-
  3857. The namespace of the Secret resource being referred to.
  3858. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3859. maxLength: 63
  3860. minLength: 1
  3861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3862. type: string
  3863. type: object
  3864. required:
  3865. - account
  3866. - apiKeyRef
  3867. - userRef
  3868. type: object
  3869. cert:
  3870. description: Cert enables certificate-based authentication using a client certificate and key.
  3871. properties:
  3872. account:
  3873. description: Account is the Conjur organization account name.
  3874. type: string
  3875. clientCertRef:
  3876. description: |-
  3877. ClientCertRef is a reference to a specific 'key' containing the client certificate
  3878. within a Secret resource. The certificate must be PEM-encoded.
  3879. properties:
  3880. key:
  3881. description: |-
  3882. A key in the referenced Secret.
  3883. Some instances of this field may be defaulted, in others it may be required.
  3884. maxLength: 253
  3885. minLength: 1
  3886. pattern: ^[-._a-zA-Z0-9]+$
  3887. type: string
  3888. name:
  3889. description: The name of the Secret resource being referred to.
  3890. maxLength: 253
  3891. minLength: 1
  3892. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3893. type: string
  3894. namespace:
  3895. description: |-
  3896. The namespace of the Secret resource being referred to.
  3897. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3898. maxLength: 63
  3899. minLength: 1
  3900. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3901. type: string
  3902. type: object
  3903. clientKeyRef:
  3904. description: |-
  3905. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  3906. within a Secret resource. The key must be PEM-encoded.
  3907. properties:
  3908. key:
  3909. description: |-
  3910. A key in the referenced Secret.
  3911. Some instances of this field may be defaulted, in others it may be required.
  3912. maxLength: 253
  3913. minLength: 1
  3914. pattern: ^[-._a-zA-Z0-9]+$
  3915. type: string
  3916. name:
  3917. description: The name of the Secret resource being referred to.
  3918. maxLength: 253
  3919. minLength: 1
  3920. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3921. type: string
  3922. namespace:
  3923. description: |-
  3924. The namespace of the Secret resource being referred to.
  3925. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3926. maxLength: 63
  3927. minLength: 1
  3928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3929. type: string
  3930. type: object
  3931. hostId:
  3932. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  3933. type: string
  3934. serviceID:
  3935. description: The conjur authn cert webservice id
  3936. type: string
  3937. required:
  3938. - account
  3939. - clientCertRef
  3940. - clientKeyRef
  3941. - serviceID
  3942. type: object
  3943. jwt:
  3944. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  3945. properties:
  3946. account:
  3947. description: Account is the Conjur organization account name.
  3948. type: string
  3949. hostId:
  3950. description: |-
  3951. Optional HostID for JWT authentication. This may be used depending
  3952. on how the Conjur JWT authenticator policy is configured.
  3953. type: string
  3954. secretRef:
  3955. description: |-
  3956. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  3957. authenticate with Conjur using the JWT authentication method.
  3958. properties:
  3959. key:
  3960. description: |-
  3961. A key in the referenced Secret.
  3962. Some instances of this field may be defaulted, in others it may be required.
  3963. maxLength: 253
  3964. minLength: 1
  3965. pattern: ^[-._a-zA-Z0-9]+$
  3966. type: string
  3967. name:
  3968. description: The name of the Secret resource being referred to.
  3969. maxLength: 253
  3970. minLength: 1
  3971. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3972. type: string
  3973. namespace:
  3974. description: |-
  3975. The namespace of the Secret resource being referred to.
  3976. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3977. maxLength: 63
  3978. minLength: 1
  3979. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3980. type: string
  3981. type: object
  3982. serviceAccountRef:
  3983. description: |-
  3984. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  3985. a token for with the `TokenRequest` API.
  3986. properties:
  3987. audiences:
  3988. description: |-
  3989. Audience specifies the `aud` claim for the service account token
  3990. Some providers automatically extend the audience field based on well-known annotations for workload
  3991. identity (e.g. IRSA or GCP Workload Identity)
  3992. items:
  3993. type: string
  3994. type: array
  3995. name:
  3996. description: The name of the ServiceAccount resource being referred to.
  3997. maxLength: 253
  3998. minLength: 1
  3999. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4000. type: string
  4001. namespace:
  4002. description: |-
  4003. Namespace of the resource being referred to.
  4004. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4005. maxLength: 63
  4006. minLength: 1
  4007. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4008. type: string
  4009. required:
  4010. - name
  4011. type: object
  4012. serviceID:
  4013. description: The conjur authn jwt webservice id
  4014. type: string
  4015. required:
  4016. - account
  4017. - serviceID
  4018. type: object
  4019. type: object
  4020. caBundle:
  4021. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  4022. type: string
  4023. caProvider:
  4024. description: |-
  4025. Used to provide custom certificate authority (CA) certificates
  4026. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  4027. that contains a PEM-encoded certificate.
  4028. properties:
  4029. key:
  4030. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4031. maxLength: 253
  4032. minLength: 1
  4033. pattern: ^[-._a-zA-Z0-9]+$
  4034. type: string
  4035. name:
  4036. description: The name of the object located at the provider type.
  4037. maxLength: 253
  4038. minLength: 1
  4039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4040. type: string
  4041. namespace:
  4042. description: |-
  4043. The namespace the Provider type is in.
  4044. Can only be defined when used in a ClusterSecretStore.
  4045. maxLength: 63
  4046. minLength: 1
  4047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4048. type: string
  4049. type:
  4050. description: The type of provider to use such as "Secret", or "ConfigMap".
  4051. enum:
  4052. - Secret
  4053. - ConfigMap
  4054. type: string
  4055. required:
  4056. - name
  4057. - type
  4058. type: object
  4059. url:
  4060. description: URL is the endpoint of the Conjur instance.
  4061. type: string
  4062. required:
  4063. - auth
  4064. - url
  4065. type: object
  4066. crd:
  4067. description: |-
  4068. CRD configures this store to sync secrets from arbitrary Kubernetes resources,
  4069. including both custom resources (CRDs) and core API resources. Resources are
  4070. selected by API group, version and kind, where group can be "" (empty string)
  4071. for core resources such as ConfigMap. Reading the core v1 Secret is
  4072. intentionally blocked — use the Kubernetes provider for that.
  4073. properties:
  4074. auth:
  4075. description: |-
  4076. Auth configures authentication to the Kubernetes API, same as the
  4077. Kubernetes provider. Required when Server.URL is set (unless using AuthRef).
  4078. maxProperties: 1
  4079. minProperties: 1
  4080. properties:
  4081. cert:
  4082. description: has both clientCert and clientKey as secretKeySelector
  4083. properties:
  4084. clientCert:
  4085. description: |-
  4086. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4087. In some instances, `key` is a required field.
  4088. properties:
  4089. key:
  4090. description: |-
  4091. A key in the referenced Secret.
  4092. Some instances of this field may be defaulted, in others it may be required.
  4093. maxLength: 253
  4094. minLength: 1
  4095. pattern: ^[-._a-zA-Z0-9]+$
  4096. type: string
  4097. name:
  4098. description: The name of the Secret resource being referred to.
  4099. maxLength: 253
  4100. minLength: 1
  4101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4102. type: string
  4103. namespace:
  4104. description: |-
  4105. The namespace of the Secret resource being referred to.
  4106. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4107. maxLength: 63
  4108. minLength: 1
  4109. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4110. type: string
  4111. type: object
  4112. clientKey:
  4113. description: |-
  4114. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4115. In some instances, `key` is a required field.
  4116. properties:
  4117. key:
  4118. description: |-
  4119. A key in the referenced Secret.
  4120. Some instances of this field may be defaulted, in others it may be required.
  4121. maxLength: 253
  4122. minLength: 1
  4123. pattern: ^[-._a-zA-Z0-9]+$
  4124. type: string
  4125. name:
  4126. description: The name of the Secret resource being referred to.
  4127. maxLength: 253
  4128. minLength: 1
  4129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4130. type: string
  4131. namespace:
  4132. description: |-
  4133. The namespace of the Secret resource being referred to.
  4134. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4135. maxLength: 63
  4136. minLength: 1
  4137. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4138. type: string
  4139. type: object
  4140. required:
  4141. - clientCert
  4142. - clientKey
  4143. type: object
  4144. serviceAccount:
  4145. description: points to a service account that should be used for authentication
  4146. properties:
  4147. audiences:
  4148. description: |-
  4149. Audience specifies the `aud` claim for the service account token
  4150. Some providers automatically extend the audience field based on well-known annotations for workload
  4151. identity (e.g. IRSA or GCP Workload Identity)
  4152. items:
  4153. type: string
  4154. type: array
  4155. name:
  4156. description: The name of the ServiceAccount resource being referred to.
  4157. maxLength: 253
  4158. minLength: 1
  4159. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4160. type: string
  4161. namespace:
  4162. description: |-
  4163. Namespace of the resource being referred to.
  4164. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4165. maxLength: 63
  4166. minLength: 1
  4167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4168. type: string
  4169. required:
  4170. - name
  4171. type: object
  4172. token:
  4173. description: use static token to authenticate with
  4174. properties:
  4175. bearerToken:
  4176. description: |-
  4177. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4178. In some instances, `key` is a required field.
  4179. properties:
  4180. key:
  4181. description: |-
  4182. A key in the referenced Secret.
  4183. Some instances of this field may be defaulted, in others it may be required.
  4184. maxLength: 253
  4185. minLength: 1
  4186. pattern: ^[-._a-zA-Z0-9]+$
  4187. type: string
  4188. name:
  4189. description: The name of the Secret resource being referred to.
  4190. maxLength: 253
  4191. minLength: 1
  4192. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4193. type: string
  4194. namespace:
  4195. description: |-
  4196. The namespace of the Secret resource being referred to.
  4197. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4198. maxLength: 63
  4199. minLength: 1
  4200. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4201. type: string
  4202. type: object
  4203. required:
  4204. - bearerToken
  4205. type: object
  4206. type: object
  4207. authRef:
  4208. description: |-
  4209. AuthRef references a Secret containing a kubeconfig. Same semantics as the
  4210. Kubernetes provider.
  4211. properties:
  4212. key:
  4213. description: |-
  4214. A key in the referenced Secret.
  4215. Some instances of this field may be defaulted, in others it may be required.
  4216. maxLength: 253
  4217. minLength: 1
  4218. pattern: ^[-._a-zA-Z0-9]+$
  4219. type: string
  4220. name:
  4221. description: The name of the Secret resource being referred to.
  4222. maxLength: 253
  4223. minLength: 1
  4224. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4225. type: string
  4226. namespace:
  4227. description: |-
  4228. The namespace of the Secret resource being referred to.
  4229. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4230. maxLength: 63
  4231. minLength: 1
  4232. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4233. type: string
  4234. type: object
  4235. resource:
  4236. description: Resource identifies the CRD by its API group, version and kind.
  4237. properties:
  4238. group:
  4239. description: |-
  4240. Group is the API group of the resource. Use "" (empty string) for core
  4241. Kubernetes resources such as ConfigMap; use e.g. "config.example.io"
  4242. for a CRD. The field is required to be present in the manifest — write
  4243. `group: ""` explicitly for core resources so typos fail at admission
  4244. time rather than later at discovery.
  4245. type: string
  4246. kind:
  4247. description: Kind is the Kubernetes resource kind (e.g. "MyCustomResource").
  4248. minLength: 1
  4249. type: string
  4250. version:
  4251. description: Version is the API version of the resource (e.g. "v1alpha1").
  4252. minLength: 1
  4253. type: string
  4254. required:
  4255. - group
  4256. - kind
  4257. - version
  4258. type: object
  4259. server:
  4260. description: |-
  4261. Server configures the Kubernetes API address and TLS trust, same as the
  4262. Kubernetes provider. When omitted, the URL defaults to the in-cluster API.
  4263. properties:
  4264. caBundle:
  4265. description: CABundle is a base64-encoded CA certificate
  4266. format: byte
  4267. type: string
  4268. caProvider:
  4269. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  4270. properties:
  4271. key:
  4272. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4273. maxLength: 253
  4274. minLength: 1
  4275. pattern: ^[-._a-zA-Z0-9]+$
  4276. type: string
  4277. name:
  4278. description: The name of the object located at the provider type.
  4279. maxLength: 253
  4280. minLength: 1
  4281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4282. type: string
  4283. namespace:
  4284. description: |-
  4285. The namespace the Provider type is in.
  4286. Can only be defined when used in a ClusterSecretStore.
  4287. maxLength: 63
  4288. minLength: 1
  4289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4290. type: string
  4291. type:
  4292. description: The type of provider to use such as "Secret", or "ConfigMap".
  4293. enum:
  4294. - Secret
  4295. - ConfigMap
  4296. type: string
  4297. required:
  4298. - name
  4299. - type
  4300. type: object
  4301. url:
  4302. default: kubernetes.default
  4303. description: configures the Kubernetes server Address.
  4304. type: string
  4305. type: object
  4306. whitelist:
  4307. description: |-
  4308. Whitelist optionally restricts which object names and requested properties
  4309. are allowed to be read.
  4310. properties:
  4311. rules:
  4312. description: |-
  4313. Rules is a list of allow rules. If rules are set, at least one rule must
  4314. match for a request to be allowed.
  4315. items:
  4316. description: CRDProviderWhitelistRule defines a single allow rule for CRD reads.
  4317. properties:
  4318. name:
  4319. description: |-
  4320. Name is an optional regular expression matched against the bare object name.
  4321. For both SecretStore and ClusterSecretStore this is always the object name
  4322. without any namespace prefix (e.g. "my-db-spec", not "prod/my-db-spec").
  4323. type: string
  4324. namespace:
  4325. description: |-
  4326. Namespace is an optional regular expression matched against the namespace of
  4327. the object. Applies only when a ClusterSecretStore is used; it is ignored
  4328. for SecretStore (where the namespace is fixed to the store namespace).
  4329. type: string
  4330. properties:
  4331. description: |-
  4332. Properties is an optional list of regular expressions matched against
  4333. requested property keys (for example: "spec.secretValue").
  4334. items:
  4335. type: string
  4336. type: array
  4337. type: object
  4338. type: array
  4339. type: object
  4340. required:
  4341. - resource
  4342. type: object
  4343. x-kubernetes-validations:
  4344. - message: one of auth or authRef is required
  4345. rule: has(self.auth) || has(self.authRef)
  4346. - message: at most one of the fields in [auth authRef] may be set
  4347. rule: '[has(self.auth),has(self.authRef)].filter(x,x==true).size() <= 1'
  4348. delinea:
  4349. description: |-
  4350. Delinea DevOps Secrets Vault
  4351. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  4352. properties:
  4353. clientId:
  4354. description: ClientID is the non-secret part of the credential.
  4355. properties:
  4356. secretRef:
  4357. description: SecretRef references a key in a secret that will be used as value.
  4358. properties:
  4359. key:
  4360. description: |-
  4361. A key in the referenced Secret.
  4362. Some instances of this field may be defaulted, in others it may be required.
  4363. maxLength: 253
  4364. minLength: 1
  4365. pattern: ^[-._a-zA-Z0-9]+$
  4366. type: string
  4367. name:
  4368. description: The name of the Secret resource being referred to.
  4369. maxLength: 253
  4370. minLength: 1
  4371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4372. type: string
  4373. namespace:
  4374. description: |-
  4375. The namespace of the Secret resource being referred to.
  4376. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4377. maxLength: 63
  4378. minLength: 1
  4379. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4380. type: string
  4381. type: object
  4382. value:
  4383. description: Value can be specified directly to set a value without using a secret.
  4384. type: string
  4385. type: object
  4386. clientSecret:
  4387. description: ClientSecret is the secret part of the credential.
  4388. properties:
  4389. secretRef:
  4390. description: SecretRef references a key in a secret that will be used as value.
  4391. properties:
  4392. key:
  4393. description: |-
  4394. A key in the referenced Secret.
  4395. Some instances of this field may be defaulted, in others it may be required.
  4396. maxLength: 253
  4397. minLength: 1
  4398. pattern: ^[-._a-zA-Z0-9]+$
  4399. type: string
  4400. name:
  4401. description: The name of the Secret resource being referred to.
  4402. maxLength: 253
  4403. minLength: 1
  4404. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4405. type: string
  4406. namespace:
  4407. description: |-
  4408. The namespace of the Secret resource being referred to.
  4409. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4410. maxLength: 63
  4411. minLength: 1
  4412. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4413. type: string
  4414. type: object
  4415. value:
  4416. description: Value can be specified directly to set a value without using a secret.
  4417. type: string
  4418. type: object
  4419. tenant:
  4420. description: Tenant is the chosen hostname / site name.
  4421. type: string
  4422. tld:
  4423. description: |-
  4424. TLD is based on the server location that was chosen during provisioning.
  4425. If unset, defaults to "com".
  4426. type: string
  4427. urlTemplate:
  4428. description: |-
  4429. URLTemplate
  4430. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  4431. type: string
  4432. required:
  4433. - clientId
  4434. - clientSecret
  4435. - tenant
  4436. type: object
  4437. doppler:
  4438. description: Doppler configures this store to sync secrets using the Doppler provider
  4439. properties:
  4440. auth:
  4441. description: Auth configures how the Operator authenticates with the Doppler API
  4442. properties:
  4443. oidcConfig:
  4444. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  4445. properties:
  4446. expirationSeconds:
  4447. default: 600
  4448. description: |-
  4449. ExpirationSeconds sets the ServiceAccount token validity duration.
  4450. Defaults to 10 minutes.
  4451. format: int64
  4452. type: integer
  4453. identity:
  4454. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  4455. type: string
  4456. serviceAccountRef:
  4457. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  4458. properties:
  4459. audiences:
  4460. description: |-
  4461. Audience specifies the `aud` claim for the service account token
  4462. Some providers automatically extend the audience field based on well-known annotations for workload
  4463. identity (e.g. IRSA or GCP Workload Identity)
  4464. items:
  4465. type: string
  4466. type: array
  4467. name:
  4468. description: The name of the ServiceAccount resource being referred to.
  4469. maxLength: 253
  4470. minLength: 1
  4471. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4472. type: string
  4473. namespace:
  4474. description: |-
  4475. Namespace of the resource being referred to.
  4476. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4477. maxLength: 63
  4478. minLength: 1
  4479. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4480. type: string
  4481. required:
  4482. - name
  4483. type: object
  4484. required:
  4485. - identity
  4486. - serviceAccountRef
  4487. type: object
  4488. secretRef:
  4489. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  4490. properties:
  4491. dopplerToken:
  4492. description: |-
  4493. The DopplerToken is used for authentication.
  4494. See https://docs.doppler.com/reference/api#authentication for auth token types.
  4495. The Key attribute defaults to dopplerToken if not specified.
  4496. properties:
  4497. key:
  4498. description: |-
  4499. A key in the referenced Secret.
  4500. Some instances of this field may be defaulted, in others it may be required.
  4501. maxLength: 253
  4502. minLength: 1
  4503. pattern: ^[-._a-zA-Z0-9]+$
  4504. type: string
  4505. name:
  4506. description: The name of the Secret resource being referred to.
  4507. maxLength: 253
  4508. minLength: 1
  4509. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4510. type: string
  4511. namespace:
  4512. description: |-
  4513. The namespace of the Secret resource being referred to.
  4514. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4515. maxLength: 63
  4516. minLength: 1
  4517. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4518. type: string
  4519. type: object
  4520. required:
  4521. - dopplerToken
  4522. type: object
  4523. type: object
  4524. x-kubernetes-validations:
  4525. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  4526. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  4527. config:
  4528. description: Doppler config (required if not using a Service Token)
  4529. type: string
  4530. format:
  4531. description: Format enables the downloading of secrets as a file (string)
  4532. enum:
  4533. - json
  4534. - dotnet-json
  4535. - env
  4536. - yaml
  4537. - docker
  4538. type: string
  4539. nameTransformer:
  4540. description: Environment variable compatible name transforms that change secret names to a different format
  4541. enum:
  4542. - upper-camel
  4543. - camel
  4544. - lower-snake
  4545. - tf-var
  4546. - dotnet-env
  4547. - lower-kebab
  4548. type: string
  4549. project:
  4550. description: Doppler project (required if not using a Service Token)
  4551. type: string
  4552. required:
  4553. - auth
  4554. type: object
  4555. dvls:
  4556. description: DVLS configures this store to sync secrets using Devolutions Server provider
  4557. properties:
  4558. auth:
  4559. description: Auth defines the authentication method to use.
  4560. properties:
  4561. secretRef:
  4562. description: SecretRef contains the Application ID and Application Secret for authentication.
  4563. properties:
  4564. appId:
  4565. description: AppID is the reference to the secret containing the Application ID.
  4566. properties:
  4567. key:
  4568. description: |-
  4569. A key in the referenced Secret.
  4570. Some instances of this field may be defaulted, in others it may be required.
  4571. maxLength: 253
  4572. minLength: 1
  4573. pattern: ^[-._a-zA-Z0-9]+$
  4574. type: string
  4575. name:
  4576. description: The name of the Secret resource being referred to.
  4577. maxLength: 253
  4578. minLength: 1
  4579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4580. type: string
  4581. namespace:
  4582. description: |-
  4583. The namespace of the Secret resource being referred to.
  4584. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4585. maxLength: 63
  4586. minLength: 1
  4587. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4588. type: string
  4589. type: object
  4590. appSecret:
  4591. description: AppSecret is the reference to the secret containing the Application Secret.
  4592. properties:
  4593. key:
  4594. description: |-
  4595. A key in the referenced Secret.
  4596. Some instances of this field may be defaulted, in others it may be required.
  4597. maxLength: 253
  4598. minLength: 1
  4599. pattern: ^[-._a-zA-Z0-9]+$
  4600. type: string
  4601. name:
  4602. description: The name of the Secret resource being referred to.
  4603. maxLength: 253
  4604. minLength: 1
  4605. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4606. type: string
  4607. namespace:
  4608. description: |-
  4609. The namespace of the Secret resource being referred to.
  4610. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4611. maxLength: 63
  4612. minLength: 1
  4613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4614. type: string
  4615. type: object
  4616. required:
  4617. - appId
  4618. - appSecret
  4619. type: object
  4620. required:
  4621. - secretRef
  4622. type: object
  4623. insecure:
  4624. description: |-
  4625. Insecure allows connecting to DVLS over plain HTTP.
  4626. This is NOT RECOMMENDED for production use.
  4627. Set to true only if you understand the security implications.
  4628. type: boolean
  4629. serverUrl:
  4630. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  4631. type: string
  4632. vault:
  4633. description: |-
  4634. Vault is the name or UUID of the vault to fetch secrets from.
  4635. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  4636. type: string
  4637. required:
  4638. - auth
  4639. - serverUrl
  4640. type: object
  4641. fake:
  4642. description: Fake configures a store with static key/value pairs
  4643. properties:
  4644. data:
  4645. items:
  4646. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  4647. properties:
  4648. key:
  4649. type: string
  4650. value:
  4651. type: string
  4652. version:
  4653. type: string
  4654. required:
  4655. - key
  4656. - value
  4657. type: object
  4658. type: array
  4659. validationResult:
  4660. description: ValidationResult is defined type for the number of validation results.
  4661. type: integer
  4662. required:
  4663. - data
  4664. type: object
  4665. fortanix:
  4666. description: Fortanix configures this store to sync secrets using the Fortanix provider
  4667. properties:
  4668. apiKey:
  4669. description: APIKey is the API token to access SDKMS Applications.
  4670. properties:
  4671. secretRef:
  4672. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  4673. properties:
  4674. key:
  4675. description: |-
  4676. A key in the referenced Secret.
  4677. Some instances of this field may be defaulted, in others it may be required.
  4678. maxLength: 253
  4679. minLength: 1
  4680. pattern: ^[-._a-zA-Z0-9]+$
  4681. type: string
  4682. name:
  4683. description: The name of the Secret resource being referred to.
  4684. maxLength: 253
  4685. minLength: 1
  4686. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4687. type: string
  4688. namespace:
  4689. description: |-
  4690. The namespace of the Secret resource being referred to.
  4691. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4692. maxLength: 63
  4693. minLength: 1
  4694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4695. type: string
  4696. type: object
  4697. type: object
  4698. apiUrl:
  4699. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  4700. type: string
  4701. type: object
  4702. gcpsm:
  4703. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  4704. properties:
  4705. auth:
  4706. description: Auth defines the information necessary to authenticate against GCP
  4707. properties:
  4708. secretRef:
  4709. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  4710. properties:
  4711. secretAccessKeySecretRef:
  4712. description: The SecretAccessKey is used for authentication
  4713. properties:
  4714. key:
  4715. description: |-
  4716. A key in the referenced Secret.
  4717. Some instances of this field may be defaulted, in others it may be required.
  4718. maxLength: 253
  4719. minLength: 1
  4720. pattern: ^[-._a-zA-Z0-9]+$
  4721. type: string
  4722. name:
  4723. description: The name of the Secret resource being referred to.
  4724. maxLength: 253
  4725. minLength: 1
  4726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4727. type: string
  4728. namespace:
  4729. description: |-
  4730. The namespace of the Secret resource being referred to.
  4731. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4732. maxLength: 63
  4733. minLength: 1
  4734. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4735. type: string
  4736. type: object
  4737. type: object
  4738. workloadIdentity:
  4739. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  4740. properties:
  4741. clusterLocation:
  4742. description: |-
  4743. ClusterLocation is the location of the cluster
  4744. If not specified, it fetches information from the metadata server
  4745. type: string
  4746. clusterName:
  4747. description: |-
  4748. ClusterName is the name of the cluster
  4749. If not specified, it fetches information from the metadata server
  4750. type: string
  4751. clusterProjectID:
  4752. description: |-
  4753. ClusterProjectID is the project ID of the cluster
  4754. If not specified, it fetches information from the metadata server
  4755. type: string
  4756. serviceAccountRef:
  4757. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  4758. properties:
  4759. audiences:
  4760. description: |-
  4761. Audience specifies the `aud` claim for the service account token
  4762. Some providers automatically extend the audience field based on well-known annotations for workload
  4763. identity (e.g. IRSA or GCP Workload Identity)
  4764. items:
  4765. type: string
  4766. type: array
  4767. name:
  4768. description: The name of the ServiceAccount resource being referred to.
  4769. maxLength: 253
  4770. minLength: 1
  4771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4772. type: string
  4773. namespace:
  4774. description: |-
  4775. Namespace of the resource being referred to.
  4776. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4777. maxLength: 63
  4778. minLength: 1
  4779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4780. type: string
  4781. required:
  4782. - name
  4783. type: object
  4784. required:
  4785. - serviceAccountRef
  4786. type: object
  4787. workloadIdentityFederation:
  4788. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  4789. properties:
  4790. audience:
  4791. description: |-
  4792. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  4793. If specified, Audience found in the external account credential config will be overridden with the configured value.
  4794. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  4795. type: string
  4796. awsSecurityCredentials:
  4797. description: |-
  4798. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  4799. when using the AWS metadata server is not an option.
  4800. properties:
  4801. awsCredentialsSecretRef:
  4802. description: |-
  4803. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  4804. Secret should be created with below names for keys
  4805. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  4806. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  4807. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  4808. properties:
  4809. name:
  4810. description: name of the secret.
  4811. maxLength: 253
  4812. minLength: 1
  4813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4814. type: string
  4815. namespace:
  4816. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  4817. maxLength: 63
  4818. minLength: 1
  4819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4820. type: string
  4821. required:
  4822. - name
  4823. type: object
  4824. region:
  4825. description: region is for configuring the AWS region to be used.
  4826. example: ap-south-1
  4827. maxLength: 50
  4828. minLength: 1
  4829. pattern: ^[a-z0-9-]+$
  4830. type: string
  4831. required:
  4832. - awsCredentialsSecretRef
  4833. - region
  4834. type: object
  4835. credConfig:
  4836. description: |-
  4837. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  4838. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  4839. serviceAccountRef must be used by providing operators service account details.
  4840. properties:
  4841. key:
  4842. description: key name holding the external account credential config.
  4843. maxLength: 253
  4844. minLength: 1
  4845. pattern: ^[-._a-zA-Z0-9]+$
  4846. type: string
  4847. name:
  4848. description: name of the configmap.
  4849. maxLength: 253
  4850. minLength: 1
  4851. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4852. type: string
  4853. namespace:
  4854. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  4855. maxLength: 63
  4856. minLength: 1
  4857. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4858. type: string
  4859. required:
  4860. - key
  4861. - name
  4862. type: object
  4863. externalTokenEndpoint:
  4864. description: |-
  4865. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  4866. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  4867. URL is having the expected value.
  4868. type: string
  4869. gcpServiceAccountEmail:
  4870. description: |-
  4871. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  4872. after Workload Identity Federation. Use this to grant access through the service account's
  4873. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  4874. service_account_impersonation_url in the external account JSON from credConfig;
  4875. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  4876. on that ServiceAccount.
  4877. example: my-gsa@my-project.iam.gserviceaccount.com
  4878. minLength: 1
  4879. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  4880. type: string
  4881. serviceAccountRef:
  4882. description: |-
  4883. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  4884. when Kubernetes is configured as provider in workload identity pool.
  4885. properties:
  4886. audiences:
  4887. description: |-
  4888. Audience specifies the `aud` claim for the service account token
  4889. Some providers automatically extend the audience field based on well-known annotations for workload
  4890. identity (e.g. IRSA or GCP Workload Identity)
  4891. items:
  4892. type: string
  4893. type: array
  4894. name:
  4895. description: The name of the ServiceAccount resource being referred to.
  4896. maxLength: 253
  4897. minLength: 1
  4898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4899. type: string
  4900. namespace:
  4901. description: |-
  4902. Namespace of the resource being referred to.
  4903. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4904. maxLength: 63
  4905. minLength: 1
  4906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4907. type: string
  4908. required:
  4909. - name
  4910. type: object
  4911. type: object
  4912. type: object
  4913. location:
  4914. description: Location optionally defines a location for a secret
  4915. type: string
  4916. projectID:
  4917. description: ProjectID project where secret is located
  4918. type: string
  4919. secretVersionSelectionPolicy:
  4920. default: LatestOrFail
  4921. description: |-
  4922. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  4923. when "latest" is disabled or destroyed.
  4924. Possible values are:
  4925. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  4926. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  4927. type: string
  4928. type: object
  4929. github:
  4930. description: |-
  4931. Github configures this store to push GitHub Actions or Dependabot secrets using the GitHub API provider.
  4932. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  4933. properties:
  4934. appID:
  4935. description: appID specifies the Github APP that will be used to authenticate the client
  4936. format: int64
  4937. type: integer
  4938. auth:
  4939. description: auth configures how secret-manager authenticates with a Github instance.
  4940. properties:
  4941. privateKey:
  4942. description: |-
  4943. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4944. In some instances, `key` is a required field.
  4945. properties:
  4946. key:
  4947. description: |-
  4948. A key in the referenced Secret.
  4949. Some instances of this field may be defaulted, in others it may be required.
  4950. maxLength: 253
  4951. minLength: 1
  4952. pattern: ^[-._a-zA-Z0-9]+$
  4953. type: string
  4954. name:
  4955. description: The name of the Secret resource being referred to.
  4956. maxLength: 253
  4957. minLength: 1
  4958. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4959. type: string
  4960. namespace:
  4961. description: |-
  4962. The namespace of the Secret resource being referred to.
  4963. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4964. maxLength: 63
  4965. minLength: 1
  4966. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4967. type: string
  4968. type: object
  4969. required:
  4970. - privateKey
  4971. type: object
  4972. environment:
  4973. description: environment will be used to fetch secrets from a particular environment within a github repository
  4974. type: string
  4975. installationID:
  4976. description: installationID specifies the Github APP installation that will be used to authenticate the client
  4977. format: int64
  4978. type: integer
  4979. orgSecretVisibility:
  4980. description: |-
  4981. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  4982. Valid values are "all" or "private".
  4983. When unset, new secrets are created with visibility "all" and existing secrets preserve
  4984. whatever visibility they already have in GitHub.
  4985. enum:
  4986. - all
  4987. - private
  4988. type: string
  4989. organization:
  4990. description: organization will be used to fetch secrets from the Github organization
  4991. type: string
  4992. repository:
  4993. description: repository will be used to fetch secrets from the Github repository within an organization
  4994. type: string
  4995. secretType:
  4996. default: Actions
  4997. description: |-
  4998. secretType specifies which GitHub secret service to use.
  4999. Defaults to Actions for backwards compatibility.
  5000. enum:
  5001. - Actions
  5002. - Dependabot
  5003. type: string
  5004. uploadURL:
  5005. description: Upload URL for enterprise instances. Default to URL.
  5006. type: string
  5007. url:
  5008. default: https://github.com/
  5009. description: URL configures the Github instance URL. Defaults to https://github.com/.
  5010. type: string
  5011. required:
  5012. - appID
  5013. - auth
  5014. - installationID
  5015. - organization
  5016. type: object
  5017. x-kubernetes-validations:
  5018. - message: Dependabot secrets do not support environments
  5019. rule: self.secretType != 'Dependabot' || !has(self.environment) || size(self.environment) == 0
  5020. gitlab:
  5021. description: GitLab configures this store to sync secrets using GitLab Variables provider
  5022. properties:
  5023. auth:
  5024. description: Auth configures how secret-manager authenticates with a GitLab instance.
  5025. properties:
  5026. SecretRef:
  5027. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  5028. properties:
  5029. accessToken:
  5030. description: AccessToken is used for authentication.
  5031. properties:
  5032. key:
  5033. description: |-
  5034. A key in the referenced Secret.
  5035. Some instances of this field may be defaulted, in others it may be required.
  5036. maxLength: 253
  5037. minLength: 1
  5038. pattern: ^[-._a-zA-Z0-9]+$
  5039. type: string
  5040. name:
  5041. description: The name of the Secret resource being referred to.
  5042. maxLength: 253
  5043. minLength: 1
  5044. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5045. type: string
  5046. namespace:
  5047. description: |-
  5048. The namespace of the Secret resource being referred to.
  5049. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5050. maxLength: 63
  5051. minLength: 1
  5052. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5053. type: string
  5054. type: object
  5055. type: object
  5056. required:
  5057. - SecretRef
  5058. type: object
  5059. caBundle:
  5060. description: |-
  5061. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  5062. can be performed.
  5063. format: byte
  5064. type: string
  5065. caProvider:
  5066. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  5067. properties:
  5068. key:
  5069. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5070. maxLength: 253
  5071. minLength: 1
  5072. pattern: ^[-._a-zA-Z0-9]+$
  5073. type: string
  5074. name:
  5075. description: The name of the object located at the provider type.
  5076. maxLength: 253
  5077. minLength: 1
  5078. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5079. type: string
  5080. namespace:
  5081. description: |-
  5082. The namespace the Provider type is in.
  5083. Can only be defined when used in a ClusterSecretStore.
  5084. maxLength: 63
  5085. minLength: 1
  5086. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5087. type: string
  5088. type:
  5089. description: The type of provider to use such as "Secret", or "ConfigMap".
  5090. enum:
  5091. - Secret
  5092. - ConfigMap
  5093. type: string
  5094. required:
  5095. - name
  5096. - type
  5097. type: object
  5098. environment:
  5099. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  5100. type: string
  5101. groupIDs:
  5102. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  5103. items:
  5104. type: string
  5105. type: array
  5106. inheritFromGroups:
  5107. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  5108. type: boolean
  5109. projectID:
  5110. description: ProjectID specifies a project where secrets are located.
  5111. type: string
  5112. url:
  5113. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  5114. type: string
  5115. required:
  5116. - auth
  5117. type: object
  5118. ibm:
  5119. description: IBM configures this store to sync secrets using IBM Cloud provider
  5120. properties:
  5121. auth:
  5122. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  5123. maxProperties: 1
  5124. minProperties: 1
  5125. properties:
  5126. containerAuth:
  5127. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  5128. properties:
  5129. iamEndpoint:
  5130. type: string
  5131. profile:
  5132. description: the IBM Trusted Profile
  5133. type: string
  5134. tokenLocation:
  5135. description: Location the token is mounted on the pod
  5136. type: string
  5137. required:
  5138. - profile
  5139. type: object
  5140. secretRef:
  5141. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  5142. properties:
  5143. iamEndpoint:
  5144. description: The IAM endpoint used to obain a token
  5145. type: string
  5146. secretApiKeySecretRef:
  5147. description: The SecretAccessKey is used for authentication
  5148. properties:
  5149. key:
  5150. description: |-
  5151. A key in the referenced Secret.
  5152. Some instances of this field may be defaulted, in others it may be required.
  5153. maxLength: 253
  5154. minLength: 1
  5155. pattern: ^[-._a-zA-Z0-9]+$
  5156. type: string
  5157. name:
  5158. description: The name of the Secret resource being referred to.
  5159. maxLength: 253
  5160. minLength: 1
  5161. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5162. type: string
  5163. namespace:
  5164. description: |-
  5165. The namespace of the Secret resource being referred to.
  5166. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5167. maxLength: 63
  5168. minLength: 1
  5169. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5170. type: string
  5171. type: object
  5172. type: object
  5173. type: object
  5174. serviceUrl:
  5175. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  5176. type: string
  5177. required:
  5178. - auth
  5179. type: object
  5180. infisical:
  5181. description: Infisical configures this store to sync secrets using the Infisical provider
  5182. properties:
  5183. auth:
  5184. description: Auth configures how the Operator authenticates with the Infisical API
  5185. properties:
  5186. awsAuthCredentials:
  5187. description: AwsAuthCredentials represents the credentials for AWS authentication.
  5188. properties:
  5189. identityId:
  5190. description: |-
  5191. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5192. In some instances, `key` is a required field.
  5193. properties:
  5194. key:
  5195. description: |-
  5196. A key in the referenced Secret.
  5197. Some instances of this field may be defaulted, in others it may be required.
  5198. maxLength: 253
  5199. minLength: 1
  5200. pattern: ^[-._a-zA-Z0-9]+$
  5201. type: string
  5202. name:
  5203. description: The name of the Secret resource being referred to.
  5204. maxLength: 253
  5205. minLength: 1
  5206. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5207. type: string
  5208. namespace:
  5209. description: |-
  5210. The namespace of the Secret resource being referred to.
  5211. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5212. maxLength: 63
  5213. minLength: 1
  5214. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5215. type: string
  5216. type: object
  5217. required:
  5218. - identityId
  5219. type: object
  5220. azureAuthCredentials:
  5221. description: AzureAuthCredentials represents the credentials for Azure authentication.
  5222. properties:
  5223. identityId:
  5224. description: |-
  5225. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5226. In some instances, `key` is a required field.
  5227. properties:
  5228. key:
  5229. description: |-
  5230. A key in the referenced Secret.
  5231. Some instances of this field may be defaulted, in others it may be required.
  5232. maxLength: 253
  5233. minLength: 1
  5234. pattern: ^[-._a-zA-Z0-9]+$
  5235. type: string
  5236. name:
  5237. description: The name of the Secret resource being referred to.
  5238. maxLength: 253
  5239. minLength: 1
  5240. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5241. type: string
  5242. namespace:
  5243. description: |-
  5244. The namespace of the Secret resource being referred to.
  5245. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5246. maxLength: 63
  5247. minLength: 1
  5248. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5249. type: string
  5250. type: object
  5251. resource:
  5252. description: |-
  5253. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5254. In some instances, `key` is a required field.
  5255. properties:
  5256. key:
  5257. description: |-
  5258. A key in the referenced Secret.
  5259. Some instances of this field may be defaulted, in others it may be required.
  5260. maxLength: 253
  5261. minLength: 1
  5262. pattern: ^[-._a-zA-Z0-9]+$
  5263. type: string
  5264. name:
  5265. description: The name of the Secret resource being referred to.
  5266. maxLength: 253
  5267. minLength: 1
  5268. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5269. type: string
  5270. namespace:
  5271. description: |-
  5272. The namespace of the Secret resource being referred to.
  5273. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5274. maxLength: 63
  5275. minLength: 1
  5276. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5277. type: string
  5278. type: object
  5279. required:
  5280. - identityId
  5281. type: object
  5282. gcpIamAuthCredentials:
  5283. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  5284. properties:
  5285. identityId:
  5286. description: |-
  5287. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5288. In some instances, `key` is a required field.
  5289. properties:
  5290. key:
  5291. description: |-
  5292. A key in the referenced Secret.
  5293. Some instances of this field may be defaulted, in others it may be required.
  5294. maxLength: 253
  5295. minLength: 1
  5296. pattern: ^[-._a-zA-Z0-9]+$
  5297. type: string
  5298. name:
  5299. description: The name of the Secret resource being referred to.
  5300. maxLength: 253
  5301. minLength: 1
  5302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5303. type: string
  5304. namespace:
  5305. description: |-
  5306. The namespace of the Secret resource being referred to.
  5307. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5308. maxLength: 63
  5309. minLength: 1
  5310. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5311. type: string
  5312. type: object
  5313. serviceAccountKeyFilePath:
  5314. description: |-
  5315. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5316. In some instances, `key` is a required field.
  5317. properties:
  5318. key:
  5319. description: |-
  5320. A key in the referenced Secret.
  5321. Some instances of this field may be defaulted, in others it may be required.
  5322. maxLength: 253
  5323. minLength: 1
  5324. pattern: ^[-._a-zA-Z0-9]+$
  5325. type: string
  5326. name:
  5327. description: The name of the Secret resource being referred to.
  5328. maxLength: 253
  5329. minLength: 1
  5330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5331. type: string
  5332. namespace:
  5333. description: |-
  5334. The namespace of the Secret resource being referred to.
  5335. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5336. maxLength: 63
  5337. minLength: 1
  5338. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5339. type: string
  5340. type: object
  5341. required:
  5342. - identityId
  5343. - serviceAccountKeyFilePath
  5344. type: object
  5345. gcpIdTokenAuthCredentials:
  5346. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  5347. properties:
  5348. identityId:
  5349. description: |-
  5350. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5351. In some instances, `key` is a required field.
  5352. properties:
  5353. key:
  5354. description: |-
  5355. A key in the referenced Secret.
  5356. Some instances of this field may be defaulted, in others it may be required.
  5357. maxLength: 253
  5358. minLength: 1
  5359. pattern: ^[-._a-zA-Z0-9]+$
  5360. type: string
  5361. name:
  5362. description: The name of the Secret resource being referred to.
  5363. maxLength: 253
  5364. minLength: 1
  5365. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5366. type: string
  5367. namespace:
  5368. description: |-
  5369. The namespace of the Secret resource being referred to.
  5370. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5371. maxLength: 63
  5372. minLength: 1
  5373. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5374. type: string
  5375. type: object
  5376. required:
  5377. - identityId
  5378. type: object
  5379. jwtAuthCredentials:
  5380. description: JwtAuthCredentials represents the credentials for JWT authentication.
  5381. properties:
  5382. identityId:
  5383. description: |-
  5384. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5385. In some instances, `key` is a required field.
  5386. properties:
  5387. key:
  5388. description: |-
  5389. A key in the referenced Secret.
  5390. Some instances of this field may be defaulted, in others it may be required.
  5391. maxLength: 253
  5392. minLength: 1
  5393. pattern: ^[-._a-zA-Z0-9]+$
  5394. type: string
  5395. name:
  5396. description: The name of the Secret resource being referred to.
  5397. maxLength: 253
  5398. minLength: 1
  5399. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5400. type: string
  5401. namespace:
  5402. description: |-
  5403. The namespace of the Secret resource being referred to.
  5404. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5405. maxLength: 63
  5406. minLength: 1
  5407. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5408. type: string
  5409. type: object
  5410. jwt:
  5411. description: |-
  5412. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5413. In some instances, `key` is a required field.
  5414. properties:
  5415. key:
  5416. description: |-
  5417. A key in the referenced Secret.
  5418. Some instances of this field may be defaulted, in others it may be required.
  5419. maxLength: 253
  5420. minLength: 1
  5421. pattern: ^[-._a-zA-Z0-9]+$
  5422. type: string
  5423. name:
  5424. description: The name of the Secret resource being referred to.
  5425. maxLength: 253
  5426. minLength: 1
  5427. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5428. type: string
  5429. namespace:
  5430. description: |-
  5431. The namespace of the Secret resource being referred to.
  5432. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5433. maxLength: 63
  5434. minLength: 1
  5435. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5436. type: string
  5437. type: object
  5438. required:
  5439. - identityId
  5440. - jwt
  5441. type: object
  5442. kubernetesAuthCredentials:
  5443. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  5444. properties:
  5445. identityId:
  5446. description: |-
  5447. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5448. In some instances, `key` is a required field.
  5449. properties:
  5450. key:
  5451. description: |-
  5452. A key in the referenced Secret.
  5453. Some instances of this field may be defaulted, in others it may be required.
  5454. maxLength: 253
  5455. minLength: 1
  5456. pattern: ^[-._a-zA-Z0-9]+$
  5457. type: string
  5458. name:
  5459. description: The name of the Secret resource being referred to.
  5460. maxLength: 253
  5461. minLength: 1
  5462. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5463. type: string
  5464. namespace:
  5465. description: |-
  5466. The namespace of the Secret resource being referred to.
  5467. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5468. maxLength: 63
  5469. minLength: 1
  5470. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5471. type: string
  5472. type: object
  5473. serviceAccountTokenPath:
  5474. description: |-
  5475. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5476. In some instances, `key` is a required field.
  5477. properties:
  5478. key:
  5479. description: |-
  5480. A key in the referenced Secret.
  5481. Some instances of this field may be defaulted, in others it may be required.
  5482. maxLength: 253
  5483. minLength: 1
  5484. pattern: ^[-._a-zA-Z0-9]+$
  5485. type: string
  5486. name:
  5487. description: The name of the Secret resource being referred to.
  5488. maxLength: 253
  5489. minLength: 1
  5490. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5491. type: string
  5492. namespace:
  5493. description: |-
  5494. The namespace of the Secret resource being referred to.
  5495. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5496. maxLength: 63
  5497. minLength: 1
  5498. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5499. type: string
  5500. type: object
  5501. required:
  5502. - identityId
  5503. type: object
  5504. ldapAuthCredentials:
  5505. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  5506. properties:
  5507. identityId:
  5508. description: |-
  5509. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5510. In some instances, `key` is a required field.
  5511. properties:
  5512. key:
  5513. description: |-
  5514. A key in the referenced Secret.
  5515. Some instances of this field may be defaulted, in others it may be required.
  5516. maxLength: 253
  5517. minLength: 1
  5518. pattern: ^[-._a-zA-Z0-9]+$
  5519. type: string
  5520. name:
  5521. description: The name of the Secret resource being referred to.
  5522. maxLength: 253
  5523. minLength: 1
  5524. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5525. type: string
  5526. namespace:
  5527. description: |-
  5528. The namespace of the Secret resource being referred to.
  5529. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5530. maxLength: 63
  5531. minLength: 1
  5532. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5533. type: string
  5534. type: object
  5535. ldapPassword:
  5536. description: |-
  5537. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5538. In some instances, `key` is a required field.
  5539. properties:
  5540. key:
  5541. description: |-
  5542. A key in the referenced Secret.
  5543. Some instances of this field may be defaulted, in others it may be required.
  5544. maxLength: 253
  5545. minLength: 1
  5546. pattern: ^[-._a-zA-Z0-9]+$
  5547. type: string
  5548. name:
  5549. description: The name of the Secret resource being referred to.
  5550. maxLength: 253
  5551. minLength: 1
  5552. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5553. type: string
  5554. namespace:
  5555. description: |-
  5556. The namespace of the Secret resource being referred to.
  5557. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5558. maxLength: 63
  5559. minLength: 1
  5560. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5561. type: string
  5562. type: object
  5563. ldapUsername:
  5564. description: |-
  5565. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5566. In some instances, `key` is a required field.
  5567. properties:
  5568. key:
  5569. description: |-
  5570. A key in the referenced Secret.
  5571. Some instances of this field may be defaulted, in others it may be required.
  5572. maxLength: 253
  5573. minLength: 1
  5574. pattern: ^[-._a-zA-Z0-9]+$
  5575. type: string
  5576. name:
  5577. description: The name of the Secret resource being referred to.
  5578. maxLength: 253
  5579. minLength: 1
  5580. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5581. type: string
  5582. namespace:
  5583. description: |-
  5584. The namespace of the Secret resource being referred to.
  5585. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5586. maxLength: 63
  5587. minLength: 1
  5588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5589. type: string
  5590. type: object
  5591. required:
  5592. - identityId
  5593. - ldapPassword
  5594. - ldapUsername
  5595. type: object
  5596. ociAuthCredentials:
  5597. description: OciAuthCredentials represents the credentials for OCI authentication.
  5598. properties:
  5599. fingerprint:
  5600. description: |-
  5601. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5602. In some instances, `key` is a required field.
  5603. properties:
  5604. key:
  5605. description: |-
  5606. A key in the referenced Secret.
  5607. Some instances of this field may be defaulted, in others it may be required.
  5608. maxLength: 253
  5609. minLength: 1
  5610. pattern: ^[-._a-zA-Z0-9]+$
  5611. type: string
  5612. name:
  5613. description: The name of the Secret resource being referred to.
  5614. maxLength: 253
  5615. minLength: 1
  5616. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5617. type: string
  5618. namespace:
  5619. description: |-
  5620. The namespace of the Secret resource being referred to.
  5621. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5622. maxLength: 63
  5623. minLength: 1
  5624. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5625. type: string
  5626. type: object
  5627. identityId:
  5628. description: |-
  5629. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5630. In some instances, `key` is a required field.
  5631. properties:
  5632. key:
  5633. description: |-
  5634. A key in the referenced Secret.
  5635. Some instances of this field may be defaulted, in others it may be required.
  5636. maxLength: 253
  5637. minLength: 1
  5638. pattern: ^[-._a-zA-Z0-9]+$
  5639. type: string
  5640. name:
  5641. description: The name of the Secret resource being referred to.
  5642. maxLength: 253
  5643. minLength: 1
  5644. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5645. type: string
  5646. namespace:
  5647. description: |-
  5648. The namespace of the Secret resource being referred to.
  5649. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5650. maxLength: 63
  5651. minLength: 1
  5652. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5653. type: string
  5654. type: object
  5655. privateKey:
  5656. description: |-
  5657. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5658. In some instances, `key` is a required field.
  5659. properties:
  5660. key:
  5661. description: |-
  5662. A key in the referenced Secret.
  5663. Some instances of this field may be defaulted, in others it may be required.
  5664. maxLength: 253
  5665. minLength: 1
  5666. pattern: ^[-._a-zA-Z0-9]+$
  5667. type: string
  5668. name:
  5669. description: The name of the Secret resource being referred to.
  5670. maxLength: 253
  5671. minLength: 1
  5672. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5673. type: string
  5674. namespace:
  5675. description: |-
  5676. The namespace of the Secret resource being referred to.
  5677. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5678. maxLength: 63
  5679. minLength: 1
  5680. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5681. type: string
  5682. type: object
  5683. privateKeyPassphrase:
  5684. description: |-
  5685. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5686. In some instances, `key` is a required field.
  5687. properties:
  5688. key:
  5689. description: |-
  5690. A key in the referenced Secret.
  5691. Some instances of this field may be defaulted, in others it may be required.
  5692. maxLength: 253
  5693. minLength: 1
  5694. pattern: ^[-._a-zA-Z0-9]+$
  5695. type: string
  5696. name:
  5697. description: The name of the Secret resource being referred to.
  5698. maxLength: 253
  5699. minLength: 1
  5700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5701. type: string
  5702. namespace:
  5703. description: |-
  5704. The namespace of the Secret resource being referred to.
  5705. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5706. maxLength: 63
  5707. minLength: 1
  5708. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5709. type: string
  5710. type: object
  5711. region:
  5712. description: |-
  5713. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5714. In some instances, `key` is a required field.
  5715. properties:
  5716. key:
  5717. description: |-
  5718. A key in the referenced Secret.
  5719. Some instances of this field may be defaulted, in others it may be required.
  5720. maxLength: 253
  5721. minLength: 1
  5722. pattern: ^[-._a-zA-Z0-9]+$
  5723. type: string
  5724. name:
  5725. description: The name of the Secret resource being referred to.
  5726. maxLength: 253
  5727. minLength: 1
  5728. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5729. type: string
  5730. namespace:
  5731. description: |-
  5732. The namespace of the Secret resource being referred to.
  5733. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5734. maxLength: 63
  5735. minLength: 1
  5736. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5737. type: string
  5738. type: object
  5739. tenancyId:
  5740. description: |-
  5741. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5742. In some instances, `key` is a required field.
  5743. properties:
  5744. key:
  5745. description: |-
  5746. A key in the referenced Secret.
  5747. Some instances of this field may be defaulted, in others it may be required.
  5748. maxLength: 253
  5749. minLength: 1
  5750. pattern: ^[-._a-zA-Z0-9]+$
  5751. type: string
  5752. name:
  5753. description: The name of the Secret resource being referred to.
  5754. maxLength: 253
  5755. minLength: 1
  5756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5757. type: string
  5758. namespace:
  5759. description: |-
  5760. The namespace of the Secret resource being referred to.
  5761. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5762. maxLength: 63
  5763. minLength: 1
  5764. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5765. type: string
  5766. type: object
  5767. userId:
  5768. description: |-
  5769. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5770. In some instances, `key` is a required field.
  5771. properties:
  5772. key:
  5773. description: |-
  5774. A key in the referenced Secret.
  5775. Some instances of this field may be defaulted, in others it may be required.
  5776. maxLength: 253
  5777. minLength: 1
  5778. pattern: ^[-._a-zA-Z0-9]+$
  5779. type: string
  5780. name:
  5781. description: The name of the Secret resource being referred to.
  5782. maxLength: 253
  5783. minLength: 1
  5784. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5785. type: string
  5786. namespace:
  5787. description: |-
  5788. The namespace of the Secret resource being referred to.
  5789. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5790. maxLength: 63
  5791. minLength: 1
  5792. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5793. type: string
  5794. type: object
  5795. required:
  5796. - fingerprint
  5797. - identityId
  5798. - privateKey
  5799. - region
  5800. - tenancyId
  5801. - userId
  5802. type: object
  5803. tokenAuthCredentials:
  5804. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  5805. properties:
  5806. accessToken:
  5807. description: |-
  5808. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5809. In some instances, `key` is a required field.
  5810. properties:
  5811. key:
  5812. description: |-
  5813. A key in the referenced Secret.
  5814. Some instances of this field may be defaulted, in others it may be required.
  5815. maxLength: 253
  5816. minLength: 1
  5817. pattern: ^[-._a-zA-Z0-9]+$
  5818. type: string
  5819. name:
  5820. description: The name of the Secret resource being referred to.
  5821. maxLength: 253
  5822. minLength: 1
  5823. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5824. type: string
  5825. namespace:
  5826. description: |-
  5827. The namespace of the Secret resource being referred to.
  5828. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5829. maxLength: 63
  5830. minLength: 1
  5831. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5832. type: string
  5833. type: object
  5834. required:
  5835. - accessToken
  5836. type: object
  5837. universalAuthCredentials:
  5838. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  5839. properties:
  5840. clientId:
  5841. description: |-
  5842. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5843. In some instances, `key` is a required field.
  5844. properties:
  5845. key:
  5846. description: |-
  5847. A key in the referenced Secret.
  5848. Some instances of this field may be defaulted, in others it may be required.
  5849. maxLength: 253
  5850. minLength: 1
  5851. pattern: ^[-._a-zA-Z0-9]+$
  5852. type: string
  5853. name:
  5854. description: The name of the Secret resource being referred to.
  5855. maxLength: 253
  5856. minLength: 1
  5857. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5858. type: string
  5859. namespace:
  5860. description: |-
  5861. The namespace of the Secret resource being referred to.
  5862. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5863. maxLength: 63
  5864. minLength: 1
  5865. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5866. type: string
  5867. type: object
  5868. clientSecret:
  5869. description: |-
  5870. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5871. In some instances, `key` is a required field.
  5872. properties:
  5873. key:
  5874. description: |-
  5875. A key in the referenced Secret.
  5876. Some instances of this field may be defaulted, in others it may be required.
  5877. maxLength: 253
  5878. minLength: 1
  5879. pattern: ^[-._a-zA-Z0-9]+$
  5880. type: string
  5881. name:
  5882. description: The name of the Secret resource being referred to.
  5883. maxLength: 253
  5884. minLength: 1
  5885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5886. type: string
  5887. namespace:
  5888. description: |-
  5889. The namespace of the Secret resource being referred to.
  5890. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5891. maxLength: 63
  5892. minLength: 1
  5893. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5894. type: string
  5895. type: object
  5896. required:
  5897. - clientId
  5898. - clientSecret
  5899. type: object
  5900. type: object
  5901. caBundle:
  5902. description: |-
  5903. CABundle is a PEM-encoded CA certificate bundle used to validate
  5904. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  5905. format: byte
  5906. type: string
  5907. caProvider:
  5908. description: |-
  5909. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  5910. The certificate is used to validate the Infisical server's TLS certificate.
  5911. Mutually exclusive with CABundle.
  5912. properties:
  5913. key:
  5914. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5915. maxLength: 253
  5916. minLength: 1
  5917. pattern: ^[-._a-zA-Z0-9]+$
  5918. type: string
  5919. name:
  5920. description: The name of the object located at the provider type.
  5921. maxLength: 253
  5922. minLength: 1
  5923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5924. type: string
  5925. namespace:
  5926. description: |-
  5927. The namespace the Provider type is in.
  5928. Can only be defined when used in a ClusterSecretStore.
  5929. maxLength: 63
  5930. minLength: 1
  5931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5932. type: string
  5933. type:
  5934. description: The type of provider to use such as "Secret", or "ConfigMap".
  5935. enum:
  5936. - Secret
  5937. - ConfigMap
  5938. type: string
  5939. required:
  5940. - name
  5941. - type
  5942. type: object
  5943. hostAPI:
  5944. default: https://app.infisical.com/api
  5945. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  5946. type: string
  5947. secretsScope:
  5948. description: SecretsScope defines the scope of the secrets within the workspace
  5949. properties:
  5950. environmentSlug:
  5951. description: EnvironmentSlug is the required slug identifier for the environment.
  5952. type: string
  5953. expandSecretReferences:
  5954. default: true
  5955. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  5956. type: boolean
  5957. organizationSlug:
  5958. description: |-
  5959. OrganizationSlug is the optional slug that identifies the organization that will be used
  5960. during authentication. Useful for sub-organization setups
  5961. type: string
  5962. projectSlug:
  5963. description: ProjectSlug is the required slug identifier for the project.
  5964. type: string
  5965. recursive:
  5966. default: false
  5967. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  5968. type: boolean
  5969. secretsPath:
  5970. default: /
  5971. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  5972. type: string
  5973. required:
  5974. - environmentSlug
  5975. - projectSlug
  5976. type: object
  5977. required:
  5978. - auth
  5979. - secretsScope
  5980. type: object
  5981. keepersecurity:
  5982. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  5983. properties:
  5984. authRef:
  5985. description: |-
  5986. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5987. In some instances, `key` is a required field.
  5988. properties:
  5989. key:
  5990. description: |-
  5991. A key in the referenced Secret.
  5992. Some instances of this field may be defaulted, in others it may be required.
  5993. maxLength: 253
  5994. minLength: 1
  5995. pattern: ^[-._a-zA-Z0-9]+$
  5996. type: string
  5997. name:
  5998. description: The name of the Secret resource being referred to.
  5999. maxLength: 253
  6000. minLength: 1
  6001. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6002. type: string
  6003. namespace:
  6004. description: |-
  6005. The namespace of the Secret resource being referred to.
  6006. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6007. maxLength: 63
  6008. minLength: 1
  6009. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6010. type: string
  6011. type: object
  6012. folderID:
  6013. type: string
  6014. getByTitleFallback:
  6015. type: boolean
  6016. required:
  6017. - authRef
  6018. - folderID
  6019. type: object
  6020. kubernetes:
  6021. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  6022. properties:
  6023. auth:
  6024. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  6025. maxProperties: 1
  6026. minProperties: 1
  6027. properties:
  6028. cert:
  6029. description: has both clientCert and clientKey as secretKeySelector
  6030. properties:
  6031. clientCert:
  6032. description: |-
  6033. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6034. In some instances, `key` is a required field.
  6035. properties:
  6036. key:
  6037. description: |-
  6038. A key in the referenced Secret.
  6039. Some instances of this field may be defaulted, in others it may be required.
  6040. maxLength: 253
  6041. minLength: 1
  6042. pattern: ^[-._a-zA-Z0-9]+$
  6043. type: string
  6044. name:
  6045. description: The name of the Secret resource being referred to.
  6046. maxLength: 253
  6047. minLength: 1
  6048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6049. type: string
  6050. namespace:
  6051. description: |-
  6052. The namespace of the Secret resource being referred to.
  6053. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6054. maxLength: 63
  6055. minLength: 1
  6056. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6057. type: string
  6058. type: object
  6059. clientKey:
  6060. description: |-
  6061. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6062. In some instances, `key` is a required field.
  6063. properties:
  6064. key:
  6065. description: |-
  6066. A key in the referenced Secret.
  6067. Some instances of this field may be defaulted, in others it may be required.
  6068. maxLength: 253
  6069. minLength: 1
  6070. pattern: ^[-._a-zA-Z0-9]+$
  6071. type: string
  6072. name:
  6073. description: The name of the Secret resource being referred to.
  6074. maxLength: 253
  6075. minLength: 1
  6076. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6077. type: string
  6078. namespace:
  6079. description: |-
  6080. The namespace of the Secret resource being referred to.
  6081. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6082. maxLength: 63
  6083. minLength: 1
  6084. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6085. type: string
  6086. type: object
  6087. required:
  6088. - clientCert
  6089. - clientKey
  6090. type: object
  6091. serviceAccount:
  6092. description: points to a service account that should be used for authentication
  6093. properties:
  6094. audiences:
  6095. description: |-
  6096. Audience specifies the `aud` claim for the service account token
  6097. Some providers automatically extend the audience field based on well-known annotations for workload
  6098. identity (e.g. IRSA or GCP Workload Identity)
  6099. items:
  6100. type: string
  6101. type: array
  6102. name:
  6103. description: The name of the ServiceAccount resource being referred to.
  6104. maxLength: 253
  6105. minLength: 1
  6106. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6107. type: string
  6108. namespace:
  6109. description: |-
  6110. Namespace of the resource being referred to.
  6111. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6112. maxLength: 63
  6113. minLength: 1
  6114. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6115. type: string
  6116. required:
  6117. - name
  6118. type: object
  6119. token:
  6120. description: use static token to authenticate with
  6121. properties:
  6122. bearerToken:
  6123. description: |-
  6124. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6125. In some instances, `key` is a required field.
  6126. properties:
  6127. key:
  6128. description: |-
  6129. A key in the referenced Secret.
  6130. Some instances of this field may be defaulted, in others it may be required.
  6131. maxLength: 253
  6132. minLength: 1
  6133. pattern: ^[-._a-zA-Z0-9]+$
  6134. type: string
  6135. name:
  6136. description: The name of the Secret resource being referred to.
  6137. maxLength: 253
  6138. minLength: 1
  6139. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6140. type: string
  6141. namespace:
  6142. description: |-
  6143. The namespace of the Secret resource being referred to.
  6144. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6145. maxLength: 63
  6146. minLength: 1
  6147. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6148. type: string
  6149. type: object
  6150. required:
  6151. - bearerToken
  6152. type: object
  6153. type: object
  6154. authRef:
  6155. description: A reference to a secret that contains the auth information.
  6156. properties:
  6157. key:
  6158. description: |-
  6159. A key in the referenced Secret.
  6160. Some instances of this field may be defaulted, in others it may be required.
  6161. maxLength: 253
  6162. minLength: 1
  6163. pattern: ^[-._a-zA-Z0-9]+$
  6164. type: string
  6165. name:
  6166. description: The name of the Secret resource being referred to.
  6167. maxLength: 253
  6168. minLength: 1
  6169. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6170. type: string
  6171. namespace:
  6172. description: |-
  6173. The namespace of the Secret resource being referred to.
  6174. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6175. maxLength: 63
  6176. minLength: 1
  6177. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6178. type: string
  6179. type: object
  6180. remoteNamespace:
  6181. default: default
  6182. description: Remote namespace to fetch the secrets from
  6183. maxLength: 63
  6184. minLength: 1
  6185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6186. type: string
  6187. server:
  6188. description: configures the Kubernetes server Address.
  6189. properties:
  6190. caBundle:
  6191. description: CABundle is a base64-encoded CA certificate
  6192. format: byte
  6193. type: string
  6194. caProvider:
  6195. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  6196. properties:
  6197. key:
  6198. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6199. maxLength: 253
  6200. minLength: 1
  6201. pattern: ^[-._a-zA-Z0-9]+$
  6202. type: string
  6203. name:
  6204. description: The name of the object located at the provider type.
  6205. maxLength: 253
  6206. minLength: 1
  6207. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6208. type: string
  6209. namespace:
  6210. description: |-
  6211. The namespace the Provider type is in.
  6212. Can only be defined when used in a ClusterSecretStore.
  6213. maxLength: 63
  6214. minLength: 1
  6215. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6216. type: string
  6217. type:
  6218. description: The type of provider to use such as "Secret", or "ConfigMap".
  6219. enum:
  6220. - Secret
  6221. - ConfigMap
  6222. type: string
  6223. required:
  6224. - name
  6225. - type
  6226. type: object
  6227. url:
  6228. default: kubernetes.default
  6229. description: configures the Kubernetes server Address.
  6230. type: string
  6231. type: object
  6232. type: object
  6233. nebiusmysterybox:
  6234. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  6235. properties:
  6236. apiDomain:
  6237. description: NebiusMysterybox API endpoint
  6238. type: string
  6239. auth:
  6240. description: Auth defines parameters to authenticate in MysteryBox
  6241. properties:
  6242. serviceAccountCredsSecretRef:
  6243. description: |-
  6244. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  6245. document with service account credentials used to get an IAM token.
  6246. Expected JSON structure:
  6247. {
  6248. "subject-credentials": {
  6249. "alg": "RS256",
  6250. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  6251. "kid": "<public-key-id>",
  6252. "iss": "<issuer-service-account-id>",
  6253. "sub": "<subject-service-account-id>"
  6254. }
  6255. }
  6256. properties:
  6257. key:
  6258. description: |-
  6259. A key in the referenced Secret.
  6260. Some instances of this field may be defaulted, in others it may be required.
  6261. maxLength: 253
  6262. minLength: 1
  6263. pattern: ^[-._a-zA-Z0-9]+$
  6264. type: string
  6265. name:
  6266. description: The name of the Secret resource being referred to.
  6267. maxLength: 253
  6268. minLength: 1
  6269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6270. type: string
  6271. namespace:
  6272. description: |-
  6273. The namespace of the Secret resource being referred to.
  6274. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6275. maxLength: 63
  6276. minLength: 1
  6277. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6278. type: string
  6279. type: object
  6280. tokenSecretRef:
  6281. description: Token authenticates with Nebius Mysterybox by presenting a token.
  6282. properties:
  6283. key:
  6284. description: |-
  6285. A key in the referenced Secret.
  6286. Some instances of this field may be defaulted, in others it may be required.
  6287. maxLength: 253
  6288. minLength: 1
  6289. pattern: ^[-._a-zA-Z0-9]+$
  6290. type: string
  6291. name:
  6292. description: The name of the Secret resource being referred to.
  6293. maxLength: 253
  6294. minLength: 1
  6295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6296. type: string
  6297. namespace:
  6298. description: |-
  6299. The namespace of the Secret resource being referred to.
  6300. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6301. maxLength: 63
  6302. minLength: 1
  6303. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6304. type: string
  6305. type: object
  6306. workloadIdentity:
  6307. description: WorkloadIdentity defines configuration for workload identity authentication to Nebius IAM.
  6308. properties:
  6309. iamServiceAccountID:
  6310. description: |-
  6311. IAMServiceAccountID is the Nebius IAM service account identifier that the
  6312. federated Kubernetes service account should impersonate during token exchange.
  6313. example: serviceaccount-e00example
  6314. minLength: 1
  6315. pattern: ^serviceaccount-[a-z][a-z0-9]{2}
  6316. type: string
  6317. serviceAccountRef:
  6318. description: |-
  6319. ServiceAccountRef references a Kubernetes ServiceAccount used to request a
  6320. temporary JWT via the TokenRequest API. The JWT is then exchanged for a
  6321. Nebius IAM token using workload federation.
  6322. properties:
  6323. audiences:
  6324. description: |-
  6325. Audience specifies the `aud` claim for the service account token
  6326. Some providers automatically extend the audience field based on well-known annotations for workload
  6327. identity (e.g. IRSA or GCP Workload Identity)
  6328. items:
  6329. type: string
  6330. type: array
  6331. name:
  6332. description: The name of the ServiceAccount resource being referred to.
  6333. maxLength: 253
  6334. minLength: 1
  6335. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6336. type: string
  6337. namespace:
  6338. description: |-
  6339. Namespace of the resource being referred to.
  6340. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6341. maxLength: 63
  6342. minLength: 1
  6343. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6344. type: string
  6345. required:
  6346. - name
  6347. type: object
  6348. required:
  6349. - iamServiceAccountID
  6350. - serviceAccountRef
  6351. type: object
  6352. type: object
  6353. x-kubernetes-validations:
  6354. - message: exactly one of serviceAccountCredsSecretRef, tokenSecretRef, or workloadIdentity must be set
  6355. rule: '(has(self.serviceAccountCredsSecretRef) && has(self.serviceAccountCredsSecretRef.name) && size(self.serviceAccountCredsSecretRef.name) > 0 ? 1 : 0) + (has(self.tokenSecretRef) && has(self.tokenSecretRef.name) && size(self.tokenSecretRef.name) > 0 ? 1 : 0) + (has(self.workloadIdentity) ? 1 : 0) == 1'
  6356. caProvider:
  6357. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  6358. properties:
  6359. certSecretRef:
  6360. description: |-
  6361. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6362. In some instances, `key` is a required field.
  6363. properties:
  6364. key:
  6365. description: |-
  6366. A key in the referenced Secret.
  6367. Some instances of this field may be defaulted, in others it may be required.
  6368. maxLength: 253
  6369. minLength: 1
  6370. pattern: ^[-._a-zA-Z0-9]+$
  6371. type: string
  6372. name:
  6373. description: The name of the Secret resource being referred to.
  6374. maxLength: 253
  6375. minLength: 1
  6376. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6377. type: string
  6378. namespace:
  6379. description: |-
  6380. The namespace of the Secret resource being referred to.
  6381. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6382. maxLength: 63
  6383. minLength: 1
  6384. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6385. type: string
  6386. type: object
  6387. type: object
  6388. required:
  6389. - apiDomain
  6390. - auth
  6391. type: object
  6392. ngrok:
  6393. description: Ngrok configures this store to sync secrets using the ngrok provider.
  6394. properties:
  6395. apiUrl:
  6396. default: https://api.ngrok.com
  6397. description: APIURL is the URL of the ngrok API.
  6398. type: string
  6399. auth:
  6400. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  6401. maxProperties: 1
  6402. minProperties: 1
  6403. properties:
  6404. apiKey:
  6405. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  6406. properties:
  6407. secretRef:
  6408. description: SecretRef is a reference to a secret containing the ngrok API key.
  6409. properties:
  6410. key:
  6411. description: |-
  6412. A key in the referenced Secret.
  6413. Some instances of this field may be defaulted, in others it may be required.
  6414. maxLength: 253
  6415. minLength: 1
  6416. pattern: ^[-._a-zA-Z0-9]+$
  6417. type: string
  6418. name:
  6419. description: The name of the Secret resource being referred to.
  6420. maxLength: 253
  6421. minLength: 1
  6422. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6423. type: string
  6424. namespace:
  6425. description: |-
  6426. The namespace of the Secret resource being referred to.
  6427. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6428. maxLength: 63
  6429. minLength: 1
  6430. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6431. type: string
  6432. type: object
  6433. type: object
  6434. type: object
  6435. vault:
  6436. description: Vault configures the ngrok vault to sync secrets with.
  6437. properties:
  6438. name:
  6439. description: Name is the name of the ngrok vault to sync secrets with.
  6440. type: string
  6441. required:
  6442. - name
  6443. type: object
  6444. required:
  6445. - auth
  6446. - vault
  6447. type: object
  6448. onboardbase:
  6449. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  6450. properties:
  6451. apiHost:
  6452. default: https://public.onboardbase.com/api/v1/
  6453. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  6454. type: string
  6455. auth:
  6456. description: Auth configures how the Operator authenticates with the Onboardbase API
  6457. properties:
  6458. apiKeyRef:
  6459. description: |-
  6460. OnboardbaseAPIKey is the APIKey generated by an admin account.
  6461. It is used to recognize and authorize access to a project and environment within onboardbase
  6462. properties:
  6463. key:
  6464. description: |-
  6465. A key in the referenced Secret.
  6466. Some instances of this field may be defaulted, in others it may be required.
  6467. maxLength: 253
  6468. minLength: 1
  6469. pattern: ^[-._a-zA-Z0-9]+$
  6470. type: string
  6471. name:
  6472. description: The name of the Secret resource being referred to.
  6473. maxLength: 253
  6474. minLength: 1
  6475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6476. type: string
  6477. namespace:
  6478. description: |-
  6479. The namespace of the Secret resource being referred to.
  6480. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6481. maxLength: 63
  6482. minLength: 1
  6483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6484. type: string
  6485. type: object
  6486. passcodeRef:
  6487. description: OnboardbasePasscode is the passcode attached to the API Key
  6488. properties:
  6489. key:
  6490. description: |-
  6491. A key in the referenced Secret.
  6492. Some instances of this field may be defaulted, in others it may be required.
  6493. maxLength: 253
  6494. minLength: 1
  6495. pattern: ^[-._a-zA-Z0-9]+$
  6496. type: string
  6497. name:
  6498. description: The name of the Secret resource being referred to.
  6499. maxLength: 253
  6500. minLength: 1
  6501. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6502. type: string
  6503. namespace:
  6504. description: |-
  6505. The namespace of the Secret resource being referred to.
  6506. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6507. maxLength: 63
  6508. minLength: 1
  6509. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6510. type: string
  6511. type: object
  6512. required:
  6513. - apiKeyRef
  6514. - passcodeRef
  6515. type: object
  6516. environment:
  6517. default: development
  6518. description: Environment is the name of an environmnent within a project to pull the secrets from
  6519. type: string
  6520. project:
  6521. default: development
  6522. description: Project is an onboardbase project that the secrets should be pulled from
  6523. type: string
  6524. required:
  6525. - apiHost
  6526. - auth
  6527. - environment
  6528. - project
  6529. type: object
  6530. onepassword:
  6531. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  6532. properties:
  6533. auth:
  6534. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  6535. properties:
  6536. secretRef:
  6537. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  6538. properties:
  6539. connectTokenSecretRef:
  6540. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  6541. properties:
  6542. key:
  6543. description: |-
  6544. A key in the referenced Secret.
  6545. Some instances of this field may be defaulted, in others it may be required.
  6546. maxLength: 253
  6547. minLength: 1
  6548. pattern: ^[-._a-zA-Z0-9]+$
  6549. type: string
  6550. name:
  6551. description: The name of the Secret resource being referred to.
  6552. maxLength: 253
  6553. minLength: 1
  6554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6555. type: string
  6556. namespace:
  6557. description: |-
  6558. The namespace of the Secret resource being referred to.
  6559. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6560. maxLength: 63
  6561. minLength: 1
  6562. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6563. type: string
  6564. type: object
  6565. required:
  6566. - connectTokenSecretRef
  6567. type: object
  6568. required:
  6569. - secretRef
  6570. type: object
  6571. connectHost:
  6572. description: ConnectHost defines the OnePassword Connect Server to connect to
  6573. type: string
  6574. vaults:
  6575. additionalProperties:
  6576. type: integer
  6577. description: Vaults defines which OnePassword vaults to search in which order
  6578. type: object
  6579. required:
  6580. - auth
  6581. - connectHost
  6582. - vaults
  6583. type: object
  6584. onepasswordSDK:
  6585. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  6586. properties:
  6587. auth:
  6588. description: Auth defines the information necessary to authenticate against OnePassword API.
  6589. properties:
  6590. serviceAccountSecretRef:
  6591. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  6592. properties:
  6593. key:
  6594. description: |-
  6595. A key in the referenced Secret.
  6596. Some instances of this field may be defaulted, in others it may be required.
  6597. maxLength: 253
  6598. minLength: 1
  6599. pattern: ^[-._a-zA-Z0-9]+$
  6600. type: string
  6601. name:
  6602. description: The name of the Secret resource being referred to.
  6603. maxLength: 253
  6604. minLength: 1
  6605. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6606. type: string
  6607. namespace:
  6608. description: |-
  6609. The namespace of the Secret resource being referred to.
  6610. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6611. maxLength: 63
  6612. minLength: 1
  6613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6614. type: string
  6615. type: object
  6616. required:
  6617. - serviceAccountSecretRef
  6618. type: object
  6619. cache:
  6620. description: |-
  6621. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  6622. When enabled, secrets are cached with the specified TTL.
  6623. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  6624. If omitted, caching is disabled (default).
  6625. cache: {} is a valid option to set.
  6626. properties:
  6627. maxSize:
  6628. default: 100
  6629. description: |-
  6630. MaxSize is the maximum number of secrets to cache.
  6631. When the cache is full, least-recently-used entries are evicted.
  6632. minimum: 1
  6633. type: integer
  6634. ttl:
  6635. default: 5m
  6636. description: |-
  6637. TTL is the time-to-live for cached secrets.
  6638. Format: duration string (e.g., "5m", "1h", "30s")
  6639. type: string
  6640. type: object
  6641. environment:
  6642. description: |-
  6643. Environment defines the 1Password Environment ID to read variables from.
  6644. Environments are read-only: PushSecret, DeleteSecret, and SecretExists return an error when set.
  6645. Mutually exclusive with Vault.
  6646. type: string
  6647. integrationInfo:
  6648. description: |-
  6649. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  6650. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  6651. properties:
  6652. name:
  6653. default: 1Password SDK
  6654. description: Name defaults to "1Password SDK".
  6655. type: string
  6656. version:
  6657. default: v1.0.0
  6658. description: Version defaults to "v1.0.0".
  6659. type: string
  6660. type: object
  6661. vault:
  6662. description: |-
  6663. Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  6664. Mutually exclusive with Environment.
  6665. type: string
  6666. required:
  6667. - auth
  6668. type: object
  6669. x-kubernetes-validations:
  6670. - message: at most one of the fields in [vault environment] may be set
  6671. rule: '[has(self.vault),has(self.environment)].filter(x,x==true).size() <= 1'
  6672. openBao:
  6673. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  6674. properties:
  6675. auth:
  6676. description: Auth configures how secret-manager authenticates with the OpenBao server.
  6677. properties:
  6678. appRole:
  6679. description: |-
  6680. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  6681. with the role and secret stored in a Kubernetes Secret resource.
  6682. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  6683. properties:
  6684. path:
  6685. default: approle
  6686. description: |-
  6687. Path where the App Role authentication backend is mounted
  6688. in OpenBao, e.g: "approle"
  6689. type: string
  6690. roleId:
  6691. description: |-
  6692. RoleID configured in the App Role authentication backend when setting
  6693. up the authentication backend in OpenBao.
  6694. minLength: 1
  6695. type: string
  6696. roleRef:
  6697. description: |-
  6698. Reference to a key in a Secret that contains the App Role ID used
  6699. to authenticate with OpenBao.
  6700. The `key` field must be specified and denotes which entry within the Secret
  6701. resource is used as the app role id.
  6702. properties:
  6703. key:
  6704. description: |-
  6705. A key in the referenced Secret.
  6706. Some instances of this field may be defaulted, in others it may be required.
  6707. maxLength: 253
  6708. minLength: 1
  6709. pattern: ^[-._a-zA-Z0-9]+$
  6710. type: string
  6711. name:
  6712. description: The name of the Secret resource being referred to.
  6713. maxLength: 253
  6714. minLength: 1
  6715. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6716. type: string
  6717. namespace:
  6718. description: |-
  6719. The namespace of the Secret resource being referred to.
  6720. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6721. maxLength: 63
  6722. minLength: 1
  6723. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6724. type: string
  6725. type: object
  6726. secretRef:
  6727. description: |-
  6728. Reference to a key in a Secret that contains the App Role secret used
  6729. to authenticate with OpenBao.
  6730. The `key` field must be specified and denotes which entry within the Secret
  6731. resource is used as the app role secret.
  6732. properties:
  6733. key:
  6734. description: |-
  6735. A key in the referenced Secret.
  6736. Some instances of this field may be defaulted, in others it may be required.
  6737. maxLength: 253
  6738. minLength: 1
  6739. pattern: ^[-._a-zA-Z0-9]+$
  6740. type: string
  6741. name:
  6742. description: The name of the Secret resource being referred to.
  6743. maxLength: 253
  6744. minLength: 1
  6745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6746. type: string
  6747. namespace:
  6748. description: |-
  6749. The namespace of the Secret resource being referred to.
  6750. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6751. maxLength: 63
  6752. minLength: 1
  6753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6754. type: string
  6755. type: object
  6756. required:
  6757. - path
  6758. - secretRef
  6759. type: object
  6760. x-kubernetes-validations:
  6761. - message: exactly one of the fields in [roleId roleRef] must be set
  6762. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  6763. kubernetes:
  6764. description: |-
  6765. Kubernetes authenticates with OpenBao by passing a ServiceAccount
  6766. token to the [Kubernetes auth mechanism].
  6767. [Kubernetes auth mechanism]: https://openbao.org/docs/auth/kubernetes/
  6768. properties:
  6769. path:
  6770. default: kubernetes
  6771. description: |-
  6772. Path where the Kubernetes authentication backend is mounted in OpenBao, e.g:
  6773. "kubernetes"
  6774. type: string
  6775. role:
  6776. description: |-
  6777. A required field containing the OpenBao Role to assume. A Role binds a
  6778. Kubernetes ServiceAccount with a set of OpenBao policies.
  6779. minLength: 1
  6780. type: string
  6781. secretRef:
  6782. description: |-
  6783. Optional secret field containing a Kubernetes ServiceAccount JWT used
  6784. for authenticating with OpenBao. If a name is specified without a key,
  6785. `token` is the default.
  6786. properties:
  6787. key:
  6788. description: |-
  6789. A key in the referenced Secret.
  6790. Some instances of this field may be defaulted, in others it may be required.
  6791. maxLength: 253
  6792. minLength: 1
  6793. pattern: ^[-._a-zA-Z0-9]+$
  6794. type: string
  6795. name:
  6796. description: The name of the Secret resource being referred to.
  6797. maxLength: 253
  6798. minLength: 1
  6799. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6800. type: string
  6801. namespace:
  6802. description: |-
  6803. The namespace of the Secret resource being referred to.
  6804. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6805. maxLength: 63
  6806. minLength: 1
  6807. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6808. type: string
  6809. type: object
  6810. serviceAccountRef:
  6811. description: |-
  6812. Optional service account field containing the name of a Kubernetes ServiceAccount.
  6813. If the service account is specified, a token will be requested from the Kubernetes
  6814. TokenRequest API for authenticating with OpenBao.
  6815. Any configured audiences will be passed to the TokenRequest as-is.
  6816. properties:
  6817. audiences:
  6818. description: |-
  6819. Audience specifies the `aud` claim for the service account token
  6820. Some providers automatically extend the audience field based on well-known annotations for workload
  6821. identity (e.g. IRSA or GCP Workload Identity)
  6822. items:
  6823. type: string
  6824. type: array
  6825. name:
  6826. description: The name of the ServiceAccount resource being referred to.
  6827. maxLength: 253
  6828. minLength: 1
  6829. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6830. type: string
  6831. namespace:
  6832. description: |-
  6833. Namespace of the resource being referred to.
  6834. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6835. maxLength: 63
  6836. minLength: 1
  6837. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6838. type: string
  6839. required:
  6840. - name
  6841. type: object
  6842. required:
  6843. - path
  6844. - role
  6845. type: object
  6846. x-kubernetes-validations:
  6847. - message: exactly one of the fields in [serviceAccountRef secretRef] must be set
  6848. rule: '[has(self.serviceAccountRef),has(self.secretRef)].filter(x,x==true).size() == 1'
  6849. namespace:
  6850. description: |-
  6851. Name of the [OpenBao Namespace] to authenticate to. This can be different
  6852. than the namespace your secret is in. Namespaces is a set of features
  6853. within OpenBao that allows OpenBao environments to support secure
  6854. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  6855. if set, or empty otherwise
  6856. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6857. type: string
  6858. tokenSecretRef:
  6859. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  6860. properties:
  6861. key:
  6862. description: |-
  6863. A key in the referenced Secret.
  6864. Some instances of this field may be defaulted, in others it may be required.
  6865. maxLength: 253
  6866. minLength: 1
  6867. pattern: ^[-._a-zA-Z0-9]+$
  6868. type: string
  6869. name:
  6870. description: The name of the Secret resource being referred to.
  6871. maxLength: 253
  6872. minLength: 1
  6873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6874. type: string
  6875. namespace:
  6876. description: |-
  6877. The namespace of the Secret resource being referred to.
  6878. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6879. maxLength: 63
  6880. minLength: 1
  6881. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6882. type: string
  6883. type: object
  6884. userPass:
  6885. description: UserPass authenticates with OpenBao by passing a username/password pair
  6886. properties:
  6887. path:
  6888. default: userpass
  6889. description: |-
  6890. Path where the UserPassword authentication backend is mounted
  6891. in OpenBao, e.g: "userpass"
  6892. type: string
  6893. secretRef:
  6894. description: |-
  6895. SecretRef to a key in a Secret resource containing password for the user
  6896. used to authenticate with OpenBao using the [UserPass authentication
  6897. method]
  6898. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6899. properties:
  6900. key:
  6901. description: |-
  6902. A key in the referenced Secret.
  6903. Some instances of this field may be defaulted, in others it may be required.
  6904. maxLength: 253
  6905. minLength: 1
  6906. pattern: ^[-._a-zA-Z0-9]+$
  6907. type: string
  6908. name:
  6909. description: The name of the Secret resource being referred to.
  6910. maxLength: 253
  6911. minLength: 1
  6912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6913. type: string
  6914. namespace:
  6915. description: |-
  6916. The namespace of the Secret resource being referred to.
  6917. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6918. maxLength: 63
  6919. minLength: 1
  6920. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6921. type: string
  6922. type: object
  6923. username:
  6924. description: |-
  6925. Username is a username used to authenticate using the [UserPass
  6926. authentication method]
  6927. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6928. type: string
  6929. required:
  6930. - path
  6931. - username
  6932. type: object
  6933. type: object
  6934. x-kubernetes-validations:
  6935. - message: exactly one of the fields in [appRole tokenSecretRef userPass kubernetes] must be set
  6936. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass),has(self.kubernetes)].filter(x,x==true).size() == 1'
  6937. caBundle:
  6938. description: |-
  6939. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  6940. this and `caProvider` are not set the system root certificates are used
  6941. to validate the TLS connection.
  6942. format: byte
  6943. type: string
  6944. caProvider:
  6945. description: |-
  6946. The provider for the CA bundle to use to validate OpenBao server
  6947. certificate. If this and `caBundle` are not set the system root
  6948. certificates are used to validate the TLS connection.
  6949. properties:
  6950. key:
  6951. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6952. maxLength: 253
  6953. minLength: 1
  6954. pattern: ^[-._a-zA-Z0-9]+$
  6955. type: string
  6956. name:
  6957. description: The name of the object located at the provider type.
  6958. maxLength: 253
  6959. minLength: 1
  6960. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6961. type: string
  6962. namespace:
  6963. description: |-
  6964. The namespace the Provider type is in.
  6965. Can only be defined when used in a ClusterSecretStore.
  6966. maxLength: 63
  6967. minLength: 1
  6968. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6969. type: string
  6970. type:
  6971. description: The type of provider to use such as "Secret", or "ConfigMap".
  6972. enum:
  6973. - Secret
  6974. - ConfigMap
  6975. type: string
  6976. required:
  6977. - name
  6978. - type
  6979. type: object
  6980. namespace:
  6981. description: |-
  6982. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  6983. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  6984. e.g: "ns1".
  6985. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6986. type: string
  6987. path:
  6988. description: |-
  6989. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  6990. "secret". The v2 KV secret engine version specific "/data" path suffix
  6991. for fetching secrets from OpenBao is optional and will be appended
  6992. if not present in specified path.
  6993. type: string
  6994. server:
  6995. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  6996. type: string
  6997. version:
  6998. default: v2
  6999. description: |-
  7000. Version is the OpenBao KV secret engine version. This can be either "v1" or
  7001. "v2". Version defaults to "v2".
  7002. enum:
  7003. - v1
  7004. - v2
  7005. type: string
  7006. required:
  7007. - server
  7008. type: object
  7009. x-kubernetes-validations:
  7010. - message: at most one of the fields in [caBundle caProvider] may be set
  7011. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  7012. oracle:
  7013. description: Oracle configures this store to sync secrets using Oracle Vault provider
  7014. properties:
  7015. auth:
  7016. description: |-
  7017. Auth configures how secret-manager authenticates with the Oracle Vault.
  7018. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  7019. properties:
  7020. secretRef:
  7021. description: SecretRef to pass through sensitive information.
  7022. properties:
  7023. fingerprint:
  7024. description: Fingerprint is the fingerprint of the API private key.
  7025. properties:
  7026. key:
  7027. description: |-
  7028. A key in the referenced Secret.
  7029. Some instances of this field may be defaulted, in others it may be required.
  7030. maxLength: 253
  7031. minLength: 1
  7032. pattern: ^[-._a-zA-Z0-9]+$
  7033. type: string
  7034. name:
  7035. description: The name of the Secret resource being referred to.
  7036. maxLength: 253
  7037. minLength: 1
  7038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7039. type: string
  7040. namespace:
  7041. description: |-
  7042. The namespace of the Secret resource being referred to.
  7043. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7044. maxLength: 63
  7045. minLength: 1
  7046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7047. type: string
  7048. type: object
  7049. privatekey:
  7050. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  7051. properties:
  7052. key:
  7053. description: |-
  7054. A key in the referenced Secret.
  7055. Some instances of this field may be defaulted, in others it may be required.
  7056. maxLength: 253
  7057. minLength: 1
  7058. pattern: ^[-._a-zA-Z0-9]+$
  7059. type: string
  7060. name:
  7061. description: The name of the Secret resource being referred to.
  7062. maxLength: 253
  7063. minLength: 1
  7064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7065. type: string
  7066. namespace:
  7067. description: |-
  7068. The namespace of the Secret resource being referred to.
  7069. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7070. maxLength: 63
  7071. minLength: 1
  7072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7073. type: string
  7074. type: object
  7075. required:
  7076. - fingerprint
  7077. - privatekey
  7078. type: object
  7079. tenancy:
  7080. description: Tenancy is the tenancy OCID where user is located.
  7081. type: string
  7082. user:
  7083. description: User is an access OCID specific to the account.
  7084. type: string
  7085. required:
  7086. - secretRef
  7087. - tenancy
  7088. - user
  7089. type: object
  7090. compartment:
  7091. description: |-
  7092. Compartment is the vault compartment OCID.
  7093. Required for PushSecret
  7094. type: string
  7095. encryptionKey:
  7096. description: |-
  7097. EncryptionKey is the OCID of the encryption key within the vault.
  7098. Required for PushSecret
  7099. type: string
  7100. principalType:
  7101. description: |-
  7102. The type of principal to use for authentication. If left blank, the Auth struct will
  7103. determine the principal type. This optional field must be specified if using
  7104. workload identity.
  7105. enum:
  7106. - ""
  7107. - UserPrincipal
  7108. - InstancePrincipal
  7109. - Workload
  7110. type: string
  7111. region:
  7112. description: Region is the region where vault is located.
  7113. type: string
  7114. serviceAccountRef:
  7115. description: |-
  7116. ServiceAccountRef specified the service account
  7117. that should be used when authenticating with WorkloadIdentity.
  7118. properties:
  7119. audiences:
  7120. description: |-
  7121. Audience specifies the `aud` claim for the service account token
  7122. Some providers automatically extend the audience field based on well-known annotations for workload
  7123. identity (e.g. IRSA or GCP Workload Identity)
  7124. items:
  7125. type: string
  7126. type: array
  7127. name:
  7128. description: The name of the ServiceAccount resource being referred to.
  7129. maxLength: 253
  7130. minLength: 1
  7131. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7132. type: string
  7133. namespace:
  7134. description: |-
  7135. Namespace of the resource being referred to.
  7136. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7137. maxLength: 63
  7138. minLength: 1
  7139. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7140. type: string
  7141. required:
  7142. - name
  7143. type: object
  7144. vault:
  7145. description: Vault is the vault's OCID of the specific vault where secret is located.
  7146. type: string
  7147. required:
  7148. - region
  7149. - vault
  7150. type: object
  7151. ovh:
  7152. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  7153. properties:
  7154. auth:
  7155. description: Authentication method (mtls or token).
  7156. properties:
  7157. mtls:
  7158. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  7159. properties:
  7160. caBundle:
  7161. format: byte
  7162. type: string
  7163. caProvider:
  7164. description: |-
  7165. CAProvider provides a custom certificate authority for accessing the provider's store.
  7166. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  7167. properties:
  7168. key:
  7169. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7170. maxLength: 253
  7171. minLength: 1
  7172. pattern: ^[-._a-zA-Z0-9]+$
  7173. type: string
  7174. name:
  7175. description: The name of the object located at the provider type.
  7176. maxLength: 253
  7177. minLength: 1
  7178. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7179. type: string
  7180. namespace:
  7181. description: |-
  7182. The namespace the Provider type is in.
  7183. Can only be defined when used in a ClusterSecretStore.
  7184. maxLength: 63
  7185. minLength: 1
  7186. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7187. type: string
  7188. type:
  7189. description: The type of provider to use such as "Secret", or "ConfigMap".
  7190. enum:
  7191. - Secret
  7192. - ConfigMap
  7193. type: string
  7194. required:
  7195. - name
  7196. - type
  7197. type: object
  7198. certSecretRef:
  7199. description: |-
  7200. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7201. In some instances, `key` is a required field.
  7202. properties:
  7203. key:
  7204. description: |-
  7205. A key in the referenced Secret.
  7206. Some instances of this field may be defaulted, in others it may be required.
  7207. maxLength: 253
  7208. minLength: 1
  7209. pattern: ^[-._a-zA-Z0-9]+$
  7210. type: string
  7211. name:
  7212. description: The name of the Secret resource being referred to.
  7213. maxLength: 253
  7214. minLength: 1
  7215. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7216. type: string
  7217. namespace:
  7218. description: |-
  7219. The namespace of the Secret resource being referred to.
  7220. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7221. maxLength: 63
  7222. minLength: 1
  7223. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7224. type: string
  7225. type: object
  7226. keySecretRef:
  7227. description: |-
  7228. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7229. In some instances, `key` is a required field.
  7230. properties:
  7231. key:
  7232. description: |-
  7233. A key in the referenced Secret.
  7234. Some instances of this field may be defaulted, in others it may be required.
  7235. maxLength: 253
  7236. minLength: 1
  7237. pattern: ^[-._a-zA-Z0-9]+$
  7238. type: string
  7239. name:
  7240. description: The name of the Secret resource being referred to.
  7241. maxLength: 253
  7242. minLength: 1
  7243. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7244. type: string
  7245. namespace:
  7246. description: |-
  7247. The namespace of the Secret resource being referred to.
  7248. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7249. maxLength: 63
  7250. minLength: 1
  7251. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7252. type: string
  7253. type: object
  7254. required:
  7255. - certSecretRef
  7256. - keySecretRef
  7257. type: object
  7258. token:
  7259. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  7260. properties:
  7261. tokenSecretRef:
  7262. description: |-
  7263. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7264. In some instances, `key` is a required field.
  7265. properties:
  7266. key:
  7267. description: |-
  7268. A key in the referenced Secret.
  7269. Some instances of this field may be defaulted, in others it may be required.
  7270. maxLength: 253
  7271. minLength: 1
  7272. pattern: ^[-._a-zA-Z0-9]+$
  7273. type: string
  7274. name:
  7275. description: The name of the Secret resource being referred to.
  7276. maxLength: 253
  7277. minLength: 1
  7278. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7279. type: string
  7280. namespace:
  7281. description: |-
  7282. The namespace of the Secret resource being referred to.
  7283. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7284. maxLength: 63
  7285. minLength: 1
  7286. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7287. type: string
  7288. type: object
  7289. required:
  7290. - tokenSecretRef
  7291. type: object
  7292. type: object
  7293. casRequired:
  7294. description: 'Enables or disables check-and-set (CAS) (default: false).'
  7295. type: boolean
  7296. okmsTimeout:
  7297. default: 30
  7298. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  7299. format: int32
  7300. minimum: 1
  7301. type: integer
  7302. okmsid:
  7303. description: specifies the OKMS ID.
  7304. type: string
  7305. server:
  7306. description: specifies the OKMS server endpoint.
  7307. type: string
  7308. required:
  7309. - auth
  7310. - okmsid
  7311. - server
  7312. type: object
  7313. passbolt:
  7314. description: |-
  7315. PassboltProvider provides access to Passbolt secrets manager.
  7316. See: https://www.passbolt.com.
  7317. properties:
  7318. auth:
  7319. description: Auth defines the information necessary to authenticate against Passbolt Server
  7320. properties:
  7321. passwordSecretRef:
  7322. description: |-
  7323. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7324. In some instances, `key` is a required field.
  7325. properties:
  7326. key:
  7327. description: |-
  7328. A key in the referenced Secret.
  7329. Some instances of this field may be defaulted, in others it may be required.
  7330. maxLength: 253
  7331. minLength: 1
  7332. pattern: ^[-._a-zA-Z0-9]+$
  7333. type: string
  7334. name:
  7335. description: The name of the Secret resource being referred to.
  7336. maxLength: 253
  7337. minLength: 1
  7338. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7339. type: string
  7340. namespace:
  7341. description: |-
  7342. The namespace of the Secret resource being referred to.
  7343. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7344. maxLength: 63
  7345. minLength: 1
  7346. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7347. type: string
  7348. type: object
  7349. privateKeySecretRef:
  7350. description: |-
  7351. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7352. In some instances, `key` is a required field.
  7353. properties:
  7354. key:
  7355. description: |-
  7356. A key in the referenced Secret.
  7357. Some instances of this field may be defaulted, in others it may be required.
  7358. maxLength: 253
  7359. minLength: 1
  7360. pattern: ^[-._a-zA-Z0-9]+$
  7361. type: string
  7362. name:
  7363. description: The name of the Secret resource being referred to.
  7364. maxLength: 253
  7365. minLength: 1
  7366. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7367. type: string
  7368. namespace:
  7369. description: |-
  7370. The namespace of the Secret resource being referred to.
  7371. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7372. maxLength: 63
  7373. minLength: 1
  7374. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7375. type: string
  7376. type: object
  7377. required:
  7378. - passwordSecretRef
  7379. - privateKeySecretRef
  7380. type: object
  7381. caBundle:
  7382. description: |-
  7383. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  7384. if the Host URL is using HTTPS protocol. If not set the system root certificates
  7385. are used to validate the TLS connection.
  7386. format: byte
  7387. type: string
  7388. caProvider:
  7389. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  7390. properties:
  7391. key:
  7392. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7393. maxLength: 253
  7394. minLength: 1
  7395. pattern: ^[-._a-zA-Z0-9]+$
  7396. type: string
  7397. name:
  7398. description: The name of the object located at the provider type.
  7399. maxLength: 253
  7400. minLength: 1
  7401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7402. type: string
  7403. namespace:
  7404. description: |-
  7405. The namespace the Provider type is in.
  7406. Can only be defined when used in a ClusterSecretStore.
  7407. maxLength: 63
  7408. minLength: 1
  7409. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7410. type: string
  7411. type:
  7412. description: The type of provider to use such as "Secret", or "ConfigMap".
  7413. enum:
  7414. - Secret
  7415. - ConfigMap
  7416. type: string
  7417. required:
  7418. - name
  7419. - type
  7420. type: object
  7421. host:
  7422. description: Host defines the Passbolt Server to connect to
  7423. type: string
  7424. required:
  7425. - auth
  7426. - host
  7427. type: object
  7428. passworddepot:
  7429. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  7430. properties:
  7431. auth:
  7432. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  7433. properties:
  7434. secretRef:
  7435. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  7436. properties:
  7437. credentials:
  7438. description: Username / Password is used for authentication.
  7439. properties:
  7440. key:
  7441. description: |-
  7442. A key in the referenced Secret.
  7443. Some instances of this field may be defaulted, in others it may be required.
  7444. maxLength: 253
  7445. minLength: 1
  7446. pattern: ^[-._a-zA-Z0-9]+$
  7447. type: string
  7448. name:
  7449. description: The name of the Secret resource being referred to.
  7450. maxLength: 253
  7451. minLength: 1
  7452. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7453. type: string
  7454. namespace:
  7455. description: |-
  7456. The namespace of the Secret resource being referred to.
  7457. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7458. maxLength: 63
  7459. minLength: 1
  7460. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7461. type: string
  7462. type: object
  7463. type: object
  7464. required:
  7465. - secretRef
  7466. type: object
  7467. database:
  7468. description: Database to use as source
  7469. type: string
  7470. host:
  7471. description: URL configures the Password Depot instance URL.
  7472. type: string
  7473. required:
  7474. - auth
  7475. - database
  7476. - host
  7477. type: object
  7478. previder:
  7479. description: Previder configures this store to sync secrets using the Previder provider
  7480. properties:
  7481. auth:
  7482. description: PreviderAuth contains a secretRef for credentials.
  7483. properties:
  7484. secretRef:
  7485. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  7486. properties:
  7487. accessToken:
  7488. description: The AccessToken is used for authentication
  7489. properties:
  7490. key:
  7491. description: |-
  7492. A key in the referenced Secret.
  7493. Some instances of this field may be defaulted, in others it may be required.
  7494. maxLength: 253
  7495. minLength: 1
  7496. pattern: ^[-._a-zA-Z0-9]+$
  7497. type: string
  7498. name:
  7499. description: The name of the Secret resource being referred to.
  7500. maxLength: 253
  7501. minLength: 1
  7502. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7503. type: string
  7504. namespace:
  7505. description: |-
  7506. The namespace of the Secret resource being referred to.
  7507. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7508. maxLength: 63
  7509. minLength: 1
  7510. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7511. type: string
  7512. type: object
  7513. required:
  7514. - accessToken
  7515. type: object
  7516. type: object
  7517. baseUri:
  7518. type: string
  7519. required:
  7520. - auth
  7521. type: object
  7522. pulumi:
  7523. description: Pulumi configures this store to sync secrets using the Pulumi provider
  7524. properties:
  7525. accessToken:
  7526. description: |-
  7527. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  7528. Deprecated: Use auth.accessToken instead.
  7529. properties:
  7530. secretRef:
  7531. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7532. properties:
  7533. key:
  7534. description: |-
  7535. A key in the referenced Secret.
  7536. Some instances of this field may be defaulted, in others it may be required.
  7537. maxLength: 253
  7538. minLength: 1
  7539. pattern: ^[-._a-zA-Z0-9]+$
  7540. type: string
  7541. name:
  7542. description: The name of the Secret resource being referred to.
  7543. maxLength: 253
  7544. minLength: 1
  7545. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7546. type: string
  7547. namespace:
  7548. description: |-
  7549. The namespace of the Secret resource being referred to.
  7550. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7551. maxLength: 63
  7552. minLength: 1
  7553. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7554. type: string
  7555. type: object
  7556. type: object
  7557. apiUrl:
  7558. default: https://api.pulumi.com/api/esc
  7559. description: APIURL is the URL of the Pulumi API.
  7560. type: string
  7561. auth:
  7562. description: |-
  7563. Auth configures how the Operator authenticates with the Pulumi API.
  7564. Either auth or the deprecated accessToken field must be specified.
  7565. properties:
  7566. accessToken:
  7567. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  7568. properties:
  7569. secretRef:
  7570. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7571. properties:
  7572. key:
  7573. description: |-
  7574. A key in the referenced Secret.
  7575. Some instances of this field may be defaulted, in others it may be required.
  7576. maxLength: 253
  7577. minLength: 1
  7578. pattern: ^[-._a-zA-Z0-9]+$
  7579. type: string
  7580. name:
  7581. description: The name of the Secret resource being referred to.
  7582. maxLength: 253
  7583. minLength: 1
  7584. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7585. type: string
  7586. namespace:
  7587. description: |-
  7588. The namespace of the Secret resource being referred to.
  7589. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7590. maxLength: 63
  7591. minLength: 1
  7592. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7593. type: string
  7594. type: object
  7595. type: object
  7596. oidcConfig:
  7597. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  7598. properties:
  7599. expirationSeconds:
  7600. default: 600
  7601. description: |-
  7602. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  7603. Defaults to 10 minutes.
  7604. format: int64
  7605. minimum: 600
  7606. type: integer
  7607. organization:
  7608. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  7609. type: string
  7610. serviceAccountRef:
  7611. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  7612. properties:
  7613. audiences:
  7614. description: |-
  7615. Audience specifies the `aud` claim for the service account token
  7616. Some providers automatically extend the audience field based on well-known annotations for workload
  7617. identity (e.g. IRSA or GCP Workload Identity)
  7618. items:
  7619. type: string
  7620. type: array
  7621. name:
  7622. description: The name of the ServiceAccount resource being referred to.
  7623. maxLength: 253
  7624. minLength: 1
  7625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7626. type: string
  7627. namespace:
  7628. description: |-
  7629. Namespace of the resource being referred to.
  7630. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7631. maxLength: 63
  7632. minLength: 1
  7633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7634. type: string
  7635. required:
  7636. - name
  7637. type: object
  7638. required:
  7639. - organization
  7640. - serviceAccountRef
  7641. type: object
  7642. type: object
  7643. x-kubernetes-validations:
  7644. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  7645. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  7646. environment:
  7647. description: |-
  7648. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  7649. dynamically retrieved values from supported providers including all major clouds,
  7650. and other Pulumi ESC environments.
  7651. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  7652. type: string
  7653. organization:
  7654. description: |-
  7655. Organization are a space to collaborate on shared projects and stacks.
  7656. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  7657. type: string
  7658. project:
  7659. description: Project is the name of the Pulumi ESC project the environment belongs to.
  7660. type: string
  7661. required:
  7662. - environment
  7663. - organization
  7664. - project
  7665. type: object
  7666. x-kubernetes-validations:
  7667. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  7668. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  7669. scaleway:
  7670. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  7671. properties:
  7672. accessKey:
  7673. description: AccessKey is the non-secret part of the api key.
  7674. properties:
  7675. secretRef:
  7676. description: SecretRef references a key in a secret that will be used as value.
  7677. properties:
  7678. key:
  7679. description: |-
  7680. A key in the referenced Secret.
  7681. Some instances of this field may be defaulted, in others it may be required.
  7682. maxLength: 253
  7683. minLength: 1
  7684. pattern: ^[-._a-zA-Z0-9]+$
  7685. type: string
  7686. name:
  7687. description: The name of the Secret resource being referred to.
  7688. maxLength: 253
  7689. minLength: 1
  7690. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7691. type: string
  7692. namespace:
  7693. description: |-
  7694. The namespace of the Secret resource being referred to.
  7695. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7696. maxLength: 63
  7697. minLength: 1
  7698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7699. type: string
  7700. type: object
  7701. value:
  7702. description: Value can be specified directly to set a value without using a secret.
  7703. type: string
  7704. type: object
  7705. apiUrl:
  7706. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  7707. type: string
  7708. projectId:
  7709. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  7710. type: string
  7711. region:
  7712. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  7713. type: string
  7714. secretKey:
  7715. description: SecretKey is the non-secret part of the api key.
  7716. properties:
  7717. secretRef:
  7718. description: SecretRef references a key in a secret that will be used as value.
  7719. properties:
  7720. key:
  7721. description: |-
  7722. A key in the referenced Secret.
  7723. Some instances of this field may be defaulted, in others it may be required.
  7724. maxLength: 253
  7725. minLength: 1
  7726. pattern: ^[-._a-zA-Z0-9]+$
  7727. type: string
  7728. name:
  7729. description: The name of the Secret resource being referred to.
  7730. maxLength: 253
  7731. minLength: 1
  7732. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7733. type: string
  7734. namespace:
  7735. description: |-
  7736. The namespace of the Secret resource being referred to.
  7737. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7738. maxLength: 63
  7739. minLength: 1
  7740. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7741. type: string
  7742. type: object
  7743. value:
  7744. description: Value can be specified directly to set a value without using a secret.
  7745. type: string
  7746. type: object
  7747. required:
  7748. - accessKey
  7749. - projectId
  7750. - region
  7751. - secretKey
  7752. type: object
  7753. secretserver:
  7754. description: |-
  7755. SecretServer configures this store to sync secrets using SecretServer provider
  7756. https://docs.delinea.com/online-help/secret-server/start.htm
  7757. properties:
  7758. caBundle:
  7759. description: |-
  7760. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  7761. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  7762. are used to validate the TLS connection.
  7763. format: byte
  7764. type: string
  7765. caProvider:
  7766. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  7767. properties:
  7768. key:
  7769. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7770. maxLength: 253
  7771. minLength: 1
  7772. pattern: ^[-._a-zA-Z0-9]+$
  7773. type: string
  7774. name:
  7775. description: The name of the object located at the provider type.
  7776. maxLength: 253
  7777. minLength: 1
  7778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7779. type: string
  7780. namespace:
  7781. description: |-
  7782. The namespace the Provider type is in.
  7783. Can only be defined when used in a ClusterSecretStore.
  7784. maxLength: 63
  7785. minLength: 1
  7786. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7787. type: string
  7788. type:
  7789. description: The type of provider to use such as "Secret", or "ConfigMap".
  7790. enum:
  7791. - Secret
  7792. - ConfigMap
  7793. type: string
  7794. required:
  7795. - name
  7796. - type
  7797. type: object
  7798. disableSiteIDValidation:
  7799. description: |-
  7800. DisableSiteIDValidation permits a missing site ID for new secrets.
  7801. The provider sends 0 if no site ID is set.
  7802. type: boolean
  7803. domain:
  7804. description: Domain is the secret server domain.
  7805. type: string
  7806. password:
  7807. description: |-
  7808. Password is the secret server account password.
  7809. Required unless Token is set.
  7810. properties:
  7811. secretRef:
  7812. description: SecretRef references a key in a secret that will be used as value.
  7813. properties:
  7814. key:
  7815. description: |-
  7816. A key in the referenced Secret.
  7817. Some instances of this field may be defaulted, in others it may be required.
  7818. maxLength: 253
  7819. minLength: 1
  7820. pattern: ^[-._a-zA-Z0-9]+$
  7821. type: string
  7822. name:
  7823. description: The name of the Secret resource being referred to.
  7824. maxLength: 253
  7825. minLength: 1
  7826. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7827. type: string
  7828. namespace:
  7829. description: |-
  7830. The namespace of the Secret resource being referred to.
  7831. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7832. maxLength: 63
  7833. minLength: 1
  7834. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7835. type: string
  7836. type: object
  7837. value:
  7838. description: Value can be specified directly to set a value without using a secret.
  7839. minLength: 1
  7840. type: string
  7841. type: object
  7842. x-kubernetes-validations:
  7843. - message: exactly one of value or secretRef must be set
  7844. rule: has(self.value) != has(self.secretRef)
  7845. serverURL:
  7846. description: |-
  7847. ServerURL
  7848. URL to your secret server installation
  7849. type: string
  7850. siteId:
  7851. description: |-
  7852. SiteID is the ID of the Secret Server site for new secrets.
  7853. PushSecret metadata can override this value for one secret.
  7854. The provider uses 1 if this field is not set.
  7855. minimum: 1
  7856. type: integer
  7857. token:
  7858. description: |-
  7859. Token is an access token used to authenticate to the secret server,
  7860. as an alternative to Username and Password. When set, Username and
  7861. Password are not required and are ignored.
  7862. properties:
  7863. secretRef:
  7864. description: SecretRef references a key in a secret that will be used as value.
  7865. properties:
  7866. key:
  7867. description: |-
  7868. A key in the referenced Secret.
  7869. Some instances of this field may be defaulted, in others it may be required.
  7870. maxLength: 253
  7871. minLength: 1
  7872. pattern: ^[-._a-zA-Z0-9]+$
  7873. type: string
  7874. name:
  7875. description: The name of the Secret resource being referred to.
  7876. maxLength: 253
  7877. minLength: 1
  7878. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7879. type: string
  7880. namespace:
  7881. description: |-
  7882. The namespace of the Secret resource being referred to.
  7883. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7884. maxLength: 63
  7885. minLength: 1
  7886. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7887. type: string
  7888. type: object
  7889. value:
  7890. description: Value can be specified directly to set a value without using a secret.
  7891. minLength: 1
  7892. type: string
  7893. type: object
  7894. x-kubernetes-validations:
  7895. - message: exactly one of value or secretRef must be set
  7896. rule: has(self.value) != has(self.secretRef)
  7897. username:
  7898. description: |-
  7899. Username is the secret server account username.
  7900. Required unless Token is set.
  7901. properties:
  7902. secretRef:
  7903. description: SecretRef references a key in a secret that will be used as value.
  7904. properties:
  7905. key:
  7906. description: |-
  7907. A key in the referenced Secret.
  7908. Some instances of this field may be defaulted, in others it may be required.
  7909. maxLength: 253
  7910. minLength: 1
  7911. pattern: ^[-._a-zA-Z0-9]+$
  7912. type: string
  7913. name:
  7914. description: The name of the Secret resource being referred to.
  7915. maxLength: 253
  7916. minLength: 1
  7917. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7918. type: string
  7919. namespace:
  7920. description: |-
  7921. The namespace of the Secret resource being referred to.
  7922. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7923. maxLength: 63
  7924. minLength: 1
  7925. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7926. type: string
  7927. type: object
  7928. value:
  7929. description: Value can be specified directly to set a value without using a secret.
  7930. minLength: 1
  7931. type: string
  7932. type: object
  7933. x-kubernetes-validations:
  7934. - message: exactly one of value or secretRef must be set
  7935. rule: has(self.value) != has(self.secretRef)
  7936. required:
  7937. - serverURL
  7938. type: object
  7939. x-kubernetes-validations:
  7940. - message: either token, or both username and password, must be set
  7941. rule: has(self.token) || (has(self.username) && has(self.password))
  7942. senhasegura:
  7943. description: Senhasegura configures this store to sync secrets using senhasegura provider
  7944. properties:
  7945. auth:
  7946. description: Auth defines parameters to authenticate in senhasegura
  7947. properties:
  7948. clientId:
  7949. type: string
  7950. clientSecretSecretRef:
  7951. description: |-
  7952. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7953. In some instances, `key` is a required field.
  7954. properties:
  7955. key:
  7956. description: |-
  7957. A key in the referenced Secret.
  7958. Some instances of this field may be defaulted, in others it may be required.
  7959. maxLength: 253
  7960. minLength: 1
  7961. pattern: ^[-._a-zA-Z0-9]+$
  7962. type: string
  7963. name:
  7964. description: The name of the Secret resource being referred to.
  7965. maxLength: 253
  7966. minLength: 1
  7967. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7968. type: string
  7969. namespace:
  7970. description: |-
  7971. The namespace of the Secret resource being referred to.
  7972. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7973. maxLength: 63
  7974. minLength: 1
  7975. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7976. type: string
  7977. type: object
  7978. required:
  7979. - clientId
  7980. - clientSecretSecretRef
  7981. type: object
  7982. ignoreSslCertificate:
  7983. default: false
  7984. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  7985. type: boolean
  7986. module:
  7987. description: Module defines which senhasegura module should be used to get secrets
  7988. type: string
  7989. url:
  7990. description: URL of senhasegura
  7991. type: string
  7992. required:
  7993. - auth
  7994. - module
  7995. - url
  7996. type: object
  7997. vault:
  7998. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  7999. properties:
  8000. auth:
  8001. description: Auth configures how secret-manager authenticates with the Vault server.
  8002. properties:
  8003. appRole:
  8004. description: |-
  8005. AppRole authenticates with Vault using the App Role auth mechanism,
  8006. with the role and secret stored in a Kubernetes Secret resource.
  8007. properties:
  8008. path:
  8009. default: approle
  8010. description: |-
  8011. Path where the App Role authentication backend is mounted
  8012. in Vault, e.g: "approle"
  8013. type: string
  8014. roleId:
  8015. description: |-
  8016. RoleID configured in the App Role authentication backend when setting
  8017. up the authentication backend in Vault.
  8018. type: string
  8019. roleRef:
  8020. description: |-
  8021. Reference to a key in a Secret that contains the App Role ID used
  8022. to authenticate with Vault.
  8023. The `key` field must be specified and denotes which entry within the Secret
  8024. resource is used as the app role id.
  8025. properties:
  8026. key:
  8027. description: |-
  8028. A key in the referenced Secret.
  8029. Some instances of this field may be defaulted, in others it may be required.
  8030. maxLength: 253
  8031. minLength: 1
  8032. pattern: ^[-._a-zA-Z0-9]+$
  8033. type: string
  8034. name:
  8035. description: The name of the Secret resource being referred to.
  8036. maxLength: 253
  8037. minLength: 1
  8038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8039. type: string
  8040. namespace:
  8041. description: |-
  8042. The namespace of the Secret resource being referred to.
  8043. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8044. maxLength: 63
  8045. minLength: 1
  8046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8047. type: string
  8048. type: object
  8049. secretRef:
  8050. description: |-
  8051. Reference to a key in a Secret that contains the App Role secret used
  8052. to authenticate with Vault.
  8053. The `key` field must be specified and denotes which entry within the Secret
  8054. resource is used as the app role secret.
  8055. properties:
  8056. key:
  8057. description: |-
  8058. A key in the referenced Secret.
  8059. Some instances of this field may be defaulted, in others it may be required.
  8060. maxLength: 253
  8061. minLength: 1
  8062. pattern: ^[-._a-zA-Z0-9]+$
  8063. type: string
  8064. name:
  8065. description: The name of the Secret resource being referred to.
  8066. maxLength: 253
  8067. minLength: 1
  8068. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8069. type: string
  8070. namespace:
  8071. description: |-
  8072. The namespace of the Secret resource being referred to.
  8073. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8074. maxLength: 63
  8075. minLength: 1
  8076. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8077. type: string
  8078. type: object
  8079. required:
  8080. - path
  8081. - secretRef
  8082. type: object
  8083. cert:
  8084. description: |-
  8085. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  8086. Cert authentication method
  8087. properties:
  8088. clientCert:
  8089. description: |-
  8090. ClientCert is a certificate to authenticate using the Cert Vault
  8091. authentication method
  8092. properties:
  8093. key:
  8094. description: |-
  8095. A key in the referenced Secret.
  8096. Some instances of this field may be defaulted, in others it may be required.
  8097. maxLength: 253
  8098. minLength: 1
  8099. pattern: ^[-._a-zA-Z0-9]+$
  8100. type: string
  8101. name:
  8102. description: The name of the Secret resource being referred to.
  8103. maxLength: 253
  8104. minLength: 1
  8105. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8106. type: string
  8107. namespace:
  8108. description: |-
  8109. The namespace of the Secret resource being referred to.
  8110. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8111. maxLength: 63
  8112. minLength: 1
  8113. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8114. type: string
  8115. type: object
  8116. path:
  8117. default: cert
  8118. description: |-
  8119. Path where the Certificate authentication backend is mounted
  8120. in Vault, e.g: "cert"
  8121. type: string
  8122. secretRef:
  8123. description: |-
  8124. SecretRef to a key in a Secret resource containing client private key to
  8125. authenticate with Vault using the Cert authentication method
  8126. properties:
  8127. key:
  8128. description: |-
  8129. A key in the referenced Secret.
  8130. Some instances of this field may be defaulted, in others it may be required.
  8131. maxLength: 253
  8132. minLength: 1
  8133. pattern: ^[-._a-zA-Z0-9]+$
  8134. type: string
  8135. name:
  8136. description: The name of the Secret resource being referred to.
  8137. maxLength: 253
  8138. minLength: 1
  8139. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8140. type: string
  8141. namespace:
  8142. description: |-
  8143. The namespace of the Secret resource being referred to.
  8144. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8145. maxLength: 63
  8146. minLength: 1
  8147. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8148. type: string
  8149. type: object
  8150. vaultRole:
  8151. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  8152. type: string
  8153. type: object
  8154. gcp:
  8155. description: |-
  8156. Gcp authenticates with Vault using Google Cloud Platform authentication method
  8157. GCP authentication method
  8158. properties:
  8159. location:
  8160. description: Location optionally defines a location/region for the secret
  8161. type: string
  8162. path:
  8163. default: gcp
  8164. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  8165. type: string
  8166. projectID:
  8167. description: Project ID of the Google Cloud Platform project
  8168. type: string
  8169. role:
  8170. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  8171. type: string
  8172. secretRef:
  8173. description: Specify credentials in a Secret object
  8174. properties:
  8175. secretAccessKeySecretRef:
  8176. description: The SecretAccessKey is used for authentication
  8177. properties:
  8178. key:
  8179. description: |-
  8180. A key in the referenced Secret.
  8181. Some instances of this field may be defaulted, in others it may be required.
  8182. maxLength: 253
  8183. minLength: 1
  8184. pattern: ^[-._a-zA-Z0-9]+$
  8185. type: string
  8186. name:
  8187. description: The name of the Secret resource being referred to.
  8188. maxLength: 253
  8189. minLength: 1
  8190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8191. type: string
  8192. namespace:
  8193. description: |-
  8194. The namespace of the Secret resource being referred to.
  8195. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8196. maxLength: 63
  8197. minLength: 1
  8198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8199. type: string
  8200. type: object
  8201. type: object
  8202. serviceAccountRef:
  8203. description: ServiceAccountRef to a service account for impersonation
  8204. properties:
  8205. audiences:
  8206. description: |-
  8207. Audience specifies the `aud` claim for the service account token
  8208. Some providers automatically extend the audience field based on well-known annotations for workload
  8209. identity (e.g. IRSA or GCP Workload Identity)
  8210. items:
  8211. type: string
  8212. type: array
  8213. name:
  8214. description: The name of the ServiceAccount resource being referred to.
  8215. maxLength: 253
  8216. minLength: 1
  8217. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8218. type: string
  8219. namespace:
  8220. description: |-
  8221. Namespace of the resource being referred to.
  8222. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8223. maxLength: 63
  8224. minLength: 1
  8225. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8226. type: string
  8227. required:
  8228. - name
  8229. type: object
  8230. workloadIdentity:
  8231. description: Specify a service account with Workload Identity
  8232. properties:
  8233. clusterLocation:
  8234. description: |-
  8235. ClusterLocation is the location of the cluster
  8236. If not specified, it fetches information from the metadata server
  8237. type: string
  8238. clusterName:
  8239. description: |-
  8240. ClusterName is the name of the cluster
  8241. If not specified, it fetches information from the metadata server
  8242. type: string
  8243. clusterProjectID:
  8244. description: |-
  8245. ClusterProjectID is the project ID of the cluster
  8246. If not specified, it fetches information from the metadata server
  8247. type: string
  8248. serviceAccountRef:
  8249. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  8250. properties:
  8251. audiences:
  8252. description: |-
  8253. Audience specifies the `aud` claim for the service account token
  8254. Some providers automatically extend the audience field based on well-known annotations for workload
  8255. identity (e.g. IRSA or GCP Workload Identity)
  8256. items:
  8257. type: string
  8258. type: array
  8259. name:
  8260. description: The name of the ServiceAccount resource being referred to.
  8261. maxLength: 253
  8262. minLength: 1
  8263. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8264. type: string
  8265. namespace:
  8266. description: |-
  8267. Namespace of the resource being referred to.
  8268. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8269. maxLength: 63
  8270. minLength: 1
  8271. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8272. type: string
  8273. required:
  8274. - name
  8275. type: object
  8276. required:
  8277. - serviceAccountRef
  8278. type: object
  8279. required:
  8280. - role
  8281. type: object
  8282. iam:
  8283. description: |-
  8284. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  8285. AWS IAM authentication method
  8286. properties:
  8287. externalID:
  8288. description: AWS External ID set on assumed IAM roles
  8289. type: string
  8290. jwt:
  8291. description: Specify a service account with IRSA enabled
  8292. properties:
  8293. serviceAccountRef:
  8294. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  8295. properties:
  8296. audiences:
  8297. description: |-
  8298. Audience specifies the `aud` claim for the service account token
  8299. Some providers automatically extend the audience field based on well-known annotations for workload
  8300. identity (e.g. IRSA or GCP Workload Identity)
  8301. items:
  8302. type: string
  8303. type: array
  8304. name:
  8305. description: The name of the ServiceAccount resource being referred to.
  8306. maxLength: 253
  8307. minLength: 1
  8308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8309. type: string
  8310. namespace:
  8311. description: |-
  8312. Namespace of the resource being referred to.
  8313. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8314. maxLength: 63
  8315. minLength: 1
  8316. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8317. type: string
  8318. required:
  8319. - name
  8320. type: object
  8321. type: object
  8322. path:
  8323. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  8324. type: string
  8325. region:
  8326. description: AWS region
  8327. type: string
  8328. role:
  8329. description: This is the AWS role to be assumed before talking to vault
  8330. type: string
  8331. secretRef:
  8332. description: Specify credentials in a Secret object
  8333. properties:
  8334. accessKeyIDSecretRef:
  8335. description: The AccessKeyID is used for authentication
  8336. properties:
  8337. key:
  8338. description: |-
  8339. A key in the referenced Secret.
  8340. Some instances of this field may be defaulted, in others it may be required.
  8341. maxLength: 253
  8342. minLength: 1
  8343. pattern: ^[-._a-zA-Z0-9]+$
  8344. type: string
  8345. name:
  8346. description: The name of the Secret resource being referred to.
  8347. maxLength: 253
  8348. minLength: 1
  8349. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8350. type: string
  8351. namespace:
  8352. description: |-
  8353. The namespace of the Secret resource being referred to.
  8354. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8355. maxLength: 63
  8356. minLength: 1
  8357. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8358. type: string
  8359. type: object
  8360. secretAccessKeySecretRef:
  8361. description: The SecretAccessKey is used for authentication
  8362. properties:
  8363. key:
  8364. description: |-
  8365. A key in the referenced Secret.
  8366. Some instances of this field may be defaulted, in others it may be required.
  8367. maxLength: 253
  8368. minLength: 1
  8369. pattern: ^[-._a-zA-Z0-9]+$
  8370. type: string
  8371. name:
  8372. description: The name of the Secret resource being referred to.
  8373. maxLength: 253
  8374. minLength: 1
  8375. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8376. type: string
  8377. namespace:
  8378. description: |-
  8379. The namespace of the Secret resource being referred to.
  8380. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8381. maxLength: 63
  8382. minLength: 1
  8383. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8384. type: string
  8385. type: object
  8386. sessionTokenSecretRef:
  8387. description: |-
  8388. The SessionToken used for authentication
  8389. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  8390. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  8391. properties:
  8392. key:
  8393. description: |-
  8394. A key in the referenced Secret.
  8395. Some instances of this field may be defaulted, in others it may be required.
  8396. maxLength: 253
  8397. minLength: 1
  8398. pattern: ^[-._a-zA-Z0-9]+$
  8399. type: string
  8400. name:
  8401. description: The name of the Secret resource being referred to.
  8402. maxLength: 253
  8403. minLength: 1
  8404. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8405. type: string
  8406. namespace:
  8407. description: |-
  8408. The namespace of the Secret resource being referred to.
  8409. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8410. maxLength: 63
  8411. minLength: 1
  8412. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8413. type: string
  8414. type: object
  8415. type: object
  8416. vaultAwsIamServerID:
  8417. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  8418. type: string
  8419. vaultRole:
  8420. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  8421. type: string
  8422. required:
  8423. - vaultRole
  8424. type: object
  8425. jwt:
  8426. description: |-
  8427. Jwt authenticates with Vault by passing role and JWT token using the
  8428. JWT/OIDC authentication method
  8429. properties:
  8430. kubernetesServiceAccountToken:
  8431. description: |-
  8432. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  8433. a token for with the `TokenRequest` API.
  8434. properties:
  8435. audiences:
  8436. description: |-
  8437. Optional audiences field that will be used to request a temporary Kubernetes service
  8438. account token for the service account referenced by `serviceAccountRef`.
  8439. Defaults to a single audience `vault` it not specified.
  8440. Deprecated: use serviceAccountRef.Audiences instead
  8441. items:
  8442. type: string
  8443. type: array
  8444. expirationSeconds:
  8445. description: |-
  8446. Optional expiration time in seconds that will be used to request a temporary
  8447. Kubernetes service account token for the service account referenced by
  8448. `serviceAccountRef`.
  8449. Deprecated: this will be removed in the future.
  8450. Defaults to 10 minutes.
  8451. format: int64
  8452. type: integer
  8453. serviceAccountRef:
  8454. description: Service account field containing the name of a kubernetes ServiceAccount.
  8455. properties:
  8456. audiences:
  8457. description: |-
  8458. Audience specifies the `aud` claim for the service account token
  8459. Some providers automatically extend the audience field based on well-known annotations for workload
  8460. identity (e.g. IRSA or GCP Workload Identity)
  8461. items:
  8462. type: string
  8463. type: array
  8464. name:
  8465. description: The name of the ServiceAccount resource being referred to.
  8466. maxLength: 253
  8467. minLength: 1
  8468. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8469. type: string
  8470. namespace:
  8471. description: |-
  8472. Namespace of the resource being referred to.
  8473. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8474. maxLength: 63
  8475. minLength: 1
  8476. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8477. type: string
  8478. required:
  8479. - name
  8480. type: object
  8481. required:
  8482. - serviceAccountRef
  8483. type: object
  8484. path:
  8485. default: jwt
  8486. description: |-
  8487. Path where the JWT authentication backend is mounted
  8488. in Vault, e.g: "jwt"
  8489. type: string
  8490. role:
  8491. description: |-
  8492. Role is a JWT role to authenticate using the JWT/OIDC Vault
  8493. authentication method
  8494. type: string
  8495. secretRef:
  8496. description: |-
  8497. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  8498. authenticate with Vault using the JWT/OIDC authentication method.
  8499. properties:
  8500. key:
  8501. description: |-
  8502. A key in the referenced Secret.
  8503. Some instances of this field may be defaulted, in others it may be required.
  8504. maxLength: 253
  8505. minLength: 1
  8506. pattern: ^[-._a-zA-Z0-9]+$
  8507. type: string
  8508. name:
  8509. description: The name of the Secret resource being referred to.
  8510. maxLength: 253
  8511. minLength: 1
  8512. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8513. type: string
  8514. namespace:
  8515. description: |-
  8516. The namespace of the Secret resource being referred to.
  8517. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8518. maxLength: 63
  8519. minLength: 1
  8520. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8521. type: string
  8522. type: object
  8523. required:
  8524. - path
  8525. type: object
  8526. kubernetes:
  8527. description: |-
  8528. Kubernetes authenticates with Vault by passing the ServiceAccount
  8529. token stored in the named Secret resource to the Vault server.
  8530. properties:
  8531. mountPath:
  8532. default: kubernetes
  8533. description: |-
  8534. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  8535. "kubernetes"
  8536. type: string
  8537. role:
  8538. description: |-
  8539. A required field containing the Vault Role to assume. A Role binds a
  8540. Kubernetes ServiceAccount with a set of Vault policies.
  8541. type: string
  8542. secretRef:
  8543. description: |-
  8544. Optional secret field containing a Kubernetes ServiceAccount JWT used
  8545. for authenticating with Vault. If a name is specified without a key,
  8546. `token` is the default. If one is not specified, the one bound to
  8547. the controller will be used.
  8548. properties:
  8549. key:
  8550. description: |-
  8551. A key in the referenced Secret.
  8552. Some instances of this field may be defaulted, in others it may be required.
  8553. maxLength: 253
  8554. minLength: 1
  8555. pattern: ^[-._a-zA-Z0-9]+$
  8556. type: string
  8557. name:
  8558. description: The name of the Secret resource being referred to.
  8559. maxLength: 253
  8560. minLength: 1
  8561. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8562. type: string
  8563. namespace:
  8564. description: |-
  8565. The namespace of the Secret resource being referred to.
  8566. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8567. maxLength: 63
  8568. minLength: 1
  8569. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8570. type: string
  8571. type: object
  8572. serviceAccountRef:
  8573. description: |-
  8574. Optional service account field containing the name of a kubernetes ServiceAccount.
  8575. If the service account is specified, the service account secret token JWT will be used
  8576. for authenticating with Vault. If the service account selector is not supplied,
  8577. the secretRef will be used instead.
  8578. properties:
  8579. audiences:
  8580. description: |-
  8581. Audience specifies the `aud` claim for the service account token
  8582. Some providers automatically extend the audience field based on well-known annotations for workload
  8583. identity (e.g. IRSA or GCP Workload Identity)
  8584. items:
  8585. type: string
  8586. type: array
  8587. name:
  8588. description: The name of the ServiceAccount resource being referred to.
  8589. maxLength: 253
  8590. minLength: 1
  8591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8592. type: string
  8593. namespace:
  8594. description: |-
  8595. Namespace of the resource being referred to.
  8596. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8597. maxLength: 63
  8598. minLength: 1
  8599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8600. type: string
  8601. required:
  8602. - name
  8603. type: object
  8604. required:
  8605. - mountPath
  8606. - role
  8607. type: object
  8608. ldap:
  8609. description: |-
  8610. Ldap authenticates with Vault by passing username/password pair using
  8611. the LDAP authentication method
  8612. properties:
  8613. path:
  8614. default: ldap
  8615. description: |-
  8616. Path where the LDAP authentication backend is mounted
  8617. in Vault, e.g: "ldap"
  8618. type: string
  8619. secretRef:
  8620. description: |-
  8621. SecretRef to a key in a Secret resource containing password for the LDAP
  8622. user used to authenticate with Vault using the LDAP authentication
  8623. method
  8624. properties:
  8625. key:
  8626. description: |-
  8627. A key in the referenced Secret.
  8628. Some instances of this field may be defaulted, in others it may be required.
  8629. maxLength: 253
  8630. minLength: 1
  8631. pattern: ^[-._a-zA-Z0-9]+$
  8632. type: string
  8633. name:
  8634. description: The name of the Secret resource being referred to.
  8635. maxLength: 253
  8636. minLength: 1
  8637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8638. type: string
  8639. namespace:
  8640. description: |-
  8641. The namespace of the Secret resource being referred to.
  8642. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8643. maxLength: 63
  8644. minLength: 1
  8645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8646. type: string
  8647. type: object
  8648. username:
  8649. description: |-
  8650. Username is an LDAP username used to authenticate using the LDAP Vault
  8651. authentication method
  8652. type: string
  8653. required:
  8654. - path
  8655. - username
  8656. type: object
  8657. namespace:
  8658. description: |-
  8659. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  8660. Namespaces is a set of features within Vault Enterprise that allows
  8661. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8662. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8663. This will default to Vault.Namespace field if set, or empty otherwise
  8664. type: string
  8665. tokenSecretRef:
  8666. description: TokenSecretRef authenticates with Vault by presenting a token.
  8667. properties:
  8668. key:
  8669. description: |-
  8670. A key in the referenced Secret.
  8671. Some instances of this field may be defaulted, in others it may be required.
  8672. maxLength: 253
  8673. minLength: 1
  8674. pattern: ^[-._a-zA-Z0-9]+$
  8675. type: string
  8676. name:
  8677. description: The name of the Secret resource being referred to.
  8678. maxLength: 253
  8679. minLength: 1
  8680. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8681. type: string
  8682. namespace:
  8683. description: |-
  8684. The namespace of the Secret resource being referred to.
  8685. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8686. maxLength: 63
  8687. minLength: 1
  8688. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8689. type: string
  8690. type: object
  8691. userPass:
  8692. description: UserPass authenticates with Vault by passing username/password pair
  8693. properties:
  8694. path:
  8695. default: userpass
  8696. description: |-
  8697. Path where the UserPassword authentication backend is mounted
  8698. in Vault, e.g: "userpass"
  8699. type: string
  8700. secretRef:
  8701. description: |-
  8702. SecretRef to a key in a Secret resource containing password for the
  8703. user used to authenticate with Vault using the UserPass authentication
  8704. method
  8705. properties:
  8706. key:
  8707. description: |-
  8708. A key in the referenced Secret.
  8709. Some instances of this field may be defaulted, in others it may be required.
  8710. maxLength: 253
  8711. minLength: 1
  8712. pattern: ^[-._a-zA-Z0-9]+$
  8713. type: string
  8714. name:
  8715. description: The name of the Secret resource being referred to.
  8716. maxLength: 253
  8717. minLength: 1
  8718. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8719. type: string
  8720. namespace:
  8721. description: |-
  8722. The namespace of the Secret resource being referred to.
  8723. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8724. maxLength: 63
  8725. minLength: 1
  8726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8727. type: string
  8728. type: object
  8729. username:
  8730. description: |-
  8731. Username is a username used to authenticate using the UserPass Vault
  8732. authentication method
  8733. type: string
  8734. required:
  8735. - path
  8736. - username
  8737. type: object
  8738. type: object
  8739. caBundle:
  8740. description: |-
  8741. PEM encoded CA bundle used to validate Vault server certificate. Only used
  8742. if the Server URL is using HTTPS protocol. This parameter is ignored for
  8743. plain HTTP protocol connection. If not set the system root certificates
  8744. are used to validate the TLS connection.
  8745. format: byte
  8746. type: string
  8747. caProvider:
  8748. description: The provider for the CA bundle to use to validate Vault server certificate.
  8749. properties:
  8750. key:
  8751. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8752. maxLength: 253
  8753. minLength: 1
  8754. pattern: ^[-._a-zA-Z0-9]+$
  8755. type: string
  8756. name:
  8757. description: The name of the object located at the provider type.
  8758. maxLength: 253
  8759. minLength: 1
  8760. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8761. type: string
  8762. namespace:
  8763. description: |-
  8764. The namespace the Provider type is in.
  8765. Can only be defined when used in a ClusterSecretStore.
  8766. maxLength: 63
  8767. minLength: 1
  8768. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8769. type: string
  8770. type:
  8771. description: The type of provider to use such as "Secret", or "ConfigMap".
  8772. enum:
  8773. - Secret
  8774. - ConfigMap
  8775. type: string
  8776. required:
  8777. - name
  8778. - type
  8779. type: object
  8780. checkAndSet:
  8781. description: |-
  8782. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  8783. Only applies to Vault KV v2 stores. When enabled, write operations must include
  8784. the current version of the secret to prevent unintentional overwrites.
  8785. properties:
  8786. required:
  8787. description: |-
  8788. Required when true, all write operations must include a check-and-set parameter.
  8789. This helps prevent unintentional overwrites of secrets.
  8790. type: boolean
  8791. type: object
  8792. forwardInconsistent:
  8793. description: |-
  8794. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  8795. leader instead of simply retrying within a loop. This can increase performance if
  8796. the option is enabled serverside.
  8797. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  8798. type: boolean
  8799. headers:
  8800. additionalProperties:
  8801. type: string
  8802. description: Headers to be added in Vault request
  8803. type: object
  8804. namespace:
  8805. description: |-
  8806. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  8807. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8808. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8809. type: string
  8810. path:
  8811. description: |-
  8812. Path is the mount path of the Vault KV backend endpoint, e.g:
  8813. "secret". The v2 KV secret engine version specific "/data" path suffix
  8814. for fetching secrets from Vault is optional and will be appended
  8815. if not present in specified path.
  8816. type: string
  8817. readYourWrites:
  8818. description: |-
  8819. ReadYourWrites ensures isolated read-after-write semantics by
  8820. providing discovered cluster replication states in each request.
  8821. More information about eventual consistency in Vault can be found here
  8822. https://www.vaultproject.io/docs/enterprise/consistency
  8823. type: boolean
  8824. server:
  8825. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  8826. type: string
  8827. tls:
  8828. description: |-
  8829. The configuration used for client side related TLS communication, when the Vault server
  8830. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  8831. This parameter is ignored for plain HTTP protocol connection.
  8832. It's worth noting this configuration is different from the "TLS certificates auth method",
  8833. which is available under the `auth.cert` section.
  8834. properties:
  8835. certSecretRef:
  8836. description: |-
  8837. CertSecretRef is a certificate added to the transport layer
  8838. when communicating with the Vault server.
  8839. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  8840. properties:
  8841. key:
  8842. description: |-
  8843. A key in the referenced Secret.
  8844. Some instances of this field may be defaulted, in others it may be required.
  8845. maxLength: 253
  8846. minLength: 1
  8847. pattern: ^[-._a-zA-Z0-9]+$
  8848. type: string
  8849. name:
  8850. description: The name of the Secret resource being referred to.
  8851. maxLength: 253
  8852. minLength: 1
  8853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8854. type: string
  8855. namespace:
  8856. description: |-
  8857. The namespace of the Secret resource being referred to.
  8858. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8859. maxLength: 63
  8860. minLength: 1
  8861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8862. type: string
  8863. type: object
  8864. keySecretRef:
  8865. description: |-
  8866. KeySecretRef to a key in a Secret resource containing client private key
  8867. added to the transport layer when communicating with the Vault server.
  8868. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  8869. properties:
  8870. key:
  8871. description: |-
  8872. A key in the referenced Secret.
  8873. Some instances of this field may be defaulted, in others it may be required.
  8874. maxLength: 253
  8875. minLength: 1
  8876. pattern: ^[-._a-zA-Z0-9]+$
  8877. type: string
  8878. name:
  8879. description: The name of the Secret resource being referred to.
  8880. maxLength: 253
  8881. minLength: 1
  8882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8883. type: string
  8884. namespace:
  8885. description: |-
  8886. The namespace of the Secret resource being referred to.
  8887. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8888. maxLength: 63
  8889. minLength: 1
  8890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8891. type: string
  8892. type: object
  8893. type: object
  8894. version:
  8895. default: v2
  8896. description: |-
  8897. Version is the Vault KV secret engine version. This can be either "v1" or
  8898. "v2". Version defaults to "v2".
  8899. enum:
  8900. - v1
  8901. - v2
  8902. type: string
  8903. required:
  8904. - server
  8905. type: object
  8906. volcengine:
  8907. description: Volcengine configures this store to sync secrets using the Volcengine provider
  8908. properties:
  8909. auth:
  8910. description: |-
  8911. Auth defines the authentication method to use.
  8912. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  8913. properties:
  8914. secretRef:
  8915. description: |-
  8916. SecretRef defines the static credentials to use for authentication.
  8917. If not set, IRSA is used.
  8918. properties:
  8919. accessKeyID:
  8920. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  8921. properties:
  8922. key:
  8923. description: |-
  8924. A key in the referenced Secret.
  8925. Some instances of this field may be defaulted, in others it may be required.
  8926. maxLength: 253
  8927. minLength: 1
  8928. pattern: ^[-._a-zA-Z0-9]+$
  8929. type: string
  8930. name:
  8931. description: The name of the Secret resource being referred to.
  8932. maxLength: 253
  8933. minLength: 1
  8934. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8935. type: string
  8936. namespace:
  8937. description: |-
  8938. The namespace of the Secret resource being referred to.
  8939. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8940. maxLength: 63
  8941. minLength: 1
  8942. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8943. type: string
  8944. type: object
  8945. secretAccessKey:
  8946. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  8947. properties:
  8948. key:
  8949. description: |-
  8950. A key in the referenced Secret.
  8951. Some instances of this field may be defaulted, in others it may be required.
  8952. maxLength: 253
  8953. minLength: 1
  8954. pattern: ^[-._a-zA-Z0-9]+$
  8955. type: string
  8956. name:
  8957. description: The name of the Secret resource being referred to.
  8958. maxLength: 253
  8959. minLength: 1
  8960. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8961. type: string
  8962. namespace:
  8963. description: |-
  8964. The namespace of the Secret resource being referred to.
  8965. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8966. maxLength: 63
  8967. minLength: 1
  8968. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8969. type: string
  8970. type: object
  8971. token:
  8972. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  8973. properties:
  8974. key:
  8975. description: |-
  8976. A key in the referenced Secret.
  8977. Some instances of this field may be defaulted, in others it may be required.
  8978. maxLength: 253
  8979. minLength: 1
  8980. pattern: ^[-._a-zA-Z0-9]+$
  8981. type: string
  8982. name:
  8983. description: The name of the Secret resource being referred to.
  8984. maxLength: 253
  8985. minLength: 1
  8986. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8987. type: string
  8988. namespace:
  8989. description: |-
  8990. The namespace of the Secret resource being referred to.
  8991. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8992. maxLength: 63
  8993. minLength: 1
  8994. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8995. type: string
  8996. type: object
  8997. required:
  8998. - accessKeyID
  8999. - secretAccessKey
  9000. type: object
  9001. type: object
  9002. region:
  9003. description: Region specifies the Volcengine region to connect to.
  9004. type: string
  9005. required:
  9006. - region
  9007. type: object
  9008. webhook:
  9009. description: Webhook configures this store to sync secrets using a generic templated webhook
  9010. properties:
  9011. auth:
  9012. description: Auth specifies a authorization protocol. Only one protocol may be set.
  9013. maxProperties: 1
  9014. minProperties: 1
  9015. properties:
  9016. ntlm:
  9017. description: NTLMProtocol configures the store to use NTLM for auth
  9018. properties:
  9019. passwordSecret:
  9020. description: |-
  9021. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9022. In some instances, `key` is a required field.
  9023. properties:
  9024. key:
  9025. description: |-
  9026. A key in the referenced Secret.
  9027. Some instances of this field may be defaulted, in others it may be required.
  9028. maxLength: 253
  9029. minLength: 1
  9030. pattern: ^[-._a-zA-Z0-9]+$
  9031. type: string
  9032. name:
  9033. description: The name of the Secret resource being referred to.
  9034. maxLength: 253
  9035. minLength: 1
  9036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9037. type: string
  9038. namespace:
  9039. description: |-
  9040. The namespace of the Secret resource being referred to.
  9041. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9042. maxLength: 63
  9043. minLength: 1
  9044. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9045. type: string
  9046. type: object
  9047. usernameSecret:
  9048. description: |-
  9049. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9050. In some instances, `key` is a required field.
  9051. properties:
  9052. key:
  9053. description: |-
  9054. A key in the referenced Secret.
  9055. Some instances of this field may be defaulted, in others it may be required.
  9056. maxLength: 253
  9057. minLength: 1
  9058. pattern: ^[-._a-zA-Z0-9]+$
  9059. type: string
  9060. name:
  9061. description: The name of the Secret resource being referred to.
  9062. maxLength: 253
  9063. minLength: 1
  9064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9065. type: string
  9066. namespace:
  9067. description: |-
  9068. The namespace of the Secret resource being referred to.
  9069. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9070. maxLength: 63
  9071. minLength: 1
  9072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9073. type: string
  9074. type: object
  9075. required:
  9076. - passwordSecret
  9077. - usernameSecret
  9078. type: object
  9079. type: object
  9080. body:
  9081. description: Body
  9082. type: string
  9083. caBundle:
  9084. description: |-
  9085. PEM encoded CA bundle used to validate webhook server certificate. Only used
  9086. if the Server URL is using HTTPS protocol. This parameter is ignored for
  9087. plain HTTP protocol connection. If not set the system root certificates
  9088. are used to validate the TLS connection.
  9089. format: byte
  9090. type: string
  9091. caProvider:
  9092. description: The provider for the CA bundle to use to validate webhook server certificate.
  9093. properties:
  9094. key:
  9095. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9096. maxLength: 253
  9097. minLength: 1
  9098. pattern: ^[-._a-zA-Z0-9]+$
  9099. type: string
  9100. name:
  9101. description: The name of the object located at the provider type.
  9102. maxLength: 253
  9103. minLength: 1
  9104. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9105. type: string
  9106. namespace:
  9107. description: The namespace the Provider type is in.
  9108. maxLength: 63
  9109. minLength: 1
  9110. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9111. type: string
  9112. type:
  9113. description: The type of provider to use such as "Secret", or "ConfigMap".
  9114. enum:
  9115. - Secret
  9116. - ConfigMap
  9117. type: string
  9118. required:
  9119. - name
  9120. - type
  9121. type: object
  9122. headers:
  9123. additionalProperties:
  9124. type: string
  9125. description: Headers
  9126. type: object
  9127. method:
  9128. description: Webhook Method
  9129. type: string
  9130. result:
  9131. description: Result formatting
  9132. properties:
  9133. jsonPath:
  9134. description: Json path of return value
  9135. type: string
  9136. type: object
  9137. secrets:
  9138. description: |-
  9139. Secrets to fill in templates
  9140. These secrets will be passed to the templating function as key value pairs under the given name
  9141. items:
  9142. description: WebhookSecret defines a secret that will be passed to the webhook request.
  9143. properties:
  9144. name:
  9145. description: Name of this secret in templates
  9146. type: string
  9147. secretRef:
  9148. description: Secret ref to fill in credentials
  9149. properties:
  9150. key:
  9151. description: |-
  9152. A key in the referenced Secret.
  9153. Some instances of this field may be defaulted, in others it may be required.
  9154. maxLength: 253
  9155. minLength: 1
  9156. pattern: ^[-._a-zA-Z0-9]+$
  9157. type: string
  9158. name:
  9159. description: The name of the Secret resource being referred to.
  9160. maxLength: 253
  9161. minLength: 1
  9162. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9163. type: string
  9164. namespace:
  9165. description: |-
  9166. The namespace of the Secret resource being referred to.
  9167. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9168. maxLength: 63
  9169. minLength: 1
  9170. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9171. type: string
  9172. type: object
  9173. required:
  9174. - name
  9175. - secretRef
  9176. type: object
  9177. type: array
  9178. timeout:
  9179. description: Timeout
  9180. type: string
  9181. url:
  9182. description: Webhook url to call
  9183. type: string
  9184. required:
  9185. - url
  9186. type: object
  9187. yandexcertificatemanager:
  9188. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  9189. properties:
  9190. apiEndpoint:
  9191. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9192. type: string
  9193. auth:
  9194. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  9195. properties:
  9196. authorizedKeySecretRef:
  9197. description: The authorized key used for authentication
  9198. properties:
  9199. key:
  9200. description: |-
  9201. A key in the referenced Secret.
  9202. Some instances of this field may be defaulted, in others it may be required.
  9203. maxLength: 253
  9204. minLength: 1
  9205. pattern: ^[-._a-zA-Z0-9]+$
  9206. type: string
  9207. name:
  9208. description: The name of the Secret resource being referred to.
  9209. maxLength: 253
  9210. minLength: 1
  9211. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9212. type: string
  9213. namespace:
  9214. description: |-
  9215. The namespace of the Secret resource being referred to.
  9216. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9217. maxLength: 63
  9218. minLength: 1
  9219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9220. type: string
  9221. type: object
  9222. type: object
  9223. caProvider:
  9224. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9225. properties:
  9226. certSecretRef:
  9227. description: |-
  9228. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9229. In some instances, `key` is a required field.
  9230. properties:
  9231. key:
  9232. description: |-
  9233. A key in the referenced Secret.
  9234. Some instances of this field may be defaulted, in others it may be required.
  9235. maxLength: 253
  9236. minLength: 1
  9237. pattern: ^[-._a-zA-Z0-9]+$
  9238. type: string
  9239. name:
  9240. description: The name of the Secret resource being referred to.
  9241. maxLength: 253
  9242. minLength: 1
  9243. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9244. type: string
  9245. namespace:
  9246. description: |-
  9247. The namespace of the Secret resource being referred to.
  9248. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9249. maxLength: 63
  9250. minLength: 1
  9251. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9252. type: string
  9253. type: object
  9254. type: object
  9255. fetching:
  9256. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  9257. maxProperties: 1
  9258. minProperties: 1
  9259. properties:
  9260. byID:
  9261. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  9262. type: object
  9263. byName:
  9264. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  9265. properties:
  9266. folderID:
  9267. description: The folder to fetch secrets from
  9268. type: string
  9269. required:
  9270. - folderID
  9271. type: object
  9272. type: object
  9273. required:
  9274. - auth
  9275. type: object
  9276. yandexlockbox:
  9277. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  9278. properties:
  9279. apiEndpoint:
  9280. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9281. type: string
  9282. auth:
  9283. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  9284. properties:
  9285. authorizedKeySecretRef:
  9286. description: The authorized key used for authentication
  9287. properties:
  9288. key:
  9289. description: |-
  9290. A key in the referenced Secret.
  9291. Some instances of this field may be defaulted, in others it may be required.
  9292. maxLength: 253
  9293. minLength: 1
  9294. pattern: ^[-._a-zA-Z0-9]+$
  9295. type: string
  9296. name:
  9297. description: The name of the Secret resource being referred to.
  9298. maxLength: 253
  9299. minLength: 1
  9300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9301. type: string
  9302. namespace:
  9303. description: |-
  9304. The namespace of the Secret resource being referred to.
  9305. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9306. maxLength: 63
  9307. minLength: 1
  9308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9309. type: string
  9310. type: object
  9311. type: object
  9312. caProvider:
  9313. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9314. properties:
  9315. certSecretRef:
  9316. description: |-
  9317. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9318. In some instances, `key` is a required field.
  9319. properties:
  9320. key:
  9321. description: |-
  9322. A key in the referenced Secret.
  9323. Some instances of this field may be defaulted, in others it may be required.
  9324. maxLength: 253
  9325. minLength: 1
  9326. pattern: ^[-._a-zA-Z0-9]+$
  9327. type: string
  9328. name:
  9329. description: The name of the Secret resource being referred to.
  9330. maxLength: 253
  9331. minLength: 1
  9332. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9333. type: string
  9334. namespace:
  9335. description: |-
  9336. The namespace of the Secret resource being referred to.
  9337. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9338. maxLength: 63
  9339. minLength: 1
  9340. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9341. type: string
  9342. type: object
  9343. type: object
  9344. fetching:
  9345. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  9346. maxProperties: 1
  9347. minProperties: 1
  9348. properties:
  9349. byID:
  9350. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  9351. type: object
  9352. byName:
  9353. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  9354. properties:
  9355. folderID:
  9356. description: The folder to fetch secrets from
  9357. type: string
  9358. required:
  9359. - folderID
  9360. type: object
  9361. type: object
  9362. required:
  9363. - auth
  9364. type: object
  9365. type: object
  9366. refreshInterval:
  9367. anyOf:
  9368. - type: integer
  9369. - type: string
  9370. description: |-
  9371. Used to configure store refresh interval. Accepts either an integer number
  9372. of seconds (legacy) or a Go duration string such as "1h" or "5m". Empty or
  9373. 0 will default to the controller config.
  9374. x-kubernetes-int-or-string: true
  9375. retrySettings:
  9376. description: Used to configure HTTP retries on failures.
  9377. properties:
  9378. maxRetries:
  9379. format: int32
  9380. type: integer
  9381. retryInterval:
  9382. type: string
  9383. type: object
  9384. required:
  9385. - provider
  9386. type: object
  9387. status:
  9388. description: SecretStoreStatus defines the observed state of the SecretStore.
  9389. properties:
  9390. capabilities:
  9391. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  9392. type: string
  9393. conditions:
  9394. items:
  9395. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  9396. properties:
  9397. lastTransitionTime:
  9398. format: date-time
  9399. type: string
  9400. message:
  9401. type: string
  9402. reason:
  9403. type: string
  9404. status:
  9405. type: string
  9406. type:
  9407. description: SecretStoreConditionType represents the condition of the SecretStore.
  9408. type: string
  9409. required:
  9410. - status
  9411. - type
  9412. type: object
  9413. type: array
  9414. type: object
  9415. type: object
  9416. served: true
  9417. storage: true
  9418. subresources:
  9419. status: {}
  9420. - additionalPrinterColumns:
  9421. - jsonPath: .metadata.creationTimestamp
  9422. name: AGE
  9423. type: date
  9424. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  9425. name: Status
  9426. type: string
  9427. - jsonPath: .status.capabilities
  9428. name: Capabilities
  9429. type: string
  9430. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  9431. name: Ready
  9432. type: string
  9433. deprecated: true
  9434. name: v1beta1
  9435. schema:
  9436. openAPIV3Schema:
  9437. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  9438. properties:
  9439. apiVersion:
  9440. description: |-
  9441. APIVersion defines the versioned schema of this representation of an object.
  9442. Servers should convert recognized schemas to the latest internal value, and
  9443. may reject unrecognized values.
  9444. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  9445. type: string
  9446. kind:
  9447. description: |-
  9448. Kind is a string value representing the REST resource this object represents.
  9449. Servers may infer this from the endpoint the client submits requests to.
  9450. Cannot be updated.
  9451. In CamelCase.
  9452. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  9453. type: string
  9454. metadata:
  9455. type: object
  9456. spec:
  9457. description: SecretStoreSpec defines the desired state of SecretStore.
  9458. properties:
  9459. conditions:
  9460. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  9461. items:
  9462. description: |-
  9463. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  9464. for a ClusterSecretStore instance.
  9465. properties:
  9466. namespaceRegexes:
  9467. description: Choose namespaces by using regex matching
  9468. items:
  9469. type: string
  9470. type: array
  9471. namespaceSelector:
  9472. description: Choose namespace using a labelSelector
  9473. properties:
  9474. matchExpressions:
  9475. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  9476. items:
  9477. description: |-
  9478. A label selector requirement is a selector that contains values, a key, and an operator that
  9479. relates the key and values.
  9480. properties:
  9481. key:
  9482. description: key is the label key that the selector applies to.
  9483. type: string
  9484. operator:
  9485. description: |-
  9486. operator represents a key's relationship to a set of values.
  9487. Valid operators are In, NotIn, Exists and DoesNotExist.
  9488. type: string
  9489. values:
  9490. description: |-
  9491. values is an array of string values. If the operator is In or NotIn,
  9492. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  9493. the values array must be empty. This array is replaced during a strategic
  9494. merge patch.
  9495. items:
  9496. type: string
  9497. type: array
  9498. x-kubernetes-list-type: atomic
  9499. required:
  9500. - key
  9501. - operator
  9502. type: object
  9503. type: array
  9504. x-kubernetes-list-type: atomic
  9505. matchLabels:
  9506. additionalProperties:
  9507. type: string
  9508. description: |-
  9509. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  9510. map is equivalent to an element of matchExpressions, whose key field is "key", the
  9511. operator is "In", and the values array contains only "value". The requirements are ANDed.
  9512. type: object
  9513. type: object
  9514. x-kubernetes-map-type: atomic
  9515. namespaces:
  9516. description: Choose namespaces by name
  9517. items:
  9518. maxLength: 63
  9519. minLength: 1
  9520. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9521. type: string
  9522. type: array
  9523. type: object
  9524. type: array
  9525. controller:
  9526. description: |-
  9527. Used to select the correct ESO controller (think: ingress.ingressClassName)
  9528. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  9529. type: string
  9530. provider:
  9531. description: Used to configure the provider. Only one provider may be set
  9532. maxProperties: 1
  9533. minProperties: 1
  9534. properties:
  9535. akeyless:
  9536. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  9537. properties:
  9538. akeylessGWApiURL:
  9539. description: Akeyless GW API Url from which the secrets to be fetched from.
  9540. type: string
  9541. authSecretRef:
  9542. description: Auth configures how the operator authenticates with Akeyless.
  9543. properties:
  9544. kubernetesAuth:
  9545. description: |-
  9546. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  9547. token stored in the named Secret resource.
  9548. properties:
  9549. accessID:
  9550. description: the Akeyless Kubernetes auth-method access-id
  9551. type: string
  9552. k8sConfName:
  9553. description: Kubernetes-auth configuration name in Akeyless-Gateway
  9554. type: string
  9555. secretRef:
  9556. description: |-
  9557. Optional secret field containing a Kubernetes ServiceAccount JWT used
  9558. for authenticating with Akeyless. If a name is specified without a key,
  9559. `token` is the default. If one is not specified, the one bound to
  9560. the controller will be used.
  9561. properties:
  9562. key:
  9563. description: |-
  9564. A key in the referenced Secret.
  9565. Some instances of this field may be defaulted, in others it may be required.
  9566. maxLength: 253
  9567. minLength: 1
  9568. pattern: ^[-._a-zA-Z0-9]+$
  9569. type: string
  9570. name:
  9571. description: The name of the Secret resource being referred to.
  9572. maxLength: 253
  9573. minLength: 1
  9574. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9575. type: string
  9576. namespace:
  9577. description: |-
  9578. The namespace of the Secret resource being referred to.
  9579. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9580. maxLength: 63
  9581. minLength: 1
  9582. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9583. type: string
  9584. type: object
  9585. serviceAccountRef:
  9586. description: |-
  9587. Optional service account field containing the name of a kubernetes ServiceAccount.
  9588. If the service account is specified, the service account secret token JWT will be used
  9589. for authenticating with Akeyless. If the service account selector is not supplied,
  9590. the secretRef will be used instead.
  9591. properties:
  9592. audiences:
  9593. description: |-
  9594. Audience specifies the `aud` claim for the service account token
  9595. Some providers automatically extend the audience field based on well-known annotations for workload
  9596. identity (e.g. IRSA or GCP Workload Identity)
  9597. items:
  9598. type: string
  9599. type: array
  9600. name:
  9601. description: The name of the ServiceAccount resource being referred to.
  9602. maxLength: 253
  9603. minLength: 1
  9604. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9605. type: string
  9606. namespace:
  9607. description: |-
  9608. Namespace of the resource being referred to.
  9609. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9610. maxLength: 63
  9611. minLength: 1
  9612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9613. type: string
  9614. required:
  9615. - name
  9616. type: object
  9617. required:
  9618. - accessID
  9619. - k8sConfName
  9620. type: object
  9621. secretRef:
  9622. description: |-
  9623. Reference to a Secret that contains the details
  9624. to authenticate with Akeyless.
  9625. properties:
  9626. accessID:
  9627. description: The SecretAccessID is used for authentication
  9628. properties:
  9629. key:
  9630. description: |-
  9631. A key in the referenced Secret.
  9632. Some instances of this field may be defaulted, in others it may be required.
  9633. maxLength: 253
  9634. minLength: 1
  9635. pattern: ^[-._a-zA-Z0-9]+$
  9636. type: string
  9637. name:
  9638. description: The name of the Secret resource being referred to.
  9639. maxLength: 253
  9640. minLength: 1
  9641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9642. type: string
  9643. namespace:
  9644. description: |-
  9645. The namespace of the Secret resource being referred to.
  9646. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9647. maxLength: 63
  9648. minLength: 1
  9649. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9650. type: string
  9651. type: object
  9652. accessType:
  9653. description: |-
  9654. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9655. In some instances, `key` is a required field.
  9656. properties:
  9657. key:
  9658. description: |-
  9659. A key in the referenced Secret.
  9660. Some instances of this field may be defaulted, in others it may be required.
  9661. maxLength: 253
  9662. minLength: 1
  9663. pattern: ^[-._a-zA-Z0-9]+$
  9664. type: string
  9665. name:
  9666. description: The name of the Secret resource being referred to.
  9667. maxLength: 253
  9668. minLength: 1
  9669. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9670. type: string
  9671. namespace:
  9672. description: |-
  9673. The namespace of the Secret resource being referred to.
  9674. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9675. maxLength: 63
  9676. minLength: 1
  9677. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9678. type: string
  9679. type: object
  9680. accessTypeParam:
  9681. description: |-
  9682. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9683. In some instances, `key` is a required field.
  9684. properties:
  9685. key:
  9686. description: |-
  9687. A key in the referenced Secret.
  9688. Some instances of this field may be defaulted, in others it may be required.
  9689. maxLength: 253
  9690. minLength: 1
  9691. pattern: ^[-._a-zA-Z0-9]+$
  9692. type: string
  9693. name:
  9694. description: The name of the Secret resource being referred to.
  9695. maxLength: 253
  9696. minLength: 1
  9697. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9698. type: string
  9699. namespace:
  9700. description: |-
  9701. The namespace of the Secret resource being referred to.
  9702. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9703. maxLength: 63
  9704. minLength: 1
  9705. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9706. type: string
  9707. type: object
  9708. type: object
  9709. type: object
  9710. caBundle:
  9711. description: |-
  9712. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  9713. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  9714. are used to validate the TLS connection.
  9715. format: byte
  9716. type: string
  9717. caProvider:
  9718. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  9719. properties:
  9720. key:
  9721. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9722. maxLength: 253
  9723. minLength: 1
  9724. pattern: ^[-._a-zA-Z0-9]+$
  9725. type: string
  9726. name:
  9727. description: The name of the object located at the provider type.
  9728. maxLength: 253
  9729. minLength: 1
  9730. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9731. type: string
  9732. namespace:
  9733. description: |-
  9734. The namespace the Provider type is in.
  9735. Can only be defined when used in a ClusterSecretStore.
  9736. maxLength: 63
  9737. minLength: 1
  9738. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9739. type: string
  9740. type:
  9741. description: The type of provider to use such as "Secret", or "ConfigMap".
  9742. enum:
  9743. - Secret
  9744. - ConfigMap
  9745. type: string
  9746. required:
  9747. - name
  9748. - type
  9749. type: object
  9750. required:
  9751. - akeylessGWApiURL
  9752. - authSecretRef
  9753. type: object
  9754. alibaba:
  9755. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  9756. properties:
  9757. auth:
  9758. description: AlibabaAuth contains a secretRef for credentials.
  9759. properties:
  9760. rrsa:
  9761. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  9762. properties:
  9763. oidcProviderArn:
  9764. type: string
  9765. oidcTokenFilePath:
  9766. type: string
  9767. roleArn:
  9768. type: string
  9769. sessionName:
  9770. type: string
  9771. required:
  9772. - oidcProviderArn
  9773. - oidcTokenFilePath
  9774. - roleArn
  9775. - sessionName
  9776. type: object
  9777. secretRef:
  9778. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  9779. properties:
  9780. accessKeyIDSecretRef:
  9781. description: The AccessKeyID is used for authentication
  9782. properties:
  9783. key:
  9784. description: |-
  9785. A key in the referenced Secret.
  9786. Some instances of this field may be defaulted, in others it may be required.
  9787. maxLength: 253
  9788. minLength: 1
  9789. pattern: ^[-._a-zA-Z0-9]+$
  9790. type: string
  9791. name:
  9792. description: The name of the Secret resource being referred to.
  9793. maxLength: 253
  9794. minLength: 1
  9795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9796. type: string
  9797. namespace:
  9798. description: |-
  9799. The namespace of the Secret resource being referred to.
  9800. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9801. maxLength: 63
  9802. minLength: 1
  9803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9804. type: string
  9805. type: object
  9806. accessKeySecretSecretRef:
  9807. description: The AccessKeySecret is used for authentication
  9808. properties:
  9809. key:
  9810. description: |-
  9811. A key in the referenced Secret.
  9812. Some instances of this field may be defaulted, in others it may be required.
  9813. maxLength: 253
  9814. minLength: 1
  9815. pattern: ^[-._a-zA-Z0-9]+$
  9816. type: string
  9817. name:
  9818. description: The name of the Secret resource being referred to.
  9819. maxLength: 253
  9820. minLength: 1
  9821. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9822. type: string
  9823. namespace:
  9824. description: |-
  9825. The namespace of the Secret resource being referred to.
  9826. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9827. maxLength: 63
  9828. minLength: 1
  9829. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9830. type: string
  9831. type: object
  9832. required:
  9833. - accessKeyIDSecretRef
  9834. - accessKeySecretSecretRef
  9835. type: object
  9836. type: object
  9837. regionID:
  9838. description: Alibaba Region to be used for the provider
  9839. type: string
  9840. required:
  9841. - auth
  9842. - regionID
  9843. type: object
  9844. aws:
  9845. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  9846. properties:
  9847. additionalRoles:
  9848. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  9849. items:
  9850. type: string
  9851. type: array
  9852. auth:
  9853. description: |-
  9854. Auth defines the information necessary to authenticate against AWS
  9855. if not set aws sdk will infer credentials from your environment
  9856. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  9857. properties:
  9858. jwt:
  9859. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  9860. properties:
  9861. serviceAccountRef:
  9862. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  9863. properties:
  9864. audiences:
  9865. description: |-
  9866. Audience specifies the `aud` claim for the service account token
  9867. Some providers automatically extend the audience field based on well-known annotations for workload
  9868. identity (e.g. IRSA or GCP Workload Identity)
  9869. items:
  9870. type: string
  9871. type: array
  9872. name:
  9873. description: The name of the ServiceAccount resource being referred to.
  9874. maxLength: 253
  9875. minLength: 1
  9876. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9877. type: string
  9878. namespace:
  9879. description: |-
  9880. Namespace of the resource being referred to.
  9881. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9882. maxLength: 63
  9883. minLength: 1
  9884. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9885. type: string
  9886. required:
  9887. - name
  9888. type: object
  9889. type: object
  9890. secretRef:
  9891. description: |-
  9892. AWSAuthSecretRef holds secret references for AWS credentials
  9893. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  9894. properties:
  9895. accessKeyIDSecretRef:
  9896. description: The AccessKeyID is used for authentication
  9897. properties:
  9898. key:
  9899. description: |-
  9900. A key in the referenced Secret.
  9901. Some instances of this field may be defaulted, in others it may be required.
  9902. maxLength: 253
  9903. minLength: 1
  9904. pattern: ^[-._a-zA-Z0-9]+$
  9905. type: string
  9906. name:
  9907. description: The name of the Secret resource being referred to.
  9908. maxLength: 253
  9909. minLength: 1
  9910. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9911. type: string
  9912. namespace:
  9913. description: |-
  9914. The namespace of the Secret resource being referred to.
  9915. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9916. maxLength: 63
  9917. minLength: 1
  9918. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9919. type: string
  9920. type: object
  9921. secretAccessKeySecretRef:
  9922. description: The SecretAccessKey is used for authentication
  9923. properties:
  9924. key:
  9925. description: |-
  9926. A key in the referenced Secret.
  9927. Some instances of this field may be defaulted, in others it may be required.
  9928. maxLength: 253
  9929. minLength: 1
  9930. pattern: ^[-._a-zA-Z0-9]+$
  9931. type: string
  9932. name:
  9933. description: The name of the Secret resource being referred to.
  9934. maxLength: 253
  9935. minLength: 1
  9936. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9937. type: string
  9938. namespace:
  9939. description: |-
  9940. The namespace of the Secret resource being referred to.
  9941. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9942. maxLength: 63
  9943. minLength: 1
  9944. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9945. type: string
  9946. type: object
  9947. sessionTokenSecretRef:
  9948. description: |-
  9949. The SessionToken used for authentication
  9950. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  9951. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  9952. properties:
  9953. key:
  9954. description: |-
  9955. A key in the referenced Secret.
  9956. Some instances of this field may be defaulted, in others it may be required.
  9957. maxLength: 253
  9958. minLength: 1
  9959. pattern: ^[-._a-zA-Z0-9]+$
  9960. type: string
  9961. name:
  9962. description: The name of the Secret resource being referred to.
  9963. maxLength: 253
  9964. minLength: 1
  9965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9966. type: string
  9967. namespace:
  9968. description: |-
  9969. The namespace of the Secret resource being referred to.
  9970. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9971. maxLength: 63
  9972. minLength: 1
  9973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9974. type: string
  9975. type: object
  9976. type: object
  9977. type: object
  9978. externalID:
  9979. description: AWS External ID set on assumed IAM roles
  9980. type: string
  9981. prefix:
  9982. description: Prefix adds a prefix to all retrieved values.
  9983. type: string
  9984. region:
  9985. description: AWS Region to be used for the provider
  9986. type: string
  9987. role:
  9988. description: Role is a Role ARN which the provider will assume
  9989. type: string
  9990. secretsManager:
  9991. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  9992. properties:
  9993. forceDeleteWithoutRecovery:
  9994. description: |-
  9995. Specifies whether to delete the secret without any recovery window. You
  9996. can't use both this parameter and RecoveryWindowInDays in the same call.
  9997. If you don't use either, then by default Secrets Manager uses a 30 day
  9998. recovery window.
  9999. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  10000. type: boolean
  10001. recoveryWindowInDays:
  10002. description: |-
  10003. The number of days from 7 to 30 that Secrets Manager waits before
  10004. permanently deleting the secret. You can't use both this parameter and
  10005. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  10006. then by default Secrets Manager uses a 30 day recovery window.
  10007. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  10008. format: int64
  10009. type: integer
  10010. type: object
  10011. service:
  10012. description: Service defines which service should be used to fetch the secrets
  10013. enum:
  10014. - SecretsManager
  10015. - ParameterStore
  10016. type: string
  10017. sessionTags:
  10018. description: AWS STS assume role session tags
  10019. items:
  10020. description: Tag defines a tag key and value for AWS resources.
  10021. properties:
  10022. key:
  10023. type: string
  10024. value:
  10025. type: string
  10026. required:
  10027. - key
  10028. - value
  10029. type: object
  10030. type: array
  10031. transitiveTagKeys:
  10032. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  10033. items:
  10034. type: string
  10035. type: array
  10036. required:
  10037. - region
  10038. - service
  10039. type: object
  10040. azurekv:
  10041. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  10042. properties:
  10043. authSecretRef:
  10044. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  10045. properties:
  10046. clientCertificate:
  10047. description: The Azure ClientCertificate of the service principle used for authentication.
  10048. properties:
  10049. key:
  10050. description: |-
  10051. A key in the referenced Secret.
  10052. Some instances of this field may be defaulted, in others it may be required.
  10053. maxLength: 253
  10054. minLength: 1
  10055. pattern: ^[-._a-zA-Z0-9]+$
  10056. type: string
  10057. name:
  10058. description: The name of the Secret resource being referred to.
  10059. maxLength: 253
  10060. minLength: 1
  10061. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10062. type: string
  10063. namespace:
  10064. description: |-
  10065. The namespace of the Secret resource being referred to.
  10066. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10067. maxLength: 63
  10068. minLength: 1
  10069. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10070. type: string
  10071. type: object
  10072. clientId:
  10073. description: The Azure clientId of the service principle or managed identity used for authentication.
  10074. properties:
  10075. key:
  10076. description: |-
  10077. A key in the referenced Secret.
  10078. Some instances of this field may be defaulted, in others it may be required.
  10079. maxLength: 253
  10080. minLength: 1
  10081. pattern: ^[-._a-zA-Z0-9]+$
  10082. type: string
  10083. name:
  10084. description: The name of the Secret resource being referred to.
  10085. maxLength: 253
  10086. minLength: 1
  10087. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10088. type: string
  10089. namespace:
  10090. description: |-
  10091. The namespace of the Secret resource being referred to.
  10092. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10093. maxLength: 63
  10094. minLength: 1
  10095. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10096. type: string
  10097. type: object
  10098. clientSecret:
  10099. description: The Azure ClientSecret of the service principle used for authentication.
  10100. properties:
  10101. key:
  10102. description: |-
  10103. A key in the referenced Secret.
  10104. Some instances of this field may be defaulted, in others it may be required.
  10105. maxLength: 253
  10106. minLength: 1
  10107. pattern: ^[-._a-zA-Z0-9]+$
  10108. type: string
  10109. name:
  10110. description: The name of the Secret resource being referred to.
  10111. maxLength: 253
  10112. minLength: 1
  10113. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10114. type: string
  10115. namespace:
  10116. description: |-
  10117. The namespace of the Secret resource being referred to.
  10118. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10119. maxLength: 63
  10120. minLength: 1
  10121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10122. type: string
  10123. type: object
  10124. tenantId:
  10125. description: The Azure tenantId of the managed identity used for authentication.
  10126. properties:
  10127. key:
  10128. description: |-
  10129. A key in the referenced Secret.
  10130. Some instances of this field may be defaulted, in others it may be required.
  10131. maxLength: 253
  10132. minLength: 1
  10133. pattern: ^[-._a-zA-Z0-9]+$
  10134. type: string
  10135. name:
  10136. description: The name of the Secret resource being referred to.
  10137. maxLength: 253
  10138. minLength: 1
  10139. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10140. type: string
  10141. namespace:
  10142. description: |-
  10143. The namespace of the Secret resource being referred to.
  10144. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10145. maxLength: 63
  10146. minLength: 1
  10147. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10148. type: string
  10149. type: object
  10150. type: object
  10151. authType:
  10152. default: ServicePrincipal
  10153. description: |-
  10154. Auth type defines how to authenticate to the keyvault service.
  10155. Valid values are:
  10156. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  10157. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  10158. enum:
  10159. - ServicePrincipal
  10160. - ManagedIdentity
  10161. - WorkloadIdentity
  10162. type: string
  10163. environmentType:
  10164. default: PublicCloud
  10165. description: |-
  10166. EnvironmentType specifies the Azure cloud environment endpoints to use for
  10167. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  10168. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  10169. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  10170. enum:
  10171. - PublicCloud
  10172. - USGovernmentCloud
  10173. - ChinaCloud
  10174. - GermanCloud
  10175. type: string
  10176. identityId:
  10177. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  10178. type: string
  10179. serviceAccountRef:
  10180. description: |-
  10181. ServiceAccountRef specified the service account
  10182. that should be used when authenticating with WorkloadIdentity.
  10183. properties:
  10184. audiences:
  10185. description: |-
  10186. Audience specifies the `aud` claim for the service account token
  10187. Some providers automatically extend the audience field based on well-known annotations for workload
  10188. identity (e.g. IRSA or GCP Workload Identity)
  10189. items:
  10190. type: string
  10191. type: array
  10192. name:
  10193. description: The name of the ServiceAccount resource being referred to.
  10194. maxLength: 253
  10195. minLength: 1
  10196. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10197. type: string
  10198. namespace:
  10199. description: |-
  10200. Namespace of the resource being referred to.
  10201. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10202. maxLength: 63
  10203. minLength: 1
  10204. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10205. type: string
  10206. required:
  10207. - name
  10208. type: object
  10209. tenantId:
  10210. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  10211. type: string
  10212. vaultUrl:
  10213. description: Vault Url from which the secrets to be fetched from.
  10214. type: string
  10215. required:
  10216. - vaultUrl
  10217. type: object
  10218. beyondtrust:
  10219. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  10220. properties:
  10221. auth:
  10222. description: Auth configures how the operator authenticates with Beyondtrust.
  10223. properties:
  10224. apiKey:
  10225. description: APIKey If not provided then ClientID/ClientSecret become required.
  10226. properties:
  10227. secretRef:
  10228. description: SecretRef references a key in a secret that will be used as value.
  10229. properties:
  10230. key:
  10231. description: |-
  10232. A key in the referenced Secret.
  10233. Some instances of this field may be defaulted, in others it may be required.
  10234. maxLength: 253
  10235. minLength: 1
  10236. pattern: ^[-._a-zA-Z0-9]+$
  10237. type: string
  10238. name:
  10239. description: The name of the Secret resource being referred to.
  10240. maxLength: 253
  10241. minLength: 1
  10242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10243. type: string
  10244. namespace:
  10245. description: |-
  10246. The namespace of the Secret resource being referred to.
  10247. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10248. maxLength: 63
  10249. minLength: 1
  10250. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10251. type: string
  10252. type: object
  10253. value:
  10254. description: Value can be specified directly to set a value without using a secret.
  10255. type: string
  10256. type: object
  10257. certificate:
  10258. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  10259. properties:
  10260. secretRef:
  10261. description: SecretRef references a key in a secret that will be used as value.
  10262. properties:
  10263. key:
  10264. description: |-
  10265. A key in the referenced Secret.
  10266. Some instances of this field may be defaulted, in others it may be required.
  10267. maxLength: 253
  10268. minLength: 1
  10269. pattern: ^[-._a-zA-Z0-9]+$
  10270. type: string
  10271. name:
  10272. description: The name of the Secret resource being referred to.
  10273. maxLength: 253
  10274. minLength: 1
  10275. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10276. type: string
  10277. namespace:
  10278. description: |-
  10279. The namespace of the Secret resource being referred to.
  10280. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10281. maxLength: 63
  10282. minLength: 1
  10283. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10284. type: string
  10285. type: object
  10286. value:
  10287. description: Value can be specified directly to set a value without using a secret.
  10288. type: string
  10289. type: object
  10290. certificateKey:
  10291. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  10292. properties:
  10293. secretRef:
  10294. description: SecretRef references a key in a secret that will be used as value.
  10295. properties:
  10296. key:
  10297. description: |-
  10298. A key in the referenced Secret.
  10299. Some instances of this field may be defaulted, in others it may be required.
  10300. maxLength: 253
  10301. minLength: 1
  10302. pattern: ^[-._a-zA-Z0-9]+$
  10303. type: string
  10304. name:
  10305. description: The name of the Secret resource being referred to.
  10306. maxLength: 253
  10307. minLength: 1
  10308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10309. type: string
  10310. namespace:
  10311. description: |-
  10312. The namespace of the Secret resource being referred to.
  10313. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10314. maxLength: 63
  10315. minLength: 1
  10316. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10317. type: string
  10318. type: object
  10319. value:
  10320. description: Value can be specified directly to set a value without using a secret.
  10321. type: string
  10322. type: object
  10323. clientId:
  10324. description: ClientID is the API OAuth Client ID.
  10325. properties:
  10326. secretRef:
  10327. description: SecretRef references a key in a secret that will be used as value.
  10328. properties:
  10329. key:
  10330. description: |-
  10331. A key in the referenced Secret.
  10332. Some instances of this field may be defaulted, in others it may be required.
  10333. maxLength: 253
  10334. minLength: 1
  10335. pattern: ^[-._a-zA-Z0-9]+$
  10336. type: string
  10337. name:
  10338. description: The name of the Secret resource being referred to.
  10339. maxLength: 253
  10340. minLength: 1
  10341. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10342. type: string
  10343. namespace:
  10344. description: |-
  10345. The namespace of the Secret resource being referred to.
  10346. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10347. maxLength: 63
  10348. minLength: 1
  10349. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10350. type: string
  10351. type: object
  10352. value:
  10353. description: Value can be specified directly to set a value without using a secret.
  10354. type: string
  10355. type: object
  10356. clientSecret:
  10357. description: ClientSecret is the API OAuth Client Secret.
  10358. properties:
  10359. secretRef:
  10360. description: SecretRef references a key in a secret that will be used as value.
  10361. properties:
  10362. key:
  10363. description: |-
  10364. A key in the referenced Secret.
  10365. Some instances of this field may be defaulted, in others it may be required.
  10366. maxLength: 253
  10367. minLength: 1
  10368. pattern: ^[-._a-zA-Z0-9]+$
  10369. type: string
  10370. name:
  10371. description: The name of the Secret resource being referred to.
  10372. maxLength: 253
  10373. minLength: 1
  10374. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10375. type: string
  10376. namespace:
  10377. description: |-
  10378. The namespace of the Secret resource being referred to.
  10379. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10380. maxLength: 63
  10381. minLength: 1
  10382. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10383. type: string
  10384. type: object
  10385. value:
  10386. description: Value can be specified directly to set a value without using a secret.
  10387. type: string
  10388. type: object
  10389. type: object
  10390. server:
  10391. description: Auth configures how API server works.
  10392. properties:
  10393. apiUrl:
  10394. type: string
  10395. apiVersion:
  10396. type: string
  10397. clientTimeOutSeconds:
  10398. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  10399. type: integer
  10400. decrypt:
  10401. default: true
  10402. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  10403. type: boolean
  10404. retrievalType:
  10405. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  10406. type: string
  10407. separator:
  10408. description: A character that separates the folder names.
  10409. type: string
  10410. verifyCA:
  10411. type: boolean
  10412. required:
  10413. - apiUrl
  10414. - verifyCA
  10415. type: object
  10416. required:
  10417. - auth
  10418. - server
  10419. type: object
  10420. bitwardensecretsmanager:
  10421. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  10422. properties:
  10423. apiURL:
  10424. type: string
  10425. auth:
  10426. description: |-
  10427. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  10428. Make sure that the token being used has permissions on the given secret.
  10429. properties:
  10430. secretRef:
  10431. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  10432. properties:
  10433. credentials:
  10434. description: AccessToken used for the bitwarden instance.
  10435. properties:
  10436. key:
  10437. description: |-
  10438. A key in the referenced Secret.
  10439. Some instances of this field may be defaulted, in others it may be required.
  10440. maxLength: 253
  10441. minLength: 1
  10442. pattern: ^[-._a-zA-Z0-9]+$
  10443. type: string
  10444. name:
  10445. description: The name of the Secret resource being referred to.
  10446. maxLength: 253
  10447. minLength: 1
  10448. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10449. type: string
  10450. namespace:
  10451. description: |-
  10452. The namespace of the Secret resource being referred to.
  10453. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10454. maxLength: 63
  10455. minLength: 1
  10456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10457. type: string
  10458. type: object
  10459. required:
  10460. - credentials
  10461. type: object
  10462. required:
  10463. - secretRef
  10464. type: object
  10465. bitwardenServerSDKURL:
  10466. type: string
  10467. caBundle:
  10468. description: |-
  10469. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  10470. can be performed.
  10471. type: string
  10472. caProvider:
  10473. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  10474. properties:
  10475. key:
  10476. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10477. maxLength: 253
  10478. minLength: 1
  10479. pattern: ^[-._a-zA-Z0-9]+$
  10480. type: string
  10481. name:
  10482. description: The name of the object located at the provider type.
  10483. maxLength: 253
  10484. minLength: 1
  10485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10486. type: string
  10487. namespace:
  10488. description: |-
  10489. The namespace the Provider type is in.
  10490. Can only be defined when used in a ClusterSecretStore.
  10491. maxLength: 63
  10492. minLength: 1
  10493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10494. type: string
  10495. type:
  10496. description: The type of provider to use such as "Secret", or "ConfigMap".
  10497. enum:
  10498. - Secret
  10499. - ConfigMap
  10500. type: string
  10501. required:
  10502. - name
  10503. - type
  10504. type: object
  10505. identityURL:
  10506. type: string
  10507. organizationID:
  10508. description: OrganizationID determines which organization this secret store manages.
  10509. type: string
  10510. projectID:
  10511. description: ProjectID determines which project this secret store manages.
  10512. type: string
  10513. required:
  10514. - auth
  10515. - organizationID
  10516. - projectID
  10517. type: object
  10518. chef:
  10519. description: Chef configures this store to sync secrets with chef server
  10520. properties:
  10521. auth:
  10522. description: Auth defines the information necessary to authenticate against chef Server
  10523. properties:
  10524. secretRef:
  10525. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  10526. properties:
  10527. privateKeySecretRef:
  10528. description: SecretKey is the Signing Key in PEM format, used for authentication.
  10529. properties:
  10530. key:
  10531. description: |-
  10532. A key in the referenced Secret.
  10533. Some instances of this field may be defaulted, in others it may be required.
  10534. maxLength: 253
  10535. minLength: 1
  10536. pattern: ^[-._a-zA-Z0-9]+$
  10537. type: string
  10538. name:
  10539. description: The name of the Secret resource being referred to.
  10540. maxLength: 253
  10541. minLength: 1
  10542. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10543. type: string
  10544. namespace:
  10545. description: |-
  10546. The namespace of the Secret resource being referred to.
  10547. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10548. maxLength: 63
  10549. minLength: 1
  10550. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10551. type: string
  10552. type: object
  10553. required:
  10554. - privateKeySecretRef
  10555. type: object
  10556. required:
  10557. - secretRef
  10558. type: object
  10559. serverUrl:
  10560. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  10561. type: string
  10562. username:
  10563. description: UserName should be the user ID on the chef server
  10564. type: string
  10565. required:
  10566. - auth
  10567. - serverUrl
  10568. - username
  10569. type: object
  10570. cloudrusm:
  10571. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  10572. properties:
  10573. auth:
  10574. description: CSMAuth contains a secretRef for credentials.
  10575. properties:
  10576. secretRef:
  10577. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  10578. properties:
  10579. accessKeyIDSecretRef:
  10580. description: The AccessKeyID is used for authentication
  10581. properties:
  10582. key:
  10583. description: |-
  10584. A key in the referenced Secret.
  10585. Some instances of this field may be defaulted, in others it may be required.
  10586. maxLength: 253
  10587. minLength: 1
  10588. pattern: ^[-._a-zA-Z0-9]+$
  10589. type: string
  10590. name:
  10591. description: The name of the Secret resource being referred to.
  10592. maxLength: 253
  10593. minLength: 1
  10594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10595. type: string
  10596. namespace:
  10597. description: |-
  10598. The namespace of the Secret resource being referred to.
  10599. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10600. maxLength: 63
  10601. minLength: 1
  10602. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10603. type: string
  10604. type: object
  10605. accessKeySecretSecretRef:
  10606. description: The AccessKeySecret is used for authentication
  10607. properties:
  10608. key:
  10609. description: |-
  10610. A key in the referenced Secret.
  10611. Some instances of this field may be defaulted, in others it may be required.
  10612. maxLength: 253
  10613. minLength: 1
  10614. pattern: ^[-._a-zA-Z0-9]+$
  10615. type: string
  10616. name:
  10617. description: The name of the Secret resource being referred to.
  10618. maxLength: 253
  10619. minLength: 1
  10620. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10621. type: string
  10622. namespace:
  10623. description: |-
  10624. The namespace of the Secret resource being referred to.
  10625. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10626. maxLength: 63
  10627. minLength: 1
  10628. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10629. type: string
  10630. type: object
  10631. required:
  10632. - accessKeyIDSecretRef
  10633. - accessKeySecretSecretRef
  10634. type: object
  10635. type: object
  10636. projectID:
  10637. description: ProjectID is the project, which the secrets are stored in.
  10638. type: string
  10639. required:
  10640. - auth
  10641. type: object
  10642. conjur:
  10643. description: Conjur configures this store to sync secrets using conjur provider
  10644. properties:
  10645. auth:
  10646. description: Defines authentication settings for connecting to Conjur.
  10647. properties:
  10648. apikey:
  10649. description: Authenticates with Conjur using an API key.
  10650. properties:
  10651. account:
  10652. description: Account is the Conjur organization account name.
  10653. type: string
  10654. apiKeyRef:
  10655. description: |-
  10656. A reference to a specific 'key' containing the Conjur API key
  10657. within a Secret resource. In some instances, `key` is a required field.
  10658. properties:
  10659. key:
  10660. description: |-
  10661. A key in the referenced Secret.
  10662. Some instances of this field may be defaulted, in others it may be required.
  10663. maxLength: 253
  10664. minLength: 1
  10665. pattern: ^[-._a-zA-Z0-9]+$
  10666. type: string
  10667. name:
  10668. description: The name of the Secret resource being referred to.
  10669. maxLength: 253
  10670. minLength: 1
  10671. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10672. type: string
  10673. namespace:
  10674. description: |-
  10675. The namespace of the Secret resource being referred to.
  10676. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10677. maxLength: 63
  10678. minLength: 1
  10679. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10680. type: string
  10681. type: object
  10682. userRef:
  10683. description: |-
  10684. A reference to a specific 'key' containing the Conjur username
  10685. within a Secret resource. In some instances, `key` is a required field.
  10686. properties:
  10687. key:
  10688. description: |-
  10689. A key in the referenced Secret.
  10690. Some instances of this field may be defaulted, in others it may be required.
  10691. maxLength: 253
  10692. minLength: 1
  10693. pattern: ^[-._a-zA-Z0-9]+$
  10694. type: string
  10695. name:
  10696. description: The name of the Secret resource being referred to.
  10697. maxLength: 253
  10698. minLength: 1
  10699. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10700. type: string
  10701. namespace:
  10702. description: |-
  10703. The namespace of the Secret resource being referred to.
  10704. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10705. maxLength: 63
  10706. minLength: 1
  10707. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10708. type: string
  10709. type: object
  10710. required:
  10711. - account
  10712. - apiKeyRef
  10713. - userRef
  10714. type: object
  10715. jwt:
  10716. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  10717. properties:
  10718. account:
  10719. description: Account is the Conjur organization account name.
  10720. type: string
  10721. hostId:
  10722. description: |-
  10723. Optional HostID for JWT authentication. This may be used depending
  10724. on how the Conjur JWT authenticator policy is configured.
  10725. type: string
  10726. secretRef:
  10727. description: |-
  10728. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  10729. authenticate with Conjur using the JWT authentication method.
  10730. properties:
  10731. key:
  10732. description: |-
  10733. A key in the referenced Secret.
  10734. Some instances of this field may be defaulted, in others it may be required.
  10735. maxLength: 253
  10736. minLength: 1
  10737. pattern: ^[-._a-zA-Z0-9]+$
  10738. type: string
  10739. name:
  10740. description: The name of the Secret resource being referred to.
  10741. maxLength: 253
  10742. minLength: 1
  10743. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10744. type: string
  10745. namespace:
  10746. description: |-
  10747. The namespace of the Secret resource being referred to.
  10748. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10749. maxLength: 63
  10750. minLength: 1
  10751. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10752. type: string
  10753. type: object
  10754. serviceAccountRef:
  10755. description: |-
  10756. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  10757. a token for with the `TokenRequest` API.
  10758. properties:
  10759. audiences:
  10760. description: |-
  10761. Audience specifies the `aud` claim for the service account token
  10762. Some providers automatically extend the audience field based on well-known annotations for workload
  10763. identity (e.g. IRSA or GCP Workload Identity)
  10764. items:
  10765. type: string
  10766. type: array
  10767. name:
  10768. description: The name of the ServiceAccount resource being referred to.
  10769. maxLength: 253
  10770. minLength: 1
  10771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10772. type: string
  10773. namespace:
  10774. description: |-
  10775. Namespace of the resource being referred to.
  10776. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10777. maxLength: 63
  10778. minLength: 1
  10779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10780. type: string
  10781. required:
  10782. - name
  10783. type: object
  10784. serviceID:
  10785. description: The conjur authn jwt webservice id
  10786. type: string
  10787. required:
  10788. - account
  10789. - serviceID
  10790. type: object
  10791. type: object
  10792. caBundle:
  10793. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  10794. type: string
  10795. caProvider:
  10796. description: |-
  10797. Used to provide custom certificate authority (CA) certificates
  10798. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  10799. that contains a PEM-encoded certificate.
  10800. properties:
  10801. key:
  10802. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10803. maxLength: 253
  10804. minLength: 1
  10805. pattern: ^[-._a-zA-Z0-9]+$
  10806. type: string
  10807. name:
  10808. description: The name of the object located at the provider type.
  10809. maxLength: 253
  10810. minLength: 1
  10811. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10812. type: string
  10813. namespace:
  10814. description: |-
  10815. The namespace the Provider type is in.
  10816. Can only be defined when used in a ClusterSecretStore.
  10817. maxLength: 63
  10818. minLength: 1
  10819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10820. type: string
  10821. type:
  10822. description: The type of provider to use such as "Secret", or "ConfigMap".
  10823. enum:
  10824. - Secret
  10825. - ConfigMap
  10826. type: string
  10827. required:
  10828. - name
  10829. - type
  10830. type: object
  10831. url:
  10832. description: URL is the endpoint of the Conjur instance.
  10833. type: string
  10834. required:
  10835. - auth
  10836. - url
  10837. type: object
  10838. delinea:
  10839. description: |-
  10840. Delinea DevOps Secrets Vault
  10841. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  10842. properties:
  10843. clientId:
  10844. description: ClientID is the non-secret part of the credential.
  10845. properties:
  10846. secretRef:
  10847. description: SecretRef references a key in a secret that will be used as value.
  10848. properties:
  10849. key:
  10850. description: |-
  10851. A key in the referenced Secret.
  10852. Some instances of this field may be defaulted, in others it may be required.
  10853. maxLength: 253
  10854. minLength: 1
  10855. pattern: ^[-._a-zA-Z0-9]+$
  10856. type: string
  10857. name:
  10858. description: The name of the Secret resource being referred to.
  10859. maxLength: 253
  10860. minLength: 1
  10861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10862. type: string
  10863. namespace:
  10864. description: |-
  10865. The namespace of the Secret resource being referred to.
  10866. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10867. maxLength: 63
  10868. minLength: 1
  10869. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10870. type: string
  10871. type: object
  10872. value:
  10873. description: Value can be specified directly to set a value without using a secret.
  10874. type: string
  10875. type: object
  10876. clientSecret:
  10877. description: ClientSecret is the secret part of the credential.
  10878. properties:
  10879. secretRef:
  10880. description: SecretRef references a key in a secret that will be used as value.
  10881. properties:
  10882. key:
  10883. description: |-
  10884. A key in the referenced Secret.
  10885. Some instances of this field may be defaulted, in others it may be required.
  10886. maxLength: 253
  10887. minLength: 1
  10888. pattern: ^[-._a-zA-Z0-9]+$
  10889. type: string
  10890. name:
  10891. description: The name of the Secret resource being referred to.
  10892. maxLength: 253
  10893. minLength: 1
  10894. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10895. type: string
  10896. namespace:
  10897. description: |-
  10898. The namespace of the Secret resource being referred to.
  10899. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10900. maxLength: 63
  10901. minLength: 1
  10902. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10903. type: string
  10904. type: object
  10905. value:
  10906. description: Value can be specified directly to set a value without using a secret.
  10907. type: string
  10908. type: object
  10909. tenant:
  10910. description: Tenant is the chosen hostname / site name.
  10911. type: string
  10912. tld:
  10913. description: |-
  10914. TLD is based on the server location that was chosen during provisioning.
  10915. If unset, defaults to "com".
  10916. type: string
  10917. urlTemplate:
  10918. description: |-
  10919. URLTemplate
  10920. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  10921. type: string
  10922. required:
  10923. - clientId
  10924. - clientSecret
  10925. - tenant
  10926. type: object
  10927. device42:
  10928. description: Device42 configures this store to sync secrets using the Device42 provider
  10929. properties:
  10930. auth:
  10931. description: Auth configures how secret-manager authenticates with a Device42 instance.
  10932. properties:
  10933. secretRef:
  10934. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  10935. properties:
  10936. credentials:
  10937. description: Username / Password is used for authentication.
  10938. properties:
  10939. key:
  10940. description: |-
  10941. A key in the referenced Secret.
  10942. Some instances of this field may be defaulted, in others it may be required.
  10943. maxLength: 253
  10944. minLength: 1
  10945. pattern: ^[-._a-zA-Z0-9]+$
  10946. type: string
  10947. name:
  10948. description: The name of the Secret resource being referred to.
  10949. maxLength: 253
  10950. minLength: 1
  10951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10952. type: string
  10953. namespace:
  10954. description: |-
  10955. The namespace of the Secret resource being referred to.
  10956. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10957. maxLength: 63
  10958. minLength: 1
  10959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10960. type: string
  10961. type: object
  10962. type: object
  10963. required:
  10964. - secretRef
  10965. type: object
  10966. host:
  10967. description: URL configures the Device42 instance URL.
  10968. type: string
  10969. required:
  10970. - auth
  10971. - host
  10972. type: object
  10973. doppler:
  10974. description: Doppler configures this store to sync secrets using the Doppler provider
  10975. properties:
  10976. auth:
  10977. description: Auth configures how the Operator authenticates with the Doppler API
  10978. properties:
  10979. secretRef:
  10980. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  10981. properties:
  10982. dopplerToken:
  10983. description: |-
  10984. The DopplerToken is used for authentication.
  10985. See https://docs.doppler.com/reference/api#authentication for auth token types.
  10986. The Key attribute defaults to dopplerToken if not specified.
  10987. properties:
  10988. key:
  10989. description: |-
  10990. A key in the referenced Secret.
  10991. Some instances of this field may be defaulted, in others it may be required.
  10992. maxLength: 253
  10993. minLength: 1
  10994. pattern: ^[-._a-zA-Z0-9]+$
  10995. type: string
  10996. name:
  10997. description: The name of the Secret resource being referred to.
  10998. maxLength: 253
  10999. minLength: 1
  11000. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11001. type: string
  11002. namespace:
  11003. description: |-
  11004. The namespace of the Secret resource being referred to.
  11005. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11006. maxLength: 63
  11007. minLength: 1
  11008. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11009. type: string
  11010. type: object
  11011. required:
  11012. - dopplerToken
  11013. type: object
  11014. required:
  11015. - secretRef
  11016. type: object
  11017. config:
  11018. description: Doppler config (required if not using a Service Token)
  11019. type: string
  11020. format:
  11021. description: Format enables the downloading of secrets as a file (string)
  11022. enum:
  11023. - json
  11024. - dotnet-json
  11025. - env
  11026. - yaml
  11027. - docker
  11028. type: string
  11029. nameTransformer:
  11030. description: Environment variable compatible name transforms that change secret names to a different format
  11031. enum:
  11032. - upper-camel
  11033. - camel
  11034. - lower-snake
  11035. - tf-var
  11036. - dotnet-env
  11037. - lower-kebab
  11038. type: string
  11039. project:
  11040. description: Doppler project (required if not using a Service Token)
  11041. type: string
  11042. required:
  11043. - auth
  11044. type: object
  11045. fake:
  11046. description: Fake configures a store with static key/value pairs
  11047. properties:
  11048. data:
  11049. items:
  11050. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  11051. properties:
  11052. key:
  11053. type: string
  11054. value:
  11055. type: string
  11056. version:
  11057. type: string
  11058. required:
  11059. - key
  11060. - value
  11061. type: object
  11062. type: array
  11063. required:
  11064. - data
  11065. type: object
  11066. fortanix:
  11067. description: Fortanix configures this store to sync secrets using the Fortanix provider
  11068. properties:
  11069. apiKey:
  11070. description: APIKey is the API token to access SDKMS Applications.
  11071. properties:
  11072. secretRef:
  11073. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  11074. properties:
  11075. key:
  11076. description: |-
  11077. A key in the referenced Secret.
  11078. Some instances of this field may be defaulted, in others it may be required.
  11079. maxLength: 253
  11080. minLength: 1
  11081. pattern: ^[-._a-zA-Z0-9]+$
  11082. type: string
  11083. name:
  11084. description: The name of the Secret resource being referred to.
  11085. maxLength: 253
  11086. minLength: 1
  11087. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11088. type: string
  11089. namespace:
  11090. description: |-
  11091. The namespace of the Secret resource being referred to.
  11092. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11093. maxLength: 63
  11094. minLength: 1
  11095. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11096. type: string
  11097. type: object
  11098. type: object
  11099. apiUrl:
  11100. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  11101. type: string
  11102. type: object
  11103. gcpsm:
  11104. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  11105. properties:
  11106. auth:
  11107. description: Auth defines the information necessary to authenticate against GCP
  11108. properties:
  11109. secretRef:
  11110. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  11111. properties:
  11112. secretAccessKeySecretRef:
  11113. description: The SecretAccessKey is used for authentication
  11114. properties:
  11115. key:
  11116. description: |-
  11117. A key in the referenced Secret.
  11118. Some instances of this field may be defaulted, in others it may be required.
  11119. maxLength: 253
  11120. minLength: 1
  11121. pattern: ^[-._a-zA-Z0-9]+$
  11122. type: string
  11123. name:
  11124. description: The name of the Secret resource being referred to.
  11125. maxLength: 253
  11126. minLength: 1
  11127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11128. type: string
  11129. namespace:
  11130. description: |-
  11131. The namespace of the Secret resource being referred to.
  11132. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11133. maxLength: 63
  11134. minLength: 1
  11135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11136. type: string
  11137. type: object
  11138. type: object
  11139. workloadIdentity:
  11140. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  11141. properties:
  11142. clusterLocation:
  11143. description: |-
  11144. ClusterLocation is the location of the cluster
  11145. If not specified, it fetches information from the metadata server
  11146. type: string
  11147. clusterName:
  11148. description: |-
  11149. ClusterName is the name of the cluster
  11150. If not specified, it fetches information from the metadata server
  11151. type: string
  11152. clusterProjectID:
  11153. description: |-
  11154. ClusterProjectID is the project ID of the cluster
  11155. If not specified, it fetches information from the metadata server
  11156. type: string
  11157. serviceAccountRef:
  11158. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  11159. properties:
  11160. audiences:
  11161. description: |-
  11162. Audience specifies the `aud` claim for the service account token
  11163. Some providers automatically extend the audience field based on well-known annotations for workload
  11164. identity (e.g. IRSA or GCP Workload Identity)
  11165. items:
  11166. type: string
  11167. type: array
  11168. name:
  11169. description: The name of the ServiceAccount resource being referred to.
  11170. maxLength: 253
  11171. minLength: 1
  11172. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11173. type: string
  11174. namespace:
  11175. description: |-
  11176. Namespace of the resource being referred to.
  11177. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11178. maxLength: 63
  11179. minLength: 1
  11180. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11181. type: string
  11182. required:
  11183. - name
  11184. type: object
  11185. required:
  11186. - serviceAccountRef
  11187. type: object
  11188. type: object
  11189. location:
  11190. description: Location optionally defines a location for a secret
  11191. type: string
  11192. projectID:
  11193. description: ProjectID project where secret is located
  11194. type: string
  11195. type: object
  11196. github:
  11197. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  11198. properties:
  11199. appID:
  11200. description: appID specifies the Github APP that will be used to authenticate the client
  11201. format: int64
  11202. type: integer
  11203. auth:
  11204. description: auth configures how secret-manager authenticates with a Github instance.
  11205. properties:
  11206. privateKey:
  11207. description: |-
  11208. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11209. In some instances, `key` is a required field.
  11210. properties:
  11211. key:
  11212. description: |-
  11213. A key in the referenced Secret.
  11214. Some instances of this field may be defaulted, in others it may be required.
  11215. maxLength: 253
  11216. minLength: 1
  11217. pattern: ^[-._a-zA-Z0-9]+$
  11218. type: string
  11219. name:
  11220. description: The name of the Secret resource being referred to.
  11221. maxLength: 253
  11222. minLength: 1
  11223. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11224. type: string
  11225. namespace:
  11226. description: |-
  11227. The namespace of the Secret resource being referred to.
  11228. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11229. maxLength: 63
  11230. minLength: 1
  11231. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11232. type: string
  11233. type: object
  11234. required:
  11235. - privateKey
  11236. type: object
  11237. environment:
  11238. description: environment will be used to fetch secrets from a particular environment within a github repository
  11239. type: string
  11240. installationID:
  11241. description: installationID specifies the Github APP installation that will be used to authenticate the client
  11242. format: int64
  11243. type: integer
  11244. organization:
  11245. description: organization will be used to fetch secrets from the Github organization
  11246. type: string
  11247. repository:
  11248. description: repository will be used to fetch secrets from the Github repository within an organization
  11249. type: string
  11250. uploadURL:
  11251. description: Upload URL for enterprise instances. Default to URL.
  11252. type: string
  11253. url:
  11254. default: https://github.com/
  11255. description: URL configures the Github instance URL. Defaults to https://github.com/.
  11256. type: string
  11257. required:
  11258. - appID
  11259. - auth
  11260. - installationID
  11261. - organization
  11262. type: object
  11263. gitlab:
  11264. description: GitLab configures this store to sync secrets using GitLab Variables provider
  11265. properties:
  11266. auth:
  11267. description: Auth configures how secret-manager authenticates with a GitLab instance.
  11268. properties:
  11269. SecretRef:
  11270. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  11271. properties:
  11272. accessToken:
  11273. description: AccessToken is used for authentication.
  11274. properties:
  11275. key:
  11276. description: |-
  11277. A key in the referenced Secret.
  11278. Some instances of this field may be defaulted, in others it may be required.
  11279. maxLength: 253
  11280. minLength: 1
  11281. pattern: ^[-._a-zA-Z0-9]+$
  11282. type: string
  11283. name:
  11284. description: The name of the Secret resource being referred to.
  11285. maxLength: 253
  11286. minLength: 1
  11287. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11288. type: string
  11289. namespace:
  11290. description: |-
  11291. The namespace of the Secret resource being referred to.
  11292. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11293. maxLength: 63
  11294. minLength: 1
  11295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11296. type: string
  11297. type: object
  11298. type: object
  11299. required:
  11300. - SecretRef
  11301. type: object
  11302. caBundle:
  11303. description: |-
  11304. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  11305. can be performed.
  11306. format: byte
  11307. type: string
  11308. caProvider:
  11309. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  11310. properties:
  11311. key:
  11312. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11313. maxLength: 253
  11314. minLength: 1
  11315. pattern: ^[-._a-zA-Z0-9]+$
  11316. type: string
  11317. name:
  11318. description: The name of the object located at the provider type.
  11319. maxLength: 253
  11320. minLength: 1
  11321. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11322. type: string
  11323. namespace:
  11324. description: |-
  11325. The namespace the Provider type is in.
  11326. Can only be defined when used in a ClusterSecretStore.
  11327. maxLength: 63
  11328. minLength: 1
  11329. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11330. type: string
  11331. type:
  11332. description: The type of provider to use such as "Secret", or "ConfigMap".
  11333. enum:
  11334. - Secret
  11335. - ConfigMap
  11336. type: string
  11337. required:
  11338. - name
  11339. - type
  11340. type: object
  11341. environment:
  11342. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  11343. type: string
  11344. groupIDs:
  11345. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  11346. items:
  11347. type: string
  11348. type: array
  11349. inheritFromGroups:
  11350. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  11351. type: boolean
  11352. projectID:
  11353. description: ProjectID specifies a project where secrets are located.
  11354. type: string
  11355. url:
  11356. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  11357. type: string
  11358. required:
  11359. - auth
  11360. type: object
  11361. ibm:
  11362. description: IBM configures this store to sync secrets using IBM Cloud provider
  11363. properties:
  11364. auth:
  11365. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  11366. maxProperties: 1
  11367. minProperties: 1
  11368. properties:
  11369. containerAuth:
  11370. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  11371. properties:
  11372. iamEndpoint:
  11373. type: string
  11374. profile:
  11375. description: the IBM Trusted Profile
  11376. type: string
  11377. tokenLocation:
  11378. description: Location the token is mounted on the pod
  11379. type: string
  11380. required:
  11381. - profile
  11382. type: object
  11383. secretRef:
  11384. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  11385. properties:
  11386. secretApiKeySecretRef:
  11387. description: The SecretAccessKey is used for authentication
  11388. properties:
  11389. key:
  11390. description: |-
  11391. A key in the referenced Secret.
  11392. Some instances of this field may be defaulted, in others it may be required.
  11393. maxLength: 253
  11394. minLength: 1
  11395. pattern: ^[-._a-zA-Z0-9]+$
  11396. type: string
  11397. name:
  11398. description: The name of the Secret resource being referred to.
  11399. maxLength: 253
  11400. minLength: 1
  11401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11402. type: string
  11403. namespace:
  11404. description: |-
  11405. The namespace of the Secret resource being referred to.
  11406. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11407. maxLength: 63
  11408. minLength: 1
  11409. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11410. type: string
  11411. type: object
  11412. type: object
  11413. type: object
  11414. serviceUrl:
  11415. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  11416. type: string
  11417. required:
  11418. - auth
  11419. type: object
  11420. infisical:
  11421. description: Infisical configures this store to sync secrets using the Infisical provider
  11422. properties:
  11423. auth:
  11424. description: Auth configures how the Operator authenticates with the Infisical API
  11425. properties:
  11426. universalAuthCredentials:
  11427. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  11428. properties:
  11429. clientId:
  11430. description: |-
  11431. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11432. In some instances, `key` is a required field.
  11433. properties:
  11434. key:
  11435. description: |-
  11436. A key in the referenced Secret.
  11437. Some instances of this field may be defaulted, in others it may be required.
  11438. maxLength: 253
  11439. minLength: 1
  11440. pattern: ^[-._a-zA-Z0-9]+$
  11441. type: string
  11442. name:
  11443. description: The name of the Secret resource being referred to.
  11444. maxLength: 253
  11445. minLength: 1
  11446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11447. type: string
  11448. namespace:
  11449. description: |-
  11450. The namespace of the Secret resource being referred to.
  11451. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11452. maxLength: 63
  11453. minLength: 1
  11454. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11455. type: string
  11456. type: object
  11457. clientSecret:
  11458. description: |-
  11459. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11460. In some instances, `key` is a required field.
  11461. properties:
  11462. key:
  11463. description: |-
  11464. A key in the referenced Secret.
  11465. Some instances of this field may be defaulted, in others it may be required.
  11466. maxLength: 253
  11467. minLength: 1
  11468. pattern: ^[-._a-zA-Z0-9]+$
  11469. type: string
  11470. name:
  11471. description: The name of the Secret resource being referred to.
  11472. maxLength: 253
  11473. minLength: 1
  11474. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11475. type: string
  11476. namespace:
  11477. description: |-
  11478. The namespace of the Secret resource being referred to.
  11479. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11480. maxLength: 63
  11481. minLength: 1
  11482. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11483. type: string
  11484. type: object
  11485. required:
  11486. - clientId
  11487. - clientSecret
  11488. type: object
  11489. type: object
  11490. hostAPI:
  11491. default: https://app.infisical.com/api
  11492. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  11493. type: string
  11494. secretsScope:
  11495. description: SecretsScope defines the scope of the secrets within the workspace
  11496. properties:
  11497. environmentSlug:
  11498. description: EnvironmentSlug is the required slug identifier for the environment.
  11499. type: string
  11500. expandSecretReferences:
  11501. default: true
  11502. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  11503. type: boolean
  11504. projectSlug:
  11505. description: ProjectSlug is the required slug identifier for the project.
  11506. type: string
  11507. recursive:
  11508. default: false
  11509. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  11510. type: boolean
  11511. secretsPath:
  11512. default: /
  11513. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  11514. type: string
  11515. required:
  11516. - environmentSlug
  11517. - projectSlug
  11518. type: object
  11519. required:
  11520. - auth
  11521. - secretsScope
  11522. type: object
  11523. keepersecurity:
  11524. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  11525. properties:
  11526. authRef:
  11527. description: |-
  11528. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11529. In some instances, `key` is a required field.
  11530. properties:
  11531. key:
  11532. description: |-
  11533. A key in the referenced Secret.
  11534. Some instances of this field may be defaulted, in others it may be required.
  11535. maxLength: 253
  11536. minLength: 1
  11537. pattern: ^[-._a-zA-Z0-9]+$
  11538. type: string
  11539. name:
  11540. description: The name of the Secret resource being referred to.
  11541. maxLength: 253
  11542. minLength: 1
  11543. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11544. type: string
  11545. namespace:
  11546. description: |-
  11547. The namespace of the Secret resource being referred to.
  11548. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11549. maxLength: 63
  11550. minLength: 1
  11551. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11552. type: string
  11553. type: object
  11554. folderID:
  11555. type: string
  11556. required:
  11557. - authRef
  11558. - folderID
  11559. type: object
  11560. kubernetes:
  11561. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  11562. properties:
  11563. auth:
  11564. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  11565. maxProperties: 1
  11566. minProperties: 1
  11567. properties:
  11568. cert:
  11569. description: has both clientCert and clientKey as secretKeySelector
  11570. properties:
  11571. clientCert:
  11572. description: |-
  11573. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11574. In some instances, `key` is a required field.
  11575. properties:
  11576. key:
  11577. description: |-
  11578. A key in the referenced Secret.
  11579. Some instances of this field may be defaulted, in others it may be required.
  11580. maxLength: 253
  11581. minLength: 1
  11582. pattern: ^[-._a-zA-Z0-9]+$
  11583. type: string
  11584. name:
  11585. description: The name of the Secret resource being referred to.
  11586. maxLength: 253
  11587. minLength: 1
  11588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11589. type: string
  11590. namespace:
  11591. description: |-
  11592. The namespace of the Secret resource being referred to.
  11593. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11594. maxLength: 63
  11595. minLength: 1
  11596. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11597. type: string
  11598. type: object
  11599. clientKey:
  11600. description: |-
  11601. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11602. In some instances, `key` is a required field.
  11603. properties:
  11604. key:
  11605. description: |-
  11606. A key in the referenced Secret.
  11607. Some instances of this field may be defaulted, in others it may be required.
  11608. maxLength: 253
  11609. minLength: 1
  11610. pattern: ^[-._a-zA-Z0-9]+$
  11611. type: string
  11612. name:
  11613. description: The name of the Secret resource being referred to.
  11614. maxLength: 253
  11615. minLength: 1
  11616. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11617. type: string
  11618. namespace:
  11619. description: |-
  11620. The namespace of the Secret resource being referred to.
  11621. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11622. maxLength: 63
  11623. minLength: 1
  11624. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11625. type: string
  11626. type: object
  11627. type: object
  11628. serviceAccount:
  11629. description: points to a service account that should be used for authentication
  11630. properties:
  11631. audiences:
  11632. description: |-
  11633. Audience specifies the `aud` claim for the service account token
  11634. Some providers automatically extend the audience field based on well-known annotations for workload
  11635. identity (e.g. IRSA or GCP Workload Identity)
  11636. items:
  11637. type: string
  11638. type: array
  11639. name:
  11640. description: The name of the ServiceAccount resource being referred to.
  11641. maxLength: 253
  11642. minLength: 1
  11643. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11644. type: string
  11645. namespace:
  11646. description: |-
  11647. Namespace of the resource being referred to.
  11648. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11649. maxLength: 63
  11650. minLength: 1
  11651. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11652. type: string
  11653. required:
  11654. - name
  11655. type: object
  11656. token:
  11657. description: use static token to authenticate with
  11658. properties:
  11659. bearerToken:
  11660. description: |-
  11661. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11662. In some instances, `key` is a required field.
  11663. properties:
  11664. key:
  11665. description: |-
  11666. A key in the referenced Secret.
  11667. Some instances of this field may be defaulted, in others it may be required.
  11668. maxLength: 253
  11669. minLength: 1
  11670. pattern: ^[-._a-zA-Z0-9]+$
  11671. type: string
  11672. name:
  11673. description: The name of the Secret resource being referred to.
  11674. maxLength: 253
  11675. minLength: 1
  11676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11677. type: string
  11678. namespace:
  11679. description: |-
  11680. The namespace of the Secret resource being referred to.
  11681. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11682. maxLength: 63
  11683. minLength: 1
  11684. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11685. type: string
  11686. type: object
  11687. type: object
  11688. type: object
  11689. authRef:
  11690. description: A reference to a secret that contains the auth information.
  11691. properties:
  11692. key:
  11693. description: |-
  11694. A key in the referenced Secret.
  11695. Some instances of this field may be defaulted, in others it may be required.
  11696. maxLength: 253
  11697. minLength: 1
  11698. pattern: ^[-._a-zA-Z0-9]+$
  11699. type: string
  11700. name:
  11701. description: The name of the Secret resource being referred to.
  11702. maxLength: 253
  11703. minLength: 1
  11704. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11705. type: string
  11706. namespace:
  11707. description: |-
  11708. The namespace of the Secret resource being referred to.
  11709. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11710. maxLength: 63
  11711. minLength: 1
  11712. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11713. type: string
  11714. type: object
  11715. remoteNamespace:
  11716. default: default
  11717. description: Remote namespace to fetch the secrets from
  11718. maxLength: 63
  11719. minLength: 1
  11720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11721. type: string
  11722. server:
  11723. description: configures the Kubernetes server Address.
  11724. properties:
  11725. caBundle:
  11726. description: CABundle is a base64-encoded CA certificate
  11727. format: byte
  11728. type: string
  11729. caProvider:
  11730. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  11731. properties:
  11732. key:
  11733. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11734. maxLength: 253
  11735. minLength: 1
  11736. pattern: ^[-._a-zA-Z0-9]+$
  11737. type: string
  11738. name:
  11739. description: The name of the object located at the provider type.
  11740. maxLength: 253
  11741. minLength: 1
  11742. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11743. type: string
  11744. namespace:
  11745. description: |-
  11746. The namespace the Provider type is in.
  11747. Can only be defined when used in a ClusterSecretStore.
  11748. maxLength: 63
  11749. minLength: 1
  11750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11751. type: string
  11752. type:
  11753. description: The type of provider to use such as "Secret", or "ConfigMap".
  11754. enum:
  11755. - Secret
  11756. - ConfigMap
  11757. type: string
  11758. required:
  11759. - name
  11760. - type
  11761. type: object
  11762. url:
  11763. default: kubernetes.default
  11764. description: configures the Kubernetes server Address.
  11765. type: string
  11766. type: object
  11767. type: object
  11768. onboardbase:
  11769. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  11770. properties:
  11771. apiHost:
  11772. default: https://public.onboardbase.com/api/v1/
  11773. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  11774. type: string
  11775. auth:
  11776. description: Auth configures how the Operator authenticates with the Onboardbase API
  11777. properties:
  11778. apiKeyRef:
  11779. description: |-
  11780. OnboardbaseAPIKey is the APIKey generated by an admin account.
  11781. It is used to recognize and authorize access to a project and environment within onboardbase
  11782. properties:
  11783. key:
  11784. description: |-
  11785. A key in the referenced Secret.
  11786. Some instances of this field may be defaulted, in others it may be required.
  11787. maxLength: 253
  11788. minLength: 1
  11789. pattern: ^[-._a-zA-Z0-9]+$
  11790. type: string
  11791. name:
  11792. description: The name of the Secret resource being referred to.
  11793. maxLength: 253
  11794. minLength: 1
  11795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11796. type: string
  11797. namespace:
  11798. description: |-
  11799. The namespace of the Secret resource being referred to.
  11800. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11801. maxLength: 63
  11802. minLength: 1
  11803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11804. type: string
  11805. type: object
  11806. passcodeRef:
  11807. description: OnboardbasePasscode is the passcode attached to the API Key
  11808. properties:
  11809. key:
  11810. description: |-
  11811. A key in the referenced Secret.
  11812. Some instances of this field may be defaulted, in others it may be required.
  11813. maxLength: 253
  11814. minLength: 1
  11815. pattern: ^[-._a-zA-Z0-9]+$
  11816. type: string
  11817. name:
  11818. description: The name of the Secret resource being referred to.
  11819. maxLength: 253
  11820. minLength: 1
  11821. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11822. type: string
  11823. namespace:
  11824. description: |-
  11825. The namespace of the Secret resource being referred to.
  11826. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11827. maxLength: 63
  11828. minLength: 1
  11829. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11830. type: string
  11831. type: object
  11832. required:
  11833. - apiKeyRef
  11834. - passcodeRef
  11835. type: object
  11836. environment:
  11837. default: development
  11838. description: Environment is the name of an environmnent within a project to pull the secrets from
  11839. type: string
  11840. project:
  11841. default: development
  11842. description: Project is an onboardbase project that the secrets should be pulled from
  11843. type: string
  11844. required:
  11845. - apiHost
  11846. - auth
  11847. - environment
  11848. - project
  11849. type: object
  11850. onepassword:
  11851. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  11852. properties:
  11853. auth:
  11854. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  11855. properties:
  11856. secretRef:
  11857. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  11858. properties:
  11859. connectTokenSecretRef:
  11860. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  11861. properties:
  11862. key:
  11863. description: |-
  11864. A key in the referenced Secret.
  11865. Some instances of this field may be defaulted, in others it may be required.
  11866. maxLength: 253
  11867. minLength: 1
  11868. pattern: ^[-._a-zA-Z0-9]+$
  11869. type: string
  11870. name:
  11871. description: The name of the Secret resource being referred to.
  11872. maxLength: 253
  11873. minLength: 1
  11874. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11875. type: string
  11876. namespace:
  11877. description: |-
  11878. The namespace of the Secret resource being referred to.
  11879. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11880. maxLength: 63
  11881. minLength: 1
  11882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11883. type: string
  11884. type: object
  11885. required:
  11886. - connectTokenSecretRef
  11887. type: object
  11888. required:
  11889. - secretRef
  11890. type: object
  11891. connectHost:
  11892. description: ConnectHost defines the OnePassword Connect Server to connect to
  11893. type: string
  11894. vaults:
  11895. additionalProperties:
  11896. type: integer
  11897. description: Vaults defines which OnePassword vaults to search in which order
  11898. type: object
  11899. required:
  11900. - auth
  11901. - connectHost
  11902. - vaults
  11903. type: object
  11904. oracle:
  11905. description: Oracle configures this store to sync secrets using Oracle Vault provider
  11906. properties:
  11907. auth:
  11908. description: |-
  11909. Auth configures how secret-manager authenticates with the Oracle Vault.
  11910. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  11911. properties:
  11912. secretRef:
  11913. description: SecretRef to pass through sensitive information.
  11914. properties:
  11915. fingerprint:
  11916. description: Fingerprint is the fingerprint of the API private key.
  11917. properties:
  11918. key:
  11919. description: |-
  11920. A key in the referenced Secret.
  11921. Some instances of this field may be defaulted, in others it may be required.
  11922. maxLength: 253
  11923. minLength: 1
  11924. pattern: ^[-._a-zA-Z0-9]+$
  11925. type: string
  11926. name:
  11927. description: The name of the Secret resource being referred to.
  11928. maxLength: 253
  11929. minLength: 1
  11930. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11931. type: string
  11932. namespace:
  11933. description: |-
  11934. The namespace of the Secret resource being referred to.
  11935. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11936. maxLength: 63
  11937. minLength: 1
  11938. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11939. type: string
  11940. type: object
  11941. privatekey:
  11942. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  11943. properties:
  11944. key:
  11945. description: |-
  11946. A key in the referenced Secret.
  11947. Some instances of this field may be defaulted, in others it may be required.
  11948. maxLength: 253
  11949. minLength: 1
  11950. pattern: ^[-._a-zA-Z0-9]+$
  11951. type: string
  11952. name:
  11953. description: The name of the Secret resource being referred to.
  11954. maxLength: 253
  11955. minLength: 1
  11956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11957. type: string
  11958. namespace:
  11959. description: |-
  11960. The namespace of the Secret resource being referred to.
  11961. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11962. maxLength: 63
  11963. minLength: 1
  11964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11965. type: string
  11966. type: object
  11967. required:
  11968. - fingerprint
  11969. - privatekey
  11970. type: object
  11971. tenancy:
  11972. description: Tenancy is the tenancy OCID where user is located.
  11973. type: string
  11974. user:
  11975. description: User is an access OCID specific to the account.
  11976. type: string
  11977. required:
  11978. - secretRef
  11979. - tenancy
  11980. - user
  11981. type: object
  11982. compartment:
  11983. description: |-
  11984. Compartment is the vault compartment OCID.
  11985. Required for PushSecret
  11986. type: string
  11987. encryptionKey:
  11988. description: |-
  11989. EncryptionKey is the OCID of the encryption key within the vault.
  11990. Required for PushSecret
  11991. type: string
  11992. principalType:
  11993. description: |-
  11994. The type of principal to use for authentication. If left blank, the Auth struct will
  11995. determine the principal type. This optional field must be specified if using
  11996. workload identity.
  11997. enum:
  11998. - ""
  11999. - UserPrincipal
  12000. - InstancePrincipal
  12001. - Workload
  12002. type: string
  12003. region:
  12004. description: Region is the region where vault is located.
  12005. type: string
  12006. serviceAccountRef:
  12007. description: |-
  12008. ServiceAccountRef specified the service account
  12009. that should be used when authenticating with WorkloadIdentity.
  12010. properties:
  12011. audiences:
  12012. description: |-
  12013. Audience specifies the `aud` claim for the service account token
  12014. Some providers automatically extend the audience field based on well-known annotations for workload
  12015. identity (e.g. IRSA or GCP Workload Identity)
  12016. items:
  12017. type: string
  12018. type: array
  12019. name:
  12020. description: The name of the ServiceAccount resource being referred to.
  12021. maxLength: 253
  12022. minLength: 1
  12023. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12024. type: string
  12025. namespace:
  12026. description: |-
  12027. Namespace of the resource being referred to.
  12028. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12029. maxLength: 63
  12030. minLength: 1
  12031. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12032. type: string
  12033. required:
  12034. - name
  12035. type: object
  12036. vault:
  12037. description: Vault is the vault's OCID of the specific vault where secret is located.
  12038. type: string
  12039. required:
  12040. - region
  12041. - vault
  12042. type: object
  12043. passbolt:
  12044. description: PassboltProvider defines configuration for the Passbolt provider.
  12045. properties:
  12046. auth:
  12047. description: Auth defines the information necessary to authenticate against Passbolt Server
  12048. properties:
  12049. passwordSecretRef:
  12050. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  12051. properties:
  12052. key:
  12053. description: |-
  12054. A key in the referenced Secret.
  12055. Some instances of this field may be defaulted, in others it may be required.
  12056. maxLength: 253
  12057. minLength: 1
  12058. pattern: ^[-._a-zA-Z0-9]+$
  12059. type: string
  12060. name:
  12061. description: The name of the Secret resource being referred to.
  12062. maxLength: 253
  12063. minLength: 1
  12064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12065. type: string
  12066. namespace:
  12067. description: |-
  12068. The namespace of the Secret resource being referred to.
  12069. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12070. maxLength: 63
  12071. minLength: 1
  12072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12073. type: string
  12074. type: object
  12075. privateKeySecretRef:
  12076. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  12077. properties:
  12078. key:
  12079. description: |-
  12080. A key in the referenced Secret.
  12081. Some instances of this field may be defaulted, in others it may be required.
  12082. maxLength: 253
  12083. minLength: 1
  12084. pattern: ^[-._a-zA-Z0-9]+$
  12085. type: string
  12086. name:
  12087. description: The name of the Secret resource being referred to.
  12088. maxLength: 253
  12089. minLength: 1
  12090. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12091. type: string
  12092. namespace:
  12093. description: |-
  12094. The namespace of the Secret resource being referred to.
  12095. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12096. maxLength: 63
  12097. minLength: 1
  12098. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12099. type: string
  12100. type: object
  12101. required:
  12102. - passwordSecretRef
  12103. - privateKeySecretRef
  12104. type: object
  12105. host:
  12106. description: Host defines the Passbolt Server to connect to
  12107. type: string
  12108. required:
  12109. - auth
  12110. - host
  12111. type: object
  12112. passworddepot:
  12113. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  12114. properties:
  12115. auth:
  12116. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  12117. properties:
  12118. secretRef:
  12119. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  12120. properties:
  12121. credentials:
  12122. description: Username / Password is used for authentication.
  12123. properties:
  12124. key:
  12125. description: |-
  12126. A key in the referenced Secret.
  12127. Some instances of this field may be defaulted, in others it may be required.
  12128. maxLength: 253
  12129. minLength: 1
  12130. pattern: ^[-._a-zA-Z0-9]+$
  12131. type: string
  12132. name:
  12133. description: The name of the Secret resource being referred to.
  12134. maxLength: 253
  12135. minLength: 1
  12136. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12137. type: string
  12138. namespace:
  12139. description: |-
  12140. The namespace of the Secret resource being referred to.
  12141. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12142. maxLength: 63
  12143. minLength: 1
  12144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12145. type: string
  12146. type: object
  12147. type: object
  12148. required:
  12149. - secretRef
  12150. type: object
  12151. database:
  12152. description: Database to use as source
  12153. type: string
  12154. host:
  12155. description: URL configures the Password Depot instance URL.
  12156. type: string
  12157. required:
  12158. - auth
  12159. - database
  12160. - host
  12161. type: object
  12162. previder:
  12163. description: Previder configures this store to sync secrets using the Previder provider
  12164. properties:
  12165. auth:
  12166. description: PreviderAuth contains a secretRef for credentials.
  12167. properties:
  12168. secretRef:
  12169. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  12170. properties:
  12171. accessToken:
  12172. description: The AccessToken is used for authentication
  12173. properties:
  12174. key:
  12175. description: |-
  12176. A key in the referenced Secret.
  12177. Some instances of this field may be defaulted, in others it may be required.
  12178. maxLength: 253
  12179. minLength: 1
  12180. pattern: ^[-._a-zA-Z0-9]+$
  12181. type: string
  12182. name:
  12183. description: The name of the Secret resource being referred to.
  12184. maxLength: 253
  12185. minLength: 1
  12186. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12187. type: string
  12188. namespace:
  12189. description: |-
  12190. The namespace of the Secret resource being referred to.
  12191. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12192. maxLength: 63
  12193. minLength: 1
  12194. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12195. type: string
  12196. type: object
  12197. required:
  12198. - accessToken
  12199. type: object
  12200. type: object
  12201. baseUri:
  12202. type: string
  12203. required:
  12204. - auth
  12205. type: object
  12206. pulumi:
  12207. description: Pulumi configures this store to sync secrets using the Pulumi provider
  12208. properties:
  12209. accessToken:
  12210. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  12211. properties:
  12212. secretRef:
  12213. description: SecretRef is a reference to a secret containing the Pulumi API token.
  12214. properties:
  12215. key:
  12216. description: |-
  12217. A key in the referenced Secret.
  12218. Some instances of this field may be defaulted, in others it may be required.
  12219. maxLength: 253
  12220. minLength: 1
  12221. pattern: ^[-._a-zA-Z0-9]+$
  12222. type: string
  12223. name:
  12224. description: The name of the Secret resource being referred to.
  12225. maxLength: 253
  12226. minLength: 1
  12227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12228. type: string
  12229. namespace:
  12230. description: |-
  12231. The namespace of the Secret resource being referred to.
  12232. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12233. maxLength: 63
  12234. minLength: 1
  12235. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12236. type: string
  12237. type: object
  12238. type: object
  12239. apiUrl:
  12240. default: https://api.pulumi.com/api/esc
  12241. description: APIURL is the URL of the Pulumi API.
  12242. type: string
  12243. environment:
  12244. description: |-
  12245. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  12246. dynamically retrieved values from supported providers including all major clouds,
  12247. and other Pulumi ESC environments.
  12248. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  12249. type: string
  12250. organization:
  12251. description: |-
  12252. Organization are a space to collaborate on shared projects and stacks.
  12253. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  12254. type: string
  12255. project:
  12256. description: Project is the name of the Pulumi ESC project the environment belongs to.
  12257. type: string
  12258. required:
  12259. - accessToken
  12260. - environment
  12261. - organization
  12262. - project
  12263. type: object
  12264. scaleway:
  12265. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  12266. properties:
  12267. accessKey:
  12268. description: AccessKey is the non-secret part of the api key.
  12269. properties:
  12270. secretRef:
  12271. description: SecretRef references a key in a secret that will be used as value.
  12272. properties:
  12273. key:
  12274. description: |-
  12275. A key in the referenced Secret.
  12276. Some instances of this field may be defaulted, in others it may be required.
  12277. maxLength: 253
  12278. minLength: 1
  12279. pattern: ^[-._a-zA-Z0-9]+$
  12280. type: string
  12281. name:
  12282. description: The name of the Secret resource being referred to.
  12283. maxLength: 253
  12284. minLength: 1
  12285. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12286. type: string
  12287. namespace:
  12288. description: |-
  12289. The namespace of the Secret resource being referred to.
  12290. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12291. maxLength: 63
  12292. minLength: 1
  12293. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12294. type: string
  12295. type: object
  12296. value:
  12297. description: Value can be specified directly to set a value without using a secret.
  12298. type: string
  12299. type: object
  12300. apiUrl:
  12301. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  12302. type: string
  12303. projectId:
  12304. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  12305. type: string
  12306. region:
  12307. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  12308. type: string
  12309. secretKey:
  12310. description: SecretKey is the non-secret part of the api key.
  12311. properties:
  12312. secretRef:
  12313. description: SecretRef references a key in a secret that will be used as value.
  12314. properties:
  12315. key:
  12316. description: |-
  12317. A key in the referenced Secret.
  12318. Some instances of this field may be defaulted, in others it may be required.
  12319. maxLength: 253
  12320. minLength: 1
  12321. pattern: ^[-._a-zA-Z0-9]+$
  12322. type: string
  12323. name:
  12324. description: The name of the Secret resource being referred to.
  12325. maxLength: 253
  12326. minLength: 1
  12327. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12328. type: string
  12329. namespace:
  12330. description: |-
  12331. The namespace of the Secret resource being referred to.
  12332. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12333. maxLength: 63
  12334. minLength: 1
  12335. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12336. type: string
  12337. type: object
  12338. value:
  12339. description: Value can be specified directly to set a value without using a secret.
  12340. type: string
  12341. type: object
  12342. required:
  12343. - accessKey
  12344. - projectId
  12345. - region
  12346. - secretKey
  12347. type: object
  12348. secretserver:
  12349. description: |-
  12350. SecretServer configures this store to sync secrets using SecretServer provider
  12351. https://docs.delinea.com/online-help/secret-server/start.htm
  12352. properties:
  12353. password:
  12354. description: Password is the secret server account password.
  12355. properties:
  12356. secretRef:
  12357. description: SecretRef references a key in a secret that will be used as value.
  12358. properties:
  12359. key:
  12360. description: |-
  12361. A key in the referenced Secret.
  12362. Some instances of this field may be defaulted, in others it may be required.
  12363. maxLength: 253
  12364. minLength: 1
  12365. pattern: ^[-._a-zA-Z0-9]+$
  12366. type: string
  12367. name:
  12368. description: The name of the Secret resource being referred to.
  12369. maxLength: 253
  12370. minLength: 1
  12371. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12372. type: string
  12373. namespace:
  12374. description: |-
  12375. The namespace of the Secret resource being referred to.
  12376. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12377. maxLength: 63
  12378. minLength: 1
  12379. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12380. type: string
  12381. type: object
  12382. value:
  12383. description: Value can be specified directly to set a value without using a secret.
  12384. type: string
  12385. type: object
  12386. serverURL:
  12387. description: |-
  12388. ServerURL
  12389. URL to your secret server installation
  12390. type: string
  12391. username:
  12392. description: Username is the secret server account username.
  12393. properties:
  12394. secretRef:
  12395. description: SecretRef references a key in a secret that will be used as value.
  12396. properties:
  12397. key:
  12398. description: |-
  12399. A key in the referenced Secret.
  12400. Some instances of this field may be defaulted, in others it may be required.
  12401. maxLength: 253
  12402. minLength: 1
  12403. pattern: ^[-._a-zA-Z0-9]+$
  12404. type: string
  12405. name:
  12406. description: The name of the Secret resource being referred to.
  12407. maxLength: 253
  12408. minLength: 1
  12409. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12410. type: string
  12411. namespace:
  12412. description: |-
  12413. The namespace of the Secret resource being referred to.
  12414. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12415. maxLength: 63
  12416. minLength: 1
  12417. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12418. type: string
  12419. type: object
  12420. value:
  12421. description: Value can be specified directly to set a value without using a secret.
  12422. type: string
  12423. type: object
  12424. required:
  12425. - password
  12426. - serverURL
  12427. - username
  12428. type: object
  12429. senhasegura:
  12430. description: Senhasegura configures this store to sync secrets using senhasegura provider
  12431. properties:
  12432. auth:
  12433. description: Auth defines parameters to authenticate in senhasegura
  12434. properties:
  12435. clientId:
  12436. type: string
  12437. clientSecretSecretRef:
  12438. description: |-
  12439. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  12440. In some instances, `key` is a required field.
  12441. properties:
  12442. key:
  12443. description: |-
  12444. A key in the referenced Secret.
  12445. Some instances of this field may be defaulted, in others it may be required.
  12446. maxLength: 253
  12447. minLength: 1
  12448. pattern: ^[-._a-zA-Z0-9]+$
  12449. type: string
  12450. name:
  12451. description: The name of the Secret resource being referred to.
  12452. maxLength: 253
  12453. minLength: 1
  12454. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12455. type: string
  12456. namespace:
  12457. description: |-
  12458. The namespace of the Secret resource being referred to.
  12459. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12460. maxLength: 63
  12461. minLength: 1
  12462. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12463. type: string
  12464. type: object
  12465. required:
  12466. - clientId
  12467. - clientSecretSecretRef
  12468. type: object
  12469. ignoreSslCertificate:
  12470. default: false
  12471. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  12472. type: boolean
  12473. module:
  12474. description: Module defines which senhasegura module should be used to get secrets
  12475. type: string
  12476. url:
  12477. description: URL of senhasegura
  12478. type: string
  12479. required:
  12480. - auth
  12481. - module
  12482. - url
  12483. type: object
  12484. vault:
  12485. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  12486. properties:
  12487. auth:
  12488. description: Auth configures how secret-manager authenticates with the Vault server.
  12489. properties:
  12490. appRole:
  12491. description: |-
  12492. AppRole authenticates with Vault using the App Role auth mechanism,
  12493. with the role and secret stored in a Kubernetes Secret resource.
  12494. properties:
  12495. path:
  12496. default: approle
  12497. description: |-
  12498. Path where the App Role authentication backend is mounted
  12499. in Vault, e.g: "approle"
  12500. type: string
  12501. roleId:
  12502. description: |-
  12503. RoleID configured in the App Role authentication backend when setting
  12504. up the authentication backend in Vault.
  12505. type: string
  12506. roleRef:
  12507. description: |-
  12508. Reference to a key in a Secret that contains the App Role ID used
  12509. to authenticate with Vault.
  12510. The `key` field must be specified and denotes which entry within the Secret
  12511. resource is used as the app role id.
  12512. properties:
  12513. key:
  12514. description: |-
  12515. A key in the referenced Secret.
  12516. Some instances of this field may be defaulted, in others it may be required.
  12517. maxLength: 253
  12518. minLength: 1
  12519. pattern: ^[-._a-zA-Z0-9]+$
  12520. type: string
  12521. name:
  12522. description: The name of the Secret resource being referred to.
  12523. maxLength: 253
  12524. minLength: 1
  12525. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12526. type: string
  12527. namespace:
  12528. description: |-
  12529. The namespace of the Secret resource being referred to.
  12530. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12531. maxLength: 63
  12532. minLength: 1
  12533. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12534. type: string
  12535. type: object
  12536. secretRef:
  12537. description: |-
  12538. Reference to a key in a Secret that contains the App Role secret used
  12539. to authenticate with Vault.
  12540. The `key` field must be specified and denotes which entry within the Secret
  12541. resource is used as the app role secret.
  12542. properties:
  12543. key:
  12544. description: |-
  12545. A key in the referenced Secret.
  12546. Some instances of this field may be defaulted, in others it may be required.
  12547. maxLength: 253
  12548. minLength: 1
  12549. pattern: ^[-._a-zA-Z0-9]+$
  12550. type: string
  12551. name:
  12552. description: The name of the Secret resource being referred to.
  12553. maxLength: 253
  12554. minLength: 1
  12555. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12556. type: string
  12557. namespace:
  12558. description: |-
  12559. The namespace of the Secret resource being referred to.
  12560. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12561. maxLength: 63
  12562. minLength: 1
  12563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12564. type: string
  12565. type: object
  12566. required:
  12567. - path
  12568. - secretRef
  12569. type: object
  12570. cert:
  12571. description: |-
  12572. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  12573. Cert authentication method
  12574. properties:
  12575. clientCert:
  12576. description: |-
  12577. ClientCert is a certificate to authenticate using the Cert Vault
  12578. authentication method
  12579. properties:
  12580. key:
  12581. description: |-
  12582. A key in the referenced Secret.
  12583. Some instances of this field may be defaulted, in others it may be required.
  12584. maxLength: 253
  12585. minLength: 1
  12586. pattern: ^[-._a-zA-Z0-9]+$
  12587. type: string
  12588. name:
  12589. description: The name of the Secret resource being referred to.
  12590. maxLength: 253
  12591. minLength: 1
  12592. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12593. type: string
  12594. namespace:
  12595. description: |-
  12596. The namespace of the Secret resource being referred to.
  12597. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12598. maxLength: 63
  12599. minLength: 1
  12600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12601. type: string
  12602. type: object
  12603. secretRef:
  12604. description: |-
  12605. SecretRef to a key in a Secret resource containing client private key to
  12606. authenticate with Vault using the Cert authentication method
  12607. properties:
  12608. key:
  12609. description: |-
  12610. A key in the referenced Secret.
  12611. Some instances of this field may be defaulted, in others it may be required.
  12612. maxLength: 253
  12613. minLength: 1
  12614. pattern: ^[-._a-zA-Z0-9]+$
  12615. type: string
  12616. name:
  12617. description: The name of the Secret resource being referred to.
  12618. maxLength: 253
  12619. minLength: 1
  12620. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12621. type: string
  12622. namespace:
  12623. description: |-
  12624. The namespace of the Secret resource being referred to.
  12625. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12626. maxLength: 63
  12627. minLength: 1
  12628. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12629. type: string
  12630. type: object
  12631. type: object
  12632. iam:
  12633. description: |-
  12634. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  12635. AWS IAM authentication method
  12636. properties:
  12637. externalID:
  12638. description: AWS External ID set on assumed IAM roles
  12639. type: string
  12640. jwt:
  12641. description: Specify a service account with IRSA enabled
  12642. properties:
  12643. serviceAccountRef:
  12644. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  12645. properties:
  12646. audiences:
  12647. description: |-
  12648. Audience specifies the `aud` claim for the service account token
  12649. Some providers automatically extend the audience field based on well-known annotations for workload
  12650. identity (e.g. IRSA or GCP Workload Identity)
  12651. items:
  12652. type: string
  12653. type: array
  12654. name:
  12655. description: The name of the ServiceAccount resource being referred to.
  12656. maxLength: 253
  12657. minLength: 1
  12658. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12659. type: string
  12660. namespace:
  12661. description: |-
  12662. Namespace of the resource being referred to.
  12663. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12664. maxLength: 63
  12665. minLength: 1
  12666. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12667. type: string
  12668. required:
  12669. - name
  12670. type: object
  12671. type: object
  12672. path:
  12673. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  12674. type: string
  12675. region:
  12676. description: AWS region
  12677. type: string
  12678. role:
  12679. description: This is the AWS role to be assumed before talking to vault
  12680. type: string
  12681. secretRef:
  12682. description: Specify credentials in a Secret object
  12683. properties:
  12684. accessKeyIDSecretRef:
  12685. description: The AccessKeyID is used for authentication
  12686. properties:
  12687. key:
  12688. description: |-
  12689. A key in the referenced Secret.
  12690. Some instances of this field may be defaulted, in others it may be required.
  12691. maxLength: 253
  12692. minLength: 1
  12693. pattern: ^[-._a-zA-Z0-9]+$
  12694. type: string
  12695. name:
  12696. description: The name of the Secret resource being referred to.
  12697. maxLength: 253
  12698. minLength: 1
  12699. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12700. type: string
  12701. namespace:
  12702. description: |-
  12703. The namespace of the Secret resource being referred to.
  12704. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12705. maxLength: 63
  12706. minLength: 1
  12707. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12708. type: string
  12709. type: object
  12710. secretAccessKeySecretRef:
  12711. description: The SecretAccessKey is used for authentication
  12712. properties:
  12713. key:
  12714. description: |-
  12715. A key in the referenced Secret.
  12716. Some instances of this field may be defaulted, in others it may be required.
  12717. maxLength: 253
  12718. minLength: 1
  12719. pattern: ^[-._a-zA-Z0-9]+$
  12720. type: string
  12721. name:
  12722. description: The name of the Secret resource being referred to.
  12723. maxLength: 253
  12724. minLength: 1
  12725. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12726. type: string
  12727. namespace:
  12728. description: |-
  12729. The namespace of the Secret resource being referred to.
  12730. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12731. maxLength: 63
  12732. minLength: 1
  12733. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12734. type: string
  12735. type: object
  12736. sessionTokenSecretRef:
  12737. description: |-
  12738. The SessionToken used for authentication
  12739. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  12740. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  12741. properties:
  12742. key:
  12743. description: |-
  12744. A key in the referenced Secret.
  12745. Some instances of this field may be defaulted, in others it may be required.
  12746. maxLength: 253
  12747. minLength: 1
  12748. pattern: ^[-._a-zA-Z0-9]+$
  12749. type: string
  12750. name:
  12751. description: The name of the Secret resource being referred to.
  12752. maxLength: 253
  12753. minLength: 1
  12754. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12755. type: string
  12756. namespace:
  12757. description: |-
  12758. The namespace of the Secret resource being referred to.
  12759. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12760. maxLength: 63
  12761. minLength: 1
  12762. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12763. type: string
  12764. type: object
  12765. type: object
  12766. vaultAwsIamServerID:
  12767. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  12768. type: string
  12769. vaultRole:
  12770. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  12771. type: string
  12772. required:
  12773. - vaultRole
  12774. type: object
  12775. jwt:
  12776. description: |-
  12777. Jwt authenticates with Vault by passing role and JWT token using the
  12778. JWT/OIDC authentication method
  12779. properties:
  12780. kubernetesServiceAccountToken:
  12781. description: |-
  12782. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  12783. a token for with the `TokenRequest` API.
  12784. properties:
  12785. audiences:
  12786. description: |-
  12787. Optional audiences field that will be used to request a temporary Kubernetes service
  12788. account token for the service account referenced by `serviceAccountRef`.
  12789. Defaults to a single audience `vault` it not specified.
  12790. Deprecated: use serviceAccountRef.Audiences instead
  12791. items:
  12792. type: string
  12793. type: array
  12794. expirationSeconds:
  12795. description: |-
  12796. Optional expiration time in seconds that will be used to request a temporary
  12797. Kubernetes service account token for the service account referenced by
  12798. `serviceAccountRef`.
  12799. Deprecated: this will be removed in the future.
  12800. Defaults to 10 minutes.
  12801. format: int64
  12802. type: integer
  12803. serviceAccountRef:
  12804. description: Service account field containing the name of a kubernetes ServiceAccount.
  12805. properties:
  12806. audiences:
  12807. description: |-
  12808. Audience specifies the `aud` claim for the service account token
  12809. Some providers automatically extend the audience field based on well-known annotations for workload
  12810. identity (e.g. IRSA or GCP Workload Identity)
  12811. items:
  12812. type: string
  12813. type: array
  12814. name:
  12815. description: The name of the ServiceAccount resource being referred to.
  12816. maxLength: 253
  12817. minLength: 1
  12818. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12819. type: string
  12820. namespace:
  12821. description: |-
  12822. Namespace of the resource being referred to.
  12823. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12824. maxLength: 63
  12825. minLength: 1
  12826. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12827. type: string
  12828. required:
  12829. - name
  12830. type: object
  12831. required:
  12832. - serviceAccountRef
  12833. type: object
  12834. path:
  12835. default: jwt
  12836. description: |-
  12837. Path where the JWT authentication backend is mounted
  12838. in Vault, e.g: "jwt"
  12839. type: string
  12840. role:
  12841. description: |-
  12842. Role is a JWT role to authenticate using the JWT/OIDC Vault
  12843. authentication method
  12844. type: string
  12845. secretRef:
  12846. description: |-
  12847. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  12848. authenticate with Vault using the JWT/OIDC authentication method.
  12849. properties:
  12850. key:
  12851. description: |-
  12852. A key in the referenced Secret.
  12853. Some instances of this field may be defaulted, in others it may be required.
  12854. maxLength: 253
  12855. minLength: 1
  12856. pattern: ^[-._a-zA-Z0-9]+$
  12857. type: string
  12858. name:
  12859. description: The name of the Secret resource being referred to.
  12860. maxLength: 253
  12861. minLength: 1
  12862. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12863. type: string
  12864. namespace:
  12865. description: |-
  12866. The namespace of the Secret resource being referred to.
  12867. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12868. maxLength: 63
  12869. minLength: 1
  12870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12871. type: string
  12872. type: object
  12873. required:
  12874. - path
  12875. type: object
  12876. kubernetes:
  12877. description: |-
  12878. Kubernetes authenticates with Vault by passing the ServiceAccount
  12879. token stored in the named Secret resource to the Vault server.
  12880. properties:
  12881. mountPath:
  12882. default: kubernetes
  12883. description: |-
  12884. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  12885. "kubernetes"
  12886. type: string
  12887. role:
  12888. description: |-
  12889. A required field containing the Vault Role to assume. A Role binds a
  12890. Kubernetes ServiceAccount with a set of Vault policies.
  12891. type: string
  12892. secretRef:
  12893. description: |-
  12894. Optional secret field containing a Kubernetes ServiceAccount JWT used
  12895. for authenticating with Vault. If a name is specified without a key,
  12896. `token` is the default. If one is not specified, the one bound to
  12897. the controller will be used.
  12898. properties:
  12899. key:
  12900. description: |-
  12901. A key in the referenced Secret.
  12902. Some instances of this field may be defaulted, in others it may be required.
  12903. maxLength: 253
  12904. minLength: 1
  12905. pattern: ^[-._a-zA-Z0-9]+$
  12906. type: string
  12907. name:
  12908. description: The name of the Secret resource being referred to.
  12909. maxLength: 253
  12910. minLength: 1
  12911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12912. type: string
  12913. namespace:
  12914. description: |-
  12915. The namespace of the Secret resource being referred to.
  12916. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12917. maxLength: 63
  12918. minLength: 1
  12919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12920. type: string
  12921. type: object
  12922. serviceAccountRef:
  12923. description: |-
  12924. Optional service account field containing the name of a kubernetes ServiceAccount.
  12925. If the service account is specified, the service account secret token JWT will be used
  12926. for authenticating with Vault. If the service account selector is not supplied,
  12927. the secretRef will be used instead.
  12928. properties:
  12929. audiences:
  12930. description: |-
  12931. Audience specifies the `aud` claim for the service account token
  12932. Some providers automatically extend the audience field based on well-known annotations for workload
  12933. identity (e.g. IRSA or GCP Workload Identity)
  12934. items:
  12935. type: string
  12936. type: array
  12937. name:
  12938. description: The name of the ServiceAccount resource being referred to.
  12939. maxLength: 253
  12940. minLength: 1
  12941. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12942. type: string
  12943. namespace:
  12944. description: |-
  12945. Namespace of the resource being referred to.
  12946. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12947. maxLength: 63
  12948. minLength: 1
  12949. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12950. type: string
  12951. required:
  12952. - name
  12953. type: object
  12954. required:
  12955. - mountPath
  12956. - role
  12957. type: object
  12958. ldap:
  12959. description: |-
  12960. Ldap authenticates with Vault by passing username/password pair using
  12961. the LDAP authentication method
  12962. properties:
  12963. path:
  12964. default: ldap
  12965. description: |-
  12966. Path where the LDAP authentication backend is mounted
  12967. in Vault, e.g: "ldap"
  12968. type: string
  12969. secretRef:
  12970. description: |-
  12971. SecretRef to a key in a Secret resource containing password for the LDAP
  12972. user used to authenticate with Vault using the LDAP authentication
  12973. method
  12974. properties:
  12975. key:
  12976. description: |-
  12977. A key in the referenced Secret.
  12978. Some instances of this field may be defaulted, in others it may be required.
  12979. maxLength: 253
  12980. minLength: 1
  12981. pattern: ^[-._a-zA-Z0-9]+$
  12982. type: string
  12983. name:
  12984. description: The name of the Secret resource being referred to.
  12985. maxLength: 253
  12986. minLength: 1
  12987. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12988. type: string
  12989. namespace:
  12990. description: |-
  12991. The namespace of the Secret resource being referred to.
  12992. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12993. maxLength: 63
  12994. minLength: 1
  12995. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12996. type: string
  12997. type: object
  12998. username:
  12999. description: |-
  13000. Username is an LDAP username used to authenticate using the LDAP Vault
  13001. authentication method
  13002. type: string
  13003. required:
  13004. - path
  13005. - username
  13006. type: object
  13007. namespace:
  13008. description: |-
  13009. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  13010. Namespaces is a set of features within Vault Enterprise that allows
  13011. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  13012. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  13013. This will default to Vault.Namespace field if set, or empty otherwise
  13014. type: string
  13015. tokenSecretRef:
  13016. description: TokenSecretRef authenticates with Vault by presenting a token.
  13017. properties:
  13018. key:
  13019. description: |-
  13020. A key in the referenced Secret.
  13021. Some instances of this field may be defaulted, in others it may be required.
  13022. maxLength: 253
  13023. minLength: 1
  13024. pattern: ^[-._a-zA-Z0-9]+$
  13025. type: string
  13026. name:
  13027. description: The name of the Secret resource being referred to.
  13028. maxLength: 253
  13029. minLength: 1
  13030. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13031. type: string
  13032. namespace:
  13033. description: |-
  13034. The namespace of the Secret resource being referred to.
  13035. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13036. maxLength: 63
  13037. minLength: 1
  13038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13039. type: string
  13040. type: object
  13041. userPass:
  13042. description: UserPass authenticates with Vault by passing username/password pair
  13043. properties:
  13044. path:
  13045. default: userpass
  13046. description: |-
  13047. Path where the UserPassword authentication backend is mounted
  13048. in Vault, e.g: "userpass"
  13049. type: string
  13050. secretRef:
  13051. description: |-
  13052. SecretRef to a key in a Secret resource containing password for the
  13053. user used to authenticate with Vault using the UserPass authentication
  13054. method
  13055. properties:
  13056. key:
  13057. description: |-
  13058. A key in the referenced Secret.
  13059. Some instances of this field may be defaulted, in others it may be required.
  13060. maxLength: 253
  13061. minLength: 1
  13062. pattern: ^[-._a-zA-Z0-9]+$
  13063. type: string
  13064. name:
  13065. description: The name of the Secret resource being referred to.
  13066. maxLength: 253
  13067. minLength: 1
  13068. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13069. type: string
  13070. namespace:
  13071. description: |-
  13072. The namespace of the Secret resource being referred to.
  13073. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13074. maxLength: 63
  13075. minLength: 1
  13076. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13077. type: string
  13078. type: object
  13079. username:
  13080. description: |-
  13081. Username is a username used to authenticate using the UserPass Vault
  13082. authentication method
  13083. type: string
  13084. required:
  13085. - path
  13086. - username
  13087. type: object
  13088. type: object
  13089. caBundle:
  13090. description: |-
  13091. PEM encoded CA bundle used to validate Vault server certificate. Only used
  13092. if the Server URL is using HTTPS protocol. This parameter is ignored for
  13093. plain HTTP protocol connection. If not set the system root certificates
  13094. are used to validate the TLS connection.
  13095. format: byte
  13096. type: string
  13097. caProvider:
  13098. description: The provider for the CA bundle to use to validate Vault server certificate.
  13099. properties:
  13100. key:
  13101. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  13102. maxLength: 253
  13103. minLength: 1
  13104. pattern: ^[-._a-zA-Z0-9]+$
  13105. type: string
  13106. name:
  13107. description: The name of the object located at the provider type.
  13108. maxLength: 253
  13109. minLength: 1
  13110. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13111. type: string
  13112. namespace:
  13113. description: |-
  13114. The namespace the Provider type is in.
  13115. Can only be defined when used in a ClusterSecretStore.
  13116. maxLength: 63
  13117. minLength: 1
  13118. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13119. type: string
  13120. type:
  13121. description: The type of provider to use such as "Secret", or "ConfigMap".
  13122. enum:
  13123. - Secret
  13124. - ConfigMap
  13125. type: string
  13126. required:
  13127. - name
  13128. - type
  13129. type: object
  13130. forwardInconsistent:
  13131. description: |-
  13132. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  13133. leader instead of simply retrying within a loop. This can increase performance if
  13134. the option is enabled serverside.
  13135. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  13136. type: boolean
  13137. headers:
  13138. additionalProperties:
  13139. type: string
  13140. description: Headers to be added in Vault request
  13141. type: object
  13142. namespace:
  13143. description: |-
  13144. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  13145. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  13146. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  13147. type: string
  13148. path:
  13149. description: |-
  13150. Path is the mount path of the Vault KV backend endpoint, e.g:
  13151. "secret". The v2 KV secret engine version specific "/data" path suffix
  13152. for fetching secrets from Vault is optional and will be appended
  13153. if not present in specified path.
  13154. type: string
  13155. readYourWrites:
  13156. description: |-
  13157. ReadYourWrites ensures isolated read-after-write semantics by
  13158. providing discovered cluster replication states in each request.
  13159. More information about eventual consistency in Vault can be found here
  13160. https://www.vaultproject.io/docs/enterprise/consistency
  13161. type: boolean
  13162. server:
  13163. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  13164. type: string
  13165. tls:
  13166. description: |-
  13167. The configuration used for client side related TLS communication, when the Vault server
  13168. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  13169. This parameter is ignored for plain HTTP protocol connection.
  13170. It's worth noting this configuration is different from the "TLS certificates auth method",
  13171. which is available under the `auth.cert` section.
  13172. properties:
  13173. certSecretRef:
  13174. description: |-
  13175. CertSecretRef is a certificate added to the transport layer
  13176. when communicating with the Vault server.
  13177. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  13178. properties:
  13179. key:
  13180. description: |-
  13181. A key in the referenced Secret.
  13182. Some instances of this field may be defaulted, in others it may be required.
  13183. maxLength: 253
  13184. minLength: 1
  13185. pattern: ^[-._a-zA-Z0-9]+$
  13186. type: string
  13187. name:
  13188. description: The name of the Secret resource being referred to.
  13189. maxLength: 253
  13190. minLength: 1
  13191. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13192. type: string
  13193. namespace:
  13194. description: |-
  13195. The namespace of the Secret resource being referred to.
  13196. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13197. maxLength: 63
  13198. minLength: 1
  13199. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13200. type: string
  13201. type: object
  13202. keySecretRef:
  13203. description: |-
  13204. KeySecretRef to a key in a Secret resource containing client private key
  13205. added to the transport layer when communicating with the Vault server.
  13206. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  13207. properties:
  13208. key:
  13209. description: |-
  13210. A key in the referenced Secret.
  13211. Some instances of this field may be defaulted, in others it may be required.
  13212. maxLength: 253
  13213. minLength: 1
  13214. pattern: ^[-._a-zA-Z0-9]+$
  13215. type: string
  13216. name:
  13217. description: The name of the Secret resource being referred to.
  13218. maxLength: 253
  13219. minLength: 1
  13220. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13221. type: string
  13222. namespace:
  13223. description: |-
  13224. The namespace of the Secret resource being referred to.
  13225. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13226. maxLength: 63
  13227. minLength: 1
  13228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13229. type: string
  13230. type: object
  13231. type: object
  13232. version:
  13233. default: v2
  13234. description: |-
  13235. Version is the Vault KV secret engine version. This can be either "v1" or
  13236. "v2". Version defaults to "v2".
  13237. enum:
  13238. - v1
  13239. - v2
  13240. type: string
  13241. required:
  13242. - server
  13243. type: object
  13244. webhook:
  13245. description: Webhook configures this store to sync secrets using a generic templated webhook
  13246. properties:
  13247. auth:
  13248. description: Auth specifies a authorization protocol. Only one protocol may be set.
  13249. maxProperties: 1
  13250. minProperties: 1
  13251. properties:
  13252. ntlm:
  13253. description: NTLMProtocol configures the store to use NTLM for auth
  13254. properties:
  13255. passwordSecret:
  13256. description: |-
  13257. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13258. In some instances, `key` is a required field.
  13259. properties:
  13260. key:
  13261. description: |-
  13262. A key in the referenced Secret.
  13263. Some instances of this field may be defaulted, in others it may be required.
  13264. maxLength: 253
  13265. minLength: 1
  13266. pattern: ^[-._a-zA-Z0-9]+$
  13267. type: string
  13268. name:
  13269. description: The name of the Secret resource being referred to.
  13270. maxLength: 253
  13271. minLength: 1
  13272. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13273. type: string
  13274. namespace:
  13275. description: |-
  13276. The namespace of the Secret resource being referred to.
  13277. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13278. maxLength: 63
  13279. minLength: 1
  13280. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13281. type: string
  13282. type: object
  13283. usernameSecret:
  13284. description: |-
  13285. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13286. In some instances, `key` is a required field.
  13287. properties:
  13288. key:
  13289. description: |-
  13290. A key in the referenced Secret.
  13291. Some instances of this field may be defaulted, in others it may be required.
  13292. maxLength: 253
  13293. minLength: 1
  13294. pattern: ^[-._a-zA-Z0-9]+$
  13295. type: string
  13296. name:
  13297. description: The name of the Secret resource being referred to.
  13298. maxLength: 253
  13299. minLength: 1
  13300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13301. type: string
  13302. namespace:
  13303. description: |-
  13304. The namespace of the Secret resource being referred to.
  13305. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13306. maxLength: 63
  13307. minLength: 1
  13308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13309. type: string
  13310. type: object
  13311. required:
  13312. - passwordSecret
  13313. - usernameSecret
  13314. type: object
  13315. type: object
  13316. body:
  13317. description: Body
  13318. type: string
  13319. caBundle:
  13320. description: |-
  13321. PEM encoded CA bundle used to validate webhook server certificate. Only used
  13322. if the Server URL is using HTTPS protocol. This parameter is ignored for
  13323. plain HTTP protocol connection. If not set the system root certificates
  13324. are used to validate the TLS connection.
  13325. format: byte
  13326. type: string
  13327. caProvider:
  13328. description: The provider for the CA bundle to use to validate webhook server certificate.
  13329. properties:
  13330. key:
  13331. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  13332. maxLength: 253
  13333. minLength: 1
  13334. pattern: ^[-._a-zA-Z0-9]+$
  13335. type: string
  13336. name:
  13337. description: The name of the object located at the provider type.
  13338. maxLength: 253
  13339. minLength: 1
  13340. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13341. type: string
  13342. namespace:
  13343. description: The namespace the Provider type is in.
  13344. maxLength: 63
  13345. minLength: 1
  13346. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13347. type: string
  13348. type:
  13349. description: The type of provider to use such as "Secret", or "ConfigMap".
  13350. enum:
  13351. - Secret
  13352. - ConfigMap
  13353. type: string
  13354. required:
  13355. - name
  13356. - type
  13357. type: object
  13358. headers:
  13359. additionalProperties:
  13360. type: string
  13361. description: Headers
  13362. type: object
  13363. method:
  13364. description: Webhook Method
  13365. type: string
  13366. result:
  13367. description: Result formatting
  13368. properties:
  13369. jsonPath:
  13370. description: Json path of return value
  13371. type: string
  13372. type: object
  13373. secrets:
  13374. description: |-
  13375. Secrets to fill in templates
  13376. These secrets will be passed to the templating function as key value pairs under the given name
  13377. items:
  13378. description: WebhookSecret defines a secret to be used in webhook templates.
  13379. properties:
  13380. name:
  13381. description: Name of this secret in templates
  13382. type: string
  13383. secretRef:
  13384. description: Secret ref to fill in credentials
  13385. properties:
  13386. key:
  13387. description: |-
  13388. A key in the referenced Secret.
  13389. Some instances of this field may be defaulted, in others it may be required.
  13390. maxLength: 253
  13391. minLength: 1
  13392. pattern: ^[-._a-zA-Z0-9]+$
  13393. type: string
  13394. name:
  13395. description: The name of the Secret resource being referred to.
  13396. maxLength: 253
  13397. minLength: 1
  13398. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13399. type: string
  13400. namespace:
  13401. description: |-
  13402. The namespace of the Secret resource being referred to.
  13403. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13404. maxLength: 63
  13405. minLength: 1
  13406. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13407. type: string
  13408. type: object
  13409. required:
  13410. - name
  13411. - secretRef
  13412. type: object
  13413. type: array
  13414. timeout:
  13415. description: Timeout
  13416. type: string
  13417. url:
  13418. description: Webhook url to call
  13419. type: string
  13420. required:
  13421. - result
  13422. - url
  13423. type: object
  13424. yandexcertificatemanager:
  13425. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  13426. properties:
  13427. apiEndpoint:
  13428. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13429. type: string
  13430. auth:
  13431. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  13432. properties:
  13433. authorizedKeySecretRef:
  13434. description: The authorized key used for authentication
  13435. properties:
  13436. key:
  13437. description: |-
  13438. A key in the referenced Secret.
  13439. Some instances of this field may be defaulted, in others it may be required.
  13440. maxLength: 253
  13441. minLength: 1
  13442. pattern: ^[-._a-zA-Z0-9]+$
  13443. type: string
  13444. name:
  13445. description: The name of the Secret resource being referred to.
  13446. maxLength: 253
  13447. minLength: 1
  13448. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13449. type: string
  13450. namespace:
  13451. description: |-
  13452. The namespace of the Secret resource being referred to.
  13453. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13454. maxLength: 63
  13455. minLength: 1
  13456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13457. type: string
  13458. type: object
  13459. type: object
  13460. caProvider:
  13461. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13462. properties:
  13463. certSecretRef:
  13464. description: |-
  13465. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13466. In some instances, `key` is a required field.
  13467. properties:
  13468. key:
  13469. description: |-
  13470. A key in the referenced Secret.
  13471. Some instances of this field may be defaulted, in others it may be required.
  13472. maxLength: 253
  13473. minLength: 1
  13474. pattern: ^[-._a-zA-Z0-9]+$
  13475. type: string
  13476. name:
  13477. description: The name of the Secret resource being referred to.
  13478. maxLength: 253
  13479. minLength: 1
  13480. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13481. type: string
  13482. namespace:
  13483. description: |-
  13484. The namespace of the Secret resource being referred to.
  13485. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13486. maxLength: 63
  13487. minLength: 1
  13488. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13489. type: string
  13490. type: object
  13491. type: object
  13492. required:
  13493. - auth
  13494. type: object
  13495. yandexlockbox:
  13496. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  13497. properties:
  13498. apiEndpoint:
  13499. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13500. type: string
  13501. auth:
  13502. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  13503. properties:
  13504. authorizedKeySecretRef:
  13505. description: The authorized key used for authentication
  13506. properties:
  13507. key:
  13508. description: |-
  13509. A key in the referenced Secret.
  13510. Some instances of this field may be defaulted, in others it may be required.
  13511. maxLength: 253
  13512. minLength: 1
  13513. pattern: ^[-._a-zA-Z0-9]+$
  13514. type: string
  13515. name:
  13516. description: The name of the Secret resource being referred to.
  13517. maxLength: 253
  13518. minLength: 1
  13519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13520. type: string
  13521. namespace:
  13522. description: |-
  13523. The namespace of the Secret resource being referred to.
  13524. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13525. maxLength: 63
  13526. minLength: 1
  13527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13528. type: string
  13529. type: object
  13530. type: object
  13531. caProvider:
  13532. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13533. properties:
  13534. certSecretRef:
  13535. description: |-
  13536. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13537. In some instances, `key` is a required field.
  13538. properties:
  13539. key:
  13540. description: |-
  13541. A key in the referenced Secret.
  13542. Some instances of this field may be defaulted, in others it may be required.
  13543. maxLength: 253
  13544. minLength: 1
  13545. pattern: ^[-._a-zA-Z0-9]+$
  13546. type: string
  13547. name:
  13548. description: The name of the Secret resource being referred to.
  13549. maxLength: 253
  13550. minLength: 1
  13551. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13552. type: string
  13553. namespace:
  13554. description: |-
  13555. The namespace of the Secret resource being referred to.
  13556. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13557. maxLength: 63
  13558. minLength: 1
  13559. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13560. type: string
  13561. type: object
  13562. type: object
  13563. required:
  13564. - auth
  13565. type: object
  13566. type: object
  13567. refreshInterval:
  13568. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  13569. type: integer
  13570. retrySettings:
  13571. description: Used to configure HTTP retries on failures.
  13572. properties:
  13573. maxRetries:
  13574. description: MaxRetries is the maximum number of retry attempts.
  13575. format: int32
  13576. type: integer
  13577. retryInterval:
  13578. description: RetryInterval is the interval between retry attempts.
  13579. type: string
  13580. type: object
  13581. required:
  13582. - provider
  13583. type: object
  13584. status:
  13585. description: SecretStoreStatus defines the observed state of the SecretStore.
  13586. properties:
  13587. capabilities:
  13588. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  13589. type: string
  13590. conditions:
  13591. items:
  13592. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  13593. properties:
  13594. lastTransitionTime:
  13595. format: date-time
  13596. type: string
  13597. message:
  13598. type: string
  13599. reason:
  13600. type: string
  13601. status:
  13602. type: string
  13603. type:
  13604. description: SecretStoreConditionType represents the condition type of the SecretStore.
  13605. type: string
  13606. required:
  13607. - status
  13608. - type
  13609. type: object
  13610. type: array
  13611. type: object
  13612. type: object
  13613. served: false
  13614. storage: false
  13615. subresources:
  13616. status: {}
  13617. ---
  13618. apiVersion: apiextensions.k8s.io/v1
  13619. kind: CustomResourceDefinition
  13620. metadata:
  13621. annotations:
  13622. controller-gen.kubebuilder.io/version: v0.19.0
  13623. labels:
  13624. external-secrets.io/component: controller
  13625. name: externalsecrets.external-secrets.io
  13626. spec:
  13627. group: external-secrets.io
  13628. names:
  13629. categories:
  13630. - external-secrets
  13631. kind: ExternalSecret
  13632. listKind: ExternalSecretList
  13633. plural: externalsecrets
  13634. shortNames:
  13635. - es
  13636. singular: externalsecret
  13637. scope: Namespaced
  13638. versions:
  13639. - additionalPrinterColumns:
  13640. - jsonPath: .spec.secretStoreRef.kind
  13641. name: StoreType
  13642. type: string
  13643. - jsonPath: .spec.secretStoreRef.name
  13644. name: Store
  13645. type: string
  13646. - jsonPath: .spec.refreshInterval
  13647. name: Refresh Interval
  13648. type: string
  13649. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  13650. name: Status
  13651. type: string
  13652. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  13653. name: Ready
  13654. type: string
  13655. - jsonPath: .status.refreshTime
  13656. name: Last Sync
  13657. type: date
  13658. name: v1
  13659. schema:
  13660. openAPIV3Schema:
  13661. description: |-
  13662. ExternalSecret is the Schema for the external-secrets API.
  13663. It defines how to fetch data from external APIs and make it available as Kubernetes Secrets.
  13664. properties:
  13665. apiVersion:
  13666. description: |-
  13667. APIVersion defines the versioned schema of this representation of an object.
  13668. Servers should convert recognized schemas to the latest internal value, and
  13669. may reject unrecognized values.
  13670. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  13671. type: string
  13672. kind:
  13673. description: |-
  13674. Kind is a string value representing the REST resource this object represents.
  13675. Servers may infer this from the endpoint the client submits requests to.
  13676. Cannot be updated.
  13677. In CamelCase.
  13678. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  13679. type: string
  13680. metadata:
  13681. type: object
  13682. spec:
  13683. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  13684. properties:
  13685. data:
  13686. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  13687. items:
  13688. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  13689. properties:
  13690. remoteRef:
  13691. description: |-
  13692. RemoteRef points to the remote secret and defines
  13693. which secret (version/property/..) to fetch.
  13694. properties:
  13695. conversionStrategy:
  13696. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  13697. enum:
  13698. - Default
  13699. - Unicode
  13700. type: string
  13701. decodingStrategy:
  13702. description: Used to define a decoding Strategy. Defaults to None when omitted.
  13703. enum:
  13704. - Auto
  13705. - Base64
  13706. - Base64URL
  13707. - None
  13708. type: string
  13709. key:
  13710. description: Key is the key used in the Provider, mandatory
  13711. type: string
  13712. metadataPolicy:
  13713. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13714. enum:
  13715. - None
  13716. - Fetch
  13717. type: string
  13718. nullBytePolicy:
  13719. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13720. enum:
  13721. - Ignore
  13722. - Fail
  13723. type: string
  13724. property:
  13725. description: Used to select a specific property of the Provider value (if a map), if supported
  13726. type: string
  13727. version:
  13728. description: Used to select a specific version of the Provider value, if supported
  13729. type: string
  13730. required:
  13731. - key
  13732. type: object
  13733. secretKey:
  13734. description: The key in the Kubernetes Secret to store the value.
  13735. maxLength: 253
  13736. minLength: 1
  13737. pattern: ^[-._a-zA-Z0-9]+$
  13738. type: string
  13739. sourceRef:
  13740. description: |-
  13741. SourceRef allows you to override the source
  13742. from which the value will be pulled.
  13743. maxProperties: 1
  13744. minProperties: 1
  13745. properties:
  13746. generatorRef:
  13747. description: |-
  13748. GeneratorRef points to a generator custom resource.
  13749. Deprecated: The generatorRef is not implemented in .data[].
  13750. this will be removed with v1.
  13751. properties:
  13752. apiVersion:
  13753. default: generators.external-secrets.io/v1alpha1
  13754. description: Specify the apiVersion of the generator resource
  13755. type: string
  13756. kind:
  13757. description: Specify the Kind of the generator resource
  13758. enum:
  13759. - ACRAccessToken
  13760. - BeyondtrustWorkloadCredentialsDynamicSecret
  13761. - ClusterGenerator
  13762. - CloudsmithAccessToken
  13763. - ECRAuthorizationToken
  13764. - Fake
  13765. - GCRAccessToken
  13766. - GithubAccessToken
  13767. - GitlabDeployToken
  13768. - QuayAccessToken
  13769. - Password
  13770. - SSHKey
  13771. - STSSessionToken
  13772. - UUID
  13773. - VaultDynamicSecret
  13774. - Webhook
  13775. - Grafana
  13776. - MFA
  13777. type: string
  13778. name:
  13779. description: Specify the name of the generator resource
  13780. maxLength: 253
  13781. minLength: 1
  13782. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13783. type: string
  13784. required:
  13785. - kind
  13786. - name
  13787. type: object
  13788. storeRef:
  13789. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13790. properties:
  13791. kind:
  13792. description: |-
  13793. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13794. Defaults to `SecretStore`
  13795. enum:
  13796. - SecretStore
  13797. - ClusterSecretStore
  13798. type: string
  13799. name:
  13800. description: Name of the SecretStore resource
  13801. maxLength: 253
  13802. minLength: 1
  13803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13804. type: string
  13805. type: object
  13806. type: object
  13807. required:
  13808. - remoteRef
  13809. - secretKey
  13810. type: object
  13811. type: array
  13812. dataFrom:
  13813. description: |-
  13814. DataFrom is used to fetch all properties from a specific Provider data
  13815. If multiple entries are specified, the Secret keys are merged in the specified order
  13816. items:
  13817. description: |-
  13818. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  13819. when using DataFrom to fetch multiple values from a Provider.
  13820. properties:
  13821. extract:
  13822. description: |-
  13823. Used to extract multiple key/value pairs from one secret
  13824. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13825. properties:
  13826. conversionStrategy:
  13827. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  13828. enum:
  13829. - Default
  13830. - Unicode
  13831. type: string
  13832. decodingStrategy:
  13833. description: Used to define a decoding Strategy. Defaults to None when omitted.
  13834. enum:
  13835. - Auto
  13836. - Base64
  13837. - Base64URL
  13838. - None
  13839. type: string
  13840. key:
  13841. description: Key is the key used in the Provider, mandatory
  13842. type: string
  13843. metadataPolicy:
  13844. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13845. enum:
  13846. - None
  13847. - Fetch
  13848. type: string
  13849. nullBytePolicy:
  13850. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13851. enum:
  13852. - Ignore
  13853. - Fail
  13854. type: string
  13855. property:
  13856. description: Used to select a specific property of the Provider value (if a map), if supported
  13857. type: string
  13858. version:
  13859. description: Used to select a specific version of the Provider value, if supported
  13860. type: string
  13861. required:
  13862. - key
  13863. type: object
  13864. find:
  13865. description: |-
  13866. Used to find secrets based on tags or regular expressions
  13867. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13868. properties:
  13869. conversionStrategy:
  13870. description: Used to define a conversion Strategy. Defaults to Default when omitted.
  13871. enum:
  13872. - Default
  13873. - Unicode
  13874. type: string
  13875. decodingStrategy:
  13876. description: Used to define a decoding Strategy. Defaults to None when omitted.
  13877. enum:
  13878. - Auto
  13879. - Base64
  13880. - Base64URL
  13881. - None
  13882. type: string
  13883. name:
  13884. description: Finds secrets based on the name.
  13885. properties:
  13886. regexp:
  13887. description: Finds secrets base
  13888. type: string
  13889. type: object
  13890. nullBytePolicy:
  13891. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  13892. enum:
  13893. - Ignore
  13894. - Fail
  13895. type: string
  13896. path:
  13897. description: A root path to start the find operations.
  13898. type: string
  13899. tags:
  13900. additionalProperties:
  13901. type: string
  13902. description: Find secrets based on tags.
  13903. type: object
  13904. type: object
  13905. rewrite:
  13906. description: |-
  13907. Used to rewrite secret Keys after getting them from the secret Provider
  13908. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  13909. items:
  13910. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  13911. maxProperties: 1
  13912. minProperties: 1
  13913. properties:
  13914. merge:
  13915. description: |-
  13916. Used to merge key/values in one single Secret
  13917. The resulting key will contain all values from the specified secrets
  13918. properties:
  13919. conflictPolicy:
  13920. default: Error
  13921. description: Used to define the policy to use in conflict resolution.
  13922. enum:
  13923. - Ignore
  13924. - Error
  13925. type: string
  13926. into:
  13927. default: ""
  13928. description: |-
  13929. Used to define the target key of the merge operation.
  13930. Required if strategy is JSON. Ignored otherwise.
  13931. type: string
  13932. priority:
  13933. description: Used to define key priority in conflict resolution.
  13934. items:
  13935. type: string
  13936. type: array
  13937. priorityPolicy:
  13938. default: Strict
  13939. description: Used to define the policy when a key in the priority list does not exist in the input.
  13940. enum:
  13941. - IgnoreNotFound
  13942. - Strict
  13943. type: string
  13944. strategy:
  13945. default: Extract
  13946. description: Used to define the strategy to use in the merge operation.
  13947. enum:
  13948. - Extract
  13949. - JSON
  13950. type: string
  13951. type: object
  13952. regexp:
  13953. description: |-
  13954. Used to rewrite with regular expressions.
  13955. The resulting key will be the output of a regexp.ReplaceAll operation.
  13956. properties:
  13957. source:
  13958. description: Used to define the regular expression of a re.Compiler.
  13959. type: string
  13960. target:
  13961. description: Used to define the target pattern of a ReplaceAll operation.
  13962. type: string
  13963. required:
  13964. - source
  13965. - target
  13966. type: object
  13967. transform:
  13968. description: |-
  13969. Used to apply string transformation on the secrets.
  13970. The resulting key will be the output of the template applied by the operation.
  13971. properties:
  13972. template:
  13973. description: |-
  13974. Used to define the template to apply on the secret name.
  13975. `.value ` will specify the secret name in the template.
  13976. type: string
  13977. required:
  13978. - template
  13979. type: object
  13980. type: object
  13981. type: array
  13982. sourceRef:
  13983. description: |-
  13984. SourceRef points to a store or generator
  13985. which contains secret values ready to use.
  13986. Use this in combination with Extract or Find pull values out of
  13987. a specific SecretStore.
  13988. When sourceRef points to a generator Extract or Find is not supported.
  13989. The generator returns a static map of values
  13990. maxProperties: 1
  13991. minProperties: 1
  13992. properties:
  13993. generatorRef:
  13994. description: GeneratorRef points to a generator custom resource.
  13995. properties:
  13996. apiVersion:
  13997. default: generators.external-secrets.io/v1alpha1
  13998. description: Specify the apiVersion of the generator resource
  13999. type: string
  14000. kind:
  14001. description: Specify the Kind of the generator resource
  14002. enum:
  14003. - ACRAccessToken
  14004. - BeyondtrustWorkloadCredentialsDynamicSecret
  14005. - ClusterGenerator
  14006. - CloudsmithAccessToken
  14007. - ECRAuthorizationToken
  14008. - Fake
  14009. - GCRAccessToken
  14010. - GithubAccessToken
  14011. - GitlabDeployToken
  14012. - QuayAccessToken
  14013. - Password
  14014. - SSHKey
  14015. - STSSessionToken
  14016. - UUID
  14017. - VaultDynamicSecret
  14018. - Webhook
  14019. - Grafana
  14020. - MFA
  14021. type: string
  14022. name:
  14023. description: Specify the name of the generator resource
  14024. maxLength: 253
  14025. minLength: 1
  14026. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14027. type: string
  14028. required:
  14029. - kind
  14030. - name
  14031. type: object
  14032. storeRef:
  14033. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14034. properties:
  14035. kind:
  14036. description: |-
  14037. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14038. Defaults to `SecretStore`
  14039. enum:
  14040. - SecretStore
  14041. - ClusterSecretStore
  14042. type: string
  14043. name:
  14044. description: Name of the SecretStore resource
  14045. maxLength: 253
  14046. minLength: 1
  14047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14048. type: string
  14049. type: object
  14050. type: object
  14051. type: object
  14052. type: array
  14053. refreshInterval:
  14054. default: 1h0m0s
  14055. description: |-
  14056. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  14057. specified as Golang Duration strings.
  14058. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  14059. Example values: "1h0m0s", "2h30m0s", "10m0s"
  14060. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  14061. type: string
  14062. refreshPolicy:
  14063. description: |-
  14064. RefreshPolicy determines how the ExternalSecret should be refreshed:
  14065. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  14066. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  14067. No periodic updates occur if refreshInterval is 0.
  14068. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  14069. enum:
  14070. - CreatedOnce
  14071. - Periodic
  14072. - OnChange
  14073. type: string
  14074. secretStoreRef:
  14075. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14076. properties:
  14077. kind:
  14078. description: |-
  14079. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14080. Defaults to `SecretStore`
  14081. enum:
  14082. - SecretStore
  14083. - ClusterSecretStore
  14084. type: string
  14085. name:
  14086. description: Name of the SecretStore resource
  14087. maxLength: 253
  14088. minLength: 1
  14089. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14090. type: string
  14091. type: object
  14092. syncWindows:
  14093. description: |-
  14094. SyncWindows optionally restricts when periodic refreshes may occur.
  14095. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  14096. properties:
  14097. kind:
  14098. description: |-
  14099. Kind applies to every window in the list.
  14100. "allow" -- syncs are permitted only while at least one window is active;
  14101. all other times are blocked.
  14102. "deny" -- syncs are blocked while any window is active;
  14103. all other times are permitted.
  14104. enum:
  14105. - allow
  14106. - deny
  14107. type: string
  14108. windows:
  14109. description: Windows is the list of schedule+duration pairs.
  14110. items:
  14111. description: |-
  14112. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  14113. within a SyncWindows block.
  14114. properties:
  14115. duration:
  14116. description: |-
  14117. Duration specifies how long the window stays open after each Schedule
  14118. firing. Example: "8h".
  14119. type: string
  14120. schedule:
  14121. description: |-
  14122. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  14123. named shorthand such as @daily or @every 1h. It marks the start time of
  14124. each window occurrence.
  14125. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  14126. minLength: 1
  14127. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  14128. type: string
  14129. required:
  14130. - duration
  14131. - schedule
  14132. type: object
  14133. minItems: 1
  14134. type: array
  14135. required:
  14136. - kind
  14137. - windows
  14138. type: object
  14139. target:
  14140. default:
  14141. creationPolicy: Owner
  14142. deletionPolicy: Retain
  14143. description: |-
  14144. ExternalSecretTarget defines the Kubernetes Secret to be created,
  14145. there can be only one target per ExternalSecret.
  14146. properties:
  14147. creationPolicy:
  14148. default: Owner
  14149. description: |-
  14150. CreationPolicy defines rules on how to create the resulting Secret.
  14151. Defaults to "Owner"
  14152. enum:
  14153. - Owner
  14154. - Orphan
  14155. - Merge
  14156. - None
  14157. - CreateOrMerge
  14158. type: string
  14159. deletionPolicy:
  14160. default: Retain
  14161. description: |-
  14162. DeletionPolicy defines rules on how to delete the resulting Secret.
  14163. Defaults to "Retain"
  14164. enum:
  14165. - Delete
  14166. - Merge
  14167. - Retain
  14168. type: string
  14169. immutable:
  14170. description: Immutable defines if the final secret will be immutable
  14171. type: boolean
  14172. manifest:
  14173. description: |-
  14174. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  14175. When specified, ExternalSecret will create the resource type defined here
  14176. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  14177. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  14178. properties:
  14179. apiVersion:
  14180. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  14181. minLength: 1
  14182. type: string
  14183. kind:
  14184. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  14185. minLength: 1
  14186. type: string
  14187. required:
  14188. - apiVersion
  14189. - kind
  14190. type: object
  14191. name:
  14192. description: |-
  14193. The name of the Secret resource to be managed.
  14194. Defaults to the .metadata.name of the ExternalSecret resource
  14195. maxLength: 253
  14196. minLength: 1
  14197. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14198. type: string
  14199. template:
  14200. description: Template defines a blueprint for the created Secret resource.
  14201. properties:
  14202. data:
  14203. additionalProperties:
  14204. type: string
  14205. type: object
  14206. engineVersion:
  14207. default: v2
  14208. description: |-
  14209. EngineVersion specifies the template engine version
  14210. that should be used to compile/execute the
  14211. template specified in .data and .templateFrom[].
  14212. enum:
  14213. - v2
  14214. type: string
  14215. mergePolicy:
  14216. default: Replace
  14217. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  14218. enum:
  14219. - Replace
  14220. - Merge
  14221. type: string
  14222. metadata:
  14223. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14224. properties:
  14225. annotations:
  14226. additionalProperties:
  14227. type: string
  14228. type: object
  14229. finalizers:
  14230. items:
  14231. type: string
  14232. type: array
  14233. labels:
  14234. additionalProperties:
  14235. type: string
  14236. type: object
  14237. type: object
  14238. templateFrom:
  14239. items:
  14240. description: |-
  14241. TemplateFrom specifies a source for templates.
  14242. Each item in the list can either reference a ConfigMap or a Secret resource.
  14243. properties:
  14244. configMap:
  14245. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14246. properties:
  14247. items:
  14248. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14249. items:
  14250. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14251. properties:
  14252. key:
  14253. description: A key in the ConfigMap/Secret
  14254. maxLength: 253
  14255. minLength: 1
  14256. pattern: ^[-._a-zA-Z0-9]+$
  14257. type: string
  14258. templateAs:
  14259. default: Values
  14260. description: TemplateScope specifies how the template keys should be interpreted.
  14261. enum:
  14262. - Values
  14263. - KeysAndValues
  14264. type: string
  14265. required:
  14266. - key
  14267. type: object
  14268. type: array
  14269. name:
  14270. description: The name of the ConfigMap/Secret resource
  14271. maxLength: 253
  14272. minLength: 1
  14273. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14274. type: string
  14275. required:
  14276. - items
  14277. - name
  14278. type: object
  14279. literal:
  14280. type: string
  14281. secret:
  14282. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14283. properties:
  14284. items:
  14285. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14286. items:
  14287. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14288. properties:
  14289. key:
  14290. description: A key in the ConfigMap/Secret
  14291. maxLength: 253
  14292. minLength: 1
  14293. pattern: ^[-._a-zA-Z0-9]+$
  14294. type: string
  14295. templateAs:
  14296. default: Values
  14297. description: TemplateScope specifies how the template keys should be interpreted.
  14298. enum:
  14299. - Values
  14300. - KeysAndValues
  14301. type: string
  14302. required:
  14303. - key
  14304. type: object
  14305. type: array
  14306. name:
  14307. description: The name of the ConfigMap/Secret resource
  14308. maxLength: 253
  14309. minLength: 1
  14310. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14311. type: string
  14312. required:
  14313. - items
  14314. - name
  14315. type: object
  14316. target:
  14317. default: Data
  14318. description: |-
  14319. Target specifies where to place the template result.
  14320. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  14321. any other value is rejected because it would allow writes to privileged Secret fields.
  14322. For custom resources (when spec.target.manifest is set), this supports
  14323. nested paths like "spec.database.config" or "data".
  14324. type: string
  14325. valuesDecodingStrategy:
  14326. description: |-
  14327. Used to define a decoding Strategy for the rendered template values.
  14328. Defaults to None when omitted.
  14329. enum:
  14330. - Auto
  14331. - Base64
  14332. - Base64URL
  14333. - None
  14334. type: string
  14335. type: object
  14336. type: array
  14337. type:
  14338. type: string
  14339. type: object
  14340. type: object
  14341. type: object
  14342. status:
  14343. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  14344. properties:
  14345. binding:
  14346. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  14347. properties:
  14348. name:
  14349. default: ""
  14350. description: |-
  14351. Name of the referent.
  14352. This field is effectively required, but due to backwards compatibility is
  14353. allowed to be empty. Instances of this type with an empty value here are
  14354. almost certainly wrong.
  14355. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  14356. type: string
  14357. type: object
  14358. x-kubernetes-map-type: atomic
  14359. conditions:
  14360. items:
  14361. description: ExternalSecretStatusCondition defines a status condition of an ExternalSecret resource.
  14362. properties:
  14363. lastTransitionTime:
  14364. format: date-time
  14365. type: string
  14366. message:
  14367. type: string
  14368. reason:
  14369. type: string
  14370. status:
  14371. type: string
  14372. type:
  14373. description: ExternalSecretConditionType defines a value type for ExternalSecret conditions.
  14374. enum:
  14375. - Ready
  14376. - Deleted
  14377. type: string
  14378. required:
  14379. - status
  14380. - type
  14381. type: object
  14382. type: array
  14383. refreshTime:
  14384. description: |-
  14385. refreshTime is the time and date the external secret was fetched and
  14386. the target secret updated
  14387. format: date-time
  14388. nullable: true
  14389. type: string
  14390. syncedResourceVersion:
  14391. description: SyncedResourceVersion keeps track of the last synced version
  14392. type: string
  14393. type: object
  14394. type: object
  14395. selectableFields:
  14396. - jsonPath: .spec.secretStoreRef.name
  14397. - jsonPath: .spec.secretStoreRef.kind
  14398. - jsonPath: .spec.target.name
  14399. - jsonPath: .spec.refreshInterval
  14400. served: true
  14401. storage: true
  14402. subresources:
  14403. status: {}
  14404. - additionalPrinterColumns:
  14405. - jsonPath: .spec.secretStoreRef.kind
  14406. name: StoreType
  14407. type: string
  14408. - jsonPath: .spec.secretStoreRef.name
  14409. name: Store
  14410. type: string
  14411. - jsonPath: .spec.refreshInterval
  14412. name: Refresh Interval
  14413. type: string
  14414. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  14415. name: Status
  14416. type: string
  14417. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  14418. name: Ready
  14419. type: string
  14420. - jsonPath: .status.refreshTime
  14421. name: Last Sync
  14422. type: date
  14423. deprecated: true
  14424. name: v1beta1
  14425. schema:
  14426. openAPIV3Schema:
  14427. description: ExternalSecret is the schema for the external-secrets API.
  14428. properties:
  14429. apiVersion:
  14430. description: |-
  14431. APIVersion defines the versioned schema of this representation of an object.
  14432. Servers should convert recognized schemas to the latest internal value, and
  14433. may reject unrecognized values.
  14434. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  14435. type: string
  14436. kind:
  14437. description: |-
  14438. Kind is a string value representing the REST resource this object represents.
  14439. Servers may infer this from the endpoint the client submits requests to.
  14440. Cannot be updated.
  14441. In CamelCase.
  14442. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  14443. type: string
  14444. metadata:
  14445. type: object
  14446. spec:
  14447. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  14448. properties:
  14449. data:
  14450. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  14451. items:
  14452. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  14453. properties:
  14454. remoteRef:
  14455. description: |-
  14456. RemoteRef points to the remote secret and defines
  14457. which secret (version/property/..) to fetch.
  14458. properties:
  14459. conversionStrategy:
  14460. default: Default
  14461. description: Used to define a conversion Strategy
  14462. enum:
  14463. - Default
  14464. - Unicode
  14465. type: string
  14466. decodingStrategy:
  14467. default: None
  14468. description: Used to define a decoding Strategy
  14469. enum:
  14470. - Auto
  14471. - Base64
  14472. - Base64URL
  14473. - None
  14474. type: string
  14475. key:
  14476. description: Key is the key used in the Provider, mandatory
  14477. type: string
  14478. metadataPolicy:
  14479. default: None
  14480. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14481. enum:
  14482. - None
  14483. - Fetch
  14484. type: string
  14485. property:
  14486. description: Used to select a specific property of the Provider value (if a map), if supported
  14487. type: string
  14488. version:
  14489. description: Used to select a specific version of the Provider value, if supported
  14490. type: string
  14491. required:
  14492. - key
  14493. type: object
  14494. secretKey:
  14495. description: The key in the Kubernetes Secret to store the value.
  14496. maxLength: 253
  14497. minLength: 1
  14498. pattern: ^[-._a-zA-Z0-9]+$
  14499. type: string
  14500. sourceRef:
  14501. description: |-
  14502. SourceRef allows you to override the source
  14503. from which the value will be pulled.
  14504. maxProperties: 1
  14505. minProperties: 1
  14506. properties:
  14507. generatorRef:
  14508. description: |-
  14509. GeneratorRef points to a generator custom resource.
  14510. Deprecated: The generatorRef is not implemented in .data[].
  14511. this will be removed with v1.
  14512. properties:
  14513. apiVersion:
  14514. default: generators.external-secrets.io/v1alpha1
  14515. description: Specify the apiVersion of the generator resource
  14516. type: string
  14517. kind:
  14518. description: Specify the Kind of the generator resource
  14519. enum:
  14520. - ACRAccessToken
  14521. - ClusterGenerator
  14522. - ECRAuthorizationToken
  14523. - Fake
  14524. - GCRAccessToken
  14525. - GithubAccessToken
  14526. - QuayAccessToken
  14527. - Password
  14528. - SSHKey
  14529. - STSSessionToken
  14530. - UUID
  14531. - VaultDynamicSecret
  14532. - Webhook
  14533. - Grafana
  14534. type: string
  14535. name:
  14536. description: Specify the name of the generator resource
  14537. maxLength: 253
  14538. minLength: 1
  14539. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14540. type: string
  14541. required:
  14542. - kind
  14543. - name
  14544. type: object
  14545. storeRef:
  14546. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14547. properties:
  14548. kind:
  14549. description: |-
  14550. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14551. Defaults to `SecretStore`
  14552. enum:
  14553. - SecretStore
  14554. - ClusterSecretStore
  14555. type: string
  14556. name:
  14557. description: Name of the SecretStore resource
  14558. maxLength: 253
  14559. minLength: 1
  14560. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14561. type: string
  14562. type: object
  14563. type: object
  14564. required:
  14565. - remoteRef
  14566. - secretKey
  14567. type: object
  14568. type: array
  14569. dataFrom:
  14570. description: |-
  14571. DataFrom is used to fetch all properties from a specific Provider data
  14572. If multiple entries are specified, the Secret keys are merged in the specified order
  14573. items:
  14574. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  14575. properties:
  14576. extract:
  14577. description: |-
  14578. Used to extract multiple key/value pairs from one secret
  14579. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14580. properties:
  14581. conversionStrategy:
  14582. default: Default
  14583. description: Used to define a conversion Strategy
  14584. enum:
  14585. - Default
  14586. - Unicode
  14587. type: string
  14588. decodingStrategy:
  14589. default: None
  14590. description: Used to define a decoding Strategy
  14591. enum:
  14592. - Auto
  14593. - Base64
  14594. - Base64URL
  14595. - None
  14596. type: string
  14597. key:
  14598. description: Key is the key used in the Provider, mandatory
  14599. type: string
  14600. metadataPolicy:
  14601. default: None
  14602. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14603. enum:
  14604. - None
  14605. - Fetch
  14606. type: string
  14607. property:
  14608. description: Used to select a specific property of the Provider value (if a map), if supported
  14609. type: string
  14610. version:
  14611. description: Used to select a specific version of the Provider value, if supported
  14612. type: string
  14613. required:
  14614. - key
  14615. type: object
  14616. find:
  14617. description: |-
  14618. Used to find secrets based on tags or regular expressions
  14619. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14620. properties:
  14621. conversionStrategy:
  14622. default: Default
  14623. description: Used to define a conversion Strategy
  14624. enum:
  14625. - Default
  14626. - Unicode
  14627. type: string
  14628. decodingStrategy:
  14629. default: None
  14630. description: Used to define a decoding Strategy
  14631. enum:
  14632. - Auto
  14633. - Base64
  14634. - Base64URL
  14635. - None
  14636. type: string
  14637. name:
  14638. description: Finds secrets based on the name.
  14639. properties:
  14640. regexp:
  14641. description: Finds secrets base
  14642. type: string
  14643. type: object
  14644. path:
  14645. description: A root path to start the find operations.
  14646. type: string
  14647. tags:
  14648. additionalProperties:
  14649. type: string
  14650. description: Find secrets based on tags.
  14651. type: object
  14652. type: object
  14653. rewrite:
  14654. description: |-
  14655. Used to rewrite secret Keys after getting them from the secret Provider
  14656. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  14657. items:
  14658. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  14659. maxProperties: 1
  14660. minProperties: 1
  14661. properties:
  14662. regexp:
  14663. description: |-
  14664. Used to rewrite with regular expressions.
  14665. The resulting key will be the output of a regexp.ReplaceAll operation.
  14666. properties:
  14667. source:
  14668. description: Used to define the regular expression of a re.Compiler.
  14669. type: string
  14670. target:
  14671. description: Used to define the target pattern of a ReplaceAll operation.
  14672. type: string
  14673. required:
  14674. - source
  14675. - target
  14676. type: object
  14677. transform:
  14678. description: |-
  14679. Used to apply string transformation on the secrets.
  14680. The resulting key will be the output of the template applied by the operation.
  14681. properties:
  14682. template:
  14683. description: |-
  14684. Used to define the template to apply on the secret name.
  14685. `.value ` will specify the secret name in the template.
  14686. type: string
  14687. required:
  14688. - template
  14689. type: object
  14690. type: object
  14691. type: array
  14692. sourceRef:
  14693. description: |-
  14694. SourceRef points to a store or generator
  14695. which contains secret values ready to use.
  14696. Use this in combination with Extract or Find pull values out of
  14697. a specific SecretStore.
  14698. When sourceRef points to a generator Extract or Find is not supported.
  14699. The generator returns a static map of values
  14700. maxProperties: 1
  14701. minProperties: 1
  14702. properties:
  14703. generatorRef:
  14704. description: GeneratorRef points to a generator custom resource.
  14705. properties:
  14706. apiVersion:
  14707. default: generators.external-secrets.io/v1alpha1
  14708. description: Specify the apiVersion of the generator resource
  14709. type: string
  14710. kind:
  14711. description: Specify the Kind of the generator resource
  14712. enum:
  14713. - ACRAccessToken
  14714. - ClusterGenerator
  14715. - ECRAuthorizationToken
  14716. - Fake
  14717. - GCRAccessToken
  14718. - GithubAccessToken
  14719. - QuayAccessToken
  14720. - Password
  14721. - SSHKey
  14722. - STSSessionToken
  14723. - UUID
  14724. - VaultDynamicSecret
  14725. - Webhook
  14726. - Grafana
  14727. type: string
  14728. name:
  14729. description: Specify the name of the generator resource
  14730. maxLength: 253
  14731. minLength: 1
  14732. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14733. type: string
  14734. required:
  14735. - kind
  14736. - name
  14737. type: object
  14738. storeRef:
  14739. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14740. properties:
  14741. kind:
  14742. description: |-
  14743. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14744. Defaults to `SecretStore`
  14745. enum:
  14746. - SecretStore
  14747. - ClusterSecretStore
  14748. type: string
  14749. name:
  14750. description: Name of the SecretStore resource
  14751. maxLength: 253
  14752. minLength: 1
  14753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14754. type: string
  14755. type: object
  14756. type: object
  14757. type: object
  14758. type: array
  14759. refreshInterval:
  14760. default: 1h0m0s
  14761. description: |-
  14762. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  14763. specified as Golang Duration strings.
  14764. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  14765. Example values: "1h0m0s", "2h30m0s", "10m0s"
  14766. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  14767. type: string
  14768. refreshPolicy:
  14769. description: |-
  14770. RefreshPolicy determines how the ExternalSecret should be refreshed:
  14771. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  14772. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  14773. No periodic updates occur if refreshInterval is 0.
  14774. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  14775. enum:
  14776. - CreatedOnce
  14777. - Periodic
  14778. - OnChange
  14779. type: string
  14780. secretStoreRef:
  14781. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14782. properties:
  14783. kind:
  14784. description: |-
  14785. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14786. Defaults to `SecretStore`
  14787. enum:
  14788. - SecretStore
  14789. - ClusterSecretStore
  14790. type: string
  14791. name:
  14792. description: Name of the SecretStore resource
  14793. maxLength: 253
  14794. minLength: 1
  14795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14796. type: string
  14797. type: object
  14798. target:
  14799. default:
  14800. creationPolicy: Owner
  14801. deletionPolicy: Retain
  14802. description: |-
  14803. ExternalSecretTarget defines the Kubernetes Secret to be created
  14804. There can be only one target per ExternalSecret.
  14805. properties:
  14806. creationPolicy:
  14807. default: Owner
  14808. description: |-
  14809. CreationPolicy defines rules on how to create the resulting Secret.
  14810. Defaults to "Owner"
  14811. enum:
  14812. - Owner
  14813. - Orphan
  14814. - Merge
  14815. - None
  14816. type: string
  14817. deletionPolicy:
  14818. default: Retain
  14819. description: |-
  14820. DeletionPolicy defines rules on how to delete the resulting Secret.
  14821. Defaults to "Retain"
  14822. enum:
  14823. - Delete
  14824. - Merge
  14825. - Retain
  14826. type: string
  14827. immutable:
  14828. description: Immutable defines if the final secret will be immutable
  14829. type: boolean
  14830. name:
  14831. description: |-
  14832. The name of the Secret resource to be managed.
  14833. Defaults to the .metadata.name of the ExternalSecret resource
  14834. maxLength: 253
  14835. minLength: 1
  14836. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14837. type: string
  14838. template:
  14839. description: Template defines a blueprint for the created Secret resource.
  14840. properties:
  14841. data:
  14842. additionalProperties:
  14843. type: string
  14844. type: object
  14845. engineVersion:
  14846. default: v2
  14847. description: |-
  14848. EngineVersion specifies the template engine version
  14849. that should be used to compile/execute the
  14850. template specified in .data and .templateFrom[].
  14851. enum:
  14852. - v2
  14853. type: string
  14854. mergePolicy:
  14855. default: Replace
  14856. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  14857. enum:
  14858. - Replace
  14859. - Merge
  14860. type: string
  14861. metadata:
  14862. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14863. properties:
  14864. annotations:
  14865. additionalProperties:
  14866. type: string
  14867. type: object
  14868. labels:
  14869. additionalProperties:
  14870. type: string
  14871. type: object
  14872. type: object
  14873. templateFrom:
  14874. items:
  14875. description: TemplateFrom defines a source for template data.
  14876. properties:
  14877. configMap:
  14878. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14879. properties:
  14880. items:
  14881. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14882. items:
  14883. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14884. properties:
  14885. key:
  14886. description: A key in the ConfigMap/Secret
  14887. maxLength: 253
  14888. minLength: 1
  14889. pattern: ^[-._a-zA-Z0-9]+$
  14890. type: string
  14891. templateAs:
  14892. default: Values
  14893. description: TemplateScope defines the scope of the template when processing template data.
  14894. enum:
  14895. - Values
  14896. - KeysAndValues
  14897. type: string
  14898. required:
  14899. - key
  14900. type: object
  14901. type: array
  14902. name:
  14903. description: The name of the ConfigMap/Secret resource
  14904. maxLength: 253
  14905. minLength: 1
  14906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14907. type: string
  14908. required:
  14909. - items
  14910. - name
  14911. type: object
  14912. literal:
  14913. type: string
  14914. secret:
  14915. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14916. properties:
  14917. items:
  14918. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14919. items:
  14920. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14921. properties:
  14922. key:
  14923. description: A key in the ConfigMap/Secret
  14924. maxLength: 253
  14925. minLength: 1
  14926. pattern: ^[-._a-zA-Z0-9]+$
  14927. type: string
  14928. templateAs:
  14929. default: Values
  14930. description: TemplateScope defines the scope of the template when processing template data.
  14931. enum:
  14932. - Values
  14933. - KeysAndValues
  14934. type: string
  14935. required:
  14936. - key
  14937. type: object
  14938. type: array
  14939. name:
  14940. description: The name of the ConfigMap/Secret resource
  14941. maxLength: 253
  14942. minLength: 1
  14943. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14944. type: string
  14945. required:
  14946. - items
  14947. - name
  14948. type: object
  14949. target:
  14950. default: Data
  14951. description: TemplateTarget defines the target field where the template result will be stored.
  14952. enum:
  14953. - Data
  14954. - Annotations
  14955. - Labels
  14956. type: string
  14957. type: object
  14958. type: array
  14959. type:
  14960. type: string
  14961. type: object
  14962. type: object
  14963. type: object
  14964. status:
  14965. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  14966. properties:
  14967. binding:
  14968. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  14969. properties:
  14970. name:
  14971. default: ""
  14972. description: |-
  14973. Name of the referent.
  14974. This field is effectively required, but due to backwards compatibility is
  14975. allowed to be empty. Instances of this type with an empty value here are
  14976. almost certainly wrong.
  14977. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  14978. type: string
  14979. type: object
  14980. x-kubernetes-map-type: atomic
  14981. conditions:
  14982. items:
  14983. description: ExternalSecretStatusCondition contains condition information for an ExternalSecret.
  14984. properties:
  14985. lastTransitionTime:
  14986. format: date-time
  14987. type: string
  14988. message:
  14989. type: string
  14990. reason:
  14991. type: string
  14992. status:
  14993. type: string
  14994. type:
  14995. description: ExternalSecretConditionType defines the condition type for an ExternalSecret.
  14996. type: string
  14997. required:
  14998. - status
  14999. - type
  15000. type: object
  15001. type: array
  15002. refreshTime:
  15003. description: |-
  15004. refreshTime is the time and date the external secret was fetched and
  15005. the target secret updated
  15006. format: date-time
  15007. nullable: true
  15008. type: string
  15009. syncedResourceVersion:
  15010. description: SyncedResourceVersion keeps track of the last synced version
  15011. type: string
  15012. type: object
  15013. type: object
  15014. served: false
  15015. storage: false
  15016. subresources:
  15017. status: {}
  15018. ---
  15019. apiVersion: apiextensions.k8s.io/v1
  15020. kind: CustomResourceDefinition
  15021. metadata:
  15022. annotations:
  15023. controller-gen.kubebuilder.io/version: v0.19.0
  15024. labels:
  15025. external-secrets.io/component: controller
  15026. name: pushsecrets.external-secrets.io
  15027. spec:
  15028. group: external-secrets.io
  15029. names:
  15030. categories:
  15031. - external-secrets
  15032. kind: PushSecret
  15033. listKind: PushSecretList
  15034. plural: pushsecrets
  15035. shortNames:
  15036. - ps
  15037. singular: pushsecret
  15038. scope: Namespaced
  15039. versions:
  15040. - additionalPrinterColumns:
  15041. - jsonPath: .metadata.creationTimestamp
  15042. name: AGE
  15043. type: date
  15044. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  15045. name: Status
  15046. type: string
  15047. - jsonPath: .status.refreshTime
  15048. name: Last Sync
  15049. type: date
  15050. name: v1alpha1
  15051. schema:
  15052. openAPIV3Schema:
  15053. description: PushSecret is the Schema for the PushSecrets API that enables pushing Kubernetes secrets to external secret providers.
  15054. properties:
  15055. apiVersion:
  15056. description: |-
  15057. APIVersion defines the versioned schema of this representation of an object.
  15058. Servers should convert recognized schemas to the latest internal value, and
  15059. may reject unrecognized values.
  15060. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15061. type: string
  15062. kind:
  15063. description: |-
  15064. Kind is a string value representing the REST resource this object represents.
  15065. Servers may infer this from the endpoint the client submits requests to.
  15066. Cannot be updated.
  15067. In CamelCase.
  15068. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15069. type: string
  15070. metadata:
  15071. type: object
  15072. spec:
  15073. description: PushSecretSpec configures the behavior of the PushSecret.
  15074. properties:
  15075. data:
  15076. description: Secret Data that should be pushed to providers
  15077. items:
  15078. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  15079. properties:
  15080. conversionStrategy:
  15081. default: None
  15082. description: Used to define a conversion Strategy for the secret keys
  15083. enum:
  15084. - None
  15085. - ReverseUnicode
  15086. type: string
  15087. match:
  15088. description: Match a given Secret Key to be pushed to the provider.
  15089. properties:
  15090. remoteRef:
  15091. description: Remote Refs to push to providers.
  15092. properties:
  15093. property:
  15094. description: Name of the property in the resulting secret
  15095. type: string
  15096. remoteKey:
  15097. description: Name of the resulting provider secret.
  15098. type: string
  15099. required:
  15100. - remoteKey
  15101. type: object
  15102. secretKey:
  15103. description: Secret Key to be pushed
  15104. type: string
  15105. required:
  15106. - remoteRef
  15107. type: object
  15108. metadata:
  15109. description: |-
  15110. Metadata is metadata attached to the secret.
  15111. The structure of metadata is provider specific, please look it up in the provider documentation.
  15112. x-kubernetes-preserve-unknown-fields: true
  15113. required:
  15114. - match
  15115. type: object
  15116. type: array
  15117. dataTo:
  15118. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  15119. items:
  15120. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  15121. properties:
  15122. conversionStrategy:
  15123. default: None
  15124. description: Used to define a conversion Strategy for the secret keys
  15125. enum:
  15126. - None
  15127. - ReverseUnicode
  15128. type: string
  15129. match:
  15130. description: |-
  15131. Match pattern for selecting keys from the source Secret.
  15132. If not specified, all keys are selected.
  15133. properties:
  15134. regexp:
  15135. description: |-
  15136. Regexp matches keys by regular expression.
  15137. If not specified, all keys are matched.
  15138. type: string
  15139. type: object
  15140. metadata:
  15141. description: |-
  15142. Metadata is metadata attached to the secret.
  15143. The structure of metadata is provider specific, please look it up in the provider documentation.
  15144. x-kubernetes-preserve-unknown-fields: true
  15145. remoteKey:
  15146. description: |-
  15147. RemoteKey is the name of the single provider secret that will receive ALL
  15148. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  15149. When set, per-key expansion is skipped and a single push is performed.
  15150. The provider's store prefix (if any) is still prepended to this value.
  15151. When not set, each matched key is pushed as its own individual provider secret.
  15152. type: string
  15153. rewrite:
  15154. description: |-
  15155. Rewrite operations to transform keys before pushing to the provider.
  15156. Operations are applied sequentially.
  15157. items:
  15158. description: PushSecretRewrite defines how to transform secret keys before pushing.
  15159. properties:
  15160. regexp:
  15161. description: Used to rewrite with regular expressions.
  15162. properties:
  15163. source:
  15164. description: Used to define the regular expression of a re.Compiler.
  15165. type: string
  15166. target:
  15167. description: Used to define the target pattern of a ReplaceAll operation.
  15168. type: string
  15169. required:
  15170. - source
  15171. - target
  15172. type: object
  15173. transform:
  15174. description: Used to apply string transformation on the secrets.
  15175. properties:
  15176. template:
  15177. description: |-
  15178. Used to define the template to apply on the secret name.
  15179. `.value ` will specify the secret name in the template.
  15180. type: string
  15181. required:
  15182. - template
  15183. type: object
  15184. type: object
  15185. x-kubernetes-validations:
  15186. - message: exactly one of regexp or transform must be set
  15187. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  15188. type: array
  15189. storeRef:
  15190. description: StoreRef specifies which SecretStore to push to. Required.
  15191. properties:
  15192. kind:
  15193. default: SecretStore
  15194. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  15195. enum:
  15196. - SecretStore
  15197. - ClusterSecretStore
  15198. type: string
  15199. labelSelector:
  15200. description: Optionally, sync to secret stores with label selector
  15201. properties:
  15202. matchExpressions:
  15203. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15204. items:
  15205. description: |-
  15206. A label selector requirement is a selector that contains values, a key, and an operator that
  15207. relates the key and values.
  15208. properties:
  15209. key:
  15210. description: key is the label key that the selector applies to.
  15211. type: string
  15212. operator:
  15213. description: |-
  15214. operator represents a key's relationship to a set of values.
  15215. Valid operators are In, NotIn, Exists and DoesNotExist.
  15216. type: string
  15217. values:
  15218. description: |-
  15219. values is an array of string values. If the operator is In or NotIn,
  15220. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15221. the values array must be empty. This array is replaced during a strategic
  15222. merge patch.
  15223. items:
  15224. type: string
  15225. type: array
  15226. x-kubernetes-list-type: atomic
  15227. required:
  15228. - key
  15229. - operator
  15230. type: object
  15231. type: array
  15232. x-kubernetes-list-type: atomic
  15233. matchLabels:
  15234. additionalProperties:
  15235. type: string
  15236. description: |-
  15237. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15238. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15239. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15240. type: object
  15241. type: object
  15242. x-kubernetes-map-type: atomic
  15243. name:
  15244. description: Optionally, sync to the SecretStore of the given name
  15245. maxLength: 253
  15246. minLength: 1
  15247. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15248. type: string
  15249. type: object
  15250. type: object
  15251. x-kubernetes-validations:
  15252. - message: storeRef must specify either name or labelSelector
  15253. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  15254. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  15255. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  15256. type: array
  15257. deletionPolicy:
  15258. default: None
  15259. description: Deletion Policy to handle Secrets in the provider.
  15260. enum:
  15261. - Delete
  15262. - None
  15263. type: string
  15264. refreshInterval:
  15265. default: 1h0m0s
  15266. description: The Interval to which External Secrets will try to push a secret definition
  15267. type: string
  15268. secretStoreRefs:
  15269. items:
  15270. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  15271. properties:
  15272. kind:
  15273. default: SecretStore
  15274. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  15275. enum:
  15276. - SecretStore
  15277. - ClusterSecretStore
  15278. type: string
  15279. labelSelector:
  15280. description: Optionally, sync to secret stores with label selector
  15281. properties:
  15282. matchExpressions:
  15283. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15284. items:
  15285. description: |-
  15286. A label selector requirement is a selector that contains values, a key, and an operator that
  15287. relates the key and values.
  15288. properties:
  15289. key:
  15290. description: key is the label key that the selector applies to.
  15291. type: string
  15292. operator:
  15293. description: |-
  15294. operator represents a key's relationship to a set of values.
  15295. Valid operators are In, NotIn, Exists and DoesNotExist.
  15296. type: string
  15297. values:
  15298. description: |-
  15299. values is an array of string values. If the operator is In or NotIn,
  15300. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15301. the values array must be empty. This array is replaced during a strategic
  15302. merge patch.
  15303. items:
  15304. type: string
  15305. type: array
  15306. x-kubernetes-list-type: atomic
  15307. required:
  15308. - key
  15309. - operator
  15310. type: object
  15311. type: array
  15312. x-kubernetes-list-type: atomic
  15313. matchLabels:
  15314. additionalProperties:
  15315. type: string
  15316. description: |-
  15317. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15318. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15319. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15320. type: object
  15321. type: object
  15322. x-kubernetes-map-type: atomic
  15323. name:
  15324. description: Optionally, sync to the SecretStore of the given name
  15325. maxLength: 253
  15326. minLength: 1
  15327. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15328. type: string
  15329. type: object
  15330. type: array
  15331. selector:
  15332. description: The Secret Selector (k8s source) for the Push Secret
  15333. maxProperties: 1
  15334. minProperties: 1
  15335. properties:
  15336. generatorRef:
  15337. description: Point to a generator to create a Secret.
  15338. properties:
  15339. apiVersion:
  15340. default: generators.external-secrets.io/v1alpha1
  15341. description: Specify the apiVersion of the generator resource
  15342. type: string
  15343. kind:
  15344. description: Specify the Kind of the generator resource
  15345. enum:
  15346. - ACRAccessToken
  15347. - BeyondtrustWorkloadCredentialsDynamicSecret
  15348. - ClusterGenerator
  15349. - CloudsmithAccessToken
  15350. - ECRAuthorizationToken
  15351. - Fake
  15352. - GCRAccessToken
  15353. - GithubAccessToken
  15354. - GitlabDeployToken
  15355. - QuayAccessToken
  15356. - Password
  15357. - SSHKey
  15358. - STSSessionToken
  15359. - UUID
  15360. - VaultDynamicSecret
  15361. - Webhook
  15362. - Grafana
  15363. - MFA
  15364. type: string
  15365. name:
  15366. description: Specify the name of the generator resource
  15367. maxLength: 253
  15368. minLength: 1
  15369. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15370. type: string
  15371. required:
  15372. - kind
  15373. - name
  15374. type: object
  15375. secret:
  15376. description: Select a Secret to Push.
  15377. properties:
  15378. name:
  15379. description: |-
  15380. Name of the Secret.
  15381. The Secret must exist in the same namespace as the PushSecret manifest.
  15382. maxLength: 253
  15383. minLength: 1
  15384. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15385. type: string
  15386. selector:
  15387. description: Selector chooses secrets using a labelSelector.
  15388. properties:
  15389. matchExpressions:
  15390. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15391. items:
  15392. description: |-
  15393. A label selector requirement is a selector that contains values, a key, and an operator that
  15394. relates the key and values.
  15395. properties:
  15396. key:
  15397. description: key is the label key that the selector applies to.
  15398. type: string
  15399. operator:
  15400. description: |-
  15401. operator represents a key's relationship to a set of values.
  15402. Valid operators are In, NotIn, Exists and DoesNotExist.
  15403. type: string
  15404. values:
  15405. description: |-
  15406. values is an array of string values. If the operator is In or NotIn,
  15407. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15408. the values array must be empty. This array is replaced during a strategic
  15409. merge patch.
  15410. items:
  15411. type: string
  15412. type: array
  15413. x-kubernetes-list-type: atomic
  15414. required:
  15415. - key
  15416. - operator
  15417. type: object
  15418. type: array
  15419. x-kubernetes-list-type: atomic
  15420. matchLabels:
  15421. additionalProperties:
  15422. type: string
  15423. description: |-
  15424. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15425. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15426. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15427. type: object
  15428. type: object
  15429. x-kubernetes-map-type: atomic
  15430. type: object
  15431. type: object
  15432. template:
  15433. description: Template defines a blueprint for the created Secret resource.
  15434. properties:
  15435. data:
  15436. additionalProperties:
  15437. type: string
  15438. type: object
  15439. engineVersion:
  15440. default: v2
  15441. description: |-
  15442. EngineVersion specifies the template engine version
  15443. that should be used to compile/execute the
  15444. template specified in .data and .templateFrom[].
  15445. enum:
  15446. - v2
  15447. type: string
  15448. mergePolicy:
  15449. default: Replace
  15450. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  15451. enum:
  15452. - Replace
  15453. - Merge
  15454. type: string
  15455. metadata:
  15456. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  15457. properties:
  15458. annotations:
  15459. additionalProperties:
  15460. type: string
  15461. type: object
  15462. finalizers:
  15463. items:
  15464. type: string
  15465. type: array
  15466. labels:
  15467. additionalProperties:
  15468. type: string
  15469. type: object
  15470. type: object
  15471. templateFrom:
  15472. items:
  15473. description: |-
  15474. TemplateFrom specifies a source for templates.
  15475. Each item in the list can either reference a ConfigMap or a Secret resource.
  15476. properties:
  15477. configMap:
  15478. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15479. properties:
  15480. items:
  15481. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15482. items:
  15483. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15484. properties:
  15485. key:
  15486. description: A key in the ConfigMap/Secret
  15487. maxLength: 253
  15488. minLength: 1
  15489. pattern: ^[-._a-zA-Z0-9]+$
  15490. type: string
  15491. templateAs:
  15492. default: Values
  15493. description: TemplateScope specifies how the template keys should be interpreted.
  15494. enum:
  15495. - Values
  15496. - KeysAndValues
  15497. type: string
  15498. required:
  15499. - key
  15500. type: object
  15501. type: array
  15502. name:
  15503. description: The name of the ConfigMap/Secret resource
  15504. maxLength: 253
  15505. minLength: 1
  15506. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15507. type: string
  15508. required:
  15509. - items
  15510. - name
  15511. type: object
  15512. literal:
  15513. type: string
  15514. secret:
  15515. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15516. properties:
  15517. items:
  15518. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15519. items:
  15520. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15521. properties:
  15522. key:
  15523. description: A key in the ConfigMap/Secret
  15524. maxLength: 253
  15525. minLength: 1
  15526. pattern: ^[-._a-zA-Z0-9]+$
  15527. type: string
  15528. templateAs:
  15529. default: Values
  15530. description: TemplateScope specifies how the template keys should be interpreted.
  15531. enum:
  15532. - Values
  15533. - KeysAndValues
  15534. type: string
  15535. required:
  15536. - key
  15537. type: object
  15538. type: array
  15539. name:
  15540. description: The name of the ConfigMap/Secret resource
  15541. maxLength: 253
  15542. minLength: 1
  15543. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15544. type: string
  15545. required:
  15546. - items
  15547. - name
  15548. type: object
  15549. target:
  15550. default: Data
  15551. description: |-
  15552. Target specifies where to place the template result.
  15553. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  15554. any other value is rejected because it would allow writes to privileged Secret fields.
  15555. For custom resources (when spec.target.manifest is set), this supports
  15556. nested paths like "spec.database.config" or "data".
  15557. type: string
  15558. valuesDecodingStrategy:
  15559. description: |-
  15560. Used to define a decoding Strategy for the rendered template values.
  15561. Defaults to None when omitted.
  15562. enum:
  15563. - Auto
  15564. - Base64
  15565. - Base64URL
  15566. - None
  15567. type: string
  15568. type: object
  15569. type: array
  15570. type:
  15571. type: string
  15572. type: object
  15573. updatePolicy:
  15574. default: Replace
  15575. description: UpdatePolicy to handle Secrets in the provider.
  15576. enum:
  15577. - Replace
  15578. - IfNotExists
  15579. type: string
  15580. required:
  15581. - secretStoreRefs
  15582. - selector
  15583. type: object
  15584. status:
  15585. description: PushSecretStatus indicates the history of the status of PushSecret.
  15586. properties:
  15587. conditions:
  15588. items:
  15589. description: PushSecretStatusCondition indicates the status of the PushSecret.
  15590. properties:
  15591. lastTransitionTime:
  15592. format: date-time
  15593. type: string
  15594. message:
  15595. type: string
  15596. reason:
  15597. type: string
  15598. status:
  15599. type: string
  15600. type:
  15601. description: PushSecretConditionType indicates the condition of the PushSecret.
  15602. type: string
  15603. required:
  15604. - status
  15605. - type
  15606. type: object
  15607. type: array
  15608. refreshTime:
  15609. description: |-
  15610. refreshTime is the time and date the external secret was fetched and
  15611. the target secret updated
  15612. format: date-time
  15613. nullable: true
  15614. type: string
  15615. syncedPushSecrets:
  15616. additionalProperties:
  15617. additionalProperties:
  15618. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  15619. properties:
  15620. conversionStrategy:
  15621. default: None
  15622. description: Used to define a conversion Strategy for the secret keys
  15623. enum:
  15624. - None
  15625. - ReverseUnicode
  15626. type: string
  15627. match:
  15628. description: Match a given Secret Key to be pushed to the provider.
  15629. properties:
  15630. remoteRef:
  15631. description: Remote Refs to push to providers.
  15632. properties:
  15633. property:
  15634. description: Name of the property in the resulting secret
  15635. type: string
  15636. remoteKey:
  15637. description: Name of the resulting provider secret.
  15638. type: string
  15639. required:
  15640. - remoteKey
  15641. type: object
  15642. secretKey:
  15643. description: Secret Key to be pushed
  15644. type: string
  15645. required:
  15646. - remoteRef
  15647. type: object
  15648. metadata:
  15649. description: |-
  15650. Metadata is metadata attached to the secret.
  15651. The structure of metadata is provider specific, please look it up in the provider documentation.
  15652. x-kubernetes-preserve-unknown-fields: true
  15653. required:
  15654. - match
  15655. type: object
  15656. type: object
  15657. description: |-
  15658. Synced PushSecrets, including secrets that already exist in provider.
  15659. Matches secret stores to PushSecretData that was stored to that secret store.
  15660. type: object
  15661. syncedResourceVersion:
  15662. description: SyncedResourceVersion keeps track of the last synced version.
  15663. type: string
  15664. type: object
  15665. type: object
  15666. served: true
  15667. storage: true
  15668. subresources:
  15669. status: {}
  15670. ---
  15671. apiVersion: apiextensions.k8s.io/v1
  15672. kind: CustomResourceDefinition
  15673. metadata:
  15674. annotations:
  15675. controller-gen.kubebuilder.io/version: v0.19.0
  15676. labels:
  15677. external-secrets.io/component: controller
  15678. name: secretstores.external-secrets.io
  15679. spec:
  15680. group: external-secrets.io
  15681. names:
  15682. categories:
  15683. - external-secrets
  15684. kind: SecretStore
  15685. listKind: SecretStoreList
  15686. plural: secretstores
  15687. shortNames:
  15688. - ss
  15689. singular: secretstore
  15690. scope: Namespaced
  15691. versions:
  15692. - additionalPrinterColumns:
  15693. - jsonPath: .metadata.creationTimestamp
  15694. name: AGE
  15695. type: date
  15696. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  15697. name: Status
  15698. type: string
  15699. - jsonPath: .status.capabilities
  15700. name: Capabilities
  15701. type: string
  15702. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  15703. name: Ready
  15704. type: string
  15705. name: v1
  15706. schema:
  15707. openAPIV3Schema:
  15708. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  15709. properties:
  15710. apiVersion:
  15711. description: |-
  15712. APIVersion defines the versioned schema of this representation of an object.
  15713. Servers should convert recognized schemas to the latest internal value, and
  15714. may reject unrecognized values.
  15715. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15716. type: string
  15717. kind:
  15718. description: |-
  15719. Kind is a string value representing the REST resource this object represents.
  15720. Servers may infer this from the endpoint the client submits requests to.
  15721. Cannot be updated.
  15722. In CamelCase.
  15723. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15724. type: string
  15725. metadata:
  15726. type: object
  15727. spec:
  15728. description: SecretStoreSpec defines the desired state of SecretStore.
  15729. properties:
  15730. conditions:
  15731. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  15732. items:
  15733. description: |-
  15734. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  15735. for a ClusterSecretStore instance.
  15736. properties:
  15737. namespaceRegexes:
  15738. description: Choose namespaces by using regex matching
  15739. items:
  15740. type: string
  15741. type: array
  15742. namespaceSelector:
  15743. description: Choose namespace using a labelSelector
  15744. properties:
  15745. matchExpressions:
  15746. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15747. items:
  15748. description: |-
  15749. A label selector requirement is a selector that contains values, a key, and an operator that
  15750. relates the key and values.
  15751. properties:
  15752. key:
  15753. description: key is the label key that the selector applies to.
  15754. type: string
  15755. operator:
  15756. description: |-
  15757. operator represents a key's relationship to a set of values.
  15758. Valid operators are In, NotIn, Exists and DoesNotExist.
  15759. type: string
  15760. values:
  15761. description: |-
  15762. values is an array of string values. If the operator is In or NotIn,
  15763. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15764. the values array must be empty. This array is replaced during a strategic
  15765. merge patch.
  15766. items:
  15767. type: string
  15768. type: array
  15769. x-kubernetes-list-type: atomic
  15770. required:
  15771. - key
  15772. - operator
  15773. type: object
  15774. type: array
  15775. x-kubernetes-list-type: atomic
  15776. matchLabels:
  15777. additionalProperties:
  15778. type: string
  15779. description: |-
  15780. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15781. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15782. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15783. type: object
  15784. type: object
  15785. x-kubernetes-map-type: atomic
  15786. namespaces:
  15787. description: Choose namespaces by name
  15788. items:
  15789. maxLength: 63
  15790. minLength: 1
  15791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15792. type: string
  15793. type: array
  15794. type: object
  15795. type: array
  15796. controller:
  15797. description: |-
  15798. Used to select the correct ESO controller (think: ingress.ingressClassName)
  15799. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  15800. type: string
  15801. provider:
  15802. description: Used to configure the provider. Only one provider may be set
  15803. maxProperties: 1
  15804. minProperties: 1
  15805. properties:
  15806. akeyless:
  15807. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  15808. properties:
  15809. akeylessGWApiURL:
  15810. description: Akeyless GW API Url from which the secrets to be fetched from.
  15811. type: string
  15812. authSecretRef:
  15813. description: Auth configures how the operator authenticates with Akeyless.
  15814. properties:
  15815. kubernetesAuth:
  15816. description: |-
  15817. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  15818. token stored in the named Secret resource.
  15819. properties:
  15820. accessID:
  15821. description: the Akeyless Kubernetes auth-method access-id
  15822. type: string
  15823. k8sConfName:
  15824. description: Kubernetes-auth configuration name in Akeyless-Gateway
  15825. type: string
  15826. secretRef:
  15827. description: |-
  15828. Optional secret field containing a Kubernetes ServiceAccount JWT used
  15829. for authenticating with Akeyless. If a name is specified without a key,
  15830. `token` is the default. If one is not specified, the one bound to
  15831. the controller will be used.
  15832. properties:
  15833. key:
  15834. description: |-
  15835. A key in the referenced Secret.
  15836. Some instances of this field may be defaulted, in others it may be required.
  15837. maxLength: 253
  15838. minLength: 1
  15839. pattern: ^[-._a-zA-Z0-9]+$
  15840. type: string
  15841. name:
  15842. description: The name of the Secret resource being referred to.
  15843. maxLength: 253
  15844. minLength: 1
  15845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15846. type: string
  15847. namespace:
  15848. description: |-
  15849. The namespace of the Secret resource being referred to.
  15850. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15851. maxLength: 63
  15852. minLength: 1
  15853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15854. type: string
  15855. type: object
  15856. serviceAccountRef:
  15857. description: |-
  15858. Optional service account field containing the name of a kubernetes ServiceAccount.
  15859. If the service account is specified, the service account secret token JWT will be used
  15860. for authenticating with Akeyless. If the service account selector is not supplied,
  15861. the secretRef will be used instead.
  15862. properties:
  15863. audiences:
  15864. description: |-
  15865. Audience specifies the `aud` claim for the service account token
  15866. Some providers automatically extend the audience field based on well-known annotations for workload
  15867. identity (e.g. IRSA or GCP Workload Identity)
  15868. items:
  15869. type: string
  15870. type: array
  15871. name:
  15872. description: The name of the ServiceAccount resource being referred to.
  15873. maxLength: 253
  15874. minLength: 1
  15875. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15876. type: string
  15877. namespace:
  15878. description: |-
  15879. Namespace of the resource being referred to.
  15880. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15881. maxLength: 63
  15882. minLength: 1
  15883. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15884. type: string
  15885. required:
  15886. - name
  15887. type: object
  15888. required:
  15889. - accessID
  15890. - k8sConfName
  15891. type: object
  15892. secretRef:
  15893. description: |-
  15894. Reference to a Secret that contains the details
  15895. to authenticate with Akeyless.
  15896. properties:
  15897. accessID:
  15898. description: The SecretAccessID is used for authentication
  15899. properties:
  15900. key:
  15901. description: |-
  15902. A key in the referenced Secret.
  15903. Some instances of this field may be defaulted, in others it may be required.
  15904. maxLength: 253
  15905. minLength: 1
  15906. pattern: ^[-._a-zA-Z0-9]+$
  15907. type: string
  15908. name:
  15909. description: The name of the Secret resource being referred to.
  15910. maxLength: 253
  15911. minLength: 1
  15912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15913. type: string
  15914. namespace:
  15915. description: |-
  15916. The namespace of the Secret resource being referred to.
  15917. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15918. maxLength: 63
  15919. minLength: 1
  15920. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15921. type: string
  15922. type: object
  15923. accessType:
  15924. description: |-
  15925. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15926. In some instances, `key` is a required field.
  15927. properties:
  15928. key:
  15929. description: |-
  15930. A key in the referenced Secret.
  15931. Some instances of this field may be defaulted, in others it may be required.
  15932. maxLength: 253
  15933. minLength: 1
  15934. pattern: ^[-._a-zA-Z0-9]+$
  15935. type: string
  15936. name:
  15937. description: The name of the Secret resource being referred to.
  15938. maxLength: 253
  15939. minLength: 1
  15940. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15941. type: string
  15942. namespace:
  15943. description: |-
  15944. The namespace of the Secret resource being referred to.
  15945. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15946. maxLength: 63
  15947. minLength: 1
  15948. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15949. type: string
  15950. type: object
  15951. accessTypeParam:
  15952. description: |-
  15953. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15954. In some instances, `key` is a required field.
  15955. properties:
  15956. key:
  15957. description: |-
  15958. A key in the referenced Secret.
  15959. Some instances of this field may be defaulted, in others it may be required.
  15960. maxLength: 253
  15961. minLength: 1
  15962. pattern: ^[-._a-zA-Z0-9]+$
  15963. type: string
  15964. name:
  15965. description: The name of the Secret resource being referred to.
  15966. maxLength: 253
  15967. minLength: 1
  15968. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15969. type: string
  15970. namespace:
  15971. description: |-
  15972. The namespace of the Secret resource being referred to.
  15973. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15974. maxLength: 63
  15975. minLength: 1
  15976. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15977. type: string
  15978. type: object
  15979. type: object
  15980. serviceAccountRef:
  15981. description: |-
  15982. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  15983. authentication on AKS Workload Identity. The operator obtains a federated
  15984. identity token from this ServiceAccount via the TokenRequest API instead
  15985. of using the ESO controller pod identity. Ignored for other access types.
  15986. properties:
  15987. audiences:
  15988. description: |-
  15989. Audience specifies the `aud` claim for the service account token
  15990. Some providers automatically extend the audience field based on well-known annotations for workload
  15991. identity (e.g. IRSA or GCP Workload Identity)
  15992. items:
  15993. type: string
  15994. type: array
  15995. name:
  15996. description: The name of the ServiceAccount resource being referred to.
  15997. maxLength: 253
  15998. minLength: 1
  15999. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16000. type: string
  16001. namespace:
  16002. description: |-
  16003. Namespace of the resource being referred to.
  16004. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16005. maxLength: 63
  16006. minLength: 1
  16007. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16008. type: string
  16009. required:
  16010. - name
  16011. type: object
  16012. type: object
  16013. caBundle:
  16014. description: |-
  16015. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  16016. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  16017. are used to validate the TLS connection.
  16018. format: byte
  16019. type: string
  16020. caProvider:
  16021. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  16022. properties:
  16023. key:
  16024. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16025. maxLength: 253
  16026. minLength: 1
  16027. pattern: ^[-._a-zA-Z0-9]+$
  16028. type: string
  16029. name:
  16030. description: The name of the object located at the provider type.
  16031. maxLength: 253
  16032. minLength: 1
  16033. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16034. type: string
  16035. namespace:
  16036. description: |-
  16037. The namespace the Provider type is in.
  16038. Can only be defined when used in a ClusterSecretStore.
  16039. maxLength: 63
  16040. minLength: 1
  16041. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16042. type: string
  16043. type:
  16044. description: The type of provider to use such as "Secret", or "ConfigMap".
  16045. enum:
  16046. - Secret
  16047. - ConfigMap
  16048. type: string
  16049. required:
  16050. - name
  16051. - type
  16052. type: object
  16053. ignoreCache:
  16054. description: |-
  16055. IgnoreCache bypasses the Gateway cache for secret reads when true.
  16056. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  16057. type: boolean
  16058. required:
  16059. - akeylessGWApiURL
  16060. - authSecretRef
  16061. type: object
  16062. aws:
  16063. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  16064. properties:
  16065. additionalRoles:
  16066. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  16067. items:
  16068. type: string
  16069. type: array
  16070. auth:
  16071. description: |-
  16072. Auth defines the information necessary to authenticate against AWS
  16073. if not set aws sdk will infer credentials from your environment
  16074. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  16075. properties:
  16076. jwt:
  16077. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  16078. properties:
  16079. serviceAccountRef:
  16080. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  16081. properties:
  16082. audiences:
  16083. description: |-
  16084. Audience specifies the `aud` claim for the service account token
  16085. Some providers automatically extend the audience field based on well-known annotations for workload
  16086. identity (e.g. IRSA or GCP Workload Identity)
  16087. items:
  16088. type: string
  16089. type: array
  16090. name:
  16091. description: The name of the ServiceAccount resource being referred to.
  16092. maxLength: 253
  16093. minLength: 1
  16094. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16095. type: string
  16096. namespace:
  16097. description: |-
  16098. Namespace of the resource being referred to.
  16099. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16100. maxLength: 63
  16101. minLength: 1
  16102. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16103. type: string
  16104. required:
  16105. - name
  16106. type: object
  16107. type: object
  16108. secretRef:
  16109. description: |-
  16110. AWSAuthSecretRef holds secret references for AWS credentials
  16111. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  16112. properties:
  16113. accessKeyIDSecretRef:
  16114. description: The AccessKeyID is used for authentication
  16115. properties:
  16116. key:
  16117. description: |-
  16118. A key in the referenced Secret.
  16119. Some instances of this field may be defaulted, in others it may be required.
  16120. maxLength: 253
  16121. minLength: 1
  16122. pattern: ^[-._a-zA-Z0-9]+$
  16123. type: string
  16124. name:
  16125. description: The name of the Secret resource being referred to.
  16126. maxLength: 253
  16127. minLength: 1
  16128. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16129. type: string
  16130. namespace:
  16131. description: |-
  16132. The namespace of the Secret resource being referred to.
  16133. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16134. maxLength: 63
  16135. minLength: 1
  16136. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16137. type: string
  16138. type: object
  16139. secretAccessKeySecretRef:
  16140. description: The SecretAccessKey is used for authentication
  16141. properties:
  16142. key:
  16143. description: |-
  16144. A key in the referenced Secret.
  16145. Some instances of this field may be defaulted, in others it may be required.
  16146. maxLength: 253
  16147. minLength: 1
  16148. pattern: ^[-._a-zA-Z0-9]+$
  16149. type: string
  16150. name:
  16151. description: The name of the Secret resource being referred to.
  16152. maxLength: 253
  16153. minLength: 1
  16154. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16155. type: string
  16156. namespace:
  16157. description: |-
  16158. The namespace of the Secret resource being referred to.
  16159. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16160. maxLength: 63
  16161. minLength: 1
  16162. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16163. type: string
  16164. type: object
  16165. sessionTokenSecretRef:
  16166. description: |-
  16167. The SessionToken used for authentication
  16168. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  16169. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  16170. properties:
  16171. key:
  16172. description: |-
  16173. A key in the referenced Secret.
  16174. Some instances of this field may be defaulted, in others it may be required.
  16175. maxLength: 253
  16176. minLength: 1
  16177. pattern: ^[-._a-zA-Z0-9]+$
  16178. type: string
  16179. name:
  16180. description: The name of the Secret resource being referred to.
  16181. maxLength: 253
  16182. minLength: 1
  16183. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16184. type: string
  16185. namespace:
  16186. description: |-
  16187. The namespace of the Secret resource being referred to.
  16188. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16189. maxLength: 63
  16190. minLength: 1
  16191. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16192. type: string
  16193. type: object
  16194. type: object
  16195. type: object
  16196. customSessionTags:
  16197. additionalProperties:
  16198. type: string
  16199. description: |-
  16200. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  16201. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  16202. type: object
  16203. x-kubernetes-validations:
  16204. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  16205. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  16206. externalID:
  16207. description: AWS External ID set on assumed IAM roles
  16208. type: string
  16209. prefix:
  16210. description: Prefix adds a prefix to all retrieved values.
  16211. type: string
  16212. region:
  16213. description: AWS Region to be used for the provider
  16214. type: string
  16215. role:
  16216. description: Role is a Role ARN which the provider will assume
  16217. type: string
  16218. secretsManager:
  16219. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  16220. properties:
  16221. forceDeleteWithoutRecovery:
  16222. description: |-
  16223. Specifies whether to delete the secret without any recovery window. You
  16224. can't use both this parameter and RecoveryWindowInDays in the same call.
  16225. If you don't use either, then by default Secrets Manager uses a 30 day
  16226. recovery window.
  16227. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  16228. type: boolean
  16229. recoveryWindowInDays:
  16230. description: |-
  16231. The number of days from 7 to 30 that Secrets Manager waits before
  16232. permanently deleting the secret. You can't use both this parameter and
  16233. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  16234. then by default Secrets Manager uses a 30-day recovery window.
  16235. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  16236. format: int64
  16237. type: integer
  16238. type: object
  16239. service:
  16240. description: Service defines which service should be used to fetch the secrets
  16241. enum:
  16242. - SecretsManager
  16243. - ParameterStore
  16244. - CertificateManager
  16245. type: string
  16246. sessionTags:
  16247. description: AWS STS assume role session tags
  16248. items:
  16249. description: |-
  16250. Tag is a key-value pair that can be attached to an AWS resource.
  16251. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  16252. properties:
  16253. key:
  16254. type: string
  16255. value:
  16256. type: string
  16257. required:
  16258. - key
  16259. - value
  16260. type: object
  16261. type: array
  16262. sessionTagsPolicy:
  16263. default: None
  16264. description: |-
  16265. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  16266. None (default): no tags are added.
  16267. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  16268. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  16269. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  16270. enum:
  16271. - None
  16272. - Simple
  16273. - Custom
  16274. type: string
  16275. transitiveTagKeys:
  16276. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  16277. items:
  16278. type: string
  16279. type: array
  16280. required:
  16281. - region
  16282. - service
  16283. type: object
  16284. azurekv:
  16285. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  16286. properties:
  16287. authSecretRef:
  16288. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16289. properties:
  16290. clientCertificate:
  16291. description: The Azure ClientCertificate of the service principle used for authentication.
  16292. properties:
  16293. key:
  16294. description: |-
  16295. A key in the referenced Secret.
  16296. Some instances of this field may be defaulted, in others it may be required.
  16297. maxLength: 253
  16298. minLength: 1
  16299. pattern: ^[-._a-zA-Z0-9]+$
  16300. type: string
  16301. name:
  16302. description: The name of the Secret resource being referred to.
  16303. maxLength: 253
  16304. minLength: 1
  16305. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16306. type: string
  16307. namespace:
  16308. description: |-
  16309. The namespace of the Secret resource being referred to.
  16310. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16311. maxLength: 63
  16312. minLength: 1
  16313. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16314. type: string
  16315. type: object
  16316. clientId:
  16317. description: The Azure clientId of the service principle or managed identity used for authentication.
  16318. properties:
  16319. key:
  16320. description: |-
  16321. A key in the referenced Secret.
  16322. Some instances of this field may be defaulted, in others it may be required.
  16323. maxLength: 253
  16324. minLength: 1
  16325. pattern: ^[-._a-zA-Z0-9]+$
  16326. type: string
  16327. name:
  16328. description: The name of the Secret resource being referred to.
  16329. maxLength: 253
  16330. minLength: 1
  16331. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16332. type: string
  16333. namespace:
  16334. description: |-
  16335. The namespace of the Secret resource being referred to.
  16336. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16337. maxLength: 63
  16338. minLength: 1
  16339. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16340. type: string
  16341. type: object
  16342. clientSecret:
  16343. description: The Azure ClientSecret of the service principle used for authentication.
  16344. properties:
  16345. key:
  16346. description: |-
  16347. A key in the referenced Secret.
  16348. Some instances of this field may be defaulted, in others it may be required.
  16349. maxLength: 253
  16350. minLength: 1
  16351. pattern: ^[-._a-zA-Z0-9]+$
  16352. type: string
  16353. name:
  16354. description: The name of the Secret resource being referred to.
  16355. maxLength: 253
  16356. minLength: 1
  16357. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16358. type: string
  16359. namespace:
  16360. description: |-
  16361. The namespace of the Secret resource being referred to.
  16362. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16363. maxLength: 63
  16364. minLength: 1
  16365. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16366. type: string
  16367. type: object
  16368. tenantId:
  16369. description: The Azure tenantId of the managed identity used for authentication.
  16370. properties:
  16371. key:
  16372. description: |-
  16373. A key in the referenced Secret.
  16374. Some instances of this field may be defaulted, in others it may be required.
  16375. maxLength: 253
  16376. minLength: 1
  16377. pattern: ^[-._a-zA-Z0-9]+$
  16378. type: string
  16379. name:
  16380. description: The name of the Secret resource being referred to.
  16381. maxLength: 253
  16382. minLength: 1
  16383. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16384. type: string
  16385. namespace:
  16386. description: |-
  16387. The namespace of the Secret resource being referred to.
  16388. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16389. maxLength: 63
  16390. minLength: 1
  16391. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16392. type: string
  16393. type: object
  16394. type: object
  16395. authType:
  16396. default: ServicePrincipal
  16397. description: |-
  16398. Auth type defines how to authenticate to the keyvault service.
  16399. Valid values are:
  16400. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  16401. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  16402. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  16403. enum:
  16404. - ServicePrincipal
  16405. - ManagedIdentity
  16406. - WorkloadIdentity
  16407. type: string
  16408. customCloudConfig:
  16409. description: |-
  16410. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  16411. Required when EnvironmentType is AzureStackCloud.
  16412. Optional for other environment types - useful for Azure China when using Workload Identity
  16413. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  16414. standard China Cloud endpoint (login.chinacloudapi.cn).
  16415. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  16416. configuration is not supported with the legacy go-autorest SDK.
  16417. properties:
  16418. activeDirectoryEndpoint:
  16419. description: |-
  16420. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  16421. Required when using custom cloud configuration
  16422. type: string
  16423. keyVaultDNSSuffix:
  16424. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  16425. type: string
  16426. keyVaultEndpoint:
  16427. description: KeyVaultEndpoint is the Key Vault service endpoint
  16428. type: string
  16429. resourceManagerEndpoint:
  16430. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  16431. type: string
  16432. required:
  16433. - activeDirectoryEndpoint
  16434. type: object
  16435. environmentType:
  16436. default: PublicCloud
  16437. description: |-
  16438. EnvironmentType specifies the Azure cloud environment endpoints to use for
  16439. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  16440. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  16441. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  16442. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  16443. enum:
  16444. - PublicCloud
  16445. - USGovernmentCloud
  16446. - ChinaCloud
  16447. - GermanCloud
  16448. - AzureStackCloud
  16449. type: string
  16450. identityId:
  16451. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  16452. type: string
  16453. serviceAccountRef:
  16454. description: |-
  16455. ServiceAccountRef specified the service account
  16456. that should be used when authenticating with WorkloadIdentity.
  16457. properties:
  16458. audiences:
  16459. description: |-
  16460. Audience specifies the `aud` claim for the service account token
  16461. Some providers automatically extend the audience field based on well-known annotations for workload
  16462. identity (e.g. IRSA or GCP Workload Identity)
  16463. items:
  16464. type: string
  16465. type: array
  16466. name:
  16467. description: The name of the ServiceAccount resource being referred to.
  16468. maxLength: 253
  16469. minLength: 1
  16470. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16471. type: string
  16472. namespace:
  16473. description: |-
  16474. Namespace of the resource being referred to.
  16475. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16476. maxLength: 63
  16477. minLength: 1
  16478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16479. type: string
  16480. required:
  16481. - name
  16482. type: object
  16483. tenantId:
  16484. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16485. type: string
  16486. useAzureSDK:
  16487. default: false
  16488. description: |-
  16489. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  16490. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  16491. type: boolean
  16492. vaultUrl:
  16493. description: Vault Url from which the secrets to be fetched from.
  16494. type: string
  16495. required:
  16496. - vaultUrl
  16497. type: object
  16498. barbican:
  16499. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  16500. properties:
  16501. auth:
  16502. description: BarbicanAuth contains the authentication information for Barbican.
  16503. properties:
  16504. password:
  16505. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  16506. properties:
  16507. secretRef:
  16508. description: |-
  16509. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16510. In some instances, `key` is a required field.
  16511. properties:
  16512. key:
  16513. description: |-
  16514. A key in the referenced Secret.
  16515. Some instances of this field may be defaulted, in others it may be required.
  16516. maxLength: 253
  16517. minLength: 1
  16518. pattern: ^[-._a-zA-Z0-9]+$
  16519. type: string
  16520. name:
  16521. description: The name of the Secret resource being referred to.
  16522. maxLength: 253
  16523. minLength: 1
  16524. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16525. type: string
  16526. namespace:
  16527. description: |-
  16528. The namespace of the Secret resource being referred to.
  16529. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16530. maxLength: 63
  16531. minLength: 1
  16532. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16533. type: string
  16534. type: object
  16535. required:
  16536. - secretRef
  16537. type: object
  16538. username:
  16539. description: BarbicanProviderUsernameRef defines a reference to a secret containing username for the Barbican provider.
  16540. maxProperties: 1
  16541. minProperties: 1
  16542. properties:
  16543. secretRef:
  16544. description: |-
  16545. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16546. In some instances, `key` is a required field.
  16547. properties:
  16548. key:
  16549. description: |-
  16550. A key in the referenced Secret.
  16551. Some instances of this field may be defaulted, in others it may be required.
  16552. maxLength: 253
  16553. minLength: 1
  16554. pattern: ^[-._a-zA-Z0-9]+$
  16555. type: string
  16556. name:
  16557. description: The name of the Secret resource being referred to.
  16558. maxLength: 253
  16559. minLength: 1
  16560. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16561. type: string
  16562. namespace:
  16563. description: |-
  16564. The namespace of the Secret resource being referred to.
  16565. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16566. maxLength: 63
  16567. minLength: 1
  16568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16569. type: string
  16570. type: object
  16571. value:
  16572. type: string
  16573. type: object
  16574. required:
  16575. - password
  16576. - username
  16577. type: object
  16578. authURL:
  16579. type: string
  16580. domainName:
  16581. type: string
  16582. region:
  16583. type: string
  16584. tenantName:
  16585. type: string
  16586. required:
  16587. - auth
  16588. type: object
  16589. beyondtrust:
  16590. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  16591. properties:
  16592. auth:
  16593. description: Auth configures how the operator authenticates with Beyondtrust.
  16594. properties:
  16595. apiKey:
  16596. description: APIKey If not provided then ClientID/ClientSecret become required.
  16597. properties:
  16598. secretRef:
  16599. description: SecretRef references a key in a secret that will be used as value.
  16600. properties:
  16601. key:
  16602. description: |-
  16603. A key in the referenced Secret.
  16604. Some instances of this field may be defaulted, in others it may be required.
  16605. maxLength: 253
  16606. minLength: 1
  16607. pattern: ^[-._a-zA-Z0-9]+$
  16608. type: string
  16609. name:
  16610. description: The name of the Secret resource being referred to.
  16611. maxLength: 253
  16612. minLength: 1
  16613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16614. type: string
  16615. namespace:
  16616. description: |-
  16617. The namespace of the Secret resource being referred to.
  16618. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16619. maxLength: 63
  16620. minLength: 1
  16621. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16622. type: string
  16623. type: object
  16624. value:
  16625. description: Value can be specified directly to set a value without using a secret.
  16626. type: string
  16627. type: object
  16628. certificate:
  16629. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  16630. properties:
  16631. secretRef:
  16632. description: SecretRef references a key in a secret that will be used as value.
  16633. properties:
  16634. key:
  16635. description: |-
  16636. A key in the referenced Secret.
  16637. Some instances of this field may be defaulted, in others it may be required.
  16638. maxLength: 253
  16639. minLength: 1
  16640. pattern: ^[-._a-zA-Z0-9]+$
  16641. type: string
  16642. name:
  16643. description: The name of the Secret resource being referred to.
  16644. maxLength: 253
  16645. minLength: 1
  16646. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16647. type: string
  16648. namespace:
  16649. description: |-
  16650. The namespace of the Secret resource being referred to.
  16651. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16652. maxLength: 63
  16653. minLength: 1
  16654. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16655. type: string
  16656. type: object
  16657. value:
  16658. description: Value can be specified directly to set a value without using a secret.
  16659. type: string
  16660. type: object
  16661. certificateKey:
  16662. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  16663. properties:
  16664. secretRef:
  16665. description: SecretRef references a key in a secret that will be used as value.
  16666. properties:
  16667. key:
  16668. description: |-
  16669. A key in the referenced Secret.
  16670. Some instances of this field may be defaulted, in others it may be required.
  16671. maxLength: 253
  16672. minLength: 1
  16673. pattern: ^[-._a-zA-Z0-9]+$
  16674. type: string
  16675. name:
  16676. description: The name of the Secret resource being referred to.
  16677. maxLength: 253
  16678. minLength: 1
  16679. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16680. type: string
  16681. namespace:
  16682. description: |-
  16683. The namespace of the Secret resource being referred to.
  16684. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16685. maxLength: 63
  16686. minLength: 1
  16687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16688. type: string
  16689. type: object
  16690. value:
  16691. description: Value can be specified directly to set a value without using a secret.
  16692. type: string
  16693. type: object
  16694. clientId:
  16695. description: ClientID is the API OAuth Client ID.
  16696. properties:
  16697. secretRef:
  16698. description: SecretRef references a key in a secret that will be used as value.
  16699. properties:
  16700. key:
  16701. description: |-
  16702. A key in the referenced Secret.
  16703. Some instances of this field may be defaulted, in others it may be required.
  16704. maxLength: 253
  16705. minLength: 1
  16706. pattern: ^[-._a-zA-Z0-9]+$
  16707. type: string
  16708. name:
  16709. description: The name of the Secret resource being referred to.
  16710. maxLength: 253
  16711. minLength: 1
  16712. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16713. type: string
  16714. namespace:
  16715. description: |-
  16716. The namespace of the Secret resource being referred to.
  16717. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16718. maxLength: 63
  16719. minLength: 1
  16720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16721. type: string
  16722. type: object
  16723. value:
  16724. description: Value can be specified directly to set a value without using a secret.
  16725. type: string
  16726. type: object
  16727. clientSecret:
  16728. description: ClientSecret is the API OAuth Client Secret.
  16729. properties:
  16730. secretRef:
  16731. description: SecretRef references a key in a secret that will be used as value.
  16732. properties:
  16733. key:
  16734. description: |-
  16735. A key in the referenced Secret.
  16736. Some instances of this field may be defaulted, in others it may be required.
  16737. maxLength: 253
  16738. minLength: 1
  16739. pattern: ^[-._a-zA-Z0-9]+$
  16740. type: string
  16741. name:
  16742. description: The name of the Secret resource being referred to.
  16743. maxLength: 253
  16744. minLength: 1
  16745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16746. type: string
  16747. namespace:
  16748. description: |-
  16749. The namespace of the Secret resource being referred to.
  16750. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16751. maxLength: 63
  16752. minLength: 1
  16753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16754. type: string
  16755. type: object
  16756. value:
  16757. description: Value can be specified directly to set a value without using a secret.
  16758. type: string
  16759. type: object
  16760. type: object
  16761. server:
  16762. description: Auth configures how API server works.
  16763. properties:
  16764. apiUrl:
  16765. type: string
  16766. apiVersion:
  16767. type: string
  16768. clientTimeOutSeconds:
  16769. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  16770. type: integer
  16771. decrypt:
  16772. default: true
  16773. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  16774. type: boolean
  16775. retrievalType:
  16776. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  16777. type: string
  16778. separator:
  16779. description: A character that separates the folder names.
  16780. type: string
  16781. verifyCA:
  16782. type: boolean
  16783. required:
  16784. - apiUrl
  16785. - verifyCA
  16786. type: object
  16787. required:
  16788. - auth
  16789. - server
  16790. type: object
  16791. beyondtrustworkloadcredentials:
  16792. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  16793. properties:
  16794. auth:
  16795. description: |-
  16796. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  16797. Currently supports API key authentication via Kubernetes secret reference.
  16798. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16799. properties:
  16800. apikey:
  16801. description: |-
  16802. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  16803. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  16804. properties:
  16805. token:
  16806. description: |-
  16807. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  16808. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  16809. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  16810. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16811. properties:
  16812. key:
  16813. description: |-
  16814. A key in the referenced Secret.
  16815. Some instances of this field may be defaulted, in others it may be required.
  16816. maxLength: 253
  16817. minLength: 1
  16818. pattern: ^[-._a-zA-Z0-9]+$
  16819. type: string
  16820. name:
  16821. description: The name of the Secret resource being referred to.
  16822. maxLength: 253
  16823. minLength: 1
  16824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16825. type: string
  16826. namespace:
  16827. description: |-
  16828. The namespace of the Secret resource being referred to.
  16829. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16830. maxLength: 63
  16831. minLength: 1
  16832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16833. type: string
  16834. type: object
  16835. required:
  16836. - token
  16837. type: object
  16838. required:
  16839. - apikey
  16840. type: object
  16841. caBundle:
  16842. description: |-
  16843. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  16844. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  16845. If not set, the system's trusted root certificates are used.
  16846. format: byte
  16847. type: string
  16848. caProvider:
  16849. description: |-
  16850. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  16851. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  16852. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  16853. properties:
  16854. key:
  16855. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16856. maxLength: 253
  16857. minLength: 1
  16858. pattern: ^[-._a-zA-Z0-9]+$
  16859. type: string
  16860. name:
  16861. description: The name of the object located at the provider type.
  16862. maxLength: 253
  16863. minLength: 1
  16864. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16865. type: string
  16866. namespace:
  16867. description: |-
  16868. The namespace the Provider type is in.
  16869. Can only be defined when used in a ClusterSecretStore.
  16870. maxLength: 63
  16871. minLength: 1
  16872. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16873. type: string
  16874. type:
  16875. description: The type of provider to use such as "Secret", or "ConfigMap".
  16876. enum:
  16877. - Secret
  16878. - ConfigMap
  16879. type: string
  16880. required:
  16881. - name
  16882. - type
  16883. type: object
  16884. folderPath:
  16885. description: |-
  16886. FolderPath specifies the default folder path for secret retrieval.
  16887. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  16888. Example: "production/database" or "dev/api-keys"
  16889. Leave empty to retrieve secrets from the root folder.
  16890. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  16891. type: string
  16892. server:
  16893. description: |-
  16894. Server configures the BeyondTrust Workload Credentials server connection details.
  16895. Includes the API URL and Site ID for your BeyondTrust instance.
  16896. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  16897. properties:
  16898. apiUrl:
  16899. description: |-
  16900. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  16901. This should be the full URL to your BeyondTrust instance.
  16902. Example: https://api.beyondtrust.io/siie
  16903. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  16904. type: string
  16905. siteId:
  16906. description: |-
  16907. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  16908. This identifier is unique to your BeyondTrust Workload Credentials instance.
  16909. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  16910. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  16911. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  16912. type: string
  16913. required:
  16914. - apiUrl
  16915. - siteId
  16916. type: object
  16917. required:
  16918. - auth
  16919. - server
  16920. type: object
  16921. bitwardensecretsmanager:
  16922. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  16923. properties:
  16924. apiURL:
  16925. type: string
  16926. auth:
  16927. description: |-
  16928. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  16929. Make sure that the token being used has permissions on the given secret.
  16930. properties:
  16931. secretRef:
  16932. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  16933. properties:
  16934. credentials:
  16935. description: AccessToken used for the bitwarden instance.
  16936. properties:
  16937. key:
  16938. description: |-
  16939. A key in the referenced Secret.
  16940. Some instances of this field may be defaulted, in others it may be required.
  16941. maxLength: 253
  16942. minLength: 1
  16943. pattern: ^[-._a-zA-Z0-9]+$
  16944. type: string
  16945. name:
  16946. description: The name of the Secret resource being referred to.
  16947. maxLength: 253
  16948. minLength: 1
  16949. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16950. type: string
  16951. namespace:
  16952. description: |-
  16953. The namespace of the Secret resource being referred to.
  16954. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16955. maxLength: 63
  16956. minLength: 1
  16957. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16958. type: string
  16959. type: object
  16960. required:
  16961. - credentials
  16962. type: object
  16963. required:
  16964. - secretRef
  16965. type: object
  16966. bitwardenServerSDKURL:
  16967. type: string
  16968. caBundle:
  16969. description: |-
  16970. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  16971. can be performed.
  16972. type: string
  16973. caProvider:
  16974. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  16975. properties:
  16976. key:
  16977. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16978. maxLength: 253
  16979. minLength: 1
  16980. pattern: ^[-._a-zA-Z0-9]+$
  16981. type: string
  16982. name:
  16983. description: The name of the object located at the provider type.
  16984. maxLength: 253
  16985. minLength: 1
  16986. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16987. type: string
  16988. namespace:
  16989. description: |-
  16990. The namespace the Provider type is in.
  16991. Can only be defined when used in a ClusterSecretStore.
  16992. maxLength: 63
  16993. minLength: 1
  16994. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16995. type: string
  16996. type:
  16997. description: The type of provider to use such as "Secret", or "ConfigMap".
  16998. enum:
  16999. - Secret
  17000. - ConfigMap
  17001. type: string
  17002. required:
  17003. - name
  17004. - type
  17005. type: object
  17006. identityURL:
  17007. type: string
  17008. organizationID:
  17009. description: OrganizationID determines which organization this secret store manages.
  17010. type: string
  17011. projectID:
  17012. description: ProjectID determines which project this secret store manages.
  17013. type: string
  17014. required:
  17015. - auth
  17016. - organizationID
  17017. - projectID
  17018. type: object
  17019. chef:
  17020. description: Chef configures this store to sync secrets with chef server
  17021. properties:
  17022. auth:
  17023. description: Auth defines the information necessary to authenticate against chef Server
  17024. properties:
  17025. secretRef:
  17026. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  17027. properties:
  17028. privateKeySecretRef:
  17029. description: SecretKey is the Signing Key in PEM format, used for authentication.
  17030. properties:
  17031. key:
  17032. description: |-
  17033. A key in the referenced Secret.
  17034. Some instances of this field may be defaulted, in others it may be required.
  17035. maxLength: 253
  17036. minLength: 1
  17037. pattern: ^[-._a-zA-Z0-9]+$
  17038. type: string
  17039. name:
  17040. description: The name of the Secret resource being referred to.
  17041. maxLength: 253
  17042. minLength: 1
  17043. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17044. type: string
  17045. namespace:
  17046. description: |-
  17047. The namespace of the Secret resource being referred to.
  17048. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17049. maxLength: 63
  17050. minLength: 1
  17051. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17052. type: string
  17053. type: object
  17054. required:
  17055. - privateKeySecretRef
  17056. type: object
  17057. required:
  17058. - secretRef
  17059. type: object
  17060. serverUrl:
  17061. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  17062. type: string
  17063. username:
  17064. description: UserName should be the user ID on the chef server
  17065. type: string
  17066. required:
  17067. - auth
  17068. - serverUrl
  17069. - username
  17070. type: object
  17071. cloudrusm:
  17072. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  17073. properties:
  17074. auth:
  17075. description: CSMAuth contains a secretRef for credentials.
  17076. properties:
  17077. secretRef:
  17078. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  17079. properties:
  17080. accessKeyIDSecretRef:
  17081. description: The AccessKeyID is used for authentication
  17082. properties:
  17083. key:
  17084. description: |-
  17085. A key in the referenced Secret.
  17086. Some instances of this field may be defaulted, in others it may be required.
  17087. maxLength: 253
  17088. minLength: 1
  17089. pattern: ^[-._a-zA-Z0-9]+$
  17090. type: string
  17091. name:
  17092. description: The name of the Secret resource being referred to.
  17093. maxLength: 253
  17094. minLength: 1
  17095. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17096. type: string
  17097. namespace:
  17098. description: |-
  17099. The namespace of the Secret resource being referred to.
  17100. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17101. maxLength: 63
  17102. minLength: 1
  17103. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17104. type: string
  17105. type: object
  17106. accessKeySecretSecretRef:
  17107. description: The AccessKeySecret is used for authentication
  17108. properties:
  17109. key:
  17110. description: |-
  17111. A key in the referenced Secret.
  17112. Some instances of this field may be defaulted, in others it may be required.
  17113. maxLength: 253
  17114. minLength: 1
  17115. pattern: ^[-._a-zA-Z0-9]+$
  17116. type: string
  17117. name:
  17118. description: The name of the Secret resource being referred to.
  17119. maxLength: 253
  17120. minLength: 1
  17121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17122. type: string
  17123. namespace:
  17124. description: |-
  17125. The namespace of the Secret resource being referred to.
  17126. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17127. maxLength: 63
  17128. minLength: 1
  17129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17130. type: string
  17131. type: object
  17132. required:
  17133. - accessKeyIDSecretRef
  17134. - accessKeySecretSecretRef
  17135. type: object
  17136. type: object
  17137. projectID:
  17138. description: ProjectID is the project, which the secrets are stored in.
  17139. type: string
  17140. required:
  17141. - auth
  17142. type: object
  17143. conjur:
  17144. description: Conjur configures this store to sync secrets using conjur provider
  17145. properties:
  17146. auth:
  17147. description: Defines authentication settings for connecting to Conjur.
  17148. maxProperties: 1
  17149. minProperties: 1
  17150. properties:
  17151. apikey:
  17152. description: Authenticates with Conjur using an API key.
  17153. properties:
  17154. account:
  17155. description: Account is the Conjur organization account name.
  17156. type: string
  17157. apiKeyRef:
  17158. description: |-
  17159. A reference to a specific 'key' containing the Conjur API key
  17160. within a Secret resource. In some instances, `key` is a required field.
  17161. properties:
  17162. key:
  17163. description: |-
  17164. A key in the referenced Secret.
  17165. Some instances of this field may be defaulted, in others it may be required.
  17166. maxLength: 253
  17167. minLength: 1
  17168. pattern: ^[-._a-zA-Z0-9]+$
  17169. type: string
  17170. name:
  17171. description: The name of the Secret resource being referred to.
  17172. maxLength: 253
  17173. minLength: 1
  17174. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17175. type: string
  17176. namespace:
  17177. description: |-
  17178. The namespace of the Secret resource being referred to.
  17179. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17180. maxLength: 63
  17181. minLength: 1
  17182. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17183. type: string
  17184. type: object
  17185. userRef:
  17186. description: |-
  17187. A reference to a specific 'key' containing the Conjur username
  17188. within a Secret resource. In some instances, `key` is a required field.
  17189. properties:
  17190. key:
  17191. description: |-
  17192. A key in the referenced Secret.
  17193. Some instances of this field may be defaulted, in others it may be required.
  17194. maxLength: 253
  17195. minLength: 1
  17196. pattern: ^[-._a-zA-Z0-9]+$
  17197. type: string
  17198. name:
  17199. description: The name of the Secret resource being referred to.
  17200. maxLength: 253
  17201. minLength: 1
  17202. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17203. type: string
  17204. namespace:
  17205. description: |-
  17206. The namespace of the Secret resource being referred to.
  17207. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17208. maxLength: 63
  17209. minLength: 1
  17210. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17211. type: string
  17212. type: object
  17213. required:
  17214. - account
  17215. - apiKeyRef
  17216. - userRef
  17217. type: object
  17218. cert:
  17219. description: Cert enables certificate-based authentication using a client certificate and key.
  17220. properties:
  17221. account:
  17222. description: Account is the Conjur organization account name.
  17223. type: string
  17224. clientCertRef:
  17225. description: |-
  17226. ClientCertRef is a reference to a specific 'key' containing the client certificate
  17227. within a Secret resource. The certificate must be PEM-encoded.
  17228. properties:
  17229. key:
  17230. description: |-
  17231. A key in the referenced Secret.
  17232. Some instances of this field may be defaulted, in others it may be required.
  17233. maxLength: 253
  17234. minLength: 1
  17235. pattern: ^[-._a-zA-Z0-9]+$
  17236. type: string
  17237. name:
  17238. description: The name of the Secret resource being referred to.
  17239. maxLength: 253
  17240. minLength: 1
  17241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17242. type: string
  17243. namespace:
  17244. description: |-
  17245. The namespace of the Secret resource being referred to.
  17246. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17247. maxLength: 63
  17248. minLength: 1
  17249. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17250. type: string
  17251. type: object
  17252. clientKeyRef:
  17253. description: |-
  17254. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  17255. within a Secret resource. The key must be PEM-encoded.
  17256. properties:
  17257. key:
  17258. description: |-
  17259. A key in the referenced Secret.
  17260. Some instances of this field may be defaulted, in others it may be required.
  17261. maxLength: 253
  17262. minLength: 1
  17263. pattern: ^[-._a-zA-Z0-9]+$
  17264. type: string
  17265. name:
  17266. description: The name of the Secret resource being referred to.
  17267. maxLength: 253
  17268. minLength: 1
  17269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17270. type: string
  17271. namespace:
  17272. description: |-
  17273. The namespace of the Secret resource being referred to.
  17274. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17275. maxLength: 63
  17276. minLength: 1
  17277. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17278. type: string
  17279. type: object
  17280. hostId:
  17281. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  17282. type: string
  17283. serviceID:
  17284. description: The conjur authn cert webservice id
  17285. type: string
  17286. required:
  17287. - account
  17288. - clientCertRef
  17289. - clientKeyRef
  17290. - serviceID
  17291. type: object
  17292. jwt:
  17293. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  17294. properties:
  17295. account:
  17296. description: Account is the Conjur organization account name.
  17297. type: string
  17298. hostId:
  17299. description: |-
  17300. Optional HostID for JWT authentication. This may be used depending
  17301. on how the Conjur JWT authenticator policy is configured.
  17302. type: string
  17303. secretRef:
  17304. description: |-
  17305. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  17306. authenticate with Conjur using the JWT authentication method.
  17307. properties:
  17308. key:
  17309. description: |-
  17310. A key in the referenced Secret.
  17311. Some instances of this field may be defaulted, in others it may be required.
  17312. maxLength: 253
  17313. minLength: 1
  17314. pattern: ^[-._a-zA-Z0-9]+$
  17315. type: string
  17316. name:
  17317. description: The name of the Secret resource being referred to.
  17318. maxLength: 253
  17319. minLength: 1
  17320. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17321. type: string
  17322. namespace:
  17323. description: |-
  17324. The namespace of the Secret resource being referred to.
  17325. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17326. maxLength: 63
  17327. minLength: 1
  17328. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17329. type: string
  17330. type: object
  17331. serviceAccountRef:
  17332. description: |-
  17333. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  17334. a token for with the `TokenRequest` API.
  17335. properties:
  17336. audiences:
  17337. description: |-
  17338. Audience specifies the `aud` claim for the service account token
  17339. Some providers automatically extend the audience field based on well-known annotations for workload
  17340. identity (e.g. IRSA or GCP Workload Identity)
  17341. items:
  17342. type: string
  17343. type: array
  17344. name:
  17345. description: The name of the ServiceAccount resource being referred to.
  17346. maxLength: 253
  17347. minLength: 1
  17348. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17349. type: string
  17350. namespace:
  17351. description: |-
  17352. Namespace of the resource being referred to.
  17353. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17354. maxLength: 63
  17355. minLength: 1
  17356. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17357. type: string
  17358. required:
  17359. - name
  17360. type: object
  17361. serviceID:
  17362. description: The conjur authn jwt webservice id
  17363. type: string
  17364. required:
  17365. - account
  17366. - serviceID
  17367. type: object
  17368. type: object
  17369. caBundle:
  17370. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  17371. type: string
  17372. caProvider:
  17373. description: |-
  17374. Used to provide custom certificate authority (CA) certificates
  17375. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  17376. that contains a PEM-encoded certificate.
  17377. properties:
  17378. key:
  17379. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17380. maxLength: 253
  17381. minLength: 1
  17382. pattern: ^[-._a-zA-Z0-9]+$
  17383. type: string
  17384. name:
  17385. description: The name of the object located at the provider type.
  17386. maxLength: 253
  17387. minLength: 1
  17388. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17389. type: string
  17390. namespace:
  17391. description: |-
  17392. The namespace the Provider type is in.
  17393. Can only be defined when used in a ClusterSecretStore.
  17394. maxLength: 63
  17395. minLength: 1
  17396. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17397. type: string
  17398. type:
  17399. description: The type of provider to use such as "Secret", or "ConfigMap".
  17400. enum:
  17401. - Secret
  17402. - ConfigMap
  17403. type: string
  17404. required:
  17405. - name
  17406. - type
  17407. type: object
  17408. url:
  17409. description: URL is the endpoint of the Conjur instance.
  17410. type: string
  17411. required:
  17412. - auth
  17413. - url
  17414. type: object
  17415. crd:
  17416. description: |-
  17417. CRD configures this store to sync secrets from arbitrary Kubernetes resources,
  17418. including both custom resources (CRDs) and core API resources. Resources are
  17419. selected by API group, version and kind, where group can be "" (empty string)
  17420. for core resources such as ConfigMap. Reading the core v1 Secret is
  17421. intentionally blocked — use the Kubernetes provider for that.
  17422. properties:
  17423. auth:
  17424. description: |-
  17425. Auth configures authentication to the Kubernetes API, same as the
  17426. Kubernetes provider. Required when Server.URL is set (unless using AuthRef).
  17427. maxProperties: 1
  17428. minProperties: 1
  17429. properties:
  17430. cert:
  17431. description: has both clientCert and clientKey as secretKeySelector
  17432. properties:
  17433. clientCert:
  17434. description: |-
  17435. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17436. In some instances, `key` is a required field.
  17437. properties:
  17438. key:
  17439. description: |-
  17440. A key in the referenced Secret.
  17441. Some instances of this field may be defaulted, in others it may be required.
  17442. maxLength: 253
  17443. minLength: 1
  17444. pattern: ^[-._a-zA-Z0-9]+$
  17445. type: string
  17446. name:
  17447. description: The name of the Secret resource being referred to.
  17448. maxLength: 253
  17449. minLength: 1
  17450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17451. type: string
  17452. namespace:
  17453. description: |-
  17454. The namespace of the Secret resource being referred to.
  17455. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17456. maxLength: 63
  17457. minLength: 1
  17458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17459. type: string
  17460. type: object
  17461. clientKey:
  17462. description: |-
  17463. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17464. In some instances, `key` is a required field.
  17465. properties:
  17466. key:
  17467. description: |-
  17468. A key in the referenced Secret.
  17469. Some instances of this field may be defaulted, in others it may be required.
  17470. maxLength: 253
  17471. minLength: 1
  17472. pattern: ^[-._a-zA-Z0-9]+$
  17473. type: string
  17474. name:
  17475. description: The name of the Secret resource being referred to.
  17476. maxLength: 253
  17477. minLength: 1
  17478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17479. type: string
  17480. namespace:
  17481. description: |-
  17482. The namespace of the Secret resource being referred to.
  17483. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17484. maxLength: 63
  17485. minLength: 1
  17486. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17487. type: string
  17488. type: object
  17489. required:
  17490. - clientCert
  17491. - clientKey
  17492. type: object
  17493. serviceAccount:
  17494. description: points to a service account that should be used for authentication
  17495. properties:
  17496. audiences:
  17497. description: |-
  17498. Audience specifies the `aud` claim for the service account token
  17499. Some providers automatically extend the audience field based on well-known annotations for workload
  17500. identity (e.g. IRSA or GCP Workload Identity)
  17501. items:
  17502. type: string
  17503. type: array
  17504. name:
  17505. description: The name of the ServiceAccount resource being referred to.
  17506. maxLength: 253
  17507. minLength: 1
  17508. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17509. type: string
  17510. namespace:
  17511. description: |-
  17512. Namespace of the resource being referred to.
  17513. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17514. maxLength: 63
  17515. minLength: 1
  17516. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17517. type: string
  17518. required:
  17519. - name
  17520. type: object
  17521. token:
  17522. description: use static token to authenticate with
  17523. properties:
  17524. bearerToken:
  17525. description: |-
  17526. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17527. In some instances, `key` is a required field.
  17528. properties:
  17529. key:
  17530. description: |-
  17531. A key in the referenced Secret.
  17532. Some instances of this field may be defaulted, in others it may be required.
  17533. maxLength: 253
  17534. minLength: 1
  17535. pattern: ^[-._a-zA-Z0-9]+$
  17536. type: string
  17537. name:
  17538. description: The name of the Secret resource being referred to.
  17539. maxLength: 253
  17540. minLength: 1
  17541. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17542. type: string
  17543. namespace:
  17544. description: |-
  17545. The namespace of the Secret resource being referred to.
  17546. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17547. maxLength: 63
  17548. minLength: 1
  17549. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17550. type: string
  17551. type: object
  17552. required:
  17553. - bearerToken
  17554. type: object
  17555. type: object
  17556. authRef:
  17557. description: |-
  17558. AuthRef references a Secret containing a kubeconfig. Same semantics as the
  17559. Kubernetes provider.
  17560. properties:
  17561. key:
  17562. description: |-
  17563. A key in the referenced Secret.
  17564. Some instances of this field may be defaulted, in others it may be required.
  17565. maxLength: 253
  17566. minLength: 1
  17567. pattern: ^[-._a-zA-Z0-9]+$
  17568. type: string
  17569. name:
  17570. description: The name of the Secret resource being referred to.
  17571. maxLength: 253
  17572. minLength: 1
  17573. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17574. type: string
  17575. namespace:
  17576. description: |-
  17577. The namespace of the Secret resource being referred to.
  17578. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17579. maxLength: 63
  17580. minLength: 1
  17581. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17582. type: string
  17583. type: object
  17584. resource:
  17585. description: Resource identifies the CRD by its API group, version and kind.
  17586. properties:
  17587. group:
  17588. description: |-
  17589. Group is the API group of the resource. Use "" (empty string) for core
  17590. Kubernetes resources such as ConfigMap; use e.g. "config.example.io"
  17591. for a CRD. The field is required to be present in the manifest — write
  17592. `group: ""` explicitly for core resources so typos fail at admission
  17593. time rather than later at discovery.
  17594. type: string
  17595. kind:
  17596. description: Kind is the Kubernetes resource kind (e.g. "MyCustomResource").
  17597. minLength: 1
  17598. type: string
  17599. version:
  17600. description: Version is the API version of the resource (e.g. "v1alpha1").
  17601. minLength: 1
  17602. type: string
  17603. required:
  17604. - group
  17605. - kind
  17606. - version
  17607. type: object
  17608. server:
  17609. description: |-
  17610. Server configures the Kubernetes API address and TLS trust, same as the
  17611. Kubernetes provider. When omitted, the URL defaults to the in-cluster API.
  17612. properties:
  17613. caBundle:
  17614. description: CABundle is a base64-encoded CA certificate
  17615. format: byte
  17616. type: string
  17617. caProvider:
  17618. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  17619. properties:
  17620. key:
  17621. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17622. maxLength: 253
  17623. minLength: 1
  17624. pattern: ^[-._a-zA-Z0-9]+$
  17625. type: string
  17626. name:
  17627. description: The name of the object located at the provider type.
  17628. maxLength: 253
  17629. minLength: 1
  17630. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17631. type: string
  17632. namespace:
  17633. description: |-
  17634. The namespace the Provider type is in.
  17635. Can only be defined when used in a ClusterSecretStore.
  17636. maxLength: 63
  17637. minLength: 1
  17638. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17639. type: string
  17640. type:
  17641. description: The type of provider to use such as "Secret", or "ConfigMap".
  17642. enum:
  17643. - Secret
  17644. - ConfigMap
  17645. type: string
  17646. required:
  17647. - name
  17648. - type
  17649. type: object
  17650. url:
  17651. default: kubernetes.default
  17652. description: configures the Kubernetes server Address.
  17653. type: string
  17654. type: object
  17655. whitelist:
  17656. description: |-
  17657. Whitelist optionally restricts which object names and requested properties
  17658. are allowed to be read.
  17659. properties:
  17660. rules:
  17661. description: |-
  17662. Rules is a list of allow rules. If rules are set, at least one rule must
  17663. match for a request to be allowed.
  17664. items:
  17665. description: CRDProviderWhitelistRule defines a single allow rule for CRD reads.
  17666. properties:
  17667. name:
  17668. description: |-
  17669. Name is an optional regular expression matched against the bare object name.
  17670. For both SecretStore and ClusterSecretStore this is always the object name
  17671. without any namespace prefix (e.g. "my-db-spec", not "prod/my-db-spec").
  17672. type: string
  17673. namespace:
  17674. description: |-
  17675. Namespace is an optional regular expression matched against the namespace of
  17676. the object. Applies only when a ClusterSecretStore is used; it is ignored
  17677. for SecretStore (where the namespace is fixed to the store namespace).
  17678. type: string
  17679. properties:
  17680. description: |-
  17681. Properties is an optional list of regular expressions matched against
  17682. requested property keys (for example: "spec.secretValue").
  17683. items:
  17684. type: string
  17685. type: array
  17686. type: object
  17687. type: array
  17688. type: object
  17689. required:
  17690. - resource
  17691. type: object
  17692. x-kubernetes-validations:
  17693. - message: one of auth or authRef is required
  17694. rule: has(self.auth) || has(self.authRef)
  17695. - message: at most one of the fields in [auth authRef] may be set
  17696. rule: '[has(self.auth),has(self.authRef)].filter(x,x==true).size() <= 1'
  17697. delinea:
  17698. description: |-
  17699. Delinea DevOps Secrets Vault
  17700. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  17701. properties:
  17702. clientId:
  17703. description: ClientID is the non-secret part of the credential.
  17704. properties:
  17705. secretRef:
  17706. description: SecretRef references a key in a secret that will be used as value.
  17707. properties:
  17708. key:
  17709. description: |-
  17710. A key in the referenced Secret.
  17711. Some instances of this field may be defaulted, in others it may be required.
  17712. maxLength: 253
  17713. minLength: 1
  17714. pattern: ^[-._a-zA-Z0-9]+$
  17715. type: string
  17716. name:
  17717. description: The name of the Secret resource being referred to.
  17718. maxLength: 253
  17719. minLength: 1
  17720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17721. type: string
  17722. namespace:
  17723. description: |-
  17724. The namespace of the Secret resource being referred to.
  17725. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17726. maxLength: 63
  17727. minLength: 1
  17728. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17729. type: string
  17730. type: object
  17731. value:
  17732. description: Value can be specified directly to set a value without using a secret.
  17733. type: string
  17734. type: object
  17735. clientSecret:
  17736. description: ClientSecret is the secret part of the credential.
  17737. properties:
  17738. secretRef:
  17739. description: SecretRef references a key in a secret that will be used as value.
  17740. properties:
  17741. key:
  17742. description: |-
  17743. A key in the referenced Secret.
  17744. Some instances of this field may be defaulted, in others it may be required.
  17745. maxLength: 253
  17746. minLength: 1
  17747. pattern: ^[-._a-zA-Z0-9]+$
  17748. type: string
  17749. name:
  17750. description: The name of the Secret resource being referred to.
  17751. maxLength: 253
  17752. minLength: 1
  17753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17754. type: string
  17755. namespace:
  17756. description: |-
  17757. The namespace of the Secret resource being referred to.
  17758. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17759. maxLength: 63
  17760. minLength: 1
  17761. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17762. type: string
  17763. type: object
  17764. value:
  17765. description: Value can be specified directly to set a value without using a secret.
  17766. type: string
  17767. type: object
  17768. tenant:
  17769. description: Tenant is the chosen hostname / site name.
  17770. type: string
  17771. tld:
  17772. description: |-
  17773. TLD is based on the server location that was chosen during provisioning.
  17774. If unset, defaults to "com".
  17775. type: string
  17776. urlTemplate:
  17777. description: |-
  17778. URLTemplate
  17779. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  17780. type: string
  17781. required:
  17782. - clientId
  17783. - clientSecret
  17784. - tenant
  17785. type: object
  17786. doppler:
  17787. description: Doppler configures this store to sync secrets using the Doppler provider
  17788. properties:
  17789. auth:
  17790. description: Auth configures how the Operator authenticates with the Doppler API
  17791. properties:
  17792. oidcConfig:
  17793. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  17794. properties:
  17795. expirationSeconds:
  17796. default: 600
  17797. description: |-
  17798. ExpirationSeconds sets the ServiceAccount token validity duration.
  17799. Defaults to 10 minutes.
  17800. format: int64
  17801. type: integer
  17802. identity:
  17803. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  17804. type: string
  17805. serviceAccountRef:
  17806. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  17807. properties:
  17808. audiences:
  17809. description: |-
  17810. Audience specifies the `aud` claim for the service account token
  17811. Some providers automatically extend the audience field based on well-known annotations for workload
  17812. identity (e.g. IRSA or GCP Workload Identity)
  17813. items:
  17814. type: string
  17815. type: array
  17816. name:
  17817. description: The name of the ServiceAccount resource being referred to.
  17818. maxLength: 253
  17819. minLength: 1
  17820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17821. type: string
  17822. namespace:
  17823. description: |-
  17824. Namespace of the resource being referred to.
  17825. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17826. maxLength: 63
  17827. minLength: 1
  17828. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17829. type: string
  17830. required:
  17831. - name
  17832. type: object
  17833. required:
  17834. - identity
  17835. - serviceAccountRef
  17836. type: object
  17837. secretRef:
  17838. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  17839. properties:
  17840. dopplerToken:
  17841. description: |-
  17842. The DopplerToken is used for authentication.
  17843. See https://docs.doppler.com/reference/api#authentication for auth token types.
  17844. The Key attribute defaults to dopplerToken if not specified.
  17845. properties:
  17846. key:
  17847. description: |-
  17848. A key in the referenced Secret.
  17849. Some instances of this field may be defaulted, in others it may be required.
  17850. maxLength: 253
  17851. minLength: 1
  17852. pattern: ^[-._a-zA-Z0-9]+$
  17853. type: string
  17854. name:
  17855. description: The name of the Secret resource being referred to.
  17856. maxLength: 253
  17857. minLength: 1
  17858. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17859. type: string
  17860. namespace:
  17861. description: |-
  17862. The namespace of the Secret resource being referred to.
  17863. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17864. maxLength: 63
  17865. minLength: 1
  17866. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17867. type: string
  17868. type: object
  17869. required:
  17870. - dopplerToken
  17871. type: object
  17872. type: object
  17873. x-kubernetes-validations:
  17874. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  17875. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  17876. config:
  17877. description: Doppler config (required if not using a Service Token)
  17878. type: string
  17879. format:
  17880. description: Format enables the downloading of secrets as a file (string)
  17881. enum:
  17882. - json
  17883. - dotnet-json
  17884. - env
  17885. - yaml
  17886. - docker
  17887. type: string
  17888. nameTransformer:
  17889. description: Environment variable compatible name transforms that change secret names to a different format
  17890. enum:
  17891. - upper-camel
  17892. - camel
  17893. - lower-snake
  17894. - tf-var
  17895. - dotnet-env
  17896. - lower-kebab
  17897. type: string
  17898. project:
  17899. description: Doppler project (required if not using a Service Token)
  17900. type: string
  17901. required:
  17902. - auth
  17903. type: object
  17904. dvls:
  17905. description: DVLS configures this store to sync secrets using Devolutions Server provider
  17906. properties:
  17907. auth:
  17908. description: Auth defines the authentication method to use.
  17909. properties:
  17910. secretRef:
  17911. description: SecretRef contains the Application ID and Application Secret for authentication.
  17912. properties:
  17913. appId:
  17914. description: AppID is the reference to the secret containing the Application ID.
  17915. properties:
  17916. key:
  17917. description: |-
  17918. A key in the referenced Secret.
  17919. Some instances of this field may be defaulted, in others it may be required.
  17920. maxLength: 253
  17921. minLength: 1
  17922. pattern: ^[-._a-zA-Z0-9]+$
  17923. type: string
  17924. name:
  17925. description: The name of the Secret resource being referred to.
  17926. maxLength: 253
  17927. minLength: 1
  17928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17929. type: string
  17930. namespace:
  17931. description: |-
  17932. The namespace of the Secret resource being referred to.
  17933. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17934. maxLength: 63
  17935. minLength: 1
  17936. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17937. type: string
  17938. type: object
  17939. appSecret:
  17940. description: AppSecret is the reference to the secret containing the Application Secret.
  17941. properties:
  17942. key:
  17943. description: |-
  17944. A key in the referenced Secret.
  17945. Some instances of this field may be defaulted, in others it may be required.
  17946. maxLength: 253
  17947. minLength: 1
  17948. pattern: ^[-._a-zA-Z0-9]+$
  17949. type: string
  17950. name:
  17951. description: The name of the Secret resource being referred to.
  17952. maxLength: 253
  17953. minLength: 1
  17954. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17955. type: string
  17956. namespace:
  17957. description: |-
  17958. The namespace of the Secret resource being referred to.
  17959. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17960. maxLength: 63
  17961. minLength: 1
  17962. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17963. type: string
  17964. type: object
  17965. required:
  17966. - appId
  17967. - appSecret
  17968. type: object
  17969. required:
  17970. - secretRef
  17971. type: object
  17972. insecure:
  17973. description: |-
  17974. Insecure allows connecting to DVLS over plain HTTP.
  17975. This is NOT RECOMMENDED for production use.
  17976. Set to true only if you understand the security implications.
  17977. type: boolean
  17978. serverUrl:
  17979. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  17980. type: string
  17981. vault:
  17982. description: |-
  17983. Vault is the name or UUID of the vault to fetch secrets from.
  17984. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  17985. type: string
  17986. required:
  17987. - auth
  17988. - serverUrl
  17989. type: object
  17990. fake:
  17991. description: Fake configures a store with static key/value pairs
  17992. properties:
  17993. data:
  17994. items:
  17995. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  17996. properties:
  17997. key:
  17998. type: string
  17999. value:
  18000. type: string
  18001. version:
  18002. type: string
  18003. required:
  18004. - key
  18005. - value
  18006. type: object
  18007. type: array
  18008. validationResult:
  18009. description: ValidationResult is defined type for the number of validation results.
  18010. type: integer
  18011. required:
  18012. - data
  18013. type: object
  18014. fortanix:
  18015. description: Fortanix configures this store to sync secrets using the Fortanix provider
  18016. properties:
  18017. apiKey:
  18018. description: APIKey is the API token to access SDKMS Applications.
  18019. properties:
  18020. secretRef:
  18021. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  18022. properties:
  18023. key:
  18024. description: |-
  18025. A key in the referenced Secret.
  18026. Some instances of this field may be defaulted, in others it may be required.
  18027. maxLength: 253
  18028. minLength: 1
  18029. pattern: ^[-._a-zA-Z0-9]+$
  18030. type: string
  18031. name:
  18032. description: The name of the Secret resource being referred to.
  18033. maxLength: 253
  18034. minLength: 1
  18035. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18036. type: string
  18037. namespace:
  18038. description: |-
  18039. The namespace of the Secret resource being referred to.
  18040. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18041. maxLength: 63
  18042. minLength: 1
  18043. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18044. type: string
  18045. type: object
  18046. type: object
  18047. apiUrl:
  18048. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  18049. type: string
  18050. type: object
  18051. gcpsm:
  18052. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  18053. properties:
  18054. auth:
  18055. description: Auth defines the information necessary to authenticate against GCP
  18056. properties:
  18057. secretRef:
  18058. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  18059. properties:
  18060. secretAccessKeySecretRef:
  18061. description: The SecretAccessKey is used for authentication
  18062. properties:
  18063. key:
  18064. description: |-
  18065. A key in the referenced Secret.
  18066. Some instances of this field may be defaulted, in others it may be required.
  18067. maxLength: 253
  18068. minLength: 1
  18069. pattern: ^[-._a-zA-Z0-9]+$
  18070. type: string
  18071. name:
  18072. description: The name of the Secret resource being referred to.
  18073. maxLength: 253
  18074. minLength: 1
  18075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18076. type: string
  18077. namespace:
  18078. description: |-
  18079. The namespace of the Secret resource being referred to.
  18080. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18081. maxLength: 63
  18082. minLength: 1
  18083. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18084. type: string
  18085. type: object
  18086. type: object
  18087. workloadIdentity:
  18088. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  18089. properties:
  18090. clusterLocation:
  18091. description: |-
  18092. ClusterLocation is the location of the cluster
  18093. If not specified, it fetches information from the metadata server
  18094. type: string
  18095. clusterName:
  18096. description: |-
  18097. ClusterName is the name of the cluster
  18098. If not specified, it fetches information from the metadata server
  18099. type: string
  18100. clusterProjectID:
  18101. description: |-
  18102. ClusterProjectID is the project ID of the cluster
  18103. If not specified, it fetches information from the metadata server
  18104. type: string
  18105. serviceAccountRef:
  18106. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  18107. properties:
  18108. audiences:
  18109. description: |-
  18110. Audience specifies the `aud` claim for the service account token
  18111. Some providers automatically extend the audience field based on well-known annotations for workload
  18112. identity (e.g. IRSA or GCP Workload Identity)
  18113. items:
  18114. type: string
  18115. type: array
  18116. name:
  18117. description: The name of the ServiceAccount resource being referred to.
  18118. maxLength: 253
  18119. minLength: 1
  18120. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18121. type: string
  18122. namespace:
  18123. description: |-
  18124. Namespace of the resource being referred to.
  18125. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18126. maxLength: 63
  18127. minLength: 1
  18128. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18129. type: string
  18130. required:
  18131. - name
  18132. type: object
  18133. required:
  18134. - serviceAccountRef
  18135. type: object
  18136. workloadIdentityFederation:
  18137. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  18138. properties:
  18139. audience:
  18140. description: |-
  18141. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  18142. If specified, Audience found in the external account credential config will be overridden with the configured value.
  18143. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  18144. type: string
  18145. awsSecurityCredentials:
  18146. description: |-
  18147. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  18148. when using the AWS metadata server is not an option.
  18149. properties:
  18150. awsCredentialsSecretRef:
  18151. description: |-
  18152. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  18153. Secret should be created with below names for keys
  18154. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  18155. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  18156. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  18157. properties:
  18158. name:
  18159. description: name of the secret.
  18160. maxLength: 253
  18161. minLength: 1
  18162. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18163. type: string
  18164. namespace:
  18165. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  18166. maxLength: 63
  18167. minLength: 1
  18168. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18169. type: string
  18170. required:
  18171. - name
  18172. type: object
  18173. region:
  18174. description: region is for configuring the AWS region to be used.
  18175. example: ap-south-1
  18176. maxLength: 50
  18177. minLength: 1
  18178. pattern: ^[a-z0-9-]+$
  18179. type: string
  18180. required:
  18181. - awsCredentialsSecretRef
  18182. - region
  18183. type: object
  18184. credConfig:
  18185. description: |-
  18186. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  18187. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  18188. serviceAccountRef must be used by providing operators service account details.
  18189. properties:
  18190. key:
  18191. description: key name holding the external account credential config.
  18192. maxLength: 253
  18193. minLength: 1
  18194. pattern: ^[-._a-zA-Z0-9]+$
  18195. type: string
  18196. name:
  18197. description: name of the configmap.
  18198. maxLength: 253
  18199. minLength: 1
  18200. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18201. type: string
  18202. namespace:
  18203. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  18204. maxLength: 63
  18205. minLength: 1
  18206. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18207. type: string
  18208. required:
  18209. - key
  18210. - name
  18211. type: object
  18212. externalTokenEndpoint:
  18213. description: |-
  18214. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  18215. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  18216. URL is having the expected value.
  18217. type: string
  18218. gcpServiceAccountEmail:
  18219. description: |-
  18220. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  18221. after Workload Identity Federation. Use this to grant access through the service account's
  18222. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  18223. service_account_impersonation_url in the external account JSON from credConfig;
  18224. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  18225. on that ServiceAccount.
  18226. example: my-gsa@my-project.iam.gserviceaccount.com
  18227. minLength: 1
  18228. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  18229. type: string
  18230. serviceAccountRef:
  18231. description: |-
  18232. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  18233. when Kubernetes is configured as provider in workload identity pool.
  18234. properties:
  18235. audiences:
  18236. description: |-
  18237. Audience specifies the `aud` claim for the service account token
  18238. Some providers automatically extend the audience field based on well-known annotations for workload
  18239. identity (e.g. IRSA or GCP Workload Identity)
  18240. items:
  18241. type: string
  18242. type: array
  18243. name:
  18244. description: The name of the ServiceAccount resource being referred to.
  18245. maxLength: 253
  18246. minLength: 1
  18247. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18248. type: string
  18249. namespace:
  18250. description: |-
  18251. Namespace of the resource being referred to.
  18252. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18253. maxLength: 63
  18254. minLength: 1
  18255. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18256. type: string
  18257. required:
  18258. - name
  18259. type: object
  18260. type: object
  18261. type: object
  18262. location:
  18263. description: Location optionally defines a location for a secret
  18264. type: string
  18265. projectID:
  18266. description: ProjectID project where secret is located
  18267. type: string
  18268. secretVersionSelectionPolicy:
  18269. default: LatestOrFail
  18270. description: |-
  18271. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  18272. when "latest" is disabled or destroyed.
  18273. Possible values are:
  18274. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  18275. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  18276. type: string
  18277. type: object
  18278. github:
  18279. description: |-
  18280. Github configures this store to push GitHub Actions or Dependabot secrets using the GitHub API provider.
  18281. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  18282. properties:
  18283. appID:
  18284. description: appID specifies the Github APP that will be used to authenticate the client
  18285. format: int64
  18286. type: integer
  18287. auth:
  18288. description: auth configures how secret-manager authenticates with a Github instance.
  18289. properties:
  18290. privateKey:
  18291. description: |-
  18292. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18293. In some instances, `key` is a required field.
  18294. properties:
  18295. key:
  18296. description: |-
  18297. A key in the referenced Secret.
  18298. Some instances of this field may be defaulted, in others it may be required.
  18299. maxLength: 253
  18300. minLength: 1
  18301. pattern: ^[-._a-zA-Z0-9]+$
  18302. type: string
  18303. name:
  18304. description: The name of the Secret resource being referred to.
  18305. maxLength: 253
  18306. minLength: 1
  18307. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18308. type: string
  18309. namespace:
  18310. description: |-
  18311. The namespace of the Secret resource being referred to.
  18312. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18313. maxLength: 63
  18314. minLength: 1
  18315. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18316. type: string
  18317. type: object
  18318. required:
  18319. - privateKey
  18320. type: object
  18321. environment:
  18322. description: environment will be used to fetch secrets from a particular environment within a github repository
  18323. type: string
  18324. installationID:
  18325. description: installationID specifies the Github APP installation that will be used to authenticate the client
  18326. format: int64
  18327. type: integer
  18328. orgSecretVisibility:
  18329. description: |-
  18330. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  18331. Valid values are "all" or "private".
  18332. When unset, new secrets are created with visibility "all" and existing secrets preserve
  18333. whatever visibility they already have in GitHub.
  18334. enum:
  18335. - all
  18336. - private
  18337. type: string
  18338. organization:
  18339. description: organization will be used to fetch secrets from the Github organization
  18340. type: string
  18341. repository:
  18342. description: repository will be used to fetch secrets from the Github repository within an organization
  18343. type: string
  18344. secretType:
  18345. default: Actions
  18346. description: |-
  18347. secretType specifies which GitHub secret service to use.
  18348. Defaults to Actions for backwards compatibility.
  18349. enum:
  18350. - Actions
  18351. - Dependabot
  18352. type: string
  18353. uploadURL:
  18354. description: Upload URL for enterprise instances. Default to URL.
  18355. type: string
  18356. url:
  18357. default: https://github.com/
  18358. description: URL configures the Github instance URL. Defaults to https://github.com/.
  18359. type: string
  18360. required:
  18361. - appID
  18362. - auth
  18363. - installationID
  18364. - organization
  18365. type: object
  18366. x-kubernetes-validations:
  18367. - message: Dependabot secrets do not support environments
  18368. rule: self.secretType != 'Dependabot' || !has(self.environment) || size(self.environment) == 0
  18369. gitlab:
  18370. description: GitLab configures this store to sync secrets using GitLab Variables provider
  18371. properties:
  18372. auth:
  18373. description: Auth configures how secret-manager authenticates with a GitLab instance.
  18374. properties:
  18375. SecretRef:
  18376. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  18377. properties:
  18378. accessToken:
  18379. description: AccessToken is used for authentication.
  18380. properties:
  18381. key:
  18382. description: |-
  18383. A key in the referenced Secret.
  18384. Some instances of this field may be defaulted, in others it may be required.
  18385. maxLength: 253
  18386. minLength: 1
  18387. pattern: ^[-._a-zA-Z0-9]+$
  18388. type: string
  18389. name:
  18390. description: The name of the Secret resource being referred to.
  18391. maxLength: 253
  18392. minLength: 1
  18393. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18394. type: string
  18395. namespace:
  18396. description: |-
  18397. The namespace of the Secret resource being referred to.
  18398. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18399. maxLength: 63
  18400. minLength: 1
  18401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18402. type: string
  18403. type: object
  18404. type: object
  18405. required:
  18406. - SecretRef
  18407. type: object
  18408. caBundle:
  18409. description: |-
  18410. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  18411. can be performed.
  18412. format: byte
  18413. type: string
  18414. caProvider:
  18415. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  18416. properties:
  18417. key:
  18418. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  18419. maxLength: 253
  18420. minLength: 1
  18421. pattern: ^[-._a-zA-Z0-9]+$
  18422. type: string
  18423. name:
  18424. description: The name of the object located at the provider type.
  18425. maxLength: 253
  18426. minLength: 1
  18427. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18428. type: string
  18429. namespace:
  18430. description: |-
  18431. The namespace the Provider type is in.
  18432. Can only be defined when used in a ClusterSecretStore.
  18433. maxLength: 63
  18434. minLength: 1
  18435. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18436. type: string
  18437. type:
  18438. description: The type of provider to use such as "Secret", or "ConfigMap".
  18439. enum:
  18440. - Secret
  18441. - ConfigMap
  18442. type: string
  18443. required:
  18444. - name
  18445. - type
  18446. type: object
  18447. environment:
  18448. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  18449. type: string
  18450. groupIDs:
  18451. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  18452. items:
  18453. type: string
  18454. type: array
  18455. inheritFromGroups:
  18456. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  18457. type: boolean
  18458. projectID:
  18459. description: ProjectID specifies a project where secrets are located.
  18460. type: string
  18461. url:
  18462. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  18463. type: string
  18464. required:
  18465. - auth
  18466. type: object
  18467. ibm:
  18468. description: IBM configures this store to sync secrets using IBM Cloud provider
  18469. properties:
  18470. auth:
  18471. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  18472. maxProperties: 1
  18473. minProperties: 1
  18474. properties:
  18475. containerAuth:
  18476. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  18477. properties:
  18478. iamEndpoint:
  18479. type: string
  18480. profile:
  18481. description: the IBM Trusted Profile
  18482. type: string
  18483. tokenLocation:
  18484. description: Location the token is mounted on the pod
  18485. type: string
  18486. required:
  18487. - profile
  18488. type: object
  18489. secretRef:
  18490. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  18491. properties:
  18492. iamEndpoint:
  18493. description: The IAM endpoint used to obain a token
  18494. type: string
  18495. secretApiKeySecretRef:
  18496. description: The SecretAccessKey is used for authentication
  18497. properties:
  18498. key:
  18499. description: |-
  18500. A key in the referenced Secret.
  18501. Some instances of this field may be defaulted, in others it may be required.
  18502. maxLength: 253
  18503. minLength: 1
  18504. pattern: ^[-._a-zA-Z0-9]+$
  18505. type: string
  18506. name:
  18507. description: The name of the Secret resource being referred to.
  18508. maxLength: 253
  18509. minLength: 1
  18510. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18511. type: string
  18512. namespace:
  18513. description: |-
  18514. The namespace of the Secret resource being referred to.
  18515. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18516. maxLength: 63
  18517. minLength: 1
  18518. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18519. type: string
  18520. type: object
  18521. type: object
  18522. type: object
  18523. serviceUrl:
  18524. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  18525. type: string
  18526. required:
  18527. - auth
  18528. type: object
  18529. infisical:
  18530. description: Infisical configures this store to sync secrets using the Infisical provider
  18531. properties:
  18532. auth:
  18533. description: Auth configures how the Operator authenticates with the Infisical API
  18534. properties:
  18535. awsAuthCredentials:
  18536. description: AwsAuthCredentials represents the credentials for AWS authentication.
  18537. properties:
  18538. identityId:
  18539. description: |-
  18540. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18541. In some instances, `key` is a required field.
  18542. properties:
  18543. key:
  18544. description: |-
  18545. A key in the referenced Secret.
  18546. Some instances of this field may be defaulted, in others it may be required.
  18547. maxLength: 253
  18548. minLength: 1
  18549. pattern: ^[-._a-zA-Z0-9]+$
  18550. type: string
  18551. name:
  18552. description: The name of the Secret resource being referred to.
  18553. maxLength: 253
  18554. minLength: 1
  18555. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18556. type: string
  18557. namespace:
  18558. description: |-
  18559. The namespace of the Secret resource being referred to.
  18560. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18561. maxLength: 63
  18562. minLength: 1
  18563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18564. type: string
  18565. type: object
  18566. required:
  18567. - identityId
  18568. type: object
  18569. azureAuthCredentials:
  18570. description: AzureAuthCredentials represents the credentials for Azure authentication.
  18571. properties:
  18572. identityId:
  18573. description: |-
  18574. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18575. In some instances, `key` is a required field.
  18576. properties:
  18577. key:
  18578. description: |-
  18579. A key in the referenced Secret.
  18580. Some instances of this field may be defaulted, in others it may be required.
  18581. maxLength: 253
  18582. minLength: 1
  18583. pattern: ^[-._a-zA-Z0-9]+$
  18584. type: string
  18585. name:
  18586. description: The name of the Secret resource being referred to.
  18587. maxLength: 253
  18588. minLength: 1
  18589. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18590. type: string
  18591. namespace:
  18592. description: |-
  18593. The namespace of the Secret resource being referred to.
  18594. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18595. maxLength: 63
  18596. minLength: 1
  18597. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18598. type: string
  18599. type: object
  18600. resource:
  18601. description: |-
  18602. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18603. In some instances, `key` is a required field.
  18604. properties:
  18605. key:
  18606. description: |-
  18607. A key in the referenced Secret.
  18608. Some instances of this field may be defaulted, in others it may be required.
  18609. maxLength: 253
  18610. minLength: 1
  18611. pattern: ^[-._a-zA-Z0-9]+$
  18612. type: string
  18613. name:
  18614. description: The name of the Secret resource being referred to.
  18615. maxLength: 253
  18616. minLength: 1
  18617. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18618. type: string
  18619. namespace:
  18620. description: |-
  18621. The namespace of the Secret resource being referred to.
  18622. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18623. maxLength: 63
  18624. minLength: 1
  18625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18626. type: string
  18627. type: object
  18628. required:
  18629. - identityId
  18630. type: object
  18631. gcpIamAuthCredentials:
  18632. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  18633. properties:
  18634. identityId:
  18635. description: |-
  18636. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18637. In some instances, `key` is a required field.
  18638. properties:
  18639. key:
  18640. description: |-
  18641. A key in the referenced Secret.
  18642. Some instances of this field may be defaulted, in others it may be required.
  18643. maxLength: 253
  18644. minLength: 1
  18645. pattern: ^[-._a-zA-Z0-9]+$
  18646. type: string
  18647. name:
  18648. description: The name of the Secret resource being referred to.
  18649. maxLength: 253
  18650. minLength: 1
  18651. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18652. type: string
  18653. namespace:
  18654. description: |-
  18655. The namespace of the Secret resource being referred to.
  18656. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18657. maxLength: 63
  18658. minLength: 1
  18659. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18660. type: string
  18661. type: object
  18662. serviceAccountKeyFilePath:
  18663. description: |-
  18664. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18665. In some instances, `key` is a required field.
  18666. properties:
  18667. key:
  18668. description: |-
  18669. A key in the referenced Secret.
  18670. Some instances of this field may be defaulted, in others it may be required.
  18671. maxLength: 253
  18672. minLength: 1
  18673. pattern: ^[-._a-zA-Z0-9]+$
  18674. type: string
  18675. name:
  18676. description: The name of the Secret resource being referred to.
  18677. maxLength: 253
  18678. minLength: 1
  18679. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18680. type: string
  18681. namespace:
  18682. description: |-
  18683. The namespace of the Secret resource being referred to.
  18684. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18685. maxLength: 63
  18686. minLength: 1
  18687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18688. type: string
  18689. type: object
  18690. required:
  18691. - identityId
  18692. - serviceAccountKeyFilePath
  18693. type: object
  18694. gcpIdTokenAuthCredentials:
  18695. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  18696. properties:
  18697. identityId:
  18698. description: |-
  18699. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18700. In some instances, `key` is a required field.
  18701. properties:
  18702. key:
  18703. description: |-
  18704. A key in the referenced Secret.
  18705. Some instances of this field may be defaulted, in others it may be required.
  18706. maxLength: 253
  18707. minLength: 1
  18708. pattern: ^[-._a-zA-Z0-9]+$
  18709. type: string
  18710. name:
  18711. description: The name of the Secret resource being referred to.
  18712. maxLength: 253
  18713. minLength: 1
  18714. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18715. type: string
  18716. namespace:
  18717. description: |-
  18718. The namespace of the Secret resource being referred to.
  18719. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18720. maxLength: 63
  18721. minLength: 1
  18722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18723. type: string
  18724. type: object
  18725. required:
  18726. - identityId
  18727. type: object
  18728. jwtAuthCredentials:
  18729. description: JwtAuthCredentials represents the credentials for JWT authentication.
  18730. properties:
  18731. identityId:
  18732. description: |-
  18733. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18734. In some instances, `key` is a required field.
  18735. properties:
  18736. key:
  18737. description: |-
  18738. A key in the referenced Secret.
  18739. Some instances of this field may be defaulted, in others it may be required.
  18740. maxLength: 253
  18741. minLength: 1
  18742. pattern: ^[-._a-zA-Z0-9]+$
  18743. type: string
  18744. name:
  18745. description: The name of the Secret resource being referred to.
  18746. maxLength: 253
  18747. minLength: 1
  18748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18749. type: string
  18750. namespace:
  18751. description: |-
  18752. The namespace of the Secret resource being referred to.
  18753. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18754. maxLength: 63
  18755. minLength: 1
  18756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18757. type: string
  18758. type: object
  18759. jwt:
  18760. description: |-
  18761. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18762. In some instances, `key` is a required field.
  18763. properties:
  18764. key:
  18765. description: |-
  18766. A key in the referenced Secret.
  18767. Some instances of this field may be defaulted, in others it may be required.
  18768. maxLength: 253
  18769. minLength: 1
  18770. pattern: ^[-._a-zA-Z0-9]+$
  18771. type: string
  18772. name:
  18773. description: The name of the Secret resource being referred to.
  18774. maxLength: 253
  18775. minLength: 1
  18776. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18777. type: string
  18778. namespace:
  18779. description: |-
  18780. The namespace of the Secret resource being referred to.
  18781. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18782. maxLength: 63
  18783. minLength: 1
  18784. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18785. type: string
  18786. type: object
  18787. required:
  18788. - identityId
  18789. - jwt
  18790. type: object
  18791. kubernetesAuthCredentials:
  18792. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  18793. properties:
  18794. identityId:
  18795. description: |-
  18796. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18797. In some instances, `key` is a required field.
  18798. properties:
  18799. key:
  18800. description: |-
  18801. A key in the referenced Secret.
  18802. Some instances of this field may be defaulted, in others it may be required.
  18803. maxLength: 253
  18804. minLength: 1
  18805. pattern: ^[-._a-zA-Z0-9]+$
  18806. type: string
  18807. name:
  18808. description: The name of the Secret resource being referred to.
  18809. maxLength: 253
  18810. minLength: 1
  18811. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18812. type: string
  18813. namespace:
  18814. description: |-
  18815. The namespace of the Secret resource being referred to.
  18816. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18817. maxLength: 63
  18818. minLength: 1
  18819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18820. type: string
  18821. type: object
  18822. serviceAccountTokenPath:
  18823. description: |-
  18824. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18825. In some instances, `key` is a required field.
  18826. properties:
  18827. key:
  18828. description: |-
  18829. A key in the referenced Secret.
  18830. Some instances of this field may be defaulted, in others it may be required.
  18831. maxLength: 253
  18832. minLength: 1
  18833. pattern: ^[-._a-zA-Z0-9]+$
  18834. type: string
  18835. name:
  18836. description: The name of the Secret resource being referred to.
  18837. maxLength: 253
  18838. minLength: 1
  18839. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18840. type: string
  18841. namespace:
  18842. description: |-
  18843. The namespace of the Secret resource being referred to.
  18844. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18845. maxLength: 63
  18846. minLength: 1
  18847. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18848. type: string
  18849. type: object
  18850. required:
  18851. - identityId
  18852. type: object
  18853. ldapAuthCredentials:
  18854. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  18855. properties:
  18856. identityId:
  18857. description: |-
  18858. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18859. In some instances, `key` is a required field.
  18860. properties:
  18861. key:
  18862. description: |-
  18863. A key in the referenced Secret.
  18864. Some instances of this field may be defaulted, in others it may be required.
  18865. maxLength: 253
  18866. minLength: 1
  18867. pattern: ^[-._a-zA-Z0-9]+$
  18868. type: string
  18869. name:
  18870. description: The name of the Secret resource being referred to.
  18871. maxLength: 253
  18872. minLength: 1
  18873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18874. type: string
  18875. namespace:
  18876. description: |-
  18877. The namespace of the Secret resource being referred to.
  18878. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18879. maxLength: 63
  18880. minLength: 1
  18881. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18882. type: string
  18883. type: object
  18884. ldapPassword:
  18885. description: |-
  18886. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18887. In some instances, `key` is a required field.
  18888. properties:
  18889. key:
  18890. description: |-
  18891. A key in the referenced Secret.
  18892. Some instances of this field may be defaulted, in others it may be required.
  18893. maxLength: 253
  18894. minLength: 1
  18895. pattern: ^[-._a-zA-Z0-9]+$
  18896. type: string
  18897. name:
  18898. description: The name of the Secret resource being referred to.
  18899. maxLength: 253
  18900. minLength: 1
  18901. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18902. type: string
  18903. namespace:
  18904. description: |-
  18905. The namespace of the Secret resource being referred to.
  18906. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18907. maxLength: 63
  18908. minLength: 1
  18909. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18910. type: string
  18911. type: object
  18912. ldapUsername:
  18913. description: |-
  18914. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18915. In some instances, `key` is a required field.
  18916. properties:
  18917. key:
  18918. description: |-
  18919. A key in the referenced Secret.
  18920. Some instances of this field may be defaulted, in others it may be required.
  18921. maxLength: 253
  18922. minLength: 1
  18923. pattern: ^[-._a-zA-Z0-9]+$
  18924. type: string
  18925. name:
  18926. description: The name of the Secret resource being referred to.
  18927. maxLength: 253
  18928. minLength: 1
  18929. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18930. type: string
  18931. namespace:
  18932. description: |-
  18933. The namespace of the Secret resource being referred to.
  18934. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18935. maxLength: 63
  18936. minLength: 1
  18937. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18938. type: string
  18939. type: object
  18940. required:
  18941. - identityId
  18942. - ldapPassword
  18943. - ldapUsername
  18944. type: object
  18945. ociAuthCredentials:
  18946. description: OciAuthCredentials represents the credentials for OCI authentication.
  18947. properties:
  18948. fingerprint:
  18949. description: |-
  18950. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18951. In some instances, `key` is a required field.
  18952. properties:
  18953. key:
  18954. description: |-
  18955. A key in the referenced Secret.
  18956. Some instances of this field may be defaulted, in others it may be required.
  18957. maxLength: 253
  18958. minLength: 1
  18959. pattern: ^[-._a-zA-Z0-9]+$
  18960. type: string
  18961. name:
  18962. description: The name of the Secret resource being referred to.
  18963. maxLength: 253
  18964. minLength: 1
  18965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18966. type: string
  18967. namespace:
  18968. description: |-
  18969. The namespace of the Secret resource being referred to.
  18970. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18971. maxLength: 63
  18972. minLength: 1
  18973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18974. type: string
  18975. type: object
  18976. identityId:
  18977. description: |-
  18978. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18979. In some instances, `key` is a required field.
  18980. properties:
  18981. key:
  18982. description: |-
  18983. A key in the referenced Secret.
  18984. Some instances of this field may be defaulted, in others it may be required.
  18985. maxLength: 253
  18986. minLength: 1
  18987. pattern: ^[-._a-zA-Z0-9]+$
  18988. type: string
  18989. name:
  18990. description: The name of the Secret resource being referred to.
  18991. maxLength: 253
  18992. minLength: 1
  18993. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18994. type: string
  18995. namespace:
  18996. description: |-
  18997. The namespace of the Secret resource being referred to.
  18998. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18999. maxLength: 63
  19000. minLength: 1
  19001. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19002. type: string
  19003. type: object
  19004. privateKey:
  19005. description: |-
  19006. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19007. In some instances, `key` is a required field.
  19008. properties:
  19009. key:
  19010. description: |-
  19011. A key in the referenced Secret.
  19012. Some instances of this field may be defaulted, in others it may be required.
  19013. maxLength: 253
  19014. minLength: 1
  19015. pattern: ^[-._a-zA-Z0-9]+$
  19016. type: string
  19017. name:
  19018. description: The name of the Secret resource being referred to.
  19019. maxLength: 253
  19020. minLength: 1
  19021. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19022. type: string
  19023. namespace:
  19024. description: |-
  19025. The namespace of the Secret resource being referred to.
  19026. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19027. maxLength: 63
  19028. minLength: 1
  19029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19030. type: string
  19031. type: object
  19032. privateKeyPassphrase:
  19033. description: |-
  19034. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19035. In some instances, `key` is a required field.
  19036. properties:
  19037. key:
  19038. description: |-
  19039. A key in the referenced Secret.
  19040. Some instances of this field may be defaulted, in others it may be required.
  19041. maxLength: 253
  19042. minLength: 1
  19043. pattern: ^[-._a-zA-Z0-9]+$
  19044. type: string
  19045. name:
  19046. description: The name of the Secret resource being referred to.
  19047. maxLength: 253
  19048. minLength: 1
  19049. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19050. type: string
  19051. namespace:
  19052. description: |-
  19053. The namespace of the Secret resource being referred to.
  19054. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19055. maxLength: 63
  19056. minLength: 1
  19057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19058. type: string
  19059. type: object
  19060. region:
  19061. description: |-
  19062. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19063. In some instances, `key` is a required field.
  19064. properties:
  19065. key:
  19066. description: |-
  19067. A key in the referenced Secret.
  19068. Some instances of this field may be defaulted, in others it may be required.
  19069. maxLength: 253
  19070. minLength: 1
  19071. pattern: ^[-._a-zA-Z0-9]+$
  19072. type: string
  19073. name:
  19074. description: The name of the Secret resource being referred to.
  19075. maxLength: 253
  19076. minLength: 1
  19077. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19078. type: string
  19079. namespace:
  19080. description: |-
  19081. The namespace of the Secret resource being referred to.
  19082. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19083. maxLength: 63
  19084. minLength: 1
  19085. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19086. type: string
  19087. type: object
  19088. tenancyId:
  19089. description: |-
  19090. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19091. In some instances, `key` is a required field.
  19092. properties:
  19093. key:
  19094. description: |-
  19095. A key in the referenced Secret.
  19096. Some instances of this field may be defaulted, in others it may be required.
  19097. maxLength: 253
  19098. minLength: 1
  19099. pattern: ^[-._a-zA-Z0-9]+$
  19100. type: string
  19101. name:
  19102. description: The name of the Secret resource being referred to.
  19103. maxLength: 253
  19104. minLength: 1
  19105. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19106. type: string
  19107. namespace:
  19108. description: |-
  19109. The namespace of the Secret resource being referred to.
  19110. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19111. maxLength: 63
  19112. minLength: 1
  19113. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19114. type: string
  19115. type: object
  19116. userId:
  19117. description: |-
  19118. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19119. In some instances, `key` is a required field.
  19120. properties:
  19121. key:
  19122. description: |-
  19123. A key in the referenced Secret.
  19124. Some instances of this field may be defaulted, in others it may be required.
  19125. maxLength: 253
  19126. minLength: 1
  19127. pattern: ^[-._a-zA-Z0-9]+$
  19128. type: string
  19129. name:
  19130. description: The name of the Secret resource being referred to.
  19131. maxLength: 253
  19132. minLength: 1
  19133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19134. type: string
  19135. namespace:
  19136. description: |-
  19137. The namespace of the Secret resource being referred to.
  19138. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19139. maxLength: 63
  19140. minLength: 1
  19141. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19142. type: string
  19143. type: object
  19144. required:
  19145. - fingerprint
  19146. - identityId
  19147. - privateKey
  19148. - region
  19149. - tenancyId
  19150. - userId
  19151. type: object
  19152. tokenAuthCredentials:
  19153. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  19154. properties:
  19155. accessToken:
  19156. description: |-
  19157. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19158. In some instances, `key` is a required field.
  19159. properties:
  19160. key:
  19161. description: |-
  19162. A key in the referenced Secret.
  19163. Some instances of this field may be defaulted, in others it may be required.
  19164. maxLength: 253
  19165. minLength: 1
  19166. pattern: ^[-._a-zA-Z0-9]+$
  19167. type: string
  19168. name:
  19169. description: The name of the Secret resource being referred to.
  19170. maxLength: 253
  19171. minLength: 1
  19172. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19173. type: string
  19174. namespace:
  19175. description: |-
  19176. The namespace of the Secret resource being referred to.
  19177. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19178. maxLength: 63
  19179. minLength: 1
  19180. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19181. type: string
  19182. type: object
  19183. required:
  19184. - accessToken
  19185. type: object
  19186. universalAuthCredentials:
  19187. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  19188. properties:
  19189. clientId:
  19190. description: |-
  19191. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19192. In some instances, `key` is a required field.
  19193. properties:
  19194. key:
  19195. description: |-
  19196. A key in the referenced Secret.
  19197. Some instances of this field may be defaulted, in others it may be required.
  19198. maxLength: 253
  19199. minLength: 1
  19200. pattern: ^[-._a-zA-Z0-9]+$
  19201. type: string
  19202. name:
  19203. description: The name of the Secret resource being referred to.
  19204. maxLength: 253
  19205. minLength: 1
  19206. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19207. type: string
  19208. namespace:
  19209. description: |-
  19210. The namespace of the Secret resource being referred to.
  19211. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19212. maxLength: 63
  19213. minLength: 1
  19214. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19215. type: string
  19216. type: object
  19217. clientSecret:
  19218. description: |-
  19219. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19220. In some instances, `key` is a required field.
  19221. properties:
  19222. key:
  19223. description: |-
  19224. A key in the referenced Secret.
  19225. Some instances of this field may be defaulted, in others it may be required.
  19226. maxLength: 253
  19227. minLength: 1
  19228. pattern: ^[-._a-zA-Z0-9]+$
  19229. type: string
  19230. name:
  19231. description: The name of the Secret resource being referred to.
  19232. maxLength: 253
  19233. minLength: 1
  19234. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19235. type: string
  19236. namespace:
  19237. description: |-
  19238. The namespace of the Secret resource being referred to.
  19239. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19240. maxLength: 63
  19241. minLength: 1
  19242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19243. type: string
  19244. type: object
  19245. required:
  19246. - clientId
  19247. - clientSecret
  19248. type: object
  19249. type: object
  19250. caBundle:
  19251. description: |-
  19252. CABundle is a PEM-encoded CA certificate bundle used to validate
  19253. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  19254. format: byte
  19255. type: string
  19256. caProvider:
  19257. description: |-
  19258. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  19259. The certificate is used to validate the Infisical server's TLS certificate.
  19260. Mutually exclusive with CABundle.
  19261. properties:
  19262. key:
  19263. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19264. maxLength: 253
  19265. minLength: 1
  19266. pattern: ^[-._a-zA-Z0-9]+$
  19267. type: string
  19268. name:
  19269. description: The name of the object located at the provider type.
  19270. maxLength: 253
  19271. minLength: 1
  19272. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19273. type: string
  19274. namespace:
  19275. description: |-
  19276. The namespace the Provider type is in.
  19277. Can only be defined when used in a ClusterSecretStore.
  19278. maxLength: 63
  19279. minLength: 1
  19280. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19281. type: string
  19282. type:
  19283. description: The type of provider to use such as "Secret", or "ConfigMap".
  19284. enum:
  19285. - Secret
  19286. - ConfigMap
  19287. type: string
  19288. required:
  19289. - name
  19290. - type
  19291. type: object
  19292. hostAPI:
  19293. default: https://app.infisical.com/api
  19294. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  19295. type: string
  19296. secretsScope:
  19297. description: SecretsScope defines the scope of the secrets within the workspace
  19298. properties:
  19299. environmentSlug:
  19300. description: EnvironmentSlug is the required slug identifier for the environment.
  19301. type: string
  19302. expandSecretReferences:
  19303. default: true
  19304. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  19305. type: boolean
  19306. organizationSlug:
  19307. description: |-
  19308. OrganizationSlug is the optional slug that identifies the organization that will be used
  19309. during authentication. Useful for sub-organization setups
  19310. type: string
  19311. projectSlug:
  19312. description: ProjectSlug is the required slug identifier for the project.
  19313. type: string
  19314. recursive:
  19315. default: false
  19316. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  19317. type: boolean
  19318. secretsPath:
  19319. default: /
  19320. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  19321. type: string
  19322. required:
  19323. - environmentSlug
  19324. - projectSlug
  19325. type: object
  19326. required:
  19327. - auth
  19328. - secretsScope
  19329. type: object
  19330. keepersecurity:
  19331. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  19332. properties:
  19333. authRef:
  19334. description: |-
  19335. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19336. In some instances, `key` is a required field.
  19337. properties:
  19338. key:
  19339. description: |-
  19340. A key in the referenced Secret.
  19341. Some instances of this field may be defaulted, in others it may be required.
  19342. maxLength: 253
  19343. minLength: 1
  19344. pattern: ^[-._a-zA-Z0-9]+$
  19345. type: string
  19346. name:
  19347. description: The name of the Secret resource being referred to.
  19348. maxLength: 253
  19349. minLength: 1
  19350. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19351. type: string
  19352. namespace:
  19353. description: |-
  19354. The namespace of the Secret resource being referred to.
  19355. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19356. maxLength: 63
  19357. minLength: 1
  19358. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19359. type: string
  19360. type: object
  19361. folderID:
  19362. type: string
  19363. getByTitleFallback:
  19364. type: boolean
  19365. required:
  19366. - authRef
  19367. - folderID
  19368. type: object
  19369. kubernetes:
  19370. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  19371. properties:
  19372. auth:
  19373. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  19374. maxProperties: 1
  19375. minProperties: 1
  19376. properties:
  19377. cert:
  19378. description: has both clientCert and clientKey as secretKeySelector
  19379. properties:
  19380. clientCert:
  19381. description: |-
  19382. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19383. In some instances, `key` is a required field.
  19384. properties:
  19385. key:
  19386. description: |-
  19387. A key in the referenced Secret.
  19388. Some instances of this field may be defaulted, in others it may be required.
  19389. maxLength: 253
  19390. minLength: 1
  19391. pattern: ^[-._a-zA-Z0-9]+$
  19392. type: string
  19393. name:
  19394. description: The name of the Secret resource being referred to.
  19395. maxLength: 253
  19396. minLength: 1
  19397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19398. type: string
  19399. namespace:
  19400. description: |-
  19401. The namespace of the Secret resource being referred to.
  19402. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19403. maxLength: 63
  19404. minLength: 1
  19405. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19406. type: string
  19407. type: object
  19408. clientKey:
  19409. description: |-
  19410. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19411. In some instances, `key` is a required field.
  19412. properties:
  19413. key:
  19414. description: |-
  19415. A key in the referenced Secret.
  19416. Some instances of this field may be defaulted, in others it may be required.
  19417. maxLength: 253
  19418. minLength: 1
  19419. pattern: ^[-._a-zA-Z0-9]+$
  19420. type: string
  19421. name:
  19422. description: The name of the Secret resource being referred to.
  19423. maxLength: 253
  19424. minLength: 1
  19425. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19426. type: string
  19427. namespace:
  19428. description: |-
  19429. The namespace of the Secret resource being referred to.
  19430. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19431. maxLength: 63
  19432. minLength: 1
  19433. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19434. type: string
  19435. type: object
  19436. required:
  19437. - clientCert
  19438. - clientKey
  19439. type: object
  19440. serviceAccount:
  19441. description: points to a service account that should be used for authentication
  19442. properties:
  19443. audiences:
  19444. description: |-
  19445. Audience specifies the `aud` claim for the service account token
  19446. Some providers automatically extend the audience field based on well-known annotations for workload
  19447. identity (e.g. IRSA or GCP Workload Identity)
  19448. items:
  19449. type: string
  19450. type: array
  19451. name:
  19452. description: The name of the ServiceAccount resource being referred to.
  19453. maxLength: 253
  19454. minLength: 1
  19455. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19456. type: string
  19457. namespace:
  19458. description: |-
  19459. Namespace of the resource being referred to.
  19460. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19461. maxLength: 63
  19462. minLength: 1
  19463. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19464. type: string
  19465. required:
  19466. - name
  19467. type: object
  19468. token:
  19469. description: use static token to authenticate with
  19470. properties:
  19471. bearerToken:
  19472. description: |-
  19473. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19474. In some instances, `key` is a required field.
  19475. properties:
  19476. key:
  19477. description: |-
  19478. A key in the referenced Secret.
  19479. Some instances of this field may be defaulted, in others it may be required.
  19480. maxLength: 253
  19481. minLength: 1
  19482. pattern: ^[-._a-zA-Z0-9]+$
  19483. type: string
  19484. name:
  19485. description: The name of the Secret resource being referred to.
  19486. maxLength: 253
  19487. minLength: 1
  19488. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19489. type: string
  19490. namespace:
  19491. description: |-
  19492. The namespace of the Secret resource being referred to.
  19493. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19494. maxLength: 63
  19495. minLength: 1
  19496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19497. type: string
  19498. type: object
  19499. required:
  19500. - bearerToken
  19501. type: object
  19502. type: object
  19503. authRef:
  19504. description: A reference to a secret that contains the auth information.
  19505. properties:
  19506. key:
  19507. description: |-
  19508. A key in the referenced Secret.
  19509. Some instances of this field may be defaulted, in others it may be required.
  19510. maxLength: 253
  19511. minLength: 1
  19512. pattern: ^[-._a-zA-Z0-9]+$
  19513. type: string
  19514. name:
  19515. description: The name of the Secret resource being referred to.
  19516. maxLength: 253
  19517. minLength: 1
  19518. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19519. type: string
  19520. namespace:
  19521. description: |-
  19522. The namespace of the Secret resource being referred to.
  19523. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19524. maxLength: 63
  19525. minLength: 1
  19526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19527. type: string
  19528. type: object
  19529. remoteNamespace:
  19530. default: default
  19531. description: Remote namespace to fetch the secrets from
  19532. maxLength: 63
  19533. minLength: 1
  19534. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19535. type: string
  19536. server:
  19537. description: configures the Kubernetes server Address.
  19538. properties:
  19539. caBundle:
  19540. description: CABundle is a base64-encoded CA certificate
  19541. format: byte
  19542. type: string
  19543. caProvider:
  19544. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  19545. properties:
  19546. key:
  19547. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19548. maxLength: 253
  19549. minLength: 1
  19550. pattern: ^[-._a-zA-Z0-9]+$
  19551. type: string
  19552. name:
  19553. description: The name of the object located at the provider type.
  19554. maxLength: 253
  19555. minLength: 1
  19556. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19557. type: string
  19558. namespace:
  19559. description: |-
  19560. The namespace the Provider type is in.
  19561. Can only be defined when used in a ClusterSecretStore.
  19562. maxLength: 63
  19563. minLength: 1
  19564. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19565. type: string
  19566. type:
  19567. description: The type of provider to use such as "Secret", or "ConfigMap".
  19568. enum:
  19569. - Secret
  19570. - ConfigMap
  19571. type: string
  19572. required:
  19573. - name
  19574. - type
  19575. type: object
  19576. url:
  19577. default: kubernetes.default
  19578. description: configures the Kubernetes server Address.
  19579. type: string
  19580. type: object
  19581. type: object
  19582. nebiusmysterybox:
  19583. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  19584. properties:
  19585. apiDomain:
  19586. description: NebiusMysterybox API endpoint
  19587. type: string
  19588. auth:
  19589. description: Auth defines parameters to authenticate in MysteryBox
  19590. properties:
  19591. serviceAccountCredsSecretRef:
  19592. description: |-
  19593. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  19594. document with service account credentials used to get an IAM token.
  19595. Expected JSON structure:
  19596. {
  19597. "subject-credentials": {
  19598. "alg": "RS256",
  19599. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  19600. "kid": "<public-key-id>",
  19601. "iss": "<issuer-service-account-id>",
  19602. "sub": "<subject-service-account-id>"
  19603. }
  19604. }
  19605. properties:
  19606. key:
  19607. description: |-
  19608. A key in the referenced Secret.
  19609. Some instances of this field may be defaulted, in others it may be required.
  19610. maxLength: 253
  19611. minLength: 1
  19612. pattern: ^[-._a-zA-Z0-9]+$
  19613. type: string
  19614. name:
  19615. description: The name of the Secret resource being referred to.
  19616. maxLength: 253
  19617. minLength: 1
  19618. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19619. type: string
  19620. namespace:
  19621. description: |-
  19622. The namespace of the Secret resource being referred to.
  19623. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19624. maxLength: 63
  19625. minLength: 1
  19626. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19627. type: string
  19628. type: object
  19629. tokenSecretRef:
  19630. description: Token authenticates with Nebius Mysterybox by presenting a token.
  19631. properties:
  19632. key:
  19633. description: |-
  19634. A key in the referenced Secret.
  19635. Some instances of this field may be defaulted, in others it may be required.
  19636. maxLength: 253
  19637. minLength: 1
  19638. pattern: ^[-._a-zA-Z0-9]+$
  19639. type: string
  19640. name:
  19641. description: The name of the Secret resource being referred to.
  19642. maxLength: 253
  19643. minLength: 1
  19644. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19645. type: string
  19646. namespace:
  19647. description: |-
  19648. The namespace of the Secret resource being referred to.
  19649. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19650. maxLength: 63
  19651. minLength: 1
  19652. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19653. type: string
  19654. type: object
  19655. workloadIdentity:
  19656. description: WorkloadIdentity defines configuration for workload identity authentication to Nebius IAM.
  19657. properties:
  19658. iamServiceAccountID:
  19659. description: |-
  19660. IAMServiceAccountID is the Nebius IAM service account identifier that the
  19661. federated Kubernetes service account should impersonate during token exchange.
  19662. example: serviceaccount-e00example
  19663. minLength: 1
  19664. pattern: ^serviceaccount-[a-z][a-z0-9]{2}
  19665. type: string
  19666. serviceAccountRef:
  19667. description: |-
  19668. ServiceAccountRef references a Kubernetes ServiceAccount used to request a
  19669. temporary JWT via the TokenRequest API. The JWT is then exchanged for a
  19670. Nebius IAM token using workload federation.
  19671. properties:
  19672. audiences:
  19673. description: |-
  19674. Audience specifies the `aud` claim for the service account token
  19675. Some providers automatically extend the audience field based on well-known annotations for workload
  19676. identity (e.g. IRSA or GCP Workload Identity)
  19677. items:
  19678. type: string
  19679. type: array
  19680. name:
  19681. description: The name of the ServiceAccount resource being referred to.
  19682. maxLength: 253
  19683. minLength: 1
  19684. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19685. type: string
  19686. namespace:
  19687. description: |-
  19688. Namespace of the resource being referred to.
  19689. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19690. maxLength: 63
  19691. minLength: 1
  19692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19693. type: string
  19694. required:
  19695. - name
  19696. type: object
  19697. required:
  19698. - iamServiceAccountID
  19699. - serviceAccountRef
  19700. type: object
  19701. type: object
  19702. x-kubernetes-validations:
  19703. - message: exactly one of serviceAccountCredsSecretRef, tokenSecretRef, or workloadIdentity must be set
  19704. rule: '(has(self.serviceAccountCredsSecretRef) && has(self.serviceAccountCredsSecretRef.name) && size(self.serviceAccountCredsSecretRef.name) > 0 ? 1 : 0) + (has(self.tokenSecretRef) && has(self.tokenSecretRef.name) && size(self.tokenSecretRef.name) > 0 ? 1 : 0) + (has(self.workloadIdentity) ? 1 : 0) == 1'
  19705. caProvider:
  19706. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  19707. properties:
  19708. certSecretRef:
  19709. description: |-
  19710. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19711. In some instances, `key` is a required field.
  19712. properties:
  19713. key:
  19714. description: |-
  19715. A key in the referenced Secret.
  19716. Some instances of this field may be defaulted, in others it may be required.
  19717. maxLength: 253
  19718. minLength: 1
  19719. pattern: ^[-._a-zA-Z0-9]+$
  19720. type: string
  19721. name:
  19722. description: The name of the Secret resource being referred to.
  19723. maxLength: 253
  19724. minLength: 1
  19725. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19726. type: string
  19727. namespace:
  19728. description: |-
  19729. The namespace of the Secret resource being referred to.
  19730. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19731. maxLength: 63
  19732. minLength: 1
  19733. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19734. type: string
  19735. type: object
  19736. type: object
  19737. required:
  19738. - apiDomain
  19739. - auth
  19740. type: object
  19741. ngrok:
  19742. description: Ngrok configures this store to sync secrets using the ngrok provider.
  19743. properties:
  19744. apiUrl:
  19745. default: https://api.ngrok.com
  19746. description: APIURL is the URL of the ngrok API.
  19747. type: string
  19748. auth:
  19749. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  19750. maxProperties: 1
  19751. minProperties: 1
  19752. properties:
  19753. apiKey:
  19754. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  19755. properties:
  19756. secretRef:
  19757. description: SecretRef is a reference to a secret containing the ngrok API key.
  19758. properties:
  19759. key:
  19760. description: |-
  19761. A key in the referenced Secret.
  19762. Some instances of this field may be defaulted, in others it may be required.
  19763. maxLength: 253
  19764. minLength: 1
  19765. pattern: ^[-._a-zA-Z0-9]+$
  19766. type: string
  19767. name:
  19768. description: The name of the Secret resource being referred to.
  19769. maxLength: 253
  19770. minLength: 1
  19771. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19772. type: string
  19773. namespace:
  19774. description: |-
  19775. The namespace of the Secret resource being referred to.
  19776. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19777. maxLength: 63
  19778. minLength: 1
  19779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19780. type: string
  19781. type: object
  19782. type: object
  19783. type: object
  19784. vault:
  19785. description: Vault configures the ngrok vault to sync secrets with.
  19786. properties:
  19787. name:
  19788. description: Name is the name of the ngrok vault to sync secrets with.
  19789. type: string
  19790. required:
  19791. - name
  19792. type: object
  19793. required:
  19794. - auth
  19795. - vault
  19796. type: object
  19797. onboardbase:
  19798. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  19799. properties:
  19800. apiHost:
  19801. default: https://public.onboardbase.com/api/v1/
  19802. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  19803. type: string
  19804. auth:
  19805. description: Auth configures how the Operator authenticates with the Onboardbase API
  19806. properties:
  19807. apiKeyRef:
  19808. description: |-
  19809. OnboardbaseAPIKey is the APIKey generated by an admin account.
  19810. It is used to recognize and authorize access to a project and environment within onboardbase
  19811. properties:
  19812. key:
  19813. description: |-
  19814. A key in the referenced Secret.
  19815. Some instances of this field may be defaulted, in others it may be required.
  19816. maxLength: 253
  19817. minLength: 1
  19818. pattern: ^[-._a-zA-Z0-9]+$
  19819. type: string
  19820. name:
  19821. description: The name of the Secret resource being referred to.
  19822. maxLength: 253
  19823. minLength: 1
  19824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19825. type: string
  19826. namespace:
  19827. description: |-
  19828. The namespace of the Secret resource being referred to.
  19829. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19830. maxLength: 63
  19831. minLength: 1
  19832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19833. type: string
  19834. type: object
  19835. passcodeRef:
  19836. description: OnboardbasePasscode is the passcode attached to the API Key
  19837. properties:
  19838. key:
  19839. description: |-
  19840. A key in the referenced Secret.
  19841. Some instances of this field may be defaulted, in others it may be required.
  19842. maxLength: 253
  19843. minLength: 1
  19844. pattern: ^[-._a-zA-Z0-9]+$
  19845. type: string
  19846. name:
  19847. description: The name of the Secret resource being referred to.
  19848. maxLength: 253
  19849. minLength: 1
  19850. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19851. type: string
  19852. namespace:
  19853. description: |-
  19854. The namespace of the Secret resource being referred to.
  19855. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19856. maxLength: 63
  19857. minLength: 1
  19858. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19859. type: string
  19860. type: object
  19861. required:
  19862. - apiKeyRef
  19863. - passcodeRef
  19864. type: object
  19865. environment:
  19866. default: development
  19867. description: Environment is the name of an environmnent within a project to pull the secrets from
  19868. type: string
  19869. project:
  19870. default: development
  19871. description: Project is an onboardbase project that the secrets should be pulled from
  19872. type: string
  19873. required:
  19874. - apiHost
  19875. - auth
  19876. - environment
  19877. - project
  19878. type: object
  19879. onepassword:
  19880. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  19881. properties:
  19882. auth:
  19883. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  19884. properties:
  19885. secretRef:
  19886. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  19887. properties:
  19888. connectTokenSecretRef:
  19889. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  19890. properties:
  19891. key:
  19892. description: |-
  19893. A key in the referenced Secret.
  19894. Some instances of this field may be defaulted, in others it may be required.
  19895. maxLength: 253
  19896. minLength: 1
  19897. pattern: ^[-._a-zA-Z0-9]+$
  19898. type: string
  19899. name:
  19900. description: The name of the Secret resource being referred to.
  19901. maxLength: 253
  19902. minLength: 1
  19903. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19904. type: string
  19905. namespace:
  19906. description: |-
  19907. The namespace of the Secret resource being referred to.
  19908. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19909. maxLength: 63
  19910. minLength: 1
  19911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19912. type: string
  19913. type: object
  19914. required:
  19915. - connectTokenSecretRef
  19916. type: object
  19917. required:
  19918. - secretRef
  19919. type: object
  19920. connectHost:
  19921. description: ConnectHost defines the OnePassword Connect Server to connect to
  19922. type: string
  19923. vaults:
  19924. additionalProperties:
  19925. type: integer
  19926. description: Vaults defines which OnePassword vaults to search in which order
  19927. type: object
  19928. required:
  19929. - auth
  19930. - connectHost
  19931. - vaults
  19932. type: object
  19933. onepasswordSDK:
  19934. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  19935. properties:
  19936. auth:
  19937. description: Auth defines the information necessary to authenticate against OnePassword API.
  19938. properties:
  19939. serviceAccountSecretRef:
  19940. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  19941. properties:
  19942. key:
  19943. description: |-
  19944. A key in the referenced Secret.
  19945. Some instances of this field may be defaulted, in others it may be required.
  19946. maxLength: 253
  19947. minLength: 1
  19948. pattern: ^[-._a-zA-Z0-9]+$
  19949. type: string
  19950. name:
  19951. description: The name of the Secret resource being referred to.
  19952. maxLength: 253
  19953. minLength: 1
  19954. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19955. type: string
  19956. namespace:
  19957. description: |-
  19958. The namespace of the Secret resource being referred to.
  19959. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19960. maxLength: 63
  19961. minLength: 1
  19962. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19963. type: string
  19964. type: object
  19965. required:
  19966. - serviceAccountSecretRef
  19967. type: object
  19968. cache:
  19969. description: |-
  19970. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  19971. When enabled, secrets are cached with the specified TTL.
  19972. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  19973. If omitted, caching is disabled (default).
  19974. cache: {} is a valid option to set.
  19975. properties:
  19976. maxSize:
  19977. default: 100
  19978. description: |-
  19979. MaxSize is the maximum number of secrets to cache.
  19980. When the cache is full, least-recently-used entries are evicted.
  19981. minimum: 1
  19982. type: integer
  19983. ttl:
  19984. default: 5m
  19985. description: |-
  19986. TTL is the time-to-live for cached secrets.
  19987. Format: duration string (e.g., "5m", "1h", "30s")
  19988. type: string
  19989. type: object
  19990. environment:
  19991. description: |-
  19992. Environment defines the 1Password Environment ID to read variables from.
  19993. Environments are read-only: PushSecret, DeleteSecret, and SecretExists return an error when set.
  19994. Mutually exclusive with Vault.
  19995. type: string
  19996. integrationInfo:
  19997. description: |-
  19998. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  19999. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  20000. properties:
  20001. name:
  20002. default: 1Password SDK
  20003. description: Name defaults to "1Password SDK".
  20004. type: string
  20005. version:
  20006. default: v1.0.0
  20007. description: Version defaults to "v1.0.0".
  20008. type: string
  20009. type: object
  20010. vault:
  20011. description: |-
  20012. Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  20013. Mutually exclusive with Environment.
  20014. type: string
  20015. required:
  20016. - auth
  20017. type: object
  20018. x-kubernetes-validations:
  20019. - message: at most one of the fields in [vault environment] may be set
  20020. rule: '[has(self.vault),has(self.environment)].filter(x,x==true).size() <= 1'
  20021. openBao:
  20022. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  20023. properties:
  20024. auth:
  20025. description: Auth configures how secret-manager authenticates with the OpenBao server.
  20026. properties:
  20027. appRole:
  20028. description: |-
  20029. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  20030. with the role and secret stored in a Kubernetes Secret resource.
  20031. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  20032. properties:
  20033. path:
  20034. default: approle
  20035. description: |-
  20036. Path where the App Role authentication backend is mounted
  20037. in OpenBao, e.g: "approle"
  20038. type: string
  20039. roleId:
  20040. description: |-
  20041. RoleID configured in the App Role authentication backend when setting
  20042. up the authentication backend in OpenBao.
  20043. minLength: 1
  20044. type: string
  20045. roleRef:
  20046. description: |-
  20047. Reference to a key in a Secret that contains the App Role ID used
  20048. to authenticate with OpenBao.
  20049. The `key` field must be specified and denotes which entry within the Secret
  20050. resource is used as the app role id.
  20051. properties:
  20052. key:
  20053. description: |-
  20054. A key in the referenced Secret.
  20055. Some instances of this field may be defaulted, in others it may be required.
  20056. maxLength: 253
  20057. minLength: 1
  20058. pattern: ^[-._a-zA-Z0-9]+$
  20059. type: string
  20060. name:
  20061. description: The name of the Secret resource being referred to.
  20062. maxLength: 253
  20063. minLength: 1
  20064. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20065. type: string
  20066. namespace:
  20067. description: |-
  20068. The namespace of the Secret resource being referred to.
  20069. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20070. maxLength: 63
  20071. minLength: 1
  20072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20073. type: string
  20074. type: object
  20075. secretRef:
  20076. description: |-
  20077. Reference to a key in a Secret that contains the App Role secret used
  20078. to authenticate with OpenBao.
  20079. The `key` field must be specified and denotes which entry within the Secret
  20080. resource is used as the app role secret.
  20081. properties:
  20082. key:
  20083. description: |-
  20084. A key in the referenced Secret.
  20085. Some instances of this field may be defaulted, in others it may be required.
  20086. maxLength: 253
  20087. minLength: 1
  20088. pattern: ^[-._a-zA-Z0-9]+$
  20089. type: string
  20090. name:
  20091. description: The name of the Secret resource being referred to.
  20092. maxLength: 253
  20093. minLength: 1
  20094. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20095. type: string
  20096. namespace:
  20097. description: |-
  20098. The namespace of the Secret resource being referred to.
  20099. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20100. maxLength: 63
  20101. minLength: 1
  20102. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20103. type: string
  20104. type: object
  20105. required:
  20106. - path
  20107. - secretRef
  20108. type: object
  20109. x-kubernetes-validations:
  20110. - message: exactly one of the fields in [roleId roleRef] must be set
  20111. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  20112. kubernetes:
  20113. description: |-
  20114. Kubernetes authenticates with OpenBao by passing a ServiceAccount
  20115. token to the [Kubernetes auth mechanism].
  20116. [Kubernetes auth mechanism]: https://openbao.org/docs/auth/kubernetes/
  20117. properties:
  20118. path:
  20119. default: kubernetes
  20120. description: |-
  20121. Path where the Kubernetes authentication backend is mounted in OpenBao, e.g:
  20122. "kubernetes"
  20123. type: string
  20124. role:
  20125. description: |-
  20126. A required field containing the OpenBao Role to assume. A Role binds a
  20127. Kubernetes ServiceAccount with a set of OpenBao policies.
  20128. minLength: 1
  20129. type: string
  20130. secretRef:
  20131. description: |-
  20132. Optional secret field containing a Kubernetes ServiceAccount JWT used
  20133. for authenticating with OpenBao. If a name is specified without a key,
  20134. `token` is the default.
  20135. properties:
  20136. key:
  20137. description: |-
  20138. A key in the referenced Secret.
  20139. Some instances of this field may be defaulted, in others it may be required.
  20140. maxLength: 253
  20141. minLength: 1
  20142. pattern: ^[-._a-zA-Z0-9]+$
  20143. type: string
  20144. name:
  20145. description: The name of the Secret resource being referred to.
  20146. maxLength: 253
  20147. minLength: 1
  20148. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20149. type: string
  20150. namespace:
  20151. description: |-
  20152. The namespace of the Secret resource being referred to.
  20153. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20154. maxLength: 63
  20155. minLength: 1
  20156. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20157. type: string
  20158. type: object
  20159. serviceAccountRef:
  20160. description: |-
  20161. Optional service account field containing the name of a Kubernetes ServiceAccount.
  20162. If the service account is specified, a token will be requested from the Kubernetes
  20163. TokenRequest API for authenticating with OpenBao.
  20164. Any configured audiences will be passed to the TokenRequest as-is.
  20165. properties:
  20166. audiences:
  20167. description: |-
  20168. Audience specifies the `aud` claim for the service account token
  20169. Some providers automatically extend the audience field based on well-known annotations for workload
  20170. identity (e.g. IRSA or GCP Workload Identity)
  20171. items:
  20172. type: string
  20173. type: array
  20174. name:
  20175. description: The name of the ServiceAccount resource being referred to.
  20176. maxLength: 253
  20177. minLength: 1
  20178. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20179. type: string
  20180. namespace:
  20181. description: |-
  20182. Namespace of the resource being referred to.
  20183. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20184. maxLength: 63
  20185. minLength: 1
  20186. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20187. type: string
  20188. required:
  20189. - name
  20190. type: object
  20191. required:
  20192. - path
  20193. - role
  20194. type: object
  20195. x-kubernetes-validations:
  20196. - message: exactly one of the fields in [serviceAccountRef secretRef] must be set
  20197. rule: '[has(self.serviceAccountRef),has(self.secretRef)].filter(x,x==true).size() == 1'
  20198. namespace:
  20199. description: |-
  20200. Name of the [OpenBao Namespace] to authenticate to. This can be different
  20201. than the namespace your secret is in. Namespaces is a set of features
  20202. within OpenBao that allows OpenBao environments to support secure
  20203. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  20204. if set, or empty otherwise
  20205. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  20206. type: string
  20207. tokenSecretRef:
  20208. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  20209. properties:
  20210. key:
  20211. description: |-
  20212. A key in the referenced Secret.
  20213. Some instances of this field may be defaulted, in others it may be required.
  20214. maxLength: 253
  20215. minLength: 1
  20216. pattern: ^[-._a-zA-Z0-9]+$
  20217. type: string
  20218. name:
  20219. description: The name of the Secret resource being referred to.
  20220. maxLength: 253
  20221. minLength: 1
  20222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20223. type: string
  20224. namespace:
  20225. description: |-
  20226. The namespace of the Secret resource being referred to.
  20227. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20228. maxLength: 63
  20229. minLength: 1
  20230. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20231. type: string
  20232. type: object
  20233. userPass:
  20234. description: UserPass authenticates with OpenBao by passing a username/password pair
  20235. properties:
  20236. path:
  20237. default: userpass
  20238. description: |-
  20239. Path where the UserPassword authentication backend is mounted
  20240. in OpenBao, e.g: "userpass"
  20241. type: string
  20242. secretRef:
  20243. description: |-
  20244. SecretRef to a key in a Secret resource containing password for the user
  20245. used to authenticate with OpenBao using the [UserPass authentication
  20246. method]
  20247. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  20248. properties:
  20249. key:
  20250. description: |-
  20251. A key in the referenced Secret.
  20252. Some instances of this field may be defaulted, in others it may be required.
  20253. maxLength: 253
  20254. minLength: 1
  20255. pattern: ^[-._a-zA-Z0-9]+$
  20256. type: string
  20257. name:
  20258. description: The name of the Secret resource being referred to.
  20259. maxLength: 253
  20260. minLength: 1
  20261. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20262. type: string
  20263. namespace:
  20264. description: |-
  20265. The namespace of the Secret resource being referred to.
  20266. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20267. maxLength: 63
  20268. minLength: 1
  20269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20270. type: string
  20271. type: object
  20272. username:
  20273. description: |-
  20274. Username is a username used to authenticate using the [UserPass
  20275. authentication method]
  20276. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  20277. type: string
  20278. required:
  20279. - path
  20280. - username
  20281. type: object
  20282. type: object
  20283. x-kubernetes-validations:
  20284. - message: exactly one of the fields in [appRole tokenSecretRef userPass kubernetes] must be set
  20285. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass),has(self.kubernetes)].filter(x,x==true).size() == 1'
  20286. caBundle:
  20287. description: |-
  20288. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  20289. this and `caProvider` are not set the system root certificates are used
  20290. to validate the TLS connection.
  20291. format: byte
  20292. type: string
  20293. caProvider:
  20294. description: |-
  20295. The provider for the CA bundle to use to validate OpenBao server
  20296. certificate. If this and `caBundle` are not set the system root
  20297. certificates are used to validate the TLS connection.
  20298. properties:
  20299. key:
  20300. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20301. maxLength: 253
  20302. minLength: 1
  20303. pattern: ^[-._a-zA-Z0-9]+$
  20304. type: string
  20305. name:
  20306. description: The name of the object located at the provider type.
  20307. maxLength: 253
  20308. minLength: 1
  20309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20310. type: string
  20311. namespace:
  20312. description: |-
  20313. The namespace the Provider type is in.
  20314. Can only be defined when used in a ClusterSecretStore.
  20315. maxLength: 63
  20316. minLength: 1
  20317. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20318. type: string
  20319. type:
  20320. description: The type of provider to use such as "Secret", or "ConfigMap".
  20321. enum:
  20322. - Secret
  20323. - ConfigMap
  20324. type: string
  20325. required:
  20326. - name
  20327. - type
  20328. type: object
  20329. namespace:
  20330. description: |-
  20331. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  20332. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  20333. e.g: "ns1".
  20334. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  20335. type: string
  20336. path:
  20337. description: |-
  20338. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  20339. "secret". The v2 KV secret engine version specific "/data" path suffix
  20340. for fetching secrets from OpenBao is optional and will be appended
  20341. if not present in specified path.
  20342. type: string
  20343. server:
  20344. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  20345. type: string
  20346. version:
  20347. default: v2
  20348. description: |-
  20349. Version is the OpenBao KV secret engine version. This can be either "v1" or
  20350. "v2". Version defaults to "v2".
  20351. enum:
  20352. - v1
  20353. - v2
  20354. type: string
  20355. required:
  20356. - server
  20357. type: object
  20358. x-kubernetes-validations:
  20359. - message: at most one of the fields in [caBundle caProvider] may be set
  20360. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  20361. oracle:
  20362. description: Oracle configures this store to sync secrets using Oracle Vault provider
  20363. properties:
  20364. auth:
  20365. description: |-
  20366. Auth configures how secret-manager authenticates with the Oracle Vault.
  20367. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  20368. properties:
  20369. secretRef:
  20370. description: SecretRef to pass through sensitive information.
  20371. properties:
  20372. fingerprint:
  20373. description: Fingerprint is the fingerprint of the API private key.
  20374. properties:
  20375. key:
  20376. description: |-
  20377. A key in the referenced Secret.
  20378. Some instances of this field may be defaulted, in others it may be required.
  20379. maxLength: 253
  20380. minLength: 1
  20381. pattern: ^[-._a-zA-Z0-9]+$
  20382. type: string
  20383. name:
  20384. description: The name of the Secret resource being referred to.
  20385. maxLength: 253
  20386. minLength: 1
  20387. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20388. type: string
  20389. namespace:
  20390. description: |-
  20391. The namespace of the Secret resource being referred to.
  20392. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20393. maxLength: 63
  20394. minLength: 1
  20395. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20396. type: string
  20397. type: object
  20398. privatekey:
  20399. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  20400. properties:
  20401. key:
  20402. description: |-
  20403. A key in the referenced Secret.
  20404. Some instances of this field may be defaulted, in others it may be required.
  20405. maxLength: 253
  20406. minLength: 1
  20407. pattern: ^[-._a-zA-Z0-9]+$
  20408. type: string
  20409. name:
  20410. description: The name of the Secret resource being referred to.
  20411. maxLength: 253
  20412. minLength: 1
  20413. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20414. type: string
  20415. namespace:
  20416. description: |-
  20417. The namespace of the Secret resource being referred to.
  20418. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20419. maxLength: 63
  20420. minLength: 1
  20421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20422. type: string
  20423. type: object
  20424. required:
  20425. - fingerprint
  20426. - privatekey
  20427. type: object
  20428. tenancy:
  20429. description: Tenancy is the tenancy OCID where user is located.
  20430. type: string
  20431. user:
  20432. description: User is an access OCID specific to the account.
  20433. type: string
  20434. required:
  20435. - secretRef
  20436. - tenancy
  20437. - user
  20438. type: object
  20439. compartment:
  20440. description: |-
  20441. Compartment is the vault compartment OCID.
  20442. Required for PushSecret
  20443. type: string
  20444. encryptionKey:
  20445. description: |-
  20446. EncryptionKey is the OCID of the encryption key within the vault.
  20447. Required for PushSecret
  20448. type: string
  20449. principalType:
  20450. description: |-
  20451. The type of principal to use for authentication. If left blank, the Auth struct will
  20452. determine the principal type. This optional field must be specified if using
  20453. workload identity.
  20454. enum:
  20455. - ""
  20456. - UserPrincipal
  20457. - InstancePrincipal
  20458. - Workload
  20459. type: string
  20460. region:
  20461. description: Region is the region where vault is located.
  20462. type: string
  20463. serviceAccountRef:
  20464. description: |-
  20465. ServiceAccountRef specified the service account
  20466. that should be used when authenticating with WorkloadIdentity.
  20467. properties:
  20468. audiences:
  20469. description: |-
  20470. Audience specifies the `aud` claim for the service account token
  20471. Some providers automatically extend the audience field based on well-known annotations for workload
  20472. identity (e.g. IRSA or GCP Workload Identity)
  20473. items:
  20474. type: string
  20475. type: array
  20476. name:
  20477. description: The name of the ServiceAccount resource being referred to.
  20478. maxLength: 253
  20479. minLength: 1
  20480. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20481. type: string
  20482. namespace:
  20483. description: |-
  20484. Namespace of the resource being referred to.
  20485. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20486. maxLength: 63
  20487. minLength: 1
  20488. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20489. type: string
  20490. required:
  20491. - name
  20492. type: object
  20493. vault:
  20494. description: Vault is the vault's OCID of the specific vault where secret is located.
  20495. type: string
  20496. required:
  20497. - region
  20498. - vault
  20499. type: object
  20500. ovh:
  20501. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  20502. properties:
  20503. auth:
  20504. description: Authentication method (mtls or token).
  20505. properties:
  20506. mtls:
  20507. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  20508. properties:
  20509. caBundle:
  20510. format: byte
  20511. type: string
  20512. caProvider:
  20513. description: |-
  20514. CAProvider provides a custom certificate authority for accessing the provider's store.
  20515. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  20516. properties:
  20517. key:
  20518. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20519. maxLength: 253
  20520. minLength: 1
  20521. pattern: ^[-._a-zA-Z0-9]+$
  20522. type: string
  20523. name:
  20524. description: The name of the object located at the provider type.
  20525. maxLength: 253
  20526. minLength: 1
  20527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20528. type: string
  20529. namespace:
  20530. description: |-
  20531. The namespace the Provider type is in.
  20532. Can only be defined when used in a ClusterSecretStore.
  20533. maxLength: 63
  20534. minLength: 1
  20535. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20536. type: string
  20537. type:
  20538. description: The type of provider to use such as "Secret", or "ConfigMap".
  20539. enum:
  20540. - Secret
  20541. - ConfigMap
  20542. type: string
  20543. required:
  20544. - name
  20545. - type
  20546. type: object
  20547. certSecretRef:
  20548. description: |-
  20549. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20550. In some instances, `key` is a required field.
  20551. properties:
  20552. key:
  20553. description: |-
  20554. A key in the referenced Secret.
  20555. Some instances of this field may be defaulted, in others it may be required.
  20556. maxLength: 253
  20557. minLength: 1
  20558. pattern: ^[-._a-zA-Z0-9]+$
  20559. type: string
  20560. name:
  20561. description: The name of the Secret resource being referred to.
  20562. maxLength: 253
  20563. minLength: 1
  20564. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20565. type: string
  20566. namespace:
  20567. description: |-
  20568. The namespace of the Secret resource being referred to.
  20569. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20570. maxLength: 63
  20571. minLength: 1
  20572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20573. type: string
  20574. type: object
  20575. keySecretRef:
  20576. description: |-
  20577. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20578. In some instances, `key` is a required field.
  20579. properties:
  20580. key:
  20581. description: |-
  20582. A key in the referenced Secret.
  20583. Some instances of this field may be defaulted, in others it may be required.
  20584. maxLength: 253
  20585. minLength: 1
  20586. pattern: ^[-._a-zA-Z0-9]+$
  20587. type: string
  20588. name:
  20589. description: The name of the Secret resource being referred to.
  20590. maxLength: 253
  20591. minLength: 1
  20592. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20593. type: string
  20594. namespace:
  20595. description: |-
  20596. The namespace of the Secret resource being referred to.
  20597. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20598. maxLength: 63
  20599. minLength: 1
  20600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20601. type: string
  20602. type: object
  20603. required:
  20604. - certSecretRef
  20605. - keySecretRef
  20606. type: object
  20607. token:
  20608. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  20609. properties:
  20610. tokenSecretRef:
  20611. description: |-
  20612. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20613. In some instances, `key` is a required field.
  20614. properties:
  20615. key:
  20616. description: |-
  20617. A key in the referenced Secret.
  20618. Some instances of this field may be defaulted, in others it may be required.
  20619. maxLength: 253
  20620. minLength: 1
  20621. pattern: ^[-._a-zA-Z0-9]+$
  20622. type: string
  20623. name:
  20624. description: The name of the Secret resource being referred to.
  20625. maxLength: 253
  20626. minLength: 1
  20627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20628. type: string
  20629. namespace:
  20630. description: |-
  20631. The namespace of the Secret resource being referred to.
  20632. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20633. maxLength: 63
  20634. minLength: 1
  20635. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20636. type: string
  20637. type: object
  20638. required:
  20639. - tokenSecretRef
  20640. type: object
  20641. type: object
  20642. casRequired:
  20643. description: 'Enables or disables check-and-set (CAS) (default: false).'
  20644. type: boolean
  20645. okmsTimeout:
  20646. default: 30
  20647. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  20648. format: int32
  20649. minimum: 1
  20650. type: integer
  20651. okmsid:
  20652. description: specifies the OKMS ID.
  20653. type: string
  20654. server:
  20655. description: specifies the OKMS server endpoint.
  20656. type: string
  20657. required:
  20658. - auth
  20659. - okmsid
  20660. - server
  20661. type: object
  20662. passbolt:
  20663. description: |-
  20664. PassboltProvider provides access to Passbolt secrets manager.
  20665. See: https://www.passbolt.com.
  20666. properties:
  20667. auth:
  20668. description: Auth defines the information necessary to authenticate against Passbolt Server
  20669. properties:
  20670. passwordSecretRef:
  20671. description: |-
  20672. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20673. In some instances, `key` is a required field.
  20674. properties:
  20675. key:
  20676. description: |-
  20677. A key in the referenced Secret.
  20678. Some instances of this field may be defaulted, in others it may be required.
  20679. maxLength: 253
  20680. minLength: 1
  20681. pattern: ^[-._a-zA-Z0-9]+$
  20682. type: string
  20683. name:
  20684. description: The name of the Secret resource being referred to.
  20685. maxLength: 253
  20686. minLength: 1
  20687. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20688. type: string
  20689. namespace:
  20690. description: |-
  20691. The namespace of the Secret resource being referred to.
  20692. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20693. maxLength: 63
  20694. minLength: 1
  20695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20696. type: string
  20697. type: object
  20698. privateKeySecretRef:
  20699. description: |-
  20700. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20701. In some instances, `key` is a required field.
  20702. properties:
  20703. key:
  20704. description: |-
  20705. A key in the referenced Secret.
  20706. Some instances of this field may be defaulted, in others it may be required.
  20707. maxLength: 253
  20708. minLength: 1
  20709. pattern: ^[-._a-zA-Z0-9]+$
  20710. type: string
  20711. name:
  20712. description: The name of the Secret resource being referred to.
  20713. maxLength: 253
  20714. minLength: 1
  20715. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20716. type: string
  20717. namespace:
  20718. description: |-
  20719. The namespace of the Secret resource being referred to.
  20720. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20721. maxLength: 63
  20722. minLength: 1
  20723. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20724. type: string
  20725. type: object
  20726. required:
  20727. - passwordSecretRef
  20728. - privateKeySecretRef
  20729. type: object
  20730. caBundle:
  20731. description: |-
  20732. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  20733. if the Host URL is using HTTPS protocol. If not set the system root certificates
  20734. are used to validate the TLS connection.
  20735. format: byte
  20736. type: string
  20737. caProvider:
  20738. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  20739. properties:
  20740. key:
  20741. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20742. maxLength: 253
  20743. minLength: 1
  20744. pattern: ^[-._a-zA-Z0-9]+$
  20745. type: string
  20746. name:
  20747. description: The name of the object located at the provider type.
  20748. maxLength: 253
  20749. minLength: 1
  20750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20751. type: string
  20752. namespace:
  20753. description: |-
  20754. The namespace the Provider type is in.
  20755. Can only be defined when used in a ClusterSecretStore.
  20756. maxLength: 63
  20757. minLength: 1
  20758. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20759. type: string
  20760. type:
  20761. description: The type of provider to use such as "Secret", or "ConfigMap".
  20762. enum:
  20763. - Secret
  20764. - ConfigMap
  20765. type: string
  20766. required:
  20767. - name
  20768. - type
  20769. type: object
  20770. host:
  20771. description: Host defines the Passbolt Server to connect to
  20772. type: string
  20773. required:
  20774. - auth
  20775. - host
  20776. type: object
  20777. passworddepot:
  20778. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  20779. properties:
  20780. auth:
  20781. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  20782. properties:
  20783. secretRef:
  20784. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  20785. properties:
  20786. credentials:
  20787. description: Username / Password is used for authentication.
  20788. properties:
  20789. key:
  20790. description: |-
  20791. A key in the referenced Secret.
  20792. Some instances of this field may be defaulted, in others it may be required.
  20793. maxLength: 253
  20794. minLength: 1
  20795. pattern: ^[-._a-zA-Z0-9]+$
  20796. type: string
  20797. name:
  20798. description: The name of the Secret resource being referred to.
  20799. maxLength: 253
  20800. minLength: 1
  20801. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20802. type: string
  20803. namespace:
  20804. description: |-
  20805. The namespace of the Secret resource being referred to.
  20806. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20807. maxLength: 63
  20808. minLength: 1
  20809. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20810. type: string
  20811. type: object
  20812. type: object
  20813. required:
  20814. - secretRef
  20815. type: object
  20816. database:
  20817. description: Database to use as source
  20818. type: string
  20819. host:
  20820. description: URL configures the Password Depot instance URL.
  20821. type: string
  20822. required:
  20823. - auth
  20824. - database
  20825. - host
  20826. type: object
  20827. previder:
  20828. description: Previder configures this store to sync secrets using the Previder provider
  20829. properties:
  20830. auth:
  20831. description: PreviderAuth contains a secretRef for credentials.
  20832. properties:
  20833. secretRef:
  20834. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  20835. properties:
  20836. accessToken:
  20837. description: The AccessToken is used for authentication
  20838. properties:
  20839. key:
  20840. description: |-
  20841. A key in the referenced Secret.
  20842. Some instances of this field may be defaulted, in others it may be required.
  20843. maxLength: 253
  20844. minLength: 1
  20845. pattern: ^[-._a-zA-Z0-9]+$
  20846. type: string
  20847. name:
  20848. description: The name of the Secret resource being referred to.
  20849. maxLength: 253
  20850. minLength: 1
  20851. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20852. type: string
  20853. namespace:
  20854. description: |-
  20855. The namespace of the Secret resource being referred to.
  20856. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20857. maxLength: 63
  20858. minLength: 1
  20859. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20860. type: string
  20861. type: object
  20862. required:
  20863. - accessToken
  20864. type: object
  20865. type: object
  20866. baseUri:
  20867. type: string
  20868. required:
  20869. - auth
  20870. type: object
  20871. pulumi:
  20872. description: Pulumi configures this store to sync secrets using the Pulumi provider
  20873. properties:
  20874. accessToken:
  20875. description: |-
  20876. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  20877. Deprecated: Use auth.accessToken instead.
  20878. properties:
  20879. secretRef:
  20880. description: SecretRef is a reference to a secret containing the Pulumi API token.
  20881. properties:
  20882. key:
  20883. description: |-
  20884. A key in the referenced Secret.
  20885. Some instances of this field may be defaulted, in others it may be required.
  20886. maxLength: 253
  20887. minLength: 1
  20888. pattern: ^[-._a-zA-Z0-9]+$
  20889. type: string
  20890. name:
  20891. description: The name of the Secret resource being referred to.
  20892. maxLength: 253
  20893. minLength: 1
  20894. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20895. type: string
  20896. namespace:
  20897. description: |-
  20898. The namespace of the Secret resource being referred to.
  20899. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20900. maxLength: 63
  20901. minLength: 1
  20902. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20903. type: string
  20904. type: object
  20905. type: object
  20906. apiUrl:
  20907. default: https://api.pulumi.com/api/esc
  20908. description: APIURL is the URL of the Pulumi API.
  20909. type: string
  20910. auth:
  20911. description: |-
  20912. Auth configures how the Operator authenticates with the Pulumi API.
  20913. Either auth or the deprecated accessToken field must be specified.
  20914. properties:
  20915. accessToken:
  20916. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  20917. properties:
  20918. secretRef:
  20919. description: SecretRef is a reference to a secret containing the Pulumi API token.
  20920. properties:
  20921. key:
  20922. description: |-
  20923. A key in the referenced Secret.
  20924. Some instances of this field may be defaulted, in others it may be required.
  20925. maxLength: 253
  20926. minLength: 1
  20927. pattern: ^[-._a-zA-Z0-9]+$
  20928. type: string
  20929. name:
  20930. description: The name of the Secret resource being referred to.
  20931. maxLength: 253
  20932. minLength: 1
  20933. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20934. type: string
  20935. namespace:
  20936. description: |-
  20937. The namespace of the Secret resource being referred to.
  20938. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20939. maxLength: 63
  20940. minLength: 1
  20941. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20942. type: string
  20943. type: object
  20944. type: object
  20945. oidcConfig:
  20946. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  20947. properties:
  20948. expirationSeconds:
  20949. default: 600
  20950. description: |-
  20951. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  20952. Defaults to 10 minutes.
  20953. format: int64
  20954. minimum: 600
  20955. type: integer
  20956. organization:
  20957. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  20958. type: string
  20959. serviceAccountRef:
  20960. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  20961. properties:
  20962. audiences:
  20963. description: |-
  20964. Audience specifies the `aud` claim for the service account token
  20965. Some providers automatically extend the audience field based on well-known annotations for workload
  20966. identity (e.g. IRSA or GCP Workload Identity)
  20967. items:
  20968. type: string
  20969. type: array
  20970. name:
  20971. description: The name of the ServiceAccount resource being referred to.
  20972. maxLength: 253
  20973. minLength: 1
  20974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20975. type: string
  20976. namespace:
  20977. description: |-
  20978. Namespace of the resource being referred to.
  20979. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20980. maxLength: 63
  20981. minLength: 1
  20982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20983. type: string
  20984. required:
  20985. - name
  20986. type: object
  20987. required:
  20988. - organization
  20989. - serviceAccountRef
  20990. type: object
  20991. type: object
  20992. x-kubernetes-validations:
  20993. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  20994. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  20995. environment:
  20996. description: |-
  20997. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  20998. dynamically retrieved values from supported providers including all major clouds,
  20999. and other Pulumi ESC environments.
  21000. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  21001. type: string
  21002. organization:
  21003. description: |-
  21004. Organization are a space to collaborate on shared projects and stacks.
  21005. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  21006. type: string
  21007. project:
  21008. description: Project is the name of the Pulumi ESC project the environment belongs to.
  21009. type: string
  21010. required:
  21011. - environment
  21012. - organization
  21013. - project
  21014. type: object
  21015. x-kubernetes-validations:
  21016. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  21017. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  21018. scaleway:
  21019. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  21020. properties:
  21021. accessKey:
  21022. description: AccessKey is the non-secret part of the api key.
  21023. properties:
  21024. secretRef:
  21025. description: SecretRef references a key in a secret that will be used as value.
  21026. properties:
  21027. key:
  21028. description: |-
  21029. A key in the referenced Secret.
  21030. Some instances of this field may be defaulted, in others it may be required.
  21031. maxLength: 253
  21032. minLength: 1
  21033. pattern: ^[-._a-zA-Z0-9]+$
  21034. type: string
  21035. name:
  21036. description: The name of the Secret resource being referred to.
  21037. maxLength: 253
  21038. minLength: 1
  21039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21040. type: string
  21041. namespace:
  21042. description: |-
  21043. The namespace of the Secret resource being referred to.
  21044. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21045. maxLength: 63
  21046. minLength: 1
  21047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21048. type: string
  21049. type: object
  21050. value:
  21051. description: Value can be specified directly to set a value without using a secret.
  21052. type: string
  21053. type: object
  21054. apiUrl:
  21055. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  21056. type: string
  21057. projectId:
  21058. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  21059. type: string
  21060. region:
  21061. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  21062. type: string
  21063. secretKey:
  21064. description: SecretKey is the non-secret part of the api key.
  21065. properties:
  21066. secretRef:
  21067. description: SecretRef references a key in a secret that will be used as value.
  21068. properties:
  21069. key:
  21070. description: |-
  21071. A key in the referenced Secret.
  21072. Some instances of this field may be defaulted, in others it may be required.
  21073. maxLength: 253
  21074. minLength: 1
  21075. pattern: ^[-._a-zA-Z0-9]+$
  21076. type: string
  21077. name:
  21078. description: The name of the Secret resource being referred to.
  21079. maxLength: 253
  21080. minLength: 1
  21081. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21082. type: string
  21083. namespace:
  21084. description: |-
  21085. The namespace of the Secret resource being referred to.
  21086. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21087. maxLength: 63
  21088. minLength: 1
  21089. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21090. type: string
  21091. type: object
  21092. value:
  21093. description: Value can be specified directly to set a value without using a secret.
  21094. type: string
  21095. type: object
  21096. required:
  21097. - accessKey
  21098. - projectId
  21099. - region
  21100. - secretKey
  21101. type: object
  21102. secretserver:
  21103. description: |-
  21104. SecretServer configures this store to sync secrets using SecretServer provider
  21105. https://docs.delinea.com/online-help/secret-server/start.htm
  21106. properties:
  21107. caBundle:
  21108. description: |-
  21109. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  21110. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  21111. are used to validate the TLS connection.
  21112. format: byte
  21113. type: string
  21114. caProvider:
  21115. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  21116. properties:
  21117. key:
  21118. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  21119. maxLength: 253
  21120. minLength: 1
  21121. pattern: ^[-._a-zA-Z0-9]+$
  21122. type: string
  21123. name:
  21124. description: The name of the object located at the provider type.
  21125. maxLength: 253
  21126. minLength: 1
  21127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21128. type: string
  21129. namespace:
  21130. description: |-
  21131. The namespace the Provider type is in.
  21132. Can only be defined when used in a ClusterSecretStore.
  21133. maxLength: 63
  21134. minLength: 1
  21135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21136. type: string
  21137. type:
  21138. description: The type of provider to use such as "Secret", or "ConfigMap".
  21139. enum:
  21140. - Secret
  21141. - ConfigMap
  21142. type: string
  21143. required:
  21144. - name
  21145. - type
  21146. type: object
  21147. disableSiteIDValidation:
  21148. description: |-
  21149. DisableSiteIDValidation permits a missing site ID for new secrets.
  21150. The provider sends 0 if no site ID is set.
  21151. type: boolean
  21152. domain:
  21153. description: Domain is the secret server domain.
  21154. type: string
  21155. password:
  21156. description: |-
  21157. Password is the secret server account password.
  21158. Required unless Token is set.
  21159. properties:
  21160. secretRef:
  21161. description: SecretRef references a key in a secret that will be used as value.
  21162. properties:
  21163. key:
  21164. description: |-
  21165. A key in the referenced Secret.
  21166. Some instances of this field may be defaulted, in others it may be required.
  21167. maxLength: 253
  21168. minLength: 1
  21169. pattern: ^[-._a-zA-Z0-9]+$
  21170. type: string
  21171. name:
  21172. description: The name of the Secret resource being referred to.
  21173. maxLength: 253
  21174. minLength: 1
  21175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21176. type: string
  21177. namespace:
  21178. description: |-
  21179. The namespace of the Secret resource being referred to.
  21180. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21181. maxLength: 63
  21182. minLength: 1
  21183. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21184. type: string
  21185. type: object
  21186. value:
  21187. description: Value can be specified directly to set a value without using a secret.
  21188. minLength: 1
  21189. type: string
  21190. type: object
  21191. x-kubernetes-validations:
  21192. - message: exactly one of value or secretRef must be set
  21193. rule: has(self.value) != has(self.secretRef)
  21194. serverURL:
  21195. description: |-
  21196. ServerURL
  21197. URL to your secret server installation
  21198. type: string
  21199. siteId:
  21200. description: |-
  21201. SiteID is the ID of the Secret Server site for new secrets.
  21202. PushSecret metadata can override this value for one secret.
  21203. The provider uses 1 if this field is not set.
  21204. minimum: 1
  21205. type: integer
  21206. token:
  21207. description: |-
  21208. Token is an access token used to authenticate to the secret server,
  21209. as an alternative to Username and Password. When set, Username and
  21210. Password are not required and are ignored.
  21211. properties:
  21212. secretRef:
  21213. description: SecretRef references a key in a secret that will be used as value.
  21214. properties:
  21215. key:
  21216. description: |-
  21217. A key in the referenced Secret.
  21218. Some instances of this field may be defaulted, in others it may be required.
  21219. maxLength: 253
  21220. minLength: 1
  21221. pattern: ^[-._a-zA-Z0-9]+$
  21222. type: string
  21223. name:
  21224. description: The name of the Secret resource being referred to.
  21225. maxLength: 253
  21226. minLength: 1
  21227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21228. type: string
  21229. namespace:
  21230. description: |-
  21231. The namespace of the Secret resource being referred to.
  21232. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21233. maxLength: 63
  21234. minLength: 1
  21235. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21236. type: string
  21237. type: object
  21238. value:
  21239. description: Value can be specified directly to set a value without using a secret.
  21240. minLength: 1
  21241. type: string
  21242. type: object
  21243. x-kubernetes-validations:
  21244. - message: exactly one of value or secretRef must be set
  21245. rule: has(self.value) != has(self.secretRef)
  21246. username:
  21247. description: |-
  21248. Username is the secret server account username.
  21249. Required unless Token is set.
  21250. properties:
  21251. secretRef:
  21252. description: SecretRef references a key in a secret that will be used as value.
  21253. properties:
  21254. key:
  21255. description: |-
  21256. A key in the referenced Secret.
  21257. Some instances of this field may be defaulted, in others it may be required.
  21258. maxLength: 253
  21259. minLength: 1
  21260. pattern: ^[-._a-zA-Z0-9]+$
  21261. type: string
  21262. name:
  21263. description: The name of the Secret resource being referred to.
  21264. maxLength: 253
  21265. minLength: 1
  21266. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21267. type: string
  21268. namespace:
  21269. description: |-
  21270. The namespace of the Secret resource being referred to.
  21271. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21272. maxLength: 63
  21273. minLength: 1
  21274. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21275. type: string
  21276. type: object
  21277. value:
  21278. description: Value can be specified directly to set a value without using a secret.
  21279. minLength: 1
  21280. type: string
  21281. type: object
  21282. x-kubernetes-validations:
  21283. - message: exactly one of value or secretRef must be set
  21284. rule: has(self.value) != has(self.secretRef)
  21285. required:
  21286. - serverURL
  21287. type: object
  21288. x-kubernetes-validations:
  21289. - message: either token, or both username and password, must be set
  21290. rule: has(self.token) || (has(self.username) && has(self.password))
  21291. senhasegura:
  21292. description: Senhasegura configures this store to sync secrets using senhasegura provider
  21293. properties:
  21294. auth:
  21295. description: Auth defines parameters to authenticate in senhasegura
  21296. properties:
  21297. clientId:
  21298. type: string
  21299. clientSecretSecretRef:
  21300. description: |-
  21301. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  21302. In some instances, `key` is a required field.
  21303. properties:
  21304. key:
  21305. description: |-
  21306. A key in the referenced Secret.
  21307. Some instances of this field may be defaulted, in others it may be required.
  21308. maxLength: 253
  21309. minLength: 1
  21310. pattern: ^[-._a-zA-Z0-9]+$
  21311. type: string
  21312. name:
  21313. description: The name of the Secret resource being referred to.
  21314. maxLength: 253
  21315. minLength: 1
  21316. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21317. type: string
  21318. namespace:
  21319. description: |-
  21320. The namespace of the Secret resource being referred to.
  21321. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21322. maxLength: 63
  21323. minLength: 1
  21324. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21325. type: string
  21326. type: object
  21327. required:
  21328. - clientId
  21329. - clientSecretSecretRef
  21330. type: object
  21331. ignoreSslCertificate:
  21332. default: false
  21333. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  21334. type: boolean
  21335. module:
  21336. description: Module defines which senhasegura module should be used to get secrets
  21337. type: string
  21338. url:
  21339. description: URL of senhasegura
  21340. type: string
  21341. required:
  21342. - auth
  21343. - module
  21344. - url
  21345. type: object
  21346. vault:
  21347. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  21348. properties:
  21349. auth:
  21350. description: Auth configures how secret-manager authenticates with the Vault server.
  21351. properties:
  21352. appRole:
  21353. description: |-
  21354. AppRole authenticates with Vault using the App Role auth mechanism,
  21355. with the role and secret stored in a Kubernetes Secret resource.
  21356. properties:
  21357. path:
  21358. default: approle
  21359. description: |-
  21360. Path where the App Role authentication backend is mounted
  21361. in Vault, e.g: "approle"
  21362. type: string
  21363. roleId:
  21364. description: |-
  21365. RoleID configured in the App Role authentication backend when setting
  21366. up the authentication backend in Vault.
  21367. type: string
  21368. roleRef:
  21369. description: |-
  21370. Reference to a key in a Secret that contains the App Role ID used
  21371. to authenticate with Vault.
  21372. The `key` field must be specified and denotes which entry within the Secret
  21373. resource is used as the app role id.
  21374. properties:
  21375. key:
  21376. description: |-
  21377. A key in the referenced Secret.
  21378. Some instances of this field may be defaulted, in others it may be required.
  21379. maxLength: 253
  21380. minLength: 1
  21381. pattern: ^[-._a-zA-Z0-9]+$
  21382. type: string
  21383. name:
  21384. description: The name of the Secret resource being referred to.
  21385. maxLength: 253
  21386. minLength: 1
  21387. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21388. type: string
  21389. namespace:
  21390. description: |-
  21391. The namespace of the Secret resource being referred to.
  21392. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21393. maxLength: 63
  21394. minLength: 1
  21395. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21396. type: string
  21397. type: object
  21398. secretRef:
  21399. description: |-
  21400. Reference to a key in a Secret that contains the App Role secret used
  21401. to authenticate with Vault.
  21402. The `key` field must be specified and denotes which entry within the Secret
  21403. resource is used as the app role secret.
  21404. properties:
  21405. key:
  21406. description: |-
  21407. A key in the referenced Secret.
  21408. Some instances of this field may be defaulted, in others it may be required.
  21409. maxLength: 253
  21410. minLength: 1
  21411. pattern: ^[-._a-zA-Z0-9]+$
  21412. type: string
  21413. name:
  21414. description: The name of the Secret resource being referred to.
  21415. maxLength: 253
  21416. minLength: 1
  21417. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21418. type: string
  21419. namespace:
  21420. description: |-
  21421. The namespace of the Secret resource being referred to.
  21422. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21423. maxLength: 63
  21424. minLength: 1
  21425. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21426. type: string
  21427. type: object
  21428. required:
  21429. - path
  21430. - secretRef
  21431. type: object
  21432. cert:
  21433. description: |-
  21434. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  21435. Cert authentication method
  21436. properties:
  21437. clientCert:
  21438. description: |-
  21439. ClientCert is a certificate to authenticate using the Cert Vault
  21440. authentication method
  21441. properties:
  21442. key:
  21443. description: |-
  21444. A key in the referenced Secret.
  21445. Some instances of this field may be defaulted, in others it may be required.
  21446. maxLength: 253
  21447. minLength: 1
  21448. pattern: ^[-._a-zA-Z0-9]+$
  21449. type: string
  21450. name:
  21451. description: The name of the Secret resource being referred to.
  21452. maxLength: 253
  21453. minLength: 1
  21454. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21455. type: string
  21456. namespace:
  21457. description: |-
  21458. The namespace of the Secret resource being referred to.
  21459. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21460. maxLength: 63
  21461. minLength: 1
  21462. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21463. type: string
  21464. type: object
  21465. path:
  21466. default: cert
  21467. description: |-
  21468. Path where the Certificate authentication backend is mounted
  21469. in Vault, e.g: "cert"
  21470. type: string
  21471. secretRef:
  21472. description: |-
  21473. SecretRef to a key in a Secret resource containing client private key to
  21474. authenticate with Vault using the Cert authentication method
  21475. properties:
  21476. key:
  21477. description: |-
  21478. A key in the referenced Secret.
  21479. Some instances of this field may be defaulted, in others it may be required.
  21480. maxLength: 253
  21481. minLength: 1
  21482. pattern: ^[-._a-zA-Z0-9]+$
  21483. type: string
  21484. name:
  21485. description: The name of the Secret resource being referred to.
  21486. maxLength: 253
  21487. minLength: 1
  21488. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21489. type: string
  21490. namespace:
  21491. description: |-
  21492. The namespace of the Secret resource being referred to.
  21493. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21494. maxLength: 63
  21495. minLength: 1
  21496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21497. type: string
  21498. type: object
  21499. vaultRole:
  21500. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  21501. type: string
  21502. type: object
  21503. gcp:
  21504. description: |-
  21505. Gcp authenticates with Vault using Google Cloud Platform authentication method
  21506. GCP authentication method
  21507. properties:
  21508. location:
  21509. description: Location optionally defines a location/region for the secret
  21510. type: string
  21511. path:
  21512. default: gcp
  21513. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  21514. type: string
  21515. projectID:
  21516. description: Project ID of the Google Cloud Platform project
  21517. type: string
  21518. role:
  21519. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  21520. type: string
  21521. secretRef:
  21522. description: Specify credentials in a Secret object
  21523. properties:
  21524. secretAccessKeySecretRef:
  21525. description: The SecretAccessKey is used for authentication
  21526. properties:
  21527. key:
  21528. description: |-
  21529. A key in the referenced Secret.
  21530. Some instances of this field may be defaulted, in others it may be required.
  21531. maxLength: 253
  21532. minLength: 1
  21533. pattern: ^[-._a-zA-Z0-9]+$
  21534. type: string
  21535. name:
  21536. description: The name of the Secret resource being referred to.
  21537. maxLength: 253
  21538. minLength: 1
  21539. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21540. type: string
  21541. namespace:
  21542. description: |-
  21543. The namespace of the Secret resource being referred to.
  21544. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21545. maxLength: 63
  21546. minLength: 1
  21547. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21548. type: string
  21549. type: object
  21550. type: object
  21551. serviceAccountRef:
  21552. description: ServiceAccountRef to a service account for impersonation
  21553. properties:
  21554. audiences:
  21555. description: |-
  21556. Audience specifies the `aud` claim for the service account token
  21557. Some providers automatically extend the audience field based on well-known annotations for workload
  21558. identity (e.g. IRSA or GCP Workload Identity)
  21559. items:
  21560. type: string
  21561. type: array
  21562. name:
  21563. description: The name of the ServiceAccount resource being referred to.
  21564. maxLength: 253
  21565. minLength: 1
  21566. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21567. type: string
  21568. namespace:
  21569. description: |-
  21570. Namespace of the resource being referred to.
  21571. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21572. maxLength: 63
  21573. minLength: 1
  21574. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21575. type: string
  21576. required:
  21577. - name
  21578. type: object
  21579. workloadIdentity:
  21580. description: Specify a service account with Workload Identity
  21581. properties:
  21582. clusterLocation:
  21583. description: |-
  21584. ClusterLocation is the location of the cluster
  21585. If not specified, it fetches information from the metadata server
  21586. type: string
  21587. clusterName:
  21588. description: |-
  21589. ClusterName is the name of the cluster
  21590. If not specified, it fetches information from the metadata server
  21591. type: string
  21592. clusterProjectID:
  21593. description: |-
  21594. ClusterProjectID is the project ID of the cluster
  21595. If not specified, it fetches information from the metadata server
  21596. type: string
  21597. serviceAccountRef:
  21598. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  21599. properties:
  21600. audiences:
  21601. description: |-
  21602. Audience specifies the `aud` claim for the service account token
  21603. Some providers automatically extend the audience field based on well-known annotations for workload
  21604. identity (e.g. IRSA or GCP Workload Identity)
  21605. items:
  21606. type: string
  21607. type: array
  21608. name:
  21609. description: The name of the ServiceAccount resource being referred to.
  21610. maxLength: 253
  21611. minLength: 1
  21612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21613. type: string
  21614. namespace:
  21615. description: |-
  21616. Namespace of the resource being referred to.
  21617. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21618. maxLength: 63
  21619. minLength: 1
  21620. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21621. type: string
  21622. required:
  21623. - name
  21624. type: object
  21625. required:
  21626. - serviceAccountRef
  21627. type: object
  21628. required:
  21629. - role
  21630. type: object
  21631. iam:
  21632. description: |-
  21633. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  21634. AWS IAM authentication method
  21635. properties:
  21636. externalID:
  21637. description: AWS External ID set on assumed IAM roles
  21638. type: string
  21639. jwt:
  21640. description: Specify a service account with IRSA enabled
  21641. properties:
  21642. serviceAccountRef:
  21643. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  21644. properties:
  21645. audiences:
  21646. description: |-
  21647. Audience specifies the `aud` claim for the service account token
  21648. Some providers automatically extend the audience field based on well-known annotations for workload
  21649. identity (e.g. IRSA or GCP Workload Identity)
  21650. items:
  21651. type: string
  21652. type: array
  21653. name:
  21654. description: The name of the ServiceAccount resource being referred to.
  21655. maxLength: 253
  21656. minLength: 1
  21657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21658. type: string
  21659. namespace:
  21660. description: |-
  21661. Namespace of the resource being referred to.
  21662. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21663. maxLength: 63
  21664. minLength: 1
  21665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21666. type: string
  21667. required:
  21668. - name
  21669. type: object
  21670. type: object
  21671. path:
  21672. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  21673. type: string
  21674. region:
  21675. description: AWS region
  21676. type: string
  21677. role:
  21678. description: This is the AWS role to be assumed before talking to vault
  21679. type: string
  21680. secretRef:
  21681. description: Specify credentials in a Secret object
  21682. properties:
  21683. accessKeyIDSecretRef:
  21684. description: The AccessKeyID is used for authentication
  21685. properties:
  21686. key:
  21687. description: |-
  21688. A key in the referenced Secret.
  21689. Some instances of this field may be defaulted, in others it may be required.
  21690. maxLength: 253
  21691. minLength: 1
  21692. pattern: ^[-._a-zA-Z0-9]+$
  21693. type: string
  21694. name:
  21695. description: The name of the Secret resource being referred to.
  21696. maxLength: 253
  21697. minLength: 1
  21698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21699. type: string
  21700. namespace:
  21701. description: |-
  21702. The namespace of the Secret resource being referred to.
  21703. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21704. maxLength: 63
  21705. minLength: 1
  21706. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21707. type: string
  21708. type: object
  21709. secretAccessKeySecretRef:
  21710. description: The SecretAccessKey is used for authentication
  21711. properties:
  21712. key:
  21713. description: |-
  21714. A key in the referenced Secret.
  21715. Some instances of this field may be defaulted, in others it may be required.
  21716. maxLength: 253
  21717. minLength: 1
  21718. pattern: ^[-._a-zA-Z0-9]+$
  21719. type: string
  21720. name:
  21721. description: The name of the Secret resource being referred to.
  21722. maxLength: 253
  21723. minLength: 1
  21724. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21725. type: string
  21726. namespace:
  21727. description: |-
  21728. The namespace of the Secret resource being referred to.
  21729. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21730. maxLength: 63
  21731. minLength: 1
  21732. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21733. type: string
  21734. type: object
  21735. sessionTokenSecretRef:
  21736. description: |-
  21737. The SessionToken used for authentication
  21738. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  21739. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  21740. properties:
  21741. key:
  21742. description: |-
  21743. A key in the referenced Secret.
  21744. Some instances of this field may be defaulted, in others it may be required.
  21745. maxLength: 253
  21746. minLength: 1
  21747. pattern: ^[-._a-zA-Z0-9]+$
  21748. type: string
  21749. name:
  21750. description: The name of the Secret resource being referred to.
  21751. maxLength: 253
  21752. minLength: 1
  21753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21754. type: string
  21755. namespace:
  21756. description: |-
  21757. The namespace of the Secret resource being referred to.
  21758. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21759. maxLength: 63
  21760. minLength: 1
  21761. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21762. type: string
  21763. type: object
  21764. type: object
  21765. vaultAwsIamServerID:
  21766. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  21767. type: string
  21768. vaultRole:
  21769. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  21770. type: string
  21771. required:
  21772. - vaultRole
  21773. type: object
  21774. jwt:
  21775. description: |-
  21776. Jwt authenticates with Vault by passing role and JWT token using the
  21777. JWT/OIDC authentication method
  21778. properties:
  21779. kubernetesServiceAccountToken:
  21780. description: |-
  21781. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  21782. a token for with the `TokenRequest` API.
  21783. properties:
  21784. audiences:
  21785. description: |-
  21786. Optional audiences field that will be used to request a temporary Kubernetes service
  21787. account token for the service account referenced by `serviceAccountRef`.
  21788. Defaults to a single audience `vault` it not specified.
  21789. Deprecated: use serviceAccountRef.Audiences instead
  21790. items:
  21791. type: string
  21792. type: array
  21793. expirationSeconds:
  21794. description: |-
  21795. Optional expiration time in seconds that will be used to request a temporary
  21796. Kubernetes service account token for the service account referenced by
  21797. `serviceAccountRef`.
  21798. Deprecated: this will be removed in the future.
  21799. Defaults to 10 minutes.
  21800. format: int64
  21801. type: integer
  21802. serviceAccountRef:
  21803. description: Service account field containing the name of a kubernetes ServiceAccount.
  21804. properties:
  21805. audiences:
  21806. description: |-
  21807. Audience specifies the `aud` claim for the service account token
  21808. Some providers automatically extend the audience field based on well-known annotations for workload
  21809. identity (e.g. IRSA or GCP Workload Identity)
  21810. items:
  21811. type: string
  21812. type: array
  21813. name:
  21814. description: The name of the ServiceAccount resource being referred to.
  21815. maxLength: 253
  21816. minLength: 1
  21817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21818. type: string
  21819. namespace:
  21820. description: |-
  21821. Namespace of the resource being referred to.
  21822. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21823. maxLength: 63
  21824. minLength: 1
  21825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21826. type: string
  21827. required:
  21828. - name
  21829. type: object
  21830. required:
  21831. - serviceAccountRef
  21832. type: object
  21833. path:
  21834. default: jwt
  21835. description: |-
  21836. Path where the JWT authentication backend is mounted
  21837. in Vault, e.g: "jwt"
  21838. type: string
  21839. role:
  21840. description: |-
  21841. Role is a JWT role to authenticate using the JWT/OIDC Vault
  21842. authentication method
  21843. type: string
  21844. secretRef:
  21845. description: |-
  21846. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  21847. authenticate with Vault using the JWT/OIDC authentication method.
  21848. properties:
  21849. key:
  21850. description: |-
  21851. A key in the referenced Secret.
  21852. Some instances of this field may be defaulted, in others it may be required.
  21853. maxLength: 253
  21854. minLength: 1
  21855. pattern: ^[-._a-zA-Z0-9]+$
  21856. type: string
  21857. name:
  21858. description: The name of the Secret resource being referred to.
  21859. maxLength: 253
  21860. minLength: 1
  21861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21862. type: string
  21863. namespace:
  21864. description: |-
  21865. The namespace of the Secret resource being referred to.
  21866. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21867. maxLength: 63
  21868. minLength: 1
  21869. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21870. type: string
  21871. type: object
  21872. required:
  21873. - path
  21874. type: object
  21875. kubernetes:
  21876. description: |-
  21877. Kubernetes authenticates with Vault by passing the ServiceAccount
  21878. token stored in the named Secret resource to the Vault server.
  21879. properties:
  21880. mountPath:
  21881. default: kubernetes
  21882. description: |-
  21883. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  21884. "kubernetes"
  21885. type: string
  21886. role:
  21887. description: |-
  21888. A required field containing the Vault Role to assume. A Role binds a
  21889. Kubernetes ServiceAccount with a set of Vault policies.
  21890. type: string
  21891. secretRef:
  21892. description: |-
  21893. Optional secret field containing a Kubernetes ServiceAccount JWT used
  21894. for authenticating with Vault. If a name is specified without a key,
  21895. `token` is the default. If one is not specified, the one bound to
  21896. the controller will be used.
  21897. properties:
  21898. key:
  21899. description: |-
  21900. A key in the referenced Secret.
  21901. Some instances of this field may be defaulted, in others it may be required.
  21902. maxLength: 253
  21903. minLength: 1
  21904. pattern: ^[-._a-zA-Z0-9]+$
  21905. type: string
  21906. name:
  21907. description: The name of the Secret resource being referred to.
  21908. maxLength: 253
  21909. minLength: 1
  21910. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21911. type: string
  21912. namespace:
  21913. description: |-
  21914. The namespace of the Secret resource being referred to.
  21915. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21916. maxLength: 63
  21917. minLength: 1
  21918. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21919. type: string
  21920. type: object
  21921. serviceAccountRef:
  21922. description: |-
  21923. Optional service account field containing the name of a kubernetes ServiceAccount.
  21924. If the service account is specified, the service account secret token JWT will be used
  21925. for authenticating with Vault. If the service account selector is not supplied,
  21926. the secretRef will be used instead.
  21927. properties:
  21928. audiences:
  21929. description: |-
  21930. Audience specifies the `aud` claim for the service account token
  21931. Some providers automatically extend the audience field based on well-known annotations for workload
  21932. identity (e.g. IRSA or GCP Workload Identity)
  21933. items:
  21934. type: string
  21935. type: array
  21936. name:
  21937. description: The name of the ServiceAccount resource being referred to.
  21938. maxLength: 253
  21939. minLength: 1
  21940. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21941. type: string
  21942. namespace:
  21943. description: |-
  21944. Namespace of the resource being referred to.
  21945. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21946. maxLength: 63
  21947. minLength: 1
  21948. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21949. type: string
  21950. required:
  21951. - name
  21952. type: object
  21953. required:
  21954. - mountPath
  21955. - role
  21956. type: object
  21957. ldap:
  21958. description: |-
  21959. Ldap authenticates with Vault by passing username/password pair using
  21960. the LDAP authentication method
  21961. properties:
  21962. path:
  21963. default: ldap
  21964. description: |-
  21965. Path where the LDAP authentication backend is mounted
  21966. in Vault, e.g: "ldap"
  21967. type: string
  21968. secretRef:
  21969. description: |-
  21970. SecretRef to a key in a Secret resource containing password for the LDAP
  21971. user used to authenticate with Vault using the LDAP authentication
  21972. method
  21973. properties:
  21974. key:
  21975. description: |-
  21976. A key in the referenced Secret.
  21977. Some instances of this field may be defaulted, in others it may be required.
  21978. maxLength: 253
  21979. minLength: 1
  21980. pattern: ^[-._a-zA-Z0-9]+$
  21981. type: string
  21982. name:
  21983. description: The name of the Secret resource being referred to.
  21984. maxLength: 253
  21985. minLength: 1
  21986. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21987. type: string
  21988. namespace:
  21989. description: |-
  21990. The namespace of the Secret resource being referred to.
  21991. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21992. maxLength: 63
  21993. minLength: 1
  21994. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21995. type: string
  21996. type: object
  21997. username:
  21998. description: |-
  21999. Username is an LDAP username used to authenticate using the LDAP Vault
  22000. authentication method
  22001. type: string
  22002. required:
  22003. - path
  22004. - username
  22005. type: object
  22006. namespace:
  22007. description: |-
  22008. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  22009. Namespaces is a set of features within Vault Enterprise that allows
  22010. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  22011. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  22012. This will default to Vault.Namespace field if set, or empty otherwise
  22013. type: string
  22014. tokenSecretRef:
  22015. description: TokenSecretRef authenticates with Vault by presenting a token.
  22016. properties:
  22017. key:
  22018. description: |-
  22019. A key in the referenced Secret.
  22020. Some instances of this field may be defaulted, in others it may be required.
  22021. maxLength: 253
  22022. minLength: 1
  22023. pattern: ^[-._a-zA-Z0-9]+$
  22024. type: string
  22025. name:
  22026. description: The name of the Secret resource being referred to.
  22027. maxLength: 253
  22028. minLength: 1
  22029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22030. type: string
  22031. namespace:
  22032. description: |-
  22033. The namespace of the Secret resource being referred to.
  22034. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22035. maxLength: 63
  22036. minLength: 1
  22037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22038. type: string
  22039. type: object
  22040. userPass:
  22041. description: UserPass authenticates with Vault by passing username/password pair
  22042. properties:
  22043. path:
  22044. default: userpass
  22045. description: |-
  22046. Path where the UserPassword authentication backend is mounted
  22047. in Vault, e.g: "userpass"
  22048. type: string
  22049. secretRef:
  22050. description: |-
  22051. SecretRef to a key in a Secret resource containing password for the
  22052. user used to authenticate with Vault using the UserPass authentication
  22053. method
  22054. properties:
  22055. key:
  22056. description: |-
  22057. A key in the referenced Secret.
  22058. Some instances of this field may be defaulted, in others it may be required.
  22059. maxLength: 253
  22060. minLength: 1
  22061. pattern: ^[-._a-zA-Z0-9]+$
  22062. type: string
  22063. name:
  22064. description: The name of the Secret resource being referred to.
  22065. maxLength: 253
  22066. minLength: 1
  22067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22068. type: string
  22069. namespace:
  22070. description: |-
  22071. The namespace of the Secret resource being referred to.
  22072. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22073. maxLength: 63
  22074. minLength: 1
  22075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22076. type: string
  22077. type: object
  22078. username:
  22079. description: |-
  22080. Username is a username used to authenticate using the UserPass Vault
  22081. authentication method
  22082. type: string
  22083. required:
  22084. - path
  22085. - username
  22086. type: object
  22087. type: object
  22088. caBundle:
  22089. description: |-
  22090. PEM encoded CA bundle used to validate Vault server certificate. Only used
  22091. if the Server URL is using HTTPS protocol. This parameter is ignored for
  22092. plain HTTP protocol connection. If not set the system root certificates
  22093. are used to validate the TLS connection.
  22094. format: byte
  22095. type: string
  22096. caProvider:
  22097. description: The provider for the CA bundle to use to validate Vault server certificate.
  22098. properties:
  22099. key:
  22100. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22101. maxLength: 253
  22102. minLength: 1
  22103. pattern: ^[-._a-zA-Z0-9]+$
  22104. type: string
  22105. name:
  22106. description: The name of the object located at the provider type.
  22107. maxLength: 253
  22108. minLength: 1
  22109. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22110. type: string
  22111. namespace:
  22112. description: |-
  22113. The namespace the Provider type is in.
  22114. Can only be defined when used in a ClusterSecretStore.
  22115. maxLength: 63
  22116. minLength: 1
  22117. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22118. type: string
  22119. type:
  22120. description: The type of provider to use such as "Secret", or "ConfigMap".
  22121. enum:
  22122. - Secret
  22123. - ConfigMap
  22124. type: string
  22125. required:
  22126. - name
  22127. - type
  22128. type: object
  22129. checkAndSet:
  22130. description: |-
  22131. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  22132. Only applies to Vault KV v2 stores. When enabled, write operations must include
  22133. the current version of the secret to prevent unintentional overwrites.
  22134. properties:
  22135. required:
  22136. description: |-
  22137. Required when true, all write operations must include a check-and-set parameter.
  22138. This helps prevent unintentional overwrites of secrets.
  22139. type: boolean
  22140. type: object
  22141. forwardInconsistent:
  22142. description: |-
  22143. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  22144. leader instead of simply retrying within a loop. This can increase performance if
  22145. the option is enabled serverside.
  22146. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  22147. type: boolean
  22148. headers:
  22149. additionalProperties:
  22150. type: string
  22151. description: Headers to be added in Vault request
  22152. type: object
  22153. namespace:
  22154. description: |-
  22155. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  22156. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  22157. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  22158. type: string
  22159. path:
  22160. description: |-
  22161. Path is the mount path of the Vault KV backend endpoint, e.g:
  22162. "secret". The v2 KV secret engine version specific "/data" path suffix
  22163. for fetching secrets from Vault is optional and will be appended
  22164. if not present in specified path.
  22165. type: string
  22166. readYourWrites:
  22167. description: |-
  22168. ReadYourWrites ensures isolated read-after-write semantics by
  22169. providing discovered cluster replication states in each request.
  22170. More information about eventual consistency in Vault can be found here
  22171. https://www.vaultproject.io/docs/enterprise/consistency
  22172. type: boolean
  22173. server:
  22174. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  22175. type: string
  22176. tls:
  22177. description: |-
  22178. The configuration used for client side related TLS communication, when the Vault server
  22179. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  22180. This parameter is ignored for plain HTTP protocol connection.
  22181. It's worth noting this configuration is different from the "TLS certificates auth method",
  22182. which is available under the `auth.cert` section.
  22183. properties:
  22184. certSecretRef:
  22185. description: |-
  22186. CertSecretRef is a certificate added to the transport layer
  22187. when communicating with the Vault server.
  22188. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  22189. properties:
  22190. key:
  22191. description: |-
  22192. A key in the referenced Secret.
  22193. Some instances of this field may be defaulted, in others it may be required.
  22194. maxLength: 253
  22195. minLength: 1
  22196. pattern: ^[-._a-zA-Z0-9]+$
  22197. type: string
  22198. name:
  22199. description: The name of the Secret resource being referred to.
  22200. maxLength: 253
  22201. minLength: 1
  22202. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22203. type: string
  22204. namespace:
  22205. description: |-
  22206. The namespace of the Secret resource being referred to.
  22207. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22208. maxLength: 63
  22209. minLength: 1
  22210. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22211. type: string
  22212. type: object
  22213. keySecretRef:
  22214. description: |-
  22215. KeySecretRef to a key in a Secret resource containing client private key
  22216. added to the transport layer when communicating with the Vault server.
  22217. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  22218. properties:
  22219. key:
  22220. description: |-
  22221. A key in the referenced Secret.
  22222. Some instances of this field may be defaulted, in others it may be required.
  22223. maxLength: 253
  22224. minLength: 1
  22225. pattern: ^[-._a-zA-Z0-9]+$
  22226. type: string
  22227. name:
  22228. description: The name of the Secret resource being referred to.
  22229. maxLength: 253
  22230. minLength: 1
  22231. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22232. type: string
  22233. namespace:
  22234. description: |-
  22235. The namespace of the Secret resource being referred to.
  22236. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22237. maxLength: 63
  22238. minLength: 1
  22239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22240. type: string
  22241. type: object
  22242. type: object
  22243. version:
  22244. default: v2
  22245. description: |-
  22246. Version is the Vault KV secret engine version. This can be either "v1" or
  22247. "v2". Version defaults to "v2".
  22248. enum:
  22249. - v1
  22250. - v2
  22251. type: string
  22252. required:
  22253. - server
  22254. type: object
  22255. volcengine:
  22256. description: Volcengine configures this store to sync secrets using the Volcengine provider
  22257. properties:
  22258. auth:
  22259. description: |-
  22260. Auth defines the authentication method to use.
  22261. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  22262. properties:
  22263. secretRef:
  22264. description: |-
  22265. SecretRef defines the static credentials to use for authentication.
  22266. If not set, IRSA is used.
  22267. properties:
  22268. accessKeyID:
  22269. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  22270. properties:
  22271. key:
  22272. description: |-
  22273. A key in the referenced Secret.
  22274. Some instances of this field may be defaulted, in others it may be required.
  22275. maxLength: 253
  22276. minLength: 1
  22277. pattern: ^[-._a-zA-Z0-9]+$
  22278. type: string
  22279. name:
  22280. description: The name of the Secret resource being referred to.
  22281. maxLength: 253
  22282. minLength: 1
  22283. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22284. type: string
  22285. namespace:
  22286. description: |-
  22287. The namespace of the Secret resource being referred to.
  22288. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22289. maxLength: 63
  22290. minLength: 1
  22291. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22292. type: string
  22293. type: object
  22294. secretAccessKey:
  22295. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  22296. properties:
  22297. key:
  22298. description: |-
  22299. A key in the referenced Secret.
  22300. Some instances of this field may be defaulted, in others it may be required.
  22301. maxLength: 253
  22302. minLength: 1
  22303. pattern: ^[-._a-zA-Z0-9]+$
  22304. type: string
  22305. name:
  22306. description: The name of the Secret resource being referred to.
  22307. maxLength: 253
  22308. minLength: 1
  22309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22310. type: string
  22311. namespace:
  22312. description: |-
  22313. The namespace of the Secret resource being referred to.
  22314. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22315. maxLength: 63
  22316. minLength: 1
  22317. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22318. type: string
  22319. type: object
  22320. token:
  22321. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  22322. properties:
  22323. key:
  22324. description: |-
  22325. A key in the referenced Secret.
  22326. Some instances of this field may be defaulted, in others it may be required.
  22327. maxLength: 253
  22328. minLength: 1
  22329. pattern: ^[-._a-zA-Z0-9]+$
  22330. type: string
  22331. name:
  22332. description: The name of the Secret resource being referred to.
  22333. maxLength: 253
  22334. minLength: 1
  22335. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22336. type: string
  22337. namespace:
  22338. description: |-
  22339. The namespace of the Secret resource being referred to.
  22340. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22341. maxLength: 63
  22342. minLength: 1
  22343. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22344. type: string
  22345. type: object
  22346. required:
  22347. - accessKeyID
  22348. - secretAccessKey
  22349. type: object
  22350. type: object
  22351. region:
  22352. description: Region specifies the Volcengine region to connect to.
  22353. type: string
  22354. required:
  22355. - region
  22356. type: object
  22357. webhook:
  22358. description: Webhook configures this store to sync secrets using a generic templated webhook
  22359. properties:
  22360. auth:
  22361. description: Auth specifies a authorization protocol. Only one protocol may be set.
  22362. maxProperties: 1
  22363. minProperties: 1
  22364. properties:
  22365. ntlm:
  22366. description: NTLMProtocol configures the store to use NTLM for auth
  22367. properties:
  22368. passwordSecret:
  22369. description: |-
  22370. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22371. In some instances, `key` is a required field.
  22372. properties:
  22373. key:
  22374. description: |-
  22375. A key in the referenced Secret.
  22376. Some instances of this field may be defaulted, in others it may be required.
  22377. maxLength: 253
  22378. minLength: 1
  22379. pattern: ^[-._a-zA-Z0-9]+$
  22380. type: string
  22381. name:
  22382. description: The name of the Secret resource being referred to.
  22383. maxLength: 253
  22384. minLength: 1
  22385. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22386. type: string
  22387. namespace:
  22388. description: |-
  22389. The namespace of the Secret resource being referred to.
  22390. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22391. maxLength: 63
  22392. minLength: 1
  22393. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22394. type: string
  22395. type: object
  22396. usernameSecret:
  22397. description: |-
  22398. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22399. In some instances, `key` is a required field.
  22400. properties:
  22401. key:
  22402. description: |-
  22403. A key in the referenced Secret.
  22404. Some instances of this field may be defaulted, in others it may be required.
  22405. maxLength: 253
  22406. minLength: 1
  22407. pattern: ^[-._a-zA-Z0-9]+$
  22408. type: string
  22409. name:
  22410. description: The name of the Secret resource being referred to.
  22411. maxLength: 253
  22412. minLength: 1
  22413. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22414. type: string
  22415. namespace:
  22416. description: |-
  22417. The namespace of the Secret resource being referred to.
  22418. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22419. maxLength: 63
  22420. minLength: 1
  22421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22422. type: string
  22423. type: object
  22424. required:
  22425. - passwordSecret
  22426. - usernameSecret
  22427. type: object
  22428. type: object
  22429. body:
  22430. description: Body
  22431. type: string
  22432. caBundle:
  22433. description: |-
  22434. PEM encoded CA bundle used to validate webhook server certificate. Only used
  22435. if the Server URL is using HTTPS protocol. This parameter is ignored for
  22436. plain HTTP protocol connection. If not set the system root certificates
  22437. are used to validate the TLS connection.
  22438. format: byte
  22439. type: string
  22440. caProvider:
  22441. description: The provider for the CA bundle to use to validate webhook server certificate.
  22442. properties:
  22443. key:
  22444. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22445. maxLength: 253
  22446. minLength: 1
  22447. pattern: ^[-._a-zA-Z0-9]+$
  22448. type: string
  22449. name:
  22450. description: The name of the object located at the provider type.
  22451. maxLength: 253
  22452. minLength: 1
  22453. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22454. type: string
  22455. namespace:
  22456. description: The namespace the Provider type is in.
  22457. maxLength: 63
  22458. minLength: 1
  22459. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22460. type: string
  22461. type:
  22462. description: The type of provider to use such as "Secret", or "ConfigMap".
  22463. enum:
  22464. - Secret
  22465. - ConfigMap
  22466. type: string
  22467. required:
  22468. - name
  22469. - type
  22470. type: object
  22471. headers:
  22472. additionalProperties:
  22473. type: string
  22474. description: Headers
  22475. type: object
  22476. method:
  22477. description: Webhook Method
  22478. type: string
  22479. result:
  22480. description: Result formatting
  22481. properties:
  22482. jsonPath:
  22483. description: Json path of return value
  22484. type: string
  22485. type: object
  22486. secrets:
  22487. description: |-
  22488. Secrets to fill in templates
  22489. These secrets will be passed to the templating function as key value pairs under the given name
  22490. items:
  22491. description: WebhookSecret defines a secret that will be passed to the webhook request.
  22492. properties:
  22493. name:
  22494. description: Name of this secret in templates
  22495. type: string
  22496. secretRef:
  22497. description: Secret ref to fill in credentials
  22498. properties:
  22499. key:
  22500. description: |-
  22501. A key in the referenced Secret.
  22502. Some instances of this field may be defaulted, in others it may be required.
  22503. maxLength: 253
  22504. minLength: 1
  22505. pattern: ^[-._a-zA-Z0-9]+$
  22506. type: string
  22507. name:
  22508. description: The name of the Secret resource being referred to.
  22509. maxLength: 253
  22510. minLength: 1
  22511. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22512. type: string
  22513. namespace:
  22514. description: |-
  22515. The namespace of the Secret resource being referred to.
  22516. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22517. maxLength: 63
  22518. minLength: 1
  22519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22520. type: string
  22521. type: object
  22522. required:
  22523. - name
  22524. - secretRef
  22525. type: object
  22526. type: array
  22527. timeout:
  22528. description: Timeout
  22529. type: string
  22530. url:
  22531. description: Webhook url to call
  22532. type: string
  22533. required:
  22534. - url
  22535. type: object
  22536. yandexcertificatemanager:
  22537. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  22538. properties:
  22539. apiEndpoint:
  22540. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  22541. type: string
  22542. auth:
  22543. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  22544. properties:
  22545. authorizedKeySecretRef:
  22546. description: The authorized key used for authentication
  22547. properties:
  22548. key:
  22549. description: |-
  22550. A key in the referenced Secret.
  22551. Some instances of this field may be defaulted, in others it may be required.
  22552. maxLength: 253
  22553. minLength: 1
  22554. pattern: ^[-._a-zA-Z0-9]+$
  22555. type: string
  22556. name:
  22557. description: The name of the Secret resource being referred to.
  22558. maxLength: 253
  22559. minLength: 1
  22560. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22561. type: string
  22562. namespace:
  22563. description: |-
  22564. The namespace of the Secret resource being referred to.
  22565. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22566. maxLength: 63
  22567. minLength: 1
  22568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22569. type: string
  22570. type: object
  22571. type: object
  22572. caProvider:
  22573. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  22574. properties:
  22575. certSecretRef:
  22576. description: |-
  22577. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22578. In some instances, `key` is a required field.
  22579. properties:
  22580. key:
  22581. description: |-
  22582. A key in the referenced Secret.
  22583. Some instances of this field may be defaulted, in others it may be required.
  22584. maxLength: 253
  22585. minLength: 1
  22586. pattern: ^[-._a-zA-Z0-9]+$
  22587. type: string
  22588. name:
  22589. description: The name of the Secret resource being referred to.
  22590. maxLength: 253
  22591. minLength: 1
  22592. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22593. type: string
  22594. namespace:
  22595. description: |-
  22596. The namespace of the Secret resource being referred to.
  22597. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22598. maxLength: 63
  22599. minLength: 1
  22600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22601. type: string
  22602. type: object
  22603. type: object
  22604. fetching:
  22605. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  22606. maxProperties: 1
  22607. minProperties: 1
  22608. properties:
  22609. byID:
  22610. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  22611. type: object
  22612. byName:
  22613. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  22614. properties:
  22615. folderID:
  22616. description: The folder to fetch secrets from
  22617. type: string
  22618. required:
  22619. - folderID
  22620. type: object
  22621. type: object
  22622. required:
  22623. - auth
  22624. type: object
  22625. yandexlockbox:
  22626. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  22627. properties:
  22628. apiEndpoint:
  22629. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  22630. type: string
  22631. auth:
  22632. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  22633. properties:
  22634. authorizedKeySecretRef:
  22635. description: The authorized key used for authentication
  22636. properties:
  22637. key:
  22638. description: |-
  22639. A key in the referenced Secret.
  22640. Some instances of this field may be defaulted, in others it may be required.
  22641. maxLength: 253
  22642. minLength: 1
  22643. pattern: ^[-._a-zA-Z0-9]+$
  22644. type: string
  22645. name:
  22646. description: The name of the Secret resource being referred to.
  22647. maxLength: 253
  22648. minLength: 1
  22649. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22650. type: string
  22651. namespace:
  22652. description: |-
  22653. The namespace of the Secret resource being referred to.
  22654. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22655. maxLength: 63
  22656. minLength: 1
  22657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22658. type: string
  22659. type: object
  22660. type: object
  22661. caProvider:
  22662. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  22663. properties:
  22664. certSecretRef:
  22665. description: |-
  22666. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22667. In some instances, `key` is a required field.
  22668. properties:
  22669. key:
  22670. description: |-
  22671. A key in the referenced Secret.
  22672. Some instances of this field may be defaulted, in others it may be required.
  22673. maxLength: 253
  22674. minLength: 1
  22675. pattern: ^[-._a-zA-Z0-9]+$
  22676. type: string
  22677. name:
  22678. description: The name of the Secret resource being referred to.
  22679. maxLength: 253
  22680. minLength: 1
  22681. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22682. type: string
  22683. namespace:
  22684. description: |-
  22685. The namespace of the Secret resource being referred to.
  22686. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22687. maxLength: 63
  22688. minLength: 1
  22689. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22690. type: string
  22691. type: object
  22692. type: object
  22693. fetching:
  22694. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  22695. maxProperties: 1
  22696. minProperties: 1
  22697. properties:
  22698. byID:
  22699. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  22700. type: object
  22701. byName:
  22702. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  22703. properties:
  22704. folderID:
  22705. description: The folder to fetch secrets from
  22706. type: string
  22707. required:
  22708. - folderID
  22709. type: object
  22710. type: object
  22711. required:
  22712. - auth
  22713. type: object
  22714. type: object
  22715. refreshInterval:
  22716. anyOf:
  22717. - type: integer
  22718. - type: string
  22719. description: |-
  22720. Used to configure store refresh interval. Accepts either an integer number
  22721. of seconds (legacy) or a Go duration string such as "1h" or "5m". Empty or
  22722. 0 will default to the controller config.
  22723. x-kubernetes-int-or-string: true
  22724. retrySettings:
  22725. description: Used to configure HTTP retries on failures.
  22726. properties:
  22727. maxRetries:
  22728. format: int32
  22729. type: integer
  22730. retryInterval:
  22731. type: string
  22732. type: object
  22733. required:
  22734. - provider
  22735. type: object
  22736. status:
  22737. description: SecretStoreStatus defines the observed state of the SecretStore.
  22738. properties:
  22739. capabilities:
  22740. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  22741. type: string
  22742. conditions:
  22743. items:
  22744. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  22745. properties:
  22746. lastTransitionTime:
  22747. format: date-time
  22748. type: string
  22749. message:
  22750. type: string
  22751. reason:
  22752. type: string
  22753. status:
  22754. type: string
  22755. type:
  22756. description: SecretStoreConditionType represents the condition of the SecretStore.
  22757. type: string
  22758. required:
  22759. - status
  22760. - type
  22761. type: object
  22762. type: array
  22763. type: object
  22764. type: object
  22765. served: true
  22766. storage: true
  22767. subresources:
  22768. status: {}
  22769. - additionalPrinterColumns:
  22770. - jsonPath: .metadata.creationTimestamp
  22771. name: AGE
  22772. type: date
  22773. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  22774. name: Status
  22775. type: string
  22776. - jsonPath: .status.capabilities
  22777. name: Capabilities
  22778. type: string
  22779. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  22780. name: Ready
  22781. type: string
  22782. deprecated: true
  22783. name: v1beta1
  22784. schema:
  22785. openAPIV3Schema:
  22786. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  22787. properties:
  22788. apiVersion:
  22789. description: |-
  22790. APIVersion defines the versioned schema of this representation of an object.
  22791. Servers should convert recognized schemas to the latest internal value, and
  22792. may reject unrecognized values.
  22793. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  22794. type: string
  22795. kind:
  22796. description: |-
  22797. Kind is a string value representing the REST resource this object represents.
  22798. Servers may infer this from the endpoint the client submits requests to.
  22799. Cannot be updated.
  22800. In CamelCase.
  22801. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  22802. type: string
  22803. metadata:
  22804. type: object
  22805. spec:
  22806. description: SecretStoreSpec defines the desired state of SecretStore.
  22807. properties:
  22808. conditions:
  22809. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  22810. items:
  22811. description: |-
  22812. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  22813. for a ClusterSecretStore instance.
  22814. properties:
  22815. namespaceRegexes:
  22816. description: Choose namespaces by using regex matching
  22817. items:
  22818. type: string
  22819. type: array
  22820. namespaceSelector:
  22821. description: Choose namespace using a labelSelector
  22822. properties:
  22823. matchExpressions:
  22824. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  22825. items:
  22826. description: |-
  22827. A label selector requirement is a selector that contains values, a key, and an operator that
  22828. relates the key and values.
  22829. properties:
  22830. key:
  22831. description: key is the label key that the selector applies to.
  22832. type: string
  22833. operator:
  22834. description: |-
  22835. operator represents a key's relationship to a set of values.
  22836. Valid operators are In, NotIn, Exists and DoesNotExist.
  22837. type: string
  22838. values:
  22839. description: |-
  22840. values is an array of string values. If the operator is In or NotIn,
  22841. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  22842. the values array must be empty. This array is replaced during a strategic
  22843. merge patch.
  22844. items:
  22845. type: string
  22846. type: array
  22847. x-kubernetes-list-type: atomic
  22848. required:
  22849. - key
  22850. - operator
  22851. type: object
  22852. type: array
  22853. x-kubernetes-list-type: atomic
  22854. matchLabels:
  22855. additionalProperties:
  22856. type: string
  22857. description: |-
  22858. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  22859. map is equivalent to an element of matchExpressions, whose key field is "key", the
  22860. operator is "In", and the values array contains only "value". The requirements are ANDed.
  22861. type: object
  22862. type: object
  22863. x-kubernetes-map-type: atomic
  22864. namespaces:
  22865. description: Choose namespaces by name
  22866. items:
  22867. maxLength: 63
  22868. minLength: 1
  22869. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22870. type: string
  22871. type: array
  22872. type: object
  22873. type: array
  22874. controller:
  22875. description: |-
  22876. Used to select the correct ESO controller (think: ingress.ingressClassName)
  22877. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  22878. type: string
  22879. provider:
  22880. description: Used to configure the provider. Only one provider may be set
  22881. maxProperties: 1
  22882. minProperties: 1
  22883. properties:
  22884. akeyless:
  22885. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  22886. properties:
  22887. akeylessGWApiURL:
  22888. description: Akeyless GW API Url from which the secrets to be fetched from.
  22889. type: string
  22890. authSecretRef:
  22891. description: Auth configures how the operator authenticates with Akeyless.
  22892. properties:
  22893. kubernetesAuth:
  22894. description: |-
  22895. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  22896. token stored in the named Secret resource.
  22897. properties:
  22898. accessID:
  22899. description: the Akeyless Kubernetes auth-method access-id
  22900. type: string
  22901. k8sConfName:
  22902. description: Kubernetes-auth configuration name in Akeyless-Gateway
  22903. type: string
  22904. secretRef:
  22905. description: |-
  22906. Optional secret field containing a Kubernetes ServiceAccount JWT used
  22907. for authenticating with Akeyless. If a name is specified without a key,
  22908. `token` is the default. If one is not specified, the one bound to
  22909. the controller will be used.
  22910. properties:
  22911. key:
  22912. description: |-
  22913. A key in the referenced Secret.
  22914. Some instances of this field may be defaulted, in others it may be required.
  22915. maxLength: 253
  22916. minLength: 1
  22917. pattern: ^[-._a-zA-Z0-9]+$
  22918. type: string
  22919. name:
  22920. description: The name of the Secret resource being referred to.
  22921. maxLength: 253
  22922. minLength: 1
  22923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22924. type: string
  22925. namespace:
  22926. description: |-
  22927. The namespace of the Secret resource being referred to.
  22928. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22929. maxLength: 63
  22930. minLength: 1
  22931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22932. type: string
  22933. type: object
  22934. serviceAccountRef:
  22935. description: |-
  22936. Optional service account field containing the name of a kubernetes ServiceAccount.
  22937. If the service account is specified, the service account secret token JWT will be used
  22938. for authenticating with Akeyless. If the service account selector is not supplied,
  22939. the secretRef will be used instead.
  22940. properties:
  22941. audiences:
  22942. description: |-
  22943. Audience specifies the `aud` claim for the service account token
  22944. Some providers automatically extend the audience field based on well-known annotations for workload
  22945. identity (e.g. IRSA or GCP Workload Identity)
  22946. items:
  22947. type: string
  22948. type: array
  22949. name:
  22950. description: The name of the ServiceAccount resource being referred to.
  22951. maxLength: 253
  22952. minLength: 1
  22953. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22954. type: string
  22955. namespace:
  22956. description: |-
  22957. Namespace of the resource being referred to.
  22958. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22959. maxLength: 63
  22960. minLength: 1
  22961. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22962. type: string
  22963. required:
  22964. - name
  22965. type: object
  22966. required:
  22967. - accessID
  22968. - k8sConfName
  22969. type: object
  22970. secretRef:
  22971. description: |-
  22972. Reference to a Secret that contains the details
  22973. to authenticate with Akeyless.
  22974. properties:
  22975. accessID:
  22976. description: The SecretAccessID is used for authentication
  22977. properties:
  22978. key:
  22979. description: |-
  22980. A key in the referenced Secret.
  22981. Some instances of this field may be defaulted, in others it may be required.
  22982. maxLength: 253
  22983. minLength: 1
  22984. pattern: ^[-._a-zA-Z0-9]+$
  22985. type: string
  22986. name:
  22987. description: The name of the Secret resource being referred to.
  22988. maxLength: 253
  22989. minLength: 1
  22990. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22991. type: string
  22992. namespace:
  22993. description: |-
  22994. The namespace of the Secret resource being referred to.
  22995. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22996. maxLength: 63
  22997. minLength: 1
  22998. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22999. type: string
  23000. type: object
  23001. accessType:
  23002. description: |-
  23003. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23004. In some instances, `key` is a required field.
  23005. properties:
  23006. key:
  23007. description: |-
  23008. A key in the referenced Secret.
  23009. Some instances of this field may be defaulted, in others it may be required.
  23010. maxLength: 253
  23011. minLength: 1
  23012. pattern: ^[-._a-zA-Z0-9]+$
  23013. type: string
  23014. name:
  23015. description: The name of the Secret resource being referred to.
  23016. maxLength: 253
  23017. minLength: 1
  23018. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23019. type: string
  23020. namespace:
  23021. description: |-
  23022. The namespace of the Secret resource being referred to.
  23023. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23024. maxLength: 63
  23025. minLength: 1
  23026. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23027. type: string
  23028. type: object
  23029. accessTypeParam:
  23030. description: |-
  23031. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  23032. In some instances, `key` is a required field.
  23033. properties:
  23034. key:
  23035. description: |-
  23036. A key in the referenced Secret.
  23037. Some instances of this field may be defaulted, in others it may be required.
  23038. maxLength: 253
  23039. minLength: 1
  23040. pattern: ^[-._a-zA-Z0-9]+$
  23041. type: string
  23042. name:
  23043. description: The name of the Secret resource being referred to.
  23044. maxLength: 253
  23045. minLength: 1
  23046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23047. type: string
  23048. namespace:
  23049. description: |-
  23050. The namespace of the Secret resource being referred to.
  23051. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23052. maxLength: 63
  23053. minLength: 1
  23054. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23055. type: string
  23056. type: object
  23057. type: object
  23058. type: object
  23059. caBundle:
  23060. description: |-
  23061. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  23062. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  23063. are used to validate the TLS connection.
  23064. format: byte
  23065. type: string
  23066. caProvider:
  23067. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  23068. properties:
  23069. key:
  23070. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23071. maxLength: 253
  23072. minLength: 1
  23073. pattern: ^[-._a-zA-Z0-9]+$
  23074. type: string
  23075. name:
  23076. description: The name of the object located at the provider type.
  23077. maxLength: 253
  23078. minLength: 1
  23079. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23080. type: string
  23081. namespace:
  23082. description: |-
  23083. The namespace the Provider type is in.
  23084. Can only be defined when used in a ClusterSecretStore.
  23085. maxLength: 63
  23086. minLength: 1
  23087. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23088. type: string
  23089. type:
  23090. description: The type of provider to use such as "Secret", or "ConfigMap".
  23091. enum:
  23092. - Secret
  23093. - ConfigMap
  23094. type: string
  23095. required:
  23096. - name
  23097. - type
  23098. type: object
  23099. required:
  23100. - akeylessGWApiURL
  23101. - authSecretRef
  23102. type: object
  23103. alibaba:
  23104. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  23105. properties:
  23106. auth:
  23107. description: AlibabaAuth contains a secretRef for credentials.
  23108. properties:
  23109. rrsa:
  23110. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  23111. properties:
  23112. oidcProviderArn:
  23113. type: string
  23114. oidcTokenFilePath:
  23115. type: string
  23116. roleArn:
  23117. type: string
  23118. sessionName:
  23119. type: string
  23120. required:
  23121. - oidcProviderArn
  23122. - oidcTokenFilePath
  23123. - roleArn
  23124. - sessionName
  23125. type: object
  23126. secretRef:
  23127. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  23128. properties:
  23129. accessKeyIDSecretRef:
  23130. description: The AccessKeyID is used for authentication
  23131. properties:
  23132. key:
  23133. description: |-
  23134. A key in the referenced Secret.
  23135. Some instances of this field may be defaulted, in others it may be required.
  23136. maxLength: 253
  23137. minLength: 1
  23138. pattern: ^[-._a-zA-Z0-9]+$
  23139. type: string
  23140. name:
  23141. description: The name of the Secret resource being referred to.
  23142. maxLength: 253
  23143. minLength: 1
  23144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23145. type: string
  23146. namespace:
  23147. description: |-
  23148. The namespace of the Secret resource being referred to.
  23149. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23150. maxLength: 63
  23151. minLength: 1
  23152. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23153. type: string
  23154. type: object
  23155. accessKeySecretSecretRef:
  23156. description: The AccessKeySecret is used for authentication
  23157. properties:
  23158. key:
  23159. description: |-
  23160. A key in the referenced Secret.
  23161. Some instances of this field may be defaulted, in others it may be required.
  23162. maxLength: 253
  23163. minLength: 1
  23164. pattern: ^[-._a-zA-Z0-9]+$
  23165. type: string
  23166. name:
  23167. description: The name of the Secret resource being referred to.
  23168. maxLength: 253
  23169. minLength: 1
  23170. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23171. type: string
  23172. namespace:
  23173. description: |-
  23174. The namespace of the Secret resource being referred to.
  23175. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23176. maxLength: 63
  23177. minLength: 1
  23178. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23179. type: string
  23180. type: object
  23181. required:
  23182. - accessKeyIDSecretRef
  23183. - accessKeySecretSecretRef
  23184. type: object
  23185. type: object
  23186. regionID:
  23187. description: Alibaba Region to be used for the provider
  23188. type: string
  23189. required:
  23190. - auth
  23191. - regionID
  23192. type: object
  23193. aws:
  23194. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  23195. properties:
  23196. additionalRoles:
  23197. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  23198. items:
  23199. type: string
  23200. type: array
  23201. auth:
  23202. description: |-
  23203. Auth defines the information necessary to authenticate against AWS
  23204. if not set aws sdk will infer credentials from your environment
  23205. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  23206. properties:
  23207. jwt:
  23208. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  23209. properties:
  23210. serviceAccountRef:
  23211. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  23212. properties:
  23213. audiences:
  23214. description: |-
  23215. Audience specifies the `aud` claim for the service account token
  23216. Some providers automatically extend the audience field based on well-known annotations for workload
  23217. identity (e.g. IRSA or GCP Workload Identity)
  23218. items:
  23219. type: string
  23220. type: array
  23221. name:
  23222. description: The name of the ServiceAccount resource being referred to.
  23223. maxLength: 253
  23224. minLength: 1
  23225. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23226. type: string
  23227. namespace:
  23228. description: |-
  23229. Namespace of the resource being referred to.
  23230. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23231. maxLength: 63
  23232. minLength: 1
  23233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23234. type: string
  23235. required:
  23236. - name
  23237. type: object
  23238. type: object
  23239. secretRef:
  23240. description: |-
  23241. AWSAuthSecretRef holds secret references for AWS credentials
  23242. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  23243. properties:
  23244. accessKeyIDSecretRef:
  23245. description: The AccessKeyID is used for authentication
  23246. properties:
  23247. key:
  23248. description: |-
  23249. A key in the referenced Secret.
  23250. Some instances of this field may be defaulted, in others it may be required.
  23251. maxLength: 253
  23252. minLength: 1
  23253. pattern: ^[-._a-zA-Z0-9]+$
  23254. type: string
  23255. name:
  23256. description: The name of the Secret resource being referred to.
  23257. maxLength: 253
  23258. minLength: 1
  23259. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23260. type: string
  23261. namespace:
  23262. description: |-
  23263. The namespace of the Secret resource being referred to.
  23264. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23265. maxLength: 63
  23266. minLength: 1
  23267. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23268. type: string
  23269. type: object
  23270. secretAccessKeySecretRef:
  23271. description: The SecretAccessKey is used for authentication
  23272. properties:
  23273. key:
  23274. description: |-
  23275. A key in the referenced Secret.
  23276. Some instances of this field may be defaulted, in others it may be required.
  23277. maxLength: 253
  23278. minLength: 1
  23279. pattern: ^[-._a-zA-Z0-9]+$
  23280. type: string
  23281. name:
  23282. description: The name of the Secret resource being referred to.
  23283. maxLength: 253
  23284. minLength: 1
  23285. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23286. type: string
  23287. namespace:
  23288. description: |-
  23289. The namespace of the Secret resource being referred to.
  23290. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23291. maxLength: 63
  23292. minLength: 1
  23293. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23294. type: string
  23295. type: object
  23296. sessionTokenSecretRef:
  23297. description: |-
  23298. The SessionToken used for authentication
  23299. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  23300. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  23301. properties:
  23302. key:
  23303. description: |-
  23304. A key in the referenced Secret.
  23305. Some instances of this field may be defaulted, in others it may be required.
  23306. maxLength: 253
  23307. minLength: 1
  23308. pattern: ^[-._a-zA-Z0-9]+$
  23309. type: string
  23310. name:
  23311. description: The name of the Secret resource being referred to.
  23312. maxLength: 253
  23313. minLength: 1
  23314. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23315. type: string
  23316. namespace:
  23317. description: |-
  23318. The namespace of the Secret resource being referred to.
  23319. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23320. maxLength: 63
  23321. minLength: 1
  23322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23323. type: string
  23324. type: object
  23325. type: object
  23326. type: object
  23327. externalID:
  23328. description: AWS External ID set on assumed IAM roles
  23329. type: string
  23330. prefix:
  23331. description: Prefix adds a prefix to all retrieved values.
  23332. type: string
  23333. region:
  23334. description: AWS Region to be used for the provider
  23335. type: string
  23336. role:
  23337. description: Role is a Role ARN which the provider will assume
  23338. type: string
  23339. secretsManager:
  23340. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  23341. properties:
  23342. forceDeleteWithoutRecovery:
  23343. description: |-
  23344. Specifies whether to delete the secret without any recovery window. You
  23345. can't use both this parameter and RecoveryWindowInDays in the same call.
  23346. If you don't use either, then by default Secrets Manager uses a 30 day
  23347. recovery window.
  23348. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  23349. type: boolean
  23350. recoveryWindowInDays:
  23351. description: |-
  23352. The number of days from 7 to 30 that Secrets Manager waits before
  23353. permanently deleting the secret. You can't use both this parameter and
  23354. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  23355. then by default Secrets Manager uses a 30 day recovery window.
  23356. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  23357. format: int64
  23358. type: integer
  23359. type: object
  23360. service:
  23361. description: Service defines which service should be used to fetch the secrets
  23362. enum:
  23363. - SecretsManager
  23364. - ParameterStore
  23365. type: string
  23366. sessionTags:
  23367. description: AWS STS assume role session tags
  23368. items:
  23369. description: Tag defines a tag key and value for AWS resources.
  23370. properties:
  23371. key:
  23372. type: string
  23373. value:
  23374. type: string
  23375. required:
  23376. - key
  23377. - value
  23378. type: object
  23379. type: array
  23380. transitiveTagKeys:
  23381. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  23382. items:
  23383. type: string
  23384. type: array
  23385. required:
  23386. - region
  23387. - service
  23388. type: object
  23389. azurekv:
  23390. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  23391. properties:
  23392. authSecretRef:
  23393. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  23394. properties:
  23395. clientCertificate:
  23396. description: The Azure ClientCertificate of the service principle used for authentication.
  23397. properties:
  23398. key:
  23399. description: |-
  23400. A key in the referenced Secret.
  23401. Some instances of this field may be defaulted, in others it may be required.
  23402. maxLength: 253
  23403. minLength: 1
  23404. pattern: ^[-._a-zA-Z0-9]+$
  23405. type: string
  23406. name:
  23407. description: The name of the Secret resource being referred to.
  23408. maxLength: 253
  23409. minLength: 1
  23410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23411. type: string
  23412. namespace:
  23413. description: |-
  23414. The namespace of the Secret resource being referred to.
  23415. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23416. maxLength: 63
  23417. minLength: 1
  23418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23419. type: string
  23420. type: object
  23421. clientId:
  23422. description: The Azure clientId of the service principle or managed identity used for authentication.
  23423. properties:
  23424. key:
  23425. description: |-
  23426. A key in the referenced Secret.
  23427. Some instances of this field may be defaulted, in others it may be required.
  23428. maxLength: 253
  23429. minLength: 1
  23430. pattern: ^[-._a-zA-Z0-9]+$
  23431. type: string
  23432. name:
  23433. description: The name of the Secret resource being referred to.
  23434. maxLength: 253
  23435. minLength: 1
  23436. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23437. type: string
  23438. namespace:
  23439. description: |-
  23440. The namespace of the Secret resource being referred to.
  23441. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23442. maxLength: 63
  23443. minLength: 1
  23444. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23445. type: string
  23446. type: object
  23447. clientSecret:
  23448. description: The Azure ClientSecret of the service principle used for authentication.
  23449. properties:
  23450. key:
  23451. description: |-
  23452. A key in the referenced Secret.
  23453. Some instances of this field may be defaulted, in others it may be required.
  23454. maxLength: 253
  23455. minLength: 1
  23456. pattern: ^[-._a-zA-Z0-9]+$
  23457. type: string
  23458. name:
  23459. description: The name of the Secret resource being referred to.
  23460. maxLength: 253
  23461. minLength: 1
  23462. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23463. type: string
  23464. namespace:
  23465. description: |-
  23466. The namespace of the Secret resource being referred to.
  23467. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23468. maxLength: 63
  23469. minLength: 1
  23470. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23471. type: string
  23472. type: object
  23473. tenantId:
  23474. description: The Azure tenantId of the managed identity used for authentication.
  23475. properties:
  23476. key:
  23477. description: |-
  23478. A key in the referenced Secret.
  23479. Some instances of this field may be defaulted, in others it may be required.
  23480. maxLength: 253
  23481. minLength: 1
  23482. pattern: ^[-._a-zA-Z0-9]+$
  23483. type: string
  23484. name:
  23485. description: The name of the Secret resource being referred to.
  23486. maxLength: 253
  23487. minLength: 1
  23488. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23489. type: string
  23490. namespace:
  23491. description: |-
  23492. The namespace of the Secret resource being referred to.
  23493. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23494. maxLength: 63
  23495. minLength: 1
  23496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23497. type: string
  23498. type: object
  23499. type: object
  23500. authType:
  23501. default: ServicePrincipal
  23502. description: |-
  23503. Auth type defines how to authenticate to the keyvault service.
  23504. Valid values are:
  23505. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  23506. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  23507. enum:
  23508. - ServicePrincipal
  23509. - ManagedIdentity
  23510. - WorkloadIdentity
  23511. type: string
  23512. environmentType:
  23513. default: PublicCloud
  23514. description: |-
  23515. EnvironmentType specifies the Azure cloud environment endpoints to use for
  23516. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  23517. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  23518. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  23519. enum:
  23520. - PublicCloud
  23521. - USGovernmentCloud
  23522. - ChinaCloud
  23523. - GermanCloud
  23524. type: string
  23525. identityId:
  23526. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  23527. type: string
  23528. serviceAccountRef:
  23529. description: |-
  23530. ServiceAccountRef specified the service account
  23531. that should be used when authenticating with WorkloadIdentity.
  23532. properties:
  23533. audiences:
  23534. description: |-
  23535. Audience specifies the `aud` claim for the service account token
  23536. Some providers automatically extend the audience field based on well-known annotations for workload
  23537. identity (e.g. IRSA or GCP Workload Identity)
  23538. items:
  23539. type: string
  23540. type: array
  23541. name:
  23542. description: The name of the ServiceAccount resource being referred to.
  23543. maxLength: 253
  23544. minLength: 1
  23545. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23546. type: string
  23547. namespace:
  23548. description: |-
  23549. Namespace of the resource being referred to.
  23550. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23551. maxLength: 63
  23552. minLength: 1
  23553. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23554. type: string
  23555. required:
  23556. - name
  23557. type: object
  23558. tenantId:
  23559. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  23560. type: string
  23561. vaultUrl:
  23562. description: Vault Url from which the secrets to be fetched from.
  23563. type: string
  23564. required:
  23565. - vaultUrl
  23566. type: object
  23567. beyondtrust:
  23568. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  23569. properties:
  23570. auth:
  23571. description: Auth configures how the operator authenticates with Beyondtrust.
  23572. properties:
  23573. apiKey:
  23574. description: APIKey If not provided then ClientID/ClientSecret become required.
  23575. properties:
  23576. secretRef:
  23577. description: SecretRef references a key in a secret that will be used as value.
  23578. properties:
  23579. key:
  23580. description: |-
  23581. A key in the referenced Secret.
  23582. Some instances of this field may be defaulted, in others it may be required.
  23583. maxLength: 253
  23584. minLength: 1
  23585. pattern: ^[-._a-zA-Z0-9]+$
  23586. type: string
  23587. name:
  23588. description: The name of the Secret resource being referred to.
  23589. maxLength: 253
  23590. minLength: 1
  23591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23592. type: string
  23593. namespace:
  23594. description: |-
  23595. The namespace of the Secret resource being referred to.
  23596. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23597. maxLength: 63
  23598. minLength: 1
  23599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23600. type: string
  23601. type: object
  23602. value:
  23603. description: Value can be specified directly to set a value without using a secret.
  23604. type: string
  23605. type: object
  23606. certificate:
  23607. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  23608. properties:
  23609. secretRef:
  23610. description: SecretRef references a key in a secret that will be used as value.
  23611. properties:
  23612. key:
  23613. description: |-
  23614. A key in the referenced Secret.
  23615. Some instances of this field may be defaulted, in others it may be required.
  23616. maxLength: 253
  23617. minLength: 1
  23618. pattern: ^[-._a-zA-Z0-9]+$
  23619. type: string
  23620. name:
  23621. description: The name of the Secret resource being referred to.
  23622. maxLength: 253
  23623. minLength: 1
  23624. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23625. type: string
  23626. namespace:
  23627. description: |-
  23628. The namespace of the Secret resource being referred to.
  23629. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23630. maxLength: 63
  23631. minLength: 1
  23632. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23633. type: string
  23634. type: object
  23635. value:
  23636. description: Value can be specified directly to set a value without using a secret.
  23637. type: string
  23638. type: object
  23639. certificateKey:
  23640. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  23641. properties:
  23642. secretRef:
  23643. description: SecretRef references a key in a secret that will be used as value.
  23644. properties:
  23645. key:
  23646. description: |-
  23647. A key in the referenced Secret.
  23648. Some instances of this field may be defaulted, in others it may be required.
  23649. maxLength: 253
  23650. minLength: 1
  23651. pattern: ^[-._a-zA-Z0-9]+$
  23652. type: string
  23653. name:
  23654. description: The name of the Secret resource being referred to.
  23655. maxLength: 253
  23656. minLength: 1
  23657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23658. type: string
  23659. namespace:
  23660. description: |-
  23661. The namespace of the Secret resource being referred to.
  23662. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23663. maxLength: 63
  23664. minLength: 1
  23665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23666. type: string
  23667. type: object
  23668. value:
  23669. description: Value can be specified directly to set a value without using a secret.
  23670. type: string
  23671. type: object
  23672. clientId:
  23673. description: ClientID is the API OAuth Client ID.
  23674. properties:
  23675. secretRef:
  23676. description: SecretRef references a key in a secret that will be used as value.
  23677. properties:
  23678. key:
  23679. description: |-
  23680. A key in the referenced Secret.
  23681. Some instances of this field may be defaulted, in others it may be required.
  23682. maxLength: 253
  23683. minLength: 1
  23684. pattern: ^[-._a-zA-Z0-9]+$
  23685. type: string
  23686. name:
  23687. description: The name of the Secret resource being referred to.
  23688. maxLength: 253
  23689. minLength: 1
  23690. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23691. type: string
  23692. namespace:
  23693. description: |-
  23694. The namespace of the Secret resource being referred to.
  23695. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23696. maxLength: 63
  23697. minLength: 1
  23698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23699. type: string
  23700. type: object
  23701. value:
  23702. description: Value can be specified directly to set a value without using a secret.
  23703. type: string
  23704. type: object
  23705. clientSecret:
  23706. description: ClientSecret is the API OAuth Client Secret.
  23707. properties:
  23708. secretRef:
  23709. description: SecretRef references a key in a secret that will be used as value.
  23710. properties:
  23711. key:
  23712. description: |-
  23713. A key in the referenced Secret.
  23714. Some instances of this field may be defaulted, in others it may be required.
  23715. maxLength: 253
  23716. minLength: 1
  23717. pattern: ^[-._a-zA-Z0-9]+$
  23718. type: string
  23719. name:
  23720. description: The name of the Secret resource being referred to.
  23721. maxLength: 253
  23722. minLength: 1
  23723. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23724. type: string
  23725. namespace:
  23726. description: |-
  23727. The namespace of the Secret resource being referred to.
  23728. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23729. maxLength: 63
  23730. minLength: 1
  23731. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23732. type: string
  23733. type: object
  23734. value:
  23735. description: Value can be specified directly to set a value without using a secret.
  23736. type: string
  23737. type: object
  23738. type: object
  23739. server:
  23740. description: Auth configures how API server works.
  23741. properties:
  23742. apiUrl:
  23743. type: string
  23744. apiVersion:
  23745. type: string
  23746. clientTimeOutSeconds:
  23747. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  23748. type: integer
  23749. decrypt:
  23750. default: true
  23751. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  23752. type: boolean
  23753. retrievalType:
  23754. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  23755. type: string
  23756. separator:
  23757. description: A character that separates the folder names.
  23758. type: string
  23759. verifyCA:
  23760. type: boolean
  23761. required:
  23762. - apiUrl
  23763. - verifyCA
  23764. type: object
  23765. required:
  23766. - auth
  23767. - server
  23768. type: object
  23769. bitwardensecretsmanager:
  23770. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  23771. properties:
  23772. apiURL:
  23773. type: string
  23774. auth:
  23775. description: |-
  23776. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  23777. Make sure that the token being used has permissions on the given secret.
  23778. properties:
  23779. secretRef:
  23780. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  23781. properties:
  23782. credentials:
  23783. description: AccessToken used for the bitwarden instance.
  23784. properties:
  23785. key:
  23786. description: |-
  23787. A key in the referenced Secret.
  23788. Some instances of this field may be defaulted, in others it may be required.
  23789. maxLength: 253
  23790. minLength: 1
  23791. pattern: ^[-._a-zA-Z0-9]+$
  23792. type: string
  23793. name:
  23794. description: The name of the Secret resource being referred to.
  23795. maxLength: 253
  23796. minLength: 1
  23797. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23798. type: string
  23799. namespace:
  23800. description: |-
  23801. The namespace of the Secret resource being referred to.
  23802. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23803. maxLength: 63
  23804. minLength: 1
  23805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23806. type: string
  23807. type: object
  23808. required:
  23809. - credentials
  23810. type: object
  23811. required:
  23812. - secretRef
  23813. type: object
  23814. bitwardenServerSDKURL:
  23815. type: string
  23816. caBundle:
  23817. description: |-
  23818. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  23819. can be performed.
  23820. type: string
  23821. caProvider:
  23822. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  23823. properties:
  23824. key:
  23825. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23826. maxLength: 253
  23827. minLength: 1
  23828. pattern: ^[-._a-zA-Z0-9]+$
  23829. type: string
  23830. name:
  23831. description: The name of the object located at the provider type.
  23832. maxLength: 253
  23833. minLength: 1
  23834. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23835. type: string
  23836. namespace:
  23837. description: |-
  23838. The namespace the Provider type is in.
  23839. Can only be defined when used in a ClusterSecretStore.
  23840. maxLength: 63
  23841. minLength: 1
  23842. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23843. type: string
  23844. type:
  23845. description: The type of provider to use such as "Secret", or "ConfigMap".
  23846. enum:
  23847. - Secret
  23848. - ConfigMap
  23849. type: string
  23850. required:
  23851. - name
  23852. - type
  23853. type: object
  23854. identityURL:
  23855. type: string
  23856. organizationID:
  23857. description: OrganizationID determines which organization this secret store manages.
  23858. type: string
  23859. projectID:
  23860. description: ProjectID determines which project this secret store manages.
  23861. type: string
  23862. required:
  23863. - auth
  23864. - organizationID
  23865. - projectID
  23866. type: object
  23867. chef:
  23868. description: Chef configures this store to sync secrets with chef server
  23869. properties:
  23870. auth:
  23871. description: Auth defines the information necessary to authenticate against chef Server
  23872. properties:
  23873. secretRef:
  23874. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  23875. properties:
  23876. privateKeySecretRef:
  23877. description: SecretKey is the Signing Key in PEM format, used for authentication.
  23878. properties:
  23879. key:
  23880. description: |-
  23881. A key in the referenced Secret.
  23882. Some instances of this field may be defaulted, in others it may be required.
  23883. maxLength: 253
  23884. minLength: 1
  23885. pattern: ^[-._a-zA-Z0-9]+$
  23886. type: string
  23887. name:
  23888. description: The name of the Secret resource being referred to.
  23889. maxLength: 253
  23890. minLength: 1
  23891. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23892. type: string
  23893. namespace:
  23894. description: |-
  23895. The namespace of the Secret resource being referred to.
  23896. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23897. maxLength: 63
  23898. minLength: 1
  23899. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23900. type: string
  23901. type: object
  23902. required:
  23903. - privateKeySecretRef
  23904. type: object
  23905. required:
  23906. - secretRef
  23907. type: object
  23908. serverUrl:
  23909. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  23910. type: string
  23911. username:
  23912. description: UserName should be the user ID on the chef server
  23913. type: string
  23914. required:
  23915. - auth
  23916. - serverUrl
  23917. - username
  23918. type: object
  23919. cloudrusm:
  23920. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  23921. properties:
  23922. auth:
  23923. description: CSMAuth contains a secretRef for credentials.
  23924. properties:
  23925. secretRef:
  23926. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  23927. properties:
  23928. accessKeyIDSecretRef:
  23929. description: The AccessKeyID is used for authentication
  23930. properties:
  23931. key:
  23932. description: |-
  23933. A key in the referenced Secret.
  23934. Some instances of this field may be defaulted, in others it may be required.
  23935. maxLength: 253
  23936. minLength: 1
  23937. pattern: ^[-._a-zA-Z0-9]+$
  23938. type: string
  23939. name:
  23940. description: The name of the Secret resource being referred to.
  23941. maxLength: 253
  23942. minLength: 1
  23943. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23944. type: string
  23945. namespace:
  23946. description: |-
  23947. The namespace of the Secret resource being referred to.
  23948. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23949. maxLength: 63
  23950. minLength: 1
  23951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23952. type: string
  23953. type: object
  23954. accessKeySecretSecretRef:
  23955. description: The AccessKeySecret is used for authentication
  23956. properties:
  23957. key:
  23958. description: |-
  23959. A key in the referenced Secret.
  23960. Some instances of this field may be defaulted, in others it may be required.
  23961. maxLength: 253
  23962. minLength: 1
  23963. pattern: ^[-._a-zA-Z0-9]+$
  23964. type: string
  23965. name:
  23966. description: The name of the Secret resource being referred to.
  23967. maxLength: 253
  23968. minLength: 1
  23969. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23970. type: string
  23971. namespace:
  23972. description: |-
  23973. The namespace of the Secret resource being referred to.
  23974. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23975. maxLength: 63
  23976. minLength: 1
  23977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23978. type: string
  23979. type: object
  23980. required:
  23981. - accessKeyIDSecretRef
  23982. - accessKeySecretSecretRef
  23983. type: object
  23984. type: object
  23985. projectID:
  23986. description: ProjectID is the project, which the secrets are stored in.
  23987. type: string
  23988. required:
  23989. - auth
  23990. type: object
  23991. conjur:
  23992. description: Conjur configures this store to sync secrets using conjur provider
  23993. properties:
  23994. auth:
  23995. description: Defines authentication settings for connecting to Conjur.
  23996. properties:
  23997. apikey:
  23998. description: Authenticates with Conjur using an API key.
  23999. properties:
  24000. account:
  24001. description: Account is the Conjur organization account name.
  24002. type: string
  24003. apiKeyRef:
  24004. description: |-
  24005. A reference to a specific 'key' containing the Conjur API key
  24006. within a Secret resource. In some instances, `key` is a required field.
  24007. properties:
  24008. key:
  24009. description: |-
  24010. A key in the referenced Secret.
  24011. Some instances of this field may be defaulted, in others it may be required.
  24012. maxLength: 253
  24013. minLength: 1
  24014. pattern: ^[-._a-zA-Z0-9]+$
  24015. type: string
  24016. name:
  24017. description: The name of the Secret resource being referred to.
  24018. maxLength: 253
  24019. minLength: 1
  24020. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24021. type: string
  24022. namespace:
  24023. description: |-
  24024. The namespace of the Secret resource being referred to.
  24025. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24026. maxLength: 63
  24027. minLength: 1
  24028. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24029. type: string
  24030. type: object
  24031. userRef:
  24032. description: |-
  24033. A reference to a specific 'key' containing the Conjur username
  24034. within a Secret resource. In some instances, `key` is a required field.
  24035. properties:
  24036. key:
  24037. description: |-
  24038. A key in the referenced Secret.
  24039. Some instances of this field may be defaulted, in others it may be required.
  24040. maxLength: 253
  24041. minLength: 1
  24042. pattern: ^[-._a-zA-Z0-9]+$
  24043. type: string
  24044. name:
  24045. description: The name of the Secret resource being referred to.
  24046. maxLength: 253
  24047. minLength: 1
  24048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24049. type: string
  24050. namespace:
  24051. description: |-
  24052. The namespace of the Secret resource being referred to.
  24053. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24054. maxLength: 63
  24055. minLength: 1
  24056. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24057. type: string
  24058. type: object
  24059. required:
  24060. - account
  24061. - apiKeyRef
  24062. - userRef
  24063. type: object
  24064. jwt:
  24065. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  24066. properties:
  24067. account:
  24068. description: Account is the Conjur organization account name.
  24069. type: string
  24070. hostId:
  24071. description: |-
  24072. Optional HostID for JWT authentication. This may be used depending
  24073. on how the Conjur JWT authenticator policy is configured.
  24074. type: string
  24075. secretRef:
  24076. description: |-
  24077. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  24078. authenticate with Conjur using the JWT authentication method.
  24079. properties:
  24080. key:
  24081. description: |-
  24082. A key in the referenced Secret.
  24083. Some instances of this field may be defaulted, in others it may be required.
  24084. maxLength: 253
  24085. minLength: 1
  24086. pattern: ^[-._a-zA-Z0-9]+$
  24087. type: string
  24088. name:
  24089. description: The name of the Secret resource being referred to.
  24090. maxLength: 253
  24091. minLength: 1
  24092. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24093. type: string
  24094. namespace:
  24095. description: |-
  24096. The namespace of the Secret resource being referred to.
  24097. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24098. maxLength: 63
  24099. minLength: 1
  24100. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24101. type: string
  24102. type: object
  24103. serviceAccountRef:
  24104. description: |-
  24105. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  24106. a token for with the `TokenRequest` API.
  24107. properties:
  24108. audiences:
  24109. description: |-
  24110. Audience specifies the `aud` claim for the service account token
  24111. Some providers automatically extend the audience field based on well-known annotations for workload
  24112. identity (e.g. IRSA or GCP Workload Identity)
  24113. items:
  24114. type: string
  24115. type: array
  24116. name:
  24117. description: The name of the ServiceAccount resource being referred to.
  24118. maxLength: 253
  24119. minLength: 1
  24120. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24121. type: string
  24122. namespace:
  24123. description: |-
  24124. Namespace of the resource being referred to.
  24125. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24126. maxLength: 63
  24127. minLength: 1
  24128. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24129. type: string
  24130. required:
  24131. - name
  24132. type: object
  24133. serviceID:
  24134. description: The conjur authn jwt webservice id
  24135. type: string
  24136. required:
  24137. - account
  24138. - serviceID
  24139. type: object
  24140. type: object
  24141. caBundle:
  24142. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  24143. type: string
  24144. caProvider:
  24145. description: |-
  24146. Used to provide custom certificate authority (CA) certificates
  24147. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  24148. that contains a PEM-encoded certificate.
  24149. properties:
  24150. key:
  24151. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24152. maxLength: 253
  24153. minLength: 1
  24154. pattern: ^[-._a-zA-Z0-9]+$
  24155. type: string
  24156. name:
  24157. description: The name of the object located at the provider type.
  24158. maxLength: 253
  24159. minLength: 1
  24160. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24161. type: string
  24162. namespace:
  24163. description: |-
  24164. The namespace the Provider type is in.
  24165. Can only be defined when used in a ClusterSecretStore.
  24166. maxLength: 63
  24167. minLength: 1
  24168. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24169. type: string
  24170. type:
  24171. description: The type of provider to use such as "Secret", or "ConfigMap".
  24172. enum:
  24173. - Secret
  24174. - ConfigMap
  24175. type: string
  24176. required:
  24177. - name
  24178. - type
  24179. type: object
  24180. url:
  24181. description: URL is the endpoint of the Conjur instance.
  24182. type: string
  24183. required:
  24184. - auth
  24185. - url
  24186. type: object
  24187. delinea:
  24188. description: |-
  24189. Delinea DevOps Secrets Vault
  24190. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  24191. properties:
  24192. clientId:
  24193. description: ClientID is the non-secret part of the credential.
  24194. properties:
  24195. secretRef:
  24196. description: SecretRef references a key in a secret that will be used as value.
  24197. properties:
  24198. key:
  24199. description: |-
  24200. A key in the referenced Secret.
  24201. Some instances of this field may be defaulted, in others it may be required.
  24202. maxLength: 253
  24203. minLength: 1
  24204. pattern: ^[-._a-zA-Z0-9]+$
  24205. type: string
  24206. name:
  24207. description: The name of the Secret resource being referred to.
  24208. maxLength: 253
  24209. minLength: 1
  24210. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24211. type: string
  24212. namespace:
  24213. description: |-
  24214. The namespace of the Secret resource being referred to.
  24215. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24216. maxLength: 63
  24217. minLength: 1
  24218. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24219. type: string
  24220. type: object
  24221. value:
  24222. description: Value can be specified directly to set a value without using a secret.
  24223. type: string
  24224. type: object
  24225. clientSecret:
  24226. description: ClientSecret is the secret part of the credential.
  24227. properties:
  24228. secretRef:
  24229. description: SecretRef references a key in a secret that will be used as value.
  24230. properties:
  24231. key:
  24232. description: |-
  24233. A key in the referenced Secret.
  24234. Some instances of this field may be defaulted, in others it may be required.
  24235. maxLength: 253
  24236. minLength: 1
  24237. pattern: ^[-._a-zA-Z0-9]+$
  24238. type: string
  24239. name:
  24240. description: The name of the Secret resource being referred to.
  24241. maxLength: 253
  24242. minLength: 1
  24243. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24244. type: string
  24245. namespace:
  24246. description: |-
  24247. The namespace of the Secret resource being referred to.
  24248. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24249. maxLength: 63
  24250. minLength: 1
  24251. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24252. type: string
  24253. type: object
  24254. value:
  24255. description: Value can be specified directly to set a value without using a secret.
  24256. type: string
  24257. type: object
  24258. tenant:
  24259. description: Tenant is the chosen hostname / site name.
  24260. type: string
  24261. tld:
  24262. description: |-
  24263. TLD is based on the server location that was chosen during provisioning.
  24264. If unset, defaults to "com".
  24265. type: string
  24266. urlTemplate:
  24267. description: |-
  24268. URLTemplate
  24269. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  24270. type: string
  24271. required:
  24272. - clientId
  24273. - clientSecret
  24274. - tenant
  24275. type: object
  24276. device42:
  24277. description: Device42 configures this store to sync secrets using the Device42 provider
  24278. properties:
  24279. auth:
  24280. description: Auth configures how secret-manager authenticates with a Device42 instance.
  24281. properties:
  24282. secretRef:
  24283. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  24284. properties:
  24285. credentials:
  24286. description: Username / Password is used for authentication.
  24287. properties:
  24288. key:
  24289. description: |-
  24290. A key in the referenced Secret.
  24291. Some instances of this field may be defaulted, in others it may be required.
  24292. maxLength: 253
  24293. minLength: 1
  24294. pattern: ^[-._a-zA-Z0-9]+$
  24295. type: string
  24296. name:
  24297. description: The name of the Secret resource being referred to.
  24298. maxLength: 253
  24299. minLength: 1
  24300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24301. type: string
  24302. namespace:
  24303. description: |-
  24304. The namespace of the Secret resource being referred to.
  24305. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24306. maxLength: 63
  24307. minLength: 1
  24308. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24309. type: string
  24310. type: object
  24311. type: object
  24312. required:
  24313. - secretRef
  24314. type: object
  24315. host:
  24316. description: URL configures the Device42 instance URL.
  24317. type: string
  24318. required:
  24319. - auth
  24320. - host
  24321. type: object
  24322. doppler:
  24323. description: Doppler configures this store to sync secrets using the Doppler provider
  24324. properties:
  24325. auth:
  24326. description: Auth configures how the Operator authenticates with the Doppler API
  24327. properties:
  24328. secretRef:
  24329. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  24330. properties:
  24331. dopplerToken:
  24332. description: |-
  24333. The DopplerToken is used for authentication.
  24334. See https://docs.doppler.com/reference/api#authentication for auth token types.
  24335. The Key attribute defaults to dopplerToken if not specified.
  24336. properties:
  24337. key:
  24338. description: |-
  24339. A key in the referenced Secret.
  24340. Some instances of this field may be defaulted, in others it may be required.
  24341. maxLength: 253
  24342. minLength: 1
  24343. pattern: ^[-._a-zA-Z0-9]+$
  24344. type: string
  24345. name:
  24346. description: The name of the Secret resource being referred to.
  24347. maxLength: 253
  24348. minLength: 1
  24349. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24350. type: string
  24351. namespace:
  24352. description: |-
  24353. The namespace of the Secret resource being referred to.
  24354. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24355. maxLength: 63
  24356. minLength: 1
  24357. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24358. type: string
  24359. type: object
  24360. required:
  24361. - dopplerToken
  24362. type: object
  24363. required:
  24364. - secretRef
  24365. type: object
  24366. config:
  24367. description: Doppler config (required if not using a Service Token)
  24368. type: string
  24369. format:
  24370. description: Format enables the downloading of secrets as a file (string)
  24371. enum:
  24372. - json
  24373. - dotnet-json
  24374. - env
  24375. - yaml
  24376. - docker
  24377. type: string
  24378. nameTransformer:
  24379. description: Environment variable compatible name transforms that change secret names to a different format
  24380. enum:
  24381. - upper-camel
  24382. - camel
  24383. - lower-snake
  24384. - tf-var
  24385. - dotnet-env
  24386. - lower-kebab
  24387. type: string
  24388. project:
  24389. description: Doppler project (required if not using a Service Token)
  24390. type: string
  24391. required:
  24392. - auth
  24393. type: object
  24394. fake:
  24395. description: Fake configures a store with static key/value pairs
  24396. properties:
  24397. data:
  24398. items:
  24399. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  24400. properties:
  24401. key:
  24402. type: string
  24403. value:
  24404. type: string
  24405. version:
  24406. type: string
  24407. required:
  24408. - key
  24409. - value
  24410. type: object
  24411. type: array
  24412. required:
  24413. - data
  24414. type: object
  24415. fortanix:
  24416. description: Fortanix configures this store to sync secrets using the Fortanix provider
  24417. properties:
  24418. apiKey:
  24419. description: APIKey is the API token to access SDKMS Applications.
  24420. properties:
  24421. secretRef:
  24422. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  24423. properties:
  24424. key:
  24425. description: |-
  24426. A key in the referenced Secret.
  24427. Some instances of this field may be defaulted, in others it may be required.
  24428. maxLength: 253
  24429. minLength: 1
  24430. pattern: ^[-._a-zA-Z0-9]+$
  24431. type: string
  24432. name:
  24433. description: The name of the Secret resource being referred to.
  24434. maxLength: 253
  24435. minLength: 1
  24436. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24437. type: string
  24438. namespace:
  24439. description: |-
  24440. The namespace of the Secret resource being referred to.
  24441. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24442. maxLength: 63
  24443. minLength: 1
  24444. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24445. type: string
  24446. type: object
  24447. type: object
  24448. apiUrl:
  24449. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  24450. type: string
  24451. type: object
  24452. gcpsm:
  24453. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  24454. properties:
  24455. auth:
  24456. description: Auth defines the information necessary to authenticate against GCP
  24457. properties:
  24458. secretRef:
  24459. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  24460. properties:
  24461. secretAccessKeySecretRef:
  24462. description: The SecretAccessKey is used for authentication
  24463. properties:
  24464. key:
  24465. description: |-
  24466. A key in the referenced Secret.
  24467. Some instances of this field may be defaulted, in others it may be required.
  24468. maxLength: 253
  24469. minLength: 1
  24470. pattern: ^[-._a-zA-Z0-9]+$
  24471. type: string
  24472. name:
  24473. description: The name of the Secret resource being referred to.
  24474. maxLength: 253
  24475. minLength: 1
  24476. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24477. type: string
  24478. namespace:
  24479. description: |-
  24480. The namespace of the Secret resource being referred to.
  24481. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24482. maxLength: 63
  24483. minLength: 1
  24484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24485. type: string
  24486. type: object
  24487. type: object
  24488. workloadIdentity:
  24489. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  24490. properties:
  24491. clusterLocation:
  24492. description: |-
  24493. ClusterLocation is the location of the cluster
  24494. If not specified, it fetches information from the metadata server
  24495. type: string
  24496. clusterName:
  24497. description: |-
  24498. ClusterName is the name of the cluster
  24499. If not specified, it fetches information from the metadata server
  24500. type: string
  24501. clusterProjectID:
  24502. description: |-
  24503. ClusterProjectID is the project ID of the cluster
  24504. If not specified, it fetches information from the metadata server
  24505. type: string
  24506. serviceAccountRef:
  24507. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  24508. properties:
  24509. audiences:
  24510. description: |-
  24511. Audience specifies the `aud` claim for the service account token
  24512. Some providers automatically extend the audience field based on well-known annotations for workload
  24513. identity (e.g. IRSA or GCP Workload Identity)
  24514. items:
  24515. type: string
  24516. type: array
  24517. name:
  24518. description: The name of the ServiceAccount resource being referred to.
  24519. maxLength: 253
  24520. minLength: 1
  24521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24522. type: string
  24523. namespace:
  24524. description: |-
  24525. Namespace of the resource being referred to.
  24526. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24527. maxLength: 63
  24528. minLength: 1
  24529. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24530. type: string
  24531. required:
  24532. - name
  24533. type: object
  24534. required:
  24535. - serviceAccountRef
  24536. type: object
  24537. type: object
  24538. location:
  24539. description: Location optionally defines a location for a secret
  24540. type: string
  24541. projectID:
  24542. description: ProjectID project where secret is located
  24543. type: string
  24544. type: object
  24545. github:
  24546. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  24547. properties:
  24548. appID:
  24549. description: appID specifies the Github APP that will be used to authenticate the client
  24550. format: int64
  24551. type: integer
  24552. auth:
  24553. description: auth configures how secret-manager authenticates with a Github instance.
  24554. properties:
  24555. privateKey:
  24556. description: |-
  24557. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24558. In some instances, `key` is a required field.
  24559. properties:
  24560. key:
  24561. description: |-
  24562. A key in the referenced Secret.
  24563. Some instances of this field may be defaulted, in others it may be required.
  24564. maxLength: 253
  24565. minLength: 1
  24566. pattern: ^[-._a-zA-Z0-9]+$
  24567. type: string
  24568. name:
  24569. description: The name of the Secret resource being referred to.
  24570. maxLength: 253
  24571. minLength: 1
  24572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24573. type: string
  24574. namespace:
  24575. description: |-
  24576. The namespace of the Secret resource being referred to.
  24577. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24578. maxLength: 63
  24579. minLength: 1
  24580. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24581. type: string
  24582. type: object
  24583. required:
  24584. - privateKey
  24585. type: object
  24586. environment:
  24587. description: environment will be used to fetch secrets from a particular environment within a github repository
  24588. type: string
  24589. installationID:
  24590. description: installationID specifies the Github APP installation that will be used to authenticate the client
  24591. format: int64
  24592. type: integer
  24593. organization:
  24594. description: organization will be used to fetch secrets from the Github organization
  24595. type: string
  24596. repository:
  24597. description: repository will be used to fetch secrets from the Github repository within an organization
  24598. type: string
  24599. uploadURL:
  24600. description: Upload URL for enterprise instances. Default to URL.
  24601. type: string
  24602. url:
  24603. default: https://github.com/
  24604. description: URL configures the Github instance URL. Defaults to https://github.com/.
  24605. type: string
  24606. required:
  24607. - appID
  24608. - auth
  24609. - installationID
  24610. - organization
  24611. type: object
  24612. gitlab:
  24613. description: GitLab configures this store to sync secrets using GitLab Variables provider
  24614. properties:
  24615. auth:
  24616. description: Auth configures how secret-manager authenticates with a GitLab instance.
  24617. properties:
  24618. SecretRef:
  24619. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  24620. properties:
  24621. accessToken:
  24622. description: AccessToken is used for authentication.
  24623. properties:
  24624. key:
  24625. description: |-
  24626. A key in the referenced Secret.
  24627. Some instances of this field may be defaulted, in others it may be required.
  24628. maxLength: 253
  24629. minLength: 1
  24630. pattern: ^[-._a-zA-Z0-9]+$
  24631. type: string
  24632. name:
  24633. description: The name of the Secret resource being referred to.
  24634. maxLength: 253
  24635. minLength: 1
  24636. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24637. type: string
  24638. namespace:
  24639. description: |-
  24640. The namespace of the Secret resource being referred to.
  24641. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24642. maxLength: 63
  24643. minLength: 1
  24644. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24645. type: string
  24646. type: object
  24647. type: object
  24648. required:
  24649. - SecretRef
  24650. type: object
  24651. caBundle:
  24652. description: |-
  24653. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  24654. can be performed.
  24655. format: byte
  24656. type: string
  24657. caProvider:
  24658. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  24659. properties:
  24660. key:
  24661. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24662. maxLength: 253
  24663. minLength: 1
  24664. pattern: ^[-._a-zA-Z0-9]+$
  24665. type: string
  24666. name:
  24667. description: The name of the object located at the provider type.
  24668. maxLength: 253
  24669. minLength: 1
  24670. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24671. type: string
  24672. namespace:
  24673. description: |-
  24674. The namespace the Provider type is in.
  24675. Can only be defined when used in a ClusterSecretStore.
  24676. maxLength: 63
  24677. minLength: 1
  24678. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24679. type: string
  24680. type:
  24681. description: The type of provider to use such as "Secret", or "ConfigMap".
  24682. enum:
  24683. - Secret
  24684. - ConfigMap
  24685. type: string
  24686. required:
  24687. - name
  24688. - type
  24689. type: object
  24690. environment:
  24691. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  24692. type: string
  24693. groupIDs:
  24694. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  24695. items:
  24696. type: string
  24697. type: array
  24698. inheritFromGroups:
  24699. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  24700. type: boolean
  24701. projectID:
  24702. description: ProjectID specifies a project where secrets are located.
  24703. type: string
  24704. url:
  24705. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  24706. type: string
  24707. required:
  24708. - auth
  24709. type: object
  24710. ibm:
  24711. description: IBM configures this store to sync secrets using IBM Cloud provider
  24712. properties:
  24713. auth:
  24714. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  24715. maxProperties: 1
  24716. minProperties: 1
  24717. properties:
  24718. containerAuth:
  24719. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  24720. properties:
  24721. iamEndpoint:
  24722. type: string
  24723. profile:
  24724. description: the IBM Trusted Profile
  24725. type: string
  24726. tokenLocation:
  24727. description: Location the token is mounted on the pod
  24728. type: string
  24729. required:
  24730. - profile
  24731. type: object
  24732. secretRef:
  24733. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  24734. properties:
  24735. secretApiKeySecretRef:
  24736. description: The SecretAccessKey is used for authentication
  24737. properties:
  24738. key:
  24739. description: |-
  24740. A key in the referenced Secret.
  24741. Some instances of this field may be defaulted, in others it may be required.
  24742. maxLength: 253
  24743. minLength: 1
  24744. pattern: ^[-._a-zA-Z0-9]+$
  24745. type: string
  24746. name:
  24747. description: The name of the Secret resource being referred to.
  24748. maxLength: 253
  24749. minLength: 1
  24750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24751. type: string
  24752. namespace:
  24753. description: |-
  24754. The namespace of the Secret resource being referred to.
  24755. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24756. maxLength: 63
  24757. minLength: 1
  24758. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24759. type: string
  24760. type: object
  24761. type: object
  24762. type: object
  24763. serviceUrl:
  24764. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  24765. type: string
  24766. required:
  24767. - auth
  24768. type: object
  24769. infisical:
  24770. description: Infisical configures this store to sync secrets using the Infisical provider
  24771. properties:
  24772. auth:
  24773. description: Auth configures how the Operator authenticates with the Infisical API
  24774. properties:
  24775. universalAuthCredentials:
  24776. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  24777. properties:
  24778. clientId:
  24779. description: |-
  24780. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24781. In some instances, `key` is a required field.
  24782. properties:
  24783. key:
  24784. description: |-
  24785. A key in the referenced Secret.
  24786. Some instances of this field may be defaulted, in others it may be required.
  24787. maxLength: 253
  24788. minLength: 1
  24789. pattern: ^[-._a-zA-Z0-9]+$
  24790. type: string
  24791. name:
  24792. description: The name of the Secret resource being referred to.
  24793. maxLength: 253
  24794. minLength: 1
  24795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24796. type: string
  24797. namespace:
  24798. description: |-
  24799. The namespace of the Secret resource being referred to.
  24800. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24801. maxLength: 63
  24802. minLength: 1
  24803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24804. type: string
  24805. type: object
  24806. clientSecret:
  24807. description: |-
  24808. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24809. In some instances, `key` is a required field.
  24810. properties:
  24811. key:
  24812. description: |-
  24813. A key in the referenced Secret.
  24814. Some instances of this field may be defaulted, in others it may be required.
  24815. maxLength: 253
  24816. minLength: 1
  24817. pattern: ^[-._a-zA-Z0-9]+$
  24818. type: string
  24819. name:
  24820. description: The name of the Secret resource being referred to.
  24821. maxLength: 253
  24822. minLength: 1
  24823. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24824. type: string
  24825. namespace:
  24826. description: |-
  24827. The namespace of the Secret resource being referred to.
  24828. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24829. maxLength: 63
  24830. minLength: 1
  24831. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24832. type: string
  24833. type: object
  24834. required:
  24835. - clientId
  24836. - clientSecret
  24837. type: object
  24838. type: object
  24839. hostAPI:
  24840. default: https://app.infisical.com/api
  24841. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  24842. type: string
  24843. secretsScope:
  24844. description: SecretsScope defines the scope of the secrets within the workspace
  24845. properties:
  24846. environmentSlug:
  24847. description: EnvironmentSlug is the required slug identifier for the environment.
  24848. type: string
  24849. expandSecretReferences:
  24850. default: true
  24851. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  24852. type: boolean
  24853. projectSlug:
  24854. description: ProjectSlug is the required slug identifier for the project.
  24855. type: string
  24856. recursive:
  24857. default: false
  24858. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  24859. type: boolean
  24860. secretsPath:
  24861. default: /
  24862. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  24863. type: string
  24864. required:
  24865. - environmentSlug
  24866. - projectSlug
  24867. type: object
  24868. required:
  24869. - auth
  24870. - secretsScope
  24871. type: object
  24872. keepersecurity:
  24873. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  24874. properties:
  24875. authRef:
  24876. description: |-
  24877. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24878. In some instances, `key` is a required field.
  24879. properties:
  24880. key:
  24881. description: |-
  24882. A key in the referenced Secret.
  24883. Some instances of this field may be defaulted, in others it may be required.
  24884. maxLength: 253
  24885. minLength: 1
  24886. pattern: ^[-._a-zA-Z0-9]+$
  24887. type: string
  24888. name:
  24889. description: The name of the Secret resource being referred to.
  24890. maxLength: 253
  24891. minLength: 1
  24892. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24893. type: string
  24894. namespace:
  24895. description: |-
  24896. The namespace of the Secret resource being referred to.
  24897. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24898. maxLength: 63
  24899. minLength: 1
  24900. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24901. type: string
  24902. type: object
  24903. folderID:
  24904. type: string
  24905. required:
  24906. - authRef
  24907. - folderID
  24908. type: object
  24909. kubernetes:
  24910. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  24911. properties:
  24912. auth:
  24913. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  24914. maxProperties: 1
  24915. minProperties: 1
  24916. properties:
  24917. cert:
  24918. description: has both clientCert and clientKey as secretKeySelector
  24919. properties:
  24920. clientCert:
  24921. description: |-
  24922. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24923. In some instances, `key` is a required field.
  24924. properties:
  24925. key:
  24926. description: |-
  24927. A key in the referenced Secret.
  24928. Some instances of this field may be defaulted, in others it may be required.
  24929. maxLength: 253
  24930. minLength: 1
  24931. pattern: ^[-._a-zA-Z0-9]+$
  24932. type: string
  24933. name:
  24934. description: The name of the Secret resource being referred to.
  24935. maxLength: 253
  24936. minLength: 1
  24937. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24938. type: string
  24939. namespace:
  24940. description: |-
  24941. The namespace of the Secret resource being referred to.
  24942. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24943. maxLength: 63
  24944. minLength: 1
  24945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24946. type: string
  24947. type: object
  24948. clientKey:
  24949. description: |-
  24950. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24951. In some instances, `key` is a required field.
  24952. properties:
  24953. key:
  24954. description: |-
  24955. A key in the referenced Secret.
  24956. Some instances of this field may be defaulted, in others it may be required.
  24957. maxLength: 253
  24958. minLength: 1
  24959. pattern: ^[-._a-zA-Z0-9]+$
  24960. type: string
  24961. name:
  24962. description: The name of the Secret resource being referred to.
  24963. maxLength: 253
  24964. minLength: 1
  24965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24966. type: string
  24967. namespace:
  24968. description: |-
  24969. The namespace of the Secret resource being referred to.
  24970. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24971. maxLength: 63
  24972. minLength: 1
  24973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24974. type: string
  24975. type: object
  24976. type: object
  24977. serviceAccount:
  24978. description: points to a service account that should be used for authentication
  24979. properties:
  24980. audiences:
  24981. description: |-
  24982. Audience specifies the `aud` claim for the service account token
  24983. Some providers automatically extend the audience field based on well-known annotations for workload
  24984. identity (e.g. IRSA or GCP Workload Identity)
  24985. items:
  24986. type: string
  24987. type: array
  24988. name:
  24989. description: The name of the ServiceAccount resource being referred to.
  24990. maxLength: 253
  24991. minLength: 1
  24992. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24993. type: string
  24994. namespace:
  24995. description: |-
  24996. Namespace of the resource being referred to.
  24997. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24998. maxLength: 63
  24999. minLength: 1
  25000. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25001. type: string
  25002. required:
  25003. - name
  25004. type: object
  25005. token:
  25006. description: use static token to authenticate with
  25007. properties:
  25008. bearerToken:
  25009. description: |-
  25010. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25011. In some instances, `key` is a required field.
  25012. properties:
  25013. key:
  25014. description: |-
  25015. A key in the referenced Secret.
  25016. Some instances of this field may be defaulted, in others it may be required.
  25017. maxLength: 253
  25018. minLength: 1
  25019. pattern: ^[-._a-zA-Z0-9]+$
  25020. type: string
  25021. name:
  25022. description: The name of the Secret resource being referred to.
  25023. maxLength: 253
  25024. minLength: 1
  25025. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25026. type: string
  25027. namespace:
  25028. description: |-
  25029. The namespace of the Secret resource being referred to.
  25030. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25031. maxLength: 63
  25032. minLength: 1
  25033. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25034. type: string
  25035. type: object
  25036. type: object
  25037. type: object
  25038. authRef:
  25039. description: A reference to a secret that contains the auth information.
  25040. properties:
  25041. key:
  25042. description: |-
  25043. A key in the referenced Secret.
  25044. Some instances of this field may be defaulted, in others it may be required.
  25045. maxLength: 253
  25046. minLength: 1
  25047. pattern: ^[-._a-zA-Z0-9]+$
  25048. type: string
  25049. name:
  25050. description: The name of the Secret resource being referred to.
  25051. maxLength: 253
  25052. minLength: 1
  25053. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25054. type: string
  25055. namespace:
  25056. description: |-
  25057. The namespace of the Secret resource being referred to.
  25058. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25059. maxLength: 63
  25060. minLength: 1
  25061. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25062. type: string
  25063. type: object
  25064. remoteNamespace:
  25065. default: default
  25066. description: Remote namespace to fetch the secrets from
  25067. maxLength: 63
  25068. minLength: 1
  25069. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25070. type: string
  25071. server:
  25072. description: configures the Kubernetes server Address.
  25073. properties:
  25074. caBundle:
  25075. description: CABundle is a base64-encoded CA certificate
  25076. format: byte
  25077. type: string
  25078. caProvider:
  25079. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  25080. properties:
  25081. key:
  25082. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  25083. maxLength: 253
  25084. minLength: 1
  25085. pattern: ^[-._a-zA-Z0-9]+$
  25086. type: string
  25087. name:
  25088. description: The name of the object located at the provider type.
  25089. maxLength: 253
  25090. minLength: 1
  25091. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25092. type: string
  25093. namespace:
  25094. description: |-
  25095. The namespace the Provider type is in.
  25096. Can only be defined when used in a ClusterSecretStore.
  25097. maxLength: 63
  25098. minLength: 1
  25099. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25100. type: string
  25101. type:
  25102. description: The type of provider to use such as "Secret", or "ConfigMap".
  25103. enum:
  25104. - Secret
  25105. - ConfigMap
  25106. type: string
  25107. required:
  25108. - name
  25109. - type
  25110. type: object
  25111. url:
  25112. default: kubernetes.default
  25113. description: configures the Kubernetes server Address.
  25114. type: string
  25115. type: object
  25116. type: object
  25117. onboardbase:
  25118. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  25119. properties:
  25120. apiHost:
  25121. default: https://public.onboardbase.com/api/v1/
  25122. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  25123. type: string
  25124. auth:
  25125. description: Auth configures how the Operator authenticates with the Onboardbase API
  25126. properties:
  25127. apiKeyRef:
  25128. description: |-
  25129. OnboardbaseAPIKey is the APIKey generated by an admin account.
  25130. It is used to recognize and authorize access to a project and environment within onboardbase
  25131. properties:
  25132. key:
  25133. description: |-
  25134. A key in the referenced Secret.
  25135. Some instances of this field may be defaulted, in others it may be required.
  25136. maxLength: 253
  25137. minLength: 1
  25138. pattern: ^[-._a-zA-Z0-9]+$
  25139. type: string
  25140. name:
  25141. description: The name of the Secret resource being referred to.
  25142. maxLength: 253
  25143. minLength: 1
  25144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25145. type: string
  25146. namespace:
  25147. description: |-
  25148. The namespace of the Secret resource being referred to.
  25149. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25150. maxLength: 63
  25151. minLength: 1
  25152. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25153. type: string
  25154. type: object
  25155. passcodeRef:
  25156. description: OnboardbasePasscode is the passcode attached to the API Key
  25157. properties:
  25158. key:
  25159. description: |-
  25160. A key in the referenced Secret.
  25161. Some instances of this field may be defaulted, in others it may be required.
  25162. maxLength: 253
  25163. minLength: 1
  25164. pattern: ^[-._a-zA-Z0-9]+$
  25165. type: string
  25166. name:
  25167. description: The name of the Secret resource being referred to.
  25168. maxLength: 253
  25169. minLength: 1
  25170. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25171. type: string
  25172. namespace:
  25173. description: |-
  25174. The namespace of the Secret resource being referred to.
  25175. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25176. maxLength: 63
  25177. minLength: 1
  25178. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25179. type: string
  25180. type: object
  25181. required:
  25182. - apiKeyRef
  25183. - passcodeRef
  25184. type: object
  25185. environment:
  25186. default: development
  25187. description: Environment is the name of an environmnent within a project to pull the secrets from
  25188. type: string
  25189. project:
  25190. default: development
  25191. description: Project is an onboardbase project that the secrets should be pulled from
  25192. type: string
  25193. required:
  25194. - apiHost
  25195. - auth
  25196. - environment
  25197. - project
  25198. type: object
  25199. onepassword:
  25200. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  25201. properties:
  25202. auth:
  25203. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  25204. properties:
  25205. secretRef:
  25206. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  25207. properties:
  25208. connectTokenSecretRef:
  25209. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  25210. properties:
  25211. key:
  25212. description: |-
  25213. A key in the referenced Secret.
  25214. Some instances of this field may be defaulted, in others it may be required.
  25215. maxLength: 253
  25216. minLength: 1
  25217. pattern: ^[-._a-zA-Z0-9]+$
  25218. type: string
  25219. name:
  25220. description: The name of the Secret resource being referred to.
  25221. maxLength: 253
  25222. minLength: 1
  25223. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25224. type: string
  25225. namespace:
  25226. description: |-
  25227. The namespace of the Secret resource being referred to.
  25228. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25229. maxLength: 63
  25230. minLength: 1
  25231. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25232. type: string
  25233. type: object
  25234. required:
  25235. - connectTokenSecretRef
  25236. type: object
  25237. required:
  25238. - secretRef
  25239. type: object
  25240. connectHost:
  25241. description: ConnectHost defines the OnePassword Connect Server to connect to
  25242. type: string
  25243. vaults:
  25244. additionalProperties:
  25245. type: integer
  25246. description: Vaults defines which OnePassword vaults to search in which order
  25247. type: object
  25248. required:
  25249. - auth
  25250. - connectHost
  25251. - vaults
  25252. type: object
  25253. oracle:
  25254. description: Oracle configures this store to sync secrets using Oracle Vault provider
  25255. properties:
  25256. auth:
  25257. description: |-
  25258. Auth configures how secret-manager authenticates with the Oracle Vault.
  25259. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  25260. properties:
  25261. secretRef:
  25262. description: SecretRef to pass through sensitive information.
  25263. properties:
  25264. fingerprint:
  25265. description: Fingerprint is the fingerprint of the API private key.
  25266. properties:
  25267. key:
  25268. description: |-
  25269. A key in the referenced Secret.
  25270. Some instances of this field may be defaulted, in others it may be required.
  25271. maxLength: 253
  25272. minLength: 1
  25273. pattern: ^[-._a-zA-Z0-9]+$
  25274. type: string
  25275. name:
  25276. description: The name of the Secret resource being referred to.
  25277. maxLength: 253
  25278. minLength: 1
  25279. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25280. type: string
  25281. namespace:
  25282. description: |-
  25283. The namespace of the Secret resource being referred to.
  25284. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25285. maxLength: 63
  25286. minLength: 1
  25287. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25288. type: string
  25289. type: object
  25290. privatekey:
  25291. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  25292. properties:
  25293. key:
  25294. description: |-
  25295. A key in the referenced Secret.
  25296. Some instances of this field may be defaulted, in others it may be required.
  25297. maxLength: 253
  25298. minLength: 1
  25299. pattern: ^[-._a-zA-Z0-9]+$
  25300. type: string
  25301. name:
  25302. description: The name of the Secret resource being referred to.
  25303. maxLength: 253
  25304. minLength: 1
  25305. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25306. type: string
  25307. namespace:
  25308. description: |-
  25309. The namespace of the Secret resource being referred to.
  25310. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25311. maxLength: 63
  25312. minLength: 1
  25313. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25314. type: string
  25315. type: object
  25316. required:
  25317. - fingerprint
  25318. - privatekey
  25319. type: object
  25320. tenancy:
  25321. description: Tenancy is the tenancy OCID where user is located.
  25322. type: string
  25323. user:
  25324. description: User is an access OCID specific to the account.
  25325. type: string
  25326. required:
  25327. - secretRef
  25328. - tenancy
  25329. - user
  25330. type: object
  25331. compartment:
  25332. description: |-
  25333. Compartment is the vault compartment OCID.
  25334. Required for PushSecret
  25335. type: string
  25336. encryptionKey:
  25337. description: |-
  25338. EncryptionKey is the OCID of the encryption key within the vault.
  25339. Required for PushSecret
  25340. type: string
  25341. principalType:
  25342. description: |-
  25343. The type of principal to use for authentication. If left blank, the Auth struct will
  25344. determine the principal type. This optional field must be specified if using
  25345. workload identity.
  25346. enum:
  25347. - ""
  25348. - UserPrincipal
  25349. - InstancePrincipal
  25350. - Workload
  25351. type: string
  25352. region:
  25353. description: Region is the region where vault is located.
  25354. type: string
  25355. serviceAccountRef:
  25356. description: |-
  25357. ServiceAccountRef specified the service account
  25358. that should be used when authenticating with WorkloadIdentity.
  25359. properties:
  25360. audiences:
  25361. description: |-
  25362. Audience specifies the `aud` claim for the service account token
  25363. Some providers automatically extend the audience field based on well-known annotations for workload
  25364. identity (e.g. IRSA or GCP Workload Identity)
  25365. items:
  25366. type: string
  25367. type: array
  25368. name:
  25369. description: The name of the ServiceAccount resource being referred to.
  25370. maxLength: 253
  25371. minLength: 1
  25372. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25373. type: string
  25374. namespace:
  25375. description: |-
  25376. Namespace of the resource being referred to.
  25377. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25378. maxLength: 63
  25379. minLength: 1
  25380. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25381. type: string
  25382. required:
  25383. - name
  25384. type: object
  25385. vault:
  25386. description: Vault is the vault's OCID of the specific vault where secret is located.
  25387. type: string
  25388. required:
  25389. - region
  25390. - vault
  25391. type: object
  25392. passbolt:
  25393. description: PassboltProvider defines configuration for the Passbolt provider.
  25394. properties:
  25395. auth:
  25396. description: Auth defines the information necessary to authenticate against Passbolt Server
  25397. properties:
  25398. passwordSecretRef:
  25399. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  25400. properties:
  25401. key:
  25402. description: |-
  25403. A key in the referenced Secret.
  25404. Some instances of this field may be defaulted, in others it may be required.
  25405. maxLength: 253
  25406. minLength: 1
  25407. pattern: ^[-._a-zA-Z0-9]+$
  25408. type: string
  25409. name:
  25410. description: The name of the Secret resource being referred to.
  25411. maxLength: 253
  25412. minLength: 1
  25413. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25414. type: string
  25415. namespace:
  25416. description: |-
  25417. The namespace of the Secret resource being referred to.
  25418. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25419. maxLength: 63
  25420. minLength: 1
  25421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25422. type: string
  25423. type: object
  25424. privateKeySecretRef:
  25425. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  25426. properties:
  25427. key:
  25428. description: |-
  25429. A key in the referenced Secret.
  25430. Some instances of this field may be defaulted, in others it may be required.
  25431. maxLength: 253
  25432. minLength: 1
  25433. pattern: ^[-._a-zA-Z0-9]+$
  25434. type: string
  25435. name:
  25436. description: The name of the Secret resource being referred to.
  25437. maxLength: 253
  25438. minLength: 1
  25439. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25440. type: string
  25441. namespace:
  25442. description: |-
  25443. The namespace of the Secret resource being referred to.
  25444. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25445. maxLength: 63
  25446. minLength: 1
  25447. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25448. type: string
  25449. type: object
  25450. required:
  25451. - passwordSecretRef
  25452. - privateKeySecretRef
  25453. type: object
  25454. host:
  25455. description: Host defines the Passbolt Server to connect to
  25456. type: string
  25457. required:
  25458. - auth
  25459. - host
  25460. type: object
  25461. passworddepot:
  25462. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  25463. properties:
  25464. auth:
  25465. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  25466. properties:
  25467. secretRef:
  25468. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  25469. properties:
  25470. credentials:
  25471. description: Username / Password is used for authentication.
  25472. properties:
  25473. key:
  25474. description: |-
  25475. A key in the referenced Secret.
  25476. Some instances of this field may be defaulted, in others it may be required.
  25477. maxLength: 253
  25478. minLength: 1
  25479. pattern: ^[-._a-zA-Z0-9]+$
  25480. type: string
  25481. name:
  25482. description: The name of the Secret resource being referred to.
  25483. maxLength: 253
  25484. minLength: 1
  25485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25486. type: string
  25487. namespace:
  25488. description: |-
  25489. The namespace of the Secret resource being referred to.
  25490. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25491. maxLength: 63
  25492. minLength: 1
  25493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25494. type: string
  25495. type: object
  25496. type: object
  25497. required:
  25498. - secretRef
  25499. type: object
  25500. database:
  25501. description: Database to use as source
  25502. type: string
  25503. host:
  25504. description: URL configures the Password Depot instance URL.
  25505. type: string
  25506. required:
  25507. - auth
  25508. - database
  25509. - host
  25510. type: object
  25511. previder:
  25512. description: Previder configures this store to sync secrets using the Previder provider
  25513. properties:
  25514. auth:
  25515. description: PreviderAuth contains a secretRef for credentials.
  25516. properties:
  25517. secretRef:
  25518. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  25519. properties:
  25520. accessToken:
  25521. description: The AccessToken is used for authentication
  25522. properties:
  25523. key:
  25524. description: |-
  25525. A key in the referenced Secret.
  25526. Some instances of this field may be defaulted, in others it may be required.
  25527. maxLength: 253
  25528. minLength: 1
  25529. pattern: ^[-._a-zA-Z0-9]+$
  25530. type: string
  25531. name:
  25532. description: The name of the Secret resource being referred to.
  25533. maxLength: 253
  25534. minLength: 1
  25535. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25536. type: string
  25537. namespace:
  25538. description: |-
  25539. The namespace of the Secret resource being referred to.
  25540. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25541. maxLength: 63
  25542. minLength: 1
  25543. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25544. type: string
  25545. type: object
  25546. required:
  25547. - accessToken
  25548. type: object
  25549. type: object
  25550. baseUri:
  25551. type: string
  25552. required:
  25553. - auth
  25554. type: object
  25555. pulumi:
  25556. description: Pulumi configures this store to sync secrets using the Pulumi provider
  25557. properties:
  25558. accessToken:
  25559. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  25560. properties:
  25561. secretRef:
  25562. description: SecretRef is a reference to a secret containing the Pulumi API token.
  25563. properties:
  25564. key:
  25565. description: |-
  25566. A key in the referenced Secret.
  25567. Some instances of this field may be defaulted, in others it may be required.
  25568. maxLength: 253
  25569. minLength: 1
  25570. pattern: ^[-._a-zA-Z0-9]+$
  25571. type: string
  25572. name:
  25573. description: The name of the Secret resource being referred to.
  25574. maxLength: 253
  25575. minLength: 1
  25576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25577. type: string
  25578. namespace:
  25579. description: |-
  25580. The namespace of the Secret resource being referred to.
  25581. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25582. maxLength: 63
  25583. minLength: 1
  25584. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25585. type: string
  25586. type: object
  25587. type: object
  25588. apiUrl:
  25589. default: https://api.pulumi.com/api/esc
  25590. description: APIURL is the URL of the Pulumi API.
  25591. type: string
  25592. environment:
  25593. description: |-
  25594. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  25595. dynamically retrieved values from supported providers including all major clouds,
  25596. and other Pulumi ESC environments.
  25597. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  25598. type: string
  25599. organization:
  25600. description: |-
  25601. Organization are a space to collaborate on shared projects and stacks.
  25602. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  25603. type: string
  25604. project:
  25605. description: Project is the name of the Pulumi ESC project the environment belongs to.
  25606. type: string
  25607. required:
  25608. - accessToken
  25609. - environment
  25610. - organization
  25611. - project
  25612. type: object
  25613. scaleway:
  25614. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  25615. properties:
  25616. accessKey:
  25617. description: AccessKey is the non-secret part of the api key.
  25618. properties:
  25619. secretRef:
  25620. description: SecretRef references a key in a secret that will be used as value.
  25621. properties:
  25622. key:
  25623. description: |-
  25624. A key in the referenced Secret.
  25625. Some instances of this field may be defaulted, in others it may be required.
  25626. maxLength: 253
  25627. minLength: 1
  25628. pattern: ^[-._a-zA-Z0-9]+$
  25629. type: string
  25630. name:
  25631. description: The name of the Secret resource being referred to.
  25632. maxLength: 253
  25633. minLength: 1
  25634. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25635. type: string
  25636. namespace:
  25637. description: |-
  25638. The namespace of the Secret resource being referred to.
  25639. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25640. maxLength: 63
  25641. minLength: 1
  25642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25643. type: string
  25644. type: object
  25645. value:
  25646. description: Value can be specified directly to set a value without using a secret.
  25647. type: string
  25648. type: object
  25649. apiUrl:
  25650. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  25651. type: string
  25652. projectId:
  25653. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  25654. type: string
  25655. region:
  25656. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  25657. type: string
  25658. secretKey:
  25659. description: SecretKey is the non-secret part of the api key.
  25660. properties:
  25661. secretRef:
  25662. description: SecretRef references a key in a secret that will be used as value.
  25663. properties:
  25664. key:
  25665. description: |-
  25666. A key in the referenced Secret.
  25667. Some instances of this field may be defaulted, in others it may be required.
  25668. maxLength: 253
  25669. minLength: 1
  25670. pattern: ^[-._a-zA-Z0-9]+$
  25671. type: string
  25672. name:
  25673. description: The name of the Secret resource being referred to.
  25674. maxLength: 253
  25675. minLength: 1
  25676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25677. type: string
  25678. namespace:
  25679. description: |-
  25680. The namespace of the Secret resource being referred to.
  25681. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25682. maxLength: 63
  25683. minLength: 1
  25684. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25685. type: string
  25686. type: object
  25687. value:
  25688. description: Value can be specified directly to set a value without using a secret.
  25689. type: string
  25690. type: object
  25691. required:
  25692. - accessKey
  25693. - projectId
  25694. - region
  25695. - secretKey
  25696. type: object
  25697. secretserver:
  25698. description: |-
  25699. SecretServer configures this store to sync secrets using SecretServer provider
  25700. https://docs.delinea.com/online-help/secret-server/start.htm
  25701. properties:
  25702. password:
  25703. description: Password is the secret server account password.
  25704. properties:
  25705. secretRef:
  25706. description: SecretRef references a key in a secret that will be used as value.
  25707. properties:
  25708. key:
  25709. description: |-
  25710. A key in the referenced Secret.
  25711. Some instances of this field may be defaulted, in others it may be required.
  25712. maxLength: 253
  25713. minLength: 1
  25714. pattern: ^[-._a-zA-Z0-9]+$
  25715. type: string
  25716. name:
  25717. description: The name of the Secret resource being referred to.
  25718. maxLength: 253
  25719. minLength: 1
  25720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25721. type: string
  25722. namespace:
  25723. description: |-
  25724. The namespace of the Secret resource being referred to.
  25725. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25726. maxLength: 63
  25727. minLength: 1
  25728. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25729. type: string
  25730. type: object
  25731. value:
  25732. description: Value can be specified directly to set a value without using a secret.
  25733. type: string
  25734. type: object
  25735. serverURL:
  25736. description: |-
  25737. ServerURL
  25738. URL to your secret server installation
  25739. type: string
  25740. username:
  25741. description: Username is the secret server account username.
  25742. properties:
  25743. secretRef:
  25744. description: SecretRef references a key in a secret that will be used as value.
  25745. properties:
  25746. key:
  25747. description: |-
  25748. A key in the referenced Secret.
  25749. Some instances of this field may be defaulted, in others it may be required.
  25750. maxLength: 253
  25751. minLength: 1
  25752. pattern: ^[-._a-zA-Z0-9]+$
  25753. type: string
  25754. name:
  25755. description: The name of the Secret resource being referred to.
  25756. maxLength: 253
  25757. minLength: 1
  25758. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25759. type: string
  25760. namespace:
  25761. description: |-
  25762. The namespace of the Secret resource being referred to.
  25763. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25764. maxLength: 63
  25765. minLength: 1
  25766. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25767. type: string
  25768. type: object
  25769. value:
  25770. description: Value can be specified directly to set a value without using a secret.
  25771. type: string
  25772. type: object
  25773. required:
  25774. - password
  25775. - serverURL
  25776. - username
  25777. type: object
  25778. senhasegura:
  25779. description: Senhasegura configures this store to sync secrets using senhasegura provider
  25780. properties:
  25781. auth:
  25782. description: Auth defines parameters to authenticate in senhasegura
  25783. properties:
  25784. clientId:
  25785. type: string
  25786. clientSecretSecretRef:
  25787. description: |-
  25788. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25789. In some instances, `key` is a required field.
  25790. properties:
  25791. key:
  25792. description: |-
  25793. A key in the referenced Secret.
  25794. Some instances of this field may be defaulted, in others it may be required.
  25795. maxLength: 253
  25796. minLength: 1
  25797. pattern: ^[-._a-zA-Z0-9]+$
  25798. type: string
  25799. name:
  25800. description: The name of the Secret resource being referred to.
  25801. maxLength: 253
  25802. minLength: 1
  25803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25804. type: string
  25805. namespace:
  25806. description: |-
  25807. The namespace of the Secret resource being referred to.
  25808. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25809. maxLength: 63
  25810. minLength: 1
  25811. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25812. type: string
  25813. type: object
  25814. required:
  25815. - clientId
  25816. - clientSecretSecretRef
  25817. type: object
  25818. ignoreSslCertificate:
  25819. default: false
  25820. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  25821. type: boolean
  25822. module:
  25823. description: Module defines which senhasegura module should be used to get secrets
  25824. type: string
  25825. url:
  25826. description: URL of senhasegura
  25827. type: string
  25828. required:
  25829. - auth
  25830. - module
  25831. - url
  25832. type: object
  25833. vault:
  25834. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  25835. properties:
  25836. auth:
  25837. description: Auth configures how secret-manager authenticates with the Vault server.
  25838. properties:
  25839. appRole:
  25840. description: |-
  25841. AppRole authenticates with Vault using the App Role auth mechanism,
  25842. with the role and secret stored in a Kubernetes Secret resource.
  25843. properties:
  25844. path:
  25845. default: approle
  25846. description: |-
  25847. Path where the App Role authentication backend is mounted
  25848. in Vault, e.g: "approle"
  25849. type: string
  25850. roleId:
  25851. description: |-
  25852. RoleID configured in the App Role authentication backend when setting
  25853. up the authentication backend in Vault.
  25854. type: string
  25855. roleRef:
  25856. description: |-
  25857. Reference to a key in a Secret that contains the App Role ID used
  25858. to authenticate with Vault.
  25859. The `key` field must be specified and denotes which entry within the Secret
  25860. resource is used as the app role id.
  25861. properties:
  25862. key:
  25863. description: |-
  25864. A key in the referenced Secret.
  25865. Some instances of this field may be defaulted, in others it may be required.
  25866. maxLength: 253
  25867. minLength: 1
  25868. pattern: ^[-._a-zA-Z0-9]+$
  25869. type: string
  25870. name:
  25871. description: The name of the Secret resource being referred to.
  25872. maxLength: 253
  25873. minLength: 1
  25874. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25875. type: string
  25876. namespace:
  25877. description: |-
  25878. The namespace of the Secret resource being referred to.
  25879. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25880. maxLength: 63
  25881. minLength: 1
  25882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25883. type: string
  25884. type: object
  25885. secretRef:
  25886. description: |-
  25887. Reference to a key in a Secret that contains the App Role secret used
  25888. to authenticate with Vault.
  25889. The `key` field must be specified and denotes which entry within the Secret
  25890. resource is used as the app role secret.
  25891. properties:
  25892. key:
  25893. description: |-
  25894. A key in the referenced Secret.
  25895. Some instances of this field may be defaulted, in others it may be required.
  25896. maxLength: 253
  25897. minLength: 1
  25898. pattern: ^[-._a-zA-Z0-9]+$
  25899. type: string
  25900. name:
  25901. description: The name of the Secret resource being referred to.
  25902. maxLength: 253
  25903. minLength: 1
  25904. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25905. type: string
  25906. namespace:
  25907. description: |-
  25908. The namespace of the Secret resource being referred to.
  25909. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25910. maxLength: 63
  25911. minLength: 1
  25912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25913. type: string
  25914. type: object
  25915. required:
  25916. - path
  25917. - secretRef
  25918. type: object
  25919. cert:
  25920. description: |-
  25921. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  25922. Cert authentication method
  25923. properties:
  25924. clientCert:
  25925. description: |-
  25926. ClientCert is a certificate to authenticate using the Cert Vault
  25927. authentication method
  25928. properties:
  25929. key:
  25930. description: |-
  25931. A key in the referenced Secret.
  25932. Some instances of this field may be defaulted, in others it may be required.
  25933. maxLength: 253
  25934. minLength: 1
  25935. pattern: ^[-._a-zA-Z0-9]+$
  25936. type: string
  25937. name:
  25938. description: The name of the Secret resource being referred to.
  25939. maxLength: 253
  25940. minLength: 1
  25941. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25942. type: string
  25943. namespace:
  25944. description: |-
  25945. The namespace of the Secret resource being referred to.
  25946. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25947. maxLength: 63
  25948. minLength: 1
  25949. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25950. type: string
  25951. type: object
  25952. secretRef:
  25953. description: |-
  25954. SecretRef to a key in a Secret resource containing client private key to
  25955. authenticate with Vault using the Cert authentication method
  25956. properties:
  25957. key:
  25958. description: |-
  25959. A key in the referenced Secret.
  25960. Some instances of this field may be defaulted, in others it may be required.
  25961. maxLength: 253
  25962. minLength: 1
  25963. pattern: ^[-._a-zA-Z0-9]+$
  25964. type: string
  25965. name:
  25966. description: The name of the Secret resource being referred to.
  25967. maxLength: 253
  25968. minLength: 1
  25969. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25970. type: string
  25971. namespace:
  25972. description: |-
  25973. The namespace of the Secret resource being referred to.
  25974. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25975. maxLength: 63
  25976. minLength: 1
  25977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25978. type: string
  25979. type: object
  25980. type: object
  25981. iam:
  25982. description: |-
  25983. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  25984. AWS IAM authentication method
  25985. properties:
  25986. externalID:
  25987. description: AWS External ID set on assumed IAM roles
  25988. type: string
  25989. jwt:
  25990. description: Specify a service account with IRSA enabled
  25991. properties:
  25992. serviceAccountRef:
  25993. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  25994. properties:
  25995. audiences:
  25996. description: |-
  25997. Audience specifies the `aud` claim for the service account token
  25998. Some providers automatically extend the audience field based on well-known annotations for workload
  25999. identity (e.g. IRSA or GCP Workload Identity)
  26000. items:
  26001. type: string
  26002. type: array
  26003. name:
  26004. description: The name of the ServiceAccount resource being referred to.
  26005. maxLength: 253
  26006. minLength: 1
  26007. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26008. type: string
  26009. namespace:
  26010. description: |-
  26011. Namespace of the resource being referred to.
  26012. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26013. maxLength: 63
  26014. minLength: 1
  26015. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26016. type: string
  26017. required:
  26018. - name
  26019. type: object
  26020. type: object
  26021. path:
  26022. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  26023. type: string
  26024. region:
  26025. description: AWS region
  26026. type: string
  26027. role:
  26028. description: This is the AWS role to be assumed before talking to vault
  26029. type: string
  26030. secretRef:
  26031. description: Specify credentials in a Secret object
  26032. properties:
  26033. accessKeyIDSecretRef:
  26034. description: The AccessKeyID is used for authentication
  26035. properties:
  26036. key:
  26037. description: |-
  26038. A key in the referenced Secret.
  26039. Some instances of this field may be defaulted, in others it may be required.
  26040. maxLength: 253
  26041. minLength: 1
  26042. pattern: ^[-._a-zA-Z0-9]+$
  26043. type: string
  26044. name:
  26045. description: The name of the Secret resource being referred to.
  26046. maxLength: 253
  26047. minLength: 1
  26048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26049. type: string
  26050. namespace:
  26051. description: |-
  26052. The namespace of the Secret resource being referred to.
  26053. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26054. maxLength: 63
  26055. minLength: 1
  26056. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26057. type: string
  26058. type: object
  26059. secretAccessKeySecretRef:
  26060. description: The SecretAccessKey is used for authentication
  26061. properties:
  26062. key:
  26063. description: |-
  26064. A key in the referenced Secret.
  26065. Some instances of this field may be defaulted, in others it may be required.
  26066. maxLength: 253
  26067. minLength: 1
  26068. pattern: ^[-._a-zA-Z0-9]+$
  26069. type: string
  26070. name:
  26071. description: The name of the Secret resource being referred to.
  26072. maxLength: 253
  26073. minLength: 1
  26074. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26075. type: string
  26076. namespace:
  26077. description: |-
  26078. The namespace of the Secret resource being referred to.
  26079. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26080. maxLength: 63
  26081. minLength: 1
  26082. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26083. type: string
  26084. type: object
  26085. sessionTokenSecretRef:
  26086. description: |-
  26087. The SessionToken used for authentication
  26088. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  26089. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  26090. properties:
  26091. key:
  26092. description: |-
  26093. A key in the referenced Secret.
  26094. Some instances of this field may be defaulted, in others it may be required.
  26095. maxLength: 253
  26096. minLength: 1
  26097. pattern: ^[-._a-zA-Z0-9]+$
  26098. type: string
  26099. name:
  26100. description: The name of the Secret resource being referred to.
  26101. maxLength: 253
  26102. minLength: 1
  26103. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26104. type: string
  26105. namespace:
  26106. description: |-
  26107. The namespace of the Secret resource being referred to.
  26108. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26109. maxLength: 63
  26110. minLength: 1
  26111. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26112. type: string
  26113. type: object
  26114. type: object
  26115. vaultAwsIamServerID:
  26116. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  26117. type: string
  26118. vaultRole:
  26119. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  26120. type: string
  26121. required:
  26122. - vaultRole
  26123. type: object
  26124. jwt:
  26125. description: |-
  26126. Jwt authenticates with Vault by passing role and JWT token using the
  26127. JWT/OIDC authentication method
  26128. properties:
  26129. kubernetesServiceAccountToken:
  26130. description: |-
  26131. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  26132. a token for with the `TokenRequest` API.
  26133. properties:
  26134. audiences:
  26135. description: |-
  26136. Optional audiences field that will be used to request a temporary Kubernetes service
  26137. account token for the service account referenced by `serviceAccountRef`.
  26138. Defaults to a single audience `vault` it not specified.
  26139. Deprecated: use serviceAccountRef.Audiences instead
  26140. items:
  26141. type: string
  26142. type: array
  26143. expirationSeconds:
  26144. description: |-
  26145. Optional expiration time in seconds that will be used to request a temporary
  26146. Kubernetes service account token for the service account referenced by
  26147. `serviceAccountRef`.
  26148. Deprecated: this will be removed in the future.
  26149. Defaults to 10 minutes.
  26150. format: int64
  26151. type: integer
  26152. serviceAccountRef:
  26153. description: Service account field containing the name of a kubernetes ServiceAccount.
  26154. properties:
  26155. audiences:
  26156. description: |-
  26157. Audience specifies the `aud` claim for the service account token
  26158. Some providers automatically extend the audience field based on well-known annotations for workload
  26159. identity (e.g. IRSA or GCP Workload Identity)
  26160. items:
  26161. type: string
  26162. type: array
  26163. name:
  26164. description: The name of the ServiceAccount resource being referred to.
  26165. maxLength: 253
  26166. minLength: 1
  26167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26168. type: string
  26169. namespace:
  26170. description: |-
  26171. Namespace of the resource being referred to.
  26172. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26173. maxLength: 63
  26174. minLength: 1
  26175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26176. type: string
  26177. required:
  26178. - name
  26179. type: object
  26180. required:
  26181. - serviceAccountRef
  26182. type: object
  26183. path:
  26184. default: jwt
  26185. description: |-
  26186. Path where the JWT authentication backend is mounted
  26187. in Vault, e.g: "jwt"
  26188. type: string
  26189. role:
  26190. description: |-
  26191. Role is a JWT role to authenticate using the JWT/OIDC Vault
  26192. authentication method
  26193. type: string
  26194. secretRef:
  26195. description: |-
  26196. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  26197. authenticate with Vault using the JWT/OIDC authentication method.
  26198. properties:
  26199. key:
  26200. description: |-
  26201. A key in the referenced Secret.
  26202. Some instances of this field may be defaulted, in others it may be required.
  26203. maxLength: 253
  26204. minLength: 1
  26205. pattern: ^[-._a-zA-Z0-9]+$
  26206. type: string
  26207. name:
  26208. description: The name of the Secret resource being referred to.
  26209. maxLength: 253
  26210. minLength: 1
  26211. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26212. type: string
  26213. namespace:
  26214. description: |-
  26215. The namespace of the Secret resource being referred to.
  26216. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26217. maxLength: 63
  26218. minLength: 1
  26219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26220. type: string
  26221. type: object
  26222. required:
  26223. - path
  26224. type: object
  26225. kubernetes:
  26226. description: |-
  26227. Kubernetes authenticates with Vault by passing the ServiceAccount
  26228. token stored in the named Secret resource to the Vault server.
  26229. properties:
  26230. mountPath:
  26231. default: kubernetes
  26232. description: |-
  26233. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  26234. "kubernetes"
  26235. type: string
  26236. role:
  26237. description: |-
  26238. A required field containing the Vault Role to assume. A Role binds a
  26239. Kubernetes ServiceAccount with a set of Vault policies.
  26240. type: string
  26241. secretRef:
  26242. description: |-
  26243. Optional secret field containing a Kubernetes ServiceAccount JWT used
  26244. for authenticating with Vault. If a name is specified without a key,
  26245. `token` is the default. If one is not specified, the one bound to
  26246. the controller will be used.
  26247. properties:
  26248. key:
  26249. description: |-
  26250. A key in the referenced Secret.
  26251. Some instances of this field may be defaulted, in others it may be required.
  26252. maxLength: 253
  26253. minLength: 1
  26254. pattern: ^[-._a-zA-Z0-9]+$
  26255. type: string
  26256. name:
  26257. description: The name of the Secret resource being referred to.
  26258. maxLength: 253
  26259. minLength: 1
  26260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26261. type: string
  26262. namespace:
  26263. description: |-
  26264. The namespace of the Secret resource being referred to.
  26265. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26266. maxLength: 63
  26267. minLength: 1
  26268. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26269. type: string
  26270. type: object
  26271. serviceAccountRef:
  26272. description: |-
  26273. Optional service account field containing the name of a kubernetes ServiceAccount.
  26274. If the service account is specified, the service account secret token JWT will be used
  26275. for authenticating with Vault. If the service account selector is not supplied,
  26276. the secretRef will be used instead.
  26277. properties:
  26278. audiences:
  26279. description: |-
  26280. Audience specifies the `aud` claim for the service account token
  26281. Some providers automatically extend the audience field based on well-known annotations for workload
  26282. identity (e.g. IRSA or GCP Workload Identity)
  26283. items:
  26284. type: string
  26285. type: array
  26286. name:
  26287. description: The name of the ServiceAccount resource being referred to.
  26288. maxLength: 253
  26289. minLength: 1
  26290. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26291. type: string
  26292. namespace:
  26293. description: |-
  26294. Namespace of the resource being referred to.
  26295. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26296. maxLength: 63
  26297. minLength: 1
  26298. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26299. type: string
  26300. required:
  26301. - name
  26302. type: object
  26303. required:
  26304. - mountPath
  26305. - role
  26306. type: object
  26307. ldap:
  26308. description: |-
  26309. Ldap authenticates with Vault by passing username/password pair using
  26310. the LDAP authentication method
  26311. properties:
  26312. path:
  26313. default: ldap
  26314. description: |-
  26315. Path where the LDAP authentication backend is mounted
  26316. in Vault, e.g: "ldap"
  26317. type: string
  26318. secretRef:
  26319. description: |-
  26320. SecretRef to a key in a Secret resource containing password for the LDAP
  26321. user used to authenticate with Vault using the LDAP authentication
  26322. method
  26323. properties:
  26324. key:
  26325. description: |-
  26326. A key in the referenced Secret.
  26327. Some instances of this field may be defaulted, in others it may be required.
  26328. maxLength: 253
  26329. minLength: 1
  26330. pattern: ^[-._a-zA-Z0-9]+$
  26331. type: string
  26332. name:
  26333. description: The name of the Secret resource being referred to.
  26334. maxLength: 253
  26335. minLength: 1
  26336. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26337. type: string
  26338. namespace:
  26339. description: |-
  26340. The namespace of the Secret resource being referred to.
  26341. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26342. maxLength: 63
  26343. minLength: 1
  26344. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26345. type: string
  26346. type: object
  26347. username:
  26348. description: |-
  26349. Username is an LDAP username used to authenticate using the LDAP Vault
  26350. authentication method
  26351. type: string
  26352. required:
  26353. - path
  26354. - username
  26355. type: object
  26356. namespace:
  26357. description: |-
  26358. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  26359. Namespaces is a set of features within Vault Enterprise that allows
  26360. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  26361. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  26362. This will default to Vault.Namespace field if set, or empty otherwise
  26363. type: string
  26364. tokenSecretRef:
  26365. description: TokenSecretRef authenticates with Vault by presenting a token.
  26366. properties:
  26367. key:
  26368. description: |-
  26369. A key in the referenced Secret.
  26370. Some instances of this field may be defaulted, in others it may be required.
  26371. maxLength: 253
  26372. minLength: 1
  26373. pattern: ^[-._a-zA-Z0-9]+$
  26374. type: string
  26375. name:
  26376. description: The name of the Secret resource being referred to.
  26377. maxLength: 253
  26378. minLength: 1
  26379. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26380. type: string
  26381. namespace:
  26382. description: |-
  26383. The namespace of the Secret resource being referred to.
  26384. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26385. maxLength: 63
  26386. minLength: 1
  26387. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26388. type: string
  26389. type: object
  26390. userPass:
  26391. description: UserPass authenticates with Vault by passing username/password pair
  26392. properties:
  26393. path:
  26394. default: userpass
  26395. description: |-
  26396. Path where the UserPassword authentication backend is mounted
  26397. in Vault, e.g: "userpass"
  26398. type: string
  26399. secretRef:
  26400. description: |-
  26401. SecretRef to a key in a Secret resource containing password for the
  26402. user used to authenticate with Vault using the UserPass authentication
  26403. method
  26404. properties:
  26405. key:
  26406. description: |-
  26407. A key in the referenced Secret.
  26408. Some instances of this field may be defaulted, in others it may be required.
  26409. maxLength: 253
  26410. minLength: 1
  26411. pattern: ^[-._a-zA-Z0-9]+$
  26412. type: string
  26413. name:
  26414. description: The name of the Secret resource being referred to.
  26415. maxLength: 253
  26416. minLength: 1
  26417. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26418. type: string
  26419. namespace:
  26420. description: |-
  26421. The namespace of the Secret resource being referred to.
  26422. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26423. maxLength: 63
  26424. minLength: 1
  26425. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26426. type: string
  26427. type: object
  26428. username:
  26429. description: |-
  26430. Username is a username used to authenticate using the UserPass Vault
  26431. authentication method
  26432. type: string
  26433. required:
  26434. - path
  26435. - username
  26436. type: object
  26437. type: object
  26438. caBundle:
  26439. description: |-
  26440. PEM encoded CA bundle used to validate Vault server certificate. Only used
  26441. if the Server URL is using HTTPS protocol. This parameter is ignored for
  26442. plain HTTP protocol connection. If not set the system root certificates
  26443. are used to validate the TLS connection.
  26444. format: byte
  26445. type: string
  26446. caProvider:
  26447. description: The provider for the CA bundle to use to validate Vault server certificate.
  26448. properties:
  26449. key:
  26450. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26451. maxLength: 253
  26452. minLength: 1
  26453. pattern: ^[-._a-zA-Z0-9]+$
  26454. type: string
  26455. name:
  26456. description: The name of the object located at the provider type.
  26457. maxLength: 253
  26458. minLength: 1
  26459. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26460. type: string
  26461. namespace:
  26462. description: |-
  26463. The namespace the Provider type is in.
  26464. Can only be defined when used in a ClusterSecretStore.
  26465. maxLength: 63
  26466. minLength: 1
  26467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26468. type: string
  26469. type:
  26470. description: The type of provider to use such as "Secret", or "ConfigMap".
  26471. enum:
  26472. - Secret
  26473. - ConfigMap
  26474. type: string
  26475. required:
  26476. - name
  26477. - type
  26478. type: object
  26479. forwardInconsistent:
  26480. description: |-
  26481. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  26482. leader instead of simply retrying within a loop. This can increase performance if
  26483. the option is enabled serverside.
  26484. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  26485. type: boolean
  26486. headers:
  26487. additionalProperties:
  26488. type: string
  26489. description: Headers to be added in Vault request
  26490. type: object
  26491. namespace:
  26492. description: |-
  26493. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  26494. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  26495. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  26496. type: string
  26497. path:
  26498. description: |-
  26499. Path is the mount path of the Vault KV backend endpoint, e.g:
  26500. "secret". The v2 KV secret engine version specific "/data" path suffix
  26501. for fetching secrets from Vault is optional and will be appended
  26502. if not present in specified path.
  26503. type: string
  26504. readYourWrites:
  26505. description: |-
  26506. ReadYourWrites ensures isolated read-after-write semantics by
  26507. providing discovered cluster replication states in each request.
  26508. More information about eventual consistency in Vault can be found here
  26509. https://www.vaultproject.io/docs/enterprise/consistency
  26510. type: boolean
  26511. server:
  26512. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  26513. type: string
  26514. tls:
  26515. description: |-
  26516. The configuration used for client side related TLS communication, when the Vault server
  26517. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  26518. This parameter is ignored for plain HTTP protocol connection.
  26519. It's worth noting this configuration is different from the "TLS certificates auth method",
  26520. which is available under the `auth.cert` section.
  26521. properties:
  26522. certSecretRef:
  26523. description: |-
  26524. CertSecretRef is a certificate added to the transport layer
  26525. when communicating with the Vault server.
  26526. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  26527. properties:
  26528. key:
  26529. description: |-
  26530. A key in the referenced Secret.
  26531. Some instances of this field may be defaulted, in others it may be required.
  26532. maxLength: 253
  26533. minLength: 1
  26534. pattern: ^[-._a-zA-Z0-9]+$
  26535. type: string
  26536. name:
  26537. description: The name of the Secret resource being referred to.
  26538. maxLength: 253
  26539. minLength: 1
  26540. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26541. type: string
  26542. namespace:
  26543. description: |-
  26544. The namespace of the Secret resource being referred to.
  26545. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26546. maxLength: 63
  26547. minLength: 1
  26548. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26549. type: string
  26550. type: object
  26551. keySecretRef:
  26552. description: |-
  26553. KeySecretRef to a key in a Secret resource containing client private key
  26554. added to the transport layer when communicating with the Vault server.
  26555. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  26556. properties:
  26557. key:
  26558. description: |-
  26559. A key in the referenced Secret.
  26560. Some instances of this field may be defaulted, in others it may be required.
  26561. maxLength: 253
  26562. minLength: 1
  26563. pattern: ^[-._a-zA-Z0-9]+$
  26564. type: string
  26565. name:
  26566. description: The name of the Secret resource being referred to.
  26567. maxLength: 253
  26568. minLength: 1
  26569. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26570. type: string
  26571. namespace:
  26572. description: |-
  26573. The namespace of the Secret resource being referred to.
  26574. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26575. maxLength: 63
  26576. minLength: 1
  26577. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26578. type: string
  26579. type: object
  26580. type: object
  26581. version:
  26582. default: v2
  26583. description: |-
  26584. Version is the Vault KV secret engine version. This can be either "v1" or
  26585. "v2". Version defaults to "v2".
  26586. enum:
  26587. - v1
  26588. - v2
  26589. type: string
  26590. required:
  26591. - server
  26592. type: object
  26593. webhook:
  26594. description: Webhook configures this store to sync secrets using a generic templated webhook
  26595. properties:
  26596. auth:
  26597. description: Auth specifies a authorization protocol. Only one protocol may be set.
  26598. maxProperties: 1
  26599. minProperties: 1
  26600. properties:
  26601. ntlm:
  26602. description: NTLMProtocol configures the store to use NTLM for auth
  26603. properties:
  26604. passwordSecret:
  26605. description: |-
  26606. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26607. In some instances, `key` is a required field.
  26608. properties:
  26609. key:
  26610. description: |-
  26611. A key in the referenced Secret.
  26612. Some instances of this field may be defaulted, in others it may be required.
  26613. maxLength: 253
  26614. minLength: 1
  26615. pattern: ^[-._a-zA-Z0-9]+$
  26616. type: string
  26617. name:
  26618. description: The name of the Secret resource being referred to.
  26619. maxLength: 253
  26620. minLength: 1
  26621. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26622. type: string
  26623. namespace:
  26624. description: |-
  26625. The namespace of the Secret resource being referred to.
  26626. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26627. maxLength: 63
  26628. minLength: 1
  26629. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26630. type: string
  26631. type: object
  26632. usernameSecret:
  26633. description: |-
  26634. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26635. In some instances, `key` is a required field.
  26636. properties:
  26637. key:
  26638. description: |-
  26639. A key in the referenced Secret.
  26640. Some instances of this field may be defaulted, in others it may be required.
  26641. maxLength: 253
  26642. minLength: 1
  26643. pattern: ^[-._a-zA-Z0-9]+$
  26644. type: string
  26645. name:
  26646. description: The name of the Secret resource being referred to.
  26647. maxLength: 253
  26648. minLength: 1
  26649. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26650. type: string
  26651. namespace:
  26652. description: |-
  26653. The namespace of the Secret resource being referred to.
  26654. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26655. maxLength: 63
  26656. minLength: 1
  26657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26658. type: string
  26659. type: object
  26660. required:
  26661. - passwordSecret
  26662. - usernameSecret
  26663. type: object
  26664. type: object
  26665. body:
  26666. description: Body
  26667. type: string
  26668. caBundle:
  26669. description: |-
  26670. PEM encoded CA bundle used to validate webhook server certificate. Only used
  26671. if the Server URL is using HTTPS protocol. This parameter is ignored for
  26672. plain HTTP protocol connection. If not set the system root certificates
  26673. are used to validate the TLS connection.
  26674. format: byte
  26675. type: string
  26676. caProvider:
  26677. description: The provider for the CA bundle to use to validate webhook server certificate.
  26678. properties:
  26679. key:
  26680. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26681. maxLength: 253
  26682. minLength: 1
  26683. pattern: ^[-._a-zA-Z0-9]+$
  26684. type: string
  26685. name:
  26686. description: The name of the object located at the provider type.
  26687. maxLength: 253
  26688. minLength: 1
  26689. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26690. type: string
  26691. namespace:
  26692. description: The namespace the Provider type is in.
  26693. maxLength: 63
  26694. minLength: 1
  26695. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26696. type: string
  26697. type:
  26698. description: The type of provider to use such as "Secret", or "ConfigMap".
  26699. enum:
  26700. - Secret
  26701. - ConfigMap
  26702. type: string
  26703. required:
  26704. - name
  26705. - type
  26706. type: object
  26707. headers:
  26708. additionalProperties:
  26709. type: string
  26710. description: Headers
  26711. type: object
  26712. method:
  26713. description: Webhook Method
  26714. type: string
  26715. result:
  26716. description: Result formatting
  26717. properties:
  26718. jsonPath:
  26719. description: Json path of return value
  26720. type: string
  26721. type: object
  26722. secrets:
  26723. description: |-
  26724. Secrets to fill in templates
  26725. These secrets will be passed to the templating function as key value pairs under the given name
  26726. items:
  26727. description: WebhookSecret defines a secret to be used in webhook templates.
  26728. properties:
  26729. name:
  26730. description: Name of this secret in templates
  26731. type: string
  26732. secretRef:
  26733. description: Secret ref to fill in credentials
  26734. properties:
  26735. key:
  26736. description: |-
  26737. A key in the referenced Secret.
  26738. Some instances of this field may be defaulted, in others it may be required.
  26739. maxLength: 253
  26740. minLength: 1
  26741. pattern: ^[-._a-zA-Z0-9]+$
  26742. type: string
  26743. name:
  26744. description: The name of the Secret resource being referred to.
  26745. maxLength: 253
  26746. minLength: 1
  26747. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26748. type: string
  26749. namespace:
  26750. description: |-
  26751. The namespace of the Secret resource being referred to.
  26752. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26753. maxLength: 63
  26754. minLength: 1
  26755. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26756. type: string
  26757. type: object
  26758. required:
  26759. - name
  26760. - secretRef
  26761. type: object
  26762. type: array
  26763. timeout:
  26764. description: Timeout
  26765. type: string
  26766. url:
  26767. description: Webhook url to call
  26768. type: string
  26769. required:
  26770. - result
  26771. - url
  26772. type: object
  26773. yandexcertificatemanager:
  26774. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  26775. properties:
  26776. apiEndpoint:
  26777. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  26778. type: string
  26779. auth:
  26780. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  26781. properties:
  26782. authorizedKeySecretRef:
  26783. description: The authorized key used for authentication
  26784. properties:
  26785. key:
  26786. description: |-
  26787. A key in the referenced Secret.
  26788. Some instances of this field may be defaulted, in others it may be required.
  26789. maxLength: 253
  26790. minLength: 1
  26791. pattern: ^[-._a-zA-Z0-9]+$
  26792. type: string
  26793. name:
  26794. description: The name of the Secret resource being referred to.
  26795. maxLength: 253
  26796. minLength: 1
  26797. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26798. type: string
  26799. namespace:
  26800. description: |-
  26801. The namespace of the Secret resource being referred to.
  26802. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26803. maxLength: 63
  26804. minLength: 1
  26805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26806. type: string
  26807. type: object
  26808. type: object
  26809. caProvider:
  26810. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  26811. properties:
  26812. certSecretRef:
  26813. description: |-
  26814. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26815. In some instances, `key` is a required field.
  26816. properties:
  26817. key:
  26818. description: |-
  26819. A key in the referenced Secret.
  26820. Some instances of this field may be defaulted, in others it may be required.
  26821. maxLength: 253
  26822. minLength: 1
  26823. pattern: ^[-._a-zA-Z0-9]+$
  26824. type: string
  26825. name:
  26826. description: The name of the Secret resource being referred to.
  26827. maxLength: 253
  26828. minLength: 1
  26829. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26830. type: string
  26831. namespace:
  26832. description: |-
  26833. The namespace of the Secret resource being referred to.
  26834. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26835. maxLength: 63
  26836. minLength: 1
  26837. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26838. type: string
  26839. type: object
  26840. type: object
  26841. required:
  26842. - auth
  26843. type: object
  26844. yandexlockbox:
  26845. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  26846. properties:
  26847. apiEndpoint:
  26848. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  26849. type: string
  26850. auth:
  26851. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  26852. properties:
  26853. authorizedKeySecretRef:
  26854. description: The authorized key used for authentication
  26855. properties:
  26856. key:
  26857. description: |-
  26858. A key in the referenced Secret.
  26859. Some instances of this field may be defaulted, in others it may be required.
  26860. maxLength: 253
  26861. minLength: 1
  26862. pattern: ^[-._a-zA-Z0-9]+$
  26863. type: string
  26864. name:
  26865. description: The name of the Secret resource being referred to.
  26866. maxLength: 253
  26867. minLength: 1
  26868. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26869. type: string
  26870. namespace:
  26871. description: |-
  26872. The namespace of the Secret resource being referred to.
  26873. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26874. maxLength: 63
  26875. minLength: 1
  26876. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26877. type: string
  26878. type: object
  26879. type: object
  26880. caProvider:
  26881. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  26882. properties:
  26883. certSecretRef:
  26884. description: |-
  26885. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26886. In some instances, `key` is a required field.
  26887. properties:
  26888. key:
  26889. description: |-
  26890. A key in the referenced Secret.
  26891. Some instances of this field may be defaulted, in others it may be required.
  26892. maxLength: 253
  26893. minLength: 1
  26894. pattern: ^[-._a-zA-Z0-9]+$
  26895. type: string
  26896. name:
  26897. description: The name of the Secret resource being referred to.
  26898. maxLength: 253
  26899. minLength: 1
  26900. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26901. type: string
  26902. namespace:
  26903. description: |-
  26904. The namespace of the Secret resource being referred to.
  26905. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26906. maxLength: 63
  26907. minLength: 1
  26908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26909. type: string
  26910. type: object
  26911. type: object
  26912. required:
  26913. - auth
  26914. type: object
  26915. type: object
  26916. refreshInterval:
  26917. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  26918. type: integer
  26919. retrySettings:
  26920. description: Used to configure HTTP retries on failures.
  26921. properties:
  26922. maxRetries:
  26923. description: MaxRetries is the maximum number of retry attempts.
  26924. format: int32
  26925. type: integer
  26926. retryInterval:
  26927. description: RetryInterval is the interval between retry attempts.
  26928. type: string
  26929. type: object
  26930. required:
  26931. - provider
  26932. type: object
  26933. status:
  26934. description: SecretStoreStatus defines the observed state of the SecretStore.
  26935. properties:
  26936. capabilities:
  26937. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  26938. type: string
  26939. conditions:
  26940. items:
  26941. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  26942. properties:
  26943. lastTransitionTime:
  26944. format: date-time
  26945. type: string
  26946. message:
  26947. type: string
  26948. reason:
  26949. type: string
  26950. status:
  26951. type: string
  26952. type:
  26953. description: SecretStoreConditionType represents the condition type of the SecretStore.
  26954. type: string
  26955. required:
  26956. - status
  26957. - type
  26958. type: object
  26959. type: array
  26960. type: object
  26961. type: object
  26962. served: false
  26963. storage: false
  26964. subresources:
  26965. status: {}
  26966. ---
  26967. apiVersion: apiextensions.k8s.io/v1
  26968. kind: CustomResourceDefinition
  26969. metadata:
  26970. annotations:
  26971. controller-gen.kubebuilder.io/version: v0.19.0
  26972. labels:
  26973. external-secrets.io/component: controller
  26974. name: acraccesstokens.generators.external-secrets.io
  26975. spec:
  26976. group: generators.external-secrets.io
  26977. names:
  26978. categories:
  26979. - external-secrets
  26980. - external-secrets-generators
  26981. kind: ACRAccessToken
  26982. listKind: ACRAccessTokenList
  26983. plural: acraccesstokens
  26984. singular: acraccesstoken
  26985. scope: Namespaced
  26986. versions:
  26987. - name: v1alpha1
  26988. schema:
  26989. openAPIV3Schema:
  26990. description: |-
  26991. ACRAccessToken returns an Azure Container Registry token
  26992. that can be used for pushing/pulling images.
  26993. Note: by default it will return an ACR Refresh Token with full access
  26994. (depending on the identity).
  26995. This can be scoped down to the repository level using .spec.scope.
  26996. In case scope is defined it will return an ACR Access Token.
  26997. See docs: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md
  26998. properties:
  26999. apiVersion:
  27000. description: |-
  27001. APIVersion defines the versioned schema of this representation of an object.
  27002. Servers should convert recognized schemas to the latest internal value, and
  27003. may reject unrecognized values.
  27004. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27005. type: string
  27006. kind:
  27007. description: |-
  27008. Kind is a string value representing the REST resource this object represents.
  27009. Servers may infer this from the endpoint the client submits requests to.
  27010. Cannot be updated.
  27011. In CamelCase.
  27012. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27013. type: string
  27014. metadata:
  27015. type: object
  27016. spec:
  27017. description: |-
  27018. ACRAccessTokenSpec defines how to generate the access token
  27019. e.g. how to authenticate and which registry to use.
  27020. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  27021. properties:
  27022. auth:
  27023. description: ACRAuth defines the authentication methods for Azure Container Registry.
  27024. properties:
  27025. managedIdentity:
  27026. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  27027. properties:
  27028. identityId:
  27029. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  27030. type: string
  27031. type: object
  27032. servicePrincipal:
  27033. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  27034. properties:
  27035. secretRef:
  27036. description: |-
  27037. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  27038. It uses static credentials stored in a Kind=Secret.
  27039. properties:
  27040. clientId:
  27041. description: The Azure clientId of the service principle used for authentication.
  27042. properties:
  27043. key:
  27044. description: |-
  27045. A key in the referenced Secret.
  27046. Some instances of this field may be defaulted, in others it may be required.
  27047. maxLength: 253
  27048. minLength: 1
  27049. pattern: ^[-._a-zA-Z0-9]+$
  27050. type: string
  27051. name:
  27052. description: The name of the Secret resource being referred to.
  27053. maxLength: 253
  27054. minLength: 1
  27055. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27056. type: string
  27057. namespace:
  27058. description: |-
  27059. The namespace of the Secret resource being referred to.
  27060. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27061. maxLength: 63
  27062. minLength: 1
  27063. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27064. type: string
  27065. type: object
  27066. clientSecret:
  27067. description: The Azure ClientSecret of the service principle used for authentication.
  27068. properties:
  27069. key:
  27070. description: |-
  27071. A key in the referenced Secret.
  27072. Some instances of this field may be defaulted, in others it may be required.
  27073. maxLength: 253
  27074. minLength: 1
  27075. pattern: ^[-._a-zA-Z0-9]+$
  27076. type: string
  27077. name:
  27078. description: The name of the Secret resource being referred to.
  27079. maxLength: 253
  27080. minLength: 1
  27081. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27082. type: string
  27083. namespace:
  27084. description: |-
  27085. The namespace of the Secret resource being referred to.
  27086. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27087. maxLength: 63
  27088. minLength: 1
  27089. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27090. type: string
  27091. type: object
  27092. type: object
  27093. required:
  27094. - secretRef
  27095. type: object
  27096. workloadIdentity:
  27097. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  27098. properties:
  27099. serviceAccountRef:
  27100. description: |-
  27101. ServiceAccountRef specified the service account
  27102. that should be used when authenticating with WorkloadIdentity.
  27103. properties:
  27104. audiences:
  27105. description: |-
  27106. Audience specifies the `aud` claim for the service account token
  27107. Some providers automatically extend the audience field based on well-known annotations for workload
  27108. identity (e.g. IRSA or GCP Workload Identity)
  27109. items:
  27110. type: string
  27111. type: array
  27112. name:
  27113. description: The name of the ServiceAccount resource being referred to.
  27114. maxLength: 253
  27115. minLength: 1
  27116. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27117. type: string
  27118. namespace:
  27119. description: |-
  27120. Namespace of the resource being referred to.
  27121. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27122. maxLength: 63
  27123. minLength: 1
  27124. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27125. type: string
  27126. required:
  27127. - name
  27128. type: object
  27129. type: object
  27130. type: object
  27131. environmentType:
  27132. default: PublicCloud
  27133. description: |-
  27134. EnvironmentType specifies the Azure cloud environment endpoints to use for
  27135. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  27136. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  27137. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  27138. enum:
  27139. - PublicCloud
  27140. - USGovernmentCloud
  27141. - ChinaCloud
  27142. - GermanCloud
  27143. - AzureStackCloud
  27144. type: string
  27145. registry:
  27146. description: |-
  27147. the domain name of the ACR registry
  27148. e.g. foobarexample.azurecr.io
  27149. type: string
  27150. scope:
  27151. description: |-
  27152. Define the scope for the access token, e.g. pull/push access for a repository.
  27153. if not provided it will return a refresh token that has full scope.
  27154. Note: you need to pin it down to the repository level, there is no wildcard available.
  27155. examples:
  27156. repository:my-repository:pull,push
  27157. repository:my-repository:pull
  27158. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  27159. type: string
  27160. tenantId:
  27161. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  27162. type: string
  27163. required:
  27164. - auth
  27165. - registry
  27166. type: object
  27167. type: object
  27168. served: true
  27169. storage: true
  27170. subresources:
  27171. status: {}
  27172. ---
  27173. apiVersion: apiextensions.k8s.io/v1
  27174. kind: CustomResourceDefinition
  27175. metadata:
  27176. annotations:
  27177. controller-gen.kubebuilder.io/version: v0.19.0
  27178. labels:
  27179. external-secrets.io/component: controller
  27180. name: beyondtrustworkloadcredentialsdynamicsecrets.generators.external-secrets.io
  27181. spec:
  27182. group: generators.external-secrets.io
  27183. names:
  27184. categories:
  27185. - external-secrets
  27186. - external-secrets-generators
  27187. kind: BeyondtrustWorkloadCredentialsDynamicSecret
  27188. listKind: BeyondtrustWorkloadCredentialsDynamicSecretList
  27189. plural: beyondtrustworkloadcredentialsdynamicsecrets
  27190. singular: beyondtrustworkloadcredentialsdynamicsecret
  27191. scope: Namespaced
  27192. versions:
  27193. - name: v1alpha1
  27194. schema:
  27195. openAPIV3Schema:
  27196. description: |-
  27197. BeyondtrustWorkloadCredentialsDynamicSecret represents a generator that requests dynamic credentials from BeyondTrust Workload Credentials.
  27198. This generator calls the BeyondTrust Workload Credentials API to generate fresh, temporary credentials
  27199. (such as AWS STS credentials) each time an ExternalSecret is refreshed.
  27200. Dynamic secret definitions must be created in BeyondTrust Workload Credentials before they can be referenced.
  27201. For complete documentation, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27202. properties:
  27203. apiVersion:
  27204. description: |-
  27205. APIVersion defines the versioned schema of this representation of an object.
  27206. Servers should convert recognized schemas to the latest internal value, and
  27207. may reject unrecognized values.
  27208. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27209. type: string
  27210. kind:
  27211. description: |-
  27212. Kind is a string value representing the REST resource this object represents.
  27213. Servers may infer this from the endpoint the client submits requests to.
  27214. Cannot be updated.
  27215. In CamelCase.
  27216. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27217. type: string
  27218. metadata:
  27219. type: object
  27220. spec:
  27221. description: |-
  27222. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  27223. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  27224. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27225. properties:
  27226. controller:
  27227. description: |-
  27228. Controller selects the controller that should handle this generator.
  27229. Leave empty to use the default controller.
  27230. type: string
  27231. provider:
  27232. description: |-
  27233. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  27234. server connection details, and the folder path to the dynamic secret definition.
  27235. The folderPath should point to a dynamic secret definition that has been created in
  27236. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  27237. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27238. properties:
  27239. auth:
  27240. description: |-
  27241. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  27242. Currently supports API key authentication via Kubernetes secret reference.
  27243. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27244. properties:
  27245. apikey:
  27246. description: |-
  27247. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  27248. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  27249. properties:
  27250. token:
  27251. description: |-
  27252. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  27253. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  27254. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  27255. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27256. properties:
  27257. key:
  27258. description: |-
  27259. A key in the referenced Secret.
  27260. Some instances of this field may be defaulted, in others it may be required.
  27261. maxLength: 253
  27262. minLength: 1
  27263. pattern: ^[-._a-zA-Z0-9]+$
  27264. type: string
  27265. name:
  27266. description: The name of the Secret resource being referred to.
  27267. maxLength: 253
  27268. minLength: 1
  27269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27270. type: string
  27271. namespace:
  27272. description: |-
  27273. The namespace of the Secret resource being referred to.
  27274. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27275. maxLength: 63
  27276. minLength: 1
  27277. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27278. type: string
  27279. type: object
  27280. required:
  27281. - token
  27282. type: object
  27283. required:
  27284. - apikey
  27285. type: object
  27286. caBundle:
  27287. description: |-
  27288. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27289. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  27290. If not set, the system's trusted root certificates are used.
  27291. format: byte
  27292. type: string
  27293. caProvider:
  27294. description: |-
  27295. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  27296. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27297. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  27298. properties:
  27299. key:
  27300. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  27301. maxLength: 253
  27302. minLength: 1
  27303. pattern: ^[-._a-zA-Z0-9]+$
  27304. type: string
  27305. name:
  27306. description: The name of the object located at the provider type.
  27307. maxLength: 253
  27308. minLength: 1
  27309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27310. type: string
  27311. namespace:
  27312. description: |-
  27313. The namespace the Provider type is in.
  27314. Can only be defined when used in a ClusterSecretStore.
  27315. maxLength: 63
  27316. minLength: 1
  27317. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27318. type: string
  27319. type:
  27320. description: The type of provider to use such as "Secret", or "ConfigMap".
  27321. enum:
  27322. - Secret
  27323. - ConfigMap
  27324. type: string
  27325. required:
  27326. - name
  27327. - type
  27328. type: object
  27329. folderPath:
  27330. description: |-
  27331. FolderPath specifies the default folder path for secret retrieval.
  27332. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  27333. Example: "production/database" or "dev/api-keys"
  27334. Leave empty to retrieve secrets from the root folder.
  27335. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  27336. type: string
  27337. server:
  27338. description: |-
  27339. Server configures the BeyondTrust Workload Credentials server connection details.
  27340. Includes the API URL and Site ID for your BeyondTrust instance.
  27341. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27342. properties:
  27343. apiUrl:
  27344. description: |-
  27345. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  27346. This should be the full URL to your BeyondTrust instance.
  27347. Example: https://api.beyondtrust.io/siie
  27348. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  27349. type: string
  27350. siteId:
  27351. description: |-
  27352. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  27353. This identifier is unique to your BeyondTrust Workload Credentials instance.
  27354. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  27355. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  27356. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27357. type: string
  27358. required:
  27359. - apiUrl
  27360. - siteId
  27361. type: object
  27362. required:
  27363. - auth
  27364. - server
  27365. type: object
  27366. retrySettings:
  27367. description: |-
  27368. RetrySettings configures exponential backoff for failed API requests.
  27369. If not specified, uses the default retry settings.
  27370. properties:
  27371. maxRetries:
  27372. format: int32
  27373. type: integer
  27374. retryInterval:
  27375. type: string
  27376. type: object
  27377. required:
  27378. - provider
  27379. type: object
  27380. type: object
  27381. served: true
  27382. storage: true
  27383. subresources:
  27384. status: {}
  27385. ---
  27386. apiVersion: apiextensions.k8s.io/v1
  27387. kind: CustomResourceDefinition
  27388. metadata:
  27389. annotations:
  27390. controller-gen.kubebuilder.io/version: v0.19.0
  27391. labels:
  27392. external-secrets.io/component: controller
  27393. name: cloudsmithaccesstokens.generators.external-secrets.io
  27394. spec:
  27395. group: generators.external-secrets.io
  27396. names:
  27397. categories:
  27398. - external-secrets
  27399. - external-secrets-generators
  27400. kind: CloudsmithAccessToken
  27401. listKind: CloudsmithAccessTokenList
  27402. plural: cloudsmithaccesstokens
  27403. singular: cloudsmithaccesstoken
  27404. scope: Namespaced
  27405. versions:
  27406. - name: v1alpha1
  27407. schema:
  27408. openAPIV3Schema:
  27409. description: CloudsmithAccessToken generates Cloudsmith access token using OIDC authentication
  27410. properties:
  27411. apiVersion:
  27412. description: |-
  27413. APIVersion defines the versioned schema of this representation of an object.
  27414. Servers should convert recognized schemas to the latest internal value, and
  27415. may reject unrecognized values.
  27416. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27417. type: string
  27418. kind:
  27419. description: |-
  27420. Kind is a string value representing the REST resource this object represents.
  27421. Servers may infer this from the endpoint the client submits requests to.
  27422. Cannot be updated.
  27423. In CamelCase.
  27424. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27425. type: string
  27426. metadata:
  27427. type: object
  27428. spec:
  27429. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  27430. properties:
  27431. apiUrl:
  27432. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  27433. type: string
  27434. orgSlug:
  27435. description: OrgSlug is the organization slug in Cloudsmith
  27436. type: string
  27437. serviceAccountRef:
  27438. description: Name of the service account you are federating with
  27439. properties:
  27440. audiences:
  27441. description: |-
  27442. Audience specifies the `aud` claim for the service account token
  27443. Some providers automatically extend the audience field based on well-known annotations for workload
  27444. identity (e.g. IRSA or GCP Workload Identity)
  27445. items:
  27446. type: string
  27447. type: array
  27448. name:
  27449. description: The name of the ServiceAccount resource being referred to.
  27450. maxLength: 253
  27451. minLength: 1
  27452. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27453. type: string
  27454. namespace:
  27455. description: |-
  27456. Namespace of the resource being referred to.
  27457. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27458. maxLength: 63
  27459. minLength: 1
  27460. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27461. type: string
  27462. required:
  27463. - name
  27464. type: object
  27465. serviceSlug:
  27466. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  27467. type: string
  27468. required:
  27469. - orgSlug
  27470. - serviceAccountRef
  27471. - serviceSlug
  27472. type: object
  27473. type: object
  27474. served: true
  27475. storage: true
  27476. subresources:
  27477. status: {}
  27478. ---
  27479. apiVersion: apiextensions.k8s.io/v1
  27480. kind: CustomResourceDefinition
  27481. metadata:
  27482. annotations:
  27483. controller-gen.kubebuilder.io/version: v0.19.0
  27484. labels:
  27485. external-secrets.io/component: controller
  27486. name: clustergenerators.generators.external-secrets.io
  27487. spec:
  27488. group: generators.external-secrets.io
  27489. names:
  27490. categories:
  27491. - external-secrets
  27492. - external-secrets-generators
  27493. kind: ClusterGenerator
  27494. listKind: ClusterGeneratorList
  27495. plural: clustergenerators
  27496. singular: clustergenerator
  27497. scope: Cluster
  27498. versions:
  27499. - name: v1alpha1
  27500. schema:
  27501. openAPIV3Schema:
  27502. description: ClusterGenerator represents a cluster-wide generator which can be referenced as part of `generatorRef` fields.
  27503. properties:
  27504. apiVersion:
  27505. description: |-
  27506. APIVersion defines the versioned schema of this representation of an object.
  27507. Servers should convert recognized schemas to the latest internal value, and
  27508. may reject unrecognized values.
  27509. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27510. type: string
  27511. kind:
  27512. description: |-
  27513. Kind is a string value representing the REST resource this object represents.
  27514. Servers may infer this from the endpoint the client submits requests to.
  27515. Cannot be updated.
  27516. In CamelCase.
  27517. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27518. type: string
  27519. metadata:
  27520. type: object
  27521. spec:
  27522. description: ClusterGeneratorSpec defines the desired state of a ClusterGenerator.
  27523. properties:
  27524. generator:
  27525. description: Generator the spec for this generator, must match the kind.
  27526. maxProperties: 1
  27527. minProperties: 1
  27528. properties:
  27529. acrAccessTokenSpec:
  27530. description: |-
  27531. ACRAccessTokenSpec defines how to generate the access token
  27532. e.g. how to authenticate and which registry to use.
  27533. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  27534. properties:
  27535. auth:
  27536. description: ACRAuth defines the authentication methods for Azure Container Registry.
  27537. properties:
  27538. managedIdentity:
  27539. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  27540. properties:
  27541. identityId:
  27542. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  27543. type: string
  27544. type: object
  27545. servicePrincipal:
  27546. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  27547. properties:
  27548. secretRef:
  27549. description: |-
  27550. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  27551. It uses static credentials stored in a Kind=Secret.
  27552. properties:
  27553. clientId:
  27554. description: The Azure clientId of the service principle used for authentication.
  27555. properties:
  27556. key:
  27557. description: |-
  27558. A key in the referenced Secret.
  27559. Some instances of this field may be defaulted, in others it may be required.
  27560. maxLength: 253
  27561. minLength: 1
  27562. pattern: ^[-._a-zA-Z0-9]+$
  27563. type: string
  27564. name:
  27565. description: The name of the Secret resource being referred to.
  27566. maxLength: 253
  27567. minLength: 1
  27568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27569. type: string
  27570. namespace:
  27571. description: |-
  27572. The namespace of the Secret resource being referred to.
  27573. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27574. maxLength: 63
  27575. minLength: 1
  27576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27577. type: string
  27578. type: object
  27579. clientSecret:
  27580. description: The Azure ClientSecret of the service principle used for authentication.
  27581. properties:
  27582. key:
  27583. description: |-
  27584. A key in the referenced Secret.
  27585. Some instances of this field may be defaulted, in others it may be required.
  27586. maxLength: 253
  27587. minLength: 1
  27588. pattern: ^[-._a-zA-Z0-9]+$
  27589. type: string
  27590. name:
  27591. description: The name of the Secret resource being referred to.
  27592. maxLength: 253
  27593. minLength: 1
  27594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27595. type: string
  27596. namespace:
  27597. description: |-
  27598. The namespace of the Secret resource being referred to.
  27599. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27600. maxLength: 63
  27601. minLength: 1
  27602. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27603. type: string
  27604. type: object
  27605. type: object
  27606. required:
  27607. - secretRef
  27608. type: object
  27609. workloadIdentity:
  27610. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  27611. properties:
  27612. serviceAccountRef:
  27613. description: |-
  27614. ServiceAccountRef specified the service account
  27615. that should be used when authenticating with WorkloadIdentity.
  27616. properties:
  27617. audiences:
  27618. description: |-
  27619. Audience specifies the `aud` claim for the service account token
  27620. Some providers automatically extend the audience field based on well-known annotations for workload
  27621. identity (e.g. IRSA or GCP Workload Identity)
  27622. items:
  27623. type: string
  27624. type: array
  27625. name:
  27626. description: The name of the ServiceAccount resource being referred to.
  27627. maxLength: 253
  27628. minLength: 1
  27629. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27630. type: string
  27631. namespace:
  27632. description: |-
  27633. Namespace of the resource being referred to.
  27634. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27635. maxLength: 63
  27636. minLength: 1
  27637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27638. type: string
  27639. required:
  27640. - name
  27641. type: object
  27642. type: object
  27643. type: object
  27644. environmentType:
  27645. default: PublicCloud
  27646. description: |-
  27647. EnvironmentType specifies the Azure cloud environment endpoints to use for
  27648. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  27649. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  27650. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  27651. enum:
  27652. - PublicCloud
  27653. - USGovernmentCloud
  27654. - ChinaCloud
  27655. - GermanCloud
  27656. - AzureStackCloud
  27657. type: string
  27658. registry:
  27659. description: |-
  27660. the domain name of the ACR registry
  27661. e.g. foobarexample.azurecr.io
  27662. type: string
  27663. scope:
  27664. description: |-
  27665. Define the scope for the access token, e.g. pull/push access for a repository.
  27666. if not provided it will return a refresh token that has full scope.
  27667. Note: you need to pin it down to the repository level, there is no wildcard available.
  27668. examples:
  27669. repository:my-repository:pull,push
  27670. repository:my-repository:pull
  27671. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  27672. type: string
  27673. tenantId:
  27674. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  27675. type: string
  27676. required:
  27677. - auth
  27678. - registry
  27679. type: object
  27680. beyondtrustWorkloadCredentialsDynamicSecretSpec:
  27681. description: |-
  27682. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  27683. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  27684. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27685. properties:
  27686. controller:
  27687. description: |-
  27688. Controller selects the controller that should handle this generator.
  27689. Leave empty to use the default controller.
  27690. type: string
  27691. provider:
  27692. description: |-
  27693. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  27694. server connection details, and the folder path to the dynamic secret definition.
  27695. The folderPath should point to a dynamic secret definition that has been created in
  27696. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  27697. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27698. properties:
  27699. auth:
  27700. description: |-
  27701. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  27702. Currently supports API key authentication via Kubernetes secret reference.
  27703. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27704. properties:
  27705. apikey:
  27706. description: |-
  27707. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  27708. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  27709. properties:
  27710. token:
  27711. description: |-
  27712. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  27713. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  27714. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  27715. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27716. properties:
  27717. key:
  27718. description: |-
  27719. A key in the referenced Secret.
  27720. Some instances of this field may be defaulted, in others it may be required.
  27721. maxLength: 253
  27722. minLength: 1
  27723. pattern: ^[-._a-zA-Z0-9]+$
  27724. type: string
  27725. name:
  27726. description: The name of the Secret resource being referred to.
  27727. maxLength: 253
  27728. minLength: 1
  27729. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27730. type: string
  27731. namespace:
  27732. description: |-
  27733. The namespace of the Secret resource being referred to.
  27734. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27735. maxLength: 63
  27736. minLength: 1
  27737. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27738. type: string
  27739. type: object
  27740. required:
  27741. - token
  27742. type: object
  27743. required:
  27744. - apikey
  27745. type: object
  27746. caBundle:
  27747. description: |-
  27748. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27749. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  27750. If not set, the system's trusted root certificates are used.
  27751. format: byte
  27752. type: string
  27753. caProvider:
  27754. description: |-
  27755. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  27756. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27757. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  27758. properties:
  27759. key:
  27760. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  27761. maxLength: 253
  27762. minLength: 1
  27763. pattern: ^[-._a-zA-Z0-9]+$
  27764. type: string
  27765. name:
  27766. description: The name of the object located at the provider type.
  27767. maxLength: 253
  27768. minLength: 1
  27769. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27770. type: string
  27771. namespace:
  27772. description: |-
  27773. The namespace the Provider type is in.
  27774. Can only be defined when used in a ClusterSecretStore.
  27775. maxLength: 63
  27776. minLength: 1
  27777. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27778. type: string
  27779. type:
  27780. description: The type of provider to use such as "Secret", or "ConfigMap".
  27781. enum:
  27782. - Secret
  27783. - ConfigMap
  27784. type: string
  27785. required:
  27786. - name
  27787. - type
  27788. type: object
  27789. folderPath:
  27790. description: |-
  27791. FolderPath specifies the default folder path for secret retrieval.
  27792. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  27793. Example: "production/database" or "dev/api-keys"
  27794. Leave empty to retrieve secrets from the root folder.
  27795. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  27796. type: string
  27797. server:
  27798. description: |-
  27799. Server configures the BeyondTrust Workload Credentials server connection details.
  27800. Includes the API URL and Site ID for your BeyondTrust instance.
  27801. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27802. properties:
  27803. apiUrl:
  27804. description: |-
  27805. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  27806. This should be the full URL to your BeyondTrust instance.
  27807. Example: https://api.beyondtrust.io/siie
  27808. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  27809. type: string
  27810. siteId:
  27811. description: |-
  27812. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  27813. This identifier is unique to your BeyondTrust Workload Credentials instance.
  27814. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  27815. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  27816. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27817. type: string
  27818. required:
  27819. - apiUrl
  27820. - siteId
  27821. type: object
  27822. required:
  27823. - auth
  27824. - server
  27825. type: object
  27826. retrySettings:
  27827. description: |-
  27828. RetrySettings configures exponential backoff for failed API requests.
  27829. If not specified, uses the default retry settings.
  27830. properties:
  27831. maxRetries:
  27832. format: int32
  27833. type: integer
  27834. retryInterval:
  27835. type: string
  27836. type: object
  27837. required:
  27838. - provider
  27839. type: object
  27840. cloudsmithAccessTokenSpec:
  27841. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  27842. properties:
  27843. apiUrl:
  27844. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  27845. type: string
  27846. orgSlug:
  27847. description: OrgSlug is the organization slug in Cloudsmith
  27848. type: string
  27849. serviceAccountRef:
  27850. description: Name of the service account you are federating with
  27851. properties:
  27852. audiences:
  27853. description: |-
  27854. Audience specifies the `aud` claim for the service account token
  27855. Some providers automatically extend the audience field based on well-known annotations for workload
  27856. identity (e.g. IRSA or GCP Workload Identity)
  27857. items:
  27858. type: string
  27859. type: array
  27860. name:
  27861. description: The name of the ServiceAccount resource being referred to.
  27862. maxLength: 253
  27863. minLength: 1
  27864. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27865. type: string
  27866. namespace:
  27867. description: |-
  27868. Namespace of the resource being referred to.
  27869. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27870. maxLength: 63
  27871. minLength: 1
  27872. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27873. type: string
  27874. required:
  27875. - name
  27876. type: object
  27877. serviceSlug:
  27878. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  27879. type: string
  27880. required:
  27881. - orgSlug
  27882. - serviceAccountRef
  27883. - serviceSlug
  27884. type: object
  27885. ecrAuthorizationTokenSpec:
  27886. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  27887. properties:
  27888. auth:
  27889. description: Auth defines how to authenticate with AWS
  27890. properties:
  27891. jwt:
  27892. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  27893. properties:
  27894. serviceAccountRef:
  27895. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  27896. properties:
  27897. audiences:
  27898. description: |-
  27899. Audience specifies the `aud` claim for the service account token
  27900. Some providers automatically extend the audience field based on well-known annotations for workload
  27901. identity (e.g. IRSA or GCP Workload Identity)
  27902. items:
  27903. type: string
  27904. type: array
  27905. name:
  27906. description: The name of the ServiceAccount resource being referred to.
  27907. maxLength: 253
  27908. minLength: 1
  27909. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27910. type: string
  27911. namespace:
  27912. description: |-
  27913. Namespace of the resource being referred to.
  27914. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27915. maxLength: 63
  27916. minLength: 1
  27917. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27918. type: string
  27919. required:
  27920. - name
  27921. type: object
  27922. type: object
  27923. secretRef:
  27924. description: |-
  27925. AWSAuthSecretRef holds secret references for AWS credentials
  27926. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  27927. properties:
  27928. accessKeyIDSecretRef:
  27929. description: The AccessKeyID is used for authentication
  27930. properties:
  27931. key:
  27932. description: |-
  27933. A key in the referenced Secret.
  27934. Some instances of this field may be defaulted, in others it may be required.
  27935. maxLength: 253
  27936. minLength: 1
  27937. pattern: ^[-._a-zA-Z0-9]+$
  27938. type: string
  27939. name:
  27940. description: The name of the Secret resource being referred to.
  27941. maxLength: 253
  27942. minLength: 1
  27943. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27944. type: string
  27945. namespace:
  27946. description: |-
  27947. The namespace of the Secret resource being referred to.
  27948. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27949. maxLength: 63
  27950. minLength: 1
  27951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27952. type: string
  27953. type: object
  27954. secretAccessKeySecretRef:
  27955. description: The SecretAccessKey is used for authentication
  27956. properties:
  27957. key:
  27958. description: |-
  27959. A key in the referenced Secret.
  27960. Some instances of this field may be defaulted, in others it may be required.
  27961. maxLength: 253
  27962. minLength: 1
  27963. pattern: ^[-._a-zA-Z0-9]+$
  27964. type: string
  27965. name:
  27966. description: The name of the Secret resource being referred to.
  27967. maxLength: 253
  27968. minLength: 1
  27969. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27970. type: string
  27971. namespace:
  27972. description: |-
  27973. The namespace of the Secret resource being referred to.
  27974. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27975. maxLength: 63
  27976. minLength: 1
  27977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27978. type: string
  27979. type: object
  27980. sessionTokenSecretRef:
  27981. description: |-
  27982. The SessionToken used for authentication
  27983. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  27984. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  27985. properties:
  27986. key:
  27987. description: |-
  27988. A key in the referenced Secret.
  27989. Some instances of this field may be defaulted, in others it may be required.
  27990. maxLength: 253
  27991. minLength: 1
  27992. pattern: ^[-._a-zA-Z0-9]+$
  27993. type: string
  27994. name:
  27995. description: The name of the Secret resource being referred to.
  27996. maxLength: 253
  27997. minLength: 1
  27998. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27999. type: string
  28000. namespace:
  28001. description: |-
  28002. The namespace of the Secret resource being referred to.
  28003. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28004. maxLength: 63
  28005. minLength: 1
  28006. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28007. type: string
  28008. type: object
  28009. type: object
  28010. type: object
  28011. region:
  28012. description: Region specifies the region to operate in.
  28013. type: string
  28014. role:
  28015. description: |-
  28016. You can assume a role before making calls to the
  28017. desired AWS service.
  28018. type: string
  28019. scope:
  28020. description: |-
  28021. Scope specifies the ECR service scope.
  28022. Valid options are private and public.
  28023. type: string
  28024. required:
  28025. - region
  28026. type: object
  28027. fakeSpec:
  28028. description: FakeSpec contains the static data.
  28029. properties:
  28030. controller:
  28031. description: |-
  28032. Used to select the correct ESO controller (think: ingress.ingressClassName)
  28033. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  28034. type: string
  28035. data:
  28036. additionalProperties:
  28037. type: string
  28038. description: |-
  28039. Data defines the static data returned
  28040. by this generator.
  28041. type: object
  28042. type: object
  28043. gcrAccessTokenSpec:
  28044. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  28045. properties:
  28046. auth:
  28047. description: Auth defines the means for authenticating with GCP
  28048. properties:
  28049. secretRef:
  28050. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  28051. properties:
  28052. secretAccessKeySecretRef:
  28053. description: The SecretAccessKey is used for authentication
  28054. properties:
  28055. key:
  28056. description: |-
  28057. A key in the referenced Secret.
  28058. Some instances of this field may be defaulted, in others it may be required.
  28059. maxLength: 253
  28060. minLength: 1
  28061. pattern: ^[-._a-zA-Z0-9]+$
  28062. type: string
  28063. name:
  28064. description: The name of the Secret resource being referred to.
  28065. maxLength: 253
  28066. minLength: 1
  28067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28068. type: string
  28069. namespace:
  28070. description: |-
  28071. The namespace of the Secret resource being referred to.
  28072. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28073. maxLength: 63
  28074. minLength: 1
  28075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28076. type: string
  28077. type: object
  28078. type: object
  28079. workloadIdentity:
  28080. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  28081. properties:
  28082. clusterLocation:
  28083. type: string
  28084. clusterName:
  28085. type: string
  28086. clusterProjectID:
  28087. type: string
  28088. serviceAccountRef:
  28089. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28090. properties:
  28091. audiences:
  28092. description: |-
  28093. Audience specifies the `aud` claim for the service account token
  28094. Some providers automatically extend the audience field based on well-known annotations for workload
  28095. identity (e.g. IRSA or GCP Workload Identity)
  28096. items:
  28097. type: string
  28098. type: array
  28099. name:
  28100. description: The name of the ServiceAccount resource being referred to.
  28101. maxLength: 253
  28102. minLength: 1
  28103. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28104. type: string
  28105. namespace:
  28106. description: |-
  28107. Namespace of the resource being referred to.
  28108. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28109. maxLength: 63
  28110. minLength: 1
  28111. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28112. type: string
  28113. required:
  28114. - name
  28115. type: object
  28116. required:
  28117. - clusterLocation
  28118. - clusterName
  28119. - serviceAccountRef
  28120. type: object
  28121. workloadIdentityFederation:
  28122. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  28123. properties:
  28124. audience:
  28125. description: |-
  28126. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  28127. If specified, Audience found in the external account credential config will be overridden with the configured value.
  28128. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  28129. type: string
  28130. awsSecurityCredentials:
  28131. description: |-
  28132. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  28133. when using the AWS metadata server is not an option.
  28134. properties:
  28135. awsCredentialsSecretRef:
  28136. description: |-
  28137. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  28138. Secret should be created with below names for keys
  28139. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  28140. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  28141. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  28142. properties:
  28143. name:
  28144. description: name of the secret.
  28145. maxLength: 253
  28146. minLength: 1
  28147. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28148. type: string
  28149. namespace:
  28150. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  28151. maxLength: 63
  28152. minLength: 1
  28153. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28154. type: string
  28155. required:
  28156. - name
  28157. type: object
  28158. region:
  28159. description: region is for configuring the AWS region to be used.
  28160. example: ap-south-1
  28161. maxLength: 50
  28162. minLength: 1
  28163. pattern: ^[a-z0-9-]+$
  28164. type: string
  28165. required:
  28166. - awsCredentialsSecretRef
  28167. - region
  28168. type: object
  28169. credConfig:
  28170. description: |-
  28171. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  28172. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  28173. serviceAccountRef must be used by providing operators service account details.
  28174. properties:
  28175. key:
  28176. description: key name holding the external account credential config.
  28177. maxLength: 253
  28178. minLength: 1
  28179. pattern: ^[-._a-zA-Z0-9]+$
  28180. type: string
  28181. name:
  28182. description: name of the configmap.
  28183. maxLength: 253
  28184. minLength: 1
  28185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28186. type: string
  28187. namespace:
  28188. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  28189. maxLength: 63
  28190. minLength: 1
  28191. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28192. type: string
  28193. required:
  28194. - key
  28195. - name
  28196. type: object
  28197. externalTokenEndpoint:
  28198. description: |-
  28199. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  28200. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  28201. URL is having the expected value.
  28202. type: string
  28203. gcpServiceAccountEmail:
  28204. description: |-
  28205. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  28206. after Workload Identity Federation. Use this to grant access through the service account's
  28207. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  28208. service_account_impersonation_url in the external account JSON from credConfig;
  28209. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  28210. on that ServiceAccount.
  28211. example: my-gsa@my-project.iam.gserviceaccount.com
  28212. minLength: 1
  28213. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  28214. type: string
  28215. serviceAccountRef:
  28216. description: |-
  28217. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  28218. when Kubernetes is configured as provider in workload identity pool.
  28219. properties:
  28220. audiences:
  28221. description: |-
  28222. Audience specifies the `aud` claim for the service account token
  28223. Some providers automatically extend the audience field based on well-known annotations for workload
  28224. identity (e.g. IRSA or GCP Workload Identity)
  28225. items:
  28226. type: string
  28227. type: array
  28228. name:
  28229. description: The name of the ServiceAccount resource being referred to.
  28230. maxLength: 253
  28231. minLength: 1
  28232. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28233. type: string
  28234. namespace:
  28235. description: |-
  28236. Namespace of the resource being referred to.
  28237. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28238. maxLength: 63
  28239. minLength: 1
  28240. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28241. type: string
  28242. required:
  28243. - name
  28244. type: object
  28245. type: object
  28246. type: object
  28247. projectID:
  28248. description: ProjectID defines which project to use to authenticate with
  28249. type: string
  28250. required:
  28251. - auth
  28252. - projectID
  28253. type: object
  28254. githubAccessTokenSpec:
  28255. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  28256. properties:
  28257. appID:
  28258. type: string
  28259. auth:
  28260. description: Auth configures how ESO authenticates with a Github instance.
  28261. properties:
  28262. privateKey:
  28263. description: GithubSecretRef references a secret containing GitHub credentials.
  28264. properties:
  28265. secretRef:
  28266. description: |-
  28267. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28268. In some instances, `key` is a required field.
  28269. properties:
  28270. key:
  28271. description: |-
  28272. A key in the referenced Secret.
  28273. Some instances of this field may be defaulted, in others it may be required.
  28274. maxLength: 253
  28275. minLength: 1
  28276. pattern: ^[-._a-zA-Z0-9]+$
  28277. type: string
  28278. name:
  28279. description: The name of the Secret resource being referred to.
  28280. maxLength: 253
  28281. minLength: 1
  28282. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28283. type: string
  28284. namespace:
  28285. description: |-
  28286. The namespace of the Secret resource being referred to.
  28287. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28288. maxLength: 63
  28289. minLength: 1
  28290. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28291. type: string
  28292. type: object
  28293. required:
  28294. - secretRef
  28295. type: object
  28296. required:
  28297. - privateKey
  28298. type: object
  28299. installID:
  28300. type: string
  28301. permissions:
  28302. additionalProperties:
  28303. type: string
  28304. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  28305. type: object
  28306. repositories:
  28307. description: |-
  28308. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  28309. is installed to.
  28310. items:
  28311. type: string
  28312. type: array
  28313. url:
  28314. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  28315. type: string
  28316. required:
  28317. - appID
  28318. - auth
  28319. - installID
  28320. type: object
  28321. gitlabDeployTokenSpec:
  28322. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  28323. properties:
  28324. auth:
  28325. description: Auth configures how ESO authenticates with the GitLab API.
  28326. properties:
  28327. token:
  28328. description: |-
  28329. Token references a secret containing a GitLab access token (personal, group, or
  28330. project) with the api scope and at least the Maintainer role on the target.
  28331. properties:
  28332. secretRef:
  28333. description: |-
  28334. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28335. In some instances, `key` is a required field.
  28336. properties:
  28337. key:
  28338. description: |-
  28339. A key in the referenced Secret.
  28340. Some instances of this field may be defaulted, in others it may be required.
  28341. maxLength: 253
  28342. minLength: 1
  28343. pattern: ^[-._a-zA-Z0-9]+$
  28344. type: string
  28345. name:
  28346. description: The name of the Secret resource being referred to.
  28347. maxLength: 253
  28348. minLength: 1
  28349. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28350. type: string
  28351. namespace:
  28352. description: |-
  28353. The namespace of the Secret resource being referred to.
  28354. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28355. maxLength: 63
  28356. minLength: 1
  28357. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28358. type: string
  28359. type: object
  28360. required:
  28361. - secretRef
  28362. type: object
  28363. required:
  28364. - token
  28365. type: object
  28366. expiresAt:
  28367. description: |-
  28368. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  28369. not expire on the GitLab side and is revoked only when the generator state is
  28370. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  28371. format: date-time
  28372. type: string
  28373. groupID:
  28374. description: |-
  28375. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  28376. create the deploy token in. The generator URL-escapes paths before calling the
  28377. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  28378. minLength: 1
  28379. type: string
  28380. name:
  28381. description: Name of the deploy token.
  28382. minLength: 1
  28383. type: string
  28384. projectID:
  28385. description: |-
  28386. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  28387. project to create the deploy token in. The generator URL-escapes paths before
  28388. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  28389. minLength: 1
  28390. type: string
  28391. scopes:
  28392. description: Scopes granted to the deploy token. At least one scope is required.
  28393. items:
  28394. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  28395. enum:
  28396. - read_repository
  28397. - read_registry
  28398. - write_registry
  28399. - read_package_registry
  28400. - write_package_registry
  28401. - read_virtual_registry
  28402. - write_virtual_registry
  28403. type: string
  28404. minItems: 1
  28405. type: array
  28406. url:
  28407. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  28408. type: string
  28409. username:
  28410. description: |-
  28411. Username is an optional username for the deploy token. GitLab defaults it to
  28412. gitlab+deploy-token-{n} when omitted.
  28413. type: string
  28414. required:
  28415. - auth
  28416. - name
  28417. - scopes
  28418. type: object
  28419. x-kubernetes-validations:
  28420. - message: exactly one of projectID or groupID must be set
  28421. rule: has(self.projectID) != has(self.groupID)
  28422. grafanaSpec:
  28423. description: GrafanaSpec controls the behavior of the grafana generator.
  28424. properties:
  28425. auth:
  28426. description: |-
  28427. Auth is the authentication configuration to authenticate
  28428. against the Grafana instance.
  28429. properties:
  28430. basic:
  28431. description: |-
  28432. Basic auth credentials used to authenticate against the Grafana instance.
  28433. Note: you need a token which has elevated permissions to create service accounts.
  28434. See here for the documentation on basic roles offered by Grafana:
  28435. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28436. properties:
  28437. password:
  28438. description: A basic auth password used to authenticate against the Grafana instance.
  28439. properties:
  28440. key:
  28441. description: The key where the token is found.
  28442. maxLength: 253
  28443. minLength: 1
  28444. pattern: ^[-._a-zA-Z0-9]+$
  28445. type: string
  28446. name:
  28447. description: The name of the Secret resource being referred to.
  28448. maxLength: 253
  28449. minLength: 1
  28450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28451. type: string
  28452. type: object
  28453. username:
  28454. description: A basic auth username used to authenticate against the Grafana instance.
  28455. type: string
  28456. required:
  28457. - password
  28458. - username
  28459. type: object
  28460. token:
  28461. description: |-
  28462. A service account token used to authenticate against the Grafana instance.
  28463. Note: you need a token which has elevated permissions to create service accounts.
  28464. See here for the documentation on basic roles offered by Grafana:
  28465. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28466. properties:
  28467. key:
  28468. description: The key where the token is found.
  28469. maxLength: 253
  28470. minLength: 1
  28471. pattern: ^[-._a-zA-Z0-9]+$
  28472. type: string
  28473. name:
  28474. description: The name of the Secret resource being referred to.
  28475. maxLength: 253
  28476. minLength: 1
  28477. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28478. type: string
  28479. type: object
  28480. type: object
  28481. serviceAccount:
  28482. description: |-
  28483. ServiceAccount is the configuration for the service account that
  28484. is supposed to be generated by the generator.
  28485. properties:
  28486. name:
  28487. description: Name is the name of the service account that will be created by ESO.
  28488. type: string
  28489. role:
  28490. description: |-
  28491. Role is the role of the service account.
  28492. See here for the documentation on basic roles offered by Grafana:
  28493. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28494. type: string
  28495. secondsToLive:
  28496. description: |-
  28497. SecondsToLive is the number of seconds before the generated service account token will expire.
  28498. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  28499. format: int64
  28500. minimum: 1
  28501. type: integer
  28502. required:
  28503. - name
  28504. - role
  28505. type: object
  28506. url:
  28507. description: URL is the URL of the Grafana instance.
  28508. type: string
  28509. required:
  28510. - auth
  28511. - serviceAccount
  28512. - url
  28513. type: object
  28514. mfaSpec:
  28515. description: MFASpec controls the behavior of the mfa generator.
  28516. properties:
  28517. algorithm:
  28518. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  28519. type: string
  28520. length:
  28521. description: Length defines the token length. Defaults to 6 characters.
  28522. type: integer
  28523. secret:
  28524. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  28525. properties:
  28526. key:
  28527. description: |-
  28528. A key in the referenced Secret.
  28529. Some instances of this field may be defaulted, in others it may be required.
  28530. maxLength: 253
  28531. minLength: 1
  28532. pattern: ^[-._a-zA-Z0-9]+$
  28533. type: string
  28534. name:
  28535. description: The name of the Secret resource being referred to.
  28536. maxLength: 253
  28537. minLength: 1
  28538. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28539. type: string
  28540. namespace:
  28541. description: |-
  28542. The namespace of the Secret resource being referred to.
  28543. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28544. maxLength: 63
  28545. minLength: 1
  28546. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28547. type: string
  28548. type: object
  28549. timePeriod:
  28550. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  28551. type: integer
  28552. when:
  28553. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  28554. format: date-time
  28555. type: string
  28556. required:
  28557. - secret
  28558. type: object
  28559. passwordSpec:
  28560. description: PasswordSpec controls the behavior of the password generator.
  28561. properties:
  28562. allowRepeat:
  28563. default: false
  28564. description: set AllowRepeat to true to allow repeating characters.
  28565. type: boolean
  28566. digits:
  28567. description: |-
  28568. Digits specifies the number of digits in the generated
  28569. password. If omitted it defaults to 25% of the length of the password
  28570. type: integer
  28571. encoding:
  28572. default: raw
  28573. description: |-
  28574. Encoding specifies the encoding of the generated password.
  28575. Valid values are:
  28576. - "raw" (default): no encoding
  28577. - "base64": standard base64 encoding
  28578. - "base64url": base64url encoding
  28579. - "base32": base32 encoding
  28580. - "hex": hexadecimal encoding
  28581. enum:
  28582. - base64
  28583. - base64url
  28584. - base32
  28585. - hex
  28586. - raw
  28587. type: string
  28588. length:
  28589. default: 24
  28590. description: |-
  28591. Length of the password to be generated.
  28592. Defaults to 24
  28593. type: integer
  28594. noUpper:
  28595. default: false
  28596. description: Set NoUpper to disable uppercase characters
  28597. type: boolean
  28598. secretKeys:
  28599. description: |-
  28600. SecretKeys defines the keys that will be populated with generated passwords.
  28601. Defaults to "password" when not set.
  28602. items:
  28603. type: string
  28604. minItems: 1
  28605. type: array
  28606. symbolCharacters:
  28607. description: |-
  28608. SymbolCharacters specifies the special characters that should be used
  28609. in the generated password.
  28610. type: string
  28611. symbols:
  28612. description: |-
  28613. Symbols specifies the number of symbol characters in the generated
  28614. password. If omitted it defaults to 25% of the length of the password
  28615. type: integer
  28616. required:
  28617. - allowRepeat
  28618. - length
  28619. - noUpper
  28620. type: object
  28621. quayAccessTokenSpec:
  28622. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  28623. properties:
  28624. robotAccount:
  28625. description: Name of the robot account you are federating with
  28626. type: string
  28627. serviceAccountRef:
  28628. description: Name of the service account you are federating with
  28629. properties:
  28630. audiences:
  28631. description: |-
  28632. Audience specifies the `aud` claim for the service account token
  28633. Some providers automatically extend the audience field based on well-known annotations for workload
  28634. identity (e.g. IRSA or GCP Workload Identity)
  28635. items:
  28636. type: string
  28637. type: array
  28638. name:
  28639. description: The name of the ServiceAccount resource being referred to.
  28640. maxLength: 253
  28641. minLength: 1
  28642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28643. type: string
  28644. namespace:
  28645. description: |-
  28646. Namespace of the resource being referred to.
  28647. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28648. maxLength: 63
  28649. minLength: 1
  28650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28651. type: string
  28652. required:
  28653. - name
  28654. type: object
  28655. url:
  28656. description: URL configures the Quay instance URL. Defaults to quay.io.
  28657. type: string
  28658. required:
  28659. - robotAccount
  28660. - serviceAccountRef
  28661. type: object
  28662. sshKeySpec:
  28663. description: SSHKeySpec controls the behavior of the ssh key generator.
  28664. properties:
  28665. comment:
  28666. description: Comment specifies an optional comment for the SSH key
  28667. type: string
  28668. keySize:
  28669. description: |-
  28670. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  28671. For RSA keys: 2048, 3072, 4096
  28672. For ECDSA keys: 256, 384, 521
  28673. Ignored for ed25519 keys
  28674. maximum: 8192
  28675. minimum: 256
  28676. type: integer
  28677. keyType:
  28678. default: rsa
  28679. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  28680. enum:
  28681. - rsa
  28682. - ecdsa
  28683. - ed25519
  28684. type: string
  28685. type: object
  28686. stsSessionTokenSpec:
  28687. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  28688. properties:
  28689. auth:
  28690. description: Auth defines how to authenticate with AWS
  28691. properties:
  28692. jwt:
  28693. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  28694. properties:
  28695. serviceAccountRef:
  28696. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28697. properties:
  28698. audiences:
  28699. description: |-
  28700. Audience specifies the `aud` claim for the service account token
  28701. Some providers automatically extend the audience field based on well-known annotations for workload
  28702. identity (e.g. IRSA or GCP Workload Identity)
  28703. items:
  28704. type: string
  28705. type: array
  28706. name:
  28707. description: The name of the ServiceAccount resource being referred to.
  28708. maxLength: 253
  28709. minLength: 1
  28710. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28711. type: string
  28712. namespace:
  28713. description: |-
  28714. Namespace of the resource being referred to.
  28715. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28716. maxLength: 63
  28717. minLength: 1
  28718. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28719. type: string
  28720. required:
  28721. - name
  28722. type: object
  28723. type: object
  28724. secretRef:
  28725. description: |-
  28726. AWSAuthSecretRef holds secret references for AWS credentials
  28727. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  28728. properties:
  28729. accessKeyIDSecretRef:
  28730. description: The AccessKeyID is used for authentication
  28731. properties:
  28732. key:
  28733. description: |-
  28734. A key in the referenced Secret.
  28735. Some instances of this field may be defaulted, in others it may be required.
  28736. maxLength: 253
  28737. minLength: 1
  28738. pattern: ^[-._a-zA-Z0-9]+$
  28739. type: string
  28740. name:
  28741. description: The name of the Secret resource being referred to.
  28742. maxLength: 253
  28743. minLength: 1
  28744. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28745. type: string
  28746. namespace:
  28747. description: |-
  28748. The namespace of the Secret resource being referred to.
  28749. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28750. maxLength: 63
  28751. minLength: 1
  28752. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28753. type: string
  28754. type: object
  28755. secretAccessKeySecretRef:
  28756. description: The SecretAccessKey is used for authentication
  28757. properties:
  28758. key:
  28759. description: |-
  28760. A key in the referenced Secret.
  28761. Some instances of this field may be defaulted, in others it may be required.
  28762. maxLength: 253
  28763. minLength: 1
  28764. pattern: ^[-._a-zA-Z0-9]+$
  28765. type: string
  28766. name:
  28767. description: The name of the Secret resource being referred to.
  28768. maxLength: 253
  28769. minLength: 1
  28770. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28771. type: string
  28772. namespace:
  28773. description: |-
  28774. The namespace of the Secret resource being referred to.
  28775. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28776. maxLength: 63
  28777. minLength: 1
  28778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28779. type: string
  28780. type: object
  28781. sessionTokenSecretRef:
  28782. description: |-
  28783. The SessionToken used for authentication
  28784. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28785. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28786. properties:
  28787. key:
  28788. description: |-
  28789. A key in the referenced Secret.
  28790. Some instances of this field may be defaulted, in others it may be required.
  28791. maxLength: 253
  28792. minLength: 1
  28793. pattern: ^[-._a-zA-Z0-9]+$
  28794. type: string
  28795. name:
  28796. description: The name of the Secret resource being referred to.
  28797. maxLength: 253
  28798. minLength: 1
  28799. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28800. type: string
  28801. namespace:
  28802. description: |-
  28803. The namespace of the Secret resource being referred to.
  28804. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28805. maxLength: 63
  28806. minLength: 1
  28807. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28808. type: string
  28809. type: object
  28810. type: object
  28811. type: object
  28812. region:
  28813. description: Region specifies the region to operate in.
  28814. type: string
  28815. requestParameters:
  28816. description: RequestParameters contains parameters that can be passed to the STS service.
  28817. properties:
  28818. serialNumber:
  28819. description: |-
  28820. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  28821. the GetSessionToken call.
  28822. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  28823. (such as arn:aws:iam::123456789012:mfa/user)
  28824. type: string
  28825. sessionDuration:
  28826. format: int32
  28827. type: integer
  28828. tokenCode:
  28829. description: TokenCode is the value provided by the MFA device, if MFA is required.
  28830. type: string
  28831. type: object
  28832. role:
  28833. description: |-
  28834. You can assume a role before making calls to the
  28835. desired AWS service.
  28836. type: string
  28837. required:
  28838. - region
  28839. type: object
  28840. uuidSpec:
  28841. description: UUIDSpec controls the behavior of the uuid generator.
  28842. type: object
  28843. vaultDynamicSecretSpec:
  28844. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  28845. properties:
  28846. allowEmptyResponse:
  28847. default: false
  28848. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  28849. type: boolean
  28850. controller:
  28851. description: |-
  28852. Used to select the correct ESO controller (think: ingress.ingressClassName)
  28853. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  28854. type: string
  28855. getParameters:
  28856. additionalProperties:
  28857. items:
  28858. type: string
  28859. type: array
  28860. description: |-
  28861. GetParameters are query-string parameters passed to Vault on GET calls.
  28862. Each key may map to multiple values, matching HTTP query-string semantics.
  28863. Ignored for non-GET methods; use Parameters for write bodies.
  28864. type: object
  28865. method:
  28866. description: Vault API method to use (GET/POST/other)
  28867. type: string
  28868. parameters:
  28869. description: Parameters to pass to Vault write (for non-GET methods)
  28870. x-kubernetes-preserve-unknown-fields: true
  28871. path:
  28872. description: Vault path to obtain the dynamic secret from
  28873. type: string
  28874. provider:
  28875. description: Vault provider common spec
  28876. properties:
  28877. auth:
  28878. description: Auth configures how secret-manager authenticates with the Vault server.
  28879. properties:
  28880. appRole:
  28881. description: |-
  28882. AppRole authenticates with Vault using the App Role auth mechanism,
  28883. with the role and secret stored in a Kubernetes Secret resource.
  28884. properties:
  28885. path:
  28886. default: approle
  28887. description: |-
  28888. Path where the App Role authentication backend is mounted
  28889. in Vault, e.g: "approle"
  28890. type: string
  28891. roleId:
  28892. description: |-
  28893. RoleID configured in the App Role authentication backend when setting
  28894. up the authentication backend in Vault.
  28895. type: string
  28896. roleRef:
  28897. description: |-
  28898. Reference to a key in a Secret that contains the App Role ID used
  28899. to authenticate with Vault.
  28900. The `key` field must be specified and denotes which entry within the Secret
  28901. resource is used as the app role id.
  28902. properties:
  28903. key:
  28904. description: |-
  28905. A key in the referenced Secret.
  28906. Some instances of this field may be defaulted, in others it may be required.
  28907. maxLength: 253
  28908. minLength: 1
  28909. pattern: ^[-._a-zA-Z0-9]+$
  28910. type: string
  28911. name:
  28912. description: The name of the Secret resource being referred to.
  28913. maxLength: 253
  28914. minLength: 1
  28915. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28916. type: string
  28917. namespace:
  28918. description: |-
  28919. The namespace of the Secret resource being referred to.
  28920. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28921. maxLength: 63
  28922. minLength: 1
  28923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28924. type: string
  28925. type: object
  28926. secretRef:
  28927. description: |-
  28928. Reference to a key in a Secret that contains the App Role secret used
  28929. to authenticate with Vault.
  28930. The `key` field must be specified and denotes which entry within the Secret
  28931. resource is used as the app role secret.
  28932. properties:
  28933. key:
  28934. description: |-
  28935. A key in the referenced Secret.
  28936. Some instances of this field may be defaulted, in others it may be required.
  28937. maxLength: 253
  28938. minLength: 1
  28939. pattern: ^[-._a-zA-Z0-9]+$
  28940. type: string
  28941. name:
  28942. description: The name of the Secret resource being referred to.
  28943. maxLength: 253
  28944. minLength: 1
  28945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28946. type: string
  28947. namespace:
  28948. description: |-
  28949. The namespace of the Secret resource being referred to.
  28950. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28951. maxLength: 63
  28952. minLength: 1
  28953. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28954. type: string
  28955. type: object
  28956. required:
  28957. - path
  28958. - secretRef
  28959. type: object
  28960. cert:
  28961. description: |-
  28962. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  28963. Cert authentication method
  28964. properties:
  28965. clientCert:
  28966. description: |-
  28967. ClientCert is a certificate to authenticate using the Cert Vault
  28968. authentication method
  28969. properties:
  28970. key:
  28971. description: |-
  28972. A key in the referenced Secret.
  28973. Some instances of this field may be defaulted, in others it may be required.
  28974. maxLength: 253
  28975. minLength: 1
  28976. pattern: ^[-._a-zA-Z0-9]+$
  28977. type: string
  28978. name:
  28979. description: The name of the Secret resource being referred to.
  28980. maxLength: 253
  28981. minLength: 1
  28982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28983. type: string
  28984. namespace:
  28985. description: |-
  28986. The namespace of the Secret resource being referred to.
  28987. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28988. maxLength: 63
  28989. minLength: 1
  28990. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28991. type: string
  28992. type: object
  28993. path:
  28994. default: cert
  28995. description: |-
  28996. Path where the Certificate authentication backend is mounted
  28997. in Vault, e.g: "cert"
  28998. type: string
  28999. secretRef:
  29000. description: |-
  29001. SecretRef to a key in a Secret resource containing client private key to
  29002. authenticate with Vault using the Cert authentication method
  29003. properties:
  29004. key:
  29005. description: |-
  29006. A key in the referenced Secret.
  29007. Some instances of this field may be defaulted, in others it may be required.
  29008. maxLength: 253
  29009. minLength: 1
  29010. pattern: ^[-._a-zA-Z0-9]+$
  29011. type: string
  29012. name:
  29013. description: The name of the Secret resource being referred to.
  29014. maxLength: 253
  29015. minLength: 1
  29016. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29017. type: string
  29018. namespace:
  29019. description: |-
  29020. The namespace of the Secret resource being referred to.
  29021. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29022. maxLength: 63
  29023. minLength: 1
  29024. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29025. type: string
  29026. type: object
  29027. vaultRole:
  29028. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  29029. type: string
  29030. type: object
  29031. gcp:
  29032. description: |-
  29033. Gcp authenticates with Vault using Google Cloud Platform authentication method
  29034. GCP authentication method
  29035. properties:
  29036. location:
  29037. description: Location optionally defines a location/region for the secret
  29038. type: string
  29039. path:
  29040. default: gcp
  29041. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  29042. type: string
  29043. projectID:
  29044. description: Project ID of the Google Cloud Platform project
  29045. type: string
  29046. role:
  29047. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  29048. type: string
  29049. secretRef:
  29050. description: Specify credentials in a Secret object
  29051. properties:
  29052. secretAccessKeySecretRef:
  29053. description: The SecretAccessKey is used for authentication
  29054. properties:
  29055. key:
  29056. description: |-
  29057. A key in the referenced Secret.
  29058. Some instances of this field may be defaulted, in others it may be required.
  29059. maxLength: 253
  29060. minLength: 1
  29061. pattern: ^[-._a-zA-Z0-9]+$
  29062. type: string
  29063. name:
  29064. description: The name of the Secret resource being referred to.
  29065. maxLength: 253
  29066. minLength: 1
  29067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29068. type: string
  29069. namespace:
  29070. description: |-
  29071. The namespace of the Secret resource being referred to.
  29072. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29073. maxLength: 63
  29074. minLength: 1
  29075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29076. type: string
  29077. type: object
  29078. type: object
  29079. serviceAccountRef:
  29080. description: ServiceAccountRef to a service account for impersonation
  29081. properties:
  29082. audiences:
  29083. description: |-
  29084. Audience specifies the `aud` claim for the service account token
  29085. Some providers automatically extend the audience field based on well-known annotations for workload
  29086. identity (e.g. IRSA or GCP Workload Identity)
  29087. items:
  29088. type: string
  29089. type: array
  29090. name:
  29091. description: The name of the ServiceAccount resource being referred to.
  29092. maxLength: 253
  29093. minLength: 1
  29094. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29095. type: string
  29096. namespace:
  29097. description: |-
  29098. Namespace of the resource being referred to.
  29099. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29100. maxLength: 63
  29101. minLength: 1
  29102. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29103. type: string
  29104. required:
  29105. - name
  29106. type: object
  29107. workloadIdentity:
  29108. description: Specify a service account with Workload Identity
  29109. properties:
  29110. clusterLocation:
  29111. description: |-
  29112. ClusterLocation is the location of the cluster
  29113. If not specified, it fetches information from the metadata server
  29114. type: string
  29115. clusterName:
  29116. description: |-
  29117. ClusterName is the name of the cluster
  29118. If not specified, it fetches information from the metadata server
  29119. type: string
  29120. clusterProjectID:
  29121. description: |-
  29122. ClusterProjectID is the project ID of the cluster
  29123. If not specified, it fetches information from the metadata server
  29124. type: string
  29125. serviceAccountRef:
  29126. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29127. properties:
  29128. audiences:
  29129. description: |-
  29130. Audience specifies the `aud` claim for the service account token
  29131. Some providers automatically extend the audience field based on well-known annotations for workload
  29132. identity (e.g. IRSA or GCP Workload Identity)
  29133. items:
  29134. type: string
  29135. type: array
  29136. name:
  29137. description: The name of the ServiceAccount resource being referred to.
  29138. maxLength: 253
  29139. minLength: 1
  29140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29141. type: string
  29142. namespace:
  29143. description: |-
  29144. Namespace of the resource being referred to.
  29145. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29146. maxLength: 63
  29147. minLength: 1
  29148. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29149. type: string
  29150. required:
  29151. - name
  29152. type: object
  29153. required:
  29154. - serviceAccountRef
  29155. type: object
  29156. required:
  29157. - role
  29158. type: object
  29159. iam:
  29160. description: |-
  29161. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  29162. AWS IAM authentication method
  29163. properties:
  29164. externalID:
  29165. description: AWS External ID set on assumed IAM roles
  29166. type: string
  29167. jwt:
  29168. description: Specify a service account with IRSA enabled
  29169. properties:
  29170. serviceAccountRef:
  29171. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29172. properties:
  29173. audiences:
  29174. description: |-
  29175. Audience specifies the `aud` claim for the service account token
  29176. Some providers automatically extend the audience field based on well-known annotations for workload
  29177. identity (e.g. IRSA or GCP Workload Identity)
  29178. items:
  29179. type: string
  29180. type: array
  29181. name:
  29182. description: The name of the ServiceAccount resource being referred to.
  29183. maxLength: 253
  29184. minLength: 1
  29185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29186. type: string
  29187. namespace:
  29188. description: |-
  29189. Namespace of the resource being referred to.
  29190. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29191. maxLength: 63
  29192. minLength: 1
  29193. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29194. type: string
  29195. required:
  29196. - name
  29197. type: object
  29198. type: object
  29199. path:
  29200. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  29201. type: string
  29202. region:
  29203. description: AWS region
  29204. type: string
  29205. role:
  29206. description: This is the AWS role to be assumed before talking to vault
  29207. type: string
  29208. secretRef:
  29209. description: Specify credentials in a Secret object
  29210. properties:
  29211. accessKeyIDSecretRef:
  29212. description: The AccessKeyID is used for authentication
  29213. properties:
  29214. key:
  29215. description: |-
  29216. A key in the referenced Secret.
  29217. Some instances of this field may be defaulted, in others it may be required.
  29218. maxLength: 253
  29219. minLength: 1
  29220. pattern: ^[-._a-zA-Z0-9]+$
  29221. type: string
  29222. name:
  29223. description: The name of the Secret resource being referred to.
  29224. maxLength: 253
  29225. minLength: 1
  29226. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29227. type: string
  29228. namespace:
  29229. description: |-
  29230. The namespace of the Secret resource being referred to.
  29231. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29232. maxLength: 63
  29233. minLength: 1
  29234. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29235. type: string
  29236. type: object
  29237. secretAccessKeySecretRef:
  29238. description: The SecretAccessKey is used for authentication
  29239. properties:
  29240. key:
  29241. description: |-
  29242. A key in the referenced Secret.
  29243. Some instances of this field may be defaulted, in others it may be required.
  29244. maxLength: 253
  29245. minLength: 1
  29246. pattern: ^[-._a-zA-Z0-9]+$
  29247. type: string
  29248. name:
  29249. description: The name of the Secret resource being referred to.
  29250. maxLength: 253
  29251. minLength: 1
  29252. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29253. type: string
  29254. namespace:
  29255. description: |-
  29256. The namespace of the Secret resource being referred to.
  29257. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29258. maxLength: 63
  29259. minLength: 1
  29260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29261. type: string
  29262. type: object
  29263. sessionTokenSecretRef:
  29264. description: |-
  29265. The SessionToken used for authentication
  29266. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  29267. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  29268. properties:
  29269. key:
  29270. description: |-
  29271. A key in the referenced Secret.
  29272. Some instances of this field may be defaulted, in others it may be required.
  29273. maxLength: 253
  29274. minLength: 1
  29275. pattern: ^[-._a-zA-Z0-9]+$
  29276. type: string
  29277. name:
  29278. description: The name of the Secret resource being referred to.
  29279. maxLength: 253
  29280. minLength: 1
  29281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29282. type: string
  29283. namespace:
  29284. description: |-
  29285. The namespace of the Secret resource being referred to.
  29286. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29287. maxLength: 63
  29288. minLength: 1
  29289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29290. type: string
  29291. type: object
  29292. type: object
  29293. vaultAwsIamServerID:
  29294. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  29295. type: string
  29296. vaultRole:
  29297. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  29298. type: string
  29299. required:
  29300. - vaultRole
  29301. type: object
  29302. jwt:
  29303. description: |-
  29304. Jwt authenticates with Vault by passing role and JWT token using the
  29305. JWT/OIDC authentication method
  29306. properties:
  29307. kubernetesServiceAccountToken:
  29308. description: |-
  29309. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  29310. a token for with the `TokenRequest` API.
  29311. properties:
  29312. audiences:
  29313. description: |-
  29314. Optional audiences field that will be used to request a temporary Kubernetes service
  29315. account token for the service account referenced by `serviceAccountRef`.
  29316. Defaults to a single audience `vault` it not specified.
  29317. Deprecated: use serviceAccountRef.Audiences instead
  29318. items:
  29319. type: string
  29320. type: array
  29321. expirationSeconds:
  29322. description: |-
  29323. Optional expiration time in seconds that will be used to request a temporary
  29324. Kubernetes service account token for the service account referenced by
  29325. `serviceAccountRef`.
  29326. Deprecated: this will be removed in the future.
  29327. Defaults to 10 minutes.
  29328. format: int64
  29329. type: integer
  29330. serviceAccountRef:
  29331. description: Service account field containing the name of a kubernetes ServiceAccount.
  29332. properties:
  29333. audiences:
  29334. description: |-
  29335. Audience specifies the `aud` claim for the service account token
  29336. Some providers automatically extend the audience field based on well-known annotations for workload
  29337. identity (e.g. IRSA or GCP Workload Identity)
  29338. items:
  29339. type: string
  29340. type: array
  29341. name:
  29342. description: The name of the ServiceAccount resource being referred to.
  29343. maxLength: 253
  29344. minLength: 1
  29345. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29346. type: string
  29347. namespace:
  29348. description: |-
  29349. Namespace of the resource being referred to.
  29350. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29351. maxLength: 63
  29352. minLength: 1
  29353. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29354. type: string
  29355. required:
  29356. - name
  29357. type: object
  29358. required:
  29359. - serviceAccountRef
  29360. type: object
  29361. path:
  29362. default: jwt
  29363. description: |-
  29364. Path where the JWT authentication backend is mounted
  29365. in Vault, e.g: "jwt"
  29366. type: string
  29367. role:
  29368. description: |-
  29369. Role is a JWT role to authenticate using the JWT/OIDC Vault
  29370. authentication method
  29371. type: string
  29372. secretRef:
  29373. description: |-
  29374. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  29375. authenticate with Vault using the JWT/OIDC authentication method.
  29376. properties:
  29377. key:
  29378. description: |-
  29379. A key in the referenced Secret.
  29380. Some instances of this field may be defaulted, in others it may be required.
  29381. maxLength: 253
  29382. minLength: 1
  29383. pattern: ^[-._a-zA-Z0-9]+$
  29384. type: string
  29385. name:
  29386. description: The name of the Secret resource being referred to.
  29387. maxLength: 253
  29388. minLength: 1
  29389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29390. type: string
  29391. namespace:
  29392. description: |-
  29393. The namespace of the Secret resource being referred to.
  29394. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29395. maxLength: 63
  29396. minLength: 1
  29397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29398. type: string
  29399. type: object
  29400. required:
  29401. - path
  29402. type: object
  29403. kubernetes:
  29404. description: |-
  29405. Kubernetes authenticates with Vault by passing the ServiceAccount
  29406. token stored in the named Secret resource to the Vault server.
  29407. properties:
  29408. mountPath:
  29409. default: kubernetes
  29410. description: |-
  29411. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  29412. "kubernetes"
  29413. type: string
  29414. role:
  29415. description: |-
  29416. A required field containing the Vault Role to assume. A Role binds a
  29417. Kubernetes ServiceAccount with a set of Vault policies.
  29418. type: string
  29419. secretRef:
  29420. description: |-
  29421. Optional secret field containing a Kubernetes ServiceAccount JWT used
  29422. for authenticating with Vault. If a name is specified without a key,
  29423. `token` is the default. If one is not specified, the one bound to
  29424. the controller will be used.
  29425. properties:
  29426. key:
  29427. description: |-
  29428. A key in the referenced Secret.
  29429. Some instances of this field may be defaulted, in others it may be required.
  29430. maxLength: 253
  29431. minLength: 1
  29432. pattern: ^[-._a-zA-Z0-9]+$
  29433. type: string
  29434. name:
  29435. description: The name of the Secret resource being referred to.
  29436. maxLength: 253
  29437. minLength: 1
  29438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29439. type: string
  29440. namespace:
  29441. description: |-
  29442. The namespace of the Secret resource being referred to.
  29443. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29444. maxLength: 63
  29445. minLength: 1
  29446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29447. type: string
  29448. type: object
  29449. serviceAccountRef:
  29450. description: |-
  29451. Optional service account field containing the name of a kubernetes ServiceAccount.
  29452. If the service account is specified, the service account secret token JWT will be used
  29453. for authenticating with Vault. If the service account selector is not supplied,
  29454. the secretRef will be used instead.
  29455. properties:
  29456. audiences:
  29457. description: |-
  29458. Audience specifies the `aud` claim for the service account token
  29459. Some providers automatically extend the audience field based on well-known annotations for workload
  29460. identity (e.g. IRSA or GCP Workload Identity)
  29461. items:
  29462. type: string
  29463. type: array
  29464. name:
  29465. description: The name of the ServiceAccount resource being referred to.
  29466. maxLength: 253
  29467. minLength: 1
  29468. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29469. type: string
  29470. namespace:
  29471. description: |-
  29472. Namespace of the resource being referred to.
  29473. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29474. maxLength: 63
  29475. minLength: 1
  29476. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29477. type: string
  29478. required:
  29479. - name
  29480. type: object
  29481. required:
  29482. - mountPath
  29483. - role
  29484. type: object
  29485. ldap:
  29486. description: |-
  29487. Ldap authenticates with Vault by passing username/password pair using
  29488. the LDAP authentication method
  29489. properties:
  29490. path:
  29491. default: ldap
  29492. description: |-
  29493. Path where the LDAP authentication backend is mounted
  29494. in Vault, e.g: "ldap"
  29495. type: string
  29496. secretRef:
  29497. description: |-
  29498. SecretRef to a key in a Secret resource containing password for the LDAP
  29499. user used to authenticate with Vault using the LDAP authentication
  29500. method
  29501. properties:
  29502. key:
  29503. description: |-
  29504. A key in the referenced Secret.
  29505. Some instances of this field may be defaulted, in others it may be required.
  29506. maxLength: 253
  29507. minLength: 1
  29508. pattern: ^[-._a-zA-Z0-9]+$
  29509. type: string
  29510. name:
  29511. description: The name of the Secret resource being referred to.
  29512. maxLength: 253
  29513. minLength: 1
  29514. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29515. type: string
  29516. namespace:
  29517. description: |-
  29518. The namespace of the Secret resource being referred to.
  29519. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29520. maxLength: 63
  29521. minLength: 1
  29522. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29523. type: string
  29524. type: object
  29525. username:
  29526. description: |-
  29527. Username is an LDAP username used to authenticate using the LDAP Vault
  29528. authentication method
  29529. type: string
  29530. required:
  29531. - path
  29532. - username
  29533. type: object
  29534. namespace:
  29535. description: |-
  29536. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  29537. Namespaces is a set of features within Vault Enterprise that allows
  29538. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  29539. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  29540. This will default to Vault.Namespace field if set, or empty otherwise
  29541. type: string
  29542. tokenSecretRef:
  29543. description: TokenSecretRef authenticates with Vault by presenting a token.
  29544. properties:
  29545. key:
  29546. description: |-
  29547. A key in the referenced Secret.
  29548. Some instances of this field may be defaulted, in others it may be required.
  29549. maxLength: 253
  29550. minLength: 1
  29551. pattern: ^[-._a-zA-Z0-9]+$
  29552. type: string
  29553. name:
  29554. description: The name of the Secret resource being referred to.
  29555. maxLength: 253
  29556. minLength: 1
  29557. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29558. type: string
  29559. namespace:
  29560. description: |-
  29561. The namespace of the Secret resource being referred to.
  29562. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29563. maxLength: 63
  29564. minLength: 1
  29565. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29566. type: string
  29567. type: object
  29568. userPass:
  29569. description: UserPass authenticates with Vault by passing username/password pair
  29570. properties:
  29571. path:
  29572. default: userpass
  29573. description: |-
  29574. Path where the UserPassword authentication backend is mounted
  29575. in Vault, e.g: "userpass"
  29576. type: string
  29577. secretRef:
  29578. description: |-
  29579. SecretRef to a key in a Secret resource containing password for the
  29580. user used to authenticate with Vault using the UserPass authentication
  29581. method
  29582. properties:
  29583. key:
  29584. description: |-
  29585. A key in the referenced Secret.
  29586. Some instances of this field may be defaulted, in others it may be required.
  29587. maxLength: 253
  29588. minLength: 1
  29589. pattern: ^[-._a-zA-Z0-9]+$
  29590. type: string
  29591. name:
  29592. description: The name of the Secret resource being referred to.
  29593. maxLength: 253
  29594. minLength: 1
  29595. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29596. type: string
  29597. namespace:
  29598. description: |-
  29599. The namespace of the Secret resource being referred to.
  29600. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29601. maxLength: 63
  29602. minLength: 1
  29603. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29604. type: string
  29605. type: object
  29606. username:
  29607. description: |-
  29608. Username is a username used to authenticate using the UserPass Vault
  29609. authentication method
  29610. type: string
  29611. required:
  29612. - path
  29613. - username
  29614. type: object
  29615. type: object
  29616. caBundle:
  29617. description: |-
  29618. PEM encoded CA bundle used to validate Vault server certificate. Only used
  29619. if the Server URL is using HTTPS protocol. This parameter is ignored for
  29620. plain HTTP protocol connection. If not set the system root certificates
  29621. are used to validate the TLS connection.
  29622. format: byte
  29623. type: string
  29624. caProvider:
  29625. description: The provider for the CA bundle to use to validate Vault server certificate.
  29626. properties:
  29627. key:
  29628. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  29629. maxLength: 253
  29630. minLength: 1
  29631. pattern: ^[-._a-zA-Z0-9]+$
  29632. type: string
  29633. name:
  29634. description: The name of the object located at the provider type.
  29635. maxLength: 253
  29636. minLength: 1
  29637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29638. type: string
  29639. namespace:
  29640. description: |-
  29641. The namespace the Provider type is in.
  29642. Can only be defined when used in a ClusterSecretStore.
  29643. maxLength: 63
  29644. minLength: 1
  29645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29646. type: string
  29647. type:
  29648. description: The type of provider to use such as "Secret", or "ConfigMap".
  29649. enum:
  29650. - Secret
  29651. - ConfigMap
  29652. type: string
  29653. required:
  29654. - name
  29655. - type
  29656. type: object
  29657. checkAndSet:
  29658. description: |-
  29659. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  29660. Only applies to Vault KV v2 stores. When enabled, write operations must include
  29661. the current version of the secret to prevent unintentional overwrites.
  29662. properties:
  29663. required:
  29664. description: |-
  29665. Required when true, all write operations must include a check-and-set parameter.
  29666. This helps prevent unintentional overwrites of secrets.
  29667. type: boolean
  29668. type: object
  29669. forwardInconsistent:
  29670. description: |-
  29671. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  29672. leader instead of simply retrying within a loop. This can increase performance if
  29673. the option is enabled serverside.
  29674. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  29675. type: boolean
  29676. headers:
  29677. additionalProperties:
  29678. type: string
  29679. description: Headers to be added in Vault request
  29680. type: object
  29681. namespace:
  29682. description: |-
  29683. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  29684. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  29685. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  29686. type: string
  29687. path:
  29688. description: |-
  29689. Path is the mount path of the Vault KV backend endpoint, e.g:
  29690. "secret". The v2 KV secret engine version specific "/data" path suffix
  29691. for fetching secrets from Vault is optional and will be appended
  29692. if not present in specified path.
  29693. type: string
  29694. readYourWrites:
  29695. description: |-
  29696. ReadYourWrites ensures isolated read-after-write semantics by
  29697. providing discovered cluster replication states in each request.
  29698. More information about eventual consistency in Vault can be found here
  29699. https://www.vaultproject.io/docs/enterprise/consistency
  29700. type: boolean
  29701. server:
  29702. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  29703. type: string
  29704. tls:
  29705. description: |-
  29706. The configuration used for client side related TLS communication, when the Vault server
  29707. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  29708. This parameter is ignored for plain HTTP protocol connection.
  29709. It's worth noting this configuration is different from the "TLS certificates auth method",
  29710. which is available under the `auth.cert` section.
  29711. properties:
  29712. certSecretRef:
  29713. description: |-
  29714. CertSecretRef is a certificate added to the transport layer
  29715. when communicating with the Vault server.
  29716. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  29717. properties:
  29718. key:
  29719. description: |-
  29720. A key in the referenced Secret.
  29721. Some instances of this field may be defaulted, in others it may be required.
  29722. maxLength: 253
  29723. minLength: 1
  29724. pattern: ^[-._a-zA-Z0-9]+$
  29725. type: string
  29726. name:
  29727. description: The name of the Secret resource being referred to.
  29728. maxLength: 253
  29729. minLength: 1
  29730. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29731. type: string
  29732. namespace:
  29733. description: |-
  29734. The namespace of the Secret resource being referred to.
  29735. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29736. maxLength: 63
  29737. minLength: 1
  29738. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29739. type: string
  29740. type: object
  29741. keySecretRef:
  29742. description: |-
  29743. KeySecretRef to a key in a Secret resource containing client private key
  29744. added to the transport layer when communicating with the Vault server.
  29745. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  29746. properties:
  29747. key:
  29748. description: |-
  29749. A key in the referenced Secret.
  29750. Some instances of this field may be defaulted, in others it may be required.
  29751. maxLength: 253
  29752. minLength: 1
  29753. pattern: ^[-._a-zA-Z0-9]+$
  29754. type: string
  29755. name:
  29756. description: The name of the Secret resource being referred to.
  29757. maxLength: 253
  29758. minLength: 1
  29759. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29760. type: string
  29761. namespace:
  29762. description: |-
  29763. The namespace of the Secret resource being referred to.
  29764. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29765. maxLength: 63
  29766. minLength: 1
  29767. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29768. type: string
  29769. type: object
  29770. type: object
  29771. version:
  29772. default: v2
  29773. description: |-
  29774. Version is the Vault KV secret engine version. This can be either "v1" or
  29775. "v2". Version defaults to "v2".
  29776. enum:
  29777. - v1
  29778. - v2
  29779. type: string
  29780. required:
  29781. - server
  29782. type: object
  29783. resultType:
  29784. default: Data
  29785. description: |-
  29786. Result type defines which data is returned from the generator.
  29787. By default, it is the "data" section of the Vault API response.
  29788. When using e.g. /auth/token/create the "data" section is empty but
  29789. the "auth" section contains the generated token.
  29790. Please refer to the vault docs regarding the result data structure.
  29791. Additionally, accessing the raw response is possibly by using "Raw" result type.
  29792. enum:
  29793. - Data
  29794. - Auth
  29795. - Raw
  29796. type: string
  29797. retrySettings:
  29798. description: Used to configure http retries if failed
  29799. properties:
  29800. maxRetries:
  29801. format: int32
  29802. type: integer
  29803. retryInterval:
  29804. type: string
  29805. type: object
  29806. required:
  29807. - path
  29808. - provider
  29809. type: object
  29810. webhookSpec:
  29811. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  29812. properties:
  29813. auth:
  29814. description: Auth specifies a authorization protocol. Only one protocol may be set.
  29815. maxProperties: 1
  29816. minProperties: 1
  29817. properties:
  29818. ntlm:
  29819. description: NTLMProtocol configures the store to use NTLM for auth
  29820. properties:
  29821. passwordSecret:
  29822. description: |-
  29823. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  29824. In some instances, `key` is a required field.
  29825. properties:
  29826. key:
  29827. description: |-
  29828. A key in the referenced Secret.
  29829. Some instances of this field may be defaulted, in others it may be required.
  29830. maxLength: 253
  29831. minLength: 1
  29832. pattern: ^[-._a-zA-Z0-9]+$
  29833. type: string
  29834. name:
  29835. description: The name of the Secret resource being referred to.
  29836. maxLength: 253
  29837. minLength: 1
  29838. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29839. type: string
  29840. namespace:
  29841. description: |-
  29842. The namespace of the Secret resource being referred to.
  29843. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29844. maxLength: 63
  29845. minLength: 1
  29846. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29847. type: string
  29848. type: object
  29849. usernameSecret:
  29850. description: |-
  29851. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  29852. In some instances, `key` is a required field.
  29853. properties:
  29854. key:
  29855. description: |-
  29856. A key in the referenced Secret.
  29857. Some instances of this field may be defaulted, in others it may be required.
  29858. maxLength: 253
  29859. minLength: 1
  29860. pattern: ^[-._a-zA-Z0-9]+$
  29861. type: string
  29862. name:
  29863. description: The name of the Secret resource being referred to.
  29864. maxLength: 253
  29865. minLength: 1
  29866. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29867. type: string
  29868. namespace:
  29869. description: |-
  29870. The namespace of the Secret resource being referred to.
  29871. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29872. maxLength: 63
  29873. minLength: 1
  29874. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29875. type: string
  29876. type: object
  29877. required:
  29878. - passwordSecret
  29879. - usernameSecret
  29880. type: object
  29881. type: object
  29882. body:
  29883. description: Body
  29884. type: string
  29885. caBundle:
  29886. description: |-
  29887. PEM encoded CA bundle used to validate webhook server certificate. Only used
  29888. if the Server URL is using HTTPS protocol. This parameter is ignored for
  29889. plain HTTP protocol connection. If not set the system root certificates
  29890. are used to validate the TLS connection.
  29891. format: byte
  29892. type: string
  29893. caProvider:
  29894. description: The provider for the CA bundle to use to validate webhook server certificate.
  29895. properties:
  29896. key:
  29897. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  29898. maxLength: 253
  29899. minLength: 1
  29900. pattern: ^[-._a-zA-Z0-9]+$
  29901. type: string
  29902. name:
  29903. description: The name of the object located at the provider type.
  29904. maxLength: 253
  29905. minLength: 1
  29906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29907. type: string
  29908. namespace:
  29909. description: The namespace the Provider type is in.
  29910. maxLength: 63
  29911. minLength: 1
  29912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29913. type: string
  29914. type:
  29915. description: The type of provider to use such as "Secret", or "ConfigMap".
  29916. enum:
  29917. - Secret
  29918. - ConfigMap
  29919. type: string
  29920. required:
  29921. - name
  29922. - type
  29923. type: object
  29924. headers:
  29925. additionalProperties:
  29926. type: string
  29927. description: Headers
  29928. type: object
  29929. method:
  29930. description: Webhook Method
  29931. type: string
  29932. result:
  29933. description: Result formatting
  29934. properties:
  29935. jsonPath:
  29936. description: Json path of return value
  29937. type: string
  29938. type: object
  29939. secrets:
  29940. description: |-
  29941. Secrets to fill in templates
  29942. These secrets will be passed to the templating function as key value pairs under the given name
  29943. items:
  29944. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  29945. properties:
  29946. name:
  29947. description: Name of this secret in templates
  29948. type: string
  29949. secretRef:
  29950. description: Secret ref to fill in credentials
  29951. properties:
  29952. key:
  29953. description: The key where the token is found.
  29954. maxLength: 253
  29955. minLength: 1
  29956. pattern: ^[-._a-zA-Z0-9]+$
  29957. type: string
  29958. name:
  29959. description: The name of the Secret resource being referred to.
  29960. maxLength: 253
  29961. minLength: 1
  29962. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29963. type: string
  29964. type: object
  29965. required:
  29966. - name
  29967. - secretRef
  29968. type: object
  29969. type: array
  29970. timeout:
  29971. description: Timeout
  29972. type: string
  29973. url:
  29974. description: Webhook url to call
  29975. type: string
  29976. required:
  29977. - result
  29978. - url
  29979. type: object
  29980. type: object
  29981. kind:
  29982. description: Kind the kind of this generator.
  29983. enum:
  29984. - ACRAccessToken
  29985. - BeyondtrustWorkloadCredentialsDynamicSecret
  29986. - CloudsmithAccessToken
  29987. - ECRAuthorizationToken
  29988. - Fake
  29989. - GCRAccessToken
  29990. - GithubAccessToken
  29991. - GitlabDeployToken
  29992. - QuayAccessToken
  29993. - Password
  29994. - SSHKey
  29995. - STSSessionToken
  29996. - UUID
  29997. - VaultDynamicSecret
  29998. - Webhook
  29999. - Grafana
  30000. - MFA
  30001. type: string
  30002. required:
  30003. - generator
  30004. - kind
  30005. type: object
  30006. type: object
  30007. served: true
  30008. storage: true
  30009. subresources:
  30010. status: {}
  30011. ---
  30012. apiVersion: apiextensions.k8s.io/v1
  30013. kind: CustomResourceDefinition
  30014. metadata:
  30015. annotations:
  30016. controller-gen.kubebuilder.io/version: v0.19.0
  30017. labels:
  30018. external-secrets.io/component: controller
  30019. name: ecrauthorizationtokens.generators.external-secrets.io
  30020. spec:
  30021. group: generators.external-secrets.io
  30022. names:
  30023. categories:
  30024. - external-secrets
  30025. - external-secrets-generators
  30026. kind: ECRAuthorizationToken
  30027. listKind: ECRAuthorizationTokenList
  30028. plural: ecrauthorizationtokens
  30029. singular: ecrauthorizationtoken
  30030. scope: Namespaced
  30031. versions:
  30032. - name: v1alpha1
  30033. schema:
  30034. openAPIV3Schema:
  30035. description: |-
  30036. ECRAuthorizationToken uses the GetAuthorizationToken API to retrieve an authorization token.
  30037. The authorization token is valid for 12 hours.
  30038. The authorizationToken returned is a base64 encoded string that can be decoded
  30039. and used in a docker login command to authenticate to a registry.
  30040. For more information, see Registry authentication (https://docs.aws.amazon.com/AmazonECR/latest/userguide/Registries.html#registry_auth) in the Amazon Elastic Container Registry User Guide.
  30041. properties:
  30042. apiVersion:
  30043. description: |-
  30044. APIVersion defines the versioned schema of this representation of an object.
  30045. Servers should convert recognized schemas to the latest internal value, and
  30046. may reject unrecognized values.
  30047. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30048. type: string
  30049. kind:
  30050. description: |-
  30051. Kind is a string value representing the REST resource this object represents.
  30052. Servers may infer this from the endpoint the client submits requests to.
  30053. Cannot be updated.
  30054. In CamelCase.
  30055. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30056. type: string
  30057. metadata:
  30058. type: object
  30059. spec:
  30060. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  30061. properties:
  30062. auth:
  30063. description: Auth defines how to authenticate with AWS
  30064. properties:
  30065. jwt:
  30066. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  30067. properties:
  30068. serviceAccountRef:
  30069. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  30070. properties:
  30071. audiences:
  30072. description: |-
  30073. Audience specifies the `aud` claim for the service account token
  30074. Some providers automatically extend the audience field based on well-known annotations for workload
  30075. identity (e.g. IRSA or GCP Workload Identity)
  30076. items:
  30077. type: string
  30078. type: array
  30079. name:
  30080. description: The name of the ServiceAccount resource being referred to.
  30081. maxLength: 253
  30082. minLength: 1
  30083. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30084. type: string
  30085. namespace:
  30086. description: |-
  30087. Namespace of the resource being referred to.
  30088. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30089. maxLength: 63
  30090. minLength: 1
  30091. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30092. type: string
  30093. required:
  30094. - name
  30095. type: object
  30096. type: object
  30097. secretRef:
  30098. description: |-
  30099. AWSAuthSecretRef holds secret references for AWS credentials
  30100. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  30101. properties:
  30102. accessKeyIDSecretRef:
  30103. description: The AccessKeyID is used for authentication
  30104. properties:
  30105. key:
  30106. description: |-
  30107. A key in the referenced Secret.
  30108. Some instances of this field may be defaulted, in others it may be required.
  30109. maxLength: 253
  30110. minLength: 1
  30111. pattern: ^[-._a-zA-Z0-9]+$
  30112. type: string
  30113. name:
  30114. description: The name of the Secret resource being referred to.
  30115. maxLength: 253
  30116. minLength: 1
  30117. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30118. type: string
  30119. namespace:
  30120. description: |-
  30121. The namespace of the Secret resource being referred to.
  30122. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30123. maxLength: 63
  30124. minLength: 1
  30125. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30126. type: string
  30127. type: object
  30128. secretAccessKeySecretRef:
  30129. description: The SecretAccessKey is used for authentication
  30130. properties:
  30131. key:
  30132. description: |-
  30133. A key in the referenced Secret.
  30134. Some instances of this field may be defaulted, in others it may be required.
  30135. maxLength: 253
  30136. minLength: 1
  30137. pattern: ^[-._a-zA-Z0-9]+$
  30138. type: string
  30139. name:
  30140. description: The name of the Secret resource being referred to.
  30141. maxLength: 253
  30142. minLength: 1
  30143. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30144. type: string
  30145. namespace:
  30146. description: |-
  30147. The namespace of the Secret resource being referred to.
  30148. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30149. maxLength: 63
  30150. minLength: 1
  30151. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30152. type: string
  30153. type: object
  30154. sessionTokenSecretRef:
  30155. description: |-
  30156. The SessionToken used for authentication
  30157. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  30158. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  30159. properties:
  30160. key:
  30161. description: |-
  30162. A key in the referenced Secret.
  30163. Some instances of this field may be defaulted, in others it may be required.
  30164. maxLength: 253
  30165. minLength: 1
  30166. pattern: ^[-._a-zA-Z0-9]+$
  30167. type: string
  30168. name:
  30169. description: The name of the Secret resource being referred to.
  30170. maxLength: 253
  30171. minLength: 1
  30172. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30173. type: string
  30174. namespace:
  30175. description: |-
  30176. The namespace of the Secret resource being referred to.
  30177. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30178. maxLength: 63
  30179. minLength: 1
  30180. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30181. type: string
  30182. type: object
  30183. type: object
  30184. type: object
  30185. region:
  30186. description: Region specifies the region to operate in.
  30187. type: string
  30188. role:
  30189. description: |-
  30190. You can assume a role before making calls to the
  30191. desired AWS service.
  30192. type: string
  30193. scope:
  30194. description: |-
  30195. Scope specifies the ECR service scope.
  30196. Valid options are private and public.
  30197. type: string
  30198. required:
  30199. - region
  30200. type: object
  30201. type: object
  30202. served: true
  30203. storage: true
  30204. subresources:
  30205. status: {}
  30206. ---
  30207. apiVersion: apiextensions.k8s.io/v1
  30208. kind: CustomResourceDefinition
  30209. metadata:
  30210. annotations:
  30211. controller-gen.kubebuilder.io/version: v0.19.0
  30212. labels:
  30213. external-secrets.io/component: controller
  30214. name: fakes.generators.external-secrets.io
  30215. spec:
  30216. group: generators.external-secrets.io
  30217. names:
  30218. categories:
  30219. - external-secrets
  30220. - external-secrets-generators
  30221. kind: Fake
  30222. listKind: FakeList
  30223. plural: fakes
  30224. singular: fake
  30225. scope: Namespaced
  30226. versions:
  30227. - name: v1alpha1
  30228. schema:
  30229. openAPIV3Schema:
  30230. description: |-
  30231. Fake generator is used for testing. It lets you define
  30232. a static set of credentials that is always returned.
  30233. properties:
  30234. apiVersion:
  30235. description: |-
  30236. APIVersion defines the versioned schema of this representation of an object.
  30237. Servers should convert recognized schemas to the latest internal value, and
  30238. may reject unrecognized values.
  30239. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30240. type: string
  30241. kind:
  30242. description: |-
  30243. Kind is a string value representing the REST resource this object represents.
  30244. Servers may infer this from the endpoint the client submits requests to.
  30245. Cannot be updated.
  30246. In CamelCase.
  30247. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30248. type: string
  30249. metadata:
  30250. type: object
  30251. spec:
  30252. description: FakeSpec contains the static data.
  30253. properties:
  30254. controller:
  30255. description: |-
  30256. Used to select the correct ESO controller (think: ingress.ingressClassName)
  30257. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  30258. type: string
  30259. data:
  30260. additionalProperties:
  30261. type: string
  30262. description: |-
  30263. Data defines the static data returned
  30264. by this generator.
  30265. type: object
  30266. type: object
  30267. type: object
  30268. served: true
  30269. storage: true
  30270. subresources:
  30271. status: {}
  30272. ---
  30273. apiVersion: apiextensions.k8s.io/v1
  30274. kind: CustomResourceDefinition
  30275. metadata:
  30276. annotations:
  30277. controller-gen.kubebuilder.io/version: v0.19.0
  30278. labels:
  30279. external-secrets.io/component: controller
  30280. name: gcraccesstokens.generators.external-secrets.io
  30281. spec:
  30282. group: generators.external-secrets.io
  30283. names:
  30284. categories:
  30285. - external-secrets
  30286. - external-secrets-generators
  30287. kind: GCRAccessToken
  30288. listKind: GCRAccessTokenList
  30289. plural: gcraccesstokens
  30290. singular: gcraccesstoken
  30291. scope: Namespaced
  30292. versions:
  30293. - name: v1alpha1
  30294. schema:
  30295. openAPIV3Schema:
  30296. description: |-
  30297. GCRAccessToken generates an GCP access token
  30298. that can be used to authenticate with GCR.
  30299. properties:
  30300. apiVersion:
  30301. description: |-
  30302. APIVersion defines the versioned schema of this representation of an object.
  30303. Servers should convert recognized schemas to the latest internal value, and
  30304. may reject unrecognized values.
  30305. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30306. type: string
  30307. kind:
  30308. description: |-
  30309. Kind is a string value representing the REST resource this object represents.
  30310. Servers may infer this from the endpoint the client submits requests to.
  30311. Cannot be updated.
  30312. In CamelCase.
  30313. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30314. type: string
  30315. metadata:
  30316. type: object
  30317. spec:
  30318. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  30319. properties:
  30320. auth:
  30321. description: Auth defines the means for authenticating with GCP
  30322. properties:
  30323. secretRef:
  30324. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  30325. properties:
  30326. secretAccessKeySecretRef:
  30327. description: The SecretAccessKey is used for authentication
  30328. properties:
  30329. key:
  30330. description: |-
  30331. A key in the referenced Secret.
  30332. Some instances of this field may be defaulted, in others it may be required.
  30333. maxLength: 253
  30334. minLength: 1
  30335. pattern: ^[-._a-zA-Z0-9]+$
  30336. type: string
  30337. name:
  30338. description: The name of the Secret resource being referred to.
  30339. maxLength: 253
  30340. minLength: 1
  30341. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30342. type: string
  30343. namespace:
  30344. description: |-
  30345. The namespace of the Secret resource being referred to.
  30346. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30347. maxLength: 63
  30348. minLength: 1
  30349. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30350. type: string
  30351. type: object
  30352. type: object
  30353. workloadIdentity:
  30354. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  30355. properties:
  30356. clusterLocation:
  30357. type: string
  30358. clusterName:
  30359. type: string
  30360. clusterProjectID:
  30361. type: string
  30362. serviceAccountRef:
  30363. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  30364. properties:
  30365. audiences:
  30366. description: |-
  30367. Audience specifies the `aud` claim for the service account token
  30368. Some providers automatically extend the audience field based on well-known annotations for workload
  30369. identity (e.g. IRSA or GCP Workload Identity)
  30370. items:
  30371. type: string
  30372. type: array
  30373. name:
  30374. description: The name of the ServiceAccount resource being referred to.
  30375. maxLength: 253
  30376. minLength: 1
  30377. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30378. type: string
  30379. namespace:
  30380. description: |-
  30381. Namespace of the resource being referred to.
  30382. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30383. maxLength: 63
  30384. minLength: 1
  30385. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30386. type: string
  30387. required:
  30388. - name
  30389. type: object
  30390. required:
  30391. - clusterLocation
  30392. - clusterName
  30393. - serviceAccountRef
  30394. type: object
  30395. workloadIdentityFederation:
  30396. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  30397. properties:
  30398. audience:
  30399. description: |-
  30400. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  30401. If specified, Audience found in the external account credential config will be overridden with the configured value.
  30402. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  30403. type: string
  30404. awsSecurityCredentials:
  30405. description: |-
  30406. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  30407. when using the AWS metadata server is not an option.
  30408. properties:
  30409. awsCredentialsSecretRef:
  30410. description: |-
  30411. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  30412. Secret should be created with below names for keys
  30413. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  30414. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  30415. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  30416. properties:
  30417. name:
  30418. description: name of the secret.
  30419. maxLength: 253
  30420. minLength: 1
  30421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30422. type: string
  30423. namespace:
  30424. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  30425. maxLength: 63
  30426. minLength: 1
  30427. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30428. type: string
  30429. required:
  30430. - name
  30431. type: object
  30432. region:
  30433. description: region is for configuring the AWS region to be used.
  30434. example: ap-south-1
  30435. maxLength: 50
  30436. minLength: 1
  30437. pattern: ^[a-z0-9-]+$
  30438. type: string
  30439. required:
  30440. - awsCredentialsSecretRef
  30441. - region
  30442. type: object
  30443. credConfig:
  30444. description: |-
  30445. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  30446. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  30447. serviceAccountRef must be used by providing operators service account details.
  30448. properties:
  30449. key:
  30450. description: key name holding the external account credential config.
  30451. maxLength: 253
  30452. minLength: 1
  30453. pattern: ^[-._a-zA-Z0-9]+$
  30454. type: string
  30455. name:
  30456. description: name of the configmap.
  30457. maxLength: 253
  30458. minLength: 1
  30459. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30460. type: string
  30461. namespace:
  30462. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  30463. maxLength: 63
  30464. minLength: 1
  30465. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30466. type: string
  30467. required:
  30468. - key
  30469. - name
  30470. type: object
  30471. externalTokenEndpoint:
  30472. description: |-
  30473. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  30474. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  30475. URL is having the expected value.
  30476. type: string
  30477. gcpServiceAccountEmail:
  30478. description: |-
  30479. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  30480. after Workload Identity Federation. Use this to grant access through the service account's
  30481. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  30482. service_account_impersonation_url in the external account JSON from credConfig;
  30483. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  30484. on that ServiceAccount.
  30485. example: my-gsa@my-project.iam.gserviceaccount.com
  30486. minLength: 1
  30487. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  30488. type: string
  30489. serviceAccountRef:
  30490. description: |-
  30491. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  30492. when Kubernetes is configured as provider in workload identity pool.
  30493. properties:
  30494. audiences:
  30495. description: |-
  30496. Audience specifies the `aud` claim for the service account token
  30497. Some providers automatically extend the audience field based on well-known annotations for workload
  30498. identity (e.g. IRSA or GCP Workload Identity)
  30499. items:
  30500. type: string
  30501. type: array
  30502. name:
  30503. description: The name of the ServiceAccount resource being referred to.
  30504. maxLength: 253
  30505. minLength: 1
  30506. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30507. type: string
  30508. namespace:
  30509. description: |-
  30510. Namespace of the resource being referred to.
  30511. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30512. maxLength: 63
  30513. minLength: 1
  30514. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30515. type: string
  30516. required:
  30517. - name
  30518. type: object
  30519. type: object
  30520. type: object
  30521. projectID:
  30522. description: ProjectID defines which project to use to authenticate with
  30523. type: string
  30524. required:
  30525. - auth
  30526. - projectID
  30527. type: object
  30528. type: object
  30529. served: true
  30530. storage: true
  30531. subresources:
  30532. status: {}
  30533. ---
  30534. apiVersion: apiextensions.k8s.io/v1
  30535. kind: CustomResourceDefinition
  30536. metadata:
  30537. annotations:
  30538. controller-gen.kubebuilder.io/version: v0.19.0
  30539. labels:
  30540. external-secrets.io/component: controller
  30541. name: generatorstates.generators.external-secrets.io
  30542. spec:
  30543. group: generators.external-secrets.io
  30544. names:
  30545. categories:
  30546. - external-secrets
  30547. - external-secrets-generators
  30548. kind: GeneratorState
  30549. listKind: GeneratorStateList
  30550. plural: generatorstates
  30551. shortNames:
  30552. - gs
  30553. singular: generatorstate
  30554. scope: Namespaced
  30555. versions:
  30556. - additionalPrinterColumns:
  30557. - jsonPath: .spec.garbageCollectionDeadline
  30558. name: GC Deadline
  30559. type: string
  30560. - jsonPath: .metadata.creationTimestamp
  30561. name: Age
  30562. type: date
  30563. name: v1alpha1
  30564. schema:
  30565. openAPIV3Schema:
  30566. description: GeneratorState represents the state created and managed by a generator resource.
  30567. properties:
  30568. apiVersion:
  30569. description: |-
  30570. APIVersion defines the versioned schema of this representation of an object.
  30571. Servers should convert recognized schemas to the latest internal value, and
  30572. may reject unrecognized values.
  30573. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30574. type: string
  30575. kind:
  30576. description: |-
  30577. Kind is a string value representing the REST resource this object represents.
  30578. Servers may infer this from the endpoint the client submits requests to.
  30579. Cannot be updated.
  30580. In CamelCase.
  30581. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30582. type: string
  30583. metadata:
  30584. type: object
  30585. spec:
  30586. description: GeneratorStateSpec defines the desired state of a generator state resource.
  30587. properties:
  30588. garbageCollectionDeadline:
  30589. description: |-
  30590. GarbageCollectionDeadline is the time after which the generator state
  30591. will be deleted.
  30592. It is set by the controller which creates the generator state and
  30593. can be set configured by the user.
  30594. If the garbage collection deadline is not set the generator state will not be deleted.
  30595. format: date-time
  30596. type: string
  30597. resource:
  30598. description: |-
  30599. Resource is the generator manifest that produced the state.
  30600. It is a snapshot of the generator manifest at the time the state was produced.
  30601. This manifest will be used to delete the resource. Any configuration that is referenced
  30602. in the manifest should be available at the time of garbage collection. If that is not the case deletion will
  30603. be blocked by a finalizer.
  30604. x-kubernetes-preserve-unknown-fields: true
  30605. state:
  30606. description: State is the state that was produced by the generator implementation.
  30607. x-kubernetes-preserve-unknown-fields: true
  30608. required:
  30609. - resource
  30610. - state
  30611. type: object
  30612. status:
  30613. description: GeneratorStateStatus defines the observed state of a generator state resource.
  30614. properties:
  30615. conditions:
  30616. items:
  30617. description: GeneratorStateStatusCondition represents the observed condition of a generator state.
  30618. properties:
  30619. lastTransitionTime:
  30620. format: date-time
  30621. type: string
  30622. message:
  30623. type: string
  30624. reason:
  30625. type: string
  30626. status:
  30627. type: string
  30628. type:
  30629. description: GeneratorStateConditionType represents the type of condition for a generator state.
  30630. type: string
  30631. required:
  30632. - status
  30633. - type
  30634. type: object
  30635. type: array
  30636. type: object
  30637. type: object
  30638. served: true
  30639. storage: true
  30640. subresources: {}
  30641. ---
  30642. apiVersion: apiextensions.k8s.io/v1
  30643. kind: CustomResourceDefinition
  30644. metadata:
  30645. annotations:
  30646. controller-gen.kubebuilder.io/version: v0.19.0
  30647. labels:
  30648. external-secrets.io/component: controller
  30649. name: githubaccesstokens.generators.external-secrets.io
  30650. spec:
  30651. group: generators.external-secrets.io
  30652. names:
  30653. categories:
  30654. - external-secrets
  30655. - external-secrets-generators
  30656. kind: GithubAccessToken
  30657. listKind: GithubAccessTokenList
  30658. plural: githubaccesstokens
  30659. singular: githubaccesstoken
  30660. scope: Namespaced
  30661. versions:
  30662. - name: v1alpha1
  30663. schema:
  30664. openAPIV3Schema:
  30665. description: GithubAccessToken generates ghs_ accessToken
  30666. properties:
  30667. apiVersion:
  30668. description: |-
  30669. APIVersion defines the versioned schema of this representation of an object.
  30670. Servers should convert recognized schemas to the latest internal value, and
  30671. may reject unrecognized values.
  30672. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30673. type: string
  30674. kind:
  30675. description: |-
  30676. Kind is a string value representing the REST resource this object represents.
  30677. Servers may infer this from the endpoint the client submits requests to.
  30678. Cannot be updated.
  30679. In CamelCase.
  30680. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30681. type: string
  30682. metadata:
  30683. type: object
  30684. spec:
  30685. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  30686. properties:
  30687. appID:
  30688. type: string
  30689. auth:
  30690. description: Auth configures how ESO authenticates with a Github instance.
  30691. properties:
  30692. privateKey:
  30693. description: GithubSecretRef references a secret containing GitHub credentials.
  30694. properties:
  30695. secretRef:
  30696. description: |-
  30697. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30698. In some instances, `key` is a required field.
  30699. properties:
  30700. key:
  30701. description: |-
  30702. A key in the referenced Secret.
  30703. Some instances of this field may be defaulted, in others it may be required.
  30704. maxLength: 253
  30705. minLength: 1
  30706. pattern: ^[-._a-zA-Z0-9]+$
  30707. type: string
  30708. name:
  30709. description: The name of the Secret resource being referred to.
  30710. maxLength: 253
  30711. minLength: 1
  30712. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30713. type: string
  30714. namespace:
  30715. description: |-
  30716. The namespace of the Secret resource being referred to.
  30717. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30718. maxLength: 63
  30719. minLength: 1
  30720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30721. type: string
  30722. type: object
  30723. required:
  30724. - secretRef
  30725. type: object
  30726. required:
  30727. - privateKey
  30728. type: object
  30729. installID:
  30730. type: string
  30731. permissions:
  30732. additionalProperties:
  30733. type: string
  30734. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  30735. type: object
  30736. repositories:
  30737. description: |-
  30738. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  30739. is installed to.
  30740. items:
  30741. type: string
  30742. type: array
  30743. url:
  30744. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  30745. type: string
  30746. required:
  30747. - appID
  30748. - auth
  30749. - installID
  30750. type: object
  30751. type: object
  30752. served: true
  30753. storage: true
  30754. subresources:
  30755. status: {}
  30756. ---
  30757. apiVersion: apiextensions.k8s.io/v1
  30758. kind: CustomResourceDefinition
  30759. metadata:
  30760. annotations:
  30761. controller-gen.kubebuilder.io/version: v0.19.0
  30762. labels:
  30763. external-secrets.io/component: controller
  30764. name: gitlabdeploytokens.generators.external-secrets.io
  30765. spec:
  30766. group: generators.external-secrets.io
  30767. names:
  30768. categories:
  30769. - external-secrets
  30770. - external-secrets-generators
  30771. kind: GitlabDeployToken
  30772. listKind: GitlabDeployTokenList
  30773. plural: gitlabdeploytokens
  30774. singular: gitlabdeploytoken
  30775. scope: Namespaced
  30776. versions:
  30777. - name: v1alpha1
  30778. schema:
  30779. openAPIV3Schema:
  30780. description: GitlabDeployToken generates a GitLab deploy token.
  30781. properties:
  30782. apiVersion:
  30783. description: |-
  30784. APIVersion defines the versioned schema of this representation of an object.
  30785. Servers should convert recognized schemas to the latest internal value, and
  30786. may reject unrecognized values.
  30787. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30788. type: string
  30789. kind:
  30790. description: |-
  30791. Kind is a string value representing the REST resource this object represents.
  30792. Servers may infer this from the endpoint the client submits requests to.
  30793. Cannot be updated.
  30794. In CamelCase.
  30795. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30796. type: string
  30797. metadata:
  30798. type: object
  30799. spec:
  30800. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  30801. properties:
  30802. auth:
  30803. description: Auth configures how ESO authenticates with the GitLab API.
  30804. properties:
  30805. token:
  30806. description: |-
  30807. Token references a secret containing a GitLab access token (personal, group, or
  30808. project) with the api scope and at least the Maintainer role on the target.
  30809. properties:
  30810. secretRef:
  30811. description: |-
  30812. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30813. In some instances, `key` is a required field.
  30814. properties:
  30815. key:
  30816. description: |-
  30817. A key in the referenced Secret.
  30818. Some instances of this field may be defaulted, in others it may be required.
  30819. maxLength: 253
  30820. minLength: 1
  30821. pattern: ^[-._a-zA-Z0-9]+$
  30822. type: string
  30823. name:
  30824. description: The name of the Secret resource being referred to.
  30825. maxLength: 253
  30826. minLength: 1
  30827. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30828. type: string
  30829. namespace:
  30830. description: |-
  30831. The namespace of the Secret resource being referred to.
  30832. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30833. maxLength: 63
  30834. minLength: 1
  30835. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30836. type: string
  30837. type: object
  30838. required:
  30839. - secretRef
  30840. type: object
  30841. required:
  30842. - token
  30843. type: object
  30844. expiresAt:
  30845. description: |-
  30846. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  30847. not expire on the GitLab side and is revoked only when the generator state is
  30848. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  30849. format: date-time
  30850. type: string
  30851. groupID:
  30852. description: |-
  30853. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  30854. create the deploy token in. The generator URL-escapes paths before calling the
  30855. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  30856. minLength: 1
  30857. type: string
  30858. name:
  30859. description: Name of the deploy token.
  30860. minLength: 1
  30861. type: string
  30862. projectID:
  30863. description: |-
  30864. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  30865. project to create the deploy token in. The generator URL-escapes paths before
  30866. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  30867. minLength: 1
  30868. type: string
  30869. scopes:
  30870. description: Scopes granted to the deploy token. At least one scope is required.
  30871. items:
  30872. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  30873. enum:
  30874. - read_repository
  30875. - read_registry
  30876. - write_registry
  30877. - read_package_registry
  30878. - write_package_registry
  30879. - read_virtual_registry
  30880. - write_virtual_registry
  30881. type: string
  30882. minItems: 1
  30883. type: array
  30884. url:
  30885. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  30886. type: string
  30887. username:
  30888. description: |-
  30889. Username is an optional username for the deploy token. GitLab defaults it to
  30890. gitlab+deploy-token-{n} when omitted.
  30891. type: string
  30892. required:
  30893. - auth
  30894. - name
  30895. - scopes
  30896. type: object
  30897. x-kubernetes-validations:
  30898. - message: exactly one of projectID or groupID must be set
  30899. rule: has(self.projectID) != has(self.groupID)
  30900. type: object
  30901. served: true
  30902. storage: true
  30903. subresources:
  30904. status: {}
  30905. ---
  30906. apiVersion: apiextensions.k8s.io/v1
  30907. kind: CustomResourceDefinition
  30908. metadata:
  30909. annotations:
  30910. controller-gen.kubebuilder.io/version: v0.19.0
  30911. labels:
  30912. external-secrets.io/component: controller
  30913. name: grafanas.generators.external-secrets.io
  30914. spec:
  30915. group: generators.external-secrets.io
  30916. names:
  30917. categories:
  30918. - external-secrets
  30919. - external-secrets-generators
  30920. kind: Grafana
  30921. listKind: GrafanaList
  30922. plural: grafanas
  30923. singular: grafana
  30924. scope: Namespaced
  30925. versions:
  30926. - name: v1alpha1
  30927. schema:
  30928. openAPIV3Schema:
  30929. description: Grafana represents a generator for Grafana service account tokens.
  30930. properties:
  30931. apiVersion:
  30932. description: |-
  30933. APIVersion defines the versioned schema of this representation of an object.
  30934. Servers should convert recognized schemas to the latest internal value, and
  30935. may reject unrecognized values.
  30936. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30937. type: string
  30938. kind:
  30939. description: |-
  30940. Kind is a string value representing the REST resource this object represents.
  30941. Servers may infer this from the endpoint the client submits requests to.
  30942. Cannot be updated.
  30943. In CamelCase.
  30944. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30945. type: string
  30946. metadata:
  30947. type: object
  30948. spec:
  30949. description: GrafanaSpec controls the behavior of the grafana generator.
  30950. properties:
  30951. auth:
  30952. description: |-
  30953. Auth is the authentication configuration to authenticate
  30954. against the Grafana instance.
  30955. properties:
  30956. basic:
  30957. description: |-
  30958. Basic auth credentials used to authenticate against the Grafana instance.
  30959. Note: you need a token which has elevated permissions to create service accounts.
  30960. See here for the documentation on basic roles offered by Grafana:
  30961. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30962. properties:
  30963. password:
  30964. description: A basic auth password used to authenticate against the Grafana instance.
  30965. properties:
  30966. key:
  30967. description: The key where the token is found.
  30968. maxLength: 253
  30969. minLength: 1
  30970. pattern: ^[-._a-zA-Z0-9]+$
  30971. type: string
  30972. name:
  30973. description: The name of the Secret resource being referred to.
  30974. maxLength: 253
  30975. minLength: 1
  30976. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30977. type: string
  30978. type: object
  30979. username:
  30980. description: A basic auth username used to authenticate against the Grafana instance.
  30981. type: string
  30982. required:
  30983. - password
  30984. - username
  30985. type: object
  30986. token:
  30987. description: |-
  30988. A service account token used to authenticate against the Grafana instance.
  30989. Note: you need a token which has elevated permissions to create service accounts.
  30990. See here for the documentation on basic roles offered by Grafana:
  30991. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30992. properties:
  30993. key:
  30994. description: The key where the token is found.
  30995. maxLength: 253
  30996. minLength: 1
  30997. pattern: ^[-._a-zA-Z0-9]+$
  30998. type: string
  30999. name:
  31000. description: The name of the Secret resource being referred to.
  31001. maxLength: 253
  31002. minLength: 1
  31003. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31004. type: string
  31005. type: object
  31006. type: object
  31007. serviceAccount:
  31008. description: |-
  31009. ServiceAccount is the configuration for the service account that
  31010. is supposed to be generated by the generator.
  31011. properties:
  31012. name:
  31013. description: Name is the name of the service account that will be created by ESO.
  31014. type: string
  31015. role:
  31016. description: |-
  31017. Role is the role of the service account.
  31018. See here for the documentation on basic roles offered by Grafana:
  31019. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  31020. type: string
  31021. secondsToLive:
  31022. description: |-
  31023. SecondsToLive is the number of seconds before the generated service account token will expire.
  31024. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  31025. format: int64
  31026. minimum: 1
  31027. type: integer
  31028. required:
  31029. - name
  31030. - role
  31031. type: object
  31032. url:
  31033. description: URL is the URL of the Grafana instance.
  31034. type: string
  31035. required:
  31036. - auth
  31037. - serviceAccount
  31038. - url
  31039. type: object
  31040. type: object
  31041. served: true
  31042. storage: true
  31043. subresources:
  31044. status: {}
  31045. ---
  31046. apiVersion: apiextensions.k8s.io/v1
  31047. kind: CustomResourceDefinition
  31048. metadata:
  31049. annotations:
  31050. controller-gen.kubebuilder.io/version: v0.19.0
  31051. labels:
  31052. external-secrets.io/component: controller
  31053. name: mfas.generators.external-secrets.io
  31054. spec:
  31055. group: generators.external-secrets.io
  31056. names:
  31057. categories:
  31058. - external-secrets
  31059. - external-secrets-generators
  31060. kind: MFA
  31061. listKind: MFAList
  31062. plural: mfas
  31063. singular: mfa
  31064. scope: Namespaced
  31065. versions:
  31066. - name: v1alpha1
  31067. schema:
  31068. openAPIV3Schema:
  31069. description: MFA generates a new TOTP token that is compliant with RFC 6238.
  31070. properties:
  31071. apiVersion:
  31072. description: |-
  31073. APIVersion defines the versioned schema of this representation of an object.
  31074. Servers should convert recognized schemas to the latest internal value, and
  31075. may reject unrecognized values.
  31076. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31077. type: string
  31078. kind:
  31079. description: |-
  31080. Kind is a string value representing the REST resource this object represents.
  31081. Servers may infer this from the endpoint the client submits requests to.
  31082. Cannot be updated.
  31083. In CamelCase.
  31084. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31085. type: string
  31086. metadata:
  31087. type: object
  31088. spec:
  31089. description: MFASpec controls the behavior of the mfa generator.
  31090. properties:
  31091. algorithm:
  31092. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  31093. type: string
  31094. length:
  31095. description: Length defines the token length. Defaults to 6 characters.
  31096. type: integer
  31097. secret:
  31098. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  31099. properties:
  31100. key:
  31101. description: |-
  31102. A key in the referenced Secret.
  31103. Some instances of this field may be defaulted, in others it may be required.
  31104. maxLength: 253
  31105. minLength: 1
  31106. pattern: ^[-._a-zA-Z0-9]+$
  31107. type: string
  31108. name:
  31109. description: The name of the Secret resource being referred to.
  31110. maxLength: 253
  31111. minLength: 1
  31112. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31113. type: string
  31114. namespace:
  31115. description: |-
  31116. The namespace of the Secret resource being referred to.
  31117. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31118. maxLength: 63
  31119. minLength: 1
  31120. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31121. type: string
  31122. type: object
  31123. timePeriod:
  31124. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  31125. type: integer
  31126. when:
  31127. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  31128. format: date-time
  31129. type: string
  31130. required:
  31131. - secret
  31132. type: object
  31133. type: object
  31134. served: true
  31135. storage: true
  31136. subresources:
  31137. status: {}
  31138. ---
  31139. apiVersion: apiextensions.k8s.io/v1
  31140. kind: CustomResourceDefinition
  31141. metadata:
  31142. annotations:
  31143. controller-gen.kubebuilder.io/version: v0.19.0
  31144. labels:
  31145. external-secrets.io/component: controller
  31146. name: passwords.generators.external-secrets.io
  31147. spec:
  31148. group: generators.external-secrets.io
  31149. names:
  31150. categories:
  31151. - external-secrets
  31152. - external-secrets-generators
  31153. kind: Password
  31154. listKind: PasswordList
  31155. plural: passwords
  31156. singular: password
  31157. scope: Namespaced
  31158. versions:
  31159. - name: v1alpha1
  31160. schema:
  31161. openAPIV3Schema:
  31162. description: |-
  31163. Password generates a random password based on the
  31164. configuration parameters in spec.
  31165. You can specify the length, characterset and other attributes.
  31166. properties:
  31167. apiVersion:
  31168. description: |-
  31169. APIVersion defines the versioned schema of this representation of an object.
  31170. Servers should convert recognized schemas to the latest internal value, and
  31171. may reject unrecognized values.
  31172. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31173. type: string
  31174. kind:
  31175. description: |-
  31176. Kind is a string value representing the REST resource this object represents.
  31177. Servers may infer this from the endpoint the client submits requests to.
  31178. Cannot be updated.
  31179. In CamelCase.
  31180. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31181. type: string
  31182. metadata:
  31183. type: object
  31184. spec:
  31185. description: PasswordSpec controls the behavior of the password generator.
  31186. properties:
  31187. allowRepeat:
  31188. default: false
  31189. description: set AllowRepeat to true to allow repeating characters.
  31190. type: boolean
  31191. digits:
  31192. description: |-
  31193. Digits specifies the number of digits in the generated
  31194. password. If omitted it defaults to 25% of the length of the password
  31195. type: integer
  31196. encoding:
  31197. default: raw
  31198. description: |-
  31199. Encoding specifies the encoding of the generated password.
  31200. Valid values are:
  31201. - "raw" (default): no encoding
  31202. - "base64": standard base64 encoding
  31203. - "base64url": base64url encoding
  31204. - "base32": base32 encoding
  31205. - "hex": hexadecimal encoding
  31206. enum:
  31207. - base64
  31208. - base64url
  31209. - base32
  31210. - hex
  31211. - raw
  31212. type: string
  31213. length:
  31214. default: 24
  31215. description: |-
  31216. Length of the password to be generated.
  31217. Defaults to 24
  31218. type: integer
  31219. noUpper:
  31220. default: false
  31221. description: Set NoUpper to disable uppercase characters
  31222. type: boolean
  31223. secretKeys:
  31224. description: |-
  31225. SecretKeys defines the keys that will be populated with generated passwords.
  31226. Defaults to "password" when not set.
  31227. items:
  31228. type: string
  31229. minItems: 1
  31230. type: array
  31231. symbolCharacters:
  31232. description: |-
  31233. SymbolCharacters specifies the special characters that should be used
  31234. in the generated password.
  31235. type: string
  31236. symbols:
  31237. description: |-
  31238. Symbols specifies the number of symbol characters in the generated
  31239. password. If omitted it defaults to 25% of the length of the password
  31240. type: integer
  31241. required:
  31242. - allowRepeat
  31243. - length
  31244. - noUpper
  31245. type: object
  31246. type: object
  31247. served: true
  31248. storage: true
  31249. subresources:
  31250. status: {}
  31251. ---
  31252. apiVersion: apiextensions.k8s.io/v1
  31253. kind: CustomResourceDefinition
  31254. metadata:
  31255. annotations:
  31256. controller-gen.kubebuilder.io/version: v0.19.0
  31257. labels:
  31258. external-secrets.io/component: controller
  31259. name: quayaccesstokens.generators.external-secrets.io
  31260. spec:
  31261. group: generators.external-secrets.io
  31262. names:
  31263. categories:
  31264. - external-secrets
  31265. - external-secrets-generators
  31266. kind: QuayAccessToken
  31267. listKind: QuayAccessTokenList
  31268. plural: quayaccesstokens
  31269. singular: quayaccesstoken
  31270. scope: Namespaced
  31271. versions:
  31272. - name: v1alpha1
  31273. schema:
  31274. openAPIV3Schema:
  31275. description: QuayAccessToken generates Quay oauth token for pulling/pushing images
  31276. properties:
  31277. apiVersion:
  31278. description: |-
  31279. APIVersion defines the versioned schema of this representation of an object.
  31280. Servers should convert recognized schemas to the latest internal value, and
  31281. may reject unrecognized values.
  31282. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31283. type: string
  31284. kind:
  31285. description: |-
  31286. Kind is a string value representing the REST resource this object represents.
  31287. Servers may infer this from the endpoint the client submits requests to.
  31288. Cannot be updated.
  31289. In CamelCase.
  31290. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31291. type: string
  31292. metadata:
  31293. type: object
  31294. spec:
  31295. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  31296. properties:
  31297. robotAccount:
  31298. description: Name of the robot account you are federating with
  31299. type: string
  31300. serviceAccountRef:
  31301. description: Name of the service account you are federating with
  31302. properties:
  31303. audiences:
  31304. description: |-
  31305. Audience specifies the `aud` claim for the service account token
  31306. Some providers automatically extend the audience field based on well-known annotations for workload
  31307. identity (e.g. IRSA or GCP Workload Identity)
  31308. items:
  31309. type: string
  31310. type: array
  31311. name:
  31312. description: The name of the ServiceAccount resource being referred to.
  31313. maxLength: 253
  31314. minLength: 1
  31315. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31316. type: string
  31317. namespace:
  31318. description: |-
  31319. Namespace of the resource being referred to.
  31320. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31321. maxLength: 63
  31322. minLength: 1
  31323. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31324. type: string
  31325. required:
  31326. - name
  31327. type: object
  31328. url:
  31329. description: URL configures the Quay instance URL. Defaults to quay.io.
  31330. type: string
  31331. required:
  31332. - robotAccount
  31333. - serviceAccountRef
  31334. type: object
  31335. type: object
  31336. served: true
  31337. storage: true
  31338. subresources:
  31339. status: {}
  31340. ---
  31341. apiVersion: apiextensions.k8s.io/v1
  31342. kind: CustomResourceDefinition
  31343. metadata:
  31344. annotations:
  31345. controller-gen.kubebuilder.io/version: v0.19.0
  31346. labels:
  31347. external-secrets.io/component: controller
  31348. name: sshkeys.generators.external-secrets.io
  31349. spec:
  31350. group: generators.external-secrets.io
  31351. names:
  31352. categories:
  31353. - external-secrets
  31354. - external-secrets-generators
  31355. kind: SSHKey
  31356. listKind: SSHKeyList
  31357. plural: sshkeys
  31358. singular: sshkey
  31359. scope: Namespaced
  31360. versions:
  31361. - name: v1alpha1
  31362. schema:
  31363. openAPIV3Schema:
  31364. description: SSHKey generates SSH key pairs.
  31365. properties:
  31366. apiVersion:
  31367. description: |-
  31368. APIVersion defines the versioned schema of this representation of an object.
  31369. Servers should convert recognized schemas to the latest internal value, and
  31370. may reject unrecognized values.
  31371. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31372. type: string
  31373. kind:
  31374. description: |-
  31375. Kind is a string value representing the REST resource this object represents.
  31376. Servers may infer this from the endpoint the client submits requests to.
  31377. Cannot be updated.
  31378. In CamelCase.
  31379. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31380. type: string
  31381. metadata:
  31382. type: object
  31383. spec:
  31384. description: SSHKeySpec controls the behavior of the ssh key generator.
  31385. properties:
  31386. comment:
  31387. description: Comment specifies an optional comment for the SSH key
  31388. type: string
  31389. keySize:
  31390. description: |-
  31391. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  31392. For RSA keys: 2048, 3072, 4096
  31393. For ECDSA keys: 256, 384, 521
  31394. Ignored for ed25519 keys
  31395. maximum: 8192
  31396. minimum: 256
  31397. type: integer
  31398. keyType:
  31399. default: rsa
  31400. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  31401. enum:
  31402. - rsa
  31403. - ecdsa
  31404. - ed25519
  31405. type: string
  31406. type: object
  31407. type: object
  31408. served: true
  31409. storage: true
  31410. subresources:
  31411. status: {}
  31412. ---
  31413. apiVersion: apiextensions.k8s.io/v1
  31414. kind: CustomResourceDefinition
  31415. metadata:
  31416. annotations:
  31417. controller-gen.kubebuilder.io/version: v0.19.0
  31418. labels:
  31419. external-secrets.io/component: controller
  31420. name: stssessiontokens.generators.external-secrets.io
  31421. spec:
  31422. group: generators.external-secrets.io
  31423. names:
  31424. categories:
  31425. - external-secrets
  31426. - external-secrets-generators
  31427. kind: STSSessionToken
  31428. listKind: STSSessionTokenList
  31429. plural: stssessiontokens
  31430. singular: stssessiontoken
  31431. scope: Namespaced
  31432. versions:
  31433. - name: v1alpha1
  31434. schema:
  31435. openAPIV3Schema:
  31436. description: |-
  31437. STSSessionToken uses the GetSessionToken API to retrieve an authorization token.
  31438. The authorization token is valid for 12 hours.
  31439. The authorizationToken returned is a base64 encoded string that can be decoded.
  31440. For more information, see GetSessionToken (https://docs.aws.amazon.com/STS/latest/APIReference/API_GetSessionToken.html).
  31441. properties:
  31442. apiVersion:
  31443. description: |-
  31444. APIVersion defines the versioned schema of this representation of an object.
  31445. Servers should convert recognized schemas to the latest internal value, and
  31446. may reject unrecognized values.
  31447. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31448. type: string
  31449. kind:
  31450. description: |-
  31451. Kind is a string value representing the REST resource this object represents.
  31452. Servers may infer this from the endpoint the client submits requests to.
  31453. Cannot be updated.
  31454. In CamelCase.
  31455. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31456. type: string
  31457. metadata:
  31458. type: object
  31459. spec:
  31460. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  31461. properties:
  31462. auth:
  31463. description: Auth defines how to authenticate with AWS
  31464. properties:
  31465. jwt:
  31466. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  31467. properties:
  31468. serviceAccountRef:
  31469. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31470. properties:
  31471. audiences:
  31472. description: |-
  31473. Audience specifies the `aud` claim for the service account token
  31474. Some providers automatically extend the audience field based on well-known annotations for workload
  31475. identity (e.g. IRSA or GCP Workload Identity)
  31476. items:
  31477. type: string
  31478. type: array
  31479. name:
  31480. description: The name of the ServiceAccount resource being referred to.
  31481. maxLength: 253
  31482. minLength: 1
  31483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31484. type: string
  31485. namespace:
  31486. description: |-
  31487. Namespace of the resource being referred to.
  31488. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31489. maxLength: 63
  31490. minLength: 1
  31491. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31492. type: string
  31493. required:
  31494. - name
  31495. type: object
  31496. type: object
  31497. secretRef:
  31498. description: |-
  31499. AWSAuthSecretRef holds secret references for AWS credentials
  31500. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  31501. properties:
  31502. accessKeyIDSecretRef:
  31503. description: The AccessKeyID is used for authentication
  31504. properties:
  31505. key:
  31506. description: |-
  31507. A key in the referenced Secret.
  31508. Some instances of this field may be defaulted, in others it may be required.
  31509. maxLength: 253
  31510. minLength: 1
  31511. pattern: ^[-._a-zA-Z0-9]+$
  31512. type: string
  31513. name:
  31514. description: The name of the Secret resource being referred to.
  31515. maxLength: 253
  31516. minLength: 1
  31517. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31518. type: string
  31519. namespace:
  31520. description: |-
  31521. The namespace of the Secret resource being referred to.
  31522. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31523. maxLength: 63
  31524. minLength: 1
  31525. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31526. type: string
  31527. type: object
  31528. secretAccessKeySecretRef:
  31529. description: The SecretAccessKey is used for authentication
  31530. properties:
  31531. key:
  31532. description: |-
  31533. A key in the referenced Secret.
  31534. Some instances of this field may be defaulted, in others it may be required.
  31535. maxLength: 253
  31536. minLength: 1
  31537. pattern: ^[-._a-zA-Z0-9]+$
  31538. type: string
  31539. name:
  31540. description: The name of the Secret resource being referred to.
  31541. maxLength: 253
  31542. minLength: 1
  31543. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31544. type: string
  31545. namespace:
  31546. description: |-
  31547. The namespace of the Secret resource being referred to.
  31548. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31549. maxLength: 63
  31550. minLength: 1
  31551. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31552. type: string
  31553. type: object
  31554. sessionTokenSecretRef:
  31555. description: |-
  31556. The SessionToken used for authentication
  31557. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  31558. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  31559. properties:
  31560. key:
  31561. description: |-
  31562. A key in the referenced Secret.
  31563. Some instances of this field may be defaulted, in others it may be required.
  31564. maxLength: 253
  31565. minLength: 1
  31566. pattern: ^[-._a-zA-Z0-9]+$
  31567. type: string
  31568. name:
  31569. description: The name of the Secret resource being referred to.
  31570. maxLength: 253
  31571. minLength: 1
  31572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31573. type: string
  31574. namespace:
  31575. description: |-
  31576. The namespace of the Secret resource being referred to.
  31577. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31578. maxLength: 63
  31579. minLength: 1
  31580. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31581. type: string
  31582. type: object
  31583. type: object
  31584. type: object
  31585. region:
  31586. description: Region specifies the region to operate in.
  31587. type: string
  31588. requestParameters:
  31589. description: RequestParameters contains parameters that can be passed to the STS service.
  31590. properties:
  31591. serialNumber:
  31592. description: |-
  31593. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  31594. the GetSessionToken call.
  31595. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  31596. (such as arn:aws:iam::123456789012:mfa/user)
  31597. type: string
  31598. sessionDuration:
  31599. format: int32
  31600. type: integer
  31601. tokenCode:
  31602. description: TokenCode is the value provided by the MFA device, if MFA is required.
  31603. type: string
  31604. type: object
  31605. role:
  31606. description: |-
  31607. You can assume a role before making calls to the
  31608. desired AWS service.
  31609. type: string
  31610. required:
  31611. - region
  31612. type: object
  31613. type: object
  31614. served: true
  31615. storage: true
  31616. subresources:
  31617. status: {}
  31618. ---
  31619. apiVersion: apiextensions.k8s.io/v1
  31620. kind: CustomResourceDefinition
  31621. metadata:
  31622. annotations:
  31623. controller-gen.kubebuilder.io/version: v0.19.0
  31624. labels:
  31625. external-secrets.io/component: controller
  31626. name: uuids.generators.external-secrets.io
  31627. spec:
  31628. group: generators.external-secrets.io
  31629. names:
  31630. categories:
  31631. - external-secrets
  31632. - external-secrets-generators
  31633. kind: UUID
  31634. listKind: UUIDList
  31635. plural: uuids
  31636. singular: uuid
  31637. scope: Namespaced
  31638. versions:
  31639. - name: v1alpha1
  31640. schema:
  31641. openAPIV3Schema:
  31642. description: UUID generates a version 1 UUID (e56657e3-764f-11ef-a397-65231a88c216).
  31643. properties:
  31644. apiVersion:
  31645. description: |-
  31646. APIVersion defines the versioned schema of this representation of an object.
  31647. Servers should convert recognized schemas to the latest internal value, and
  31648. may reject unrecognized values.
  31649. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31650. type: string
  31651. kind:
  31652. description: |-
  31653. Kind is a string value representing the REST resource this object represents.
  31654. Servers may infer this from the endpoint the client submits requests to.
  31655. Cannot be updated.
  31656. In CamelCase.
  31657. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31658. type: string
  31659. metadata:
  31660. type: object
  31661. spec:
  31662. description: UUIDSpec controls the behavior of the uuid generator.
  31663. type: object
  31664. type: object
  31665. served: true
  31666. storage: true
  31667. subresources:
  31668. status: {}
  31669. ---
  31670. apiVersion: apiextensions.k8s.io/v1
  31671. kind: CustomResourceDefinition
  31672. metadata:
  31673. annotations:
  31674. controller-gen.kubebuilder.io/version: v0.19.0
  31675. labels:
  31676. external-secrets.io/component: controller
  31677. name: vaultdynamicsecrets.generators.external-secrets.io
  31678. spec:
  31679. group: generators.external-secrets.io
  31680. names:
  31681. categories:
  31682. - external-secrets
  31683. - external-secrets-generators
  31684. kind: VaultDynamicSecret
  31685. listKind: VaultDynamicSecretList
  31686. plural: vaultdynamicsecrets
  31687. singular: vaultdynamicsecret
  31688. scope: Namespaced
  31689. versions:
  31690. - name: v1alpha1
  31691. schema:
  31692. openAPIV3Schema:
  31693. description: VaultDynamicSecret represents a generator that can create dynamic secrets from HashiCorp Vault.
  31694. properties:
  31695. apiVersion:
  31696. description: |-
  31697. APIVersion defines the versioned schema of this representation of an object.
  31698. Servers should convert recognized schemas to the latest internal value, and
  31699. may reject unrecognized values.
  31700. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31701. type: string
  31702. kind:
  31703. description: |-
  31704. Kind is a string value representing the REST resource this object represents.
  31705. Servers may infer this from the endpoint the client submits requests to.
  31706. Cannot be updated.
  31707. In CamelCase.
  31708. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31709. type: string
  31710. metadata:
  31711. type: object
  31712. spec:
  31713. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  31714. properties:
  31715. allowEmptyResponse:
  31716. default: false
  31717. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  31718. type: boolean
  31719. controller:
  31720. description: |-
  31721. Used to select the correct ESO controller (think: ingress.ingressClassName)
  31722. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  31723. type: string
  31724. getParameters:
  31725. additionalProperties:
  31726. items:
  31727. type: string
  31728. type: array
  31729. description: |-
  31730. GetParameters are query-string parameters passed to Vault on GET calls.
  31731. Each key may map to multiple values, matching HTTP query-string semantics.
  31732. Ignored for non-GET methods; use Parameters for write bodies.
  31733. type: object
  31734. method:
  31735. description: Vault API method to use (GET/POST/other)
  31736. type: string
  31737. parameters:
  31738. description: Parameters to pass to Vault write (for non-GET methods)
  31739. x-kubernetes-preserve-unknown-fields: true
  31740. path:
  31741. description: Vault path to obtain the dynamic secret from
  31742. type: string
  31743. provider:
  31744. description: Vault provider common spec
  31745. properties:
  31746. auth:
  31747. description: Auth configures how secret-manager authenticates with the Vault server.
  31748. properties:
  31749. appRole:
  31750. description: |-
  31751. AppRole authenticates with Vault using the App Role auth mechanism,
  31752. with the role and secret stored in a Kubernetes Secret resource.
  31753. properties:
  31754. path:
  31755. default: approle
  31756. description: |-
  31757. Path where the App Role authentication backend is mounted
  31758. in Vault, e.g: "approle"
  31759. type: string
  31760. roleId:
  31761. description: |-
  31762. RoleID configured in the App Role authentication backend when setting
  31763. up the authentication backend in Vault.
  31764. type: string
  31765. roleRef:
  31766. description: |-
  31767. Reference to a key in a Secret that contains the App Role ID used
  31768. to authenticate with Vault.
  31769. The `key` field must be specified and denotes which entry within the Secret
  31770. resource is used as the app role id.
  31771. properties:
  31772. key:
  31773. description: |-
  31774. A key in the referenced Secret.
  31775. Some instances of this field may be defaulted, in others it may be required.
  31776. maxLength: 253
  31777. minLength: 1
  31778. pattern: ^[-._a-zA-Z0-9]+$
  31779. type: string
  31780. name:
  31781. description: The name of the Secret resource being referred to.
  31782. maxLength: 253
  31783. minLength: 1
  31784. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31785. type: string
  31786. namespace:
  31787. description: |-
  31788. The namespace of the Secret resource being referred to.
  31789. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31790. maxLength: 63
  31791. minLength: 1
  31792. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31793. type: string
  31794. type: object
  31795. secretRef:
  31796. description: |-
  31797. Reference to a key in a Secret that contains the App Role secret used
  31798. to authenticate with Vault.
  31799. The `key` field must be specified and denotes which entry within the Secret
  31800. resource is used as the app role secret.
  31801. properties:
  31802. key:
  31803. description: |-
  31804. A key in the referenced Secret.
  31805. Some instances of this field may be defaulted, in others it may be required.
  31806. maxLength: 253
  31807. minLength: 1
  31808. pattern: ^[-._a-zA-Z0-9]+$
  31809. type: string
  31810. name:
  31811. description: The name of the Secret resource being referred to.
  31812. maxLength: 253
  31813. minLength: 1
  31814. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31815. type: string
  31816. namespace:
  31817. description: |-
  31818. The namespace of the Secret resource being referred to.
  31819. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31820. maxLength: 63
  31821. minLength: 1
  31822. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31823. type: string
  31824. type: object
  31825. required:
  31826. - path
  31827. - secretRef
  31828. type: object
  31829. cert:
  31830. description: |-
  31831. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  31832. Cert authentication method
  31833. properties:
  31834. clientCert:
  31835. description: |-
  31836. ClientCert is a certificate to authenticate using the Cert Vault
  31837. authentication method
  31838. properties:
  31839. key:
  31840. description: |-
  31841. A key in the referenced Secret.
  31842. Some instances of this field may be defaulted, in others it may be required.
  31843. maxLength: 253
  31844. minLength: 1
  31845. pattern: ^[-._a-zA-Z0-9]+$
  31846. type: string
  31847. name:
  31848. description: The name of the Secret resource being referred to.
  31849. maxLength: 253
  31850. minLength: 1
  31851. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31852. type: string
  31853. namespace:
  31854. description: |-
  31855. The namespace of the Secret resource being referred to.
  31856. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31857. maxLength: 63
  31858. minLength: 1
  31859. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31860. type: string
  31861. type: object
  31862. path:
  31863. default: cert
  31864. description: |-
  31865. Path where the Certificate authentication backend is mounted
  31866. in Vault, e.g: "cert"
  31867. type: string
  31868. secretRef:
  31869. description: |-
  31870. SecretRef to a key in a Secret resource containing client private key to
  31871. authenticate with Vault using the Cert authentication method
  31872. properties:
  31873. key:
  31874. description: |-
  31875. A key in the referenced Secret.
  31876. Some instances of this field may be defaulted, in others it may be required.
  31877. maxLength: 253
  31878. minLength: 1
  31879. pattern: ^[-._a-zA-Z0-9]+$
  31880. type: string
  31881. name:
  31882. description: The name of the Secret resource being referred to.
  31883. maxLength: 253
  31884. minLength: 1
  31885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31886. type: string
  31887. namespace:
  31888. description: |-
  31889. The namespace of the Secret resource being referred to.
  31890. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31891. maxLength: 63
  31892. minLength: 1
  31893. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31894. type: string
  31895. type: object
  31896. vaultRole:
  31897. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  31898. type: string
  31899. type: object
  31900. gcp:
  31901. description: |-
  31902. Gcp authenticates with Vault using Google Cloud Platform authentication method
  31903. GCP authentication method
  31904. properties:
  31905. location:
  31906. description: Location optionally defines a location/region for the secret
  31907. type: string
  31908. path:
  31909. default: gcp
  31910. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  31911. type: string
  31912. projectID:
  31913. description: Project ID of the Google Cloud Platform project
  31914. type: string
  31915. role:
  31916. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  31917. type: string
  31918. secretRef:
  31919. description: Specify credentials in a Secret object
  31920. properties:
  31921. secretAccessKeySecretRef:
  31922. description: The SecretAccessKey is used for authentication
  31923. properties:
  31924. key:
  31925. description: |-
  31926. A key in the referenced Secret.
  31927. Some instances of this field may be defaulted, in others it may be required.
  31928. maxLength: 253
  31929. minLength: 1
  31930. pattern: ^[-._a-zA-Z0-9]+$
  31931. type: string
  31932. name:
  31933. description: The name of the Secret resource being referred to.
  31934. maxLength: 253
  31935. minLength: 1
  31936. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31937. type: string
  31938. namespace:
  31939. description: |-
  31940. The namespace of the Secret resource being referred to.
  31941. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31942. maxLength: 63
  31943. minLength: 1
  31944. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31945. type: string
  31946. type: object
  31947. type: object
  31948. serviceAccountRef:
  31949. description: ServiceAccountRef to a service account for impersonation
  31950. properties:
  31951. audiences:
  31952. description: |-
  31953. Audience specifies the `aud` claim for the service account token
  31954. Some providers automatically extend the audience field based on well-known annotations for workload
  31955. identity (e.g. IRSA or GCP Workload Identity)
  31956. items:
  31957. type: string
  31958. type: array
  31959. name:
  31960. description: The name of the ServiceAccount resource being referred to.
  31961. maxLength: 253
  31962. minLength: 1
  31963. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31964. type: string
  31965. namespace:
  31966. description: |-
  31967. Namespace of the resource being referred to.
  31968. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31969. maxLength: 63
  31970. minLength: 1
  31971. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31972. type: string
  31973. required:
  31974. - name
  31975. type: object
  31976. workloadIdentity:
  31977. description: Specify a service account with Workload Identity
  31978. properties:
  31979. clusterLocation:
  31980. description: |-
  31981. ClusterLocation is the location of the cluster
  31982. If not specified, it fetches information from the metadata server
  31983. type: string
  31984. clusterName:
  31985. description: |-
  31986. ClusterName is the name of the cluster
  31987. If not specified, it fetches information from the metadata server
  31988. type: string
  31989. clusterProjectID:
  31990. description: |-
  31991. ClusterProjectID is the project ID of the cluster
  31992. If not specified, it fetches information from the metadata server
  31993. type: string
  31994. serviceAccountRef:
  31995. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31996. properties:
  31997. audiences:
  31998. description: |-
  31999. Audience specifies the `aud` claim for the service account token
  32000. Some providers automatically extend the audience field based on well-known annotations for workload
  32001. identity (e.g. IRSA or GCP Workload Identity)
  32002. items:
  32003. type: string
  32004. type: array
  32005. name:
  32006. description: The name of the ServiceAccount resource being referred to.
  32007. maxLength: 253
  32008. minLength: 1
  32009. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32010. type: string
  32011. namespace:
  32012. description: |-
  32013. Namespace of the resource being referred to.
  32014. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32015. maxLength: 63
  32016. minLength: 1
  32017. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32018. type: string
  32019. required:
  32020. - name
  32021. type: object
  32022. required:
  32023. - serviceAccountRef
  32024. type: object
  32025. required:
  32026. - role
  32027. type: object
  32028. iam:
  32029. description: |-
  32030. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  32031. AWS IAM authentication method
  32032. properties:
  32033. externalID:
  32034. description: AWS External ID set on assumed IAM roles
  32035. type: string
  32036. jwt:
  32037. description: Specify a service account with IRSA enabled
  32038. properties:
  32039. serviceAccountRef:
  32040. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  32041. properties:
  32042. audiences:
  32043. description: |-
  32044. Audience specifies the `aud` claim for the service account token
  32045. Some providers automatically extend the audience field based on well-known annotations for workload
  32046. identity (e.g. IRSA or GCP Workload Identity)
  32047. items:
  32048. type: string
  32049. type: array
  32050. name:
  32051. description: The name of the ServiceAccount resource being referred to.
  32052. maxLength: 253
  32053. minLength: 1
  32054. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32055. type: string
  32056. namespace:
  32057. description: |-
  32058. Namespace of the resource being referred to.
  32059. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32060. maxLength: 63
  32061. minLength: 1
  32062. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32063. type: string
  32064. required:
  32065. - name
  32066. type: object
  32067. type: object
  32068. path:
  32069. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  32070. type: string
  32071. region:
  32072. description: AWS region
  32073. type: string
  32074. role:
  32075. description: This is the AWS role to be assumed before talking to vault
  32076. type: string
  32077. secretRef:
  32078. description: Specify credentials in a Secret object
  32079. properties:
  32080. accessKeyIDSecretRef:
  32081. description: The AccessKeyID is used for authentication
  32082. properties:
  32083. key:
  32084. description: |-
  32085. A key in the referenced Secret.
  32086. Some instances of this field may be defaulted, in others it may be required.
  32087. maxLength: 253
  32088. minLength: 1
  32089. pattern: ^[-._a-zA-Z0-9]+$
  32090. type: string
  32091. name:
  32092. description: The name of the Secret resource being referred to.
  32093. maxLength: 253
  32094. minLength: 1
  32095. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32096. type: string
  32097. namespace:
  32098. description: |-
  32099. The namespace of the Secret resource being referred to.
  32100. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32101. maxLength: 63
  32102. minLength: 1
  32103. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32104. type: string
  32105. type: object
  32106. secretAccessKeySecretRef:
  32107. description: The SecretAccessKey is used for authentication
  32108. properties:
  32109. key:
  32110. description: |-
  32111. A key in the referenced Secret.
  32112. Some instances of this field may be defaulted, in others it may be required.
  32113. maxLength: 253
  32114. minLength: 1
  32115. pattern: ^[-._a-zA-Z0-9]+$
  32116. type: string
  32117. name:
  32118. description: The name of the Secret resource being referred to.
  32119. maxLength: 253
  32120. minLength: 1
  32121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32122. type: string
  32123. namespace:
  32124. description: |-
  32125. The namespace of the Secret resource being referred to.
  32126. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32127. maxLength: 63
  32128. minLength: 1
  32129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32130. type: string
  32131. type: object
  32132. sessionTokenSecretRef:
  32133. description: |-
  32134. The SessionToken used for authentication
  32135. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  32136. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  32137. properties:
  32138. key:
  32139. description: |-
  32140. A key in the referenced Secret.
  32141. Some instances of this field may be defaulted, in others it may be required.
  32142. maxLength: 253
  32143. minLength: 1
  32144. pattern: ^[-._a-zA-Z0-9]+$
  32145. type: string
  32146. name:
  32147. description: The name of the Secret resource being referred to.
  32148. maxLength: 253
  32149. minLength: 1
  32150. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32151. type: string
  32152. namespace:
  32153. description: |-
  32154. The namespace of the Secret resource being referred to.
  32155. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32156. maxLength: 63
  32157. minLength: 1
  32158. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32159. type: string
  32160. type: object
  32161. type: object
  32162. vaultAwsIamServerID:
  32163. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  32164. type: string
  32165. vaultRole:
  32166. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  32167. type: string
  32168. required:
  32169. - vaultRole
  32170. type: object
  32171. jwt:
  32172. description: |-
  32173. Jwt authenticates with Vault by passing role and JWT token using the
  32174. JWT/OIDC authentication method
  32175. properties:
  32176. kubernetesServiceAccountToken:
  32177. description: |-
  32178. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  32179. a token for with the `TokenRequest` API.
  32180. properties:
  32181. audiences:
  32182. description: |-
  32183. Optional audiences field that will be used to request a temporary Kubernetes service
  32184. account token for the service account referenced by `serviceAccountRef`.
  32185. Defaults to a single audience `vault` it not specified.
  32186. Deprecated: use serviceAccountRef.Audiences instead
  32187. items:
  32188. type: string
  32189. type: array
  32190. expirationSeconds:
  32191. description: |-
  32192. Optional expiration time in seconds that will be used to request a temporary
  32193. Kubernetes service account token for the service account referenced by
  32194. `serviceAccountRef`.
  32195. Deprecated: this will be removed in the future.
  32196. Defaults to 10 minutes.
  32197. format: int64
  32198. type: integer
  32199. serviceAccountRef:
  32200. description: Service account field containing the name of a kubernetes ServiceAccount.
  32201. properties:
  32202. audiences:
  32203. description: |-
  32204. Audience specifies the `aud` claim for the service account token
  32205. Some providers automatically extend the audience field based on well-known annotations for workload
  32206. identity (e.g. IRSA or GCP Workload Identity)
  32207. items:
  32208. type: string
  32209. type: array
  32210. name:
  32211. description: The name of the ServiceAccount resource being referred to.
  32212. maxLength: 253
  32213. minLength: 1
  32214. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32215. type: string
  32216. namespace:
  32217. description: |-
  32218. Namespace of the resource being referred to.
  32219. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32220. maxLength: 63
  32221. minLength: 1
  32222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32223. type: string
  32224. required:
  32225. - name
  32226. type: object
  32227. required:
  32228. - serviceAccountRef
  32229. type: object
  32230. path:
  32231. default: jwt
  32232. description: |-
  32233. Path where the JWT authentication backend is mounted
  32234. in Vault, e.g: "jwt"
  32235. type: string
  32236. role:
  32237. description: |-
  32238. Role is a JWT role to authenticate using the JWT/OIDC Vault
  32239. authentication method
  32240. type: string
  32241. secretRef:
  32242. description: |-
  32243. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  32244. authenticate with Vault using the JWT/OIDC authentication method.
  32245. properties:
  32246. key:
  32247. description: |-
  32248. A key in the referenced Secret.
  32249. Some instances of this field may be defaulted, in others it may be required.
  32250. maxLength: 253
  32251. minLength: 1
  32252. pattern: ^[-._a-zA-Z0-9]+$
  32253. type: string
  32254. name:
  32255. description: The name of the Secret resource being referred to.
  32256. maxLength: 253
  32257. minLength: 1
  32258. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32259. type: string
  32260. namespace:
  32261. description: |-
  32262. The namespace of the Secret resource being referred to.
  32263. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32264. maxLength: 63
  32265. minLength: 1
  32266. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32267. type: string
  32268. type: object
  32269. required:
  32270. - path
  32271. type: object
  32272. kubernetes:
  32273. description: |-
  32274. Kubernetes authenticates with Vault by passing the ServiceAccount
  32275. token stored in the named Secret resource to the Vault server.
  32276. properties:
  32277. mountPath:
  32278. default: kubernetes
  32279. description: |-
  32280. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  32281. "kubernetes"
  32282. type: string
  32283. role:
  32284. description: |-
  32285. A required field containing the Vault Role to assume. A Role binds a
  32286. Kubernetes ServiceAccount with a set of Vault policies.
  32287. type: string
  32288. secretRef:
  32289. description: |-
  32290. Optional secret field containing a Kubernetes ServiceAccount JWT used
  32291. for authenticating with Vault. If a name is specified without a key,
  32292. `token` is the default. If one is not specified, the one bound to
  32293. the controller will be used.
  32294. properties:
  32295. key:
  32296. description: |-
  32297. A key in the referenced Secret.
  32298. Some instances of this field may be defaulted, in others it may be required.
  32299. maxLength: 253
  32300. minLength: 1
  32301. pattern: ^[-._a-zA-Z0-9]+$
  32302. type: string
  32303. name:
  32304. description: The name of the Secret resource being referred to.
  32305. maxLength: 253
  32306. minLength: 1
  32307. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32308. type: string
  32309. namespace:
  32310. description: |-
  32311. The namespace of the Secret resource being referred to.
  32312. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32313. maxLength: 63
  32314. minLength: 1
  32315. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32316. type: string
  32317. type: object
  32318. serviceAccountRef:
  32319. description: |-
  32320. Optional service account field containing the name of a kubernetes ServiceAccount.
  32321. If the service account is specified, the service account secret token JWT will be used
  32322. for authenticating with Vault. If the service account selector is not supplied,
  32323. the secretRef will be used instead.
  32324. properties:
  32325. audiences:
  32326. description: |-
  32327. Audience specifies the `aud` claim for the service account token
  32328. Some providers automatically extend the audience field based on well-known annotations for workload
  32329. identity (e.g. IRSA or GCP Workload Identity)
  32330. items:
  32331. type: string
  32332. type: array
  32333. name:
  32334. description: The name of the ServiceAccount resource being referred to.
  32335. maxLength: 253
  32336. minLength: 1
  32337. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32338. type: string
  32339. namespace:
  32340. description: |-
  32341. Namespace of the resource being referred to.
  32342. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32343. maxLength: 63
  32344. minLength: 1
  32345. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32346. type: string
  32347. required:
  32348. - name
  32349. type: object
  32350. required:
  32351. - mountPath
  32352. - role
  32353. type: object
  32354. ldap:
  32355. description: |-
  32356. Ldap authenticates with Vault by passing username/password pair using
  32357. the LDAP authentication method
  32358. properties:
  32359. path:
  32360. default: ldap
  32361. description: |-
  32362. Path where the LDAP authentication backend is mounted
  32363. in Vault, e.g: "ldap"
  32364. type: string
  32365. secretRef:
  32366. description: |-
  32367. SecretRef to a key in a Secret resource containing password for the LDAP
  32368. user used to authenticate with Vault using the LDAP authentication
  32369. method
  32370. properties:
  32371. key:
  32372. description: |-
  32373. A key in the referenced Secret.
  32374. Some instances of this field may be defaulted, in others it may be required.
  32375. maxLength: 253
  32376. minLength: 1
  32377. pattern: ^[-._a-zA-Z0-9]+$
  32378. type: string
  32379. name:
  32380. description: The name of the Secret resource being referred to.
  32381. maxLength: 253
  32382. minLength: 1
  32383. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32384. type: string
  32385. namespace:
  32386. description: |-
  32387. The namespace of the Secret resource being referred to.
  32388. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32389. maxLength: 63
  32390. minLength: 1
  32391. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32392. type: string
  32393. type: object
  32394. username:
  32395. description: |-
  32396. Username is an LDAP username used to authenticate using the LDAP Vault
  32397. authentication method
  32398. type: string
  32399. required:
  32400. - path
  32401. - username
  32402. type: object
  32403. namespace:
  32404. description: |-
  32405. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  32406. Namespaces is a set of features within Vault Enterprise that allows
  32407. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  32408. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  32409. This will default to Vault.Namespace field if set, or empty otherwise
  32410. type: string
  32411. tokenSecretRef:
  32412. description: TokenSecretRef authenticates with Vault by presenting a token.
  32413. properties:
  32414. key:
  32415. description: |-
  32416. A key in the referenced Secret.
  32417. Some instances of this field may be defaulted, in others it may be required.
  32418. maxLength: 253
  32419. minLength: 1
  32420. pattern: ^[-._a-zA-Z0-9]+$
  32421. type: string
  32422. name:
  32423. description: The name of the Secret resource being referred to.
  32424. maxLength: 253
  32425. minLength: 1
  32426. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32427. type: string
  32428. namespace:
  32429. description: |-
  32430. The namespace of the Secret resource being referred to.
  32431. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32432. maxLength: 63
  32433. minLength: 1
  32434. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32435. type: string
  32436. type: object
  32437. userPass:
  32438. description: UserPass authenticates with Vault by passing username/password pair
  32439. properties:
  32440. path:
  32441. default: userpass
  32442. description: |-
  32443. Path where the UserPassword authentication backend is mounted
  32444. in Vault, e.g: "userpass"
  32445. type: string
  32446. secretRef:
  32447. description: |-
  32448. SecretRef to a key in a Secret resource containing password for the
  32449. user used to authenticate with Vault using the UserPass authentication
  32450. method
  32451. properties:
  32452. key:
  32453. description: |-
  32454. A key in the referenced Secret.
  32455. Some instances of this field may be defaulted, in others it may be required.
  32456. maxLength: 253
  32457. minLength: 1
  32458. pattern: ^[-._a-zA-Z0-9]+$
  32459. type: string
  32460. name:
  32461. description: The name of the Secret resource being referred to.
  32462. maxLength: 253
  32463. minLength: 1
  32464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32465. type: string
  32466. namespace:
  32467. description: |-
  32468. The namespace of the Secret resource being referred to.
  32469. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32470. maxLength: 63
  32471. minLength: 1
  32472. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32473. type: string
  32474. type: object
  32475. username:
  32476. description: |-
  32477. Username is a username used to authenticate using the UserPass Vault
  32478. authentication method
  32479. type: string
  32480. required:
  32481. - path
  32482. - username
  32483. type: object
  32484. type: object
  32485. caBundle:
  32486. description: |-
  32487. PEM encoded CA bundle used to validate Vault server certificate. Only used
  32488. if the Server URL is using HTTPS protocol. This parameter is ignored for
  32489. plain HTTP protocol connection. If not set the system root certificates
  32490. are used to validate the TLS connection.
  32491. format: byte
  32492. type: string
  32493. caProvider:
  32494. description: The provider for the CA bundle to use to validate Vault server certificate.
  32495. properties:
  32496. key:
  32497. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  32498. maxLength: 253
  32499. minLength: 1
  32500. pattern: ^[-._a-zA-Z0-9]+$
  32501. type: string
  32502. name:
  32503. description: The name of the object located at the provider type.
  32504. maxLength: 253
  32505. minLength: 1
  32506. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32507. type: string
  32508. namespace:
  32509. description: |-
  32510. The namespace the Provider type is in.
  32511. Can only be defined when used in a ClusterSecretStore.
  32512. maxLength: 63
  32513. minLength: 1
  32514. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32515. type: string
  32516. type:
  32517. description: The type of provider to use such as "Secret", or "ConfigMap".
  32518. enum:
  32519. - Secret
  32520. - ConfigMap
  32521. type: string
  32522. required:
  32523. - name
  32524. - type
  32525. type: object
  32526. checkAndSet:
  32527. description: |-
  32528. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  32529. Only applies to Vault KV v2 stores. When enabled, write operations must include
  32530. the current version of the secret to prevent unintentional overwrites.
  32531. properties:
  32532. required:
  32533. description: |-
  32534. Required when true, all write operations must include a check-and-set parameter.
  32535. This helps prevent unintentional overwrites of secrets.
  32536. type: boolean
  32537. type: object
  32538. forwardInconsistent:
  32539. description: |-
  32540. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  32541. leader instead of simply retrying within a loop. This can increase performance if
  32542. the option is enabled serverside.
  32543. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  32544. type: boolean
  32545. headers:
  32546. additionalProperties:
  32547. type: string
  32548. description: Headers to be added in Vault request
  32549. type: object
  32550. namespace:
  32551. description: |-
  32552. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  32553. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  32554. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  32555. type: string
  32556. path:
  32557. description: |-
  32558. Path is the mount path of the Vault KV backend endpoint, e.g:
  32559. "secret". The v2 KV secret engine version specific "/data" path suffix
  32560. for fetching secrets from Vault is optional and will be appended
  32561. if not present in specified path.
  32562. type: string
  32563. readYourWrites:
  32564. description: |-
  32565. ReadYourWrites ensures isolated read-after-write semantics by
  32566. providing discovered cluster replication states in each request.
  32567. More information about eventual consistency in Vault can be found here
  32568. https://www.vaultproject.io/docs/enterprise/consistency
  32569. type: boolean
  32570. server:
  32571. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  32572. type: string
  32573. tls:
  32574. description: |-
  32575. The configuration used for client side related TLS communication, when the Vault server
  32576. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  32577. This parameter is ignored for plain HTTP protocol connection.
  32578. It's worth noting this configuration is different from the "TLS certificates auth method",
  32579. which is available under the `auth.cert` section.
  32580. properties:
  32581. certSecretRef:
  32582. description: |-
  32583. CertSecretRef is a certificate added to the transport layer
  32584. when communicating with the Vault server.
  32585. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  32586. properties:
  32587. key:
  32588. description: |-
  32589. A key in the referenced Secret.
  32590. Some instances of this field may be defaulted, in others it may be required.
  32591. maxLength: 253
  32592. minLength: 1
  32593. pattern: ^[-._a-zA-Z0-9]+$
  32594. type: string
  32595. name:
  32596. description: The name of the Secret resource being referred to.
  32597. maxLength: 253
  32598. minLength: 1
  32599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32600. type: string
  32601. namespace:
  32602. description: |-
  32603. The namespace of the Secret resource being referred to.
  32604. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32605. maxLength: 63
  32606. minLength: 1
  32607. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32608. type: string
  32609. type: object
  32610. keySecretRef:
  32611. description: |-
  32612. KeySecretRef to a key in a Secret resource containing client private key
  32613. added to the transport layer when communicating with the Vault server.
  32614. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  32615. properties:
  32616. key:
  32617. description: |-
  32618. A key in the referenced Secret.
  32619. Some instances of this field may be defaulted, in others it may be required.
  32620. maxLength: 253
  32621. minLength: 1
  32622. pattern: ^[-._a-zA-Z0-9]+$
  32623. type: string
  32624. name:
  32625. description: The name of the Secret resource being referred to.
  32626. maxLength: 253
  32627. minLength: 1
  32628. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32629. type: string
  32630. namespace:
  32631. description: |-
  32632. The namespace of the Secret resource being referred to.
  32633. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32634. maxLength: 63
  32635. minLength: 1
  32636. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32637. type: string
  32638. type: object
  32639. type: object
  32640. version:
  32641. default: v2
  32642. description: |-
  32643. Version is the Vault KV secret engine version. This can be either "v1" or
  32644. "v2". Version defaults to "v2".
  32645. enum:
  32646. - v1
  32647. - v2
  32648. type: string
  32649. required:
  32650. - server
  32651. type: object
  32652. resultType:
  32653. default: Data
  32654. description: |-
  32655. Result type defines which data is returned from the generator.
  32656. By default, it is the "data" section of the Vault API response.
  32657. When using e.g. /auth/token/create the "data" section is empty but
  32658. the "auth" section contains the generated token.
  32659. Please refer to the vault docs regarding the result data structure.
  32660. Additionally, accessing the raw response is possibly by using "Raw" result type.
  32661. enum:
  32662. - Data
  32663. - Auth
  32664. - Raw
  32665. type: string
  32666. retrySettings:
  32667. description: Used to configure http retries if failed
  32668. properties:
  32669. maxRetries:
  32670. format: int32
  32671. type: integer
  32672. retryInterval:
  32673. type: string
  32674. type: object
  32675. required:
  32676. - path
  32677. - provider
  32678. type: object
  32679. type: object
  32680. served: true
  32681. storage: true
  32682. subresources:
  32683. status: {}
  32684. ---
  32685. apiVersion: apiextensions.k8s.io/v1
  32686. kind: CustomResourceDefinition
  32687. metadata:
  32688. annotations:
  32689. controller-gen.kubebuilder.io/version: v0.19.0
  32690. labels:
  32691. external-secrets.io/component: controller
  32692. name: webhooks.generators.external-secrets.io
  32693. spec:
  32694. group: generators.external-secrets.io
  32695. names:
  32696. categories:
  32697. - external-secrets
  32698. - external-secrets-generators
  32699. kind: Webhook
  32700. listKind: WebhookList
  32701. plural: webhooks
  32702. singular: webhook
  32703. scope: Namespaced
  32704. versions:
  32705. - name: v1alpha1
  32706. schema:
  32707. openAPIV3Schema:
  32708. description: |-
  32709. Webhook connects to a third party API server to handle the secrets generation
  32710. configuration parameters in spec.
  32711. You can specify the server, the token, and additional body parameters.
  32712. See documentation for the full API specification for requests and responses.
  32713. properties:
  32714. apiVersion:
  32715. description: |-
  32716. APIVersion defines the versioned schema of this representation of an object.
  32717. Servers should convert recognized schemas to the latest internal value, and
  32718. may reject unrecognized values.
  32719. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  32720. type: string
  32721. kind:
  32722. description: |-
  32723. Kind is a string value representing the REST resource this object represents.
  32724. Servers may infer this from the endpoint the client submits requests to.
  32725. Cannot be updated.
  32726. In CamelCase.
  32727. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  32728. type: string
  32729. metadata:
  32730. type: object
  32731. spec:
  32732. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  32733. properties:
  32734. auth:
  32735. description: Auth specifies a authorization protocol. Only one protocol may be set.
  32736. maxProperties: 1
  32737. minProperties: 1
  32738. properties:
  32739. ntlm:
  32740. description: NTLMProtocol configures the store to use NTLM for auth
  32741. properties:
  32742. passwordSecret:
  32743. description: |-
  32744. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  32745. In some instances, `key` is a required field.
  32746. properties:
  32747. key:
  32748. description: |-
  32749. A key in the referenced Secret.
  32750. Some instances of this field may be defaulted, in others it may be required.
  32751. maxLength: 253
  32752. minLength: 1
  32753. pattern: ^[-._a-zA-Z0-9]+$
  32754. type: string
  32755. name:
  32756. description: The name of the Secret resource being referred to.
  32757. maxLength: 253
  32758. minLength: 1
  32759. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32760. type: string
  32761. namespace:
  32762. description: |-
  32763. The namespace of the Secret resource being referred to.
  32764. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32765. maxLength: 63
  32766. minLength: 1
  32767. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32768. type: string
  32769. type: object
  32770. usernameSecret:
  32771. description: |-
  32772. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  32773. In some instances, `key` is a required field.
  32774. properties:
  32775. key:
  32776. description: |-
  32777. A key in the referenced Secret.
  32778. Some instances of this field may be defaulted, in others it may be required.
  32779. maxLength: 253
  32780. minLength: 1
  32781. pattern: ^[-._a-zA-Z0-9]+$
  32782. type: string
  32783. name:
  32784. description: The name of the Secret resource being referred to.
  32785. maxLength: 253
  32786. minLength: 1
  32787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32788. type: string
  32789. namespace:
  32790. description: |-
  32791. The namespace of the Secret resource being referred to.
  32792. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32793. maxLength: 63
  32794. minLength: 1
  32795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32796. type: string
  32797. type: object
  32798. required:
  32799. - passwordSecret
  32800. - usernameSecret
  32801. type: object
  32802. type: object
  32803. body:
  32804. description: Body
  32805. type: string
  32806. caBundle:
  32807. description: |-
  32808. PEM encoded CA bundle used to validate webhook server certificate. Only used
  32809. if the Server URL is using HTTPS protocol. This parameter is ignored for
  32810. plain HTTP protocol connection. If not set the system root certificates
  32811. are used to validate the TLS connection.
  32812. format: byte
  32813. type: string
  32814. caProvider:
  32815. description: The provider for the CA bundle to use to validate webhook server certificate.
  32816. properties:
  32817. key:
  32818. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  32819. maxLength: 253
  32820. minLength: 1
  32821. pattern: ^[-._a-zA-Z0-9]+$
  32822. type: string
  32823. name:
  32824. description: The name of the object located at the provider type.
  32825. maxLength: 253
  32826. minLength: 1
  32827. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32828. type: string
  32829. namespace:
  32830. description: The namespace the Provider type is in.
  32831. maxLength: 63
  32832. minLength: 1
  32833. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32834. type: string
  32835. type:
  32836. description: The type of provider to use such as "Secret", or "ConfigMap".
  32837. enum:
  32838. - Secret
  32839. - ConfigMap
  32840. type: string
  32841. required:
  32842. - name
  32843. - type
  32844. type: object
  32845. headers:
  32846. additionalProperties:
  32847. type: string
  32848. description: Headers
  32849. type: object
  32850. method:
  32851. description: Webhook Method
  32852. type: string
  32853. result:
  32854. description: Result formatting
  32855. properties:
  32856. jsonPath:
  32857. description: Json path of return value
  32858. type: string
  32859. type: object
  32860. secrets:
  32861. description: |-
  32862. Secrets to fill in templates
  32863. These secrets will be passed to the templating function as key value pairs under the given name
  32864. items:
  32865. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  32866. properties:
  32867. name:
  32868. description: Name of this secret in templates
  32869. type: string
  32870. secretRef:
  32871. description: Secret ref to fill in credentials
  32872. properties:
  32873. key:
  32874. description: The key where the token is found.
  32875. maxLength: 253
  32876. minLength: 1
  32877. pattern: ^[-._a-zA-Z0-9]+$
  32878. type: string
  32879. name:
  32880. description: The name of the Secret resource being referred to.
  32881. maxLength: 253
  32882. minLength: 1
  32883. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32884. type: string
  32885. type: object
  32886. required:
  32887. - name
  32888. - secretRef
  32889. type: object
  32890. type: array
  32891. timeout:
  32892. description: Timeout
  32893. type: string
  32894. url:
  32895. description: Webhook url to call
  32896. type: string
  32897. required:
  32898. - result
  32899. - url
  32900. type: object
  32901. type: object
  32902. served: true
  32903. storage: true
  32904. subresources:
  32905. status: {}