mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
223 lines
8.2 KiB
YAML
223 lines
8.2 KiB
YAML
---
|
|
apiVersion: apiextensions.k8s.io/v1
|
|
kind: CustomResourceDefinition
|
|
metadata:
|
|
annotations:
|
|
controller-gen.kubebuilder.io/version: v0.10.0
|
|
creationTimestamp: null
|
|
name: infisicaldynamicsecrets.secrets.infisical.com
|
|
spec:
|
|
group: secrets.infisical.com
|
|
names:
|
|
kind: InfisicalDynamicSecret
|
|
listKind: InfisicalDynamicSecretList
|
|
plural: infisicaldynamicsecrets
|
|
singular: infisicaldynamicsecret
|
|
scope: Namespaced
|
|
versions:
|
|
- name: v1alpha1
|
|
schema:
|
|
openAPIV3Schema:
|
|
description: InfisicalDynamicSecret is the Schema for the infisicaldynamicsecrets
|
|
API.
|
|
properties:
|
|
apiVersion:
|
|
description: 'APIVersion defines the versioned schema of this representation
|
|
of an object. Servers should convert recognized schemas to the latest
|
|
internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources'
|
|
type: string
|
|
kind:
|
|
description: 'Kind is a string value representing the REST resource this
|
|
object represents. Servers may infer this from the endpoint the client
|
|
submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds'
|
|
type: string
|
|
metadata:
|
|
type: object
|
|
spec:
|
|
description: InfisicalDynamicSecretSpec defines the desired state of InfisicalDynamicSecret.
|
|
properties:
|
|
authentication:
|
|
properties:
|
|
awsIamAuth:
|
|
properties:
|
|
identityId:
|
|
type: string
|
|
required:
|
|
- identityId
|
|
type: object
|
|
azureAuth:
|
|
properties:
|
|
identityId:
|
|
type: string
|
|
resource:
|
|
type: string
|
|
required:
|
|
- identityId
|
|
type: object
|
|
gcpIamAuth:
|
|
properties:
|
|
identityId:
|
|
type: string
|
|
serviceAccountKeyFilePath:
|
|
type: string
|
|
required:
|
|
- identityId
|
|
- serviceAccountKeyFilePath
|
|
type: object
|
|
gcpIdTokenAuth:
|
|
properties:
|
|
identityId:
|
|
type: string
|
|
required:
|
|
- identityId
|
|
type: object
|
|
kubernetesAuth:
|
|
properties:
|
|
identityId:
|
|
type: string
|
|
serviceAccountRef:
|
|
properties:
|
|
name:
|
|
type: string
|
|
namespace:
|
|
type: string
|
|
required:
|
|
- name
|
|
- namespace
|
|
type: object
|
|
required:
|
|
- identityId
|
|
- serviceAccountRef
|
|
type: object
|
|
universalAuth:
|
|
properties:
|
|
credentialsRef:
|
|
properties:
|
|
secretName:
|
|
description: The name of the Kubernetes Secret
|
|
type: string
|
|
secretNamespace:
|
|
description: The name space where the Kubernetes Secret
|
|
is located
|
|
type: string
|
|
required:
|
|
- secretName
|
|
- secretNamespace
|
|
type: object
|
|
required:
|
|
- credentialsRef
|
|
type: object
|
|
type: object
|
|
dynamicSecret:
|
|
properties:
|
|
environmentSlug:
|
|
type: string
|
|
projectId:
|
|
type: string
|
|
secretName:
|
|
type: string
|
|
secretsPath:
|
|
type: string
|
|
required:
|
|
- environmentSlug
|
|
- projectId
|
|
- secretName
|
|
- secretsPath
|
|
type: object
|
|
hostAPI:
|
|
type: string
|
|
leaseRevocationPolicy:
|
|
type: string
|
|
leaseTTL:
|
|
type: string
|
|
managedSecretReference:
|
|
properties:
|
|
creationPolicy:
|
|
default: Orphan
|
|
description: 'The Kubernetes Secret creation policy. Enum with
|
|
values: ''Owner'', ''Orphan''. Owner creates the secret and
|
|
sets .metadata.ownerReferences of the InfisicalSecret CRD that
|
|
created it. Orphan will not set the secret owner. This will
|
|
result in the secret being orphaned and not deleted when the
|
|
resource is deleted.'
|
|
type: string
|
|
secretName:
|
|
description: The name of the Kubernetes Secret
|
|
type: string
|
|
secretNamespace:
|
|
description: The name space where the Kubernetes Secret is located
|
|
type: string
|
|
secretType:
|
|
default: Opaque
|
|
description: 'The Kubernetes Secret type (experimental feature).
|
|
More info: https://kubernetes.io/docs/concepts/configuration/secret/#secret-types'
|
|
type: string
|
|
required:
|
|
- secretName
|
|
- secretNamespace
|
|
type: object
|
|
tls:
|
|
properties:
|
|
caRef:
|
|
description: Reference to secret containing CA cert
|
|
properties:
|
|
key:
|
|
description: The name of the secret property with the CA certificate
|
|
value
|
|
type: string
|
|
secretName:
|
|
description: The name of the Kubernetes Secret
|
|
type: string
|
|
secretNamespace:
|
|
description: The namespace where the Kubernetes Secret is
|
|
located
|
|
type: string
|
|
required:
|
|
- key
|
|
- secretName
|
|
- secretNamespace
|
|
type: object
|
|
type: object
|
|
required:
|
|
- authentication
|
|
- dynamicSecret
|
|
- leaseRevocationPolicy
|
|
- leaseTTL
|
|
- managedSecretReference
|
|
type: object
|
|
status:
|
|
description: InfisicalDynamicSecretStatus defines the observed state of
|
|
InfisicalDynamicSecret.
|
|
properties:
|
|
dynamicSecretId:
|
|
type: string
|
|
lease:
|
|
properties:
|
|
creationTimestamp:
|
|
format: date-time
|
|
type: string
|
|
expiresAt:
|
|
format: date-time
|
|
type: string
|
|
id:
|
|
type: string
|
|
version:
|
|
format: int64
|
|
type: integer
|
|
required:
|
|
- creationTimestamp
|
|
- expiresAt
|
|
- id
|
|
- version
|
|
type: object
|
|
maxTTL:
|
|
description: The MaxTTL can be null, if it's null, there's no max
|
|
TTL and we should never have to renew.
|
|
type: string
|
|
type: object
|
|
type: object
|
|
served: true
|
|
storage: true
|
|
subresources:
|
|
status: {}
|