diff --git a/apps/external-secrets/crds.yaml b/apps/external-secrets/crds.yaml index 7f03f9b0..d5cdacf7 100644 --- a/apps/external-secrets/crds.yaml +++ b/apps/external-secrets/crds.yaml @@ -140,8 +140,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -480,8 +480,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -2293,8 +2293,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -2530,8 +2530,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -2575,8 +2575,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -2769,8 +2769,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -2898,8 +2898,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -3308,8 +3308,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -3376,8 +3376,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -3760,8 +3760,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -3806,8 +3806,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -3851,8 +3851,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -4013,8 +4013,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -4136,8 +4136,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -5578,8 +5578,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -5702,8 +5702,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -5797,8 +5797,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -6173,8 +6173,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -7051,8 +7051,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -7211,8 +7211,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -7523,8 +7523,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -7823,8 +7823,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -7950,8 +7950,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -7992,7 +7992,7 @@ spec: type: object github: description: |- - Github configures this store to push GitHub Actions secrets using the GitHub API provider. + Github configures this store to push GitHub Actions or Dependabot secrets using the GitHub API provider. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub properties: appID: @@ -8056,6 +8056,15 @@ spec: repository: description: repository will be used to fetch secrets from the Github repository within an organization type: string + secretType: + default: Actions + description: |- + secretType specifies which GitHub secret service to use. + Defaults to Actions for backwards compatibility. + enum: + - Actions + - Dependabot + type: string uploadURL: description: Upload URL for enterprise instances. Default to URL. type: string @@ -8069,6 +8078,9 @@ spec: - installationID - organization type: object + x-kubernetes-validations: + - message: Dependabot secrets do not support environments + rule: self.secretType != 'Dependabot' || !has(self.environment) || size(self.environment) == 0 gitlab: description: GitLab configures this store to sync secrets using GitLab Variables provider properties: @@ -9146,8 +9158,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -9356,10 +9368,56 @@ spec: pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$ type: string type: object + workloadIdentity: + description: WorkloadIdentity defines configuration for workload identity authentication to Nebius IAM. + properties: + iamServiceAccountID: + description: |- + IAMServiceAccountID is the Nebius IAM service account identifier that the + federated Kubernetes service account should impersonate during token exchange. + example: serviceaccount-e00example + minLength: 1 + pattern: ^serviceaccount-[a-z][a-z0-9]{2} + type: string + serviceAccountRef: + description: |- + ServiceAccountRef references a Kubernetes ServiceAccount used to request a + temporary JWT via the TokenRequest API. The JWT is then exchanged for a + Nebius IAM token using workload federation. + properties: + audiences: + description: |- + Audience specifies the `aud` claim for the service account token + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) + items: + type: string + type: array + name: + description: The name of the ServiceAccount resource being referred to. + maxLength: 253 + minLength: 1 + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$ + type: string + namespace: + description: |- + Namespace of the resource being referred to. + Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent. + maxLength: 63 + minLength: 1 + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$ + type: string + required: + - name + type: object + required: + - iamServiceAccountID + - serviceAccountRef + type: object type: object x-kubernetes-validations: - - message: either serviceAccountCredsSecretRef or tokenSecretRef must be set - rule: has(self.serviceAccountCredsSecretRef) || has(self.tokenSecretRef) + - message: exactly one of serviceAccountCredsSecretRef, tokenSecretRef, or workloadIdentity must be set + rule: '(has(self.serviceAccountCredsSecretRef) && has(self.serviceAccountCredsSecretRef.name) && size(self.serviceAccountCredsSecretRef.name) > 0 ? 1 : 0) + (has(self.tokenSecretRef) && has(self.tokenSecretRef.name) && size(self.tokenSecretRef.name) > 0 ? 1 : 0) + (has(self.workloadIdentity) ? 1 : 0) == 1' caProvider: description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate. properties: @@ -9768,6 +9826,93 @@ spec: x-kubernetes-validations: - message: exactly one of the fields in [roleId roleRef] must be set rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1' + kubernetes: + description: |- + Kubernetes authenticates with OpenBao by passing a ServiceAccount + token to the [Kubernetes auth mechanism]. + + [Kubernetes auth mechanism]: https://openbao.org/docs/auth/kubernetes/ + properties: + path: + default: kubernetes + description: |- + Path where the Kubernetes authentication backend is mounted in OpenBao, e.g: + "kubernetes" + type: string + role: + description: |- + A required field containing the OpenBao Role to assume. A Role binds a + Kubernetes ServiceAccount with a set of OpenBao policies. + minLength: 1 + type: string + secretRef: + description: |- + Optional secret field containing a Kubernetes ServiceAccount JWT used + for authenticating with OpenBao. If a name is specified without a key, + `token` is the default. + properties: + key: + description: |- + A key in the referenced Secret. + Some instances of this field may be defaulted, in others it may be required. + maxLength: 253 + minLength: 1 + pattern: ^[-._a-zA-Z0-9]+$ + type: string + name: + description: The name of the Secret resource being referred to. + maxLength: 253 + minLength: 1 + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$ + type: string + namespace: + description: |- + The namespace of the Secret resource being referred to. + Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent. + maxLength: 63 + minLength: 1 + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$ + type: string + type: object + serviceAccountRef: + description: |- + Optional service account field containing the name of a Kubernetes ServiceAccount. + If the service account is specified, a token will be requested from the Kubernetes + TokenRequest API for authenticating with OpenBao. + Any configured audiences will be passed to the TokenRequest as-is. + properties: + audiences: + description: |- + Audience specifies the `aud` claim for the service account token + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) + items: + type: string + type: array + name: + description: The name of the ServiceAccount resource being referred to. + maxLength: 253 + minLength: 1 + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$ + type: string + namespace: + description: |- + Namespace of the resource being referred to. + Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent. + maxLength: 63 + minLength: 1 + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$ + type: string + required: + - name + type: object + required: + - path + - role + type: object + x-kubernetes-validations: + - message: exactly one of the fields in [serviceAccountRef secretRef] must be set + rule: '[has(self.serviceAccountRef),has(self.secretRef)].filter(x,x==true).size() == 1' namespace: description: |- Name of the [OpenBao Namespace] to authenticate to. This can be different @@ -9857,8 +10002,8 @@ spec: type: object type: object x-kubernetes-validations: - - message: exactly one of the fields in [appRole tokenSecretRef userPass] must be set - rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass)].filter(x,x==true).size() == 1' + - message: exactly one of the fields in [appRole tokenSecretRef userPass kubernetes] must be set + rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass),has(self.kubernetes)].filter(x,x==true).size() == 1' caBundle: description: |- PEM encoded CA bundle used to validate the OpenBao server certificate. If @@ -10045,8 +10190,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -10540,8 +10685,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -10722,6 +10867,11 @@ spec: - name - type type: object + disableSiteIDValidation: + description: |- + DisableSiteIDValidation permits a missing site ID for new secrets. + The provider sends 0 if no site ID is set. + type: boolean domain: description: Domain is the secret server domain. type: string @@ -10769,6 +10919,13 @@ spec: ServerURL URL to your secret server installation type: string + siteId: + description: |- + SiteID is the ID of the Secret Server site for new secrets. + PushSecret metadata can override this value for one secret. + The provider uses 1 if this field is not set. + minimum: 1 + type: integer token: description: |- Token is an access token used to authenticate to the secret server, @@ -11120,8 +11277,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -11166,8 +11323,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -11211,8 +11368,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -11373,8 +11530,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -11496,8 +11653,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -12509,8 +12666,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -12781,8 +12938,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -13101,8 +13258,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -13676,8 +13833,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -14077,8 +14234,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -14548,8 +14705,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -14928,8 +15085,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -15563,8 +15720,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -15725,8 +15882,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -15848,8 +16005,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -16597,8 +16754,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -18297,8 +18454,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -18426,8 +18583,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -19895,8 +20052,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -20126,8 +20283,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -20250,8 +20407,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -20345,8 +20502,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -20721,8 +20878,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -21599,8 +21756,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -21759,8 +21916,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -22071,8 +22228,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -22371,8 +22528,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -22498,8 +22655,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -22540,7 +22697,7 @@ spec: type: object github: description: |- - Github configures this store to push GitHub Actions secrets using the GitHub API provider. + Github configures this store to push GitHub Actions or Dependabot secrets using the GitHub API provider. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub properties: appID: @@ -22604,6 +22761,15 @@ spec: repository: description: repository will be used to fetch secrets from the Github repository within an organization type: string + secretType: + default: Actions + description: |- + secretType specifies which GitHub secret service to use. + Defaults to Actions for backwards compatibility. + enum: + - Actions + - Dependabot + type: string uploadURL: description: Upload URL for enterprise instances. Default to URL. type: string @@ -22617,6 +22783,9 @@ spec: - installationID - organization type: object + x-kubernetes-validations: + - message: Dependabot secrets do not support environments + rule: self.secretType != 'Dependabot' || !has(self.environment) || size(self.environment) == 0 gitlab: description: GitLab configures this store to sync secrets using GitLab Variables provider properties: @@ -23694,8 +23863,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -23904,10 +24073,56 @@ spec: pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$ type: string type: object + workloadIdentity: + description: WorkloadIdentity defines configuration for workload identity authentication to Nebius IAM. + properties: + iamServiceAccountID: + description: |- + IAMServiceAccountID is the Nebius IAM service account identifier that the + federated Kubernetes service account should impersonate during token exchange. + example: serviceaccount-e00example + minLength: 1 + pattern: ^serviceaccount-[a-z][a-z0-9]{2} + type: string + serviceAccountRef: + description: |- + ServiceAccountRef references a Kubernetes ServiceAccount used to request a + temporary JWT via the TokenRequest API. The JWT is then exchanged for a + Nebius IAM token using workload federation. + properties: + audiences: + description: |- + Audience specifies the `aud` claim for the service account token + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) + items: + type: string + type: array + name: + description: The name of the ServiceAccount resource being referred to. + maxLength: 253 + minLength: 1 + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$ + type: string + namespace: + description: |- + Namespace of the resource being referred to. + Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent. + maxLength: 63 + minLength: 1 + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$ + type: string + required: + - name + type: object + required: + - iamServiceAccountID + - serviceAccountRef + type: object type: object x-kubernetes-validations: - - message: either serviceAccountCredsSecretRef or tokenSecretRef must be set - rule: has(self.serviceAccountCredsSecretRef) || has(self.tokenSecretRef) + - message: exactly one of serviceAccountCredsSecretRef, tokenSecretRef, or workloadIdentity must be set + rule: '(has(self.serviceAccountCredsSecretRef) && has(self.serviceAccountCredsSecretRef.name) && size(self.serviceAccountCredsSecretRef.name) > 0 ? 1 : 0) + (has(self.tokenSecretRef) && has(self.tokenSecretRef.name) && size(self.tokenSecretRef.name) > 0 ? 1 : 0) + (has(self.workloadIdentity) ? 1 : 0) == 1' caProvider: description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate. properties: @@ -24316,6 +24531,93 @@ spec: x-kubernetes-validations: - message: exactly one of the fields in [roleId roleRef] must be set rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1' + kubernetes: + description: |- + Kubernetes authenticates with OpenBao by passing a ServiceAccount + token to the [Kubernetes auth mechanism]. + + [Kubernetes auth mechanism]: https://openbao.org/docs/auth/kubernetes/ + properties: + path: + default: kubernetes + description: |- + Path where the Kubernetes authentication backend is mounted in OpenBao, e.g: + "kubernetes" + type: string + role: + description: |- + A required field containing the OpenBao Role to assume. A Role binds a + Kubernetes ServiceAccount with a set of OpenBao policies. + minLength: 1 + type: string + secretRef: + description: |- + Optional secret field containing a Kubernetes ServiceAccount JWT used + for authenticating with OpenBao. If a name is specified without a key, + `token` is the default. + properties: + key: + description: |- + A key in the referenced Secret. + Some instances of this field may be defaulted, in others it may be required. + maxLength: 253 + minLength: 1 + pattern: ^[-._a-zA-Z0-9]+$ + type: string + name: + description: The name of the Secret resource being referred to. + maxLength: 253 + minLength: 1 + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$ + type: string + namespace: + description: |- + The namespace of the Secret resource being referred to. + Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent. + maxLength: 63 + minLength: 1 + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$ + type: string + type: object + serviceAccountRef: + description: |- + Optional service account field containing the name of a Kubernetes ServiceAccount. + If the service account is specified, a token will be requested from the Kubernetes + TokenRequest API for authenticating with OpenBao. + Any configured audiences will be passed to the TokenRequest as-is. + properties: + audiences: + description: |- + Audience specifies the `aud` claim for the service account token + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) + items: + type: string + type: array + name: + description: The name of the ServiceAccount resource being referred to. + maxLength: 253 + minLength: 1 + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$ + type: string + namespace: + description: |- + Namespace of the resource being referred to. + Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent. + maxLength: 63 + minLength: 1 + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$ + type: string + required: + - name + type: object + required: + - path + - role + type: object + x-kubernetes-validations: + - message: exactly one of the fields in [serviceAccountRef secretRef] must be set + rule: '[has(self.serviceAccountRef),has(self.secretRef)].filter(x,x==true).size() == 1' namespace: description: |- Name of the [OpenBao Namespace] to authenticate to. This can be different @@ -24405,8 +24707,8 @@ spec: type: object type: object x-kubernetes-validations: - - message: exactly one of the fields in [appRole tokenSecretRef userPass] must be set - rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass)].filter(x,x==true).size() == 1' + - message: exactly one of the fields in [appRole tokenSecretRef userPass kubernetes] must be set + rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass),has(self.kubernetes)].filter(x,x==true).size() == 1' caBundle: description: |- PEM encoded CA bundle used to validate the OpenBao server certificate. If @@ -24593,8 +24895,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -25088,8 +25390,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -25270,6 +25572,11 @@ spec: - name - type type: object + disableSiteIDValidation: + description: |- + DisableSiteIDValidation permits a missing site ID for new secrets. + The provider sends 0 if no site ID is set. + type: boolean domain: description: Domain is the secret server domain. type: string @@ -25317,6 +25624,13 @@ spec: ServerURL URL to your secret server installation type: string + siteId: + description: |- + SiteID is the ID of the Secret Server site for new secrets. + PushSecret metadata can override this value for one secret. + The provider uses 1 if this field is not set. + minimum: 1 + type: integer token: description: |- Token is an access token used to authenticate to the secret server, @@ -25668,8 +25982,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -25714,8 +26028,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -25759,8 +26073,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -25921,8 +26235,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -26044,8 +26358,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -27057,8 +27371,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -27329,8 +27643,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -27649,8 +27963,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -28224,8 +28538,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -28625,8 +28939,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -29096,8 +29410,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -29476,8 +29790,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -30111,8 +30425,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -30273,8 +30587,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -30396,8 +30710,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -31217,8 +31531,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -31699,8 +32013,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -31745,8 +32059,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -31790,8 +32104,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -31952,8 +32266,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array @@ -32075,8 +32389,8 @@ spec: audiences: description: |- Audience specifies the `aud` claim for the service account token - If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity - then this audiences will be appended to the list + Some providers automatically extend the audience field based on well-known annotations for workload + identity (e.g. IRSA or GCP Workload Identity) items: type: string type: array diff --git a/apps/external-secrets/manifests/Deployment-external-secrets-cert-controller.yml b/apps/external-secrets/manifests/Deployment-external-secrets-cert-controller.yml index 502daeab..76f050e7 100644 --- a/apps/external-secrets/manifests/Deployment-external-secrets-cert-controller.yml +++ b/apps/external-secrets/manifests/Deployment-external-secrets-cert-controller.yml @@ -38,7 +38,7 @@ spec: runAsUser: 1000 seccompProfile: type: RuntimeDefault - image: ghcr.io/external-secrets/external-secrets:v2.9.0 + image: ghcr.io/external-secrets/external-secrets:v2.10.0 imagePullPolicy: IfNotPresent args: - certcontroller diff --git a/apps/external-secrets/manifests/Deployment-external-secrets-webhook.yml b/apps/external-secrets/manifests/Deployment-external-secrets-webhook.yml index 08007923..89dc2127 100644 --- a/apps/external-secrets/manifests/Deployment-external-secrets-webhook.yml +++ b/apps/external-secrets/manifests/Deployment-external-secrets-webhook.yml @@ -38,7 +38,7 @@ spec: runAsUser: 1000 seccompProfile: type: RuntimeDefault - image: ghcr.io/external-secrets/external-secrets:v2.9.0 + image: ghcr.io/external-secrets/external-secrets:v2.10.0 imagePullPolicy: IfNotPresent args: - webhook diff --git a/apps/external-secrets/manifests/Deployment-external-secrets.yml b/apps/external-secrets/manifests/Deployment-external-secrets.yml index ec0327d6..cf5783d7 100644 --- a/apps/external-secrets/manifests/Deployment-external-secrets.yml +++ b/apps/external-secrets/manifests/Deployment-external-secrets.yml @@ -38,7 +38,7 @@ spec: runAsUser: 1000 seccompProfile: type: RuntimeDefault - image: ghcr.io/external-secrets/external-secrets:v2.9.0 + image: ghcr.io/external-secrets/external-secrets:v2.10.0 imagePullPolicy: IfNotPresent args: - --concurrent=1 diff --git a/apps/external-secrets/release.yaml b/apps/external-secrets/release.yaml index 27bb28bb..adcbbf98 100644 --- a/apps/external-secrets/release.yaml +++ b/apps/external-secrets/release.yaml @@ -9,7 +9,7 @@ spec: chart: spec: chart: external-secrets - version: 2.9.0 + version: 2.10.0 sourceRef: kind: HelmRepository name: external-secrets