secrets-operator v0.10.33 → 0.11.8 (#59)
* chart_version_detector: repo가 이미 등록돼 있으면 update를 건너뛰던 버그를 고친다 repo alias가 이미 helm repo list에 있으면 add/update를 통째로 건너뛰어, 로컬에 예전에 캐시된 index.yaml을 그대로 썼다 — latest_version이 조용히 낡은 값으로 나온다(실측: secrets-operator에서 실제 최신 0.11.8 대신 0.11.4가 나왔다). repo 등록 여부와 무관하게 update는 항상 호출하도록 고친다. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * secrets-operator v0.10.33 → 0.11.8 호환성: breaking_change_check 결과 breaking=false(이 차트는 custom-values.yaml이 없어 오버라이드 충돌 자체가 불가능). CVE: infisical/kubernetes-operator 이미지를 trivy+CoverageProbe로 실측한 결과 실효 HIGH 차단이 34→10건으로 줄었다(CRITICAL은 둘 다 0, 둘 다 CoverageProbe: ok로 측정 신뢰 가능). 신규 CRD 3개 (InfisicalAuth·InfisicalConnection·InfisicalStaticSecret) 추가 — 상세는 CUSTOM-README.md. 기존 v0.10.33 디렉토리는 카탈로그 정책대로 동결 보관한다(삭제하지 않음). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * secrets-operator 자체 빌드 이미지 배포 테스트 오버라이드 추가 dev 클러스터에서 hardened-containers 자체 빌드 이미지(v0.11.8-security-hardened)로 실제 업그레이드·CRD 적용·Infisical 시크릿 동기화까지 검증할 때 쓴 오버라이드. 카탈로그 값(이 차트는 애초에 custom-values.yaml 없음)은 건드리지 않는다. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
+7
-5
@@ -63,14 +63,16 @@ def _parse_repo_from_build_readme(path: Path) -> Tuple[Optional[str], Optional[s
|
|||||||
|
|
||||||
|
|
||||||
def _ensure_repo(repo: str, url: str) -> None:
|
def _ensure_repo(repo: str, url: str) -> None:
|
||||||
|
# repo가 이미 등록돼 있어도 update는 항상 호출한다 — 등록만 하고 갱신을 건너뛰면
|
||||||
|
# 로컬에 예전에 캐시된 index.yaml을 그대로 써서 latest_version이 조용히 낡은 값으로
|
||||||
|
# 나온다(실측: secrets-operator에서 0.11.8이 나와야 할 자리에 0.11.4가 나왔다).
|
||||||
try:
|
try:
|
||||||
out = _run(["helm", "repo", "list"])
|
out = _run(["helm", "repo", "list"])
|
||||||
if repo in out:
|
if repo not in out:
|
||||||
return
|
_run(["helm", "repo", "add", repo, url])
|
||||||
except Exception:
|
except Exception:
|
||||||
pass
|
_run(["helm", "repo", "add", repo, url])
|
||||||
_run(["helm", "repo", "add", repo, url])
|
_run(["helm", "repo", "update", repo])
|
||||||
_run(["helm", "repo", "update"])
|
|
||||||
|
|
||||||
|
|
||||||
def _latest_version(repo: str, chart: str) -> Optional[str]:
|
def _latest_version(repo: str, chart: str) -> Optional[str]:
|
||||||
|
|||||||
@@ -0,0 +1,23 @@
|
|||||||
|
# Patterns to ignore when building packages.
|
||||||
|
# This supports shell glob matching, relative path matching, and
|
||||||
|
# negation (prefixed with !). Only one pattern per line.
|
||||||
|
.DS_Store
|
||||||
|
# Common VCS dirs
|
||||||
|
.git/
|
||||||
|
.gitignore
|
||||||
|
.bzr/
|
||||||
|
.bzrignore
|
||||||
|
.hg/
|
||||||
|
.hgignore
|
||||||
|
.svn/
|
||||||
|
# Common backup files
|
||||||
|
*.swp
|
||||||
|
*.bak
|
||||||
|
*.tmp
|
||||||
|
*.orig
|
||||||
|
*~
|
||||||
|
# Various IDEs
|
||||||
|
.project
|
||||||
|
.idea/
|
||||||
|
*.tmproj
|
||||||
|
.vscode/
|
||||||
@@ -0,0 +1,78 @@
|
|||||||
|
# secrets-operator 버전 갱신 가이드
|
||||||
|
|
||||||
|
## 1. git 작업 환경 구성
|
||||||
|
|
||||||
|
- DIP 카탈로그 git 다운로드
|
||||||
|
```sh
|
||||||
|
git clone https://github.com/paasup/dip-catalog.git
|
||||||
|
```
|
||||||
|
|
||||||
|
- 작업 브랜치로 체크아웃
|
||||||
|
```sh
|
||||||
|
git checkout -b update-secrets-operator/0.11.8
|
||||||
|
```
|
||||||
|
|
||||||
|
## 2. helm 차트 버전 업데이트
|
||||||
|
|
||||||
|
- BUILD-README.md, CUSTOM-README.md, custom-values.yaml을 제외한 파일 삭제
|
||||||
|
```sh
|
||||||
|
# chart 디렉토리로 이동
|
||||||
|
cd ~/dip-catalog/manifests/helm/secrets-operator/0.11.8
|
||||||
|
|
||||||
|
# 삭제할 파일 목록 확인
|
||||||
|
find . -mindepth 1 \( -name "CUSTOM-README.md" -o -name "BUILD-README.md" -o -name "custom-values.yaml" \) -prune -o -print
|
||||||
|
|
||||||
|
# 파일 삭제
|
||||||
|
find . -mindepth 1 \( -name "CUSTOM-README.md" -o -name "BUILD-README.md" -o -name "custom-values.yaml" \) -prune -o -exec rm -rf {} +
|
||||||
|
```
|
||||||
|
|
||||||
|
- secrets-operator 차트 다운로드
|
||||||
|
```sh
|
||||||
|
# manifests/helm/secrets-operator 디렉토리로 이동
|
||||||
|
cd ~/dip-catalog/manifests/helm/secrets-operator
|
||||||
|
|
||||||
|
# helm repo 추가
|
||||||
|
helm repo add infisical-helm-charts https://dl.cloudsmith.io/public/infisical/helm-charts/helm/charts/
|
||||||
|
helm repo update
|
||||||
|
|
||||||
|
# helm 차트 pull
|
||||||
|
helm pull infisical-helm-charts/secrets-operator --version="0.11.8"
|
||||||
|
|
||||||
|
# 차트 압축 해제
|
||||||
|
tar xzvf secrets-operator-0.11.8.tgz
|
||||||
|
|
||||||
|
# 압축 파일 삭제
|
||||||
|
rm secrets-operator-0.11.8.tgz
|
||||||
|
```
|
||||||
|
|
||||||
|
## 3. git push 및 tag 추가
|
||||||
|
|
||||||
|
- 갱신작업 진행 후 commit
|
||||||
|
```sh
|
||||||
|
git add .
|
||||||
|
git commit -m "update secrets-operator/0.11.8"
|
||||||
|
```
|
||||||
|
|
||||||
|
- main 브랜치에 체크아웃 후 merge
|
||||||
|
```sh
|
||||||
|
git checkout main
|
||||||
|
git merge update-secrets-operator/0.11.8
|
||||||
|
```
|
||||||
|
|
||||||
|
- git에 push 후 작업 브랜치 삭제
|
||||||
|
```sh
|
||||||
|
git push -u origin main
|
||||||
|
git branch -d update-secrets-operator/0.11.8
|
||||||
|
```
|
||||||
|
|
||||||
|
- git tag 추가 후 push
|
||||||
|
```sh
|
||||||
|
git tag secrets-operator/0.11.8
|
||||||
|
git push origin secrets-operator/0.11.8
|
||||||
|
```
|
||||||
|
|
||||||
|
## 4. 차트 버전 정보
|
||||||
|
|
||||||
|
- secrets-operator/0.11.8 (app version: 0.11.8)
|
||||||
|
- Infisical Secrets Operator (InfisicalSecret CRD 로 시크릿을 클러스터에 동기화)
|
||||||
|
- infisical-standalone 과 짝을 이루어 설치한다.
|
||||||
@@ -0,0 +1,53 @@
|
|||||||
|
# Upgrade History
|
||||||
|
|
||||||
|
## v0.10.33 → 0.11.8
|
||||||
|
### 변경 요약
|
||||||
|
- from_version: v0.10.33
|
||||||
|
- to_version: 0.11.8
|
||||||
|
- Chart `secrets-operator` v0.10.33 → 0.11.8 업데이트
|
||||||
|
- Values: +0 / -0 / ~1 / type~0
|
||||||
|
- Templates: +3 / -0
|
||||||
|
- Dependencies: +0 / -0 / ~0
|
||||||
|
|
||||||
|
### custom-values.yaml 수정 필요 항목
|
||||||
|
없음 (이 차트는 애초에 custom-values.yaml이 없다 — 차트 기본값만 씀)
|
||||||
|
|
||||||
|
### CVE 실측 (업그레이드 트리거)
|
||||||
|
이미지 `infisical/kubernetes-operator`를 trivy(+CoverageProbe 자가진단)로 직접 스캔한 결과:
|
||||||
|
|
||||||
|
| 버전 | OS | 커버리지 | 실효 HIGH(차단) |
|
||||||
|
|---|---|---|---:|
|
||||||
|
| v0.10.33 | debian 13.4 | ✅ ok | 34 |
|
||||||
|
| v0.11.8 | debian 13.6 | ✅ ok | 10 |
|
||||||
|
|
||||||
|
CRITICAL은 둘 다 0건. 34건 중 24건이 해소됨(대부분 stdlib·golang.org/x/net·x/crypto —
|
||||||
|
빌더 Go 툴체인이 올라가며 해소된 것으로 보임). 둘 다 `CoverageProbe: ok`라 이 수치는
|
||||||
|
실측이지 데이터 부재로 인한 거짓 clean이 아니다.
|
||||||
|
|
||||||
|
### 신규 CRD 3개 — `⚠️ 업그레이드 시 helm이 CRD를 자동 적용하지 않을 수 있다`
|
||||||
|
`InfisicalAuth`·`InfisicalConnection`·`InfisicalStaticSecret`가 새로 추가됐다
|
||||||
|
(`infisicalauths.secrets.infisical.com` 등). helm은 기존 릴리스 업그레이드 시 CRD를
|
||||||
|
자동으로 설치/갱신하지 않는 경우가 있다(helm 자체의 알려진 제약) — 업그레이드 후
|
||||||
|
`kubectl get crd | grep infisical`로 3개가 실제로 생겼는지 반드시 확인한다.
|
||||||
|
|
||||||
|
### 참고
|
||||||
|
- severity: warning
|
||||||
|
- breaking: false
|
||||||
|
|
||||||
|
# secrets-operator 배포 가이드
|
||||||
|
|
||||||
|
## 개요
|
||||||
|
|
||||||
|
Infisical Secrets Operator. `InfisicalSecret` CRD 를 감시해 Infisical 에 저장된 시크릿을
|
||||||
|
클러스터 Secret 으로 동기화한다. `infisical-standalone` 과 짝을 이루어 설치한다.
|
||||||
|
|
||||||
|
## custom-values
|
||||||
|
|
||||||
|
없다 — 차트 기본값을 그대로 쓴다.
|
||||||
|
|
||||||
|
## 주의사항
|
||||||
|
|
||||||
|
- 설치 순서: `infisical-standalone` 이 먼저 떠 있어야 오퍼레이터가 인증에 성공한다.
|
||||||
|
- 인증에는 Universal Auth(machine identity) 또는 Kubernetes Auth 를 쓴다. 사설 클러스터에서
|
||||||
|
Kubernetes Auth 를 등록하려면 백엔드 쪽에 `ALLOW_INTERNAL_IP_CONNECTIONS=true` 가 필요하다
|
||||||
|
(infisical-standalone 의 CUSTOM-README 참고).
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
appVersion: v0.11.8
|
||||||
|
description: A Helm chart for Infisical secrets
|
||||||
|
name: secrets-operator
|
||||||
|
type: application
|
||||||
|
version: v0.11.8
|
||||||
@@ -0,0 +1,99 @@
|
|||||||
|
# Infisical Helm Chart
|
||||||
|
|
||||||
|
This is the Infisical Secrets Operator Helm chart. Find the integration documentation [here](https://infisical.com/docs/integrations/platforms/kubernetes)
|
||||||
|
|
||||||
|
## Installation
|
||||||
|
|
||||||
|
To install the chart, run the following :
|
||||||
|
|
||||||
|
```sh
|
||||||
|
# Add the Infisical repository
|
||||||
|
helm repo add infisical 'https://dl.cloudsmith.io/public/infisical/helm-charts/helm/charts/' && helm repo update
|
||||||
|
|
||||||
|
# Install Infisical Secrets Operator (with default values)
|
||||||
|
helm upgrade --install --atomic \
|
||||||
|
-n infisical-dev --create-namespace \
|
||||||
|
infisical-secrets-operator infisical/secrets-operator
|
||||||
|
|
||||||
|
# Install Infisical Secrets Operator (with custom inline values, replace with your own values)
|
||||||
|
helm upgrade --install --atomic \
|
||||||
|
-n infisical-dev --create-namespace \
|
||||||
|
--set controllerManager.replicas=3 \
|
||||||
|
infisical-secrets-operator infisical/secrets-operator
|
||||||
|
|
||||||
|
# Install Infisical Secrets Operator (with custom values file, replace with your own values file)
|
||||||
|
helm upgrade --install --atomic \
|
||||||
|
-n infisical-dev --create-namespace \
|
||||||
|
-f custom-values.yaml \
|
||||||
|
infisical-secrets-operator infisical/secrets-operator
|
||||||
|
```
|
||||||
|
|
||||||
|
## Synchronization
|
||||||
|
|
||||||
|
To sync your secrets from Infisical (or from your own instance), create the below resources :
|
||||||
|
|
||||||
|
```sh
|
||||||
|
# Create the tokenSecretReference (replace with your own token)
|
||||||
|
kubectl create secret generic infisical-example-service-token \
|
||||||
|
--from-literal=infisicalToken="<infisical-token-here>"
|
||||||
|
|
||||||
|
# Create the InfisicalSecret
|
||||||
|
cat <<EOF | kubectl apply -f -
|
||||||
|
apiVersion: secrets.infisical.com/v1alpha1
|
||||||
|
kind: InfisicalSecret
|
||||||
|
metadata:
|
||||||
|
# Name of of this InfisicalSecret resource
|
||||||
|
name: infisicalsecret-example
|
||||||
|
spec:
|
||||||
|
# The host that should be used to pull secrets from. The default value is https://app.infisical.com/api.
|
||||||
|
hostAPI: https://app.infisical.com/api
|
||||||
|
|
||||||
|
# The Kubernetes secret the stores the Infisical token
|
||||||
|
tokenSecretReference:
|
||||||
|
# Kubernetes secret name
|
||||||
|
secretName: infisical-example-service-token
|
||||||
|
# The secret namespace
|
||||||
|
secretNamespace: default
|
||||||
|
|
||||||
|
# The Kubernetes secret that Infisical Operator will create and populate with secrets from the above project
|
||||||
|
managedSecretReference:
|
||||||
|
# The name of managed Kubernetes secret that should be created
|
||||||
|
secretName: infisical-managed-secret
|
||||||
|
# The namespace the managed secret should be installed in
|
||||||
|
secretNamespace: default
|
||||||
|
EOF
|
||||||
|
```
|
||||||
|
|
||||||
|
### Managed secrets
|
||||||
|
|
||||||
|
#### Methods
|
||||||
|
|
||||||
|
To use the above created manage secrets, you can use the below methods :
|
||||||
|
- `env`
|
||||||
|
- `envFrom`
|
||||||
|
- `volumes`
|
||||||
|
|
||||||
|
Check the [docs](https://infisical.com/docs/integrations/platforms/kubernetes#using-managed-secret-in-your-deployment) to learn more about their implementation within your k8s resources
|
||||||
|
|
||||||
|
#### Auto-reload
|
||||||
|
|
||||||
|
And if you want to [auto-reload](https://infisical.com/docs/integrations/platforms/kubernetes#auto-redeployment) your deployments, add this annotation where the managed secret is consumed :
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
annotations:
|
||||||
|
secrets.infisical.com/auto-reload: "true"
|
||||||
|
```
|
||||||
|
|
||||||
|
## Parameters
|
||||||
|
|
||||||
|
*Coming soon*
|
||||||
|
|
||||||
|
## Local development
|
||||||
|
|
||||||
|
*Coming soon*
|
||||||
|
|
||||||
|
## Upgrading
|
||||||
|
|
||||||
|
### 0.1.2
|
||||||
|
|
||||||
|
Latest stable version, no breaking changes
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
# Values file for chart testing
|
||||||
|
# CRDs are installed separately in the CI workflow
|
||||||
|
installCRDs: false
|
||||||
|
|
||||||
|
# Use latest released image for CI testing (unreleased versions don't exist on Docker Hub)
|
||||||
|
controllerManager:
|
||||||
|
manager:
|
||||||
|
image:
|
||||||
|
tag: v0.11.4
|
||||||
@@ -0,0 +1,219 @@
|
|||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
name: minimal-operator-permissions
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- configmaps
|
||||||
|
- secrets
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- update
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- pods/log
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- serviceaccounts
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- serviceaccounts/token
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- apiGroups:
|
||||||
|
- apps
|
||||||
|
resources:
|
||||||
|
- daemonsets
|
||||||
|
- deployments
|
||||||
|
- statefulsets
|
||||||
|
- replicasets
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- update
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- authentication.k8s.io
|
||||||
|
resources:
|
||||||
|
- tokenreviews
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- apiGroups:
|
||||||
|
- secrets.infisical.com
|
||||||
|
resources:
|
||||||
|
- clustergenerators
|
||||||
|
- infisicalauths
|
||||||
|
- infisicalconnections
|
||||||
|
- infisicaldynamicsecrets
|
||||||
|
- infisicalpushsecrets
|
||||||
|
- infisicalsecrets
|
||||||
|
- infisicalstaticsecrets
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- patch
|
||||||
|
- update
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- secrets.infisical.com
|
||||||
|
resources:
|
||||||
|
- infisicaldynamicsecrets/finalizers
|
||||||
|
- infisicalpushsecrets/finalizers
|
||||||
|
- infisicalsecrets/finalizers
|
||||||
|
- infisicalstaticsecrets/finalizers
|
||||||
|
verbs:
|
||||||
|
- update
|
||||||
|
- apiGroups:
|
||||||
|
- secrets.infisical.com
|
||||||
|
resources:
|
||||||
|
- infisicalauths/status
|
||||||
|
- infisicalconnections/status
|
||||||
|
- infisicaldynamicsecrets/status
|
||||||
|
- infisicalpushsecrets/status
|
||||||
|
- infisicalsecrets/status
|
||||||
|
- infisicalstaticsecrets/status
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- patch
|
||||||
|
- update
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- configmaps
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- create
|
||||||
|
- update
|
||||||
|
- patch
|
||||||
|
- delete
|
||||||
|
- apiGroups:
|
||||||
|
- coordination.k8s.io
|
||||||
|
resources:
|
||||||
|
- leases
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- create
|
||||||
|
- update
|
||||||
|
- patch
|
||||||
|
- delete
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- events
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- patch
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- authentication.k8s.io
|
||||||
|
resources:
|
||||||
|
- tokenreviews
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- apiGroups:
|
||||||
|
- authorization.k8s.io
|
||||||
|
resources:
|
||||||
|
- subjectaccessreviews
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- namespaces
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- apiGroups:
|
||||||
|
- rbac.authorization.k8s.io
|
||||||
|
resources:
|
||||||
|
- roles
|
||||||
|
- rolebindings
|
||||||
|
- clusterroles
|
||||||
|
- clusterrolebindings
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- update
|
||||||
|
- patch
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- serviceaccounts
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- update
|
||||||
|
- patch
|
||||||
|
- apiGroups:
|
||||||
|
- apps
|
||||||
|
resources:
|
||||||
|
- deployments
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- patch
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- services
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- update
|
||||||
|
- patch
|
||||||
|
- nonResourceURLs:
|
||||||
|
- /metrics
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
metadata:
|
||||||
|
name: minimal-operator-binding
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: minimal-operator-permissions
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: minimal-test-user
|
||||||
|
namespace: kube-system
|
||||||
@@ -0,0 +1,98 @@
|
|||||||
|
{{/*
|
||||||
|
Expand the name of the chart.
|
||||||
|
*/}}
|
||||||
|
{{- define "secrets-operator.name" -}}
|
||||||
|
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create a default fully qualified app name.
|
||||||
|
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
|
||||||
|
If release name contains chart name it will be used as a full name.
|
||||||
|
*/}}
|
||||||
|
{{- define "secrets-operator.fullname" -}}
|
||||||
|
{{- if .Values.fullnameOverride }}
|
||||||
|
{{- .Values.fullnameOverride | trunc 15 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- $name := default .Chart.Name .Values.nameOverride }}
|
||||||
|
{{- if contains $name .Release.Name }}
|
||||||
|
{{- .Release.Name | trunc 15 | trimSuffix "-" }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "%s-%s" .Release.Name $name | trunc 15 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create chart name and version as used by the chart label.
|
||||||
|
*/}}
|
||||||
|
{{- define "secrets-operator.chart" -}}
|
||||||
|
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Common labels
|
||||||
|
*/}}
|
||||||
|
{{- define "secrets-operator.labels" -}}
|
||||||
|
helm.sh/chart: {{ include "secrets-operator.chart" . }}
|
||||||
|
{{ include "secrets-operator.selectorLabels" . }}
|
||||||
|
{{- if .Chart.AppVersion }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
{{- end }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Selector labels
|
||||||
|
*/}}
|
||||||
|
{{- define "secrets-operator.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ include "secrets-operator.name" . }}
|
||||||
|
app.kubernetes.io/instance: {{ .Release.Name }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Create the name of the service account to use
|
||||||
|
*/}}
|
||||||
|
{{- define "secrets-operator.serviceAccountName" -}}
|
||||||
|
{{- if .Values.controllerManager.serviceAccount.name }}
|
||||||
|
{{- .Values.controllerManager.serviceAccount.name }}
|
||||||
|
{{- else }}
|
||||||
|
{{- printf "%s-controller-manager" (include "secrets-operator.fullname" .) }}
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Compute the list of scoped namespaces.
|
||||||
|
scopedNamespaces takes precedence over the deprecated scopedNamespace.
|
||||||
|
Handles both array input (--set "scopedNamespaces={ns1,ns2}") and
|
||||||
|
comma-separated string input (--set scopedNamespaces="ns1,ns2").
|
||||||
|
Returns a JSON object with a "list" key that should be parsed with fromJson.
|
||||||
|
Usage: $namespaces := (include "secrets-operator.scopedNamespaces" . | fromJson).list
|
||||||
|
*/}}
|
||||||
|
{{- define "secrets-operator.scopedNamespaces" -}}
|
||||||
|
{{- if .Values.scopedNamespaces -}}
|
||||||
|
{{- if kindIs "string" .Values.scopedNamespaces -}}
|
||||||
|
{{- /* Handle comma-separated string input */ -}}
|
||||||
|
{"list": {{ splitList "," .Values.scopedNamespaces | toJson }}}
|
||||||
|
{{- else -}}
|
||||||
|
{{- /* Handle array input */ -}}
|
||||||
|
{"list": {{ .Values.scopedNamespaces | toJson }}}
|
||||||
|
{{- end -}}
|
||||||
|
{{- else if .Values.scopedNamespace -}}
|
||||||
|
{"list": {{ list .Values.scopedNamespace | toJson }}}
|
||||||
|
{{- else -}}
|
||||||
|
{"list": []}
|
||||||
|
{{- end -}}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{/*
|
||||||
|
Check if we're using the deprecated scopedNamespace field.
|
||||||
|
Returns "true" or "false" as a string.
|
||||||
|
*/}}
|
||||||
|
{{- define "secrets-operator.usingDeprecatedScopedNamespace" -}}
|
||||||
|
{{- if and (not .Values.scopedNamespaces) .Values.scopedNamespace -}}
|
||||||
|
true
|
||||||
|
{{- else -}}
|
||||||
|
false
|
||||||
|
{{- end -}}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,104 @@
|
|||||||
|
{{- if .Values.installCRDs }}
|
||||||
|
apiVersion: apiextensions.k8s.io/v1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: clustergenerators.secrets.infisical.com
|
||||||
|
annotations:
|
||||||
|
controller-gen.kubebuilder.io/version: v0.18.0
|
||||||
|
labels:
|
||||||
|
{{- include "secrets-operator.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
group: secrets.infisical.com
|
||||||
|
names:
|
||||||
|
kind: ClusterGenerator
|
||||||
|
listKind: ClusterGeneratorList
|
||||||
|
plural: clustergenerators
|
||||||
|
singular: clustergenerator
|
||||||
|
scope: Cluster
|
||||||
|
versions:
|
||||||
|
- name: v1alpha1
|
||||||
|
schema:
|
||||||
|
openAPIV3Schema:
|
||||||
|
description: ClusterGenerator represents a cluster-wide generator
|
||||||
|
properties:
|
||||||
|
apiVersion:
|
||||||
|
description: |-
|
||||||
|
APIVersion defines the versioned schema of this representation of an object.
|
||||||
|
Servers should convert recognized schemas to the latest internal value, and
|
||||||
|
may reject unrecognized values.
|
||||||
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
||||||
|
type: string
|
||||||
|
kind:
|
||||||
|
description: |-
|
||||||
|
Kind is a string value representing the REST resource this object represents.
|
||||||
|
Servers may infer this from the endpoint the client submits requests to.
|
||||||
|
Cannot be updated.
|
||||||
|
In CamelCase.
|
||||||
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
||||||
|
type: string
|
||||||
|
metadata:
|
||||||
|
type: object
|
||||||
|
spec:
|
||||||
|
properties:
|
||||||
|
generator:
|
||||||
|
description: Generator the spec for this generator, must match the kind.
|
||||||
|
properties:
|
||||||
|
passwordSpec:
|
||||||
|
description: PasswordSpec controls the behavior of the password
|
||||||
|
generator.
|
||||||
|
properties:
|
||||||
|
allowRepeat:
|
||||||
|
default: false
|
||||||
|
description: set allowRepeat to true to allow repeating characters.
|
||||||
|
type: boolean
|
||||||
|
digits:
|
||||||
|
description: |-
|
||||||
|
digits specifies the number of digits in the generated
|
||||||
|
password. If omitted it defaults to 25% of the length of the password
|
||||||
|
type: integer
|
||||||
|
length:
|
||||||
|
default: 24
|
||||||
|
description: |-
|
||||||
|
Length of the password to be generated.
|
||||||
|
Defaults to 24
|
||||||
|
type: integer
|
||||||
|
noUpper:
|
||||||
|
default: false
|
||||||
|
description: Set noUpper to disable uppercase characters
|
||||||
|
type: boolean
|
||||||
|
symbolCharacters:
|
||||||
|
description: |-
|
||||||
|
symbolCharacters specifies the special characters that should be used
|
||||||
|
in the generated password.
|
||||||
|
type: string
|
||||||
|
symbols:
|
||||||
|
description: |-
|
||||||
|
symbols specifies the number of symbol characters in the generated
|
||||||
|
password. If omitted it defaults to 25% of the length of the password
|
||||||
|
type: integer
|
||||||
|
type: object
|
||||||
|
uuidSpec:
|
||||||
|
description: UUIDSpec controls the behavior of the uuid generator.
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
kind:
|
||||||
|
description: Kind the kind of this generator.
|
||||||
|
enum:
|
||||||
|
- Password
|
||||||
|
- UUID
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- kind
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
served: true
|
||||||
|
storage: true
|
||||||
|
subresources:
|
||||||
|
status: {}
|
||||||
|
status:
|
||||||
|
acceptedNames:
|
||||||
|
kind: ""
|
||||||
|
plural: ""
|
||||||
|
conditions: []
|
||||||
|
storedVersions: []
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,90 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ include "secrets-operator.fullname" . }}-controller-manager
|
||||||
|
labels:
|
||||||
|
control-plane: controller-manager
|
||||||
|
{{- include "secrets-operator.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.controllerManager.replicas }}
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
control-plane: controller-manager
|
||||||
|
{{- include "secrets-operator.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
control-plane: controller-manager
|
||||||
|
{{- include "secrets-operator.selectorLabels" . | nindent 8 }}
|
||||||
|
annotations:
|
||||||
|
kubectl.kubernetes.io/default-container: manager
|
||||||
|
spec:
|
||||||
|
{{- with .Values.controllerManager.extraInitContainers }}
|
||||||
|
initContainers:
|
||||||
|
{{- tpl (toYaml . | nindent 8) $ }}
|
||||||
|
{{- end }}
|
||||||
|
containers:
|
||||||
|
- args:
|
||||||
|
{{- toYaml .Values.controllerManager.manager.args | nindent 8 }}
|
||||||
|
{{- $namespaces := (include "secrets-operator.scopedNamespaces" . | fromJson).list }}
|
||||||
|
{{- if and $namespaces .Values.scopedRBAC }}
|
||||||
|
- --namespaces={{ join "," $namespaces }}
|
||||||
|
{{- if eq (include "secrets-operator.usingDeprecatedScopedNamespace" .) "true" }}
|
||||||
|
- --deprecated-scoped-namespace-warning
|
||||||
|
{{- end }}
|
||||||
|
{{- end }}
|
||||||
|
command:
|
||||||
|
- /manager
|
||||||
|
env:
|
||||||
|
- name: KUBERNETES_CLUSTER_DOMAIN
|
||||||
|
value: {{ quote .Values.kubernetesClusterDomain }}
|
||||||
|
- name: INFISICAL_HOST_API
|
||||||
|
value: {{ quote .Values.hostAPI }}
|
||||||
|
- name: INFISICAL_LOG_WRITER
|
||||||
|
value: {{ quote .Values.logger.writer }}
|
||||||
|
{{- with .Values.controllerManager.manager.extraEnv }}
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
image: {{ .Values.controllerManager.manager.image.repository }}:{{ .Values.controllerManager.manager.image.tag
|
||||||
|
| default .Chart.AppVersion }}
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /healthz
|
||||||
|
port: 8081
|
||||||
|
initialDelaySeconds: 15
|
||||||
|
periodSeconds: 20
|
||||||
|
name: manager
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: /readyz
|
||||||
|
port: 8081
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 10
|
||||||
|
resources: {{- toYaml .Values.controllerManager.manager.resources | nindent 10
|
||||||
|
}}
|
||||||
|
securityContext: {{- toYaml .Values.controllerManager.manager.containerSecurityContext
|
||||||
|
| nindent 10 }}
|
||||||
|
{{- with .Values.controllerManager.manager.extraVolumeMounts }}
|
||||||
|
volumeMounts:
|
||||||
|
{{- toYaml . | nindent 10 }}
|
||||||
|
{{- end }}
|
||||||
|
securityContext: {{- toYaml .Values.controllerManager.podSecurityContext | nindent
|
||||||
|
8 }}
|
||||||
|
serviceAccountName: {{ include "secrets-operator.serviceAccountName" . }}
|
||||||
|
{{- with .Values.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.controllerManager.extraVolumes }}
|
||||||
|
volumes:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
terminationGracePeriodSeconds: 10
|
||||||
|
nodeSelector: {{ toYaml .Values.controllerManager.nodeSelector | nindent 8 }}
|
||||||
|
tolerations: {{ toYaml .Values.controllerManager.tolerations | nindent 8 }}
|
||||||
|
{{- with .Values.controllerManager.affinity }}
|
||||||
|
affinity: {{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
{{- with .Values.controllerManager.topologySpreadConstraints }}
|
||||||
|
topologySpreadConstraints: {{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,373 @@
|
|||||||
|
{{- if .Values.installCRDs }}
|
||||||
|
apiVersion: apiextensions.k8s.io/v1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: infisicalauths.secrets.infisical.com
|
||||||
|
annotations:
|
||||||
|
controller-gen.kubebuilder.io/version: v0.18.0
|
||||||
|
labels:
|
||||||
|
{{- include "secrets-operator.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
group: secrets.infisical.com
|
||||||
|
names:
|
||||||
|
kind: InfisicalAuth
|
||||||
|
listKind: InfisicalAuthList
|
||||||
|
plural: infisicalauths
|
||||||
|
singular: infisicalauth
|
||||||
|
scope: Namespaced
|
||||||
|
versions:
|
||||||
|
- additionalPrinterColumns:
|
||||||
|
- jsonPath: .spec.infisicalConnectionRef.name
|
||||||
|
name: Connection
|
||||||
|
type: string
|
||||||
|
- jsonPath: .spec.method
|
||||||
|
name: Method
|
||||||
|
type: string
|
||||||
|
- jsonPath: .metadata.creationTimestamp
|
||||||
|
name: Age
|
||||||
|
type: date
|
||||||
|
- jsonPath: .status.conditions[?(@.type=="secrets.infisical.com/IsReady")].status
|
||||||
|
name: Ready
|
||||||
|
type: string
|
||||||
|
name: v1beta1
|
||||||
|
schema:
|
||||||
|
openAPIV3Schema:
|
||||||
|
description: InfisicalAuth is the Schema for the InfisicalAuth API.
|
||||||
|
properties:
|
||||||
|
apiVersion:
|
||||||
|
description: |-
|
||||||
|
APIVersion defines the versioned schema of this representation of an object.
|
||||||
|
Servers should convert recognized schemas to the latest internal value, and
|
||||||
|
may reject unrecognized values.
|
||||||
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
||||||
|
type: string
|
||||||
|
kind:
|
||||||
|
description: |-
|
||||||
|
Kind is a string value representing the REST resource this object represents.
|
||||||
|
Servers may infer this from the endpoint the client submits requests to.
|
||||||
|
Cannot be updated.
|
||||||
|
In CamelCase.
|
||||||
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
||||||
|
type: string
|
||||||
|
metadata:
|
||||||
|
type: object
|
||||||
|
spec:
|
||||||
|
properties:
|
||||||
|
awsIam:
|
||||||
|
properties:
|
||||||
|
identityIdRef:
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
description: The name of the secret property with the value
|
||||||
|
type: string
|
||||||
|
name:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
namespace:
|
||||||
|
description: The namespace where the Kubernetes Secret is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- name
|
||||||
|
- namespace
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- identityIdRef
|
||||||
|
type: object
|
||||||
|
azure:
|
||||||
|
properties:
|
||||||
|
identityIdRef:
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
description: The name of the secret property with the value
|
||||||
|
type: string
|
||||||
|
name:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
namespace:
|
||||||
|
description: The namespace where the Kubernetes Secret is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- name
|
||||||
|
- namespace
|
||||||
|
type: object
|
||||||
|
resource:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- identityIdRef
|
||||||
|
type: object
|
||||||
|
gcpIam:
|
||||||
|
properties:
|
||||||
|
identityIdRef:
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
description: The name of the secret property with the value
|
||||||
|
type: string
|
||||||
|
name:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
namespace:
|
||||||
|
description: The namespace where the Kubernetes Secret is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- name
|
||||||
|
- namespace
|
||||||
|
type: object
|
||||||
|
serviceAccountKeyFilePath:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- identityIdRef
|
||||||
|
- serviceAccountKeyFilePath
|
||||||
|
type: object
|
||||||
|
gcpIdToken:
|
||||||
|
properties:
|
||||||
|
identityIdRef:
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
description: The name of the secret property with the value
|
||||||
|
type: string
|
||||||
|
name:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
namespace:
|
||||||
|
description: The namespace where the Kubernetes Secret is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- name
|
||||||
|
- namespace
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- identityIdRef
|
||||||
|
type: object
|
||||||
|
infisicalConnectionRef:
|
||||||
|
properties:
|
||||||
|
name:
|
||||||
|
type: string
|
||||||
|
namespace:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- name
|
||||||
|
- namespace
|
||||||
|
type: object
|
||||||
|
kubernetes:
|
||||||
|
properties:
|
||||||
|
identityIdRef:
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
description: The name of the secret property with the value
|
||||||
|
type: string
|
||||||
|
name:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
namespace:
|
||||||
|
description: The namespace where the Kubernetes Secret is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- name
|
||||||
|
- namespace
|
||||||
|
type: object
|
||||||
|
serviceAccountRef:
|
||||||
|
properties:
|
||||||
|
name:
|
||||||
|
type: string
|
||||||
|
namespace:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- name
|
||||||
|
- namespace
|
||||||
|
type: object
|
||||||
|
serviceAccountTokenAudiences:
|
||||||
|
description: The audiences to use for the service account token.
|
||||||
|
This is only relevant if `autoCreateServiceAccountToken` is true.
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- identityIdRef
|
||||||
|
- serviceAccountRef
|
||||||
|
type: object
|
||||||
|
ldap:
|
||||||
|
properties:
|
||||||
|
identityIdRef:
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
description: The name of the secret property with the value
|
||||||
|
type: string
|
||||||
|
name:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
namespace:
|
||||||
|
description: The namespace where the Kubernetes Secret is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- name
|
||||||
|
- namespace
|
||||||
|
type: object
|
||||||
|
passwordRef:
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
description: The name of the secret property with the value
|
||||||
|
type: string
|
||||||
|
name:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
namespace:
|
||||||
|
description: The namespace where the Kubernetes Secret is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- name
|
||||||
|
- namespace
|
||||||
|
type: object
|
||||||
|
usernameRef:
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
description: The name of the secret property with the value
|
||||||
|
type: string
|
||||||
|
name:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
namespace:
|
||||||
|
description: The namespace where the Kubernetes Secret is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- name
|
||||||
|
- namespace
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- identityIdRef
|
||||||
|
- passwordRef
|
||||||
|
- usernameRef
|
||||||
|
type: object
|
||||||
|
method:
|
||||||
|
enum:
|
||||||
|
- universal
|
||||||
|
- kubernetes
|
||||||
|
- aws-iam
|
||||||
|
- azure
|
||||||
|
- gcp-id-token
|
||||||
|
- gcp-iam
|
||||||
|
- ldap
|
||||||
|
type: string
|
||||||
|
universal:
|
||||||
|
properties:
|
||||||
|
clientIdRef:
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
description: The name of the secret property with the value
|
||||||
|
type: string
|
||||||
|
name:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
namespace:
|
||||||
|
description: The namespace where the Kubernetes Secret is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- name
|
||||||
|
- namespace
|
||||||
|
type: object
|
||||||
|
clientSecretRef:
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
description: The name of the secret property with the value
|
||||||
|
type: string
|
||||||
|
name:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
namespace:
|
||||||
|
description: The namespace where the Kubernetes Secret is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- name
|
||||||
|
- namespace
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- clientIdRef
|
||||||
|
- clientSecretRef
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- infisicalConnectionRef
|
||||||
|
- method
|
||||||
|
type: object
|
||||||
|
status:
|
||||||
|
description: InfisicalAuthStatus defines the observed state of InfisicalAuth
|
||||||
|
properties:
|
||||||
|
conditions:
|
||||||
|
items:
|
||||||
|
description: Condition contains details for one aspect of the current
|
||||||
|
state of this API Resource.
|
||||||
|
properties:
|
||||||
|
lastTransitionTime:
|
||||||
|
description: |-
|
||||||
|
lastTransitionTime is the last time the condition transitioned from one status to another.
|
||||||
|
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
|
||||||
|
format: date-time
|
||||||
|
type: string
|
||||||
|
message:
|
||||||
|
description: |-
|
||||||
|
message is a human readable message indicating details about the transition.
|
||||||
|
This may be an empty string.
|
||||||
|
maxLength: 32768
|
||||||
|
type: string
|
||||||
|
observedGeneration:
|
||||||
|
description: |-
|
||||||
|
observedGeneration represents the .metadata.generation that the condition was set based upon.
|
||||||
|
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
|
||||||
|
with respect to the current state of the instance.
|
||||||
|
format: int64
|
||||||
|
minimum: 0
|
||||||
|
type: integer
|
||||||
|
reason:
|
||||||
|
description: |-
|
||||||
|
reason contains a programmatic identifier indicating the reason for the condition's last transition.
|
||||||
|
Producers of specific condition types may define expected values and meanings for this field,
|
||||||
|
and whether the values are considered a guaranteed API.
|
||||||
|
The value should be a CamelCase string.
|
||||||
|
This field may not be empty.
|
||||||
|
maxLength: 1024
|
||||||
|
minLength: 1
|
||||||
|
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
|
||||||
|
type: string
|
||||||
|
status:
|
||||||
|
description: status of the condition, one of True, False, Unknown.
|
||||||
|
enum:
|
||||||
|
- "True"
|
||||||
|
- "False"
|
||||||
|
- Unknown
|
||||||
|
type: string
|
||||||
|
type:
|
||||||
|
description: type of condition in CamelCase or in foo.example.com/CamelCase.
|
||||||
|
maxLength: 316
|
||||||
|
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- lastTransitionTime
|
||||||
|
- message
|
||||||
|
- reason
|
||||||
|
- status
|
||||||
|
- type
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- conditions
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
served: true
|
||||||
|
storage: true
|
||||||
|
subresources:
|
||||||
|
status: {}
|
||||||
|
status:
|
||||||
|
acceptedNames:
|
||||||
|
kind: ""
|
||||||
|
plural: ""
|
||||||
|
conditions: []
|
||||||
|
storedVersions: []
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,151 @@
|
|||||||
|
{{- if .Values.installCRDs }}
|
||||||
|
apiVersion: apiextensions.k8s.io/v1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: infisicalconnections.secrets.infisical.com
|
||||||
|
annotations:
|
||||||
|
controller-gen.kubebuilder.io/version: v0.18.0
|
||||||
|
labels:
|
||||||
|
{{- include "secrets-operator.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
group: secrets.infisical.com
|
||||||
|
names:
|
||||||
|
kind: InfisicalConnection
|
||||||
|
listKind: InfisicalConnectionList
|
||||||
|
plural: infisicalconnections
|
||||||
|
singular: infisicalconnection
|
||||||
|
scope: Namespaced
|
||||||
|
versions:
|
||||||
|
- additionalPrinterColumns:
|
||||||
|
- jsonPath: .metadata.creationTimestamp
|
||||||
|
name: Age
|
||||||
|
type: date
|
||||||
|
- jsonPath: .spec.address
|
||||||
|
name: Address
|
||||||
|
type: string
|
||||||
|
- jsonPath: .status.conditions[?(@.type=="secrets.infisical.com/IsReady")].status
|
||||||
|
name: Ready
|
||||||
|
type: string
|
||||||
|
name: v1beta1
|
||||||
|
schema:
|
||||||
|
openAPIV3Schema:
|
||||||
|
description: InfisicalConnection is the Schema for the infisicalconnection API.
|
||||||
|
properties:
|
||||||
|
apiVersion:
|
||||||
|
description: |-
|
||||||
|
APIVersion defines the versioned schema of this representation of an object.
|
||||||
|
Servers should convert recognized schemas to the latest internal value, and
|
||||||
|
may reject unrecognized values.
|
||||||
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
||||||
|
type: string
|
||||||
|
kind:
|
||||||
|
description: |-
|
||||||
|
Kind is a string value representing the REST resource this object represents.
|
||||||
|
Servers may infer this from the endpoint the client submits requests to.
|
||||||
|
Cannot be updated.
|
||||||
|
In CamelCase.
|
||||||
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
||||||
|
type: string
|
||||||
|
metadata:
|
||||||
|
type: object
|
||||||
|
spec:
|
||||||
|
description: InfisicalConnectionSpec defines how the operator connects to
|
||||||
|
a Infisical instance
|
||||||
|
properties:
|
||||||
|
address:
|
||||||
|
type: string
|
||||||
|
tls:
|
||||||
|
properties:
|
||||||
|
caCertificate:
|
||||||
|
description: Reference to secret containing CA cert
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
description: The name of the secret property with the value
|
||||||
|
type: string
|
||||||
|
name:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
namespace:
|
||||||
|
description: The namespace where the Kubernetes Secret is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- name
|
||||||
|
- namespace
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
status:
|
||||||
|
description: InfisicalConnectionStatus defines the observed state of InfisicalConnection
|
||||||
|
properties:
|
||||||
|
conditions:
|
||||||
|
items:
|
||||||
|
description: Condition contains details for one aspect of the current
|
||||||
|
state of this API Resource.
|
||||||
|
properties:
|
||||||
|
lastTransitionTime:
|
||||||
|
description: |-
|
||||||
|
lastTransitionTime is the last time the condition transitioned from one status to another.
|
||||||
|
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
|
||||||
|
format: date-time
|
||||||
|
type: string
|
||||||
|
message:
|
||||||
|
description: |-
|
||||||
|
message is a human readable message indicating details about the transition.
|
||||||
|
This may be an empty string.
|
||||||
|
maxLength: 32768
|
||||||
|
type: string
|
||||||
|
observedGeneration:
|
||||||
|
description: |-
|
||||||
|
observedGeneration represents the .metadata.generation that the condition was set based upon.
|
||||||
|
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
|
||||||
|
with respect to the current state of the instance.
|
||||||
|
format: int64
|
||||||
|
minimum: 0
|
||||||
|
type: integer
|
||||||
|
reason:
|
||||||
|
description: |-
|
||||||
|
reason contains a programmatic identifier indicating the reason for the condition's last transition.
|
||||||
|
Producers of specific condition types may define expected values and meanings for this field,
|
||||||
|
and whether the values are considered a guaranteed API.
|
||||||
|
The value should be a CamelCase string.
|
||||||
|
This field may not be empty.
|
||||||
|
maxLength: 1024
|
||||||
|
minLength: 1
|
||||||
|
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
|
||||||
|
type: string
|
||||||
|
status:
|
||||||
|
description: status of the condition, one of True, False, Unknown.
|
||||||
|
enum:
|
||||||
|
- "True"
|
||||||
|
- "False"
|
||||||
|
- Unknown
|
||||||
|
type: string
|
||||||
|
type:
|
||||||
|
description: type of condition in CamelCase or in foo.example.com/CamelCase.
|
||||||
|
maxLength: 316
|
||||||
|
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- lastTransitionTime
|
||||||
|
- message
|
||||||
|
- reason
|
||||||
|
- status
|
||||||
|
- type
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- conditions
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
served: true
|
||||||
|
storage: true
|
||||||
|
subresources:
|
||||||
|
status: {}
|
||||||
|
status:
|
||||||
|
acceptedNames:
|
||||||
|
kind: ""
|
||||||
|
plural: ""
|
||||||
|
conditions: []
|
||||||
|
storedVersions: []
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,356 @@
|
|||||||
|
{{- if .Values.installCRDs }}
|
||||||
|
apiVersion: apiextensions.k8s.io/v1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: infisicaldynamicsecrets.secrets.infisical.com
|
||||||
|
annotations:
|
||||||
|
controller-gen.kubebuilder.io/version: v0.18.0
|
||||||
|
labels:
|
||||||
|
{{- include "secrets-operator.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
group: secrets.infisical.com
|
||||||
|
names:
|
||||||
|
kind: InfisicalDynamicSecret
|
||||||
|
listKind: InfisicalDynamicSecretList
|
||||||
|
plural: infisicaldynamicsecrets
|
||||||
|
singular: infisicaldynamicsecret
|
||||||
|
scope: Namespaced
|
||||||
|
versions:
|
||||||
|
- name: v1alpha1
|
||||||
|
schema:
|
||||||
|
openAPIV3Schema:
|
||||||
|
description: InfisicalDynamicSecret is the Schema for the infisicaldynamicsecrets
|
||||||
|
API.
|
||||||
|
properties:
|
||||||
|
apiVersion:
|
||||||
|
description: |-
|
||||||
|
APIVersion defines the versioned schema of this representation of an object.
|
||||||
|
Servers should convert recognized schemas to the latest internal value, and
|
||||||
|
may reject unrecognized values.
|
||||||
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
||||||
|
type: string
|
||||||
|
kind:
|
||||||
|
description: |-
|
||||||
|
Kind is a string value representing the REST resource this object represents.
|
||||||
|
Servers may infer this from the endpoint the client submits requests to.
|
||||||
|
Cannot be updated.
|
||||||
|
In CamelCase.
|
||||||
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
||||||
|
type: string
|
||||||
|
metadata:
|
||||||
|
type: object
|
||||||
|
spec:
|
||||||
|
description: InfisicalDynamicSecretSpec defines the desired state of InfisicalDynamicSecret.
|
||||||
|
properties:
|
||||||
|
authentication:
|
||||||
|
properties:
|
||||||
|
awsIamAuth:
|
||||||
|
properties:
|
||||||
|
identityId:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- identityId
|
||||||
|
type: object
|
||||||
|
azureAuth:
|
||||||
|
properties:
|
||||||
|
identityId:
|
||||||
|
type: string
|
||||||
|
resource:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- identityId
|
||||||
|
type: object
|
||||||
|
gcpIamAuth:
|
||||||
|
properties:
|
||||||
|
identityId:
|
||||||
|
type: string
|
||||||
|
serviceAccountKeyFilePath:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- identityId
|
||||||
|
- serviceAccountKeyFilePath
|
||||||
|
type: object
|
||||||
|
gcpIdTokenAuth:
|
||||||
|
properties:
|
||||||
|
identityId:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- identityId
|
||||||
|
type: object
|
||||||
|
kubernetesAuth:
|
||||||
|
properties:
|
||||||
|
autoCreateServiceAccountToken:
|
||||||
|
description: |-
|
||||||
|
Optionally automatically create a service account token for the configured service account.
|
||||||
|
If this is set to `true`, the operator will automatically create a service account token for the configured service account. This field is recommended in most cases.
|
||||||
|
type: boolean
|
||||||
|
identityId:
|
||||||
|
type: string
|
||||||
|
serviceAccountRef:
|
||||||
|
properties:
|
||||||
|
name:
|
||||||
|
type: string
|
||||||
|
namespace:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- name
|
||||||
|
- namespace
|
||||||
|
type: object
|
||||||
|
serviceAccountTokenAudiences:
|
||||||
|
description: The audiences to use for the service account token.
|
||||||
|
This is only relevant if `autoCreateServiceAccountToken` is
|
||||||
|
true.
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- identityId
|
||||||
|
- serviceAccountRef
|
||||||
|
type: object
|
||||||
|
ldapAuth:
|
||||||
|
properties:
|
||||||
|
credentialsRef:
|
||||||
|
properties:
|
||||||
|
secretName:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
secretNamespace:
|
||||||
|
description: The name space where the Kubernetes Secret
|
||||||
|
is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- secretName
|
||||||
|
- secretNamespace
|
||||||
|
type: object
|
||||||
|
identityId:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- credentialsRef
|
||||||
|
- identityId
|
||||||
|
type: object
|
||||||
|
universalAuth:
|
||||||
|
properties:
|
||||||
|
credentialsRef:
|
||||||
|
properties:
|
||||||
|
secretName:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
secretNamespace:
|
||||||
|
description: The name space where the Kubernetes Secret
|
||||||
|
is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- secretName
|
||||||
|
- secretNamespace
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- credentialsRef
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
dynamicSecret:
|
||||||
|
properties:
|
||||||
|
environmentSlug:
|
||||||
|
type: string
|
||||||
|
projectId:
|
||||||
|
type: string
|
||||||
|
projectSlug:
|
||||||
|
type: string
|
||||||
|
secretName:
|
||||||
|
type: string
|
||||||
|
secretsPath:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- environmentSlug
|
||||||
|
- secretName
|
||||||
|
- secretsPath
|
||||||
|
type: object
|
||||||
|
hostAPI:
|
||||||
|
type: string
|
||||||
|
leaseRevocationPolicy:
|
||||||
|
type: string
|
||||||
|
leaseTTL:
|
||||||
|
type: string
|
||||||
|
managedSecretReference:
|
||||||
|
properties:
|
||||||
|
creationPolicy:
|
||||||
|
default: Orphan
|
||||||
|
description: |-
|
||||||
|
The Kubernetes Secret creation policy.
|
||||||
|
Enum with values: 'Owner', 'Orphan'.
|
||||||
|
Owner creates the secret and sets .metadata.ownerReferences of the InfisicalSecret CRD that created it.
|
||||||
|
Orphan will not set the secret owner. This will result in the secret being orphaned and not deleted when the resource is deleted.
|
||||||
|
type: string
|
||||||
|
secretName:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
secretNamespace:
|
||||||
|
description: The name space where the Kubernetes Secret is located
|
||||||
|
type: string
|
||||||
|
secretType:
|
||||||
|
default: Opaque
|
||||||
|
description: 'The Kubernetes Secret type (experimental feature).
|
||||||
|
More info: https://kubernetes.io/docs/concepts/configuration/secret/#secret-types'
|
||||||
|
type: string
|
||||||
|
template:
|
||||||
|
description: The template to transform the secret data
|
||||||
|
properties:
|
||||||
|
data:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
description: The template key values
|
||||||
|
type: object
|
||||||
|
includeAllSecrets:
|
||||||
|
description: |-
|
||||||
|
This injects all retrieved secrets into the top level of your template.
|
||||||
|
Secrets defined in the template will take precedence over the injected ones.
|
||||||
|
type: boolean
|
||||||
|
metadata:
|
||||||
|
description: |-
|
||||||
|
Custom metadata (labels/annotations) for the managed secret.
|
||||||
|
When specified, these values are used instead of copying metadata from the InfisicalSecret CR.
|
||||||
|
properties:
|
||||||
|
annotations:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
description: Custom annotations to apply to the managed
|
||||||
|
secret
|
||||||
|
type: object
|
||||||
|
labels:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
description: Custom labels to apply to the managed secret
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- secretName
|
||||||
|
- secretNamespace
|
||||||
|
type: object
|
||||||
|
tls:
|
||||||
|
properties:
|
||||||
|
caRef:
|
||||||
|
description: Reference to secret containing CA cert
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
description: The name of the secret property with the CA certificate
|
||||||
|
value
|
||||||
|
type: string
|
||||||
|
secretName:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
secretNamespace:
|
||||||
|
description: The namespace where the Kubernetes Secret is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- secretName
|
||||||
|
- secretNamespace
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- authentication
|
||||||
|
- dynamicSecret
|
||||||
|
- leaseRevocationPolicy
|
||||||
|
- leaseTTL
|
||||||
|
- managedSecretReference
|
||||||
|
type: object
|
||||||
|
status:
|
||||||
|
description: InfisicalDynamicSecretStatus defines the observed state of
|
||||||
|
InfisicalDynamicSecret.
|
||||||
|
properties:
|
||||||
|
conditions:
|
||||||
|
items:
|
||||||
|
description: Condition contains details for one aspect of the current
|
||||||
|
state of this API Resource.
|
||||||
|
properties:
|
||||||
|
lastTransitionTime:
|
||||||
|
description: |-
|
||||||
|
lastTransitionTime is the last time the condition transitioned from one status to another.
|
||||||
|
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
|
||||||
|
format: date-time
|
||||||
|
type: string
|
||||||
|
message:
|
||||||
|
description: |-
|
||||||
|
message is a human readable message indicating details about the transition.
|
||||||
|
This may be an empty string.
|
||||||
|
maxLength: 32768
|
||||||
|
type: string
|
||||||
|
observedGeneration:
|
||||||
|
description: |-
|
||||||
|
observedGeneration represents the .metadata.generation that the condition was set based upon.
|
||||||
|
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
|
||||||
|
with respect to the current state of the instance.
|
||||||
|
format: int64
|
||||||
|
minimum: 0
|
||||||
|
type: integer
|
||||||
|
reason:
|
||||||
|
description: |-
|
||||||
|
reason contains a programmatic identifier indicating the reason for the condition's last transition.
|
||||||
|
Producers of specific condition types may define expected values and meanings for this field,
|
||||||
|
and whether the values are considered a guaranteed API.
|
||||||
|
The value should be a CamelCase string.
|
||||||
|
This field may not be empty.
|
||||||
|
maxLength: 1024
|
||||||
|
minLength: 1
|
||||||
|
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
|
||||||
|
type: string
|
||||||
|
status:
|
||||||
|
description: status of the condition, one of True, False, Unknown.
|
||||||
|
enum:
|
||||||
|
- "True"
|
||||||
|
- "False"
|
||||||
|
- Unknown
|
||||||
|
type: string
|
||||||
|
type:
|
||||||
|
description: type of condition in CamelCase or in foo.example.com/CamelCase.
|
||||||
|
maxLength: 316
|
||||||
|
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- lastTransitionTime
|
||||||
|
- message
|
||||||
|
- reason
|
||||||
|
- status
|
||||||
|
- type
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
dynamicSecretId:
|
||||||
|
type: string
|
||||||
|
lease:
|
||||||
|
properties:
|
||||||
|
creationTimestamp:
|
||||||
|
format: date-time
|
||||||
|
type: string
|
||||||
|
expiresAt:
|
||||||
|
format: date-time
|
||||||
|
type: string
|
||||||
|
id:
|
||||||
|
type: string
|
||||||
|
version:
|
||||||
|
format: int64
|
||||||
|
type: integer
|
||||||
|
required:
|
||||||
|
- creationTimestamp
|
||||||
|
- expiresAt
|
||||||
|
- id
|
||||||
|
- version
|
||||||
|
type: object
|
||||||
|
maxTTL:
|
||||||
|
description: The MaxTTL can be null, if it's null, there's no max TTL
|
||||||
|
and we should never have to renew.
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- conditions
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
served: true
|
||||||
|
storage: true
|
||||||
|
subresources:
|
||||||
|
status: {}
|
||||||
|
status:
|
||||||
|
acceptedNames:
|
||||||
|
kind: ""
|
||||||
|
plural: ""
|
||||||
|
conditions: []
|
||||||
|
storedVersions: []
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,351 @@
|
|||||||
|
{{- if .Values.installCRDs }}
|
||||||
|
apiVersion: apiextensions.k8s.io/v1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: infisicalpushsecrets.secrets.infisical.com
|
||||||
|
annotations:
|
||||||
|
controller-gen.kubebuilder.io/version: v0.18.0
|
||||||
|
labels:
|
||||||
|
{{- include "secrets-operator.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
group: secrets.infisical.com
|
||||||
|
names:
|
||||||
|
kind: InfisicalPushSecret
|
||||||
|
listKind: InfisicalPushSecretList
|
||||||
|
plural: infisicalpushsecrets
|
||||||
|
singular: infisicalpushsecret
|
||||||
|
scope: Namespaced
|
||||||
|
versions:
|
||||||
|
- name: v1alpha1
|
||||||
|
schema:
|
||||||
|
openAPIV3Schema:
|
||||||
|
description: InfisicalPushSecret is the Schema for the infisicalpushsecrets
|
||||||
|
API
|
||||||
|
properties:
|
||||||
|
apiVersion:
|
||||||
|
description: |-
|
||||||
|
APIVersion defines the versioned schema of this representation of an object.
|
||||||
|
Servers should convert recognized schemas to the latest internal value, and
|
||||||
|
may reject unrecognized values.
|
||||||
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
||||||
|
type: string
|
||||||
|
kind:
|
||||||
|
description: |-
|
||||||
|
Kind is a string value representing the REST resource this object represents.
|
||||||
|
Servers may infer this from the endpoint the client submits requests to.
|
||||||
|
Cannot be updated.
|
||||||
|
In CamelCase.
|
||||||
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
||||||
|
type: string
|
||||||
|
metadata:
|
||||||
|
type: object
|
||||||
|
spec:
|
||||||
|
description: InfisicalPushSecretSpec defines the desired state of InfisicalPushSecret
|
||||||
|
properties:
|
||||||
|
authentication:
|
||||||
|
properties:
|
||||||
|
awsIamAuth:
|
||||||
|
properties:
|
||||||
|
identityId:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- identityId
|
||||||
|
type: object
|
||||||
|
azureAuth:
|
||||||
|
properties:
|
||||||
|
identityId:
|
||||||
|
type: string
|
||||||
|
resource:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- identityId
|
||||||
|
type: object
|
||||||
|
gcpIamAuth:
|
||||||
|
properties:
|
||||||
|
identityId:
|
||||||
|
type: string
|
||||||
|
serviceAccountKeyFilePath:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- identityId
|
||||||
|
- serviceAccountKeyFilePath
|
||||||
|
type: object
|
||||||
|
gcpIdTokenAuth:
|
||||||
|
properties:
|
||||||
|
identityId:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- identityId
|
||||||
|
type: object
|
||||||
|
kubernetesAuth:
|
||||||
|
properties:
|
||||||
|
autoCreateServiceAccountToken:
|
||||||
|
description: |-
|
||||||
|
Optionally automatically create a service account token for the configured service account.
|
||||||
|
If this is set to `true`, the operator will automatically create a service account token for the configured service account. This field is recommended in most cases.
|
||||||
|
type: boolean
|
||||||
|
identityId:
|
||||||
|
type: string
|
||||||
|
serviceAccountRef:
|
||||||
|
properties:
|
||||||
|
name:
|
||||||
|
type: string
|
||||||
|
namespace:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- name
|
||||||
|
- namespace
|
||||||
|
type: object
|
||||||
|
serviceAccountTokenAudiences:
|
||||||
|
description: The audiences to use for the service account token.
|
||||||
|
This is only relevant if `autoCreateServiceAccountToken` is
|
||||||
|
true.
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- identityId
|
||||||
|
- serviceAccountRef
|
||||||
|
type: object
|
||||||
|
ldapAuth:
|
||||||
|
properties:
|
||||||
|
credentialsRef:
|
||||||
|
properties:
|
||||||
|
secretName:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
secretNamespace:
|
||||||
|
description: The name space where the Kubernetes Secret
|
||||||
|
is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- secretName
|
||||||
|
- secretNamespace
|
||||||
|
type: object
|
||||||
|
identityId:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- credentialsRef
|
||||||
|
- identityId
|
||||||
|
type: object
|
||||||
|
universalAuth:
|
||||||
|
properties:
|
||||||
|
credentialsRef:
|
||||||
|
properties:
|
||||||
|
secretName:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
secretNamespace:
|
||||||
|
description: The name space where the Kubernetes Secret
|
||||||
|
is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- secretName
|
||||||
|
- secretNamespace
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- credentialsRef
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
deletionPolicy:
|
||||||
|
type: string
|
||||||
|
destination:
|
||||||
|
properties:
|
||||||
|
environmentSlug:
|
||||||
|
type: string
|
||||||
|
projectId:
|
||||||
|
type: string
|
||||||
|
projectSlug:
|
||||||
|
type: string
|
||||||
|
secretsPath:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- environmentSlug
|
||||||
|
- secretsPath
|
||||||
|
type: object
|
||||||
|
hostAPI:
|
||||||
|
description: Infisical host to pull secrets from
|
||||||
|
type: string
|
||||||
|
push:
|
||||||
|
properties:
|
||||||
|
generators:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
destinationSecretName:
|
||||||
|
type: string
|
||||||
|
generatorRef:
|
||||||
|
properties:
|
||||||
|
kind:
|
||||||
|
allOf:
|
||||||
|
- enum:
|
||||||
|
- Password
|
||||||
|
- UUID
|
||||||
|
- enum:
|
||||||
|
- Password
|
||||||
|
- UUID
|
||||||
|
description: Specify the Kind of the generator resource
|
||||||
|
type: string
|
||||||
|
name:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- kind
|
||||||
|
- name
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- destinationSecretName
|
||||||
|
- generatorRef
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
secret:
|
||||||
|
properties:
|
||||||
|
secretName:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
secretNamespace:
|
||||||
|
description: The name space where the Kubernetes Secret is located
|
||||||
|
type: string
|
||||||
|
template:
|
||||||
|
properties:
|
||||||
|
data:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
description: The template key values
|
||||||
|
type: object
|
||||||
|
includeAllSecrets:
|
||||||
|
description: |-
|
||||||
|
This injects all retrieved secrets into the top level of your template.
|
||||||
|
Secrets defined in the template will take precedence over the injected ones.
|
||||||
|
type: boolean
|
||||||
|
metadata:
|
||||||
|
description: |-
|
||||||
|
Custom metadata (labels/annotations) for the managed secret.
|
||||||
|
When specified, these values are used instead of copying metadata from the InfisicalSecret CR.
|
||||||
|
properties:
|
||||||
|
annotations:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
description: Custom annotations to apply to the managed
|
||||||
|
secret
|
||||||
|
type: object
|
||||||
|
labels:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
description: Custom labels to apply to the managed secret
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- secretName
|
||||||
|
- secretNamespace
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
resyncInterval:
|
||||||
|
type: string
|
||||||
|
tls:
|
||||||
|
properties:
|
||||||
|
caRef:
|
||||||
|
description: Reference to secret containing CA cert
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
description: The name of the secret property with the CA certificate
|
||||||
|
value
|
||||||
|
type: string
|
||||||
|
secretName:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
secretNamespace:
|
||||||
|
description: The namespace where the Kubernetes Secret is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- secretName
|
||||||
|
- secretNamespace
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
updatePolicy:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- destination
|
||||||
|
- push
|
||||||
|
type: object
|
||||||
|
status:
|
||||||
|
description: InfisicalPushSecretStatus defines the observed state of InfisicalPushSecret
|
||||||
|
properties:
|
||||||
|
conditions:
|
||||||
|
items:
|
||||||
|
description: Condition contains details for one aspect of the current
|
||||||
|
state of this API Resource.
|
||||||
|
properties:
|
||||||
|
lastTransitionTime:
|
||||||
|
description: |-
|
||||||
|
lastTransitionTime is the last time the condition transitioned from one status to another.
|
||||||
|
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
|
||||||
|
format: date-time
|
||||||
|
type: string
|
||||||
|
message:
|
||||||
|
description: |-
|
||||||
|
message is a human readable message indicating details about the transition.
|
||||||
|
This may be an empty string.
|
||||||
|
maxLength: 32768
|
||||||
|
type: string
|
||||||
|
observedGeneration:
|
||||||
|
description: |-
|
||||||
|
observedGeneration represents the .metadata.generation that the condition was set based upon.
|
||||||
|
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
|
||||||
|
with respect to the current state of the instance.
|
||||||
|
format: int64
|
||||||
|
minimum: 0
|
||||||
|
type: integer
|
||||||
|
reason:
|
||||||
|
description: |-
|
||||||
|
reason contains a programmatic identifier indicating the reason for the condition's last transition.
|
||||||
|
Producers of specific condition types may define expected values and meanings for this field,
|
||||||
|
and whether the values are considered a guaranteed API.
|
||||||
|
The value should be a CamelCase string.
|
||||||
|
This field may not be empty.
|
||||||
|
maxLength: 1024
|
||||||
|
minLength: 1
|
||||||
|
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
|
||||||
|
type: string
|
||||||
|
status:
|
||||||
|
description: status of the condition, one of True, False, Unknown.
|
||||||
|
enum:
|
||||||
|
- "True"
|
||||||
|
- "False"
|
||||||
|
- Unknown
|
||||||
|
type: string
|
||||||
|
type:
|
||||||
|
description: type of condition in CamelCase or in foo.example.com/CamelCase.
|
||||||
|
maxLength: 316
|
||||||
|
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- lastTransitionTime
|
||||||
|
- message
|
||||||
|
- reason
|
||||||
|
- status
|
||||||
|
- type
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
managedSecrets:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
description: managed secrets is a map where the key is the ID, and the
|
||||||
|
value is the secret key (string[id], string[key] )
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- conditions
|
||||||
|
- managedSecrets
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
served: true
|
||||||
|
storage: true
|
||||||
|
subresources:
|
||||||
|
status: {}
|
||||||
|
status:
|
||||||
|
acceptedNames:
|
||||||
|
kind: ""
|
||||||
|
plural: ""
|
||||||
|
conditions: []
|
||||||
|
storedVersions: []
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,627 @@
|
|||||||
|
{{- if .Values.installCRDs }}
|
||||||
|
apiVersion: apiextensions.k8s.io/v1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: infisicalsecrets.secrets.infisical.com
|
||||||
|
annotations:
|
||||||
|
controller-gen.kubebuilder.io/version: v0.18.0
|
||||||
|
labels:
|
||||||
|
{{- include "secrets-operator.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
group: secrets.infisical.com
|
||||||
|
names:
|
||||||
|
kind: InfisicalSecret
|
||||||
|
listKind: InfisicalSecretList
|
||||||
|
plural: infisicalsecrets
|
||||||
|
singular: infisicalsecret
|
||||||
|
scope: Namespaced
|
||||||
|
versions:
|
||||||
|
- name: v1alpha1
|
||||||
|
schema:
|
||||||
|
openAPIV3Schema:
|
||||||
|
description: InfisicalSecret is the Schema for the infisicalsecrets API
|
||||||
|
properties:
|
||||||
|
apiVersion:
|
||||||
|
description: |-
|
||||||
|
APIVersion defines the versioned schema of this representation of an object.
|
||||||
|
Servers should convert recognized schemas to the latest internal value, and
|
||||||
|
may reject unrecognized values.
|
||||||
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
||||||
|
type: string
|
||||||
|
kind:
|
||||||
|
description: |-
|
||||||
|
Kind is a string value representing the REST resource this object represents.
|
||||||
|
Servers may infer this from the endpoint the client submits requests to.
|
||||||
|
Cannot be updated.
|
||||||
|
In CamelCase.
|
||||||
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
||||||
|
type: string
|
||||||
|
metadata:
|
||||||
|
type: object
|
||||||
|
spec:
|
||||||
|
description: InfisicalSecretSpec defines the desired state of InfisicalSecret
|
||||||
|
properties:
|
||||||
|
authentication:
|
||||||
|
properties:
|
||||||
|
awsIamAuth:
|
||||||
|
properties:
|
||||||
|
identityId:
|
||||||
|
type: string
|
||||||
|
secretsScope:
|
||||||
|
properties:
|
||||||
|
envSlug:
|
||||||
|
type: string
|
||||||
|
projectId:
|
||||||
|
type: string
|
||||||
|
projectSlug:
|
||||||
|
type: string
|
||||||
|
recursive:
|
||||||
|
type: boolean
|
||||||
|
secretName:
|
||||||
|
type: string
|
||||||
|
secretsPath:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- envSlug
|
||||||
|
- secretsPath
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- identityId
|
||||||
|
- secretsScope
|
||||||
|
type: object
|
||||||
|
azureAuth:
|
||||||
|
properties:
|
||||||
|
azureManagedIdentityClientId:
|
||||||
|
type: string
|
||||||
|
identityId:
|
||||||
|
type: string
|
||||||
|
resource:
|
||||||
|
type: string
|
||||||
|
secretsScope:
|
||||||
|
properties:
|
||||||
|
envSlug:
|
||||||
|
type: string
|
||||||
|
projectId:
|
||||||
|
type: string
|
||||||
|
projectSlug:
|
||||||
|
type: string
|
||||||
|
recursive:
|
||||||
|
type: boolean
|
||||||
|
secretName:
|
||||||
|
type: string
|
||||||
|
secretsPath:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- envSlug
|
||||||
|
- secretsPath
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- identityId
|
||||||
|
- secretsScope
|
||||||
|
type: object
|
||||||
|
gcpIamAuth:
|
||||||
|
properties:
|
||||||
|
identityId:
|
||||||
|
type: string
|
||||||
|
secretsScope:
|
||||||
|
properties:
|
||||||
|
envSlug:
|
||||||
|
type: string
|
||||||
|
projectId:
|
||||||
|
type: string
|
||||||
|
projectSlug:
|
||||||
|
type: string
|
||||||
|
recursive:
|
||||||
|
type: boolean
|
||||||
|
secretName:
|
||||||
|
type: string
|
||||||
|
secretsPath:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- envSlug
|
||||||
|
- secretsPath
|
||||||
|
type: object
|
||||||
|
serviceAccountKeyFilePath:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- identityId
|
||||||
|
- secretsScope
|
||||||
|
- serviceAccountKeyFilePath
|
||||||
|
type: object
|
||||||
|
gcpIdTokenAuth:
|
||||||
|
properties:
|
||||||
|
identityId:
|
||||||
|
type: string
|
||||||
|
secretsScope:
|
||||||
|
properties:
|
||||||
|
envSlug:
|
||||||
|
type: string
|
||||||
|
projectId:
|
||||||
|
type: string
|
||||||
|
projectSlug:
|
||||||
|
type: string
|
||||||
|
recursive:
|
||||||
|
type: boolean
|
||||||
|
secretName:
|
||||||
|
type: string
|
||||||
|
secretsPath:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- envSlug
|
||||||
|
- secretsPath
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- identityId
|
||||||
|
- secretsScope
|
||||||
|
type: object
|
||||||
|
kubernetesAuth:
|
||||||
|
properties:
|
||||||
|
autoCreateServiceAccountToken:
|
||||||
|
description: |-
|
||||||
|
Optionally automatically create a service account token for the configured service account.
|
||||||
|
If this is set to `true`, the operator will automatically create a service account token for the configured service account.
|
||||||
|
type: boolean
|
||||||
|
identityId:
|
||||||
|
type: string
|
||||||
|
secretsScope:
|
||||||
|
properties:
|
||||||
|
envSlug:
|
||||||
|
type: string
|
||||||
|
projectId:
|
||||||
|
type: string
|
||||||
|
projectSlug:
|
||||||
|
type: string
|
||||||
|
recursive:
|
||||||
|
type: boolean
|
||||||
|
secretName:
|
||||||
|
type: string
|
||||||
|
secretsPath:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- envSlug
|
||||||
|
- secretsPath
|
||||||
|
type: object
|
||||||
|
serviceAccountRef:
|
||||||
|
properties:
|
||||||
|
name:
|
||||||
|
type: string
|
||||||
|
namespace:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- name
|
||||||
|
- namespace
|
||||||
|
type: object
|
||||||
|
serviceAccountTokenAudiences:
|
||||||
|
description: The audiences to use for the service account token.
|
||||||
|
This is only relevant if `autoCreateServiceAccountToken` is
|
||||||
|
true.
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- identityId
|
||||||
|
- secretsScope
|
||||||
|
- serviceAccountRef
|
||||||
|
type: object
|
||||||
|
ldapAuth:
|
||||||
|
properties:
|
||||||
|
credentialsRef:
|
||||||
|
properties:
|
||||||
|
secretName:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
secretNamespace:
|
||||||
|
description: The name space where the Kubernetes Secret
|
||||||
|
is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- secretName
|
||||||
|
- secretNamespace
|
||||||
|
type: object
|
||||||
|
identityId:
|
||||||
|
type: string
|
||||||
|
secretsScope:
|
||||||
|
properties:
|
||||||
|
envSlug:
|
||||||
|
type: string
|
||||||
|
projectId:
|
||||||
|
type: string
|
||||||
|
projectSlug:
|
||||||
|
type: string
|
||||||
|
recursive:
|
||||||
|
type: boolean
|
||||||
|
secretName:
|
||||||
|
type: string
|
||||||
|
secretsPath:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- envSlug
|
||||||
|
- secretsPath
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- credentialsRef
|
||||||
|
- identityId
|
||||||
|
- secretsScope
|
||||||
|
type: object
|
||||||
|
serviceAccount:
|
||||||
|
properties:
|
||||||
|
environmentName:
|
||||||
|
type: string
|
||||||
|
projectId:
|
||||||
|
type: string
|
||||||
|
serviceAccountSecretReference:
|
||||||
|
properties:
|
||||||
|
secretName:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
secretNamespace:
|
||||||
|
description: The name space where the Kubernetes Secret
|
||||||
|
is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- secretName
|
||||||
|
- secretNamespace
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- environmentName
|
||||||
|
- projectId
|
||||||
|
- serviceAccountSecretReference
|
||||||
|
type: object
|
||||||
|
serviceToken:
|
||||||
|
properties:
|
||||||
|
secretsScope:
|
||||||
|
properties:
|
||||||
|
envSlug:
|
||||||
|
type: string
|
||||||
|
recursive:
|
||||||
|
type: boolean
|
||||||
|
secretsPath:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- envSlug
|
||||||
|
- secretsPath
|
||||||
|
type: object
|
||||||
|
serviceTokenSecretReference:
|
||||||
|
properties:
|
||||||
|
secretName:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
secretNamespace:
|
||||||
|
description: The name space where the Kubernetes Secret
|
||||||
|
is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- secretName
|
||||||
|
- secretNamespace
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- secretsScope
|
||||||
|
- serviceTokenSecretReference
|
||||||
|
type: object
|
||||||
|
universalAuth:
|
||||||
|
properties:
|
||||||
|
credentialsRef:
|
||||||
|
properties:
|
||||||
|
secretName:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
secretNamespace:
|
||||||
|
description: The name space where the Kubernetes Secret
|
||||||
|
is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- secretName
|
||||||
|
- secretNamespace
|
||||||
|
type: object
|
||||||
|
secretsScope:
|
||||||
|
properties:
|
||||||
|
envSlug:
|
||||||
|
type: string
|
||||||
|
projectId:
|
||||||
|
type: string
|
||||||
|
projectSlug:
|
||||||
|
type: string
|
||||||
|
recursive:
|
||||||
|
type: boolean
|
||||||
|
secretName:
|
||||||
|
type: string
|
||||||
|
secretsPath:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- envSlug
|
||||||
|
- secretsPath
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- credentialsRef
|
||||||
|
- secretsScope
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
hostAPI:
|
||||||
|
description: Infisical host to pull secrets from
|
||||||
|
type: string
|
||||||
|
instantUpdates:
|
||||||
|
type: boolean
|
||||||
|
managedKubeConfigMapReferences:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
configMapName:
|
||||||
|
description: The name of the Kubernetes ConfigMap
|
||||||
|
type: string
|
||||||
|
configMapNamespace:
|
||||||
|
description: The namespace where the Kubernetes ConfigMap is located
|
||||||
|
type: string
|
||||||
|
creationPolicy:
|
||||||
|
default: Orphan
|
||||||
|
description: |-
|
||||||
|
The Kubernetes ConfigMap creation policy.
|
||||||
|
Enum with values: 'Owner', 'Orphan'.
|
||||||
|
Owner creates the config map and sets .metadata.ownerReferences of the InfisicalSecret CRD that created it.
|
||||||
|
Orphan will not set the config map owner. This will result in the config map being orphaned and not deleted when the resource is deleted.
|
||||||
|
type: string
|
||||||
|
template:
|
||||||
|
description: The template to transform the secret data
|
||||||
|
properties:
|
||||||
|
data:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
description: The template key values
|
||||||
|
type: object
|
||||||
|
includeAllSecrets:
|
||||||
|
description: |-
|
||||||
|
This injects all retrieved secrets into the top level of your template.
|
||||||
|
Secrets defined in the template will take precedence over the injected ones.
|
||||||
|
type: boolean
|
||||||
|
metadata:
|
||||||
|
description: |-
|
||||||
|
Custom metadata (labels/annotations) for the managed secret.
|
||||||
|
When specified, these values are used instead of copying metadata from the InfisicalSecret CR.
|
||||||
|
properties:
|
||||||
|
annotations:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
description: Custom annotations to apply to the managed
|
||||||
|
secret
|
||||||
|
type: object
|
||||||
|
labels:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
description: Custom labels to apply to the managed secret
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- configMapName
|
||||||
|
- configMapNamespace
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
managedKubeSecretReferences:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
creationPolicy:
|
||||||
|
default: Orphan
|
||||||
|
description: |-
|
||||||
|
The Kubernetes Secret creation policy.
|
||||||
|
Enum with values: 'Owner', 'Orphan'.
|
||||||
|
Owner creates the secret and sets .metadata.ownerReferences of the InfisicalSecret CRD that created it.
|
||||||
|
Orphan will not set the secret owner. This will result in the secret being orphaned and not deleted when the resource is deleted.
|
||||||
|
type: string
|
||||||
|
secretName:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
secretNamespace:
|
||||||
|
description: The name space where the Kubernetes Secret is located
|
||||||
|
type: string
|
||||||
|
secretType:
|
||||||
|
default: Opaque
|
||||||
|
description: 'The Kubernetes Secret type (experimental feature).
|
||||||
|
More info: https://kubernetes.io/docs/concepts/configuration/secret/#secret-types'
|
||||||
|
type: string
|
||||||
|
template:
|
||||||
|
description: The template to transform the secret data
|
||||||
|
properties:
|
||||||
|
data:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
description: The template key values
|
||||||
|
type: object
|
||||||
|
includeAllSecrets:
|
||||||
|
description: |-
|
||||||
|
This injects all retrieved secrets into the top level of your template.
|
||||||
|
Secrets defined in the template will take precedence over the injected ones.
|
||||||
|
type: boolean
|
||||||
|
metadata:
|
||||||
|
description: |-
|
||||||
|
Custom metadata (labels/annotations) for the managed secret.
|
||||||
|
When specified, these values are used instead of copying metadata from the InfisicalSecret CR.
|
||||||
|
properties:
|
||||||
|
annotations:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
description: Custom annotations to apply to the managed
|
||||||
|
secret
|
||||||
|
type: object
|
||||||
|
labels:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
description: Custom labels to apply to the managed secret
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- secretName
|
||||||
|
- secretNamespace
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
managedSecretReference:
|
||||||
|
properties:
|
||||||
|
creationPolicy:
|
||||||
|
default: Orphan
|
||||||
|
description: |-
|
||||||
|
The Kubernetes Secret creation policy.
|
||||||
|
Enum with values: 'Owner', 'Orphan'.
|
||||||
|
Owner creates the secret and sets .metadata.ownerReferences of the InfisicalSecret CRD that created it.
|
||||||
|
Orphan will not set the secret owner. This will result in the secret being orphaned and not deleted when the resource is deleted.
|
||||||
|
type: string
|
||||||
|
secretName:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
secretNamespace:
|
||||||
|
description: The name space where the Kubernetes Secret is located
|
||||||
|
type: string
|
||||||
|
secretType:
|
||||||
|
default: Opaque
|
||||||
|
description: 'The Kubernetes Secret type (experimental feature).
|
||||||
|
More info: https://kubernetes.io/docs/concepts/configuration/secret/#secret-types'
|
||||||
|
type: string
|
||||||
|
template:
|
||||||
|
description: The template to transform the secret data
|
||||||
|
properties:
|
||||||
|
data:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
description: The template key values
|
||||||
|
type: object
|
||||||
|
includeAllSecrets:
|
||||||
|
description: |-
|
||||||
|
This injects all retrieved secrets into the top level of your template.
|
||||||
|
Secrets defined in the template will take precedence over the injected ones.
|
||||||
|
type: boolean
|
||||||
|
metadata:
|
||||||
|
description: |-
|
||||||
|
Custom metadata (labels/annotations) for the managed secret.
|
||||||
|
When specified, these values are used instead of copying metadata from the InfisicalSecret CR.
|
||||||
|
properties:
|
||||||
|
annotations:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
description: Custom annotations to apply to the managed
|
||||||
|
secret
|
||||||
|
type: object
|
||||||
|
labels:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
description: Custom labels to apply to the managed secret
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- secretName
|
||||||
|
- secretNamespace
|
||||||
|
type: object
|
||||||
|
resyncInterval:
|
||||||
|
type: integer
|
||||||
|
syncConfig:
|
||||||
|
properties:
|
||||||
|
instantUpdates:
|
||||||
|
type: boolean
|
||||||
|
resyncInterval:
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
tls:
|
||||||
|
properties:
|
||||||
|
caRef:
|
||||||
|
description: Reference to secret containing CA cert
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
description: The name of the secret property with the CA certificate
|
||||||
|
value
|
||||||
|
type: string
|
||||||
|
secretName:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
secretNamespace:
|
||||||
|
description: The namespace where the Kubernetes Secret is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- secretName
|
||||||
|
- secretNamespace
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
tokenSecretReference:
|
||||||
|
properties:
|
||||||
|
secretName:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
secretNamespace:
|
||||||
|
description: The name space where the Kubernetes Secret is located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- secretName
|
||||||
|
- secretNamespace
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
status:
|
||||||
|
description: InfisicalSecretStatus defines the observed state of InfisicalSecret
|
||||||
|
properties:
|
||||||
|
conditions:
|
||||||
|
items:
|
||||||
|
description: Condition contains details for one aspect of the current
|
||||||
|
state of this API Resource.
|
||||||
|
properties:
|
||||||
|
lastTransitionTime:
|
||||||
|
description: |-
|
||||||
|
lastTransitionTime is the last time the condition transitioned from one status to another.
|
||||||
|
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
|
||||||
|
format: date-time
|
||||||
|
type: string
|
||||||
|
message:
|
||||||
|
description: |-
|
||||||
|
message is a human readable message indicating details about the transition.
|
||||||
|
This may be an empty string.
|
||||||
|
maxLength: 32768
|
||||||
|
type: string
|
||||||
|
observedGeneration:
|
||||||
|
description: |-
|
||||||
|
observedGeneration represents the .metadata.generation that the condition was set based upon.
|
||||||
|
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
|
||||||
|
with respect to the current state of the instance.
|
||||||
|
format: int64
|
||||||
|
minimum: 0
|
||||||
|
type: integer
|
||||||
|
reason:
|
||||||
|
description: |-
|
||||||
|
reason contains a programmatic identifier indicating the reason for the condition's last transition.
|
||||||
|
Producers of specific condition types may define expected values and meanings for this field,
|
||||||
|
and whether the values are considered a guaranteed API.
|
||||||
|
The value should be a CamelCase string.
|
||||||
|
This field may not be empty.
|
||||||
|
maxLength: 1024
|
||||||
|
minLength: 1
|
||||||
|
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
|
||||||
|
type: string
|
||||||
|
status:
|
||||||
|
description: status of the condition, one of True, False, Unknown.
|
||||||
|
enum:
|
||||||
|
- "True"
|
||||||
|
- "False"
|
||||||
|
- Unknown
|
||||||
|
type: string
|
||||||
|
type:
|
||||||
|
description: type of condition in CamelCase or in foo.example.com/CamelCase.
|
||||||
|
maxLength: 316
|
||||||
|
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- lastTransitionTime
|
||||||
|
- message
|
||||||
|
- reason
|
||||||
|
- status
|
||||||
|
- type
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- conditions
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
served: true
|
||||||
|
storage: true
|
||||||
|
subresources:
|
||||||
|
status: {}
|
||||||
|
status:
|
||||||
|
acceptedNames:
|
||||||
|
kind: ""
|
||||||
|
plural: ""
|
||||||
|
conditions: []
|
||||||
|
storedVersions: []
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,234 @@
|
|||||||
|
{{- if .Values.installCRDs }}
|
||||||
|
apiVersion: apiextensions.k8s.io/v1
|
||||||
|
kind: CustomResourceDefinition
|
||||||
|
metadata:
|
||||||
|
name: infisicalstaticsecrets.secrets.infisical.com
|
||||||
|
annotations:
|
||||||
|
controller-gen.kubebuilder.io/version: v0.18.0
|
||||||
|
labels:
|
||||||
|
{{- include "secrets-operator.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
group: secrets.infisical.com
|
||||||
|
names:
|
||||||
|
kind: InfisicalStaticSecret
|
||||||
|
listKind: InfisicalStaticSecretList
|
||||||
|
plural: infisicalstaticsecrets
|
||||||
|
singular: infisicalstaticsecret
|
||||||
|
scope: Namespaced
|
||||||
|
versions:
|
||||||
|
- additionalPrinterColumns:
|
||||||
|
- jsonPath: .metadata.creationTimestamp
|
||||||
|
name: Age
|
||||||
|
type: date
|
||||||
|
- jsonPath: .status.conditions[?(@.type=="secrets.infisical.com/LastReconcileAuthMethod")].message
|
||||||
|
name: Auth Method
|
||||||
|
type: string
|
||||||
|
- jsonPath: .status.conditions[?(@.type=="secrets.infisical.com/LastReconcileStatus")].status
|
||||||
|
name: Synced
|
||||||
|
type: string
|
||||||
|
- jsonPath: .status.conditions[?(@.type=="secrets.infisical.com/LastReconcileAffectedDeployments")].message
|
||||||
|
name: Affected Deployments
|
||||||
|
type: string
|
||||||
|
name: v1beta1
|
||||||
|
schema:
|
||||||
|
openAPIV3Schema:
|
||||||
|
description: InfisicalStaticSecret is the Schema for the InfisicalStaticSecret
|
||||||
|
API.
|
||||||
|
properties:
|
||||||
|
apiVersion:
|
||||||
|
description: |-
|
||||||
|
APIVersion defines the versioned schema of this representation of an object.
|
||||||
|
Servers should convert recognized schemas to the latest internal value, and
|
||||||
|
may reject unrecognized values.
|
||||||
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
||||||
|
type: string
|
||||||
|
kind:
|
||||||
|
description: |-
|
||||||
|
Kind is a string value representing the REST resource this object represents.
|
||||||
|
Servers may infer this from the endpoint the client submits requests to.
|
||||||
|
Cannot be updated.
|
||||||
|
In CamelCase.
|
||||||
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
||||||
|
type: string
|
||||||
|
metadata:
|
||||||
|
type: object
|
||||||
|
spec:
|
||||||
|
properties:
|
||||||
|
infisicalAuthRef:
|
||||||
|
properties:
|
||||||
|
name:
|
||||||
|
type: string
|
||||||
|
namespace:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- name
|
||||||
|
- namespace
|
||||||
|
type: object
|
||||||
|
sources:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
environmentSlug:
|
||||||
|
type: string
|
||||||
|
projectId:
|
||||||
|
type: string
|
||||||
|
projectSlug:
|
||||||
|
type: string
|
||||||
|
recursive:
|
||||||
|
type: boolean
|
||||||
|
secretPath:
|
||||||
|
type: string
|
||||||
|
tagSlugs:
|
||||||
|
items:
|
||||||
|
type: string
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- environmentSlug
|
||||||
|
- secretPath
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
syncOptions:
|
||||||
|
properties:
|
||||||
|
instantUpdates:
|
||||||
|
type: boolean
|
||||||
|
refreshInterval:
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- refreshInterval
|
||||||
|
type: object
|
||||||
|
targets:
|
||||||
|
items:
|
||||||
|
properties:
|
||||||
|
creationPolicy:
|
||||||
|
enum:
|
||||||
|
- Owner
|
||||||
|
- Orphan
|
||||||
|
type: string
|
||||||
|
kind:
|
||||||
|
enum:
|
||||||
|
- Secret
|
||||||
|
- ConfigMap
|
||||||
|
type: string
|
||||||
|
metadata:
|
||||||
|
properties:
|
||||||
|
annotations:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
labels:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- annotations
|
||||||
|
- labels
|
||||||
|
type: object
|
||||||
|
name:
|
||||||
|
type: string
|
||||||
|
namespace:
|
||||||
|
type: string
|
||||||
|
secretType:
|
||||||
|
type: string
|
||||||
|
template:
|
||||||
|
properties:
|
||||||
|
data:
|
||||||
|
description: |-
|
||||||
|
Data defines the templated output. It accepts either a map of per-key
|
||||||
|
Go templates (each entry becomes one key in the resulting Secret /
|
||||||
|
ConfigMap) or a single Go template string whose rendered output is
|
||||||
|
YAML-decoded into a map of key/value pairs.
|
||||||
|
x-kubernetes-preserve-unknown-fields: true
|
||||||
|
engineVersion:
|
||||||
|
enum:
|
||||||
|
- v1
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- data
|
||||||
|
- engineVersion
|
||||||
|
type: object
|
||||||
|
required:
|
||||||
|
- creationPolicy
|
||||||
|
- kind
|
||||||
|
- name
|
||||||
|
- namespace
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- infisicalAuthRef
|
||||||
|
- sources
|
||||||
|
- syncOptions
|
||||||
|
- targets
|
||||||
|
type: object
|
||||||
|
status:
|
||||||
|
description: InfisicalStaticSecretStatus defines the observed state of InfisicalAuth
|
||||||
|
properties:
|
||||||
|
conditions:
|
||||||
|
items:
|
||||||
|
description: Condition contains details for one aspect of the current
|
||||||
|
state of this API Resource.
|
||||||
|
properties:
|
||||||
|
lastTransitionTime:
|
||||||
|
description: |-
|
||||||
|
lastTransitionTime is the last time the condition transitioned from one status to another.
|
||||||
|
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
|
||||||
|
format: date-time
|
||||||
|
type: string
|
||||||
|
message:
|
||||||
|
description: |-
|
||||||
|
message is a human readable message indicating details about the transition.
|
||||||
|
This may be an empty string.
|
||||||
|
maxLength: 32768
|
||||||
|
type: string
|
||||||
|
observedGeneration:
|
||||||
|
description: |-
|
||||||
|
observedGeneration represents the .metadata.generation that the condition was set based upon.
|
||||||
|
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
|
||||||
|
with respect to the current state of the instance.
|
||||||
|
format: int64
|
||||||
|
minimum: 0
|
||||||
|
type: integer
|
||||||
|
reason:
|
||||||
|
description: |-
|
||||||
|
reason contains a programmatic identifier indicating the reason for the condition's last transition.
|
||||||
|
Producers of specific condition types may define expected values and meanings for this field,
|
||||||
|
and whether the values are considered a guaranteed API.
|
||||||
|
The value should be a CamelCase string.
|
||||||
|
This field may not be empty.
|
||||||
|
maxLength: 1024
|
||||||
|
minLength: 1
|
||||||
|
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
|
||||||
|
type: string
|
||||||
|
status:
|
||||||
|
description: status of the condition, one of True, False, Unknown.
|
||||||
|
enum:
|
||||||
|
- "True"
|
||||||
|
- "False"
|
||||||
|
- Unknown
|
||||||
|
type: string
|
||||||
|
type:
|
||||||
|
description: type of condition in CamelCase or in foo.example.com/CamelCase.
|
||||||
|
maxLength: 316
|
||||||
|
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- lastTransitionTime
|
||||||
|
- message
|
||||||
|
- reason
|
||||||
|
- status
|
||||||
|
- type
|
||||||
|
type: object
|
||||||
|
type: array
|
||||||
|
required:
|
||||||
|
- conditions
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
|
served: true
|
||||||
|
storage: true
|
||||||
|
subresources:
|
||||||
|
status: {}
|
||||||
|
status:
|
||||||
|
acceptedNames:
|
||||||
|
kind: ""
|
||||||
|
plural: ""
|
||||||
|
conditions: []
|
||||||
|
storedVersions: []
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,53 @@
|
|||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: Role
|
||||||
|
metadata:
|
||||||
|
name: {{ include "secrets-operator.fullname" . }}-leader-election-role
|
||||||
|
labels:
|
||||||
|
{{- include "secrets-operator.labels" . | nindent 4 }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- configmaps
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- create
|
||||||
|
- update
|
||||||
|
- patch
|
||||||
|
- delete
|
||||||
|
- apiGroups:
|
||||||
|
- coordination.k8s.io
|
||||||
|
resources:
|
||||||
|
- leases
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- create
|
||||||
|
- update
|
||||||
|
- patch
|
||||||
|
- delete
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- events
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- patch
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: RoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ include "secrets-operator.fullname" . }}-leader-election-rolebinding
|
||||||
|
labels:
|
||||||
|
{{- include "secrets-operator.labels" . | nindent 4 }}
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: Role
|
||||||
|
name: '{{ include "secrets-operator.fullname" . }}-leader-election-role'
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: '{{ include "secrets-operator.serviceAccountName" . }}'
|
||||||
|
namespace: '{{ .Release.Namespace }}'
|
||||||
@@ -0,0 +1,152 @@
|
|||||||
|
{{- $namespaces := (include "secrets-operator.scopedNamespaces" . | fromJson).list }}
|
||||||
|
{{- $isScopedMode := and $namespaces .Values.scopedRBAC }}
|
||||||
|
|
||||||
|
{{- /* Define the rules once to avoid repetition */ -}}
|
||||||
|
{{- define "secrets-operator.managerRules" }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- configmaps
|
||||||
|
- secrets
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- update
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- pods
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- serviceaccounts
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- ""
|
||||||
|
resources:
|
||||||
|
- serviceaccounts/token
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- apiGroups:
|
||||||
|
- apps
|
||||||
|
resources:
|
||||||
|
- daemonsets
|
||||||
|
- deployments
|
||||||
|
- statefulsets
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- update
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- authentication.k8s.io
|
||||||
|
resources:
|
||||||
|
- tokenreviews
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- apiGroups:
|
||||||
|
- secrets.infisical.com
|
||||||
|
resources:
|
||||||
|
- clustergenerators
|
||||||
|
- infisicalauths
|
||||||
|
- infisicalconnections
|
||||||
|
- infisicaldynamicsecrets
|
||||||
|
- infisicalpushsecrets
|
||||||
|
- infisicalsecrets
|
||||||
|
- infisicalstaticsecrets
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- delete
|
||||||
|
- get
|
||||||
|
- list
|
||||||
|
- patch
|
||||||
|
- update
|
||||||
|
- watch
|
||||||
|
- apiGroups:
|
||||||
|
- secrets.infisical.com
|
||||||
|
resources:
|
||||||
|
- infisicalauths/status
|
||||||
|
- infisicalconnections/status
|
||||||
|
- infisicaldynamicsecrets/status
|
||||||
|
- infisicalpushsecrets/status
|
||||||
|
- infisicalsecrets/status
|
||||||
|
- infisicalstaticsecrets/status
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
- patch
|
||||||
|
- update
|
||||||
|
- apiGroups:
|
||||||
|
- secrets.infisical.com
|
||||||
|
resources:
|
||||||
|
- infisicaldynamicsecrets/finalizers
|
||||||
|
- infisicalpushsecrets/finalizers
|
||||||
|
- infisicalsecrets/finalizers
|
||||||
|
- infisicalstaticsecrets/finalizers
|
||||||
|
verbs:
|
||||||
|
- update
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{- if $isScopedMode }}
|
||||||
|
{{- /* Scoped mode: Create a Role and RoleBinding in each namespace */ -}}
|
||||||
|
{{- range $ns := $namespaces }}
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: Role
|
||||||
|
metadata:
|
||||||
|
name: {{ include "secrets-operator.fullname" $ }}-manager-role
|
||||||
|
namespace: {{ $ns | quote }}
|
||||||
|
labels:
|
||||||
|
{{- include "secrets-operator.labels" $ | nindent 4 }}
|
||||||
|
{{- include "secrets-operator.managerRules" $ }}
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: RoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ include "secrets-operator.fullname" $ }}-manager-rolebinding
|
||||||
|
namespace: {{ $ns | quote }}
|
||||||
|
labels:
|
||||||
|
{{- include "secrets-operator.labels" $ | nindent 4 }}
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: Role
|
||||||
|
name: {{ include "secrets-operator.fullname" $ }}-manager-role
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: {{ include "secrets-operator.serviceAccountName" $ }}
|
||||||
|
namespace: {{ $.Release.Namespace }}
|
||||||
|
{{- end }}
|
||||||
|
{{- else }}
|
||||||
|
{{- /* Cluster-scoped mode: Create a ClusterRole and ClusterRoleBinding */ -}}
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
name: {{ include "secrets-operator.fullname" . }}-manager-role
|
||||||
|
labels:
|
||||||
|
{{- include "secrets-operator.labels" . | nindent 4 }}
|
||||||
|
{{- include "secrets-operator.managerRules" . }}
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
metadata:
|
||||||
|
name: {{ include "secrets-operator.fullname" . }}-manager-rolebinding
|
||||||
|
labels:
|
||||||
|
{{- include "secrets-operator.labels" . | nindent 4 }}
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
kind: ClusterRole
|
||||||
|
name: {{ include "secrets-operator.fullname" . }}-manager-role
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: {{ include "secrets-operator.serviceAccountName" . }}
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,53 @@
|
|||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
{{- if and .Values.scopedNamespace .Values.scopedRBAC }}
|
||||||
|
kind: Role
|
||||||
|
{{- else }}
|
||||||
|
kind: ClusterRole
|
||||||
|
{{- end }}
|
||||||
|
metadata:
|
||||||
|
name: {{ include "secrets-operator.fullname" . }}-metrics-auth-role
|
||||||
|
{{- if and .Values.scopedNamespace .Values.scopedRBAC }}
|
||||||
|
namespace: {{ .Values.scopedNamespace | quote }}
|
||||||
|
{{- end }}
|
||||||
|
labels:
|
||||||
|
{{- include "secrets-operator.labels" . | nindent 4 }}
|
||||||
|
rules:
|
||||||
|
- apiGroups:
|
||||||
|
- authentication.k8s.io
|
||||||
|
resources:
|
||||||
|
- tokenreviews
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
- apiGroups:
|
||||||
|
- authorization.k8s.io
|
||||||
|
resources:
|
||||||
|
- subjectaccessreviews
|
||||||
|
verbs:
|
||||||
|
- create
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
{{- if and .Values.scopedNamespace .Values.scopedRBAC }}
|
||||||
|
kind: RoleBinding
|
||||||
|
{{- else }}
|
||||||
|
kind: ClusterRoleBinding
|
||||||
|
{{- end }}
|
||||||
|
metadata:
|
||||||
|
name: {{ include "secrets-operator.fullname" . }}-metrics-auth-rolebinding
|
||||||
|
{{- if and .Values.scopedNamespace .Values.scopedRBAC }}
|
||||||
|
namespace: {{ .Values.scopedNamespace | quote }}
|
||||||
|
{{- end }}
|
||||||
|
labels:
|
||||||
|
|
||||||
|
{{- include "secrets-operator.labels" . | nindent 4 }}
|
||||||
|
roleRef:
|
||||||
|
apiGroup: rbac.authorization.k8s.io
|
||||||
|
{{- if and .Values.scopedNamespace .Values.scopedRBAC }}
|
||||||
|
kind: Role
|
||||||
|
{{- else }}
|
||||||
|
kind: ClusterRole
|
||||||
|
{{- end }}
|
||||||
|
name: '{{ include "secrets-operator.fullname" . }}-metrics-auth-role'
|
||||||
|
subjects:
|
||||||
|
- kind: ServiceAccount
|
||||||
|
name: '{{ include "secrets-operator.serviceAccountName" . }}'
|
||||||
|
namespace: '{{ .Release.Namespace }}'
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
{{- if not .Values.scopedNamespace }}
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
name: {{ include "secrets-operator.fullname" . }}-metrics-reader
|
||||||
|
labels:
|
||||||
|
{{- include "secrets-operator.labels" . | nindent 4 }}
|
||||||
|
rules:
|
||||||
|
- nonResourceURLs:
|
||||||
|
- /metrics
|
||||||
|
verbs:
|
||||||
|
- get
|
||||||
|
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ include "secrets-operator.fullname" . }}-controller-manager-metrics-service
|
||||||
|
labels:
|
||||||
|
control-plane: controller-manager
|
||||||
|
{{- include "secrets-operator.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.metricsService.type }}
|
||||||
|
selector:
|
||||||
|
control-plane: controller-manager
|
||||||
|
{{- include "secrets-operator.selectorLabels" . | nindent 4 }}
|
||||||
|
ports:
|
||||||
|
{{- .Values.metricsService.ports | toYaml | nindent 2 }}
|
||||||
@@ -0,0 +1,32 @@
|
|||||||
|
{{- if .Values.telemetry.serviceMonitor.enabled }}
|
||||||
|
---
|
||||||
|
apiVersion: monitoring.coreos.com/v1
|
||||||
|
kind: ServiceMonitor
|
||||||
|
metadata:
|
||||||
|
name: {{ include "secrets-operator.fullname" . }}-controller-manager-metrics-monitor
|
||||||
|
namespace: {{ .Release.Namespace }}
|
||||||
|
labels:
|
||||||
|
{{- include "secrets-operator.labels" . | nindent 4 }}
|
||||||
|
{{- $selectors := .Values.telemetry.serviceMonitor.selectors }}
|
||||||
|
{{- if $selectors }}
|
||||||
|
{{- toYaml $selectors | nindent 4 }}
|
||||||
|
{{ end }}
|
||||||
|
control-plane: controller-manager
|
||||||
|
release: prometheus
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
control-plane: controller-manager
|
||||||
|
endpoints:
|
||||||
|
- port: {{ .Values.telemetry.serviceMonitor.port }}
|
||||||
|
bearerTokenFile: {{ .Values.telemetry.serviceMonitor.bearerTokenFile }}
|
||||||
|
path: {{ .Values.telemetry.serviceMonitor.path }}
|
||||||
|
scrapeTimeout: {{ .Values.telemetry.serviceMonitor.scrapeTimeout }}
|
||||||
|
interval: {{ .Values.telemetry.serviceMonitor.interval }}
|
||||||
|
scheme: {{ .Values.telemetry.serviceMonitor.scheme }}
|
||||||
|
params:
|
||||||
|
format:
|
||||||
|
- prometheus
|
||||||
|
tlsConfig:
|
||||||
|
insecureSkipVerify: true
|
||||||
|
{{ end }}
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
{{- if and (eq .Values.controllerManager.serviceAccount.create false) (eq .Values.controllerManager.serviceAccount.name "") }}
|
||||||
|
{{- fail "if controllerManager.serviceAccount.create = false, a controllerManager.serviceAccount.name must be provided" }}
|
||||||
|
{{- end }}
|
||||||
|
|
||||||
|
{{- if .Values.controllerManager.serviceAccount.create }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ServiceAccount
|
||||||
|
metadata:
|
||||||
|
name: {{ include "secrets-operator.serviceAccountName" . }}
|
||||||
|
labels:
|
||||||
|
{{- include "secrets-operator.labels" . | nindent 4 }}
|
||||||
|
annotations:
|
||||||
|
{{- toYaml .Values.controllerManager.serviceAccount.annotations | nindent 4 }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,35 @@
|
|||||||
|
{{- if .Values.enableUserRBAC }}
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
name: {{ include "secrets-operator.fullname" . }}-user-admin
|
||||||
|
labels:
|
||||||
|
{{- include "secrets-operator.labels" . | nindent 4 }}
|
||||||
|
rbac.authorization.k8s.io/aggregate-to-admin: "true"
|
||||||
|
rbac.authorization.k8s.io/aggregate-to-edit: "true"
|
||||||
|
rules:
|
||||||
|
- apiGroups: ["secrets.infisical.com"]
|
||||||
|
resources: ["infisicalsecrets", "infisicalpushsecrets", "infisicaldynamicsecrets", "infisicalstaticsecrets", "clustergenerators"]
|
||||||
|
verbs: ["get", "list", "watch", "create", "update", "patch", "delete", "deletecollection"]
|
||||||
|
- apiGroups: ["secrets.infisical.com"]
|
||||||
|
resources: ["infisicalsecrets/status", "infisicalpushsecrets/status", "infisicaldynamicsecrets/status", "infisicalstaticsecrets/status"]
|
||||||
|
verbs: ["get", "list", "watch"]
|
||||||
|
|
||||||
|
---
|
||||||
|
apiVersion: rbac.authorization.k8s.io/v1
|
||||||
|
kind: ClusterRole
|
||||||
|
metadata:
|
||||||
|
name: {{ include "secrets-operator.fullname" . }}-user-view
|
||||||
|
labels:
|
||||||
|
{{- include "secrets-operator.labels" . | nindent 4 }}
|
||||||
|
rbac.authorization.k8s.io/aggregate-to-view: "true"
|
||||||
|
rbac.authorization.k8s.io/aggregate-to-cluster-reader: "true"
|
||||||
|
rules:
|
||||||
|
- apiGroups: ["secrets.infisical.com"]
|
||||||
|
resources: ["infisicalsecrets", "infisicalpushsecrets", "infisicaldynamicsecrets", "infisicalstaticsecrets", "clustergenerators"]
|
||||||
|
verbs: ["get", "list", "watch"]
|
||||||
|
- apiGroups: ["secrets.infisical.com"]
|
||||||
|
resources: ["infisicalsecrets/status", "infisicalpushsecrets/status", "infisicaldynamicsecrets/status", "infisicalstaticsecrets/status"]
|
||||||
|
verbs: ["get", "list", "watch"]
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,87 @@
|
|||||||
|
# -- The Infisical API host URL. This is the default host used when no hostAPI is set on the CRD or global ConfigMap.
|
||||||
|
hostAPI: "https://app.infisical.com/api"
|
||||||
|
|
||||||
|
logger:
|
||||||
|
# -- The output of the logs. Can be "stdout" or "stderr". Defaults to "stderr".
|
||||||
|
writer: "stderr"
|
||||||
|
|
||||||
|
controllerManager:
|
||||||
|
serviceAccount:
|
||||||
|
create: true
|
||||||
|
name: ""
|
||||||
|
annotations: {}
|
||||||
|
nodeSelector: {}
|
||||||
|
tolerations: []
|
||||||
|
affinity: {}
|
||||||
|
topologySpreadConstraints: []
|
||||||
|
# -- Extra volumes to add to the pod
|
||||||
|
extraVolumes: []
|
||||||
|
# -- Extra init containers to add to the pod
|
||||||
|
extraInitContainers: []
|
||||||
|
manager:
|
||||||
|
args:
|
||||||
|
- --metrics-bind-address=:8443
|
||||||
|
- --leader-elect
|
||||||
|
- --health-probe-bind-address=:8081
|
||||||
|
containerSecurityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
|
readOnlyRootFilesystem: true
|
||||||
|
image:
|
||||||
|
repository: infisical/kubernetes-operator
|
||||||
|
tag: v0.11.8
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu: 500m
|
||||||
|
memory: 128Mi
|
||||||
|
requests:
|
||||||
|
cpu: 10m
|
||||||
|
memory: 64Mi
|
||||||
|
# -- Extra environment variables to add to the manager container
|
||||||
|
extraEnv: []
|
||||||
|
# -- Extra volume mounts to add to the manager container
|
||||||
|
extraVolumeMounts: []
|
||||||
|
podSecurityContext:
|
||||||
|
runAsNonRoot: true
|
||||||
|
seccompProfile:
|
||||||
|
type: RuntimeDefault
|
||||||
|
replicas: 1
|
||||||
|
kubernetesClusterDomain: cluster.local
|
||||||
|
|
||||||
|
# DEPRECATED: Use scopedNamespaces instead. This field will be removed in a future version.
|
||||||
|
# If both scopedNamespace and scopedNamespaces are set, scopedNamespaces takes precedence.
|
||||||
|
scopedNamespace: ""
|
||||||
|
|
||||||
|
# List of namespaces to watch. If empty, the operator watches all namespaces (cluster-scoped).
|
||||||
|
# When scopedRBAC is true, a Role and RoleBinding will be created in each namespace.
|
||||||
|
# Example:
|
||||||
|
# scopedNamespaces:
|
||||||
|
# - team-a-namespace
|
||||||
|
# - team-b-namespace
|
||||||
|
scopedNamespaces: []
|
||||||
|
|
||||||
|
scopedRBAC: false
|
||||||
|
installCRDs: true
|
||||||
|
imagePullSecrets: []
|
||||||
|
|
||||||
|
metricsService:
|
||||||
|
ports:
|
||||||
|
- name: https
|
||||||
|
port: 8443
|
||||||
|
protocol: TCP
|
||||||
|
targetPort: 8443
|
||||||
|
type: ClusterIP
|
||||||
|
|
||||||
|
telemetry:
|
||||||
|
serviceMonitor:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
selectors: {}
|
||||||
|
scheme: https
|
||||||
|
port: https
|
||||||
|
path: /metrics
|
||||||
|
bearerTokenFile: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||||
|
interval: 30s
|
||||||
|
scrapeTimeout: 10s
|
||||||
@@ -0,0 +1,12 @@
|
|||||||
|
# secrets-operator 자체 빌드 이미지 배포 테스트 전용 오버라이드 — 차트 기본값 위에 얹어서 쓴다.
|
||||||
|
#
|
||||||
|
# hardened-containers에서 만든 자체 빌드 이미지를 병합·게시 전에 실제 클러스터 동작부터
|
||||||
|
# 확인하기 위한 임시 오버라이드다. docker.io/wbsong111/*는 개인 테스트 푸시이지 카탈로그가
|
||||||
|
# 실제로 참조할 좌표가 아니다 — 정식 반영은 published.json → catalog/image-map/*.env →
|
||||||
|
# catalog-tag-update.yml 경로를 따른다. 이 차트는 애초에 custom-values.yaml이 없다(카탈로그
|
||||||
|
# 값 자체를 건드리지 않는다).
|
||||||
|
controllerManager:
|
||||||
|
manager:
|
||||||
|
image:
|
||||||
|
repository: wbsong111/infisical-secrets-operator
|
||||||
|
tag: v0.11.8-security-hardened-20260827
|
||||||
Reference in New Issue
Block a user