{{- if .Values.installCRDs }} apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: name: infisicalauths.secrets.infisical.com annotations: controller-gen.kubebuilder.io/version: v0.18.0 labels: {{- include "secrets-operator.labels" . | nindent 4 }} spec: group: secrets.infisical.com names: kind: InfisicalAuth listKind: InfisicalAuthList plural: infisicalauths singular: infisicalauth scope: Namespaced versions: - additionalPrinterColumns: - jsonPath: .spec.infisicalConnectionRef.name name: Connection type: string - jsonPath: .spec.method name: Method type: string - jsonPath: .metadata.creationTimestamp name: Age type: date - jsonPath: .status.conditions[?(@.type=="secrets.infisical.com/IsReady")].status name: Ready type: string name: v1beta1 schema: openAPIV3Schema: description: InfisicalAuth is the Schema for the InfisicalAuth API. properties: apiVersion: description: |- APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources type: string kind: description: |- Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds type: string metadata: type: object spec: properties: awsIam: properties: identityIdRef: properties: key: description: The name of the secret property with the value type: string name: description: The name of the Kubernetes Secret type: string namespace: description: The namespace where the Kubernetes Secret is located type: string required: - key - name - namespace type: object required: - identityIdRef type: object azure: properties: identityIdRef: properties: key: description: The name of the secret property with the value type: string name: description: The name of the Kubernetes Secret type: string namespace: description: The namespace where the Kubernetes Secret is located type: string required: - key - name - namespace type: object resource: type: string required: - identityIdRef type: object gcpIam: properties: identityIdRef: properties: key: description: The name of the secret property with the value type: string name: description: The name of the Kubernetes Secret type: string namespace: description: The namespace where the Kubernetes Secret is located type: string required: - key - name - namespace type: object serviceAccountKeyFilePath: type: string required: - identityIdRef - serviceAccountKeyFilePath type: object gcpIdToken: properties: identityIdRef: properties: key: description: The name of the secret property with the value type: string name: description: The name of the Kubernetes Secret type: string namespace: description: The namespace where the Kubernetes Secret is located type: string required: - key - name - namespace type: object required: - identityIdRef type: object infisicalConnectionRef: properties: name: type: string namespace: type: string required: - name - namespace type: object kubernetes: properties: identityIdRef: properties: key: description: The name of the secret property with the value type: string name: description: The name of the Kubernetes Secret type: string namespace: description: The namespace where the Kubernetes Secret is located type: string required: - key - name - namespace type: object serviceAccountRef: properties: name: type: string namespace: type: string required: - name - namespace type: object serviceAccountTokenAudiences: description: The audiences to use for the service account token. This is only relevant if `autoCreateServiceAccountToken` is true. items: type: string type: array required: - identityIdRef - serviceAccountRef type: object ldap: properties: identityIdRef: properties: key: description: The name of the secret property with the value type: string name: description: The name of the Kubernetes Secret type: string namespace: description: The namespace where the Kubernetes Secret is located type: string required: - key - name - namespace type: object passwordRef: properties: key: description: The name of the secret property with the value type: string name: description: The name of the Kubernetes Secret type: string namespace: description: The namespace where the Kubernetes Secret is located type: string required: - key - name - namespace type: object usernameRef: properties: key: description: The name of the secret property with the value type: string name: description: The name of the Kubernetes Secret type: string namespace: description: The namespace where the Kubernetes Secret is located type: string required: - key - name - namespace type: object required: - identityIdRef - passwordRef - usernameRef type: object method: enum: - universal - kubernetes - aws-iam - azure - gcp-id-token - gcp-iam - ldap type: string universal: properties: clientIdRef: properties: key: description: The name of the secret property with the value type: string name: description: The name of the Kubernetes Secret type: string namespace: description: The namespace where the Kubernetes Secret is located type: string required: - key - name - namespace type: object clientSecretRef: properties: key: description: The name of the secret property with the value type: string name: description: The name of the Kubernetes Secret type: string namespace: description: The namespace where the Kubernetes Secret is located type: string required: - key - name - namespace type: object required: - clientIdRef - clientSecretRef type: object required: - infisicalConnectionRef - method type: object status: description: InfisicalAuthStatus defines the observed state of InfisicalAuth properties: conditions: items: description: Condition contains details for one aspect of the current state of this API Resource. properties: lastTransitionTime: description: |- lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. format: date-time type: string message: description: |- message is a human readable message indicating details about the transition. This may be an empty string. maxLength: 32768 type: string observedGeneration: description: |- observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance. format: int64 minimum: 0 type: integer reason: description: |- reason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty. maxLength: 1024 minLength: 1 pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ type: string status: description: status of the condition, one of True, False, Unknown. enum: - "True" - "False" - Unknown type: string type: description: type of condition in CamelCase or in foo.example.com/CamelCase. maxLength: 316 pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ type: string required: - lastTransitionTime - message - reason - status - type type: object type: array required: - conditions type: object type: object served: true storage: true subresources: status: {} status: acceptedNames: kind: "" plural: "" conditions: [] storedVersions: [] {{- end }}