Files
wbsong111 09d0d4e59d secrets-operator v0.10.33 → 0.11.8 (#59)
* chart_version_detector: repo가 이미 등록돼 있으면 update를 건너뛰던 버그를 고친다

repo alias가 이미 helm repo list에 있으면 add/update를 통째로 건너뛰어, 로컬에
예전에 캐시된 index.yaml을 그대로 썼다 — latest_version이 조용히 낡은 값으로
나온다(실측: secrets-operator에서 실제 최신 0.11.8 대신 0.11.4가 나왔다). repo
등록 여부와 무관하게 update는 항상 호출하도록 고친다.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* secrets-operator v0.10.33 → 0.11.8

호환성: breaking_change_check 결과 breaking=false(이 차트는 custom-values.yaml이
없어 오버라이드 충돌 자체가 불가능). CVE: infisical/kubernetes-operator 이미지를
trivy+CoverageProbe로 실측한 결과 실효 HIGH 차단이 34→10건으로 줄었다(CRITICAL은
둘 다 0, 둘 다 CoverageProbe: ok로 측정 신뢰 가능). 신규 CRD 3개
(InfisicalAuth·InfisicalConnection·InfisicalStaticSecret) 추가 — 상세는
CUSTOM-README.md.

기존 v0.10.33 디렉토리는 카탈로그 정책대로 동결 보관한다(삭제하지 않음).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* secrets-operator 자체 빌드 이미지 배포 테스트 오버라이드 추가

dev 클러스터에서 hardened-containers 자체 빌드 이미지(v0.11.8-security-hardened)로
실제 업그레이드·CRD 적용·Infisical 시크릿 동기화까지 검증할 때 쓴 오버라이드.
카탈로그 값(이 차트는 애초에 custom-values.yaml 없음)은 건드리지 않는다.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 09:13:57 +09:00

374 lines
14 KiB
YAML

{{- if .Values.installCRDs }}
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
name: infisicalauths.secrets.infisical.com
annotations:
controller-gen.kubebuilder.io/version: v0.18.0
labels:
{{- include "secrets-operator.labels" . | nindent 4 }}
spec:
group: secrets.infisical.com
names:
kind: InfisicalAuth
listKind: InfisicalAuthList
plural: infisicalauths
singular: infisicalauth
scope: Namespaced
versions:
- additionalPrinterColumns:
- jsonPath: .spec.infisicalConnectionRef.name
name: Connection
type: string
- jsonPath: .spec.method
name: Method
type: string
- jsonPath: .metadata.creationTimestamp
name: Age
type: date
- jsonPath: .status.conditions[?(@.type=="secrets.infisical.com/IsReady")].status
name: Ready
type: string
name: v1beta1
schema:
openAPIV3Schema:
description: InfisicalAuth is the Schema for the InfisicalAuth API.
properties:
apiVersion:
description: |-
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
kind:
description: |-
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
type: object
spec:
properties:
awsIam:
properties:
identityIdRef:
properties:
key:
description: The name of the secret property with the value
type: string
name:
description: The name of the Kubernetes Secret
type: string
namespace:
description: The namespace where the Kubernetes Secret is located
type: string
required:
- key
- name
- namespace
type: object
required:
- identityIdRef
type: object
azure:
properties:
identityIdRef:
properties:
key:
description: The name of the secret property with the value
type: string
name:
description: The name of the Kubernetes Secret
type: string
namespace:
description: The namespace where the Kubernetes Secret is located
type: string
required:
- key
- name
- namespace
type: object
resource:
type: string
required:
- identityIdRef
type: object
gcpIam:
properties:
identityIdRef:
properties:
key:
description: The name of the secret property with the value
type: string
name:
description: The name of the Kubernetes Secret
type: string
namespace:
description: The namespace where the Kubernetes Secret is located
type: string
required:
- key
- name
- namespace
type: object
serviceAccountKeyFilePath:
type: string
required:
- identityIdRef
- serviceAccountKeyFilePath
type: object
gcpIdToken:
properties:
identityIdRef:
properties:
key:
description: The name of the secret property with the value
type: string
name:
description: The name of the Kubernetes Secret
type: string
namespace:
description: The namespace where the Kubernetes Secret is located
type: string
required:
- key
- name
- namespace
type: object
required:
- identityIdRef
type: object
infisicalConnectionRef:
properties:
name:
type: string
namespace:
type: string
required:
- name
- namespace
type: object
kubernetes:
properties:
identityIdRef:
properties:
key:
description: The name of the secret property with the value
type: string
name:
description: The name of the Kubernetes Secret
type: string
namespace:
description: The namespace where the Kubernetes Secret is located
type: string
required:
- key
- name
- namespace
type: object
serviceAccountRef:
properties:
name:
type: string
namespace:
type: string
required:
- name
- namespace
type: object
serviceAccountTokenAudiences:
description: The audiences to use for the service account token.
This is only relevant if `autoCreateServiceAccountToken` is true.
items:
type: string
type: array
required:
- identityIdRef
- serviceAccountRef
type: object
ldap:
properties:
identityIdRef:
properties:
key:
description: The name of the secret property with the value
type: string
name:
description: The name of the Kubernetes Secret
type: string
namespace:
description: The namespace where the Kubernetes Secret is located
type: string
required:
- key
- name
- namespace
type: object
passwordRef:
properties:
key:
description: The name of the secret property with the value
type: string
name:
description: The name of the Kubernetes Secret
type: string
namespace:
description: The namespace where the Kubernetes Secret is located
type: string
required:
- key
- name
- namespace
type: object
usernameRef:
properties:
key:
description: The name of the secret property with the value
type: string
name:
description: The name of the Kubernetes Secret
type: string
namespace:
description: The namespace where the Kubernetes Secret is located
type: string
required:
- key
- name
- namespace
type: object
required:
- identityIdRef
- passwordRef
- usernameRef
type: object
method:
enum:
- universal
- kubernetes
- aws-iam
- azure
- gcp-id-token
- gcp-iam
- ldap
type: string
universal:
properties:
clientIdRef:
properties:
key:
description: The name of the secret property with the value
type: string
name:
description: The name of the Kubernetes Secret
type: string
namespace:
description: The namespace where the Kubernetes Secret is located
type: string
required:
- key
- name
- namespace
type: object
clientSecretRef:
properties:
key:
description: The name of the secret property with the value
type: string
name:
description: The name of the Kubernetes Secret
type: string
namespace:
description: The namespace where the Kubernetes Secret is located
type: string
required:
- key
- name
- namespace
type: object
required:
- clientIdRef
- clientSecretRef
type: object
required:
- infisicalConnectionRef
- method
type: object
status:
description: InfisicalAuthStatus defines the observed state of InfisicalAuth
properties:
conditions:
items:
description: Condition contains details for one aspect of the current
state of this API Resource.
properties:
lastTransitionTime:
description: |-
lastTransitionTime is the last time the condition transitioned from one status to another.
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format: date-time
type: string
message:
description: |-
message is a human readable message indicating details about the transition.
This may be an empty string.
maxLength: 32768
type: string
observedGeneration:
description: |-
observedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.
format: int64
minimum: 0
type: integer
reason:
description: |-
reason contains a programmatic identifier indicating the reason for the condition's last transition.
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.
maxLength: 1024
minLength: 1
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
type: string
status:
description: status of the condition, one of True, False, Unknown.
enum:
- "True"
- "False"
- Unknown
type: string
type:
description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
required:
- lastTransitionTime
- message
- reason
- status
- type
type: object
type: array
required:
- conditions
type: object
type: object
served: true
storage: true
subresources:
status: {}
status:
acceptedNames:
kind: ""
plural: ""
conditions: []
storedVersions: []
{{- end }}