# Copyright (c) HashiCorp, Inc. # SPDX-License-Identifier: BUSL-1.1 --- apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: controller-gen.kubebuilder.io/version: v0.16.3 name: vaultconnections.secrets.hashicorp.com spec: group: secrets.hashicorp.com names: kind: VaultConnection listKind: VaultConnectionList plural: vaultconnections singular: vaultconnection scope: Namespaced versions: - name: v1beta1 schema: openAPIV3Schema: description: VaultConnection is the Schema for the vaultconnections API properties: apiVersion: description: |- APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources type: string kind: description: |- Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds type: string metadata: type: object spec: description: VaultConnectionSpec defines the desired state of VaultConnection properties: address: description: Address of the Vault server type: string caCertSecretRef: description: CACertSecretRef is the name of a Kubernetes secret containing the trusted PEM encoded CA certificate chain as `ca.crt`. type: string headers: additionalProperties: type: string description: Headers to be included in all Vault requests. type: object skipTLSVerify: default: false description: SkipTLSVerify for TLS connections. type: boolean timeout: description: |- Timeout applied to all Vault requests for this connection. If not set, the default timeout from the Vault API client config is used. pattern: ^([0-9]+(\.[0-9]+)?(s|m|h))$ type: string tlsServerName: description: TLSServerName to use as the SNI host for TLS connections. type: string required: - address - skipTLSVerify type: object status: description: VaultConnectionStatus defines the observed state of VaultConnection properties: valid: description: Valid auth mechanism. type: boolean required: - valid type: object type: object served: true storage: true subresources: status: {}