387 lines
18 KiB
YAML
387 lines
18 KiB
YAML
# Copyright (c) HashiCorp, Inc.
|
|
# SPDX-License-Identifier: BUSL-1.1
|
|
|
|
---
|
|
apiVersion: apiextensions.k8s.io/v1
|
|
kind: CustomResourceDefinition
|
|
metadata:
|
|
annotations:
|
|
controller-gen.kubebuilder.io/version: v0.16.3
|
|
name: vaultpkisecrets.secrets.hashicorp.com
|
|
spec:
|
|
group: secrets.hashicorp.com
|
|
names:
|
|
kind: VaultPKISecret
|
|
listKind: VaultPKISecretList
|
|
plural: vaultpkisecrets
|
|
singular: vaultpkisecret
|
|
scope: Namespaced
|
|
versions:
|
|
- name: v1beta1
|
|
schema:
|
|
openAPIV3Schema:
|
|
description: VaultPKISecret is the Schema for the vaultpkisecrets API
|
|
properties:
|
|
apiVersion:
|
|
description: |-
|
|
APIVersion defines the versioned schema of this representation of an object.
|
|
Servers should convert recognized schemas to the latest internal value, and
|
|
may reject unrecognized values.
|
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
|
type: string
|
|
kind:
|
|
description: |-
|
|
Kind is a string value representing the REST resource this object represents.
|
|
Servers may infer this from the endpoint the client submits requests to.
|
|
Cannot be updated.
|
|
In CamelCase.
|
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
type: string
|
|
metadata:
|
|
type: object
|
|
spec:
|
|
description: VaultPKISecretSpec defines the desired state of VaultPKISecret
|
|
properties:
|
|
altNames:
|
|
description: |-
|
|
AltNames to include in the request
|
|
May contain both DNS names and email addresses.
|
|
items:
|
|
type: string
|
|
type: array
|
|
clear:
|
|
description: Clear the Kubernetes secret when the resource is deleted.
|
|
type: boolean
|
|
commonName:
|
|
description: CommonName to include in the request.
|
|
type: string
|
|
destination:
|
|
description: |-
|
|
Destination provides configuration necessary for syncing the Vault secret
|
|
to Kubernetes. If the type is set to "kubernetes.io/tls", "tls.key" will
|
|
be set to the "private_key" response from Vault, and "tls.crt" will be
|
|
set to "certificate" + "ca_chain" from the Vault response ("issuing_ca"
|
|
is used when "ca_chain" is empty). The "remove_roots_from_chain=true"
|
|
option is used with Vault to exclude the root CA from the Vault response.
|
|
properties:
|
|
annotations:
|
|
additionalProperties:
|
|
type: string
|
|
description: Annotations to apply to the Secret. Requires Create
|
|
to be set to true.
|
|
type: object
|
|
create:
|
|
default: false
|
|
description: |-
|
|
Create the destination Secret.
|
|
If the Secret already exists this should be set to false.
|
|
type: boolean
|
|
labels:
|
|
additionalProperties:
|
|
type: string
|
|
description: Labels to apply to the Secret. Requires Create to
|
|
be set to true.
|
|
type: object
|
|
name:
|
|
description: Name of the Secret
|
|
type: string
|
|
overwrite:
|
|
default: false
|
|
description: |-
|
|
Overwrite the destination Secret if it exists and Create is true. This is
|
|
useful when migrating to VSO from a previous secret deployment strategy.
|
|
type: boolean
|
|
transformation:
|
|
description: |-
|
|
Transformation provides configuration for transforming the secret data before
|
|
it is stored in the Destination.
|
|
properties:
|
|
excludeRaw:
|
|
description: |-
|
|
ExcludeRaw data from the destination Secret. Exclusion policy can be set
|
|
globally by including 'exclude-raw` in the '--global-transformation-options'
|
|
command line flag. If set, the command line flag always takes precedence over
|
|
this configuration.
|
|
type: boolean
|
|
excludes:
|
|
description: |-
|
|
Excludes contains regex patterns used to filter top-level source secret data
|
|
fields for exclusion from the final K8s Secret data. These pattern filters are
|
|
never applied to templated fields as defined in Templates. They are always
|
|
applied before any inclusion patterns. To exclude all source secret data
|
|
fields, you can configure the single pattern ".*".
|
|
items:
|
|
type: string
|
|
type: array
|
|
includes:
|
|
description: |-
|
|
Includes contains regex patterns used to filter top-level source secret data
|
|
fields for inclusion in the final K8s Secret data. These pattern filters are
|
|
never applied to templated fields as defined in Templates. They are always
|
|
applied last.
|
|
items:
|
|
type: string
|
|
type: array
|
|
templates:
|
|
additionalProperties:
|
|
description: Template provides templating configuration.
|
|
properties:
|
|
name:
|
|
description: Name of the Template
|
|
type: string
|
|
text:
|
|
description: |-
|
|
Text contains the Go text template format. The template
|
|
references attributes from the data structure of the source secret.
|
|
Refer to https://pkg.go.dev/text/template for more information.
|
|
type: string
|
|
required:
|
|
- text
|
|
type: object
|
|
description: |-
|
|
Templates maps a template name to its Template. Templates are always included
|
|
in the rendered K8s Secret, and take precedence over templates defined in a
|
|
SecretTransformation.
|
|
type: object
|
|
transformationRefs:
|
|
description: |-
|
|
TransformationRefs contain references to template configuration from
|
|
SecretTransformation.
|
|
items:
|
|
description: |-
|
|
TransformationRef contains the configuration for accessing templates from an
|
|
SecretTransformation resource. TransformationRefs can be shared across all
|
|
syncable secret custom resources.
|
|
properties:
|
|
ignoreExcludes:
|
|
description: |-
|
|
IgnoreExcludes controls whether to use the SecretTransformation's Excludes
|
|
data key filters.
|
|
type: boolean
|
|
ignoreIncludes:
|
|
description: |-
|
|
IgnoreIncludes controls whether to use the SecretTransformation's Includes
|
|
data key filters.
|
|
type: boolean
|
|
name:
|
|
description: Name of the SecretTransformation resource.
|
|
type: string
|
|
namespace:
|
|
description: Namespace of the SecretTransformation resource.
|
|
type: string
|
|
templateRefs:
|
|
description: |-
|
|
TemplateRefs map to a Template found in this TransformationRef. If empty, then
|
|
all templates from the SecretTransformation will be rendered to the K8s Secret.
|
|
items:
|
|
description: |-
|
|
TemplateRef points to templating text that is stored in a
|
|
SecretTransformation custom resource.
|
|
properties:
|
|
keyOverride:
|
|
description: |-
|
|
KeyOverride to the rendered template in the Destination secret. If Key is
|
|
empty, then the Key from reference spec will be used. Set this to override the
|
|
Key set from the reference spec.
|
|
type: string
|
|
name:
|
|
description: |-
|
|
Name of the Template in SecretTransformationSpec.Templates.
|
|
the rendered secret data.
|
|
type: string
|
|
required:
|
|
- name
|
|
type: object
|
|
type: array
|
|
required:
|
|
- name
|
|
type: object
|
|
type: array
|
|
type: object
|
|
type:
|
|
description: |-
|
|
Type of Kubernetes Secret. Requires Create to be set to true.
|
|
Defaults to Opaque.
|
|
type: string
|
|
required:
|
|
- name
|
|
type: object
|
|
excludeCNFromSans:
|
|
description: |-
|
|
ExcludeCNFromSans from DNS or Email Subject Alternate Names.
|
|
Default: false
|
|
type: boolean
|
|
expiryOffset:
|
|
description: |-
|
|
ExpiryOffset to use for computing when the certificate should be renewed.
|
|
The rotation time will be difference between the expiration and the offset.
|
|
Should be in duration notation e.g. 30s, 120s, etc.
|
|
pattern: ^([0-9]+(\.[0-9]+)?(s|m|h))$
|
|
type: string
|
|
format:
|
|
description: |-
|
|
Format for the certificate. Choices: "pem", "der", "pem_bundle".
|
|
If "pem_bundle",
|
|
any private key and issuing cert will be appended to the certificate pem.
|
|
If "der", the value will be base64 encoded.
|
|
Default: pem
|
|
type: string
|
|
ipSans:
|
|
description: IPSans to include in the request.
|
|
items:
|
|
type: string
|
|
type: array
|
|
issuerRef:
|
|
description: |-
|
|
IssuerRef reference to an existing PKI issuer, either by Vault-generated
|
|
identifier, the literal string default to refer to the currently
|
|
configured default issuer, or the name assigned to an issuer.
|
|
This parameter is part of the request URL.
|
|
type: string
|
|
mount:
|
|
description: Mount for the secret in Vault
|
|
type: string
|
|
namespace:
|
|
description: |-
|
|
Namespace of the secrets engine mount in Vault. If not set, the namespace that's
|
|
part of VaultAuth resource will be inferred.
|
|
type: string
|
|
notAfter:
|
|
description: |-
|
|
NotAfter field of the certificate with specified date value.
|
|
The value format should be given in UTC format YYYY-MM-ddTHH:MM:SSZ
|
|
type: string
|
|
otherSans:
|
|
description: |-
|
|
Requested other SANs, in an array with the format
|
|
oid;type:value for each entry.
|
|
items:
|
|
type: string
|
|
type: array
|
|
privateKeyFormat:
|
|
description: |-
|
|
PrivateKeyFormat, generally the default will be controlled by the Format
|
|
parameter as either base64-encoded DER or PEM-encoded DER.
|
|
However, this can be set to "pkcs8" to have the returned
|
|
private key contain base64-encoded pkcs8 or PEM-encoded
|
|
pkcs8 instead.
|
|
Default: der
|
|
type: string
|
|
revoke:
|
|
description: Revoke the certificate when the resource is deleted.
|
|
type: boolean
|
|
role:
|
|
description: Role in Vault to use when issuing TLS certificates.
|
|
type: string
|
|
rolloutRestartTargets:
|
|
description: |-
|
|
RolloutRestartTargets should be configured whenever the application(s) consuming the Vault secret does
|
|
not support dynamically reloading a rotated secret.
|
|
In that case one, or more RolloutRestartTarget(s) can be configured here. The Operator will
|
|
trigger a "rollout-restart" for each target whenever the Vault secret changes between reconciliation events.
|
|
See RolloutRestartTarget for more details.
|
|
items:
|
|
description: |-
|
|
RolloutRestartTarget provides the configuration required to perform a
|
|
rollout-restart of the supported resources upon Vault Secret rotation.
|
|
The rollout-restart is triggered by patching the target resource's
|
|
'spec.template.metadata.annotations' to include 'vso.secrets.hashicorp.com/restartedAt'
|
|
with a timestamp value of when the trigger was executed.
|
|
E.g. vso.secrets.hashicorp.com/restartedAt: "2023-03-23T13:39:31Z"
|
|
|
|
Supported resources: Deployment, DaemonSet, StatefulSet, argo.Rollout
|
|
properties:
|
|
kind:
|
|
description: Kind of the resource
|
|
enum:
|
|
- Deployment
|
|
- DaemonSet
|
|
- StatefulSet
|
|
- argo.Rollout
|
|
type: string
|
|
name:
|
|
description: Name of the resource
|
|
type: string
|
|
required:
|
|
- kind
|
|
- name
|
|
type: object
|
|
type: array
|
|
ttl:
|
|
description: |-
|
|
TTL for the certificate; sets the expiration date.
|
|
If not specified the Vault role's default,
|
|
backend default, or system default TTL is used, in that order.
|
|
Cannot be larger than the mount's max TTL.
|
|
Note: this only has an effect when generating a CA cert or signing a CA cert,
|
|
not when generating a CSR for an intermediate CA.
|
|
Should be in duration notation e.g. 120s, 2h, etc.
|
|
pattern: ^([0-9]+(\.[0-9]+)?(s|m|h|d))$
|
|
type: string
|
|
uriSans:
|
|
description: The requested URI SANs.
|
|
items:
|
|
type: string
|
|
type: array
|
|
userIDs:
|
|
description: |-
|
|
User ID (OID 0.9.2342.19200300.100.1.1) Subject values to be placed on the
|
|
signed certificate.
|
|
items:
|
|
type: string
|
|
type: array
|
|
vaultAuthRef:
|
|
description: |-
|
|
VaultAuthRef to the VaultAuth resource, can be prefixed with a namespace,
|
|
eg: `namespaceA/vaultAuthRefB`. If no namespace prefix is provided it will default to
|
|
the namespace of the VaultAuth CR. If no value is specified for VaultAuthRef the Operator
|
|
will default to the `default` VaultAuth, configured in the operator's namespace.
|
|
type: string
|
|
required:
|
|
- destination
|
|
- mount
|
|
- role
|
|
type: object
|
|
status:
|
|
description: VaultPKISecretStatus defines the observed state of VaultPKISecret
|
|
properties:
|
|
error:
|
|
type: string
|
|
expiration:
|
|
format: int64
|
|
type: integer
|
|
lastGeneration:
|
|
description: LastGeneration is the Generation of the last reconciled
|
|
resource.
|
|
format: int64
|
|
type: integer
|
|
lastRotation:
|
|
description: LastLastRotation of the certificate.
|
|
format: int64
|
|
type: integer
|
|
secretMAC:
|
|
description: |-
|
|
SecretMAC used when deciding whether new Vault secret data should be synced.
|
|
|
|
The controller will compare the "new" Vault secret data to this value using HMAC,
|
|
if they are different, then the data will be synced to the Destination.
|
|
|
|
The SecretMac is also used to detect drift in the Destination Secret's Data.
|
|
If drift is detected the data will be synced to the Destination.
|
|
type: string
|
|
serialNumber:
|
|
type: string
|
|
valid:
|
|
type: boolean
|
|
required:
|
|
- error
|
|
- lastGeneration
|
|
- lastRotation
|
|
- valid
|
|
type: object
|
|
type: object
|
|
served: true
|
|
storage: true
|
|
subresources:
|
|
status: {}
|