411 lines
20 KiB
YAML
411 lines
20 KiB
YAML
# Copyright (c) HashiCorp, Inc.
|
|
# SPDX-License-Identifier: BUSL-1.1
|
|
|
|
---
|
|
apiVersion: apiextensions.k8s.io/v1
|
|
kind: CustomResourceDefinition
|
|
metadata:
|
|
annotations:
|
|
controller-gen.kubebuilder.io/version: v0.16.3
|
|
name: vaultdynamicsecrets.secrets.hashicorp.com
|
|
spec:
|
|
group: secrets.hashicorp.com
|
|
names:
|
|
kind: VaultDynamicSecret
|
|
listKind: VaultDynamicSecretList
|
|
plural: vaultdynamicsecrets
|
|
singular: vaultdynamicsecret
|
|
scope: Namespaced
|
|
versions:
|
|
- name: v1beta1
|
|
schema:
|
|
openAPIV3Schema:
|
|
description: VaultDynamicSecret is the Schema for the vaultdynamicsecrets
|
|
API
|
|
properties:
|
|
apiVersion:
|
|
description: |-
|
|
APIVersion defines the versioned schema of this representation of an object.
|
|
Servers should convert recognized schemas to the latest internal value, and
|
|
may reject unrecognized values.
|
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
|
type: string
|
|
kind:
|
|
description: |-
|
|
Kind is a string value representing the REST resource this object represents.
|
|
Servers may infer this from the endpoint the client submits requests to.
|
|
Cannot be updated.
|
|
In CamelCase.
|
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
type: string
|
|
metadata:
|
|
type: object
|
|
spec:
|
|
description: VaultDynamicSecretSpec defines the desired state of VaultDynamicSecret
|
|
properties:
|
|
allowStaticCreds:
|
|
description: |-
|
|
AllowStaticCreds should be set when syncing credentials that are periodically
|
|
rotated by the Vault server, rather than created upon request. These secrets
|
|
are sometimes referred to as "static roles", or "static credentials", with a
|
|
request path that contains "static-creds".
|
|
type: boolean
|
|
destination:
|
|
description: Destination provides configuration necessary for syncing
|
|
the Vault secret to Kubernetes.
|
|
properties:
|
|
annotations:
|
|
additionalProperties:
|
|
type: string
|
|
description: Annotations to apply to the Secret. Requires Create
|
|
to be set to true.
|
|
type: object
|
|
create:
|
|
default: false
|
|
description: |-
|
|
Create the destination Secret.
|
|
If the Secret already exists this should be set to false.
|
|
type: boolean
|
|
labels:
|
|
additionalProperties:
|
|
type: string
|
|
description: Labels to apply to the Secret. Requires Create to
|
|
be set to true.
|
|
type: object
|
|
name:
|
|
description: Name of the Secret
|
|
type: string
|
|
overwrite:
|
|
default: false
|
|
description: |-
|
|
Overwrite the destination Secret if it exists and Create is true. This is
|
|
useful when migrating to VSO from a previous secret deployment strategy.
|
|
type: boolean
|
|
transformation:
|
|
description: |-
|
|
Transformation provides configuration for transforming the secret data before
|
|
it is stored in the Destination.
|
|
properties:
|
|
excludeRaw:
|
|
description: |-
|
|
ExcludeRaw data from the destination Secret. Exclusion policy can be set
|
|
globally by including 'exclude-raw` in the '--global-transformation-options'
|
|
command line flag. If set, the command line flag always takes precedence over
|
|
this configuration.
|
|
type: boolean
|
|
excludes:
|
|
description: |-
|
|
Excludes contains regex patterns used to filter top-level source secret data
|
|
fields for exclusion from the final K8s Secret data. These pattern filters are
|
|
never applied to templated fields as defined in Templates. They are always
|
|
applied before any inclusion patterns. To exclude all source secret data
|
|
fields, you can configure the single pattern ".*".
|
|
items:
|
|
type: string
|
|
type: array
|
|
includes:
|
|
description: |-
|
|
Includes contains regex patterns used to filter top-level source secret data
|
|
fields for inclusion in the final K8s Secret data. These pattern filters are
|
|
never applied to templated fields as defined in Templates. They are always
|
|
applied last.
|
|
items:
|
|
type: string
|
|
type: array
|
|
templates:
|
|
additionalProperties:
|
|
description: Template provides templating configuration.
|
|
properties:
|
|
name:
|
|
description: Name of the Template
|
|
type: string
|
|
text:
|
|
description: |-
|
|
Text contains the Go text template format. The template
|
|
references attributes from the data structure of the source secret.
|
|
Refer to https://pkg.go.dev/text/template for more information.
|
|
type: string
|
|
required:
|
|
- text
|
|
type: object
|
|
description: |-
|
|
Templates maps a template name to its Template. Templates are always included
|
|
in the rendered K8s Secret, and take precedence over templates defined in a
|
|
SecretTransformation.
|
|
type: object
|
|
transformationRefs:
|
|
description: |-
|
|
TransformationRefs contain references to template configuration from
|
|
SecretTransformation.
|
|
items:
|
|
description: |-
|
|
TransformationRef contains the configuration for accessing templates from an
|
|
SecretTransformation resource. TransformationRefs can be shared across all
|
|
syncable secret custom resources.
|
|
properties:
|
|
ignoreExcludes:
|
|
description: |-
|
|
IgnoreExcludes controls whether to use the SecretTransformation's Excludes
|
|
data key filters.
|
|
type: boolean
|
|
ignoreIncludes:
|
|
description: |-
|
|
IgnoreIncludes controls whether to use the SecretTransformation's Includes
|
|
data key filters.
|
|
type: boolean
|
|
name:
|
|
description: Name of the SecretTransformation resource.
|
|
type: string
|
|
namespace:
|
|
description: Namespace of the SecretTransformation resource.
|
|
type: string
|
|
templateRefs:
|
|
description: |-
|
|
TemplateRefs map to a Template found in this TransformationRef. If empty, then
|
|
all templates from the SecretTransformation will be rendered to the K8s Secret.
|
|
items:
|
|
description: |-
|
|
TemplateRef points to templating text that is stored in a
|
|
SecretTransformation custom resource.
|
|
properties:
|
|
keyOverride:
|
|
description: |-
|
|
KeyOverride to the rendered template in the Destination secret. If Key is
|
|
empty, then the Key from reference spec will be used. Set this to override the
|
|
Key set from the reference spec.
|
|
type: string
|
|
name:
|
|
description: |-
|
|
Name of the Template in SecretTransformationSpec.Templates.
|
|
the rendered secret data.
|
|
type: string
|
|
required:
|
|
- name
|
|
type: object
|
|
type: array
|
|
required:
|
|
- name
|
|
type: object
|
|
type: array
|
|
type: object
|
|
type:
|
|
description: |-
|
|
Type of Kubernetes Secret. Requires Create to be set to true.
|
|
Defaults to Opaque.
|
|
type: string
|
|
required:
|
|
- name
|
|
type: object
|
|
mount:
|
|
description: Mount path of the secret's engine in Vault.
|
|
type: string
|
|
namespace:
|
|
description: |-
|
|
Namespace of the secrets engine mount in Vault. If not set, the namespace that's
|
|
part of VaultAuth resource will be inferred.
|
|
type: string
|
|
params:
|
|
additionalProperties:
|
|
type: string
|
|
description: |-
|
|
Params that can be passed when requesting credentials/secrets.
|
|
When Params is set the configured RequestHTTPMethod will be
|
|
ignored. See RequestHTTPMethod for more details.
|
|
Please consult https://developer.hashicorp.com/vault/docs/secrets if you are
|
|
uncertain about what 'params' should/can be set to.
|
|
type: object
|
|
path:
|
|
description: |-
|
|
Path in Vault to get the credentials for, and is relative to Mount.
|
|
Please consult https://developer.hashicorp.com/vault/docs/secrets if you are
|
|
uncertain about what 'path' should be set to.
|
|
type: string
|
|
refreshAfter:
|
|
description: |-
|
|
RefreshAfter a period of time for VSO to sync the source secret data, in
|
|
duration notation e.g. 30s, 1m, 24h. This value only needs to be set when
|
|
syncing from a secret's engine that does not provide a lease TTL in its
|
|
response. The value should be within the secret engine's configured ttl or
|
|
max_ttl. The source secret's lease duration takes precedence over this
|
|
configuration when it is greater than 0.
|
|
pattern: ^([0-9]+(\.[0-9]+)?(s|m|h))$
|
|
type: string
|
|
renewalPercent:
|
|
default: 67
|
|
description: |-
|
|
RenewalPercent is the percent out of 100 of the lease duration when the
|
|
lease is renewed. Defaults to 67 percent plus jitter.
|
|
maximum: 90
|
|
minimum: 0
|
|
type: integer
|
|
requestHTTPMethod:
|
|
description: |-
|
|
RequestHTTPMethod to use when syncing Secrets from Vault.
|
|
Setting a value here is not typically required.
|
|
If left unset the Operator will make requests using the GET method.
|
|
In the case where Params are specified the Operator will use the PUT method.
|
|
Please consult https://developer.hashicorp.com/vault/docs/secrets if you are
|
|
uncertain about what method to use.
|
|
Of note, the Vault client treats PUT and POST as being equivalent.
|
|
The underlying Vault client implementation will always use the PUT method.
|
|
enum:
|
|
- GET
|
|
- POST
|
|
- PUT
|
|
type: string
|
|
revoke:
|
|
description: Revoke the existing lease on VDS resource deletion.
|
|
type: boolean
|
|
rolloutRestartTargets:
|
|
description: |-
|
|
RolloutRestartTargets should be configured whenever the application(s) consuming the Vault secret does
|
|
not support dynamically reloading a rotated secret.
|
|
In that case one, or more RolloutRestartTarget(s) can be configured here. The Operator will
|
|
trigger a "rollout-restart" for each target whenever the Vault secret changes between reconciliation events.
|
|
See RolloutRestartTarget for more details.
|
|
items:
|
|
description: |-
|
|
RolloutRestartTarget provides the configuration required to perform a
|
|
rollout-restart of the supported resources upon Vault Secret rotation.
|
|
The rollout-restart is triggered by patching the target resource's
|
|
'spec.template.metadata.annotations' to include 'vso.secrets.hashicorp.com/restartedAt'
|
|
with a timestamp value of when the trigger was executed.
|
|
E.g. vso.secrets.hashicorp.com/restartedAt: "2023-03-23T13:39:31Z"
|
|
|
|
Supported resources: Deployment, DaemonSet, StatefulSet, argo.Rollout
|
|
properties:
|
|
kind:
|
|
description: Kind of the resource
|
|
enum:
|
|
- Deployment
|
|
- DaemonSet
|
|
- StatefulSet
|
|
- argo.Rollout
|
|
type: string
|
|
name:
|
|
description: Name of the resource
|
|
type: string
|
|
required:
|
|
- kind
|
|
- name
|
|
type: object
|
|
type: array
|
|
vaultAuthRef:
|
|
description: |-
|
|
VaultAuthRef to the VaultAuth resource, can be prefixed with a namespace,
|
|
eg: `namespaceA/vaultAuthRefB`. If no namespace prefix is provided it will default to
|
|
the namespace of the VaultAuth CR. If no value is specified for VaultAuthRef the Operator
|
|
will default to the `default` VaultAuth, configured in the operator's namespace.
|
|
type: string
|
|
required:
|
|
- destination
|
|
- mount
|
|
- path
|
|
type: object
|
|
status:
|
|
description: VaultDynamicSecretStatus defines the observed state of VaultDynamicSecret
|
|
properties:
|
|
lastGeneration:
|
|
description: LastGeneration is the Generation of the last reconciled
|
|
resource.
|
|
format: int64
|
|
type: integer
|
|
lastRenewalTime:
|
|
description: LastRenewalTime of the last successful secret lease renewal.
|
|
format: int64
|
|
type: integer
|
|
lastRuntimePodUID:
|
|
description: |-
|
|
LastRuntimePodUID used for tracking the transition from one Pod to the next.
|
|
It is used to mitigate the effects of a Vault lease renewal storm.
|
|
type: string
|
|
secretLease:
|
|
description: SecretLease for the Vault secret.
|
|
properties:
|
|
duration:
|
|
description: LeaseDuration of the Vault secret.
|
|
type: integer
|
|
id:
|
|
description: ID of the Vault secret.
|
|
type: string
|
|
renewable:
|
|
description: Renewable Vault secret lease
|
|
type: boolean
|
|
requestID:
|
|
description: RequestID of the Vault secret request.
|
|
type: string
|
|
required:
|
|
- duration
|
|
- id
|
|
- renewable
|
|
- requestID
|
|
type: object
|
|
secretMAC:
|
|
description: |-
|
|
SecretMAC used when deciding whether new Vault secret data should be synced.
|
|
|
|
The controller will compare the "new" Vault secret data to this value using HMAC,
|
|
if they are different, then the data will be synced to the Destination.
|
|
|
|
The SecretMac is also used to detect drift in the Destination Secret's Data.
|
|
If drift is detected the data will be synced to the Destination.
|
|
SecretMAC will only be stored when VaultDynamicSecretSpec.AllowStaticCreds is true.
|
|
type: string
|
|
staticCredsMetaData:
|
|
description: StaticCredsMetaData contains the static creds response
|
|
meta-data
|
|
properties:
|
|
lastVaultRotation:
|
|
description: LastVaultRotation represents the last time Vault
|
|
rotated the password
|
|
format: int64
|
|
type: integer
|
|
rotationPeriod:
|
|
description: |-
|
|
RotationPeriod is number in seconds between each rotation, effectively a
|
|
"time to live". This value is compared to the LastVaultRotation to
|
|
determine if a password needs to be rotated
|
|
format: int64
|
|
type: integer
|
|
rotationSchedule:
|
|
description: |-
|
|
RotationSchedule is a "cron style" string representing the allowed
|
|
schedule for each rotation.
|
|
e.g. "1 0 * * *" would rotate at one minute past midnight (00:01) every
|
|
day.
|
|
type: string
|
|
ttl:
|
|
description: TTL is the seconds remaining before the next rotation.
|
|
format: int64
|
|
type: integer
|
|
required:
|
|
- lastVaultRotation
|
|
- rotationPeriod
|
|
- ttl
|
|
type: object
|
|
vaultClientMeta:
|
|
description: |-
|
|
VaultClientMeta contains the status of the Vault client and is used during
|
|
resource reconciliation.
|
|
properties:
|
|
cacheKey:
|
|
description: CacheKey is the unique key used to identify the client
|
|
cache.
|
|
type: string
|
|
id:
|
|
description: |-
|
|
ID is the Vault ID of the authenticated client. The ID should never contain
|
|
any sensitive information.
|
|
type: string
|
|
type: object
|
|
required:
|
|
- lastGeneration
|
|
- lastRenewalTime
|
|
- secretLease
|
|
type: object
|
|
type: object
|
|
served: true
|
|
storage: true
|
|
subresources:
|
|
status: {}
|