Skip to content

externalSecrets

ExternalSecret objects to be generated by the chart. Each key is an ExternalSecret identifier.

object

Keys are identifiers for externalSecrets instances.

externalSecrets:
main:
enabled: true
# ... configuration
secondary:
enabled: true
# ... configuration

Available properties:

PropertyTypeRequiredDefaultDescription
annotationsobject / nullNo-Annotations to set on the item.
dataarrayNo-Mappings between Kubernetes Secret keys and provider data…
dataFromarrayNo-Provider data sources whose values are merged into the ta…
enabledbooleanNotrueSet to false to disable the ExternalSecret.
forceRenamestringNo-Override the default resource name. Mutually exclusive wi…
labelsobject / nullNo-Labels to set on the item.
prefixstringNo“Prefix to prepend to the resource name. Mutually exclusiv…
refreshIntervalstringNo-Amount of time before values are read again from the Secr…
refreshPolicystringNo-Policy controlling when the ExternalSecret is refreshed.
secretStoreRefobjectNo-SecretStore or ClusterSecretStore to fetch secret data fr…
suffixstringNo-Suffix to append to the resource name. Defaults to the re…
syncWindowsobjectNo-Time windows restricting when periodic refreshes may occu…
targetobjectNo-Target Secret configuration. For more details, see https:…

Mappings between Kubernetes Secret keys and provider data. See https://external-secrets.io/latest/api/externalsecret/ for details.

Provider data sources whose values are merged into the target Secret. See https://external-secrets.io/latest/api/externalsecret/ for details.

Override the default resource name. Mutually exclusive with prefix and suffix.

Prefix to prepend to the resource name. Mutually exclusive with forceRename.

Amount of time before values are read again from the SecretStore provider.

Suffix to append to the resource name. Defaults to the resource identifier if there are multiple items, otherwise empty. Mutually exclusive with forceRename.