Discover modules > cue.dev/x/crd/bitnami.com/sealed-secrets > v1alpha1
v0.4.0
#SealedSecret: ¶

SealedSecret is the K8s representation of a "sealed Secret" - a regular k8s Secret that has been sealed (encrypted) using the controller's key.

"apiVersion":
click to see definition
string
& "bitnami.com/v1alpha1"
¶

APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources

"kind":
click to see definition
string
& "SealedSecret"
¶

Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds

"metadata"!: ¶
"name"!: string ¶
"namespace"!: string ¶
"labels"?: ¶
[string]: string ¶
"annotations"?: ¶
[string]: string ¶
"spec"!: ¶

SealedSecretSpec is the specification of a SealedSecret.

"data"?: string ¶

Data is deprecated and will be removed eventually. Use per-value EncryptedData instead.

"encryptedData"!: ¶
[string]: string ¶
"template"?: ¶

Template defines the structure of the Secret that will be created from this sealed secret.

"data"?: null | {[string]: string} ¶

Keys that should be templated using decrypted data.

[string]: string ¶
"immutable"?: bool ¶

Immutable, if set to true, ensures that data stored in the Secret cannot be updated (only object metadata can be modified). If not set to true, the field can be modified at any time. Defaulted to nil.

"metadata"?:
click to see definition
null | {
	"annotations"?: [string]: string
	"finalizers"?: [...string]
	"labels"?: [string]: string
	"name"?:      string
	"namespace"?: string
	...
}
¶

Standard object's metadata. More info: https://git.k8s.io/community/contributors/devel/api-conventions.md#metadata

"annotations"?: ¶
[string]: string ¶
"finalizers"?: [...string] ¶
[...]: string
"labels"?: ¶
[string]: string ¶
"name"?: string ¶
"namespace"?: string ¶
"type"?: string ¶

Used to facilitate programmatic handling of secret data.

"status"?: ¶

SealedSecretStatus is the most recently observed status of the SealedSecret.

"conditions"?:
click to see definition
[...{
	// Last time the condition transitioned from one status to another.
	"lastTransitionTime"?: time.Time

	// The last time this condition was updated.
	"lastUpdateTime"?: time.Time

	// A human readable message indicating details about the transition.
	"message"?: string

	// The reason for the condition's last transition.
	"reason"?: string

	// Status of the condition for a sealed secret.
	// Valid values for "Synced": "True", "False", or "Unknown".
	"status"!: string

	// Type of condition for a sealed secret.
	// Valid value: "Synced"
	"type"!: string
}]
¶

Represents the latest available observations of a sealed secret's current state.

[...]:
"lastTransitionTime"?: time.Time

Last time the condition transitioned from one status to another.

"lastUpdateTime"?: time.Time

The last time this condition was updated.

"message"?: string

A human readable message indicating details about the transition.

"reason"?: string

The reason for the condition's last transition.

"status"!: string

Status of the condition for a sealed secret. Valid values for "Synced": "True", "False", or "Unknown".

"type"!: string

Type of condition for a sealed secret. Valid value: "Synced"

"observedGeneration"?: int64 & int ¶

ObservedGeneration reflects the generation most recently observed by the sealed-secrets controller.

Source files

  • schema.cue