cue.dev/x/crd/bitnami.com/sealed-secrets@v0.4.0

v1alpha1/schema.cue raw

  1package v1alpha1
  2
  3import "time"
  4
  5// SealedSecret is the K8s representation of a "sealed Secret" - a
  6// regular k8s Secret that has been sealed (encrypted) using the
  7// controller's key.
  8#SealedSecret: {
  9	_embeddedResource
 10
 11	// APIVersion defines the versioned schema of this representation of an object.
 12	// Servers should convert recognized schemas to the latest internal value, and
 13	// may reject unrecognized values.
 14	// More info:
 15	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
 16	"apiVersion"?: string
 17
 18	// Kind is a string value representing the REST resource this object represents.
 19	// Servers may infer this from the endpoint the client submits requests to.
 20	// Cannot be updated.
 21	// In CamelCase.
 22	// More info:
 23	// https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
 24	"kind"?:     string
 25	"metadata"?: {}
 26
 27	// SealedSecretSpec is the specification of a SealedSecret.
 28	"spec"!: {
 29		// Data is deprecated and will be removed eventually. Use per-value EncryptedData instead.
 30		"data"?: string
 31		"encryptedData"!: {
 32			[string]: string
 33			...
 34		}
 35
 36		// Template defines the structure of the Secret that will be
 37		// created from this sealed secret.
 38		"template"?: {
 39			// Keys that should be templated using decrypted data.
 40			"data"?: null | {[string]: string}
 41
 42			// Immutable, if set to true, ensures that data stored in the Secret cannot
 43			// be updated (only object metadata can be modified).
 44			// If not set to true, the field can be modified at any time.
 45			// Defaulted to nil.
 46			"immutable"?: bool
 47
 48			// Standard object's metadata.
 49			// More info: https://git.k8s.io/community/contributors/devel/api-conventions.md#metadata
 50			"metadata"?: null | {
 51				"annotations"?: [string]: string
 52				"finalizers"?: [...string]
 53				"labels"?: [string]: string
 54				"name"?:      string
 55				"namespace"?: string
 56				...
 57			}
 58
 59			// Used to facilitate programmatic handling of secret data.
 60			"type"?: string
 61		}
 62	}
 63
 64	// SealedSecretStatus is the most recently observed status of the SealedSecret.
 65	"status"?: {
 66		// Represents the latest available observations of a sealed secret's current state.
 67		"conditions"?: [...{
 68			// Last time the condition transitioned from one status to another.
 69			"lastTransitionTime"?: time.Time
 70
 71			// The last time this condition was updated.
 72			"lastUpdateTime"?: time.Time
 73
 74			// A human readable message indicating details about the transition.
 75			"message"?: string
 76
 77			// The reason for the condition's last transition.
 78			"reason"?: string
 79
 80			// Status of the condition for a sealed secret.
 81			// Valid values for "Synced": "True", "False", or "Unknown".
 82			"status"!: string
 83
 84			// Type of condition for a sealed secret.
 85			// Valid value: "Synced"
 86			"type"!: string
 87		}]
 88
 89		// ObservedGeneration reflects the generation most recently observed by the
 90		// sealed-secrets controller.
 91		"observedGeneration"?: int64 & int
 92	}
 93
 94	_embeddedResource: {
 95		"apiVersion"!: string
 96		"kind"!:       string
 97		"metadata"?:   {...}
 98	}
 99	apiVersion: "bitnami.com/v1alpha1"
100	kind:       "SealedSecret"
101	metadata!: {
102		"name"!:        string
103		"namespace"!:   string
104		"labels"?:      {[string]: string}
105		"annotations"?: {[string]: string}
106		...
107	}
108}