Skip to content

External Secrets Operator for Red Hat OpenShift APIs

External Secrets Operator for Red Hat OpenShift uses the following two APIs to configure the external-secrets application deployment.

Group Version Kind
operator.openshift.io v1alpha1 externalsecretsConfig
operator.openshift.io v1alpha1 externalsecretsmanager

The following list contains the External Secrets Operator for Red Hat OpenShift APIs:

  • ExternalSecretsConfig
  • ExternalSecretsManager

applicationConfig

The applicationConfig object customizes the runtime behavior and deployment constraints of the operand. Use this section to control observability, define the operational scope, and configure webhook specifics. Additionally, you can tailor the deployment to your infrastructure requirements.

Field Type Description Default Validation
logLevel integer logLevel supports a range of values as defined in the kubernetes logging guidelines. 1 The maximum range value is 5
The minimum range value is 1
Optional
operatingNamespace string operatingNamespace restricts the external-secrets operand operations to the provided namespace. Enabling this field disables ClusterSecretStore and ClusterExternalSecret. The maximum length is 63
The minimum length is 1
Optional
webhookConfig object webhookConfig configures webhook specifics of the external-secrets operand.
resources ResourceRequirements resources defines the resource requirements. You cannot change the value of this field after setting it initially. For more information, see https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ Optional
affinity Affinity affinity sets the scheduling affinity rules. For more information, see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/ Optional
tolerations Toleration array tolerations sets the pod tolerations. For more information, see https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/ The maximum number of items is 50
The minimum number of items is 0
Optional
nodeSelector object (keys:string, values:string) nodeSelector defines the scheduling criteria by using node labels. For more information, see https://kubernetes.io/docs/concepts/configuration/assign-pod-node/ The maximum number of properties is 50
The minimum number of properties is 0
Optional
proxy object (keys:string, values:string) proxy sets the proxy configurations available in operand containers managed by the Operator as environment variables. Optional

bitwardenSecretManagerProvider

To enable the Bitwarden secrets manager provider and set up the additional service required to connect to the Bitwarden server, you can configure the bitwardenSecretManagerProvider field.

Field Type Description Default Validation
mode string mode field enables the bitwardenSecretManagerProvider provider state, which can be set to Enabled or Disabled. If set to Enabled, the Operator ensures the plugin is deployed and synchronized. If set to Disabled, the Bitwarden provider plugin reconciliation is disabled. The plugin and resources remain in their current state, and are not managed by the Operator. Disabled enum: [Enabled Disabled]
Optional
secretRef SecretReference SecretRef specifies the Kubernetes secret that contains the TLS key pair for the Bitwarden server. If this reference is not provided and the certManagerConfig field is configured, the issuer defined in certManagerConfig generates the required certificate. The secret must use tls.crt for certificate, tls.key for the private key, and ca.crt for CA certificate. Optional

certManagerConfig

You can integrate the External Secrets Operator for Red Hat OpenShift with cert-manager to secure internal webhooks. Use these settings to replace the default internal certificate management with cert-manager, specify custom issuers, and define certificate lifecycle and renewal policies.

Field Type Description Default Validation
mode string mode specifies whether to use cert-manager for certificate management instead of the built-in cert-controller which can be indicated by setting either Enabled or Disabled. If set to Enabled, uses cert-manager for obtaining the certificates for the webhook server and other components. If set to Disabled, uses the cert-controller for obtaining the certificates for the webhook server. Disabled is the default behavior. enum: [Enabled Disabled]
injectAnnotations string injectAnnotations adds the cert-manager.io/inject-ca-from annotation to the webhooks and custom resource definitions (CRDs) to automatically configure the webhook with the cert-manager Operator certificate authority (CA). This requires CA Injector to be enabled in cert-manager Operator. Set this field to true or false. When set, this field cannot be changed. false enum: [true false]
issuerRef ObjectReference issuerRef contains details of the referenced object used for obtaining certificates. The object must exist in the external-secrets namespace unless a cluster-scoped cert-manager Operator issuer is used.
certificateDuration Duration certificateDuration sets the validity period of the webhook certificate. 8760h
certificateRenewBefore Duration certificateRenewBefore sets the ahead time to renew the webhook certificate before expiry. 30m

certProvidersConfig

The certProvidersConfig defines the configuration for the certificate providers used to manage TLS certificates for webhook and plugins.

Field Type Description Default Validation
certManager object certManager defines the configuration for cert-manager provider specifics.

commonConfigs

The commonConfigs specifies the common configurations available for all operands managed by the Operator.

Field Type Description Default Validation
logLevel integer logLevel supports the value range as defined in the Time. 1 The maximum number of log levels is 5.

The minimum number of log levels is 1.
resources ResourceRequirements. resources defines the resource requirements. This cannot be updated. See Resource Management for Pods and Containers.
affinity affinity. affinity is used for setting scheduling affinity rules. See See Assigning Pods to Nodes.
tolerations toleration array tolerations sets the pod tolerations. The maximum number of items is 50.

The minimum number of items is 0.
nodeSelector object (keys:string, values:string) nodeSelector defines the scheduling criteria using node labels. The maximum number of properties is 50.

The minimum number of properties is 0.
proxy proxyConfig proxy sets the proxy configurations which are made available in operand containers managed by the Operator as environment variables.

componentConfig

The componentConfig field defines configuration overrides for a specific external-secrets component.

Field Type Description Default Validation
componentName string componentName identifies which external-secrets component this configuration applies to. Valid values are ExternalSecretsCoreController, Webhook, CertController, and BitwardenSDKServer. Enum: [ExternalSecretsCoreController, Webhook, CertController, BitwardenSDKServer]

Required
deploymentConfigs object deploymentConfigs specifies overrides for the Kubernetes Deployment resource of this component.
overrideEnv EnvVar

array
overrideEnv specifies custom environment variables for this component's container. These are merged with operator-managed environment variables, with user-defined values taking precedence. Environment variable names starting with HOSTNAME, KUBERNETES_ or EXTERNAL_SECRETS_ are reserved and are not allowed. The maximum number of items is 50.

componentName

The componentName field represents the different external-secrets components that can have network policies applied.

Field Type Description
ExternalSecretsCoreController object ExternalSecretsCoreController represents the external-secret component.
BitwardenSDKServer object BitwardenSDKServer represents the bitwarden-sdk-server component.
Webhook object Webhook represents the external-secrets webhook component.
CertController object CertController represents the cert-controller component.

condition

The condition object reports the current health and operational state of the External Secrets Operator for Red Hat OpenShift deployment. It provides a standardized status check by detailing the specific type of condition, its current status, and a message to verify deployment success or troubleshooting errors.

Field Type Description
type string type contains the condition of the deployment.
status ConditionStatus status contains the status of the condition of the deployment
message string message provides details on the state of the deployment

conditionalStatus

The conditionalStatus field holds information about the current state of the external-secrets deployment.

Field Type Description
conditions array conditions contains information on the current state of the deployment.

configMapKeyReference

The configMapKeyReference specifies a specific key in a ConfigMap.

Field Type Description Default Validation
name string name specifies the name of the ConfigMap resource being referred to. The maximum length of the name is 253 characters.

The minimum length of the name is 1 character.
key string key specifies the specific key to be used in the ConfigMap. When ommitted, defaults to ca-bundle.crt. ca-bundle.crt The maximum length of the key is 253 characters.

The minimum length of the key is 1 character.

The pattern is: ^[-._a-zA-Z0-9]+$

controllerConfig

The controllerConfig specifies the configurations used by the controller when installing the external-secrets operand and the plugins.

Field Type Description Default Validation
certProvider string certProvider defines the configuration for the certificate providers used to manage TLS certificates for webhook and plugins.
labels object (keys:string, values:string) labels field applies labels to all resources created for the external-secrets operand deployment. The maximum number of properties is 20.

The minimum number of properties is 0.
annotations object (keys:string, values:string) annotations add custom annotations to all the resources created for the external-secrets deployment. The annotations are merged with any default annotations set by the Operator. User-specified annotations take precedence over defaults in case of conflicts. Annotation keys containing the reserved domains kubernetes.io/, openshift.io/, k8s.io/, or cert-manager.io/ (including subdomains like *.kubernetes.io/) are not allowed. The maximum number of annotations is 20.

The minimum number of annotations is 0.
networkPolicies networkPolicy array networkPolicies specifies the list of network policy configurations to be applied to the external-secrets pods. Each entry allows specifying a name for the generated NetworkPolicy object, along with its full Kubernetes NetworkPolicy definition. The Operator prepends eso-user- to the provided name when creating the Kubernetes object. If this field is not provided, external-secrets components are isolated with deny-all network policies, which prevents proper operation. The maximum number of items is 50.

The minimum number of items is 0.
componentConfigs ComponentConfig array componentConfigs allows specifying deployment-level configuration overrides for individual external-secrets components. This field enables fine-grained control over deployment settings for each component independently. Each component can have only one configuration entry. The maximum number of items is 4.

The minimum number of items is 0.
trustedCABundle ConfigMapKeyReference object trustedCABundle references a ConfigMap containing PEM-encoded CA certificates for the external-secrets core controller to trust when making outbound TLS connections. If specified, this bundle is used for all outbound TLS traffic, including connections to external secret management systems and configured proxies.

The ConfigMap must exist in the external-secrets Operand namespace and must not carry the CNO inject-trusted-cabundle label when proxy is configured. When omitted, external providers use standard system certificates. When proxy is configured, proxy TLS connections use the operator-managed OpenShift Container Platform trusted CA bundle injected by the Cluster Network Operator.

controllerStatus

The controllerStatus field tracks the health and synchronization state of the individual controllers managed by the Operator. It identifies each controller by name, details its current operational conditions, and verifies that the controller is processing the latest configuration version.

Field Type Description Default Validation
name string name specifies the name of the controller for which the observed condition is recorded.
conditions array conditions contains information about the current state of the External Secrets Operator controllers.
observedGeneration integer observedGeneration represents the .metadata.generation on the observed resource. The minimum number of observed resources is 0.

deploymentConfig

The deploymentConfig field defines configuration overrides for a Kubernetes Deployment resource.

Field Type Description Default Validation
revisionHistoryLimit integer revisionHistoryLimit specifies the number of old ReplicaSets to retain for rollback purposes. This allows rolling back to previous deployment versions using the command oc rollout undo. Must be at least 1 to ensure rollback capability. 10 The maximum value is 50.

The minimum value is 1.

externalSecretsConfig

The externalSecretsConfig object defines the configuration and information for the managed external-secrets operand deployment. Set the name to cluster as externalSecretsConfig object allows only one instance per cluster.

Creating an externalSecretsConfig object triggers the deployment of the external-secrets operand and maintains the desired state.

Field Type Description
apiVersion string The apiVersion specifies the version of the schema in use, which is operator.openshift.io/v1alpha1.
kind string kind specifies the type of the object, which is externalSecrets for this object.
metadata ObjectMeta Refer to Kubernetes API documentation for details about the metadata fields.
spec object spec contains the specifications of the desired behavior of the externalSecrets object.
status object status displays the most recently observed status of the externalSecrets object.

externalSecretsConfigList

The externalSecretsConfigList object fetches the list of externalSecretsConfig objects.

Field Type Description
apiVersion string The apiVersion specifies the version of the schema in use, which is operator.openshift.io/v1alpha1
kind string kind specifies the type of the object, which is externalSecretsList for this API.
metadata ListMeta Refer to Kubernetes API documentation for details about the metadata fields.
items array Items contains a list of externalSecrets objects.

externalSecretsConfigSpec

The externalSecretsConfigSpec field defines the desired behavior of the externalSecrets object.

Field Type Description
appConfig object appConfig configures the behavior of the external-secrets operand.
plugins object plugins configures the optional provider plugins.
controllerConfig object controllerConfig configures the controller to set up defaults that enable external-secrets operand.

externalSecretsConfigStatus

The externalSecretsConfigStatus field shows the most recently observed status of the externalSecretsConfig Object.

Field Type Description
conditions Condition array conditions contains information about the current state of deployment.
externalSecretsImage string externalSecretsImage specifies the image name and tag used for deploy external-secrets operand.
bitwardenSDKServerImage string bitwardenSDKServerImage specifies the name of the image and tag used for deploying the bitwarden-sdk-server.

externalSecretsManager

The externalSecretsManager object defines the configuration and information of deployments managed by the External Secrets Operator. Set the name to cluster as this allows only one instance of externalSecretsManager per cluster. You can configure global options by using externalSecretsManager. This serves as a centralized configuration for managing multiple controllers of the Operator. The Operator automatically creates the externalSecretsManager object during installation.

Field Type Description
apiVersion string The apiVersion specifies the version of the schema in use, which is operator.openshift.io/v1alpha1.
kind string kind specifies the type of the object, which is externalSecretsManager for this Object.
metadata ObjectMeta Refer to Kubernetes API documentation for details about the metadata fields.
spec object spec contains specifications of the desired behavior.
status object status displays the most recently observed state of the controllers in the External Secrets Operator.

externalSecretsManagerList

The externalSecretsManagerList object fetches the list of externalSecretsManager objects.

Field Type Description Default Validation
apiVersion string The apiVersion specifies the version of the schema in use, which is operator.openshift.io/v1alpha1.
kind string kind specifies the type of the object, which is externalSecretsManagerList for this API.
metadata ListMeta Refer to Kubernetes API documentation for details about the metadata fields.
items array

externalSecretsManagerSpec

The externalSecretsManagerSpec field defines the desired behavior of the externalSecretsManager object.

Field type Description Default Validation
globalConfig object globalConfig configures the behavior of deployments that External Secrets Operator manages. Optional

externalSecretsManagerStatus

The externalSecretsManagerStatus field shows the most recently observed status of the externalSecretsManager object.

Field Type Description Default Validation
controllerStatuses array controllerStatuses holds the observed conditions of the controllers used by the Operator.
lastTransitionTime Time lastTransitionTime records the most recent time the status of the condition changed. Format: date-time
Type: string

Feature

The Feature field configures an optional capability that is applied by the external-secrets-operator across its managed deployments.

Field Type Description Default Validation
name FeatureName

string
name identifies the optional feature to configure. Currently, the only supported value is UnsafeAllowGenericTargets. Enum: [UnsafeAllowGenericTargets]
mode mode

string
mode mode controls whether the feature is active. When set to Enabled, the Operator applies the configuration associated with the named feature to the relevant managed deployments. For UnsafeAllowGenericTargets, this passes the --unsafe-allow-generic-targets flag to the external-secrets core controller, allowing ExternalSecret resources to target Kubernetes resources other than Secrets. For example, ConfigMaps or custom resources.

Warning

Generic targets require additional RBAC permissions on the affected operand; enabling this feature without the appropriate permissions will cause reconciliation failures.

Disabled Enum:[Enabled Disabled]

featureName

The featureName field identifies an optional feature that can be configured on the ExternalSecretsManager and applied by the external-secrets-operator.

Field Type Description
UnsafeAllowGenericTargets object UnsafeAllowGenericTargets configures the external-secrets core controller to run with the --unsafe-allow-generic-targets startup flag, which allows ExternalSecret resources to sync data into Kubernetes resources other than Secrets.

globalConfig

The globalConfig field defines the baseline behavior and deployment parameters for the External Secrets Operator for Red Hat OpenShift. Use this section to apply labels to all managed resources and configure the logging verbosity. It also provides infrastructure-level controls to govern where and how the Operator is scheduled, alongside proxy settings for network compatibility.

Field Type Description Default Validation
logLevel integer logLevel supports a range of values as defined in the kubernetes logging guidelines. 1 The maximum range value is 5
The minimum range value is 1
resources ResourceRequirements resources defines the resource requirements. You cannot change the value of this field after setting it initially. For more information, see https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
affinity Affinity affinity sets the scheduling affinity rules. For more information, see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/
tolerations Toleration array tolerations sets the pod tolerations. For more information, see https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/ The maximum number of items is 50
The minimum number of items is 0
nodeSelector object (keys:string, values:string) nodeSelector defines the scheduling criteria by using the node labels. For more information, see https://kubernetes.io/docs/concepts/configuration/assign-pod-node/ The maximum number of properties is 50
The minimum number of properties is 0
proxy object proxy sets the proxy configurations available in the operand containers managed by the Operator as environment variables.
labels object (keys:string, values:string) labels applies to all resources created by the Operator. This field can have a maximum of 20 entries The maximum number of properties is 20
The minimum number of properties is 0

managementState

The managementState field controls whether the Operator manages the resource lifecycle.

Field Type Description
Managed string ManagementStateManaged indicates the Operator is responsible for the resource lifecycle.
Unmanaged string ManagementStateUnmanaged indicates the user is responsible for the resource lifecycle.

mode

The mode field indicates the operational state of the optional features.

Field Type Description
Enabled string Enabled indicates the optional configuration is enabled.
Disabled string Disabled indicates the optional configuration is disabled.

networkPolicy

The networkPolicy field represents a custom network policy configuration for operator-managed components. The field includes a name for identification and the network policy rules to be enforced.

Field Type Description Default Validation
name string name is the logical identifier for this network policy entry. The Operator prepends eso-user- to this value when creating the Kubernetes NetworkPolicy object, for example allow-egress becomes eso-user-allow-egress. The maximum length is 243 to accommodate the prefix within the 253-character Kubernetes name limit. The maximum length is 243 characters.

The minimum length is 1. character.
componentName string componentName specifies which external-secrets component this network policy applies to. Enum:[ExternalSecretsCoreController BitwardenSDIServer]
egress NetworkPolicyegressRule array egress is a list of egress rules to be applied to the selected pods. Outgoing traffic is allowed if there are no NetworkPolicies selecting the pod, and cluster policy otherwise allows the traffic, or if the traffic matches at least one egress rule across all the NetworkPolicy objects whose podSelector matches the pod. If this field is empty, then this NetworkPolicy limits all outgoing traffic and serves solely to ensure that the pods it selects are isolated by default. The Operator automatically handles ingress rules based on the current running ports.

objectReference

The ObjectReference object acts as a pointer to a specific Kubernetes resource. It uniquely identifies the target by requiring its name, and optionally, helps scope the reference to a specific resource type and API group.

Field Type Description Default Validation
name string name specifies the name of the resource being referred to. The maximum length is 253 characters.
The minimum length is 1 character.
Required
kind string kind specifies the kind of the resource being referred to. The maximum length is 253 characters.
The minimum length is 1 character.
Optional
group string group specifies the group of the resource being referred to. The maximum length is 253 characters.
The minimum length is 1 character.
Optional

pluginsConfig

The pluginsConfig configures the optional plugins.

Field Type Description Default Validation
bitwardenSecretManagerProvider object bitwardenSecretManagerProvider enables the bitwarden-secrets-manager provider plugin for connecting with the 'bitwarden-secrets-manager'. Optional

proxyConfig

The proxyConfig object defines the network proxy settings that the Operator injects into managed containers as environment variables. Use this configuration to ensure proper connectivity in restricted network environments, or to bypass the proxy and connect directly.

Field Type Description Default Validation
httpProxy string The httpProxy field contains the URL of the proxy for HTTP requests. This field can have a maximum of 2048 characters. The maximum length is 2048 characters.
The minimum length is 0 characters.
httpsProxy string The httpsProxy field contains the URL of the proxy for HTTPS requests. This field can have a maximum of 2048 characters. The maximum length is 2048 characters.
The minimum length is 0 characters.
noProxy string The noProxy field is a comma-separated list of hostnames, classless inter-domain routings (CIDRs), and IP addresses or a combination of the three for which the proxy should not be used. This field can have a maximum of 4096 characters. The maximum length is 4096 characters.
The minimum length is 0 characters.
networkPolicyProvisioning
ManagementState
string The networkPolicyProvisioning field defines the management strategy for the proxy egress rule. When set to Managed, the Operator automatically provisions and maintains a NetworkPolicy allowing traffic to the configured proxy. If no proxy is configured, a NetworkPolicy is not created regardless of this setting. Managed Enum:[Managed Unmanaged]

secretReference

The secretReference field refers to a secret with the given name in the same namespace where it used.

Field Type Description Default Validation
name string name specifies the name of the secret resource being referred to. The maximum length is 253.
The minimum length is 1.

webhookConfig

The webhookConfig field configures the specifics of the external-secrets application webhook.

Field Type Description Default Validation
certificateCheckInterval Duration certificateCheckInterval configures the polling interval to check certificate validity. 5m Optional