External Secrets Operator for Red Hat OpenShift APIs¶
External Secrets Operator for Red Hat OpenShift uses the following two APIs to configure the external-secrets application deployment.
| Group | Version | Kind |
|---|---|---|
operator.openshift.io |
v1alpha1 |
externalsecretsConfig |
operator.openshift.io |
v1alpha1 |
externalsecretsmanager |
The following list contains the External Secrets Operator for Red Hat OpenShift APIs:
- ExternalSecretsConfig
- ExternalSecretsManager
applicationConfig¶
The applicationConfig object customizes the runtime behavior and deployment constraints of the operand. Use this section to control observability, define the operational scope, and configure webhook specifics. Additionally, you can tailor the deployment to your infrastructure requirements.
| Field | Type | Description | Default | Validation |
|---|---|---|---|---|
logLevel |
integer | logLevel supports a range of values as defined in the kubernetes logging guidelines. |
1 | The maximum range value is 5 The minimum range value is 1 Optional |
operatingNamespace |
string | operatingNamespace restricts the external-secrets operand operations to the provided namespace. Enabling this field disables ClusterSecretStore and ClusterExternalSecret. |
The maximum length is 63 The minimum length is 1 Optional |
|
webhookConfig |
object | webhookConfig configures webhook specifics of the external-secrets operand. |
||
resources |
ResourceRequirements | resources defines the resource requirements. You cannot change the value of this field after setting it initially. For more information, see https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ |
Optional | |
affinity |
Affinity | affinity sets the scheduling affinity rules. For more information, see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/ |
Optional | |
tolerations |
Toleration array | tolerations sets the pod tolerations. For more information, see https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/ |
The maximum number of items is 50 The minimum number of items is 0 Optional |
|
nodeSelector |
object (keys:string, values:string) | nodeSelector defines the scheduling criteria by using node labels. For more information, see https://kubernetes.io/docs/concepts/configuration/assign-pod-node/ |
The maximum number of properties is 50 The minimum number of properties is 0 Optional |
|
proxy |
object (keys:string, values:string) | proxy sets the proxy configurations available in operand containers managed by the Operator as environment variables. |
Optional |
bitwardenSecretManagerProvider¶
To enable the Bitwarden secrets manager provider and set up the additional service required to connect to the Bitwarden server, you can configure the bitwardenSecretManagerProvider field.
| Field | Type | Description | Default | Validation |
|---|---|---|---|---|
mode |
string | mode field enables the bitwardenSecretManagerProvider provider state, which can be set to Enabled or Disabled. If set to Enabled, the Operator ensures the plugin is deployed and synchronized. If set to Disabled, the Bitwarden provider plugin reconciliation is disabled. The plugin and resources remain in their current state, and are not managed by the Operator. |
Disabled |
enum: [Enabled Disabled] Optional |
secretRef |
SecretReference | SecretRef specifies the Kubernetes secret that contains the TLS key pair for the Bitwarden server. If this reference is not provided and the certManagerConfig field is configured, the issuer defined in certManagerConfig generates the required certificate. The secret must use tls.crt for certificate, tls.key for the private key, and ca.crt for CA certificate. |
Optional |
certManagerConfig¶
You can integrate the External Secrets Operator for Red Hat OpenShift with cert-manager to secure internal webhooks. Use these settings to replace the default internal certificate management with cert-manager, specify custom issuers, and define certificate lifecycle and renewal policies.
| Field | Type | Description | Default | Validation |
|---|---|---|---|---|
mode |
string | mode specifies whether to use cert-manager for certificate management instead of the built-in cert-controller which can be indicated by setting either Enabled or Disabled. If set to Enabled, uses cert-manager for obtaining the certificates for the webhook server and other components. If set to Disabled, uses the cert-controller for obtaining the certificates for the webhook server. Disabled is the default behavior. |
enum: [Enabled Disabled] | |
injectAnnotations |
string | injectAnnotations adds the cert-manager.io/inject-ca-from annotation to the webhooks and custom resource definitions (CRDs) to automatically configure the webhook with the cert-manager Operator certificate authority (CA). This requires CA Injector to be enabled in cert-manager Operator. Set this field to true or false. When set, this field cannot be changed. |
false | enum: [true false] |
issuerRef |
ObjectReference | issuerRef contains details of the referenced object used for obtaining certificates. The object must exist in the external-secrets namespace unless a cluster-scoped cert-manager Operator issuer is used. |
||
certificateDuration |
Duration | certificateDuration sets the validity period of the webhook certificate. |
8760h | |
certificateRenewBefore |
Duration | certificateRenewBefore sets the ahead time to renew the webhook certificate before expiry. |
30m |
certProvidersConfig¶
The certProvidersConfig defines the configuration for the certificate providers used to manage TLS certificates for webhook and plugins.
| Field | Type | Description | Default | Validation |
|---|---|---|---|---|
certManager |
object | certManager defines the configuration for cert-manager provider specifics. |
commonConfigs¶
The commonConfigs specifies the common configurations available for all operands managed by the Operator.
| Field | Type | Description | Default | Validation |
|---|---|---|---|---|
logLevel |
integer | logLevel supports the value range as defined in the Time. |
1 | The maximum number of log levels is 5. The minimum number of log levels is 1. |
resources |
ResourceRequirements. | resources defines the resource requirements. This cannot be updated. See Resource Management for Pods and Containers. |
||
affinity |
affinity. | affinity is used for setting scheduling affinity rules. See See Assigning Pods to Nodes. |
||
tolerations |
toleration array | tolerations sets the pod tolerations. |
The maximum number of items is 50. The minimum number of items is 0. |
|
nodeSelector |
object (keys:string, values:string) | nodeSelector defines the scheduling criteria using node labels. |
The maximum number of properties is 50. The minimum number of properties is 0. |
|
proxy |
proxyConfig | proxy sets the proxy configurations which are made available in operand containers managed by the Operator as environment variables. |
componentConfig¶
The componentConfig field defines configuration overrides for a specific external-secrets component.
| Field | Type | Description | Default | Validation |
|---|---|---|---|---|
componentName |
string | componentName identifies which external-secrets component this configuration applies to. Valid values are ExternalSecretsCoreController, Webhook, CertController, and BitwardenSDKServer. |
Enum: [ExternalSecretsCoreController, Webhook, CertController, BitwardenSDKServer]Required |
|
deploymentConfigs |
object | deploymentConfigs specifies overrides for the Kubernetes Deployment resource of this component. |
||
overrideEnv |
EnvVar array |
overrideEnv specifies custom environment variables for this component's container. These are merged with operator-managed environment variables, with user-defined values taking precedence. Environment variable names starting with HOSTNAME, KUBERNETES_ or EXTERNAL_SECRETS_ are reserved and are not allowed. |
The maximum number of items is 50. |
componentName¶
The componentName field represents the different external-secrets components that can have network policies applied.
| Field | Type | Description |
|---|---|---|
ExternalSecretsCoreController |
object | ExternalSecretsCoreController represents the external-secret component. |
BitwardenSDKServer |
object | BitwardenSDKServer represents the bitwarden-sdk-server component. |
Webhook |
object | Webhook represents the external-secrets webhook component. |
CertController |
object | CertController represents the cert-controller component. |
condition¶
The condition object reports the current health and operational state of the External Secrets Operator for Red Hat OpenShift deployment. It provides a standardized status check by detailing the specific type of condition, its current status, and a message to verify deployment success or troubleshooting errors.
| Field | Type | Description |
|---|---|---|
type |
string | type contains the condition of the deployment. |
status |
ConditionStatus | status contains the status of the condition of the deployment |
message |
string | message provides details on the state of the deployment |
conditionalStatus¶
The conditionalStatus field holds information about the current state of the external-secrets deployment.
| Field | Type | Description |
|---|---|---|
conditions |
array | conditions contains information on the current state of the deployment. |
configMapKeyReference¶
The configMapKeyReference specifies a specific key in a ConfigMap.
| Field | Type | Description | Default | Validation |
|---|---|---|---|---|
name |
string | name specifies the name of the ConfigMap resource being referred to. |
The maximum length of the name is 253 characters. The minimum length of the name is 1 character. |
|
key |
string | key specifies the specific key to be used in the ConfigMap. When ommitted, defaults to ca-bundle.crt. |
ca-bundle.crt |
The maximum length of the key is 253 characters. The minimum length of the key is 1 character. The pattern is: ^[-._a-zA-Z0-9]+$ |
controllerConfig¶
The controllerConfig specifies the configurations used by the controller when installing the external-secrets operand and the plugins.
| Field | Type | Description | Default | Validation |
|---|---|---|---|---|
certProvider |
string | certProvider defines the configuration for the certificate providers used to manage TLS certificates for webhook and plugins. |
||
labels |
object (keys:string, values:string) | labels field applies labels to all resources created for the external-secrets operand deployment. |
The maximum number of properties is 20. The minimum number of properties is 0. |
|
annotations |
object (keys:string, values:string) | annotations add custom annotations to all the resources created for the external-secrets deployment. The annotations are merged with any default annotations set by the Operator. User-specified annotations take precedence over defaults in case of conflicts. Annotation keys containing the reserved domains kubernetes.io/, openshift.io/, k8s.io/, or cert-manager.io/ (including subdomains like *.kubernetes.io/) are not allowed. |
The maximum number of annotations is 20. The minimum number of annotations is 0. |
|
networkPolicies |
networkPolicy array | networkPolicies specifies the list of network policy configurations to be applied to the external-secrets pods. Each entry allows specifying a name for the generated NetworkPolicy object, along with its full Kubernetes NetworkPolicy definition. The Operator prepends eso-user- to the provided name when creating the Kubernetes object. If this field is not provided, external-secrets components are isolated with deny-all network policies, which prevents proper operation. |
The maximum number of items is 50. The minimum number of items is 0. |
|
componentConfigs |
ComponentConfig array | componentConfigs allows specifying deployment-level configuration overrides for individual external-secrets components. This field enables fine-grained control over deployment settings for each component independently. Each component can have only one configuration entry. |
The maximum number of items is 4. The minimum number of items is 0. |
|
trustedCABundle ConfigMapKeyReference |
object | trustedCABundle references a ConfigMap containing PEM-encoded CA certificates for the external-secrets core controller to trust when making outbound TLS connections. If specified, this bundle is used for all outbound TLS traffic, including connections to external secret management systems and configured proxies.The ConfigMap must exist in the external-secrets Operand namespace and must not carry the CNO inject-trusted-cabundle label when proxy is configured. When omitted, external providers use standard system certificates. When proxy is configured, proxy TLS connections use the operator-managed OpenShift Container Platform trusted CA bundle injected by the Cluster Network Operator. |
controllerStatus¶
The controllerStatus field tracks the health and synchronization state of the individual controllers managed by the Operator. It identifies each controller by name, details its current operational conditions, and verifies that the controller is processing the latest configuration version.
| Field | Type | Description | Default | Validation |
|---|---|---|---|---|
name |
string | name specifies the name of the controller for which the observed condition is recorded. |
||
conditions |
array | conditions contains information about the current state of the External Secrets Operator controllers. |
||
observedGeneration |
integer | observedGeneration represents the .metadata.generation on the observed resource. |
The minimum number of observed resources is 0. |
deploymentConfig¶
The deploymentConfig field defines configuration overrides for a Kubernetes Deployment resource.
| Field | Type | Description | Default | Validation |
|---|---|---|---|---|
revisionHistoryLimit |
integer | revisionHistoryLimit specifies the number of old ReplicaSets to retain for rollback purposes. This allows rolling back to previous deployment versions using the command oc rollout undo. Must be at least 1 to ensure rollback capability. |
10 | The maximum value is 50. The minimum value is 1. |
externalSecretsConfig¶
The externalSecretsConfig object defines the configuration and information for the managed external-secrets operand deployment. Set the name to cluster as externalSecretsConfig object allows only one instance per cluster.
Creating an externalSecretsConfig object triggers the deployment of the external-secrets operand and maintains the desired state.
| Field | Type | Description |
|---|---|---|
apiVersion |
string | The apiVersion specifies the version of the schema in use, which is operator.openshift.io/v1alpha1. |
kind |
string | kind specifies the type of the object, which is externalSecrets for this object. |
metadata |
ObjectMeta | Refer to Kubernetes API documentation for details about the metadata fields. |
spec |
object | spec contains the specifications of the desired behavior of the externalSecrets object. |
status |
object | status displays the most recently observed status of the externalSecrets object. |
externalSecretsConfigList¶
The externalSecretsConfigList object fetches the list of externalSecretsConfig objects.
| Field | Type | Description |
|---|---|---|
apiVersion |
string | The apiVersion specifies the version of the schema in use, which is operator.openshift.io/v1alpha1 |
kind |
string | kind specifies the type of the object, which is externalSecretsList for this API. |
metadata |
ListMeta | Refer to Kubernetes API documentation for details about the metadata fields. |
items |
array | Items contains a list of externalSecrets objects. |
externalSecretsConfigSpec¶
The externalSecretsConfigSpec field defines the desired behavior of the externalSecrets object.
| Field | Type | Description |
|---|---|---|
appConfig |
object | appConfig configures the behavior of the external-secrets operand. |
plugins |
object | plugins configures the optional provider plugins. |
controllerConfig |
object | controllerConfig configures the controller to set up defaults that enable external-secrets operand. |
externalSecretsConfigStatus¶
The externalSecretsConfigStatus field shows the most recently observed status of the externalSecretsConfig Object.
| Field | Type | Description |
|---|---|---|
conditions |
Condition array | conditions contains information about the current state of deployment. |
externalSecretsImage |
string | externalSecretsImage specifies the image name and tag used for deploy external-secrets operand. |
bitwardenSDKServerImage |
string | bitwardenSDKServerImage specifies the name of the image and tag used for deploying the bitwarden-sdk-server. |
externalSecretsManager¶
The externalSecretsManager object defines the configuration and information of deployments managed by the External Secrets Operator. Set the name to cluster as this allows only one instance of externalSecretsManager per cluster. You can configure global options by using externalSecretsManager. This serves as a centralized configuration for managing multiple controllers of the Operator. The Operator automatically creates the externalSecretsManager object during installation.
| Field | Type | Description |
|---|---|---|
apiVersion |
string | The apiVersion specifies the version of the schema in use, which is operator.openshift.io/v1alpha1. |
kind |
string | kind specifies the type of the object, which is externalSecretsManager for this Object. |
metadata |
ObjectMeta | Refer to Kubernetes API documentation for details about the metadata fields. |
spec |
object | spec contains specifications of the desired behavior. |
status |
object | status displays the most recently observed state of the controllers in the External Secrets Operator. |
externalSecretsManagerList¶
The externalSecretsManagerList object fetches the list of externalSecretsManager objects.
| Field | Type | Description | Default | Validation |
|---|---|---|---|---|
apiVersion |
string | The apiVersion specifies the version of the schema in use, which is operator.openshift.io/v1alpha1. |
||
kind |
string | kind specifies the type of the object, which is externalSecretsManagerList for this API. |
||
metadata |
ListMeta | Refer to Kubernetes API documentation for details about the metadata fields. |
||
items |
array |
externalSecretsManagerSpec¶
The externalSecretsManagerSpec field defines the desired behavior of the externalSecretsManager object.
| Field | type | Description | Default | Validation |
|---|---|---|---|---|
globalConfig |
object | globalConfig configures the behavior of deployments that External Secrets Operator manages. |
Optional |
externalSecretsManagerStatus¶
The externalSecretsManagerStatus field shows the most recently observed status of the externalSecretsManager object.
| Field | Type | Description | Default | Validation |
|---|---|---|---|---|
controllerStatuses |
array | controllerStatuses holds the observed conditions of the controllers used by the Operator. |
||
lastTransitionTime |
Time | lastTransitionTime records the most recent time the status of the condition changed. |
Format: date-time Type: string |
Feature¶
The Feature field configures an optional capability that is applied by the external-secrets-operator across its managed deployments.
| Field | Type | Description | Default | Validation |
|---|---|---|---|---|
name |
FeatureName string |
name identifies the optional feature to configure. Currently, the only supported value is UnsafeAllowGenericTargets. |
Enum: [UnsafeAllowGenericTargets] |
|
mode |
mode string |
mode mode controls whether the feature is active. When set to Enabled, the Operator applies the configuration associated with the named feature to the relevant managed deployments. For UnsafeAllowGenericTargets, this passes the --unsafe-allow-generic-targets flag to the external-secrets core controller, allowing ExternalSecret resources to target Kubernetes resources other than Secrets. For example, ConfigMaps or custom resources.Warning Generic targets require additional RBAC permissions on the affected operand; enabling this feature without the appropriate permissions will cause reconciliation failures. |
Disabled | Enum:[Enabled Disabled] |
featureName¶
The featureName field identifies an optional feature that can be configured on the ExternalSecretsManager and applied by the external-secrets-operator.
| Field | Type | Description |
|---|---|---|
UnsafeAllowGenericTargets |
object | UnsafeAllowGenericTargets configures the external-secrets core controller to run with the --unsafe-allow-generic-targets startup flag, which allows ExternalSecret resources to sync data into Kubernetes resources other than Secrets. |
globalConfig¶
The globalConfig field defines the baseline behavior and deployment parameters for the External Secrets Operator for Red Hat OpenShift. Use this section to apply labels to all managed resources and configure the logging verbosity. It also provides infrastructure-level controls to govern where and how the Operator is scheduled, alongside proxy settings for network compatibility.
| Field | Type | Description | Default | Validation |
|---|---|---|---|---|
logLevel |
integer | logLevel supports a range of values as defined in the kubernetes logging guidelines. |
1 | The maximum range value is 5 The minimum range value is 1 |
resources |
ResourceRequirements | resources defines the resource requirements. You cannot change the value of this field after setting it initially. For more information, see https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/ |
||
affinity |
Affinity | affinity sets the scheduling affinity rules. For more information, see https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/ |
||
tolerations |
Toleration array | tolerations sets the pod tolerations. For more information, see https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/ |
The maximum number of items is 50 The minimum number of items is 0 |
|
nodeSelector |
object (keys:string, values:string) | nodeSelector defines the scheduling criteria by using the node labels. For more information, see https://kubernetes.io/docs/concepts/configuration/assign-pod-node/ |
The maximum number of properties is 50 The minimum number of properties is 0 |
|
proxy |
object | proxy sets the proxy configurations available in the operand containers managed by the Operator as environment variables. |
||
labels |
object (keys:string, values:string) | labels applies to all resources created by the Operator. This field can have a maximum of 20 entries |
The maximum number of properties is 20 The minimum number of properties is 0 |
managementState¶
The managementState field controls whether the Operator manages the resource lifecycle.
| Field | Type | Description |
|---|---|---|
Managed |
string | ManagementStateManaged indicates the Operator is responsible for the resource lifecycle. |
Unmanaged |
string | ManagementStateUnmanaged indicates the user is responsible for the resource lifecycle. |
mode¶
The mode field indicates the operational state of the optional features.
| Field | Type | Description |
|---|---|---|
Enabled |
string | Enabled indicates the optional configuration is enabled. |
Disabled |
string | Disabled indicates the optional configuration is disabled. |
networkPolicy¶
The networkPolicy field represents a custom network policy configuration for operator-managed components. The field includes a name for identification and the network policy rules to be enforced.
| Field | Type | Description | Default | Validation |
|---|---|---|---|---|
name |
string | name is the logical identifier for this network policy entry. The Operator prepends eso-user- to this value when creating the Kubernetes NetworkPolicy object, for example allow-egress becomes eso-user-allow-egress. The maximum length is 243 to accommodate the prefix within the 253-character Kubernetes name limit. |
The maximum length is 243 characters. The minimum length is 1. character. |
|
componentName |
string | componentName specifies which external-secrets component this network policy applies to. |
Enum:[ExternalSecretsCoreController BitwardenSDIServer] |
|
egress NetworkPolicyegressRule |
array | egress is a list of egress rules to be applied to the selected pods. Outgoing traffic is allowed if there are no NetworkPolicies selecting the pod, and cluster policy otherwise allows the traffic, or if the traffic matches at least one egress rule across all the NetworkPolicy objects whose podSelector matches the pod. If this field is empty, then this NetworkPolicy limits all outgoing traffic and serves solely to ensure that the pods it selects are isolated by default. The Operator automatically handles ingress rules based on the current running ports. |
objectReference¶
The ObjectReference object acts as a pointer to a specific Kubernetes resource. It uniquely identifies the target by requiring its name, and optionally, helps scope the reference to a specific resource type and API group.
| Field | Type | Description | Default | Validation |
|---|---|---|---|---|
name |
string | name specifies the name of the resource being referred to. |
The maximum length is 253 characters. The minimum length is 1 character. Required |
|
kind |
string | kind specifies the kind of the resource being referred to. |
The maximum length is 253 characters. The minimum length is 1 character. Optional |
|
group |
string | group specifies the group of the resource being referred to. |
The maximum length is 253 characters. The minimum length is 1 character. Optional |
pluginsConfig¶
The pluginsConfig configures the optional plugins.
| Field | Type | Description | Default | Validation |
|---|---|---|---|---|
bitwardenSecretManagerProvider |
object | bitwardenSecretManagerProvider enables the bitwarden-secrets-manager provider plugin for connecting with the 'bitwarden-secrets-manager'. |
Optional |
proxyConfig¶
The proxyConfig object defines the network proxy settings that the Operator injects into managed containers as environment variables. Use this configuration to ensure proper connectivity in restricted network environments, or to bypass the proxy and connect directly.
| Field | Type | Description | Default | Validation |
|---|---|---|---|---|
httpProxy |
string | The httpProxy field contains the URL of the proxy for HTTP requests. This field can have a maximum of 2048 characters. |
The maximum length is 2048 characters. The minimum length is 0 characters. |
|
httpsProxy |
string | The httpsProxy field contains the URL of the proxy for HTTPS requests. This field can have a maximum of 2048 characters. |
The maximum length is 2048 characters. The minimum length is 0 characters. |
|
noProxy |
string | The noProxy field is a comma-separated list of hostnames, classless inter-domain routings (CIDRs), and IP addresses or a combination of the three for which the proxy should not be used. This field can have a maximum of 4096 characters. |
The maximum length is 4096 characters. The minimum length is 0 characters. |
|
networkPolicyProvisioningManagementState |
string | The networkPolicyProvisioning field defines the management strategy for the proxy egress rule. When set to Managed, the Operator automatically provisions and maintains a NetworkPolicy allowing traffic to the configured proxy. If no proxy is configured, a NetworkPolicy is not created regardless of this setting. |
Managed | Enum:[Managed Unmanaged] |
secretReference¶
The secretReference field refers to a secret with the given name in the same namespace where it used.
| Field | Type | Description | Default | Validation |
|---|---|---|---|---|
name |
string | name specifies the name of the secret resource being referred to. |
The maximum length is 253. The minimum length is 1. |
webhookConfig¶
The webhookConfig field configures the specifics of the external-secrets application webhook.
| Field | Type | Description | Default | Validation |
|---|---|---|---|---|
certificateCheckInterval |
Duration | certificateCheckInterval configures the polling interval to check certificate validity. |
5m | Optional |