1apiVersion: aws.vault.m.upbound.io/v1alpha1
2kind: SecretBackend
SecretBackendSpec defines the desired state of SecretBackend
(No description available)
The AWS Access Key ID this backend should use to issue new credentials. Vault uses the official AWS SDK to authenticate, and thus can also use standard AWS environment credentials, shared file credentials or IAM role/ECS task credentials. The AWS Access Key ID to use when generating new credentials.
Set of managed key registry entry names that the mount in question is allowed to access List of managed key registry entry names that the mount in question is allowed to access
List of headers to allow, allowing a plugin to include them in the response. List of headers to allow and pass from the request to the plugin
Specifies the list of keys that will not be HMAC'd by audit devices in the request data object. Specifies the list of keys that will not be HMAC'd by audit devices in the request data object.
Specifies the list of keys that will not be HMAC'd by audit devices in the response data object. Specifies the list of keys that will not be HMAC'd by audit devices in the response data object.
List of allowed authentication mount accessors the backend can request delegated authentication for. List of headers to allow and pass from the request to the plugin
List of headers to allow and pass from the request to the plugin. List of headers to allow and pass from the request to the plugin
The AWS Secret Key this backend should use to issue new credentials. Vault uses the official AWS SDK to authenticate, and thus can also use standard AWS environment credentials, shared file credentials or IAM role/ECS task credentials. The AWS Secret Access Key to use when generating new credentials.
Ordered list of sts_endpoints to try if the defined one fails. Requires Vault 1.19+ Specifies a list of custom STS fallback endpoints to use (in order).
Ordered list of sts_regions matching the fallback endpoints. Should correspond in order with those endpoints. Requires Vault 1.19+ Specifies a list of custom STS fallback regions to use (in order).
THIS IS A BETA FIELD. It will be honored unless the Management Policies feature flag is disabled. InitProvider holds the same fields as ForProvider, with the exception of Identifier and other resource reference fields. The fields that are in InitProvider are merged into ForProvider when the resource is created. The same fields are also added to the terraform ignore_changes hook, to avoid updating them after creation. This is useful for fields that are required on creation, but we do not desire to update them after creation, for example because of an external controller is managing them, like an autoscaler.
The AWS Access Key ID this backend should use to issue new credentials. Vault uses the official AWS SDK to authenticate, and thus can also use standard AWS environment credentials, shared file credentials or IAM role/ECS task credentials. The AWS Access Key ID to use when generating new credentials.
Set of managed key registry entry names that the mount in question is allowed to access List of managed key registry entry names that the mount in question is allowed to access
List of headers to allow, allowing a plugin to include them in the response. List of headers to allow and pass from the request to the plugin
Specifies the list of keys that will not be HMAC'd by audit devices in the request data object. Specifies the list of keys that will not be HMAC'd by audit devices in the request data object.
Specifies the list of keys that will not be HMAC'd by audit devices in the response data object. Specifies the list of keys that will not be HMAC'd by audit devices in the response data object.
List of allowed authentication mount accessors the backend can request delegated authentication for. List of headers to allow and pass from the request to the plugin
List of headers to allow and pass from the request to the plugin. List of headers to allow and pass from the request to the plugin
The AWS Secret Key this backend should use to issue new credentials. Vault uses the official AWS SDK to authenticate, and thus can also use standard AWS environment credentials, shared file credentials or IAM role/ECS task credentials. The AWS Secret Access Key to use when generating new credentials.
Ordered list of sts_endpoints to try if the defined one fails. Requires Vault 1.19+ Specifies a list of custom STS fallback endpoints to use (in order).
Ordered list of sts_regions matching the fallback endpoints. Should correspond in order with those endpoints. Requires Vault 1.19+ Specifies a list of custom STS fallback regions to use (in order).
THIS IS A BETA FIELD. It is on by default but can be opted out through a Crossplane feature flag. ManagementPolicies specify the array of actions Crossplane is allowed to take on the managed and external resources. See the design doc for more information: https://github.com/crossplane/crossplane/blob/499895a25d1a1a0ba1604944ef98ac7a1a71f197/design/design-doc-observe-only-resources.md?plain=1#L223 and this one: https://github.com/crossplane/crossplane/blob/444267e84783136daa93568b364a5f01228cacbe/design/one-pager-ignore-changes.md
WriteConnectionSecretToReference specifies the namespace and name of a Secret to which any connection details for this managed resource should be written. Connection details frequently include the endpoint, username, and password required to connect to the managed resource.
SecretBackendStatus defines the observed state of SecretBackend.
(No description available)
Set of managed key registry entry names that the mount in question is allowed to access List of managed key registry entry names that the mount in question is allowed to access
List of headers to allow, allowing a plugin to include them in the response. List of headers to allow and pass from the request to the plugin
Specifies the list of keys that will not be HMAC'd by audit devices in the request data object. Specifies the list of keys that will not be HMAC'd by audit devices in the request data object.
Specifies the list of keys that will not be HMAC'd by audit devices in the response data object. Specifies the list of keys that will not be HMAC'd by audit devices in the response data object.
List of allowed authentication mount accessors the backend can request delegated authentication for. List of headers to allow and pass from the request to the plugin
List of headers to allow and pass from the request to the plugin. List of headers to allow and pass from the request to the plugin
Ordered list of sts_endpoints to try if the defined one fails. Requires Vault 1.19+ Specifies a list of custom STS fallback endpoints to use (in order).
Ordered list of sts_regions matching the fallback endpoints. Should correspond in order with those endpoints. Requires Vault 1.19+ Specifies a list of custom STS fallback regions to use (in order).
Conditions of the resource.