cyberark/secrets-provider-for-k8s

View on GitHub
deploy/config/k8s/k8s-secret.yml

Summary

Maintainability
Test Coverage
# kics-scan ignore - Kics incorrectly identifies the Conjur secret paths as hardcoded values
apiVersion: v1
kind: Secret
metadata:
  name: test-k8s-secret
type: Opaque
stringData:
  conjur-map: |-
    secret: secrets/test_secret
    ssh_key: secrets/ssh_key
    json_object_secret: secrets/json_object_secret
    var_with_spaces: secrets/var with spaces
    var_with_pluses: secrets/var+with+pluses
    var_with_umlaut: secrets/umlaut
    var_with_base64:
      id: secrets/encoded
      content-type: base64
  non-conjur-key: some-value

---
apiVersion: v1
kind: Secret
metadata:
  name: test-k8s-secret-fetch-all
type: Opaque
stringData:
  conjur-map: |-
    "*": "*"
  non-conjur-key: some-value

---
apiVersion: v1
kind: Secret
metadata:
  name: test-k8s-secret-fetch-all-base64
type: Opaque
stringData:
  conjur-map: |-
    "*":
      id: "*"
      content-type: base64
  non-conjur-key: some-value