Secret fields
Reference for kind: Secret. Deploy and consumption are on Secrets.
Strict decoding applies to spec. data is a separate map of strings.
apiVersion: datasance.com/v3 # required, string
kind: Secret # required, string
metadata:
name: postgres-creds # required, string. Lowercase alphanumeric
namespace: my-ecn # no, string. Must match -n
spec:
type: Opaque # no, string. Opaque or tls. Re-deploy updates data only
data: # required, map of string. Document root
password: changeme
metadata.namespace must match -n.
Fields
| Field | Location | Required | Description |
|---|---|---|---|
metadata.name | metadata | Yes | Secret name. Lowercase alphanumeric. Unique in the namespace. |
spec.type | spec | No | Type on create, such as Opaque or tls. Re-deploy updates data only. |
data | root | Yes | Keys to string values. Encoding depends on spec.type. |
type: tls
Used when a certificate authority imports type: direct. Each value is a single-line base64 string of the raw PEM bytes. Standard base64. No line breaks.
| Key | PEM content before base64 |
|---|---|
tls.crt | Certificate |
tls.key | Private key |
ca.crt | CA or bundle. Optional. |
spec:
type: tls
data:
tls.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0t
tls.key: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQ
Encode on the operator machine with base64 and strip newlines. A multiline -----BEGIN CERTIFICATE----- block in data is the wrong shape for type: tls.
Opaque values
For Opaque, or when type is omitted, data values are plain strings: passwords, tokens, JWT text. They are base64 only when you choose to store base64 text. valueFromSecret reads the stored string.
Deploy
| State | CLI |
|---|---|
| Absent | Create with name, type, and data. |
| Present | Update with the new data map. |
| Condition | Result |
|---|---|
| Empty name | Error. |
| Invalid name characters | Lowercase alphanumeric check fails. |
| No Controller in the namespace | Error. |
| Invalid YAML | Unmarshal error. |
Describe round-trips spec.type and data.
A volume mount sets spec.secretName to this metadata.name. See VolumeMount fields.