Skip to main content
Version: v3.9.0

Secret fields

Reference for kind: Secret. Deploy and consumption are on Secrets.

Strict decoding applies to spec. data is a separate map of strings.

Deploy
apiVersion: datasance.com/v3 # required, string
kind: Secret # required, string
metadata:
name: postgres-creds # required, string. Lowercase alphanumeric
namespace: my-ecn # no, string. Must match -n
spec:
type: Opaque # no, string. Opaque or tls. Re-deploy updates data only
data: # required, map of string. Document root
password: changeme

metadata.namespace must match -n.

Fields​

FieldLocationRequiredDescription
metadata.namemetadataYesSecret name. Lowercase alphanumeric. Unique in the namespace.
spec.typespecNoType on create, such as Opaque or tls. Re-deploy updates data only.
datarootYesKeys to string values. Encoding depends on spec.type.

type: tls​

Used when a certificate authority imports type: direct. Each value is a single-line base64 string of the raw PEM bytes. Standard base64. No line breaks.

KeyPEM content before base64
tls.crtCertificate
tls.keyPrivate key
ca.crtCA or bundle. Optional.
spec:
type: tls
data:
tls.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0t
tls.key: LS0tLS1CRUdJTiBSU0EgUFJJVkFURSBLRVktLS0tLQ

Encode on the operator machine with base64 and strip newlines. A multiline -----BEGIN CERTIFICATE----- block in data is the wrong shape for type: tls.

Opaque values​

For Opaque, or when type is omitted, data values are plain strings: passwords, tokens, JWT text. They are base64 only when you choose to store base64 text. valueFromSecret reads the stored string.

Deploy​

StateCLI
AbsentCreate with name, type, and data.
PresentUpdate with the new data map.
ConditionResult
Empty nameError.
Invalid name charactersLowercase alphanumeric check fails.
No Controller in the namespaceError.
Invalid YAMLUnmarshal error.

Describe round-trips spec.type and data.

A volume mount sets spec.secretName to this metadata.name. See VolumeMount fields.

Group 3See anything wrong with the document? Help us improve it!