apiVersion: external-secrets.io/v1beta1 kind: ClusterSecretStore metadata: name: secret-store namespace: external-secrets spec: provider: vault: server: "http://vault.vault:8200" path: "kv" version: "v2" auth: kubernetes: mountPath: "kubernetes" role: "kube-role" conditions: - namespaceSelector: matchLabels: secret.roxedus.com/global-store: "true"