apiVersion: external-secrets.io/v1alpha1 kind: SecretStore metadata: name: ext-renovate-backend namespace: ci spec: provider: vault: server: "http://vault.vault:8200" path: "kv" version: "v2" auth: kubernetes: mountPath: "kubernetes" role: "kube-role" --- apiVersion: external-secrets.io/v1alpha1 kind: ExternalSecret metadata: name: ext-renovate namespace: ci spec: secretStoreRef: name: ext-renovate-backend kind: SecretStore target: name: renovate-secret data: - secretKey: GITHUB_COM_TOKEN remoteRef: key: ci/renovate property: github - secretKey: RENOVATE_TOKEN remoteRef: key: ci/renovate property: token