apiVersion: external-secrets.io/v1alpha1 kind: SecretStore metadata: name: vault-backend namespace: cert-manager spec: provider: vault: server: "http://vault.vault:8200" path: "kv" version: "v2" auth: kubernetes: mountPath: "kubernetes" role: "kube-role" --- apiVersion: external-secrets.io/v1alpha1 kind: ExternalSecret metadata: name: vault-example namespace: cert-manager spec: secretStoreRef: name: vault-backend kind: SecretStore target: name: cloudflare-api-token data: - secretKey: CLOUDFLARE_API_KEY remoteRef: key: cloudflare-api-token-secret property: CLOUDFLARE_API_KEY