apiVersion: external-secrets.io/v1beta1 kind: ExternalSecret metadata: name: vault-argocd labels: app.kubernetes.io/part-of: argocd spec: secretStoreRef: name: vault-argocd kind: SecretStore target: name: client-secret data: - secretKey: clientSecret remoteRef: key: secrets/argocd/authentik property: clientsecret --- apiVersion: external-secrets.io/v1beta1 kind: SecretStore metadata: name: vault-argocd spec: provider: vault: server: "http://vault.vault.svc.cluster.local:8200" path: "argocd" version: "v2" auth: kubernetes: mountPath: "kubernetes" role: "external-secrets"