apiVersion: external-secrets.io/v1beta1 kind: ClusterSecretStore metadata: name: vault spec: provider: vault: server: "https://vault.internal.prd.durp.info" path: "secrets" version: "v2" auth: kubernetes: mountPath: "kubernetes" role: "dmz-external-secrets" --- apiVersion: external-secrets.io/v1beta1 kind: ExternalSecret metadata: name: cloudflare-api-token-secret spec: secretStoreRef: name: vault kind: ClusterSecretStore target: name: cloudflare-api-token-secret data: - secretKey: cloudflare-api-token-secret remoteRef: key: secrets/cert-manager property: cloudflare-api-token-secret