Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: add support for Hashicorp Vault mTLS #3018

Merged
merged 3 commits into from Jan 18, 2024

Conversation

rodrigorfk
Copy link
Contributor

@rodrigorfk rodrigorfk commented Jan 11, 2024

Problem Statement

Vault server can be configured to strictly enforce clients to present client certificates while connecting to the server in the HTTPs transport layer.

It is possible to configure Vault to use a client certificate to secure the transport layer (tcp listener documentation):

listener "tcp" {
  tls_disable = false
  tls_cert_file = "/vault/tls/server.crt"
  tls_key_file = "/vault/tls/server.key"
  tls_client_ca_file = "/vault/tls/ca.crt"
  tls_require_and_verify_client_cert = true
}

When Vault is configured in the way above, there is no possibility to properly configure the Vault provider in the SecretStore by using existing CRDs.

Related Issue

Fixes #1139

Proposed Changes

This change is adding a new section in the Vault provider allow passing the client TLS certificate to the transport layer as following:

apiVersion: external-secrets.io/v1beta1
kind: SecretStore
metadata:
  name: vault-backend
  namespace: example
spec:
  provider:
    vault:
      server: "https://vault.acme.org"
      path: "secret"
      version: "v2"

      # client TLS related configuration
      caBundle: "..."
      tls:
        clientCert:
          name: "my-cert-secret"
          key: "tls.crt"
        secretRef:
          name: "my-cert-secret"
          key: "tls.key"

      # the authentication methods are not really related to the client TLS configuration
      auth:
        ...

Checklist

  • I have read the contribution guidelines
  • All commits are signed with git commit --signoff
  • My changes have reasonable test coverage
  • All tests pass with make test
  • I ensured my PR is ready for review with make reviewable

@rodrigorfk rodrigorfk requested a review from a team as a code owner January 11, 2024 15:46
@rodrigorfk rodrigorfk requested review from moolen and removed request for a team January 11, 2024 15:46
Copy link
Member

@moolen moolen left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Very nice work, thank you a lot for your contribution 🙇
I'm super happy to see e2e tests, too 🥳 🏅

apis/externalsecrets/v1beta1/secretstore_vault_types.go Outdated Show resolved Hide resolved
docs/provider/hashicorp-vault.md Show resolved Hide resolved
e2e/k8s/vault-mtls.values.yaml Outdated Show resolved Hide resolved
Comment on lines 29 to 32
framework.Compose(withTokenAuth, f, common.FindByName, useTokenAuth),
framework.Compose(withTokenAuth, f, common.FindByNameAndRewrite, useTokenAuth),
framework.Compose(withTokenAuth, f, common.JSONDataFromSync, useTokenAuth),
framework.Compose(withTokenAuth, f, common.JSONDataFromRewrite, useTokenAuth),
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These are a lot of tests that need to run, although they don't provide a lot of value. In essence only one test is needed to verify that the mTLS is being accepted by vault.

As mentioned above: if we add one additional listener for vault - one that requires mTLS - then we can add another store which has mTLS enabled and we just need to add one test to the suites/provider/cases/vault/vault.go file, something like this:

// ..
framework.Compose(
  withTokenAuthAndMTLS, f, common.FindByName, useMTLSAndTokenAuth)
// ...

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good point, thanks for the suggestion, I will update the PR to follow it.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@moolen , as commented above, using a second listener is not that simple, the Vault helm chart does not allow customising the Service and add the new port to it, I kept the vault_mtls.go implementation and reduced the number of tests to cover just a single SecretStore and ClusterSecretStore test case. What do you think?

@moolen
Copy link
Member

moolen commented Jan 12, 2024

/ok-to-test sha=0a83f73

@rodrigorfk rodrigorfk force-pushed the feat-vault-mtls branch 4 times, most recently from d11d153 to a2ebf4b Compare January 17, 2024 13:14
Signed-off-by: Rodrigo Fior Kuntzer <rodrigo@miro.com>
Signed-off-by: Rodrigo Fior Kuntzer <rodrigo@miro.com>
@moolen
Copy link
Member

moolen commented Jan 17, 2024

/ok-to-test sha=a2ebf4b

Signed-off-by: Rodrigo Fior Kuntzer <rodrigo@miro.com>
Copy link

sonarcloud bot commented Jan 17, 2024

Quality Gate Passed Quality Gate passed

The SonarCloud Quality Gate passed, but some issues were introduced.

1 New issue
0 Security Hotspots
No data about Coverage
0.0% Duplication on New Code

See analysis details on SonarCloud

@rodrigorfk
Copy link
Contributor Author

rodrigorfk commented Jan 17, 2024

@moolen I have performed a final amend to the PR because I notice a flaky integration test due to concurrency caused by the ClusterSecretStore left orphan after each Vault e2e test is executed, it should be fixed now, but I also believe is worth performing a few rounds of the vault ginkgo label suite just to make sure there is no race condition left.

I also tried to reduce the code complexity of the newConfig function as reported by Sonar above by extracting my code into a new func, however Sonar still complaining about the complexity of the existing code.

@moolen
Copy link
Member

moolen commented Jan 17, 2024

/ok-to-test sha=082bd9c

@moolen
Copy link
Member

moolen commented Jan 17, 2024

Thank you @rodrigorfk, i'll take a look. Don't mind the sonarcube failures, no need to fix it right now :)

Copy link
Member

@moolen moolen left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thank you for your contribution! 🏅

// edit: i ran the e2e tests a couple of times, looks good!

@moolen moolen merged commit 31cecaa into external-secrets:main Jan 18, 2024
14 checks passed
@rodrigorfk rodrigorfk deleted the feat-vault-mtls branch January 18, 2024 23:48
charan986 pushed a commit to charan986/external-secrets that referenced this pull request Jan 22, 2024
* feat: adding support for mTLS to the Vault provider

Signed-off-by: Rodrigo Fior Kuntzer <rodrigo@miro.com>
Signed-off-by: Sai Charan Godasi <saicharangodasi@Sais-MacBook-Air.local>
mike-serchenia pushed a commit to ElementalCognition/external-secrets that referenced this pull request Jan 30, 2024
* feat: adding support for mTLS to the Vault provider

Signed-off-by: Rodrigo Fior Kuntzer <rodrigo@miro.com>
Signed-off-by: Mike Serchenia <michael_serchenia@epam.com>
SubrotoRoy pushed a commit to cloudant/external-secrets that referenced this pull request Feb 6, 2024
* feat: adding support for mTLS to the Vault provider

Signed-off-by: Rodrigo Fior Kuntzer <rodrigo@miro.com>
vardhanreddy13 pushed a commit to cloudant/external-secrets that referenced this pull request Feb 6, 2024
* feat: adding support for mTLS to the Vault provider

Signed-off-by: Rodrigo Fior Kuntzer <rodrigo@miro.com>
sourav977 pushed a commit to cloudant/external-secrets that referenced this pull request Feb 6, 2024
* feat: adding support for mTLS to the Vault provider

Signed-off-by: Rodrigo Fior Kuntzer <rodrigo@miro.com>
SubrotoRoy pushed a commit to cloudant/external-secrets that referenced this pull request Feb 6, 2024
* feat: adding support for mTLS to the Vault provider

Signed-off-by: Rodrigo Fior Kuntzer <rodrigo@miro.com>
sourav977 pushed a commit to cloudant/external-secrets that referenced this pull request Feb 6, 2024
* feat: adding support for mTLS to the Vault provider

Signed-off-by: Rodrigo Fior Kuntzer <rodrigo@miro.com>
SubrotoRoy pushed a commit to cloudant/external-secrets that referenced this pull request Feb 6, 2024
* feat: adding support for mTLS to the Vault provider

Signed-off-by: Rodrigo Fior Kuntzer <rodrigo@miro.com>
lumiere-bot bot added a commit to coolguy1771/home-ops that referenced this pull request Feb 14, 2024
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[external-secrets](https://togithub.com/external-secrets/external-secrets)
| patch | `0.9.11` -> `0.9.12` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>external-secrets/external-secrets (external-secrets)</summary>

###
[`v0.9.12`](https://togithub.com/external-secrets/external-secrets/releases/tag/v0.9.12)

[Compare
Source](https://togithub.com/external-secrets/external-secrets/compare/v0.9.11...v0.9.12)

Image: `ghcr.io/external-secrets/external-secrets:v0.9.12`
Image: `ghcr.io/external-secrets/external-secrets:v0.9.12-ubi`
Image: `ghcr.io/external-secrets/external-secrets:v0.9.12-ubi-boringssl`

#### What's Changed

- bump 0.9.11 by [@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#2982
- chore(deps): bump golang from 1.20.1 to 1.21.5 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#2976
- fix: chart: update cert-manager cert. duration by
[@&#8203;Tycale](https://togithub.com/Tycale) in
[external-secrets/external-secrets#2986
- chore: update dependencies by
[@&#8203;eso-service-account-app](https://togithub.com/eso-service-account-app)
in
[external-secrets/external-secrets#2988
- Fix value name by [@&#8203;Aransh](https://togithub.com/Aransh) in
[external-secrets/external-secrets#2985
- feat: add ability to define flavour for tag by
[@&#8203;A1994SC](https://togithub.com/A1994SC) in
[external-secrets/external-secrets#2881
- Fix typo in pushsecrets docs by
[@&#8203;matusf](https://togithub.com/matusf) in
[external-secrets/external-secrets#2998
- feat: add PushSecret and DeleteSecret to onepassword provider by
[@&#8203;bthuilot](https://togithub.com/bthuilot) in
[external-secrets/external-secrets#2646
- Configure codecov by
[@&#8203;shuheiktgw](https://togithub.com/shuheiktgw) in
[external-secrets/external-secrets#2995
- added some example for v2 literal templating by
[@&#8203;rpasche](https://togithub.com/rpasche) in
[external-secrets/external-secrets#3007
- Akeyless Provider - Add support for Certificate items by
[@&#8203;barucoh](https://togithub.com/barucoh) in
[external-secrets/external-secrets#3013
- chore: update dependencies by
[@&#8203;eso-service-account-app](https://togithub.com/eso-service-account-app)
in
[external-secrets/external-secrets#3005
- Feat/allow keeper to work with complex types by
[@&#8203;ppodevlabs](https://togithub.com/ppodevlabs) in
[external-secrets/external-secrets#3016
- docs: update controller reconcile error rule by
[@&#8203;aslafy-z](https://togithub.com/aslafy-z) in
[external-secrets/external-secrets#3021
- Issue/2965 - Documentation does not reflect latest changes for
datafrom for IBM Secret Manager by
[@&#8203;fdberlking](https://togithub.com/fdberlking) in
[external-secrets/external-secrets#3010
- doc: update bitwarden-cli image & version by
[@&#8203;charlesthomas](https://togithub.com/charlesthomas) in
[external-secrets/external-secrets#2971
- Update the ExternalSecret status even when data is empty by
[@&#8203;shuheiktgw](https://togithub.com/shuheiktgw) in
[external-secrets/external-secrets#2927
- grammar - it is by [@&#8203;aviadkray](https://togithub.com/aviadkray)
in
[external-secrets/external-secrets#2991
- gramar2 - intuitive not intuative by
[@&#8203;aviadkray](https://togithub.com/aviadkray) in
[external-secrets/external-secrets#2992
- docs: add command to install CRDs using kustomize by
[@&#8203;PeterStolz](https://togithub.com/PeterStolz) in
[external-secrets/external-secrets#3023
- Validator by [@&#8203;Mehrbod2002](https://togithub.com/Mehrbod2002)
in
[external-secrets/external-secrets#3003
- chore(deps): bump golang from 1.21.5 to 1.21.6 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3024
- feat: set default namespace on vault secretStore (namespaced
ressource) by [@&#8203;M0NsTeRRR](https://togithub.com/M0NsTeRRR) in
[external-secrets/external-secrets#2869
- Create OSSF scorecard job by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3032
- feat: add support for Hashicorp Vault mTLS by
[@&#8203;rodrigorfk](https://togithub.com/rodrigorfk) in
[external-secrets/external-secrets#3018
- \[Snyk] Fix for 5 vulnerabilities by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3036
- chore(deps): bump tornado from 6.3.3 to 6.4 in /hack/api-docs by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3051
- chore(deps): bump click from 8.1.3 to 8.1.7 in /hack/api-docs by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3050
- chore(deps): bump actions/cache from 3.3.3 to 4.0.0 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3049
- chore(deps): bump github/codeql-action from 2.2.4 to 3.23.1 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3048
- chore(deps): bump markupsafe from 2.1.1 to 2.1.3 in /hack/api-docs by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3047
- chore(deps): bump mkdocs-macros-plugin from 0.7.0 to 1.0.5 in
/hack/api-docs by [@&#8203;dependabot](https://togithub.com/dependabot)
in
[external-secrets/external-secrets#3046
- chore(deps): bump actions/checkout from 3.1.0 to 4.1.1 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3044
- chore(deps): bump golang from `fd78f2f` to `fd78f2f` by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3042
- chore(deps): bump ubi8/ubi-minimal from `d8b81a3` to `2882390` by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3041
- chore(deps): bump alpine from `13b7e62` to `51b6726` in /e2e by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3040
- chore(deps): bump golang from `04cf306` to `c4b696f` in /e2e by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3038
- chore(deps): bump mkdocs-material from 9.5.3 to 9.5.4 in
/hack/api-docs by [@&#8203;dependabot](https://togithub.com/dependabot)
in
[external-secrets/external-secrets#3043
- chore(deps): bump ossf/scorecard-action from 2.1.2 to 2.3.1 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3045
- docs: add security response process by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3037
- Fix wrong namespaceSelector configuration in snippet in document by
[@&#8203;kyasbal](https://togithub.com/kyasbal) in
[external-secrets/external-secrets#3054
- chore: refactor/centralise secretKeyRef usage by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3022
- chore: fixup security response suggestions by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3056
- feat: allow provider to return admission warnings by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3058
- chore(deps): bump alpine from 3.18 to 3.19 in /hack/api-docs by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3039
- chore: add tests for AWS/SM by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3057
- chore(deps): bump mkdocs-minify-plugin from 0.5.0 to 0.7.2 in
/hack/api-docs by [@&#8203;dependabot](https://togithub.com/dependabot)
in
[external-secrets/external-secrets#3063
- chore(deps): bump markupsafe from 2.1.3 to 2.1.4 in /hack/api-docs by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3062
- chore: update dependencies by
[@&#8203;eso-service-account-app](https://togithub.com/eso-service-account-app)
in
[external-secrets/external-secrets#3065
- added metrics support for akeyless by
[@&#8203;charan986](https://togithub.com/charan986) in
[external-secrets/external-secrets#3069
- chore: bump jwx pkg by [@&#8203;moolen](https://togithub.com/moolen)
in
[external-secrets/external-secrets#3075
- IBM provider: remove deprecated code for fetching secret by name by
[@&#8203;Shanti-G](https://togithub.com/Shanti-G) in
[external-secrets/external-secrets#3078
- chore(deps): bump codecov/codecov-action from 3.1.4 to 3.1.5 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3090
- chore(deps): bump golang from `fd78f2f` to `a6a7f1f` by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3086
- chore(deps): bump alpine from `51b6726` to `c5b1261` in /hack/api-docs
by [@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3088
- chore(deps): bump github/codeql-action from 3.23.1 to 3.23.2 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3089
- chore(deps): bump golang from `c4b696f` to `d8c365d` in /e2e by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3084
- chore(deps): bump alpine from `51b6726` to `c5b1261` by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3087
- 🧹 refactor vault provider by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3072
- chore: bump ubi image by [@&#8203;moolen](https://togithub.com/moolen)
in
[external-secrets/external-secrets#3096
- chore: update dependencies by
[@&#8203;eso-service-account-app](https://togithub.com/eso-service-account-app)
in
[external-secrets/external-secrets#3091
- chore(deps): bump alpine from 3.19.0 to 3.19.1 in /e2e by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3083
- chore(deps): bump codecov/codecov-action from 3.1.5 to 4.0.1 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3104
- chore(deps): bump github/codeql-action from 3.23.2 to 3.24.0 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3103
- chore: update dependencies by
[@&#8203;eso-service-account-app](https://togithub.com/eso-service-account-app)
in
[external-secrets/external-secrets#3113
- chore(deps): bump peter-evans/slash-command-dispatch from 3.0.2 to
4.0.0 by [@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3102
- Feat/ready condition early by
[@&#8203;ppatel1604](https://togithub.com/ppatel1604) in
[external-secrets/external-secrets#3077
- chore(deps): bump mkdocs-material from 9.5.4 to 9.5.7 in
/hack/api-docs by [@&#8203;dependabot](https://togithub.com/dependabot)
in
[external-secrets/external-secrets#3106
- chore(deps): bump platformdirs from 4.1.0 to 4.2.0 in /hack/api-docs
by [@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3105
- chore(deps): bump markupsafe from 2.1.4 to 2.1.5 in /hack/api-docs by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3107
- chore(deps): bump urllib3 from 2.1.0 to 2.2.0 in /hack/api-docs by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3109
- chore(deps): bump mkdocs-minify-plugin from 0.7.2 to 0.8.0 in
/hack/api-docs by [@&#8203;dependabot](https://togithub.com/dependabot)
in
[external-secrets/external-secrets#3108

#### New Contributors

- [@&#8203;Tycale](https://togithub.com/Tycale) made their first
contribution in
[external-secrets/external-secrets#2986
- [@&#8203;Aransh](https://togithub.com/Aransh) made their first
contribution in
[external-secrets/external-secrets#2985
- [@&#8203;A1994SC](https://togithub.com/A1994SC) made their first
contribution in
[external-secrets/external-secrets#2881
- [@&#8203;matusf](https://togithub.com/matusf) made their first
contribution in
[external-secrets/external-secrets#2998
- [@&#8203;bthuilot](https://togithub.com/bthuilot) made their first
contribution in
[external-secrets/external-secrets#2646
- [@&#8203;rpasche](https://togithub.com/rpasche) made their first
contribution in
[external-secrets/external-secrets#3007
- [@&#8203;barucoh](https://togithub.com/barucoh) made their first
contribution in
[external-secrets/external-secrets#3013
- [@&#8203;aslafy-z](https://togithub.com/aslafy-z) made their first
contribution in
[external-secrets/external-secrets#3021
- [@&#8203;fdberlking](https://togithub.com/fdberlking) made their first
contribution in
[external-secrets/external-secrets#3010
- [@&#8203;charlesthomas](https://togithub.com/charlesthomas) made their
first contribution in
[external-secrets/external-secrets#2971
- [@&#8203;aviadkray](https://togithub.com/aviadkray) made their first
contribution in
[external-secrets/external-secrets#2991
- [@&#8203;PeterStolz](https://togithub.com/PeterStolz) made their first
contribution in
[external-secrets/external-secrets#3023
- [@&#8203;Mehrbod2002](https://togithub.com/Mehrbod2002) made their
first contribution in
[external-secrets/external-secrets#3003
- [@&#8203;M0NsTeRRR](https://togithub.com/M0NsTeRRR) made their first
contribution in
[external-secrets/external-secrets#2869
- [@&#8203;rodrigorfk](https://togithub.com/rodrigorfk) made their first
contribution in
[external-secrets/external-secrets#3018
- [@&#8203;kyasbal](https://togithub.com/kyasbal) made their first
contribution in
[external-secrets/external-secrets#3054

**Full Changelog**:
external-secrets/external-secrets@v0.9.11...v0.9.12

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://togithub.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4xODAuMCIsInVwZGF0ZWRJblZlciI6IjM3LjE4MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiJ9-->

Co-authored-by: lumiere-bot[bot] <98047013+lumiere-bot[bot]@users.noreply.github.com>
lumiere-bot bot added a commit to coolguy1771/home-ops that referenced this pull request Feb 14, 2024
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[external-secrets](https://togithub.com/external-secrets/external-secrets)
| patch | `0.9.11` -> `0.9.12` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>external-secrets/external-secrets (external-secrets)</summary>

###
[`v0.9.12`](https://togithub.com/external-secrets/external-secrets/releases/tag/v0.9.12)

[Compare
Source](https://togithub.com/external-secrets/external-secrets/compare/v0.9.11...v0.9.12)

Image: `ghcr.io/external-secrets/external-secrets:v0.9.12`
Image: `ghcr.io/external-secrets/external-secrets:v0.9.12-ubi`
Image: `ghcr.io/external-secrets/external-secrets:v0.9.12-ubi-boringssl`

#### What's Changed

- bump 0.9.11 by [@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#2982
- chore(deps): bump golang from 1.20.1 to 1.21.5 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#2976
- fix: chart: update cert-manager cert. duration by
[@&#8203;Tycale](https://togithub.com/Tycale) in
[external-secrets/external-secrets#2986
- chore: update dependencies by
[@&#8203;eso-service-account-app](https://togithub.com/eso-service-account-app)
in
[external-secrets/external-secrets#2988
- Fix value name by [@&#8203;Aransh](https://togithub.com/Aransh) in
[external-secrets/external-secrets#2985
- feat: add ability to define flavour for tag by
[@&#8203;A1994SC](https://togithub.com/A1994SC) in
[external-secrets/external-secrets#2881
- Fix typo in pushsecrets docs by
[@&#8203;matusf](https://togithub.com/matusf) in
[external-secrets/external-secrets#2998
- feat: add PushSecret and DeleteSecret to onepassword provider by
[@&#8203;bthuilot](https://togithub.com/bthuilot) in
[external-secrets/external-secrets#2646
- Configure codecov by
[@&#8203;shuheiktgw](https://togithub.com/shuheiktgw) in
[external-secrets/external-secrets#2995
- added some example for v2 literal templating by
[@&#8203;rpasche](https://togithub.com/rpasche) in
[external-secrets/external-secrets#3007
- Akeyless Provider - Add support for Certificate items by
[@&#8203;barucoh](https://togithub.com/barucoh) in
[external-secrets/external-secrets#3013
- chore: update dependencies by
[@&#8203;eso-service-account-app](https://togithub.com/eso-service-account-app)
in
[external-secrets/external-secrets#3005
- Feat/allow keeper to work with complex types by
[@&#8203;ppodevlabs](https://togithub.com/ppodevlabs) in
[external-secrets/external-secrets#3016
- docs: update controller reconcile error rule by
[@&#8203;aslafy-z](https://togithub.com/aslafy-z) in
[external-secrets/external-secrets#3021
- Issue/2965 - Documentation does not reflect latest changes for
datafrom for IBM Secret Manager by
[@&#8203;fdberlking](https://togithub.com/fdberlking) in
[external-secrets/external-secrets#3010
- doc: update bitwarden-cli image & version by
[@&#8203;charlesthomas](https://togithub.com/charlesthomas) in
[external-secrets/external-secrets#2971
- Update the ExternalSecret status even when data is empty by
[@&#8203;shuheiktgw](https://togithub.com/shuheiktgw) in
[external-secrets/external-secrets#2927
- grammar - it is by [@&#8203;aviadkray](https://togithub.com/aviadkray)
in
[external-secrets/external-secrets#2991
- gramar2 - intuitive not intuative by
[@&#8203;aviadkray](https://togithub.com/aviadkray) in
[external-secrets/external-secrets#2992
- docs: add command to install CRDs using kustomize by
[@&#8203;PeterStolz](https://togithub.com/PeterStolz) in
[external-secrets/external-secrets#3023
- Validator by [@&#8203;Mehrbod2002](https://togithub.com/Mehrbod2002)
in
[external-secrets/external-secrets#3003
- chore(deps): bump golang from 1.21.5 to 1.21.6 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3024
- feat: set default namespace on vault secretStore (namespaced
ressource) by [@&#8203;M0NsTeRRR](https://togithub.com/M0NsTeRRR) in
[external-secrets/external-secrets#2869
- Create OSSF scorecard job by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3032
- feat: add support for Hashicorp Vault mTLS by
[@&#8203;rodrigorfk](https://togithub.com/rodrigorfk) in
[external-secrets/external-secrets#3018
- \[Snyk] Fix for 5 vulnerabilities by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3036
- chore(deps): bump tornado from 6.3.3 to 6.4 in /hack/api-docs by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3051
- chore(deps): bump click from 8.1.3 to 8.1.7 in /hack/api-docs by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3050
- chore(deps): bump actions/cache from 3.3.3 to 4.0.0 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3049
- chore(deps): bump github/codeql-action from 2.2.4 to 3.23.1 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3048
- chore(deps): bump markupsafe from 2.1.1 to 2.1.3 in /hack/api-docs by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3047
- chore(deps): bump mkdocs-macros-plugin from 0.7.0 to 1.0.5 in
/hack/api-docs by [@&#8203;dependabot](https://togithub.com/dependabot)
in
[external-secrets/external-secrets#3046
- chore(deps): bump actions/checkout from 3.1.0 to 4.1.1 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3044
- chore(deps): bump golang from `fd78f2f` to `fd78f2f` by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3042
- chore(deps): bump ubi8/ubi-minimal from `d8b81a3` to `2882390` by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3041
- chore(deps): bump alpine from `13b7e62` to `51b6726` in /e2e by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3040
- chore(deps): bump golang from `04cf306` to `c4b696f` in /e2e by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3038
- chore(deps): bump mkdocs-material from 9.5.3 to 9.5.4 in
/hack/api-docs by [@&#8203;dependabot](https://togithub.com/dependabot)
in
[external-secrets/external-secrets#3043
- chore(deps): bump ossf/scorecard-action from 2.1.2 to 2.3.1 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3045
- docs: add security response process by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3037
- Fix wrong namespaceSelector configuration in snippet in document by
[@&#8203;kyasbal](https://togithub.com/kyasbal) in
[external-secrets/external-secrets#3054
- chore: refactor/centralise secretKeyRef usage by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3022
- chore: fixup security response suggestions by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3056
- feat: allow provider to return admission warnings by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3058
- chore(deps): bump alpine from 3.18 to 3.19 in /hack/api-docs by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3039
- chore: add tests for AWS/SM by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3057
- chore(deps): bump mkdocs-minify-plugin from 0.5.0 to 0.7.2 in
/hack/api-docs by [@&#8203;dependabot](https://togithub.com/dependabot)
in
[external-secrets/external-secrets#3063
- chore(deps): bump markupsafe from 2.1.3 to 2.1.4 in /hack/api-docs by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3062
- chore: update dependencies by
[@&#8203;eso-service-account-app](https://togithub.com/eso-service-account-app)
in
[external-secrets/external-secrets#3065
- added metrics support for akeyless by
[@&#8203;charan986](https://togithub.com/charan986) in
[external-secrets/external-secrets#3069
- chore: bump jwx pkg by [@&#8203;moolen](https://togithub.com/moolen)
in
[external-secrets/external-secrets#3075
- IBM provider: remove deprecated code for fetching secret by name by
[@&#8203;Shanti-G](https://togithub.com/Shanti-G) in
[external-secrets/external-secrets#3078
- chore(deps): bump codecov/codecov-action from 3.1.4 to 3.1.5 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3090
- chore(deps): bump golang from `fd78f2f` to `a6a7f1f` by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3086
- chore(deps): bump alpine from `51b6726` to `c5b1261` in /hack/api-docs
by [@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3088
- chore(deps): bump github/codeql-action from 3.23.1 to 3.23.2 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3089
- chore(deps): bump golang from `c4b696f` to `d8c365d` in /e2e by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3084
- chore(deps): bump alpine from `51b6726` to `c5b1261` by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3087
- 🧹 refactor vault provider by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3072
- chore: bump ubi image by [@&#8203;moolen](https://togithub.com/moolen)
in
[external-secrets/external-secrets#3096
- chore: update dependencies by
[@&#8203;eso-service-account-app](https://togithub.com/eso-service-account-app)
in
[external-secrets/external-secrets#3091
- chore(deps): bump alpine from 3.19.0 to 3.19.1 in /e2e by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3083
- chore(deps): bump codecov/codecov-action from 3.1.5 to 4.0.1 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3104
- chore(deps): bump github/codeql-action from 3.23.2 to 3.24.0 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3103
- chore: update dependencies by
[@&#8203;eso-service-account-app](https://togithub.com/eso-service-account-app)
in
[external-secrets/external-secrets#3113
- chore(deps): bump peter-evans/slash-command-dispatch from 3.0.2 to
4.0.0 by [@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3102
- Feat/ready condition early by
[@&#8203;ppatel1604](https://togithub.com/ppatel1604) in
[external-secrets/external-secrets#3077
- chore(deps): bump mkdocs-material from 9.5.4 to 9.5.7 in
/hack/api-docs by [@&#8203;dependabot](https://togithub.com/dependabot)
in
[external-secrets/external-secrets#3106
- chore(deps): bump platformdirs from 4.1.0 to 4.2.0 in /hack/api-docs
by [@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3105
- chore(deps): bump markupsafe from 2.1.4 to 2.1.5 in /hack/api-docs by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3107
- chore(deps): bump urllib3 from 2.1.0 to 2.2.0 in /hack/api-docs by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3109
- chore(deps): bump mkdocs-minify-plugin from 0.7.2 to 0.8.0 in
/hack/api-docs by [@&#8203;dependabot](https://togithub.com/dependabot)
in
[external-secrets/external-secrets#3108

#### New Contributors

- [@&#8203;Tycale](https://togithub.com/Tycale) made their first
contribution in
[external-secrets/external-secrets#2986
- [@&#8203;Aransh](https://togithub.com/Aransh) made their first
contribution in
[external-secrets/external-secrets#2985
- [@&#8203;A1994SC](https://togithub.com/A1994SC) made their first
contribution in
[external-secrets/external-secrets#2881
- [@&#8203;matusf](https://togithub.com/matusf) made their first
contribution in
[external-secrets/external-secrets#2998
- [@&#8203;bthuilot](https://togithub.com/bthuilot) made their first
contribution in
[external-secrets/external-secrets#2646
- [@&#8203;rpasche](https://togithub.com/rpasche) made their first
contribution in
[external-secrets/external-secrets#3007
- [@&#8203;barucoh](https://togithub.com/barucoh) made their first
contribution in
[external-secrets/external-secrets#3013
- [@&#8203;aslafy-z](https://togithub.com/aslafy-z) made their first
contribution in
[external-secrets/external-secrets#3021
- [@&#8203;fdberlking](https://togithub.com/fdberlking) made their first
contribution in
[external-secrets/external-secrets#3010
- [@&#8203;charlesthomas](https://togithub.com/charlesthomas) made their
first contribution in
[external-secrets/external-secrets#2971
- [@&#8203;aviadkray](https://togithub.com/aviadkray) made their first
contribution in
[external-secrets/external-secrets#2991
- [@&#8203;PeterStolz](https://togithub.com/PeterStolz) made their first
contribution in
[external-secrets/external-secrets#3023
- [@&#8203;Mehrbod2002](https://togithub.com/Mehrbod2002) made their
first contribution in
[external-secrets/external-secrets#3003
- [@&#8203;M0NsTeRRR](https://togithub.com/M0NsTeRRR) made their first
contribution in
[external-secrets/external-secrets#2869
- [@&#8203;rodrigorfk](https://togithub.com/rodrigorfk) made their first
contribution in
[external-secrets/external-secrets#3018
- [@&#8203;kyasbal](https://togithub.com/kyasbal) made their first
contribution in
[external-secrets/external-secrets#3054

**Full Changelog**:
external-secrets/external-secrets@v0.9.11...v0.9.12

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://togithub.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4xODAuMCIsInVwZGF0ZWRJblZlciI6IjM3LjE4MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiJ9-->

Co-authored-by: lumiere-bot[bot] <98047013+lumiere-bot[bot]@users.noreply.github.com>
kireque pushed a commit to kireque/home-ops that referenced this pull request Feb 15, 2024
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[external-secrets](https://togithub.com/external-secrets/external-secrets)
| patch | `0.9.11` -> `0.9.12` |

---

### Release Notes

<details>
<summary>external-secrets/external-secrets (external-secrets)</summary>

###
[`v0.9.12`](https://togithub.com/external-secrets/external-secrets/releases/tag/v0.9.12)

[Compare
Source](https://togithub.com/external-secrets/external-secrets/compare/v0.9.11...v0.9.12)

Image: `ghcr.io/external-secrets/external-secrets:v0.9.12`
Image: `ghcr.io/external-secrets/external-secrets:v0.9.12-ubi`
Image: `ghcr.io/external-secrets/external-secrets:v0.9.12-ubi-boringssl`

#### What's Changed

- bump 0.9.11 by [@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#2982
- chore(deps): bump golang from 1.20.1 to 1.21.5 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#2976
- fix: chart: update cert-manager cert. duration by
[@&#8203;Tycale](https://togithub.com/Tycale) in
[external-secrets/external-secrets#2986
- chore: update dependencies by
[@&#8203;eso-service-account-app](https://togithub.com/eso-service-account-app)
in
[external-secrets/external-secrets#2988
- Fix value name by [@&#8203;Aransh](https://togithub.com/Aransh) in
[external-secrets/external-secrets#2985
- feat: add ability to define flavour for tag by
[@&#8203;A1994SC](https://togithub.com/A1994SC) in
[external-secrets/external-secrets#2881
- Fix typo in pushsecrets docs by
[@&#8203;matusf](https://togithub.com/matusf) in
[external-secrets/external-secrets#2998
- feat: add PushSecret and DeleteSecret to onepassword provider by
[@&#8203;bthuilot](https://togithub.com/bthuilot) in
[external-secrets/external-secrets#2646
- Configure codecov by
[@&#8203;shuheiktgw](https://togithub.com/shuheiktgw) in
[external-secrets/external-secrets#2995
- added some example for v2 literal templating by
[@&#8203;rpasche](https://togithub.com/rpasche) in
[external-secrets/external-secrets#3007
- Akeyless Provider - Add support for Certificate items by
[@&#8203;barucoh](https://togithub.com/barucoh) in
[external-secrets/external-secrets#3013
- chore: update dependencies by
[@&#8203;eso-service-account-app](https://togithub.com/eso-service-account-app)
in
[external-secrets/external-secrets#3005
- Feat/allow keeper to work with complex types by
[@&#8203;ppodevlabs](https://togithub.com/ppodevlabs) in
[external-secrets/external-secrets#3016
- docs: update controller reconcile error rule by
[@&#8203;aslafy-z](https://togithub.com/aslafy-z) in
[external-secrets/external-secrets#3021
- Issue/2965 - Documentation does not reflect latest changes for
datafrom for IBM Secret Manager by
[@&#8203;fdberlking](https://togithub.com/fdberlking) in
[external-secrets/external-secrets#3010
- doc: update bitwarden-cli image & version by
[@&#8203;charlesthomas](https://togithub.com/charlesthomas) in
[external-secrets/external-secrets#2971
- Update the ExternalSecret status even when data is empty by
[@&#8203;shuheiktgw](https://togithub.com/shuheiktgw) in
[external-secrets/external-secrets#2927
- grammar - it is by [@&#8203;aviadkray](https://togithub.com/aviadkray)
in
[external-secrets/external-secrets#2991
- gramar2 - intuitive not intuative by
[@&#8203;aviadkray](https://togithub.com/aviadkray) in
[external-secrets/external-secrets#2992
- docs: add command to install CRDs using kustomize by
[@&#8203;PeterStolz](https://togithub.com/PeterStolz) in
[external-secrets/external-secrets#3023
- Validator by [@&#8203;Mehrbod2002](https://togithub.com/Mehrbod2002)
in
[external-secrets/external-secrets#3003
- chore(deps): bump golang from 1.21.5 to 1.21.6 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3024
- feat: set default namespace on vault secretStore (namespaced
ressource) by [@&#8203;M0NsTeRRR](https://togithub.com/M0NsTeRRR) in
[external-secrets/external-secrets#2869
- Create OSSF scorecard job by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3032
- feat: add support for Hashicorp Vault mTLS by
[@&#8203;rodrigorfk](https://togithub.com/rodrigorfk) in
[external-secrets/external-secrets#3018
- \[Snyk] Fix for 5 vulnerabilities by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3036
- chore(deps): bump tornado from 6.3.3 to 6.4 in /hack/api-docs by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3051
- chore(deps): bump click from 8.1.3 to 8.1.7 in /hack/api-docs by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3050
- chore(deps): bump actions/cache from 3.3.3 to 4.0.0 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3049
- chore(deps): bump github/codeql-action from 2.2.4 to 3.23.1 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3048
- chore(deps): bump markupsafe from 2.1.1 to 2.1.3 in /hack/api-docs by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3047
- chore(deps): bump mkdocs-macros-plugin from 0.7.0 to 1.0.5 in
/hack/api-docs by [@&#8203;dependabot](https://togithub.com/dependabot)
in
[external-secrets/external-secrets#3046
- chore(deps): bump actions/checkout from 3.1.0 to 4.1.1 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3044
- chore(deps): bump golang from `fd78f2f` to `fd78f2f` by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3042
- chore(deps): bump ubi8/ubi-minimal from `d8b81a3` to `2882390` by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3041
- chore(deps): bump alpine from `13b7e62` to `51b6726` in /e2e by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3040
- chore(deps): bump golang from `04cf306` to `c4b696f` in /e2e by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3038
- chore(deps): bump mkdocs-material from 9.5.3 to 9.5.4 in
/hack/api-docs by [@&#8203;dependabot](https://togithub.com/dependabot)
in
[external-secrets/external-secrets#3043
- chore(deps): bump ossf/scorecard-action from 2.1.2 to 2.3.1 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3045
- docs: add security response process by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3037
- Fix wrong namespaceSelector configuration in snippet in document by
[@&#8203;kyasbal](https://togithub.com/kyasbal) in
[external-secrets/external-secrets#3054
- chore: refactor/centralise secretKeyRef usage by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3022
- chore: fixup security response suggestions by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3056
- feat: allow provider to return admission warnings by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3058
- chore(deps): bump alpine from 3.18 to 3.19 in /hack/api-docs by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3039
- chore: add tests for AWS/SM by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3057
- chore(deps): bump mkdocs-minify-plugin from 0.5.0 to 0.7.2 in
/hack/api-docs by [@&#8203;dependabot](https://togithub.com/dependabot)
in
[external-secrets/external-secrets#3063
- chore(deps): bump markupsafe from 2.1.3 to 2.1.4 in /hack/api-docs by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3062
- chore: update dependencies by
[@&#8203;eso-service-account-app](https://togithub.com/eso-service-account-app)
in
[external-secrets/external-secrets#3065
- added metrics support for akeyless by
[@&#8203;charan986](https://togithub.com/charan986) in
[external-secrets/external-secrets#3069
- chore: bump jwx pkg by [@&#8203;moolen](https://togithub.com/moolen)
in
[external-secrets/external-secrets#3075
- IBM provider: remove deprecated code for fetching secret by name by
[@&#8203;Shanti-G](https://togithub.com/Shanti-G) in
[external-secrets/external-secrets#3078
- chore(deps): bump codecov/codecov-action from 3.1.4 to 3.1.5 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3090
- chore(deps): bump golang from `fd78f2f` to `a6a7f1f` by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3086
- chore(deps): bump alpine from `51b6726` to `c5b1261` in /hack/api-docs
by [@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3088
- chore(deps): bump github/codeql-action from 3.23.1 to 3.23.2 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3089
- chore(deps): bump golang from `c4b696f` to `d8c365d` in /e2e by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3084
- chore(deps): bump alpine from `51b6726` to `c5b1261` by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3087
- 🧹 refactor vault provider by
[@&#8203;moolen](https://togithub.com/moolen) in
[external-secrets/external-secrets#3072
- chore: bump ubi image by [@&#8203;moolen](https://togithub.com/moolen)
in
[external-secrets/external-secrets#3096
- chore: update dependencies by
[@&#8203;eso-service-account-app](https://togithub.com/eso-service-account-app)
in
[external-secrets/external-secrets#3091
- chore(deps): bump alpine from 3.19.0 to 3.19.1 in /e2e by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3083
- chore(deps): bump codecov/codecov-action from 3.1.5 to 4.0.1 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3104
- chore(deps): bump github/codeql-action from 3.23.2 to 3.24.0 by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3103
- chore: update dependencies by
[@&#8203;eso-service-account-app](https://togithub.com/eso-service-account-app)
in
[external-secrets/external-secrets#3113
- chore(deps): bump peter-evans/slash-command-dispatch from 3.0.2 to
4.0.0 by [@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3102
- Feat/ready condition early by
[@&#8203;ppatel1604](https://togithub.com/ppatel1604) in
[external-secrets/external-secrets#3077
- chore(deps): bump mkdocs-material from 9.5.4 to 9.5.7 in
/hack/api-docs by [@&#8203;dependabot](https://togithub.com/dependabot)
in
[external-secrets/external-secrets#3106
- chore(deps): bump platformdirs from 4.1.0 to 4.2.0 in /hack/api-docs
by [@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3105
- chore(deps): bump markupsafe from 2.1.4 to 2.1.5 in /hack/api-docs by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3107
- chore(deps): bump urllib3 from 2.1.0 to 2.2.0 in /hack/api-docs by
[@&#8203;dependabot](https://togithub.com/dependabot) in
[external-secrets/external-secrets#3109
- chore(deps): bump mkdocs-minify-plugin from 0.7.2 to 0.8.0 in
/hack/api-docs by [@&#8203;dependabot](https://togithub.com/dependabot)
in
[external-secrets/external-secrets#3108

#### New Contributors

- [@&#8203;Tycale](https://togithub.com/Tycale) made their first
contribution in
[external-secrets/external-secrets#2986
- [@&#8203;Aransh](https://togithub.com/Aransh) made their first
contribution in
[external-secrets/external-secrets#2985
- [@&#8203;A1994SC](https://togithub.com/A1994SC) made their first
contribution in
[external-secrets/external-secrets#2881
- [@&#8203;matusf](https://togithub.com/matusf) made their first
contribution in
[external-secrets/external-secrets#2998
- [@&#8203;bthuilot](https://togithub.com/bthuilot) made their first
contribution in
[external-secrets/external-secrets#2646
- [@&#8203;rpasche](https://togithub.com/rpasche) made their first
contribution in
[external-secrets/external-secrets#3007
- [@&#8203;barucoh](https://togithub.com/barucoh) made their first
contribution in
[external-secrets/external-secrets#3013
- [@&#8203;aslafy-z](https://togithub.com/aslafy-z) made their first
contribution in
[external-secrets/external-secrets#3021
- [@&#8203;fdberlking](https://togithub.com/fdberlking) made their first
contribution in
[external-secrets/external-secrets#3010
- [@&#8203;charlesthomas](https://togithub.com/charlesthomas) made their
first contribution in
[external-secrets/external-secrets#2971
- [@&#8203;aviadkray](https://togithub.com/aviadkray) made their first
contribution in
[external-secrets/external-secrets#2991
- [@&#8203;PeterStolz](https://togithub.com/PeterStolz) made their first
contribution in
[external-secrets/external-secrets#3023
- [@&#8203;Mehrbod2002](https://togithub.com/Mehrbod2002) made their
first contribution in
[external-secrets/external-secrets#3003
- [@&#8203;M0NsTeRRR](https://togithub.com/M0NsTeRRR) made their first
contribution in
[external-secrets/external-secrets#2869
- [@&#8203;rodrigorfk](https://togithub.com/rodrigorfk) made their first
contribution in
[external-secrets/external-secrets#3018
- [@&#8203;kyasbal](https://togithub.com/kyasbal) made their first
contribution in
[external-secrets/external-secrets#3054

**Full Changelog**:
external-secrets/external-secrets@v0.9.11...v0.9.12

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://togithub.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4xODAuMCIsInVwZGF0ZWRJblZlciI6IjM3LjE4MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiJ9-->

Co-authored-by: kireque-bot[bot] <143391978+kireque-bot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Add support for Hashicorp Vault mTLS
2 participants