apiVersion: external-secrets.io/v1 kind: ClusterSecretStore metadata: name: vault spec: provider: vault: server: "http://vault.infra.svc.cluster.local:8200" path: "secret" version: "v2" auth: kubernetes: mountPath: "kubernetes" role: "external-secrets" serviceAccountRef: name: external-secrets namespace: external-secrets