apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: name: grafana-config namespace: {{ .Release.Namespace }} labels: app.kubernetes.io/name: grafana-config {{- include "custom.labels" . | nindent 4 }} spec: secretStoreRef: kind: ClusterSecretStore name: openbao data: - secretKey: admin-user remoteRef: key: /cl01tl/grafana/config property: admin-user - secretKey: admin-password remoteRef: key: /cl01tl/grafana/config property: admin-password --- apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: name: grafana-oidc-authentik namespace: {{ .Release.Namespace }} labels: app.kubernetes.io/name: grafana-oidc-authentik {{- include "custom.labels" . | nindent 4 }} spec: secretStoreRef: kind: ClusterSecretStore name: openbao data: - secretKey: AUTH_CLIENT_ID remoteRef: key: /cl01tl/authentik/oidc/grafana property: client - secretKey: AUTH_CLIENT_SECRET remoteRef: key: /cl01tl/authentik/oidc/grafana property: secret