apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: name: vaultwarden-oidc-authentik namespace: {{ .Release.Namespace }} labels: app.kubernetes.io/name: vaultwarden-oidc-authentik {{- include "custom.labels" . | nindent 4 }} spec: secretStoreRef: kind: ClusterSecretStore name: openbao data: - secretKey: SSO_CLIENT_ID remoteRef: key: /cl01tl/authentik/oidc/vaultwarden property: client - secretKey: SSO_CLIENT_SECRET remoteRef: key: /cl01tl/authentik/oidc/vaultwarden property: secret