apiVersion: secrets.hashicorp.com/v1beta1 kind: VaultDynamicSecret metadata: name: crowdsec-db-credentials namespace: {{ .Release.Namespace }} spec: # Mount path of the secrets backend mount: postgres # Path to the secret path: creds/crowdsec # Where to store the secrets, VSO will create the secret destination: create: true name: crowdsec-db-credentials # Restart these pods when secrets rotated rolloutRestartTargets: - kind: Deployment name: crowdsec-lapi # Name of the CRD to authenticate to Vault vaultAuthRef: crowdsec