apiVersion: secrets.hashicorp.com/v1beta1 kind: VaultStaticSecret metadata: name: vault-kv-app namespace: {{ .Release.Namespace }} spec: type: kv-v2 # mount path mount: kvv2 # path of the secret path: webapp/config # dest k8s secret destination: name: secretkv create: true # static secret refresh interval refreshAfter: 30s # Name of the CRD to authenticate to Vault vaultAuthRef: static-auth