--- # Ephemeral arrstack virtual key. The engine mints one machine token covering # both radarr and sonarr; it is only honoured by arrproxy, which validates it and # swaps in the real per-app key upstream. Role ttl is 60s, so VSO renews the # lease continuously (renewalPercent default 67) and rewrites the secret; the # reloader annotation restarts pods when the token actually changes. apiVersion: secrets.hashicorp.com/v1beta1 kind: VaultDynamicSecret metadata: name: arrstack-virtual-key namespace: mediamark spec: allowStaticCreds: false destination: create: true name: arrstack-virtual-key overwrite: true mount: arrstack path: creds/mediamark revoke: true vaultAuthRef: arrstack-creds