--- # Only VSO uses this; repospawner itself authenticates to Vault directly with a # projected audience-vault token, not through the operator. apiVersion: secrets.hashicorp.com/v1beta1 kind: VaultAuth metadata: name: default namespace: repospawner spec: allowedNamespaces: - repospawner kubernetes: audiences: - vault role: default serviceAccount: default tokenExpirationSeconds: 600 method: kubernetes mount: k8s/au/syd1 vaultConnectionRef: vso-system/default