apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: name: lakekeeper-encryption-external-secret namespace: {{ .Env.LAKEKEEPER_NAMESPACE }} spec: refreshInterval: 1h secretStoreRef: name: vault-secret-store kind: ClusterSecretStore target: name: lakekeeper-encryption-key creationPolicy: Owner template: type: Opaque data: encryption-key: "{{ `{{ .encryption_key }}` }}" data: - secretKey: encryption_key remoteRef: key: lakekeeper/encryption property: encryption-key