apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: name: postgres-cube-external-secret namespace: {{ .Env.CUBE_NAMESPACE }} spec: refreshInterval: 1h secretStoreRef: name: vault-secret-store kind: ClusterSecretStore target: name: postgres-cube-secret creationPolicy: Owner template: type: Opaque data: password: "{{ `{{ .password }}` }}" data: - secretKey: password remoteRef: key: postgres/cube property: password