Secret spec¶
| Field | Type | Required | Notes |
|---|---|---|---|
apiVersion |
string | yes | "v1". See API versioning. |
type |
string | yes | "secret" |
name |
string | yes | Prefix for the podman secret names this spec produces: each key becomes <name>-<key>. |
ciphertext |
string | yes | The SOPS-encrypted YAML file content itself (the text, not a path and not base64). A flat mapping of key → encrypted value, plus SOPS' own sops metadata block. Key names must match [a-z0-9-]+. |
A secret has no unit, removalAllowed, or reclaimPolicy field. Referenced from a container as Secret: ["<name>-<key>,type=env,target=ENV_VAR"]. See Spec types.