apiVersion: external-secrets.io/v1beta1 kind: ExternalSecret metadata: name: postgresql-vault-user namespace: postgresql spec: refreshInterval: 1h secretStoreRef: kind: ClusterSecretStore name: vault-backend target: name: postgresql-vault-user creationPolicy: Owner template: type: kubernetes.io/basic-auth data: username: vault password: "{{ .password }}" data: - secretKey: password remoteRef: key: databases/postgresql property: VAULT_PASSWORD