Skip to content

List or watch secrets in every project

GET
/apis/nodus.dev/v1/secrets
curl --request GET \
--url https://example.com/apis/nodus.dev/v1/secrets
labelSelector
string
fieldSelector
string
limit
string
continue
string
watch
string
resourceVersion
string
allowWatchBookmarks
string
timeoutSeconds
string

OK

Media type application/json
object
apiVersion
string
items
required
Array<object>

Secret is versioned, envelope-encrypted key/value data. Values are write-only: no API returns them, and they reach containers only as env vars and 0400 tmpfs files of an attempt that pinned the version at admission.

object
apiVersion
string
kind
string
metadata
object
annotations
object
key
additional properties
string
creationTimestamp
string
deletionGracePeriodSeconds
integer format: int64
deletionTimestamp
string
finalizers
Array<string>
nullable
generateName
string
generation
integer format: int64
labels
object
key
additional properties
string
managedFields
Array<object>
nullable
object
apiVersion
string
fieldsType
string
fieldsV1
object
key
additional properties
manager
string
operation
string
subresource
string
time
string
name
string
namespace
string
ownerReferences
Array<object>
nullable
object
apiVersion
required
string
blockOwnerDeletion
boolean
controller
boolean
kind
required
string
name
required
string
uid
required
string
resourceVersion
string
selfLink
string
uid
string
spec
required

SecretSpec is a Secret’s type and its write-only values.

object
data

Data maps keys to base64 values. Write-only: a write that carries it creates a new version and the stored object keeps only the key names.

object
key
additional properties
string format: base64
stringData

StringData is Data as plain strings, merged over Data on write. Write-only.

object
key
additional properties
string
type

Type is Opaque or Registry; immutable.

string
status

SecretStatus reports versions and key names.

object
keys

Keys are the current version’s key names.

Array<string>
nullable
lastUsedTime

LastUsedTime is the last delivery to an attempt.

string
phase

Phase is Ready, or Failed when the values could not be encrypted.

string
reason

Reason says why the Secret failed.

string
version

Version is the current version; new attempts pin it.

integer format: int32
versions

Versions are the most recent versions, newest first (at most 10).

Array<object>
nullable

SecretVersionInfo describes one version without its values.

object
createTime
required

CreateTime is when the version was written.

string
createdBy

CreatedBy is the principal that wrote it.

string
keys

Keys are its key names.

Array<string>
nullable
version
required

Version is the version number, from 1.

integer format: int32
kind
string
metadata
object
continue
string
remainingItemCount
integer format: int64
resourceVersion
string
selfLink
string
shardInfo
object
selector
required
string
Example generated
{
"apiVersion": "example",
"items": [
{
"apiVersion": "example",
"kind": "example",
"metadata": {
"annotations": {
"additionalProperty": "example"
},
"creationTimestamp": "example",
"deletionGracePeriodSeconds": 1,
"deletionTimestamp": "example",
"finalizers": [
"example"
],
"generateName": "example",
"generation": 1,
"labels": {
"additionalProperty": "example"
},
"managedFields": [
{
"apiVersion": "example",
"fieldsType": "example",
"fieldsV1": {
"additionalProperty": "example"
},
"manager": "example",
"operation": "example",
"subresource": "example",
"time": "example"
}
],
"name": "example",
"namespace": "example",
"ownerReferences": [
{
"apiVersion": "example",
"blockOwnerDeletion": true,
"controller": true,
"kind": "example",
"name": "example",
"uid": "example"
}
],
"resourceVersion": "example",
"selfLink": "example",
"uid": "example"
},
"spec": {
"data": {
"additionalProperty": "example"
},
"stringData": {
"additionalProperty": "example"
},
"type": "example"
},
"status": {
"keys": [
"example"
],
"lastUsedTime": "example",
"phase": "example",
"reason": "example",
"version": 1,
"versions": [
{
"createTime": "example",
"createdBy": "example",
"keys": [
"example"
],
"version": 1
}
]
}
}
],
"kind": "example",
"metadata": {
"continue": "example",
"remainingItemCount": 1,
"resourceVersion": "example",
"selfLink": "example",
"shardInfo": {
"selector": "example"
}
}
}

An error: a metav1.Status whose reason is a registered code.

Media type application/json

Status is the error body of every API response: a Kubernetes metav1.Status (so kubectl and client-go understand it) plus three top-level extensions that those clients ignore (ADR-028).

object
apiVersion
string
code
integer format: int32
details
object
causes
Array<object>
nullable
object
field
string
message
string
reason
string
group
string
kind
string
name
string
retryAfterSeconds
integer format: int32
uid
string
docs

Docs is the URL of the code’s docs page.

string
fix

Fix says what to do next, for example a CLI command or the field to change.

string
kind
string
message
string
metadata
object
continue
string
remainingItemCount
integer format: int64
resourceVersion
string
selfLink
string
shardInfo
object
selector
required
string
reason
string
requestId

RequestID identifies the request in logs and support tickets.

string
status
string
Example generated
{
"apiVersion": "example",
"code": 1,
"details": {
"causes": [
{
"field": "example",
"message": "example",
"reason": "example"
}
],
"group": "example",
"kind": "example",
"name": "example",
"retryAfterSeconds": 1,
"uid": "example"
},
"docs": "example",
"fix": "example",
"kind": "example",
"message": "example",
"metadata": {
"continue": "example",
"remainingItemCount": 1,
"resourceVersion": "example",
"selfLink": "example",
"shardInfo": {
"selector": "example"
}
},
"reason": "example",
"requestId": "example",
"status": "example"
}