diff --git a/CHANGELOG.md b/CHANGELOG.md
index 21fd05b6a..3e5100355 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -7,6 +7,9 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
## [Unreleased]
+### Added
+- Added `file` and `azureKeyVaultSecret` token sources, so rotated credentials (e.g., GitHub App installation tokens) are picked up without restarting Sourcebot. [#1705](https://github.com/sourcebot-dev/sourcebot/pull/1705)
+
### Fixed
- Silenced a false-positive `MaxListenersExceededWarning` logged on every request proxied through an external rewrite. [#1697](https://github.com/sourcebot-dev/sourcebot/pull/1697)
diff --git a/docs/docs/configuration/config-file.mdx b/docs/docs/configuration/config-file.mdx
index 37b6b689b..abc150892 100644
--- a/docs/docs/configuration/config-file.mdx
+++ b/docs/docs/configuration/config-file.mdx
@@ -58,7 +58,9 @@ The following are settings that can be provided in your config file to modify So
# Tokens
-Tokens are used to securely pass secrets to Sourcebot in a config file. They are used in various places, including connections, language model providers, auth providers, etc. Tokens can be passed as either environment variables or Google Cloud secrets:
+Tokens are used to securely pass secrets to Sourcebot in a config file. They are used in various places, including connections, language model providers, auth providers, etc. Tokens can be passed as environment variables, files, Google Cloud secrets, or Azure Key Vault secrets.
+
+Environment variables are fixed when the container starts. File, Google Cloud, and Azure Key Vault tokens are read each time Sourcebot resolves them. For connection tokens, this happens on every sync, so you can rotate short-lived credentials (e.g., GitHub App installation tokens) without restarting Sourcebot. Tokens used in `environmentOverrides` are resolved once at startup.
@@ -79,11 +81,41 @@ Tokens are used to securely pass secrets to Sourcebot in a config file. They are
}
```
+
+ ```json
+ {
+ "token": {
+ "file": "/var/run/secrets/sourcebot/token"
+ }
+ }
+ ```
+
+ The path is resolved inside the Sourcebot container. Use an absolute path. Leading and trailing whitespace is trimmed.
+
+ This works with Kubernetes Secret volumes, Docker secrets, the [Secrets Store CSI driver](https://secrets-store-csi-driver.sigs.k8s.io/), or a sidecar that writes refreshed tokens to a shared volume.
+
+
+ Kubernetes does not update Secrets mounted with `subPath`. Mount the whole volume if you want rotated values to be picked up.
+
+
+
+ ```json
+ {
+ "token": {
+ "azureKeyVaultSecret": "https://.vault.azure.net/secrets/"
+ }
+ }
+ ```
+
+ To pin a specific version, append it to the identifier: `https://.vault.azure.net/secrets//`. If you omit the version, Sourcebot reads the latest version each time.
+
+ Sourcebot authenticates with [`DefaultAzureCredential`](https://learn.microsoft.com/en-us/azure/developer/javascript/sdk/authentication/credential-chains#use-defaultazurecredential-for-flexibility). This supports AKS Workload Identity, managed identity, and the `AZURE_CLIENT_ID`, `AZURE_TENANT_ID`, and `AZURE_CLIENT_SECRET` environment variables. The identity needs the **Key Vault Secrets User** role, or a `get` secret access policy, on the vault.
+
# Overriding environment variables from the config
-You can override / set environment variables from the config file by using the `environmentOverrides` property. Overrides can be of type `string`, `number`, `boolean`, or a [token](/docs/configuration/config-file#tokens). Tokens are useful when you want to configure a environment variable using a Google Cloud Secret or other supported secret management service.
+You can override / set environment variables from the config file by using the `environmentOverrides` property. Overrides can be of type `string`, `number`, `boolean`, or a [token](/docs/configuration/config-file#tokens). Tokens are useful when you want to configure a environment variable using a Google Cloud secret, an Azure Key Vault secret, or other supported secret management service.
diff --git a/docs/snippets/schemas/v3/app.schema.mdx b/docs/snippets/schemas/v3/app.schema.mdx
index 07fd910c9..e92e3047e 100644
--- a/docs/snippets/schemas/v3/app.schema.mdx
+++ b/docs/snippets/schemas/v3/app.schema.mdx
@@ -53,6 +53,32 @@
"googleCloudSecret"
],
"additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
}
]
}
@@ -115,6 +141,32 @@
"googleCloudSecret"
],
"additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
}
]
}
diff --git a/docs/snippets/schemas/v3/azuredevops.schema.mdx b/docs/snippets/schemas/v3/azuredevops.schema.mdx
index b3b3d282c..5b5a12285 100644
--- a/docs/snippets/schemas/v3/azuredevops.schema.mdx
+++ b/docs/snippets/schemas/v3/azuredevops.schema.mdx
@@ -37,6 +37,32 @@
"googleCloudSecret"
],
"additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
}
]
},
diff --git a/docs/snippets/schemas/v3/bitbucket.schema.mdx b/docs/snippets/schemas/v3/bitbucket.schema.mdx
index 56895a892..193e9b792 100644
--- a/docs/snippets/schemas/v3/bitbucket.schema.mdx
+++ b/docs/snippets/schemas/v3/bitbucket.schema.mdx
@@ -45,6 +45,32 @@
"googleCloudSecret"
],
"additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
}
]
},
diff --git a/docs/snippets/schemas/v3/connection.schema.mdx b/docs/snippets/schemas/v3/connection.schema.mdx
index 2d4607b9d..39a38b30f 100644
--- a/docs/snippets/schemas/v3/connection.schema.mdx
+++ b/docs/snippets/schemas/v3/connection.schema.mdx
@@ -41,6 +41,32 @@
"googleCloudSecret"
],
"additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
}
]
},
@@ -258,6 +284,32 @@
"googleCloudSecret"
],
"additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
}
]
},
@@ -478,6 +530,32 @@
"googleCloudSecret"
],
"additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
}
]
},
@@ -767,6 +845,32 @@
"googleCloudSecret"
],
"additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
}
]
},
@@ -949,6 +1053,32 @@
"googleCloudSecret"
],
"additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
}
]
},
diff --git a/docs/snippets/schemas/v3/environmentOverrides.schema.mdx b/docs/snippets/schemas/v3/environmentOverrides.schema.mdx
index bca6ec083..e3ec6626c 100644
--- a/docs/snippets/schemas/v3/environmentOverrides.schema.mdx
+++ b/docs/snippets/schemas/v3/environmentOverrides.schema.mdx
@@ -50,6 +50,32 @@
"googleCloudSecret"
],
"additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
}
]
}
diff --git a/docs/snippets/schemas/v3/gitea.schema.mdx b/docs/snippets/schemas/v3/gitea.schema.mdx
index 45e034744..6eb3ca42a 100644
--- a/docs/snippets/schemas/v3/gitea.schema.mdx
+++ b/docs/snippets/schemas/v3/gitea.schema.mdx
@@ -37,6 +37,32 @@
"googleCloudSecret"
],
"additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
}
]
},
diff --git a/docs/snippets/schemas/v3/github.schema.mdx b/docs/snippets/schemas/v3/github.schema.mdx
index 7d731cdc5..e4864551f 100644
--- a/docs/snippets/schemas/v3/github.schema.mdx
+++ b/docs/snippets/schemas/v3/github.schema.mdx
@@ -37,6 +37,32 @@
"googleCloudSecret"
],
"additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
}
]
},
diff --git a/docs/snippets/schemas/v3/gitlab.schema.mdx b/docs/snippets/schemas/v3/gitlab.schema.mdx
index 017e5fc5e..ab3ee3417 100644
--- a/docs/snippets/schemas/v3/gitlab.schema.mdx
+++ b/docs/snippets/schemas/v3/gitlab.schema.mdx
@@ -37,6 +37,32 @@
"googleCloudSecret"
],
"additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
}
]
},
diff --git a/docs/snippets/schemas/v3/identityProvider.schema.mdx b/docs/snippets/schemas/v3/identityProvider.schema.mdx
index 0be1f8f6d..c6090184c 100644
--- a/docs/snippets/schemas/v3/identityProvider.schema.mdx
+++ b/docs/snippets/schemas/v3/identityProvider.schema.mdx
@@ -48,6 +48,32 @@
"googleCloudSecret"
],
"additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
}
]
},
@@ -78,6 +104,32 @@
"googleCloudSecret"
],
"additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
}
]
},
@@ -148,6 +200,32 @@
"googleCloudSecret"
],
"additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
}
]
},
@@ -178,6 +256,32 @@
"googleCloudSecret"
],
"additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
}
]
},
@@ -245,6 +349,32 @@
"googleCloudSecret"
],
"additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
}
]
},
@@ -275,6 +405,32 @@
"googleCloudSecret"
],
"additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
}
]
}
@@ -327,6 +483,32 @@
"googleCloudSecret"
],
"additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
}
]
},
@@ -357,6 +539,32 @@
"googleCloudSecret"
],
"additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
}
]
},
@@ -387,6 +595,32 @@
"googleCloudSecret"
],
"additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
}
]
}
@@ -440,40 +674,36 @@
"googleCloudSecret"
],
"additionalProperties": false
- }
- ]
- },
- "clientSecret": {
- "anyOf": [
+ },
{
"type": "object",
"properties": {
- "env": {
+ "file": {
"type": "string",
- "description": "The name of the environment variable that contains the token."
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
}
},
"required": [
- "env"
+ "file"
],
"additionalProperties": false
},
{
"type": "object",
"properties": {
- "googleCloudSecret": {
+ "azureKeyVaultSecret": {
"type": "string",
- "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets"
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
}
},
"required": [
- "googleCloudSecret"
+ "azureKeyVaultSecret"
],
"additionalProperties": false
}
]
},
- "issuer": {
+ "clientSecret": {
"anyOf": [
{
"type": "object",
@@ -500,63 +730,36 @@
"googleCloudSecret"
],
"additionalProperties": false
- }
- ]
- }
- },
- "required": [
- "provider",
- "purpose",
- "clientId",
- "clientSecret",
- "issuer"
- ]
- },
- "MicrosoftEntraIDIdentityProviderConfig": {
- "type": "object",
- "additionalProperties": false,
- "properties": {
- "provider": {
- "const": "microsoft-entra-id"
- },
- "displayName": {
- "type": "string",
- "description": "Optional human-readable label shown on the login screen. Defaults to 'Microsoft Entra ID'."
- },
- "purpose": {
- "const": "sso"
- },
- "clientId": {
- "anyOf": [
+ },
{
"type": "object",
"properties": {
- "env": {
+ "file": {
"type": "string",
- "description": "The name of the environment variable that contains the token."
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
}
},
"required": [
- "env"
+ "file"
],
"additionalProperties": false
},
{
"type": "object",
"properties": {
- "googleCloudSecret": {
+ "azureKeyVaultSecret": {
"type": "string",
- "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets"
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
}
},
"required": [
- "googleCloudSecret"
+ "azureKeyVaultSecret"
],
"additionalProperties": false
}
]
},
- "clientSecret": {
+ "issuer": {
"anyOf": [
{
"type": "object",
@@ -583,34 +786,30 @@
"googleCloudSecret"
],
"additionalProperties": false
- }
- ]
- },
- "issuer": {
- "anyOf": [
+ },
{
"type": "object",
"properties": {
- "env": {
+ "file": {
"type": "string",
- "description": "The name of the environment variable that contains the token."
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
}
},
"required": [
- "env"
+ "file"
],
"additionalProperties": false
},
{
"type": "object",
"properties": {
- "googleCloudSecret": {
+ "azureKeyVaultSecret": {
"type": "string",
- "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets"
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
}
},
"required": [
- "googleCloudSecret"
+ "azureKeyVaultSecret"
],
"additionalProperties": false
}
@@ -625,21 +824,21 @@
"issuer"
]
},
- "GCPIAPIdentityProviderConfig": {
+ "MicrosoftEntraIDIdentityProviderConfig": {
"type": "object",
"additionalProperties": false,
"properties": {
"provider": {
- "const": "gcp-iap"
+ "const": "microsoft-entra-id"
},
"displayName": {
"type": "string",
- "description": "Optional human-readable label shown on the login screen. Defaults to 'Google Cloud IAP'."
+ "description": "Optional human-readable label shown on the login screen. Defaults to 'Microsoft Entra ID'."
},
"purpose": {
"const": "sso"
},
- "audience": {
+ "clientId": {
"anyOf": [
{
"type": "object",
@@ -666,26 +865,1261 @@
"googleCloudSecret"
],
"additionalProperties": false
- }
- ]
- }
- },
- "required": [
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
+ }
+ ]
+ },
+ "clientSecret": {
+ "anyOf": [
+ {
+ "type": "object",
+ "properties": {
+ "env": {
+ "type": "string",
+ "description": "The name of the environment variable that contains the token."
+ }
+ },
+ "required": [
+ "env"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "googleCloudSecret": {
+ "type": "string",
+ "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets"
+ }
+ },
+ "required": [
+ "googleCloudSecret"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
+ }
+ ]
+ },
+ "issuer": {
+ "anyOf": [
+ {
+ "type": "object",
+ "properties": {
+ "env": {
+ "type": "string",
+ "description": "The name of the environment variable that contains the token."
+ }
+ },
+ "required": [
+ "env"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "googleCloudSecret": {
+ "type": "string",
+ "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets"
+ }
+ },
+ "required": [
+ "googleCloudSecret"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
+ }
+ ]
+ }
+ },
+ "required": [
+ "provider",
+ "purpose",
+ "clientId",
+ "clientSecret",
+ "issuer"
+ ]
+ },
+ "GCPIAPIdentityProviderConfig": {
+ "type": "object",
+ "additionalProperties": false,
+ "properties": {
+ "provider": {
+ "const": "gcp-iap"
+ },
+ "displayName": {
+ "type": "string",
+ "description": "Optional human-readable label shown on the login screen. Defaults to 'Google Cloud IAP'."
+ },
+ "purpose": {
+ "const": "sso"
+ },
+ "audience": {
+ "anyOf": [
+ {
+ "type": "object",
+ "properties": {
+ "env": {
+ "type": "string",
+ "description": "The name of the environment variable that contains the token."
+ }
+ },
+ "required": [
+ "env"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "googleCloudSecret": {
+ "type": "string",
+ "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets"
+ }
+ },
+ "required": [
+ "googleCloudSecret"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
+ }
+ ]
+ }
+ },
+ "required": [
+ "provider",
+ "purpose",
+ "audience"
+ ]
+ },
+ "BitbucketCloudIdentityProviderConfig": {
+ "type": "object",
+ "additionalProperties": false,
+ "properties": {
+ "provider": {
+ "const": "bitbucket-cloud"
+ },
+ "displayName": {
+ "type": "string",
+ "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Cloud'."
+ },
+ "purpose": {
+ "enum": [
+ "sso",
+ "account_linking"
+ ]
+ },
+ "clientId": {
+ "anyOf": [
+ {
+ "type": "object",
+ "properties": {
+ "env": {
+ "type": "string",
+ "description": "The name of the environment variable that contains the token."
+ }
+ },
+ "required": [
+ "env"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "googleCloudSecret": {
+ "type": "string",
+ "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets"
+ }
+ },
+ "required": [
+ "googleCloudSecret"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
+ }
+ ]
+ },
+ "clientSecret": {
+ "anyOf": [
+ {
+ "type": "object",
+ "properties": {
+ "env": {
+ "type": "string",
+ "description": "The name of the environment variable that contains the token."
+ }
+ },
+ "required": [
+ "env"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "googleCloudSecret": {
+ "type": "string",
+ "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets"
+ }
+ },
+ "required": [
+ "googleCloudSecret"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
+ }
+ ]
+ },
+ "accountLinkingRequired": {
+ "type": "boolean",
+ "default": false
+ }
+ },
+ "required": [
+ "provider",
+ "purpose",
+ "clientId",
+ "clientSecret"
+ ]
+ },
+ "AuthentikIdentityProviderConfig": {
+ "type": "object",
+ "additionalProperties": false,
+ "properties": {
+ "provider": {
+ "const": "authentik"
+ },
+ "displayName": {
+ "type": "string",
+ "description": "Optional human-readable label shown on the login screen. Defaults to 'Authentik'."
+ },
+ "purpose": {
+ "const": "sso"
+ },
+ "clientId": {
+ "anyOf": [
+ {
+ "type": "object",
+ "properties": {
+ "env": {
+ "type": "string",
+ "description": "The name of the environment variable that contains the token."
+ }
+ },
+ "required": [
+ "env"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "googleCloudSecret": {
+ "type": "string",
+ "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets"
+ }
+ },
+ "required": [
+ "googleCloudSecret"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
+ }
+ ]
+ },
+ "clientSecret": {
+ "anyOf": [
+ {
+ "type": "object",
+ "properties": {
+ "env": {
+ "type": "string",
+ "description": "The name of the environment variable that contains the token."
+ }
+ },
+ "required": [
+ "env"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "googleCloudSecret": {
+ "type": "string",
+ "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets"
+ }
+ },
+ "required": [
+ "googleCloudSecret"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
+ }
+ ]
+ },
+ "issuer": {
+ "anyOf": [
+ {
+ "type": "object",
+ "properties": {
+ "env": {
+ "type": "string",
+ "description": "The name of the environment variable that contains the token."
+ }
+ },
+ "required": [
+ "env"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "googleCloudSecret": {
+ "type": "string",
+ "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets"
+ }
+ },
+ "required": [
+ "googleCloudSecret"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
+ }
+ ]
+ }
+ },
+ "required": [
+ "provider",
+ "purpose",
+ "clientId",
+ "clientSecret",
+ "issuer"
+ ]
+ },
+ "JumpCloudIdentityProviderConfig": {
+ "type": "object",
+ "additionalProperties": false,
+ "properties": {
+ "provider": {
+ "const": "jumpcloud"
+ },
+ "displayName": {
+ "type": "string",
+ "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'."
+ },
+ "purpose": {
+ "const": "sso"
+ },
+ "clientId": {
+ "anyOf": [
+ {
+ "type": "object",
+ "properties": {
+ "env": {
+ "type": "string",
+ "description": "The name of the environment variable that contains the token."
+ }
+ },
+ "required": [
+ "env"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "googleCloudSecret": {
+ "type": "string",
+ "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets"
+ }
+ },
+ "required": [
+ "googleCloudSecret"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
+ }
+ ]
+ },
+ "clientSecret": {
+ "anyOf": [
+ {
+ "type": "object",
+ "properties": {
+ "env": {
+ "type": "string",
+ "description": "The name of the environment variable that contains the token."
+ }
+ },
+ "required": [
+ "env"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "googleCloudSecret": {
+ "type": "string",
+ "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets"
+ }
+ },
+ "required": [
+ "googleCloudSecret"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
+ }
+ ]
+ },
+ "issuer": {
+ "anyOf": [
+ {
+ "type": "object",
+ "properties": {
+ "env": {
+ "type": "string",
+ "description": "The name of the environment variable that contains the token."
+ }
+ },
+ "required": [
+ "env"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "googleCloudSecret": {
+ "type": "string",
+ "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets"
+ }
+ },
+ "required": [
+ "googleCloudSecret"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
+ }
+ ]
+ }
+ },
+ "required": [
+ "provider",
+ "purpose",
+ "clientId",
+ "clientSecret",
+ "issuer"
+ ]
+ },
+ "IdiraIdentityProviderConfig": {
+ "type": "object",
+ "additionalProperties": false,
+ "properties": {
+ "provider": {
+ "const": "idira"
+ },
+ "displayName": {
+ "type": "string",
+ "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'."
+ },
+ "purpose": {
+ "const": "sso"
+ },
+ "clientId": {
+ "anyOf": [
+ {
+ "type": "object",
+ "properties": {
+ "env": {
+ "type": "string",
+ "description": "The name of the environment variable that contains the token."
+ }
+ },
+ "required": [
+ "env"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "googleCloudSecret": {
+ "type": "string",
+ "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets"
+ }
+ },
+ "required": [
+ "googleCloudSecret"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
+ }
+ ]
+ },
+ "clientSecret": {
+ "anyOf": [
+ {
+ "type": "object",
+ "properties": {
+ "env": {
+ "type": "string",
+ "description": "The name of the environment variable that contains the token."
+ }
+ },
+ "required": [
+ "env"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "googleCloudSecret": {
+ "type": "string",
+ "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets"
+ }
+ },
+ "required": [
+ "googleCloudSecret"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
+ }
+ ]
+ },
+ "issuer": {
+ "anyOf": [
+ {
+ "type": "object",
+ "properties": {
+ "env": {
+ "type": "string",
+ "description": "The name of the environment variable that contains the token."
+ }
+ },
+ "required": [
+ "env"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "googleCloudSecret": {
+ "type": "string",
+ "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets"
+ }
+ },
+ "required": [
+ "googleCloudSecret"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "file": {
+ "type": "string",
+ "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)."
+ }
+ },
+ "required": [
+ "file"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "azureKeyVaultSecret": {
+ "type": "string",
+ "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets"
+ }
+ },
+ "required": [
+ "azureKeyVaultSecret"
+ ],
+ "additionalProperties": false
+ }
+ ]
+ }
+ },
+ "required": [
+ "provider",
+ "purpose",
+ "clientId",
+ "clientSecret",
+ "issuer"
+ ]
+ },
+ "BitbucketServerIdentityProviderConfig": {
+ "type": "object",
+ "additionalProperties": false,
+ "properties": {
+ "provider": {
+ "const": "bitbucket-server"
+ },
+ "displayName": {
+ "type": "string",
+ "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Server'."
+ },
+ "purpose": {
+ "enum": [
+ "sso",
+ "account_linking"
+ ]
+ },
+ "clientId": {
+ "anyOf": [
+ {
+ "type": "object",
+ "properties": {
+ "env": {
+ "type": "string",
+ "description": "The name of the environment variable that contains the token."
+ }
+ },
+ "required": [
+ "env"
+ ],
+ "additionalProperties": false
+ },
+ {
+ "type": "object",
+ "properties": {
+ "googleCloudSecret": {
+ "type": "string",
+ "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets/