{% raw %} apiVersion: external-secrets.io/v1beta1 kind: ExternalSecret metadata: name: template spec: refreshInterval: 1h secretStoreRef: name: secretstore-sample kind: SecretStore target: name: secret-to-be-created # this is how the Kind=Secret will look like template: type: kubernetes.io/tls data: tls.crt: "{{ .mysecret | pkcs12cert | pemCertificate }}" tls.key: "{{ .mysecret | pkcs12key | pemPrivateKey }}" data: # this is a pkcs12 archive that contains # a cert and a private key - secretKey: mysecret remoteRef: key: example {% endraw %}