apiVersion: external-secrets.io/v1beta1 kind: ExternalSecret metadata: name: database-credentials spec: refreshInterval: 1h # rate SecretManager pulls GCPSM secretStoreRef: kind: SecretStore name: gcp-store # name of the SecretStore (or kind specified) target: name: database-credentials # name of the k8s Secret to be created creationPolicy: Owner data: - secretKey: database_username remoteRef: key: database_username # name of the GCPSM secret key - secretKey: database_password remoteRef: key: database_password # name of the GCPSM secret key