apiVersion: apps/v1 kind: Deployment metadata: name: secret-manager namespace: pkhub labels: app: secret-manager spec: replicas: 1 selector: matchLabels: app: secret-manager template: metadata: labels: app: secret-manager spec: serviceAccountName: pkhub-secrets containers: - name: secret-manager image: pkhub/pk-cli imagePullPolicy: Always command: ["/bin/sh", "-c"] args: - pk k8s apply secret --safe my-group-5 --lbls MySecrets --loop 1; env: - name: PK_KEY_ID valueFrom: secretKeyRef: name: pkkeys key: PK_KEY_ID - name: PK_KEY_SECRET valueFrom: secretKeyRef: name: pkkeys key: PK_KEY_SECRET