TLS cert support for GerritIndexer remote index backends

The GerritIndexer had no mechanism to provide CA certificates when
running a reindex job against a remote index backend that uses
non-publicly-trusted TLS certificates. This caused both the Python
init container and the Java reindex process to fail with SSL
verification errors.

Add openSearchSecretRef field to GerritIndexerSpec, containing a
secret with optional keys:
- A CA certificate in PEM format (ca.crt) for Python SSL verification
  in the gerrit-init container, mounted at /var/config/ca.crt
- A Java truststore in JKS format (truststore.jks) for Java SSL
  verification by the reindex process, mounted at
  /var/mnt/data/index-opensearch/

The gerrit-init-config ConfigMap mount is changed to use subPath so
that the CA certificate can be mounted alongside it in /var/config/.

Change-Id: I00a8043256c001ffa0b91bb30815511ccfd9d13f
diff --git a/Documentation/examples/1-gerritcluster.yaml b/Documentation/examples/1-gerritcluster.yaml
index a2faba6..894b603 100644
--- a/Documentation/examples/1-gerritcluster.yaml
+++ b/Documentation/examples/1-gerritcluster.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritCluster
 metadata:
   name: gerrit
diff --git a/Documentation/examples/2-gerritcluster-with-replica.yaml b/Documentation/examples/2-gerritcluster-with-replica.yaml
index 4115756..c482ce2 100644
--- a/Documentation/examples/2-gerritcluster-with-replica.yaml
+++ b/Documentation/examples/2-gerritcluster-with-replica.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritCluster
 metadata:
   name: gerrit
diff --git a/Documentation/examples/3-gerritcluster-istio.yaml b/Documentation/examples/3-gerritcluster-istio.yaml
index cb06266..6118640 100644
--- a/Documentation/examples/3-gerritcluster-istio.yaml
+++ b/Documentation/examples/3-gerritcluster-istio.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritCluster
 metadata:
   name: gerrit
diff --git a/Documentation/examples/4-gerritcluster-ha-replica.yaml b/Documentation/examples/4-gerritcluster-ha-replica.yaml
index 5d87662..1f4c56f 100644
--- a/Documentation/examples/4-gerritcluster-ha-replica.yaml
+++ b/Documentation/examples/4-gerritcluster-ha-replica.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritCluster
 metadata:
   name: gerrit
diff --git a/Documentation/examples/5-gerritcluster-refdb.yaml b/Documentation/examples/5-gerritcluster-refdb.yaml
index 0f2da8d..322efe5 100644
--- a/Documentation/examples/5-gerritcluster-refdb.yaml
+++ b/Documentation/examples/5-gerritcluster-refdb.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritCluster
 metadata:
   name: gerrit
diff --git a/Documentation/examples/6-gerritcluster-ha-primary.yaml b/Documentation/examples/6-gerritcluster-ha-primary.yaml
index 6f46a8f..0f3831b 100644
--- a/Documentation/examples/6-gerritcluster-ha-primary.yaml
+++ b/Documentation/examples/6-gerritcluster-ha-primary.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritCluster
 metadata:
   name: gerrit
diff --git a/Documentation/examples/gerritcluster-3-nodes-pr-kafka-multisite.yaml b/Documentation/examples/gerritcluster-3-nodes-pr-kafka-multisite.yaml
index bbc87dd..e16f75d 100644
--- a/Documentation/examples/gerritcluster-3-nodes-pr-kafka-multisite.yaml
+++ b/Documentation/examples/gerritcluster-3-nodes-pr-kafka-multisite.yaml
@@ -16,7 +16,7 @@
 type: Opaque
 
 ---
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritCluster
 metadata:
   name: gerrit
diff --git a/Documentation/operator-api-reference.md b/Documentation/operator-api-reference.md
index 11649f2..d2d001c 100644
--- a/Documentation/operator-api-reference.md
+++ b/Documentation/operator-api-reference.md
@@ -87,7 +87,7 @@
 ---
 
 **Group**: gerritoperator.google.com \
-**Version**: v1beta18 \
+**Version**: v1beta19 \
 **Kind**: GerritCluster
 
 ---
@@ -104,7 +104,7 @@
 Example:
 
 ```yaml
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritCluster
 metadata:
   name: gerrit
@@ -427,7 +427,7 @@
 ---
 
 **Group**: gerritoperator.google.com \
-**Version**: v1beta18 \
+**Version**: v1beta19 \
 **Kind**: Gerrit
 
 ---
@@ -444,7 +444,7 @@
 Example:
 
 ```yaml
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: Gerrit
 metadata:
   name: gerrit
@@ -658,7 +658,7 @@
 ---
 
 **Group**: gerritoperator.google.com \
-**Version**: v1beta18 \
+**Version**: v1beta19 \
 **Kind**: Receiver
 
 ---
@@ -675,7 +675,7 @@
 Example:
 
 ```yaml
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: Receiver
 metadata:
   name: receiver
@@ -786,7 +786,7 @@
 ---
 
 **Group**: gerritoperator.google.com \
-**Version**: v1beta18 \
+**Version**: v1beta19 \
 **Kind**: GitGarbageCollection
 
 ---
@@ -803,7 +803,7 @@
 Example:
 
 ```yaml
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GitGarbageCollection
 metadata:
   name: gitgc
@@ -847,7 +847,7 @@
 ---
 
 **Group**: gerritoperator.google.com \
-**Version**: v1beta18 \
+**Version**: v1beta19 \
 **Kind**: GerritNetwork
 
 ---
@@ -863,7 +863,7 @@
 Example:
 
 ```yaml
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritNetwork
 metadata:
   name: gerrit-network
@@ -897,7 +897,7 @@
 ---
 
 **Group**: gerritoperator.google.com \
-**Version**: v1beta18 \
+**Version**: v1beta19 \
 **Kind**: IncomingReplicationTask
 
 ---
@@ -913,7 +913,7 @@
 Example:
 
 ```yaml
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: IncomingReplicationTask
 metadata:
   name: incoming-repl-task
@@ -972,7 +972,7 @@
 ---
 
 **Group**: gerritoperator.google.com \
-**Version**: v1beta18 \
+**Version**: v1beta19 \
 **Kind**: GerritIndexer
 
 ---
@@ -988,7 +988,7 @@
 Example:
 
 ```yaml
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritIndexer
 metadata:
   name: gerrit-indexer
@@ -1586,6 +1586,7 @@
 | `resources` | [`ResourceRequirements`](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.27/#resourcerequirements-v1-core) | Resource requirements for the GerritIndexer container |
 | `configFiles` | `Map<String, String>` | Configuration files to be mounted in to `$SITE/etc` |
 | `storage` | [`GerritIndexerStorage`](#gerritindexerstorage) | Storage configuration of the GerritIndexer job |
+| `openSearchSecretRef` | `String` | Name of a Kubernetes secret containing TLS credentials for connecting to a remote index backend that uses a non-publicly-trusted certificate. The secret may contain a `ca.crt` key (PEM format) used by the init container for SSL verification, and/or a `truststore.jks` key (JKS format) used by the Java reindex process. Only keys present in the secret will be mounted. (default: `null`) |
 
 ## GerritIndexerStorage
 
diff --git a/crd/current/gerritclusters.gerritoperator.google.com-v1.yml b/crd/current/gerritclusters.gerritoperator.google.com-v1.yml
index 84edf2d..a9300e9 100644
--- a/crd/current/gerritclusters.gerritoperator.google.com-v1.yml
+++ b/crd/current/gerritclusters.gerritoperator.google.com-v1.yml
@@ -13,7 +13,7 @@
     singular: gerritcluster
   scope: Namespaced
   versions:
-  - name: v1beta18
+  - name: v1beta19
     schema:
       openAPIV3Schema:
         properties:
diff --git a/crd/current/gerritindexers.gerritoperator.google.com-v1.yml b/crd/current/gerritindexers.gerritoperator.google.com-v1.yml
index 2cccb93..20ee4a8 100644
--- a/crd/current/gerritindexers.gerritoperator.google.com-v1.yml
+++ b/crd/current/gerritindexers.gerritoperator.google.com-v1.yml
@@ -13,7 +13,7 @@
     singular: gerritindexer
   scope: Namespaced
   versions:
-  - name: v1beta18
+  - name: v1beta19
     schema:
       openAPIV3Schema:
         properties:
@@ -369,6 +369,8 @@
                     - OPENSEARCH
                     type: string
                 type: object
+              openSearchSecretRef:
+                type: string
               resources:
                 properties:
                   claims:
diff --git a/crd/current/gerritmaintenances.gerritoperator.google.com-v1.yml b/crd/current/gerritmaintenances.gerritoperator.google.com-v1.yml
index 7f7bfcf..a8ef662 100644
--- a/crd/current/gerritmaintenances.gerritoperator.google.com-v1.yml
+++ b/crd/current/gerritmaintenances.gerritoperator.google.com-v1.yml
@@ -11,7 +11,7 @@
     singular: gerritmaintenance
   scope: Namespaced
   versions:
-  - name: v1beta18
+  - name: v1beta19
     schema:
       openAPIV3Schema:
         properties:
diff --git a/crd/current/gerritnetworks.gerritoperator.google.com-v1.yml b/crd/current/gerritnetworks.gerritoperator.google.com-v1.yml
index 88773db..7600c7c 100644
--- a/crd/current/gerritnetworks.gerritoperator.google.com-v1.yml
+++ b/crd/current/gerritnetworks.gerritoperator.google.com-v1.yml
@@ -13,7 +13,7 @@
     singular: gerritnetwork
   scope: Namespaced
   versions:
-  - name: v1beta18
+  - name: v1beta19
     schema:
       openAPIV3Schema:
         properties:
diff --git a/crd/current/gerrits.gerritoperator.google.com-v1.yml b/crd/current/gerrits.gerritoperator.google.com-v1.yml
index 0eac805..6ec9306 100644
--- a/crd/current/gerrits.gerritoperator.google.com-v1.yml
+++ b/crd/current/gerrits.gerritoperator.google.com-v1.yml
@@ -13,7 +13,7 @@
     singular: gerrit
   scope: Namespaced
   versions:
-  - name: v1beta18
+  - name: v1beta19
     schema:
       openAPIV3Schema:
         properties:
diff --git a/crd/current/gitgcs.gerritoperator.google.com-v1.yml b/crd/current/gitgcs.gerritoperator.google.com-v1.yml
index 9ce6167..35152fa 100644
--- a/crd/current/gitgcs.gerritoperator.google.com-v1.yml
+++ b/crd/current/gitgcs.gerritoperator.google.com-v1.yml
@@ -13,7 +13,7 @@
     singular: gitgarbagecollection
   scope: Namespaced
   versions:
-  - name: v1beta18
+  - name: v1beta19
     schema:
       openAPIV3Schema:
         properties:
diff --git a/crd/current/incomingreplicationtasks.gerritoperator.google.com-v1.yml b/crd/current/incomingreplicationtasks.gerritoperator.google.com-v1.yml
index d338ee0..08be196 100644
--- a/crd/current/incomingreplicationtasks.gerritoperator.google.com-v1.yml
+++ b/crd/current/incomingreplicationtasks.gerritoperator.google.com-v1.yml
@@ -11,7 +11,7 @@
     singular: incomingreplicationtask
   scope: Namespaced
   versions:
-  - name: v1beta18
+  - name: v1beta19
     schema:
       openAPIV3Schema:
         properties:
diff --git a/crd/current/receivers.gerritoperator.google.com-v1.yml b/crd/current/receivers.gerritoperator.google.com-v1.yml
index 5cb719d..8303ecf 100644
--- a/crd/current/receivers.gerritoperator.google.com-v1.yml
+++ b/crd/current/receivers.gerritoperator.google.com-v1.yml
@@ -13,7 +13,7 @@
     singular: receiver
   scope: Namespaced
   versions:
-  - name: v1beta18
+  - name: v1beta19
     schema:
       openAPIV3Schema:
         properties:
diff --git a/crd/deprecated/gerritclusters.gerritoperator.google.com-v1.yml b/crd/deprecated/gerritclusters.gerritoperator.google.com-v1.yml
index 64d20a0..88e7443 100644
--- a/crd/deprecated/gerritclusters.gerritoperator.google.com-v1.yml
+++ b/crd/deprecated/gerritclusters.gerritoperator.google.com-v1.yml
@@ -13,7 +13,7 @@
     singular: gerritcluster
   scope: Namespaced
   versions:
-    - name: v1beta17
+    - name: v1beta18
       schema:
         openAPIV3Schema:
           properties:
diff --git a/crd/deprecated/gerritindexers.gerritoperator.google.com-v1.yml b/crd/deprecated/gerritindexers.gerritoperator.google.com-v1.yml
index f1327b8..47c2bfb 100644
--- a/crd/deprecated/gerritindexers.gerritoperator.google.com-v1.yml
+++ b/crd/deprecated/gerritindexers.gerritoperator.google.com-v1.yml
@@ -13,7 +13,7 @@
     singular: gerritindexer
   scope: Namespaced
   versions:
-    - name: v1beta17
+    - name: v1beta18
       schema:
         openAPIV3Schema:
           properties:
@@ -369,6 +369,8 @@
                         - OPENSEARCH
                       type: string
                   type: object
+                openSearchSecretRef:
+                  type: string
                 resources:
                   properties:
                     claims:
diff --git a/crd/deprecated/gerritmaintenances.gerritoperator.google.com-v1.yml b/crd/deprecated/gerritmaintenances.gerritoperator.google.com-v1.yml
index fcc963b..d660a51 100644
--- a/crd/deprecated/gerritmaintenances.gerritoperator.google.com-v1.yml
+++ b/crd/deprecated/gerritmaintenances.gerritoperator.google.com-v1.yml
@@ -11,7 +11,7 @@
     singular: gerritmaintenance
   scope: Namespaced
   versions:
-    - name: v1beta17
+    - name: v1beta18
       schema:
         openAPIV3Schema:
           properties:
diff --git a/crd/deprecated/gerritnetworks.gerritoperator.google.com-v1.yml b/crd/deprecated/gerritnetworks.gerritoperator.google.com-v1.yml
index cef26ac..601be24 100644
--- a/crd/deprecated/gerritnetworks.gerritoperator.google.com-v1.yml
+++ b/crd/deprecated/gerritnetworks.gerritoperator.google.com-v1.yml
@@ -13,7 +13,7 @@
     singular: gerritnetwork
   scope: Namespaced
   versions:
-    - name: v1beta17
+    - name: v1beta18
       schema:
         openAPIV3Schema:
           properties:
diff --git a/crd/deprecated/gerrits.gerritoperator.google.com-v1.yml b/crd/deprecated/gerrits.gerritoperator.google.com-v1.yml
index 4bc3eda..0ca7eb8 100644
--- a/crd/deprecated/gerrits.gerritoperator.google.com-v1.yml
+++ b/crd/deprecated/gerrits.gerritoperator.google.com-v1.yml
@@ -13,7 +13,7 @@
     singular: gerrit
   scope: Namespaced
   versions:
-    - name: v1beta17
+    - name: v1beta18
       schema:
         openAPIV3Schema:
           properties:
diff --git a/crd/deprecated/gitgcs.gerritoperator.google.com-v1.yml b/crd/deprecated/gitgcs.gerritoperator.google.com-v1.yml
index 4ad5728..557fcb6 100644
--- a/crd/deprecated/gitgcs.gerritoperator.google.com-v1.yml
+++ b/crd/deprecated/gitgcs.gerritoperator.google.com-v1.yml
@@ -13,7 +13,7 @@
     singular: gitgarbagecollection
   scope: Namespaced
   versions:
-    - name: v1beta17
+    - name: v1beta18
       schema:
         openAPIV3Schema:
           properties:
diff --git a/crd/deprecated/incomingreplicationtasks.gerritoperator.google.com-v1.yml b/crd/deprecated/incomingreplicationtasks.gerritoperator.google.com-v1.yml
index c995151..2a6b9a7 100644
--- a/crd/deprecated/incomingreplicationtasks.gerritoperator.google.com-v1.yml
+++ b/crd/deprecated/incomingreplicationtasks.gerritoperator.google.com-v1.yml
@@ -11,7 +11,7 @@
     singular: incomingreplicationtask
   scope: Namespaced
   versions:
-    - name: v1beta17
+    - name: v1beta18
       schema:
         openAPIV3Schema:
           properties:
diff --git a/crd/deprecated/receivers.gerritoperator.google.com-v1.yml b/crd/deprecated/receivers.gerritoperator.google.com-v1.yml
index 0ffe5fc..6092aaf 100644
--- a/crd/deprecated/receivers.gerritoperator.google.com-v1.yml
+++ b/crd/deprecated/receivers.gerritoperator.google.com-v1.yml
@@ -13,7 +13,7 @@
     singular: receiver
   scope: Namespaced
   versions:
-    - name: v1beta17
+    - name: v1beta18
       schema:
         openAPIV3Schema:
           properties:
diff --git a/helm-charts/gerrit-operator-crds/templates/gerritclusters.gerritoperator.google.com-v1.yml b/helm-charts/gerrit-operator-crds/templates/gerritclusters.gerritoperator.google.com-v1.yml
index 7999764..7d31f68 100644
--- a/helm-charts/gerrit-operator-crds/templates/gerritclusters.gerritoperator.google.com-v1.yml
+++ b/helm-charts/gerrit-operator-crds/templates/gerritclusters.gerritoperator.google.com-v1.yml
@@ -13,7 +13,7 @@
     singular: gerritcluster
   scope: Namespaced
   versions:
-    - name: v1beta18
+    - name: v1beta19
       schema:
         openAPIV3Schema:
           properties:
@@ -2564,7 +2564,7 @@
       storage: true
       subresources:
         status: {}
-    - name: v1beta17
+    - name: v1beta18
       schema:
         openAPIV3Schema:
           properties:
diff --git a/helm-charts/gerrit-operator-crds/templates/gerritindexers.gerritoperator.google.com-v1.yml b/helm-charts/gerrit-operator-crds/templates/gerritindexers.gerritoperator.google.com-v1.yml
index 21f576d..f6c931a 100644
--- a/helm-charts/gerrit-operator-crds/templates/gerritindexers.gerritoperator.google.com-v1.yml
+++ b/helm-charts/gerrit-operator-crds/templates/gerritindexers.gerritoperator.google.com-v1.yml
@@ -13,6 +13,483 @@
     singular: gerritindexer
   scope: Namespaced
   versions:
+    - name: v1beta19
+      schema:
+        openAPIV3Schema:
+          properties:
+            spec:
+              properties:
+                affinity:
+                  properties:
+                    nodeAffinity:
+                      properties:
+                        preferredDuringSchedulingIgnoredDuringExecution:
+                          items:
+                            properties:
+                              preference:
+                                properties:
+                                  matchExpressions:
+                                    items:
+                                      properties:
+                                        key:
+                                          type: string
+                                        operator:
+                                          type: string
+                                        values:
+                                          items:
+                                            type: string
+                                          type: array
+                                      type: object
+                                    type: array
+                                  matchFields:
+                                    items:
+                                      properties:
+                                        key:
+                                          type: string
+                                        operator:
+                                          type: string
+                                        values:
+                                          items:
+                                            type: string
+                                          type: array
+                                      type: object
+                                    type: array
+                                type: object
+                              weight:
+                                type: integer
+                            type: object
+                          type: array
+                        requiredDuringSchedulingIgnoredDuringExecution:
+                          properties:
+                            nodeSelectorTerms:
+                              items:
+                                properties:
+                                  matchExpressions:
+                                    items:
+                                      properties:
+                                        key:
+                                          type: string
+                                        operator:
+                                          type: string
+                                        values:
+                                          items:
+                                            type: string
+                                          type: array
+                                      type: object
+                                    type: array
+                                  matchFields:
+                                    items:
+                                      properties:
+                                        key:
+                                          type: string
+                                        operator:
+                                          type: string
+                                        values:
+                                          items:
+                                            type: string
+                                          type: array
+                                      type: object
+                                    type: array
+                                type: object
+                              type: array
+                          type: object
+                      type: object
+                    podAffinity:
+                      properties:
+                        preferredDuringSchedulingIgnoredDuringExecution:
+                          items:
+                            properties:
+                              podAffinityTerm:
+                                properties:
+                                  labelSelector:
+                                    properties:
+                                      matchExpressions:
+                                        items:
+                                          properties:
+                                            key:
+                                              type: string
+                                            operator:
+                                              type: string
+                                            values:
+                                              items:
+                                                type: string
+                                              type: array
+                                          type: object
+                                        type: array
+                                      matchLabels:
+                                        additionalProperties:
+                                          type: string
+                                        type: object
+                                    type: object
+                                  matchLabelKeys:
+                                    items:
+                                      type: string
+                                    type: array
+                                  mismatchLabelKeys:
+                                    items:
+                                      type: string
+                                    type: array
+                                  namespaceSelector:
+                                    properties:
+                                      matchExpressions:
+                                        items:
+                                          properties:
+                                            key:
+                                              type: string
+                                            operator:
+                                              type: string
+                                            values:
+                                              items:
+                                                type: string
+                                              type: array
+                                          type: object
+                                        type: array
+                                      matchLabels:
+                                        additionalProperties:
+                                          type: string
+                                        type: object
+                                    type: object
+                                  namespaces:
+                                    items:
+                                      type: string
+                                    type: array
+                                  topologyKey:
+                                    type: string
+                                type: object
+                              weight:
+                                type: integer
+                            type: object
+                          type: array
+                        requiredDuringSchedulingIgnoredDuringExecution:
+                          items:
+                            properties:
+                              labelSelector:
+                                properties:
+                                  matchExpressions:
+                                    items:
+                                      properties:
+                                        key:
+                                          type: string
+                                        operator:
+                                          type: string
+                                        values:
+                                          items:
+                                            type: string
+                                          type: array
+                                      type: object
+                                    type: array
+                                  matchLabels:
+                                    additionalProperties:
+                                      type: string
+                                    type: object
+                                type: object
+                              matchLabelKeys:
+                                items:
+                                  type: string
+                                type: array
+                              mismatchLabelKeys:
+                                items:
+                                  type: string
+                                type: array
+                              namespaceSelector:
+                                properties:
+                                  matchExpressions:
+                                    items:
+                                      properties:
+                                        key:
+                                          type: string
+                                        operator:
+                                          type: string
+                                        values:
+                                          items:
+                                            type: string
+                                          type: array
+                                      type: object
+                                    type: array
+                                  matchLabels:
+                                    additionalProperties:
+                                      type: string
+                                    type: object
+                                type: object
+                              namespaces:
+                                items:
+                                  type: string
+                                type: array
+                              topologyKey:
+                                type: string
+                            type: object
+                          type: array
+                      type: object
+                    podAntiAffinity:
+                      properties:
+                        preferredDuringSchedulingIgnoredDuringExecution:
+                          items:
+                            properties:
+                              podAffinityTerm:
+                                properties:
+                                  labelSelector:
+                                    properties:
+                                      matchExpressions:
+                                        items:
+                                          properties:
+                                            key:
+                                              type: string
+                                            operator:
+                                              type: string
+                                            values:
+                                              items:
+                                                type: string
+                                              type: array
+                                          type: object
+                                        type: array
+                                      matchLabels:
+                                        additionalProperties:
+                                          type: string
+                                        type: object
+                                    type: object
+                                  matchLabelKeys:
+                                    items:
+                                      type: string
+                                    type: array
+                                  mismatchLabelKeys:
+                                    items:
+                                      type: string
+                                    type: array
+                                  namespaceSelector:
+                                    properties:
+                                      matchExpressions:
+                                        items:
+                                          properties:
+                                            key:
+                                              type: string
+                                            operator:
+                                              type: string
+                                            values:
+                                              items:
+                                                type: string
+                                              type: array
+                                          type: object
+                                        type: array
+                                      matchLabels:
+                                        additionalProperties:
+                                          type: string
+                                        type: object
+                                    type: object
+                                  namespaces:
+                                    items:
+                                      type: string
+                                    type: array
+                                  topologyKey:
+                                    type: string
+                                type: object
+                              weight:
+                                type: integer
+                            type: object
+                          type: array
+                        requiredDuringSchedulingIgnoredDuringExecution:
+                          items:
+                            properties:
+                              labelSelector:
+                                properties:
+                                  matchExpressions:
+                                    items:
+                                      properties:
+                                        key:
+                                          type: string
+                                        operator:
+                                          type: string
+                                        values:
+                                          items:
+                                            type: string
+                                          type: array
+                                      type: object
+                                    type: array
+                                  matchLabels:
+                                    additionalProperties:
+                                      type: string
+                                    type: object
+                                type: object
+                              matchLabelKeys:
+                                items:
+                                  type: string
+                                type: array
+                              mismatchLabelKeys:
+                                items:
+                                  type: string
+                                type: array
+                              namespaceSelector:
+                                properties:
+                                  matchExpressions:
+                                    items:
+                                      properties:
+                                        key:
+                                          type: string
+                                        operator:
+                                          type: string
+                                        values:
+                                          items:
+                                            type: string
+                                          type: array
+                                      type: object
+                                    type: array
+                                  matchLabels:
+                                    additionalProperties:
+                                      type: string
+                                    type: object
+                                type: object
+                              namespaces:
+                                items:
+                                  type: string
+                                type: array
+                              topologyKey:
+                                type: string
+                            type: object
+                          type: array
+                      type: object
+                  type: object
+                cluster:
+                  type: string
+                configFiles:
+                  additionalProperties:
+                    type: string
+                  type: object
+                index:
+                  properties:
+                    remoteIndexConfig:
+                      properties:
+                        config:
+                          type: string
+                        server:
+                          type: string
+                      type: object
+                    type:
+                      enum:
+                        - ELASTICSEARCH
+                        - LUCENE
+                        - OPENSEARCH
+                      type: string
+                  type: object
+                openSearchSecretRef:
+                  type: string
+                resources:
+                  properties:
+                    claims:
+                      items:
+                        properties:
+                          name:
+                            type: string
+                        type: object
+                      type: array
+                    limits:
+                      additionalProperties:
+                        anyOf:
+                          - type: integer
+                          - type: string
+                        x-kubernetes-int-or-string: true
+                      type: object
+                    requests:
+                      additionalProperties:
+                        anyOf:
+                          - type: integer
+                          - type: string
+                        x-kubernetes-int-or-string: true
+                      type: object
+                  type: object
+                storage:
+                  properties:
+                    output:
+                      properties:
+                        persistentVolumeClaim:
+                          type: string
+                        subPath:
+                          type: string
+                      type: object
+                    repositories:
+                      properties:
+                        persistentVolumeClaim:
+                          type: string
+                        subPath:
+                          type: string
+                      type: object
+                    site:
+                      properties:
+                        persistentVolumeClaim:
+                          type: string
+                        subPath:
+                          type: string
+                      type: object
+                  type: object
+                tolerations:
+                  items:
+                    properties:
+                      effect:
+                        type: string
+                      key:
+                        type: string
+                      operator:
+                        type: string
+                      tolerationSeconds:
+                        type: integer
+                      value:
+                        type: string
+                    type: object
+                  type: array
+              type: object
+            status:
+              properties:
+                apiVersion:
+                  type: string
+                code:
+                  type: integer
+                details:
+                  properties:
+                    causes:
+                      items:
+                        properties:
+                          field:
+                            type: string
+                          message:
+                            type: string
+                          reason:
+                            type: string
+                        type: object
+                      type: array
+                    group:
+                      type: string
+                    kind:
+                      type: string
+                    name:
+                      type: string
+                    retryAfterSeconds:
+                      type: integer
+                    uid:
+                      type: string
+                  type: object
+                kind:
+                  type: string
+                message:
+                  type: string
+                metadata:
+                  properties:
+                    continue:
+                      type: string
+                    remainingItemCount:
+                      type: integer
+                    resourceVersion:
+                      type: string
+                    selfLink:
+                      type: string
+                  type: object
+                reason:
+                  type: string
+                status:
+                  type: string
+              type: object
+          type: object
+      served: true
+      storage: true
+      subresources:
+        status: {}
     - name: v1beta18
       schema:
         openAPIV3Schema:
@@ -369,481 +846,8 @@
                         - OPENSEARCH
                       type: string
                   type: object
-                resources:
-                  properties:
-                    claims:
-                      items:
-                        properties:
-                          name:
-                            type: string
-                        type: object
-                      type: array
-                    limits:
-                      additionalProperties:
-                        anyOf:
-                          - type: integer
-                          - type: string
-                        x-kubernetes-int-or-string: true
-                      type: object
-                    requests:
-                      additionalProperties:
-                        anyOf:
-                          - type: integer
-                          - type: string
-                        x-kubernetes-int-or-string: true
-                      type: object
-                  type: object
-                storage:
-                  properties:
-                    output:
-                      properties:
-                        persistentVolumeClaim:
-                          type: string
-                        subPath:
-                          type: string
-                      type: object
-                    repositories:
-                      properties:
-                        persistentVolumeClaim:
-                          type: string
-                        subPath:
-                          type: string
-                      type: object
-                    site:
-                      properties:
-                        persistentVolumeClaim:
-                          type: string
-                        subPath:
-                          type: string
-                      type: object
-                  type: object
-                tolerations:
-                  items:
-                    properties:
-                      effect:
-                        type: string
-                      key:
-                        type: string
-                      operator:
-                        type: string
-                      tolerationSeconds:
-                        type: integer
-                      value:
-                        type: string
-                    type: object
-                  type: array
-              type: object
-            status:
-              properties:
-                apiVersion:
+                openSearchSecretRef:
                   type: string
-                code:
-                  type: integer
-                details:
-                  properties:
-                    causes:
-                      items:
-                        properties:
-                          field:
-                            type: string
-                          message:
-                            type: string
-                          reason:
-                            type: string
-                        type: object
-                      type: array
-                    group:
-                      type: string
-                    kind:
-                      type: string
-                    name:
-                      type: string
-                    retryAfterSeconds:
-                      type: integer
-                    uid:
-                      type: string
-                  type: object
-                kind:
-                  type: string
-                message:
-                  type: string
-                metadata:
-                  properties:
-                    continue:
-                      type: string
-                    remainingItemCount:
-                      type: integer
-                    resourceVersion:
-                      type: string
-                    selfLink:
-                      type: string
-                  type: object
-                reason:
-                  type: string
-                status:
-                  type: string
-              type: object
-          type: object
-      served: true
-      storage: true
-      subresources:
-        status: {}
-    - name: v1beta17
-      schema:
-        openAPIV3Schema:
-          properties:
-            spec:
-              properties:
-                affinity:
-                  properties:
-                    nodeAffinity:
-                      properties:
-                        preferredDuringSchedulingIgnoredDuringExecution:
-                          items:
-                            properties:
-                              preference:
-                                properties:
-                                  matchExpressions:
-                                    items:
-                                      properties:
-                                        key:
-                                          type: string
-                                        operator:
-                                          type: string
-                                        values:
-                                          items:
-                                            type: string
-                                          type: array
-                                      type: object
-                                    type: array
-                                  matchFields:
-                                    items:
-                                      properties:
-                                        key:
-                                          type: string
-                                        operator:
-                                          type: string
-                                        values:
-                                          items:
-                                            type: string
-                                          type: array
-                                      type: object
-                                    type: array
-                                type: object
-                              weight:
-                                type: integer
-                            type: object
-                          type: array
-                        requiredDuringSchedulingIgnoredDuringExecution:
-                          properties:
-                            nodeSelectorTerms:
-                              items:
-                                properties:
-                                  matchExpressions:
-                                    items:
-                                      properties:
-                                        key:
-                                          type: string
-                                        operator:
-                                          type: string
-                                        values:
-                                          items:
-                                            type: string
-                                          type: array
-                                      type: object
-                                    type: array
-                                  matchFields:
-                                    items:
-                                      properties:
-                                        key:
-                                          type: string
-                                        operator:
-                                          type: string
-                                        values:
-                                          items:
-                                            type: string
-                                          type: array
-                                      type: object
-                                    type: array
-                                type: object
-                              type: array
-                          type: object
-                      type: object
-                    podAffinity:
-                      properties:
-                        preferredDuringSchedulingIgnoredDuringExecution:
-                          items:
-                            properties:
-                              podAffinityTerm:
-                                properties:
-                                  labelSelector:
-                                    properties:
-                                      matchExpressions:
-                                        items:
-                                          properties:
-                                            key:
-                                              type: string
-                                            operator:
-                                              type: string
-                                            values:
-                                              items:
-                                                type: string
-                                              type: array
-                                          type: object
-                                        type: array
-                                      matchLabels:
-                                        additionalProperties:
-                                          type: string
-                                        type: object
-                                    type: object
-                                  matchLabelKeys:
-                                    items:
-                                      type: string
-                                    type: array
-                                  mismatchLabelKeys:
-                                    items:
-                                      type: string
-                                    type: array
-                                  namespaceSelector:
-                                    properties:
-                                      matchExpressions:
-                                        items:
-                                          properties:
-                                            key:
-                                              type: string
-                                            operator:
-                                              type: string
-                                            values:
-                                              items:
-                                                type: string
-                                              type: array
-                                          type: object
-                                        type: array
-                                      matchLabels:
-                                        additionalProperties:
-                                          type: string
-                                        type: object
-                                    type: object
-                                  namespaces:
-                                    items:
-                                      type: string
-                                    type: array
-                                  topologyKey:
-                                    type: string
-                                type: object
-                              weight:
-                                type: integer
-                            type: object
-                          type: array
-                        requiredDuringSchedulingIgnoredDuringExecution:
-                          items:
-                            properties:
-                              labelSelector:
-                                properties:
-                                  matchExpressions:
-                                    items:
-                                      properties:
-                                        key:
-                                          type: string
-                                        operator:
-                                          type: string
-                                        values:
-                                          items:
-                                            type: string
-                                          type: array
-                                      type: object
-                                    type: array
-                                  matchLabels:
-                                    additionalProperties:
-                                      type: string
-                                    type: object
-                                type: object
-                              matchLabelKeys:
-                                items:
-                                  type: string
-                                type: array
-                              mismatchLabelKeys:
-                                items:
-                                  type: string
-                                type: array
-                              namespaceSelector:
-                                properties:
-                                  matchExpressions:
-                                    items:
-                                      properties:
-                                        key:
-                                          type: string
-                                        operator:
-                                          type: string
-                                        values:
-                                          items:
-                                            type: string
-                                          type: array
-                                      type: object
-                                    type: array
-                                  matchLabels:
-                                    additionalProperties:
-                                      type: string
-                                    type: object
-                                type: object
-                              namespaces:
-                                items:
-                                  type: string
-                                type: array
-                              topologyKey:
-                                type: string
-                            type: object
-                          type: array
-                      type: object
-                    podAntiAffinity:
-                      properties:
-                        preferredDuringSchedulingIgnoredDuringExecution:
-                          items:
-                            properties:
-                              podAffinityTerm:
-                                properties:
-                                  labelSelector:
-                                    properties:
-                                      matchExpressions:
-                                        items:
-                                          properties:
-                                            key:
-                                              type: string
-                                            operator:
-                                              type: string
-                                            values:
-                                              items:
-                                                type: string
-                                              type: array
-                                          type: object
-                                        type: array
-                                      matchLabels:
-                                        additionalProperties:
-                                          type: string
-                                        type: object
-                                    type: object
-                                  matchLabelKeys:
-                                    items:
-                                      type: string
-                                    type: array
-                                  mismatchLabelKeys:
-                                    items:
-                                      type: string
-                                    type: array
-                                  namespaceSelector:
-                                    properties:
-                                      matchExpressions:
-                                        items:
-                                          properties:
-                                            key:
-                                              type: string
-                                            operator:
-                                              type: string
-                                            values:
-                                              items:
-                                                type: string
-                                              type: array
-                                          type: object
-                                        type: array
-                                      matchLabels:
-                                        additionalProperties:
-                                          type: string
-                                        type: object
-                                    type: object
-                                  namespaces:
-                                    items:
-                                      type: string
-                                    type: array
-                                  topologyKey:
-                                    type: string
-                                type: object
-                              weight:
-                                type: integer
-                            type: object
-                          type: array
-                        requiredDuringSchedulingIgnoredDuringExecution:
-                          items:
-                            properties:
-                              labelSelector:
-                                properties:
-                                  matchExpressions:
-                                    items:
-                                      properties:
-                                        key:
-                                          type: string
-                                        operator:
-                                          type: string
-                                        values:
-                                          items:
-                                            type: string
-                                          type: array
-                                      type: object
-                                    type: array
-                                  matchLabels:
-                                    additionalProperties:
-                                      type: string
-                                    type: object
-                                type: object
-                              matchLabelKeys:
-                                items:
-                                  type: string
-                                type: array
-                              mismatchLabelKeys:
-                                items:
-                                  type: string
-                                type: array
-                              namespaceSelector:
-                                properties:
-                                  matchExpressions:
-                                    items:
-                                      properties:
-                                        key:
-                                          type: string
-                                        operator:
-                                          type: string
-                                        values:
-                                          items:
-                                            type: string
-                                          type: array
-                                      type: object
-                                    type: array
-                                  matchLabels:
-                                    additionalProperties:
-                                      type: string
-                                    type: object
-                                type: object
-                              namespaces:
-                                items:
-                                  type: string
-                                type: array
-                              topologyKey:
-                                type: string
-                            type: object
-                          type: array
-                      type: object
-                  type: object
-                cluster:
-                  type: string
-                configFiles:
-                  additionalProperties:
-                    type: string
-                  type: object
-                index:
-                  properties:
-                    remoteIndexConfig:
-                      properties:
-                        config:
-                          type: string
-                        server:
-                          type: string
-                      type: object
-                    type:
-                      enum:
-                        - ELASTICSEARCH
-                        - LUCENE
-                        - OPENSEARCH
-                      type: string
-                  type: object
                 resources:
                   properties:
                     claims:
diff --git a/helm-charts/gerrit-operator-crds/templates/gerritmaintenances.gerritoperator.google.com-v1.yml b/helm-charts/gerrit-operator-crds/templates/gerritmaintenances.gerritoperator.google.com-v1.yml
index b8c63bc..d11ddd6 100644
--- a/helm-charts/gerrit-operator-crds/templates/gerritmaintenances.gerritoperator.google.com-v1.yml
+++ b/helm-charts/gerrit-operator-crds/templates/gerritmaintenances.gerritoperator.google.com-v1.yml
@@ -11,7 +11,7 @@
     singular: gerritmaintenance
   scope: Namespaced
   versions:
-    - name: v1beta18
+    - name: v1beta19
       schema:
         openAPIV3Schema:
           properties:
@@ -555,7 +555,7 @@
       storage: true
       subresources:
         status: {}
-    - name: v1beta17
+    - name: v1beta18
       schema:
         openAPIV3Schema:
           properties:
diff --git a/helm-charts/gerrit-operator-crds/templates/gerritnetworks.gerritoperator.google.com-v1.yml b/helm-charts/gerrit-operator-crds/templates/gerritnetworks.gerritoperator.google.com-v1.yml
index 267a3d3..b8a1c13 100644
--- a/helm-charts/gerrit-operator-crds/templates/gerritnetworks.gerritoperator.google.com-v1.yml
+++ b/helm-charts/gerrit-operator-crds/templates/gerritnetworks.gerritoperator.google.com-v1.yml
@@ -13,7 +13,7 @@
     singular: gerritnetwork
   scope: Namespaced
   versions:
-    - name: v1beta18
+    - name: v1beta19
       schema:
         openAPIV3Schema:
           properties:
@@ -143,7 +143,7 @@
       storage: true
       subresources:
         status: {}
-    - name: v1beta17
+    - name: v1beta18
       schema:
         openAPIV3Schema:
           properties:
diff --git a/helm-charts/gerrit-operator-crds/templates/gerrits.gerritoperator.google.com-v1.yml b/helm-charts/gerrit-operator-crds/templates/gerrits.gerritoperator.google.com-v1.yml
index eb32fd9..b5cb2a5 100644
--- a/helm-charts/gerrit-operator-crds/templates/gerrits.gerritoperator.google.com-v1.yml
+++ b/helm-charts/gerrit-operator-crds/templates/gerrits.gerritoperator.google.com-v1.yml
@@ -13,7 +13,7 @@
     singular: gerrit
   scope: Namespaced
   versions:
-    - name: v1beta18
+    - name: v1beta19
       schema:
         openAPIV3Schema:
           properties:
@@ -948,7 +948,7 @@
       storage: true
       subresources:
         status: {}
-    - name: v1beta17
+    - name: v1beta18
       schema:
         openAPIV3Schema:
           properties:
diff --git a/helm-charts/gerrit-operator-crds/templates/gitgcs.gerritoperator.google.com-v1.yml b/helm-charts/gerrit-operator-crds/templates/gitgcs.gerritoperator.google.com-v1.yml
index 10eaf8a..9d5879d 100644
--- a/helm-charts/gerrit-operator-crds/templates/gitgcs.gerritoperator.google.com-v1.yml
+++ b/helm-charts/gerrit-operator-crds/templates/gitgcs.gerritoperator.google.com-v1.yml
@@ -13,7 +13,7 @@
     singular: gitgarbagecollection
   scope: Namespaced
   versions:
-    - name: v1beta18
+    - name: v1beta19
       schema:
         openAPIV3Schema:
           properties:
@@ -422,7 +422,7 @@
       storage: true
       subresources:
         status: {}
-    - name: v1beta17
+    - name: v1beta18
       schema:
         openAPIV3Schema:
           properties:
diff --git a/helm-charts/gerrit-operator-crds/templates/incomingreplicationtasks.gerritoperator.google.com-v1.yml b/helm-charts/gerrit-operator-crds/templates/incomingreplicationtasks.gerritoperator.google.com-v1.yml
index f00f004..ab73486 100644
--- a/helm-charts/gerrit-operator-crds/templates/incomingreplicationtasks.gerritoperator.google.com-v1.yml
+++ b/helm-charts/gerrit-operator-crds/templates/incomingreplicationtasks.gerritoperator.google.com-v1.yml
@@ -11,7 +11,7 @@
     singular: incomingreplicationtask
   scope: Namespaced
   versions:
-    - name: v1beta18
+    - name: v1beta19
       schema:
         openAPIV3Schema:
           properties:
@@ -568,7 +568,7 @@
       storage: true
       subresources:
         status: {}
-    - name: v1beta17
+    - name: v1beta18
       schema:
         openAPIV3Schema:
           properties:
diff --git a/helm-charts/gerrit-operator-crds/templates/receivers.gerritoperator.google.com-v1.yml b/helm-charts/gerrit-operator-crds/templates/receivers.gerritoperator.google.com-v1.yml
index 243fc7d..dd40f52 100644
--- a/helm-charts/gerrit-operator-crds/templates/receivers.gerritoperator.google.com-v1.yml
+++ b/helm-charts/gerrit-operator-crds/templates/receivers.gerritoperator.google.com-v1.yml
@@ -13,7 +13,7 @@
     singular: receiver
   scope: Namespaced
   versions:
-    - name: v1beta18
+    - name: v1beta19
       schema:
         openAPIV3Schema:
           properties:
@@ -687,7 +687,7 @@
       storage: true
       subresources:
         status: {}
-    - name: v1beta17
+    - name: v1beta18
       schema:
         openAPIV3Schema:
           properties:
diff --git a/operator/src/main/java/com/google/gerrit/k8s/operator/Constants.java b/operator/src/main/java/com/google/gerrit/k8s/operator/Constants.java
index 64de43f..a781fb4 100644
--- a/operator/src/main/java/com/google/gerrit/k8s/operator/Constants.java
+++ b/operator/src/main/java/com/google/gerrit/k8s/operator/Constants.java
@@ -17,7 +17,7 @@
 import com.google.inject.AbstractModule;
 
 public class Constants extends AbstractModule {
-  public static final String VERSION = "v1beta18";
+  public static final String VERSION = "v1beta19";
 
   // The resource kind always has to be plural for use in webhooks
   public static final String GERRIT_CLUSTER_KIND = "gerritclusters";
diff --git a/operator/src/main/java/com/google/gerrit/k8s/operator/api/model/indexer/GerritIndexerSpec.java b/operator/src/main/java/com/google/gerrit/k8s/operator/api/model/indexer/GerritIndexerSpec.java
index f43c7e3..599c6c0 100644
--- a/operator/src/main/java/com/google/gerrit/k8s/operator/api/model/indexer/GerritIndexerSpec.java
+++ b/operator/src/main/java/com/google/gerrit/k8s/operator/api/model/indexer/GerritIndexerSpec.java
@@ -32,6 +32,7 @@
   private Map<String, String> configFiles = new HashMap<>();
   private GerritIndexerStorage storage = new GerritIndexerStorage();
   private IndexConfig index;
+  private String openSearchSecretRef;
 
   public List<Toleration> getTolerations() {
     return tolerations;
@@ -89,9 +90,25 @@
     this.index = index;
   }
 
+  public String getOpenSearchSecretRef() {
+    return openSearchSecretRef;
+  }
+
+  public void setOpenSearchSecretRef(String openSearchSecretRef) {
+    this.openSearchSecretRef = openSearchSecretRef;
+  }
+
   @Override
   public int hashCode() {
-    return Objects.hash(affinity, cluster, configFiles, index, resources, storage, tolerations);
+    return Objects.hash(
+        affinity,
+        cluster,
+        configFiles,
+        index,
+        openSearchSecretRef,
+        resources,
+        storage,
+        tolerations);
   }
 
   @Override
@@ -104,6 +121,7 @@
         && Objects.equals(cluster, other.cluster)
         && Objects.equals(configFiles, other.configFiles)
         && Objects.equals(index, other.index)
+        && Objects.equals(openSearchSecretRef, other.openSearchSecretRef)
         && Objects.equals(resources, other.resources)
         && Objects.equals(storage, other.storage)
         && Objects.equals(tolerations, other.tolerations);
@@ -125,6 +143,8 @@
         + storage
         + ", index="
         + index
+        + ", openSearchSecretRef="
+        + openSearchSecretRef
         + "]";
   }
 }
diff --git a/operator/src/main/java/com/google/gerrit/k8s/operator/indexer/dependent/GerritIndexerJob.java b/operator/src/main/java/com/google/gerrit/k8s/operator/indexer/dependent/GerritIndexerJob.java
index 4dfcc09..efa611a 100644
--- a/operator/src/main/java/com/google/gerrit/k8s/operator/indexer/dependent/GerritIndexerJob.java
+++ b/operator/src/main/java/com/google/gerrit/k8s/operator/indexer/dependent/GerritIndexerJob.java
@@ -30,6 +30,7 @@
 import io.fabric8.kubernetes.api.model.EmptyDirVolumeSourceBuilder;
 import io.fabric8.kubernetes.api.model.LabelSelectorBuilder;
 import io.fabric8.kubernetes.api.model.Quantity;
+import io.fabric8.kubernetes.api.model.Secret;
 import io.fabric8.kubernetes.api.model.Volume;
 import io.fabric8.kubernetes.api.model.VolumeBuilder;
 import io.fabric8.kubernetes.api.model.VolumeMount;
@@ -45,6 +46,11 @@
     extends CRUDReconcileAddKubernetesDependentResource<Job, GerritIndexer> {
   private static final Quantity HOME_DIR_SIZE_LIMIT = new Quantity("500", "Mi");
   private static final String TMP_VOLUME_NAME = "tmp";
+  private static final String OPENSEARCH_SECRET_VOLUME = "opensearch-secret";
+  private static final String CA_CERT_MOUNT_PATH = "/var/config/ca.crt";
+  private static final String TRUST_STORE_MOUNT_PATH = "/var/mnt/data/index-opensearch";
+  String ns;
+  Context<GerritIndexer> context;
 
   public GerritIndexerJob() {
     super(Job.class);
@@ -52,7 +58,8 @@
 
   @Override
   protected Job desired(GerritIndexer gerritIndexer, Context<GerritIndexer> context) {
-    String ns = gerritIndexer.getMetadata().getNamespace();
+    this.ns = gerritIndexer.getMetadata().getNamespace();
+    this.context = context;
     GerritCluster gerritCluster =
         context
             .getClient()
@@ -164,9 +171,37 @@
     volumeMounts.add(
         new VolumeMountBuilder()
             .withName("gerrit-init-config")
-            .withMountPath("/var/config")
+            .withMountPath("/var/config/gerrit-init.yaml")
+            .withSubPath("gerrit-init.yaml")
             .build());
 
+    String openSearchSecretRef = indexerSpec.getOpenSearchSecretRef();
+    if (openSearchSecretRef != null && !openSearchSecretRef.isBlank()) {
+      Secret secret =
+          context
+              .getClient()
+              .resources(Secret.class)
+              .inNamespace(this.ns)
+              .withName(openSearchSecretRef)
+              .get();
+      if (secret != null) {
+        if (secret.getData().containsKey("ca.crt")) {
+          volumeMounts.add(
+              new VolumeMountBuilder()
+                  .withName(OPENSEARCH_SECRET_VOLUME)
+                  .withMountPath(CA_CERT_MOUNT_PATH)
+                  .withSubPath("ca.crt")
+                  .build());
+        }
+        if (secret.getData().containsKey("truststore.jks")) {
+          volumeMounts.add(
+              new VolumeMountBuilder()
+                  .withName(OPENSEARCH_SECRET_VOLUME)
+                  .withMountPath(TRUST_STORE_MOUNT_PATH)
+                  .build());
+        }
+      }
+    }
     volumeMounts.addAll(buildCommonVolumeMounts(indexerSpec));
 
     return volumeMounts;
@@ -183,7 +218,23 @@
               .withMountPath("/indexes")
               .build());
     }
-
+    String openSearchSecretRef = indexerSpec.getOpenSearchSecretRef();
+    if (openSearchSecretRef != null && !openSearchSecretRef.isBlank()) {
+      Secret secret =
+          context
+              .getClient()
+              .resources(Secret.class)
+              .inNamespace(ns)
+              .withName(openSearchSecretRef)
+              .get();
+      if (secret != null && secret.getData().containsKey("truststore.jks")) {
+        volumeMounts.add(
+            new VolumeMountBuilder()
+                .withName(OPENSEARCH_SECRET_VOLUME)
+                .withMountPath(TRUST_STORE_MOUNT_PATH)
+                .build());
+      }
+    }
     volumeMounts.addAll(buildCommonVolumeMounts(indexerSpec));
 
     return volumeMounts;
@@ -306,7 +357,18 @@
               .endPersistentVolumeClaim()
               .build());
     }
-
+    if (indexerSpec.getIndex().getType().isRemote()) {
+      String openSearchSecretRef = indexerSpec.getOpenSearchSecretRef();
+      if (openSearchSecretRef != null && !openSearchSecretRef.isBlank()) {
+        volumes.add(
+            new VolumeBuilder()
+                .withName(OPENSEARCH_SECRET_VOLUME)
+                .withNewSecret()
+                .withSecretName(openSearchSecretRef)
+                .endSecret()
+                .build());
+      }
+    }
     volumes.add(
         new VolumeBuilder()
             .withEmptyDir(
diff --git a/operator/src/test/java/com/google/gerrit/k8s/operator/indexer/dependent/GerritIndexerTest.java b/operator/src/test/java/com/google/gerrit/k8s/operator/indexer/dependent/GerritIndexerTest.java
index 8d99c32..b3c26bd 100644
--- a/operator/src/test/java/com/google/gerrit/k8s/operator/indexer/dependent/GerritIndexerTest.java
+++ b/operator/src/test/java/com/google/gerrit/k8s/operator/indexer/dependent/GerritIndexerTest.java
@@ -25,6 +25,8 @@
 import com.google.gerrit.k8s.operator.indexer.GerritIndexerReconciler;
 import io.fabric8.kubernetes.api.model.ConfigMap;
 import io.fabric8.kubernetes.api.model.HasMetadata;
+import io.fabric8.kubernetes.api.model.Secret;
+import io.fabric8.kubernetes.api.model.SecretBuilder;
 import io.fabric8.kubernetes.api.model.batch.v1.Job;
 import io.fabric8.kubernetes.client.server.mock.KubernetesServer;
 import io.javaoperatorsdk.operator.ReconcilerUtils;
@@ -78,9 +80,9 @@
 
     Context<GerritIndexer> context = getContext(new GerritIndexerReconciler(), input);
     GerritIndexerJob dependentCronjob = new GerritIndexerJob();
-    assertUnordered(
-        dependentCronjob.desired(input, context),
-        ReconcilerUtils.loadYaml(Job.class, this.getClass(), expectedJob));
+
+    Job actual = dependentCronjob.desired(input, context);
+    assertUnordered(actual, ReconcilerUtils.loadYaml(Job.class, this.getClass(), expectedJob));
 
     GerritIndexerConfigMap dependentConfigmap = new GerritIndexerConfigMap();
     assertDesiredConfigMapCreated(
@@ -89,6 +91,25 @@
   }
 
   private void stubs(GerritCluster gerritCluster) {
+    Secret testSecret =
+        new SecretBuilder()
+            .withNewMetadata()
+            .withName("opensearch-tls-config")
+            .withNamespace("gerrit")
+            .endMetadata()
+            .withData(
+                Map.of(
+                    "ca.crt", "Y2VydA==",
+                    "truststore.jks", "dHJ1c3RzdG9yZQ=="))
+            .build();
+
+    kubernetesServer
+        .expect()
+        .get()
+        .withPath("/api/v1/namespaces/gerrit/secrets/opensearch-tls-config")
+        .andReturn(HttpURLConnection.HTTP_OK, testSecret)
+        .always();
+
     kubernetesServer
         .expect()
         .get()
@@ -143,6 +164,11 @@
             "../indexer.yaml",
             "../gerritcluster_es.yaml",
             "indexer_es.job.yaml",
-            "indexer_es.configmap.yaml"));
+            "indexer_es.configmap.yaml"),
+        Arguments.of(
+            "../indexer_os.yaml",
+            "../gerritcluster_minimal.yaml",
+            "indexer_os.job.yaml",
+            "indexer_os.configmap.yaml"));
   }
 }
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/cluster/dependent/gerrit_maintenance.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/cluster/dependent/gerrit_maintenance.yaml
index 6f78336..4200d7e 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/cluster/dependent/gerrit_maintenance.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/cluster/dependent/gerrit_maintenance.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritMaintenance
 metadata:
   name: gerrit-gerrit-maintenance
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/cluster/dependent/gerrit_primary.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/cluster/dependent/gerrit_primary.yaml
index de1acd6..11c751a 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/cluster/dependent/gerrit_primary.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/cluster/dependent/gerrit_primary.yaml
@@ -1,9 +1,9 @@
-apiVersion: gerritoperator.google.com/v1beta18
+apiVersion: gerritoperator.google.com/v1beta19
 kind: Gerrit
 metadata:
   name: gerrit
   annotations:
-    gerritoperator.google.com/apiVersion: gerritoperator.google.com/v1beta18
+    gerritoperator.google.com/apiVersion: gerritoperator.google.com/v1beta19
 spec:
   configFiles: {}
   containerImages:
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/cluster/dependent/gerrit_replica.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/cluster/dependent/gerrit_replica.yaml
index d43d02e..87083b7 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/cluster/dependent/gerrit_replica.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/cluster/dependent/gerrit_replica.yaml
@@ -1,9 +1,9 @@
-apiVersion: gerritoperator.google.com/v1beta18
+apiVersion: gerritoperator.google.com/v1beta19
 kind: Gerrit
 metadata:
   name: gerrit-replica
   annotations:
-    gerritoperator.google.com/apiVersion: gerritoperator.google.com/v1beta18
+    gerritoperator.google.com/apiVersion: gerritoperator.google.com/v1beta19
 spec:
   configFiles: {}
   containerImages:
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/cluster/gerritcluster_primary_replica.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/cluster/gerritcluster_primary_replica.yaml
index 07fbdf2..1e66610 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/cluster/gerritcluster_primary_replica.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/cluster/gerritcluster_primary_replica.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritCluster
 metadata:
   name: gerrit
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/gerrit/gerrit_es_primary.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/gerrit/gerrit_es_primary.yaml
index 4189eda..3deb309 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/gerrit/gerrit_es_primary.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/gerrit/gerrit_es_primary.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: Gerrit
 metadata:
   name: gerrit
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/gerrit/gerrit_ha_primary.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/gerrit/gerrit_ha_primary.yaml
index 3a9f0db..f831878 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/gerrit/gerrit_ha_primary.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/gerrit/gerrit_ha_primary.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: Gerrit
 metadata:
   name: gerrit
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/gerrit/gerrit_os_primary.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/gerrit/gerrit_os_primary.yaml
index 0240683..e4c4c5f 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/gerrit/gerrit_os_primary.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/gerrit/gerrit_os_primary.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: Gerrit
 metadata:
   name: gerrit
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/gerrit/gerrit_single_primary.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/gerrit/gerrit_single_primary.yaml
index 475804a..5817fc7 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/gerrit/gerrit_single_primary.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/gerrit/gerrit_single_primary.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: Gerrit
 metadata:
   name: gerrit
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/dependent/cronjob_all_default.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/dependent/cronjob_all_default.yaml
index e0d9ab0..a372980 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/dependent/cronjob_all_default.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/dependent/cronjob_all_default.yaml
@@ -14,7 +14,7 @@
   annotations:
     app.kubernetes.io/managed-by: gerrit-operator
   ownerReferences:
-  - apiVersion: gerritoperator.google.com/v1beta18
+  - apiVersion: gerritoperator.google.com/v1beta19
     kind: GitGarbageCollection
     name: gitgc
     uid: abcd1234
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/dependent/cronjob_all_nfs_workaround.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/dependent/cronjob_all_nfs_workaround.yaml
index e46db51..88802ff 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/dependent/cronjob_all_nfs_workaround.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/dependent/cronjob_all_nfs_workaround.yaml
@@ -14,7 +14,7 @@
   annotations:
     app.kubernetes.io/managed-by: gerrit-operator
   ownerReferences:
-  - apiVersion: gerritoperator.google.com/v1beta18
+  - apiVersion: gerritoperator.google.com/v1beta19
     kind: GitGarbageCollection
     name: gitgc
     uid: abcd1234
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/dependent/cronjob_all_options_enabled.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/dependent/cronjob_all_options_enabled.yaml
index 5b270f9..1ddfd9d 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/dependent/cronjob_all_options_enabled.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/dependent/cronjob_all_options_enabled.yaml
@@ -14,7 +14,7 @@
   annotations:
     app.kubernetes.io/managed-by: gerrit-operator
   ownerReferences:
-  - apiVersion: gerritoperator.google.com/v1beta18
+  - apiVersion: gerritoperator.google.com/v1beta19
     kind: GitGarbageCollection
     name: gitgc
     uid: abcd1234
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/dependent/cronjob_selected_default.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/dependent/cronjob_selected_default.yaml
index 035afc8..237dbe6 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/dependent/cronjob_selected_default.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/dependent/cronjob_selected_default.yaml
@@ -14,7 +14,7 @@
   annotations:
     app.kubernetes.io/managed-by: gerrit-operator
   ownerReferences:
-  - apiVersion: gerritoperator.google.com/v1beta18
+  - apiVersion: gerritoperator.google.com/v1beta19
     kind: GitGarbageCollection
     name: gitgc
     uid: abcd1234
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/dependent/cronjob_selected_options_enabled.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/dependent/cronjob_selected_options_enabled.yaml
index b6486a0..eee466f 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/dependent/cronjob_selected_options_enabled.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/dependent/cronjob_selected_options_enabled.yaml
@@ -14,7 +14,7 @@
   annotations:
     app.kubernetes.io/managed-by: gerrit-operator
   ownerReferences:
-  - apiVersion: gerritoperator.google.com/v1beta18
+  - apiVersion: gerritoperator.google.com/v1beta19
     kind: GitGarbageCollection
     name: gitgc
     uid: abcd1234
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gerritcluster_minimal.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gerritcluster_minimal.yaml
index ee176d6..77a5445 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gerritcluster_minimal.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gerritcluster_minimal.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritCluster
 metadata:
   name: gerrit
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gerritcluster_nfs_workaround.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gerritcluster_nfs_workaround.yaml
index e46dcd7..34ebfd1 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gerritcluster_nfs_workaround.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gerritcluster_nfs_workaround.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritCluster
 metadata:
   name: gerrit
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gitgc_all_default.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gitgc_all_default.yaml
index 8f0512a..7e97792 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gitgc_all_default.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gitgc_all_default.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GitGarbageCollection
 metadata:
   name: gitgc
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gitgc_all_options_enabled.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gitgc_all_options_enabled.yaml
index 4d9fbbe..0b38ed8 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gitgc_all_options_enabled.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gitgc_all_options_enabled.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GitGarbageCollection
 metadata:
   name: gitgc
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gitgc_selected_default.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gitgc_selected_default.yaml
index 5c1b7d5..d65b5b8 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gitgc_selected_default.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gitgc_selected_default.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GitGarbageCollection
 metadata:
   name: gitgc
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gitgc_selected_options_enabled.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gitgc_selected_options_enabled.yaml
index 3188cf1..4ff0131 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gitgc_selected_options_enabled.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/gitgc/gitgc_selected_options_enabled.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GitGarbageCollection
 metadata:
   name: gitgc
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/dependent/indexer.job.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/dependent/indexer.job.yaml
index 9a52b5e..d2f11b0 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/dependent/indexer.job.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/dependent/indexer.job.yaml
@@ -66,8 +66,9 @@
             cpu: 3
             memory: 6Gi
         volumeMounts:
-        - mountPath: /var/config
+        - mountPath: /var/config/gerrit-init.yaml
           name: gerrit-init-config
+          subPath: gerrit-init.yaml
         - mountPath: /home/gerrit
           subPath: home
           name: tmp
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/dependent/indexer_es.job.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/dependent/indexer_es.job.yaml
index 3fd3bde..04d8264 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/dependent/indexer_es.job.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/dependent/indexer_es.job.yaml
@@ -66,8 +66,9 @@
             cpu: 3
             memory: 6Gi
         volumeMounts:
-        - mountPath: /var/config
+        - mountPath: /var/config/gerrit-init.yaml
           name: gerrit-init-config
+          subPath: gerrit-init.yaml
         - mountPath: /home/gerrit
           subPath: home
           name: tmp
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/dependent/indexer_os.configmap.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/dependent/indexer_os.configmap.yaml
new file mode 100644
index 0000000..972125a
--- /dev/null
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/dependent/indexer_os.configmap.yaml
@@ -0,0 +1,42 @@
+apiVersion: v1
+kind: ConfigMap
+metadata:
+  name: gerrit-indexer-configmap
+  namespace: gerrit
+  labels:
+    app.kubernetes.io/managed-by: gerrit-operator
+    app.kubernetes.io/name: gerrit
+    app.kubernetes.io/part-of: gerrit-indexer
+    app.kubernetes.io/created-by: GerritIndexerConfigMap
+    app.kubernetes.io/instance: gerrit-indexer
+    app.kubernetes.io/version: unknown
+    app.kubernetes.io/component: gerrit-indexer-configmap
+data:
+  gerrit.config: |
+    [log]
+      textLogging = true
+      jsonLogging = true
+    [cache]
+      directory = cache
+    [container]
+      user = gerrit
+      replica = false
+      javaHome = /usr/lib/jvm/java-11-openjdk
+      javaOptions = -Djavax.net.ssl.trustStore=/var/gerrit/etc/keystore
+      javaOptions = -Djava.net.preferIPv4Stack=true
+      javaOptions = -Djava.io.tmpdir=/var/gerrit/tmp/java
+    [opensearch]
+      server = http://opensearch.example.com:9200
+      codec = default
+    [gerrit]
+      basepath = git
+      serverId = gerrit/gerrit
+      installModule = com.gerritforge.gerrit.globalrefdb.validation.LibModule
+      installDbModule = com.ericsson.gerrit.plugins.highavailability.ValidationModule
+      installIndexModule=com.google.gerrit.opensearch.OpenSearchIndexModule
+    [plugins]
+      mandatory = healthcheck
+      mandatory = high-availability
+      mandatory = index-opensearch
+    [sshd]
+      listenAddress = *:29418
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/dependent/indexer_os.job.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/dependent/indexer_os.job.yaml
new file mode 100644
index 0000000..7a11bd4
--- /dev/null
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/dependent/indexer_os.job.yaml
@@ -0,0 +1,147 @@
+apiVersion: batch/v1
+kind: Job
+metadata:
+  name: gerrit-indexer
+  namespace: gerrit
+  labels:
+    app.kubernetes.io/managed-by: gerrit-operator
+    app.kubernetes.io/name: gerrit
+    app.kubernetes.io/part-of: gerrit-indexer
+    app.kubernetes.io/created-by: GerritIndexerReconciler
+    app.kubernetes.io/instance: gerrit-indexer
+    app.kubernetes.io/version: unknown
+    app.kubernetes.io/component: gerrit-indexer-gerrit-indexer
+spec:
+  manualSelector: true
+  selector:
+    matchLabels:
+      app.kubernetes.io/managed-by: gerrit-operator
+      app.kubernetes.io/name: gerrit
+      app.kubernetes.io/part-of: gerrit-indexer
+      app.kubernetes.io/created-by: GerritIndexerReconciler
+      app.kubernetes.io/instance: gerrit-indexer
+      app.kubernetes.io/version: unknown
+      app.kubernetes.io/component: gerrit-indexer-gerrit-indexer
+  template:
+    metadata:
+      annotations:
+        sidecar.istio.io/inject: false
+        cluster-autoscaler.kubernetes.io/safe-to-evict: false
+      labels:
+        app.kubernetes.io/managed-by: gerrit-operator
+        app.kubernetes.io/name: gerrit
+        app.kubernetes.io/part-of: gerrit-indexer
+        app.kubernetes.io/created-by: GerritIndexerReconciler
+        app.kubernetes.io/instance: gerrit-indexer
+        app.kubernetes.io/version: unknown
+        app.kubernetes.io/component: gerrit-indexer-gerrit-indexer
+    spec:
+      securityContext:
+        fsGroup: 100
+        runAsGroup: 100
+        runAsUser: 1000
+        runAsNonRoot: true
+        seccompProfile:
+          type: RuntimeDefault
+      initContainers:
+      - name: gerrit-init
+        securityContext:
+          runAsGroup: 100
+          runAsUser: 1000
+          runAsNonRoot: true
+          readOnlyRootFilesystem: true
+          allowPrivilegeEscalation: false
+          seccompProfile:
+            type: RuntimeDefault
+          capabilities:
+            drop:
+            - ALL
+        image: docker.io/k8sgerrit/gerrit-init:latest
+        imagePullPolicy: Always
+        resources:
+          requests:
+            cpu: 2
+            memory: 5Gi
+          limits:
+            cpu: 3
+            memory: 6Gi
+        volumeMounts:
+        - mountPath: /var/mnt/etc/config
+          name: gerrit-config
+        - mountPath: /var/config/gerrit-init.yaml
+          name: gerrit-init-config
+          subPath: gerrit-init.yaml
+        - mountPath: /var/mnt/data/index-opensearch
+          name: opensearch-secret
+        - mountPath: /var/config/ca.crt
+          name: opensearch-secret
+          subPath: ca.crt
+        - mountPath: /home/gerrit
+          subPath: home
+          name: tmp
+        - mountPath: /tmp
+          subPath: tmp
+          name: tmp
+        - mountPath: /var/gerrit
+          name: gerrit-site
+        - mountPath: /var/mnt/git
+          name: repositories
+          subPath: git
+      containers:
+      - name: gerrit-indexer
+        securityContext:
+          runAsGroup: 100
+          runAsUser: 1000
+          runAsNonRoot: true
+          readOnlyRootFilesystem: true
+          allowPrivilegeEscalation: false
+          seccompProfile:
+            type: RuntimeDefault
+          capabilities:
+            drop:
+            - ALL
+        image: docker.io/k8sgerrit/gerrit-indexer:latest
+        imagePullPolicy: Always
+        resources:
+          requests:
+            cpu: 2
+            memory: 5Gi
+          limits:
+            cpu: 3
+            memory: 6Gi
+        volumeMounts:
+        - mountPath: /home/gerrit
+          subPath: home
+          name: tmp
+        - mountPath: /tmp
+          subPath: tmp
+          name: tmp
+        - mountPath: /var/gerrit
+          name: gerrit-site
+        - mountPath: /var/mnt/git
+          name: repositories
+          subPath: git
+        - mountPath: /var/mnt/etc/config
+          name: gerrit-config
+        - mountPath: /var/mnt/data/index-opensearch
+          name: opensearch-secret
+      restartPolicy: OnFailure
+      volumes:
+      - name: gerrit-site
+        persistentVolumeClaim:
+          claimName: gerrit-site-pvc
+      - configMap:
+          name: gerrit-indexer-configmap
+        name: gerrit-config
+      - configMap:
+          name: gerrit-init-configmap
+        name: gerrit-init-config
+      - name: repositories
+        persistentVolumeClaim:
+          claimName: gerrit-repos-pvc
+      - name: opensearch-secret
+        secret:
+          secretName: opensearch-tls-config
+      - name: tmp
+        emptyDir:
+          sizeLimit: 500Mi
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/gerritcluster_es.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/gerritcluster_es.yaml
index e2c7898..627012e 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/gerritcluster_es.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/gerritcluster_es.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritCluster
 metadata:
   name: gerrit
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/gerritcluster_minimal.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/gerritcluster_minimal.yaml
index 32c253e..3b97a12 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/gerritcluster_minimal.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/gerritcluster_minimal.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritCluster
 metadata:
   name: gerrit
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/indexer.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/indexer.yaml
index 9db2d8a..71e5af6 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/indexer.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/indexer.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritIndexer
 metadata:
   name: gerrit-indexer
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/indexer_es.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/indexer_es.yaml
index fe63d13..01011f5 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/indexer_es.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/indexer_es.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritIndexer
 metadata:
   name: gerrit-indexer
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/indexer_os.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/indexer_os.yaml
new file mode 100644
index 0000000..1c660d7
--- /dev/null
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/indexer/indexer_os.yaml
@@ -0,0 +1,36 @@
+apiVersion: "gerritoperator.google.com/v1beta19"
+kind: GerritIndexer
+metadata:
+  name: gerrit-indexer
+  namespace: gerrit
+spec:
+  cluster: gerrit
+  index:
+    type: OPENSEARCH
+    remoteIndexConfig:
+      server: http://opensearch.example.com:9200
+      config: |-
+        [opensearch]
+          codec = default
+  openSearchSecretRef: opensearch-tls-config
+  resources:
+    requests:
+      cpu: 2
+      memory: 5Gi
+    limits:
+      cpu: 3
+      memory: 6Gi
+  configFiles:
+    gerrit.config: |-
+      [log]
+        textLogging = true
+        jsonLogging = true
+  storage:
+    site:
+      persistentVolumeClaim: gerrit-site-pvc
+    repositories:
+      persistentVolumeClaim: gerrit-repos-pvc
+      subPath: git
+    output:
+      persistentVolumeClaim: indexer-output
+      subPath: indexes/new
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/maintenance/gerrit-maintenance.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/maintenance/gerrit-maintenance.yaml
index 6f78336..4200d7e 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/maintenance/gerrit-maintenance.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/maintenance/gerrit-maintenance.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritMaintenance
 metadata:
   name: gerrit-gerrit-maintenance
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_primary.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_primary.yaml
index 64e59b3..40f509e 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_primary.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_primary.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritNetwork
 metadata:
   name: gerrit
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_primary_replica.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_primary_replica.yaml
index 719d590..2fc50e9 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_primary_replica.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_primary_replica.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritNetwork
 metadata:
   name: gerrit
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_primary_replica_ssh.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_primary_replica_ssh.yaml
index f8885db..584b2cc 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_primary_replica_ssh.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_primary_replica_ssh.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritNetwork
 metadata:
   name: gerrit
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_primary_replica_tls.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_primary_replica_tls.yaml
index 35e1651..bfb28d1 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_primary_replica_tls.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_primary_replica_tls.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritNetwork
 metadata:
   name: gerrit
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_primary_ssh.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_primary_ssh.yaml
index b83b688..e94e05f 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_primary_ssh.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_primary_ssh.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritNetwork
 metadata:
   name: gerrit
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_receiver_replica.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_receiver_replica.yaml
index 747dc16..4addeef 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_receiver_replica.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_receiver_replica.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritNetwork
 metadata:
   name: gerrit
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_receiver_replica_ssh.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_receiver_replica_ssh.yaml
index 1c010ca..fde0b57 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_receiver_replica_ssh.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_receiver_replica_ssh.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritNetwork
 metadata:
   name: gerrit
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_receiver_replica_tls.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_receiver_replica_tls.yaml
index 9efa650..c769cc8 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_receiver_replica_tls.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_receiver_replica_tls.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritNetwork
 metadata:
   name: gerrit
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_replica.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_replica.yaml
index bbb6fd5..42500e9 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_replica.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_replica.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritNetwork
 metadata:
   name: gerrit
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_replica_ssh.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_replica_ssh.yaml
index ae45f88..5ca83ca 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_replica_ssh.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/network/gerritnetwork_replica_ssh.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritNetwork
 metadata:
   name: gerrit
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/receiver/receiver.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/receiver/receiver.yaml
index 429f17c..710d377 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/receiver/receiver.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/receiver/receiver.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: Receiver
 metadata:
   name: receiver
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/receiver/receiver_minimal.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/receiver/receiver_minimal.yaml
index d6cb111..aa21b60 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/receiver/receiver_minimal.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/receiver/receiver_minimal.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: Receiver
 metadata:
   name: receiver
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/tasks/incomingrepl/gerritcluster_incomingrepl.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/tasks/incomingrepl/gerritcluster_incomingrepl.yaml
index aff47e2..40a86c2 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/tasks/incomingrepl/gerritcluster_incomingrepl.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/tasks/incomingrepl/gerritcluster_incomingrepl.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: GerritCluster
 metadata:
   name: gerrit
diff --git a/operator/src/test/resources/com/google/gerrit/k8s/operator/tasks/incomingrepl/incomingrepltask.yaml b/operator/src/test/resources/com/google/gerrit/k8s/operator/tasks/incomingrepl/incomingrepltask.yaml
index 7278ad9..23c74e7 100644
--- a/operator/src/test/resources/com/google/gerrit/k8s/operator/tasks/incomingrepl/incomingrepltask.yaml
+++ b/operator/src/test/resources/com/google/gerrit/k8s/operator/tasks/incomingrepl/incomingrepltask.yaml
@@ -1,4 +1,4 @@
-apiVersion: "gerritoperator.google.com/v1beta18"
+apiVersion: "gerritoperator.google.com/v1beta19"
 kind: IncomingReplicationTask
 metadata:
   name: incoming-replication-test