SAML with GKE+Helm installation?

I have installed the EE under GKE using the gitlab/gitlab Chart. After installation, I am trying to turn on saml authentication thus:

helm upgrade gitlab-febe293c gitlab/gitlab -f overrides.yml

where overrides.yml contains:

global:
  omniauth:
    enabled: true
    allow_single_sign_on: [ "saml" ]
    auto_link_saml_user: false
    block_auto_created_users: true
    providers:
      - secret: gitlab-okta
        key: provider

I have tried various ways of entering the provider data in the pod secret, and failed. Does anyone have a working example?