SOPS: Decrypt Kubernetes secrets generated by kustomize#329
Merged
stefanprodan merged 1 commit intofluxcd:mainfrom Apr 29, 2021
Merged
Conversation
e9b5e08 to
8127709
Compare
1706144 to
a7e7613
Compare
Member
stefanprodan
left a comment
There was a problem hiding this comment.
@bob-rohan can you please add a sub-section here https://github.com/fluxcd/kustomize-controller/blob/main/docs/spec/v1beta1/kustomization.md#secrets-decryption and document the new decryption option. Please mention kustomize secret generator and how to use it.
193e063 to
adb196d
Compare
Member
|
@bob-rohan can you please squash all commits into a single one and rename it to "Decrypt base64 encoded SOPS encrypted secrets". Thanks! |
adb196d to
9ffafd6
Compare
Signed-off-by: Bob Rohan <bob.rohan@hodge.co.uk>
9ffafd6 to
a77ea03
Compare
stefanprodan
approved these changes
Apr 29, 2021
Member
stefanprodan
left a comment
There was a problem hiding this comment.
LGTM
Thanks @bob-rohan 🏅
Contributor
|
Thank you @bob-rohan, this is fantastic work! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Kustomize-controller can currently decrypt SOPS encrypted files - but
whole files only.
Kubernetes Secrets are base64 encoded, therefore when a SOPS encrypted
file, is added as base64 encoded data to a Kubernetes Secret, it is not
decrypted.
Fix: #328