Sealed Secrets

Sealed Secrets and Encrypting Secrets for Git

Sealed Secrets 9,292 (github.com/bitnami/sealed-secrets (https://github.com/bitnami/sealed-secrets 9,292 ), Apache-2.0, v0.40.0) runs a controller holding a private key; the kubeseal CLI encrypts a Secret with the public key into a SealedSecret only that controller can open. Seal a credential for BookNest's backups (Database Backups):

Installing Sealed Secrets and sealing a Secret for GitYAML
R=https://github.com/bitnami/sealed-secrets/releases/download/v0.40.0
kubectl apply -f $R/controller.yaml >/dev/null
curl -sL $R/kubeseal-0.40.0-linux-amd64.tar.gz | sudo tar -xz -C /usr/local/bin kubeseal
kubectl -n kube-system rollout status deployment/sealed-secrets-controller >/dev/null
kubectl create secret generic backup-credentials --dry-run=client -o yaml \
  --from-literal=access-key=booknest-backup \
  --from-literal=secret-key="$(openssl rand -hex 20)" \
  | kubeseal -o yaml > k8s/backup-credentials.sealed.yaml
yq '.spec.encryptedData."access-key" | .[0:60]' k8s/backup-credentials.sealed.yaml
kubectl apply -f k8s/backup-credentials.sealed.yaml
until kubectl get secret backup-credentials >/dev/null 2>&1; do sleep 2; done
kubectl get secret backup-credentials -o jsonpath='{.data.access-key}' | base64 -d; echo
git add k8s/backup-credentials.sealed.yaml && git commit -qm "Add sealed backup credentials"
Output
AgCFyTPeYfXoAUyc8ZFt/Ggy4Ly23gmxHMwwzc77ElbUe5lGud0A3ad60dXG
sealedsecret.bitnami.com/backup-credentials created
booknest-backup

The file is safe in Git 1,932 : each value is encrypted with a random key that RSA seals, and by default (strict scope) the name and namespace are bound in, so it cannot be renamed elsewhere to reveal it. The weak point is the controller's key, renewed every 30 days: a new cluster cannot open old files, so back up the kube-system Secrets labeled sealedsecrets.bitnami.com/sealed-secrets-key. SOPS 23,231 (github.com/getsops/sops (https://github.com/getsops/sops 23,231 )) is the alternative, encrypting YAML values with age, PGP or a cloud KMS.