Sealed Secrets 9,292 (github.com/bitnami/sealed-secrets (https://github.com/bitnami/sealed-secrets 9,292 ), Apache-2.0, v0.40.0) runs a controller holding a private key; the kubeseal CLI encrypts a Secret with the public key into a SealedSecret only that controller can open. Seal a credential for BookNest's backups (Database Backups):
R=https://github.com/bitnami/sealed-secrets/releases/download/v0.40.0
kubectl apply -f $R/controller.yaml >/dev/null
curl -sL $R/kubeseal-0.40.0-linux-amd64.tar.gz | sudo tar -xz -C /usr/local/bin kubeseal
kubectl -n kube-system rollout status deployment/sealed-secrets-controller >/dev/null
kubectl create secret generic backup-credentials --dry-run=client -o yaml \
--from-literal=access-key=booknest-backup \
--from-literal=secret-key="$(openssl rand -hex 20)" \
| kubeseal -o yaml > k8s/backup-credentials.sealed.yaml
yq '.spec.encryptedData."access-key" | .[0:60]' k8s/backup-credentials.sealed.yaml
kubectl apply -f k8s/backup-credentials.sealed.yaml
until kubectl get secret backup-credentials >/dev/null 2>&1; do sleep 2; done
kubectl get secret backup-credentials -o jsonpath='{.data.access-key}' | base64 -d; echo
git add k8s/backup-credentials.sealed.yaml && git commit -qm "Add sealed backup credentials"AgCFyTPeYfXoAUyc8ZFt/Ggy4Ly23gmxHMwwzc77ElbUe5lGud0A3ad60dXG sealedsecret.bitnami.com/backup-credentials created booknest-backup
The file is safe in Git 1,932 : each value is encrypted with a random key that RSA seals, and by default (strict scope) the name and namespace are bound in, so it cannot be renamed elsewhere to reveal it. The weak point is the controller's key, renewed every 30 days: a new cluster cannot open old files, so back up the kube-system Secrets labeled sealedsecrets.bitnami.com/sealed-secrets-key. SOPS 23,231 (github.com/getsops/sops (https://github.com/getsops/sops 23,231 )) is the alternative, encrypting YAML values with age, PGP or a cloud KMS.