bitnami/sealed-secrets

Tool to help with migration of multiple/all secrets to a new cluster

開放

#365 建立於 2020年2月26日

 (5 則留言) (6 個反應) (0 位負責人)Go (771 個分叉)auto 404
enhancementhelp wanted

倉庫指標

星標
 (9,222 顆星)
PR 合併指標
 (PR 指標待抓取)

描述

Some users need to migrate their workload to another cluster. The set of all the manifests of their workload include all the SealedSecret manifests.

Commonly people simply copy the sealed-secret's controller sealing key(s) into another cluster (e.g. following the backup/restore procedures in our docs) and call it a day.

Copying private keys around is a great way to increase your chances of leaking your private key.

There may be a better way: we could create a tool that performs the same task that kubeseal --re-encrypt but by using an arbitrary public key (the one of the target cluster) and in a way that is amenable to be operated in bulk.

貢獻者指南