bitnami/sealed-secrets

Add namespace selector as scope

開放

#479 建立於 2020年11月27日

 (7 則留言) (14 個反應) (0 位負責人)Go (771 個分叉)auto 404
backlogenhancementgood first issue

倉庫指標

星標
 (9,222 顆星)
PR 合併指標
 (PR 指標待抓取)

描述

Currently there're are 3 scopes how a Sealed Secret can be encrypted:

  • strict
  • namespace
  • cluster-wide

We're maintaining a multi-tenant cluster and users are asking how they can reuse an existing Sealed Secret for a different namespace without encrypting again or make them cluster-wide.

A possible approach would be to support encryption of Sealed Secrets using a namespace selector as each tenant has its own set of labels on their namespaces.

Something like:

kubeseal --scope namespace-selector --selector owner=team1 -oyaml < secret.yaml > sealedsecret.yaml

The Sealed Secrets controller would only decrypt the Sealed Secret if the corresponding namespace has the label owner set to team1.

What are your thoughts about adding namespace selector as scope? Is this a feature which we might add?

貢獻者指南