bitnami/sealed-secrets
Tool to help with migration of multiple/all secrets to a new cluster
开放
#365 创建于 2020年2月26日
enhancementhelp wanted
仓库指标
- 星标
- (9,222 个星标)
- PR 合并指标
- (PR 指标待抓取)
描述
Some users need to migrate their workload to another cluster. The set of all the manifests of their workload include all the SealedSecret manifests.
Commonly people simply copy the sealed-secret's controller sealing key(s) into another cluster (e.g. following the backup/restore procedures in our docs) and call it a day.
Copying private keys around is a great way to increase your chances of leaking your private key.
There may be a better way: we could create a tool that performs the same task that kubeseal --re-encrypt but by using an arbitrary public key (the one of the target cluster) and in a way that is amenable to be operated in bulk.