kubeseal - encrypt a Kubernetes Secret into a SealedSecret only the cluster's controller can decrypt
kubectl create secret ... --dry-run=client -o yaml | kubeseal [--format yaml] [--scope strict|namespace-wide|cluster-wide] [--cert pub.pem]
Options you will use
--format yaml|json- Output format of the SealedSecret.
--scope strict|namespace-wide|cluster-wide- strict (default): bound to namespace AND name; namespace-wide: any name in that namespace; cluster-wide: anywhere.
--fetch-cert- Print the controller's public certificate (seal offline with --cert).
--raw --namespace NS --name N [--from-file=F]- Encrypt a single value (for editing an existing SealedSecret).
-w FILE- Write the SealedSecret to FILE.
Examples
$ kubectl create secret generic db -n pay-dev --from-literal=PASSWORD="$(cat pw)" --dry-run=client -o yaml | kubeseal --format yaml > db-sealed.yamlThe plaintext never reaches the API server or git.
Gotchas
- A strict SealedSecret moved to another namespace or renamed does not open: "no key could decrypt secret". Re-seal for the target.
- Back up the controller's keys (secrets labelled sealedsecrets.bitnami.com/sealed-secrets-key in kube-system).
Try kubeseal in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.