OnCallReady

Commands

kubeseal - encrypt a Kubernetes Secret into a SealedSecret only the cluster's controller can decrypt

kubectl create secret ... --dry-run=client -o yaml | kubeseal [--format yaml] [--scope strict|namespace-wide|cluster-wide] [--cert pub.pem]

Options you will use

--format yaml|json
Output format of the SealedSecret.
--scope strict|namespace-wide|cluster-wide
strict (default): bound to namespace AND name; namespace-wide: any name in that namespace; cluster-wide: anywhere.
--fetch-cert
Print the controller's public certificate (seal offline with --cert).
--raw --namespace NS --name N [--from-file=F]
Encrypt a single value (for editing an existing SealedSecret).
-w FILE
Write the SealedSecret to FILE.

Examples

$ kubectl create secret generic db -n pay-dev --from-literal=PASSWORD="$(cat pw)" --dry-run=client -o yaml | kubeseal --format yaml > db-sealed.yaml

The plaintext never reaches the API server or git.

Gotchas

Try kubeseal in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.