Repository files navigation

Azure Key Vault Secret Controller

This repository implements a simple Kubernetes custom controller to load secrets from Azure Key Vault and store them as Kubernetes secrets.

The idea is to store all your secrets in Azure Key Vault and then deploy KeyvaultSecret resources into Kubernetes. The secret-controller will listen for those resources and create the corresponding Kubernetes secrets for them. Within your pods you can then use these secrets just like any other secret. Kubernetes will also make sure that the pods will not start before the required secrets are created.

Deleting the KeyvaultSecret will also delete the Kubernetes secret.

Build

Clone the repo into your GOPATH

mkdir -p $GOPATH/src/github.com/twendt
cd $GOPATH/src/github.com/twendt
git clone https://github.com/twendt/secret-controller.git
cd secret-controller

Local

go get
go build

Docker

docker build -t secret-controller .

To speed up the builds there are also the file Dockerfile.dependencies and Dockerfile.build. Run them as follows so that Docker does not have to run go get on every build.

docker build -f Dockerfile.dependencies -t secret-controller-deps .
docker build -f Dockerfile.build -t secret-controller .

Usage

Deploy secret-controller

There is an example Helm chart in the helm directory. At least the following values have to be configured in values.yaml:

  • repoBase This is the Docker registry. There is no pre-built image available in Dockerhub
  • vaultName The name of the Azure Key vault to use

See values.yaml for further parameters.

Run secret-controller locally

The secret-controller can also be run locally for testing purposes.

export KEYVAULT_TENANT_ID=<enter your tenant ID here>
export KEYVAULT_CLIENT_ID=<enter your client ID here>
export KEYVAULT_CLIENT_SECRET=<enter your client secret here>
./secret-controller --vault-name <name of Key Vault> --master <api server address> --kubeconfig <path to kubeconfig>

Deploy secrets

The secret-controller provides a new resource keyvaultsecrets.secretcontroller.twendt.de. This resource can be used as follows:

apiVersion: secretcontroller.twendt.de/v1alpha1
kind: KeyvaultSecret
metadata:
name: any-secret
spec:
items:
- keyvaultName: postgres
kubernetesName: PG_USER
- secretTemplate: 'postgresql://[[ secretValue "PG-USER" ]]:[[ secretValue "PG-PASSWORD" ]]@pghost:5432/dbname'
kubernetesName: PG_DSN

The Kubernetes secret being created will get the same name as the KeyvaultSecret. This creates a 1:1 relationship between the 2. This also makes sure that it is not possible to define 2 KeyvaultSecrets that will create the same Kubernetes secret.

The items in the manifest define the entries within the secret that will be created.

As you can see there are 2 ways to define the items:

keyvaultName and kubernetesName

The kubernetesName defines the key that will be used within the Kubernetes secret.

keyvaultName simply defines the name of the secret in Key Vault and will be used as the value of the secret entry.

secretTemplate and kubernetesName

The kubernetesName defines the key that will be used within the Kubernetes secret.

The secretTemplate provides a very flexible way to define the value of the secret entry. You can use a combination of static text and Go templates. To be able to use this in Helm charts, the secret-controller uses [[ and ]] as template markers. This makes sure that Helm does not evaluate them. This also enables the possibility to use variables that Helm can replace so that you can for instance have Helm evaluate the hostname in the above example by using something like {{ .Values.postgres.hostname }} instead of pghost.

The secret-controller provides 2 template functions to retrieve the secret values from Azure Key Vault:

  • secretValue This retrieves the latest version of the secret from Azure Key Vault
  • secretValueForVersion This retrieves a specific version of the secret from Azure Key Vault. The version has to be passed as second string parameter

About

Azure Key Vault Secrets for Kubernetes

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

Azure Key Vault Secret Controller

This repository implements a simple Kubernetes custom controller to load secrets from Azure Key Vault and store them as Kubernetes secrets.

The idea is to store all your secrets in Azure Key Vault and then deploy KeyvaultSecret resources into Kubernetes. The secret-controller will listen for those resources and create the corresponding Kubernetes secrets for them. Within your pods you can then use these secrets just like any other secret. Kubernetes will also make sure that the pods will not start before the required secrets are created.

Deleting the KeyvaultSecret will also delete the Kubernetes secret.

Build

Clone the repo into your GOPATH

mkdir -p $GOPATH/src/github.com/twendt
cd $GOPATH/src/github.com/twendt
git clone https://github.com/twendt/secret-controller.git
cd secret-controller

Local

go get
go build

Docker

docker build -t secret-controller .

To speed up the builds there are also the file Dockerfile.dependencies and Dockerfile.build. Run them as follows so that Docker does not have to run go get on every build.

docker build -f Dockerfile.dependencies -t secret-controller-deps .
docker build -f Dockerfile.build -t secret-controller .

Usage

Deploy secret-controller

There is an example Helm chart in the helm directory. At least the following values have to be configured in values.yaml:

  • repoBase This is the Docker registry. There is no pre-built image available in Dockerhub
  • vaultName The name of the Azure Key vault to use

See values.yaml for further parameters.

Run secret-controller locally

The secret-controller can also be run locally for testing purposes.

export KEYVAULT_TENANT_ID=<enter your tenant ID here>
export KEYVAULT_CLIENT_ID=<enter your client ID here>
export KEYVAULT_CLIENT_SECRET=<enter your client secret here>
./secret-controller --vault-name <name of Key Vault> --master <api server address> --kubeconfig <path to kubeconfig>

Deploy secrets

The secret-controller provides a new resource keyvaultsecrets.secretcontroller.twendt.de. This resource can be used as follows:

apiVersion: secretcontroller.twendt.de/v1alpha1
kind: KeyvaultSecret
metadata:
name: any-secret
spec:
items:
- keyvaultName: postgres
kubernetesName: PG_USER
- secretTemplate: 'postgresql://[[ secretValue "PG-USER" ]]:[[ secretValue "PG-PASSWORD" ]]@pghost:5432/dbname'
kubernetesName: PG_DSN

The Kubernetes secret being created will get the same name as the KeyvaultSecret. This creates a 1:1 relationship between the 2. This also makes sure that it is not possible to define 2 KeyvaultSecrets that will create the same Kubernetes secret.

The items in the manifest define the entries within the secret that will be created.

As you can see there are 2 ways to define the items:

keyvaultName and kubernetesName

The kubernetesName defines the key that will be used within the Kubernetes secret.

keyvaultName simply defines the name of the secret in Key Vault and will be used as the value of the secret entry.

secretTemplate and kubernetesName

The kubernetesName defines the key that will be used within the Kubernetes secret.

The secretTemplate provides a very flexible way to define the value of the secret entry. You can use a combination of static text and Go templates. To be able to use this in Helm charts, the secret-controller uses [[ and ]] as template markers. This makes sure that Helm does not evaluate them. This also enables the possibility to use variables that Helm can replace so that you can for instance have Helm evaluate the hostname in the above example by using something like {{ .Values.postgres.hostname }} instead of pghost.

The secret-controller provides 2 template functions to retrieve the secret values from Azure Key Vault:

  • secretValue This retrieves the latest version of the secret from Azure Key Vault
  • secretValueForVersion This retrieves a specific version of the secret from Azure Key Vault. The version has to be passed as second string parameter

About

Azure Key Vault Secrets for Kubernetes

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Azure Key Vault Secret Controller

This repository implements a simple Kubernetes custom controller to load secrets from Azure Key Vault and store them as Kubernetes secrets.

The idea is to store all your secrets in Azure Key Vault and then deploy KeyvaultSecret resources into Kubernetes. The secret-controller will listen for those resources and create the corresponding Kubernetes secrets for them. Within your pods you can then use these secrets just like any other secret. Kubernetes will also make sure that the pods will not start before the required secrets are created.

Deleting the KeyvaultSecret will also delete the Kubernetes secret.

Build

Clone the repo into your GOPATH

mkdir -p $GOPATH/src/github.com/twendt
cd $GOPATH/src/github.com/twendt
git clone https://github.com/twendt/secret-controller.git
cd secret-controller

Local

go get
go build

Docker

docker build -t secret-controller .

To speed up the builds there are also the file Dockerfile.dependencies and Dockerfile.build. Run them as follows so that Docker does not have to run go get on every build.

docker build -f Dockerfile.dependencies -t secret-controller-deps .
docker build -f Dockerfile.build -t secret-controller .

Usage

Deploy secret-controller

There is an example Helm chart in the helm directory. At least the following values have to be configured in values.yaml:

  • repoBase This is the Docker registry. There is no pre-built image available in Dockerhub
  • vaultName The name of the Azure Key vault to use

See values.yaml for further parameters.

Run secret-controller locally

The secret-controller can also be run locally for testing purposes.

export KEYVAULT_TENANT_ID=<enter your tenant ID here>
export KEYVAULT_CLIENT_ID=<enter your client ID here>
export KEYVAULT_CLIENT_SECRET=<enter your client secret here>
./secret-controller --vault-name <name of Key Vault> --master <api server address> --kubeconfig <path to kubeconfig>

Deploy secrets

The secret-controller provides a new resource keyvaultsecrets.secretcontroller.twendt.de. This resource can be used as follows:

apiVersion: secretcontroller.twendt.de/v1alpha1
kind: KeyvaultSecret
metadata:
name: any-secret
spec:
items:
- keyvaultName: postgres
kubernetesName: PG_USER
- secretTemplate: 'postgresql://[[ secretValue "PG-USER" ]]:[[ secretValue "PG-PASSWORD" ]]@pghost:5432/dbname'
kubernetesName: PG_DSN

The Kubernetes secret being created will get the same name as the KeyvaultSecret. This creates a 1:1 relationship between the 2. This also makes sure that it is not possible to define 2 KeyvaultSecrets that will create the same Kubernetes secret.

The items in the manifest define the entries within the secret that will be created.

As you can see there are 2 ways to define the items:

keyvaultName and kubernetesName

The kubernetesName defines the key that will be used within the Kubernetes secret.

keyvaultName simply defines the name of the secret in Key Vault and will be used as the value of the secret entry.

secretTemplate and kubernetesName

The kubernetesName defines the key that will be used within the Kubernetes secret.

The secretTemplate provides a very flexible way to define the value of the secret entry. You can use a combination of static text and Go templates. To be able to use this in Helm charts, the secret-controller uses [[ and ]] as template markers. This makes sure that Helm does not evaluate them. This also enables the possibility to use variables that Helm can replace so that you can for instance have Helm evaluate the hostname in the above example by using something like {{ .Values.postgres.hostname }} instead of pghost.

The secret-controller provides 2 template functions to retrieve the secret values from Azure Key Vault:

  • secretValue This retrieves the latest version of the secret from Azure Key Vault
  • secretValueForVersion This retrieves a specific version of the secret from Azure Key Vault. The version has to be passed as second string parameter

About

Azure Key Vault Secrets for Kubernetes

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Azure Key Vault Secret Controller

This repository implements a simple Kubernetes custom controller to load secrets from Azure Key Vault and store them as Kubernetes secrets.

The idea is to store all your secrets in Azure Key Vault and then deploy KeyvaultSecret resources into Kubernetes. The secret-controller will listen for those resources and create the corresponding Kubernetes secrets for them. Within your pods you can then use these secrets just like any other secret. Kubernetes will also make sure that the pods will not start before the required secrets are created.

Deleting the KeyvaultSecret will also delete the Kubernetes secret.

Build

Clone the repo into your GOPATH

mkdir -p $GOPATH/src/github.com/twendt
cd $GOPATH/src/github.com/twendt
git clone https://github.com/twendt/secret-controller.git
cd secret-controller

Local

go get
go build

Docker

docker build -t secret-controller .

To speed up the builds there are also the file Dockerfile.dependencies and Dockerfile.build. Run them as follows so that Docker does not have to run go get on every build.

docker build -f Dockerfile.dependencies -t secret-controller-deps .
docker build -f Dockerfile.build -t secret-controller .

Usage

Deploy secret-controller

There is an example Helm chart in the helm directory. At least the following values have to be configured in values.yaml:

  • repoBase This is the Docker registry. There is no pre-built image available in Dockerhub
  • vaultName The name of the Azure Key vault to use

See values.yaml for further parameters.

Run secret-controller locally

The secret-controller can also be run locally for testing purposes.

export KEYVAULT_TENANT_ID=<enter your tenant ID here>
export KEYVAULT_CLIENT_ID=<enter your client ID here>
export KEYVAULT_CLIENT_SECRET=<enter your client secret here>
./secret-controller --vault-name <name of Key Vault> --master <api server address> --kubeconfig <path to kubeconfig>

Deploy secrets

The secret-controller provides a new resource keyvaultsecrets.secretcontroller.twendt.de. This resource can be used as follows:

apiVersion: secretcontroller.twendt.de/v1alpha1
kind: KeyvaultSecret
metadata:
name: any-secret
spec:
items:
- keyvaultName: postgres
kubernetesName: PG_USER
- secretTemplate: 'postgresql://[[ secretValue "PG-USER" ]]:[[ secretValue "PG-PASSWORD" ]]@pghost:5432/dbname'
kubernetesName: PG_DSN

The Kubernetes secret being created will get the same name as the KeyvaultSecret. This creates a 1:1 relationship between the 2. This also makes sure that it is not possible to define 2 KeyvaultSecrets that will create the same Kubernetes secret.

The items in the manifest define the entries within the secret that will be created.

As you can see there are 2 ways to define the items:

keyvaultName and kubernetesName

The kubernetesName defines the key that will be used within the Kubernetes secret.

keyvaultName simply defines the name of the secret in Key Vault and will be used as the value of the secret entry.

secretTemplate and kubernetesName

The kubernetesName defines the key that will be used within the Kubernetes secret.

The secretTemplate provides a very flexible way to define the value of the secret entry. You can use a combination of static text and Go templates. To be able to use this in Helm charts, the secret-controller uses [[ and ]] as template markers. This makes sure that Helm does not evaluate them. This also enables the possibility to use variables that Helm can replace so that you can for instance have Helm evaluate the hostname in the above example by using something like {{ .Values.postgres.hostname }} instead of pghost.

The secret-controller provides 2 template functions to retrieve the secret values from Azure Key Vault:

  • secretValue This retrieves the latest version of the secret from Azure Key Vault
  • secretValueForVersion This retrieves a specific version of the secret from Azure Key Vault. The version has to be passed as second string parameter

About

Azure Key Vault Secrets for Kubernetes

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

Azure Key Vault Secret Controller

This repository implements a simple Kubernetes custom controller to load secrets from Azure Key Vault and store them as Kubernetes secrets.

The idea is to store all your secrets in Azure Key Vault and then deploy KeyvaultSecret resources into Kubernetes. The secret-controller will listen for those resources and create the corresponding Kubernetes secrets for them. Within your pods you can then use these secrets just like any other secret. Kubernetes will also make sure that the pods will not start before the required secrets are created.

Deleting the KeyvaultSecret will also delete the Kubernetes secret.

Build

Clone the repo into your GOPATH

mkdir -p $GOPATH/src/github.com/twendt
cd $GOPATH/src/github.com/twendt
git clone https://github.com/twendt/secret-controller.git
cd secret-controller

Local

go get
go build

Docker

docker build -t secret-controller .

To speed up the builds there are also the file Dockerfile.dependencies and Dockerfile.build. Run them as follows so that Docker does not have to run go get on every build.

docker build -f Dockerfile.dependencies -t secret-controller-deps .
docker build -f Dockerfile.build -t secret-controller .

Usage

Deploy secret-controller

There is an example Helm chart in the helm directory. At least the following values have to be configured in values.yaml:

  • repoBase This is the Docker registry. There is no pre-built image available in Dockerhub
  • vaultName The name of the Azure Key vault to use

See values.yaml for further parameters.

Run secret-controller locally

The secret-controller can also be run locally for testing purposes.

export KEYVAULT_TENANT_ID=<enter your tenant ID here>
export KEYVAULT_CLIENT_ID=<enter your client ID here>
export KEYVAULT_CLIENT_SECRET=<enter your client secret here>
./secret-controller --vault-name <name of Key Vault> --master <api server address> --kubeconfig <path to kubeconfig>

Deploy secrets

The secret-controller provides a new resource keyvaultsecrets.secretcontroller.twendt.de. This resource can be used as follows:

apiVersion: secretcontroller.twendt.de/v1alpha1
kind: KeyvaultSecret
metadata:
name: any-secret
spec:
items:
- keyvaultName: postgres
kubernetesName: PG_USER
- secretTemplate: 'postgresql://[[ secretValue "PG-USER" ]]:[[ secretValue "PG-PASSWORD" ]]@pghost:5432/dbname'
kubernetesName: PG_DSN

The Kubernetes secret being created will get the same name as the KeyvaultSecret. This creates a 1:1 relationship between the 2. This also makes sure that it is not possible to define 2 KeyvaultSecrets that will create the same Kubernetes secret.

The items in the manifest define the entries within the secret that will be created.

As you can see there are 2 ways to define the items:

keyvaultName and kubernetesName

The kubernetesName defines the key that will be used within the Kubernetes secret.

keyvaultName simply defines the name of the secret in Key Vault and will be used as the value of the secret entry.

secretTemplate and kubernetesName

The kubernetesName defines the key that will be used within the Kubernetes secret.

The secretTemplate provides a very flexible way to define the value of the secret entry. You can use a combination of static text and Go templates. To be able to use this in Helm charts, the secret-controller uses [[ and ]] as template markers. This makes sure that Helm does not evaluate them. This also enables the possibility to use variables that Helm can replace so that you can for instance have Helm evaluate the hostname in the above example by using something like {{ .Values.postgres.hostname }} instead of pghost.

The secret-controller provides 2 template functions to retrieve the secret values from Azure Key Vault:

  • secretValue This retrieves the latest version of the secret from Azure Key Vault
  • secretValueForVersion This retrieves a specific version of the secret from Azure Key Vault. The version has to be passed as second string parameter

About

Azure Key Vault Secrets for Kubernetes

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Azure Key Vault Secret Controller

This repository implements a simple Kubernetes custom controller to load secrets from Azure Key Vault and store them as Kubernetes secrets.

The idea is to store all your secrets in Azure Key Vault and then deploy KeyvaultSecret resources into Kubernetes. The secret-controller will listen for those resources and create the corresponding Kubernetes secrets for them. Within your pods you can then use these secrets just like any other secret. Kubernetes will also make sure that the pods will not start before the required secrets are created.

Deleting the KeyvaultSecret will also delete the Kubernetes secret.

Build

Clone the repo into your GOPATH

mkdir -p $GOPATH/src/github.com/twendt
cd $GOPATH/src/github.com/twendt
git clone https://github.com/twendt/secret-controller.git
cd secret-controller

Local

go get
go build

Docker

docker build -t secret-controller .

To speed up the builds there are also the file Dockerfile.dependencies and Dockerfile.build. Run them as follows so that Docker does not have to run go get on every build.

docker build -f Dockerfile.dependencies -t secret-controller-deps .
docker build -f Dockerfile.build -t secret-controller .

Usage

Deploy secret-controller

There is an example Helm chart in the helm directory. At least the following values have to be configured in values.yaml:

  • repoBase This is the Docker registry. There is no pre-built image available in Dockerhub
  • vaultName The name of the Azure Key vault to use

See values.yaml for further parameters.

Run secret-controller locally

The secret-controller can also be run locally for testing purposes.

export KEYVAULT_TENANT_ID=<enter your tenant ID here>
export KEYVAULT_CLIENT_ID=<enter your client ID here>
export KEYVAULT_CLIENT_SECRET=<enter your client secret here>
./secret-controller --vault-name <name of Key Vault> --master <api server address> --kubeconfig <path to kubeconfig>

Deploy secrets

The secret-controller provides a new resource keyvaultsecrets.secretcontroller.twendt.de. This resource can be used as follows:

apiVersion: secretcontroller.twendt.de/v1alpha1
kind: KeyvaultSecret
metadata:
name: any-secret
spec:
items:
- keyvaultName: postgres
kubernetesName: PG_USER
- secretTemplate: 'postgresql://[[ secretValue "PG-USER" ]]:[[ secretValue "PG-PASSWORD" ]]@pghost:5432/dbname'
kubernetesName: PG_DSN

The Kubernetes secret being created will get the same name as the KeyvaultSecret. This creates a 1:1 relationship between the 2. This also makes sure that it is not possible to define 2 KeyvaultSecrets that will create the same Kubernetes secret.

The items in the manifest define the entries within the secret that will be created.

As you can see there are 2 ways to define the items:

keyvaultName and kubernetesName

The kubernetesName defines the key that will be used within the Kubernetes secret.

keyvaultName simply defines the name of the secret in Key Vault and will be used as the value of the secret entry.

secretTemplate and kubernetesName

The kubernetesName defines the key that will be used within the Kubernetes secret.

The secretTemplate provides a very flexible way to define the value of the secret entry. You can use a combination of static text and Go templates. To be able to use this in Helm charts, the secret-controller uses [[ and ]] as template markers. This makes sure that Helm does not evaluate them. This also enables the possibility to use variables that Helm can replace so that you can for instance have Helm evaluate the hostname in the above example by using something like {{ .Values.postgres.hostname }} instead of pghost.

The secret-controller provides 2 template functions to retrieve the secret values from Azure Key Vault:

  • secretValue This retrieves the latest version of the secret from Azure Key Vault
  • secretValueForVersion This retrieves a specific version of the secret from Azure Key Vault. The version has to be passed as second string parameter

About

Azure Key Vault Secrets for Kubernetes

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Azure Key Vault Secret Controller

This repository implements a simple Kubernetes custom controller to load secrets from Azure Key Vault and store them as Kubernetes secrets.

The idea is to store all your secrets in Azure Key Vault and then deploy KeyvaultSecret resources into Kubernetes. The secret-controller will listen for those resources and create the corresponding Kubernetes secrets for them. Within your pods you can then use these secrets just like any other secret. Kubernetes will also make sure that the pods will not start before the required secrets are created.

Deleting the KeyvaultSecret will also delete the Kubernetes secret.

Build

Clone the repo into your GOPATH

mkdir -p $GOPATH/src/github.com/twendt
cd $GOPATH/src/github.com/twendt
git clone https://github.com/twendt/secret-controller.git
cd secret-controller

Local

go get
go build

Docker

docker build -t secret-controller .

To speed up the builds there are also the file Dockerfile.dependencies and Dockerfile.build. Run them as follows so that Docker does not have to run go get on every build.

docker build -f Dockerfile.dependencies -t secret-controller-deps .
docker build -f Dockerfile.build -t secret-controller .

Usage

Deploy secret-controller

There is an example Helm chart in the helm directory. At least the following values have to be configured in values.yaml:

  • repoBase This is the Docker registry. There is no pre-built image available in Dockerhub
  • vaultName The name of the Azure Key vault to use

See values.yaml for further parameters.

Run secret-controller locally

The secret-controller can also be run locally for testing purposes.

export KEYVAULT_TENANT_ID=<enter your tenant ID here>
export KEYVAULT_CLIENT_ID=<enter your client ID here>
export KEYVAULT_CLIENT_SECRET=<enter your client secret here>
./secret-controller --vault-name <name of Key Vault> --master <api server address> --kubeconfig <path to kubeconfig>

Deploy secrets

The secret-controller provides a new resource keyvaultsecrets.secretcontroller.twendt.de. This resource can be used as follows:

apiVersion: secretcontroller.twendt.de/v1alpha1
kind: KeyvaultSecret
metadata:
name: any-secret
spec:
items:
- keyvaultName: postgres
kubernetesName: PG_USER
- secretTemplate: 'postgresql://[[ secretValue "PG-USER" ]]:[[ secretValue "PG-PASSWORD" ]]@pghost:5432/dbname'
kubernetesName: PG_DSN

The Kubernetes secret being created will get the same name as the KeyvaultSecret. This creates a 1:1 relationship between the 2. This also makes sure that it is not possible to define 2 KeyvaultSecrets that will create the same Kubernetes secret.

The items in the manifest define the entries within the secret that will be created.

As you can see there are 2 ways to define the items:

keyvaultName and kubernetesName

The kubernetesName defines the key that will be used within the Kubernetes secret.

keyvaultName simply defines the name of the secret in Key Vault and will be used as the value of the secret entry.

secretTemplate and kubernetesName

The kubernetesName defines the key that will be used within the Kubernetes secret.

The secretTemplate provides a very flexible way to define the value of the secret entry. You can use a combination of static text and Go templates. To be able to use this in Helm charts, the secret-controller uses [[ and ]] as template markers. This makes sure that Helm does not evaluate them. This also enables the possibility to use variables that Helm can replace so that you can for instance have Helm evaluate the hostname in the above example by using something like {{ .Values.postgres.hostname }} instead of pghost.

The secret-controller provides 2 template functions to retrieve the secret values from Azure Key Vault:

  • secretValue This retrieves the latest version of the secret from Azure Key Vault
  • secretValueForVersion This retrieves a specific version of the secret from Azure Key Vault. The version has to be passed as second string parameter

About

Azure Key Vault Secrets for Kubernetes

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

Azure Key Vault Secret Controller

This repository implements a simple Kubernetes custom controller to load secrets from Azure Key Vault and store them as Kubernetes secrets.

The idea is to store all your secrets in Azure Key Vault and then deploy KeyvaultSecret resources into Kubernetes. The secret-controller will listen for those resources and create the corresponding Kubernetes secrets for them. Within your pods you can then use these secrets just like any other secret. Kubernetes will also make sure that the pods will not start before the required secrets are created.

Deleting the KeyvaultSecret will also delete the Kubernetes secret.

Build

Clone the repo into your GOPATH

mkdir -p $GOPATH/src/github.com/twendt
cd $GOPATH/src/github.com/twendt
git clone https://github.com/twendt/secret-controller.git
cd secret-controller

Local

go get
go build

Docker

docker build -t secret-controller .

To speed up the builds there are also the file Dockerfile.dependencies and Dockerfile.build. Run them as follows so that Docker does not have to run go get on every build.

docker build -f Dockerfile.dependencies -t secret-controller-deps .
docker build -f Dockerfile.build -t secret-controller .

Usage

Deploy secret-controller

There is an example Helm chart in the helm directory. At least the following values have to be configured in values.yaml:

  • repoBase This is the Docker registry. There is no pre-built image available in Dockerhub
  • vaultName The name of the Azure Key vault to use

See values.yaml for further parameters.

Run secret-controller locally

The secret-controller can also be run locally for testing purposes.

export KEYVAULT_TENANT_ID=<enter your tenant ID here>
export KEYVAULT_CLIENT_ID=<enter your client ID here>
export KEYVAULT_CLIENT_SECRET=<enter your client secret here>
./secret-controller --vault-name <name of Key Vault> --master <api server address> --kubeconfig <path to kubeconfig>

Deploy secrets

The secret-controller provides a new resource keyvaultsecrets.secretcontroller.twendt.de. This resource can be used as follows:

apiVersion: secretcontroller.twendt.de/v1alpha1
kind: KeyvaultSecret
metadata:
name: any-secret
spec:
items:
- keyvaultName: postgres
kubernetesName: PG_USER
- secretTemplate: 'postgresql://[[ secretValue "PG-USER" ]]:[[ secretValue "PG-PASSWORD" ]]@pghost:5432/dbname'
kubernetesName: PG_DSN

The Kubernetes secret being created will get the same name as the KeyvaultSecret. This creates a 1:1 relationship between the 2. This also makes sure that it is not possible to define 2 KeyvaultSecrets that will create the same Kubernetes secret.

The items in the manifest define the entries within the secret that will be created.

As you can see there are 2 ways to define the items:

keyvaultName and kubernetesName

The kubernetesName defines the key that will be used within the Kubernetes secret.

keyvaultName simply defines the name of the secret in Key Vault and will be used as the value of the secret entry.

secretTemplate and kubernetesName

The kubernetesName defines the key that will be used within the Kubernetes secret.

The secretTemplate provides a very flexible way to define the value of the secret entry. You can use a combination of static text and Go templates. To be able to use this in Helm charts, the secret-controller uses [[ and ]] as template markers. This makes sure that Helm does not evaluate them. This also enables the possibility to use variables that Helm can replace so that you can for instance have Helm evaluate the hostname in the above example by using something like {{ .Values.postgres.hostname }} instead of pghost.

The secret-controller provides 2 template functions to retrieve the secret values from Azure Key Vault:

  • secretValue This retrieves the latest version of the secret from Azure Key Vault
  • secretValueForVersion This retrieves a specific version of the secret from Azure Key Vault. The version has to be passed as second string parameter

About

Azure Key Vault Secrets for Kubernetes

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages