{"repo":"amirhosssein0/vault-cicd-lab","free":true,"listed":false,"github":"https://github.com/amirhosssein0/vault-cicd-lab","clone":"git clone https://github.com/amirhosssein0/vault-cicd-lab.git","description":"HashiCorp Vault + GitHub Actions — secrets management and CI/CD integration on Kubernetes","language":"Go","stars":26,"topics":["argocd","cicd","github-actions","gitops","go","vault","devops","kubernetes","kubernetes-security","security"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"&nbsp;&nbsp;&nbsp; vault-cicd-lab HashiCorp Vault + GitHub Actions — Secrets Management on Kubernetes --- What is this? A production-pattern secrets management lab demonstrating how to eliminate hardcoded secrets from code, ConfigMaps, and git entirely. Secrets live in HashiCorp Vault . Pods receive them via Vault Agent Injector at runtime — no secret ever touches the codebase or the cluster manifests. --- How it works No secret is ever stored in git, environment variables, or ConfigMaps. --- Architecture --- Stack Tool Role --- --- HashiCorp Vault Secrets storage and management Vault Agent Injector Sidecar that injects secrets into pods at runtime Kubernetes Auth Method Pods authenticate to Vault via ServiceAccount Go + Gin API with /health , /ready , /version , /secret Helm v3 Kubernetes packaging with Vault annotations ArgoCD GitOps — auto-sync on values.yaml change GitHub Actions CI: test → build → push / CD: update values Docker Hub Container registry k3s Local Kubernetes cluster --- Screenshots Vault Dashboard Secret stored in Vault CI Pipeline — Go Test + Build & Push Deploy Pipeline — Helm Values Updated Both Workflows Green /secret endpoint — Secret injected successfully --- How to Run Prerequisites - k3s or any Kubernetes cluster - Helm v3 - kubectl - ArgoCD - Docker Hub account 1. Install Vault 2. Configure Vault 3. Create Kubernetes secrets 4. Create ServiceAccounts 5. Bootstrap with App of Apps 6. Add local DNS 7. Test --- Vault Setup Scripts File Purpose --- ---","default_branch":null,"files":null,"tree":[],"storefront":"/r/amirhosssein0","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/amirhosssein0/vault-cicd-lab/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}