{"repo":"contentful-labs/kube-secret-syncer","free":true,"listed":false,"github":"https://github.com/contentful-labs/kube-secret-syncer","clone":"git clone https://github.com/contentful-labs/kube-secret-syncer.git","description":"A Kubernetes operator to sync secrets from AWS Secrets Manager","language":"Go","stars":194,"topics":["kubernetes","aws","secrets-manager","secrets","operator","kubebuilder"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"Kube-secret-syncer Kube-secret-syncer is a Kubernetes operator developed using the Kubebuilder framework that keeps the values of Kubernetes Secrets synchronised to secrets in AWS Secrets Manager. This mapping is described in a Kubernetes custom resource called SyncedSecret. The operator polls AWS for changes in secret values at regular intervals, and upon detecting changes, updates the Kubernetes Secrets. WARNING : updating the value of a secret in AWS SecretsManager will override secrets in Kubernetes, therefore can be a destructive action. Comparison to existing projects Kube-secret-syncer is similar to other projects such as: Kubernetes external secrets AWS secret operator Kube-secret-syncer improves on this approach: uses caching to only retrieve the value of secrets when they have changed, substantially reducing costs when syncing a large number of secrets. enables sophisticated access control to secrets in AWS SecretsManager using IAM roles - see our security model supports templated fields for Kubernetes secrets - enabling the use of values from multiple AWS SecretsManager secrets in one Kubernetes Secret Defining mapping between an AWS SecretsManager secret and a Kubernetes Secret The following resource will map the AWS Secret secretsyncer/secret/sample to the Kubernetes Secret demo-service-secret , and copy all key-value pairs from the AWS SecretsManager secret to the Kubernetes secret For this example, the AWS SecretsManager secret needs to be a valid JSON consisti","default_branch":null,"files":null,"tree":[],"storefront":"/r/contentful-labs","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/contentful-labs/kube-secret-syncer/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}