{"repo":"ricoberger/vault-secrets-operator","free":true,"listed":false,"github":"https://github.com/ricoberger/vault-secrets-operator","clone":"git clone https://github.com/ricoberger/vault-secrets-operator.git","description":"Create Kubernetes secrets from Vault for a secure GitOps based workflow.","language":"Go","stars":685,"topics":["kubernetes","vault","secret","secrets","crd","operator-sdk","helm-chart","kubernetes-secrets","gitops"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"Create Kubernetes secrets from Vault for a secure GitOps based workflow. The Vault Secrets Operator creates Kubernetes secrets from Vault. The idea behind the Vault Secrets Operator is to manage secrets in Kubernetes cluster using a secure GitOps based workflow. With the help of the Vault Secrets Operator you can commit your secrets to your git repository using a custom resource. If you apply these secrets to your Kubernetes cluster the Operator will lookup the real secret in Vault and creates the corresponding Kubernetes secret. If you are using something like Sealed Secrets for this workflow the Vault Secrets Operator can be used as replacement for this. Installation The Vault Secrets Operator can be installed via Helm. A list of all configurable values can be found here. The chart assumes a vault server running at http://vault:8200 , but can be overidden by specifying --set vault.address=https://vault.example.com Prepare Vault The Vault Secrets Operator supports the KV Secrets Engine - Version 1 and KV Secrets Engine - Version 2 . To create a new secret engine under a path named kvv1 and kvv2 , you can run the following command: After you have enabled the secret engine, create a new policy for the Vault Secrets Operator. The operator only needs read access to the paths you want to use for your secrets. To create a new policy with the name vault-secrets-operator and read access to the kvv1 and kvv2 path, you can run the following command: To access Vault, the operator can c","default_branch":null,"files":null,"tree":[],"storefront":"/r/ricoberger","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ricoberger/vault-secrets-operator/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}