kubeseal: apply --namespace when unsealing secrets without one - #2017
Open
david0 wants to merge 1 commit into
Open
kubeseal: apply --namespace when unsealing secrets without one#2017david0 wants to merge 1 commit into
david0 wants to merge 1 commit into
Conversation
With --recovery-unseal, a sealed secret file that doesn't declare a namespace can now be decrypted by supplying --namespace. The flag value is used to rebuild the encryption label, so users no longer have to edit the file to add a namespace before recovering it. This is helpful because the output of `helm template` does not include a namespace by default, so being able to pass --namespace avoids having to edit the rendered manifests before recovery. Signed-off-by: David Otto <ottodavid@gmx.net>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description of the change
With --recovery-unseal, a sealed secret file that doesn't declare a namespace can now be decrypted by supplying --namespace. The flag value is used to rebuild the encryption label, so users no longer have to edit the file to add a namespace before recovering it.
Benefits
This is helpful because the output of
helm templatedoes not include a namespace by default, so being able to pass --namespace avoids having to edit the rendered manifests before recovery.Possible drawbacks
It could be that the user specifies a wrong namespace or forgets to use this parameter altogether, but thats not worse than before.
Applicable issues
Additional information