Added small shell tool for fetching certs of SealedSecrets for backup purpose (#7)

Co-authored-by: Marcel Straub <m@straubs.eu>
Reviewed-on: #7
This commit was merged in pull request #7.
This commit is contained in:
2025-09-07 15:49:23 +02:00
parent 456692fae3
commit 0bf1a4b536
2 changed files with 12 additions and 0 deletions

3
02-k8s/.gitignore vendored Normal file
View File

@@ -0,0 +1,3 @@
# Kube Seal backup
kubeseal.cert
kubeseal.key

9
02-k8s/fetch_kubeseal_certs.sh Executable file
View File

@@ -0,0 +1,9 @@
#!/usr/bin/bash
rm kubeseal.cert kubeseal.key 2> /dev/null
# public cert
(umask 0077 && kubeseal --controller-namespace=sealed-secrets --fetch-cert > kubeseal.cert)
# full cert backup
(umask 0077 && kubectl get secret -n sealed-secrets -l sealedsecrets.bitnami.com/sealed-secrets-key -o yaml > kubeseal.key)