27 lines
877 B
Markdown
27 lines
877 B
Markdown
# sealed-secrets
|
|
|
|
GitOps source for the cluster Sealed Secrets controller.
|
|
|
|
## Current deployment
|
|
|
|
- Bootstrap: `enabled: true`, applied from `main`
|
|
- Argo application: `sealed-secrets-production`
|
|
- Target namespace: `kube-system`
|
|
- Helm chart: `bitnami-labs/sealed-secrets`
|
|
- Chart version: `2.18.5`
|
|
- Helm release name: `sealed-secrets-controller`
|
|
|
|
## Runtime
|
|
|
|
Argo CD renders the upstream Helm chart with values from
|
|
`manifest/overlays/production/helm-values/values.yaml`. The controller name is
|
|
kept as `sealed-secrets-controller` so `kubeseal` works with its default
|
|
controller-name assumptions.
|
|
|
|
## Secret migration workflow
|
|
|
|
Fetch the controller cert with `kubeseal --fetch-cert --controller-namespace
|
|
kube-system`, seal app secrets into the owning app repo, then remove old
|
|
SOPS/KSOPS secret generator entries only after the app syncs from the new
|
|
`SealedSecret` path.
|