Skip to main content

No project description provided

Project description

Cloud secret manager

This is a python package to handle secrets in cloud environments, handling GCP and AWS secrets.

It also helps to create a manifest to generate fake secrets for development while using external-secrets.io.

Setup

Initialize secrets manager:

./init_secret_manager.sh

Run secret manager:

# Either activate with poetry shell and run it
poetry -C . shell
es-cloud-secret-manager --help
# deactive when done
deactivate

# Either run it through poetry
poetry -C . run es-cloud-secret-manager --help

Format the code:

# Format the code with isort and autopep8
./format.sh

Yaml format

For secret with yaml format, if you want it to have a better formatting, better install yq and sponge.

# eg. for Ubuntu
sudo apt install yq moreutils

GCP

# First authenticate to your GCP project
gcloud auth application-default login --project <project id>

es-cloud-secret-manager --project project gcp --gcp-project <project id> list --secret cluster external
es-cloud-secret-manager --project project gcp --gcp-project <project id> create --secret cluster external
es-cloud-secret-manager --project project gcp --gcp-project <project id> initialize --secret cluster external
es-cloud-secret-manager --project project gcp --gcp-project <project id> details --secret cluster external
es-cloud-secret-manager --project project gcp --gcp-project <project id> import --secret cluster external
es-cloud-secret-manager --project project gcp --gcp-project <project id> export --secret cluster external
es-cloud-secret-manager --project project gcp --gcp-project <project id> diff --secret cluster external
es-cloud-secret-manager --project project gcp --gcp-project <project id> fake --secret cluster external
es-cloud-secret-manager --project project gcp --gcp-project <project id> delete --secret external --version 1

AWS

# First configure AWS
aws configure

es-cloud-secret-manager --project project aws --aws-region eu-west-1 list --secret cluster external
es-cloud-secret-manager --project project aws --aws-region eu-west-1 create --secret cluster external
es-cloud-secret-manager --project project aws --aws-region eu-west-1 initialize --secret cluster external
es-cloud-secret-manager --project project aws --aws-region eu-west-1 details --secret cluster external
es-cloud-secret-manager --project project aws --aws-region eu-west-1 import --secret cluster external
es-cloud-secret-manager --project project aws --aws-region eu-west-1 export --secret cluster external
es-cloud-secret-manager --project project aws --aws-region eu-west-1 diff --secret cluster external
es-cloud-secret-manager --project project aws --aws-region eu-west-1 fake --secret cluster external
es-cloud-secret-manager --project project aws --aws-region eu-west-1 delete --secret external --version 84e8c4e5-27c7-4nov-z9f5-50c398fe4911

External-secrets.io fake store

# This would create a kubernetes manifest to create fake secrets store for external-secrets.io
# You can use regexp to extract the key from the secret name, eg. 'project-(.*)-test' to extract 'cluster' from 'project-cluster-test'
# That allows to change the entry in the store, eg. 'cluster' instead of 'project-cluster-test'
es-cloud-secret-manager aws --aws-region eu-west-1 fake --secret project-cluster-test project-external-test --store-key-regexp 'project-(.*)-test' --store-key-replace '\1'

Release in testpypi

You can either build it with twine or with poetry.

You would need to have a ~/.pypirc file with the API token for twine.

python3 -m pip install --upgrade build
python3 -m build
python3 -m pip install --upgrade twine
# twine would automatically look for the API token in the ~/.pypirc file
python3 -m twine upload --repository testpypi dist/es_cloud_secret_manager-$(grep -e '^version' pyproject.toml | head -1 | cut -d= -f2 | xargs printf)*
poetry config pypi-token.testpypi <YOUR_API_TOKEN>
# You can get it from your ~/.pypirc file
poetry config pypi-token.testpypi "$(git config -f ~/.pypirc --get testpypi.password | xargs printf)"

poetry config repositories.testpypi https://test.pypi.org/legacy/
poetry publish --repository testpypi

Once deployed on testpypi, you can install it as follow:

python3 -m pip install --upgrade --index-url https://test.pypi.org/simple/ --extra-index-url https://pypi.org/simple/ es-cloud-secret-manager

Release in pypi

Update the version in pyproject.toml and run:

./release.sh

Once deployed on pypi, you can install it as follow:

python3 -m pip install --upgrade es-cloud-secret-manager

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

es_cloud_secret_manager-2.0.6.tar.gz (9.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

es_cloud_secret_manager-2.0.6-py3-none-any.whl (11.2 kB view details)

Uploaded Python 3

File details

Details for the file es_cloud_secret_manager-2.0.6.tar.gz.

File metadata

  • Download URL: es_cloud_secret_manager-2.0.6.tar.gz
  • Upload date:
  • Size: 9.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/1.8.4 CPython/3.13.0 Linux/6.6.87.2-microsoft-standard-WSL2

File hashes

Hashes for es_cloud_secret_manager-2.0.6.tar.gz
Algorithm Hash digest
SHA256 31ea63746e688545d97b421178aa43a0ada411af1106b5a9519e5b608c8a477e
MD5 951826b335b61280c8664fda73e3cfc9
BLAKE2b-256 11d5fb33d8e78eb47a54f0e3bb33d16fd412960d7543b9a985c95be5aaec093c

See more details on using hashes here.

File details

Details for the file es_cloud_secret_manager-2.0.6-py3-none-any.whl.

File metadata

  • Download URL: es_cloud_secret_manager-2.0.6-py3-none-any.whl
  • Upload date:
  • Size: 11.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/1.8.4 CPython/3.13.0 Linux/6.6.87.2-microsoft-standard-WSL2

File hashes

Hashes for es_cloud_secret_manager-2.0.6-py3-none-any.whl
Algorithm Hash digest
SHA256 290bd69a77404b4710e01e6adb1cc7d8beb20f7120e6e9db45f75f140179fa2f
MD5 69f87419a9f72e9486e208324e83d09f
BLAKE2b-256 b3e50ce58687db3895786c3be2f6d47041c5678bff87aa2365f5a30b6b92f5bf

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page