No project description provided
Project description
Cloud secret manager
This is a python package to handle secrets in cloud environments, handling GCP and AWS secrets.
It also helps to create a manifest to generate fake secrets for development while using external-secrets.io.
Setup
Initialize secrets manager:
./init_secret_manager.sh
Run secret manager:
# Either activate with poetry shell and run it
poetry -C . shell
es-cloud-secret-manager --help
# deactive when done
deactivate
# Either run it through poetry
poetry -C . run es-cloud-secret-manager --help
Format the code:
# Format the code with isort and autopep8
./format.sh
Yaml format
For secret with yaml format, if you want it to have a better formatting, better install yq and sponge.
# eg. for Ubuntu
sudo apt install yq moreutils
GCP
# First authenticate to your GCP project
gcloud auth application-default login --project <project id>
es-cloud-secret-manager --project project gcp --gcp-project <project id> list --secret cluster external
es-cloud-secret-manager --project project gcp --gcp-project <project id> create --secret cluster external
es-cloud-secret-manager --project project gcp --gcp-project <project id> initialize --secret cluster external
es-cloud-secret-manager --project project gcp --gcp-project <project id> details --secret cluster external
es-cloud-secret-manager --project project gcp --gcp-project <project id> import --secret cluster external
es-cloud-secret-manager --project project gcp --gcp-project <project id> export --secret cluster external
es-cloud-secret-manager --project project gcp --gcp-project <project id> diff --secret cluster external
es-cloud-secret-manager --project project gcp --gcp-project <project id> fake --secret cluster external
es-cloud-secret-manager --project project gcp --gcp-project <project id> delete --secret external --version 1
AWS
# First configure AWS
aws configure
es-cloud-secret-manager --project project aws --aws-region eu-west-1 list --secret cluster external
es-cloud-secret-manager --project project aws --aws-region eu-west-1 create --secret cluster external
es-cloud-secret-manager --project project aws --aws-region eu-west-1 initialize --secret cluster external
es-cloud-secret-manager --project project aws --aws-region eu-west-1 details --secret cluster external
es-cloud-secret-manager --project project aws --aws-region eu-west-1 import --secret cluster external
es-cloud-secret-manager --project project aws --aws-region eu-west-1 export --secret cluster external
es-cloud-secret-manager --project project aws --aws-region eu-west-1 diff --secret cluster external
es-cloud-secret-manager --project project aws --aws-region eu-west-1 fake --secret cluster external
es-cloud-secret-manager --project project aws --aws-region eu-west-1 delete --secret external --version 84e8c4e5-27c7-4nov-z9f5-50c398fe4911
External-secrets.io fake store
Release in testpypi
You can either build it with twine or with poetry.
You would need to have a ~/.pypirc file with the API token for twine.
python3 -m pip install --upgrade build
python3 -m build
python3 -m pip install --upgrade twine
# twine would automatically look for the API token in the ~/.pypirc file
python3 -m twine upload --repository testpypi dist/es_cloud_secret_manager-$(grep -e '^version' pyproject.toml | head -1 | cut -d= -f2 | xargs printf)*
poetry config pypi-token.testpypi <YOUR_API_TOKEN>
# You can get it from your ~/.pypirc file
poetry config pypi-token.testpypi "$(git config -f ~/.pypirc --get testpypi.password | xargs printf)"
poetry config repositories.testpypi https://test.pypi.org/legacy/
poetry publish --repository testpypi
Once deployed on testpypi, you can install it as follow:
python3 -m pip install --upgrade --index-url https://test.pypi.org/simple/ --extra-index-url https://pypi.org/simple/ es-cloud-secret-manager
Release in pypi
Update the version in pyproject.toml and run:
./release.sh
Once deployed on pypi, you can install it as follow:
python3 -m pip install --upgrade es-cloud-secret-manager
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file es_cloud_secret_manager-2.0.2.tar.gz.
File metadata
- Download URL: es_cloud_secret_manager-2.0.2.tar.gz
- Upload date:
- Size: 9.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: poetry/1.8.4 CPython/3.13.0 Linux/6.6.87.2-microsoft-standard-WSL2
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
c89e6c4ffd9cd2ae79262a20463c37b34bc789289972d09a939fa9f279e7be1c
|
|
| MD5 |
083c9ad4c1941a574bab3867b2dc803a
|
|
| BLAKE2b-256 |
0a81844a7d42ecf2fbfff1f0b79dc5600c29abedc151c2020a1c01eb9a15670d
|
File details
Details for the file es_cloud_secret_manager-2.0.2-py3-none-any.whl.
File metadata
- Download URL: es_cloud_secret_manager-2.0.2-py3-none-any.whl
- Upload date:
- Size: 10.7 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: poetry/1.8.4 CPython/3.13.0 Linux/6.6.87.2-microsoft-standard-WSL2
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a3bce80f72ff1980fba528955d81f6ac36a8a32352fcb4d830bd7177993c66a8
|
|
| MD5 |
053a47f1273e183ced5edc824c303dc4
|
|
| BLAKE2b-256 |
71cd474d24418b366edd01c66985354ee158fa9bad58ac290629cf105efd2012
|