Skip to main content

Easily Read Kubernetes Secrets

Read base64 encoded Kubernetes secrets without getting in your way.

Kubernetes secrets resources base64 encode the secret values. It is often useful to view the decoded values for those secrets in place. This tool offers a useful means to do that.

Features

  • allows you to read one or more Secrets
  • works with individual secrets, lists of secrets, and multiple yaml docs
  • simple auditable Python source code

Install

Install with pip

pip install ksd

Install with pipx

pipx install ksd

Quick Example

$ kubectl get secret -n mynamespace -o yaml mysecret | ksd
apiVersion: v1
data:
  password: my-decoded-password-secret
  username: my-decoded-username-secret
kind: Secret
metadata:
  creationTimestamp: '2024-01-01T00:00:0Z'
  labels:
    name: mynamespace
  name: mysecret
  namespace: mynamespace
  resourceVersion: '1234'
  uid: c4f4c4db-bdba-47d0-9a17-1e307e1448c7
type: Opaque

Detailed Usage

Get help

ksd --help

Get single secret as YAML and decode as YAML

kubectl get secret -o yaml mysecret | ksd 

Get single secret as YAML and decode as JSON

kubectl get secret -o yaml mysecret | ksd -f json

Get multiple secrets as YAML and decode as YAML

kubectl get secret -o yaml  | ksd

Get multiple secrets as YAML and decode as JSON

kubectl get secret -o yaml  | ksd -f json

Get secrets as JSON and decode as YAML

kubectl  get secret -o json | ksd

Get secrets as JSON and decode as JSON

kubectl  get secret -o json | ksd -f json

Use k8s flags as normal

kubectl  get secret -n my_namespace -l label_key=label_value -o json | ksd

I don't know why you would do this, but the output is idempotent

kubectl get secret -o yaml  | ksd | ksd

Read Secrets from a file

cat secrets.yaml | ksd

Suppoert multi-document yaml input (separated with the yaml '---')

kubectl get secret -o yaml mysecret > secrets.yaml
echo "---" >> secrets.yaml
kubectl get secret -o yaml ohter_secret >> secrets.yaml
cat secrets.yaml | ksd

Inspired by

There are several projects with a similar name and purpose. However, they are written in Go and distribute compiled binaries. I prefer to use a version of this tool written in Python, for which the source code is auditable.

Tests

pip install -e .[tests]
pytest -vvv tests/

Release files for ksd 0.1.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ksd 0.1.3
File Size Uploaded
ksd-0.1.3.tar.gz 5.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ksd 0.1.3
File Interpreter ABI Platform
ksd-0.1.3-py3-none-any.whl Python 3 none any Details

Total release size: 10.8 kB

Release files / ksd-0.1.3.tar.gz

Download URL ksd-0.1.3.tar.gz
Size 5.8 kB
Tags Source
SHA-256 checksum
How to use checksums
25b9dc833fc1a48a9d3f56505527ec92e4543f729f7c0bee939a9397e46ee49b
BLAKE2b-256 checksum
How to use checksums
39dbaad403d5ef00602e8ba88ae8d8142f71a0ddb6f96f3f0acdbb96bb091cd0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/5.0.0 CPython/3.10.10

Release files / ksd-0.1.3-py3-none-any.whl

Download URL ksd-0.1.3-py3-none-any.whl
Size 5.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
05c7156ed18a8bebec559dfc2d06f6087b114fcd6e0455ab750fdfbb6b6923f0
BLAKE2b-256 checksum
How to use checksums
f22bd84a627f70aa4dee1ee35600b63db3941018a593caf846bb23ab341f7a29
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/5.0.0 CPython/3.10.10

Release history Release notifications | RSS feed

This release

0.1.3 This release

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page