kv-to-kube
Syncs Azure Key Vault Secrets with a kube_secret_name label to Kubernetes Secrets.
Installation
Via Kustomize/Flux for Kubernetes
Installation via Kustomize/Flux 2.0 is the recommended installation approach for kv-to-kube, note this requires Azure Workload Identity to be setup and working along with the respective OIDC Federated Credentials.
Create a kustomize.yaml file with the following content, being sure to replace keyvault-name, excluded-namespaces, and azure.workload.identity/client-id with your desired values:
resources:
- github.com/cpressland/kv-to-kube/deploy
patches:
- target:
kind: CronJob
patch: |
- op: replace
path: /spec/jobTemplate/spec/template/spec/containers/0/command
value:
- kv-to-kube
- --keyvault-name=my-keyvault
- --excluded-namespaces=kube-system
- target:
kind: ServiceAccount
patch: |
- op: replace
path: /metadata/annotations/azure.workload.identity~1client-id
value: 5d4017fa-3f60-4fcb-a15c-2ffbd8081807
Apply this to your cluster with kubectl apply -k . or using Flux 2.0.
Via Pipx
Pipx is the recommended installation method for running locally, outside of Kubernetes, note this requires azure-cli to be installed and working.
pipx install kv-to-kube
Usage
Once the application is installed either locally or in your cluster, simply create or update secrets within your Key Vault to match the following spec:
{
"postgres_user": "lunalux",
"postgres_pass": "asmr",
"postgres_host": "katherina.postgres.database.azure.com"
}
with a tag of: {"kube_secret_name": "azure-postgres"}
This will create a Kubernetes Secret in all namespaces, as follows:
{
"apiVersion": "v1",
"kind": "Secret",
"metadata": {
"name": "azure-postgres",
"namespace": "default",
},
"data": {
"postgres_host": "a2F0aGVyaW5hLnBvc3RncmVzLmRhdGFiYXNlLmF6dXJlLmNvbQ==",
"postgres_pass": "YXNtcg==",
"postgres_user": "bHVuYWx1eA=="
},
"type": "Opaque"
}
FAQs
Q: What would I use this for?
A: I use it with Terraform. During the creation of something like a Postgres Server we store the connection details in Azure Key Vault, AKS then uses kv-to-kube to syncronise those secrets so they can be used in a Pods environment variables.
Q: Why does this delete and re-create secrets instead of updating them?
A: I couldn't find an elegant way to perform this operation with the kr8s library. I've opened an issue here, should that get a satifactory resolution I'll change this to update and provide an annotation on the secret for the last updated time. Because of this, I wouldn't recommend using this for secrets that require mounting as a volume. But if thats your use case, you should probably be using a Secrets Store CSI Driver
Metadata
Release files for kv-to-kube 1.0.5
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| kv_to_kube-1.0.5.tar.gz | 3.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| kv_to_kube-1.0.5-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 7.0 kB
Release files / kv_to_kube-1.0.5.tar.gz
| Download URL | kv_to_kube-1.0.5.tar.gz |
|---|---|
| Size | 3.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
5f94a4c180e328269d05542bcf8dc8f7f37440c9780584b09b06f05e3c50d2f8
|
|
BLAKE2b-256 checksum How to use checksums |
6bd44f598ff61126fb3aaa2e2fbc62308d111447da83d4f4a476a938e8ef77a5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.7 {"installer":{"name":"uv","version":"0.11.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / kv_to_kube-1.0.5-py3-none-any.whl
| Download URL | kv_to_kube-1.0.5-py3-none-any.whl |
|---|---|
| Size | 3.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
51bc3182af08862b8a5d364dd9adad70fe16acab1bf4dc6336165fc12a9c76fd
|
|
BLAKE2b-256 checksum How to use checksums |
6aa2ddfaed17d158ffd33b2bb7b6291b51c0c2066dce4aedf69940e937d24b77
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.7 {"installer":{"name":"uv","version":"0.11.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|