bitnami/sealed-secrets

Allow add annotations/labels on private key creation/rotation

Open

#949 opened on Sep 8, 2022

 (2 comments) (0 reactions) (0 assignees)Go (771 forks)auto 404
enhancementhelp wanted

Repository metrics

Stars
 (9,222 stars)
PR merge metrics
 (PR metrics pending)

Description

Which component: controller

Is your feature request related to a problem? Please describe.

Actually, the private key creation/rotation function does not allow us to include any kind of annotations/labels to it.

Which should be useful to replicate theses secrets automatically to another(s) cluster(s) using systems like "kubed/config-syncer", which check for an specific annotations on the secrets/configmaps to be replicate.

Describe the solution you'd like

private key creation/rotation should accept a list of annotations/labels from the controller configuration.

--privatekey-annotations 'kubed.appscode.com/sync: ""'
--privatekey-labels 'app.kubernetes.io/instance=production-cluster' --privatekey-labels 'app.kubernetes.io/part-of=sysadmin'

Additional context Replicate secrets between clusters using [kubed/config-syncer](https://github.com/kubeops/config-syncer)

Note: Not sure if someone have this kind of tasks (replicate the private key between cluster) covered using another solution ?

Contributor guide