Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Thib
@thibaultamartin@mamot.fr  ·  activity timestamp 2 weeks ago

Sealed secrets seem to be much easier to set up and use than SOPS, at least for the homelab use case?

#kubernetes #selfHosting #homeLab

  • Copy link
  • Flag this post
  • Block
Clayton O'Neill
@clayton_oneill@mastodon.cloud replied  ·  activity timestamp 2 weeks ago

@thibaultamartin I’m pretty happy with external secrets operator + 1password integration. They also have integrations with a ton of other provides if 1password isn’t your thing.

I used to use git-crypt and was always paranoid about accidentally committing an unencrypted password. Maybe sealed secrets/SOPS make that harder to do?

  • Copy link
  • Flag this comment
  • Block
Sheogorath
@sheogorath@microblog.shivering-isles.com replied  ·  activity timestamp 2 weeks ago

@thibaultamartin Mhm, not sure I would go down any bitnami routes these days :X

  • Copy link
  • Flag this comment
  • Block
Zoë (english toots)
@OatPotato@hachyderm.io replied  ·  activity timestamp 2 weeks ago

@thibaultamartin I use it in homelab, also used it in production for a client (well, it was just for some "bootstrap" secrets, the rest was using External Secrets"): works well.
Don't forget to securely and regulary backup the key(s) regulary (as it rotates monthly), rotate the secrets sometimes and you should be fine.

  • Copy link
  • Flag this comment
  • Block
Thib
@thibaultamartin@mamot.fr replied  ·  activity timestamp 2 weeks ago

@OatPotato yea I plan to use velero to backup my etcd, so the privkey should be backed up. Of course this will undergo proper testing before being rolled out in production :)

  • Copy link
  • Flag this comment
  • Block
αxel simon ↙︎↙︎↙︎
@axx@mstdn.fr replied  ·  activity timestamp 2 weeks ago

@thibaultamartin Having bashed my head against – and eventually managed to make work – sops-nix, please say it ain't so.

  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0-rc.3.1 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login