clusterctl secrets check

clusterctl secrets check

clusterctl secrets check

Check the sops encrypted Secret documents

Synopsis

List every Secret document with its keys, the master keys sops encrypted it to and how many references use it. None of this needs a key or sops: the names, the keys and the sops metadata are readable, and a reference to a key that does not exist is already refused when the configuration loads.

With –decrypt each document is also decrypted by the sops command, into memory, and the result is thrown away. It proves this workstation can read every secret before a reinstall needs one, and prints nothing of the plaintext. The caption of the table names the sops that decrypts.

clusterctl secrets check –decrypt

clusterctl secrets check [flags]

Options

      --decrypt   also decrypt each document in memory
  -h, --help      help for check

Options inherited from parent commands

      --config strings        configuration file or directory to read, repeatable (default: CLUSTERCTL_CONFIG or the search path)
      --context string        context to act on (default: the current one)
      --dry-run               report what would be done and change nothing
      --fanout int            how many hosts to work on at once, at least 1; caps the service processors and the names asked at once too, which fanout.max and CLUSTERCTL_FANOUT do not (default: from the configuration)
      --force                 allow protected hosts, and nodes the inventory does not know, to be touched
  -n, --nodes stringArray     node set to act on, for example 'exe[1-10],@rack:R02' (default: CLUSTERCTL_NODES)
  -o, --output string         output format: table, wide, json, yaml, nodeset, name, jq= (default "table")
      --progress string       how to show the progress of a command on standard error: auto, tty, counter, plain, none (default: CLUSTERCTL_PROGRESS, else auto, a live tree when standard error is a terminal; plain writes lines for a log)
      --progress-log string   append the progress events of a command to this file, one JSON object per line, created readable by you alone (default: CLUSTERCTL_PROGRESS_LOG; an empty one writes none)
      --set stringArray       override one configuration value as PATH=VALUE, repeatable
  -y, --yes                   answer the confirmation prompts with yes

SEE ALSO