clusterctl secrets push
clusterctl secrets push
Write the secrets onto a node set
Synopsis
Decrypt each configured secret and write it onto the nodes with the owner and mode the configuration asks for.
Every secret is decrypted before anything is asked or written, so a key this workstation lacks stops the push, and its dry run, before a node is touched. Two secrets written to the same target are refused before that: only the last would stay, after the first had been in place for a while. Each file is written beside its target and moved into place only once all of it has arrived, so a lost connection leaves the old file as it was.
The nodes are written to side by side, fanout.max at once, each its secrets one after the other, so no node waits for another’s file before its next. A node that cannot be reached is not tried again for the next secret; when a node that failed could not be reached, for any of its secrets, the command exits 3, even when another node refused.
This overwrites files on the nodes, so it asks first.
clusterctl secrets push -n exe[1-4]
clusterctl secrets push [NODESET] [flags]Options
-h, --help help for pushOptions inherited from parent commands
--config strings configuration file or directory to read, repeatable (default: CLUSTERCTL_CONFIG or the search path)
--context string context to act on (default: the current one)
--dry-run report what would be done and change nothing
--fanout int how many hosts to work on at once, at least 1; caps the service processors and the names asked at once too, which fanout.max and CLUSTERCTL_FANOUT do not (default: from the configuration)
--force allow protected hosts, and nodes the inventory does not know, to be touched
-n, --nodes stringArray node set to act on, for example 'exe[1-10],@rack:R02' (default: CLUSTERCTL_NODES)
-o, --output string output format: table, wide, json, yaml, nodeset, name, jq= (default "table")
--progress string how to show the progress of a command on standard error: auto, tty, counter, plain, none (default: CLUSTERCTL_PROGRESS, else auto, a live tree when standard error is a terminal; plain writes lines for a log)
--progress-log string append the progress events of a command to this file, one JSON object per line, created readable by you alone (default: CLUSTERCTL_PROGRESS_LOG; an empty one writes none)
--set stringArray override one configuration value as PATH=VALUE, repeatable
-y, --yes answer the confirmation prompts with yesSEE ALSO
- clusterctl secrets - Distribute the encrypted files the nodes need