clusterctl secrets check
clusterctl secrets check
clusterctl secrets check
Check the sops encrypted Secret documents
Synopsis
List every Secret document with its keys, the master keys sops encrypted it to and how many references use it. None of this needs a key: the names, the keys and the sops metadata are readable, and a reference to a key that does not exist is already refused when the configuration loads.
With –decrypt each document is also decrypted, in memory, and the result is thrown away. It proves this workstation can read every secret before a reinstall needs one, and prints nothing of the plaintext.
clusterctl secrets check –decrypt
clusterctl secrets check [flags]Options
--decrypt also decrypt each document in memory
-h, --help help for checkOptions inherited from parent commands
--config strings configuration file or directory to read, repeatable (default: CLUSTERCTL_CONFIG or the search path)
--context string context to act on (default: the current one)
--dry-run report what would be done and change nothing
--fanout int how many hosts to work on at once (default: from the configuration)
--force allow protected hosts to be touched
-n, --nodes string node set to act on, for example 'exe[1-10],@idle'
-o, --output string output format: table, wide, json, yaml, nodeset, name, jsonpath=, jq= (default "table")
--set stringArray override one configuration value as PATH=VALUE, repeatable
-y, --yes answer the confirmation prompts with yesSEE ALSO
- clusterctl secrets - Distribute the encrypted files the nodes need