clusterctl secrets
clusterctl secrets
clusterctl secrets
Distribute the encrypted files the nodes need
Synopsis
Decrypt the files a site keeps beside its configuration, or the values of its sops encrypted Secret documents, and write them onto the nodes.
The plaintext never touches this workstation’s disk: it is decrypted into memory and streamed to each node over standard input, which is what keeps a cluster key off a laptop.
clusterctl secrets [flags]Options
-h, --help help for secretsOptions inherited from parent commands
--config strings configuration file or directory to read, repeatable (default: CLUSTERCTL_CONFIG or the search path)
--context string context to act on (default: the current one)
--dry-run report what would be done and change nothing
--fanout int how many hosts to work on at once, at least 1 (default: from the configuration)
--force allow protected hosts, and nodes the inventory does not know, to be touched
-n, --nodes stringArray node set to act on, for example 'exe[1-10],@rack:R02' (default: CLUSTERCTL_NODES)
-o, --output string output format: table, wide, json, yaml, nodeset, name, jsonpath=, jq= (default "table")
--set stringArray override one configuration value as PATH=VALUE, repeatable
-y, --yes answer the confirmation prompts with yesSEE ALSO
- clusterctl - Administer HPC clusters from one binary
- clusterctl secrets check - Check the sops encrypted Secret documents
- clusterctl secrets list - List the secrets the configuration carries
- clusterctl secrets push - Write the secrets onto a node set