This is the manual for clusterctl v0.3.0. The latest release is v0.4.0: read its manual.
clusterctl secrets check

clusterctl secrets check

clusterctl secrets check

Check the sops encrypted Secret documents

Synopsis

List every Secret document with its keys, the master keys sops encrypted it to and how many references use it. None of this needs a key: the names, the keys and the sops metadata are readable, and a reference to a key that does not exist is already refused when the configuration loads.

With –decrypt each document is also decrypted, in memory, and the result is thrown away. It proves this workstation can read every secret before a reinstall needs one, and prints nothing of the plaintext.

clusterctl secrets check –decrypt

clusterctl secrets check [flags]

Options

      --decrypt   also decrypt each document in memory
  -h, --help      help for check

Options inherited from parent commands

      --config strings      configuration file or directory to read, repeatable (default: CLUSTERCTL_CONFIG or the search path)
      --context string      context to act on (default: the current one)
      --dry-run             report what would be done and change nothing
      --fanout int          how many hosts to work on at once, at least 1 (default: from the configuration)
      --force               allow protected hosts, and nodes the inventory does not know, to be touched
  -n, --nodes stringArray   node set to act on, for example 'exe[1-10],@rack:R02' (default: CLUSTERCTL_NODES)
  -o, --output string       output format: table, wide, json, yaml, nodeset, name, jsonpath=, jq= (default "table")
      --set stringArray     override one configuration value as PATH=VALUE, repeatable
  -y, --yes                 answer the confirmation prompts with yes

SEE ALSO