Kubernetes External Secrets Operator
I wanted to put a short demo together of using External Secrets Operator (ESO) to expose secrets from a vault (like Hashicorp Vault, AWS Secrets Manager, etc) to services running in kubernetes Demo code is here in this github repo This post is a high level overview of the components, see the repo for the full example. Setup # docker for containerized development kind for setting up a quick cluster kubectl for accessing the cluster helm for installing ArgoCD and ESO and then justfile is there to wrap the commands to easier execution Step 0 - Vault # for the demo we’ll setup Hashicorp Vault in docker compose to easily bring it up and down and the init-script is in the repo - it uses curl to make some secrets in vault that we’ll reference later bringing up the vault instance is a simple (use the just recipes which some commands for checking status etc.) Step 1 - App # We need an app that requires secrets app code in repo, essentially it’s a python webserver to show the vault values (obvio…