[Verse 1] When secrets hide behind the wall Encoded data, can't read at all Base sixty-four has locked it tight But kubectl holds the key tonight Get the secret by its name Output format, play the game JSON path will lead the way To the data where it stays [Chorus] Decode decode, the secret's there Pipeline it through to make it clear Base sixty-four dash d will show The password that you need to know Decode decode, don't let it hide The value's waiting there inside [Verse 2] First you get the secret store Specify the name and nothing more O flag for output, set it right JSON path brings data to light Dot data dot password is the trail Through the structure without fail Pipe symbol sends it on its way To base sixty-four today [Chorus] Decode decode, the secret's there Pipeline it through to make it clear Base sixty-four dash d will show The password that you need to know Decode decode, don't let it hide The value's waiting there inside [Bridge] Never store them in your Git External vaults are where they sit Vault or AWS will do Azure Key Vault's good for you External Secrets Operator Makes your cluster so much greater Encrypt at rest in etcd Rotate them regularly [Verse 3] Immutable flag set to true Stops the changes coming through Performance boost for your cluster No more secret data bluster [Chorus] Decode decode, the secret's there Pipeline it through to make it clear Base sixty-four dash d will show The password that you need to know Decode decode, don't let it hide The value's waiting there inside [Outro] From encoded to the clear The secret value will appear Kubectl gets and base converts The hidden password it preserves
← Create docker registry secret | List persistent volumes (cluster-wide) →