Difference between revisions of "SOPS GCP KMS"
Jump to navigation
Jump to search
Line 12: | Line 12: | ||
* <code>[[gcloud kms keyrings create your-sops-keyring --location global]]</code> | * <code>[[gcloud kms keyrings create your-sops-keyring --location global]]</code> | ||
* <code>[[gcloud kms keys create]] --location global --keyring your-sops-keyring --purpose encryption --protection-level "hsm"</code> | * <code>[[gcloud kms keys create]] --location global --keyring your-sops-keyring --purpose encryption --protection-level "hsm"</code> | ||
− | |||
− | |||
− | |||
== Related == | == Related == |
Revision as of 09:54, 31 October 2022
Encryption/Decryption
To create file:
sops --gcp /your/path/to/your/sops-encryption-key test.yaml
To encrypt:
sops --encrypt test.yaml > test.enc.yaml
sops --encrypt --in-place
sops --encrypt --gcp-kms
Manage Keys
gcloud kms keyrings create your-sops-keyring --location global
gcloud kms keys create --location global --keyring your-sops-keyring --purpose encryption --protection-level "hsm"
Related
sops --azure-kv
SOPS_GCP_KMS_IDS
environmental variable
See also
- SOPS,
sops | sops -d | sops -e | sops exec-env | sops exec-file | sops publish | sops keyservice | sops groups | sops updatekeys | sops --help
- SOPS: Secrets OPerationS,
sops
, GCP,ENC[AES256_GCM, sops-secrets-operator
Advertising: