101 lines
4.8 KiB
Markdown
101 lines
4.8 KiB
Markdown
# Bitnami Secure Image for Sealed Secrets
|
||
|
||
## What is Sealed Secrets?
|
||
|
||
> Sealed Secrets are "one-way" encrypted K8s Secrets that can be created by anyone, but can only be decrypted by the controller running in the target cluster recovering the original object.
|
||
|
||
[Overview of Sealed Secrets](https://github.com/bitnami-labs/sealed-secrets)
|
||
|
||
## TL;DR
|
||
|
||
```console
|
||
docker run --name sealed-secrets bitnami/sealed-secrets:latest
|
||
```
|
||
|
||
## Why use Bitnami Secure Images?
|
||
|
||
Those are hardened, minimal CVE images built and maintained by Bitnami. Bitnami Secure Images are based on the cloud-optimized, security-hardened enterprise [OS Photon Linux](https://vmware.github.io/photon/). Why choose BSI images?
|
||
|
||
- Hardened secure images of popular open source software with Near-Zero Vulnerabilities
|
||
- Vulnerability Triage & Prioritization with VEX Statements, KEV and EPSS Scores
|
||
- Compliance focus with FIPS, STIG, and air-gap options, including secure bill of materials (SBOM)
|
||
- Software supply chain provenance attestation through in-toto
|
||
- First class support for the internet’s favorite Helm charts
|
||
|
||
Each image comes with valuable security metadata. You can view the metadata in [our public catalog here](https://app-catalog.vmware.com/bitnami/apps). Note: Some data is only available with [commercial subscriptions to BSI](https://bitnami.com/).
|
||
|
||

|
||

|
||
|
||
If you are looking for our previous generation of images based on Debian Linux, please see the [Bitnami Legacy registry](https://hub.docker.com/u/bitnamilegacy).
|
||
|
||
## Supported tags and respective `Dockerfile` links
|
||
|
||
Learn more about the Bitnami tagging policy and the difference between rolling tags and immutable tags [in our documentation page](https://techdocs.broadcom.com/us/en/vmware-tanzu/application-catalog/tanzu-application-catalog/services/tac-doc/apps-tutorials-understand-rolling-tags-containers-index.html).
|
||
|
||
You can see the equivalence between the different tags by taking a look at the `tags-info.yaml` file present in the branch folder, i.e `bitnami/ASSET/BRANCH/DISTRO/tags-info.yaml`.
|
||
|
||
Subscribe to project updates by watching the [bitnami/containers GitHub repo](https://github.com/bitnami/containers).
|
||
|
||
## Get this image
|
||
|
||
The recommended way to get the Bitnami sealed-secrets Docker Image is to pull the prebuilt image from the [Docker Hub Registry](https://hub.docker.com/r/bitnami/sealed-secrets).
|
||
|
||
```console
|
||
docker pull bitnami/sealed-secrets:latest
|
||
```
|
||
|
||
To use a specific version, you can pull a versioned tag. You can view the [list of available versions](https://hub.docker.com/r/bitnami/sealed-secrets/tags/) in the Docker Hub Registry.
|
||
|
||
```console
|
||
docker pull bitnami/sealed-secrets:[TAG]
|
||
```
|
||
|
||
If you wish, you can also build the image yourself by cloning the repository, changing to the directory containing the Dockerfile and executing the `docker build` command. Remember to replace the `APP`, `VERSION` and `OPERATING-SYSTEM` path placeholders in the example command below with the correct values.
|
||
|
||
```console
|
||
git clone https://github.com/bitnami/containers.git
|
||
cd bitnami/APP/VERSION/OPERATING-SYSTEM
|
||
docker build -t bitnami/APP:latest .
|
||
```
|
||
|
||
## Configuration
|
||
|
||
### Running commands
|
||
|
||
To run commands inside this container you can use `docker run`, for example to execute `kubeseal --version` you can follow the example below:
|
||
|
||
```console
|
||
docker run --rm --name sealed-secrets bitnami/sealed-secrets:latest -- kubeseal --version
|
||
```
|
||
|
||
## Notable Changes
|
||
|
||
### Starting January 16, 2024
|
||
|
||
- The `docker-compose.yaml` file has been removed, as it was solely intended for internal testing purposes.
|
||
|
||
## Contributing
|
||
|
||
We'd love for you to contribute to this container. You can request new features by creating an [issue](https://github.com/bitnami/containers/issues) or submitting a [pull request](https://github.com/bitnami/containers/pulls) with your contribution.
|
||
|
||
## Issues
|
||
|
||
If you encountered a problem running this container, you can file an [issue](https://github.com/bitnami/containers/issues/new/choose). For us to provide better support, be sure to fill the issue template.
|
||
|
||
## License
|
||
|
||
Copyright © 2025 Broadcom. The term "Broadcom" refers to Broadcom Inc. and/or its subsidiaries.
|
||
|
||
Licensed under the Apache License, Version 2.0 (the "License");
|
||
you may not use this file except in compliance with the License.
|
||
You may obtain a copy of the License at
|
||
|
||
<http://www.apache.org/licenses/LICENSE-2.0>
|
||
|
||
Unless required by applicable law or agreed to in writing, software
|
||
distributed under the License is distributed on an "AS IS" BASIS,
|
||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||
See the License for the specific language governing permissions and
|
||
limitations under the License.
|