feat(template): added secret template function (#1221)

* feat(tmpl): added fetchSecretValue template function

This adds a tmpl `fetchSecretValue` and `expandSecretRefs` function by:
- Adding:
    - `expandSecretRefs` function in tmpl package that uses vals
    package to fetch secrets
    - `fetchSecretValue` function in tmpl package like below but for
    single string value
    - gomock for tests purpose
- Changing:
    - move init of vals package to function (so the same instance can be used for template values and rendering the whole template)

* doc(secret): added doc how to use new tmpl methods

Added example usage of `fetchSecretValue` and `expandSecretRefs`
This commit is contained in:
Marcin Kaciuba
2020-04-25 21:10:02 +09:00
committed by GitHub
parent 3a19a394ab
commit b1190508b2
10 changed files with 301 additions and 145 deletions
+58
View File
@@ -0,0 +1,58 @@
# Secrets
helmfile can handle secrets using [helm-secrets](https://github.com/zendesk/helm-secrets) plugin or using remote secrets storage
(everything that package [vals](https://github.com/variantdev/vals) can handle vault, AWS SSM etc)
This section will describe the second use case.
# Remote secrets
This paragraph will describe how to use remote secrets storage (vault, SSM etc) in helmfile
## Fetching single key
To fetch single key from remote secret storage you can use `fetchSecretValue` template function example below
```yaml
# helmfile.yaml
repositories:
- name: stable
url: https://kubernetes-charts.storage.googleapis.com
environments:
default:
values:
- service:
password: ref+vault://svc/#pass
login: ref+vault://svc/#login
releases:
- name: service
namespace: default
labels:
cluster: services
secrets: vault
chart: stable/svc
version: 0.1.0
values:
- service:
login: {{ .Values.service.login | fetchSecretValue }} # this will resolve ref+vault://svc/#pass and fetch secret from vault
password: {{ .Values.service.password | fetchSecretValue | quote }}
# - values/service.yaml.gotmpl # alternatively
```
## Fetching multiple keys
Alternatively you can use `expandSecretRefs` to fetch a map of secrets
```yaml
# values/service.yaml.gotmpl
service:
{{ .Values.service | expandSecretRefs | toYaml | nindent 2 }}
```
This will produce
```yaml
# values/service.yaml
service:
login: svc-login # fetched from vault
password: pass
```