pinterb/mush is a docker image that bundles the following:
As an example, say I want to populate my Terraform tfvars file with externally sourced secrets. I'd maybe start with the following terraform.tfvars.tmpl file:
azure_settings_file = "{{AZURE_SETTINGS_FILE}}"
azure_subscription_id = "{{AZURE_SUBSCRIPTION_ID}}"
azure_certificate = "{{AZURE_CERT}}"
username = "{{VM_USER}}"
password = "{{VM_PASS}}"
key_fingerprint = "{{AZURE_SUBSCRIPTION_THUMBPRINT}}"
ssh_fingerprint = "{{SSH_FINGERPRINT}}"
region = "{{AZURE_REGION}}"
domain = "{{DOMAIN_NAME}}"
dnsimple_token = "{{DNSIMPLE_API_TOKEN}}"
dnsimple_email = "{{DNSIMPLE_EMAIL_ADDR}}"
I keep my secrets is a separate location. The sourceable file contains something like the following:
# RSA Fingerprint
export SSH_FINGERPRINT=$(ssh-keygen -lf ~/.ssh/dummy.pub | awk '{print $2}')
# DNSimple API
export DNSIMPLE_EMAIL_ADDR="[email protected]"
export DNSIMPLE_API_TOKEN="82Y0nQu238vtrYYMsab1"
# Azure Credentials
export AZURE_SETTINGS="$HOME/.cloudcreds/azure/Pay-As-You-Go-7-01-2010-credentials.publishsettings"
export AZURE_SUBSCRIPTION_ID="7g301c1-n912-7nq7-c238-951x3639-py4ik"
export AZURE_SUBSCRIPTION_THUMBPRINT="5561314766618YWUI39D91YN48QA612PNC"
export AZURE_CERTIFICATE="$HOME/.secrets/azure/azure.cer"
export AZURE_SUBSCRIPTION_EXP="2019-01-01"
# Default Cloud User Credentials
export VM_USER="clouduser"
export VM_PASS="cloudpass"
Next, I run my mush container to render my terraform.tfvars:
cat $(TEMPLATES_DIR)/terraform.tfvars.tmpl | docker run -i \
-v $(CLOUD_CREDS_DIR)/extras:/home/dev/.extra \
-v $(SSH_CREDS_DIR):/home/dev/.ssh \
-e MUSH_EXTRA=/home/dev/.extra \
-e AZURE_SETTINGS_FILE=/home/dev/.azure.settings \
-e AZURE_CERT=/home/dev/.azure.cer \
-e AZURE_REGION="West US" \
-e DOMAIN_NAME="example.com" \
pinterb/mush:0.0.16 > $(BUILD_DIR)/terraform.tfvars
The rendered output would be:
azure_settings_file = "/home/dev/.azure.settings"
azure_subscription_id = "7g301c1-n912-7nq7-c238-951x3639-py4ik"
azure_certificate = "/home/dev/.azure.cer"
username = "clouduser"
password = "cloudpass"
key_fingerprint = "5561314766618YWUI39D91YN48QA612PNC"
ssh_fingerprint = "SHA256:dtVP0UIGmAZBeaBX+ICPYyalhhYcDjeWR9vs+j5AoLc"
region = "West US"
domain = "example.com"
dnsimple_token = "82Y0nQu238vtrYYMsab1"
dnsimple_email = "[email protected]"
Content type
Image
Digest
sha256:b16827639…
Size
14.2 MB
Last updated
over 9 years ago
docker pull pinterb/mush