Sign inSign up

vimeo/pentagon

By vimeo

•Updated 8 months ago

Pentagon is an easy way to reflect your Vault secrets into Kubernetes secrets.

Image
0

500K+

vimeo/pentagon repository overview

Go GoDoc Go Report Card

⁠Pentagon

Pentagon is a small application designed to run as a Kubernetes CronJob to periodically copy secrets stored in Vault⁠ into equivalent Kubernetes Secrets⁠, keeping them synchronized. Naturally, this should be used with care as "standard" Kubernetes Secrets are simply obfuscated as base64-encoded strings. However, one can and should use more secure methods of securing secrets including Google's KMS⁠ and restricting roles and service accounts appropriately.

Use at your own risk...

⁠Why not just query Vault?

That's a good question. If you have a highly-available Vault setup that is stable and performant and you're able to modify your applications to query Vault, that's a completely reasonable approach to take. If you don't have such a setup, Pentagon provides a way to cache things securely in Kubernetes secrets which can then be provided to applications without directly introducing a Vault dependency.

⁠Configuration

Pentagon requires a simple YAML configuration file, the path to which should be passed as the first and only argument to the application. It is recommended that you store this configuration in a ConfigMap⁠ and reference it in the CronJob specification.

⁠More Information

See https://github.com/vimeo/pentagon⁠ for more information.

⁠Contributors

Pentagon is a production of Vimeo's Core Services team with lots of support from Vimeo SRE.

Tag summary

Content type

Image

Digest

Size

23.2 MB

Last updated

about 4 years ago

docker pull vimeo/pentagon