This is the Stable version of the documentation. The latest version is experimental and under active development. You can use the version selector in the top-right menu to switch versions for this specific page, or click here to go to the latest version's homepage.
External Secrets Operator (ESO) Installation
External Secrets Operator (ESO) is a Secret Syncing from Vault to Kubernetes Cluster as Kubernetes Secret Resource Utility
External Secrets Operator (ESO) can have multiple instances dedicated to each of Workload Type Kubernetes Cluster.
Pre-Installation
Section titled “Pre-Installation”ESO Preparation
Section titled “ESO Preparation”-
Create Helm Value Configurations
Terminal window cat <<EOF > $BASE_WORKING_DIR/helm-values/eso-full-values.yamlleaderElec: trueinstallCRDs: trueEOF
Complete Prerequisites
Section titled “Complete Prerequisites”Kubernetes Cluster
Section titled “Kubernetes Cluster”-
Ensure Kubernetes Namespace
Section titled “Ensure Kubernetes Namespace devsecops-system Exists”devsecops-systemExistsExternal Secrets Operator (ESO) is installed into Namespace
devsecops-systemand the Helm Command below does not create it —helm upgrade --installreturnsError: namespaces "devsecops-system" not foundwhen the Namespace is missing.Create it with DevSecOps - Create Namespace across Kubernetes Clusters.
Installation
Section titled “Installation”-
Add ESO Helm Repository.
Terminal window # Add Helm Repositoryhelm repo add external-secrets-operator https://charts.external-secrets.io/helm repo update -
Connect to Kubernetes Cluster ; i.e w/ Kubeconfig File
Set Kubeconfig File
Terminal window export KUBECONFIG="$HOME/opstella-installation/kubeconfigs/CHANGEME_cluster.yaml" -
Install ESO on Kubernetes Cluster.
-
Install a Helm Release with specific Helm Chart Version
--version 0.19.2(App Version: v0.19.2)Terminal window # Install ESO Helm Releasehelm install external-secrets-operator external-secrets-operator/external-secrets --version 0.19.2 \--namespace devsecops-system \-f $HOME/opstella-installation/helm-values/eso-full-values.yaml
-
Post-Installation
Section titled “Post-Installation”External Secrets Operator (ESO) Testing
Section titled “External Secrets Operator (ESO) Testing”-
Connect to Kubernetes Cluster ; i.e w/ Kubeconfig File
Set Kubeconfig File
Terminal window export KUBECONFIG="$HOME/opstella-installation/kubeconfigs/CHANGEME_cluster.yaml" -
Get Pod Status - External Secret Operator (ESO)
Terminal window kubectl get pods -n devsecops-systemExternal Secret Operator (ESO) should be `Running
NAME READY STATUS RESTARTS AGE... (deducted)external-secret-operator-external-secrets-XXXXXXX-YYYY 1/1 Running 0 XdXhexternal-secret-operator-external-secrets-cert-controller-YYYYY 1/1 Running 0 XdXhexternal-secret-operator-external-secrets-webhook-XXXXXXXXX 1/1 Running 0 XdXh -
Check which API version the CRDs serve
Terminal window kubectl get crd clustersecretstores.external-secrets.io \-o jsonpath='{range .spec.versions[*]}{.name}{" served="}{.served}{"\n"}{end}'💡 Chart
0.19.2servesv1only —v1beta1is still listed in the CRD but withserved=false. Anything that submitsexternal-secrets.io/v1beta1, including Secret templates rendered by the Opstella workers, has to be updated tov1; otherwise the resource is never created and the API server reports the kind as unknown.
When Vault uses a private or self-signed certificate
Section titled “When Vault uses a private or self-signed certificate”The operator validates a ClusterSecretStore by calling Vault itself. With a certificate that is
not issued by a publicly trusted CA, the store never becomes ready:
InvalidProviderConfig: unable to validate store: invalid vault credentials:Get "https://vault.example.com/v1/auth/token/lookup-self":tls: failed to verify certificate: x509: certificate signed by unknown authorityEvery ExternalSecret bound to that store then reports SecretSyncedError.
Publish the CA on the cluster where ESO runs:
kubectl create configmap vault-ca --namespace vault \ --from-file=ca.crt=/path/to/vault-ca.crt \ --dry-run=client -o yaml | kubectl apply -f -And point the store at it:
spec: provider: vault: caProvider: type: ConfigMap name: vault-ca key: ca.crt namespace: vaultFinished?
Use the below navigation to proceed