docs: improve .sops.yaml with public key and encryption guidance

- Document public AGE key for developers
- Add encrypted_regex to only encrypt data fields
- Keep Kubernetes structure readable (apiVersion, kind, metadata)
- Add usage examples in comments
This commit is contained in:
Admin Bot
2026-09-13 09:20:05 +09:00
parent d53b7632cf
commit 67f24ea763
+25 -2
View File
@@ -1,4 +1,27 @@
# SOPS Configuration for secrets encryption
# Public key is safe to commit; private key stays in cluster
creation_rules: creation_rules:
- path_regex: k8s/configmap.yaml # Encrypt secrets, configs, and sensitive files
# Public AGE key - safe to share and commit
# Files matching these patterns will be encrypted automatically with `sops -e`
- path_regex: k8s/(.*secret.*|.*config.*|.*deployment.*\.ya?ml)
age: ***REMOVED*** age: ***REMOVED***
encrypted_regex: '^data' encrypted_regex: '^data|^stringData' # Only encrypt data fields, keep structure readable
# Fallback rule for .enc.yaml files
- path_regex: '.*\.enc\.ya?ml'
age: ***REMOVED***
encrypted_regex: '^data|^stringData'
# To encrypt a file locally:
# sops --encrypt k8s/configmap.yaml > k8s/configmap.yaml
#
# To decrypt and view:
# sops k8s/configmap.yaml
#
# To decrypt to stdout:
# sops --decrypt k8s/configmap.yaml
#
# The private age key is stored in the cluster at:
# kubectl -n argocd get secret sops-age -o jsonpath='{.data.key\.txt}' | base64 -d