How to use Kubernetes External Secrets Operator with Secret Manager
Configure External Secrets Operator to store Kubernetes secrets on the OVHcloud Secret Manager
Objective
This guide explains how to set up the Kubernetes External Secrets Operator to use the OVHcloud Secret Manager as a provider.
This guide describes how to use External Secrets Operator with the HashiCorp Vault provider to access the OVHcloud Secret Manager through the HashiCorp Vault KV2-compatible API.
OVHcloud now provides a native External Secrets Operator provider. We recommend using it for new deployments. See the OVHcloud provider documentation.
Requirements
- An OVHcloud customer account.
- You must have ordered an OKMS domain or created a first secret.
- An authentication method configured for the OKMS data plane (this guide uses a Personal Access Token).
- A Managed Kubernetes Service cluster.
Instructions
Set up the Secret Manager
To allow access to the Secret Manager you will need to have a token, the region and okms-id of your Secret Manager.
Credential creation
Create an IAM local user with access rights on your domain, or use a service account. See OKMS authentication methods for the full setup and IAM policy templates.
The user should be a member of a group with the ADMIN role. If you are using IAM policies instead, the user should have at least the following rights on the OKMS domain:
okms:apikms:secret/createokms:apikms:secret/version/getDataokms:apikms:secret/getokms:apiovh:secret/get
Alternatively, it's possible to create a user using OVHcloud CLI:
Then create a Personal Acces Token (PAT) user_pat:
Use the following API call:
With the following payload (fill it in with your own values):
The API will answer with:
Keep the value of the token field as it will never be prompted again and will be used to authenticate to the Secret Manager as user_pat.
Secret Manager information
You will also need the region and the okms-id of the OKMS domain you want to use. This ID and this region can be found in the or via the OVHcloud CLI:
Set up the Secret Provider in Kubernetes
Install the External Secrets Operator (ESO) on your Kubernetes cluster
Check that the ESO is running:
Create a secret containing the PAT
Create a secret.yaml file:
The stringData field accepts the raw token โ Kubernetes base64-encodes it when storing the secret. If you prefer to use the data field instead, you must base64-encode the token yourself first (echo -n "<token>" | base64).
Apply it with the kubectl apply -f secret.yaml command.
Alternatively, if the user_pat is stored in the PAT_TOKEN environment variable, create the secret directly with kubectl, which also handles the encoding:
The secret should have been created:
When you inspect the secret with kubectl get secret ovhcloud-vault-token -n external-secrets -o yaml, the value appears under data, base64-encoded.
Configure the External Secrets Operator
First, set up a ClusterSecretStore that is responsible of the synchronization with the Secret Manager.
We configure the SecretStore using HashiCorp Vault with token authentification and with the OKMS endpoint as backend.
Add the user_pat as a secret to be able to use it in the charts.
To define a new ClusterSecretStore resource, create a clustersecretstore.yaml file with the following content:
Only token authentication is supported.
This integration works with a SecretStore as well.
The region name can be translated from your region location using:
As an example for Europe (France - Paris), the OKMS endpoint is eu-west-par.okms.ovh.net.
Deploy the resource in your cluster:
Use the External Secrets Operator
Once the ClusterSecretStore is set up you can define the ExternalSecret that comes from the secret manager.
Create an externalsecret.yaml file with this content:
Apply the resource in your cluster:
It will create a Kubernetes Secret object.
For any additional information on how to manage the External Secrets Operator, refer to the dedicated documentation, using the HashiCorp Vault provider: https://external-secrets.io/latest/.
Go further
Use Secret Manager with REST API
Join our community of users.