{"id":36829766,"url":"https://github.com/crumbhole/argocd-vault-replacer","last_synced_at":"2026-01-12T14:11:25.168Z","repository":{"id":37929504,"uuid":"339147508","full_name":"crumbhole/argocd-vault-replacer","owner":"crumbhole","description":"An Argo CD plugin to replace placeholders in Kubernetes manifests with secrets stored in Hashicorp Vault.","archived":false,"fork":false,"pushed_at":"2025-12-18T02:15:44.000Z","size":1055,"stargazers_count":112,"open_issues_count":23,"forks_count":13,"subscribers_count":2,"default_branch":"main","last_synced_at":"2025-12-21T12:29:45.157Z","etag":null,"topics":["argocd","gitops","kubernetes","secrets","vault"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"bsd-3-clause","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/crumbhole.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2021-02-15T17:03:36.000Z","updated_at":"2025-12-11T09:54:54.000Z","dependencies_parsed_at":"2023-12-12T01:40:37.650Z","dependency_job_id":"558ecedb-c452-4224-bb6f-39af6c1b1bef","html_url":"https://github.com/crumbhole/argocd-vault-replacer","commit_stats":null,"previous_names":["joibel/argocd-vault-replacer"],"tags_count":55,"template":false,"template_full_name":null,"purl":"pkg:github/crumbhole/argocd-vault-replacer","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crumbhole%2Fargocd-vault-replacer","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crumbhole%2Fargocd-vault-replacer/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crumbhole%2Fargocd-vault-replacer/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crumbhole%2Fargocd-vault-replacer/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/crumbhole","download_url":"https://codeload.github.com/crumbhole/argocd-vault-replacer/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crumbhole%2Fargocd-vault-replacer/sbom","scorecard":{"id":309930,"data":{"date":"2025-08-11","repo":{"name":"github.com/crumbhole/argocd-vault-replacer","commit":"b437b312c20b8f9c5683380ff116fe48d4fa8132"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.8,"checks":[{"name":"Code-Review","score":-1,"reason":"Found no human activity in the last 15 changesets","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Maintained","score":5,"reason":"7 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 5","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/ci.yaml:1","Warn: no topLevel permission defined: .github/workflows/codeql-analysis.yml:1","Warn: no topLevel permission defined: .github/workflows/pull.yaml:1","Warn: no topLevel permission defined: .github/workflows/release-helm.yml:1","Warn: no topLevel permission defined: .github/workflows/release.yaml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: BSD 3-Clause \"New\" or \"Revised\" License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/ci.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/ci.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/ci.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/ci.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/ci.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/ci.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/ci.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/ci.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/ci.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pull.yaml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/pull.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/pull.yaml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/pull.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pull.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/pull.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pull.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/pull.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pull.yaml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/pull.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/pull.yaml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/pull.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/pull.yaml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/pull.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/pull.yaml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/pull.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-helm.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/release-helm.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-helm.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/release-helm.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-helm.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/release-helm.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/release.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/release.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/release.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/release.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/release.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/release.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/release.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/crumbhole/argocd-vault-replacer/release.yaml/main?enable=pin","Warn: containerImage not pinned by hash: Dockerfile:1","Warn: containerImage not pinned by hash: Dockerfile:8","Info:   0 out of  16 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of  17 third-party GitHubAction dependencies pinned","Info:   0 out of   2 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/ci.yaml:32"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'main'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact 0.11.11 not signed: https://api.github.com/repos/crumbhole/argocd-vault-replacer/releases/114771666","Warn: release artifact 0.11.10 not signed: https://api.github.com/repos/crumbhole/argocd-vault-replacer/releases/111230199","Warn: release artifact 0.11.9 not signed: https://api.github.com/repos/crumbhole/argocd-vault-replacer/releases/101572041","Warn: release artifact 0.11.8 not signed: https://api.github.com/repos/crumbhole/argocd-vault-replacer/releases/97553825","Warn: release artifact 0.11.7 not signed: https://api.github.com/repos/crumbhole/argocd-vault-replacer/releases/92927538","Warn: release artifact 0.11.11 does not have provenance: https://api.github.com/repos/crumbhole/argocd-vault-replacer/releases/114771666","Warn: release artifact 0.11.10 does not have provenance: https://api.github.com/repos/crumbhole/argocd-vault-replacer/releases/111230199","Warn: release artifact 0.11.9 does not have provenance: https://api.github.com/repos/crumbhole/argocd-vault-replacer/releases/101572041","Warn: release artifact 0.11.8 does not have provenance: https://api.github.com/repos/crumbhole/argocd-vault-replacer/releases/97553825","Warn: release artifact 0.11.7 does not have provenance: https://api.github.com/repos/crumbhole/argocd-vault-replacer/releases/92927538"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"SAST","score":7,"reason":"SAST tool detected but not run on all commits","details":["Info: SAST configuration detected: CodeQL","Warn: 8 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":0,"reason":"34 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GO-2022-0635","Warn: Project is vulnerable to: GO-2022-0646","Warn: Project is vulnerable to: GO-2025-3754 / GHSA-2x5j-vhc8-9cwm","Warn: Project is vulnerable to: GO-2024-2631 / GHSA-c5q2-7r4c-mv6g","Warn: Project is vulnerable to: GO-2025-3485 / GHSA-c6gw-w398-hv78","Warn: Project is vulnerable to: GO-2024-3250 / GHSA-29wx-vh33-7x7r","Warn: Project is vulnerable to: GO-2025-3553 / GHSA-mh63-6h87-95cp","Warn: Project is vulnerable to: GO-2023-2063 / GHSA-v84f-6r39-cpfc","Warn: Project is vulnerable to: GO-2023-2329 / GHSA-4qhc-v8r6-8vwm","Warn: Project is vulnerable to: GO-2023-2399 / GHSA-6p62-6cg9-f5f5","Warn: Project is vulnerable to: GO-2024-2617 / GHSA-r3w7-mfpm-c2vw","Warn: Project is vulnerable to: GO-2024-2921 / GHSA-32cj-5wx4-gq8p","Warn: Project is vulnerable to: GO-2024-2982 / GHSA-2qmw-pvf7-4mw6","Warn: Project is vulnerable to: GO-2024-2690 / GHSA-j2rp-gmqv-frhv","Warn: Project is vulnerable to: GO-2024-3162 / GHSA-jg74-mwgw-v6x3","Warn: Project is vulnerable to: GO-2024-3191 / GHSA-rr8j-7w34-xp5j","Warn: Project is vulnerable to: GO-2024-3246 / GHSA-g233-2p4r-3q7v","Warn: Project is vulnerable to: GO-2025-3662 / GHSA-f9ch-h8j7-8jwg","Warn: Project is vulnerable to: GO-2025-3663 / GHSA-gcqf-f89c-68hv","Warn: Project is vulnerable to: GO-2025-3837 / GHSA-6h4p-m86h-hhgh","Warn: Project is vulnerable to: GO-2025-3836 / GHSA-6c5r-4wfc-3mcx","Warn: Project is vulnerable to: GO-2025-3838 / GHSA-mr4h-qf9j-f665","Warn: Project is vulnerable to: GO-2025-3839 / GHSA-mwgr-84fv-3jh9","Warn: Project is vulnerable to: GO-2025-3840 / GHSA-qgj7-fmq2-6cc4","Warn: Project is vulnerable to: GO-2025-3841 / GHSA-qv3p-fmv3-9hww","Warn: Project is vulnerable to: GO-2025-3842 / GHSA-v6r4-35f9-9rpw","Warn: Project is vulnerable to: GO-2025-3848 / GHSA-7rx2-769v-hrwf","Warn: Project is vulnerable to: GO-2024-3321 / GHSA-v778-237x-gjrc","Warn: Project is vulnerable to: GO-2025-3487 / GHSA-hcg3-q754-cr77","Warn: Project is vulnerable to: GO-2024-3333","Warn: Project is vulnerable to: GO-2025-3503 / GHSA-qxp5-gwg8-xv66","Warn: Project is vulnerable to: GO-2025-3595 / GHSA-vvgc-356p-c3xw","Warn: Project is vulnerable to: GO-2025-3488 / GHSA-6v2p-p543-phr9","Warn: Project is vulnerable to: GO-2024-2611 / GHSA-8r3f-844c-mc37"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-17T22:58:18.886Z","repository_id":37929504,"created_at":"2025-08-17T22:58:18.886Z","updated_at":"2025-08-17T22:58:18.886Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28340384,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-12T12:22:26.515Z","status":"ssl_error","status_checked_at":"2026-01-12T12:22:10.856Z","response_time":98,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["argocd","gitops","kubernetes","secrets","vault"],"created_at":"2026-01-12T14:11:24.550Z","updated_at":"2026-01-12T14:11:25.154Z","avatar_url":"https://github.com/crumbhole.png","language":"Go","funding_links":[],"categories":["Secret Management"],"sub_categories":[],"readme":"# argocd-vault-replacer\nA  plugin for [ArgoCD lovely plugin](https://github.com/crumbhole/argocd-lovely-plugin) to replace placeholders in Kubernetes manifests with secrets stored in [Hashicorp Vault](https://www.vaultproject.io/). The binary will scan the current directory recursively for any .yaml (or .yml if you're so inclined) files, or take yaml from stdin, and attempt to replace strings of the form `\u003csecret:/store/data/path~key\u003e` with those obtained from a Vault kv2 store.\n\nIf you use it as the reader in a unix pipe, it will instead read from stdin. In this scenario it can post-process the output of another tool, such as Kustomize or Helm.\n\nThis plugin used to be available as a direct plugin to ArgoCD, but has not been adapted for ArgoCD 2.7's need for running as a sidecar. If this need is one you have, please raise an issue or ideally a PR. The authors now only use this through lovely plugin.\n\nNote: This and previous versions of this plugin only talk to vault, and hence \u003csecret:...\u003e can also be specified as \u003cvault:...\u003e. Future plans may include other secret providers.\n\n\u003cimg src=\"assets/images/argocd-vault-replacer-diagram.png\"\u003e\n\n## Why?\n- Allows you to invest in Git Ops without compromising secret security.\n  - Configuration goes into Git.\n  - Secrets go into Vault.\n- yaml-agnostic. Supports any Kubernetes resource type as long as it can be expressed in .yaml (or .yml).\n  - Also supports Argo CD-managed Kustomize and Helm charts\n- Native Vault-Kubernetes authentication means you don't have to renew tokens or store/passthrough approle role-ids and secret-ids.\n\n#Installing\n\n## As a lovely plugin\n\nInstall [ArgoCD lovely plugin](https://github.com/crumbhole/argocd-lovely-plugin) using the ghcr.io/crumbhole/argocd-lovely-plugin-cmp-vault image. Setup your vault-replacer environment variables in that sidecar.\n\n## Installing as an Argo CD Plugin (deprecated)\nYou can use [our Kustomization example](https://github.com/crumbhole/argocd-vault-replacer/tree/main/examples/kustomize/argocd) to install Argo CD and to bootstrap the installation of the plugin at the same time. However the steps below will detail what is required should you wish to do things more manually. The Vault authentication setup cannot be done with Kustomize and must be done manually.\n\n## Vault Kubernetes Authentication\nYou will need to set up the Vault Kubernetes authentication method for your cluster.\n\nYou will need to create a service account. In this example, our service account will be called 'argocd'. Our example creates the serviceAccount in the argocd namespace:\n\n```YAML\napiVersion: v1\nkind: ServiceAccount\nmetadata:\n  name: argocd\n  namespace: argocd\n```\n\nFor Kubernetes [version 1.24](https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.24.md#urgent-upgrade-notes) and newer there is no automatic service account token generated. This must be generated as a secret and the service account must refer to said secret:\n\n```YAML\napiVersion: v1\nkind: ServiceAccount\nmetadata:\n  namespace: argocd\n  name: argocd\nsecrets:\n- name: argocd-sa-token\n---\napiVersion: v1\nkind: Secret\nmetadata:\n  namespace: argocd\n  name: argocd-sa-token\n  annotations:\n    kubernetes.io/service-account.name: argocd\ntype: kubernetes.io/service-account-token\n```\n\nYou will need to tell Vault about this Service Account and what policy/policies it maps to:\n\n```\nvault write auth/kubernetes/role/argocd \\\n        bound_service_account_names=argocd \\\n        bound_service_account_namespaces=argocd \\\n        policies=argocd \\\n        ttl=1h\n```\nThis is better documented by Hashicorp themselves, do please refer to [their documentation](https://www.vaultproject.io/docs/auth/kubernetes).\n\nLastly, you will need to modify the argocd-repo-server deployment to use your new serviceAccount, and to allow the serviceAccountToken to automount when the pod starts up. You must patch the deployment with:\n```YAML\napiVersion: apps/v1\nkind: Deployment\nmetadata:\n  name: patch-serviceAccount\nspec:\n  template:\n    spec:\n      serviceAccount: argocd\n      automountServiceAccountToken: true\n```\n## Plugin Installation\nIn order to install the plugin into Argo CD, you can either build your own Argo CD image with the plugin already inside, or make use of an Init Container to pull the binary. Argo CD's documentation provides further information how to do this: https://argoproj.github.io/argo-cd/operator-manual/custom_tools/\n\nWe offer a pre-built init container that moves the binary into /custom-tools on startup, so an init container manifest will look something like this:\n```YAML\ncontainers:\n- name: argocd-repo-server\n  volumeMounts:\n  - name: custom-tools\n    mountPath: /usr/local/bin/argocd-vault-replacer\n    subPath: argocd-vault-replacer\n  envFrom:\n    - secretRef:\n        name: argocd-vault-replacer-credentials\nvolumes:\n- name: custom-tools\n  emptyDir: {}\ninitContainers:\n- name: argocd-vault-replacer-install\n  image: ghcr.io/crumbhole/argocd-vault-replacer\n  imagePullPolicy: Always\n  volumeMounts:\n    - mountPath: /custom-tools\n      name: custom-tools\n```\nThe above references a Kubernetes secret called \"argocd-vault-replacer-credentials\". We use this to pass through the mandatory ARGOCD_ENV_VAULT_ADDR environment variable. We could also use it to pass through optional variables too\n```YAML\napiVersion: v1\ndata:\n  ARGOCD_ENV_VAULT_ADDR: aHR0cHM6Ly92YXVsdC5leGFtcGxlLmJpeg==\nkind: Secret\nmetadata:\n  name: argocd-vault-replacer-credentials\n  namespace: argocd\ntype: Opaque\n```\n\nEnvironment Variables:\n\n| Environment Variable Name | Purpose                                                                                                                               | Example                           | Mandatory? |\n|-------------------------- |-------------------------------------------------------------------------------------------------------------------------------------- |---------------------------------- |----------- |\n| ARGOCD_ENV_VAULT_ADDR                | Provides argocd-vault-replacer with the URL to your Hashicorp Vault instance.                                                         | https://vault.examplecompany.biz  | Y\n| ARGOCD_ENV_VAULT_TOKEN               | A valid Vault authentication token. This should only be used for debugging. This won't work inside kubernetes if you have a service account token available, as the tool considers a service account token that fails to authenticate a complete failure. You'll have to run a pod without a service account if you want to use this. The token cannot be renewed by the tool so if it expires, the tool will stop.                                                          | s.LLijB190n3c8s4fiSuvTdVNM        | N\n| ARGOCD_ENV_VAULT_ROLE                | The name of the role for the VAULT_TOKEN. This defaults to 'argocd'.                                                                  | argocd-role                       | N\n| ARGOCD_ENV_VAULT_AUTH_PATH           | Determines the authorization path for Kubernetes authentication. This defaults to 'kubernetes' so will probably not need configuring. | kubernetes                        | N\n\nBefore Argo CD 2.4 these did not need to be prefixed with ARGOCD_ENV_, and the current version will accept either type, with precedence given to the ARGOCD_ENV_ version.\n\nIf you are passing the configuration in as application environment variables in Argo CD 2.4 or higher you must not put the ARGOCD_ENV_ prefix on them, as Argo CD does that for you.\n\n## Plugin Configuration\nAfter installing the plugin into the /custom-tools/ directory, you need to register it inside the Argo CD config. Declaratively, you can add this to your argocd-cm configmap file:\n\n```YAML\nconfigManagementPlugins: |-\n  - name: argocd-vault-replacer\n    generate:\n      command: [\"argocd-vault-replacer\"]\n  - name: kustomize-argocd-vault-replacer\n    generate:\n      command: [\"sh\", \"-c\"]\n      args: [\"kustomize build . | argocd-vault-replacer\"]\n  - name: helm-argocd-vault-replacer\n    init:\n      command: [\"/bin/sh\", \"-c\"]\n      args: [\"helm dependency build\"]\n    generate:\n      command: [sh, -c]\n      args: [\"helm template -n $ARGOCD_APP_NAMESPACE $ARGOCD_APP_NAME . | argocd-vault-replacer\"]\n```\n\nThis is documented further in Argo CD's documentation: https://argoproj.github.io/argo-cd/user-guide/config-management-plugins/\n\n* argo-vault-replacer as a plugin will only work on a directory full of straight .yaml files.\n* kustomize-argo-vault-replacer as a plugin will take the output of kustomize and then do vault-replacement on those files. Note: This won't allow you to use the argo application kustomization options, it just runs a straight kustomize.\n* helm-argo-vault-replacer as a plugin will take the output of Helm and then do vault-replacement on those files. Note: This won't allow you to use the argo application Helm options, it just runs a straight Helm with the default argo name.\n## Testing\n\nCreate a test yaml file that will be used to pull a secret from Vault. The below will look in Vault for /path/to/your/secret and will return the key 'secretkey', it will then base64 encode that value. As we are using a Vault kv2 store, we must include ..`/data/`.. in our path:\n\n```YAML\napiVersion: v1\nkind: Secret\nmetadata:\n  name: argocd-vault-replacer-secret\ndata:\n  sample-secret: \u003csecret:path/data/to/your/secret~secretkey|base64\u003e\ntype: Opaque\n```\nIn this example, we pushed the above to `https://github.com/replace-me/argocd-vault-replacer-test/argocd-vault-replacer-secret.yaml`\n\nWe then deploy this as an Argo CD application, making sure we tell the application to use the argocd-vault-replacer plugin:\n\n```YAML\napiVersion: argoproj.io/v1alpha1\nkind: Application\nmetadata:\n  name: argocd-vault-replacer-test\nspec:\n  destination:\n    server: 'https://kubernetes.default.svc'\n    namespace: argocd-vault-replacer-test\n  syncPolicy:\n    automated:\n      prune: true\n      selfHeal: true\n    syncOptions:\n      - CreateNamespace=true\n  source:\n    repoURL: 'https://github.com/replace-me'\n    path: argocd-vault-replacer-test\n    plugin:\n      name: argocd-vault-replacer\n    targetRevision: HEAD\n```\n\nThere are further examples to use for testing in the [examples directory](https://github.com/crumbhole/argocd-vault-replacer/tree/main/examples/).\n## A deep-dive on authentication\n\nThe tool only has two methods of authenticating with Vault:\n* Using kubernetes authentication method https://github.com/hashicorp/vault/blob/master/website/content/docs/auth/kubernetes.mdx\n* Using a token, which is only intended for debugging\n\nBoth methods expect the environment variable ARGOCD_ENV_VAULT_ADDR to be set.\n\nIt will attempt to use kubernetes authentication through an appropriate service account first, and complain if that doesn't work. It will then use VAULT_TOKEN which should be a valid token. This tool has no way of renewing a token or obtaining one other than through a kubernetes service account.\n\nTo use the kubernetes service account your pod should be running with the appropriate service account, and will try to obtain the JWT token from /var/run/secrets/kubernetes.io/serviceaccount/token which is the default location.\n\nIt will use the environment variable ARGOCD_ENV_VAULT_ROLE as the name of the role for that token, defaulting to \"argocd\".\nIt will use the environment variable ARGOCD_ENV_VAULT_AUTH_PATH to determine the authorization path for kubernetes authentication. This defaults in this tool and in vault to \"kubernetes\" so will probably not need configuring.\n\nThe vault authentication token that the tool gets will not be cached, nor will it be renewed. It is expected that the token will last for the length of the tool's invokation, which is usually a reasonable assumption in the use case for which it was designed.\n\n## Valid vault paths\n\nCurrently the only valid 'URL style' to a path is\n\n`\u003csecret:/store/data/path~key~key~key|modifier|modifier\u003e`\n\nYou must put ..`/data/`.. into the path. If your path or key contains `~`, `\u003c`, `\u003e` or `|` you must URL escape it. If your path or key has one or more leading or trailing spaces or tabs you must URL escape them you weirdo.\n\nAny base64 encoded strings will be decoded and subsitution will happen within them (and end up being base64 encoded afterwards). These base64 strings require some form of whitespace (any non-base64 valid character) around them in order to be detected.\n\n## Modifiers\n\nYou can modify the resulting output with the following modifiers:\n\n* base64: Will base64 encode the secret. Use for data: sections in kubernetes secrets.\n* Other modifiers are documented in [docs/modifiers](docs/modifiers.md)\n\n## Rotating secrets in Vault\nCurrently, because Argo CD cannot monitor Vault for changes, when you change a secret in Vault, Argo CD will not automatically update your Kubernetes resources with the new value. You will have to either push a change to git, use the Hard Refresh option in Argo CD, or force Argo CD to heal by deleting the Kubernetes resource in question.\n\n## Development\n\nThis project only builds with go 1.18 (and presumably later when later happens).\n\nYou can build in the docker container, or look at the [Makefile] to build and test conventionally.\n\nPlease add tests for any new/changed functionality.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcrumbhole%2Fargocd-vault-replacer","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fcrumbhole%2Fargocd-vault-replacer","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcrumbhole%2Fargocd-vault-replacer/lists"}