{"id":13644984,"url":"https://github.com/ondat/trousseau","last_synced_at":"2026-03-27T03:55:32.329Z","repository":{"id":37103286,"uuid":"403980771","full_name":"ondat/trousseau","owner":"ondat","description":"Store and access your secrets the Kubernetes native way with any external KMS.","archived":false,"fork":false,"pushed_at":"2023-09-15T05:51:00.000Z","size":24552,"stargazers_count":176,"open_issues_count":28,"forks_count":11,"subscribers_count":7,"default_branch":"main","last_synced_at":"2025-04-17T23:20:45.406Z","etag":null,"topics":["encryption","hashicorp","kms","kubernetes","plugin","secrets","vault"],"latest_commit_sha":null,"homepage":"https://trousseau.io","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ondat.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":"ROADMAP.md","authors":null}},"created_at":"2021-09-07T13:03:50.000Z","updated_at":"2025-01-09T10:24:15.000Z","dependencies_parsed_at":"2024-01-14T09:37:46.355Z","dependency_job_id":null,"html_url":"https://github.com/ondat/trousseau","commit_stats":{"total_commits":202,"total_committers":8,"mean_commits":25.25,"dds":0.400990099009901,"last_synced_commit":"83a8c6eb1518ad13e3e5de7428233b33c29db6de"},"previous_names":[],"tags_count":7,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ondat%2Ftrousseau","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ondat%2Ftrousseau/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ondat%2Ftrousseau/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ondat%2Ftrousseau/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ondat","download_url":"https://codeload.github.com/ondat/trousseau/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":250047989,"owners_count":21366152,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["encryption","hashicorp","kms","kubernetes","plugin","secrets","vault"],"created_at":"2024-08-02T01:02:23.187Z","updated_at":"2025-12-15T02:35:13.337Z","avatar_url":"https://github.com/ondat.png","language":"Go","funding_links":[],"categories":["Go"],"sub_categories":[],"readme":"\u003c!-- \n\u003cp align=\"center\"\u003e\n    \u003cimg src=\"https://github.com/ondat/trousseau/blob/main/assets/logo-horizontal.png\" \u003e\n\u003c/p\u003e --\u003e\n\n\u003ch1 align=\"center\"\u003e\n  \u003cbr\u003e\n  \u003ca href=\"https://github.com/ondat/trousseau/blob/main/assets/logo-horizontal.png\"\u003e\u003cimg src=\"https://github.com/ondat/trousseau/blob/main/assets/logo-horizontal.png\" alt=\"Trousseau\" \u003e\u003c/a\u003e\n  \u003cbr\u003e\n\u003c/h1\u003e\n\n\u003ch4 align=\"center\"\u003eA multi KMS solution supporting the \u003ca href=\"https://kubernetes.io/docs/tasks/administer-cluster/kms-provider/\" target=\"_blank\"\u003eKubernetes Provider Plugin\u003c/a\u003e data encryption for Secrets and ConfigMap in etcd.\u003c/h4\u003e\n\n\n\u003cp align=\"center\"\u003e\n    \u003ca href=\"https://goreportcard.com/report/github.com/ondat/trousseau\"\u003e\n        \u003cimg src=\"https://goreportcard.com/badge/github.com/ondat/trousseau\" /\u003e\u003c/a\u003e\n    \u003ca href=\"https://lgtm.com/projects/g/ondat/trousseau/alerts/\"\u003e\n        \u003cimg alt=\"Total alerts\" src=\"https://img.shields.io/lgtm/alerts/g/ondat/trousseau.svg?logo=lgtm\u0026logoWidth=18\"/\u003e\u003c/a\u003e\n    \u003ca href=\"https://github.com/ondat/trousseau/actions/workflows/e2e-on-pr.yml\" alt=\"end-2-end build\"\u003e\n        \u003cimg src=\"https://github.com/ondat/trousseau/actions/workflows/e2e-on-pr.yml/badge.svg\" /\u003e\u003c/a\u003e\n    \u003ca href=\"https://bestpractices.coreinfrastructure.org/projects/5460\" alt=\"CII Best Practices\"\u003e\n        \u003cimg src=\"https://bestpractices.coreinfrastructure.org/projects/5460/badge\" /\u003e\u003c/a\u003e\n    \u003ca href=\"https://github.com/ondat/trousseau/pkgs/container/trousseau\" alt=\"pulled images\"\u003e\n        \u003cimg src=\"https://img.shields.io/badge/pulled%20images-15.2k-brightgreen\" /\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"#key-features\"\u003eKey Features\u003c/a\u003e •\n  \u003ca href=\"https://github.com/ondat/trousseau/wiki\"\u003eWhy\u003c/a\u003e •\n  \u003ca href=\"https://github.com/ondat/trousseau/wiki/Trousseau-Deployment\"\u003eDocumentation\u003c/a\u003e •\n  \u003ca href=\"https://github.com/ondat/trousseau/wiki/Press\"\u003ePress\u003c/a\u003e •\n  \u003ca href=\"https://www.ondat.io/trousseau\"\u003eHands-on Lab\u003c/a\u003e •\n  \u003ca href=\"#how-to-test\"\u003eHow to test\u003c/a\u003e •\n  \u003ca href=\"https://github.com/orgs/ondat/projects/3\"\u003eRoadmap\u003c/a\u003e •\n  \u003ca href=\"https://github.com/ondat/trousseau/blob/main/CONTRIBUTING.md\"\u003eContributing\u003c/a\u003e •\n  \u003ca href=\"https://github.com/ondat/trousseau/blob/main/LICENSE\"\u003eLicense\u003c/a\u003e •\n  \u003ca href=\"https://github.com/ondat/trousseau/blob/main/SECURITY.md\"\u003eSecurity\u003c/a\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n    \u003cimg src=\"https://github.com/ondat/trousseau/blob/main/assets/Ondat%20Diagram-w-all.png\" height=\"400\"\u003e\n\u003c/p\u003e\n\n## Key Features\n\n* Kubernetes native - no additional CLI tooling, respectful of the concern APIs (like Secrets, ConfigMap, ...)\n* Encryption of sensitive data payload on the fly and store in *etcd* \n* Multi KMS support - one KMS or two KMS at the same time[1]\n  * HashiCorp Vault (Community and Enterprise editions)\n  * AWS Key Vault\n  * Azure KeyVault \n* Redesign to full micro-service architecture decloupling the core components for maximum resiliency and distributed handling\n  * proxy socket to address the Kubernetes API request for encryption/decryption\n  * trousseau to handle the proxy requests and KMS interaction\n  * KMS socket to address the connection towards the KMS providers \n* Prometheus endpoint \n\nNotes: \n\n1. Trousseau will use each KMS provider to encrypt the data and combine both payload within the same secret data section. \n   This design is provide more resiliency in case of a KMS failure by introducing reduancy, and add a fast decryption appraoch with first to response decryption approach along with roundrobin.   \n   At the current stade, there is no option to have multi KMS configured and targeting one specific entry for scenario like multi-tenancy and/or multi-staging environment. This is due to a missing annotation extension within the Kubernetes API that we have address to the Kubernetes project.(see issue [#146](https://github.com/ondat/trousseau/issues/146)) \n\n## How to test\n\n⚠️ for production deployment, consult the [Documentation](https://github.com/ondat/trousseau/wiki)\n\nClone the repo and create your environment file:\n```bash\nTR_VERSION=d3e4f2569b2eddeea992e47dae29a931182379dd\nTR_VERBOSE_LEVEL=1\nTR_SOCKET_LOCATION=/opt/trousseau-kms\nTR_PROXY_IMAGE=ghcr.io/ondat/trousseau:proxy-${TR_VERSION}\nTR_TROUSSEAU_IMAGE=ghcr.io/ondat/trousseau:trousseau-${TR_VERSION}\n# Please configure your KMS plugins, maximum 2\nTR_ENABLED_PROVIDERS=\"--enabled-providers=awskms --enabled-providers=azurekms --enabled-providers=vault\"\nTR_AWSKMS_IMAGE=ghcr.io/ondat/trousseau:awskms-${TR_VERSION}\nTR_AWSKMS_CONFIG=awskms.yaml # For Kubernetes, file must exists only for generation\nTR_AWSKMS_CREDENTIALS=.aws/credentials\nTR_AZUREKMS_IMAGE=ghcr.io/ondat/trousseau:azurekms-${TR_VERSION}\nTR_AZUREKMS_CONFIG=azurekms.yaml # For Kubernetes, file must exists only for generation\nTR_AZUREKMS_CREDENTIALS=config.json\nTR_VAULT_IMAGE=ghcr.io/ondat/trousseau:vault-${TR_VERSION}\nTR_VAULT_ADDRESS=https://127.0.0.1:8200\nTR_VAULT_CONFIG=vault.yaml\n```\n\nCreate shared items on target host:\n```bash\nmkdir -p $TR_SOCKET_LOCATION\nsudo chown 10123:10123 $TR_SOCKET_LOCATION\nsudo chown 10123:10123 $TR_AWSKMS_CREDENTIALS\n# On case you haven't enable Vault agen config generation\nsudo chown 10123:10123 $TR_VAULT_CONFIG\n```\n\nCreate your config files:\n```yaml\n# awskms.yaml\nprofile: profile\nkeyArn: keyArn\n# Optional fields\nroleArn: roleArn\nencryptionContext:\n  foo: bar\n```\n```yaml\n# azurekms.yaml\nconfigFilePath: configFilePath\nkeyVaultName: keyVaultName\nkeyName: keyName\nkeyVersion: keyVersion\n```\n```yaml\n# vault.yaml\nkeyNames:\n-  keyNames\naddress: address\ntoken: token\n```\n\nGenerate service files or manifests:\n```bash\nmake prod:generate:systemd ENV_LOCATION=./bin/trousseau-env\nmake prod:generate:docker-compose ENV_LOCATION=./bin/trousseau-env\nmake prod:generate:kustomize ENV_LOCATION=./bin/trousseau-env\nmake prod:generate:helm ENV_LOCATION=./bin/trousseau-env\n```\n\nVerify output:\n```bash\nls -l generated_manifests/systemd\nls -l generated_manifests/docker-compose\nls -l generated_manifests/kustomize\nls -l generated_manifests/helm\n```\n\nDeploy the application and configure encryption:\n```yaml\nkind: EncryptionConfiguration\napiVersion: apiserver.config.k8s.io/v1\nresources:\n  - resources:\n      - secrets\n    providers:\n      - kms:\n          name: vaultprovider\n          endpoint: unix:///opt/trousseau-kms/proxy.socket\n          cachesize: 1000\n      - identity: {}\n```\n\nReconfigure Kubernetes API server:\n```yaml\nkind: ClusterConfiguration\napiServer:\n  extraArgs:\n    encryption-provider-config: \"/etc/kubernetes/encryption-config.yaml\"\n  extraVolumes:\n  - name: encryption-config\n    hostPath: \"/etc/kubernetes/encryption-config.yaml\"\n    mountPath: \"/etc/kubernetes/encryption-config.yaml\"\n    readOnly: true\n    pathType: File\n  - name: sock-path\n    hostPath: \"/opt/trousseau-kms\"\n    mountPath: \"/opt/trousseau-kms\"\n```\n\nFinally restart Kubernetes API server.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fondat%2Ftrousseau","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fondat%2Ftrousseau","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fondat%2Ftrousseau/lists"}