KSECRET(1)toolbelt manualKSECRET(1)

ksecret

Show a Secret decoded, one key or all.

Synopsis

ksecret [-n NAMESPACE] [--show-keys] NAME [-- kubectl options]
ksecret [-n NAMESPACE] [-c] NAME KEY [-- kubectl options]

Description

A Secret keeps each value in base64, so kubectl get secret -o yaml shows strings you cannot read. The usual fix is a jsonpath and a pipe to base64 -d for every key. ksecret decodes every key at once and prints them in aligned columns, with the Secret's namespace, name, type and key count on top.

Values print as text when they are text. A value over several lines is indented under the first, so a config file stored in a Secret stays readable. An empty value shows (empty). A binary value, such as a keystore, is not printed. ksecret gives its size and the command that saves it to a file.

TLS Secrets get a summary instead of a PEM block. A certificate shows its subject, the date it expires and the days left, read with openssl. A private key shows its type and size and stays hidden, since it is the one value you do not want in your scrollback or a screen share. --show-keys prints it.

With a KEY, ksecret prints that one value and nothing else, byte for byte. That makes it safe in scripts and pipes, such as ksecret db-creds DB_PASSWORD | psql .... A newline is added only when the output is a terminal. A binary value is not printed to a terminal, since its raw bytes can garble it. ksecret exits 1 and prints the command that saves it to a file instead. A pipe or a redirect still gets the bytes. -c copies the value to the clipboard with clip and prints only how many bytes it copied, so the value never shows on screen.

ksecret only reads. It never changes a Secret.

Options

OptionWhat it does
-n, --namespace NSThe Secret's namespace. The context's own namespace by default.
-c, --copyCopy the value of KEY to the clipboard and print nothing on stdout. Needs a KEY.
--show-keysPrint private keys in full when showing every key.
-q, --quietNo header line.
-v, --verbosePrint each kubectl command before it runs.
-h, --helpShow the help.

What each value shows

ValueWhat ksecret prints
Text on one lineThe text.
Text over several linesThe lines, indented under the value column.
Empty(empty)
Binary, such as a keystorebinary, N bytes, save it with: ksecret -n NS NAME KEY > file
A PEM certificateCN=..., expires DATE, N days left, or CN=..., expired DATE, N days ago
A PEM private keyRSA 2048 private key, hidden, use --show-keys, and the same for EC and Ed25519 keys
An encrypted or OpenSSH private keyencrypted private key, hidden, ... or OpenSSH private key, hidden, ...

Without openssl, a certificate shows PEM certificate, N bytes, and a private key shows private key, hidden, use --show-keys with no size.

A single KEY always prints its exact bytes, whatever they are.

Safety

Pass-through

Options after -- go to kubectl get secret.

ksecret db-creds -- --context kind-kind
ksecret -n shop shop-tls -- --kubeconfig ~/.kube/lab.yaml

Needs

kubectl, jq and base64, from coreutils. openssl, optional, for certificate and key details. clip, from this toolbelt, for -c.

The account behind your context needs get on secrets in the namespace. Many clusters give that only to admins.

Examples

Every key of a Secret

ksecret -n shop db-creds
secret shop/db-creds, type Opaque, 6 keys
DB_HOST      postgres.shop.svc.cluster.local
DB_USER      shop
DB_PASSWORD  fake-pass-123
blob         binary, 4 bytes, save it with: ksecret -n shop db-creds blob > file
app.conf     line one
             line two
empty        (empty)

A TLS Secret

ksecret -n shop shop-tls
secret shop/shop-tls, type kubernetes.io/tls, 2 keys
tls.crt  CN=shop.example.com, expires 2026-12-18, 79 days left
tls.key  RSA 2048 private key, hidden, use --show-keys

With --show-keys, the key prints as PEM, indented like any value over several lines.

ksecret -n shop --show-keys shop-tls
secret shop/shop-tls, type kubernetes.io/tls, 2 keys
tls.crt  CN=shop.example.com, expires 2026-12-18, 79 days left
tls.key  -----BEGIN PRIVATE KEY-----
         MIIEvQIBADANBgkqhkiG9w0BAQEFAASC...

One value, for a script

ksecret -n shop db-creds DB_USER
shop
ksecret -n shop db-creds DB_USER | od -c
0000000   s   h   o   p
0000004

The second command shows that no newline was added when the output went to a pipe.

Copy a password without showing it

ksecret -c -n shop db-creds DB_PASSWORD
ksecret: copied DB_PASSWORD (13 bytes) to the clipboard

A typo in the name

ksecret -n shop db-cred
ksecret: no Secret db-cred in shop. Did you mean db-creds?
ksecret -n shop db-creds NOPE
ksecret: no key NOPE in secret shop/db-creds. Keys are DB_HOST, DB_USER, DB_PASSWORD, blob, app.conf and empty

What it runs

ksecret -v -n shop db-creds DB_HOST
+ kubectl get secret db-creds -n shop -o json
ksecret: secret shop/db-creds has 6 keys
postgres.shop.svc.cluster.local

Troubleshooting

ksecret: the cluster refused: secrets "db-creds" is forbidden ...
Your account may not read Secrets in that namespace. That is common and deliberate. Ask for a Role with get on secrets, or use an admin context with -- --context NAME.
ksecret: -c copies one value, name the key
-c needs a KEY, since copying every key at once would give you one long blob.
clip could not copy the value
clip found no clipboard. Over ssh or on a server with no desktop, print the value and pipe it where it goes.

Exit status

CodeMeaning
0It printed or copied the values.
1No such Secret or key, a binary value asked for on a terminal, clip failed, or kubectl failed.
2Bad usage, such as -c without a KEY.
3kubectl, jq or base64 is missing.

See also

clip, jwtpeek, certcheck, kyaml, base64(1), openssl-x509(1)