Dagger
Search

sops

This module provides functionality for working with [Mozilla SOPS](https://github.com/getsops/sops)
in a Dagger pipeline. It supports generating AGE keys, encrypting and decrypting files.
Files are mounted into a container and processed using the `sops` CLI tool.

Functions:
- GenerateAgeKey: Generates a new AGE key pair
- GenerateSopsConfig: Generates a .sops.yaml configuration file
- Encrypt: Encrypts a plaintext file using SOPS with an AGE key
- Decrypt: Decrypts a SOPS-encrypted file and returns the decrypted file

Installation

dagger install github.com/stuttgart-things/dagger/sops@v0.137.0

Entrypoint

Return Type
Sops
Example
dagger -m github.com/stuttgart-things/dagger/sops@2eb7e67e3dc669ddf1d66c7325db4dd14bfb3d25 call \
func (m *MyModule) Example() *dagger.Sops  {
	return dag.
			Sops()
}
@function
def example() -> dagger.Sops:
	return (
		dag.sops()
	)
@func()
example(): Sops {
	return dag
		.sops()
}

Types

Sops 🔗

baseImage() 🔗

Return Type
String !
Example
dagger -m github.com/stuttgart-things/dagger/sops@2eb7e67e3dc669ddf1d66c7325db4dd14bfb3d25 call \
 base-image
func (m *MyModule) Example(ctx context.Context) string  {
	return dag.
			Sops().
			Baseimage(ctx)
}
@function
async def example() -> str:
	return await (
		dag.sops()
		.baseimage()
	)
@func()
async example(): Promise<string> {
	return dag
		.sops()
		.baseImage()
}

agePublicKey() 🔗

AgePublicKey derives the public key (age1…) from an AGE private key (age-keygen -y).

Return Type
String !
Arguments
NameTypeDefault ValueDescription
ageKeySecret !-

AGE private key (AGE-SECRET-KEY-1…) or a key file with comments

Example
dagger -m github.com/stuttgart-things/dagger/sops@2eb7e67e3dc669ddf1d66c7325db4dd14bfb3d25 call \
 age-public-key --age-key env:MYSECRET
func (m *MyModule) Example(ctx context.Context, ageKey *dagger.Secret) string  {
	return dag.
			Sops().
			Agepublickey(ctx, ageKey)
}
@function
async def example(agekey: dagger.Secret) -> str:
	return await (
		dag.sops()
		.agepublickey(agekey)
	)
@func()
async example(ageKey: Secret): Promise<string> {
	return dag
		.sops()
		.agePublicKey(ageKey)
}

decrypt() 🔗

Decrypt decrypts a SOPS-encrypted file using an AGE key. Returns the decrypted file.

Return Type
File !
Arguments
NameTypeDefault ValueDescription
ageKeySecret !-No description provided
encryptedFileFile !-No description provided
sopsConfigFile -

.sops.yaml to use

extractString -

Return a single value instead of the whole file, as a sops path, e.g. ‘[“stringData”][“KEY”]’

Example
dagger -m github.com/stuttgart-things/dagger/sops@2eb7e67e3dc669ddf1d66c7325db4dd14bfb3d25 call \
 decrypt --age-key env:MYSECRET --encrypted-file file:path
func (m *MyModule) Example(ageKey *dagger.Secret, encryptedFile *dagger.File) *dagger.File  {
	return dag.
			Sops().
			Decrypt(ageKey, encryptedFile)
}
@function
def example(agekey: dagger.Secret, encryptedfile: dagger.File) -> dagger.File:
	return (
		dag.sops()
		.decrypt(agekey, encryptedfile)
	)
@func()
example(ageKey: Secret, encryptedFile: File): File {
	return dag
		.sops()
		.decrypt(ageKey, encryptedFile)
}

encrypt() 🔗

Encrypt encrypts a file with SOPS for the given AGE recipient(s). With –sops-config or –encrypted-regex only matching values are encrypted, so a Kubernetes Secret keeps apiVersion, kind and metadata readable.

Return Type
File !
Arguments
NameTypeDefault ValueDescription
ageKeySecret !-

AGE public key(s), comma-separated

plaintextFileFile !-No description provided
fileExtensionString "yaml"

e.g., “yaml”, “json”, “env”

sopsConfigFile -

.sops.yaml whose creation_rules apply (recipients, encrypted_regex, …)

encryptedRegexString -

Encrypt only the values whose keys match, e.g. ‘^(data|stringData)$’ for a Kubernetes Secret that Flux applies. Overrides the config.

Example
dagger -m github.com/stuttgart-things/dagger/sops@2eb7e67e3dc669ddf1d66c7325db4dd14bfb3d25 call \
 encrypt --age-key env:MYSECRET --plaintext-file file:path
func (m *MyModule) Example(ageKey *dagger.Secret, plaintextFile *dagger.File) *dagger.File  {
	return dag.
			Sops().
			Encrypt(ageKey, plaintextFile)
}
@function
def example(agekey: dagger.Secret, plaintextfile: dagger.File) -> dagger.File:
	return (
		dag.sops()
		.encrypt(agekey, plaintextfile)
	)
@func()
example(ageKey: Secret, plaintextFile: File): File {
	return dag
		.sops()
		.encrypt(ageKey, plaintextFile)
}

generateAgeKey() 🔗

GenerateAgeKey generates a new AGE key pair using age-keygen. Returns the key file containing both the public key (in a comment) and the private key.

Never cached: with Dagger’s function and exec cache, every call on the same engine used to return the same private key.

Return Type
File !
Example
dagger -m github.com/stuttgart-things/dagger/sops@2eb7e67e3dc669ddf1d66c7325db4dd14bfb3d25 call \
 generate-age-key
func (m *MyModule) Example() *dagger.File  {
	return dag.
			Sops().
			Generateagekey()
}
@function
def example() -> dagger.File:
	return (
		dag.sops()
		.generateagekey()
	)
@func()
example(): File {
	return dag
		.sops()
		.generateAgeKey()
}

generateSopsConfig() 🔗

GenerateSopsConfig generates a .sops.yaml configuration file with creation rules for the given AGE key. The fileExtensions parameter accepts a comma-separated list of extensions (e.g., “yaml,json,env”). If not provided, defaults to “yaml,json”.

Return Type
File !
Arguments
NameTypeDefault ValueDescription
agePublicKeyString !-No description provided
fileExtensionsString -No description provided
encryptedRegexString -

Encrypt only the values whose keys match, e.g. ‘^(data|stringData)$’ for Kubernetes Secrets that Flux applies. Added to every rule.

pathRegexString -

One rule for files matching this regex, e.g. ‘.*.enc.yaml$’, instead of one rule per file extension

Example
dagger -m github.com/stuttgart-things/dagger/sops@2eb7e67e3dc669ddf1d66c7325db4dd14bfb3d25 call \
 generate-sops-config --age-public-key string
func (m *MyModule) Example(agePublicKey string) *dagger.File  {
	return dag.
			Sops().
			Generatesopsconfig(agePublicKey)
}
@function
def example(agepublickey: str) -> dagger.File:
	return (
		dag.sops()
		.generatesopsconfig(agepublickey)
	)
@func()
example(agePublicKey: string): File {
	return dag
		.sops()
		.generateSopsConfig(agePublicKey)
}

set() 🔗

Set changes one value in a SOPS-encrypted file without writing the rest out in plaintext (sops set). Returns the updated encrypted file.

The value never becomes an operation argument: it is JSON-encoded here, wrapped as a Secret and handed to sops with –value-file.

Return Type
File !
Arguments
NameTypeDefault ValueDescription
encryptedFileFile !-

SOPS-encrypted file to change

pathString !-

sops path of the value, e.g. ‘[“stringData”][“KEY”]’

valueSecret !-

The new value. Treated as a string unless –json-value is set.

ageKeySecret !-

AGE private key that can decrypt the file

jsonValueBoolean -

The value is already JSON (an object, a number, …) and is set as is

Example
dagger -m github.com/stuttgart-things/dagger/sops@2eb7e67e3dc669ddf1d66c7325db4dd14bfb3d25 call \
 set --encrypted-file file:path --path string --value env:MYSECRET --age-key env:MYSECRET
func (m *MyModule) Example(encryptedFile *dagger.File, path string, value *dagger.Secret, ageKey *dagger.Secret) *dagger.File  {
	return dag.
			Sops().
			Set(encryptedFile, path, value, ageKey)
}
@function
def example(encryptedfile: dagger.File, path: str, value: dagger.Secret, agekey: dagger.Secret) -> dagger.File:
	return (
		dag.sops()
		.set(encryptedfile, path, value, agekey)
	)
@func()
example(encryptedFile: File, path: string, value: Secret, ageKey: Secret): File {
	return dag
		.sops()
		.set(encryptedFile, path, value, ageKey)
}

updateKeys() 🔗

UpdateKeys re-encrypts a SOPS file’s data key for the recipients the .sops.yaml now lists (sops updatekeys -y), e.g. after adding a recipient. Returns the updated encrypted file.

Return Type
File !
Arguments
NameTypeDefault ValueDescription
encryptedFileFile !-

SOPS-encrypted file to update

sopsConfigFile !-

.sops.yaml with the new recipients. Its creation rule must match the file’s name.

ageKeySecret !-

AGE private key that can decrypt the file

Example
dagger -m github.com/stuttgart-things/dagger/sops@2eb7e67e3dc669ddf1d66c7325db4dd14bfb3d25 call \
 update-keys --encrypted-file file:path --sops-config file:path --age-key env:MYSECRET
func (m *MyModule) Example(encryptedFile *dagger.File, sopsConfig *dagger.File, ageKey *dagger.Secret) *dagger.File  {
	return dag.
			Sops().
			Updatekeys(encryptedFile, sopsConfig, ageKey)
}
@function
def example(encryptedfile: dagger.File, sopsconfig: dagger.File, agekey: dagger.Secret) -> dagger.File:
	return (
		dag.sops()
		.updatekeys(encryptedfile, sopsconfig, agekey)
	)
@func()
example(encryptedFile: File, sopsConfig: File, ageKey: Secret): File {
	return dag
		.sops()
		.updateKeys(encryptedFile, sopsConfig, ageKey)
}