sops
This module provides functionality for working with [Mozilla SOPS](https://github.com/getsops/sops)in a Dagger pipeline. It supports generating AGE keys, encrypting and decrypting files.
Files are mounted into a container and processed using the `sops` CLI tool.
Functions:
- GenerateAgeKey: Generates a new AGE key pair
- GenerateSopsConfig: Generates a .sops.yaml configuration file
- Encrypt: Encrypts a plaintext file using SOPS with an AGE key
- Decrypt: Decrypts a SOPS-encrypted file and returns the decrypted file
Installation
dagger install github.com/stuttgart-things/dagger/sops@v0.137.0Entrypoint
Return Type
Sops Example
dagger -m github.com/stuttgart-things/dagger/sops@2eb7e67e3dc669ddf1d66c7325db4dd14bfb3d25 call \
func (m *MyModule) Example() *dagger.Sops {
return dag.
Sops()
}@function
def example() -> dagger.Sops:
return (
dag.sops()
)@func()
example(): Sops {
return dag
.sops()
}Types
Sops 🔗
baseImage() 🔗
Return Type
String ! Example
dagger -m github.com/stuttgart-things/dagger/sops@2eb7e67e3dc669ddf1d66c7325db4dd14bfb3d25 call \
base-imagefunc (m *MyModule) Example(ctx context.Context) string {
return dag.
Sops().
Baseimage(ctx)
}@function
async def example() -> str:
return await (
dag.sops()
.baseimage()
)@func()
async example(): Promise<string> {
return dag
.sops()
.baseImage()
}agePublicKey() 🔗
AgePublicKey derives the public key (age1…) from an AGE private key
(age-keygen -y).
Return Type
String !Arguments
| Name | Type | Default Value | Description |
|---|---|---|---|
| ageKey | Secret ! | - | AGE private key (AGE-SECRET-KEY-1…) or a key file with comments |
Example
dagger -m github.com/stuttgart-things/dagger/sops@2eb7e67e3dc669ddf1d66c7325db4dd14bfb3d25 call \
age-public-key --age-key env:MYSECRETfunc (m *MyModule) Example(ctx context.Context, ageKey *dagger.Secret) string {
return dag.
Sops().
Agepublickey(ctx, ageKey)
}@function
async def example(agekey: dagger.Secret) -> str:
return await (
dag.sops()
.agepublickey(agekey)
)@func()
async example(ageKey: Secret): Promise<string> {
return dag
.sops()
.agePublicKey(ageKey)
}decrypt() 🔗
Decrypt decrypts a SOPS-encrypted file using an AGE key. Returns the decrypted file.
Return Type
File !Arguments
| Name | Type | Default Value | Description |
|---|---|---|---|
| ageKey | Secret ! | - | No description provided |
| encryptedFile | File ! | - | No description provided |
| sopsConfig | File | - | .sops.yaml to use |
| extract | String | - | Return a single value instead of the whole file, as a sops path, e.g. ‘[“stringData”][“KEY”]’ |
Example
dagger -m github.com/stuttgart-things/dagger/sops@2eb7e67e3dc669ddf1d66c7325db4dd14bfb3d25 call \
decrypt --age-key env:MYSECRET --encrypted-file file:pathfunc (m *MyModule) Example(ageKey *dagger.Secret, encryptedFile *dagger.File) *dagger.File {
return dag.
Sops().
Decrypt(ageKey, encryptedFile)
}@function
def example(agekey: dagger.Secret, encryptedfile: dagger.File) -> dagger.File:
return (
dag.sops()
.decrypt(agekey, encryptedfile)
)@func()
example(ageKey: Secret, encryptedFile: File): File {
return dag
.sops()
.decrypt(ageKey, encryptedFile)
}encrypt() 🔗
Encrypt encrypts a file with SOPS for the given AGE recipient(s). With –sops-config or –encrypted-regex only matching values are encrypted, so a Kubernetes Secret keeps apiVersion, kind and metadata readable.
Return Type
File !Arguments
| Name | Type | Default Value | Description |
|---|---|---|---|
| ageKey | Secret ! | - | AGE public key(s), comma-separated |
| plaintextFile | File ! | - | No description provided |
| fileExtension | String | "yaml" | e.g., “yaml”, “json”, “env” |
| sopsConfig | File | - | .sops.yaml whose creation_rules apply (recipients, encrypted_regex, …) |
| encryptedRegex | String | - | Encrypt only the values whose keys match, e.g. ‘^(data|stringData)$’ for a Kubernetes Secret that Flux applies. Overrides the config. |
Example
dagger -m github.com/stuttgart-things/dagger/sops@2eb7e67e3dc669ddf1d66c7325db4dd14bfb3d25 call \
encrypt --age-key env:MYSECRET --plaintext-file file:pathfunc (m *MyModule) Example(ageKey *dagger.Secret, plaintextFile *dagger.File) *dagger.File {
return dag.
Sops().
Encrypt(ageKey, plaintextFile)
}@function
def example(agekey: dagger.Secret, plaintextfile: dagger.File) -> dagger.File:
return (
dag.sops()
.encrypt(agekey, plaintextfile)
)@func()
example(ageKey: Secret, plaintextFile: File): File {
return dag
.sops()
.encrypt(ageKey, plaintextFile)
}generateAgeKey() 🔗
GenerateAgeKey generates a new AGE key pair using age-keygen. Returns the key file containing both the public key (in a comment) and the private key.
Never cached: with Dagger’s function and exec cache, every call on the same engine used to return the same private key.
Return Type
File ! Example
dagger -m github.com/stuttgart-things/dagger/sops@2eb7e67e3dc669ddf1d66c7325db4dd14bfb3d25 call \
generate-age-keyfunc (m *MyModule) Example() *dagger.File {
return dag.
Sops().
Generateagekey()
}@function
def example() -> dagger.File:
return (
dag.sops()
.generateagekey()
)@func()
example(): File {
return dag
.sops()
.generateAgeKey()
}generateSopsConfig() 🔗
GenerateSopsConfig generates a .sops.yaml configuration file with creation rules for the given AGE key. The fileExtensions parameter accepts a comma-separated list of extensions (e.g., “yaml,json,env”). If not provided, defaults to “yaml,json”.
Return Type
File !Arguments
| Name | Type | Default Value | Description |
|---|---|---|---|
| agePublicKey | String ! | - | No description provided |
| fileExtensions | String | - | No description provided |
| encryptedRegex | String | - | Encrypt only the values whose keys match, e.g. ‘^(data|stringData)$’ for Kubernetes Secrets that Flux applies. Added to every rule. |
| pathRegex | String | - | One rule for files matching this regex, e.g. ‘.*.enc.yaml$’, instead of one rule per file extension |
Example
dagger -m github.com/stuttgart-things/dagger/sops@2eb7e67e3dc669ddf1d66c7325db4dd14bfb3d25 call \
generate-sops-config --age-public-key stringfunc (m *MyModule) Example(agePublicKey string) *dagger.File {
return dag.
Sops().
Generatesopsconfig(agePublicKey)
}@function
def example(agepublickey: str) -> dagger.File:
return (
dag.sops()
.generatesopsconfig(agepublickey)
)@func()
example(agePublicKey: string): File {
return dag
.sops()
.generateSopsConfig(agePublicKey)
}set() 🔗
Set changes one value in a SOPS-encrypted file without writing the rest out
in plaintext (sops set). Returns the updated encrypted file.
The value never becomes an operation argument: it is JSON-encoded here, wrapped as a Secret and handed to sops with –value-file.
Return Type
File !Arguments
| Name | Type | Default Value | Description |
|---|---|---|---|
| encryptedFile | File ! | - | SOPS-encrypted file to change |
| path | String ! | - | sops path of the value, e.g. ‘[“stringData”][“KEY”]’ |
| value | Secret ! | - | The new value. Treated as a string unless –json-value is set. |
| ageKey | Secret ! | - | AGE private key that can decrypt the file |
| jsonValue | Boolean | - | The value is already JSON (an object, a number, …) and is set as is |
Example
dagger -m github.com/stuttgart-things/dagger/sops@2eb7e67e3dc669ddf1d66c7325db4dd14bfb3d25 call \
set --encrypted-file file:path --path string --value env:MYSECRET --age-key env:MYSECRETfunc (m *MyModule) Example(encryptedFile *dagger.File, path string, value *dagger.Secret, ageKey *dagger.Secret) *dagger.File {
return dag.
Sops().
Set(encryptedFile, path, value, ageKey)
}@function
def example(encryptedfile: dagger.File, path: str, value: dagger.Secret, agekey: dagger.Secret) -> dagger.File:
return (
dag.sops()
.set(encryptedfile, path, value, agekey)
)@func()
example(encryptedFile: File, path: string, value: Secret, ageKey: Secret): File {
return dag
.sops()
.set(encryptedFile, path, value, ageKey)
}updateKeys() 🔗
UpdateKeys re-encrypts a SOPS file’s data key for the recipients the
.sops.yaml now lists (sops updatekeys -y), e.g. after adding a recipient.
Returns the updated encrypted file.
Return Type
File !Arguments
| Name | Type | Default Value | Description |
|---|---|---|---|
| encryptedFile | File ! | - | SOPS-encrypted file to update |
| sopsConfig | File ! | - | .sops.yaml with the new recipients. Its creation rule must match the file’s name. |
| ageKey | Secret ! | - | AGE private key that can decrypt the file |
Example
dagger -m github.com/stuttgart-things/dagger/sops@2eb7e67e3dc669ddf1d66c7325db4dd14bfb3d25 call \
update-keys --encrypted-file file:path --sops-config file:path --age-key env:MYSECRETfunc (m *MyModule) Example(encryptedFile *dagger.File, sopsConfig *dagger.File, ageKey *dagger.Secret) *dagger.File {
return dag.
Sops().
Updatekeys(encryptedFile, sopsConfig, ageKey)
}@function
def example(encryptedfile: dagger.File, sopsconfig: dagger.File, agekey: dagger.Secret) -> dagger.File:
return (
dag.sops()
.updatekeys(encryptedfile, sopsconfig, agekey)
)@func()
example(encryptedFile: File, sopsConfig: File, ageKey: Secret): File {
return dag
.sops()
.updateKeys(encryptedFile, sopsConfig, ageKey)
}