Admiral

Security

Secrets

Admiral stores a pointer into your secret manager and the agent resolves it, while chart values pass through exactly as you wrote them.

Admiral works with the way you already handle secrets. A team that already reads secrets from its own module, or that already ships Sealed Secrets, External Secrets, or a Vault chart, keeps doing that.

How do I keep a secret out of Admiral?

For a Terraform component, a value may name an entry in GCP Secret Manager, AWS Secrets Manager, or Vault. The reference is one string, secret("<manager>:<address>"), and the address is the manager's own identifier:

db_password:
  ref: secret("gcp:projects/acme-prod/secrets/users-db-password")
api_token:
  ref: secret("aws:arn:aws:secretsmanager:us-east-1:111122223333:secret:api-token#token")
tls_key:
  ref: secret("vault:kv/data/users-db#tls_key")
  • #key reads one field of a JSON or key/value secret. Vault needs it. On AWS, leaving it off reads the whole secret string.
  • A reference reads the latest version unless you pin one, with /versions/N on GCP or ?version=<id> on AWS. An unpinned reference is read at apply, so a rotated secret needs no changeset.

Admiral stores that pointer. When you plan, Admiral renders each component into a run artifact, the exact files the agent receives, and the pointer goes into it unresolved. The agent resolves it with the cloud identity it already uses to apply. The control plane does not.

The reference is offered. It is not required. A module may keep using a data source.

What happens to secrets in chart values?

A workload gets no secret resolution from Admiral. A chart's values are what the chart takes. Sealed Secrets ciphertext, an ExternalSecret name, a Vault wrapper, or plaintext you chose to put there all pass through untouched. Admiral does not refuse a chart and does not rewrite one.

Plaintext you put in values is stored as you gave it.

Which secrets still land in Terraform state?

A secret fed to an ordinary Terraform input lands in state. An ephemeral input or a write-only argument stays out of it. The changeset review shows which kind each secret input is.

When Admiral hosts the state, it encrypts it the way it encrypts a stored credential, and Admiral can decrypt it. When a component keeps its own backend, the secret lands in that backend, and Admiral never holds it.

Admiral has no secret store of its own, so a reference always points into your own manager.

Where to go next

On this page