Skip to main content

atscalectl secrets get

The secrets get command retrieves deployment credentials and sensitive configuration values from Kubernetes secrets belonging to an AtScale deployment. The command provides a single view of commonly required credentials without manually searching Kubernetes secrets or decoding base64 values.

Typical use cases include:

  • Retrieving the Keycloak administrator credentials.
  • Checking database credentials.
  • Accessing client secrets during troubleshooting or configuration tasks.

Prerequisites​

secrets get requires the following Kubernetes permissions:

  • secrets get
  • secrets list. Required only when the --release-name flag isn't specified. This is required to detect the Helm release.

Usage​

atscalectl secrets get [flags]

Flags​

secrets get can be used with all global flags, as well as the following command-specific flags.

FlagDefaultDescription
--revealfalseShows full secret values. Values are masked by default.
--output-fileWrites the secret output to a YAML file at the specified path.

What secrets get reads​

secrets get reads the following Kubernetes secrets.

SecretContents
{release}-sml-api-crypto-keyEncryption key.
{release}-kc-usersKeycloak administrator and AtScale administrator credentials.
{release}-kc-clientsKeycloak client secrets.
{release}-db-default-userPostgreSQL credentials.
{release}-db-pgpool-userPgPool administrator credentials.
{release}-db-custom-usersCustom database users.

For all of the above, {release} is the Helm release name. This is automatically detected when possible. If multiple releases exist, you can specify the release manually with the --release-name global flag.

Secrets that do not exist are skipped. Not every AtScale deployment uses every supported secret.

Recommendations for safely handling credentials​

Use masking by default​

Secret values are hidden unless the --reveal flag is explicitly provided. Use the default masked output first to confirm that the expected credentials exist.

Protect revealed values​

Avoid using --reveal in situations where output can be exposed. For example:

  • Shared screens
  • Recorded sessions
  • CI/CD logs
  • Shared terminal environments

Take precautions with output files​

Files created with --output-file have 0600 permissions, but contain unencrypted credentials. Because of this, AtScale recommends you take the following precautions:

  • Store the file only temporarily.
  • Restrict access to the file.
  • Delete the file after use.
  • Never commit generated secret files to source control.

Secrets get usage examples​

Show available credentials with values masked​

atscalectl secrets get

The above command outputs a table similar to the following:

┌──────────────┬─────────────────────────┬──────────────┐
│ CATEGORY │ KEY │ VALUE │
├──────────────┼─────────────────────────┼──────────────┤
│ Keycloak │ KEYCLOAK_ADMIN │ ******** │
│ Keycloak │ KEYCLOAK_ADMIN_PASSWORD │ ******** │
│ PostgreSQL │ POSTGRES_USER │ ******** │
│ PostgreSQL │ POSTGRES_PASSWORD │ ******** │
└──────────────┴─────────────────────────┴──────────────┘

Reveal secret values​

Important

Use this option only when required. Revealed values may appear in terminal output, terminal scrollback, CI logs, and screen sharing sessions.

atscalectl secrets get --reveal

Retrieve secrets for a specific release​

atscalectl secrets get \
--release-name <release-name>

Output as JSON​

atscalectl secrets get \
--output json \
--reveal

Export to a file​

Important

The generated file contains the secret values in plain text. The file is created with permissions 0600, but it is still sensitive data and should be deleted after use.

atscalectl secrets get \
--output-file <filename>

Troubleshooting secrets get​

Expected secret is missing​

Optional secrets are skipped when they are not present. Verify that the correct namespace is selected and the correct release name is used. For example:

atscalectl secrets get \
--release-name <release-name>

Multiple Helm releases found​

If more than one Helm release exists in the namespace, automatic detection is disabled. If this occurs, you must specify the release explicitly:

atscalectl secrets get \
--release-name <release-name>

No secrets found​

No secrets may be found in the following cases:

  • The wrong namespace was used.
  • The wrong Helm release name was used.
  • The AtScale deployment does not contain the optional secret types being requested.

Verify the active context and namespace:

atscalectl status \
--namespace <namespace>