atscalectl secrets get
The secrets get command retrieves deployment credentials and sensitive configuration values from Kubernetes secrets belonging to an AtScale deployment. The command provides a single view of commonly required credentials without manually searching Kubernetes secrets or decoding base64 values.
Typical use cases include:
- Retrieving the Keycloak administrator credentials.
- Checking database credentials.
- Accessing client secrets during troubleshooting or configuration tasks.
Prerequisites
secrets get requires the following Kubernetes permissions:
secretsgetsecretslist. Required only when the--release-nameflag isn't specified. This is required to detect the Helm release.
Usage
atscalectl secrets get [flags]
Flags
secrets get can be used with all global flags, as well as the following command-specific flags.
| Flag | Default | Description |
|---|---|---|
--reveal | false | Shows full secret values. Values are masked by default. |
--output-file | Writes the secret output to a YAML file at the specified path. |
What secrets get reads
secrets get reads the following Kubernetes secrets.
| Secret | Contents |
|---|---|
{release}-sml-api-crypto-key | Encryption key. |
{release}-kc-users | Keycloak administrator and AtScale administrator credentials. |
{release}-kc-clients | Keycloak client secrets. |
{release}-db-default-user | PostgreSQL credentials. |
{release}-db-pgpool-user | PgPool administrator credentials. |
{release}-db-custom-users | Custom database users. |
For all of the above, {release} is the Helm release name. This is automatically detected when possible. If multiple releases exist, you can specify the release manually with the --release-name global flag.
Secrets that do not exist are skipped. Not every AtScale deployment uses every supported secret.
Recommendations for safely handling credentials
Use masking by default
Secret values are hidden unless the --reveal flag is explicitly provided. Use the default masked output first to confirm that the expected credentials exist.
Protect revealed values
Avoid using --reveal in situations where output can be exposed. For example:
- Shared screens
- Recorded sessions
- CI/CD logs
- Shared terminal environments
Take precautions with output files
Files created with --output-file have 0600 permissions, but contain unencrypted credentials. Because of this, AtScale recommends you take the following precautions:
- Store the file only temporarily.
- Restrict access to the file.
- Delete the file after use.
- Never commit generated secret files to source control.
Secrets get usage examples
Show available credentials with values masked
atscalectl secrets get
The above command outputs a table similar to the following:
┌──────────────┬─────────────────────────┬──────────────┐
│ CATEGORY │ KEY │ VALUE │
├──────────────┼─────────────────────────┼──────────────┤
│ Keycloak │ KEYCLOAK_ADMIN │ ******** │
│ Keycloak │ KEYCLOAK_ADMIN_PASSWORD │ ******** │
│ PostgreSQL │ POSTGRES_USER │ ******** │
│ PostgreSQL │ POSTGRES_PASSWORD │ ******** │
└──────────────┴─────────────────────────┴──────────────┘
Reveal secret values
Use this option only when required. Revealed values may appear in terminal output, terminal scrollback, CI logs, and screen sharing sessions.
atscalectl secrets get --reveal
Retrieve secrets for a specific release
atscalectl secrets get \
--release-name <release-name>
Output as JSON
atscalectl secrets get \
--output json \
--reveal
Export to a file
The generated file contains the secret values in plain text. The file is created with permissions 0600, but it is still sensitive data and should be deleted after use.
atscalectl secrets get \
--output-file <filename>
Troubleshooting secrets get
Expected secret is missing
Optional secrets are skipped when they are not present. Verify that the correct namespace is selected and the correct release name is used. For example:
atscalectl secrets get \
--release-name <release-name>
Multiple Helm releases found
If more than one Helm release exists in the namespace, automatic detection is disabled. If this occurs, you must specify the release explicitly:
atscalectl secrets get \
--release-name <release-name>
No secrets found
No secrets may be found in the following cases:
- The wrong namespace was used.
- The wrong Helm release name was used.
- The AtScale deployment does not contain the optional secret types being requested.
Verify the active context and namespace:
atscalectl status \
--namespace <namespace>