Edit

opencenter secrets keys

Manage SOPS encryption keys

Synopsis

Manage SOPS encryption keys for secrets management.

The keys subcommand group provides operations for Age key lifecycle management: • Generate: Create new Age key pairs for SOPS encryption • Rotate: Rotate Age keys with automatic re-encryption of existing secrets • Backup: Create secure backups of Age keys and SOPS configuration • Validate: Validate Age key configuration and SOPS setup

These commands integrate with opencenter workflows to provide seamless key management for standalone clusters and GitOps deployments.

opencenter secrets keys [flags]

Options

  -h, --help   help for keys

SEE ALSO

  • opencenter_secrets.md[opencenter secrets] - Manage secrets across backends

  • opencenter_secrets_keys_backup.md[opencenter secrets keys backup] - Create backup of Age keys and SOPS configuration

  • opencenter_secrets_keys_check.md[opencenter secrets keys check] - Check encryption key expiration status

  • opencenter_secrets_keys_generate.md[opencenter secrets keys generate] - Generate new Age key pair for SOPS encryption

  • opencenter_secrets_keys_revoke.md[opencenter secrets keys revoke] - Revoke encryption keys for users or compromised keys

  • opencenter_secrets_keys_rotate.md[opencenter secrets keys rotate] - Rotate SOPS files or cluster encryption keys

  • opencenter_secrets_keys_validate.md[opencenter secrets keys validate] - Validate Age key configuration and SOPS setup

Auto generated by spf13/cobra on 28-Apr-2026