Skip to content

qw3r/k8shh

Repository files navigation

k8shh

Interactive Kubernetes secret editor in your terminal, built with Ink (React + Yoga flexbox) and the official @kubernetes/client-node SDK.

It treats a Secret's data keys as an application's environment variables: pick a context → namespace → secret, then edit each NAME = VALUE pair. Large/JSON values can be opened in a fullscreen modal, pretty-printed, and edited. Saving shows a diff and writes back only the changed keys via a merge patch.

Install (Homebrew)

Releases ship a single self-contained bundle; Homebrew only adds Node as a dependency. Once a release is published:

brew tap qw3r/k8shh https://github.com/qw3r/k8shh
brew install k8shh

Requirements

  • A working kubectl context (this app reads your default kubeconfig — the same $KUBECONFIG / ~/.kube/config that kubectl uses). No cluster credentials are stored by this tool.
  • mise to manage the toolchain (pins Node 24 LTS).

Getting started

mise install        # installs Node 24 (from mise.toml)
mise run install    # npm install
mise run dev        # launch the TUI

Other tasks:

mise run start      # launch the TUI (alias of dev)
mise run typecheck  # tsc --noEmit
mise run build      # compile to dist/
mise run test       # unit tests
mise run fmt        # prettier

Keybindings

Browse list: ↑/↓ or j/k move · PgUp/PgDn · Home/End · Enter open value editor · n edit name · v inline-edit value · a add · d delete · s save · r reload · x reset · Tab switch panes · q quit.

Value modal — view: e edit · p pretty (JSON) · m minify (JSON) · ↑/↓ scroll · Esc close. Edit: type freely · arrows move the cursor · Enter newline · Esc back to view.

Save confirm: y/Enter to apply · n/Esc to cancel.

Safety

  • Nothing is written to the cluster until you confirm the diff on Save.
  • Only changed/added/removed keys are patched (stringData for upserts, data: { key: null } for deletes); other keys are left untouched.
  • Non-UTF8 (binary) secret values are shown read-only to avoid corrupting them.

Releasing

A release is a single self-contained ESM bundle (k8shh.mjs, ~2 MB) with Ink, React, Yoga (WASM), and the Kubernetes client inlined — no npm install at install time; only Node is required at runtime.

Build and inspect locally:

mise run release:build    # -> dist/k8shh-<version>.tar.gz (+ .sha256)
mise run release:formula  # regenerate Formula/k8shh.rb from that tarball

Cut a release (semantic versioning) and push the tag:

mise run release:patch    # or release:minor / release:major  (npm version -> vX.Y.Z tag)
git push --follow-tags

Pushing a vX.Y.Z tag triggers .github/workflows/release.yml, which builds the self-contained tarball, creates a draft GitHub release with the artifact + checksum, and commits the regenerated Homebrew formula to the default branch. Review and publish the draft to make brew install work.

About

A CLI environment & secret manager for Kubernetes Secrets.

Resources

Stars

Watchers

Forks

Releases

Packages

Used by

Contributors

Languages