Kubernetes Secret Encoder
Paste plain KEY=value lines, or a flat JSON/YAML object, to get a Secret manifest whose values are base64-encoded under data.
About the Kubernetes Secret Encoder
The Kubernetes Secret Encoder takes plain KEY=value lines, or a flat JSON or YAML object, and returns a Secret manifest whose values are base64-encoded under data. Set the Secret name, namespace and type, then copy the YAML into your repository's secret-management workflow or apply it with kubectl.
How to use the Kubernetes Secret Encoder
- Paste your plain values (KEY=value, JSON or YAML).
- Set the Secret name, namespace and type.
- Click Encode and copy or download secret.yaml.
Frequently asked questions
Which Secret types can I choose?
Opaque, kubernetes.io/basic-auth, ssh-auth, tls and dockerconfigjson. The type is written to the manifest; you still need to supply the keys that type requires, such as tls.crt and tls.key.
Why does the tool warn about git?
Base64 is not encryption. Anyone who can read the manifest can decode the values, so keep it out of source control or encrypt it with a tool such as SOPS or Sealed Secrets.
Are my data stored when I use the Kubernetes Secret Encoder?
The text you submit is processed in memory to produce the result and is not saved. Like any web server, Code Converter logs basic visit data (page, IP address and browser) but never the content you paste. Even so, use placeholder values instead of real production credentials.
Is the Kubernetes Secret Encoder free, and can I call it from a script?
It is free and needs no account or signup. The same tool is available as a REST endpoint at POST /api/k8s-secret-encode; see the API documentation for the fields and examples.