About this project
K8s Namespace Sync is a Kubernetes controller that automatically synchronizes Secrets and ConfigMaps across multiple namespaces within a Kubernetes cluster. It watches for changes in the source namespace and syncs them to all target namespaces, maintaining consistency by cleaning up resources when the source is deleted using finalizers.
Key features include:
- Automatic synchronization of Secrets and ConfigMaps.
- Automatic detection and real-time syncing of source changes.
- Selective namespace targeting and manual exclusion of specific namespaces.
- Automatic exclusion of system namespaces (kube-system, kube-public, etc.).
- Resource filtering with glob pattern matching for include/exclude rules.
- Prometheus metrics for monitoring sync operations, conflicts, and durations.
- Kubernetes events for visibility into sync operations (SyncComplete, SyncFailed, SyncConflict, etc.).
- Status conditions to reflect the current sync state.
The controller can be installed via Helm (OCI registry or classic repo), kubectl apply, or built from source. It requires Kubernetes v1.25+ due to CEL validation rules. The CRD enforces validation rules at admission time, such as requiring a non-empty sourceNamespace and at least one secret or configmap name. It also handles overlapping NamespaceSyncs carefully to prevent conflicts, ensuring that manually created objects are not overwritten unless explicitly targeted.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.