base64 encoding Kubernetes Secrets includes newline char when exported as an env variable (if you don’t use -n option with echo)

I’m deploying an app to Kubernetes that references a Kubernetes Secret that is exported as an env var on the pod. I couldn’t work out why I kept getting this error when the pod was starting up:

FATAL: password authentication failed for user "admin"

but if I exec’d into the pod to check the value of the env var, it was the correct value that I expected.

Eventually I did stumble across this clue – ‘printenv’ inside the pod shows:

DB_PASSWORD=[value here]

KUBERNETES_SERVICE_PORT_HTTPS=443
[... other values here]

Between DB_PASSWORD and the next value there’s a blank line, followed by a long list of other env var values, with no other blank lines.

From this question, the issue is how I originally encoded the base64 value with:

echo your-value-here | base64

which is not the same as:

echo -n your-value-here | base64

echo apparently includes a newline by default, so you need to use it as above with the -n option

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.