Current Behavior
When HELM_SECRETS_LOAD_GPG_KEYS is used with secrets:// values, the configured GPG keys are loaded by the initial helm-secrets process and then loaded again by helm-secrets processes started by Helm for the values downloader.
Each _gpg_load_keys() call creates and exports a new temporary GNUPGHOME.
With multiple secret inputs, this results in nested temporary directories such as:
/tmp/tmp.26Qt97iTsQ/tmp.T1XSxycdtZ/RpDzUM
and can eventually fail with errors like:
/tmp/tmp.26Qt97iTsQ/tmp.T1XSxycdtZ/RpDzUM/pubring.gpg: no such file or directory
The child processes do not need to import the keys again because they already inherit the initialised GNUPGHOME from the parent process.
Expected Behavior
HELM_SECRETS_LOAD_GPG_KEYS should be processed once by the initial helm-secrets invocation.
After the keys have been imported, Helm and helm-secrets processes started by Helm should reuse the inherited GNUPGHOME instead of creating another temporary GPG home and importing the same keys again.
Steps To Reproduce
A deterministic way to reproduce the repeated key loading is to provide the GPG key through stdin:
HELM_SECRETS_LOAD_GPG_KEYS=/dev/stdin \
helm secrets template ./chart \
-f secrets://secrets.yaml \
< private.gpg
The initial helm-secrets process successfully imports the key from /dev/stdin.
When Helm starts the secrets:// downloader, the child helm-secrets process inherits HELM_SECRETS_LOAD_GPG_KEYS=/dev/stdin and tries to import the key again.
At that point stdin has already been consumed by the first import, so the second import fails.
The same repeated import can happen with a regular key file, but using /dev/stdin makes the behaviour deterministic and easy to reproduce.
Environment
- Helm Version: 4.3.0
- Helm Secrets Version: 4.7.8
- ArgoCD Version: 3.5.3
- OS: Ubuntu 25.10
- Shell: /bin/sh
Anything else?
No response
Current Behavior
When
HELM_SECRETS_LOAD_GPG_KEYSis used withsecrets://values, the configured GPG keys are loaded by the initial helm-secrets process and then loaded again by helm-secrets processes started by Helm for the values downloader.Each
_gpg_load_keys()call creates and exports a new temporaryGNUPGHOME.With multiple secret inputs, this results in nested temporary directories such as:
/tmp/tmp.26Qt97iTsQ/tmp.T1XSxycdtZ/RpDzUMand can eventually fail with errors like:
/tmp/tmp.26Qt97iTsQ/tmp.T1XSxycdtZ/RpDzUM/pubring.gpg: no such file or directoryThe child processes do not need to import the keys again because they already inherit the initialised
GNUPGHOMEfrom the parent process.Expected Behavior
HELM_SECRETS_LOAD_GPG_KEYSshould be processed once by the initial helm-secrets invocation.After the keys have been imported, Helm and helm-secrets processes started by Helm should reuse the inherited
GNUPGHOMEinstead of creating another temporary GPG home and importing the same keys again.Steps To Reproduce
Environment
Anything else?
No response