Skip to content

HELM_SECRETS_LOAD_GPG_KEYS is processed repeatedly by nested helm-secrets invocations #898

Description

@konstantin-kelemen

Current Behavior

When HELM_SECRETS_LOAD_GPG_KEYS is used with secrets:// values, the configured GPG keys are loaded by the initial helm-secrets process and then loaded again by helm-secrets processes started by Helm for the values downloader.

Each _gpg_load_keys() call creates and exports a new temporary GNUPGHOME.

With multiple secret inputs, this results in nested temporary directories such as:

/tmp/tmp.26Qt97iTsQ/tmp.T1XSxycdtZ/RpDzUM

and can eventually fail with errors like:

/tmp/tmp.26Qt97iTsQ/tmp.T1XSxycdtZ/RpDzUM/pubring.gpg: no such file or directory

The child processes do not need to import the keys again because they already inherit the initialised GNUPGHOME from the parent process.

Expected Behavior

HELM_SECRETS_LOAD_GPG_KEYS should be processed once by the initial helm-secrets invocation.

After the keys have been imported, Helm and helm-secrets processes started by Helm should reuse the inherited GNUPGHOME instead of creating another temporary GPG home and importing the same keys again.

Steps To Reproduce

A deterministic way to reproduce the repeated key loading is to provide the GPG key through stdin:

HELM_SECRETS_LOAD_GPG_KEYS=/dev/stdin \
    helm secrets template ./chart \
    -f secrets://secrets.yaml \
    < private.gpg

The initial helm-secrets process successfully imports the key from /dev/stdin.

When Helm starts the secrets:// downloader, the child helm-secrets process inherits HELM_SECRETS_LOAD_GPG_KEYS=/dev/stdin and tries to import the key again.

At that point stdin has already been consumed by the first import, so the second import fails.

The same repeated import can happen with a regular key file, but using /dev/stdin makes the behaviour deterministic and easy to reproduce.

Environment

  • Helm Version: 4.3.0
  • Helm Secrets Version: 4.7.8
  • ArgoCD Version: 3.5.3
  • OS: Ubuntu 25.10
  • Shell: /bin/sh

Anything else?

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions