Kubernetes Manifest
Deploying to Kubernetes via manifest
The following instructions will help you setup a basic deployment of the TruffleHog scanner in Kubernetes via manifest.
For Kubernetes we recommend using the Helm Chart instead if possible. The helm chart makes it easier to customize the deployment and also includes options like a VerticalPodAutoscaler to right-size the resource requests for the deployment.
Kubernetes will ensure that TruffleHog stays running, manage your configuration secrets, and collect the logs.
Create the namespace
$ kubectl create namespace trufflehog
namespace/trufflehog createdCreate the configuration secret
Important: The config file must be named config.yaml for the field name in the secret to be correctly named and match what the Deployment is looking for.

$ kubectl create secret --namespace trufflehog generic --from-file config.yaml config
secret/config createdCreate the deployment.yaml file
apiVersion: apps/v1
kind: Deployment
metadata:
name: trufflehog
labels:
app: trufflehog
spec:
replicas: 1
selector:
matchLabels:
app: trufflehog
template:
metadata:
labels:
app: trufflehog
spec:
volumes:
- name: config-secret-volume
secret:
secretName: config
containers:
- name: trufflehog
image: us-docker.pkg.dev/thog-artifacts/public/scanner:latest
terminationMessagePolicy: FallbackToLogsOnError
command: ["/usr/local/bin/scanner", "scan", "--config=/secret/config.yaml", "--port=8080"]
livenessProbe:
httpGet:
path: /healthz
port: 8080
initialDelaySeconds: 3
periodSeconds: 3
volumeMounts:
- name: config-secret-volume
mountPath: /secret/Apply the manifest
$ kubectl apply -f /tmp/thog.yaml --namespace trufflehog
deployment.apps/trufflehog configuredWait for TruffleHog to be running
$ kubectl get pods --namespace trufflehog --watch
NAME READY STATUS RESTARTS AGE
trufflehog-7f76dc4c49-szxwv 1/1 Running 0 0m22sFollow the logs
$ kubectl logs --namespace trufflehog -f -l app=trufflehog
š·šš· TruffleHog. Unearth your secrets. š·šš·
version: v1.50.22
INFO[0000] starting scanner service client scanner_group=On-prem