jq isnt needed here. We should do it this way: kelson@testing ~]$ oc get secret rook-ceph-mds-ocs-storagecluster-cephfilesystem-a-keyring -o jsonpath='{.data.keyring}'|base64 --decode [mds.ocs-storagecluster-cephfilesystem-a] key = AQCwUGRioG50AhAAQgMYaqJQLDj49nORAOUfRg== caps mon = "allow profile mds" caps osd = "allow *" caps mds = "allow" Reported by: rhn-support-kelwhite https://access.redhat.com/documentation/en-us/red_hat_openshift_container_storage/4.8/html/troubleshooting_openshift_container_storage/restoring-the-monitor-pods-in-openshift-container-storage_rhocs#annotations:656d6450-d3a3-4427-9cef-eb6f0c16dd22