4 ms·
This is really nice. What is the equivalent in the kubernetes world?
by simplehuman 10y ago
This is really nice. What is the equivalent in the kubernetes world?
- eicnix 10y agoKubernetes supported secrets for nearly 2 years: https://kubernetes.io/docs/user-guide/secrets/ https://kubernetes.io/docs/user-guide/secrets/ They currently debate over pluggable secret stores: https://github.com/kubernetes/kubernetes/issues/10439 https://github.com/kubernetes/kubernetes/issues/10439 You can use Hashicorp Vault as a third party resource to store your secrets: https://github.com/Boostport/kubernetes-vault https://github.com/Boostport/kubernetes-vault Kubernetes also supports RBAC to control access to secrets: https://kubernetes.io/docs/admin/authorization/ https://kubernetes.io/docs/admin/authorization/
- tonyhb 10y agoSecrets as in passwords and keys stored at rest in plain text. So not really secrets.
- benth 10y agoIt's not so much the plain text part that bothers me, it's the access control. Quoting the docs at https://kubernetes.io/docs/user-guide/secrets/#security-properties https://kubernetes.io/docs/user-guide/secrets/#security-prop...: "Currently, anyone with root on any node can read any secret from the apiserver, by impersonating the kubelet. It is a planned feature to only send secrets to nodes that actually require them, to restrict the impact of a root exploit on a single node." As your cluster grows, your risk grows.