3 ms·
Kubernetes supported secrets for nearly 2 years: https://kubernetes.io/docs/user-guide/secrets/ https://kubernetes.io/docs/user-guide/secrets/ They currently d
by eicnix 10y ago
Kubernetes supported secrets for nearly 2 years: https://kubernetes.io/docs/user-guide/secrets/ https://kubernetes.io/docs/user-guide/secrets/
They currently debate over pluggable secret stores: https://github.com/kubernetes/kubernetes/issues/10439 https://github.com/kubernetes/kubernetes/issues/10439
You can use Hashicorp Vault as a third party resource to store your secrets:
https://github.com/Boostport/kubernetes-vault https://github.com/Boostport/kubernetes-vault
Kubernetes also supports RBAC to control access to secrets:
https://kubernetes.io/docs/admin/authorization/ https://kubernetes.io/docs/admin/authorization/
- tonyhb 10y agoSecrets as in passwords and keys stored at rest in plain text. So not really secrets.
- benth 10y agoIt's not so much the plain text part that bothers me, it's the access control. Quoting the docs at https://kubernetes.io/docs/user-guide/secrets/#security-properties https://kubernetes.io/docs/user-guide/secrets/#security-prop...: "Currently, anyone with root on any node can read any secret from the apiserver, by impersonating the kubelet. It is a planned feature to only send secrets to nodes that actually require them, to restrict the impact of a root exploit on a single node." As your cluster grows, your risk grows.