3 ms·
One other consideration: If you use something like the Secrets Store CSI Driver and map the resulting k8s Secret to an env variable, it won't update even if the
by traspler 4y ago
One other consideration: If you use something like the Secrets Store CSI Driver and map the resulting k8s Secret to an env variable, it won't update even if the CSI Driver updates the underlying k8s Secret. If it's mounted as a file it will update and you could potentially detect the change and reload your app.
- yonixw 4y agoGood to learn, Thanks. But I agree more with those who suggest to bind key/secret rotation with config versions (= you can only delete an old secret after all pods using it redeployed to next version with new config). Another approach that sometime is supported, is to use a proxy that handles secret based connections. Like a MySQL pod proxy that you connect to which take care of reconnecting to his upstream on secret change. Both are transparent to the app pod (and its developers)