[k8s] secret

secret์€ ๋ณด์•ˆ์— ๋ฏผ๊ฐํ•œ ๊ฐ’๋“ค์„ ๋ณด๊ด€ํ•˜๊ณ  ์‚ฌ์šฉํ•˜๊ธฐ ์œ„ํ•œ ์ž์ฒด์ ์ธ Key-Value ์Šคํ† ์–ด๋‹ค.

configmap๊ณผ ์‚ฌ์šฉ๋ฐฉ์‹์ด ์œ ์‚ฌํ•˜๋‹ค. ๋‹ค๋งŒ sensitive ์„ค์ • ๋“ฑ์œผ๋กœ ์œ ์ถœ ์œ„ํ—˜์„ ์กฐ๊ธˆ ๋‚ฎ์ถœ ๋ฟ์ด๋‹ค.

yaml์€ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์ •์˜ํ•  ์ˆ˜ ์žˆ๋‹ค.

apiVersion: v1
data:
  username: myyrakle
  password: q1w2e3r4
kind: Secret
metadata:
  name: mysecret
type: Opaque

username๊ณผ password ๊ฐ’์„ ๊ฐ–๊ณ  ์žˆ๋Š” ์‹œํฌ๋ฆฟ์ด๋‹ค.

์ด๊ฑธ ๋งŒ๋“ค๋ฉด

์ด๋ ‡๊ฒŒ ์ƒ์„ฑ์ด ๋  ๊ฒƒ์ด๋‹ค.

๊ทธ๋Ÿผ ์ด๊ฒƒ๋„ configmap๊ณผ ๋งˆ์ฐฌ๊ฐ€์ง€๋กœ describe๋กœ ์กฐํšŒ๋ฅผ ํ•  ์ˆ˜๊ฐ€ ์žˆ๋Š”๋ฐ

์—ฌ๊ธฐ์„œ ๊ฐ€์žฅ ํฐ ์ฐจ์ด์ ์ด ๋“œ๋Ÿฌ๋‚œ๋‹ค.
์œ„์—์„œ ๋ณด์ด๋“ฏ์ด, ํ‚ค๋Š” ๋ณด์—ฌ์ฃผ๋”๋ผ๋„ ๊ฐ’์€ ๊ฐ€๋ ค์„œ ๋ณด์—ฌ์ฃผ์ง€ ์•Š๋Š”๋‹ค.

์‹œํฌ๋ฆฟ์˜ ๊ฐ’์„ ์ปจํ…Œ์ด๋„ˆ ํ™˜๊ฒฝ๋ณ€์ˆ˜์— ์ฃผ์ž…ํ•˜๋ ค๋ฉด ์ด๋Ÿฐ์‹์œผ๋กœ ํ•˜๋ฉด ๋œ๋‹ค.

piVersion: apps/v1
kind: Pod
metadata:
  name: nginx-pod
  spec:
    containers:
    - name: container-name
      image: nginx
      env:
      - name: USERNAME
        valueFrom:
          secretKeyRef:
            name: mysecret
            key: username
            optional: false 
      - name: PASSWORD
        valueFrom:
          secretKeyRef:
            name: mysecret
            key: password
            optional: false

์–ด๋ ต์ง€ ์•Š๋‹ค.



์ฐธ์กฐ
https://kubernetes.io/ko/docs/concepts/configuration/secret/