[k8s] ImagePullSecret: AWS ECR ์—ฐ๋™ํ•˜๊ธฐ

ECR ๊ณ„์ •์˜ ๊ถŒํ•œ์„ ๋‹น์žฅ ์ฟ ๋ฒ„์— ๋„ฃ์œผ๋ ค๋ฉด, aws cli๋กœ ํ† ํฐ์„ ๋ฐ›์•„์„œ ์ง์ ‘ secret์„ ๋งŒ๋“ค์–ด์ฃผ๋ฉด ๋œ๋‹ค.

๋ฌธ์ œ๋Š” ecr ํ† ํฐ์— ๋งŒ๋ฃŒ ๊ธฐํ•œ์ด ์žˆ๊ณ  12์‹œ๊ฐ„ ์ •๋„๋ผ์„œ, ์ง€๋‚ ๋•Œ๋งˆ๋‹ค ๋งค๋ฒˆ ์†์œผ๋กœ ๊ฐฑ์‹ ํ•ด์ค˜์•ผ ํ•œ๋‹ค๋Š” ๊ฒƒ์ด๋‹ค.

๋‹คํ–‰ํžˆ๋„ ์ด๊ฑธ ์ž๋™ํ™”ํ•˜๋Š” ๋„๊ตฌ๋ฅผ ๋ˆ„๊ฐ€ ๋งŒ๋“ค์–ด๋†จ๋‹ค.
์ด๊ฑธ ์“ฐ๋ฉด ๋œ๋‹ค.

helm repo add nabsul https://nabsul.github.io/helm

helm install k8s-ecr-login-renew nabsul/k8s-ecr-login-renew --set awsRegion=๋ฆฌ์ „,awsAccessKeyId=์•ก์„ธ์Šคํ‚ค,awsSecretAccessKey=์‹œํฌ๋ฆฟํ‚ค

helm์œผ๋กœ aws ๊ณ„์ •์ •๋ณด๋ฅผ ๋„ฃ์–ด์„œ ์„ค์น˜ํ•œ๋‹ค.


kubectl -n default create job --from=cronjob/k8s-ecr-login-renew-cron k8s-ecr-login-renew-cron-manual-1

๊ทธ๋ฆฌ๊ณ  ์ตœ์ดˆ job์„ ํŠธ๋ฆฌ๊ฑฐํ•˜๋ฉด


๊ทธ๊ฒŒ ๋Œ๋ฉด์„œ ์‹œํฌ๋ฆฟ๋“ค์„ ๋งŒ๋“ค์–ด์ค„ ๊ฒƒ์ด๋‹ค.
์ €๊ธฐ์„œ 2๋ฒˆ์งธ์ธ docker-secret์„ ์‚ฌ์šฉํ•˜๋ฉด ๋œ๋‹ค.


์ด๋ ‡๊ฒŒ ๋ง์ด๋‹ค.


์ฐธ์กฐ
https://github.com/nabsul/k8s-ecr-login-renew
https://m.blog.naver.com/sssang97/224167915191