-
Notifications
You must be signed in to change notification settings - Fork 2
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request #24 from stakater/secrets-docs
Secrets docs
- Loading branch information
Showing
5 changed files
with
89 additions
and
0 deletions.
There are no files selected for viewing
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,89 @@ | ||
# Adding Secrets | ||
|
||
Now, we will set up applications to use consume secrets from Vault, using ExternalSecrets. | ||
|
||
Multi-Tenant Operator [MTO] creates a path for each tenant in the Vault. | ||
Each user in the cluster is part of a tenant. | ||
Users have access to the path corresponding to their tenant. | ||
In this path, a key/value pair can be stored, and/or another path containing key/value pair can exist. | ||
|
||
Login to Vault to view your tenant path. | ||
|
||
- Access Vault from [Forecastle](https://forecastle-stakater-forecastle.apps.devtest.vxdqgl7u.kubeapp.cloud) console, search `Vault` and open the `Vault` tile. | ||
|
||
data:image/s3,"s3://crabby-images/2678f/2678f65cf78502dbc59fe7e19ba575c7c695922d" alt="Forecastle-Vault" | ||
- From the drop-down menu under `Method`, select `OIDC` and click on `Sign in with OIDC Provider` and select `workshop` identity Provider | ||
|
||
data:image/s3,"s3://crabby-images/4db03/4db03320276f36be904da1ae3c7b7aa1e8b32247" alt="Vault-ocic-login" | ||
|
||
- You will be brought to the `Vault` console. You should see the key/value path for your tenant. | ||
- External Secrets Operator is used to fetch secret data from Vault, and create Kubernetes secret in the cluster. | ||
- External Secrets Operator uses SecretStore to make a connection to the Vault. | ||
- SecretStore uses ServiceAccount with Vault label to access Vault. | ||
- SecretStore and ServiceAccount is created in each tenant namespace. | ||
- Each ExternalSecret CR contains reference to SecretStore to be used. | ||
|
||
Stakater Application Chart contains support for ExternalSecret. | ||
|
||
"```" | ||
externalSecret: | ||
enabled: true | ||
|
||
#SecretStore defines which SecretStore to use when fetching the secret data | ||
secretStore: | ||
name: example-secret-store | ||
kind: SecretStore # or ClusterSecretStore | ||
|
||
#RefreshInterval is the amount of time before the values reading again from the SecretStore provider | ||
`refreshInterval`: "1m" | ||
files: | ||
secret-1-name: | ||
#Data defines the connection between the Kubernetes Secret keys and the Provider data | ||
data: | ||
example-secret-key: | ||
`remoteRef`: | ||
key: example-provider-key | ||
property: example-provider-key-property | ||
|
||
secret-2-name: | ||
#Used to fetch all properties from the Provider key | ||
dataFrom: | ||
key: example-provider-key | ||
type: Opaque | ||
annotations: | ||
key: value | ||
labels: | ||
key: value | ||
"```" | ||
From the above configuration, a Kubernetes secret is created. | ||
|
||
Let's add a sample secret for Stakater Nordmart Review UI application for demo. | ||
|
||
- In the path of your tenant, Click `Create Secret`, add path of secret, and add key/value pair as shown below. | ||
|
||
- Path for secret: `nordmart-review-ui-page-title` | ||
- Secret key: `page_title` | ||
- Secret value: Review (Secret from Vault) | ||
|
||
data:image/s3,"s3://crabby-images/daa6d/daa6ddc85271371450c53a5aa7cd8bde45c77c54" alt="create-secret" | ||
|
||
- Open `stakater-nordmart-review-ui` project, and navigate to deploy folder | ||
- In `values.yaml` file, add the following YAML for external secret: | ||
|
||
"```" | ||
externalSecret: | ||
enabled: true | ||
secretStore: | ||
name: tenant-vault-secret-store | ||
refreshInterval: "1m" | ||
files: | ||
review-ui-secret: | ||
dataFrom: | ||
- key: review-ui/dev/nordmart-review-ui-page-title | ||
"```" | ||
|
||
- Once the updated secret is created, application pod will be recreated. Refresh the application route to see the change. The title will be updated! | ||
|
||
data:image/s3,"s3://crabby-images/828f6/828f6095e3b7bc6d23a0c45330dddb9365ee371d" alt="Review-UI" | ||
|
||
For more information on ExternalSecrets, see [External Secrets documentation](https://external-secrets.io/v0.8.1/introduction/overview/) |