{"id":35994,"date":"2023-02-11T12:33:06","date_gmt":"2024-02-03T22:32:27","guid":{"rendered":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8externalsecret%e5%9c%a8eks%e4%b8%ad%e5%b0%86vault%e7%9a%84%e6%95%b0%e6%8d%aekv%e4%bd%9c%e4%b8%ba%e5%af%86%e9%92%a5%e5%8a%a0%e8%bd%bd%e8%bf%9b%e6%9d%a5%e3%80%82\/"},"modified":"2024-04-29T14:10:22","modified_gmt":"2024-04-29T06:10:22","slug":"%e4%bd%bf%e7%94%a8externalsecret%e5%9c%a8eks%e4%b8%ad%e5%b0%86vault%e7%9a%84%e6%95%b0%e6%8d%aekv%e4%bd%9c%e4%b8%ba%e5%af%86%e9%92%a5%e5%8a%a0%e8%bd%bd%e8%bf%9b%e6%9d%a5%e3%80%82","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8externalsecret%e5%9c%a8eks%e4%b8%ad%e5%b0%86vault%e7%9a%84%e6%95%b0%e6%8d%aekv%e4%bd%9c%e4%b8%ba%e5%af%86%e9%92%a5%e5%8a%a0%e8%bd%bd%e8%bf%9b%e6%9d%a5%e3%80%82\/","title":{"rendered":"\u4f7f\u7528ExternalSecret\u5728EKS\u4e2d\u5c06Vault\u7684\u6570\u636e(kv)\u4f5c\u4e3a\u5bc6\u94a5\u52a0\u8f7d\u8fdb\u6765"},"content":{"rendered":"<h2>\u5916\u90e8\u79d8\u5bc6\u662f\u6307\u7684\u662f\u4ec0\u4e48\uff1f<\/h2>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d26f237434c4406c39eca\/1-0.png\" alt=\"1654482450879.png\" \/><\/div>\n<p>\u901a\u5e38\u60c5\u51b5\u4e0b\uff0c\u5728\u4f7f\u7528EKS\u7684ExternalSecret\u65f6\uff0c\u6211\u4eec\u901a\u5e38\u4f1a\u4eceSecretManager\u4e2d\u83b7\u53d6\u503c\uff0c\u4f46\u8fd9\u6b21\u662f\u4eceVault\u4e2d\u83b7\u53d6\u503c\u7684\u9a8c\u8bc1\u8bb0\u5f55\u3002<\/p>\n<h2>\u5b89\u88c5\u5916\u90e8\u5bc6\u94a5\u64cd\u4f5c\u5458<\/h2>\n<p>\u6309\u7167\u5b98\u65b9\u7f51\u7ad9\u7684\u201c\u5165\u95e8\u6307\u5357\u201d\uff0c\u5b89\u88c5\u5916\u90e8\u5bc6\u94a5\u64cd\u4f5c\u5458\u3002<\/p>\n<pre class=\"post-pre\"><code>helm repo add external-secrets https:\/\/charts.external-secrets.io\r\nhelm install external-secrets \\\r\n   external-secrets\/external-secrets \\\r\n    -n external-secrets \\\r\n    --create-namespace \\\r\n    --set installCRDs=true\r\n<\/code><\/pre>\n<h2>\u8bf7\u5b89\u88c5Vault\u3002<\/h2>\n<p>\u6211\u4e5f\u8981\u5b89\u88c5Vault\u3002\u8bf7\u53c2\u8003\u5b98\u65b9\u6b65\u9aa4\u83b7\u53d6\u8be6\u7ec6\u4fe1\u606f\uff0c\u8fd9\u91cc\u53ea\u662f\u7b80\u5355\u8bb0\u5f55\u4e00\u4e0b\u6211\u5b8c\u6210\u7684\u6b65\u9aa4\u3002<\/p>\n<pre class=\"post-pre\"><code>helm repo add hashicorp https:\/\/helm.releases.hashicorp.com\r\nhelm show values hashicorp\/vault &gt; vault-values.yaml\r\nhelm upgrade -i -f vault-values.yaml vault -n vault --create-namespace hashicorp\/vault\r\n<\/code><\/pre>\n<p>\u5c06vault-values.yaml\u6587\u4ef6\u66f4\u6539\u4e3a\u4f7f\u7528Ingress\u3002<br \/>\n\u5728Vault\u542f\u52a8\u540e\u6267\u884c\u89e3\u5c01\u64cd\u4f5c\u3002\u5982\u679c\u4e0d\u8fdb\u884c\u89e3\u5c01\u64cd\u4f5c\uff0cPod\u5c06\u6301\u7eed\u629b\u51fa\u4ee5\u4e0b\u9519\u8bef\uff0c\u5e76\u65e0\u6cd5\u5b8c\u6210\u542f\u52a8\u3002<\/p>\n<pre class=\"post-pre\"><code>2022-08-04T03:28:40.124Z [INFO]  core: seal configuration missing, not initialized\r\n2022-08-04T03:28:45.090Z [INFO]  core: security barrier not initialized\r\n<\/code><\/pre>\n<p>\u53ef\u4ee5\u901a\u8fc7\u4f7f\u7528`vault operator init`\u547d\u4ee4\u6765\u83b7\u53d6\u89e3\u5c01\uff08unseal\uff09\u6240\u9700\u7684\u5bc6\u94a5\u548c\u4ee4\u724c\u3002<\/p>\n<pre class=\"post-pre\"><code>kubectl exec -ti vault-0 -n vault -- vault operator init\r\n<\/code><\/pre>\n<p>\u9019\u500b\u521d\u59cb\u7684\u6839\u4ee4\u724c\u6703\u7528\u65bc\u4e0d\u540c\u7684\u7528\u9014\uff0c\u6240\u4ee5\u9700\u8981\u5099\u4efd\u4fdd\u5b58\u3002\u4f7f\u7528 unseal key \u4f86\u9032\u884c\u89e3\u5c01\u3002<\/p>\n<pre class=\"post-pre\"><code>kubectl exec -ti vault-0 -n vault -- vault operator unseal\r\n<\/code><\/pre>\n<p>\u8fdb\u884c3\u6b21\u89e3\u5c01\u64cd\u4f5c\u540e\uff0c\u5c06\u83b7\u5f97\u4ee5\u4e0b\u7684\u8f93\u51fa\uff0c\u4f7fVault\u53ef\u7528\u3002<\/p>\n<pre class=\"post-pre\"><code>Key             Value\r\n---             -----\r\nSeal Type       shamir\r\nInitialized     true\r\nSealed          false\r\nTotal Shares    5\r\nThreshold       3\r\nVersion         1.10.3\r\nStorage Type    file\r\nCluster Name    vault-cluster-44f5b753\r\nCluster ID      d4b134d3-6888-37a1-dba4-3b7063a61a80\r\nHA Enabled      false\r\n<\/code><\/pre>\n<h2>Vault\u7684\u8bbe\u7f6e<\/h2>\n<p>\u5728\u8fd9\u91cc\uff0c\u5c06\u6837\u672c\u6570\u636e\u6295\u5165\u5230Vault\u5185\uff0c\u5e76\u521b\u5efa\u8bbf\u95ee\u7b56\u7565\u3002<br \/>\n\u6b64\u5904\u7684\u63cf\u8ff0\u57fa\u672c\u4e0a\u662f\u53c2\u8003\u4ee5\u4e0b\u4fe1\u606f\u7684\u3002<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">https:\/\/www.vaultproject.io\/docs\/auth\/kubernetes<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">https:\/\/learn.hashicorp.com\/tutorials\/vault\/agent-kubernetes<\/ul>\n<p>\u4ece\u672c\u5730PC\u4f7f\u7528vault\u547d\u4ee4\u8bbf\u95eeHelm Vault\u7684\u5165\u53e3\u70b9\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nb\">export <\/span><span class=\"nv\">VAULT_ADDR<\/span><span class=\"o\">=<\/span>https:\/\/vault.mydomain.info\r\nvault login\r\n<\/code><\/pre>\n<p>\u7531\u65bc\u9ed8\u8a8d\u60c5\u6cc1\u4e0b\u672a\u555f\u7528KeyValue\u5f15\u64ce\uff0c\u6240\u4ee5\u5c07\u5176\u555f\u7528\u3002<\/p>\n<pre class=\"post-pre\"><code>vault secrets enable kv\r\n<\/code><\/pre>\n<p>\u8f93\u5165Key\u548cValue\u7684\u793a\u4f8b\u6570\u636e\u3002<\/p>\n<pre class=\"post-pre\"><code>vault kv put kv\/mysecret password=himitsu\r\n<\/code><\/pre>\n<p>\u786e\u8ba4\u3002<\/p>\n<pre class=\"post-pre\"><code>$ vault kv get kv\/mysecret\r\n====== Data ======\r\nKey         Value\r\n---         -----\r\npassword    himitsu\r\n<\/code><\/pre>\n<p>\u63a5\u4e0b\u6765\u8981\u521b\u5efa\u653f\u7b56\u3002<\/p>\n<pre class=\"post-pre\"><code>cat &lt;&lt;EOF &gt; \/tmp\/vault_sample_policy.hcl\r\npath \"*\" {\r\n    capabilities = [\"read\", \"list\"]\r\n}\r\nEOF\r\n<\/code><\/pre>\n<p>\u5206\u914d\u7b56\u7565\u3002\u6309\u7167\u6559\u7a0b\uff0c\u5c06\u7b56\u7565\u547d\u540d\u4e3amyapp-kv-ro\u3002<\/p>\n<pre class=\"post-pre\"><code>vault policy write myapp-kv-ro \/tmp\/vault_sample_policy.hcl\r\n<\/code><\/pre>\n<p>\u521b\u5efa\u4e00\u4e2a\u53ef\u4ee5\u64cd\u4f5cKubernetes\u4e2d\u8d44\u6e90\u7684ServiceAccount\u3002\u8fd9\u6b21\u6839\u636e\u6559\u7a0b\u5728\u9ed8\u8ba4\u7684Namespace\u4e2d\u521b\u5efa\u4e86\u8be5\u8d26\u6237\u3002\u7531\u4e8e\u5728\u6743\u9650\u4e0a\u9047\u5230\u4e86\u4e00\u4e9b\u95ee\u9898\uff0c\u6240\u4ee5\u6211\u5c06\u5176\u8bbe\u4e3a\u4e86cluster-admin\uff0c\u4f46\u6211\u8ba4\u4e3a\u53ef\u4ee5\u66f4\u7ec6\u5316\u6743\u9650\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"s\">cat &lt;&lt;EOF | kubectl apply -f -<\/span>\r\n<span class=\"na\">apiVersion<\/span><span class=\"pi\">:<\/span> <span class=\"s\">v1<\/span>\r\n<span class=\"na\">kind<\/span><span class=\"pi\">:<\/span> <span class=\"s\">ServiceAccount<\/span>\r\n<span class=\"na\">metadata<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">vault-auth<\/span>\r\n  <span class=\"na\">namespace<\/span><span class=\"pi\">:<\/span> <span class=\"s\">default<\/span>\r\n<span class=\"nn\">---<\/span>\r\n<span class=\"na\">apiVersion<\/span><span class=\"pi\">:<\/span> <span class=\"s\">rbac.authorization.k8s.io\/v1<\/span>\r\n<span class=\"na\">kind<\/span><span class=\"pi\">:<\/span> <span class=\"s\">ClusterRoleBinding<\/span>\r\n<span class=\"na\">metadata<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">role-tokenreview-binding<\/span>\r\n  <span class=\"na\">namespace<\/span><span class=\"pi\">:<\/span> <span class=\"s\">default<\/span>\r\n<span class=\"na\">roleRef<\/span><span class=\"pi\">:<\/span>\r\n  <span class=\"na\">apiGroup<\/span><span class=\"pi\">:<\/span> <span class=\"s\">rbac.authorization.k8s.io<\/span>\r\n  <span class=\"na\">kind<\/span><span class=\"pi\">:<\/span> <span class=\"s\">ClusterRole<\/span>\r\n  <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">cluster-admin<\/span>\r\n<span class=\"na\">subjects<\/span><span class=\"pi\">:<\/span>\r\n<span class=\"pi\">-<\/span> <span class=\"na\">kind<\/span><span class=\"pi\">:<\/span> <span class=\"s\">ServiceAccount<\/span>\r\n  <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">vault-auth<\/span>\r\n  <span class=\"na\">namespace<\/span><span class=\"pi\">:<\/span> <span class=\"s\">default<\/span>\r\n<span class=\"s\">EOF<\/span>\r\n<\/code><\/pre>\n<p>\u542f\u7528Kubernetes\u7684\u8eab\u4efd\u9a8c\u8bc1\uff0c\u5e76\u6dfb\u52a0\u8ba4\u8bc1\u4fe1\u606f\u3002<\/p>\n<pre class=\"post-pre\"><code>vault auth <span class=\"nb\">enable <\/span>kubernetes\r\n<span class=\"nb\">export <\/span><span class=\"nv\">SA_SECRET_NAME<\/span><span class=\"o\">=<\/span><span class=\"si\">$(<\/span>kubectl get secrets <span class=\"nt\">--output<\/span><span class=\"o\">=<\/span>json <span class=\"se\">\\<\/span>\r\n    | jq <span class=\"nt\">-r<\/span> <span class=\"s1\">'.items[].metadata | select(.name|startswith(\"vault-auth-\")).name'<\/span><span class=\"si\">)<\/span>\r\n<span class=\"nb\">export <\/span><span class=\"nv\">SA_JWT_TOKEN<\/span><span class=\"o\">=<\/span><span class=\"si\">$(<\/span>kubectl get secret <span class=\"nv\">$SA_SECRET_NAME<\/span> <span class=\"se\">\\<\/span>\r\n    <span class=\"nt\">--output<\/span> <span class=\"s1\">'go-template={{ .data.token }}'<\/span> | <span class=\"nb\">base64<\/span> <span class=\"nt\">--decode<\/span><span class=\"si\">)<\/span>\r\n<span class=\"nb\">export <\/span><span class=\"nv\">SA_CA_CRT<\/span><span class=\"o\">=<\/span><span class=\"si\">$(<\/span>kubectl config view <span class=\"nt\">--raw<\/span> <span class=\"nt\">--minify<\/span> <span class=\"nt\">--flatten<\/span> <span class=\"se\">\\<\/span>\r\n    <span class=\"nt\">--output<\/span> <span class=\"s1\">'jsonpath={.clusters[].cluster.certificate-authority-data}'<\/span> | <span class=\"nb\">base64<\/span> <span class=\"nt\">--decode<\/span><span class=\"si\">)<\/span>\r\n<span class=\"nb\">export <\/span><span class=\"nv\">K8S_HOST<\/span><span class=\"o\">=<\/span><span class=\"si\">$(<\/span>kubectl config view <span class=\"nt\">--raw<\/span> <span class=\"nt\">--minify<\/span> <span class=\"nt\">--flatten<\/span> <span class=\"se\">\\<\/span>\r\n    <span class=\"nt\">--output<\/span> <span class=\"s1\">'jsonpath={.clusters[].cluster.server}'<\/span><span class=\"si\">)<\/span>\r\nvault write auth\/kubernetes\/config <span class=\"se\">\\<\/span>\r\n     <span class=\"nv\">token_reviewer_jwt<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"<\/span><span class=\"nv\">$SA_JWT_TOKEN<\/span><span class=\"s2\">\"<\/span> <span class=\"se\">\\<\/span>\r\n     <span class=\"nv\">kubernetes_host<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"<\/span><span class=\"nv\">$K8S_HOST<\/span><span class=\"s2\">\"<\/span> <span class=\"se\">\\<\/span>\r\n     <span class=\"nv\">kubernetes_ca_cert<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"<\/span><span class=\"nv\">$SA_CA_CRT<\/span><span class=\"s2\">\"<\/span> <span class=\"se\">\\<\/span>\r\n     <span class=\"nv\">issuer<\/span><span class=\"o\">=<\/span><span class=\"s2\">\"https:\/\/kubernetes.default.svc.cluster.local\"<\/span>\r\n<\/code><\/pre>\n<p>\u53ea\u8981\u6ca1\u6709\u95ee\u9898\uff0c\u5e94\u8be5\u4f1a\u5f97\u5230\u4ee5\u4e0b\u4fe1\u606f\u4f5c\u4e3avault write auth\/kubernetes\/config\u7684\u7ed3\u679c\u3002<\/p>\n<pre class=\"post-pre\"><code>Success! Data written to: auth\/kubernetes\/config\r\n<\/code><\/pre>\n<p>\u63a5\u4e0b\u6765\u521b\u5efa\u4e00\u4e2a\u89d2\u8272\u3002\u89d2\u8272\u540d\u79f0\u4e3ahoge\u3002<\/p>\n<pre class=\"post-pre\"><code>vault write auth\/kubernetes\/role\/hoge \\\r\n     bound_service_account_names=vault-auth \\\r\n     bound_service_account_namespaces=default \\\r\n     policies=myapp-kv-ro \\\r\n     ttl=24h\r\n<\/code><\/pre>\n<p>\u6b64\u5916\uff0c\u5982\u679c\u60a8\u66f4\u6539\u4e86ServiceAccount\u7684\u540d\u79f0\u3001Namespace\u6216\u7b56\u7565\u540d\u79f0\uff0c\u8bf7\u76f8\u5e94\u5730\u4fee\u6539\u5e76\u6267\u884c\u3002<\/p>\n<pre class=\"post-pre\"><code>vault write auth\/kubernetes\/login role=hoge jwt=$SA_JWT_TOKEN iss=https:\/\/kubernetes.default.svc.cluster.local\r\n<\/code><\/pre>\n<h2>\u5c06Vault\u7684Secrets\u90e8\u7f72\u5230EKS\u4e0a\u3002<\/h2>\n<p>\u4f7f\u7528SecretStore\u8d44\u6e90\u4e0eVault\u8fdb\u884c\u8fde\u63a5\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"s\">cat &lt;&lt; EOF | kubectl apply -f -<\/span>\r\n <span class=\"s\">apiVersion<\/span><span class=\"err\">:<\/span> <span class=\"s\">external-secrets.io\/v1beta1<\/span>\r\n <span class=\"s\">kind<\/span><span class=\"err\">:<\/span> <span class=\"s\">SecretStore<\/span>\r\n <span class=\"s\">metadata<\/span><span class=\"err\">:<\/span>\r\n   <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">vault-backend<\/span>\r\n <span class=\"na\">spec<\/span><span class=\"pi\">:<\/span>\r\n   <span class=\"na\">provider<\/span><span class=\"pi\">:<\/span>\r\n     <span class=\"na\">vault<\/span><span class=\"pi\">:<\/span>\r\n       <span class=\"na\">server<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">https:\/\/vault.mydomain.info\"<\/span>\r\n       <span class=\"na\">path<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">kv\"<\/span>\r\n       <span class=\"na\">version<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">v1\"<\/span>\r\n       <span class=\"na\">namespace<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">default\"<\/span>\r\n       <span class=\"na\">auth<\/span><span class=\"pi\">:<\/span>\r\n         <span class=\"na\">kubernetes<\/span><span class=\"pi\">:<\/span>\r\n           <span class=\"na\">mountPath<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">kubernetes\"<\/span>\r\n           <span class=\"na\">role<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">hoge\"<\/span>\r\n           <span class=\"na\">serviceAccountRef<\/span><span class=\"pi\">:<\/span>\r\n             <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s2\">\"<\/span><span class=\"s\">vault-auth\"<\/span>\r\n<span class=\"s\">EOF<\/span>\r\n<\/code><\/pre>\n<p>\u53e6\u5916\uff0c\u5982\u679c\u5c07\u7248\u672c\u8a2d\u7f6e\u70ba&#8221;v2&#8243;\uff0c\u5728\u5275\u5efaExternalSecret\u6642\u53ef\u80fd\u6703\u51fa\u73fe\u4ee5\u4e0b\u932f\u8aa4\uff0c\u5c0e\u81f4Secret\u7121\u6cd5\u6210\u529f\u5275\u5efa\u3002\u6211\u4e5f\u9047\u5230\u4e86\u9019\u500b\u554f\u984c\uff0c\u5361\u5728\u9019\u88e1\u4e00\u6bb5\u6642\u9593\u3002<\/p>\n<pre class=\"post-pre\"><code>\"cannot read secret data from Vault: Error making API request.\\n\\nNamespace: default\\nURL: GET https:\/\/vault.mydomain.info\/v1\/kv\/data\/mysecret\\nCode: 404.\r\n<\/code><\/pre>\n<p>\u56e0\u6b64\uff0c\u6211\u53c2\u8003\u4e86\u8fd9\u7bc7\u6587\u7ae0\u5e76\u8fdb\u884c\u4e86v1\u7684\u4fee\u6539\uff0c\u4ee5\u907f\u514d\u8fd9\u4e2a\u95ee\u9898\u3002<\/p>\n<p>\u203b\u8865\u5145\uff1a<br \/>\n\u901a\u8fc7GUI\u521b\u5efaKV\u65f6\u6210\u4e3av2\u7248\u672c\uff0c\u901a\u8fc7CLI\u521b\u5efa\u4e5f\u662fv2\u7248\u672c\u3002\u901a\u8fc7GUI\u521b\u5efa\u7684\u4eba\u9700\u8981\u9009\u62e9v2\u7248\u672c\u6216\u4e0d\u6307\u5b9a\u7248\u672c\u3002<\/p>\n<p>\u786e\u8ba4\u72b6\u6001\u3002<\/p>\n<pre class=\"post-pre\"><code>$ kubectl get secretstore\r\nNAME            AGE   STATUS\r\nvault-backend   8s    Valid\r\n<\/code><\/pre>\n<p>\u53e6\u5916\uff0c\u5982\u679c\u6709\u8bbe\u7f6e\u9519\u8bef\u7b49\u95ee\u9898\uff0c\u5c31\u4f1a\u51fa\u73b0\u4ee5\u4e0b\u60c5\u51b5\u3002<\/p>\n<pre class=\"post-pre\"><code>$ kubectl get secretstore.external-secrets.io\/vault-backend\r\nNAME            AGE     STATUS\r\nvault-backend   9m50s   InvalidProviderConfig\r\n<\/code><\/pre>\n<p>\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u5982\u679c\u5fd8\u8bb0\u8bbe\u7f6eServiceAccount\uff0c\u5219external-secrets\u7684Pod\u5185\u4f1a\u51fa\u73b0\u7c7b\u4f3c\u4e8eCode: 500. Errors: * service account name not authorized\u7684\u9519\u8bef\u3002\u8bf7\u6839\u636e\u9519\u8bef\u4fe1\u606f\u786e\u8ba4\u53d1\u751f\u4e86\u4ec0\u4e48\u3002<\/p>\n<p>\u63a5\u4e0b\u6765\uff0c\u5c06ExternalSecret\u4f5c\u4e3aKubernetes\u7684Secret\u8d44\u6e90\u8fdb\u884c\u5bfc\u5165\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"s\">cat &lt;&lt;EOF | kubectl apply -f -<\/span>\r\n <span class=\"s\">apiVersion<\/span><span class=\"err\">:<\/span> <span class=\"s\">external-secrets.io\/v1beta1<\/span>\r\n <span class=\"s\">kind<\/span><span class=\"err\">:<\/span> <span class=\"s\">ExternalSecret<\/span>\r\n <span class=\"s\">metadata<\/span><span class=\"err\">:<\/span>\r\n   <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">vault-example<\/span>\r\n <span class=\"na\">spec<\/span><span class=\"pi\">:<\/span>\r\n   <span class=\"na\">secretStoreRef<\/span><span class=\"pi\">:<\/span>\r\n     <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">vault-backend<\/span>\r\n     <span class=\"na\">kind<\/span><span class=\"pi\">:<\/span> <span class=\"s\">SecretStore<\/span>\r\n   <span class=\"na\">target<\/span><span class=\"pi\">:<\/span>\r\n     <span class=\"na\">name<\/span><span class=\"pi\">:<\/span> <span class=\"s\">vault-example-secret<\/span>\r\n   <span class=\"na\">data<\/span><span class=\"pi\">:<\/span>\r\n   <span class=\"pi\">-<\/span> <span class=\"na\">secretKey<\/span><span class=\"pi\">:<\/span> <span class=\"s\">fuga<\/span>\r\n     <span class=\"na\">remoteRef<\/span><span class=\"pi\">:<\/span>\r\n       <span class=\"na\">key<\/span><span class=\"pi\">:<\/span> <span class=\"s\">mysecret<\/span>\r\n       <span class=\"na\">property<\/span><span class=\"pi\">:<\/span> <span class=\"s\">password<\/span>\r\n<span class=\"s\">EOF<\/span>\r\n<\/code><\/pre>\n<p>spec.target.name\u662f\u521b\u5efa\u7684Secret\u7684\u540d\u79f0\uff0cspec.data.secretKey\u662f\u521b\u5efa\u7684Secret\u4e2d\u7684Key\u3002spec.data.remoteRef\u7528\u4e8e\u8bbe\u7f6eVault\u7aef\u7684\u8def\u5f84\uff08\u53bb\u9664SecretStore\u6307\u5b9a\u7684\u8def\u5f84\u90e8\u5206\uff09\u548cKey-Value\u7684key\uff08\u5c5e\u6027\uff09\u3002<\/p>\n<p>\u5982\u679c\u5728\u521b\u5efa\u4e0a\u8ff0\u8d44\u6e90\u540e\uff0c\u72b6\u6001\u53d8\u4e3aSecretSynced\uff0c\u5219\u8868\u793a\u4e00\u5207\u6b63\u5e38\u3002<\/p>\n<pre class=\"post-pre\"><code>$ kubectl get externalsecret\r\nNAME            STORE           REFRESH INTERVAL   STATUS\r\nvault-example   vault-backend   1h                 SecretSynced\r\n<\/code><\/pre>\n<p>\u53ef\u4ee5\u5bdf\u89c9\u5230\u5df2\u521b\u5efa\u4e86Secret\uff0c\u5e76\u4e14\u53ef\u4ee5\u4eceVault\u4e2d\u63d0\u53d6\u503c\u3002<\/p>\n<pre class=\"post-pre\"><code>$ kubectl get secret vault-example-secret -o jsonpath={.data.fuga} | base64 -d\r\nhimitsu\r\n<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>\u5916\u90e8\u79d8\u5bc6\u662f\u6307\u7684\u662f\u4ec0\u4e48\uff1f \u901a\u5e38\u60c5\u51b5\u4e0b\uff0c\u5728\u4f7f\u7528EKS\u7684ExternalSecret\u65f6\uff0c\u6211\u4eec\u901a\u5e38\u4f1a\u4eceSecretMa [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-35994","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u4f7f\u7528ExternalSecret\u5728EKS\u4e2d\u5c06Vault\u7684\u6570\u636e(kv)\u4f5c\u4e3a\u5bc6\u94a5\u52a0\u8f7d\u8fdb\u6765 - Blog - Silicon Cloud<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528externalsecret\u5728eks\u4e2d\u5c06vault\u7684\u6570\u636ekv\u4f5c\u4e3a\u5bc6\u94a5\u52a0\u8f7d\u8fdb\u6765\u3002\/\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u4f7f\u7528ExternalSecret\u5728EKS\u4e2d\u5c06Vault\u7684\u6570\u636e(kv)\u4f5c\u4e3a\u5bc6\u94a5\u52a0\u8f7d\u8fdb\u6765\" \/>\n<meta property=\"og:description\" content=\"\u5916\u90e8\u79d8\u5bc6\u662f\u6307\u7684\u662f\u4ec0\u4e48\uff1f \u901a\u5e38\u60c5\u51b5\u4e0b\uff0c\u5728\u4f7f\u7528EKS\u7684ExternalSecret\u65f6\uff0c\u6211\u4eec\u901a\u5e38\u4f1a\u4eceSecretMa [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528externalsecret\u5728eks\u4e2d\u5c06vault\u7684\u6570\u636ekv\u4f5c\u4e3a\u5bc6\u94a5\u52a0\u8f7d\u8fdb\u6765\u3002\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2024-02-03T22:32:27+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-29T06:10:22+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d26f237434c4406c39eca\/1-0.png\" \/>\n<meta name=\"author\" content=\"\u6587, \u7fd4\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u6587, \u7fd4\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8externalsecret%e5%9c%a8eks%e4%b8%ad%e5%b0%86vault%e7%9a%84%e6%95%b0%e6%8d%aekv%e4%bd%9c%e4%b8%ba%e5%af%86%e9%92%a5%e5%8a%a0%e8%bd%bd%e8%bf%9b%e6%9d%a5%e3%80%82\/\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8externalsecret%e5%9c%a8eks%e4%b8%ad%e5%b0%86vault%e7%9a%84%e6%95%b0%e6%8d%aekv%e4%bd%9c%e4%b8%ba%e5%af%86%e9%92%a5%e5%8a%a0%e8%bd%bd%e8%bf%9b%e6%9d%a5%e3%80%82\/\",\"name\":\"\u4f7f\u7528ExternalSecret\u5728EKS\u4e2d\u5c06Vault\u7684\u6570\u636e(kv)\u4f5c\u4e3a\u5bc6\u94a5\u52a0\u8f7d\u8fdb\u6765 - Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\"},\"datePublished\":\"2024-02-03T22:32:27+00:00\",\"dateModified\":\"2024-04-29T06:10:22+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/64d5cc7727fffbff2f9a2a8da1de3e5c\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8externalsecret%e5%9c%a8eks%e4%b8%ad%e5%b0%86vault%e7%9a%84%e6%95%b0%e6%8d%aekv%e4%bd%9c%e4%b8%ba%e5%af%86%e9%92%a5%e5%8a%a0%e8%bd%bd%e8%bf%9b%e6%9d%a5%e3%80%82\/#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8externalsecret%e5%9c%a8eks%e4%b8%ad%e5%b0%86vault%e7%9a%84%e6%95%b0%e6%8d%aekv%e4%bd%9c%e4%b8%ba%e5%af%86%e9%92%a5%e5%8a%a0%e8%bd%bd%e8%bf%9b%e6%9d%a5%e3%80%82\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8externalsecret%e5%9c%a8eks%e4%b8%ad%e5%b0%86vault%e7%9a%84%e6%95%b0%e6%8d%aekv%e4%bd%9c%e4%b8%ba%e5%af%86%e9%92%a5%e5%8a%a0%e8%bd%bd%e8%bf%9b%e6%9d%a5%e3%80%82\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.silicloud.com\/zh\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u4f7f\u7528ExternalSecret\u5728EKS\u4e2d\u5c06Vault\u7684\u6570\u636e(kv)\u4f5c\u4e3a\u5bc6\u94a5\u52a0\u8f7d\u8fdb\u6765\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/64d5cc7727fffbff2f9a2a8da1de3e5c\",\"name\":\"\u6587, \u7fd4\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/920c3d673e0bccacc98e5e6b7149bb3c22edd8d39cb753e5d7d7e471498118a1?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/920c3d673e0bccacc98e5e6b7149bb3c22edd8d39cb753e5d7d7e471498118a1?s=96&d=mm&r=g\",\"caption\":\"\u6587, \u7fd4\"},\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/author\/wenxiang\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8externalsecret%e5%9c%a8eks%e4%b8%ad%e5%b0%86vault%e7%9a%84%e6%95%b0%e6%8d%aekv%e4%bd%9c%e4%b8%ba%e5%af%86%e9%92%a5%e5%8a%a0%e8%bd%bd%e8%bf%9b%e6%9d%a5%e3%80%82\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u4f7f\u7528ExternalSecret\u5728EKS\u4e2d\u5c06Vault\u7684\u6570\u636e(kv)\u4f5c\u4e3a\u5bc6\u94a5\u52a0\u8f7d\u8fdb\u6765 - Blog - Silicon Cloud","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528externalsecret\u5728eks\u4e2d\u5c06vault\u7684\u6570\u636ekv\u4f5c\u4e3a\u5bc6\u94a5\u52a0\u8f7d\u8fdb\u6765\u3002\/","og_locale":"zh_CN","og_type":"article","og_title":"\u4f7f\u7528ExternalSecret\u5728EKS\u4e2d\u5c06Vault\u7684\u6570\u636e(kv)\u4f5c\u4e3a\u5bc6\u94a5\u52a0\u8f7d\u8fdb\u6765","og_description":"\u5916\u90e8\u79d8\u5bc6\u662f\u6307\u7684\u662f\u4ec0\u4e48\uff1f \u901a\u5e38\u60c5\u51b5\u4e0b\uff0c\u5728\u4f7f\u7528EKS\u7684ExternalSecret\u65f6\uff0c\u6211\u4eec\u901a\u5e38\u4f1a\u4eceSecretMa [&hellip;]","og_url":"https:\/\/www.silicloud.com\/zh\/blog\/\u4f7f\u7528externalsecret\u5728eks\u4e2d\u5c06vault\u7684\u6570\u636ekv\u4f5c\u4e3a\u5bc6\u94a5\u52a0\u8f7d\u8fdb\u6765\u3002\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2024-02-03T22:32:27+00:00","article_modified_time":"2024-04-29T06:10:22+00:00","og_image":[{"url":"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d26f237434c4406c39eca\/1-0.png"}],"author":"\u6587, \u7fd4","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"\u6587, \u7fd4","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"3 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8externalsecret%e5%9c%a8eks%e4%b8%ad%e5%b0%86vault%e7%9a%84%e6%95%b0%e6%8d%aekv%e4%bd%9c%e4%b8%ba%e5%af%86%e9%92%a5%e5%8a%a0%e8%bd%bd%e8%bf%9b%e6%9d%a5%e3%80%82\/","url":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8externalsecret%e5%9c%a8eks%e4%b8%ad%e5%b0%86vault%e7%9a%84%e6%95%b0%e6%8d%aekv%e4%bd%9c%e4%b8%ba%e5%af%86%e9%92%a5%e5%8a%a0%e8%bd%bd%e8%bf%9b%e6%9d%a5%e3%80%82\/","name":"\u4f7f\u7528ExternalSecret\u5728EKS\u4e2d\u5c06Vault\u7684\u6570\u636e(kv)\u4f5c\u4e3a\u5bc6\u94a5\u52a0\u8f7d\u8fdb\u6765 - Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website"},"datePublished":"2024-02-03T22:32:27+00:00","dateModified":"2024-04-29T06:10:22+00:00","author":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/64d5cc7727fffbff2f9a2a8da1de3e5c"},"breadcrumb":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8externalsecret%e5%9c%a8eks%e4%b8%ad%e5%b0%86vault%e7%9a%84%e6%95%b0%e6%8d%aekv%e4%bd%9c%e4%b8%ba%e5%af%86%e9%92%a5%e5%8a%a0%e8%bd%bd%e8%bf%9b%e6%9d%a5%e3%80%82\/#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8externalsecret%e5%9c%a8eks%e4%b8%ad%e5%b0%86vault%e7%9a%84%e6%95%b0%e6%8d%aekv%e4%bd%9c%e4%b8%ba%e5%af%86%e9%92%a5%e5%8a%a0%e8%bd%bd%e8%bf%9b%e6%9d%a5%e3%80%82\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8externalsecret%e5%9c%a8eks%e4%b8%ad%e5%b0%86vault%e7%9a%84%e6%95%b0%e6%8d%aekv%e4%bd%9c%e4%b8%ba%e5%af%86%e9%92%a5%e5%8a%a0%e8%bd%bd%e8%bf%9b%e6%9d%a5%e3%80%82\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.silicloud.com\/zh\/blog\/"},{"@type":"ListItem","position":2,"name":"\u4f7f\u7528ExternalSecret\u5728EKS\u4e2d\u5c06Vault\u7684\u6570\u636e(kv)\u4f5c\u4e3a\u5bc6\u94a5\u52a0\u8f7d\u8fdb\u6765"}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website","url":"https:\/\/www.silicloud.com\/zh\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/64d5cc7727fffbff2f9a2a8da1de3e5c","name":"\u6587, \u7fd4","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/920c3d673e0bccacc98e5e6b7149bb3c22edd8d39cb753e5d7d7e471498118a1?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/920c3d673e0bccacc98e5e6b7149bb3c22edd8d39cb753e5d7d7e471498118a1?s=96&d=mm&r=g","caption":"\u6587, \u7fd4"},"url":"https:\/\/www.silicloud.com\/zh\/blog\/author\/wenxiang\/"},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e4%bd%bf%e7%94%a8externalsecret%e5%9c%a8eks%e4%b8%ad%e5%b0%86vault%e7%9a%84%e6%95%b0%e6%8d%aekv%e4%bd%9c%e4%b8%ba%e5%af%86%e9%92%a5%e5%8a%a0%e8%bd%bd%e8%bf%9b%e6%9d%a5%e3%80%82\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/35994","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/comments?post=35994"}],"version-history":[{"count":2,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/35994\/revisions"}],"predecessor-version":[{"id":85739,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/35994\/revisions\/85739"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/media?parent=35994"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/categories?post=35994"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/tags?post=35994"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}