赞
踩
轻松管理很多Kubernetes资源
以有状态方式管理Kubernetes资源
进入生产之前对Kubernetes资源进行检视
Kubernetes中处理敏感数据
- context: eks_staging
- releases:
- - chart: charts/apps/event-processor
- name: staging-event-processor
- values:
- - chart/sapps/event-processor/values/staging/values.yaml
- - chart: charts/apps/delivery-manager
- name: staging-delivery-manager
- values:
- - chart/sapps/delivery-manager/values/staging/values.yaml
helmfile --file helmfiles/staging.yaml sync
- $ helmfile --selector name=ingress01 --file helmfiles/staging/infra.yaml diff
- exec: helm diff upgrade --allow-unreleased ingress01 stable/nginx-ingress --version 1.0.1 --values nginx-ingress/staging/values.yaml --kube-context eks_staging
- default, ingress01-nginx-ingress-controller, ConfigMap (v1) has changed:
- # Source: nginx-ingress/templates/controller-configmap.yaml
- apiVersion: v1
- kind: ConfigMap
- metadata:
- labels:
- app: nginx-ingress
- chart: nginx-ingress-1.0.1
- component: "controller"
- heritage: Tiller
- release: ingress01
- name: ingress01-nginx-ingress-controller
- data:
- enable-vts-status: "true"
- log-format-escape-json: "true"
- proxy-next-upstream: error timeout http_502
- - proxy-next-upstream-tries: "3"
- + proxy-next-upstream-tries: "2"
- use-geoip: "true

加密信息文件可以安全存放在Git中
对云提供商授权需要解密
YAML键值仍然未加密,因此pull请求仍然会滥用敏感字段
Helm图表中加密字段可以如其他键值对一样被使用
- context: eks_staging
- releases:
- - chart: charts/apps/event-processor
- name: staging-event-processor
- values:
- - charts/apps/event-processor/values/staging/values.yaml
- secrets:
- - charts/apps/event-processor/values/staging/secrets.yaml
- secrets:
- API_KEY: ENC[AES256_GCM,data:xxxxxxxxx=,tag:xxxxxx==,type:str]
Copyright © 2003-2013 www.wpsshop.cn 版权所有,并保留所有权利。