티스토리 뷰

문제

Cluster: kubectl config use-context k8s
Create a Kubernetes secret and expose using a file in the pod.
1. Create a kubetnetes Secret as follows:
  • Name: super-secret
  • DATA:
    password =secretpass
  1. Create a Pod named pod-secrets-via-file, using the redis image, which mounts a secret named super-secret at /secrets .
  2. Create a second Pod named pod-secrets-via-env, using the redis image, which exports password as PASSWORD.

 

문제 풀이

# 1. context 변경
kubectl config use-context k8s

# 2. Secret 생성
kubectl create secret generic super-secret --from-literal=password=secretpass
kubectl describe secrets super-secret

# 3. pod-secrets-via-file.yaml 작성 및 생성
kubectl run pod-secrets-via-file --image=redis --dry-run=client -o yaml > pod-secrets-via-file.yaml
vim pod-secrets-via-file.yaml

....

apiVersion: v1
kind: Pod
metadata:
  labels:
    run: pod-secrets-via-file
  name: pod-secrets-via-file
spec:
  containers:
  - image: redis
    name: redis
    volumeMounts:
      - name: secret-volume
        mountPath: /secrets

  volumes:
    - name: secret-volume
      secret:
        secretName: super-secret

kubectl apply -f pod-secrets-via-file.yaml


# 4. pod-secrets-via-file pod 확인
kubectl get pods
kubectl exec pod-secrets-via-file -- ls /secrets/password
kubectl exec pod-secrets-via-file -- cat /secrets/password

# 5. pod-secrets-via-env.yaml 작성 및 생성
kubectl run pod-secrets-via-env --image=redis --dry-run=client -o yaml > pod-secrets-via-env.yaml

vim pod-secrets-via-env.yaml

....

apiVersion: v1
kind: Pod
metadata:
  labels:
    run: pod-secrets-via-env
  name: pod-secrets-via-env
spec:
  containers:
  - image: redis
    name: pod-secrets-via-env
    env:
      - name: PASSWORD
        valueFrom:
          secretKeyRef:
            name: super-secret
            key: password

kubectl apply -f pod-secrets-via-env.yaml

# 6. pod-secrets-via-env pod 확인
kubectl get pods
kubectl exec pod-secrets-via-env -- env
 

Secrets

A Secret is an object that contains a small amount of sensitive data such as a password, a token, or a key. Such information might otherwise be put in a Pod specification or in a container image. Using a Secret means that you don't need to include confiden

kubernetes.io

 

 

공지사항
최근에 올라온 글
최근에 달린 댓글
Total
Today
Yesterday
링크
«   2026/09   »
일 월 화 수 목 금 토
1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30
글 보관함