Shh, It’s a Secret: Managing Your Secrets in a GitOps Way - Jake Wernette & Josh Kayani, IBM

  Рет қаралды 6,368

CNCF [Cloud Native Computing Foundation]

CNCF [Cloud Native Computing Foundation]

Күн бұрын

Don’t miss out! Join us at our next event: KubeCon + CloudNativeCon Europe 2022 in Valencia, Spain from May 17-20. Learn more at kubecon.io The conference features presentations from developers and end users of Kubernetes, Prometheus, Envoy, and all of the other CNCF-hosted projects.
Shh, It’s a Secret: Managing Your Secrets in a GitOps Way - Jake Wernette & Josh Kayani, IBM
How do you handle secrets? That is the first question that is asked whenever you are talking about GitOps. And it is a valid question! Do you put secrets directly in Git? Do you inject them in runtime? This is something that is trying to be answered across the community and in many different ways. Jake and his team at IBM looked at the landscape of GitOps specifically with Argo CD and could not find something that fit their needs. This talk will showcase how they were able to build and adopt argocd-vault-plugin and how it was able to simplify their secret management while allowing them to manage it in a GitOps way. Hopefully this talk will help you along in your GitOps journey and bridge the secrets gap that we are seeing so often in the community.

Пікірлер: 6
@harshvardhanchauhan1604
@harshvardhanchauhan1604 11 ай бұрын
Do we have a HOWTO doc for setting up ArgoCD vault plug-in + AWS secret manager?
@user-oe4jx5vj2c
@user-oe4jx5vj2c 11 ай бұрын
"Don't do it like that in production." (19:40) Well, but how should i do it instead? Create multiple roles? All are managed by argo, so what's the point?
@adarshaj
@adarshaj 2 жыл бұрын
So when i fetch the yaml for the deployed application, I'll be able to see the secret as is? I think the point of secret is that the deployment environment will ensure the secret is injected at runtime, so anyone outside of cluster will not be able to see the password.. but with this kind of rendering, we are encoding the secret right into the yaml of the resource, so anyone who can read the resources will now also know the password..
@Luther_Luffeigh
@Luther_Luffeigh 2 жыл бұрын
Anyone with permissions
@adarshaj
@adarshaj 2 жыл бұрын
@@Luther_Luffeigh That's the problem! with secrets directly interspersed into resource's yaml, I do not have a separate RBAC to restrict access to the secret. So if I use AVP there's no way for me to restrict who can access my secrets.
@destr08
@destr08 11 ай бұрын
Argocd custom plug-in is shit, don't use it. Had too much pain with it
100,000 Different Ways to Manage Secrets in GitOps - Andrew Block, Red Hat
28:54
CNCF [Cloud Native Computing Foundation]
Рет қаралды 2,4 М.
GitOps Is Likely More Than You Think It Is - Cornelia Davis, Weaveworks
33:41
CNCF [Cloud Native Computing Foundation]
Рет қаралды 8 М.
Omega Boy Past 3 #funny #viral #comedy
00:22
CRAZY GREAPA
Рет қаралды 25 МЛН
Chips evolution !! 😔😔
00:23
Tibo InShape
Рет қаралды 42 МЛН
ArgoCD Tutorial for Beginners | GitOps CD for Kubernetes
47:53
TechWorld with Nana
Рет қаралды 582 М.
How to put a Database in Kubernetes - Jeffrey Carpenter, DataStax
35:20
CNCF [Cloud Native Computing Foundation]
Рет қаралды 8 М.
Manage Kubernetes Secrets with Mozilla SOPS & Flux 2 (with Leigh Capili)
1:00:08
Kubernetes Deconstructed: Understanding Kubernetes by Breaking It Down - Carson Anderson, DOMO
33:15
CNCF [Cloud Native Computing Foundation]
Рет қаралды 186 М.
OpenTelemetry Collector Deployment Patterns - Juraci Paixão Kröhling, Red Hat
25:09
CNCF [Cloud Native Computing Foundation]
Рет қаралды 11 М.
Let's do GitOps in Kubernetes! ArgoCD Tutorial
18:01
Christian Lempa
Рет қаралды 60 М.
Practical Kubernetes Monitoring with Prometheus - Michael Friedrich, GitLab
23:51
CNCF [Cloud Native Computing Foundation]
Рет қаралды 6 М.
Kubernetes Explained
10:59
IBM Technology
Рет қаралды 599 М.
#miniphone
0:18
Miniphone
Рет қаралды 11 МЛН
wyłącznik
0:50
Panele Fotowoltaiczne
Рет қаралды 22 МЛН
📱 SAMSUNG, ЧТО С ЛИЦОМ? 🤡
0:46
Яблочный Маньяк
Рет қаралды 1,7 МЛН
iPhone 15 Pro vs Samsung s24🤣 #shorts
0:10
Tech Tonics
Рет қаралды 9 МЛН