AKS SecretProviderClass with KeyVault
Related Notes
Introduction
SecretProviderClassconfigures the Azure Key Vault provider for the Secrets Store CSI Driver. A Pod can mount Key Vault content as a volume. To sync mounted content into a Kubernetes Secret, definesecretObjectsand start a Pod that mounts the volume. The synced Secret is removed when consuming Pods are deleted. See AKS configuration options.- Reference docs:
- Azure docs: https://docs.azure.cn/en-us/aks/csi-secrets-store-configuration-options
- SecretProviderClass supported parameters: https://github.com/Azure/secrets-store-csi-driver-provider-azure/blob/master/website/content/en/getting-started/usage/_index.md
Deployment
Prerequisites
Required Steps Before Deployment
- Create a user-assigned managed identity (or configure workload identity)
- Grant the identity permission to read Secrets on Azure Key Vault (Access Policy or RBAC)
- Copy the identity's client ID
Create SecretProviderClass
apiVersion: secrets-store.csi.x-k8s.io/v1
kind: SecretProviderClass
metadata:
name: <Name-of-SecretProviderClass>
namespace: <your-namepace>
spec:
provider: azure
parameters:
usePodIdentity: "false"
useVMManagedIdentity: "true"
tenantId: <tenant-id>
# Set the clientID of the user-assigned managed identity to use, e.g. azurekeyvaultsecretsprovider-aks-commoninfra-dev-chinanorth3
userAssignedIdentityID: <secretProviderIdentityId>
keyvaultName: <keyvaultName>
cloudName: AzureChinaCloud
objects: |
array:
- |
objectName: <Azure-Key-vault-secret-name>
objectType: secret
objectVersion: ""
# Sync the mounted Key Vault value to a Kubernetes Secret when a Pod mounts this volume.
secretObjects:
- secretName: <kubernetes-secret-name-to-be-generated> # Note that the namespace of newly created secret will be the same as this SecretProviderClass
data:
- key: <key-name> # add a secret referencable with the same key as was in the keyvault
objectName: <keep-the-same-of-"spec.parameters.objects.objectName">
type: Opaque
Namespace
The synced Kubernetes Secret is created in the same namespace as the SecretProviderClass, after a Pod mounts the CSI volume.