AKS SecretProviderClass with KeyVault


Introduction

  • SecretProviderClass configures the Azure Key Vault provider for the Secrets Store CSI Driver. A Pod can mount Key Vault content as a volume. To sync mounted content into a Kubernetes Secret, define secretObjects and start a Pod that mounts the volume. The synced Secret is removed when consuming Pods are deleted. See AKS configuration options.
  • Reference docs:
  • Azure docs: https://docs.azure.cn/en-us/aks/csi-secrets-store-configuration-options
  • SecretProviderClass supported parameters: https://github.com/Azure/secrets-store-csi-driver-provider-azure/blob/master/website/content/en/getting-started/usage/_index.md

Deployment

Prerequisites

Required Steps Before Deployment

  1. Create a user-assigned managed identity (or configure workload identity)
  2. Grant the identity permission to read Secrets on Azure Key Vault (Access Policy or RBAC)
  3. Copy the identity's client ID

Create SecretProviderClass

apiVersion: secrets-store.csi.x-k8s.io/v1
kind: SecretProviderClass
metadata:
  name: <Name-of-SecretProviderClass>
  namespace: <your-namepace>
spec:
  provider: azure
  parameters:
    usePodIdentity: "false"
    useVMManagedIdentity: "true"
    tenantId: <tenant-id>
    # Set the clientID of the user-assigned managed identity to use, e.g. azurekeyvaultsecretsprovider-aks-commoninfra-dev-chinanorth3
    userAssignedIdentityID: <secretProviderIdentityId>
    keyvaultName: <keyvaultName>
    cloudName: AzureChinaCloud
    objects:  |
      array:
        - |
          objectName: <Azure-Key-vault-secret-name>
          objectType: secret
          objectVersion: ""
  # Sync the mounted Key Vault value to a Kubernetes Secret when a Pod mounts this volume.
  secretObjects:
  - secretName: <kubernetes-secret-name-to-be-generated> # Note that the namespace of newly created secret will be the same as this SecretProviderClass
    data:
    - key: <key-name> # add a secret referencable with the same key as was in the keyvault
      objectName: <keep-the-same-of-"spec.parameters.objects.objectName">
    type: Opaque

Namespace

The synced Kubernetes Secret is created in the same namespace as the SecretProviderClass, after a Pod mounts the CSI volume.