Lesson 9 - Mounting Secrets as Volumes
Hello,
On Lesson 9, mounting secrets as Volumes, it is said that we can verify that the secret is accessible in the container, by running the command:
$ kubectl ......................--cat/mysqlpassword/password
However, given the configuration of the secret spec on the same page, the secret name is mysql
Therefore, the command to verify if the secret is running on the container, perhaps it should be:
$ kubectl ......................--cat/mysqlpassword/mysql
I would appreciate if someone could shed some light on this.
Thank you,
Josep Maria
Answers
-
Hello @josepmaria,
When you mount a secret as a volume, the "keys" of the secrets will be created as files and the content of those files will be the "value".
In the above example - kubectl create secret generic mysql --from-literal=password=root
name of secret is mysql -
name of the key is password
value of the key is rootWhen you mount the secret mysql at the path /mysqlpassword (as per the yaml in the example), you will find the "keys" as files.
TLDR, The command mentioned in the course is correct to view the secret you will " kubectl exec -ti busybox -- cat /mysqlpassword/password"
Regards,
Fazlur0 -
Hello @fazlur.khan ,
Thanks for your answer.
In the provided specs for Lesson 9, Mounting secrets as Volumes, we can see:
....volumeMounts:- mountPath: /mysqlpasswordname: mysqlname: busyvolumes:- name: mysqlsecret:secretName: mysqlIf the key is
mysql, I do not understand why the command to view the password is not :" kubectl exec -ti busybox -- cat /mysqlpassword/mysql"
instead of" kubectl exec -ti busybox -- cat /mysqlpassword/password"Please kindly let me know.
Thank you.
Josep Maria
0 -
To access data from a Secret in a Pod, you can let Kubernetes create a file inside the Pod's container(s) that contains the Secret's value.
For example, if you have a Secret called mysql with a key-value pair like "password: admin", Kubernetes can place this value in a file (e.g., /mysqlpassword/password) inside the container. The container can then read the file to get the password.
In the yaml manifest, we are referring the secret name, the contents of the secret will be created as files and made available at the path you want it to be mounted.
The key is not mysql, mysql is the secret name and you are just referencing it. You are asking all of the contents of this secret "mysql" to be made available as files in the mountpath of your choice.
1 -
Hello @fazlur.khan ,
I appreciate your quick answer.
Now I understand. Thank you very much.
Sincerely,
Josep Maria
0
Categories
- All Categories
- 177 LFX Mentorship
- 177 LFX Mentorship: Linux Kernel
- 750 Linux Foundation IT Professional Programs
- 373 Cloud Engineer IT Professional Program
- 169 Advanced Cloud Engineer IT Professional Program
- 74 DevOps IT Professional Program - Discontinued
- 4 DevOps & GitOps IT Professional Program
- 99 Cloud Native Developer IT Professional Program
- 7.6K Training Courses & Learning Paths
- 1 AI & ML Training
- 1 Blockchain & Decentralized Identity Training
- 4 Cloud & Containers Training
- 1 Cybersecurity Training
- 2 DevOps & Site-Reliability Training
- 1 Linux Kernel Development Training
- 1 Networking Training
- 2 Open Source Best Practice Training
- 1 System Administration Training
- 1 System Engineering Training
- 1 Web & Application Development Training
- 792 Hardware
- 202 Drivers
- 68 I/O Devices
- 37 Monitors
- 95 Multimedia
- 173 Networking
- 91 Printers & Scanners
- 87 Storage
- 769 Linux Distributions
- 81 Debian
- 68 Fedora
- 22 Linux Mint
- 13 Mageia
- 24 openSUSE
- 150 Red Hat Enterprise
- 31 Slackware
- 13 SUSE Enterprise
- 356 Ubuntu
- 465 Linux System Administration
- 31 Cloud Computing
- 73 Command Line/Scripting
- Github systems admin projects
- 98 Linux Security
- 78 Network Management
- 101 System Management
- 46 Web Management
- 106 Mobile Computing
- 18 Android
- 73 Development
- 1.2K New to Linux
- 1K Getting Started with Linux
- 392 Off Topic
- 121 Introductions
- 181 Small Talk
- 29 Study Material
- 955 Programming and Development
- 310 Kernel Development
- 627 Software Development
- 983 Software
- 375 Applications
- 182 Command Line
- 5 Compiling/Installing
- 68 Games
- 317 Installation
- Archived
- 2 LFD140 Class Forum
- 1.4K LFS258 Class Forum
Upcoming Training
-
August 20, 2018
Kubernetes Administration (LFS458)
-
August 20, 2018
Linux System Administration (LFS301)
-
August 27, 2018
Open Source Virtualization (LFS462)
-
August 27, 2018
Linux Kernel Debugging and Security (LFD440)
