Merge remote-tracking branch 'origin/1.0.x'

This commit is contained in:
Ryan Baxter
2019-09-03 19:44:46 -04:00

View File

@@ -302,10 +302,13 @@ When enabled, the `SecretsPropertySource` looks up Kubernetes for `Secrets` from
. Named after the application (as defined by `spring.application.name`)
. Matching some labels
Note that, by default, consuming Secrets through the API (points 2 and 3 above) *is not enabled* for security reasons.
*Note:*
By default, consuming Secrets through the API (points 2 and 3 above) *is not enabled* for security reasons. The permission 'list' on secrets allows clients to inspect secrets values in the specified namespace.
Further, we recommend that containers share secrets through mounted volumes.
If you enable consuming Secrets through the API, we recommend that you limit access to Secrets by using an
[authorization policy, such as RBAC](https://kubernetes.io/docs/concepts/configuration/secret/#best-practices).
If you enable consuming Secrets through the API, we recommend that you limit access to Secrets by using an authorization policy, such as RBAC.
For more information about risks and best practices when consuming Secrets through the API refer to https://kubernetes.io/docs/concepts/configuration/secret/#best-practices[this doc].
If the secrets are found, their data is made available to the application.
@@ -451,6 +454,7 @@ the `Secret` named `s1` would be looked up in the namespace that the application
|===
Notes:
* The `spring.cloud.kubernetes.secrets.labels` property behaves as defined by
https://github.com/spring-projects/spring-boot/wiki/Spring-Boot-Configuration-Binding#map-based-binding[Map-based binding].
* The `spring.cloud.kubernetes.secrets.paths` property behaves as defined by