Merge remote-tracking branch 'origin/1.0.x'
This commit is contained in:
@@ -302,10 +302,13 @@ When enabled, the `SecretsPropertySource` looks up Kubernetes for `Secrets` from
|
||||
. Named after the application (as defined by `spring.application.name`)
|
||||
. Matching some labels
|
||||
|
||||
Note that, by default, consuming Secrets through the API (points 2 and 3 above) *is not enabled* for security reasons.
|
||||
*Note:*
|
||||
|
||||
By default, consuming Secrets through the API (points 2 and 3 above) *is not enabled* for security reasons. The permission 'list' on secrets allows clients to inspect secrets values in the specified namespace.
|
||||
Further, we recommend that containers share secrets through mounted volumes.
|
||||
If you enable consuming Secrets through the API, we recommend that you limit access to Secrets by using an
|
||||
[authorization policy, such as RBAC](https://kubernetes.io/docs/concepts/configuration/secret/#best-practices).
|
||||
|
||||
If you enable consuming Secrets through the API, we recommend that you limit access to Secrets by using an authorization policy, such as RBAC.
|
||||
For more information about risks and best practices when consuming Secrets through the API refer to https://kubernetes.io/docs/concepts/configuration/secret/#best-practices[this doc].
|
||||
|
||||
If the secrets are found, their data is made available to the application.
|
||||
|
||||
@@ -451,6 +454,7 @@ the `Secret` named `s1` would be looked up in the namespace that the application
|
||||
|===
|
||||
|
||||
Notes:
|
||||
|
||||
* The `spring.cloud.kubernetes.secrets.labels` property behaves as defined by
|
||||
https://github.com/spring-projects/spring-boot/wiki/Spring-Boot-Configuration-Binding#map-based-binding[Map-based binding].
|
||||
* The `spring.cloud.kubernetes.secrets.paths` property behaves as defined by
|
||||
|
||||
Reference in New Issue
Block a user