diff --git a/docs/src/main/asciidoc/property-source-config.adoc b/docs/src/main/asciidoc/property-source-config.adoc index 9b54236a..b0de6a14 100644 --- a/docs/src/main/asciidoc/property-source-config.adoc +++ b/docs/src/main/asciidoc/property-source-config.adoc @@ -302,10 +302,13 @@ When enabled, the `SecretsPropertySource` looks up Kubernetes for `Secrets` from . Named after the application (as defined by `spring.application.name`) . Matching some labels -Note that, by default, consuming Secrets through the API (points 2 and 3 above) *is not enabled* for security reasons. +*Note:* + +By default, consuming Secrets through the API (points 2 and 3 above) *is not enabled* for security reasons. The permission 'list' on secrets allows clients to inspect secrets values in the specified namespace. Further, we recommend that containers share secrets through mounted volumes. -If you enable consuming Secrets through the API, we recommend that you limit access to Secrets by using an -[authorization policy, such as RBAC](https://kubernetes.io/docs/concepts/configuration/secret/#best-practices). + +If you enable consuming Secrets through the API, we recommend that you limit access to Secrets by using an authorization policy, such as RBAC. +For more information about risks and best practices when consuming Secrets through the API refer to https://kubernetes.io/docs/concepts/configuration/secret/#best-practices[this doc]. If the secrets are found, their data is made available to the application. @@ -451,6 +454,7 @@ the `Secret` named `s1` would be looked up in the namespace that the application |=== Notes: + * The `spring.cloud.kubernetes.secrets.labels` property behaves as defined by https://github.com/spring-projects/spring-boot/wiki/Spring-Boot-Configuration-Binding#map-based-binding[Map-based binding]. * The `spring.cloud.kubernetes.secrets.paths` property behaves as defined by