Slide 22
Slide 22 text
22
改善点1︓Vault Agentのリソース削減
annotations:
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/role: "devweb-app"
vault.hashicorp.com/agent-inject-secret-credentials.txt: "secret/data/devwebapp/config"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/agent-inject-template-credentials.txt : |
{{ with secret "secrets/data/devwebapp/config" -}}
export ID="{{ .Data.data.ID }}"
export PASSWORD="{{ .Data.data.PASSWORD}}"
{{- end }}
spec:
serviceAccountName: internal-app
containers:
- args: [ 'sh', '-c', ‘source /vault/secrets/credentials.txt && ' ]
• vault.hashicorp.com/agent-pre-populate-only: "true ”のannotationを追加
注⽬