Repository navigation
feat(quoter-bot:PLA-3840): render the runtime Secret from AWS Secrets Manager via ESO #1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,23 @@ | ||
| {{- if .Values.externalSecret.enabled }} | ||
| # Extracts the whole Secrets Manager value as a flat JSON object of environment variables. | ||
| # creationPolicy Owner garbage-collects the rendered Secret with this ExternalSecret; | ||
| # deletionPolicy Retain keeps it (and the pod's env) if the ExternalSecret itself is removed. | ||
| apiVersion: external-secrets.io/v1 | ||
| kind: ExternalSecret | ||
| metadata: | ||
| name: {{ include "quoter-bot.runtimeSecretName" . | quote }} | ||
| labels: | ||
| {{- include "quoter-bot.labels" . | nindent 4 }} | ||
| spec: | ||
| refreshInterval: {{ .Values.externalSecret.refreshInterval }} | ||
| secretStoreRef: | ||
| name: {{ include "quoter-bot.fullname" . }}-aws | ||
| kind: SecretStore | ||
| target: | ||
| name: {{ include "quoter-bot.runtimeSecretName" . | quote }} | ||
| creationPolicy: Owner | ||
| deletionPolicy: Retain | ||
| dataFrom: | ||
| - extract: | ||
| key: {{ .Values.externalSecret.remoteKey | quote }} | ||
| {{- end }} | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,28 @@ | ||
| {{- if .Values.externalSecret.enabled }} | ||
| {{- if not .Values.serviceAccount.create }} | ||
| {{- fail "externalSecret.enabled requires serviceAccount.create: the SecretStore authenticates as the chart-managed ServiceAccount (auth.jwt.serviceAccountRef)" }} | ||
| {{- end }} | ||
| {{- if not .Values.externalSecret.remoteKey }} | ||
| {{- fail "externalSecret.enabled requires externalSecret.remoteKey: the AWS Secrets Manager secret name or ARN" }} | ||
| {{- end }} | ||
| {{- if not .Values.externalSecret.region }} | ||
| {{- fail "externalSecret.enabled requires externalSecret.region: the AWS region of remoteKey" }} | ||
| {{- end }} | ||
| # Namespaced SecretStore authenticating as the chart-managed ServiceAccount; IRSA or EKS Pod | ||
| # Identity turns its projected token into the bot's IAM role. | ||
| apiVersion: external-secrets.io/v1 | ||
| kind: SecretStore | ||
| metadata: | ||
| name: {{ include "quoter-bot.fullname" . }}-aws | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🟡 Long release names block secret sync For a fullname over 59 characters, Learn moreThe fullname helper permits names up to 63 characters, while a Kubernetes SecretStore name must also fit within 63 characters. The same overlong value appears in secretStoreRef. The runtime Secret already uses a bounded, hashed name helper. Example: With a 63-character fullname, appending Recommended fix: Add a bounded, hash-suffixed SecretStore name helper and use it for both the SecretStore metadata name and the ExternalSecret's Was this helpful? React with 👍 or 👎 to provide feedback. |
||
| labels: | ||
| {{- include "quoter-bot.labels" . | nindent 4 }} | ||
| spec: | ||
| provider: | ||
| aws: | ||
| service: SecretsManager | ||
| region: {{ .Values.externalSecret.region | quote }} | ||
| auth: | ||
| jwt: | ||
| serviceAccountRef: | ||
| name: {{ include "quoter-bot.serviceAccountName" . | quote }} | ||
|
Comment on lines
+24
to
+27
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔴 Pod Identity cannot sync runtime secrets With EKS Pod Identity alone, Learn moreA SecretStore runs in External Secrets Operator, not in the bot pod. JWT service-account authentication uses a requested service-account token for a web-identity exchange with AWS STS. An EKS Pod Identity association supplies container credentials to pods using the account, not a web-identity role ARN on the ServiceAccount. The chart advertises both IRSA and EKS Pod Identity as compatible identities in runtime Secret setup. Example: An operator associates the chart's ServiceAccount with an IAM role using EKS Pod Identity and enables Recommended fix: Either restrict this SecretStore configuration and documentation to IRSA with a service-account role annotation, or implement an ESO-supported Pod Identity authentication mode and document the required identity of the ESO controller. Was this helpful? React with 👍 or 👎 to provide feedback.
Comment on lines
+24
to
+27
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
When this chart is deployed with EKS Pod Identity as the README permits, Useful? React with 👍 / 👎. |
||
| {{- end }} | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
If
externalSecret.enabledis later disabled or the ExternalSecret is otherwise removed,creationPolicy: Ownerplaces an owner reference on the generated Secret, so Kubernetes garbage collection deletes it with the ExternalSecret despitedeletionPolicy: Retain. That deletion policy only governs what happens when the provider-side secret disappears. Consequently, a migration that disables this feature and references the supposedly retained runtime Secret throughenvFromleaves the replacement pod unable to start; usecreationPolicy: Orphanif retention on ExternalSecret removal is intended, or remove the retention claim.Useful? React with 👍 / 👎.