{"id":89143,"date":"2020-07-19T07:42:22","date_gmt":"2020-07-19T05:42:22","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/avtogeneracziya-sekretov-v-helm"},"modified":"2020-07-19T07:42:22","modified_gmt":"2020-07-19T05:42:22","slug":"avtogeneracziya-sekretov-v-helm","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/administrirovanie\/avtogeneracziya-sekretov-v-helm","title":{"rendered":"Generare automat\u0103 a secretelor \u00een Helm","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Generare automat\u0103 a secretelor \u00een Helm\" src=\"\/wp-content\/uploads\/2020\/07\/e2ba6ab1bf5b50c7cfcbf62d56ff15da.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>Comanda <noindex><a rel=\"nofollow\" href=\"https:\/\/mcs.mail.ru\/containers\/\">Kubernetes aaS de la Mail.ru<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/medium.com\/workfloplus\/reusing-auto-generated-helm-secrets-a7426403d4bb\">a tradus o not\u0103 scurt\u0103<\/a><\/noindex> despre cum s\u0103 genera\u021bi automat secrete Helm la actualizare. Mai departe, textul autorului articolului \u2014 directorul tehnic la Intoware, compania dezvoltatoare de solu\u021bii SaaS. <\/p>\n<p>Containerele sunt grozave. La \u00eenceput am fost \u00eempotriva containerelor (tragic de recunoscut), dar acum sprijin pe deplin utilizarea acestei tehnologii. Dac\u0103 citi\u021bi asta, sper c\u0103 a\u021bi navigat cu succes pe m\u0103rile Docker, a\u021bi realizat avantajele Kubernetes \u0219i v-a\u021bi simplificat semnificativ via\u021ba cu Helm.<\/p>\n<p>Cu toate acestea, unele lucruri sunt evident mai complicate dec\u00e2t ar trebui s\u0103 fie.<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\nCum s\u0103 genera\u021bi automat secrete la actualizare?<\/p>\n<p>Secretul Kubernetes este un resurs care con\u021bine perechi cheie\/valoare pe care dori\u021bi s\u0103 le utiliza\u021bi \u00een codul dumneavoastr\u0103. Acestea pot fi stringuri de conexiune la baza de date, parole de email \u0219i a\u0219a mai departe. Folosind secrete, crea\u021bi o separare clar\u0103 \u00eentre cod \u0219i configura\u021bii, ceea ce permite configurarea u\u0219oar\u0103 a diferitelor desf\u0103\u0219ur\u0103ri f\u0103r\u0103 a modifica baza de cod.<\/p>\n<p>O situa\u021bie frecvent \u00eent\u00e2lnit\u0103 este c\u00e2nd dou\u0103 module trebuie s\u0103 interac\u021bioneze printr-o cheie comun\u0103. Nimeni din afara clusterului nu ar trebui s\u0103 \u0219tie aceast\u0103 cheie, deoarece este destinat\u0103 comunic\u0103rii \u00abde la unul la altul\u00bb \u00een interiorul clusterului.<\/p>\n<h2>Crearea de secrete<\/h2>\n<p>\nDe obicei, pentru a crea un secret \u00een Helm, trebuie s\u0103:<\/p>\n<ul>\n<li>descrie\u021bi secretul \u00een fi\u0219ierul de valori;<\/li>\n<li>s\u0103-l suprascrie\u021bi \u00een procesul de desf\u0103\u0219urare;<\/li>\n<li>s\u0103 face\u021bi referire la el \u00een cadrul desf\u0103\u0219ur\u0103rii\/podului;<\/li>\n<li>\u2026 profit!<\/li>\n<\/ul>\n<p>\nDe obicei, arat\u0103 cam a\u0219a:<\/p>\n<pre><code class=\"plaintext\">apiVersion: v1\nkind: Secret\nmetadata:\n  name: my-super-awesome-api-key\ntype: Opaque\nstringData:\n  apiKey: {{ .Values.MyApiKeySecret | quote }}\n<\/code><\/pre>\n<p>\n<i>Un secret simplu Kubernetes, folosind valori din values.yml<\/i><\/p>\n<p>Dar, s\u0103 zicem c\u0103 nu dori\u021bi s\u0103 specifica\u021bi secretul \u00een fi\u0219ierul de valori.<\/p>\n<p>Exist\u0103 multe situa\u021bii \u00een care desf\u0103\u0219urarea necesit\u0103 o cheie comun\u0103, care trebuie generat\u0103 \u00een timpul instal\u0103rii.<\/p>\n<p>\u00cen exemplul de mai sus cu comunicarea \u00eentre module, nu este recomandabil s\u0103 \u00eemp\u0103rt\u0103\u0219i\u021bi secretul dincolo de desf\u0103\u0219urare. A\u0219adar, este foarte dorit ca Helm s\u0103 aib\u0103 mecanisme pentru generarea automat\u0103 a secretului f\u0103r\u0103 a necesita specificarea direct\u0103 a acestuia.<\/p>\n<h2>Hook-uri<\/h2>\n<p>\nHooks allow you to execute code at specific points during the installation process. There may be a setup task that needs to run after the initial installation, or perhaps some cleanup is required before any updates are performed.<\/p>\n<p>To solve our problem of adding a key generated during installation, pre-installation hooks are ideal. But there's one catch: you cannot automatically generate the secret once upon updating. Hooks will run on every update.<\/p>\n<p>If you have generated your secret and your first installation has not yet taken place, then stop reading; the pre-installation hook is perfect for you.<\/p>\n<p>But if the secret is part of an update (perhaps a new feature that was not available during installation), it's unfortunate that you cannot create a pre-installation hook that would run just once.<\/p>\n<h2>Functions<\/h2>\n<p>\nHelm functions allow you to add various script elements to deployment scripts.<\/p>\n<pre><code class=\"plaintext\">apiVersion: v1\nkind: Secret\nmetadata:\n  name: my-super-awesome-api-key\ntype: Opaque\nstringData:\n  apiKey: {{ uuidv4 | quote }} #Generate a new UUID and quote it\n<\/code><\/pre>\n<p>\nThis example shows that the value of the secret apiKey will be a new UUID generated during installation.<\/p>\n<p>Helm includes a really extensive library of functions that utilizes amazing features of the GO templating and the Sprig function library to create customizable deployments.<\/p>\n<h3>Lookup Function<\/h3>\n<p>\nIn Helm 3.1, the <noindex><a rel=\"nofollow\" href=\"https:\/\/helm.sh\/docs\/chart_template_guide\/functions_and_pipelines\/\">Lookup function<\/a><\/noindex>, which allows querying existing deployments to:<\/p>\n<ul>\n<li>check for the existence of resources;<\/li>\n<li>return the value of an existing resource for future use.<\/li>\n<\/ul>\n<p>\nBy using both of these capabilities, we can create a one-time dynamically generated secret!<\/p>\n<pre><code class=\"plaintext\"># 1. \u0417\u0430\u043f\u0440\u043e\u0441\u0438\u0442\u044c \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u043e\u0432\u0430\u043d\u0438\u0435 \u0441\u0435\u043a\u0440\u0435\u0442\u0430 \u0438 \u0432\u0435\u0440\u043d\u0443\u0442\u044c \u0432 \u043f\u0435\u0440\u0435\u043c\u0435\u043d\u043d\u043e\u0439 $secret\n{{- $secret := (lookup &quot;v1&quot; &quot;Secret&quot; .Release.Namespace &quot;some-awesome-secret&quot; -}}\napiVersion: v1\nkind: Secret\nmetadata:\n  name: some-awesome-secret\ntype: Opaque\n\n# 2. \u0415\u0441\u043b\u0438 \u0441\u0435\u043a\u0440\u0435\u0442 \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u0435\u0442, \u0432\u0437\u044f\u0442\u044c \u0435\u0433\u043e \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435 \u043a\u0430\u043a apiKey (\u0441\u0435\u043a\u0440\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 \u043a\u043e\u0434\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0435 Base64, \u0442\u0430\u043a \u0447\u0442\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0439\u0442\u0435 \u043a\u043b\u044e\u0447 &quot;data&quot;)\n{{ if $secret -}}\ndata:\n  apiKey: {{ $secret.data.apiKey }}\n\n# 3. \u0415\u0441\u043b\u0438 \u0441\u0435\u043a\u0440\u0435\u0442 \u043d\u0435 \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u0435\u0442 \u2014 \u0441\u043e\u0437\u0434\u0430\u0442\u044c \u0435\u0433\u043e (\u0432 \u044d\u0442\u043e\u0442 \u0440\u0430\u0437 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0439\u0442\u0435 &quot;stringData&quot;, \u0442\u0430\u043a \u043a\u0430\u043a \u0431\u0443\u0434\u0435\u0442 \u043e\u0431\u044b\u0447\u043d\u043e\u0435 \u0437\u043d\u0430\u0447\u0435\u043d\u0438\u0435)!\n{{ else -}}\nstringData:\n  apiKey: {{ uuidv4 | quote }}\n{{ end }}\n<\/code><\/pre>\n<p>\nWhenever a new update is applied to the server, Helm will either generate a new secret value (if the secret does not yet exist) or reuse the existing value.<\/p>\n<p>Good luck!<\/p>\n<p><strong>What else to read on the topic<\/strong>:<\/p>\n<ol>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/mcs.mail.ru\/blog\/tri-urovnya-avtomasshtabirovaniya-v-kubernetes-kak-ikh-effektivno-ispolzovat\">Three levels of autoscaling in Kubernetes and how to use them effectively<\/a><\/noindex>.<\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/mailru\/blog\/490362\/\">Kubernetes in the spirit of piracy with an implementation template<\/a><\/noindex>.<\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/tele.click\/k8s_mail\">Our Around Kubernetes channel on Telegram<\/a><\/noindex>.<\/li>\n<\/ol>\n<p>Sursa: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/mailru\/blog\/507376\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043e\u043c\u0430\u043d\u0434\u0430 Kubernetes aaS \u043e\u0442 Mail.ru \u043f\u0435\u0440\u0435\u0432\u0435\u043b\u0430 \u043a\u043e\u0440\u043e\u0442\u043a\u0443\u044e \u0437\u0430\u043c\u0435\u0442\u043a\u0443 \u043e \u0442\u043e\u043c, \u043a\u0430\u043a \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0447\u0435\u0441\u043a\u0438 \u0433\u0435\u043d\u0435\u0440\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0441\u0435\u043a\u0440\u0435\u0442\u044b Helm \u043f\u0440\u0438 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0438. \u0414\u0430\u043b\u0435\u0435 \u0442\u0435\u043a\u0441\u0442 \u043e\u0442 \u0430\u0432\u0442\u043e\u0440\u0430 \u0441\u0442\u0430\u0442\u044c\u0438 \u2014 \u0442\u0435\u0445\u043d\u0438\u0447\u0435\u0441\u043a\u043e\u0433\u043e \u0434\u0438\u0440\u0435\u043a\u0442\u043e\u0440\u0430 Intoware, \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438-\u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0430 SaaS-\u0440\u0435\u0448\u0435\u043d\u0438\u0439. \u041a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u044b \u2014 \u044d\u0442\u043e \u043a\u0440\u0443\u0442\u043e. \u0421\u043d\u0430\u0447\u0430\u043b\u0430 \u044f \u0431\u044b\u043b \u043f\u0440\u043e\u0442\u0438\u0432\u043d\u0438\u043a\u043e\u043c \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u043e\u0432 (\u0441\u0442\u044b\u0434\u043d\u043e \u043f\u0440\u0438\u0437\u043d\u0430\u0442\u044c\u0441\u044f), \u043d\u043e \u0442\u0435\u043f\u0435\u0440\u044c \u044f \u043f\u043e\u043b\u043d\u043e\u0441\u0442\u044c\u044e \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u044e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435 \u044d\u0442\u043e\u0439 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438. \u0415\u0441\u043b\u0438 \u0432\u044b \u0447\u0438\u0442\u0430\u0435\u0442\u0435 \u044d\u0442\u043e, \u0442\u043e, \u043d\u0430\u0434\u0435\u044e\u0441\u044c, \u0443\u0441\u043f\u0435\u0448\u043d\u043e \u043f\u043b\u0430\u0432\u0430\u043b\u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":89144,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-89143","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043e\u043c\u0430\u043d\u0434\u0430\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/administrirovanie\/avtogeneracziya-sekretov-v-helm\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0410\u0432\u0442\u043e\u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u044f \u0441\u0435\u043a\u0440\u0435\u0442\u043e\u0432 \u0432 Helm | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043e\u043c\u0430\u043d\u0434\u0430\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/administrirovanie\/avtogeneracziya-sekretov-v-helm\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-07-19T05:42:22+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-07-19T05:42:22+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Auto-generating secrets in Helm | ProHoster","description":"Comanda","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/administrirovanie\/avtogeneracziya-sekretov-v-helm","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0410\u0432\u0442\u043e\u0433\u0435\u043d\u0435\u0440\u0430\u0446\u0438\u044f \u0441\u0435\u043a\u0440\u0435\u0442\u043e\u0432 \u0432 Helm | ProHoster","og:description":"\u041a\u043e\u043c\u0430\u043d\u0434\u0430","og:url":"https:\/\/prohoster.info\/ro\/blog\/administrirovanie\/avtogeneracziya-sekretov-v-helm","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-07-19T05:42:22+00:00","article:modified_time":"2020-07-19T05:42:22+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"89143","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 13:15:24","updated":"2022-10-05 12:06:33","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/89143","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=89143"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/89143\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media\/89144"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=89143"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=89143"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=89143"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}