KOP Recipes - AWS Secrets Manager Configure - Rafay Product Documentation

Configure

In this part, you will


Step 1: Create Secret

When Vault is run in development mode, a KV secret engine is enabled at the path /secret.

kubectl exec -it vault-0 -- /bin/sh
vault kv put secret/db-pass password="db-secret-password"
vault kv get secret/db-pass

Step 2: Configure Kubernetes Authentication

Vault provides a Kubernetes authentication method that enables clients to authenticate with a Kubernetes Service Account Token. The Kubernetes resources that access the secret and create the volume authenticate through this method through a role.

vault auth enable kubernetes
vault write auth/kubernetes/config \
    kubernetes_host="https://$KUBERNETES_PORT_443_TCP_ADDR:443"

Step 3: Create a policy, role and service account

vault policy write internal-app - <<EOF
path "secret/data/db-pass" {
  capabilities = ["read"]
}
EOF
vault write auth/kubernetes/role/database \
    bound_service_account_names=webapp-sa \
    bound_service_account_namespaces=web-app \
    policies=internal-app \
    ttl=20m

The role connects the Kubernetes service account "webapp-sa" in the namespace "web-app" with the Vault policy "internal-app".

Exit the vault-0 pod.

exit
kubectl create serviceaccount webapp-sa -n web-app

Next Steps

You are now ready to move on to the next part of the recipe where you will create a workload and access the secrets.