You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Argo Workflows UI中隐藏输入输出参数里的敏感值?

解决Argo Workflow中敏感参数明文显示的问题

核心实现步骤

  • 将敏感信息存入Kubernetes Secret
    先把api-key这类敏感值存入Secret,彻底避免明文出现在Workflow定义或参数传递链路中:

    kubectl create secret generic my-api-secret --from-literal=api-key=your-real-api-key
    
  • 修改Workflow定义,引用Secret并标记参数为敏感
    调整Workflow代码,从Secret读取敏感参数,同时在模板的输入参数里添加sensitive: true标记,Argo UI会自动对该参数值进行掩码处理:

    apiVersion: argoproj.io/v1alpha1
    kind: Workflow
    metadata:
      generateName: demo-hello-world-
    spec:
      entrypoint: hello-world
      ttlStrategy:
        secondsAfterCompletion: 72000  # Pods will be deleted 20 hours after workflow completion
      templates:
      - name: hello-world
        steps:
          - - name: task-ask-whale
              template: whale-say
              arguments:
                parameters:
                - name: message
                  value: "hello world"
                - name: api-key
                  # 从指定Secret中读取api-key的值
                  valueFrom:
                    secretKeyRef:
                      name: my-api-secret
                      key: api-key
    
      - name: whale-say
        inputs:
          parameters:
            - name: message
            - name: api-key
              # 标记该参数为敏感,UI中会显示为***
              sensitive: true
        container:
          image: docker/whalesay:latest
          command: ["cowsay"]
          args: ["echo", "{{inputs.parameters.message}}"]
    

补充场景处理

  • 如果需要通过Argo UI手动输入敏感参数(比如提交Workflow时填写api-key),可以在Workflow的全局参数定义里标记敏感:
    spec:
      arguments:
        parameters:
          - name: api-key
            sensitive: true
    
    这样用户输入时会自动掩码,后续传递过程中也不会暴露明文。
  • 确保不要在容器的命令、参数或日志中打印敏感参数值,避免从其他渠道泄露。

内容的提问来源于stack exchange,提问作者Sukhbir

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 05:38:16