You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何管理Kubernetes非容器对象的敏感信息?以EKS ServiceAccount为例

EKS ServiceAccount注解敏感信息的变量替换方案

下面是几种无需将敏感信息(如AWS账户ID)明文存储在代码仓库的可行方案:

1. 用envsubst工具直接替换环境变量

  • 先编写ServiceAccount模板文件(比如sa-template.yaml),将敏感值用环境变量占位:
    apiVersion: v1
    kind: ServiceAccount
    metadata:
      name: my-app-sa
      annotations:
        eks.amazonaws.com/role-arn: arn:aws:iam::${AWS_ACCOUNT_ID}:role/eks-app-role
    
  • 部署时先设置环境变量,再用envsubst替换并应用:
    export AWS_ACCOUNT_ID=111111111
    envsubst < sa-template.yaml | kubectl apply -f -
    
  • 补充:envsubst属于GNU gettext工具集,Linux系统一般自带,macOS可通过brew install gettext安装。

2. 用kubectl内置的Kustomize实现动态替换

  • 编写基础ServiceAccount清单(sa-base.yaml),保留占位符:
    apiVersion: v1
    kind: ServiceAccount
    metadata:
      name: my-app-sa
      annotations:
        eks.amazonaws.com/role-arn: arn:aws:iam::ACCOUNT_PLACEHOLDER:role/eks-app-role
    
  • 编写kustomization.yaml配置替换规则:
    apiVersion: kustomize.config.k8s.io/v1beta1
    kind: Kustomization
    resources:
      - sa-base.yaml
    replacements:
      - source:
          kind: ConfigMap
          name: account-config
          fieldPath: data.accountId
        targets:
          - select:
              kind: ServiceAccount
              name: my-app-sa
            fieldPaths:
              - metadata.annotations.eks.amazonaws.com/role-arn
            options:
              delimiter: ":"
              index: 4
    
  • 部署时动态生成临时ConfigMap(不提交到代码库),再应用Kustomize:
    # 创建临时ConfigMap存储账户ID
    kubectl create configmap account-config --from-literal=accountId=111111111 --dry-run=client -o yaml | kubectl apply -f -
    # 应用替换后的配置
    kubectl apply -k .
    

3. 用Shell脚本结合sed自动替换

  • 编写模板文件sa-template.yaml,用ACCOUNT_PLACEHOLDER作为占位符:
    apiVersion: v1
    kind: ServiceAccount
    metadata:
      name: my-app-sa
      annotations:
        eks.amazonaws.com/role-arn: arn:aws:iam::ACCOUNT_PLACEHOLDER:role/eks-app-role
    
  • 编写部署脚本deploy-sa.sh(可提交到代码库),从环境变量或AWS CLI自动获取账户ID:
    #!/bin/bash
    # 优先从环境变量取,否则用AWS CLI获取当前身份的账户ID
    ACCOUNT_ID=${AWS_ACCOUNT_ID:-$(aws sts get-caller-identity --query Account --output text)}
    # 替换占位符并应用配置
    sed "s/ACCOUNT_PLACEHOLDER/$ACCOUNT_ID/g" sa-template.yaml | kubectl apply -f -
    
  • 执行脚本部署:chmod +x deploy-sa.sh && ./deploy-sa.sh

4. 用Helm模板管理(适合Helm部署场景)

  • 在Helm Chart的templates/serviceaccount.yaml中使用模板变量:
    apiVersion: v1
    kind: ServiceAccount
    metadata:
      name: {{ .Release.Name }}-app-sa
      annotations:
        eks.amazonaws.com/role-arn: arn:aws:iam::{{ .Values.awsAccountId }}:role/eks-app-role
    
  • 部署时通过--set参数传入账户ID,或从环境变量读取:
    # 直接传入参数
    helm install my-app ./app-chart --set awsAccountId=111111111
    # 从环境变量读取
    helm install my-app ./app-chart --set awsAccountId=$AWS_ACCOUNT_ID
    
  • 补充:Chart的values.yaml中可将awsAccountId设为空或占位符,避免明文存储。

内容的提问来源于stack exchange,提问作者Arun Lal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 11:23:23