You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为AKS的Elastic Agent DaemonSet配置Workload Identity拉取密钥

AKS Workload Identity 集成 Elastic Agent DaemonSet 拉取 Azure Key Vault 密钥方案

Workload Identity 不支持 akv2k8s 那种直接用 secretname@azurekeyvault 的密钥注入方式,需要借助 Azure Secrets Store CSI Driver 或者 Init 容器拉取 实现,以下是具体配置步骤:

方法一:通过 Secrets Store CSI Driver 同步密钥到环境变量

这是推荐方式,CSI 驱动会自动同步 AKV 密钥到 Kubernetes Secret,再挂载为环境变量:

  1. 创建 SecretProviderClass 资源,关联你的 AKV、Workload Identity 和目标 Secret:
apiVersion: secrets-store.csi.x-k8s.io/v1
kind: SecretProviderClass
metadata:
  name: elastic-agent-akv-sync
spec:
  provider: azure
  parameters:
    usePodIdentity: "false"
    useVMManagedIdentity: "false"
    clientID: "<你的 Workload Identity Client ID>" # 与 ServiceAccount 注解的 client-id 一致
    keyvaultName: "<你的 AKV 名称>"
    objects: |
      array:
        - |
          objectName: fleet-enrollment-token # AKV 中存储的密钥名称
          objectType: secret
    tenantId: "<你的 Azure 租户 ID>"
  secretObjects:
  - data:
    - key: fleet-enrollment-token
      objectName: fleet-enrollment-token
    secretName: elastic-agent-fleet-token # 同步生成的 Kubernetes Secret 名称
    type: Opaque
  1. 修改 Elastic Agent DaemonSet 的 Pod 模板,挂载该 Secret 为环境变量:
spec:
  template:
    spec:
      volumes:
      - name: secrets-store-inline
        csi:
          driver: secrets-store.csi.k8s.io
          readOnly: true
          volumeAttributes:
            secretProviderClass: "elastic-agent-akv-sync" # 对应上面创建的 SecretProviderClass 名称
      containers:
      - name: elastic-agent
        env:
        - name: FLEET_ENROLLMENT_TOKEN
          valueFrom:
            secretKeyRef:
              name: elastic-agent-fleet-token # 对应 SecretProviderClass 中定义的 secretName
              key: fleet-enrollment-token
        volumeMounts:
        - name: secrets-store-inline
          mountPath: "/mnt/secrets-store"
          readOnly: true

方法二:用 Init 容器拉取密钥到共享目录

如果 Elastic Agent 需要从文件读取密钥,可通过 Init 容器借助 Azure CLI 拉取:

  1. 修改 Elastic Agent DaemonSet 的 Pod 模板,添加 Init 容器和共享空目录:
spec:
  template:
    spec:
      initContainers:
      - name: fetch-fleet-token
        image: mcr.microsoft.com/azure-cli:latest
        command:
        - sh
        - -c
        - az keyvault secret show --name fleet-enrollment-token --vault-name <你的 AKV 名称> --query value -o tsv > /agent-secrets/token
        volumeMounts:
        - name: token-volume
          mountPath: /agent-secrets
        env:
        - name: AZURE_CLIENT_ID
          value: "<你的 Workload Identity Client ID>"
        - name: AZURE_TENANT_ID
          value: "<你的 Azure 租户 ID>"
      containers:
      - name: elastic-agent
        env:
        - name: FLEET_ENROLLMENT_TOKEN
          value: "file:/agent-secrets/token" # 根据 Elastic Agent 配置调整读取方式
        volumeMounts:
        - name: token-volume
          mountPath: /agent-secrets
          readOnly: true
      volumes:
      - name: token-volume
        emptyDir: {}

注意事项

  • 确保你的 Workload Identity 已被授予 AKV 的 Secrets User 权限(你已通过测试 Pod 验证,此步可忽略)
  • 若 Elastic Cloud 自动生成的 YAML 会被定期覆盖,建议将修改后的配置保存为自定义资源,避免同步丢失

内容的提问来源于stack exchange,提问作者Emanuele

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 13:32:40