如何为AKS的Elastic Agent DaemonSet配置Workload Identity拉取密钥
AKS Workload Identity 集成 Elastic Agent DaemonSet 拉取 Azure Key Vault 密钥方案
Workload Identity 不支持 akv2k8s 那种直接用 secretname@azurekeyvault 的密钥注入方式,需要借助 Azure Secrets Store CSI Driver 或者 Init 容器拉取 实现,以下是具体配置步骤:
方法一:通过 Secrets Store CSI Driver 同步密钥到环境变量
这是推荐方式,CSI 驱动会自动同步 AKV 密钥到 Kubernetes Secret,再挂载为环境变量:
- 创建
SecretProviderClass资源,关联你的 AKV、Workload Identity 和目标 Secret:
apiVersion: secrets-store.csi.x-k8s.io/v1 kind: SecretProviderClass metadata: name: elastic-agent-akv-sync spec: provider: azure parameters: usePodIdentity: "false" useVMManagedIdentity: "false" clientID: "<你的 Workload Identity Client ID>" # 与 ServiceAccount 注解的 client-id 一致 keyvaultName: "<你的 AKV 名称>" objects: | array: - | objectName: fleet-enrollment-token # AKV 中存储的密钥名称 objectType: secret tenantId: "<你的 Azure 租户 ID>" secretObjects: - data: - key: fleet-enrollment-token objectName: fleet-enrollment-token secretName: elastic-agent-fleet-token # 同步生成的 Kubernetes Secret 名称 type: Opaque
- 修改 Elastic Agent DaemonSet 的 Pod 模板,挂载该 Secret 为环境变量:
spec: template: spec: volumes: - name: secrets-store-inline csi: driver: secrets-store.csi.k8s.io readOnly: true volumeAttributes: secretProviderClass: "elastic-agent-akv-sync" # 对应上面创建的 SecretProviderClass 名称 containers: - name: elastic-agent env: - name: FLEET_ENROLLMENT_TOKEN valueFrom: secretKeyRef: name: elastic-agent-fleet-token # 对应 SecretProviderClass 中定义的 secretName key: fleet-enrollment-token volumeMounts: - name: secrets-store-inline mountPath: "/mnt/secrets-store" readOnly: true
方法二:用 Init 容器拉取密钥到共享目录
如果 Elastic Agent 需要从文件读取密钥,可通过 Init 容器借助 Azure CLI 拉取:
- 修改 Elastic Agent DaemonSet 的 Pod 模板,添加 Init 容器和共享空目录:
spec: template: spec: initContainers: - name: fetch-fleet-token image: mcr.microsoft.com/azure-cli:latest command: - sh - -c - az keyvault secret show --name fleet-enrollment-token --vault-name <你的 AKV 名称> --query value -o tsv > /agent-secrets/token volumeMounts: - name: token-volume mountPath: /agent-secrets env: - name: AZURE_CLIENT_ID value: "<你的 Workload Identity Client ID>" - name: AZURE_TENANT_ID value: "<你的 Azure 租户 ID>" containers: - name: elastic-agent env: - name: FLEET_ENROLLMENT_TOKEN value: "file:/agent-secrets/token" # 根据 Elastic Agent 配置调整读取方式 volumeMounts: - name: token-volume mountPath: /agent-secrets readOnly: true volumes: - name: token-volume emptyDir: {}
注意事项
- 确保你的 Workload Identity 已被授予 AKV 的
Secrets User权限(你已通过测试 Pod 验证,此步可忽略) - 若 Elastic Cloud 自动生成的 YAML 会被定期覆盖,建议将修改后的配置保存为自定义资源,避免同步丢失
内容的提问来源于stack exchange,提问作者Emanuele
相关产品推荐
相关产品推荐

