如何在AWS EKS Pod中获取并复用AWS SSM参数存储值?
可行实现方案
方案一:使用Helm模板渲染(推荐,支持容器级条件判断)
Kubernetes原生配置是静态的,无法直接在Deployment模板中引用运行时从SSM拉取的参数做条件判断。Helm作为模板渲染工具,可以在部署阶段提前获取SSM参数值,再动态生成符合需求的Deployment配置。
步骤1:转换为Helm模板
将现有配置调整为Helm模板,修改Deployment的条件判断逻辑:
# templates/deployment.yaml apiVersion: apps/v1 kind: Deployment metadata: name: myapp spec: replicas: 1 selector: matchLabels: app.kubernetes.io/name: myapp template: metadata: labels: app.kubernetes.io/name: myapp spec: containers: - name: myapp image: quay.io/jpkroehling/generate-span-java:0.1.0 {{- if .Values.otel_enabled_status }} - name: agent image: otel/opentelemetry-collector:0.18.0 args: - --config=/conf/agent.yaml volumeMounts: - mountPath: /conf name: agent-config {{- end }} volumes: - configMap: items: - key: agent.yaml path: agent.yaml name: agent-config name: agent-config
步骤2:获取SSM参数并传入Helm
部署前用AWS CLI拉取SSM参数值,作为Helm变量传入部署命令:
OTEL_STATUS=$(aws ssm get-parameter --name "/abc/myparameter" --query "Parameter.Value" --output text) helm install myapp ./mychart --set otel_enabled_status=$OTEL_STATUS
方案二:Secrets Store CSI Driver + 容器内逻辑(适合运行时判断,不支持容器级条件部署)
如果不需要动态控制agent容器是否存在,只是需要在容器内使用SSM参数,可以通过Secrets Store CSI Driver将参数挂载到Pod或转为环境变量:
步骤1:完善SecretProviderClass配置
添加secretObjects字段,将SSM参数转换为Kubernetes Secret,方便注入为环境变量:
apiVersion: secrets-store.csi.x-k8s.io/v1 kind: SecretProviderClass metadata: name: aws-secrets spec: provider: aws parameters: objects: | - objectName: "/abc/myparameter" objectType: "ssmparameter" objectAlias: otel_enalbed_status secretObjects: - secretName: otel-status-secret type: Opaque data: - key: otel_enabled_status objectName: otel_enalbed_status
步骤2:在Pod中注入环境变量或挂载卷
修改Deployment,将生成的Secret注入为容器环境变量,同时挂载CSI卷:
apiVersion: apps/v1 kind: Deployment metadata: name: myapp spec: replicas: 1 selector: matchLabels: app.kubernetes.io/name: myapp template: metadata: labels: app.kubernetes.io/name: myapp spec: volumes: - name: agent-config configMap: name: agent-config - name: secrets-store-inline csi: driver: secrets-store.csi.k8s.io readOnly: true volumeAttributes: secretProviderClass: "aws-secrets" containers: - name: myapp image: quay.io/jpkroehling/generate-span-java:0.1.0 env: - name: OTEL_ENABLED_STATUS valueFrom: secretKeyRef: name: otel-status-secret key: otel_enabled_status volumeMounts: - name: secrets-store-inline mountPath: "/mnt/secrets-store" readOnly: true - name: agent image: otel/opentelemetry-collector:0.18.0 args: - --config=/conf/agent.yaml volumeMounts: - mountPath: /conf name: agent-config
这种方式下agent容器始终存在,你可以在agent的启动脚本中根据环境变量OTEL_ENABLED_STATUS决定是否真正启动服务。
方案三:Kustomize + 脚本预生成配置
用脚本提前获取SSM参数,生成Kustomize补丁文件,再通过Kustomize构建最终部署配置:
步骤1:编写脚本生成补丁
#!/bin/bash OTEL_STATUS=$(aws ssm get-parameter --name "/abc/myparameter" --query "Parameter.Value" --output text) # 根据参数值生成对应的Kustomize补丁 cat <<EOF > patch-agent.yaml - op: $(if [ "$OTEL_STATUS" = "true" ]; then echo "add"; else echo "remove"; fi) path: /spec/template/spec/containers/- value: name: agent image: otel/opentelemetry-collector:0.18.0 args: - --config=/conf/agent.yaml volumeMounts: - mountPath: /conf name: agent-config EOF
步骤2:用Kustomize应用补丁
在kustomization.yaml中引用补丁文件:
apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization resources: - configmap.yaml - secretproviderclass.yaml - deployment-base.yaml patches: - path: patch-agent.yaml
运行脚本生成补丁后,执行kustomize build | kubectl apply -f -完成部署。
内容的提问来源于stack exchange,提问作者ctgopinaath
相关产品推荐
相关产品推荐

