You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为YAML凭证列表中不同银行配置加密Sealed Secrets密码?

问题:如何为多银行配置不同的加密密码

我需要在YAML配置的credentials列表中为每个银行设置独立的加密密码,但当前配置无法生效,以下是现有配置内容及正确解决方案:


当前配置内容

1. config.yml

infopoint:
  endpoint: https://test.test.com/ws/SSS/Somthing.pl
  system: TEST
  mock: false
  credentials:
    - bank: 1111
      user: LSSER
      existingSecret:
        name: infopoint-creds-s1-hb
    - bank: 2222
      user: TESSER
      existingSecret:
        name: infopoint-creds-s1
envFrom:       
 - secretRef:
     name: infopoint-creds-s1-hb
 - secretRef:
     name: infopoint-creds-s1

2. Sealed Secrets 创建命令

C:\Users\mks\IdeaProjects>kubectl.exe create secret generic infopoint-creds-s1-hb --from-literal=INFOPOINT_CREDENTIALS_PASSWORD=SOMEPASS -o yaml -n test-env --dry-run=client | kubeseal -o yaml --scope namespace-wide > infopoint-creds-s1-hb.yaml

C:\Users\mks\IdeaProjects>kubectl.exe create secret generic infopoint-creds-s1 --from-literal=INFOPOINT_CREDENTIALS_PASSWORD=SOMEPASS -o yaml -n test-env --dry-run=client | kubeseal -o yaml --scope namespace-wide > infopoint-creds-s1.yaml

3. Spring 配置类

@Configuration
@ConfigurationProperties(prefix = "infopoint")
class InfopointAPIConfiguration {

    lateinit var endpoint: String

    var proxyServerName: String? = null

    var proxyPortNumber: String? = null

    lateinit var system: String

    lateinit var mock: String

    lateinit var credentials: List<Credentials>

    data class Credentials(
        var bank: String? = null,
        var user: String? = null,
        var password: String? = null
    )

    fun credentialsByBank(bank: Int): Credentials {
        return credentials.firstOrNull { it.bank == bank.toString() }
            ?: error("Could not load credential for bank $bank")
    }
}

问题根源

  1. 两个Secret使用了完全相同的环境变量名INFOPOINT_CREDENTIALS_PASSWORD,后加载的Secret会直接覆盖前者的值,导致所有银行共用同一个密码。
  2. config.yml中的existingSecret配置无法直接将Secret值映射到对应银行的password字段,Spring不会自动关联列表项与指定Secret。

正确配置方案

步骤1:为每个银行创建带唯一键的Secret

修改Secret创建命令,使用与银行ID绑定的唯一环境变量键:

# 为银行1111创建专属Secret
kubectl.exe create secret generic infopoint-creds-s1-hb --from-literal=INFOPOINT_CREDENTIALS_1111_PASSWORD=SOMEPASS1 -o yaml -n test-env --dry-run=client | kubeseal -o yaml --scope namespace-wide > infopoint-creds-s1-hb.yaml

# 为银行2222创建专属Secret
kubectl.exe create secret generic infopoint-creds-s1 --from-literal=INFOPOINT_CREDENTIALS_2222_PASSWORD=SOMEPASS2 -o yaml -n test-env --dry-run=client | kubeseal -o yaml --scope namespace-wide > infopoint-creds-s1.yaml

步骤2:修改config.yml,通过占位符引用对应密码

在credentials列表中,直接用${环境变量名}的形式引用对应Secret中的密码值:

infopoint:
  endpoint: https://test.test.com/ws/SSS/Somthing.pl
  system: TEST
  mock: false
  credentials:
    - bank: 1111
      user: LSSER
      password: "${INFOPOINT_CREDENTIALS_1111_PASSWORD}"
    - bank: 2222
      user: TESSER
      password: "${INFOPOINT_CREDENTIALS_2222_PASSWORD}"
envFrom:       
 - secretRef:
     name: infopoint-creds-s1-hb
 - secretRef:
     name: infopoint-creds-s1

步骤3:验证Spring配置

现有Spring配置类无需修改,Spring Boot默认支持${}占位符解析,会自动将环境变量值注入到对应银行的password字段中。


内容的提问来源于stack exchange,提问作者JavaGeek

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 09:05:15