You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Helm+ArgoCD部署的Alertmanager配置中插入非明文密码

无需External Secret的几种简便实现方式

方案1:Kubernetes Secret + 环境变量注入

这是最轻量化的方案,无需额外工具依赖:

  1. 创建存储SMTP密钥的K8s Secret
kubectl create secret generic alertmanager-smtp-secret \
  --namespace=你的目标命名空间 \
  --from-literal=smtp-password="你的实际API密钥"
  1. 修改Helm values.yaml,配置Alertmanager从Secret注入环境变量,并在配置中引用该变量:
# Alertmanager 核心配置
config:
  global:
    smtp_auth_username: 'apikey'
    smtp_auth_password: ${SMTP_PASSWORD}  # 引用环境变量

# Pod 环境变量注入(以prometheus-community/alertmanager chart为例,其他chart路径可能略有差异)
alertmanager:
  env:
    - name: SMTP_PASSWORD
      valueFrom:
        secretKeyRef:
          name: alertmanager-smtp-secret
          key: smtp-password

Alertmanager原生支持解析配置中的环境变量,启动时会自动替换${SMTP_PASSWORD}为Pod环境变量的实际值。

方案2:Helm Secrets插件加密敏感配置

如果希望把敏感值和其他配置放在一起管理,可使用Helm Secrets插件(基于sops加密):

  1. 安装Helm Secrets插件
helm plugin install https://github.com/jkroepke/helm-secrets
  1. 创建包含敏感值的明文文件(如secrets.yaml):
config:
  global:
    smtp_auth_password: "你的实际API密钥"
  1. 用sops加密该文件(需提前配置GPG/AWS KMS等加密密钥):
sops -e secrets.yaml > secrets.enc.yaml
  1. 在ArgoCD中配置支持Helm Secrets插件(确保ArgoCD的Helm控制器已安装该插件),然后在Application中引用加密文件:
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: alertmanager
spec:
  source:
    repoURL: https://prometheus-community.github.io/helm-charts
    chart: alertmanager
    targetRevision: x.x.x
    helm:
      valueFiles:
        - values.yaml
        - secrets.enc.yaml
  # 其他部署配置...

方案3:ArgoCD原生Secret引用

利用ArgoCD的valuesFrom特性,直接从K8s Secret读取敏感配置片段:

  1. 创建存储Helm values片段的Secret(放在ArgoCD所在命名空间):
kubectl create secret generic alertmanager-helm-values \
  --namespace=argocd \
  --from-literal=values.yaml='{"config":{"global":{"smtp_auth_password":"你的实际API密钥"}}}'
  1. 修改ArgoCD Application配置,引用该Secret作为额外values来源:
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: alertmanager
spec:
  source:
    repoURL: https://prometheus-community.github.io/helm-charts
    chart: alertmanager
    targetRevision: x.x.x
    helm:
      valueFiles:
        - values.yaml
      valuesFrom:
        - secretKeyRef:
            name: alertmanager-helm-values
            key: values.yaml
  destination:
    server: https://kubernetes.default.svc
    namespace: monitoring

ArgoCD会自动合并Secret中的values片段到主配置中,全程无需明文暴露敏感值。

内容的提问来源于stack exchange,提问作者Tomer Aharon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.14 23:35:23