咨询Kubernetes可创建的Secret类型官方文档位置,已发现generic、docker-registry类型
Hey there! I totally get the confusion—hunting down all valid Kubernetes Secret types when you only have those two docs linked can feel tricky. Let me break this down for you using exactly the pages you can access:
Where to find the full list in your available docs
The Secret Concepts page (the first one you mentioned) actually has a dedicated section that lists every built-in Secret type. Look for the Secret Types subsection—this is where all official, supported types are documented in detail.
Built-in Secret types you'll find there
Here’s a quick rundown of the core types you’ll see, including the ones you already found:
- Opaque: This is the type created when you run
kubectl create secret generic—it’s a generic catch-all for arbitrary key-value pairs. - kubernetes.io/dockerconfigjson (aliased by
docker-registry): The type used for Docker registry credentials, which is whatkubectl create secret docker-registrygenerates under the hood. - kubernetes.io/service-account-token: Used for service account authentication to the Kubernetes API.
- kubernetes.io/basic-auth: For storing HTTP basic authentication credentials (username + password).
- kubernetes.io/ssh-auth: For SSH private keys used to access external systems.
- kubernetes.io/tls: For storing TLS certificates and keys (used for things like Ingress resources).
- bootstrap.kubernetes.io/token: Used for node bootstrap authentication in clusters using kubeadm.
Bonus: How kubectl commands map to types
Most kubectl create secret subcommands directly correspond to these built-in types:
kubectl create secret generic→ Opaquekubectl create secret docker-registry→ kubernetes.io/dockerconfigjsonkubectl create secret tls→ kubernetes.io/tlskubectl create secret generic --type=kubernetes.io/basic-auth→ kubernetes.io/basic-auth (you specify the type explicitly here)
If you dig into that Secret Types section in the concepts doc, you’ll also get specifics on each type’s format, use cases, and how to create them either via kubectl or YAML manifests.
内容的提问来源于stack exchange,提问作者Jxadro

