You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Java客户端获取Kubernetes加密Secret数据

Great question! When working with encrypted Secrets in Kubernetes, the Java client takes care of the decryption process automatically for authorized clients—you don’t need to handle any encryption/decryption logic yourself. Here’s a step-by-step guide to retrieving those key-value pairs:

1. Add the Kubernetes Java Client Dependency

First, make sure you have the official Kubernetes Java client in your project. For Maven, add this to your pom.xml:

<dependency>
    <groupId>io.kubernetes</groupId>
    <artifactId>client-java</artifactId>
    <version>19.0.0</version> <!-- Use the latest stable version available -->
</dependency>
2. Configure Client Authentication

You’ll need to authenticate the client to access your Kubernetes cluster. Pick the method that fits your use case:

Option A: Local development (using kubeconfig)

import io.kubernetes.client.openapi.ApiClient;
import io.kubernetes.client.openapi.Configuration;
import io.kubernetes.client.util.ClientBuilder;
import io.kubernetes.client.util.KubeConfig;

import java.io.FileReader;

public class SecretFetcher {
    public static void main(String[] args) throws Exception {
        // Load kubeconfig from the default user directory
        String kubeConfigPath = System.getProperty("user.home") + "/.kube/config";
        ApiClient client = ClientBuilder.kubeconfig(KubeConfig.loadKubeConfig(new FileReader(kubeConfigPath))).build();
        
        Configuration.setDefaultApiClient(client);
        // Proceed to fetch the secret...
    }
}

Option B: In-cluster deployment (using service account)

If your Java app runs inside a Kubernetes pod, you can use the cluster’s built-in service account authentication—no extra config needed:

import io.kubernetes.client.openapi.ApiClient;
import io.kubernetes.client.openapi.Configuration;
import io.kubernetes.client.util.ClientBuilder;

public class SecretFetcher {
    public static void main(String[] args) throws Exception {
        ApiClient client = ClientBuilder.cluster().build();
        Configuration.setDefaultApiClient(client);
        // Proceed to fetch the secret...
    }
}
3. Fetch the Secret and Extract Key-Value Pairs

Once the client is set up, you can retrieve the Secret and decode its Base64-encoded values to get the plaintext key-value pairs:

import io.kubernetes.client.openapi.ApiException;
import io.kubernetes.client.openapi.apis.CoreV1Api;
import io.kubernetes.client.openapi.models.V1Secret;

import java.util.Base64;

public class SecretFetcher {
    public static void main(String[] args) throws Exception {
        // Initialize client (use one of the authentication methods above)
        ApiClient client = ClientBuilder.cluster().build();
        Configuration.setDefaultApiClient(client);
        
        CoreV1Api api = new CoreV1Api();
        String targetNamespace = "default"; // Replace with your Secret's namespace
        String secretName = "my-encrypted-secret"; // Replace with your Secret's name
        
        try {
            V1Secret secret = api.readNamespacedSecret(secretName, targetNamespace, null, null, null);
            
            // Iterate over the Secret's data and decode values
            secret.getData().forEach((key, encodedValue) -> {
                String plaintextValue = new String(Base64.getDecoder().decode(encodedValue));
                System.out.printf("Key: %s, Plaintext Value: %s%n", key, plaintextValue);
            });
        } catch (ApiException e) {
            System.err.printf("Error fetching Secret: %s%n", e.getResponseBody());
            e.printStackTrace();
        }
    }
}
Key Notes
  • Automatic Decryption: Kubernetes handles decrypting the Secret data before sending it to your client—this works as long as your client has the secrets.get permission in the target namespace.
  • Permissions Check: Make sure the service account or user associated with your Java app has a Role/RoleBinding that grants access to read Secrets in the relevant namespace.
  • StringData vs Data: If you created the Secret with stringData (plaintext input), Kubernetes automatically converts it to Base64-encoded entries in the data field—so you still use the same decoding step above.

内容的提问来源于stack exchange,提问作者emanuel07

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 08:21:25