ACK access credentials
In an ACK cluster, you can use three components—ack-secret-manager, csi-secrets-store-provider-alibabacloud, and ack-kms-agent-webhook-injector—to retrieve managed credentials from Key Management Service (KMS). The three components differ in supported cluster versions and access methods. Select the appropriate component based on your business requirements.
Add-on overview overview
-
ack-secret-manager: Syncs secrets from KMS Secrets Manager to Kubernetes Secrets in the cluster so that applications can securely access sensitive data. Workloads can mount these Secrets as a file system.
-
csi-secrets-store-provider-alibabacloud: Syncs secrets from KMS Secrets Manager to Kubernetes Secrets. Also supports mounting secrets directly into applications as a file system through CSI inline volumes, ideal for file-based access.
-
ack-kms-agent-webhook-injector: Injects the KMS Agent as a sidecar into pods. Applications fetch KMS secrets through the agent over local HTTP and cache them in memory, avoiding hardcoded sensitive data.
Use cases
|
Component |
Supported clusters |
Description |
Related operations |
|
ack-secret-manager |
|
Supports Secret synchronization and update. |
Use ack-secret-manager to import Alibaba Cloud KMS service credentials |
|
csi-secrets-store-provider-alibabacloud |
ACK clusters of version 1.20 and later:
|
|
Use csi-secrets-store-provider-alibabacloud to import service credentials from KMS |
|
ack-kms-agent-webhook-injector |
ACK clusters of version 1.22 and later:
|
|
Deploy KMS Agent in ACK to retrieve secrets, ACK cloud-native access |
Billing
-
ack-secret-manager and csi-secrets-store-provider-alibabacloud are free to install and use, but they consume worker node resources after installation. You can configure the resource requests for each module during installation.
-
Using KMS Secrets Manager incurs charges. For more information, see Billing.