mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-04 17:26:19 +00:00
doc: added daemonset and statefulset auto-redeploy example
This commit is contained in:
@@ -1230,13 +1230,13 @@ To address this, we added functionality to automatically redeploy your deploymen
|
|||||||
|
|
||||||
#### Enabling Automatic Redeployment
|
#### Enabling Automatic Redeployment
|
||||||
|
|
||||||
To enable auto redeployment you simply have to add the following annotation to the deployment, statefulset, or daemonset that consumes a managed secret.
|
To enable auto redeployment you simply have to add the following annotation to the Deployment, StatefulSet, or DaemonSet that consumes a managed secret.
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
secrets.infisical.com/auto-reload: "true"
|
secrets.infisical.com/auto-reload: "true"
|
||||||
```
|
```
|
||||||
|
|
||||||
<Accordion title="Deployment example with auto redeploy enabled">
|
<Accordion title="Deployment example">
|
||||||
```yaml
|
```yaml
|
||||||
apiVersion: apps/v1
|
apiVersion: apps/v1
|
||||||
kind: Deployment
|
kind: Deployment
|
||||||
@@ -1266,10 +1266,82 @@ secrets.infisical.com/auto-reload: "true"
|
|||||||
- containerPort: 80
|
- containerPort: 80
|
||||||
```
|
```
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
|
<Accordion title="DaemonSet example">
|
||||||
|
```yaml
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: DaemonSet
|
||||||
|
metadata:
|
||||||
|
name: log-agent
|
||||||
|
labels:
|
||||||
|
app: log-agent
|
||||||
|
annotations:
|
||||||
|
secrets.infisical.com/auto-reload: "true" # <- redeployment annotation
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: log-agent
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: log-agent
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: log-agent
|
||||||
|
image: mycompany/log-agent:latest
|
||||||
|
envFrom:
|
||||||
|
- secretRef:
|
||||||
|
name: managed-secret # <- name of the managed secret
|
||||||
|
volumeMounts:
|
||||||
|
- name: config-volume
|
||||||
|
mountPath: /etc/config
|
||||||
|
readOnly: true
|
||||||
|
volumes:
|
||||||
|
- name: config-volume
|
||||||
|
secret:
|
||||||
|
secretName: managed-secret
|
||||||
|
```
|
||||||
|
</Accordion>
|
||||||
|
|
||||||
|
<Accordion title="StatefulSet example">
|
||||||
|
```yaml
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: StatefulSet
|
||||||
|
metadata:
|
||||||
|
name: db-worker
|
||||||
|
labels:
|
||||||
|
app: db-worker
|
||||||
|
annotations:
|
||||||
|
secrets.infisical.com/auto-reload: "true" # <- redeployment annotation
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: db-worker
|
||||||
|
serviceName: "db-worker"
|
||||||
|
replicas: 2
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: db-worker
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: db-worker
|
||||||
|
image: mycompany/db-worker:stable
|
||||||
|
env:
|
||||||
|
- name: DATABASE_PASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: managed-secret
|
||||||
|
key: DB_PASSWORD
|
||||||
|
ports:
|
||||||
|
- containerPort: 5432
|
||||||
|
```
|
||||||
|
</Accordion>
|
||||||
|
|
||||||
<Info>
|
<Info>
|
||||||
#### How it works
|
#### How it works
|
||||||
When a secret change occurs, the operator will check to see which deployments are using the operator-managed Kubernetes secret that received the update.
|
When a managed secret is updated, the operator checks for any Deployments, DaemonSets, or StatefulSets that consume the updated secret and have the annotation
|
||||||
Then, for each deployment that has this annotation present, a rolling update will be triggered.
|
`secrets.infisical.com/auto-reload: "true"`. For each matching workload, the operator triggers a rolling restart to ensure it picks up the latest secret values.
|
||||||
</Info>
|
</Info>
|
||||||
|
|
||||||
## Using Managed ConfigMap In Your Deployment
|
## Using Managed ConfigMap In Your Deployment
|
||||||
|
|||||||
Reference in New Issue
Block a user