Skip to main content

Use External Secrets Operator (ESO) secrets in a Kubernetes Engine cluster

Synchronize a string stored in Secrets Manager to a Kubernetes Secret and verify updates after changing its default version.

Basic information
  • Estimated time: About 15 minutes
  • Prerequisites
    • Completed Install ESO and verify basic synchronization
    • Reuse the eso-demo namespace and kakaocloud-secret-store created in the installation tutorial
    • kubectl installed and configured for the target cluster
    • Secret ID and read permission for the KakaoCloud Secrets Manager secret
    • Console permission to create a new version for scenario 2

Scenario overview​

Run this tutorial after verifying basic synchronization in the ESO installation tutorial. Using the installed ESO, credentials, and SecretStore, create a separate Kubernetes Secret for this exercise and verify value updates.

The main steps are:

  • Synchronize a string secret
  • Verify that a Kubernetes Secret is updated after changing the default version

See Additional usage to connect the synchronized Secret to an application or apply other configurations.

Before you start​

Check the resources created in the installation tutorial. SecretStore must be Ready=True, and the ExternalSecret used for basic synchronization must be Ready=True with status SecretSynced.

Check basic synchronization status
kubectl get secretstore kakaocloud-secret-store -n eso-demo
kubectl get externalsecret kakaocloud-external-secret -n eso-demo
kubectl get secret kakaocloud-synced-secret -n eso-demo

If basic synchronization is incomplete, first follow Verify synchronization and Troubleshooting in the installation tutorial.

This tutorial creates an exercise ExternalSecret and target Kubernetes Secret with separate names. It uses the external-secrets.io/v1 API, the eso-demo namespace, and the kakaocloud-secret-store from the installation tutorial.

See the service guide's Deployment information and Scope and limitations for the deployment version and supported scope.

Scenario 1: Synchronize string secret​

Pass a value stored as a single string in Secrets Manager, such as an API key, password, or token, to the password key of the app-password Kubernetes Secret. This Secret is used to verify value replacement in the next scenario.

1. Create ExternalSecret​

Enter the actual Secrets Manager secret ID in the input field below the code and create app-password.yaml.

app-password.yaml
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: app-password
namespace: eso-demo
spec:
refreshPolicy: Periodic
refreshInterval: 1m0s
secretStoreRef:
name: kakaocloud-secret-store
kind: SecretStore
target:
name: app-password
creationPolicy: Owner
data:
- secretKey: password
remoteRef:
key: ${SECRET_ID}
VariableDescription
SECRET_ID🖌︎Secrets Manager secret ID
Note

refreshInterval: 1m0s is used for quick testing. In production, adjust the interval to match your secret rotation policy and API call cycle.

Because remoteRef.version is omitted, the default version is retrieved. To pin a specific version, see Pin a specific secret version.

2. Verify result​

Apply and check ExternalSecret
kubectl apply -f app-password.yaml

kubectl wait --for=condition=Ready \
externalsecret/app-password -n eso-demo --timeout=60s

kubectl get externalsecret app-password -n eso-demo
kubectl get secret app-password -n eso-demo

Check only the data keys without printing Secret values.

Check data keys
kubectl get secret app-password -n eso-demo \
-o go-template='{{range $key, $_ := .data}}{{$key}}{{"\n"}}{{end}}'

Success criteria​

  • Ready for ExternalSecret is True.
  • The app-password Kubernetes Secret is created.
  • The Secret contains the password key.

Scenario 2: Update Kubernetes Secret after changing default version​

Use app-password from scenario 1 to verify that a password or API key rotation is reflected. When remoteRef.version is omitted, KakaoCloud Secrets Manager's default version is retrieved. A newly created version becomes the default, and ESO updates the target Kubernetes Secret at the next synchronization.

1. Create new version​

Use the app-password from scenario 1. If you added remoteRef.version to app-password.yaml, remove it and apply the manifest again.

  1. In KakaoCloud Console, create a new version for the same secret used in scenario 1.
  2. Enter eso-demo-password-002, a practice string different from the existing value.

eso-demo-password-002 is a public practice value. Do not use it as a production password.

2. Check updated value​

Because scenario 1 uses refreshInterval: 1m0s, ESO automatically synchronizes the default version about once per minute. Wait about one minute after creating the new version, then run the command below.

To request synchronization immediately, run the following optional command. It does not change the configured interval.

Request manual synchronization (optional)
kubectl annotate externalsecret app-password -n eso-demo \
force-sync="$(date +%s)" --overwrite

After waiting for automatic synchronization or requesting a manual synchronization, check the Kubernetes Secret value. This command prints the practice value; do not use it for production secrets.

Check the Kubernetes Secret value
kubectl get secret app-password -n eso-demo \
-o jsonpath='{.data.password}' | base64 --decode
Output
eso-demo-password-002

The update is complete when the output matches the value entered in the new version. If the old value is displayed, check again later. If it still does not change, verify the new version and remoteRef.version, then see ESO integration troubleshooting.

Troubleshooting

If installation or synchronization fails, see ESO integration troubleshooting for symptom-specific checks.

Additional usage​

After verifying synchronization and updates, see the service guide examples as needed.

Clean up practice resources​

Delete practice resources that are no longer needed. ESO, SecretStore, IAM credentials Secret, and the basic synchronization resources from the installation tutorial are retained. Keep these shared resources if you plan to continue with Additional usage.

The examples in this tutorial and the service guide use creationPolicy: Owner. Deleting an ExternalSecret also deletes its owned target Kubernetes Secret.

Delete this tutorial's resources​

Delete app-password used in scenarios 1 and 2.

Delete exercise resources
kubectl delete externalsecret app-password -n eso-demo --ignore-not-found

Delete service guide example resources (optional)​

Run these commands only if you also ran the JSON secret, application settings, or TLS certificate examples in the service guide. Remove or change existing Ingress TLS references and clean up environment variable references added to an existing Deployment.

Delete service guide example resources
kubectl delete deployment app-credentials-volume -n eso-demo --ignore-not-found
kubectl delete externalsecret app-credentials database-credentials ingress-tls \
-n eso-demo --ignore-not-found

Delete shared resources​

If you no longer need ESO, SecretStore, the IAM credentials Secret, or the basic synchronization resources, follow the installation tutorial cleanup procedure.

Troubleshooting

If installation or synchronization fails, see ESO integration troubleshooting for symptom-specific checks.