Use External Secrets Operator (ESO) secrets in a Kubernetes Engine cluster
Synchronize a string stored in Secrets Manager to a Kubernetes Secret and verify updates after changing its default version.
- Estimated time: About 15 minutes
- Prerequisites
- Completed Install ESO and verify basic synchronization
- Reuse the
eso-demonamespace andkakaocloud-secret-storecreated in the installation tutorial kubectlinstalled and configured for the target cluster- Secret ID and read permission for the KakaoCloud Secrets Manager secret
- Console permission to create a new version for scenario 2
Scenario overview
Run this tutorial after verifying basic synchronization in the ESO installation tutorial. Using the installed ESO, credentials, and SecretStore, create a separate Kubernetes Secret for this exercise and verify value updates.
The main steps are:
- Synchronize a string secret
- Verify that a Kubernetes Secret is updated after changing the default version
See Additional usage to connect the synchronized Secret to an application or apply other configurations.
Before you start
Check the resources created in the installation tutorial. SecretStore must be Ready=True, and the ExternalSecret used for basic synchronization must be Ready=True with status SecretSynced.
kubectl get secretstore kakaocloud-secret-store -n eso-demo
kubectl get externalsecret kakaocloud-external-secret -n eso-demo
kubectl get secret kakaocloud-synced-secret -n eso-demo
If basic synchronization is incomplete, first follow Verify synchronization and Troubleshooting in the installation tutorial.
This tutorial creates an exercise ExternalSecret and target Kubernetes Secret with separate names. It uses the external-secrets.io/v1 API, the eso-demo namespace, and the kakaocloud-secret-store from the installation tutorial.
See the service guide's Deployment information and Scope and limitations for the deployment version and supported scope.
Scenario 1: Synchronize string secret
Pass a value stored as a single string in Secrets Manager, such as an API key, password, or token, to the password key of the app-password Kubernetes Secret. This Secret is used to verify value replacement in the next scenario.
1. Create ExternalSecret
Enter the actual Secrets Manager secret ID in the input field below the code and create app-password.yaml.
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: app-password
namespace: eso-demo
spec:
refreshPolicy: Periodic
refreshInterval: 1m0s
secretStoreRef:
name: kakaocloud-secret-store
kind: SecretStore
target:
name: app-password
creationPolicy: Owner
data:
- secretKey: password
remoteRef:
key: ${SECRET_ID}
| Variable | Description |
|---|---|
| SECRET_ID🖌︎ | Secrets Manager secret ID |
refreshInterval: 1m0s is used for quick testing. In production, adjust the interval to match your secret rotation policy and API call cycle.
Because remoteRef.version is omitted, the default version is retrieved. To pin a specific version, see Pin a specific secret version.
2. Verify result
kubectl apply -f app-password.yaml
kubectl wait --for=condition=Ready \
externalsecret/app-password -n eso-demo --timeout=60s
kubectl get externalsecret app-password -n eso-demo
kubectl get secret app-password -n eso-demo
Check only the data keys without printing Secret values.
kubectl get secret app-password -n eso-demo \
-o go-template='{{range $key, $_ := .data}}{{$key}}{{"\n"}}{{end}}'
Success criteria
ReadyforExternalSecretisTrue.- The
app-passwordKubernetes Secret is created. - The Secret contains the
passwordkey.
Scenario 2: Update Kubernetes Secret after changing default version
Use app-password from scenario 1 to verify that a password or API key rotation is reflected. When remoteRef.version is omitted, KakaoCloud Secrets Manager's default version is retrieved. A newly created version becomes the default, and ESO updates the target Kubernetes Secret at the next synchronization.
1. Create new version
Use the app-password from scenario 1. If you added remoteRef.version to app-password.yaml, remove it and apply the manifest again.
- In KakaoCloud Console, create a new version for the same secret used in scenario 1.
- Enter
eso-demo-password-002, a practice string different from the existing value.
eso-demo-password-002 is a public practice value. Do not use it as a production password.
2. Check updated value
Because scenario 1 uses refreshInterval: 1m0s, ESO automatically synchronizes the default version about once per minute. Wait about one minute after creating the new version, then run the command below.
To request synchronization immediately, run the following optional command. It does not change the configured interval.
kubectl annotate externalsecret app-password -n eso-demo \
force-sync="$(date +%s)" --overwrite
After waiting for automatic synchronization or requesting a manual synchronization, check the Kubernetes Secret value. This command prints the practice value; do not use it for production secrets.
kubectl get secret app-password -n eso-demo \
-o jsonpath='{.data.password}' | base64 --decode
eso-demo-password-002
The update is complete when the output matches the value entered in the new version. If the old value is displayed, check again later. If it still does not change, verify the new version and remoteRef.version, then see ESO integration troubleshooting.
If installation or synchronization fails, see ESO integration troubleshooting for symptom-specific checks.
Additional usage
After verifying synchronization and updates, see the service guide examples as needed.
- Pin a specific secret version
- Synchronize a JSON secret
- Pass application settings
- Pass a TLS certificate to Ingress
Clean up practice resources
Delete practice resources that are no longer needed. ESO, SecretStore, IAM credentials Secret, and the basic synchronization resources from the installation tutorial are retained. Keep these shared resources if you plan to continue with Additional usage.
The examples in this tutorial and the service guide use creationPolicy: Owner. Deleting an ExternalSecret also deletes its owned target Kubernetes Secret.
Delete this tutorial's resources
Delete app-password used in scenarios 1 and 2.
kubectl delete externalsecret app-password -n eso-demo --ignore-not-found
Delete service guide example resources (optional)
Run these commands only if you also ran the JSON secret, application settings, or TLS certificate examples in the service guide. Remove or change existing Ingress TLS references and clean up environment variable references added to an existing Deployment.
kubectl delete deployment app-credentials-volume -n eso-demo --ignore-not-found
kubectl delete externalsecret app-credentials database-credentials ingress-tls \
-n eso-demo --ignore-not-found
Delete shared resources
If you no longer need ESO, SecretStore, the IAM credentials Secret, or the basic synchronization resources, follow the installation tutorial cleanup procedure.
If installation or synchronization fails, see ESO integration troubleshooting for symptom-specific checks.