Skip to content

Instantly share code, notes, and snippets.

View alexei-led's full-sized avatar
🤖
Don't panic!

Alexei Ledenev alexei-led

🤖
Don't panic!
View GitHub Profile
@alexei-led
alexei-led / Markdium-Shell.sh
Created April 27, 2020 06:41
Markdium-Kubernetes and Secrets Management in Cloud: Part 2
# create a cluster role
kubectl create -f deployment/clusterrole.yaml
# define a cluster role binding
kubectl create -f deployment/clusterrolebinding.yaml
@alexei-led
alexei-led / Markdium-Shell.sh
Created April 27, 2020 06:41
Markdium-Kubernetes and Secrets Management in Cloud: Part 2
# environment variable passed to `secrets-init`
API_KEY=arn:aws:ssm:$AWS_REGION:$AWS_ACCOUNT_ID:parameter/api/key
# environment variable passed to child process, resolved by `secrets-init`
API_KEY=key-123456789
@alexei-led
alexei-led / Markdium-Shell.sh
Created April 27, 2020 06:41
Markdium-Kubernetes and Secrets Management in Cloud: Part 2
# environment variable passed to `secrets-init`
DB_PASSWORD=gcp:secretmanager:projects/$PROJECT_ID/secrets/db/password
# OR versioned secret (with version or 'latest')
DB_PASSWORD=gcp:secretmanager:projects/$PROJECT_ID/secrets/db/password/versions/2
# environment variable passed to child process, resolved by `secrets-init`
DB_PASSWORD=very-secret-password
@alexei-led
alexei-led / Markdium-YAML.yaml
Created April 27, 2020 06:41
Markdium-Kubernetes and Secrets Management in Cloud: Part 2
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "ssm:GetParameter",
"Resource": "arn:aws:ssm:us-west-2:123456789012:parameter/prod-*"
}
]
}
@alexei-led
alexei-led / Markdium-YAML.yaml
Created April 27, 2020 06:41
Markdium-Kubernetes and Secrets Management in Cloud: Part 2
[...]
args:
[...]
- --tls-cert-file=/etc/webhook/certs/cert.pem
- --tls-private-key-file=/etc/webhook/certs/key.pem
volumeMounts:
- name: webhook-certs
mountPath: /etc/webhook/certs
readOnly: true
[...]
@alexei-led
alexei-led / Markdium-Shell.sh
Created February 17, 2020 09:02
Markdium-Securely Access AWS from GKE
kubectl create -f deployment/mutatingwebhook-bundle.yaml
@alexei-led
alexei-led / Markdium-Shell.sh
Created February 17, 2020 09:02
Markdium-Securely Access AWS from GKE
kubectl create serviceaccount --namespace ${K8S_NAMESPACE} ${KSA_NAME}
@alexei-led
alexei-led / Markdium-Shell.sh
Created February 17, 2020 09:02
Markdium-Securely Access AWS from GKE
kubectl annotate serviceaccount --namespace ${K8S_NAMESPACE} ${KSA_NAME}
amazonaws.com/role-arn=${AWS_ROLE_ARN}
@alexei-led
alexei-led / Markdium-Shell.sh
Created February 17, 2020 09:02
Markdium-Securely Access AWS from GKE
kubectl annotate serviceaccount --namespace ${K8S_NAMESPACE} ${KSA_NAME}
iam.gke.io/gcp-service-account=${GSA_NAME}@${PROJECT_ID}.iam.gserviceaccount.com
@alexei-led
alexei-led / Markdium-Shell.sh
Created February 17, 2020 09:02
Markdium-Securely Access AWS from GKE
cat ./deployment/mutatingwebhook.yaml | ./deployment/webhook-patch-ca-bundle.sh > ./deployment/mutatingwebhook-bundle.yaml