Microsoft Certified: DevOps Engineer ExpertDesign and implement pipelinesMedium
A DevOps team is managing a complex application deployed to an Azure Kubernetes Service (AKS) cluster. The application requires access to sensitive secrets like API keys and database connection strings. To enhance security, the team wants to avoid storing these secrets directly in Kubernetes manifests or as environment variables in pods. They need a solution that allows pods to securely retrieve secrets from Azure Key Vault. Which Azure Kubernetes Service feature, combined with Azure Key Vault, should the team implement?
- AManually mount Key Vault secrets as volumes using `kubectl` commands.
- BAzure AD Pod Identity for direct Key Vault access.
- CKubernetes Secrets configured with Base64 encoding.
- DAzure Key Vault Provider for Secrets Store CSI Driver.
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Key Vault Provider for Secrets Store CSI Driver.
The Azure Key Vault Provider for Secrets Store CSI Driver allows Kubernetes pods to mount secrets from Azure Key Vault as a volume. This enables applications to consume secrets securely from Key Vault without having to modify their code or store secrets in environment variables or Kubernetes Secrets.
Why the other options are wrong
- A. Manual mounting is not a scalable or automated solution for CI/CD pipelines and doesn't leverage the CSI driver's benefits.
- B. Azure AD Pod Identity is deprecated. Workload Identity is the current recommended approach for AKS identity.
- C. Base64 encoding is not encryption and offers no security for secrets at rest or in transit.
Key Vault Provider for CSI Driver
Enables Kubernetes applications to securely mount secrets, keys, and certificates stored in Azure Key Vault as a volume.
- Integrates Azure Key Vault with AKS pods.
- Secrets are mounted as files, not environment variables.
- Enhances security by centralizing secret management.
Memory trick: CSI mounts Key Vault, keeping secrets sound.