์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด ๊ตฌ์„ฑ ํŒŒ์ผ

์ด ํŽ˜์ด์ง€์—์„œ๋Š” Google Distributed Cloud์˜ ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด ๊ตฌ์„ฑ ํŒŒ์ผ์— ์žˆ๋Š” ํ•„๋“œ๋ฅผ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค.

์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด ๊ตฌ์„ฑ ํŒŒ์ผ์„ ์‚ฌ์šฉํ•˜์—ฌ ์‚ฌ์šฉ์ž ์ด๋ฆ„๊ณผ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ €์žฅํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‹ค์Œ์€ ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด ๊ตฌ์„ฑ ํŒŒ์ผ ์‚ฌ์šฉ ๋ฐฉ๋ฒ•์„ ๋ณด์—ฌ์ฃผ๋Š” ๋ช‡ ๊ฐ€์ง€ ์˜ˆ์‹œ์ž…๋‹ˆ๋‹ค.

  • ๊ด€๋ฆฌ์ž ํด๋Ÿฌ์Šคํ„ฐ ๊ตฌ์„ฑ ํŒŒ์ผ์—์„œ vCenter ์„œ๋ฒ„์˜ ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด๋ฅผ ์ €์žฅํ•  ํŒŒ์ผ์„ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.

  • ๊ด€๋ฆฌ์ž ํด๋Ÿฌ์Šคํ„ฐ ๊ตฌ์„ฑ ํŒŒ์ผ์—์„œ ๋น„๊ณต๊ฐœ Docker ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ์˜ ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด๋ฅผ ์ €์žฅํ•  ํŒŒ์ผ์„ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.

ํ…œํ”Œ๋ฆฟ

์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด๋ฅผ ํด๋Ÿฌ์Šคํ„ฐ ๊ตฌ์„ฑ ํŒŒ์ผ๊ณผ ๋ณ„๊ฐœ์˜ ํŒŒ์ผ์— ๋ณด๊ด€ํ•˜๋ฉด ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด์— ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ๋Š” ์‚ฌ์šฉ์ž ์ˆ˜๋ฅผ ์ œํ•œํ•˜๋Š” ๋ฐ ๋„์›€์ด ๋ฉ๋‹ˆ๋‹ค.

์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด ๊ตฌ์„ฑ ํŒŒ์ผ์˜ ํ•„๋“œ ์ž…๋ ฅ

์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด ๊ตฌ์„ฑ ํŒŒ์ผ์—์„œ ์ด ์„น์…˜์˜ ์„ค๋ช…์— ๋”ฐ๋ผ ํ•„๋“œ ๊ฐ’์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

items

๊ฐ๊ฐ ์‚ฌ์šฉ์ž ์ด๋ฆ„๊ณผ ๋น„๋ฐ€๋ฒˆํ˜ธ๊ฐ€ ํฌํ•จ๋œ ๊ฐ์ฒด ๋ฐฐ์—ด์ž…๋‹ˆ๋‹ค.

items[0].name

๋ฌธ์ž์—ด. ๊ฐ์ฒด์— ๋Œ€ํ•ด ์‚ฌ์šฉ์ž๊ฐ€ ์„ ํƒํ•œ ์ด๋ฆ„์ž…๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

items:
- name: "vcenter-creds"

items[0].username

๋ฌธ์ž์—ด. ์‚ฌ์šฉ์ž ์ด๋ฆ„์ž…๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

items:
- name: "vcenter-creds"
  username: "my-vcenter-account"

Active Directory(AD)๋ฅผ ์‚ฌ์šฉํ•  ๊ฒฝ์šฐ username ํ•„๋“œ์— ๋„๋ฉ”์ธ ์ด๋ฆ„์œผ๋กœ ์‚ฌ์šฉ์ž ์ด๋ฆ„์„ ์ง€์ •ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค(์˜ˆ: username: "userName@domainName" ๋˜๋Š” username: "domainName\\username"). ๋„๋ฉ”์ธ ์ด๋ฆ„์„ ์ง€์ •ํ•˜์ง€ ์•Š์œผ๋ฉด vSphere ์ปจํ…Œ์ด๋„ˆ ์Šคํ† ๋ฆฌ์ง€ ํ”Œ๋Ÿฌ๊ทธ์ธ์ด ์ œ๋Œ€๋กœ ์ž‘๋™ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

items[0].password

๋ฌธ์ž์—ด. ๋น„๋ฐ€๋ฒˆํ˜ธ์ž…๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

items:
- name: "vcenter-creds"
  passwords: "U$icUKEW#INE"

์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด ๊ตฌ์„ฑ ํŒŒ์ผ์˜ ์˜ˆ์‹œ

๋‹ค์Œ์€ ์„ธ ๊ฐ€์ง€ ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด ์ง‘ํ•ฉ์„ ์ €์žฅํ•˜๋Š” ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด ๊ตฌ์„ฑ ํŒŒ์ผ์˜ ์˜ˆ์‹œ์ž…๋‹ˆ๋‹ค.

apiVersion: v1
kind: "CredentialFile"
items:
- name: "vcenter-creds"
  username: "my-vcenter-account"
  password: "U$icUKEW#INE"
- name: "f5-creds"
  username: "my-f5-account"
  password: "exvQVx^@L%F1"
- name: "private-registry-creds"
  username: "my-registry-account"
  password: "kIJGS&uRm2Vh"

๊ฐ ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด ๋ธ”๋ก์—๋Š” ์ด๋ฆ„์ด ์žˆ์Šต๋‹ˆ๋‹ค. ๊ด€๋ฆฌ์ž ํด๋Ÿฌ์Šคํ„ฐ ๊ตฌ์„ฑ ํŒŒ์ผ์—์„œ fileRef.entry ํ•„๋“œ์— ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด ๋ธ”๋ก์˜ ์ด๋ฆ„์„ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.

๋‹ค์Œ์€ ๊ด€๋ฆฌ์ž ํด๋Ÿฌ์Šคํ„ฐ ๊ตฌ์„ฑ ํŒŒ์ผ์˜ ์ผ๋ถ€๋ฅผ ๋ณด์—ฌ์ฃผ๋Š” ์˜ˆ์‹œ์ž…๋‹ˆ๋‹ค. ์ด ํŒŒ์ผ์€ ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด์˜ ์„ธ ๊ฐ€์ง€ ๋ธ”๋ก์„ ์ง€์ •ํ•˜๋ฉฐ, ์ด ๋ธ”๋ก๋“ค์€ ๋ชจ๋‘ ๋™์ผํ•œ ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด ํŒŒ์ผ์— ์žˆ์Šต๋‹ˆ๋‹ค.

vCenter:
  credentials:
    fileRef:
      path: "my-folder/my-creds.yaml"
      entry: "vcenter-creds"
...
loadBalancer:
  f5BigIP:
    credentials:
      fileRef:
        path: "my-folder/my-creds.yaml"
        entry: "f5-creds"
...
privateRegistry:
  credentials:
    fileRef:
      path: "my-folder/my-creds.yaml"
      entry: "private-registry-creds"