Fix secrets docs in 1.12 branch (#10056)

* Fix secrets docs

* Update secret.md
This commit is contained in:
Wojciech Tyczynski
2018-09-13 20:05:24 +02:00
committed by k8s-ci-robot
parent e7319eeb8c
commit 3286b00f58
@@ -339,9 +339,15 @@ files.
When a secret being already consumed in a volume is updated, projected keys are eventually updated as well. When a secret being already consumed in a volume is updated, projected keys are eventually updated as well.
Kubelet is checking whether the mounted secret is fresh on every periodic sync. Kubelet is checking whether the mounted secret is fresh on every periodic sync.
However, it is using its local ttl-based cache for getting the current value of the secret. However, it is using its local cache for getting the current value of the Secret.
As a result, the total delay from the moment when the secret is updated to the moment when new keys are The type of the cache is configurable using the (`ConfigMapAndSecretChangeDetectionStrategy` field in
projected to the pod can be as long as kubelet sync period + ttl of secrets cache in kubelet. [KubeletConfiguration struct](https://github.com/kubernetes/kubernetes/blob/{{< param "docsbranch" >}}/pkg/kubelet/apis/kubeletconfig/v1beta1/types.go)).
It can be either propagated via watch (default), ttl-based, or simply redirecting
all requests to directly kube-apiserver.
As a result, the total delay from the moment when the Secret is updated to the moment
when new keys are projected to the Pod can be as long as kubelet sync period + cache
propagation delay, where cache propagation delay depends on the chosen cache type
(it equals to watch propagation delay, ttl of cache, or zero corespondingly).
{{< note >}} {{< note >}}
**Note:** A container using a Secret as a **Note:** A container using a Secret as a