Fix secrets docs in 1.12 branch (#10056)
* Fix secrets docs * Update secret.md
This commit is contained in:
committed by
k8s-ci-robot
parent
e7319eeb8c
commit
3286b00f58
@@ -339,9 +339,15 @@ files.
|
|||||||
|
|
||||||
When a secret being already consumed in a volume is updated, projected keys are eventually updated as well.
|
When a secret being already consumed in a volume is updated, projected keys are eventually updated as well.
|
||||||
Kubelet is checking whether the mounted secret is fresh on every periodic sync.
|
Kubelet is checking whether the mounted secret is fresh on every periodic sync.
|
||||||
However, it is using its local ttl-based cache for getting the current value of the secret.
|
However, it is using its local cache for getting the current value of the Secret.
|
||||||
As a result, the total delay from the moment when the secret is updated to the moment when new keys are
|
The type of the cache is configurable using the (`ConfigMapAndSecretChangeDetectionStrategy` field in
|
||||||
projected to the pod can be as long as kubelet sync period + ttl of secrets cache in kubelet.
|
[KubeletConfiguration struct](https://github.com/kubernetes/kubernetes/blob/{{< param "docsbranch" >}}/pkg/kubelet/apis/kubeletconfig/v1beta1/types.go)).
|
||||||
|
It can be either propagated via watch (default), ttl-based, or simply redirecting
|
||||||
|
all requests to directly kube-apiserver.
|
||||||
|
As a result, the total delay from the moment when the Secret is updated to the moment
|
||||||
|
when new keys are projected to the Pod can be as long as kubelet sync period + cache
|
||||||
|
propagation delay, where cache propagation delay depends on the chosen cache type
|
||||||
|
(it equals to watch propagation delay, ttl of cache, or zero corespondingly).
|
||||||
|
|
||||||
{{< note >}}
|
{{< note >}}
|
||||||
**Note:** A container using a Secret as a
|
**Note:** A container using a Secret as a
|
||||||
|
|||||||
Reference in New Issue
Block a user