New to KubeVault? Please start here.
To use kubernetesSecret mode specify mode.kubernetesSecret
. In this mode, unseal keys and root token will be stored in Kubernetes secret.
spec:
unsealer:
mode:
kubernetesSecret:
secretName: <secret_name>
mode.kubernetesSecret
has following field:
kubernetesSecret.secretName
is a required field that specifies the name of Kubernetes secret. If this secret does not exist, then Unsealer will create it. The secret will be created in the same namespace of VaultServer.
spec:
unsealer:
mode:
kubernetesSecret:
secretName: "vault-keys"