Secrets
A secret holds sensitive strings on the Controller for one namespace. Keys live in a root data block, beside metadata.
The short map is Config, secrets, and volumes. Fields are on Secret fields.
This object is the Controller secret. A Kubernetes Secret is a different store, used only when a certificate authority imports type: k8s-secret.
When to use it
Use a secret for passwords, tokens, and key material. Deploy it before a microservice valueFromSecret, before a volume mount that sets secretName, and before a certificate authority that imports type: direct.
Non-secret settings belong in a config map.
What deploy does
potctl deploy -f secret.yaml -n my-ecn
Deploy looks up metadata.name. A missing name creates the secret, including spec.type when you set it. The same name updates data. Re-deploy sends the data map in the file. Prefer delete secret when you need to drop a key or rename the secret.
There is no attach on the secret. A volume mount publishes it onto Edgelet nodes.
apiVersion: datasance.com/v3
kind: Secret
metadata:
name: postgres-creds
namespace: my-ecn
spec:
type: Opaque
data:
username: app
password: changeme
For spec.type: tls, each data value is one line of base64-encoded PEM. See Secret fields.
How a microservice uses it
Set valueFromSecret to secret-name/key. The secret and the microservice share the namespace.
apiVersion: datasance.com/v3
kind: Microservice
metadata:
name: line-monitor/reader
spec:
container:
env:
- key: DB_PASSWORD
valueFromSecret: postgres-creds/password
To mount keys as files, set spec.secretName on a volume mount, then use type: volumeMount. See Volume mounts and Microservice fields.
CLI
potctl get secrets -n my-ecn
potctl describe secret postgres-creds -n my-ecn
potctl delete secret postgres-creds -n my-ecn
describe secret prints spec.type and data. Treat that file as confidential. delete secret takes the name.
Console
Config → Secrets reviews types and edits YAML. See Configuration.