-->

Sidecar pattern

The sidecar pattern is about co-locating another container in a pod in addition to the main application container. The application container is unaware of the sidecar container and just goes about its business. A great example is a central logging agent. Your main container can just log to stdout, but the sidecar container will send all logs to a central logging service where they will be aggregated with the logs from the entire system. The benefits of using a sidecar container versus adding central logging to the main application container are enormous. First, applications are not burdened anymore with central logging, which could be a nuisance. If you want to upgrade or change your central logging policy or switch to a totally new provider, you just need to update the sidecar container and deploy it. None of your application containers change, so you can't break them by accident.

Random Pic Of The Day!
Random Pic Of The Day!
Question Of The Day!

Kubernetes Secrets vs ConfigMaps

Have been using Kubernetes secrets up to date. Now we have ConfigMaps as well.

What is the preferred way forward - secrets or config maps?

P.S. After a few iterations we have stabilised at the following rule:

  • configMaps are per solution domain (can be shared across microservices within the domain, but ultimately are single purpose config entries)

  • secrets are shared across solution domains, usually represent third party systems or databases

BEST ANSWER:

I'm the author of both of these features. The idea is that you should:

  1. Use secrets for things which are actually secret like API keys, credentials, etc
  2. Use config map for not-secret configuration data

In the future there will likely be some differentiators for secrets like rotation or support for backing the secret API w/ HSMs, etc. In general we like intent-based APIs, and the intent is definitely different for secret data vs. plain old configs.

Hope that helps.

Quote Of The Day!

Just because you took longer than others, doesn’t mean you failed.
Unknown

Sidecar pattern Laurent Skinner 5 of 5
The sidecar pattern is about co-locating another container in a pod in addition to the main application container. The application containe...

Posts relacionados: No está disponible si la entrada carece de etiquetas

0 Comentarios