秘钥管理秘钥Turtles all the way down - Securely managing Kubernetes Secretsthe KMS plugin Master kube-apiserver etcd kms-plugin SECRETDEK DEKKEK KEK Terminology and Notation DEK Data encryption key KEK Key encryption key {SECRET}DEK Secret is encrypted with DEK {DEK}KEK encrypted with KEK {SECRET}DEK + {DEK}KEK Envelope Source for crypto notation: https://en.wikipedia.org/wiki/Security_protocol_notation KMS 1.10 Envelope Encryption Sequence Master kube-apiserver etcd0 码力 | 52 页 | 2.84 MB | 1 年前3
Kubernetes开源书 - 周立that the JSON spec doesn’t support octal notation, so use the value 256 for 0400 permissions. If you use yaml instead of json for the pod, you can use octal notation to specify permissions in a more natural0 码力 | 135 页 | 21.02 MB | 1 年前3
共 2 条
- 1













