With this AKS add-on, pods read Key Vault certificates, keys and secrets as files from a mounted CSI volume. It can also rotate them and copy them into Kubernetes Secrets.
Also called Azure Key Vault provider for Secrets Store CSI Driver.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Secrets Store CSI Driver in context, with comparison tables and the common traps.
Terms in this definition
- AKS
Short for Azure Kubernetes Service, a managed Kubernetes offering that gives full control of clusters and node pools. Scaling uses the cluster autoscaler and Horizontal Pod Autoscaler; user sign-in is not built in.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
- CSI
Short for Container Storage Interface, the Kubernetes standard for storage drivers. Using the Azure Key Vault provider, the Secrets Store CSI Driver gives AKS pods a mounted volume containing Key Vault certificates, keys and secrets.
- Volume
Holds non-tabular files sitting in cloud storage under Unity Catalog governance, addressed as
/Volumes/<catalog>/<schema>/<volume>. A volume can be external or managed, andWRITE VOLUMEorREAD VOLUMEdecide who may use it.
Related terms
- Key Vault Certificate User
Lets the holder read public keys and complete certificates, the latter through the secret endpoint, using Key Vault RBAC. The Secrets Store CSI Driver needs this role to retrieve certificates and keys.
- Kubernetes Secret
Kubernetes resource for passing sensitive values to pods. Since manifests hold them merely base64-encoded and etcd keeps them too, Microsoft Learn favours Key Vault through the Secrets Store CSI Driver.
- SecretProviderClass
Kubernetes custom resource naming the Key Vault, the identity to use and the objects the Secrets Store CSI Driver should mount. Pods can only use one created in their own namespace.