Skip to content

Add support for fileKeyRef to the Kubernetes Publisher #19756

Description

Is there an existing issue for this?

  • I have searched the existing issues

Is your feature request related to a problem? Please describe the problem.

It's sometimes necessary to derive environment variables from a sidecar or init container. For example, Vault Agent Injector can write files to disk when pods start up that contain secrets from the cluster's Vault instance. Some of those secrets are useful when setting environment variables (for instance, PostgresServerResource has POSTGRES_USER and POSTGRES_PASSWORD environment variables that configure the container prior to spinning up).

Current workarounds exist like overriding the Workload.PodTemplate.Spec.Container[].Command, to source the injected file and then run the container as normal. However manual work is then needed to determine the image's original entrypoint.

Describe the solution you'd like

Kubernetes v1.34 introduced a method of injecting environment variables by having an init container write secrets to a shared file, and then having the primary container source the file via a fileKeyRef. https://kubernetes.io/docs/tasks/inject-data-application/define-environment-variable-via-file/

It would be great to see fileKeyRef added to the EnvVarSourceV1 object as a means of natively supporting this use-case through Aspire.

Additional context

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area-deploymentneeds-area-labelAn area label is needed to ensure this gets routed to the appropriate area ownerstriage:bot-seenAspire triage bot has seen this issue

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions