build/kanikohelp wantedkind/frictionpriority/p1
倉庫指標
- 星標
- (12,822 顆星)
- PR 合併指標
- (平均合併 3天 6小時) (30 天內合併 16 個 PR)
描述
I'm using Skaffold with a Kaniko build step on GKE and am wondering why the need for the kaniko-secret.
If I'm in GKE and the default SA used has permissions to push to my GCR repo why do I need to also supply SA keys via the kaniko-secret?
I see that things are working without the secret if Workload Identity is enabled but what about clusters not yet migrated to Workload Identity? https://github.com/GoogleContainerTools/skaffold/issues/3468
The only way I found to get it working is with the following instructions and skaffold.yaml.
Instructions:
- Create SA with
Starage Admin - Download keys
- Rename keys to kaniko-secret
kubectl create secret generic kaniko-secret --from-file=kaniko-secret
skaffold.yaml
apiVersion: skaffold/v2beta7
kind: Config
metadata:
name: my-image
build:
artifacts:
- image: gcr.io/my-repo/my-image
kaniko:
cache: {}
cluster:
pullSecretName: kaniko-secret
How can I make this work with the default SA and not have to add secondary keys?