【问题标题】:Can anyone explain what is meant by <CERTIFICATE_DATA_REDACTED>?谁能解释 <CERTIFICATE_DATA_REDACTED> 的含义?
【发布时间】:2019-07-14 22:44:28
【问题描述】:

我正在尝试设置 ElasticSearch OpenDistro,但我无法理解链接中 &lt;CERTIFICATE_DATA_REDACTED&gt; 的含义

https://github.com/opendistro-for-elasticsearch/community/blob/master/open-distro-elasticsearch-kubernetes/elasticsearch/35-es-bootstrap-secrets.yml 。

我应该如何使用这个 yaml 文件?我是否需要将 base64 编码值放在这里替换 kubectl apply -f secrets.yaml 或什么?

有人可以提供任何对此进行解释的参考链接吗?

kind: Secret
metadata:
  name: elasticsearch-tls-data
  namespace: elasticsearch
type: Opaque
stringData:
  elk-crt.pem: |-
    <CERTIFICATE_DATA_REDACTED>
  elk-key.pem: |-
    <CERTIFICATE_DATA_REDACTED>
  elk-root-ca.pem: |-
    <CERTIFICATE_DATA_REDACTED>
  admin-crt.pem: |-
    <CERTIFICATE_DATA_REDACTED>
  admin-key.pem: |-
    <CERTIFICATE_DATA_REDACTED>
  admin-root-ca.pem: |-
    <CERTIFICATE_DATA_REDACTED> ````

【问题讨论】:

    标签: kubernetes elasticsearch-opendistro


    【解决方案1】:

    我以前没有使用过这个配置,但我认为你应该做的是创建自己的证书elk-crt.pem, elk-key.pem, elk-root-ca.pem, admin-crt.pem, admin-key.pem, admin-root-ca.pem 与 Kibana 相同(如果你将使用它),然后只需使用原始值创建你的 Secret,

    请阅读:

    For certain scenarios, you may wish to use the stringData field instead. This field allows you to put a non-base64 encoded string directly into the Secret, and the string will be encoded for you when the Secret is created or updated.

    https://kubernetes.io/docs/concepts/configuration/secret/

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多