Secrets
The chart has two ways to get secret data into your containers: values mounted as environment variables, and files mounted onto disk. Both are wired into every container automatically through the configure flags, so you rarely reference the resulting Secret by name.
For secrets you want to keep encrypted in Git, use Sealed Secrets instead of the plain values below. It mirrors the same API key for key and is documented on the Sealed Secrets page.
Environment variables
secrets declares key/value pairs that land in a Secret named <fullname>-secrets and are injected into every container as environment variables (via envFrom):
secrets:
DATABASE_PASSWORD: supersecret
API_KEY: abcd1234The Secret is a generated singleton with a flat data map, so it has no per-resource annotations key of its own. It still receives the global annotations and labels, so a shared metadata set reaches it. See Annotations.
The values are base64-encoded into the Secret for you. Because they sit in plain text in your values, only use secrets for values that are not committed to Git, set them from the command line or a CI variable:
helm install myapp hosst/standard --set secrets.DATABASE_PASSWORD="$DB_PASSWORD"Injection is controlled by configure.secrets (on by default). See Config for the same mechanism applied to non-secret variables.
Mounted files
mountedSecretFiles mounts secret files into containers. A key that starts with / is an absolute path; anything else is mounted under /config:
mountedSecretFiles:
"conf/serviceaccount.json": <base64 content> # mounted at /config/conf/serviceaccount.json
"/etc/app/token": <base64 content> # mounted at the absolute pathStore the base64-encoded content directly, or set it from a file at install time:
helm install myapp hosst/standard \
--set-file mountedSecretFiles.'/conf/serviceaccount\.json'=files/serviceaccount.jsonMounting is controlled by configure.secretFiles (on by default).
Rolling on change
Changing any secrets or mounted-file value updates a checksum annotation on the deployment pod template, so the pods roll to pick up the new value. Version bumps alone do not roll them. See Annotations.
Opting a container out
Set the relevant configure flag to false on a container to stop the automatic injection, for example a sidecar that should not receive the app's secrets:
deployments:
app:
containers:
app:
# inherits configure.secrets: true → gets the Secret
metrics:
configure:
secrets: false # this container gets no secrets