Parameter name containing special characters on Helm chart

Viewed 437

In my Helm chart, I need to set the following Java Spring parameter name:

company.sms.security.password@id(name):
  secret:
    name: mypasswd
    key: mysecretkey

But when applying the template, I encounter a syntax issue.

oc apply -f template.yml

The Deployment "template" is invalid: spec.template.spec.containers[0].env[79].name: Invalid value: "company.sms.security.password@id(name)": a valid environment variable name must consist of alphabetic characters, digits, '_', '-', or '.', and must not start with a digit (e.g. 'my.env-name',  or 'MY_ENV.NAME',  or 'MyEnvName1', regex used for validation is '[-._a-zA-Z][-._a-zA-Z0-9]*')

What I would usually do is defining this variable at runtime like this:

JAVA_TOOL_OPTIONS:
-Dcompany.sms.security.password@id(name)=mypass

But since it's storing sensitive data, obviously I cannot log in clear the password. So far I could only think about defining an Initcontainer as a workaround, changing the parameter name is not an option. Edit: So the goal is to not log the password neither in the manifest nor in the application logs.

1 Answers

Edited:

Assign the value from your secret to one environment variable, and use it in the JAVA_TOOL_OPTIONS environment variable value. the way to expand the value of a previously defined variable VAR_NAME, is $(VAR_NAME).

For example:

- name: MY_PASSWORD
  valueFrom:
    secretKeyRef:
      name: mypasswd
      key: mysecretkey
- name: JAVA_TOOL_OPTIONS
  value: "-Dcompany.sms.security.password@id(name)=$(MY_PASSWORD)"

Constrains

There are some conditions for kuberenetes in order to parse the $(VAR_NAME) correctly, otherwise $(VAR_NAME) will be parsed as a regular string:

  1. The variable VAR_NAME should be defined before the one that uses it
  2. The value of VAR_NAME must not be another variable, and must be defined. If the value of VAR_NAME consists of other variables or is undefined, $(VAR_NAME) will be parsed as a string.

In the example above, if the secret mypasswd in the pod's namespace doesn't have a value for the key mysecretkey, $(MY_PASSWORD) will appear literally as a string and will not be parsed.

References:

Related