[{"data":1,"prerenderedAt":69},["ShallowReactive",2],{"/2026/03/08-container-storage-interface":3},{"id":4,"title":5,"body":6,"date":60,"description":57,"extension":61,"meta":62,"navigation":63,"path":64,"robots":65,"seo":66,"stem":67,"__hash__":68},"posts/2026/03/08 Container-Storage-Interface.md","08 Container Storage Interface",{"type":7,"value":8,"toc":56},"minimark",[9,18,21,25,27,30,32,35,37,40,42],[10,11,13],"post-title",{":date":12},"date",[14,15,17],"h1",{"id":16},"container-storage-interface-csi","Container Storage Interface (CSI)",[19,20],"br",{},[22,23,24],"p",{},"I was investigating how to get a secret from Hashicorp Vault down to a Kubernetes pod and encountered an interesting concept called Container Storage Interface (CSI).",[19,26],{},[22,28,29],{},"Basically, using CSI driver, providing the secret name and key, a SecretProviderClass object can pull each secret value as a file in the filesystem in the pod.",[19,31],{},[22,33,34],{},"Then, use entrypoint script of the pod to pull each file and set environment variable using the file name as key and content as value.",[19,36],{},[22,38,39],{},"The application can then pull the secret from the environment variables without additional package/library.",[19,41],{},[22,43,44,45],{},"For more information: ",[46,47,50],"span",{"className":48},[49],"text-blue-600",[51,52,53],"a",{"href":53,"rel":54},"https://developer.hashicorp.com/vault/docs/deploy/kubernetes/csi",[55],"nofollow",{"title":57,"searchDepth":58,"depth":58,"links":59},"",2,[],"2026-03-08T00:00:00.000Z","md",{},true,"/2026/03/08-container-storage-interface",null,{"title":5,"description":57},"2026/03/08 Container-Storage-Interface","A_HqJ5SvEZZ1FqEkAOv3aksRt1iQS7nHkYP5ntieR7k",1785167451480]