[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-06-12 (世界標準時間)。"],[[["Avoid managing application secrets within Cloud Deploy pipelines due to security risks; instead, manage and rotate them externally."],["This document recommends two external secrets management approaches for GKE or GKE Enterprise: Google Secret Manager and Hashicorp Vault."],["Google Secret Manager is a fully managed Google Cloud service for securely storing sensitive data like API keys and passwords, accessible via client libraries, Workload Identity, or the Secrets Store CSI driver."],["Hashicorp Vault is an open-source tool for secrets management that integrates with Kubernetes via API access, Vault Agent containers, and the Vault CSI Provider, and has full support and integrations with google cloud."],["Kubernetes Secrets, while designed to store sensitive data, are not considered secure by default and are therefore not recommended in this document without encryption."]]],[]]