How to use the Secrets Store CSI Driver provider Amazon EKS add-on with Secrets Manager
Security Blog
This article explains how to use the new AWS Secrets Store CSI Driver provider EKS add-on to securely retrieve secrets from AWS Secrets Manager and mount them as files in Kubernetes pods.
- New EKS add-on simplifies installation and management of Secrets Store CSI Driver provider
- Mounts secrets from Secrets Manager and parameters from Systems Manager Parameter Store as pod files
- Works on EC2 instances and hybrid nodes with latest security updates included
- Supports two authentication methods: IRSA and EKS Pod Identity
- Requires IAM permissions for Secrets Manager access; AWS managed policy recommended
- Step-by-step walkthrough covers cluster creation, secret setup, add-on installation, and deployment
- Reduces installation complexity compared to legacy Helm or kubectl methods
The add-on provides a secure, managed way to handle secrets in Kubernetes workloads without hardcoding credentials in application code.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.