Rotating Credentials ​
Update the credentials used by Registry Cache to authenticate against a private upstream registry.
Context ​
Credential Secrets are immutable and you cannot update them in place.
Procedure ​
Create a new Secret with the updated credentials. Use a different name (for example,
rc-secret-v2).bashkubectl create -f - <<EOF apiVersion: v1 kind: Secret metadata: name: rc-secret-v2 namespace: <namespace> type: Opaque immutable: true data: username: $(echo -n $USERNAME | base64 | tr -d '\n') password: $(echo -n $PASSWORD | base64 | tr -d '\n') EOFTo reference the new Secret, update spec.secretReferenceName in the existing
RegistryCacheConfigresource.bashkubectl patch registrycacheconfig <name> -n <namespace> \ --type=merge -p '{"spec":{"secretReferenceName":"rc-secret-v2"}}'When the
RegistryCacheConfigis inReadystate, verify that image pulls succeed with the new Secret, and delete the old Secret.bashkubectl delete secret rc-secret -n <namespace>