apiVersion: apps/v1 kind: Deployment metadata: name: nginx-one labels: app: nginx-one spec: replicas: 1 selector: matchLabels: app: nginx-one template: metadata: labels: app: nginx-one spec: containers: - image: nginx name: nginx volumeMounts: - name: secrets-store-inline mountPath: "/mnt/secrets-store" readOnly: true volumes: - name: secrets-store-inline csi: driver: secrets-store.csi.k8s.io readOnly: true volumeAttributes: secretProviderClass: "azure-tls" nodePublishSecretRef: name: secrets-store-creds --- apiVersion: v1 kind: Service metadata: name: nginx-one spec: type: ClusterIP ports: - port: 80 selector: app: nginx-one