Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium
A large enterprise uses multiple Kubernetes clusters across different cloud providers. They need a centralized and consistent way to manage and inject sensitive credentials, such as API keys and database passwords, into their applications without storing them directly in Kubernetes Secrets objects or configuration files. This solution must also integrate with existing enterprise secret stores. Which approach is best suited for this scenario?
- AHardcoding secrets into container images
- BMounting Kubernetes Secrets as environment variables
- CUsing a dedicated External Secrets Management system
- DStoring secrets in ConfigMaps
Show answer & explanationAnswer & explanation
Correct answer: C. Using a dedicated External Secrets Management system
An External Secrets Management system (like HashiCorp Vault or cloud provider secrets managers) provides a centralized, secure, and auditable solution for storing and retrieving secrets. It can integrate with existing enterprise stores and dynamically inject secrets into Kubernetes Pods without storing them natively in Kubernetes Secrets or application code.
Why the other options are wrong
- A. Hardcoding secrets is a severe security anti-pattern and highly insecure.
- B. Mounting Kubernetes Secrets still implies storing them in the cluster's `etcd`, which the scenario aims to avoid for sensitive enterprise secrets.
- D. ConfigMaps are for non-sensitive configuration data and offer no encryption or security features suitable for secrets.
External Secrets Management
The practice of storing and managing sensitive credentials outside of Kubernetes, using specialized secret management systems that then integrate with Kubernetes to inject secrets into applications at runtime.
- Centralizes secret storage.
- Integrates with enterprise secret stores.
- Avoids storing secrets in `etcd` or application code.
- Enhances security, auditability, and rotation.
Memory trick: External systems manage enterprise secrets, keeping Kubernetes clean.