Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium
A security auditor is reviewing a Kubernetes cluster's secrets management strategy. They find that sensitive API keys are stored directly as plain text within Kubernetes Secret objects, and these objects are frequently accessed by multiple applications. Which best practice is being violated, and what is its primary risk?
- ASecrets encryption at rest; risk of data exposure if the underlying storage is compromised.
- BImage signing and verification; risk of deploying untrusted container images.
- CPrinciple of Least Privilege; risk of unauthorized network access.
- DRuntime security monitoring; risk of undetected malicious container activity.
Show answer & explanationAnswer & explanation
Correct answer: A. Secrets encryption at rest; risk of data exposure if the underlying storage is compromised.
Storing Kubernetes Secrets as plain text violates the principle of 'secrets encryption at rest'. If the underlying etcd storage or a backup is compromised, the sensitive data would be immediately exposed without any encryption layer.
Why the other options are wrong
- B. Image signing relates to container image authenticity, not secrets storage.
- C. Least Privilege is violated by frequent access by multiple apps, but plain text storage is a distinct issue with a different direct risk.
- D. Runtime security monitoring is about active containers, not the storage of secrets.
Secrets Encryption At Rest
The practice of encrypting sensitive data, such as Kubernetes Secrets, when it is stored on persistent storage (e.g., etcd), protecting it from unauthorized access even if the storage medium is compromised.
- Protects data on disk, not just in transit or memory.
- Essential for sensitive data like API keys, passwords, certificates.
- Kubernetes can use KMS providers for etcd encryption.
Memory trick: Manage secrets carefully: encrypt, rotate, restrict.