Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityHard

A large organization uses multiple Kubernetes clusters across different cloud providers. They need a unified solution for managing and distributing secrets (e.g., database passwords, API keys) that can integrate with their existing enterprise Key Management System (KMS) and provide features like secret rotation and auditing. Which solution pattern is most appropriate for this scenario?

  1. AManually creating Kubernetes Secret objects in each cluster.
  2. BImplementing an External Secrets operator with a centralized KMS.
  3. CUsing ConfigMaps to store secrets in each cluster.
  4. DBaking secrets directly into container images for each application.
Show answer & explanation

Correct answer: B. Implementing an External Secrets operator with a centralized KMS.

An External Secrets operator allows Kubernetes to integrate with external secret management systems (like enterprise KMS solutions). It synchronizes secrets from the external system into Kubernetes Secrets, providing centralized management, rotation, and auditing capabilities across multiple clusters and cloud providers.

Why the other options are wrong

  • A. Manual creation is error-prone, lacks centralized management, rotation, and auditing across multiple clusters.
  • C. ConfigMaps are for non-sensitive data and offer no security features for secrets.
  • D. Baking secrets into images is a severe security anti-pattern, making secrets immutable and difficult to rotate.

External Secrets Management

The practice of using dedicated, external systems (like KMS or secret vaults) to store, manage, and distribute sensitive data, integrating them with Kubernetes via operators or controllers to provision secrets into the cluster.

  • Centralizes secret storage and lifecycle management.
  • Integrates with enterprise KMS solutions.
  • Provides features like secret rotation, auditing, and fine-grained access control.
  • Reduces the security burden on Kubernetes itself.

Memory trick: External secrets, central control.

More Cloud Native Security questions