Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityEasy
A security auditor is reviewing a Kubernetes cluster's secrets management strategy. They find that while secrets are stored natively in Kubernetes, there is no additional encryption layer for these secrets when they are at rest within the etcd datastore. Which security control is missing to enhance the protection of these secrets?
- AConfiguring encryption at rest for etcd data.
- BEnabling Pod Security Admission (PSA) in 'enforce' mode.
- CImplementing a service mesh with mutual TLS.
- DRestricting network policies for the kube-system namespace.
Show answer & explanationAnswer & explanation
Correct answer: A. Configuring encryption at rest for etcd data.
By default, Kubernetes secrets are Base64 encoded but not encrypted at rest in etcd. To add an additional layer of protection, especially for sensitive data, etcd encryption at rest should be configured. This ensures that even if an attacker gains access to the underlying etcd data, the secrets remain unreadable.
Why the other options are wrong
- B. PSA enforces Pod-level security standards but does not directly encrypt secrets stored in etcd.
- C. A service mesh with mutual TLS encrypts traffic in transit between services but does not encrypt data at rest in etcd.
- D. Restricting network policies enhances network security but does not provide encryption for data stored in etcd.
Secrets Encryption at Rest (etcd)
The practice of encrypting Kubernetes Secrets data when it is stored within the etcd key-value store, providing an additional layer of security beyond Base64 encoding.
- Protects secrets even if etcd data is exfiltrated.
- Configured via the Kubernetes API server's encryption configuration.
- Uses an EncryptionConfiguration API object to define providers.
Memory trick: Encrypt etcd data to keep secrets safe, even at rest.