Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityEasy
A development team is deploying a new microservice to a Kubernetes cluster. They need to ensure that sensitive database credentials are securely managed and only accessible by the specific microservice that requires them, without being hardcoded into the application's container image or configuration files. Which Kubernetes native object is best suited for this requirement?
- AConfigMap
- BDeployment
- CPersistentVolume
- DSecret
Show answer & explanationAnswer & explanation
Correct answer: D. Secret
Kubernetes Secrets are specifically designed to store sensitive information like passwords, OAuth tokens, and SSH keys. They provide a more secure way to manage and distribute credentials compared to ConfigMaps, which are for non-sensitive configuration data.
Why the other options are wrong
- A. ConfigMaps are used for non-sensitive configuration data and are not designed for securing credentials.
- B. Deployments manage the lifecycle of application pods and do not directly handle sensitive data storage.
- C. PersistentVolumes are used for durable storage of data and have no direct role in managing application credentials.
Kubernetes Secret
A Kubernetes object used to store and manage sensitive information, such as passwords, OAuth tokens, and SSH keys, securely within the cluster.
- Stores sensitive data in base64 encoded format (not encrypted by default at rest).
- Can be mounted as files in pods or exposed as environment variables.
- Access control is managed via RBAC.
Memory trick: Secrets secure your sensitive stuff.