Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityHard

A critical application in a Kubernetes cluster needs to access an external Key Management System (KMS) to retrieve database credentials. The application's Pod should not store the credentials directly, nor should it have long-lived static credentials for the KMS. Which secure method allows the Pod to authenticate to the KMS and fetch secrets dynamically?

  1. AHardcoding the KMS API key directly into the application's container image.
  2. BImplementing Workload Identity (e.g., service account token exchange for cloud IAM role).
  3. CStoring KMS credentials as a Kubernetes Secret and mounting it into the Pod.
  4. DUsing a ConfigMap to store the KMS endpoint and API key.
Show answer & explanation

Correct answer: B. Implementing Workload Identity (e.g., service account token exchange for cloud IAM role).

Workload Identity allows Kubernetes Service Accounts to impersonate cloud IAM identities. This enables Pods to securely authenticate to external services like KMS using short-lived, automatically rotated credentials derived from their service account token, eliminating the need to store long-lived static credentials.

Why the other options are wrong

  • A. Hardcoding credentials is a severe security anti-pattern and highly insecure.
  • C. Storing KMS credentials in a Kubernetes Secret still means storing credentials, which is what Workload Identity aims to avoid for external services.
  • D. ConfigMaps are for non-sensitive configuration, not API keys, and don't provide authentication.

Workload Identity

A mechanism that allows Kubernetes Service Accounts to authenticate as specific identities in external cloud providers (e.g., AWS IAM, Google Cloud IAM), enabling Pods to access cloud resources securely without managing separate credentials.

  • Binds Kubernetes Service Accounts to external cloud identities.
  • Enables Pods to get short-lived, dynamically provisioned credentials.
  • Eliminates the need to store static cloud credentials in Kubernetes Secrets.
  • Reduces the risk of credential theft and reuse.

Memory trick: Workload Identity marries Pods to cloud roles.

More Cloud Native Security questions