Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium

A security engineer is implementing a secrets management solution for a Kubernetes cluster. The goal is to ensure that application secrets are encrypted at rest, rotated regularly, and only accessible by authorized workloads. Which of the following best describes the principle of 'secrets encryption at rest' in this context?

  1. AEncrypting secret values only when they are mounted into a Pod's filesystem.
  2. BEncrypting secret values only when they are transmitted over the network.
  3. CEncrypting secret values within the Kubernetes API server's etcd storage.
  4. DEncrypting secret values within the application code itself before deployment.
Show answer & explanation

Correct answer: C. Encrypting secret values within the Kubernetes API server's etcd storage.

Secrets encryption at rest in Kubernetes primarily refers to encrypting the secret data when it is stored in the etcd key-value store, which is the backing store for all Kubernetes cluster data. This protects secrets even if an attacker gains access to etcd.

Why the other options are wrong

  • A. Secrets are typically mounted as files or environment variables; encrypting them at this stage is less about 'at rest' storage and more about in-use access.
  • B. This describes encryption in transit, not at rest.
  • D. Encrypting secrets in application code is generally not a recommended practice for secrets management, as it shifts the burden of key management to the application.

Secrets Encryption At Rest

The practice of encrypting sensitive data, such as Kubernetes Secrets, when they are stored persistently, typically within the cluster's etcd database, to prevent unauthorized access even if the storage is compromised.

  • Protects data when not in active use or transit.
  • In Kubernetes, applies primarily to etcd storage.
  • Often implemented using KMS or external vault solutions.

Memory trick: Resting secrets sleep soundly, in transit they travel safely, in use they are awake and active.

More Cloud Native Security questions