DevNet Associate (DEVASC) v1.0Application Deployment and SecurityMedium
A development team is deploying a new microservice that needs to communicate securely with an existing database. The database credentials, including the username and password, must be protected both during deployment and at runtime. Which of the following is the most secure approach for storing and injecting these credentials into the microservice in a Kubernetes environment?
- AStoring credentials as plain text in a ConfigMap and mounting it as a volume.
- BEncrypting credentials with a custom algorithm and storing them in an external Git repository.
- CHardcoding the credentials directly into the application's source code.
- DUsing Kubernetes Secrets and mounting them as files or environment variables into the pod.
Show answer & explanationAnswer & explanation
Correct answer: D. Using Kubernetes Secrets and mounting them as files or environment variables into the pod.
Kubernetes Secrets are specifically designed for storing sensitive information like passwords, OAuth tokens, and SSH keys. They provide a more secure method than ConfigMaps or hardcoding by encrypting data at rest (when properly configured) and restricting access.
Why the other options are wrong
- A. ConfigMaps are for non-confidential data; storing plain text credentials in them is insecure.
- B. While encryption is good, storing encrypted credentials in a Git repository still poses risks if the key is compromised, and it's not the native Kubernetes solution for secret management.
- C. Hardcoding credentials is a severe security risk as it exposes sensitive data in the codebase.
Kubernetes Secrets
Kubernetes Secrets are objects that store sensitive data, such as passwords, OAuth tokens, and SSH keys, securely within a Kubernetes cluster.
- Designed for confidential data.
- Can be mounted as files or environment variables.
- Base64 encoded by default, but can be encrypted at rest with proper configuration.
Memory trick: Secrets secure sensitive stuff, not just plain text maps.