DevNet Associate (DEVASC) v1.0Application Deployment and SecurityMedium
An organization is migrating its legacy monolithic application to a microservices architecture using Kubernetes. The application needs to securely store sensitive database credentials and API keys. Which Kubernetes object is specifically designed for managing and providing these secrets to pods?
- AService
- BSecret
- CConfigMap
- DPersistentVolume
Show answer & explanationAnswer & explanation
Correct answer: B. Secret
Kubernetes Secrets are specifically designed to store sensitive information like passwords, OAuth tokens, and SSH keys. They provide a more secure way to manage this data than embedding it directly in pod definitions or ConfigMaps.
Why the other options are wrong
- A. Services define a logical set of Pods and a policy by which to access them.
- C. ConfigMaps are for non-confidential configuration data, not secrets.
- D. PersistentVolumes are for storing persistent data, not for managing application secrets.
Kubernetes Secret
A Kubernetes object used to store and manage sensitive information, such as passwords, OAuth tokens, and SSH keys. Secrets can be mounted as data volumes or exposed as environment variables to pods.
- Stores sensitive data.
- Can be mounted as volumes or env vars.
- Base64 encoded by default (not encrypted at rest without additional setup).
Memory trick: ConfigMaps for general settings, Secrets for sensitive stuff.