DevNet Associate (DEVASC) v1.0Application Deployment and SecurityEasy

A development team is deploying a new web application to a Kubernetes cluster. They need to ensure that all sensitive configuration data, such as database passwords and API keys, are securely managed and injected into the application containers without exposing them in the Git repository or Docker images. Which Kubernetes resource should they use for this purpose?

  1. AService
  2. BSecret
  3. CDeployment
  4. DConfigMap
Show answer & explanation

Correct answer: B. Secret

Kubernetes Secrets are specifically designed to store and manage sensitive information like passwords, OAuth tokens, and SSH keys. They provide a secure way to inject this data into pods.

Why the other options are wrong

  • A. Services define a logical set of Pods and a policy for accessing them, unrelated to secrets management.
  • C. Deployments manage the desired state of ReplicaSets and Pods, not sensitive data storage.
  • D. ConfigMaps are used for non-sensitive configuration data, not secrets.

Kubernetes Secret

A Kubernetes object used to store and manage sensitive data, such as passwords, OAuth tokens, and SSH keys, securely.

  • Encrypts data at rest (when properly configured).
  • Can be mounted as data volumes or exposed as environment variables.
  • Prevents sensitive data from being exposed in code or container images.

Memory trick: ConfigMaps for common, Secrets for sensitive stuff.

More Application Deployment and Security questions