Kubernetes and Cloud Native Associate (KCNA)Kubernetes FundamentalsMedium
A security auditor is reviewing a Kubernetes cluster and wants to understand how sensitive information, such as database credentials or API keys, is stored and managed securely. Which Kubernetes object is designed specifically for storing and managing such sensitive data?
- AServiceAccount
- BConfigMap
- CSecret
- DPersistentVolume
Show answer & explanationAnswer & explanation
Correct answer: C. Secret
A Kubernetes Secret is an object designed to store sensitive data like passwords, OAuth tokens, and SSH keys. It provides a more secure way to manage sensitive information than putting it directly into Pod or Deployment definitions.
Why the other options are wrong
- A. ServiceAccounts provide an identity for processes running in Pods, used for API authentication, but don't store arbitrary sensitive data.
- B. ConfigMaps are used to store non-confidential configuration data, not sensitive information.
- D. PersistentVolumes are for persistent storage of application data, not for storing credentials.
Kubernetes Secret
A Kubernetes object used to store and manage sensitive information.
- Stores data in base64 encoded format (not encrypted by default).
- Can be mounted as files into Pods or exposed as environment variables.
- Access to Secrets is controlled via RBAC.
Memory trick: Secrets keep your 'sensitive stuff' 'secret'.