Kubernetes and Cloud Native Associate (KCNA)Kubernetes FundamentalsMedium

A cluster administrator is setting up a new Kubernetes cluster and wants to ensure that specific sensitive configuration data, such as database credentials, are securely stored and accessible only by authorized Pods. Which Kubernetes object is designed for this purpose?

  1. AServiceAccount
  2. BSecret
  3. CPersistentVolume
  4. DConfigMap
Show answer & explanation

Correct answer: B. Secret

Secrets are specifically designed to store sensitive information like passwords, OAuth tokens, and SSH keys in Kubernetes. ConfigMaps are for non-sensitive configuration data.

Why the other options are wrong

  • A. ServiceAccounts provide an identity for Pods to interact with the Kubernetes API, not for storing application credentials.
  • C. PersistentVolumes are used for persistent storage, not for storing configuration or credentials.
  • D. ConfigMaps are used for non-confidential configuration data, not sensitive information.

Kubernetes Secret

A Kubernetes Secret is an object used to store sensitive information, such as passwords, OAuth tokens, and SSH keys. It allows you to keep sensitive data out of your application code and Pod definitions.

  • Stores data in base64 encoded format (not encrypted at rest by default without additional configuration).
  • Can be mounted as files in a Pod or exposed as environment variables.
  • Access can be controlled via RBAC.

Memory trick: Secrets Safeguard Sensitive Stuff

More Kubernetes Fundamentals questions