Kubernetes and Cloud Native Associate (KCNA)Kubernetes FundamentalsMedium
A security auditor is reviewing a Kubernetes cluster and wants to ensure that sensitive information, such as database credentials, is stored securely and injected into Pods without being exposed in plain text within YAML manifests or environment variables. Which Kubernetes resource is designed for this purpose?
- AConfigMap
- BSecret
- CPersistentVolumeClaim
- DServiceAccount
Show answer & explanationAnswer & explanation
Correct answer: B. Secret
Kubernetes Secrets are designed to store sensitive information like passwords, OAuth tokens, and SSH keys. They provide a more secure way to manage and deliver this data to Pods compared to ConfigMaps, though they are still base64 encoded, not encrypted at rest by default.
Why the other options are wrong
- A. A ConfigMap stores non-confidential configuration data, not sensitive secrets.
- C. A PersistentVolumeClaim is a request for storage, unrelated to storing sensitive credentials.
- D. A ServiceAccount provides an identity for processes running in Pods to interact with the Kubernetes API, not for storing general sensitive data.
Kubernetes Secret
A Kubernetes object used to store and manage sensitive information, such as passwords, OAuth tokens, and SSH keys.
- Data is base64 encoded, not encrypted by default at rest.
- Can be mounted as files in Pods or injected as environment variables.
- Access control (RBAC) is crucial for securing Secrets.
Memory trick: Secrets are like a locked safe for your sensitive data.