A DevOps team is managing a complex application deployed to an Azure Kubernetes Service (AKS) cluster. They need to ensure that application configurations, which include sensitive API keys and connection strings, are securely injected into pods at runtime without hardcoding them in container images or YAML manifests. These configurations also need to be easily updated and managed centrally. What is the most secure and efficient method to achieve this in AKS?
- AStore configurations in ConfigMaps and restrict access via Kubernetes RBAC.
- BStore secrets as Kubernetes Secrets and mount them as environment variables or files.
- CUse Azure Key Vault with the Azure Key Vault Provider for Secrets Store CSI Driver.
- DEmbed sensitive information directly into the Docker image build process.
Show answer & explanationAnswer & explanation
Correct answer: C. Use Azure Key Vault with the Azure Key Vault Provider for Secrets Store CSI Driver.
Using Azure Key Vault with the Azure Key Vault Provider for Secrets Store CSI Driver allows AKS pods to securely access secrets, keys, and certificates stored in Azure Key Vault. This approach centralizes secret management, enhances security by not storing secrets in Kubernetes native Secrets (which are base64 encoded, not truly encrypted at rest by default in all scenarios), and integrates directly with Azure's robust key management capabilities.
Why the other options are wrong
- A. ConfigMaps are designed for non-sensitive configuration data. Storing sensitive API keys in ConfigMaps is insecure, as they are stored as plain text.
- B. Kubernetes Secrets are base64 encoded by default, not encrypted at rest without additional configuration (e.g., ETCD encryption), and require careful RBAC management. While better than hardcoding, it's not the most secure or efficient for Azure-native environments.
- D. Embedding secrets in Docker images is highly insecure and violates best practices, as the secrets become part of the image layer history.
Azure Key Vault Provider for Secrets Store CSI Driver
Enables Kubernetes pods to securely mount secrets, keys, and certificates stored in Azure Key Vault as a volume. This provides secure, centralized secret management for AKS.
- Integrates AKS with Azure Key Vault.
- Allows pods to access Key Vault secrets as files or environment variables.
- Secrets are never stored in Kubernetes native Secrets or manifests.
- Enhances security and compliance for sensitive data.
Memory trick: Key Vault: Secrets in the Cloud, Secure in the Pod.