Learning · Kubernetes

Configuration and secrets

ConfigMaps, Secrets, and twelve-factor config — without baking credentials into images or cluster YAML lore.

Config must be injectable, reviewable, and rotatable. Kubernetes gives primitives; you still need a story.

ConfigMaps for non-secret config

Mount or inject environment for environment-specific settings. Prefer files over giant env blobs when configs grow. Treat ConfigMap changes as releases — pods do not always pick up live edits the way people assume.

Secrets are not strong vaults by default

etcd-stored Secrets are base64-encoded objects with access control — not encryption magic unless you enable encryption at rest and tight RBAC. Prefer:

  • external secret managers (cloud KMS/Secrets Manager, Vault) with short-lived injection where practical
  • least-privilege ServiceAccounts reading only what they need
  • no secrets in container images or public charts

Rotate with a plan: new value, roll pods, revoke old.

Do not commit plaintext secrets

GitOps works when secrets are sealed/encrypted or referenced externally. Plain Secret manifests in git are an incident template.

Twelve-factor still applies

Same artifact across environments; config via env/mount. Divergence through rebuilt images per environment is how “works in staging” becomes a lifestyle.

← Kubernetes