Configuration and secrets
ConfigMaps, Secrets, and twelve-factor config — without baking credentials into images or cluster YAML lore.
Config must be injectable, reviewable, and rotatable. Kubernetes gives primitives; you still need a story.
ConfigMaps for non-secret config
Mount or inject environment for environment-specific settings. Prefer files over giant env blobs when configs grow. Treat ConfigMap changes as releases — pods do not always pick up live edits the way people assume.
Secrets are not strong vaults by default
etcd-stored Secrets are base64-encoded objects with access control — not encryption magic unless you enable encryption at rest and tight RBAC. Prefer:
- external secret managers (cloud KMS/Secrets Manager, Vault) with short-lived injection where practical
- least-privilege ServiceAccounts reading only what they need
- no secrets in container images or public charts
Rotate with a plan: new value, roll pods, revoke old.
Do not commit plaintext secrets
GitOps works when secrets are sealed/encrypted or referenced externally. Plain Secret manifests in git are an incident template.
Twelve-factor still applies
Same artifact across environments; config via env/mount. Divergence through rebuilt images per environment is how “works in staging” becomes a lifestyle.