Lesson 2.317mAdvanced6.4k students

ConfigMaps and Secrets

Configuration belongs outside the image. Secrets look like ConfigMaps but need encryption at rest and tighter access control.

This lesson sits in Kubernetes Core Objects, part of DevOps with Docker and Kubernetes. It assumes what came before it and leads directly into the next lesson in the module.

In this lesson you will

  • Inject configuration as environment variables or files
  • Keep secrets out of images and manifests
  • Roll configuration changes without rebuilding

Pro tip

A Kubernetes Secret is only base64 encoded by default. Encryption at rest and RBAC are what make it a secret.

Resources