ConfigMaps hold ordinary configuration; Secrets represent sensitive values with distinct handling. A Secret’s encoding alone is not encryption or a complete access boundary.
Before you start
You should understand Pods, Deployments and Services. Read desired configuration separately from observed cluster state. Use a development cluster when trying changes, and inspect events and status rather than assuming that an accepted manifest means the workload is ready to serve traffic.
The practical goal is to reason through this situation: Store a database password as a Secret and limit who can read it. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.
Step-by-step walkthrough
Step 1: Classify configuration
Ordinary settings and sensitive credentials need different handling.
Step 2: Control readers and delivery
Limit API access and apply appropriate storage and runtime protections.
Step 3: Avoid secondary exposure
Logs, image layers and diagnostic output can leak injected secrets.
Worked scenario
Store a database password as a Secret and limit who can read it.
A password stored in a Secret is base64-encoded for representation, which is not encryption by itself. A workload with read access can obtain it, and logging all environment variables exposes it again. Protect the complete delivery path rather than assuming the resource kind solves every confidentiality concern.
Common mistake
Printing injected configuration can expose the secret regardless of storage type.
Verify the behavior
Test permissions and inspect safe diagnostics without printing actual secret values.
Interview exercise
Protect sensitive configuration.
Answer and reasoning
Use least-privilege access, appropriate encryption and delivery controls, and avoid secret values in logs or images.
Continue learning
Compare the scenario with the Kubernetes interview questions and test your understanding with the Kubernetes MCQs. For terminology and implementation details, consult the reference material.