Ch. 14 · Kubernetes

Kubernetes ConfigMaps Versus Secrets

Kubernetes ConfigMaps Versus Secrets. Learn the reasoning, a practical example, common mistakes and an interview exercise.

~2 min readbeginnerupdated Oct 3, 2026

ConfigMaps hold ordinary configuration; Secrets represent sensitive values with distinct handling. A Secret’s encoding alone is not encryption or a complete access boundary.

Before you start

You should understand Pods, Deployments and Services. Read desired configuration separately from observed cluster state. Use a development cluster when trying changes, and inspect events and status rather than assuming that an accepted manifest means the workload is ready to serve traffic.

The practical goal is to reason through this situation: Store a database password as a Secret and limit who can read it. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.

Step-by-step walkthrough

Step 1: Classify configuration

Ordinary settings and sensitive credentials need different handling.

Step 2: Control readers and delivery

Limit API access and apply appropriate storage and runtime protections.

Step 3: Avoid secondary exposure

Logs, image layers and diagnostic output can leak injected secrets.

Worked scenario

Store a database password as a Secret and limit who can read it.

A password stored in a Secret is base64-encoded for representation, which is not encryption by itself. A workload with read access can obtain it, and logging all environment variables exposes it again. Protect the complete delivery path rather than assuming the resource kind solves every confidentiality concern.

Common mistake

Printing injected configuration can expose the secret regardless of storage type.

Verify the behavior

Test permissions and inspect safe diagnostics without printing actual secret values.

Interview exercise

Protect sensitive configuration.

Answer and reasoning

Use least-privilege access, appropriate encryption and delivery controls, and avoid secret values in logs or images.

Continue learning

Compare the scenario with the Kubernetes interview questions and test your understanding with the Kubernetes MCQs. For terminology and implementation details, consult the reference material.

More in Kubernetes

read ✓Kubernetes · mid

Kubernetes ConfigMap Update Behavior

Understand why ConfigMap changes reach volumes but not environment variables, and how to roll a Deployment deliberately.

~2 min readread →
read ✓Kubernetes · mid

Kubernetes emptyDir Volumes

Share scratch space between containers in a pod with emptyDir, choose the backing medium, and bound its size.

~2 min readread →
read ✓Kubernetes · hard

Kubernetes Gateway API for Ingress

Route traffic with GatewayClass, Gateway and HTTPRoute, and understand how the Gateway API improves on Ingress.

~2 min readread →
esc