logo

Kubernetes security fundamentals: Secrets

ID: 5e8cfaec-e353-5971-9850-dfbb5491b2a6

STIX ID: report--5e8cfaec-e353-5971-9850-dfbb5491b2a6

Feed Name: Datadog Security Labs

Date Published: 2026-05-08

Date Updated: 2026-05-08

...
...

This post reviews Kubernetes secrets management: threat models for secrets (at rest, in transit, and API attacks), how Kubernetes Secret objects are stored and consumed (env vars vs mounted files), differences between Secrets and ConfigMaps, considerations for managed vs unmanaged clusters (including encryption at rest), dangers on worker nodes and with hostPath mounts, RBAC/list-and-watch implications, and trade-offs of using external secret stores versus native Secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.