Kubernetes security fundamentals: Secrets
ID: 5e8cfaec-e353-5971-9850-dfbb5491b2a6
STIX ID: report--5e8cfaec-e353-5971-9850-dfbb5491b2a6
Feed Name: Datadog Security Labs
This post reviews Kubernetes secrets management: threat models for secrets (at rest, in transit, and API attacks), how Kubernetes Secret objects are stored and consumed (env vars vs mounted files), differences between Secrets and ConfigMaps, considerations for managed vs unmanaged clusters (including encryption at rest), dangers on worker nodes and with hostPath mounts, RBAC/list-and-watch implications, and trade-offs of using external secret stores versus native Secrets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
