logo

Why You Shouldn’t Use Config Maps to Store Sensitive Data in K8s

ID: a76a4532-aa59-5959-87f6-ac5659d9ed9a

STIX ID: report--a76a4532-aa59-5959-87f6-ac5659d9ed9a

Feed Name: Aqua Security Blog

Date Published: 2021-04-28

Date Updated: 2026-04-26

...
...

This report advises that Kubernetes Secret objects, not ConfigMaps or other object types, should be used for sensitive data because they convey intent and enable stricter RBAC controls, reduce the risk of accidental logging or exposure, and allow for optional encryption at rest. It recommends using external secret management systems when available, ensuring Kubernetes secrets encryption is enabled, and reviewing cluster components for proper handling of sensitive information.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.