Injecting Secrets
Store sensitive configuration in a Secret and inject it into a workload as environment variables — never in plaintext.
Your mission
Configuration a container needs at runtime falls into two kinds. Non-sensitive values — a log level, a feature flag, a public URL — belong in a ConfigMap. Anything dangerous to leak — a password, an API token, a connection string — belongs in a Secret.
A Secret is not encrypted by default, but it is handled differently: its
values are base64-encoded at rest, kept out of most logs, and delivered only to
the Pods that reference it. The habit that matters is never pasting a credential
straight into a Deployment's env as plaintext — you reference it from a Secret
instead, so it lives in exactly one place and can be rotated without editing the
workload.
In this lab you create a Secret and wire it into a Deployment as environment variables, the right way.
Useful aliases
In your terminal, k is aliased to kubectl and completion is configured. The
jumpbox also has k9s, jq and yq installed.