Lab
Hardening Secret Consumption
Environment variables leak — through /proc, crash dumps, and child processes. Mount a Secret as a read-only file instead, and scope who can read it down to that single object with RBAC.
Your mission
Two habits separate a CKS-grade Secret from a leaky one:
- Mount it as a file, not an environment variable. Env vars show up in
/proc/<pid>/environ, get inherited by every child process, and land in crash dumps andkubectl describe. A file mount stays on a tmpfs and is far harder to exfiltrate. - Scope who can read it. A Role that grants
get secretsreads every secret in the namespace. Pin it to the one object withresourceNames.
The db-cred Secret already exists in the apps namespace. Consume it well, then
lock down access to it.
kubectl config set-context --current --namespace=appsSkills you'll put into practice
securitysecretsrbaccks