Back to Practice
Lab

Hardening Secret Consumption

Environment variables leak — through /proc, crash dumps, and child processes. Mount a Secret as a read-only file instead, and scope who can read it down to that single object with RBAC.

Your mission

Two habits separate a CKS-grade Secret from a leaky one:

  1. Mount it as a file, not an environment variable. Env vars show up in /proc/<pid>/environ, get inherited by every child process, and land in crash dumps and kubectl describe. A file mount stays on a tmpfs and is far harder to exfiltrate.
  2. Scope who can read it. A Role that grants get secrets reads every secret in the namespace. Pin it to the one object with resourceNames.

The db-cred Secret already exists in the apps namespace. Consume it well, then lock down access to it.

kubectl config set-context --current --namespace=apps

Skills you'll put into practice

securitysecretsrbaccks

Make it your own.

Use this topic as a starting point for a fresh custom scenario.

Create a variation