How Do You Secure Kubernetes Secrets

How Do You Secure Kubernetes Secrets

Use SSL/TLS—when running etcd in a cluster, you must use secure peer-to-peer communication. You can’t share the manifest file or check it into a repo—commonly, secrets are configured using JSON or YAML files, with the secret encoded in base64. If you share or check in these manifest files, the secret is compromised.

Where do you keep Kubernetes secrets?

When you create a Secret with kubectl create -f secret. yaml , Kubernetes stores it in etcd. The Secrets are stored in clear in etcd unless you define an encryption provider. When you define the provider, before the Secret is stored in etcd and after the values are submitted to the API, the Secrets are encrypted.

How can we protect our secrets?

  1. Identify What Needs Protection. …
  2. Label Documents That Contain Protected Information. …
  3. Monitor Where Information is Stored. …
  4. Secure Computers. …
  5. Maintain Secrecy With Outside Vendors. …
  6. Provide Adequate Security. …
  7. Limit Public Access to the Company.
James H. Sterling
Author

James H. Sterling

James Sterling reports on renewable energy developments, climate policy, ecological conservation, and green tech innovations around the globe.