ConfigMaps & Secrets (CKAD)
Keep settings out of the image: hand them to pods as variables or files, and know what base64 does not protect.
An interactive Kubernetes lesson: 21 steps, about 30 minutes, on a live simulation in your browser.
The shop's api is running and answering web. Its settings, a log level and a database host, were written into the container image at build time.
Now you need LOG_LEVEL=debug for an hour. With settings baked in, that is a rebuild, a new image tag and a rollout. Staging needs a different database host, so it needs a different image, and what you tested is no longer what you ship.
What you will learn
Settings do not belong in the image
- Settings baked into the image: The image is the program. The ConfigMap is the settings. One image runs everywhere; only the ConfigMap differs.
- Three ways to fill a ConfigMap: --from-literal: one key per flag. --from-file: one key per file. --from-env-file: one key per line.
ConfigMaps as environment variables
- One key into one variable: valueFrom copies one key into one variable, and lets you rename it on the way.
- envFrom: the whole map at once
- A reference to nothing: A ConfigMap reference is resolved by the kubelet when the container starts, not by the API server when the pod is created.
ConfigMaps as files
- Every key becomes a file: Mounted as a volume, a ConfigMap is a directory: each key is a file name, each value is that file's contents.
- Break it: the volume has no source: Missing reference as env: CreateContainerConfigError. Missing reference as volume: ContainerCreating with FailedMount. describe names the object either way.
What happens on update
- Change the ConfigMap, check the pod: Environment variables are copied once, when the container starts. Editing the ConfigMap changes nothing inside a running process.
- Mounted files do follow: Files from a ConfigMap volume follow the ConfigMap after a short delay. The app still has to re-read them.
- The subPath exception: A subPath mount is a one-time copy of one key. It never sees an update.
- Nothing restarts your pods for you: A ConfigMap change does not roll your pods. kubectl rollout restart does, and the new containers read the new values.
Secrets
- A Secret: same shape, stricter handling: A Secret is a ConfigMap the cluster handles more carefully: separate permissions, values hidden from describe, kept off the node's disk.
- What base64 protects: base64 is packaging, not protection. A Secret is protected by who may read it (RBAC) and by encryption at rest in etcd.
- A secret as a variable or as a file: A secret in a variable is visible to everything in the container and frozen until restart. A secret in a file can be permission-restricted and rotated in place.
- Three kinds of Secret
- Break it: edit an immutable object: immutable: true freezes the data for the object's whole life. To change it you replace the object and restart its pods.
Exam speed
- Drill: a ConfigMap from literals
- Drill: a generic Secret
- Drill: read a Secret's value
Recap & playground
- Cheat sheet
- Playground