learninfra · Linux · Networking · Kubernetes · System Design · AI Infrastructure · Exam blueprints · Drills

ConfigMaps & Secrets (CKAD)

Keep settings out of the image: hand them to pods as variables or files, and know what base64 does not protect.

An interactive Kubernetes lesson: 21 steps, about 30 minutes, on a live simulation in your browser.

The shop's api is running and answering web. Its settings, a log level and a database host, were written into the container image at build time.

Now you need LOG_LEVEL=debug for an hour. With settings baked in, that is a rebuild, a new image tag and a rollout. Staging needs a different database host, so it needs a different image, and what you tested is no longer what you ship.

What you will learn

  1. Settings do not belong in the image

    • Settings baked into the image: The image is the program. The ConfigMap is the settings. One image runs everywhere; only the ConfigMap differs.
    • Three ways to fill a ConfigMap: --from-literal: one key per flag. --from-file: one key per file. --from-env-file: one key per line.
  2. ConfigMaps as environment variables

    • One key into one variable: valueFrom copies one key into one variable, and lets you rename it on the way.
    • envFrom: the whole map at once
    • A reference to nothing: A ConfigMap reference is resolved by the kubelet when the container starts, not by the API server when the pod is created.
  3. ConfigMaps as files

    • Every key becomes a file: Mounted as a volume, a ConfigMap is a directory: each key is a file name, each value is that file's contents.
    • Break it: the volume has no source: Missing reference as env: CreateContainerConfigError. Missing reference as volume: ContainerCreating with FailedMount. describe names the object either way.
  4. What happens on update

    • Change the ConfigMap, check the pod: Environment variables are copied once, when the container starts. Editing the ConfigMap changes nothing inside a running process.
    • Mounted files do follow: Files from a ConfigMap volume follow the ConfigMap after a short delay. The app still has to re-read them.
    • The subPath exception: A subPath mount is a one-time copy of one key. It never sees an update.
    • Nothing restarts your pods for you: A ConfigMap change does not roll your pods. kubectl rollout restart does, and the new containers read the new values.
  5. Secrets

    • A Secret: same shape, stricter handling: A Secret is a ConfigMap the cluster handles more carefully: separate permissions, values hidden from describe, kept off the node's disk.
    • What base64 protects: base64 is packaging, not protection. A Secret is protected by who may read it (RBAC) and by encryption at rest in etcd.
    • A secret as a variable or as a file: A secret in a variable is visible to everything in the container and frozen until restart. A secret in a file can be permission-restricted and rotated in place.
    • Three kinds of Secret
    • Break it: edit an immutable object: immutable: true freezes the data for the object's whole life. To change it you replace the object and restart its pods.
  6. Exam speed

    • Drill: a ConfigMap from literals
    • Drill: a generic Secret
    • Drill: read a Secret's value
  7. Recap & playground

    • Cheat sheet
    • Playground