Topic 2: Secrets
Official baseline: (The Kubernetes Authors, 2026b, 2026a). My working version: A Kubernetes Secret is an API object for sensitive material. It is not automatically a complete secrets management program.
Mental Model
A Kubernetes Secret is an API object for sensitive material. It is not automatically a complete secrets management program.
Notes
- Base64 is encoding, not encryption.
- RBAC, encryption at rest, rotation, and external secret sources matter.
- Secrets mounted into Pods become part of the runtime threat model.
Homelab Angle
Start simple, but write down how secrets are created, rotated, and removed.
Verify It
- Read the object status before changing the manifest.
- Check events for the controller or node that is actually complaining.
- Confirm the official source linked below still matches the cluster version you run.
Common Failure Modes
- Treating the YAML object as the system, instead of one input to a reconciliation loop.
- Debugging from outside the cluster when the failure only exists inside cluster networking or node state.
- Forgetting that Kubernetes version, addon version, and runtime behavior are linked.
Sources
- Secrets - source path:
content/en/docs/concepts/configuration/secret.md, commit 8cc9e19b8eec8d5cf49eacd66f86a81648edb1a0. - Good Practices for Kubernetes Secrets - source path:
content/en/docs/concepts/security/secrets-good-practices.md, commit 8cc9e19b8eec8d5cf49eacd66f86a81648edb1a0. - Kubernetes documentation is licensed under CC BY 4.0; these notes are original commentary and link back to the official source.
The Kubernetes Authors. (2026a). Good Practices for Kubernetes Secrets. https://kubernetes.io/docs/concepts/security/secrets-good-practices/
The Kubernetes Authors. (2026b). Secrets. https://kubernetes.io/docs/concepts/configuration/secret/