Core objects
ConfigMap and Secret
15 / 82

ConfigMaps hold settings, Secrets hold credentials, and neither belongs in the image.

The same image runs in every environment because configuration is injected at runtime as environment variables or mounted files.

cm icon

ConfigMap

plain text
kind: ConfigMap
metadata: {name: checkout-config}
data:
  LOG_LEVEL: info
  app.properties: |
    currency=EUR
    retries=3

Non-sensitive settings and whole config files. Up to about 1 MiB per object.

secret icon

Secret

base64, not encrypted
kind: Secret
type: Opaque
metadata: {name: payments-db}
data:
  password: c2VjcmV0LXZhbHVl   # base64
# anyone who can read it can decode it

Same API, but access is controlled separately with RBAC and it can be encrypted at rest in etcd.

As environment variables

envFrom or valueFrom. Simple, but read only at container start.

As mounted files

A volume under /etc/config. Updates reach the files without a restart (after a short delay).

Real secret management

Prefer an external store (Secret Manager, AWS Secrets Manager, Vault) synced by an operator or CSI driver.