ConfigMaps hold settings, Secrets hold credentials, and neither belongs in the image.
The same image runs in every environment because configuration is injected at runtime as environment variables or mounted files.
ConfigMap
plain textkind: ConfigMap metadata: {name: checkout-config} data: LOG_LEVEL: info app.properties: | currency=EUR retries=3
Non-sensitive settings and whole config files. Up to about 1 MiB per object.
Secret
base64, not encryptedkind: Secret type: Opaque metadata: {name: payments-db} data: password: c2VjcmV0LXZhbHVl # base64 # anyone who can read it can decode it
Same API, but access is controlled separately with RBAC and it can be encrypted at rest in etcd.
As environment variables
envFrom or valueFrom. Simple, but read only at container start.
As mounted files
A volume under /etc/config. Updates reach the files without a restart (after a short delay).
Real secret management
Prefer an external store (Secret Manager, AWS Secrets Manager, Vault) synced by an operator or CSI driver.