Identity and security
Secrets and encryption
36 / 69

Kubernetes Secrets are base64; encrypt them at rest and prefer a real secrets manager.

Two layers help: envelope encryption of etcd data with a KMS key, and syncing values from AWS Secrets Manager so the cluster never owns the master copy.

Secrets Managersource of truth, rotation, auditExternal Secrets Operatoror Secrets Store CSI driverwith Pod Identity to readKubernetes Secretor mounted file in the PodKMS envelopeencryption of API data in etcdyour key: audit and revokeRotate in Secrets Manager once; every consumer receives the new value without a redeploy of manifests.

Never commit Secret manifests

Base64 is not encryption. Use sealed secrets, SOPS or an external store.

Own your KMS key

Recent EKS versions encrypt API data by default with AWS-owned keys; a customer KMS key gives audit and revocation control. Enable it at creation where possible.

Prefer files over env vars

Mounted files can refresh; environment variables are fixed at start and leak into crash dumps and child processes.