M4 · Identity and security
Secret delivery
29 / 61

Secret Manager can deliver secrets without baking them into images

A Pod identity receives permission to a specific secret, and a CSI integration or application call obtains the current value at runtime.

1Kubernetes ServiceAccountIdentifies the workload through federation.
2IAM policyGrants only the required secret accessor permission.
3Secret ManagerStores versions, rotation history and audit evidence.
4CSI or APIDelivers the value to the Pod at runtime.
5ApplicationReads the mounted file or client response and handles rotation.
A secret mounted as a file is still sensitive inside the Pod; minimize readers and avoid logging it.