An external secret controller or CSI integration adds another reconciliation path between an issuer and an application. The issuer can rotate a credential while the cluster copy, mounted file, or process cache remains older. A controller reporting success at one moment does not prove that every Pod has loaded the latest usable value. Refresh intervals, API failures, issuer outages, mount behavior, and application reload rules all affect the age of the credential that handles requests.
External secret sync: treat freshness as a monitored runtime contract
Operational decision
A receipt exporter receives a short-lived object-store credential from an external issuer. Record issuance and expiry times without recording the token itself. Set a maximum allowed age that leaves room for retry and clock skew, and alert before expiry rather than after the first failed upload. In a disposable environment, block the controller's issuer access, rotate the credential, and observe the external version, Kubernetes or CSI version, file version, process version, and successful upload. Restore access and measure catch-up time. If the application reads the file once, use a supervised reload or Pod rollout; a changed mount is not enough. If the integration does not create a Kubernetes Secret, do not use a Secret-object check as the only evidence. The policy fragment sets an acceptance rule independent of a particular controller; the implementation must map its own status fields to these checks.
Receipt exporter credential freshness contract
Issued lifetime: 46 minutes
Maximum active age: 29 minutes
Alert before expiry: 14 minutes
Evidence: issuer version, projected version, process version
Request proof: upload and read-back with active credential
Failure action: stop new exports before an expired credential causes repeated retriesCost and verification
Short refresh intervals increase issuer traffic and control-plane work; long intervals increase stale-credential risk. Alert on age and failed authenticated requests together, because a credential can be fresh but invalid for its audience. Model the retry budget against credential lifetime, issuer rate limits, and restart time. Avoid recording the credential value in telemetry; version identifiers and timestamps are enough for correlation.
Common Mistakes
- Do not equate controller Ready status with the version currently held by a process.
- Do not set refresh timing close to credential expiry without a failure margin.
- Do not inspect freshness by printing token bytes into logs.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Secret rotation rollout: update the issuer, consumer, and active connections
- ConfigMap projection: prove when a running process sees a new value
- Alert design: page on impact and include a first action
- Credential incident response: revoke access before rebuilding trust
