Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Secrets and configuration across the delivery path

Last updated: 2 Oct 20266 min read
tutorial
IntermediateBy AITrove Editorial

Configuration changes runtime behavior without changing application code. A secret is configuration whose disclosure grants access or reveals protected data. Encoding a value as base64, including in a Kubernetes Secret manifest, is not encryption. The storage system, transport, runtime mount, role permissions, and rotation procedure all matter.

Operational decision

A settlement worker reads a database credential from a restricted runtime secret source rather than baking it into the image. Give the workload only the secret it needs, protect the cluster store with encryption at rest and access control, and avoid printing environment variables during troubleshooting. Rotate a credential by introducing the new value, verifying connections, then revoking the old one; abrupt replacement can strand long-lived connections. Use separate identities for CI, deployment, and application runtime. The YAML fragment shows a key reference, not the secret value or its creation. Whether an update reaches a running process depends on the injection method and application behavior. Test revocation and incident response, not just initial access.

yaml
env:
  - name: SETTLEMENT_DB_PASSWORD
    valueFrom:
      secretKeyRef:
        name: settlement-db
        key: password

Cost and verification

A managed secret service and frequent rotation add requests and operational work, but reduce the blast radius of a leaked credential. Environment variables are convenient yet can be exposed through process inspection or accidental diagnostics; a mounted file or direct secret client may fit stricter environments. No storage mechanism prevents an authorized process from mishandling the secret. Restrict log access and set retention. Check that backups and disaster-recovery copies protect the same material.

Common Mistakes

  • Do not commit base64-encoded credentials.
  • Do not share one cloud identity between CI and the running service.
  • Do not rotate a credential without testing live connection behavior.

Connected lessons

Operational follow-up

Advanced follow-up

Advanced follow-up

Advanced follow-up

Web publishing follow-up

Related Prompt Engineering lesson: Prompt privacy: send only the fields needed for the task.

devops
operations
Storage details