Choose the runtime evidence required before a configuration, credential, or identity update is promoted. Separate object state from the value active in a process and from a successful authenticated request.
Review these lessons
- ConfigMap projection: prove when a running process sees a new value
- Immutable configuration: bind each release to one named generation
- Required configuration keys: fail startup before accepting traffic
- Configuration pairs: prevent mixed policy and credential generations
- External secret sync: treat freshness as a monitored runtime contract
- Secret access: audit workload creation as an indirect read permission
- Kubernetes Secret encryption: rotate keys without losing restore access
- Projected identity tokens: reopen the file and verify its audience
Other checks
Common Mistakes
- Do not infer process freshness from an API object version.
- Do not overlook indirect Secret access through workload creation.
