Notes / Kubernetes / 06 Authentication And Authorization / 8 Secret Encryption

8 — Secret Encryption

Secrets are only base64-encoded in etcd by default, not encrypted, so without an EncryptionConfiguration enabling envelope encryption (ideally via a KMS provider) anyone with etcd access reads them in plaintext.

· §202607201139-57 ·
Chapter Navigation
On This Page

8 — Secret Encryption

Purpose

[stub: secret-encryption]

Metadata

AuthorAmit Singh
Scopekubernetes

Local graph

Full graph →