ConfigMaps and Secrets separate configuration from container images. A ConfigMap holds non-sensitive key-value data; a Secret holds sensitive values such as passwords, tokens and TLS keys. Their data is only base64-encoded, which is not encryption, so protect Secrets with RBAC and, ideally, encryption at rest configured on the API server.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.