StudyToCert

All certifications / CKAD / Lessons

Certified Kubernetes Application Developer CKAD (Kubernetes v1.35 curriculum) · Domain 4: Application Environment, Configuration and Security

Secrets: generic, docker-registry and tls types; base64 encoding vs encryption; secretKeyRef and volume mounts

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

A Secret holds sensitive data such as passwords, API tokens, TLS keys and registry credentials. It is used much like a ConfigMap, but Kubernetes treats it more carefully: it can be restricted separately with RBAC, kubelets only receive Secrets for Pods scheduled on their node, and Secret volumes are stored in memory (tmpfs) on the node rather than on disk.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CKAD for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CKAD study plan