Description
Passwords, API keys, tokens, or private keys written directly in infrastructure code can expose credentials to people with access to the repository or deployment artifacts. Deleting a value from a file can leave it in commit history and other copies.
Potential impact
An exposed credential can grant access to services or data within the account’s permissions.
Remediation
Store secrets in a secret management service and reference or inject them during deployment. Revoke and replace exposed credentials, then remove them from code and historical copies. Kubernetes Secrets also need access restrictions and encryption at rest.
Examples
The revised example only shows passing a value from the separately created secret-basic-auth Secret into an environment variable. Application configuration that consumes the value is omitted.
Before
apiVersion: v1
kind: Secret
metadata:
name: secret-basic-auth
type: kubernetes.io/basic-auth
stringData:
password: "root"
After
apiVersion: v1
kind: Pod
metadata:
name: nginx
spec:
containers:
- name: nginx
image: nginx
env:
- name: PASSWORD
valueFrom:
secretKeyRef:
name: secret-basic-auth
key: password