Kubernetes secrets

Calling an object a Secret is a naming convention, not protection.

By default they are base64-encoded rather than encrypted, readable by anything with the right permission, and visible in the underlying datastore. Encryption at rest and tight access control have to be configured deliberately. The name reliably creates an impression of safety that the default does not support.

Checked against the primary source.

More on Containers & Kubernetes