Lesson 13 / 25
Consuming Configuration in Pods
Environment variables or mounted files.
env, envFrom and volumes
Pods consume ConfigMaps and Secrets as environment variables (env for single keys, envFrom for all keys) or as files in a mounted volume. Environment variables are read once at start; mounted files are updated in place when the object changes (with a delay), which suits apps that reload configuration. Mounting secrets as files avoids them appearing in process listings and crash dumps of environment variables, and lets you set file permissions.
Env vars from a ConfigMap and a mounted Secret
Not applied to a live cluster in this course; check field names against the API reference for your version.
spec:
containers:
- name: web
image: ghcr.io/example/web:1.5.2
envFrom:
- configMapRef: {name: web-config} # LOG_LEVEL, FEATURE_SEARCH
env:
- name: DB_HOST
value: db.shop-prod
volumeMounts:
- {name: db-cred, mountPath: /run/secrets/db, readOnly: true}
volumes:
- name: db-cred
secret: {secretName: db-cred, defaultMode: 0400}Prefer files for secrets
Mounted secret files with tight permissions leak less easily than environment variables.
Quick check: What happens to environment variables from a ConfigMap when the ConfigMap changes?
- They update instantly
- Running containers keep the old values until they restart
- The pod crashes
- The ConfigMap is deleted
Answer
Running containers keep the old values until they restart — Env vars are read at start.