Lesson 13 / 25

Consuming Configuration in Pods

Environment variables or mounted files.

env, envFrom and volumes

Pods consume ConfigMaps and Secrets as environment variables (env for single keys, envFrom for all keys) or as files in a mounted volume. Environment variables are read once at start; mounted files are updated in place when the object changes (with a delay), which suits apps that reload configuration. Mounting secrets as files avoids them appearing in process listings and crash dumps of environment variables, and lets you set file permissions.

Env vars from a ConfigMap and a mounted Secret

Not applied to a live cluster in this course; check field names against the API reference for your version.

spec:
  containers:
  - name: web
    image: ghcr.io/example/web:1.5.2
    envFrom:
    - configMapRef: {name: web-config}          # LOG_LEVEL, FEATURE_SEARCH
    env:
    - name: DB_HOST
      value: db.shop-prod
    volumeMounts:
    - {name: db-cred, mountPath: /run/secrets/db, readOnly: true}
  volumes:
  - name: db-cred
    secret: {secretName: db-cred, defaultMode: 0400}

Prefer files for secrets

Mounted secret files with tight permissions leak less easily than environment variables.

Quick check: What happens to environment variables from a ConfigMap when the ConfigMap changes?

  • They update instantly
  • Running containers keep the old values until they restart
  • The pod crashes
  • The ConfigMap is deleted
Answer

Running containers keep the old values until they restart — Env vars are read at start.