# Consuming Configuration in Pods — Kubernetes

Source: https://www.skillbyai.com/en/kubernetes/c-consume

> Environment variables or mounted files.

## env, envFrom and volumes

Pods consume ConfigMaps and Secrets as **environment variables** (`env` for single keys, `envFrom` for all keys) or as **files** in a mounted volume. Environment variables are read once at start; mounted files are updated in place when the object changes (with a delay), which suits apps that reload configuration. Mounting secrets as files avoids them appearing in process listings and crash dumps of environment variables, and lets you set file permissions.

## Env vars from a ConfigMap and a mounted Secret

Not applied to a live cluster in this course; check field names against the API reference for your version.

```yaml
spec:
  containers:
  - name: web
    image: ghcr.io/example/web:1.5.2
    envFrom:
    - configMapRef: {name: web-config}          # LOG_LEVEL, FEATURE_SEARCH
    env:
    - name: DB_HOST
      value: db.shop-prod
    volumeMounts:
    - {name: db-cred, mountPath: /run/secrets/db, readOnly: true}
  volumes:
  - name: db-cred
    secret: {secretName: db-cred, defaultMode: 0400}
```

## Prefer files for secrets

Mounted secret files with tight permissions leak less easily than environment variables.

**Quiz:** What happens to environment variables from a ConfigMap when the ConfigMap changes?

- [ ] They update instantly
- [x] Running containers keep the old values until they restart
- [ ] The pod crashes
- [ ] The ConfigMap is deleted

*Answer:* Running containers keep the old values until they restart. Env vars are read at start.
