# Secrets: Encoding Is Not Encryption — Kubernetes

Source: https://www.skillbyai.com/en/kubernetes/c-secret

> Handle sensitive values carefully.

## base64 is reversible

A **Secret** holds sensitive values such as passwords, tokens and keys. In the manifest, values are **base64-encoded**, which anyone can decode; this is not encryption. Protect Secrets by enabling **encryption at rest** for etcd, restricting access with **RBAC**, never committing plain Secret manifests to git, and preferably syncing from an external secret manager (cloud secret managers or Vault via the External Secrets Operator, or Sealed Secrets for git workflows).

## A Secret and its trivially decoded value, run

I ran this with kubectl 1.37.0 using --dry-run=client (or kubectl kustomize), which generates manifests locally without a cluster; nothing was applied to a live cluster. The password appears base64-encoded in the manifest, and one base64 -d command recovers it. Treat Secret manifests as sensitive files.

```bash
kubectl create secret generic db-cred --from-literal=password=s3cr3t-Pa55 --dry-run=client -o yaml
echo czNjcjN0LVBhNTU= | base64 -d; echo
```

Output:

```
apiVersion: v1
data:
  password: czNjcjN0LVBhNTU=
kind: Secret
metadata:
  name: db-cred
s3cr3t-Pa55
```

## Keep secrets out of git

Commit references to secrets (External Secrets, Sealed Secrets), not the encoded values themselves.

**Quiz:** What protection does base64 encoding in a Secret provide?

- [ ] Strong encryption
- [x] None; it is reversible encoding, not encryption
- [ ] It hides values from cluster admins
- [ ] It rotates passwords

*Answer:* None; it is reversible encoding, not encryption. Use encryption at rest, RBAC and external secret stores.
