पाठ 12 / 25
Secrets: Encoding Is Not Encryption
Handle sensitive values carefully.
base64 is reversible
A Secret holds sensitive values such as passwords, tokens and keys. In the manifest, values are base64-encoded, which anyone can decode; this is not encryption. Protect Secrets by enabling encryption at rest for etcd, restricting access with RBAC, never committing plain Secret manifests to git, and preferably syncing from an external secret manager (cloud secret managers or Vault via the External Secrets Operator, or Sealed Secrets for git workflows).
A Secret and its trivially decoded value, run
I ran this with kubectl 1.37.0 using --dry-run=client (or kubectl kustomize), which generates manifests locally without a cluster; nothing was applied to a live cluster. The password appears base64-encoded in the manifest, and one base64 -d command recovers it. Treat Secret manifests as sensitive files.
kubectl create secret generic db-cred --from-literal=password=s3cr3t-Pa55 --dry-run=client -o yaml
echo czNjcjN0LVBhNTU= | base64 -d; echo
Output:
apiVersion: v1 data: password: czNjcjN0LVBhNTU= kind: Secret metadata: name: db-cred s3cr3t-Pa55
Keep secrets out of git
Commit references to secrets (External Secrets, Sealed Secrets), not the encoded values themselves.
त्वरित जाँच: What protection does base64 encoding in a Secret provide?
- Strong encryption
- None; it is reversible encoding, not encryption
- It hides values from cluster admins
- It rotates passwords
Answer
None; it is reversible encoding, not encryption — Use encryption at rest, RBAC and external secret stores.