ConfigMaps & Secrets for Configuration
Securely manage application configuration and sensitive data using ConfigMaps and Secrets within Kubernetes.
ConfigMaps & Secrets for Configuration is a free Docker & Kubernetes for Developers lesson on CoddyKit — lesson 3 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Docker & Kubernetes for Developers learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.
Configuration Challenges
Managing application configuration and sensitive data can be tricky, especially in dynamic environments like Kubernetes.
Hardcoding values into images makes them less reusable. Storing secrets directly in Git is a security risk.
Kubernetes offers two powerful resources to solve these challenges: ConfigMaps and Secrets.
Meet ConfigMaps
A ConfigMap is an API object used to store non-sensitive configuration data in key-value pairs.
Think of it as a central place for settings like database hostnames, logging levels, or API endpoints.
- Separates configuration from application code.
- Allows easy updates without rebuilding images.
- Can be consumed as environment variables or mounted files.
ConfigMap: Literal Values
You can create a ConfigMap directly from literal key-value pairs using YAML. This is great for simple, direct settings.
Here's an example for an application's settings:
apiVersion: v1
kind: ConfigMap
metadata:
name: app-settings
data:
log_level: INFO
feature_flag_a: "true"
api_url: http://backend-service/apiConfigMap: From Files
For more complex configurations, you can create a ConfigMap from an entire file.
If you have a config.properties file, its content can be directly embedded into the ConfigMap. The resulting ConfigMap would look like this:
apiVersion: v1
kind: ConfigMap
metadata:
name: app-config-from-file
data:
config.properties: |
database.host=db-service
database.port=5432
application.name=MyWebAppConfigMap as Env Vars
The most common way to use a ConfigMap is by injecting its data as environment variables into your Pods.
This allows your application to read configuration values directly.
apiVersion: v1
kind: Pod
metadata:
name: my-app-pod
spec:
containers:
- name: my-container
image: nginx
env:
- name: LOG_LEVEL
valueFrom:
configMapKeyRef:
name: app-settings
key: log_level
- name: API_URL
valueFrom:
configMapKeyRef:
name: app-settings
key: api_urlConfigMap as Volume Mounts
ConfigMap data can also be mounted as files into a Pod's filesystem. This is ideal for applications that read configuration from files.
Each key in the ConfigMap becomes a file in the specified mountPath. For example, log_level would be at /etc/config/log_level.
apiVersion: v1
kind: Pod
metadata:
name: my-app-pod-volume
spec:
containers:
- name: my-container
image: nginx
volumeMounts:
- name: config-volume
mountPath: "/etc/config"
volumes:
- name: config-volume
configMap:
name: app-settingsIntroducing Secrets
A Secret is similar to a ConfigMap but is designed for sensitive data like passwords, API keys, or TLS certificates.
Secrets are stored in Kubernetes in base64 encoded format, but this is NOT encryption. It's just encoding for safe transport.
- Provides a mechanism to distribute sensitive data.
- Accessed like ConfigMaps (env vars or volume mounts).
- Should always be managed with care and access controls.
Secret: Literal Values
Secrets are created similarly to ConfigMaps, but their data values are base64 encoded. This encoding is for safe transport, not encryption.
For example, if your password is "my-secure-password", its base64 encoding is "bXktc2VjdXJlLXBhc3N3b3Jk".
apiVersion: v1
kind: Secret
metadata:
name: db-credentials
type: Opaque
data:
username: dXNlcg== # 'user' base64 encoded
password: bXktc2VjdXJlLXBhc3N3b3Jk # 'my-secure-password' base64 encodedSecret as Env Vars
Secrets can be consumed as environment variables, just like ConfigMaps. Kubernetes automatically decodes the base64 value for the container.
This makes sensitive data available to your application without hardcoding it directly in the image.
apiVersion: v1
kind: Pod
metadata:
name: my-db-app
spec:
containers:
- name: my-container
image: my-app:1.0
env:
- name: DB_USERNAME
valueFrom:
secretKeyRef:
name: db-credentials
key: username
- name: DB_PASSWORD
valueFrom:
secretKeyRef:
name: db-credentials
key: passwordSecret as Volume Mounts
Mounting Secrets as files is often preferred for sensitive data, as it limits the exposure of the secret to the application process.
The mounted files will contain the decoded (plain-text) secret values, and you can set them to be read-only.
apiVersion: v1
kind: Pod
metadata:
name: my-secure-app
spec:
containers:
- name: my-container
image: my-app:1.0
volumeMounts:
- name: secret-volume
mountPath: "/etc/secrets"
readOnly: true
volumes:
- name: secret-volume
secret:
secretName: db-credentialsConfigMaps vs. Secrets
You need to store an API key for a third-party service and a configuration setting for your application's logging level. Which Kubernetes resources would you use for each?
Recap: Config & Secrets
We've learned how ConfigMaps and Secrets help manage configuration and sensitive data in Kubernetes.
- ConfigMaps store non-sensitive key-value pairs.
- Secrets store sensitive data, base64 encoded (not encrypted).
- Both can be consumed as environment variables or mounted files in Pods.
- Using them separates configuration from application logic, improving flexibility and security.
Frequently asked questions
Is the “ConfigMaps & Secrets for Configuration” lesson free?
Yes — the full text of “ConfigMaps & Secrets for Configuration” is free to read here on the web, and the Docker & Kubernetes for Developers course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Docker & Kubernetes for Developers course, upgrade to CoddyKit PRO.
What will I learn in “ConfigMaps & Secrets for Configuration”?
Securely manage application configuration and sensitive data using ConfigMaps and Secrets within Kubernetes. You practise Docker & Kubernetes for Developers with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start Docker & Kubernetes for Developers?
No prior experience is required. Docker & Kubernetes for Developers on CoddyKit is structured for beginners through advanced learners; this is — lesson 3 of 4, so you can start here or from the beginning and move at your own pace.
How long does the “ConfigMaps & Secrets for Configuration” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this Docker & Kubernetes for Developers lesson?
Yes. Every Docker & Kubernetes for Developers lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.
All lessons in this course
- Persistent Volumes & Persistent Volume Claims
- Managing Stateful Applications with StatefulSets
- ConfigMaps & Secrets for Configuration
- Storage Classes and Dynamic Provisioning