Q27Kubernetes Fundamentals
When a Kubernetes Secret is created, how is its data stored in etcd by default?
← → navigate · a answer
Community votes
Discussion · 1
A 1
The correct answer is:
A. As Base64-encoded strings that provide simple encoding but no actual encryption.
By default, Kubernetes Secrets are stored in etcd as Base64-encoded data. Base64 is only encoding, not encryption.
Example:
data:
password: cGFzc3dvcmQxMjM=
That value can be decoded back easily:
echo cGFzc3dvcmQxMjM= | base64 -d
Important security note: To truly protect Secrets in etcd, enable encryption at rest and restrict access using RBAC.
Answer: A.