Concept and mechanism
Limit delivery of each Secret to processes needing it. A metrics sidecar should not receive the database credential merely because it shares the processor’s Pod. If the value appears in an exported log, analysis should consider copies, readers, and usage alongside rotation or revocation. Deleting the local file does not invalidate the credential. For workloads with different trust levels, also assess a runtime providing appropriate isolation. RuntimeClass selects a configured handler; the class name neither installs nor guarantees a sandbox. Validate compatible nodes, overhead, and behavior. At-rest protection addresses another risk: access to persisted storage. Encryption-provider order matters for new writes. Placing identity first does not encrypt those writes even when a cryptographic provider appears later.
Guided application
Migration must handle existing data. Enabling a new provider does not rewrite every older object. Plan controlled transformation, validate reads, and protect recovery keys. In a 30-day retention example, an old backup may still depend on the prior key even when new writes work. Key-destruction decisions must consider that requirement, restore rehearsals, and data-owner approval. Prepare a reversible sequence while old formats coexist. For APS, the runbook should explain how to recognize read failures, who manages cryptographic material, and how to restore without exposing keys through shared channels.
A restore works only with the old key: that result prevents destruction until the dependency is resolved or legitimately ends.
Common pitfalls
Base64 treated as encryption; new writes treated as completed migration; dependency-free backups; deleting one copy treated as revocation.
Related topics: Artifacts, provenance, and vulnerabilities · Auditing and evidence preservation
Confidentiality and recovery need a shared lifecycle for data and keys.
Reference: Encryption at rest · Kubernetes v1.35; current six-domain CKS outline