Concept and mechanism
Declared configuration and consumed configuration may differ over time. A ConfigMap used for environment variables does not automatically update the environment of an already started process. Normal volume projection may update files after propagation, but the application still needs to reread them; a subPath mount has update limitations. Define change, observation, and recovery strategy for each consumer. A Secret avoids putting the value in code, but the object alone does not guarantee encryption at rest or least-privilege access. Base64 is encoding rather than cryptographic protection. Check storage, RBAC, and who can create workloads able to consume the secret.
Guided application
For persistent data, distinguish PVC, PV, provisioner, and actual storage. A Pending PVC may result from a missing class, capacity, access mode, or scheduling coordination; inspect events before deleting it. ReadWriteOnce limits read-write mounting to one node and may allow several Pods on that node. It does not mean single-Pod access; ReadWriteOncePod has its own CSI requirements. In a fictional decommissioning scenario, confirm reclaim policy, retention, dependencies, and recovery before deleting the claim. A Delete policy may also remove external storage. A persistent volume preserves data between instances but does not replace consistent backup and rehearsed restoration. Record data origin and expected state at handover.
Changing a ConfigMap at 14:00 does not establish that a process started at 13:00 uses the new values.
Common pitfalls
Base64 as encryption; RWO as one Pod; deleting a PVC as consequence-free diagnosis.
Related topics: Workloads and desired state · Traffic and probes · Resources and scheduling
Confirm what the application consumes and what each operation may delete.
Reference: Configuration consumption and propagation · Kubernetes v1.37 concepts; current official documentation consulted 2026-09-30; cluster versions and plugin capabilities must be confirmed