Hands-on Lab·Kubernetes and Cloud Native Security Associate
Kubernetes Secrets and Exposure Paths
Secrets are 27% of the KCSA pool by keyword. The exam is less interested in how you create one than in how it escapes: this guide mounts the same Secret two ways and measures the difference, then finds an RBAC rule that looks like it restricts access and does not.
Security Fundamentals Guide 21 of 42 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 18 min
- Reviewed25 August 2026
Written against the versions above. Secret volumes are tmpfs on Linux nodes, mounted read-only when the Pod asks. `resourceNames` on the `list` verb is accepted by the API and has no effect - documented behaviour, demonstrated here.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA5001 | 192.168.0.41 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE01 | 192.168.0.42 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE02 | 192.168.0.43 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE03 | 192.168.0.44 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
-
What describe will and will not tell you
-
The environment variable, and everywhere it appears
-
The volume, and what it is mounted on
-
An RBAC rule the API accepts and that grants nothing