Lab 04 — Manage Kubernetes Namespaces, ConfigMaps, Secrets and Storage
Mission Information
Section titled “Mission Information”| Item | Details |
|---|---|
| Lab ID | K8S-FND-LAB-04 |
| Difficulty | Intermediate |
| Estimated Time | 2–3 Hours |
| Environment | Local Kubernetes Cluster (kind) |
| Platform | Docker Desktop + kind |
| Cost | Free |
| Primary Role | Kubernetes Security Engineer |
| Module | Module 01 — Kubernetes Fundamentals |
| Previous Lab | Lab 03 — Explore Kubernetes Architecture and Cluster Components |
Mission Scenario
Section titled “Mission Scenario”CloudNova Technologies is preparing to migrate one of its internal inventory management applications to Kubernetes.
The application consists of:
- Web Application
- Configuration Files
- Database Credentials
- Persistent Application Storage
The application team currently stores everything inside the container image, including configuration files and passwords.
During a security review, the Cloud Security team identified several issues:
- Passwords stored inside images
- Hardcoded configuration
- No environment separation
- No persistent storage
- Shared configuration across applications
- No secret management process
Your mission is to redesign the deployment using Kubernetes best practices.
You will build a secure application architecture that separates:
- Configuration
- Secrets
- Storage
- Application workloads
while documenting the security improvements.
Learning Objectives
Section titled “Learning Objectives”By completing this lab you will learn how to:
- Create Namespaces
- Organise workloads
- Build ConfigMaps
- Consume ConfigMaps
- Create Kubernetes Secrets
- Consume Secrets securely
- Create PersistentVolumes
- Create PersistentVolumeClaims
- Use Storage Classes
- Mount persistent storage
- Inspect mounted volumes
- Rotate configuration
- Update Secrets
- Validate persistence
- Review storage security
- Produce a security assessment
Enterprise Architecture
Section titled “Enterprise Architecture” CloudNova Inventory Application
Namespace cloudnova-inventory-prod │ ┌───────────────┼────────────────┐ │ │ │ ▼ ▼ ▼
ConfigMap Kubernetes Secret PVC │ │ │ │ │ ▼ │ │ Persistent Volume │ │ └───────────────┼────────────────┐ ▼ Deployment │ Inventory Pod │ ClusterIP ServiceLab Outcomes
Section titled “Lab Outcomes”At the end of this lab you will have created:
- Dedicated Namespace
- ConfigMap
- Secret
- Persistent Volume
- Persistent Volume Claim
- Storage Class
- Deployment
- ClusterIP Service
- Mounted configuration
- Mounted secrets
- Mounted persistent storage
- Security assessment report
Tasks Overview
Section titled “Tasks Overview”Task 01
Section titled “Task 01”Verify Cluster Health
Task 02
Section titled “Task 02”Create Lab Workspace
Task 03
Section titled “Task 03”Create Enterprise Namespace
Students create
cloudnova-inventory-prodwith labels
- owner
- environment
- application
- security-tier
Task 04
Section titled “Task 04”Create ConfigMap
Students build
inventory-configcontaining
Application Name
Application Port
Logging Level
Company Name
Region
Support Email
EnvironmentStudents learn
- kubectl create configmap
- YAML definition
- Viewing ConfigMaps
- Editing ConfigMaps
- Updating ConfigMaps
Task 05
Section titled “Task 05”Consume ConfigMap
Deploy application using
- Environment Variables
AND
- Mounted Configuration Files
Students compare both methods.
Task 06
Section titled “Task 06”Create Kubernetes Secret
Students create
inventory-db-secretcontaining
-
username
-
password
-
database
-
API key
using
kubectl create secret genericthen
YAML.
Students inspect
kubectl get secret
kubectl describe secretDiscuss why
Base64
≠
Encryption.
Task 07
Section titled “Task 07”Consume Secrets
Application reads
Database Username
Database Password
API Key
through
Environment Variables
and
Mounted Secret Volumes.
Task 08
Section titled “Task 08”Inspect Secrets
Students verify
kubectl exec
env
cat
lsto locate
Secrets
inside
/etc/secretsTask 09
Section titled “Task 09”Create Persistent Volume
Students create
PersistentVolumeusing
hostPath
(local lab only)
Discuss why
hostPath
is NOT suitable
for production.
Task 10
Section titled “Task 10”Create Persistent Volume Claim
Students request
1Gi StorageObserve
Binding Process
PVC
↓
PV
↓
Mounted StorageTask 11
Section titled “Task 11”Create Storage Class
Students inspect
kubectl get storageclassUnderstand
Dynamic Provisioning
Discuss
Amazon EBS CSI
Amazon EFS CSI
Azure Disk CSI
GCP PD CSI
Task 12
Section titled “Task 12”Deploy Inventory Application
Application mounts
ConfigMap
Secret
PVC
Deployment contains
Resource Limits
Health Checks
Security Context
Read-only Filesystem
Dedicated Service Account
Task 13
Section titled “Task 13”Verify Mounted Resources
Students verify
kubectl exec
ls
cat
df
mountReview
/config
/etc/secrets
/dataTask 14
Section titled “Task 14”Test Persistence
Students create
inventory.txtinside
Persistent Volume.
Delete Pod.
Wait.
Replacement Pod appears.
Verify
File still exists.
Students now understand
Persistent Storage.
Task 15
Section titled “Task 15”Rotate Configuration
Modify ConfigMap.
Restart Pods.
Observe
Updated Configuration.
Discuss
Immutable ConfigMaps.
Task 16
Section titled “Task 16”Rotate Secret
Update
Database Password.
Restart Pods.
Verify
Application receives
new credentials.
Discuss
External Secrets Operator
AWS Secrets Manager
HashiCorp Vault.
Task 17
Section titled “Task 17”Inspect Storage
Students inspect
kubectl get pv
kubectl get pvc
kubectl describe pv
kubectl describe pvcReview
Capacity
Access Modes
Reclaim Policy
Binding Status
Task 18
Section titled “Task 18”Security Review
Students answer
Why shouldn’t passwords live inside images?
Why shouldn’t ConfigMaps contain passwords?
Why should Secrets be encrypted?
Why shouldn’t hostPath be used?
How does persistent storage survive Pod deletion?
Task 19
Section titled “Task 19”Evidence Collection
Students capture
-
Namespace
-
ConfigMap
-
Secret
-
Deployment
-
Service
-
PV
-
PVC
-
Mounted Files
-
Persistent File
-
Application Running
-
Storage Class
Task 20
Section titled “Task 20”Enterprise Assessment Report
Students complete
CloudNova Inventory Platform Assessmentincluding
Configuration Review
Secrets Review
Storage Review
Security Findings
Risk Assessment
Recommendations
Task 21
Section titled “Task 21”Cleanup
Delete
Deployment
Service
PVC
PV
Secrets
ConfigMap
Namespace
Verify
Cluster Clean
Skills Developed
Section titled “Skills Developed”Students will practise
-
Namespace Management
-
Configuration Management
-
Secret Management
-
Persistent Storage
-
Storage Classes
-
PVC Lifecycle
-
ConfigMap Lifecycle
-
Secret Lifecycle
-
Enterprise Configuration Management
-
Enterprise Storage Design
-
Secure Application Deployment
-
Storage Troubleshooting
-
Kubernetes Security Reviews
-
Architecture Documentation
Knowledge Check
Section titled “Knowledge Check”Students answer questions covering
-
ConfigMaps
-
Secrets
-
Persistent Volumes
-
Persistent Volume Claims
-
Storage Classes
-
Dynamic Provisioning
-
Secret Rotation
-
Configuration Management
-
Storage Security
-
Enterprise Best Practices
Lab Summary
Section titled “Lab Summary”In this lab you designed an enterprise Kubernetes application using industry best practices.
Instead of storing configuration, passwords and data inside container images, you separated each responsibility into dedicated Kubernetes resources.
You learned how ConfigMaps manage application configuration, how Secrets protect sensitive information, and how Persistent Volumes ensure application data survives Pod failures and redeployments.
These patterns are used across modern Kubernetes platforms running on Amazon EKS, Azure AKS and Google Kubernetes Engine, forming the foundation for secure, scalable and maintainable cloud-native applications.
What’s Next?
Section titled “What’s Next?”You have now completed Module 01 — Kubernetes Fundamentals for Security Engineers.
The next module shifts from platform fundamentals to identity and access management.
➡️ Next Module: Module 02 — Kubernetes Identity & Access Management (IAM)
In Module 02, you will learn how to secure access to Kubernetes using:
- Authentication
- Authorization
- Role-Based Access Control (RBAC)
- Service Accounts
- ClusterRoles and RoleBindings
- IAM Roles for Service Accounts (IRSA)
- OpenID Connect (OIDC)
- Least Privilege Design
- Enterprise Identity Governance
- Zero Trust for Kubernetes