Exam CKS Topic 5 Question 29 Discussion

Actual exam question for Linux Foundation's CKS exam
Question #: 29
Topic #: 5
You are building a highly secure and sensitive Kubernetes cluster. Your architecture includes a separate namespace for running all CI/CD pipeline pods, isolated from the main application namespace. You want to ensure that only authorized users can access secrets in the CI/CD namespace- Describe how you would implement a secure mechanism for managing secrets and limiting access to them within the CI/CD namespace.

Suggested Answer:

Solution (Step by Step) :
1. Create a Dedicated Service Account for CI/CD:
- In the CI/CD namespace, create a service account named 'ci-cd-sa'
- This service account will be used only for running CI/CD pipelines.
2. Create a Secret with Restricted Access:
- Use the ' kubectl create secret generic' command to create a new secret in the CI/CD namespace.
- For example, you could use 'kubectl create secret generic my-secret -namespace-ci-cd' to create a secret named 'my- secret
- Use '--type' argument to create secrets of different types such as 'opaque', 'docker-registry' etc.
3. Create a RoleBinding:
- Create a role binding named 'ci-cd-sa-rolebinding' that associates the 'ci-cd-sa' service account with a custom role named 'ci-cd-secret-reader'
- This custom role will only grant access to read tne secrets in tne CI/CD namespace.
- Create a new role for the ci-cd-sa service account to only read the secrets in the namespace.


4. Configure your CI/CD pipeline: - Ensure your CI/CD pipelines are configured to use the 'ci-cd-sa' service account. - Configure your pipeline to access the secrets using the Kubernetes API.

by Sara at Feb 15, 2026, 09:14 PM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10