Kubernetes secrets are just base64. Is that a problem

Back to list2026-08-14
You

Kubernetes secrets are just base64. Is that a problem?

ChatGPT

It is, if that is the only layer. Enable encryption at rest for etcd, restrict RBAC on the secrets resource, and keep them out of the manifests in git. Base64 is an encoding, and treating it as protection is the most common misunderstanding in this area.

You

A pod restarts every few minutes and the logs end normally.

ChatGPT

Look at the previous container, not the current one: kubectl logs pod --previous. A clean ending plus a restart usually means OOMKilled, which shows in kubectl describe pod under Last State. Memory limits are the first thing to check, requests the second.

You

What would you skip entirely?

ChatGPT

The reporting layer, until something forces it. It is the part that feels productive to build and the part nobody opens twice.