A civic open-data exporter embeds database passwords in Dockerfile ENV and COPY layers. What should the team do instead?
Select an answer to reveal the explanation.
Short Explanation
Baking passwords into image layers is like writing the vault combo on the outside of the moving box—anyone who gets the box can read it. Keep images clean and hand credentials in at runtime with Kubernetes Secrets (or non-sensitive ConfigMaps).
Full Explanation
Image layers are widely cached and often readable by anyone with registry or node access. Credentials should not be ENV, COPY, or ARG leftovers in application images. CKAD practice is to inject configuration and secrets at runtime via Secret and ConfigMap mounts or environment references. Encoding, labels, or tag tricks do not remove secrets from layer history.