How do Kubernetes workloads get secrets from Vault?
⚡
Quick Answer
They authenticate with the Kubernetes auth method (service account JWT) and fetch secrets via the Agent injector, CSI driver, or API.
Detailed Answer
The pod's service account token proves identity to Vault's Kubernetes auth method, which returns a token scoped by policy. The Vault Agent Sidecar Injector or the Secrets Store CSI driver then materializes secrets into the pod (files or env) without baking them into images — dynamic, audited, and revocable.
💡
Interview Tip
Name the injector and CSI driver approaches.
vaultkubernetesinjector