Secret as Volume vs Env Var

Two ways to inject secrets. The trade-offs.

Volume mount

Secret mounting vs environment variables is the choice of how secrets reach pods in Kubernetes. Each approach has trade-offs; the discipline is choosing the right one for the workload.

What volume mounting provides:

Volume mounts are the modern approach. Rotation-friendly; the discipline is preferred.

Env var

Environment variables are the legacy approach. They work but have rotation limitations; visibility is broader; the discipline is more constrained.

Env vars work but have limitations. The discipline is choosing them only when appropriate.

Decide

The decision depends on the workload. Volume mounts for rotation-friendly applications; env vars for legacy applications without secret management; modern is volume mounts.

Secret mounting vs env var is one of those Kubernetes pod-design choices that affects operational characteristics. Nova AI Ops integrates with cluster secret telemetry, surfaces patterns, and supports the team's secret discipline.