Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

A user wants to create a Kubernetes Secret for storing Docker registry credentials (username and password). Which type of Secret should they use?

⚠ Common exam trap

A common mix-up: candidates choose `Opaque` (Option B) because they think any secret can be used for Docker credentials, but the CKAD exam expects you to know that only `kubernetes.io/dockerconfigjson` provides the correct format and automatic integration with image pull secrets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubernetes.io/dockerconfigjson

`kubernetes.io/dockerconfigjson` is the dedicated Secret type for storing Docker registry credentials in the format expected by `docker login`. It automatically encodes the username and password into a `.dockerconfigjson` field, which is used by Kubernetes to pull images from private registries. This type is required when referencing a `imagePullSecret` in a Pod spec.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubernetes.io/tls

    Why it's wrong here

    kubernetes.io/tls is designed exclusively for TLS certificate material, requiring specific keys `tls.crt` and `tls.key` in the `data` map. It is commonly attached to Ingress resources for HTTPS termination, not to authenticate container runtime pulls against Docker registries. A TLS secret lacks the `.dockerconfigjson` payload and the registry `auths` structure, so the kubelet cannot use it as an imagePullSecret.

  • ✗

    Opaque

    Why it's wrong here

    Opaque is a generic catch-all secret type for arbitrary bytes (e.g., environment variables, configuration values) and has no schema enforcement. While you could theoretically store registry credentials inside an Opaque secret, Kubernetes API and kubectl do not treat such a secret as a Docker credential, and it cannot be referenced as `imagePullSecrets` to authorize pulls from private registries. The dedicated `kubernetes.io/dockerconfigjson` type exists precisely so the kubelet and tooling know how to decode the registry auth payload.

  • ✓

    kubernetes.io/dockerconfigjson

    Why this is correct

    kubernetes.io/dockerconfigjson is the canonical secret type for Docker registry authentication, storing the entire Docker config file (typically generated by `docker login`) in a data field named `.dockerconfigjson`. This file contains `auths` entries with base64-encoded `username:password` tokens for each registry. When this secret is attached to a Pod via `imagePullSecrets`, the kubelet decodes it and uses the embedded credentials to pull private images exactly as Docker does.

  • ✗

    kubernetes.io/basic-auth

    Why it's wrong here

    kubernetes.io/basic-auth is intended for plain username/password credentials in the `username` and `password` data keys, often used for HTTP basic authentication in ingress annotations or application configuration. Its structure does not align with Docker's `config.json` format, which nests registry URLs under an `auths` object. The kubelet expects registry-specific authentication data, so a basic-auth secret cannot authenticate image pulls and would not be accepted as an imagePullSecret.

About these practice questions

This CKAD question is part of Courseiva's 826-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.