Courseiva

CKAD Practice Question: Application Environment, Configuration and Security

How can you set the environment variable 'DATABASE_URL' in a pod to the value stored in a Kubernetes Secret named 'db-secret' under the key 'url'?

⚠ Common exam trap

A common mix-up: candidates confuse `secretKeyRef` with `configMapKeyRef` or misremember the syntax as `secretRef` (which is used for volume mounts), leading them to pick options that either reference the wrong resource type or use the wrong field structure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

env: - name: DATABASE_URL valueFrom: secretKeyRef: name: db-secret key: url

The `env.valueFrom.secretKeyRef` field in a Pod spec is the proper mechanism to inject a specific key from a Kubernetes Secret as an environment variable. The `name` field identifies the Secret (`db-secret`), and the `key` field specifies which key within that Secret (`url`) to use. This is defined in the Kubernetes API for exposing Secret data as environment variables.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    env: - name: DATABASE_URL valueFrom: configMapKeyRef: name: db-secret key: url

    Why it's wrong here

    The `configMapKeyRef` field is used exclusively to pull values from a ConfigMap, not a Secret. Even though the object is named `db-secret`, Kubernetes interprets this as a reference to a ConfigMap with that name, which would not exist if you actually created a Secret. To correctly source a value from a Secret, you must use `secretKeyRef` instead, which explicitly indicates a Secret object and a specific key within it.

  • ✗

    env: - name: DATABASE_URL valueFrom: secretRef: name: db-secret

    Why it's wrong here

    The `secretRef` field is not a valid field in the `valueFrom` spec for container environment variables. Kubernetes provides `secretKeyRef` to reference a specific key from a Secret, and you must always include the `key` property to identify which value to use. Without a valid field name and a key, the Pod definition would be rejected by the API server, so this syntax cannot work.

  • ✓

    env: - name: DATABASE_URL valueFrom: secretKeyRef: name: db-secret key: url

    Why this is correct

    This is the correct syntax because `secretKeyRef` unambiguously tells Kubernetes to fetch the value of the `url` key from the Secret named `db-secret`. The `name` field identifies the Secret, and the `key` field selects the exact data entry to load into the `DATABASE_URL` environment variable. This is the standard, documented mechanism for injecting Secret data as environment variables.

  • ✗

    env: - name: DATABASE_URL value: secretKeyRef: name: db-secret key: url

    Why it's wrong here

    The `value` field is meant only for static, literal strings, not for object references or lookups. By placing `secretKeyRef` under `value`, you are trying to assign the literal text `{secretKeyRef...}` to the environment variable, which is not what you want. To dynamically read a value from a Secret, you must use `valueFrom` to indicate that the value should be sourced from a Kubernetes object, not a fixed string.

About these practice questions

One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.