問題文
A source value is rotated in Vault and the destination Kubernetes Secret shows the new value, but one workload keeps presenting the old credential until it is restarted by hand. What explains the difference?
選択肢
- The workload is not one of the resource types the operator can roll out, so the destination was updated while the running pods kept the old value in memory.
- The destination was never updated, so the source change has not reached the cluster yet.
- The operator only rewrites the destination when the custom resource is re-applied, so the team has to re-apply it before any running instance can pick the new value up.
- The operator rolls out every resource type in the namespace, so the cause has to be that the pods cache the value and ignore the change until they are evicted.