問題文
A service specification must let the container authenticate to that partner API. Which option correctly identifies the two practices the security engineer should follow? (Select two.)
選択肢
- Store the credential in a secret object and reference the secret from the specification.
- Put the credential in the specification as an environment variable value, because the specification is only readable by the service owner and keeping the value next to the code that uses it reduces the number of objects the team has to manage.
- Name the secret in the external access integration's allowed secrets so that only that secret can be used with that destination.
- Pass the credential as an argument at service creation time so that it is never stored.
- Grant read on the secret to the public role so that any future service can reuse it.