An image should run unchanged in every environment, with its settings supplied from outside. Kubernetes 5,150 stores those settings in two namespaced key-value objects, each up to 1 MiB: a ConfigMap for ordinary configuration and a Secret for credentials, keys and certificates. Pods consume both as environment variables or as files. BookNest's API still carries its database password in plain text in k8s/api-deployment.yaml (Deploying the API); this section moves it out.