Workload security

Rotate a Kubernetes collector credential

Rotate a Secorvia Kubernetes collector credential, apply the replacement, and distinguish revoking collection from removing a cluster.

Reviewed

Before you start

Have access to the cluster installation and permission to change collector credentials. Rotation invalidates the existing credential immediately.

Select the correct cluster

Open Kubernetes Security and locate the cluster in Registered Clusters. Check its name and collector connection details before using its Actions menu.

Rotate and store the replacement

Choose Rotate collector credential. Copy the new credential when it is shown; Secorvia keeps only its hash and cannot display it again. Collection stops using the old credential immediately.

Update the collector installation

Use Apply the new credential or re-run the full generated installation command. Update the Kubernetes Secret and restart the collector as instructed by the app. Do not paste the credential into an issue or documentation page.

Verify reporting resumes

Check collector logs, Last authenticated, and Last report. Use Verify connection to confirm the replacement works, then remove obsolete copies of the previous credential from your secret-management workflow.

Understand revoke versus remove

Revoke collector credential stops reporting while retaining the cluster and its inventory. Remove cluster removes discovered cluster inventory after revocation; findings and audit history are kept. Read the confirmation text before choosing either operation.

Where you are now

The collector reports with its replacement credential and the previous credential no longer authenticates.

WHEN SOMETHING LOOKS OFF

A few things to check

Reporting stopped after rotation

The installed Secret may still contain the previous credential, or the collector was not restarted.

The new credential was lost

Rotate again and update the installation with the newly issued value.

PUT IT INTO PRACTICE

Make your next move in Secorvia.

Open the app and follow along with your own organization.

Open Secorvia