A kubernetes: Config Data import reads cluster sources during startup and follows Boot's configuration ordering.
Spring Cloud Kubernetes config import: make source precedence explicit
The import is a startup contract
A dispatch service reads a ConfigMap for route limits. With Spring Cloud Kubernetes' config starter present, spring.config.import can request kubernetes: during Config Data processing. The imported values take precedence over values in the document that declares the import. Other sources, including environment and command-line inputs, still have their own precedence. Boot source order is the underlying rule.
Fail or degrade deliberately
A required import should stop startup when the service cannot obtain its expected configuration. An optional import only makes sense if safe defaults exist and a deployment test checks them. A pod with no API permissions can start with a surprising fallback if the failure path is treated as optional. Required imports make missing state visible.
Test the deployed service account
Run the pod under its real service account. Change one value in the ConfigMap, one in the base file and one in an environment variable, then assert the winning value. Repeat with the ConfigMap absent and with API access denied.
Implementation sketch
spring:
application:
name: dispatch-service
config:
import: "kubernetes:"
dispatch:
max-active-routes: 47Cost and verification
Startup performs cluster API reads and can depend on API availability. Limit the requested namespaces and objects; a broad watch or read grant increases both load and access surface.
Common Mistakes
- Do not assume the imported ConfigMap overrides every other Boot source.
- Do not mark an import optional without safe defaults and a failure test.
- Do not grant cluster-wide read permission for one namespace's configuration.
Read next
Spring Boot config source priority: a builder default may lose to a packaged file, Spring Boot config import: fail startup when a required file is missing, Spring Cloud Kubernetes reload: decide which changes need a restart.
Related boundary
Spring Cloud Kubernetes permissions: scope the service account to its reads
