Alex Soto

Securing Secrets in the GitOps era

Your Kubernetes secrets are just base64 encoded, not encrypted. Learn a multi-layered strategy to truly secure them in a GitOps workflow.

Securing Secrets in the GitOps era
#1about 6 minutes

Defining secrets and the layers of security

Secrets are defined using analogies from music to illustrate that security is built in layers, like an onion, with no single silver bullet solution.

#2about 8 minutes

How GitOps streamlines the application delivery process

GitOps is presented as a DevOps methodology where Git serves as the single source of truth for both application code and infrastructure configuration.

#3about 4 minutes

The risk of exposing credentials in Git repositories

A live demo with Argo CD highlights the common mistake of committing plain text credentials and explains why Kubernetes' base64 encoding is not a secure solution.

#4about 8 minutes

Using Sealed Secrets to safely store secrets in Git

The Sealed Secrets project provides a way to encrypt Kubernetes secret manifests before committing them to a public or private Git repository using a public/private key pair.

#5about 6 minutes

The vulnerability of unencrypted secrets within etcd

Even with Sealed Secrets, decrypted secrets are stored in plain text in etcd, creating a vulnerability that can be addressed with Kubernetes' encryption-at-rest feature.

#6about 5 minutes

Integrating an external KMS for robust etcd encryption

To improve on native encryption-at-rest, a Key Management System (KMS) plugin offloads encryption to an external service like HashiCorp Vault, separating keys from the cluster.

#7about 11 minutes

Eliminating secret exposure with direct memory injection

The most secure approach involves applications fetching secrets directly from a secret store like Vault at runtime, holding them only in memory to avoid exposure via files or environment variables.

#8about 11 minutes

Resources and Q&A on modern secrets management

Recommended books are shared, followed by a Q&A covering DevSecOps culture, centralized vs. distributed secrets, and local development workflows.

Related jobs
Jobs that call for the skills explored in this talk.

Featured Partners

Related Articles

View all articles
AG
Andre Braun, GitLab
Now is the time for industrialized software development
Now is the time for industrialized software development Recently, I received a letter from my car’s manufacturer alerting me to a recall. They had discovered a defective part and wanted to replace it. It was easily fixed, and I might have forgotten a...
Now is the time for industrialized software development
DC
Daniel Cranney
Dev Digest 194: AI vs. Version Control, Password Louvre & Cursed Webdev
Inside last week’s Dev Digest 194 . 🧠 Learn how to become an AI-native software engineer 🤷‍♂️ How can you stand out when anyone can build anything? 👂 Whisper Leak allows listening to encrypted chats 🐝 What’s new the OWASP2025 Top Ten List 🙅‍♀️ Curse...
Dev Digest 194: AI vs. Version Control, Password Louvre & Cursed Webdev

From learning to earning

Jobs that call for the skills explored in this talk.

DevOps Engineer

SOMI Experts GmbH
Kiel, Germany

Linux
DevOps
Docker
Jenkins
Kubernetes
+2