Moritz Johner
External Secrets Operator: the secrets management toolbox for self-sufficient teams
#1about 2 minutes
Understanding the fundamentals of secrets management
Secrets management deals with the complete lifecycle of credentials like API keys and passwords to prevent sensitive data exposure.
#2about 4 minutes
A framework for classifying different types of secrets
Secrets can be categorized by their expiry, creation method, dependencies, and consumer type, which dictates how they should be managed.
#3about 4 minutes
Centralizing secrets from development, CI/CD, and production
Using a central vault like HashiCorp Vault or AWS Secrets Manager provides control, auditing, and a consistent API for all environments.
#4about 2 minutes
Overcoming common challenges in secrets management
Key challenges include secret sprawl, complex lifecycle management, poor tooling integration, and users not following security best practices.
#5about 3 minutes
Introducing the External Secrets Operator for Kubernetes
External Secrets Operator (ESO) is a CNCF project that synchronizes secrets from an external provider into native Kubernetes secrets.
#6about 4 minutes
Understanding the core concepts and CRDs of ESO
ESO uses SecretStore and ExternalSecret custom resources to define the connection to a provider and specify which secrets to fetch.
#7about 5 minutes
Using advanced ESO features for complex use cases
ESO supports advanced features like zero-configuration authentication, templating for config files, and multi-tenant isolation across different cloud accounts.
#8about 5 minutes
Q&A on pod restarts, SOPS, and caching benefits
The operator doesn't restart pods automatically, offers a smaller attack surface than SOPS in Git, and acts as a caching layer for high availability.
Related jobs
Jobs that call for the skills explored in this talk.
Team Lead DevOps (m/w/d)
Rhein-Main-Verkehrsverbund Servicegesellschaft mbH
Frankfurt am Main, Germany
Senior
Matching moments
31:09 MIN
Managing secrets with external secret managers
Securing secrets in the GitOps Era
38:03 MIN
Integrating external secret managers into Kubernetes
Securing secrets in the GitOps Era
40:22 MIN
Q&A on GitOps secret management practices
Securing secrets in the GitOps Era
12:32 MIN
Encrypting secrets in Git with Sealed Secrets
Securing secrets in the GitOps Era
42:23 MIN
Q&A: GitOps, CI tools, and security management
GitOps: The past, present and future
22:09 MIN
Centralizing security services in a Kubernetes ecosystem
DevSecOps: Security in DevOps
18:06 MIN
Using Sealed Secrets to safely store secrets in Git
Securing Secrets in the GitOps era
30:56 MIN
Securing workflows with secrets and best practices
CI/CD with Github Actions
Featured Partners
Related Videos
Securing secrets in the GitOps Era
Davide Imola
Securing Secrets in the GitOps era
Alex Soto
Best Practices for Using GitHub Secrets
Marcel Lupo
Chaos in Containers - Unleashing Resilience
Maish Saidel-Keesing
Operating etcd for Managed Kubernetes
Mario Valderrama
From Factory Floor to Kubernetes Core: Building an Edge Platform One Step at a Time
Dean Oren & Stefan Belsch
Kubernetes Security Best Practices
Rico Komenda
Kubernetes Security - Challenge and Opportunity
Marc Nimmerrichter
Related Articles
View all articles


.gif?w=240&auto=compress,format)
From learning to earning
Jobs that call for the skills explored in this talk.

DevOps Engineer – Kubernetes & Cloud (m/w/d)
epostbox epb GmbH
Berlin, Germany
Intermediate
Senior
DevOps
Kubernetes
Cloud (AWS/Google/Azure)

DevOps Engineer / Kubernetes
Passion for People GmbH
Karlsruhe, Germany
Remote
€70-90K
Azure
DevOps
Gitlab
+10

Cloud Engineer (m/w/d)
fulfillmenttools
Köln, Germany
€50-65K
Intermediate
TypeScript
Google Cloud Platform
Continuous Integration

Architekt für Cloud Security - AWS (w|m|d)
zeb consulting
Frankfurt am Main, Germany
Remote
Junior
Intermediate
Senior
Cloud Architecture
Amazon Web Services (AWS)
Cloud (AWS/Google/Azure)

Tech Lead (m/f/d) - Berlin
Patronus Group
Berlin, Germany
Senior
Kotlin
Spring Boot
Amazon Web Services (AWS)

Cloud-native Platform Engineer/Architect (Kubernetes / DevOps / GitOps)*
Cegeka Deutschland GmbH
Remote
Go
DevOps
Gitlab
Kubernetes

DevOps / Systems Engineer mit Erfahrung in Kubernetes (Main)
Cloud Solutions
Frankfurt am Main, Germany
Go
Bash
Rust
Linux
Shell
+6


DevSecOps Engineer: Kubernetes & Cloud Security
Sólo para miembros registrados
Barcelona, Spain
€55-75K
Senior
Bash
Azure
Linux
Kafka
+10