World Congress 2023 Nov 10, 2023

External Secrets Operator: the secrets management toolbox for self-sufficient teams

Moritz Johner

Stop scattering sensitive credentials across your repositories. The External Secrets Operator seamlessly bridges centralized vaults with native Kubernetes secrets to secure and streamline your GitOps workflows.

Pause
Mute Enter Fullscreen
#1 about 3 min

Introduction to the presentation context and audience

An introduction to the presentation context and an audience poll categorizing attendees by engineering roles.

#2 about 2 min

Defining secrets management and its security importance

Managing the lifecycle of credentials prevents severe operational consequences from threat actors accessing sensitive company data.

#3 about 5 min

Categorizing secrets by expiry, creation, dependency, and consumer

Secrets vary significantly based on their expiration times, internal or external dependencies, and whether a human or machine utilizes them.

#4 about 2 min

Identifying environments that require strict credential management

Different operational spaces like development laptops, continuous integration pipelines, and deployment infrastructure demand specialized credential constraints.

#5 about 2 min

Utilizing centralized vaults for secure credential storage

Consolidating credentials into a central API enables consistent auditing, lifecycle policy enforcement, and seamless authentication control.

#6 about 2 min

Overcoming secret sprawl and legacy integration challenges

Teams struggle with credentials scattered across infrastructure and the incremental engineering effort needed to automate disparate system integrations securely.

#7 about 2 min

History and evolution of External Secrets Operator

The open-source project evolved from earlier implementations like a GoDaddy toolkit into a consolidated CNCF technology footprint.

#8 about 3 min

How External Secrets Operator fetches central secrets

The operator reads from a central provider vault to automatically update native cluster resources for downstream application consumption.

#9 about 3 min

Configuring secret stores and external secret references

Deploying a custom resource definition safely connects specific service accounts to cloud providers on a configurable automated refresh interval.

#10 about 1 min

Pushing secrets and generating credentials with custom resources

Additional operator configuration APIs allow backend developers to generate new credentials within the cluster or push existing ones upstream to cloud vaults.

#11 about 2 min

Key features including zero-configuration authentication and lifecycle policies

Native IAM integration natively eliminates the initial bootstrap secret problem while enabling robust GitOps workflows via customized rotation policies.

#12 about 2 min

Rendering configuration files directly via automated secret templating

Built-in templating tools safely inject fetched credentials directly into complex runtime application configuration files without relying on extra init containers.

#13 about 2 min

Isolating tenants safely across cluster namespaces and accounts

Operator deployment patterns securely restrict specific workload namespaces to unique cloud provider accounts to enforce strict runtime multi-tenant boundaries.

#14 about 5 min

Question and answer session on caching and specific tools

Audience questions address pod reloading constraints, 1Password system integrations, Git repository encryption tradeoffs, and application caching benefits over direct vault access.

Matching moments

3:09 min

Injecting sensitive configuration values via Kubernetes secrets

Hannes Norbert Göring · LIVE

2:03 min

Additional resources on GitOps and Kubernetes secret management

Alex Soto Alex Soto · LIVE

6:14 min

Introduction to securing secrets in GitOps deployments

Alex Soto Alex Soto · LIVE

2:30 min

Handling passwords and certificates securely via Kubernetes secrets

Aurélie Vache Aurélie Vache · World Congress 2026 Europe

1:06 min

Managing tokens and user credentials securely across endpoints

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

1:42 min

Abstracting Kubernetes complexity with a self-service operator

Jan Lepsky Jan Lepsky

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 24, 2026 · 11:40–12:10

Stage 3

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

September 24, 2026 · 17:30–18:00

Stage 4

Boring Failover: Predictable Region Recovery Across 5,000 Microservices

Garvit Kataria, Sahil Sabharwal

Garvit Kataria
Sahil Sabharwal
Open session

World Congress 2026 North America

September 25, 2026 · 15:30–16:00

Mainstage

One Boundary for the Agentic Era

Mark Lechner

Chief Information Security Officer of Docker

Mark Lechner
Open session

World Congress 2026 North America

September 25, 2026 · 12:30–14:30

Stage 11

Docker sandboxes: protect your secrets, tokens, and personal data from AI agent mistakes

Kristiyan Velkov

Front-End Advocate | Speaker | AI & DevOps | Docker Captain | Cursor Ambassador | DevReal | Tech Blogger | Book Author

Kristiyan Velkov
Open session

World Congress 2026 North America

September 25, 2026 · 15:00–17:00

Stage 12

Secure development from pull request to production with GitHub

Sam Jarvinen

Senior Solutions Engineer, GitHub

Sam Jarvinen
Open session

World Congress 2026 North America

September 23, 2026 · 15:45–17:45

Stage 10

Securing the Agentic Stack: Docker Hardened Images and Supply Chain Security

Ajeet Raina

Developer Advocate at Docker

Ajeet Raina