World Congress 2023 β€’ Nov 10, 2023

External Secrets Operator: the secrets management toolbox for self-sufficient teams

Moritz Johner

Stop scattering sensitive credentials across your repositories. The External Secrets Operator seamlessly bridges centralized vaults with native Kubernetes secrets to secure and streamline your GitOps workflows.

Pause
Mute Enter Fullscreen
#1 about 3 min

Introduction to the presentation context and audience

An introduction to the presentation context and an audience poll categorizing attendees by engineering roles.

#2 about 2 min

Defining secrets management and its security importance

Managing the lifecycle of credentials prevents severe operational consequences from threat actors accessing sensitive company data.

#3 about 5 min

Categorizing secrets by expiry, creation, dependency, and consumer

Secrets vary significantly based on their expiration times, internal or external dependencies, and whether a human or machine utilizes them.

#4 about 2 min

Identifying environments that require strict credential management

Different operational spaces like development laptops, continuous integration pipelines, and deployment infrastructure demand specialized credential constraints.

#5 about 2 min

Utilizing centralized vaults for secure credential storage

Consolidating credentials into a central API enables consistent auditing, lifecycle policy enforcement, and seamless authentication control.

#6 about 2 min

Overcoming secret sprawl and legacy integration challenges

Teams struggle with credentials scattered across infrastructure and the incremental engineering effort needed to automate disparate system integrations securely.

#7 about 2 min

History and evolution of External Secrets Operator

The open-source project evolved from earlier implementations like a GoDaddy toolkit into a consolidated CNCF technology footprint.

#8 about 3 min

How External Secrets Operator fetches central secrets

The operator reads from a central provider vault to automatically update native cluster resources for downstream application consumption.

#9 about 3 min

Configuring secret stores and external secret references

Deploying a custom resource definition safely connects specific service accounts to cloud providers on a configurable automated refresh interval.

#10 about 1 min

Pushing secrets and generating credentials with custom resources

Additional operator configuration APIs allow backend developers to generate new credentials within the cluster or push existing ones upstream to cloud vaults.

#11 about 2 min

Key features including zero-configuration authentication and lifecycle policies

Native IAM integration natively eliminates the initial bootstrap secret problem while enabling robust GitOps workflows via customized rotation policies.

#12 about 2 min

Rendering configuration files directly via automated secret templating

Built-in templating tools safely inject fetched credentials directly into complex runtime application configuration files without relying on extra init containers.

#13 about 2 min

Isolating tenants safely across cluster namespaces and accounts

Operator deployment patterns securely restrict specific workload namespaces to unique cloud provider accounts to enforce strict runtime multi-tenant boundaries.

#14 about 5 min

Question and answer session on caching and specific tools

Audience questions address pod reloading constraints, 1Password system integrations, Git repository encryption tradeoffs, and application caching benefits over direct vault access.

Matching moments

3:09 min

Injecting sensitive configuration values via Kubernetes secrets

Hannes Norbert GΓΆring Β· LIVE

2:03 min

Additional resources on GitOps and Kubernetes secret management

Alex Soto Alex Soto Β· LIVE

6:14 min

Introduction to securing secrets in GitOps deployments

Alex Soto Alex Soto Β· LIVE

2:30 min

Handling passwords and certificates securely via Kubernetes secrets

AurΓ©lie Vache AurΓ©lie Vache Β· WWC Europe 2026

1:06 min

Managing tokens and user credentials securely across endpoints

Mathias Palmersheim Mathias Palmersheim Β· Europe 2026 Virtual

1:42 min

Abstracting Kubernetes complexity with a self-service operator

Jan Lepsky Jan Lepsky

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

Boring Failover: Predictable Region Recovery Across 5,000 Microservices

Garvit Kataria, Sahil Sabharwal

Garvit Kataria
Sahil Sabharwal
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Run your agents in Kubernetes: Build once, deploy anywhere. But really?

Michal Salanci

Senior Systems Engineer at ESET Cybersecurity

Michal Salanci
Open session

World Congress 2026 North America

Zero-Trust Architecture for Agentic AI: Securing Multi-User Access and Third-Party Integrations

Borko Djurkovic

Member of Technical Staff at Cohere

Borko Djurkovic
Open session

World Congress 2026 North America

It passed auth, then production caught fire

Alex Olivier

Co-founder & CPO @ Cerbos | OpenID AuthZEN Co-chair

Alex Olivier