WeAreDevelopers LIVE Feb 12, 2024

Securing secrets in the GitOps Era

Davide Imola

Storing plain-text Kubernetes secrets in Git exposes your entire infrastructure. How can you protect sensitive credentials without breaking automated deployment pipelines driven by Flux or ArgoCD?

Pause
Mute Enter Fullscreen
#1 about 6 min

Understanding principles and benefits of the GitOps workflow

How declarative version control establishes a unified deployment path for clusters.

#2 about 5 min

Security risks of storing native Kubernetes secrets in git

Why relying on standard base64 encoding exposes sensitive passwords within version control.

#3 about 4 min

Encrypting configurations with the Sealed Secrets cluster operator

Utilizing asymmetric keys to securely store and decrypt configuration data inside clusters.

#4 about 13 min

Demonstration of kubeseal encryption and Flux deployment reconciliation

A practical walkthrough encrypting manual credentials and verifying automated cluster deployment reconciliation.

#5 about 4 min

Evaluating the operational trade-offs of Sealed Secrets

The simplicity of native configurations compared to the manual overhead of updating payloads.

#6 about 5 min

Advanced credential rotation utilizing dedicated Secrets Managers

Deploying centralized database platforms enables granular management interfaces and automated credential scaling.

#7 about 5 min

Integrating cluster resources directly with Secrets Managers

Connecting cluster workloads securely utilizing dedicated provider libraries and container storage interfaces.

#8 about 19 min

Audience Q&A on tenant isolation and continuous integration

Strategies for isolating access layers, restricting public interfaces, and adapting permissions dynamically.

Matching moments

6:14 min

Introduction to securing secrets in GitOps deployments

Alex Soto Alex Soto · LIVE

2:03 min

Additional resources on GitOps and Kubernetes secret management

Alex Soto Alex Soto · LIVE

3:09 min

Injecting sensitive configuration values via Kubernetes secrets

Hannes Norbert Göring · LIVE

2:30 min

Handling passwords and certificates securely via Kubernetes secrets

Aurélie Vache Aurélie Vache · WWC Europe 2026

4:29 min

Configuring a DevSecOps pipeline and Oversecured integration demo

Moataz Nabil Moataz Nabil · LIVE

5:03 min

Designing a self-service internal developer platform with GitOps

Patrick Koss Patrick Koss · WWC Europe 2026

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

From Static Rules to Reasoning Platforms: Scaling Intelligent Canary Delivery in 2026

Daniel Oh

Senior Principal Developer Advocate

Daniel Oh
Open session

World Congress 2026 North America

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
Open session

World Congress 2026 North America

rm -rf: Horror Stories From Unsandboxed AI Agents (and How Docker Fixes This)

Rishab Kumar

Staff Developer Evangelist @ Twilio

Rishab Kumar
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

Zero-Trust Architecture for Agentic AI: Securing Multi-User Access and Third-Party Integrations

Borko Djurkovic

Member of Technical Staff at Cohere

Borko Djurkovic