WeAreDevelopers LIVE • Feb 12, 2024

Securing secrets in the GitOps Era

Davide Imola

Storing plain-text Kubernetes secrets in Git exposes your entire infrastructure. How can you protect sensitive credentials without breaking automated deployment pipelines driven by Flux or ArgoCD?

Pause
Mute Enter Fullscreen
#1 about 6 min

Understanding principles and benefits of the GitOps workflow

How declarative version control establishes a unified deployment path for clusters.

#2 about 5 min

Security risks of storing native Kubernetes secrets in git

Why relying on standard base64 encoding exposes sensitive passwords within version control.

#3 about 4 min

Encrypting configurations with the Sealed Secrets cluster operator

Utilizing asymmetric keys to securely store and decrypt configuration data inside clusters.

#4 about 13 min

Demonstration of kubeseal encryption and Flux deployment reconciliation

A practical walkthrough encrypting manual credentials and verifying automated cluster deployment reconciliation.

#5 about 4 min

Evaluating the operational trade-offs of Sealed Secrets

The simplicity of native configurations compared to the manual overhead of updating payloads.

#6 about 5 min

Advanced credential rotation utilizing dedicated Secrets Managers

Deploying centralized database platforms enables granular management interfaces and automated credential scaling.

#7 about 5 min

Integrating cluster resources directly with Secrets Managers

Connecting cluster workloads securely utilizing dedicated provider libraries and container storage interfaces.

#8 about 19 min

Audience Q&A on tenant isolation and continuous integration

Strategies for isolating access layers, restricting public interfaces, and adapting permissions dynamically.

Matching moments

6:14 min

Introduction to securing secrets in GitOps deployments

Alex Soto Alex Soto · LIVE

2:03 min

Additional resources on GitOps and Kubernetes secret management

Alex Soto Alex Soto · LIVE

3:09 min

Injecting sensitive configuration values via Kubernetes secrets

Hannes Norbert Göring · LIVE

2:30 min

Handling passwords and certificates securely via Kubernetes secrets

Aurélie Vache Aurélie Vache · World Congress 2026 Europe

4:29 min

Configuring a DevSecOps pipeline and Oversecured integration demo

Moataz Nabil Moataz Nabil · LIVE

5:03 min

Designing a self-service internal developer platform with GitOps

Patrick Koss Patrick Koss · World Congress 2026 Europe