WeAreDevelopers LIVE β€’ Feb 12, 2024

Securing secrets in the GitOps Era

Davide Imola

Storing plain-text Kubernetes secrets in Git exposes your entire infrastructure. How can you protect sensitive credentials without breaking automated deployment pipelines driven by Flux or ArgoCD?

Pause
Mute Enter Fullscreen
#1 about 6 min

Understanding principles and benefits of the GitOps workflow

How declarative version control establishes a unified deployment path for clusters.

#2 about 5 min

Security risks of storing native Kubernetes secrets in git

Why relying on standard base64 encoding exposes sensitive passwords within version control.

#3 about 4 min

Encrypting configurations with the Sealed Secrets cluster operator

Utilizing asymmetric keys to securely store and decrypt configuration data inside clusters.

#4 about 13 min

Demonstration of kubeseal encryption and Flux deployment reconciliation

A practical walkthrough encrypting manual credentials and verifying automated cluster deployment reconciliation.

#5 about 4 min

Evaluating the operational trade-offs of Sealed Secrets

The simplicity of native configurations compared to the manual overhead of updating payloads.

#6 about 5 min

Advanced credential rotation utilizing dedicated Secrets Managers

Deploying centralized database platforms enables granular management interfaces and automated credential scaling.

#7 about 5 min

Integrating cluster resources directly with Secrets Managers

Connecting cluster workloads securely utilizing dedicated provider libraries and container storage interfaces.

#8 about 19 min

Audience Q&A on tenant isolation and continuous integration

Strategies for isolating access layers, restricting public interfaces, and adapting permissions dynamically.

Matching moments

6:14 min

Introduction to securing secrets in GitOps deployments

Alex Soto Alex Soto Β· LIVE

2:03 min

Additional resources on GitOps and Kubernetes secret management

Alex Soto Alex Soto Β· LIVE

3:09 min

Injecting sensitive configuration values via Kubernetes secrets

Hannes Norbert GΓΆring Β· LIVE

2:30 min

Handling passwords and certificates securely via Kubernetes secrets

AurΓ©lie Vache AurΓ©lie Vache Β· WWC Europe 2026

4:29 min

Configuring a DevSecOps pipeline and Oversecured integration demo

Moataz Nabil Moataz Nabil Β· LIVE

5:03 min

Designing a self-service internal developer platform with GitOps

Patrick Koss Patrick Koss Β· WWC Europe 2026

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

From Static Rules to Reasoning Platforms: Scaling Intelligent Canary Delivery in 2026

Daniel Oh

Senior Principal Developer Advocate

Daniel Oh
Open session

World Congress 2026 North America

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
Open session

World Congress 2026 North America

rm -rf: Horror Stories From Unsandboxed AI Agents (and How Docker Fixes This)

Rishab Kumar

Staff Developer Evangelist @ Twilio

Rishab Kumar
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

Zero-Trust Architecture for Agentic AI: Securing Multi-User Access and Third-Party Integrations

Borko Djurkovic

Member of Technical Staff at Cohere

Borko Djurkovic