WeAreDevelopers LIVE Feb 12, 2024

Securing secrets in the GitOps Era

Davide Imola

Storing plain-text Kubernetes secrets in Git exposes your entire infrastructure. How can you protect sensitive credentials without breaking automated deployment pipelines driven by Flux or ArgoCD?

Pause
Mute Enter Fullscreen
#1 about 6 min

Understanding principles and benefits of the GitOps workflow

How declarative version control establishes a unified deployment path for clusters.

#2 about 5 min

Security risks of storing native Kubernetes secrets in git

Why relying on standard base64 encoding exposes sensitive passwords within version control.

#3 about 4 min

Encrypting configurations with the Sealed Secrets cluster operator

Utilizing asymmetric keys to securely store and decrypt configuration data inside clusters.

#4 about 13 min

Demonstration of kubeseal encryption and Flux deployment reconciliation

A practical walkthrough encrypting manual credentials and verifying automated cluster deployment reconciliation.

#5 about 4 min

Evaluating the operational trade-offs of Sealed Secrets

The simplicity of native configurations compared to the manual overhead of updating payloads.

#6 about 5 min

Advanced credential rotation utilizing dedicated Secrets Managers

Deploying centralized database platforms enables granular management interfaces and automated credential scaling.

#7 about 5 min

Integrating cluster resources directly with Secrets Managers

Connecting cluster workloads securely utilizing dedicated provider libraries and container storage interfaces.

#8 about 19 min

Audience Q&A on tenant isolation and continuous integration

Strategies for isolating access layers, restricting public interfaces, and adapting permissions dynamically.

Matching moments

6:14 min

Introduction to securing secrets in GitOps deployments

Alex Soto Alex Soto · LIVE

2:03 min

Additional resources on GitOps and Kubernetes secret management

Alex Soto Alex Soto · LIVE

3:09 min

Injecting sensitive configuration values via Kubernetes secrets

Hannes Norbert Göring · LIVE

2:30 min

Handling passwords and certificates securely via Kubernetes secrets

Aurélie Vache Aurélie Vache · World Congress 2026 Europe

4:29 min

Configuring a DevSecOps pipeline and Oversecured integration demo

Moataz Nabil Moataz Nabil · LIVE

5:03 min

Designing a self-service internal developer platform with GitOps

Patrick Koss Patrick Koss · World Congress 2026 Europe

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 15:00–17:00

Stage 12

Secure development from pull request to production with GitHub

Sam Jarvinen

Senior Solutions Engineer, GitHub

Sam Jarvinen
Open session

World Congress 2026 North America

September 23, 2026 · 15:45–17:45

Stage 10

Securing the Agentic Stack: Docker Hardened Images and Supply Chain Security

Ajeet Raina

Developer Advocate, Docker

Ajeet Raina
Open session

World Congress 2026 North America

September 25, 2026 · 12:30–14:30

Stage 11

Docker sandboxes: protect your secrets, tokens, and personal data from AI agent mistakes

Kristiyan Velkov

Front-End Advocate | Speaker | AI & DevOps | Docker Captain | Cursor Ambassador | DevReal | Tech Blogger | Book Author

Kristiyan Velkov
Open session

World Congress 2026 North America

September 24, 2026 · 14:50–15:20

Tech Leaders Stage

Ship with Context: GitLab Orbit and Google Cloud for AI-Powered Software Delivery

Michael Angelo Rivera, Mike Duchesne

Michael Angelo Rivera
Mike Duchesne
Open session

World Congress 2026 North America

September 24, 2026 · 11:40–12:10

Stage 2

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

September 25, 2026 · 15:30–16:00

Mainstage

One Boundary for the Agentic Era

Mark Lechner

Chief Information Security Officer, Dokcer

Mark Lechner