
Sealed Secrets: Encrypted Secrets You Can Safely Commit

You’ve embraced GitOps and made Git the source of truth for your Kubernetes deployments. Now it’s time to solve one of the biggest challenges in Kubernetes: safely managing Secrets in Git.
IS THIS FOR YOU?
- You run applications on Kubernetes and are comfortable using kubectl
- You know what Kubernetes Secrets and namespaces are
- You’ve ever hesitated before committing a Secret to Git—or worse, already have
- You want to keep your entire cluster configuration in Git without exposing sensitive credentials
- You want to understand Sealed Secrets without needing any cryptography background
AFTER 60 MINUTES, YOU’LL:
- Understand why a Kubernetes Secret stored in Git is simply Base64-encoded data rather than encrypted, and why deleting it later does not remove the security risk
- Install Bitnami Sealed Secrets and confidently use the kubeseal workflow to transform plaintext Secrets into encrypted SealedSecret resources that are safe to store in public or private Git repositories
- Build a clear mental model of how Sealed Secrets works, including public and private key cryptography, where the private key lives, and why only your cluster can decrypt sealed secrets
- Learn the practical differences between strict, namespace-wide, and cluster-wide sealing scopes, and know when to use each
- Understand how Sealed Secrets handles key renewal, why old keys are retained, and how to back up and restore your sealing keys so a lost cluster doesn’t become a lost estate
- Know exactly where Sealed Secrets fits in the Kubernetes ecosystem, and when solutions such as External Secrets or OpenBao are a better choice
Keeping Secrets out of Git often creates a different problem: credentials end up scattered across CI variables, chat messages, local files, or manual deployment steps. Your GitOps repository stops being the complete source of truth, and recovering a cluster becomes far more difficult.
In this session, we’ll fix that. You’ll install the Sealed Secrets controller, create and seal your first Secret, commit it safely to Git, and see why the encrypted output is useless to anyone except your Kubernetes cluster. We’ll also deliberately break a Sealed Secret by moving it to the wrong namespace, making the different sealing scopes intuitive rather than theoretical.
Finally, we’ll cover the production topics that are often overlooked: key rotation, key backup and recovery, and the operational limitations of Sealed Secrets. By the end of this free session, you’ll know how to manage Kubernetes Secrets safely in Git while understanding when Sealed Secrets is the right tool—and when it’s time to adopt a dedicated secrets management solution.
Bring a Kubernetes cluster. Kind, k3s, Minikube, or any other Kubernetes distribution is perfect. The only other prerequisite is a basic understanding of Kubernetes resources and a desire to make your GitOps workflow both secure and complete.
YOUR INSTRUCTOR:
Pascal van Dam is a seasoned Linux and Kubernetes architect with expertise in cloud technologies. As a certified Linux Foundation trainer and IT Gilde Guru, he excels at making complex concepts accessible through his straightforward teaching approach. Drawing from extensive government and enterprise experience, Pascal bridges technical solutions with business value, helping professionals master essential skills quickly.
HOW TO JOIN THIS SESSION?
This live session is completely free! – A limited-time opportunity before they become exclusive to Living Open Source members.
Click here to enter the Zoom Session
Passcode:657744
Related
Details
- Date: August 28
-
Time:
6:00 pm - 7:00 pm
Organizer
- Living Open Source Foundation
- Phone +260963542263
- Email info@livingopensource.org
- View Organizer Website
Venue
- Online