// the find
bitnami/sealed-secrets
A Kubernetes controller and tool for one-way encrypted Secrets
Sealed Secrets lets you encrypt Kubernetes Secrets client-side into a SealedSecret CRD that only the in-cluster controller can decrypt, so secrets can live safely in git repos. It's aimed at teams doing GitOps who need secrets in version control without a separate vault system.
The scope mechanism (strict/namespace-wide/cluster-wide) that binds ciphertext to name+namespace by default is a genuinely well-thought-out design decision that prevents copy-paste secret theft across namespaces. Key renewal is automatic with a sane 30-day default, and the re-encryption/rotation docs are unusually thorough and honest about what key rotation does and doesn't protect against. Wide installation surface (Helm, Kustomize, Homebrew, MacPorts, Nix, raw binaries) and it's been battle-tested for years with 9k+ stars.
Single controller instance holding the private key is a central point of failure/compromise - there's no native HSM or KMS-backed key storage yet, despite the README acknowledging this is a known gap. No built-in audit trail for who sealed what, since kubeseal doesn't authenticate the user at all, by design. Backup/restore of the sealing key is a manual, easy-to-forget operational step, and losing it means all your SealedSecrets in git become permanently undecryptable - a footgun for anyone who treats this as 'just another manifest'.