finds.dev← search

// the find

bitnami/sealed-secrets

★ 9,260 · Go · Apache-2.0 · updated Aug 2026

A Kubernetes controller and tool for one-way encrypted Secrets

Sealed Secrets lets you encrypt Kubernetes Secrets client-side into a SealedSecret CRD that only the in-cluster controller can decrypt, so secrets can live safely in git repos. It's aimed at teams doing GitOps who need secrets in version control without a separate vault system.

The scope mechanism (strict/namespace-wide/cluster-wide) that binds ciphertext to name+namespace by default is a genuinely well-thought-out design decision that prevents copy-paste secret theft across namespaces. Key renewal is automatic with a sane 30-day default, and the re-encryption/rotation docs are unusually thorough and honest about what key rotation does and doesn't protect against. Wide installation surface (Helm, Kustomize, Homebrew, MacPorts, Nix, raw binaries) and it's been battle-tested for years with 9k+ stars.

Single controller instance holding the private key is a central point of failure/compromise - there's no native HSM or KMS-backed key storage yet, despite the README acknowledging this is a known gap. No built-in audit trail for who sealed what, since kubeseal doesn't authenticate the user at all, by design. Backup/restore of the sealing key is a manual, easy-to-forget operational step, and losing it means all your SealedSecrets in git become permanently undecryptable - a footgun for anyone who treats this as 'just another manifest'.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →